cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2020.8.14.223 Par Nicolas Coolman (2020/08/14)
~ Démarré par melvi (Administrator) (2020/08/17 08:36:03)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Legal
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\melvi\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\melvi\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
Windows 10 Home, 64-bit (Build 18362) =>.Microsoft Corporation

---\\ NAVIGATEURS INTERNET (3) - 0s
~ GCIE: Google Chrome v84.0.4147.125
~ MSIE: Internet Explorer v11.959.18362.0
~ OBIE: Microsoft Edge v84.0.522.59

---\\ INFORMATIONS SUR LES PRODUITS WINDOWS (2) - 3s
~ Windows Server License Manager Script : OK
Windows Automatic Updates : OK

---\\ LOGICIELS DE PROTECTION (1) - 4s
Windows Defender W10 (Activate) (Protection)

---\\ LOGICIELS D'OPTIMISATION (3) - 4s
~ CCleaner Browser v84.0.5275.108 (Optimisation)
~ CCleaner Update Helper v1.7.913.0 (Optimisation)
~ CCleaner v5.68 (Optimisation)

---\\ INFORMATIONS SUR LE SYSTÈME (6) - 0s
~ Operating System: AMD64 Family 22 Model 48 Stepping 1, AuthenticAMD
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 7264.06 MB (44% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 876 GB (92%) free of 952 GB : OK =>.Disk Space

---\\ MODE DE CONNEXION AU SYSTÈME (3) - 0s
~ Computer Name: ASUS-MELVIN
~ User Name: melvi
~ Logged in as Administrator

---\\ ÉNUMÉRATION DES UNITÉS DE STOCKAGE (1) - 0s
~ Drive C: has 876 GB free of 952 GB (System)

---\\ ÉTAT DU CENTRE DE SÉCURITÉ WINDOWS (7) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ RECHERCHE PARTICULIÈRE DE FICHIERS GÉNÉRIQUES (26) - 10s
[MD5.8A1944E0D90C4FD44B59E07A8AB6E2C3] - 30/07/2020 - (.Microsoft Corporation - Explorateur Windows.) -- C:\WINDOWS\Explorer.exe [4625192] =>.Microsoft®
[MD5.F68AF942FD7CCC0E7BAB1A2335D2AD26] - 19/03/2019 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [71168] [Unsigned] =>.Microsoft Corporation
[MD5.E83650F70459A027AA596E1A73C961A1] - 11/10/2019 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\WINDOWS\System32\Wininit.exe [398728] [Unsigned] =>.Microsoft Corporation
[MD5.5D2F4F7CCC70ADCFEE99C56CBF09F18E] - 18/04/2020 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\WINDOWS\System32\wininet.dll [5040640] [Unsigned] =>.Microsoft Corporation
[MD5.F85DEFC2BE480CB713D2F179CB5782E0] - 12/03/2020 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\WINDOWS\System32\Winlogon.exe [845312] [Unsigned] =>.Microsoft Corporation
[MD5.8BA955BD719207F590EC8C5F2B46AE59] - 12/03/2020 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\WINDOWS\System32\sppcomapi.dll [307712] [Unsigned] =>.Microsoft Corporation
[MD5.B0F1AF6795A83628F7D785FC4621507E] - 18/05/2020 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\WINDOWS\System32\dnsapi.dll [822272] =>.Microsoft®
[MD5.23F45825244CFCB11CC6355690F3FFAB] - 18/05/2020 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\WINDOWS\Syswow64\dnsapi.dll [592944] =>.Microsoft®
[MD5.95336878FE34E39BC21F8BF5C60448C0] - 18/05/2020 - (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\WINDOWS\System32\wuaueng.dll [3109376] [Unsigned] =>.Microsoft Corporation
[MD5.4BB305AEED92BB280760B127548E1DC2] - 19/03/2019 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\WINDOWS\System32\fr-FR\user32.dll.mui [19968] [Unsigned] =>.Microsoft Corporation
[MD5.67FA68C9522EACE1A2BD44486FFC8771] - 18/05/2020 - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [661816] [Unsigned] =>.Microsoft Corporation
[MD5.30D7EEDAB3671A5DF808D1836CCACF56] - 12/03/2020 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [30008] [Unsigned] =>.Microsoft Corporation
[MD5.3E9C20ED02FAA6D194C060BC6E7D587E] - 13/12/2019 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [100352] [Unsigned] =>.Microsoft Corporation
[MD5.81E3779064C04790E30F25770F0AEADD] - 19/03/2019 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [173056] [Unsigned] =>.Microsoft Corporation
[MD5.D974C10E19DDC10622E30904AEE16FA3] - 19/03/2019 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [151040] [Unsigned] =>.Microsoft Corporation
[MD5.1D742547071FC1436ED72A3F9DB6E1F0] - 12/03/2020 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [114688] [Unsigned] =>.Microsoft Corporation
[MD5.B475892255B02D33CF29B24FBD4AFDC9] - 19/03/2019 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [119296] [Unsigned] =>.Microsoft Corporation
[MD5.5E05C0FEA671B910FEBC634E796C38B5] - 19/03/2019 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [224768] [Unsigned] =>.Microsoft Corporation
[MD5.90D2833915ACAF0F11F99B330CF2250A] - 17/06/2020 - (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [561464] [Unsigned] =>.Microsoft Corporation
[MD5.729ED379D3A960CFBE02C7634651AC63] - 20/08/2019 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [337408] [Unsigned] =>.Microsoft Corporation
[MD5.CA25673ED59E3B133B6EC7C043296FEB] - 12/03/2020 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2698040] [Unsigned] =>.Microsoft Corporation
[MD5.AC682BC99BECA3A6C8C71234A9BC4225] - 19/03/2019 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\WINDOWS\System32\drivers\Parport.sys [108032] [Unsigned] =>.Microsoft Corporation
[MD5.555E33527CC3C34620E49F5F86C8F7B0] - 19/03/2019 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [112128] [Unsigned] =>.Microsoft Corporation
[MD5.51D49770FD9D2E1956833C1F4D992893] - 20/08/2019 - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [167936] [Unsigned] =>.Microsoft Corporation
[MD5.9AF99FB2DA176C88C68D886046C56B01] - 19/03/2019 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [132616] [Unsigned] =>.Microsoft Corporation
[MD5.7764E62EF94DDA90E87309E739F6970E] - 12/03/2020 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\WINDOWS\System32\drivers\volsnap.sys [429880] [Unsigned] =>.Microsoft Corporation

---\\ LISTE DES SERVICES (Non désactivés) (68) - 11s
O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atiesrxx.exe =>.Advanced Micro Devices, Inc.®
O23 - Service: ASLDR Service (ASLDRService) . (.ASUSTek Computer Inc. - ASLDR Service.) - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe =>.ASUSTeK Computer Inc.®
O23 - Service: AtherosSvc (AtherosSvc) . (. - Windows Setup API.) - C:\WINDOWS\System32\drivers\AdminService.exe [Unsigned] =>.Atheros
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) . (.ASUSTek Computer Inc. - GFNEXSrv.) - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe =>.ASUSTeK Computer Inc.®
O23 - Service: C:\WINDOWS\System32\AudioEndpointBuilder.dll (AudioEndpointBuilder) . (.Microsoft Corporation - Générateur de points de terminaison du serv.) - C:\WINDOWS\System32\AudioEndpointBuilder.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\audiosrv.dll (Audiosrv) . (.Microsoft Corporation - Service Audio Windows.) - C:\WINDOWS\System32\Audiosrv.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\bfe.dll (BFE) . (.Microsoft Corporation - Moteur de filtrage de base.) - C:\WINDOWS\System32\bfe.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\qmgr.dll (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) - C:\WINDOWS\System32\qmgr.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\system32\bisrv.dll (BrokerInfrastructure) . (.Microsoft Corporation - Process State Manager (PSM) Service.) - C:\WINDOWS\System32\psmsrv.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Service CCleaner Browser Update (ccleaner) (ccleaner) . (.Piriform Software - CCleaner Browser.) - C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe =>.Piriform Software Ltd®
O23 - Service: C:\WINDOWS\System32\cdpusersvc.dll (CDPUserSvc) . (.Microsoft Corporation - Composants utilisateur Microsoft (R) CDP.) - C:\WINDOWS\System32\CDPUserSvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Service pour utilisateur de plateforme d’appareils connecté (CDPUserSvc_1c9fde3) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
O23 - Service: C:\WINDOWS\System32\certprop.dll (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) - C:\WINDOWS\System32\certprop.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\coremessaging.dll (CoreMessagingRegistrar) . (.Microsoft Corporation - Microsoft CoreMessaging Dll.) - C:\Windows\System32\coremessaging.dll =>.Microsoft®
O23 - Service: C:\WINDOWS\System32\cryptsvc.dll (CryptSvc) . (.Microsoft Corporation - Services de chiffrement.) - C:\WINDOWS\System32\cryptsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: @C:\WINDOWS\system32\CxAudMsg64.exe,-100 (CxAudMsg) . (.Conexant Systems Inc. - Conexant Audio Message Service.) - C:\WINDOWS\system32\CxAudMsg64.exe [Unsigned] =>.Conexant Systems Inc.
O23 - Service: C:\WINDOWS\System32\das.dll (DeviceAssociationService) . (.Microsoft Corporation - Service d’association de périphérique.) - C:\WINDOWS\System32\das.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dhcpcore.dll (Dhcp) . (.Microsoft Corporation - Service client DHCP.) - C:\Windows\System32\dhcpcore.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\diagtrack.dll (DiagTrack) . (.Microsoft Corporation - Suivi des diagnostics Microsoft Windows.) - C:\WINDOWS\System32\diagtrack.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\dispbroker.desktop.dll (DispBrokerDesktopSvc) . (.Microsoft Corporation - Courtier d'affichage du bureau.) - C:\WINDOWS\System32\DispBroker.Desktop.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dnsapi.dll (Dnscache) . (.Microsoft Corporation - Service de résolution du cache DNS.) - C:\WINDOWS\System32\dnsrslvr.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\dosvc.dll (DoSvc) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
O23 - Service: C:\WINDOWS\System32\dusmsvc.dll (DusmSvc) . (.Microsoft Corporation - Service Consommation des données.) - C:\WINDOWS\System32\dusmsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Service Mise à jour de Microsoft Edge (edgeupdate) (edgeupdate) . (.Microsoft Corporation - Microsoft Edge Update.) - C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe =>.Microsoft®
O23 - Service: C:\WINDOWS\System32\wevtsvc.dll (EventLog) . (.Microsoft Corporation - Service journal des événements.) - C:\WINDOWS\System32\wevtsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: @comres.dll,-2450 (EventSystem) . (.Microsoft Corporation - COM+.) - C:\Windows\System32\es.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\FntCache.dll (FontCache) . (.Microsoft Corporation - Service de cache de police Windows.) - C:\WINDOWS\System32\FntCache.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: @gpapi.dll,-112 (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) - C:\WINDOWS\System32\gpsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
O23 - Service: ICEsoundService (ICEsoundService) . (.ICEpower - ICEpower ICEsound APO service.) - C:\Windows\System32\DriverStore\FileRepository\x40plmwa.inf_amd64_09e65ea70153c3a6\ICEsoundService64.exe =>.ICEpower a/s®
O23 - Service: C:\WINDOWS\System32\iphlpsvc.dll (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) - C:\WINDOWS\System32\iphlpsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\srvsvc.dll (LanmanServer) . (.Microsoft Corporation - DLL du service Serveur.) - C:\WINDOWS\System32\srvsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\wkssvc.dll (LanmanWorkstation) . (.Microsoft Corporation - DLL du service Station de travail.) - C:\WINDOWS\System32\wkssvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\system32\lsm.dll (LSM) . (.Microsoft Corporation - Service du gestionnaire de session locale.) - C:\WINDOWS\System32\lsm.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\moshost.dll (MapsBroker) . (.Microsoft Corporation - Gestionnaire des cartes téléchargées.) - C:\WINDOWS\System32\moshost.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\FirewallAPI.dll (mpssvc) . (.Microsoft Corporation - Service de protection Microsoft.) - C:\WINDOWS\System32\mpssvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\nlasvc.dll (NlaSvc) . (.Microsoft Corporation - Connaissance des emplacements réseau 2.) - C:\WINDOWS\System32\nlasvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\nsisvc.dll (nsi) . (.Microsoft Corporation - Serveur RPC de l’interface du magasin résea.) - C:\WINDOWS\System32\nsisvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\APHostRes.dll (OneSyncSvc) . (.Microsoft Corporation - Accounts Host Service.) - C:\WINDOWS\System32\APHostService.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Hôte de synchronisation_1c9fde3 (OneSyncSvc_1c9fde3) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
O23 - Service: C:\WINDOWS\System32\umpo.dll (Power) . (.Microsoft Corporation - Service d’alimentation en mode utilisateur.) - C:\WINDOWS\System32\umpo.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\profsvc.dll (ProfSvc) . (.Microsoft Corporation - ProfSvc.) - C:\WINDOWS\System32\profsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\rasmans.dll (RasMan) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) - C:\WINDOWS\System32\rasmans.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\system32\RpcEpMap.dll (RpcEptMapper) . (.Microsoft Corporation - Mappeur de point de terminaison RPC.) - C:\WINDOWS\System32\RpcEpMap.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: @combase.dll,-5010 (RpcSs) . (.Microsoft Corporation - Distributed COM Services.) - C:\WINDOWS\System32\rpcss.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Conexant SmartAudio service (SAService) . (.Conexant Systems, Inc. - SmartAudio Service Application.) - C:\Windows\System32\SASrv.exe =>.Conexant Systems, Inc.®
O23 - Service: C:\WINDOWS\System32\schedsvc.dll (Schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) - C:\WINDOWS\System32\schedsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\Sens.dll (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) - C:\WINDOWS\System32\sens.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\SgrmBroker.exe,-100 (SgrmBroker) . (.Microsoft Corporation - Service Broker du moniteur d'exécution Syst.) - C:\WINDOWS\System32\SgrmBroker.exe [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\shsvcs.dll (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) - C:\Windows\System32\shsvcs.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\spoolsv.exe,-1 (Spooler) . (.Microsoft Corporation - Application sous-système spouleur.) - C:\WINDOWS\System32\spoolsv.exe [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\sppsvc.exe,-101 (sppsvc) . (.Microsoft Corporation - Service de la plateforme de protection logi.) - C:\WINDOWS\System32\sppsvc.exe [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\wiaservc.dll (stisvc) . (.Microsoft Corporation - Service de périphériques d’images fixes.) - C:\WINDOWS\System32\wiaservc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\sysmain.dll (SysMain) . (.Microsoft Corporation - Hôte de Service SysMain.) - C:\WINDOWS\System32\sysmain.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\system32\SystemEventsBrokerServer.dll (SystemEventsBroker) . (.Microsoft Corporation - Service Broker pour les événements système.) - C:\WINDOWS\System32\SystemEventsBrokerServer.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: TeamViewer 11 (TeamViewer) . (.TeamViewer GmbH - TeamViewer 11.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer®
O23 - Service: C:\WINDOWS\System32\themeservice.dll (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) - C:\WINDOWS\System32\themeservice.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\usermgr.dll (UserManager) . (.Microsoft Corporation - UserMgr.) - C:\WINDOWS\System32\usermgr.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\usosvc.dll (UsoSvc) . (.Microsoft Corporation - Mettre à jour la session du service Orchest.) - C:\WINDOWS\System32\usosvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\wcmsvc.dll (Wcmsvc) . (.Microsoft Corporation - DLL du service de gestion des connexions Wi.) - C:\WINDOWS\System32\wcmsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) . (.Microsoft Corporation - Antimalware Service Executable.) - C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2007.8-0\MsMpEng.exe =>.Microsoft®
O23 - Service: C:\WINDOWS\System32\wbem\wmisvc.dll (Winmgmt) . (.Microsoft Corporation - WMI.) - C:\WINDOWS\System32\wbem\WMIsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\wlansvc.dll (WlanSvc) . (.Microsoft Corporation - DLL du service de configuration automatique.) - C:\WINDOWS\System32\wlansvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\wpnservice.dll (WpnService) . (.Microsoft Corporation - Service du système de notifications Push Wi.) - C:\WINDOWS\System32\WpnService.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\WpnUserService.dll (WpnUserService) . (.Microsoft Corporation - Service utilisateur de notifications Push W.) - C:\WINDOWS\System32\WpnUserService.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: Service utilisateur de notifications Push Windows_1c9fde3 (WpnUserService_1c9fde3) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
O23 - Service: C:\WINDOWS\System32\wscsvc.dll (wscsvc) . (.Microsoft Corporation - Service Centre de sécurité de Windows.) - C:\WINDOWS\System32\wscsvc.dll [Unsigned] =>.Microsoft Corporation
O23 - Service: C:\WINDOWS\System32\SearchIndexer.exe,-103 (WSearch) . (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - C:\Windows\System32\SearchIndexer.exe [Unsigned] =>.Microsoft Corporation

---\\ SERVICES NON MICROSOFT (SR=Démarré,SS=Stoppé) (87) - 46s
SR - Boot [19/03/2019] [ 107528] (3ware) . (.LSI.) - C:\WINDOWS\System32\drivers\3ware.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 1135632] (ADP80XX) . (.PMC-Sierra.) - C:\WINDOWS\System32\drivers\ADP80XX.SYS =>.Microsoft Windows®
SR - Demand [25/05/2015] [ 21816] ASUS Charger Driver (AiCharger) . (.ASUSTek Computer Inc..) - C:\WINDOWS\System32\DRIVERS\AiCharger.sys =>.ASUSTeK Computer Inc.®
SR - Auto [18/09/2019] [ 508008] (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atiesrxx.exe =>.Advanced Micro Devices, Inc.®
SR - Demand [19/03/2019] [ 18432] AMD GPIO Client Driver (amdgpio2) . (.Advanced Micro Devices, Inc.) - C:\WINDOWS\System32\drivers\amdgpio2.sys [Unsigned] =>.Advanced Micro Devices, Inc
SR - Demand [19/03/2019] [ 37888] AMD I2C Controller Service (amdi2c) . (.Advanced Micro Devices, Inc.) - C:\WINDOWS\System32\drivers\amdi2c.sys [Unsigned] =>.Advanced Micro Devices, Inc
SR - Boot [18/08/2016] [ 49448] AMD Audio Bus Lower Filter (amdkmafd) . (.Advanced Micro Devices, Inc..) - C:\WINDOWS\System32\drivers\amdkmafd.sys =>.Advanced Micro Devices, Inc.®
SR - Demand [12/06/2017] [ 101232] AMD Kernel Mode CSP Service (amdkmcsp) . (.Advanced Micro Devices, Inc..) - C:\WINDOWS\System32\DRIVERS\amdkmcsp.sys =>.Advanced Micro Devices Inc.®
SR - Demand [18/09/2019] [55249512] (amdkmdag) . (.Advanced Micro Devices, Inc..) - C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atikmdag.sys =>.Advanced Micro Devices, Inc.®
SR - Demand [18/09/2019] [ 595048] (amdkmdap) . (.Advanced Micro Devices, Inc..) - C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atikmpag.sys =>.Advanced Micro Devices, Inc.®
SR - Boot [18/09/2019] [ 102832] AMD PCI Root Bus Lower Filter (amdkmpfd) . (.Advanced Micro Devices, Inc..) - C:\WINDOWS\System32\drivers\amdkmpfd.sys =>.Advanced Micro Devices, Inc.®
SR - Boot [19/03/2019] [ 83464] (amdsata) . (.Advanced Micro Devices.) - C:\WINDOWS\System32\drivers\amdsata.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 259600] (amdsbs) . (.AMD Technologies Inc..) - C:\WINDOWS\System32\drivers\amdsbs.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 27176] (amdxata) . (.Advanced Micro Devices.) - C:\WINDOWS\System32\drivers\amdxata.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 132112] Adaptec SAS/SATA-II RAID S (arcsas) . (.PMC-Sierra, Inc..) - C:\WINDOWS\System32\drivers\arcsas.sys =>.Microsoft Windows®
SR - Auto [14/12/2015] [ 126616] ASLDR Service (ASLDRService) . (.ASUSTek Computer Inc..) - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe =>.ASUSTeK Computer Inc.®
SR - Auto [08/05/2015] [ 18048] ASMMAP64 (ASMMAP64) . (.ASUS.) - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys =>.Microsoft Windows Hardware Compatibility Publisher®
SR - Demand [09/03/2017] [ 128024] ASUS Input Touchpad Device (AsusTP) . (.ASUS Corporation.) - C:\WINDOWS\System32\drivers\AsusTP.sys =>.ASUSTeK Computer Inc.®
SR - Auto [31/01/2019] [ 415992] AtherosSvc (AtherosSvc) . (.Qualcomm Atheros.) - C:\WINDOWS\System32\drivers\AdminService.exe =>.Qualcomm Atheros®
SR - Demand [19/03/2019] [ 4233728] Qualcomm Atheros Extens (athr) . (.Qualcomm Atheros Communications, Inc..) - C:\WINDOWS\System32\drivers\athw8x.sys [Unsigned] =>.Qualcomm Atheros Communications, Inc.
SR - Demand [26/04/2017] [ 110088] AMD Function Driver fo (AtiHDAudioService) . (.Advanced Micro Devices.) - C:\WINDOWS\System32\drivers\AtihdWT6.sys =>.Microsoft Windows Hardware Compatibility Publisher®
SR - Auto [01/04/2015] [ 107320] ATKGFNEX Service (ATKGFNEXSrv) . (.ASUSTek Computer Inc..) - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe =>.ASUSTeK Computer Inc.®
SR - System [08/05/2015] [ 20096] ATKWMIACPI Driver (ATKWMIACPIIO) . (.ASUSTek Computer Inc..) - C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys =>.Microsoft Windows Hardware Compatibility Publisher®
SR - Boot [19/03/2019] [ 534032] QLogic Network Adapter VBD (b06bdrv) . (.QLogic Corporation.) - C:\WINDOWS\System32\drivers\bxvbda.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 9728] bcmfn2 Service (bcmfn2) . (...) - C:\WINDOWS\System32\drivers\bcmfn2.sys [Unsigned] =>.Broadcom Corporation
SR - Demand [31/01/2019] [ 69368] BtFilter (BtFilter) . (.Qualcomm.) - C:\WINDOWS\System32\drivers\btfilter.sys =>.Qualcomm Atheros®
SR - Auto [11/07/2020] [ 200416] Service CCleaner Browser Update (ccleaner) (ccleaner) . (.Piriform Software.) - C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe =>.Piriform Software Ltd®
SS - Demand [28/07/2020] [ 1332800] CCleaner Browser Elevation Service (CCleanerBrowserElevatio (CCleanerBrowserElevationService) . (.Piriform Software.) - C:\Program Files (x86)\CCleaner Browser\Application\84.0.5275.108\elevation_service.exe =>.Piriform Software Ltd®
SS - Demand [11/07/2020] [ 200416] Service CCleaner Browser Update (ccleanerm) (ccleanerm) . (.Piriform Software.) - C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe =>.Piriform Software Ltd®
SR - Boot [19/03/2019] [ 319528] (cht4iscsi) . (.Chelsio Communications.) - C:\WINDOWS\System32\drivers\cht4sx64.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 1866768] Chelsio Virtual Bus Driver (cht4vbd) . (.Chelsio Communications.) - C:\WINDOWS\System32\drivers\cht4vx64.sys =>.Microsoft Windows®
SR - Demand [27/11/2018] [ 3463464] Conexant UA (CnxtHdAudService) . (.Conexant Systems Inc..) - C:\WINDOWS\System32\drivers\CHDRT64.sys =>.Synaptics Incorporated®
SR - Auto [20/10/2014] [ 207576] @C:\WINDOWS\system32\CxAudMsg64.exe,-100 (CxAudMsg) . (.Conexant Systems Inc..) - C:\WINDOWS\system32\CxAudMsg64.exe =>.Conexant Systems, Inc.®
SS - Demand [05/06/2018] [ 326032] Device Activation Service (DevActSvc) . (.ASUSTeK Computer Inc..) - C:\Program Files (x86)\ASUS\ASUS Device Activation\DevActSvc.exe =>.ASUSTeK Computer Inc.®
SR - Demand [18/05/2017] [ 131984] SAMSUNG Mobile USB Comp (dg_ssudbus) . (.Samsung Electronics Co., Ltd..) - C:\WINDOWS\System32\DRIVERS\ssudbus.sys =>.Samsung Electronics Co., Ltd.®
SR - Boot [19/03/2019] [ 3419176] QLogic 10 Gigabit Ethernet Ada (ebdrv) . (.QLogic Corporation.) - C:\WINDOWS\System32\drivers\evbda.sys =>.Microsoft Windows®
SS - Demand [08/08/2020] [ 1309680] Google Chrome Elevation Service (GoogleChromeElevationService) . (.Google LLC.) - C:\Program Files (x86)\Google\Chrome\Application\84.0.4147.125\elevation_service.exe =>.Google LLC®
SR - Auto [30/07/2017] [ 153168] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [30/07/2017] [ 153168] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SR - Demand [07/08/2019] [ 32680] ASUS Wireless Radio Control (HIDSwitch) . (.ASUS.) - C:\WINDOWS\System32\drivers\AsRadioControl.sys =>.ASUSTek Computer Inc.®
SR - Boot [19/03/2019] [ 64528] (HpSAMD) . (.Hewlett-Packard Company.) - C:\WINDOWS\System32\drivers\HpSAMD.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 36352] Intel Serial IO GPIO Controlle (iagpio) . (.Intel(R) Corporation.) - C:\WINDOWS\System32\drivers\iagpio.sys [Unsigned] =>.Intel(R) Corporation
SR - Demand [19/03/2019] [ 91136] Intel(R) Serial IO I2C Host Cont (iai2c) . (.Intel(R) Corporation.) - C:\WINDOWS\System32\drivers\iai2c.sys [Unsigned] =>.Intel(R) Corporation
SR - Demand [19/03/2019] [ 79360] Intel(R) S (iaLPSS2i_GPIO2) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 93184] In (iaLPSS2i_GPIO2_BXT_P) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 112128] Intel( (iaLPSS2i_GPIO2_CNL) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_CNL.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 96256] Intel( (iaLPSS2i_GPIO2_GLK) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_GLK.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 171520] Intel(R) Seria (iaLPSS2i_I2C) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 175104] Intel( (iaLPSS2i_I2C_BXT_P) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 180736] Intel(R) S (iaLPSS2i_I2C_CNL) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_CNL.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 177664] Intel(R) S (iaLPSS2i_I2C_GLK) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_GLK.sys [Unsigned] =>.Intel Corporation
SR - Demand [19/03/2019] [ 38128] Intel(R) Serial IO (iaLPSSi_GPIO) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys =>.Intel Corporation - Client Components Group®
SR - Demand [19/03/2019] [ 113152] Intel(R) Serial IO I (iaLPSSi_I2C) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [Unsigned] =>.Intel Corporation
SR - Boot [19/03/2019] [ 885048] Intel Chipset SATA RAI (iaStorAVC) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaStorAVC.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 411960] Intel RAID Controller Wi (iaStorV) . (.Intel Corporation.) - C:\WINDOWS\System32\drivers\iaStorV.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 566800] Mellanox InfiniBand Bus/A (ibbus) . (.Mellanox.) - C:\WINDOWS\System32\drivers\ibbus.sys =>.Microsoft Windows®
SR - Auto [27/11/2018] [ 806136] ICEsoundService (ICEsoundService) . (.ICEpower.) - C:\Windows\System32\DriverStore\FileRepository\x40plmwa.inf_amd64_09e65ea70153c3a6\ICEsoundService64.exe =>.ICEpower a/s®
SR - Boot [19/03/2019] [ 148520] (ItSas35i) . (.Avago Technologies.) - C:\WINDOWS\System32\drivers\ItSas35i.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 109064] (LSI_SAS) . (.LSI Corporation.) - C:\WINDOWS\System32\drivers\lsi_sas.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 124448] (LSI_SAS2i) . (.LSI Corporation.) - C:\WINDOWS\System32\drivers\lsi_sas2i.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 128528] (LSI_SAS3i) . (.Avago Technologies.) - C:\WINDOWS\System32\drivers\lsi_sas3i.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 82960] (LSI_SSS) . (.LSI Corporation.) - C:\WINDOWS\System32\drivers\lsi_sss.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 59920] (megasas) . (.Avago Technologies.) - C:\WINDOWS\System32\drivers\megasas.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 75280] (megasas2i) . (.Avago Technologies.) - C:\WINDOWS\System32\drivers\MegaSas2i.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 94736] (megasas35i) . (.Avago Technologies.) - C:\WINDOWS\System32\drivers\megasas35i.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 576016] (megasr) . (.LSI Corporation, Inc..) - C:\WINDOWS\System32\drivers\megasr.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 1150480] Mellanox ConnectX Bus E (mlx4_bus) . (.Mellanox.) - C:\WINDOWS\System32\drivers\mlx4_bus.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 64016] (mvumis) . (.Marvell Semiconductor, Inc..) - C:\WINDOWS\System32\drivers\mvumis.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 153616] NetworkDirect Service (ndfltr) . (.Mellanox.) - C:\WINDOWS\System32\drivers\ndfltr.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 150544] (nvraid) . (.NVIDIA Corporation.) - C:\WINDOWS\System32\drivers\nvraid.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 166408] (nvstor) . (.NVIDIA Corporation.) - C:\WINDOWS\System32\drivers\nvstor.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 58896] (percsas2i) . (.Avago Technologies.) - C:\WINDOWS\System32\drivers\percsas2i.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 68624] (percsas3i) . (.Avago Technologies.) - C:\WINDOWS\System32\drivers\percsas3i.sys =>.Microsoft Windows®
SR - Demand [15/07/2015] [ 887552] Realtek RT640 NT Driver (rt640x64) . (.Realtek.) - C:\WINDOWS\System32\drivers\rt640x64.sys =>.Realtek Semiconductor Corp®
SR - Auto [27/10/2016] [ 416576] Conexant SmartAudio service (SAService) . (.Conexant Systems, Inc..) - C:\Windows\System32\SASrv.exe =>.Conexant Systems, Inc.®
SR - Boot [19/03/2019] [ 45072] (SiSRaid2) . (.Silicon Integrated Systems Corp..) - C:\WINDOWS\System32\drivers\SiSRaid2.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 81936] (SiSRaid4) . (.Silicon Integrated Systems.) - C:\WINDOWS\System32\drivers\sisraid4.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 220176] (SmartSAMD) . (.Microsemi Corportation.) - C:\WINDOWS\System32\drivers\SmartSAMD.sys =>.Microsoft Windows®
SR - Demand [18/05/2017] [ 166288] SAMSUNG Mobile USB Modem Dri (ssudmdm) . (.Samsung Electronics Co., Ltd..) - C:\WINDOWS\System32\DRIVERS\ssudmdm.sys =>.Samsung Electronics Co., Ltd.®
SR - Boot [19/03/2019] [ 31240] (stexstor) . (.Promise Technology, Inc..) - C:\WINDOWS\System32\drivers\stexstor.sys =>.Microsoft Windows®
SR - Auto [12/05/2016] [ 7032080] TeamViewer 11 (TeamViewer) . (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer®
SR - Demand [13/08/2016] [ 65080] AMD USB Filter Driver (usbfilter) . (.Advanced Micro Devices, Inc.) - C:\WINDOWS\System32\DRIVERS\usbfilter.sys =>.Advanced Micro Devices, Inc.®
SR - Boot [19/03/2019] [ 166928] (vsmraid) . (.VIA Technologies Inc.,Ltd.) - C:\WINDOWS\System32\drivers\vsmraid.sys =>.Microsoft Windows®
SR - Boot [19/03/2019] [ 305672] VIA StorX Storage RAID Co (VSTXRAID) . (.VIA Corporation.) - C:\WINDOWS\System32\drivers\vstxraid.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 37928] WinMad Service (WinMad) . (.Mellanox.) - C:\WINDOWS\System32\drivers\winmad.sys =>.Microsoft Windows®
SR - Demand [19/03/2019] [ 77832] WinVerbs Service (WinVerbs) . (.Mellanox.) - C:\WINDOWS\System32\drivers\winverbs.sys =>.Microsoft Windows®
SS - Demand [31/01/2020] [ 244392] WPS Office Cloud Service (wpscloudsvr) . (.Zhuhai Kingsoft Office Software Co.,Ltd.) - C:\Program Files (x86)\Kingsoft\WPS Office\wpscloudsvr.exe =>.Zhuhai Kingsoft Office Software Co., Ltd.®

---\\ TÂCHES PLANIFIÉES EN AUTOMATIQUE (Registre) (52) - 42s
O38 - TASK: {062EAC29-52EB-4C03-A007-E9D693858131} [64Bits][\WpsExternal_melvi_20200131112448] - (.Zhuhai Kingsoft Office Software Co.,Ltd - WPS Office.) -- C:\Program Files (x86)\Kingsoft\WPS Office\ksolaunch.exe [1285800] =>.Zhuhai Kingsoft Office Software Co.,Ltd
O38 - TASK: {0DBAA825-572D-4755-9AC3-66DA8F856417} [64Bits][\StartDVR] - (.Advanced Micro Devices, Inc. - Radeon Settings: Command Line Interface.) -- C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [68280] =>.Advanced Micro Devices, Inc.
O38 - TASK: {22102042-52FB-47F1-9C15-7D763FEA94E6} [64Bits][\Update Checker] - (.ASUSTek Computer Inc. - Update Checker.) -- C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [143160] =>.ASUSTek Computer Inc.
O38 - TASK: {309E3EF8-8C76-4B15-8BA2-267A6707F7A7} [64Bits][\WpsKtpcntrQingTask_Administrator] - (.Zhuhai Kingsoft Office Software Co.,Ltd - ktpcntr.) -- C:\Program Files (x86)\Kingsoft\WPS Office\10.1.0.5644\office6\ktpcntr.exe [1531136] =>.Zhuhai Kingsoft Office Software Co.,Ltd
O38 - TASK: {4D49DE0C-60A4-4698-A960-1B6782758692} [64Bits][\AdobeAAMUpdater-1.0-MicrosoftAccount-melvin.normand99@gmail.com] - (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936] =>.Adobe Systems Incorporated
O38 - TASK: {4E75558B-F227-4C2E-AAFA-36143B34A4D6} [64Bits][\CCleanerUpdateTaskMachineUA] - (.Piriform Software - CCleaner Browser.) -- C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [200416] =>.Piriform Software
O38 - TASK: {526B461F-F78A-4DA3-BEE2-98A3AC71F919} [64Bits][\ASUSTek Computer Inc\ASUS GIFTBOX] - (.ASUSTek Computer Inc - ASUS GIFTBOX.) -- C:\Program Files (x86)\ASUS\Giftbox\asusgiftbox.exe [1049600] =>.ASUSTek Computer Inc
O38 - TASK: {5EE08B53-5F87-4A5E-86DF-72BD5B745C05} [64Bits][\ASUS\ASUS Product Register Service] - (.ASUSTek COMPUTER INC. - ASUS Product Register Program.) -- C:\Program Files (x86)\ASUS\APRP\aprp.exe [1578784] =>.ASUSTek Computer Inc.
O38 - TASK: {62C2C705-1856-4EE8-BF21-30B59A06E9E3} [64Bits][\Microsoft\Windows\Conexant\SA2] - (.Conexant Systems, Inc. - SmartAudio CPL (32bit).) -- C:\Program Files\CONEXANT\SAII\SACpl.exe [1832280] =>.Conexant Systems, Inc.
O38 - TASK: {73AA4677-0A60-44AD-9415-5248060FE718} [64Bits][\ATK Package A22126881260] - (.ASUSTek Computer Inc. - Simulate Store App Execution Application.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122008] =>.ASUSTek Computer Inc.
O38 - TASK: {762C20BA-9ABC-4E65-8E44-C3E3B9DC1074} [64Bits][\CCleanerUpdateTaskMachineCore] - (.Piriform Software - CCleaner Browser.) -- C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [200416] =>.Piriform Software
O38 - TASK: {79821A0B-553D-4A43-A59E-73C1767F6B9F} [64Bits][\CCleaner Browser Heartbeat Task (Logon)] - (.Piriform Software - CCleaner Browser.) -- C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [2167464] =>.Piriform Software
O38 - TASK: {7C50E1F9-3855-4001-8E8B-24A626ADB2FD} [64Bits][\CCleanerSkipUAC] - (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe [24584376] =>.Piriform Software Ltd
O38 - TASK: {7E979035-E137-4968-A5F8-5F213CA03B3C} [64Bits][\ATK Package 36D18D69AFC3] - (.ASUSTek Computer Inc. - Simulate Store App Execution Application.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122008] =>.ASUSTek Computer Inc.
O38 - TASK: {8A3809AB-22E3-4B69-9ECA-E257C1E2AB4E} [64Bits][\StartCN] - (.Advanced Micro Devices, Inc. - Radeon Settings: Command Line Interface.) -- C:\Program Files\AMD\CNext\CNext\cncmd.exe [61112] =>.Advanced Micro Devices, Inc.
O38 - TASK: {8FA7C841-E462-4EA6-B4BE-D6F7BFEE6812} [64Bits][\ASUS Smart Gesture Launcher] - (.AsusTek - ASUS Smart Gesture Launcher.) -- C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [18400] =>.ASUSTeK
O38 - TASK: {9DC54F85-D5C0-45E3-A30E-FCDF25E373F0} [64Bits][\ASUS USB Charger Plus] - (.ASUSTek Computer Inc. - ASUS USB Charger Plus.) -- C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [19782224] =>.ASUSTek Computer Inc.
O38 - TASK: {A098F233-D182-46E5-9758-8DDF502905AB} [64Bits][\GoogleUpdateTaskMachineCore] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc.
O38 - TASK: {A3BD0CAA-250B-49C2-BC8A-0F64E8ECBD08} [64Bits][\WpsUpdateTask_melvi] - (.Zhuhai Kingsoft Office Software Co.,Ltd - WPS Office Expansion tool.) -- C:\Program Files (x86)\Kingsoft\WPS Office\10.2.0.7646\wtoolex\wpsupdate.exe [653992] =>.Zhuhai Kingsoft Office Software Co.,Ltd
O38 - TASK: {BBC6D12D-FBB7-414F-9338-DECC1DA9A9C0} [64Bits][\AVG\Overseer] - (.AVG Technologies - AVG Overseer.) -- C:\Program Files\Common Files\AVG\Overseer\overseer.exe [1692296] =>.AVG Technologies
O38 - TASK: {C4FF17EF-0AA2-4C59-A535-01384ED5FED9} [64Bits][\CCleaner Update] - (.Piriform Software Ltd - CCleaner emergency updater.) -- C:\Program Files\CCleaner\CCUpdate.exe [686384] =>.Piriform Software Ltd
O38 - TASK: {D029F5EE-46E6-4D4F-AA02-419106B8CF3B} [64Bits][\ASUS Splendid ACMON] - (.ASUS - ACMON.) -- C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [54784] =>.ASUS
O38 - TASK: {E39B04FB-3166-494E-B519-06F60D7B1BBC} [64Bits][\WpsExternal_20161111081738] - (.Zhuhai Kingsoft Office Software Co.,Ltd - WPS Office.) -- C:\Program Files (x86)\Kingsoft\WPS Office\ksolaunch.exe [1285800] =>.Zhuhai Kingsoft Office Software Co.,Ltd
O38 - TASK: {E9F9AA59-4EF2-4726-912C-36CA7DEC1032} [64Bits][\CCleaner Browser Heartbeat Task (Hourly)] - (.Piriform Software - CCleaner Browser.) -- C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [2167464] =>.Piriform Software
O38 - TASK: {F94E9771-4936-40F9-AB90-8DCB992B4778} [64Bits][\Microsoft\Windows\Conexant\AFA] - (.Conexant Systems, Inc. - SmartAudio CPL (32bit).) -- C:\Program Files\CONEXANT\cAudioFilterAgent\SACpl.exe [1823232] =>.Conexant Systems, Inc.
O38 - TASK: {FC0236ED-FEBE-43E8-A06A-A024B320DB9C} [64Bits][\GoogleUpdateTaskMachineUA] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc.
C:\WINDOWS\System32\Tasks\WpsExternal_melvi_20200131112448 - (.Zhuhai Kingsoft Office Software Co.,Ltd.) -- C:\Program Files (x86)\Kingsoft\WPS Office\ksolaunch.exe [/wpscloudlaunch ./wpscloudlaunch] =>.Zhuhai Kingsoft Office Software Co.,Ltd
C:\WINDOWS\System32\Tasks\StartDVR - (.Advanced Micro Devices, Inc..) -- C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [] =>.Advanced Micro Devices, Inc.
C:\WINDOWS\System32\Tasks\Update Checker - (.ASUSTek Computer Inc..) -- C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [] =>.ASUSTek Computer Inc.
C:\WINDOWS\System32\Tasks\WpsKtpcntrQingTask_Administrator - (.Zhuhai Kingsoft Office Software Co.,Ltd.) -- C:\Program Files (x86)\Kingsoft\WPS Office\10.1.0.5644\office6\ktpcntr.exe [qing 10.1.0.5644 xxx server_url="http://kdl1.cache] =>.Zhuhai Kingsoft Office Software Co.,Ltd
C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-melvin.normand99@gmail.com - (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [-mode=scheduled] =>.Adobe Systems Incorporated
C:\WINDOWS\System32\Tasks\CCleanerUpdateTaskMachineUA - (.Piriform Software.) -- C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [/ua ./ua] =>.Piriform Software
C:\WINDOWS\System32\Tasks\ASUSTek Computer Inc\ASUS GIFTBOX - (.ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\Giftbox\asusgiftbox.exe [] =>.ASUSTek Computer Inc
C:\WINDOWS\System32\Tasks\ASUS\ASUS Product Register Service - (.ASUSTek COMPUTER INC..) -- C:\Program Files (x86)\ASUS\APRP\aprp.exe [] =>.ASUSTek Computer Inc.
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Conexant\SA2 - (.Conexant Systems, Inc..) -- C:\Program Files\CONEXANT\SAII\SACpl.exe [/c ./c] =>.Conexant Systems, Inc.
C:\WINDOWS\System32\Tasks\ATK Package A22126881260 - (.ASUSTek Computer Inc..) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [] =>.ASUSTek Computer Inc.
C:\WINDOWS\System32\Tasks\CCleanerUpdateTaskMachineCore - (.Piriform Software.) -- C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [/c] =>.Piriform Software
C:\WINDOWS\System32\Tasks\CCleaner Browser Heartbeat Task (Logon) - (.Piriform Software.) -- C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [--type=heartbeat --logon.--type=heartbeat] =>.Piriform Software
C:\WINDOWS\System32\Tasks\CCleanerSkipUAC - (.Piriform Software Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [$(Arg0)] =>.Piriform Software Ltd
C:\WINDOWS\System32\Tasks\ATK Package 36D18D69AFC3 - (.ASUSTek Computer Inc..) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [-CancelShutdown] =>.ASUSTek Computer Inc.
C:\WINDOWS\System32\Tasks\StartCN - (.Advanced Micro Devices, Inc..) -- C:\Program Files\AMD\CNext\CNext\cncmd.exe [startwithdelay] =>.Advanced Micro Devices, Inc.
C:\WINDOWS\System32\Tasks\ASUS Smart Gesture Launcher - (.AsusTek.) -- C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [] =>.ASUSTeK
C:\WINDOWS\System32\Tasks\ASUS USB Charger Plus - (.ASUSTek Computer Inc..) -- C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [] =>.ASUSTek Computer Inc.
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [/c] =>.Google Inc.
C:\WINDOWS\System32\Tasks\WpsUpdateTask_melvi - (.Zhuhai Kingsoft Office Software Co.,Ltd.) -- C:\Program Files (x86)\Kingsoft\WPS Office\10.2.0.7646\wtoolex\wpsupdate.exe [-from=task] =>.Zhuhai Kingsoft Office Software Co.,Ltd
C:\WINDOWS\System32\Tasks\AVG\Overseer - (.AVG Technologies.) -- C:\Program Files\Common Files\AVG\Overseer\overseer.exe [/from_scheduler:1] =>.AVG Technologies
C:\WINDOWS\System32\Tasks\CCleaner Update - (.Piriform Software Ltd.) -- C:\Program Files\CCleaner\CCUpdate.exe [] =>.Piriform Software Ltd
C:\WINDOWS\System32\Tasks\ASUS Splendid ACMON - (.ASUS.) -- C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [] =>.ASUS
C:\WINDOWS\System32\Tasks\WpsExternal_20161111081738 - (.Zhuhai Kingsoft Office Software Co.,Ltd.) -- C:\Program Files (x86)\Kingsoft\WPS Office\ksolaunch.exe [/wpscloudlaunch ./wpscloudlaunch] =>.Zhuhai Kingsoft Office Software Co.,Ltd
C:\WINDOWS\System32\Tasks\CCleaner Browser Heartbeat Task (Hourly) - (.Piriform Software.) -- C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [--type=heartbeat --hourly.--type=heartbeat] =>.Piriform Software
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Conexant\AFA - (.Conexant Systems, Inc..) -- C:\Program Files\CONEXANT\cAudioFilterAgent\SACpl.exe [/uid:cAudioFilterAgent] =>.Conexant Systems, Inc.
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [/ua ./ua] =>.Google Inc.

---\\ APPLICATIONS LANCÉES AU DÉMARRAGE DU SYSTÈME (15) - 4s
O4 - HKLM\..\Run: [SecurityHealth] . (.Microsoft Corporation - Windows Security notification icon.) -- C:\WINDOWS\system32\SecurityHealthSystray.exe [Unsigned] =>.Microsoft Corporation
O4 - HKLM\..\Run: [cAudioFilterAgent] . (.Conexant Systems, Inc. - Conexant High Definition Audio Filter Agent.) -- C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe =>.Conexant Systems LLC®
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe =>.Adobe Systems Incorporated®
O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\melvi\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - HKCU\..\Run: [Chromium] . (.The Chromium Authors - Chromium.) -- c:\Users\melvi\AppData\Local\chromium\application\chrome.exe [Unsigned] =>.The Chromium Authors
O4 - HKCU\..\Run: [CCXProcess] . (.Adobe Systems Incorporated - CCXProcess.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe =>.Adobe Inc.®
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Software Ltd®
O4 - HKCU\..\Run: [com.squirrel.Teams.Teams] . (. - .) -- Teams.exe =>.SUP.Orphan
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Corporation®
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Corporation®
O4 - HKUS\S-1-5-21-2913167448-2319757323-3006012701-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\melvi\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - HKUS\S-1-5-21-2913167448-2319757323-3006012701-1001\..\Run: [Chromium] . (.The Chromium Authors - Chromium.) -- c:\Users\melvi\AppData\Local\chromium\application\chrome.exe [Unsigned] =>.The Chromium Authors
O4 - HKUS\S-1-5-21-2913167448-2319757323-3006012701-1001\..\Run: [CCXProcess] . (.Adobe Systems Incorporated - CCXProcess.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe =>.Adobe Inc.®
O4 - HKUS\S-1-5-21-2913167448-2319757323-3006012701-1001\..\Run: [CCleaner Smart Cleaning] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Software Ltd®
O4 - HKUS\S-1-5-21-2913167448-2319757323-3006012701-1001\..\Run: [com.squirrel.Teams.Teams] . (. - .) -- Teams.exe =>.SUP.Orphan

---\\ PROCESSUS LANCÉS (60) - 32s
[MD5.F5FC96580422B5B127C6A32F42A1ABDE] - (.AMD - AMD External Events Service Module.) -- C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atiesrxx.exe [508008] [PID.1716] =>.Advanced Micro Devices, Inc.®
[MD5.8B3F83F94CB94138CBF0DCC00046453C] - (.ASUSTek Computer Inc. - ASLDR Service.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe [126616] [PID.3060] =>.ASUSTeK Computer Inc.®
[MD5.89810E9E27C8BB0AFB01814523A76347] - (.ASUSTek Computer Inc. - GFNEXSrv.) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [107320] [PID.2060] =>.ASUSTeK Computer Inc.®
[MD5.0882413280F191D815F7DF42AE64B5B6] - (. - Windows Setup API.) -- C:\Windows\System32\drivers\AdminService.exe [415992] [PID.3644] [Unsigned] =>.Atheros
[MD5.07F3534C07C5110E9A424C04634C4A8D] - (.Conexant Systems Inc. - Conexant Audio Message Service.) -- C:\WINDOWS\system32\CxAudMsg64.exe [207576] [PID.3652] [Unsigned] =>.Conexant Systems Inc.
[MD5.6BE4F8B87EDF1A5193CFB94A833FA1AC] - (.ICEpower - ICEpower ICEsound APO service.) -- C:\Windows\System32\DriverStore\FileRepository\x40plmwa.inf_amd64_09e65ea70153c3a6\ICEsoundService64.exe [806136] [PID.3660] =>.ICEpower a/s®
[MD5.6F3A5BDDFC17DD4A3E0F9F8AC809C5FD] - (.Conexant Systems, Inc. - SmartAudio Service Application.) -- C:\Windows\System32\SASrv.exe [416576] [PID.3828] =>.Conexant Systems, Inc.®
[MD5.D6DDCFFF145CB7D334EECC2F9A8E304F] - (.TeamViewer GmbH - TeamViewer 11.) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7032080] [PID.3872] =>.TeamViewer®
[MD5.3A94E27643966D08349E5BC023B01DF6] - (.Piriform Software - CCleaner Browser Crash Handler.) -- C:\Program Files (x86)\CCleaner Browser\Update\1.7.913.0\CCleanerBrowserCrashHandler.exe [440072] [PID.3776] =>.Piriform Software Ltd®
[MD5.1A3556AF2FFD5623FFBC691ECAECBDBC] - (.Piriform Software - CCleaner Browser Crash Handler.) -- C:\Program Files (x86)\CCleaner Browser\Update\1.7.913.0\CCleanerBrowserCrashHandler64.exe [555328] [PID.5188] =>.Piriform Software Ltd®
[MD5.74CDA8051136B80DC3AE4BF86623003C] - (.Google LLC - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe [295368] [PID.8964] =>.Google LLC®
[MD5.C92C82D8EF9689330621CA9D79D59ACC] - (.Google LLC - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe [376264] [PID.6112] =>.Google LLC®
[MD5.6720A82CDB334D9DFF253E634D3CDE01] - (.Piriform Software - CCleaner Browser.) -- C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [200416] [PID.9432] =>.Piriform Software Ltd®
[MD5.0545A3EB959CFA4790D267BFB8C1ACA4] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168] [PID.12032] =>.Google Inc®
[MD5.E3220A1A319ACBA9471E32CE22DD47F5] - (.ASUSTek Computer Inc. - HControl.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe [298648] [PID.6836] =>.ASUSTeK Computer Inc.®
[MD5.5499B15CE29051558BBC39BA4882E379] - (.ASUSTek Computer Inc. - ASUS USB Charger Plus.) -- C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [19782224] [PID.10768] =>.ASUSTeK Computer Inc.®
[MD5.BCE7E8ED5E131A55F79C1B5B7C0649B7] - (.ASUS - ACMON.) -- C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [54784] [PID.10172] [Unsigned] =>.ASUS
[MD5.CA348B924C8AD0E26090384968BF7F98] - (.ASUSTek Computer Inc. - ATKOSD2.) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [439096] [PID.1556] =>.ASUSTeK Computer Inc.®
[MD5.2608EEE8B37844A314103B40372186C3] - (.ASUSTek Computer Inc. - ATK Media.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [224920] [PID.11208] =>.ASUSTeK Computer Inc.®
[MD5.7D245F2BE526C4152A73C6FBDD9B5EC2] - (...) -- C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe [943928] [PID.2452] =>.Microsoft®
[MD5.0D769AB9BF218DAC9B3E6D257B3BFAC2] - (.Conexant Systems, Inc. - Conexant High Definition Audio Filter Agent.) -- C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe [604496] [PID.7696] =>.Conexant Systems LLC®
[MD5.6AA9DE1723A85DB244136C7F9CB59B1C] - (.Adobe Systems Incorporated - CCXProcess.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [144008] [PID.2248] =>.Adobe Inc.®
[MD5.A01B544BCA8F3F4451C30EBCB02A9DCD] - (.Node.js - Node.js: Server-side JavaScript.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\libs\node.exe [18410648] [PID.14892] =>.Node.js Foundation®
[MD5.675DB196CD55A7FF3D4E1A15928C9C3E] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe [91701608] [PID.5688] =>.Skype Software Sarl®
[MD5.D0A01F637E55DD7B1371B78DDCF112EA] - (.Advanced Micro Devices, Inc. - Radeon Settings: Host Application.) -- C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [17565880] [PID.11476] =>.Advanced Micro Devices, Inc.®
[MD5.316EEBEB1BD89AB60A53AF20F11F8CBB] - (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe [28990136] [PID.6388] =>.Piriform Software Ltd®
[MD5.2281DFFDB1988937B6C9D30128E64B42] - (.Adobe Systems Incorporated - Adobe IPC Broker.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe [1088976] [PID.15252] =>.Adobe Systems Incorporated®
[MD5.675DB196CD55A7FF3D4E1A15928C9C3E] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe [91701608] [PID.8908] =>.Skype Software Sarl®
[MD5.675DB196CD55A7FF3D4E1A15928C9C3E] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe [91701608] [PID.2336] =>.Skype Software Sarl®
[MD5.675DB196CD55A7FF3D4E1A15928C9C3E] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe [91701608] [PID.15064] =>.Skype Software Sarl®
[MD5.675DB196CD55A7FF3D4E1A15928C9C3E] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe [91701608] [PID.8636] =>.Skype Software Sarl®
[MD5.EEAC360113AFCC4EA16A7372212235C6] - (.AsusTek - ASUS Smart Gesture Loader.) -- C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe [366048] [PID.8556] =>.ASUSTeK Computer Inc.®
[MD5.47C77C53C41E3797046A04AFB6468ABE] - (.AsusTek - ASUS Smart Gesture Center.) -- C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe [311776] [PID.12496] =>.ASUSTeK Computer Inc.®
[MD5.3892AD0CC7DC6564D98EA5894A709857] - (.Conexant Systems, Inc - SmartAudio.) -- C:\Program Files\CONEXANT\SAII\SmartAudio.exe [1100112] [PID.13944] =>.Conexant Systems LLC®
[MD5.0F5EF3F836D2E449FE01FCAF17DBD9CF] - (.AsusTek - ASUS Smart Gesture Helper.) -- C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe [179680] [PID.9352] =>.ASUSTeK Computer Inc.®
[MD5.10700C89A4CD66702EE4473C79876ED5] - (.ASUSTek Computer Inc - ASUS GIFTBOX.) -- C:\Program Files (x86)\ASUS\Giftbox\asusgiftbox.exe [1049600] [PID.13388] =>.ASUSTek Computer Inc.®
[MD5.184AC5D5E7A81024DD8B3A961ED70735] - (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1820656] [PID.15148] =>.Google LLC®
[MD5.184AC5D5E7A81024DD8B3A961ED70735] - (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1820656] [PID.7876] =>.Google LLC®
[MD5.184AC5D5E7A81024DD8B3A961ED70735] - (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1820656] [PID.10296] =>.Google LLC®
[MD5.184AC5D5E7A81024DD8B3A961ED70735] - (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1820656] [PID.1616] =>.Google LLC®
[MD5.184AC5D5E7A81024DD8B3A961ED70735] - (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1820656] [PID.14960] =>.Google LLC®
[MD5.10700C89A4CD66702EE4473C79876ED5] - (.ASUSTek Computer Inc - ASUS GIFTBOX.) -- C:\Program Files (x86)\ASUS\Giftbox\asusgiftbox.exe [1049600] [PID.11880] =>.ASUSTek Computer Inc.®
[MD5.3CAAAB81F47BEAEEC7EDE3074B01B596] - (.Google - Software Reporter Tool.) -- C:\Users\melvi\AppData\Local\Google\Chrome\User Data\SwReporter\84.240.200\software_reporter_tool.exe [14568944] [PID.13180] =>.Google LLC®
[MD5.3CAAAB81F47BEAEEC7EDE3074B01B596] - (.Google - Software Reporter Tool.) -- c:\Users\melvi\AppData\Local\Google\Chrome\user data\swreporter\84.240.200\software_reporter_tool.exe [14568944] [PID.8476] =>.Google LLC®
[MD5.3CAAAB81F47BEAEEC7EDE3074B01B596] - (.Google - Software Reporter Tool.) -- c:\Users\melvi\AppData\Local\Google\Chrome\user data\swreporter\84.240.200\software_reporter_tool.exe [14568944] [PID.8464] =>.Google LLC®
[MD5.184AC5D5E7A81024DD8B3A961ED70735] - (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1820656] [PID.9376] =>.Google LLC®
[MD5.184AC5D5E7A81024DD8B3A961ED70735] - (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1820656] [PID.5024] =>.Google LLC®
[MD5.485C1D9F151C36CA3F2A702E8B46A4A4] - (.Zhuhai Kingsoft Office Software Co.,Ltd - WPS Office service program for service such.) -- C:\Program Files (x86)\Kingsoft\WPS Office\10.2.0.7646\office6\wpscloudsvr.exe [244392] [PID.1416] =>.Zhuhai Kingsoft Office Software Co., Ltd.®
[MD5.184AC5D5E7A81024DD8B3A961ED70735] - (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1820656] [PID.9224] =>.Google LLC®
[MD5.184AC5D5E7A81024DD8B3A961ED70735] - (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1820656] [PID.1104] =>.Google LLC®
[MD5.184AC5D5E7A81024DD8B3A961ED70735] - (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1820656] [PID.7412] =>.Google LLC®
[MD5.10700C89A4CD66702EE4473C79876ED5] - (.ASUSTek Computer Inc - ASUS GIFTBOX.) -- C:\Program Files (x86)\ASUS\Giftbox\asusgiftbox.exe [1049600] [PID.5700] =>.ASUSTek Computer Inc.®
[MD5.10700C89A4CD66702EE4473C79876ED5] - (.ASUSTek Computer Inc - ASUS GIFTBOX.) -- C:\Program Files (x86)\ASUS\Giftbox\asusgiftbox.exe [1049600] [PID.6756] =>.ASUSTek Computer Inc.®
[MD5.3CAAAB81F47BEAEEC7EDE3074B01B596] - (.Google - Software Reporter Tool.) -- c:\Users\melvi\AppData\Local\Google\Chrome\user data\swreporter\84.240.200\software_reporter_tool.exe [14568944] [PID.9164] =>.Google LLC®
[MD5.184AC5D5E7A81024DD8B3A961ED70735] - (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1820656] [PID.11060] =>.Google LLC®
[MD5.184AC5D5E7A81024DD8B3A961ED70735] - (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1820656] [PID.5172] =>.Google LLC®
[MD5.4EB47689B263EA13F7B17D8F9CE6DD5C] - (.Nicolas Coolman - ZHPSuite.) -- C:\Users\melvi\Downloads\ZHPSuite (1).exe [3456384] [PID.808] [Unsigned] =>.Nicolas Coolman
[MD5.A770FACAC301DDFDC851544881D8ECD0] - (.Piriform Software - CCleaner Browser.) -- C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [2167464] [PID.9468] =>.Piriform Software Ltd®
[MD5.A770FACAC301DDFDC851544881D8ECD0] - (.Piriform Software - CCleaner Browser.) -- C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [2167464] [PID.5716] =>.Piriform Software Ltd®
[MD5.A770FACAC301DDFDC851544881D8ECD0] - (.Piriform Software - CCleaner Browser.) -- C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [2167464] [PID.4688] =>.Piriform Software Ltd®

---\\ CHROME, Démarrage, Recherche, Extensions (12) - 1s
G2 - GCE: Preference [melvi][User Data\Default\Extensions] [aapocclcgogkmnckokdopfmhonfmgoek] =>.Google Inc. {Slides}
G2 - GCE: Preference [melvi][User Data\Default\Extensions] [aohghmighlieiainnegkcijnfilokake] =>.Google Inc. {Docs}
G2 - GCE: Preference [melvi][User Data\Default\Extensions] [apdfllckaahabafndbhieahigkjlhalf] http://drive.google.com/ =>.Google Inc. {Drive}
G2 - GCE: Preference [melvi][User Data\Default\Extensions] [blpcfgokakmgnkcojhhkbfbldkacnbeo] http://www.youtube.com =>.Youtube {Youtube}
G2 - GCE: Preference [melvi][User Data\Default\Extensions] [felcaaldnbdncclmgdcncolpebgiejap] =>.Google Inc. {Sheets}
G2 - GCE: Preference [melvi][User Data\Default\Extensions] [gighmmpiobklfepjocnamgkkbiglidom] Toggle Pause/Resume on all sites =>.Wladimir Palant {AdBlock}
G2 - GCE: Preference [melvi][User Data\Default\Extensions] [nmmhkkegccagdldgiimedpiccmgmieda] =>.Google Inc. {Wallet}
G2 - GCE: Preference [melvi][User Data\Default\Extensions] [pjkljhegncpnkpknbcohdijeoejaedia] http://mail.google.com/ =>.Google Inc. {Gmail}
G2 - GCE: Preference [melvi][User Data\Default\Extensions] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.
G2 - GCE: Preference [melvi][User Data\Default\Local Extension Settings] [gighmmpiobklfepjocnamgkkbiglidom] =>.Wladimir Palant {AdBlock}
G2 - GCE: Preference [melvi][User Data\Default\Managed Extension Settings] [gighmmpiobklfepjocnamgkkbiglidom] =>.Wladimir Palant {AdBlock}
G2 - GCE: Preference [melvi][User Data\Default\Sync Extension Settings] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] =>.Google Inc. {Chrome Media Router}

---\\ FIREFOX, Plugins,Démarrage,Recherche,Extensions (11) - 2s
P2 - EXT FILE: (.Microsoft Corporation - The plugin allows you to have a better expe.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npMeetingJoinPluginOC.dll =>.Microsoft®
C:\Users\melvi\AppData\Roaming\Mozilla\Firefox\Profiles\gnwviepz.default-release\bookmarkbackups =>Mozilla Corporation
C:\Users\melvi\AppData\Roaming\Mozilla\Firefox\Profiles\gnwviepz.default-release\crashes =>Mozilla Corporation
C:\Users\melvi\AppData\Roaming\Mozilla\Firefox\Profiles\gnwviepz.default-release\datareporting =>Mozilla Corporation
C:\Users\melvi\AppData\Roaming\Mozilla\Firefox\Profiles\gnwviepz.default-release\extensions =>Mozilla Corporation
C:\Users\melvi\AppData\Roaming\Mozilla\Firefox\Profiles\gnwviepz.default-release\gmp-gmpopenh264 =>Mozilla Corporation
C:\Users\melvi\AppData\Roaming\Mozilla\Firefox\Profiles\gnwviepz.default-release\gmp-widevinecdm =>Mozilla Corporation
C:\Users\melvi\AppData\Roaming\Mozilla\Firefox\Profiles\gnwviepz.default-release\minidumps =>Mozilla Corporation
C:\Users\melvi\AppData\Roaming\Mozilla\Firefox\Profiles\gnwviepz.default-release\saved-telemetry-pings =>Mozilla Corporation
C:\Users\melvi\AppData\Roaming\Mozilla\Firefox\Profiles\gnwviepz.default-release\sessionstore-backups =>Mozilla Corporation
C:\Users\melvi\AppData\Roaming\Mozilla\Firefox\Profiles\gnwviepz.default-release\storage =>Mozilla Corporation

---\\ INTERNET EXPLORER,Démarrage,Recherche,URLSearchHook (16) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.search.yahoo.com/ =>.Yahoo! Inc.
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.search.yahoo.com/ =>.Yahoo! Inc.
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://fr.search.yahoo.com/ =>.Yahoo! Inc.
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus17win10.msn.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.18362.890 (WinBuild.160101.0800)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation

---\\ INTERNET EXPLORER, Site de confiance et site sensible (1) - 0s
~ Microsoft Internet Explorer Restricted Site(s) Domains: 0(Good) / 0(Bad)

---\\ MICROSOFT EDGE, Plugin,Favoris,Démarrage,Recherche,Extension (1) - 1s
E2 - GCE: Preference [melvi][User Data\Default\Local Extension Settings] [jdiccldimpdaibmpdkjnbmckianbfold] =>.Microsoft Corporation

---\\ INTERNET EXPLORER,Proxy Management (4) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 =>.Default.Value
R5 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ INTERNET EXPLORER,IniFiles, Autoloading Programs (3) - 0s
F2 - REG:system.ini: UserInit=
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=

---\\ ÉTUDE DU FICHIER HOSTS (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ BROWSER HELPER OBJECT DE NAVIGATEUR (BHO) (3) - 0s
O2 - BHO: IEToEdge BHO [64Bits] - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} . (.Microsoft Corporation - IEToEdge BHO.) -- C:\Program Files (x86)\Microsoft\Edge\Application\84.0.522.59\BHO\ie_to_edge_bho_64.dll =>.Microsoft®
O2 - BHO: Skype for Business Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} . (.Microsoft Corporation - Skype for Business.) -- C:\Program Files\Microsoft Office\Office16\OCHelper.dll =>.Microsoft®
O2 - BHO: Microsoft OneDrive for Business Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} . (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft®

---\\ RACCOURCIS GLOBAL STARTUP (60) - 14s
O4 - GS\Desktop [melvi]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O4 - GS\Desktop [melvi]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\internet explorer\iexplore.exe =>.Microsoft®
O4 - GS\Desktop [melvi]: Microsoft Teams.lnk . (.Microsoft Corporation - Microsoft Teams.) C:\Users\melvi\AppData\Local\Microsoft\Teams\Update.exe --processStart "Teams.exe" =>.Microsoft®
O4 - GS\Desktop [melvi]: PhotoshopCS6Portable - Raccourci.lnk . (.PainteR - Adobe Photoshop CS6 Pre-Release Portable.) C:\Users\melvi\Downloads\photoshop cs6\photoshop cs6\AdobePhotoshopCS6Portable\PhotoshopCS6Portable.exe [Unsigned] =>.PainteR
O4 - GS\Desktop [melvi]: ZHPSuite.lnk . (.Nicolas Coolman - ZHPSuite.) C:\Users\melvi\AppData\Roaming\ZHP\ZHPSuite.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [melvi]: CCleaner Browser.lnk . (.Piriform Software - CCleaner Browser.) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe --check-run=src=quicklaunch =>.Piriform Software Ltd®
O4 - GS\Quicklaunch [melvi]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O4 - GS\Quicklaunch [melvi]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft®
O4 - GS\Quicklaunch [melvi]: Microsoft Outlook.lnk . (.Microsoft Corporation - Microsoft Outlook.) C:\Program Files (x86)\Microsoft Office\Office16\OUTLOOK.EXE /recycle =>.Microsoft®
O4 - GS\sendTo [melvi]: Destinataire de télécopie.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [melvi]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [melvi]: TeamViewer.lnk . (.TeamViewer GmbH - TeamViewer 11.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe --sendto =>.TeamViewer®
O4 - GS\sendTo [melvi]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - Transfère les fichiers entre l.) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [melvi]: ASUS GIFTBOX.lnk . (.ASUSTek Computer Inc - ASUS GIFTBOX.) C:\Program Files (x86)\ASUS\Giftbox\asusgiftbox.exe store:default src:start =>.ASUSTek Computer Inc.®
O4 - GS\TaskBar [melvi]: CCleaner Browser.lnk . (.Piriform Software - CCleaner Browser.) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe --check-run=src=taskbar =>.Piriform Software Ltd®
O4 - GS\TaskBar [melvi]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O4 - GS\TaskBar [melvi]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\internet explorer\iexplore.exe =>.Microsoft®
O4 - GS\TaskBar [melvi]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --profile-directory=Default =>.Microsoft®
O4 - GS\Programs [melvi]: Fonctionnalités optionnelles.lnk . (.Microsoft Corporation - Assistance des fonctionnalités à la demande.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Programs [melvi]: HowToRemove.lnk . (...) C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\HowToRemove.html [Unsigned] =>PUP.Optional.WinYahoo
O4 - GS\Programs [melvi]: Microsoft Teams.lnk . (.Microsoft Corporation - Microsoft Teams.) C:\Users\melvi\AppData\Local\Microsoft\Teams\Update.exe --processStart "Teams.exe" =>.Microsoft®
O4 - GS\Programs [melvi]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\melvi\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - GS\CommonDesktop [Public]: CCleaner Browser.lnk . (.Piriform Software - CCleaner Browser.) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe --check-run=src=desktop =>.Piriform Software Ltd®
O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Software Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Software Ltd®
O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O4 - GS\CommonDesktop [Public]: LibreOffice 5.4.lnk . (.The Document Foundation - LibreOffice.) C:\Program Files (x86)\LibreOffice 5\program\soffice.exe =>.The Document Foundation®
O4 - GS\CommonDesktop [Public]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft®
O4 - GS\Programs [Public]: Fonctionnalités optionnelles.lnk . (.Microsoft Corporation - Assistance des fonctionnalités à la demande.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Programs [Public]: HowToRemove.lnk . (...) C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\HowToRemove.html [Unsigned] =>PUP.Optional.WinYahoo
O4 - GS\Programs [Public]: Microsoft Teams.lnk . (.Microsoft Corporation - Microsoft Teams.) C:\Users\melvi\AppData\Local\Microsoft\Teams\Update.exe --processStart "Teams.exe" =>.Microsoft®
O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\melvi\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft®
O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft®
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\WINDOWS\system32\quickassist.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture d’écran.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Enregistreur d’actions.) C:\WINDOWS\system32\psr.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Application Windows Wordpad.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - Visionneuse XPS.) C:\WINDOWS\system32\xpsrchvw.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Table des caractères.) C:\WINDOWS\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Access 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-0000-0000000FF1CE}\accicons.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: Adobe Illustrator 2020.lnk . (.Adobe Inc. - Adobe Illustrator 2020.) C:\Users\melvi\Desktop\Adobe Illustrator 2020\Support Files\Contents\Windows\Illustrator.exe [Unsigned] =>.Adobe Inc.
O4 - GS\ProgramsCommon [Public]: ASUS GIFTBOX.lnk . (.ASUSTek Computer Inc - ASUS GIFTBOX.) C:\Program Files (x86)\ASUS\Giftbox\asusgiftbox.exe store:default src:start =>.ASUSTek Computer Inc.®
O4 - GS\ProgramsCommon [Public]: CCleaner Browser.lnk . (.Piriform Software - CCleaner Browser.) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe --check-run=src=tile =>.Piriform Software Ltd®
O4 - GS\ProgramsCommon [Public]: Excel 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-0000-0000000FF1CE}\xlicons.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\WINDOWS\System32\Control.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: OneDrive Entreprise.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-0000-0000000FF1CE}\grv_icons.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: OneNote 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-0000-0000000FF1CE}\joticon.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: Outlook 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-0000-0000000FF1CE}\outicon.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: PowerPoint 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-0000-0000000FF1CE}\pptico.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: Publisher 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-0000-0000000FF1CE}\pubs.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: Skype Entreprise 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-0000-0000000FF1CE}\lyncicon.exe =>.Microsoft®
O4 - GS\ProgramsCommon [Public]: TeamViewer 11.lnk . (.TeamViewer GmbH - TeamViewer 11.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe =>.TeamViewer®
O4 - GS\ProgramsCommon [Public]: Word 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-0000-0000000FF1CE}\wordicon.exe =>.Microsoft®

---\\ MODIFICATION DOMAINE/ADRESSES (DNS) (3) - 1s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{062202f1-18c5-4482-be2f-cb3e08f3201c}: DhcpNameServer = 192.168.100.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{96c52774-c98a-4009-9b0c-094f0ee20cba}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress

---\\ PROTOCOLE ADDITIONNEL (23) - 3s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll [Unsigned] =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation
O18 - Filter: text/xml [64Bits] - {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL =>.Microsoft®

---\\ REGISTRE AppInit_DLLs et Winlogon Notify (1) - 0s
O20 - Winlogon : UserInit . (.Microsoft Corporation - Application d’ouverture de session Userinit.) - C:\windows\system32\userinit.exe =>.Microsoft Corporation

---\\ CLÉ DE REGISTRE EXPLORER StartupApproved (8) - 0s
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:Chromium =>.Chromium Team
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:OneDrive =>.Microsoft Corporation
[HKEY_USERS\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:Chromium =>.Chromium Team
[HKEY_USERS\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:OneDrive =>.Microsoft Corporation
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:SecurityHealth =>.Microsoft Corporation
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:cAudioFilterAgent =>.Conexant Systems, Inc.
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:SmartAudio =>.Conexant Systems, Inc.
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:WindowsDefender =>.Microsoft Corporation

---\\ COMPOSANTS ACTIVESETUP INSTALLÉS (ASIC) (8) - 3s
O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Utilitaire d’installation du Lecteur Window.) -- C:\Windows\System32\unregmp2.exe [Unsigned] =>.Microsoft Corporation
O40 - ASIC: CCleaner Browser [64Bits] - {052EB454-9F19-CB42-7875-807F79F311C4} . (.Piriform Software - CCleaner Browser Installer.) -- C:\Program Files (x86)\CCleaner Browser\Application\84.0.5275.108\Installer\chrmstp.exe =>.Piriform Software Ltd®
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll [Unsigned] =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Utilitaire d’installation du Lecteur Window.) -- C:\Windows\System32\unregmp2.exe [Unsigned] =>.Microsoft Corporation
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe [Unsigned] =>.Microsoft Corporation
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft Corporation®
O40 - ASIC: Google Chrome [64Bits] - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google LLC - Google Chrome Installer.) -- C:\Program Files (x86)\Google\Chrome\Application\84.0.4147.125\Installer\chrmstp.exe =>.Google LLC®
O40 - ASIC: Microsoft Edge [64Bits] - {9459C573-B17A-45AE-9F64-1857B5D58CEE} . (.Microsoft Corporation - Microsoft Edge Installer.) -- C:\Program Files (x86)\Microsoft\Edge\Application\84.0.522.59\Installer\setup.exe =>.Microsoft®

---\\ LOGICIELS INSTALLÉS (151) - 57s
O42 - Logiciel: Adobe Illustrator 2020 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- ILST_24_0_1 =>.Adobe Inc.®
O42 - Logiciel: AMD Problem Report Wizard - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {807BBD2A-B4C2-030B-C22F-D97FA460FF79} [Unsigned] =>.Advanced Micro Devices, Inc. (Hidden)
O42 - Logiciel: AMD Radeon Settings - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- WUCCCApp [Unsigned] =>.Advanced Micro Devices, Inc.
O42 - Logiciel: AMD Settings - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {91565D49-0D00-40F6-B580-B3378FE28951} [Unsigned] =>.Advanced Micro Devices, Inc. (Hidden)
O42 - Logiciel: AMD Settings - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {9E0C0F82-4902-4ADF-B955-AC86696A71DF} [Unsigned] =>.Advanced Micro Devices, Inc. (Hidden)
O42 - Logiciel: AMD Software - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {EDF66320-A8A5-967C-1B69-484DAD822143} [Unsigned] =>.Advanced Micro Devices, Inc. (Hidden)
O42 - Logiciel: AMD Software - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- AMD Catalyst Install Manager =>.Advanced Micro Devices, Inc.®
O42 - Logiciel: AMD WVR64 - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {6497E1AF-C2C1-4D92-90DD-49EEC3F2F3B5} [Unsigned] =>.Advanced Micro Devices, Inc. (Hidden)
O42 - Logiciel: ASUS Device Activation - (.ASUSTeK COMPUTER INC..) [HKLM][64Bits] -- {9C4B0706-9F9A-47BF-B417-0A111FC52B04} [Unsigned] =>.ASUSTek Computer Inc.
O42 - Logiciel: ASUS GIFTBOX - (.ASUSTek Computer Inc.) [HKLM][64Bits] -- ASUS GIFTBOX =>.ASUSTek Computer Inc.®
O42 - Logiciel: ASUS Live Update - (.ASUSTeK COMPUTER INC..) [HKLM][64Bits] -- {FA540E67-095C-4A1B-97BA-4D547DEC9AF4} [Unsigned] =>.ASUSTek Computer Inc.
O42 - Logiciel: ASUS Smart Gesture - (.ASUS.) [HKLM][64Bits] -- {4D3286A6-F6AB-498A-82A4-E4F040529F3D} [Unsigned] =>.ASUS
O42 - Logiciel: ASUS Splendid Video Enhancement Technology - (.ASUS.) [HKLM][64Bits] -- {0969AF05-4FF6-4C00-9406-43599238DE0D} [Unsigned] =>.ASUS
O42 - Logiciel: ASUS USB Charger Plus - (.ASUS.) [HKLM][64Bits] -- {A859E3E5-C62F-4BFA-AF1D-2B95E03166AF} [Unsigned] =>.ASUS
O42 - Logiciel: ATK Package - (.ASUS.) [HKLM][64Bits] -- {AB5C933E-5C7D-4D30-B314-9C83A49B94BE} [Unsigned] =>.ASUS
O42 - Logiciel: AudioWizard - (.ICEpower a/s.) [HKLM][64Bits] -- {57E770A2-2BAF-4CAA-BAA3-BD896E2254D3} [Unsigned] =>.ICEpower a/s
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Software Ltd®
O42 - Logiciel: CCleaner Browser - (.Auteurs de CCleaner Browser.) [HKLM][64Bits] -- CCleaner Browser =>.Piriform Software Ltd®
O42 - Logiciel: CCleaner Update Helper - (.Piriform Software.) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} [Unsigned] =>Heuristic.Suspect (Hidden)
O42 - Logiciel: Conexant HD Audio - (.Conexant.) [HKLM][64Bits] -- CNXT_AUDIO_HDA =>.Conexant Systems LLC®
O42 - Logiciel: Definition Update for Microsoft Office 2016 (KB3115085) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{7EB01F8D-7721-43AF-8A71-EC89ED48ECCA} =>.Microsoft®
O42 - Logiciel: Device Setup - (.ASUSTek COMPUTER INC..) [HKLM][64Bits] -- {8D6B05E0-F457-408C-9D13-549334D8FAE1} [Unsigned] =>.ASUSTek Computer Inc.
O42 - Logiciel: Google Update Helper - (.Google LLC.) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} [Unsigned] =>.Google LLC (Hidden)
O42 - Logiciel: Google Chrome - (.Google LLC.) [HKLM][64Bits] -- Google Chrome =>.Google LLC®
O42 - Logiciel: Herramientas de corrección de Microsoft Office 2016: español - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001F-0C0A-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: LibreOffice 5.4.2.2 - (.The Document Foundation.) [HKLM][64Bits] -- {C7ED130E-8751-4248-AB98-D059CD9E7EAA} [Unsigned] =>.The Document Foundation
O42 - Logiciel: Microsoft Access MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0015-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft DCF MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0090-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Edge - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Edge =>.Microsoft®
O42 - Logiciel: Microsoft Edge Update - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Edge Update [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Microsoft Excel MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0016-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Groove MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-00BA-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft InfoPath MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0044-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office 64-bit Components 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-002A-0000-1000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office Korrekturhilfen 2016 – Deutsch - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001F-0407-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office OSM MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-00E1-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office OSM UX MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-00E2-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-0011-0000-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office Professional Plus 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office Professionnel Plus 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- Office16.PROPLUS =>.Microsoft®
O42 - Logiciel: Microsoft Office Proofing (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-002C-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office Proofing Tools 2016 - English - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001F-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office Proofing Tools 2016 - اللغة العربية - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001F-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office Shared 64-bit MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-002A-040C-1000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Office Shared MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-006E-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft OneDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- OneDriveSetup.exe =>.Microsoft®
O42 - Logiciel: Microsoft OneNote MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-00A1-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Outlook MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001A-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft PowerPoint MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0018-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Publisher MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0019-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Skype for Business MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-012B-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Teams - (.Microsoft Corporation.) [HKCU][64Bits] -- Teams =>.Microsoft®
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 - (.Microsoft Corporation.) [HKLM][64Bits] -- {8220EEFE-38CD-377E-8595-13398D740ACE} [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (.Microsoft Corporation.) [HKLM][64Bits] -- {9A25302D-30C0-39D9-BD6F-21E6EC160475} [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 - (.Microsoft Corporation.) [HKLM][64Bits] -- {1D8E6291-B0D5-35EC-8441-6616F567A0F7} [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 - (.Microsoft Corporation.) [HKLM][64Bits] -- {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 - (.Microsoft Corporation.) [HKLM][64Bits] -- {ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} =>.Microsoft®
O42 - Logiciel: Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 - (.Microsoft Corporation.) [HKLM][64Bits] -- {33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} =>.Microsoft®
O42 - Logiciel: Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 - (.Microsoft Corporation.) [HKLM][64Bits] -- {37B8F9C7-03FB-3253-8781-2517C99D7C00} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 - (.Microsoft Corporation.) [HKLM][64Bits] -- {CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 - (.Microsoft Corporation.) [HKLM][64Bits] -- {B175520C-86A2-35A7-8619-86DC379688B9} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 - (.Microsoft Corporation.) [HKLM][64Bits] -- {BD95A8CD-1D9F-35AD-981A-3E7925026EBB} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 - (.Microsoft Corporation.) [HKLM][64Bits] -- {050d4fc8-5d48-4b8f-8972-47c82c46020f} =>.Microsoft®
O42 - Logiciel: Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 - (.Microsoft Corporation.) [HKLM][64Bits] -- {ef6b00ec-13e1-4c25-9064-b2f383cb8412} =>.Microsoft®
O42 - Logiciel: Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 - (.Microsoft Corporation.) [HKLM][64Bits] -- {f65db027-aff3-4070-886a-0d87064aabb1} =>.Microsoft®
O42 - Logiciel: Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 - (.Microsoft Corporation.) [HKLM][64Bits] -- {61087a79-ac85-455c-934d-1fa22cc64f36} =>.Microsoft®
O42 - Logiciel: Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40660 - (.Microsoft Corporation.) [HKLM][64Bits] -- {5740BD44-B58D-321A-AFC0-6D3D4556DD6C} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40660 - (.Microsoft Corporation.) [HKLM][64Bits] -- {CB0836EC-B072-368D-82B2-D3470BF95707} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40660 - (.Microsoft Corporation.) [HKLM][64Bits] -- {7DAD0258-515C-3DD4-8964-BD714199E0F7} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40660 - (.Microsoft Corporation.) [HKLM][64Bits] -- {E30D8B21-D82D-3211-82CC-0F0A5D1495E8} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 - (.Microsoft Corporation.) [HKLM][64Bits] -- {95ac1cfa-f4fb-4d1b-8912-7f9d5fbb140d} =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 - (.Microsoft Corporation.) [HKLM][64Bits] -- {7e9fae12-5bbf-47fb-b944-09c49e75c061} =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Visual C++ 2017 x64 Additional Runtime - 14.15.26706 - (.Microsoft Corporation.) [HKLM][64Bits] -- {F106B700-BFF8-3065-B305-14D36AD40539} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Visual C++ 2017 x64 Minimum Runtime - 14.15.26706 - (.Microsoft Corporation.) [HKLM][64Bits] -- {C77195A4-CEB8-38EE-BDD6-C46CB459EF6E} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 - (.Microsoft Corporation.) [HKLM][64Bits] -- {2757496A-3E74-320A-B007-36120A9F126D} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 - (.Microsoft Corporation.) [HKLM][64Bits] -- {39E15475-23F2-345D-8977-B5DC47A94E26} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Microsoft Word MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001B-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: OEM Application Profile - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {B4B7FD8F-06FC-E277-4F29-8F75F8281D8F} [Unsigned] =>.Advanced Micro Devices, Inc.
O42 - Logiciel: Outils de vérification linguistique 2016 de Microsoft Office - Français - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001F-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: Qualcomm Atheros Bluetooth Suite (64) - (.Qualcomm Atheros.) [HKLM][64Bits] -- {A84A4FB1-D703-48DB-89E0-68B6499D2801} [Unsigned] =>.Qualcomm Atheros
O42 - Logiciel: Qualcomm Atheros Client Installation Program - (.Qualcomm Atheros.) [HKLM][64Bits] -- {28006915-2739-4EBE-B5E8-49B25D32EB33} [Unsigned] =>.Qualcomm Atheros
O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Search the Web (Yahoo) - (..) [HKLM][64Bits] -- {BC0F54CF-EC8F-854F-5D0F-F5CF8D8F264F} [Unsigned] =>Adware.YahooPowered
O42 - Logiciel: Security Update for Microsoft Office 2016 (KB3085635) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-006E-040C-0000-0000000FF1CE}_Office16.PROPLUS_{CCBDE2CC-9498-4937-A88B-46FD248719C9} =>.Microsoft®
O42 - Logiciel: Security Update for Microsoft Office 2016 (KB3114690) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{0431DE35-1781-4633-B69D-D547BB412C65} =>.Microsoft®
O42 - Logiciel: Security Update for Microsoft Office 2016 (KB3115103) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{58F3561B-C8E6-44A7-8303-E6F0250FDF20} =>.Microsoft®
O42 - Logiciel: Security Update for Microsoft Office 2016 (KB3115103) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-002A-0000-1000-0000000FF1CE}_Office16.PROPLUS_{58F3561B-C8E6-44A7-8303-E6F0250FDF20} =>.Microsoft®
O42 - Logiciel: Security Update for Microsoft Publisher 2016 (KB2920680) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{5182F11C-8D2E-4E2C-B36A-5B4AC5AE723C} =>.Microsoft®
O42 - Logiciel: Security Update for Microsoft Publisher 2016 (KB2920680) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0019-040C-0000-0000000FF1CE}_Office16.PROPLUS_{5182F11C-8D2E-4E2C-B36A-5B4AC5AE723C} =>.Microsoft®
O42 - Logiciel: Security Update for Microsoft Word 2016 (KB3115094) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{7879768A-94DC-44C4-BD24-F2296C903A82} =>.Microsoft®
O42 - Logiciel: Skype Meetings App - (.Microsoft Corporation.) [HKLM][64Bits] -- {BC1D9E47-8927-4AA1-A891-7763BC2475B7} [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Taalprogramma's voor Microsoft Office 2016 - Nederlands - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001F-0413-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden)
O42 - Logiciel: TeamViewer 11 - (.TeamViewer.) [HKLM][64Bits] -- TeamViewer =>.TeamViewer®
O42 - Logiciel: Update for Microsoft Access 2016 (KB3114966) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{BA46E502-C055-4C15-B468-981B723A9BA8} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Excel 2016 (KB3115090) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{F3F2A6AE-2C31-4005-9771-23BB659014A7} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Excel 2016 (KB3115090) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0016-040C-0000-0000000FF1CE}_Office16.PROPLUS_{F3F2A6AE-2C31-4005-9771-23BB659014A7} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Excel 2016 (KB3115090) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0018-040C-0000-0000000FF1CE}_Office16.PROPLUS_{F3F2A6AE-2C31-4005-9771-23BB659014A7} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Excel 2016 (KB3115090) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-001B-040C-0000-0000000FF1CE}_Office16.PROPLUS_{F3F2A6AE-2C31-4005-9771-23BB659014A7} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB2910960) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{8389A73A-BD90-4B1D-A11B-ED9E24EA6807} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB2910979) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{30BE8A1C-04BC-4CCD-942E-A10F3FA33E43} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB2920678) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{659F8DC4-0FD7-4C3C-9011-19B9FB400154} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB2920684) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-002A-0000-1000-0000000FF1CE}_Office16.PROPLUS_{FA8D0376-1138-4DE0-81B4-AE2106D5ED4D} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB2920699) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{C07AAB5B-B29E-4568-A282-2DA560D3FFB1} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB2920699) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0016-040C-0000-0000000FF1CE}_Office16.PROPLUS_{C07AAB5B-B29E-4568-A282-2DA560D3FFB1} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB2920712) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{0471C03C-B563-4F44-83E9-4D9AF243E1D3} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB2920720) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{1471A699-A87C-454C-B227-00B48E5BA75B} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB2920724) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{B5FD5FBF-150F-4BD7-A2D2-F015D1069FC5} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3114369) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{E3DCC732-0F2B-49BD-8D00-017E437F4BE7} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3114378) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{41DBA4C2-9AD4-41E2-8F52-43B72F982D49} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3114523) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{DD8AF0ED-BF65-4E4E-B735-EA9021A64557} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3114523) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-002A-0000-1000-0000000FF1CE}_Office16.PROPLUS_{DD8AF0ED-BF65-4E4E-B735-EA9021A64557} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3114535) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{27084D6E-0050-46D7-9F86-0529F47DAE43} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3114535) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-002A-0000-1000-0000000FF1CE}_Office16.PROPLUS_{27084D6E-0050-46D7-9F86-0529F47DAE43} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3114694) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{9C5B5C7D-E79A-41C8-9D29-748A5145281E} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3114705) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{B1A6B674-854F-4E43-92E1-6D3DA27B084E} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3114705) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-002A-0000-1000-0000000FF1CE}_Office16.PROPLUS_{B1A6B674-854F-4E43-92E1-6D3DA27B084E} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3114854) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{BA767A46-1772-4902-BFB8-5FF8F932AB61} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3114854) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-002A-0000-1000-0000000FF1CE}_Office16.PROPLUS_{BA767A46-1772-4902-BFB8-5FF8F932AB61} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3114859) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{4BF890A7-7EBF-4E24-A288-80723AE838CB} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3114903) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{B557BEA1-7AB8-4CA4-B9EB-7011EB0EEB4B} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3115084) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{EBE84909-BE84-40C2-A9C5-B877D79759C2} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3115091) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{2BCFA47D-966F-4AC5-8ED6-1F0DE1F4FA7E} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3115091) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-006E-040C-0000-0000000FF1CE}_Office16.PROPLUS_{2BCFA47D-966F-4AC5-8ED6-1F0DE1F4FA7E} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3115096) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{6BB730C9-AC60-46C1-B7C8-B9A33EFEC797} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3115096) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-006E-040C-0000-0000000FF1CE}_Office16.PROPLUS_{6BB730C9-AC60-46C1-B7C8-B9A33EFEC797} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Office 2016 (KB3115100) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{F73DDA0B-6B6C-4C65-B310-FFA4A0B3FB33} =>.Microsoft®
O42 - Logiciel: Update for Microsoft OneDrive for Business (KB3115104) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{B24F559A-48C9-49CC-BC8A-6943E29AE10C} =>.Microsoft®
O42 - Logiciel: Update for Microsoft OneDrive for Business (KB3115104) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-002A-0000-1000-0000000FF1CE}_Office16.PROPLUS_{B24F559A-48C9-49CC-BC8A-6943E29AE10C} =>.Microsoft®
O42 - Logiciel: Update for Microsoft OneDrive for Business (KB3115104) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-002A-040C-1000-0000000FF1CE}_Office16.PROPLUS_{B24F559A-48C9-49CC-BC8A-6943E29AE10C} =>.Microsoft®
O42 - Logiciel: Update for Microsoft OneDrive for Business (KB3115104) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-00BA-040C-0000-0000000FF1CE}_Office16.PROPLUS_{B24F559A-48C9-49CC-BC8A-6943E29AE10C} =>.Microsoft®
O42 - Logiciel: Update for Microsoft OneNote 2016 (KB3114388) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{12CB9AF3-F673-43EF-9FBE-25060DF97EFF} =>.Microsoft®
O42 - Logiciel: Update for Microsoft OneNote 2016 (KB3114388) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-002A-0000-1000-0000000FF1CE}_Office16.PROPLUS_{12CB9AF3-F673-43EF-9FBE-25060DF97EFF} =>.Microsoft®
O42 - Logiciel: Update for Microsoft OneNote 2016 (KB3114388) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-00A1-040C-0000-0000000FF1CE}_Office16.PROPLUS_{12CB9AF3-F673-43EF-9FBE-25060DF97EFF} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Outlook 2016 (KB3115101) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{EB2D07A3-C553-4F5C-8F97-66D5947F37C8} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Outlook 2016 (KB3115101) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-001A-040C-0000-0000000FF1CE}_Office16.PROPLUS_{EB2D07A3-C553-4F5C-8F97-66D5947F37C8} =>.Microsoft®
O42 - Logiciel: Update for Microsoft PowerPoint 2016 (KB3115089) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{F1FD0B1E-D16F-431D-A0F1-A149C585E68A} =>.Microsoft®
O42 - Logiciel: Update for Microsoft PowerPoint 2016 (KB3115089) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0018-040C-0000-0000000FF1CE}_Office16.PROPLUS_{F1FD0B1E-D16F-431D-A0F1-A149C585E68A} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Project 2016 (KB3115105) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{A9072C22-17F1-4C03-B546-CEA90499721D} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Project 2016 (KB3115105) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-002A-0000-1000-0000000FF1CE}_Office16.PROPLUS_{A9072C22-17F1-4C03-B546-CEA90499721D} =>.Microsoft®
O42 - Logiciel: Update for Microsoft Visio 2016 (KB3114957) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{6AAC0DBB-9379-40E8-B2FA-D320C734772F} =>.Microsoft®
O42 - Logiciel: Update for Skype for Business 2016 (KB3114846) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-0000-0000000FF1CE}_Office16.PROPLUS_{F51FCE9D-80C7-43F0-8DE6-F1173EEAE292} =>.Microsoft®
O42 - Logiciel: Update for Skype for Business 2016 (KB3114846) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-012B-040C-0000-0000000FF1CE}_Office16.PROPLUS_{F51FCE9D-80C7-43F0-8DE6-F1173EEAE292} =>.Microsoft®
O42 - Logiciel: Update for Windows 10 for x64-based Systems (KB4023057) - (.Microsoft Corporation.) [HKLM][64Bits] -- {16AD6161-2E47-4BF1-AA77-0946EFE93E08} [Unsigned] =>.Microsoft Corporation
O42 - Logiciel: Vulkan Run Time Libraries 1.0.21.0 - (.LunarG, Inc..) [HKLM][64Bits] -- VulkanRT1.0.21.0 =>.LunarG, Inc.®
O42 - Logiciel: Vulkan Run Time Libraries 1.0.51.0 - (.LunarG, Inc..) [HKLM][64Bits] -- VulkanRT1.0.51.0 =>.LunarG, Inc.®
O42 - Logiciel: Web Search (Yahoo! Provided) - (..) [HKLM][64Bits] -- {4944A184-19C4-7004-A844-008478C4D304} [Unsigned] =>Adware.YahooPowered
O42 - Logiciel: WinFlash - (.ASUSTeK COMPUTER INC..) [HKLM][64Bits] -- {8F21291E-0444-4B1D-B9F9-4370A73E346D} [Unsigned] =>.ASUSTek Computer Inc.
O42 - Logiciel: WinRAR 5.90 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH®
O42 - Logiciel: WPS Office - (.Kingsoft Corp..) [HKCU][64Bits] -- Kingsoft Office =>.Zhuhai Kingsoft Office Software Co., Ltd.®
O42 - Logiciel: WPS Office for ASUS - (.Kingsoft Corp..) [HKLM][64Bits] -- Kingsoft Office =>.Zhuhai Kingsoft Office Software Co.,Ltd®
O42 - Logiciel: Zoom - (.Zoom Video Communications, Inc..) [HKCU][64Bits] -- ZoomUMX =>.Zoom Video Communications, Inc.®

---\\ CLÉ DE REGISTRE SOFTWARE HKCU & HKLM (151) - 58s
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\Software\csastats =>Adware.InstallCore
HKCU\Software\csastats =>Adware.InstallCore
HKLM\SOFTWARE\Agere =>.Agere Systems
HKLM\SOFTWARE\AMD =>.AMD
HKLM\SOFTWARE\AMDDVR
HKLM\SOFTWARE\ASUS =>.ASUS
HKLM\SOFTWARE\Atheros =>.Qualcomm Atheros
HKLM\SOFTWARE\ATI =>.ATI
HKLM\SOFTWARE\ATI Technologies =>.ATI Technologies
HKLM\SOFTWARE\AVG =>.AVG Software
HKLM\SOFTWARE\Cnxt_UCI_Parms
HKLM\SOFTWARE\Cnxt_Uiu_Parms =>.Conexant Systems, Inc.
HKLM\SOFTWARE\Conexant =>.Conexant Systems, Inc.
HKLM\SOFTWARE\CVSM =>.Legitimate
HKLM\SOFTWARE\DefaultUserEnvironment =>.Microsoft Corporation
HKLM\SOFTWARE\Google =>.Google
HKLM\SOFTWARE\ICEpower =>.ICEpower
HKLM\SOFTWARE\INextUUID =>.Hewlett-Packard
HKLM\SOFTWARE\InstalledOptions =>.Installed Options
HKLM\SOFTWARE\Intel =>.Intel
HKLM\SOFTWARE\Khronos =>.Khronos
HKLM\SOFTWARE\LSI =>.LSI
HKLM\SOFTWARE\Macromedia =>.Macromedia
HKLM\SOFTWARE\Mozilla =>.Mozilla
HKLM\SOFTWARE\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\Nahimic =>.Nahimic
HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\OEM =>.OEM
HKLM\SOFTWARE\OpenSSH =>.OpenBSD
HKLM\SOFTWARE\Partner =>.Google Inc.
HKLM\SOFTWARE\Piriform =>.Piriform
HKLM\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKLM\SOFTWARE\RTLSetup =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Synaptics =>.Synaptics
HKLM\SOFTWARE\UIU =>.Legitimate
HKLM\SOFTWARE\UIUTask
HKLM\SOFTWARE\Windows =>.Microsoft Corporation
HKLM\SOFTWARE\WinRAR =>.WinRAR
HKLM\SOFTWARE\WOW6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\WOW6432Node\AMD =>.AMD
HKLM\SOFTWARE\WOW6432Node\Apple Inc. =>.Apple Inc.
HKLM\SOFTWARE\WOW6432Node\ASUS =>.ASUS
HKLM\SOFTWARE\WOW6432Node\Atheros =>.Qualcomm Atheros
HKLM\SOFTWARE\WOW6432Node\ATI =>.ATI
HKLM\SOFTWARE\WOW6432Node\ATI Technologies =>.ATI Technologies
HKLM\SOFTWARE\WOW6432Node\AVG =>.AVG Software
HKLM\SOFTWARE\WOW6432Node\Chromium =>.Chromium
HKLM\SOFTWARE\WOW6432Node\Conexant =>.Conexant Systems, Inc.
HKLM\SOFTWARE\WOW6432Node\Gamehouse =>.GameHouse
HKLM\SOFTWARE\WOW6432Node\Google =>.Google
HKLM\SOFTWARE\WOW6432Node\IM Providers =>.IM Providers
HKLM\SOFTWARE\WOW6432Node\Intel =>.Intel
HKLM\SOFTWARE\WOW6432Node\Khronos =>.Khronos
HKLM\SOFTWARE\WOW6432Node\Kingsoft =>.Kingosoft Technology Ltd
HKLM\SOFTWARE\WOW6432Node\LibreOffice =>.LibreOffice
HKLM\SOFTWARE\WOW6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\WOW6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\WOW6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\WOW6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\WOW6432Node\Piriform =>.Piriform
HKLM\SOFTWARE\WOW6432Node\PopCap =>.Popcap Games
HKLM\SOFTWARE\WOW6432Node\Qualcomm Atheros =>.Qualcomm Atheros
HKLM\SOFTWARE\WOW6432Node\Realtek =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\WOW6432Node\ReflexiveArcade =>.Games Software
HKLM\SOFTWARE\WOW6432Node\SuppHelpDir =>.Toshiba Corporation
HKLM\SOFTWARE\WOW6432Node\TeamViewer =>.TeamViewer GmbH
HKLM\SOFTWARE\WOW6432Node\The Document Foundation =>.The Document Foundation
HKLM\SOFTWARE\WOW6432Node\Trymedia Systems =>PUP.Optional.Trymedia
HKLM\SOFTWARE\WOW6432Node\Win8FiveKey =>PUP.Optional.WordAnchor
HKLM\SOFTWARE\WOW6432Node\WOW6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\AMD =>.AMD
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\ASUS =>.ASUS
HKCU\SOFTWARE\ATI =>.ATI
HKCU\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o
HKCU\SOFTWARE\AVG =>.AVG Software
HKCU\SOFTWARE\Browser Cleanup =>.Avast Software s.r.o
HKCU\SOFTWARE\CCleaner Browser
HKCU\SOFTWARE\Chromium =>.Chromium
HKCU\SOFTWARE\Conexant =>.Conexant Systems, Inc.
HKCU\SOFTWARE\Gamehouse =>.GameHouse
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\HDID
HKCU\SOFTWARE\IM Providers =>.IM Providers
HKCU\SOFTWARE\Intel =>.Intel
HKCU\SOFTWARE\Kingsoft =>.Kingosoft Technology Ltd
HKCU\SOFTWARE\KsoLogViewer =>..SUP.ZhuhaiKingsoft
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKCU\SOFTWARE\Netscape =>.Netscape
HKCU\SOFTWARE\nwjs =>.NW.js
HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKCU\SOFTWARE\Piriform =>.Piriform
HKCU\SOFTWARE\ReflexiveArcade =>.Games Software
HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\roamingdevice =>.Unknown
HKCU\SOFTWARE\SyncEngines =>.Microsoft Corporation
HKCU\SOFTWARE\The Document Foundation =>.The Document Foundation
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\Valve =>.Valve
HKCU\SOFTWARE\WinRAR =>.WinRAR
HKCU\SOFTWARE\WinRAR SFX =>.RarLab
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\ZoomUMX
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKU\.DEFAULT\SOFTWARE\ATI =>.ATI
HKU\.DEFAULT\SOFTWARE\Conexant =>.Conexant Systems, Inc.
HKU\.DEFAULT\SOFTWARE\Google =>.Google
HKU\.DEFAULT\SOFTWARE\Piriform =>.Piriform
HKU\.DEFAULT\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Adobe =>.Adobe
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\AMD =>.AMD
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\ASUS =>.ASUS
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\ATI =>.ATI
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\AVG =>.AVG Software
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Browser Cleanup =>.Avast Software s.r.o
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\CCleaner Browser
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Chromium =>.Chromium
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Conexant =>.Conexant Systems, Inc.
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Gamehouse =>.GameHouse
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Google =>.Google
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\HDID
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\IM Providers =>.IM Providers
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Intel =>.Intel
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Kingsoft =>.Kingosoft Technology Ltd
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\KsoLogViewer =>..SUP.ZhuhaiKingsoft
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Mozilla =>.Mozilla
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Netscape =>.Netscape
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\nwjs =>.NW.js
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Piriform =>.Piriform
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\ReflexiveArcade =>.Games Software
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\roamingdevice =>.Unknown
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\SyncEngines =>.Microsoft Corporation
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\The Document Foundation =>.The Document Foundation
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Trolltech =>.Trolltech
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Valve =>.Valve
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\WinRAR =>.WinRAR
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\WinRAR SFX =>.RarLab
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\ZHP =>.Nicolas Coolman
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\SOFTWARE\ZoomUMX

---\\ PACKAGES (12) - 0s
C:\Program Files (x86)\WindowsApps\1527c705-839a-4832-9118-54d4Bd6a0c89_10.0.18362.267_neutral_neutral_cw5n1h2txyewy - (..) [][]
C:\Program Files (x86)\WindowsApps\4DF9E0F8.Netflix_6.97.752.0_x64__mcm4njqhnhss8 - (.Netflix.) [][Netflix] =>Netflix
C:\Program Files (x86)\WindowsApps\5319275A.WhatsAppDesktop_2.2027.10.0_x64__cv1g1gvanyjgm - (..) [][WhatsApp Desktop]
C:\Program Files (x86)\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w - (.Autodesk Inc..) [][Autodesk SketchBook] =>Autodesk Inc.
C:\Program Files (x86)\WindowsApps\AD2F1837.HPPrinterControl_115.1.152.0_x64__v10z8vjag6ke6 - (.Hewlett-Packard.) [][HP Smart] =>Hewlett-Packard
C:\Program Files (x86)\WindowsApps\AdobeSystemsIncorporated.AdobeReader_3.1.8.7675_x86__ynb6jyjzte8ga - (.Adobe Systems Incorporated.) [][Adobe Reader Touch] =>Adobe Systems Incorporated
C:\Program Files (x86)\WindowsApps\B9ECED6F.MyASUS_3.3.11.0_x86__qmba6cd70vzyy - (.ASUSTeK COMPUTER INC..) [][MyASUS-Service Center] =>ASUSTeK COMPUTER INC.
C:\Program Files (x86)\WindowsApps\c5e2524a-ea46-4f67-841f-6a9465d9d515_10.0.18362.267_neutral_neutral_cw5n1h2txyewy - (..) [][]
C:\Program Files (x86)\WindowsApps\E2A4F912-2574-4A75-9BB0-0D023378592B_10.0.18362.267_neutral_neutral_cw5n1h2txyewy - (..) [][]
C:\Program Files (x86)\WindowsApps\F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_10.0.18362.267_neutral_neutral_cw5n1h2txyewy - (..) [][]
C:\Program Files (x86)\WindowsApps\Facebook.Facebook_186.2619.19263.0_x86__8xx8rvfyw5nnt - (.Facebook Inc.) [][Facebook] =>Facebook Inc
C:\Program Files (x86)\WindowsApps\king.com.CandyCrushSodaSaga_1.172.400.0_x86__kgqvnymyfvs32 - (.king.com.) [][Candy Crush Soda Saga] =>king.com

---\\ CONTENU DES DOSSIERS PROGRAMMES (207) - 16s
O43 - CFD: 25/11/2019 - [] AD -- C:\Program Files\AMD [Unsigned] =>.AMD
O43 - CFD: 11/07/2020 - [] D -- C:\Program Files\CCleaner =>.Piriform Ltd
O43 - CFD: 11/07/2020 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 20/08/2019 - [] D -- C:\Program Files\CONEXANT =>.Conexant Systems, Inc.
O43 - CFD: 03/03/2017 - [] D -- C:\Program Files\DIFX =>.Microsoft Corporation
O43 - CFD: 24/07/2017 - [0] SHD -- C:\Program Files\Fichiers communs =>.Microsoft Corporation
O43 - CFD: 13/02/2020 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 11/07/2020 - [] AD -- C:\Program Files\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [0] D -- C:\Program Files\ModifiableWindowsApps =>.Microsoft Corporation
O43 - CFD: 15/11/2019 - [0] D -- C:\Program Files\Mozilla Firefox =>.Mozilla
O43 - CFD: 20/08/2019 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 20/08/2019 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 23/08/2019 - [] D -- C:\Program Files\rempl =>.Microsoft Corporation
O43 - CFD: 11/11/2016 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 10/06/2020 - [] D -- C:\Program Files\UNP =>.Microsoft Corporation
O43 - CFD: 12/03/2020 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 31/07/2020 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 17/06/2020 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 21/08/2019 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 17/06/2020 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Windows Security =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] SHD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 31/07/2020 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 12/05/2020 - [] D -- C:\Program Files\WinRAR =>.win.rar GmbH®
O43 - CFD: 12/05/2020 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Inc.®
O43 - CFD: 25/11/2019 - [] D -- C:\Program Files (x86)\AMD [Unsigned] =>.AMD
O43 - CFD: 17/04/2019 - [] D -- C:\Program Files (x86)\ASUS =>.ASUSTeK Computer Inc.®
O43 - CFD: 03/03/2017 - [] AD -- C:\Program Files (x86)\ATI Technologies =>.ATI Technologies
O43 - CFD: 03/03/2017 - [] AD -- C:\Program Files (x86)\Bluetooth Suite =>.ASUSTeK
O43 - CFD: 14/08/2020 - [] D -- C:\Program Files (x86)\CCleaner Browser =>.Piriform Software Ltd®
O43 - CFD: 11/07/2020 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 15/11/2019 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 03/03/2017 - [] D -- C:\Program Files (x86)\ICEpower =>.ICEpower
O43 - CFD: 03/03/2017 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield
O43 - CFD: 13/02/2020 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 11/11/2016 - [] D -- C:\Program Files (x86)\Kingsoft =>.Kingosoft Technology Ltd
O43 - CFD: 08/11/2017 - [] AD -- C:\Program Files (x86)\LibreOffice 5 =>.LibreOffice
O43 - CFD: 18/06/2020 - [] D -- C:\Program Files (x86)\Microsoft =>.Microsoft Corporation
O43 - CFD: 11/07/2020 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services =>.Microsoft Corporation
O43 - CFD: 11/07/2020 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 11/07/2020 - [] D -- C:\Program Files (x86)\Microsoft SQL Server =>.Microsoft Corporation
O43 - CFD: 11/07/2020 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 11/07/2020 - [] D -- C:\Program Files (x86)\Mozilla Firefox =>.Mozilla
O43 - CFD: 11/07/2020 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 06/01/2019 - [] D -- C:\Program Files (x86)\MSECache =>.Microsoft Corporation
O43 - CFD: 03/03/2017 - [] AD -- C:\Program Files (x86)\Qualcomm Atheros =>.Qualcomm Atheros
O43 - CFD: 03/03/2017 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek
O43 - CFD: 20/08/2019 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 23/09/2018 - [] D -- C:\Program Files (x86)\ReflexiveArcade
O43 - CFD: 29/02/2020 - [] AD -- C:\Program Files (x86)\TeamViewer =>.TeamViewer GmbH
O43 - CFD: 31/07/2017 - [] D -- C:\Program Files (x86)\VulkanRT =>.LunarG, Inc
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 31/07/2020 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 17/06/2020 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 17/06/2020 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] SHD -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 17/06/2020 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 17/06/2020 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 25/11/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Settings =>.Samsung Electronics
O43 - CFD: 20/08/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assistant de signalisation de problèmes AMD
O43 - CFD: 20/08/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS =>.ASUS
O43 - CFD: 11/07/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd
O43 - CFD: 20/08/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant =>.Conexant Systems, Inc.
O43 - CFD: 20/08/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICEpower =>.ICEpower
O43 - CFD: 20/08/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.4 =>.LibreOffice
O43 - CFD: 19/03/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 20/08/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office 2016 =>.Microsoft Corporation
O43 - CFD: 11/07/2020 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office 2016 =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation
O43 - CFD: 12/03/2020 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 12/05/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 12/05/2020 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 21/08/2019 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 17/04/2019 - [] D -- C:\ProgramData\ASUS =>.ASUS
O43 - CFD: 17/08/2020 - [] D -- C:\ProgramData\ASUS Smart Gesture =>.ASUSTeK
O43 - CFD: 31/07/2017 - [] D -- C:\ProgramData\ATI =>.ATI
O43 - CFD: 24/09/2018 - [] D -- C:\ProgramData\AVG =>.AVG Software
O43 - CFD: 24/07/2017 - [0] SHD -- C:\ProgramData\Bureau =>.Microsoft Corporation
O43 - CFD: 11/07/2020 - [0] D -- C:\ProgramData\CCleaner Browser
O43 - CFD: 24/09/2018 - [] HD -- C:\ProgramData\Common Files =>.Microsoft Corporation
O43 - CFD: 16/07/2016 - [0] D -- C:\ProgramData\Comms =>.Microsoft Corporation
O43 - CFD: 03/03/2017 - [] D -- C:\ProgramData\Conexant =>.Conexant Systems, Inc.
O43 - CFD: 21/08/2019 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 01/04/2020 - [] D -- C:\ProgramData\HP =>.Hewlett-Packard
O43 - CFD: 11/11/2016 - [] D -- C:\ProgramData\Kingsoft =>.Kingosoft Technology Ltd
O43 - CFD: 24/07/2017 - [0] SHD -- C:\ProgramData\Menu Démarrer =>.Microsoft Corporation
O43 - CFD: 11/07/2020 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 11/07/2020 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 21/08/2019 - [] D -- C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation
O43 - CFD: 24/07/2017 - [0] SHD -- C:\ProgramData\Modèles =>.Microsoft Corporation
O43 - CFD: 15/11/2019 - [] D -- C:\ProgramData\Mozilla =>.Mozilla Corporation
O43 - CFD: 12/05/2020 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 01/04/2020 - [] D -- C:\ProgramData\Packages =>.Microsoft Corporation
O43 - CFD: 03/03/2017 - [] D -- C:\ProgramData\Qualcomm Atheros =>.Qualcomm Atheros
O43 - CFD: 17/08/2020 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 05/09/2017 - [] D -- C:\ProgramData\SetupTPDriver =>.ASUSTeK
O43 - CFD: 19/03/2019 - [0] D -- C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation
O43 - CFD: 13/02/2020 - [0] D -- C:\ProgramData\ssh
O43 - CFD: 14/06/2019 - [] D -- C:\ProgramData\UIU
O43 - CFD: 24/07/2017 - [] D -- C:\ProgramData\USBChargerPlus =>.ASUSTeK
O43 - CFD: 21/08/2019 - [] D -- C:\ProgramData\USOPrivate =>.Microsoft Corporation
O43 - CFD: 20/08/2019 - [] D -- C:\ProgramData\USOShared =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\ProgramData\WindowsHolographicDevices =>.Microsoft Corporation
O43 - CFD: 14/08/2020 - [] D -- C:\ProgramData\{45DD80BE-CF9F-0A78-4959-943AD31B1FF4}
O43 - CFD: 17/01/2020 - [0] D -- C:\ProgramData\{AE00923C-8628-EA44-DE70-C26C36981AB4}
O43 - CFD: 12/05/2020 - [] D -- C:\Program Files (x86)\Common Files\Adobe =>.Adobe
O43 - CFD: 03/03/2017 - [] D -- C:\Program Files (x86)\Common Files\Atheros =>.Qualcomm Atheros
O43 - CFD: 11/07/2020 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER =>.Designer
O43 - CFD: 11/07/2020 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 31/07/2020 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 12/05/2020 - [] D -- C:\Users\melvi\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 31/07/2017 - [] D -- C:\Users\melvi\AppData\Roaming\ATI =>.ATI
O43 - CFD: 09/04/2020 - [] D -- C:\Users\melvi\AppData\Roaming\discord =>.GitHub
O43 - CFD: 10/09/2017 - [] D -- C:\Users\melvi\AppData\Roaming\Kingsoft =>.Kingosoft Technology Ltd
O43 - CFD: 08/11/2017 - [] D -- C:\Users\melvi\AppData\Roaming\LibreOffice =>.LibreOffice
O43 - CFD: 24/07/2017 - [] D -- C:\Users\melvi\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 05/08/2020 - [] SD -- C:\Users\melvi\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 05/08/2020 - [] D -- C:\Users\melvi\AppData\Roaming\Microsoft Teams =>.Microsoft Corporation
O43 - CFD: 15/11/2019 - [] D -- C:\Users\melvi\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 31/01/2020 - [0] D -- C:\Users\melvi\AppData\Roaming\office6
O43 - CFD: 24/09/2018 - [] D -- C:\Users\melvi\AppData\Roaming\Rafuf
O43 - CFD: 30/07/2020 - [] D -- C:\Users\melvi\AppData\Roaming\Skype =>.Skype
O43 - CFD: 12/05/2020 - [] D -- C:\Users\melvi\AppData\Roaming\WinRAR =>.WinRAR
O43 - CFD: 31/01/2020 - [] D -- C:\Users\melvi\AppData\Roaming\wps
O43 - CFD: 17/08/2020 - [] D -- C:\Users\melvi\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 07/07/2020 - [] D -- C:\Users\melvi\AppData\Roaming\Zoom =>.ZOOM
O43 - CFD: 19/01/2020 - [] D -- C:\Users\melvi\AppData\Local\1e764bca936f249b56d11f1c3db039c0
O43 - CFD: 17/08/2020 - [] D -- C:\Users\melvi\AppData\Local\Adobe =>.Adobe
O43 - CFD: 27/11/2019 - [] D -- C:\Users\melvi\AppData\Local\AMD =>.AMD
O43 - CFD: 20/08/2019 - [0] SHD -- C:\Users\melvi\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 24/07/2017 - [] D -- C:\Users\melvi\AppData\Local\ASUS GIFTBOX =>.ASUSTeK
O43 - CFD: 31/07/2017 - [] D -- C:\Users\melvi\AppData\Local\ATI =>.ATI
O43 - CFD: 24/09/2018 - [] D -- C:\Users\melvi\AppData\Local\AVG =>.AVG Software
O43 - CFD: 11/07/2020 - [] D -- C:\Users\melvi\AppData\Local\CCleaner Browser
O43 - CFD: 24/09/2018 - [] D -- C:\Users\melvi\AppData\Local\CEF =>.CEF
O43 - CFD: 10/08/2019 - [] D -- C:\Users\melvi\AppData\Local\chromium =>.Chromium
O43 - CFD: 24/07/2017 - [] D -- C:\Users\melvi\AppData\Local\Comms =>.Microsoft Corporation
O43 - CFD: 24/07/2017 - [] D -- C:\Users\melvi\AppData\Local\Conexant =>.Conexant Systems, Inc.
O43 - CFD: 21/08/2019 - [] D -- C:\Users\melvi\AppData\Local\ConnectedDevicesPlatform =>.Microsoft Corporation
O43 - CFD: 11/07/2020 - [0] D -- C:\Users\melvi\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 24/07/2017 - [] D -- C:\Users\melvi\AppData\Local\Crashpad =>.Unknown
O43 - CFD: 12/05/2020 - [] D -- C:\Users\melvi\AppData\Local\D3DSCache =>.Legitimate
O43 - CFD: 26/07/2017 - [0] D -- C:\Users\melvi\AppData\Local\DBG =>.DBG
O43 - CFD: 26/02/2018 - [0] D -- C:\Users\melvi\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 09/04/2020 - [] D -- C:\Users\melvi\AppData\Local\Discord =>.GitHub
O43 - CFD: 16/06/2020 - [0] D -- C:\Users\melvi\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation
O43 - CFD: 30/07/2017 - [] D -- C:\Users\melvi\AppData\Local\Google =>.Google
O43 - CFD: 20/08/2019 - [0] SHD -- C:\Users\melvi\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 10/09/2017 - [] D -- C:\Users\melvi\AppData\Local\kingsoft =>.Kingosoft Technology Ltd
O43 - CFD: 05/08/2020 - [] D -- C:\Users\melvi\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 15/11/2019 - [] D -- C:\Users\melvi\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 24/07/2017 - [] D -- C:\Users\melvi\AppData\Local\MicrosoftEdge =>.Microsoft Corporation
O43 - CFD: 15/11/2019 - [] D -- C:\Users\melvi\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 24/07/2017 - [0] D -- C:\Users\melvi\AppData\Local\NetworkTiles =>.NetworkTiles
O43 - CFD: 11/07/2020 - [] D -- C:\Users\melvi\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 21/02/2018 - [] D -- C:\Users\melvi\AppData\Local\PackageStaging =>.Apcera
O43 - CFD: 11/09/2017 - [] D -- C:\Users\melvi\AppData\Local\Publishers =>.Microsoft Corporation
O43 - CFD: 27/11/2019 - [] D -- C:\Users\melvi\AppData\Local\RadeonSettings
O43 - CFD: 24/07/2017 - [] D -- C:\Users\melvi\AppData\Local\speech =>.Microsoft Corporation
O43 - CFD: 05/08/2020 - [] D -- C:\Users\melvi\AppData\Local\SquirrelTemp =>.Squirrels
O43 - CFD: 17/08/2020 - [] D -- C:\Users\melvi\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 20/08/2019 - [0] SHD -- C:\Users\melvi\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 09/12/2017 - [] D -- C:\Users\melvi\AppData\Local\TileDataLayer =>.Microsoft Corporation
O43 - CFD: 24/07/2017 - [0] D -- C:\Users\melvi\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 17/08/2020 - [] D -- C:\Users\melvi\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 05/03/2019 - [] D -- C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC} =>PUP.Optional.WinYahoo
O43 - CFD: 14/03/2019 - [] D -- C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4} =>PUP.Optional.WinYahoo
O43 - CFD: 04/03/2020 - [] D -- C:\Users\melvi\AppData\LocalLow\Adobe =>.Adobe
O43 - CFD: 31/07/2017 - [] D -- C:\Users\melvi\AppData\LocalLow\AMD =>.AMD
O43 - CFD: 05/08/2020 - [] SD -- C:\Users\melvi\AppData\LocalLow\Microsoft =>.Microsoft Corporation
O43 - CFD: 15/11/2019 - [0] D -- C:\Users\melvi\AppData\LocalLow\Mozilla =>.Mozilla Corporation
O43 - CFD: 16/02/2020 - [] D -- C:\Users\melvi\AppData\LocalLow\Temp =>.Microsoft Corporation
O43 - CFD: 12/05/2020 - [] D -- C:\Users\melvi\Desktop\Adobe Illustrator 2020
O43 - CFD: 30/07/2020 - [] D -- C:\Users\melvi\Desktop\Microsoft office =>.Microsoft Corporation
O43 - CFD: 11/07/2020 - [] D -- C:\Users\melvi\Desktop\Off Pro+ 2016 64-32Bit by lacoste62 for phoenix-warez
O43 - CFD: 05/11/2018 - [] D -- C:\Users\melvi\Desktop\Word 2007
O43 - CFD: 19/03/2019 - [] RD -- C:\Users\melvi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 21/08/2019 - [] RD -- C:\Users\melvi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 31/07/2020 - [] RD -- C:\Users\melvi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 09/04/2020 - [0] D -- C:\Users\melvi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc =>.Discord Inc
O43 - CFD: 19/03/2019 - [] D -- C:\Users\melvi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 31/07/2020 - [] RD -- C:\Users\melvi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] RD -- C:\Users\melvi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] RD -- C:\Users\melvi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation
O43 - CFD: 12/05/2020 - [] D -- C:\Users\melvi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 31/01/2020 - [] D -- C:\Users\melvi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WPS Office =>.Kingosoft Technology Ltd
O43 - CFD: 07/07/2020 - [] D -- C:\Users\melvi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom =>.ZOOM
O43 - CFD: 21/08/2019 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 24/07/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 21/08/2019 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 21/08/2019 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 24/07/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 19/03/2019 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 21/08/2019 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 23/08/2019 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation

---\\ ShellIconOverlayIdentifiers (SIOI) (4) - 1s
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) [ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) [ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 3 (InSync) [ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft®
O106 - SIOI: [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll [Unsigned] =>.Microsoft Corporation

---\\ RACCOURCIS DES MENUS CONTEXTUELS (SCMH) (28) - 3s
O108 - CMH1: EPP [64Bits] - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Extension Microsoft Security Client Shell.) -- C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows®
O108 - CMH1: ModernSharing [64Bits] - {e2bf9676-5f8f-435c-97eb-11607a5bedf7} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH1: Open With [64Bits] - {09799AFB-AD67-11d1-ABCD-00C04FC30936} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH1: Open With EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH1: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH1: WinRAR [64Bits] - {B41DB860-64E4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH®
O108 - CMH1: WinRAR32 [64Bits] - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Orphan.) [Unsigned]
O108 - CMH1: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extension d’environnement de Dossiers de tr.) -- C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH2: OpenContainingFolderMenu [64Bits] - {37ea3a21-7493-4208-a011-7f9ea79ce9f5} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH2: WinRAR [64Bits] - {B41DB860-64E4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH®
O108 - CMH2: WinRAR32 [64Bits] - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Orphan.) [Unsigned]
O108 - CMH3: CopyAsPathMenu [64Bits] - {f3d06e7c-1e45-4a26-847e-f9fcdee59be0} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH3: SendTo [64Bits] - {7BA4C740-9E81-11CF-99D3-00AA004AE837} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH4: EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH4: EPP [64Bits] - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Extension Microsoft Security Client Shell.) -- C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows®
O108 - CMH4: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH4: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extension d’environnement de Dossiers de tr.) -- C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH5: ACE [64Bits] - {5E2121EE-0300-11D4-8D3B-444553540000} . (.Advanced Micro Devices, Inc. - Radeon Settings: Desktop Control Panel.) -- C:\Program Files\AMD\CNext\CNext\atiacm64.dll =>.Advanced Micro Devices, Inc.®
O108 - CMH5: New [64Bits] - {D969A300-E7FF-11d0-A93B-00A0C90F2719} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH5: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH5: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extension d’environnement de Dossiers de tr.) -- C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH6: Library Location [64Bits] - {3dad6c5d-2167-4cae-9914-f99e41c12cfa} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft®
O108 - CMH6: PintoStartScreen [64Bits] - {470C0EBD-5D73-4d58-9CED-E91E22E23282} . (.Microsoft Corporation - Programme de résolution d’applications.) -- C:\Windows\System32\appresolver.dll =>.Microsoft®
O108 - CMH6: WinRAR [64Bits] - {B41DB860-64E4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH®
O108 - CMH6: WinRAR32 [64Bits] - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Orphan.) [Unsigned]
O108 - CMH7: EnhancedStorageShell [64Bits] - {2854F705-3548-414C-A113-93E27C808C85} . (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll [Unsigned] =>.Microsoft Corporation
O108 - CMH7: EPP [64Bits] - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Extension Microsoft Security Client Shell.) -- C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows®
O108 - CMH7: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation

---\\ IMAGE FILE EXECUTION OPTIONS (IFEO) (17) - 4s
O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\\3] =>.Microsoft Windows®
O50 - IFEO:C:\WINDOWS\System32\drvinst.exe - (.Microsoft Corporation - Module d’installation de pilotes.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\ie4uinit.exe - (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - Outil d’installation sans assistance d’IE 7.) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Microsoft Management Console.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\MRT.exe - (.Microsoft Corporation - Outil de suppression de logiciels malveilla.) [CFGOptions\\1] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Hôte des applications HTML de Microsoft(R).) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation Host.) [MitigationOptions\\1118481] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\\2097152] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\\4294967296] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Application sous-système spouleur.) [MitigationOptions\\2097152] [Unsigned] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Processus hôte pour les services Windows.) [MinimumStackCommitInBytes\\32768] =>.Microsoft Windows Publisher®
O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation

---\\ LISTE DES PILOTES DU SYSTÈME (430) - 50s
O58 - SDL:2019/03/19 06:43:39 A . (.Microsoft Corporation - 1394 OpenHCI Driver.) -- C:\WINDOWS\System32\drivers\1394ohci.sys [264704] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:39 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107528] =>.Microsoft Windows®
O58 - SDL:2019/10/01 21:53:23 A . (.Microsoft Corporation - Pilote ACPI pour NT.) -- C:\WINDOWS\System32\drivers\acpi.sys [804664] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:39 A . (.Microsoft Corporation - ACPI Devices Driver.) -- C:\WINDOWS\System32\drivers\AcpiDev.sys [20992] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:49 A . (.Microsoft Corporation - ACPIEx Driver.) -- C:\WINDOWS\System32\drivers\acpiex.sys [136712] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - ACPI Processor Aggregator Device Driver.) -- C:\WINDOWS\System32\drivers\acpipagr.sys [12800] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:38 A . (.Microsoft Corporation - ACPI Power Metering Driver.) -- C:\WINDOWS\System32\drivers\acpipmi.sys [16896] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - ACPI Wake Alarm.) -- C:\WINDOWS\System32\drivers\acpitime.sys [13824] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:09:32 A . (.Microsoft Corporation - Audio KMDF Class Extension.) -- C:\WINDOWS\System32\drivers\Acx01000.sys [337920] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:39 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135632] =>.Microsoft Windows®
O58 - SDL:2020/05/18 16:35:21 A . (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\WINDOWS\System32\drivers\afd.sys [661816] =>.Microsoft®
O58 - SDL:2020/03/12 16:10:38 A . (.Microsoft Corporation - AF_UNIX socket provider.) -- C:\WINDOWS\System32\drivers\afunix.sys [40960] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:10:39 A . (.Microsoft Corporation - Gestionnaire d'appels RAS Agile Vpn Minipor.) -- C:\WINDOWS\System32\drivers\agilevpn.sys [114176] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:10:34 A . (.Microsoft Corporation - Application Compatibility Cache.) -- C:\WINDOWS\System32\drivers\ahcache.sys [291840] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2015/05/25 15:20:18 A . (.ASUSTek Computer Inc. - ASUS Charger driver.) -- C:\WINDOWS\System32\drivers\AiCharger.sys [21816] =>.ASUSTeK Computer Inc.®
O58 - SDL:2019/03/19 06:43:33 A . (.Advanced Micro Devices, Inc - AMD GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\amdgpio2.sys [18432] [Unsigned] =>.Advanced Micro Devices, Inc
O58 - SDL:2019/03/19 06:43:33 A . (.Advanced Micro Devices, Inc - AMD I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\amdi2c.sys [37888] [Unsigned] =>.Advanced Micro Devices, Inc
O58 - SDL:2020/03/12 16:09:24 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\WINDOWS\System32\drivers\amdk8.sys [199992] =>.Microsoft®
O58 - SDL:2016/08/18 14:41:28 A . (.Advanced Micro Devices, Inc. - AMD Audio Bus Lower Filter.) -- C:\WINDOWS\System32\drivers\amdkmafd.sys [49448] =>.Advanced Micro Devices, Inc.®
O58 - SDL:2017/06/12 06:07:16 A . (.Advanced Micro Devices, Inc. - amdkmcsp sys.) -- C:\WINDOWS\System32\drivers\amdkmcsp.sys [101232] =>.Advanced Micro Devices Inc.®
O58 - SDL:2019/09/18 18:59:20 A . (.Advanced Micro Devices, Inc. - AMD PCI Root Bus Lower Filter.) -- C:\WINDOWS\System32\drivers\amdkmpfd.sys [102832] =>.Advanced Micro Devices, Inc.®
O58 - SDL:2020/03/12 16:09:24 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\WINDOWS\System32\drivers\amdppm.sys [201528] =>.Microsoft®
O58 - SDL:2017/06/12 06:07:16 A . (.Advanced Micro Devices, Inc. - amdpsp sys.) -- C:\WINDOWS\System32\drivers\amdpsp.sys [243056] =>.Advanced Micro Devices Inc.®
O58 - SDL:2019/03/19 06:43:39 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83464] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259600] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [27176] =>.Microsoft Windows®
O58 - SDL:2019/11/17 02:37:19 A . (.Microsoft Corporation - AppID Driver.) -- C:\WINDOWS\System32\drivers\appid.sys [202552] =>.Microsoft®
O58 - SDL:2019/11/17 02:37:19 A . (.Microsoft Corporation - Applocker Filter.) -- C:\WINDOWS\System32\drivers\applockerfltr.sys [18432] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:39 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [132112] =>.Microsoft Windows®
O58 - SDL:2015/08/19 12:53:54 A . (.ASUS - HID driver for ASUS Wireless Radio Control.) -- C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [27872] =>.ASUSTeK Computer Inc.®
O58 - SDL:2019/08/07 19:04:00 A . (.ASUS - ASUS Wireless Radio Control.) -- C:\WINDOWS\System32\drivers\AsRadioControl.sys [32680] =>.ASUSTek Computer Inc.®
O58 - SDL:2017/03/09 10:18:58 A . (.ASUS Corporation - Asus TP Filter Driver(X64).) -- C:\WINDOWS\System32\drivers\AsusTP.sys [128024] =>.ASUSTeK Computer Inc.®
O58 - SDL:2019/03/19 06:45:02 A . (.Microsoft Corporation - MS Remote Access serial network driver.) -- C:\WINDOWS\System32\drivers\asyncmac.sys [31232] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:09:25 A . (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [30008] =>.Microsoft®
O58 - SDL:2020/03/12 16:09:25 A . (.Microsoft Corporation - ATAPI Driver Extension.) -- C:\WINDOWS\System32\drivers\ataport.sys [222520] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:33 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\drivers\athw8x.sys [4233728] [Unsigned] =>.Qualcomm Atheros Communications, Inc.
O58 - SDL:2017/04/26 09:09:04 A . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\WINDOWS\System32\drivers\AtihdWT6.sys [110088] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2019/03/19 06:44:01 A . (.Microsoft Corporation - BAM Kernel Driver.) -- C:\WINDOWS\System32\drivers\bam.sys [70456] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - Battery Class Driver.) -- C:\WINDOWS\System32\drivers\battc.sys [41784] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:34 A . (. - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [9728] [Unsigned] =>.Broadcom Corporation
O58 - SDL:2019/03/19 06:44:32 A . (.Microsoft Corporation - BEEP Driver.) -- C:\WINDOWS\System32\drivers\beep.sys [10240] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/02/13 01:39:10 A . (.Microsoft Corporation - Windows Bind Filter Driver.) -- C:\WINDOWS\System32\drivers\bindflt.sys [117264] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:53 A . (.Microsoft Corporation - NT Lan Manager Datagram Receiver Driver.) -- C:\WINDOWS\System32\drivers\bowser.sys [117248] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:45:38 A . (.Microsoft Corporation - MAC Bridge Driver.) -- C:\WINDOWS\System32\drivers\bridge.sys [127488] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:33 A . (.Microsoft Corporation - Microsoft Bluetooth Audio Multiprofile Mana.) -- C:\WINDOWS\System32\drivers\BtaMPM.sys [36352] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/01/31 00:44:54 A . (.Qualcomm - BT Filter.) -- C:\WINDOWS\System32\drivers\btfilter.sys [69368] =>.Qualcomm Atheros®
O58 - SDL:2020/03/12 16:09:23 A . (.Microsoft Corporation - Bluetooth A2DP Driver.) -- C:\WINDOWS\System32\drivers\BthA2dp.sys [231936] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:09:25 A . (.Microsoft Corporation - Extension de bus Bluetooth.) -- C:\WINDOWS\System32\drivers\bthenum.sys [114688] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:33 A . (.Microsoft Corporation - Bluetooth Hands-free Audio Device Driver.) -- C:\WINDOWS\System32\drivers\BthHfAud.sys [57856] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:33 A . (.Microsoft Corporation - Bluetooth Hands-Free Audio and Call Control.) -- C:\WINDOWS\System32\drivers\BthHfEnum.sys [131072] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:09:25 A . (.Microsoft Corporation - Bluetooth Transport Extensibility Miniport.) -- C:\WINDOWS\System32\drivers\BthMini.SYS [36864] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:37 A . (.Microsoft Corporation - Bluetooth Communications Driver.) -- C:\WINDOWS\System32\drivers\bthmodem.sys [76288] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Bluetooth Personal Area Networking.) -- C:\WINDOWS\System32\drivers\bthpan.sys [133120] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:09:25 A . (.Microsoft Corporation - Pilote de bus Bluetooth.) -- C:\WINDOWS\System32\drivers\bthport.sys [1428992] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:09:25 A . (.Microsoft Corporation - Pilote de Miniport Bluetooth.) -- C:\WINDOWS\System32\drivers\BTHUSB.SYS [99328] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - VHD BTT Filter Driver.) -- C:\WINDOWS\System32\drivers\bttflt.sys [42808] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Button Converter Driver.) -- C:\WINDOWS\System32\drivers\buttonconverter.sys [43008] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:38 A . (.QLogic Corporation - QLogic Gigabit Ethernet VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [534032] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:34 A . (.Microsoft Corporation - Charge Arbiration Driver.) -- C:\WINDOWS\System32\drivers\CAD.sys [64312] =>.Microsoft Windows®
O58 - SDL:2019/12/13 21:19:35 A . (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\cdfs.sys [100352] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:39 A . (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\cdrom.sys [173056] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:01 A . (.Microsoft Corporation - Event Aggregation Kernel Mode Library.) -- C:\WINDOWS\System32\drivers\CEA.sys [82448] =>.Microsoft Windows®
O58 - SDL:2018/11/27 01:34:18 A . (.Conexant Systems Inc. - 64-bit High Definition Audio Function Drive.) -- C:\WINDOWS\System32\drivers\CHDRT64.sys [3463464] =>.Synaptics Incorporated®
O58 - SDL:2019/03/19 06:43:40 A . (.Chelsio Communications - Chelsio iSCSI Crash Dump Driver.) -- C:\WINDOWS\System32\drivers\cht4dx64.sys [142864] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:40 A . (.Chelsio Communications - Chelsio iSCSI VMiniport Driver.) -- C:\WINDOWS\System32\drivers\cht4sx64.sys [319528] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:41 A . (.Chelsio Communications - VF library for Chelsio ® T5/T6 Chipset.) -- C:\WINDOWS\System32\drivers\cht4vfx.sys [29696] [Unsigned] =>.Chelsio Communications
O58 - SDL:2019/03/19 06:43:41 A . (.Chelsio Communications - Virtual Bus Driver for Chelsio ® T5/T6 Chip.) -- C:\WINDOWS\System32\drivers\cht4vx64.sys [1866768] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:37 A . (.Microsoft Corporation - Consumer IR Class Driver for eHome.) -- C:\WINDOWS\System32\drivers\circlass.sys [51200] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/02/13 01:39:25 A . (.Microsoft Corporation - SCSI Class System Dll.) -- C:\WINDOWS\System32\drivers\Classpnp.sys [416056] =>.Microsoft®
O58 - SDL:2020/05/18 16:34:33 A . (.Microsoft Corporation - Cloud Files Mini Filter Driver.) -- C:\WINDOWS\System32\drivers\cldflt.sys [457216] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/18 16:35:29 A . (.Microsoft Corporation - Common Log File System Driver.) -- C:\WINDOWS\System32\drivers\clfs.sys [400696] =>.Microsoft®
O58 - SDL:2019/10/11 17:43:25 A . (.Microsoft Corporation - CLIP Service.) -- C:\WINDOWS\System32\drivers\ClipSp.sys [1029432] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - Control Method Battery Driver.) -- C:\WINDOWS\System32\drivers\CmBatt.sys [36864] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:49 A . (.Microsoft Corporation - Noyau Gestionnaire de configuration Configu.) -- C:\WINDOWS\System32\drivers\cmimcext.sys [29200] =>.Microsoft Windows®
O58 - SDL:2020/05/18 16:35:16 A . (.Microsoft Corporation - Kernel Cryptography, Next Generation.) -- C:\WINDOWS\System32\drivers\cng.sys [752584] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:18 A . (.Microsoft Corporation - CNG Hardware Assist algorithm provider.) -- C:\WINDOWS\System32\drivers\cnghwassist.sys [40760] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:16 A . (.Microsoft Corporation - Console Driver.) -- C:\WINDOWS\System32\drivers\condrv.sys [58896] =>.Microsoft Windows®
O58 - SDL:2020/03/12 16:10:20 A . (.Microsoft Corporation - Crash Dump Driver.) -- C:\WINDOWS\System32\drivers\crashdmp.sys [98104] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:00 A . (.Microsoft Corporation - DAM Kernel Driver.) -- C:\WINDOWS\System32\drivers\dam.sys [100152] =>.Microsoft Windows®
O58 - SDL:2019/08/20 21:24:49 A . (.Microsoft Corporation - Xbox Device Authentication Driver.) -- C:\WINDOWS\System32\drivers\devauthe.sys [47104] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:38 A . (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\dfsc.sys [151040] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:39 A . (.Microsoft Corporation - PnP Disk Driver.) -- C:\WINDOWS\System32\drivers\disk.sys [98104] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:45 A . (.Microsoft Corporation - Crash Dump Disk Driver.) -- C:\WINDOWS\System32\drivers\Diskdump.sys [37928] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:45 A . (.Microsoft Corporation - Boot Over USB Dump Driver.) -- C:\WINDOWS\System32\drivers\Dmpusbstor.sys [15360] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:44 A . (.Microsoft Corporation - Mémoire dynamique.) -- C:\WINDOWS\System32\drivers\dmvsc.sys [58168] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:37 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\WINDOWS\System32\drivers\drmk.sys [98304] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:37 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\WINDOWS\System32\drivers\drmkaud.sys [16344] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:28 A . (.Microsoft Corporation - ATAPI Dump Driver.) -- C:\WINDOWS\System32\drivers\Dumpata.sys [36904] =>.Microsoft Windows®
O58 - SDL:2019/08/20 21:27:57 A . (.Microsoft Corporation - Bitlocker Drive Encryption Crashdump Filter.) -- C:\WINDOWS\System32\drivers\dumpfve.sys [93104] =>.Microsoft®
O58 - SDL:2020/04/18 00:30:31 A . (.Microsoft Corporation - SD Crashdump Port Driver.) -- C:\WINDOWS\System32\drivers\dumpsd.sys [193848] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:18 A . (.Microsoft Corporation - SD Host Controller Crashdump Port Driver.) -- C:\WINDOWS\System32\drivers\dumpsdport.sys [32256] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:45 A . (.Microsoft Corporation - Storport Dump Driver.) -- C:\WINDOWS\System32\drivers\Dumpstorport.sys [34616] =>.Microsoft Windows®
O58 - SDL:2020/06/17 00:28:10 A . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\WINDOWS\System32\drivers\dxgkrnl.sys [3581240] =>.Microsoft®
O58 - SDL:2020/06/17 00:28:10 A . (.Microsoft Corporation - DirectX Graphics MMS.) -- C:\WINDOWS\System32\drivers\dxgmms1.sys [441152] =>.Microsoft®
O58 - SDL:2020/06/17 00:28:10 A . (.Microsoft Corporation - DirectX Graphics MMS.) -- C:\WINDOWS\System32\drivers\dxgmms2.sys [874296] =>.Microsoft®
O58 - SDL:2019/03/19 06:45:38 A . (.Microsoft Corporation - Enhanced Storage Class driver for IEEE 1667.) -- C:\WINDOWS\System32\drivers\EhStorClass.sys [85520] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:37 A . (.Microsoft Corporation - Microsoft driver for storage devices suppor.) -- C:\WINDOWS\System32\drivers\EhStorTcgDrv.sys [114696] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - Error Device Driver.) -- C:\WINDOWS\System32\drivers\errdev.sys [14336] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:38 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3419176] =>.Microsoft Windows®
O58 - SDL:2019/12/13 21:19:01 A . (.Microsoft Corporation - Microsoft Extended FAT File System.) -- C:\WINDOWS\System32\drivers\exfat.sys [404480] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/12/13 21:19:01 A . (.Microsoft Corporation - Fast FAT File System Driver.) -- C:\WINDOWS\System32\drivers\fastfat.sys [422712] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - Floppy Disk Controller Driver.) -- C:\WINDOWS\System32\drivers\fdc.sys [35328] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:49 A . (.Microsoft Corporation - Windows sandboxing and encryption filter.) -- C:\WINDOWS\System32\drivers\filecrypt.sys [59392] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:28 A . (.Microsoft Corporation - FileInfo Filter Driver.) -- C:\WINDOWS\System32\drivers\fileinfo.sys [94520] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:28 A . (.Microsoft Corporation - File Trace Filter Driver.) -- C:\WINDOWS\System32\drivers\filetrace.sys [40960] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/04/18 00:30:30 A . (.Microsoft Corporation - Floppy Driver.) -- C:\WINDOWS\System32\drivers\flpydisk.sys [28160] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/08/20 21:26:07 A . (.Microsoft Corporation - Gestionnaire de filtres de système de fichi.) -- C:\WINDOWS\System32\drivers\fltMgr.sys [437776] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:49 A . (.Microsoft Corporation - File System Dependency Manager Mini Filter.) -- C:\WINDOWS\System32\drivers\fsdepends.sys [67896] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:35 A . (.Microsoft Corporation - File System Recognizer Driver.) -- C:\WINDOWS\System32\drivers\fs_rec.sys [34320] =>.Microsoft Windows®
O58 - SDL:2019/08/20 21:27:57 A . (.Microsoft Corporation - BitLocker Drive Encryption Driver.) -- C:\WINDOWS\System32\drivers\fvevol.sys [800568] =>.Microsoft®
O58 - SDL:2020/05/18 16:35:26 A . (.Microsoft Corporation - FWP/IPsec Kernel-Mode API.) -- C:\WINDOWS\System32\drivers\FWPKCLNT.SYS [477496] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:45 A . (.Microsoft Corporation - GPU Energy Kernel Driver.) -- C:\WINDOWS\System32\drivers\gpuenergydrv.sys [8704] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:09:24 A . (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\hdaudbus.sys [114688] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/10/01 21:53:22 A . (.Microsoft Corporation - High Definition Audio Function Driver.) -- C:\WINDOWS\System32\drivers\HdAudio.sys [425472] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - Hid Battery Driver.) -- C:\WINDOWS\System32\drivers\hidbatt.sys [39736] =>.Microsoft Windows®
O58 - SDL:2020/05/18 16:31:27 A . (.Microsoft Corporation - Pilote de miniport Bluetooth pour les périp.) -- C:\WINDOWS\System32\drivers\hidbth.sys [121344] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/08/20 21:24:52 A . (.Microsoft Corporation - Bibliothèque Hid Class.) -- C:\WINDOWS\System32\drivers\hidclass.sys [211968] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - I2C HID Miniport Driver.) -- C:\WINDOWS\System32\drivers\hidi2c.sys [54784] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - HID Button over Interrupt Driver.) -- C:\WINDOWS\System32\drivers\hidinterrupt.sys [53560] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:37 A . (.Microsoft Corporation - Infrared Miniport Driver for Input Devices.) -- C:\WINDOWS\System32\drivers\hidir.sys [48640] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/08/20 21:24:52 A . (.Microsoft Corporation - Hid Parsing Library.) -- C:\WINDOWS\System32\drivers\hidparse.sys [46080] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/10/11 17:43:06 A . (.Microsoft Corporation - SPI HID Miniport Driver.) -- C:\WINDOWS\System32\drivers\hidspi.sys [64000] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/08/20 21:24:52 A . (.Microsoft Corporation - USB Miniport Driver for Input Devices.) -- C:\WINDOWS\System32\drivers\hidusb.sys [45568] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:39 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64528] =>.Microsoft Windows®
O58 - SDL:2020/04/18 00:31:18 A . (.Microsoft Corporation - HTTP Pile du protocole.) -- C:\WINDOWS\System32\drivers\http.sys [1300280] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:44 A . (.Microsoft Corporation - Hyper-V Crashdump.) -- C:\WINDOWS\System32\drivers\hvcrash.sys [32568] =>.Microsoft Windows®
O58 - SDL:2020/04/18 00:31:54 A . (.Microsoft Corporation - Hypervisor Boot Driver.) -- C:\WINDOWS\System32\drivers\hvservice.sys [84280] =>.Microsoft®
O58 - SDL:2019/03/19 06:45:54 A . (.Microsoft Corporation - Microsoft Hyper-V Socket Provider.) -- C:\WINDOWS\System32\drivers\hvsocket.sys [145208] =>.Microsoft Windows®
O58 - SDL:2020/04/18 00:31:19 A . (.Microsoft Corporation - Hardware Policy Driver.) -- C:\WINDOWS\System32\drivers\hwpolicy.sys [33080] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:44 A . (.Microsoft Corporation - Microsoft VMBus Synthetic Keyboard Driver.) -- C:\WINDOWS\System32\drivers\hyperkbd.sys [25400] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Microsoft VMBus Video Device Miniport Drive.) -- C:\WINDOWS\System32\drivers\HyperVideo.sys [42000] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Pilote de port i8042.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [119296] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:34 A . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iagpio.sys [36352] [Unsigned] =>.Intel(R) Corporation
O58 - SDL:2019/03/19 06:43:34 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\WINDOWS\System32\drivers\iai2c.sys [91136] [Unsigned] =>.Intel(R) Corporation
O58 - SDL:2019/03/19 06:43:34 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [79360] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 06:43:34 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [93184] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 06:43:34 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_CNL.sys [112128] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 06:43:34 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_GLK.sys [96256] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 06:43:34 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [171520] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 06:43:34 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [175104] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 06:43:34 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_CNL.sys [180736] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 06:43:34 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_GLK.sys [177664] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 06:43:38 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group®
O58 - SDL:2019/03/19 06:43:37 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [113152] [Unsigned] =>.Intel Corporation
O58 - SDL:2019/03/19 06:43:41 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAVC.sys [885048] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:41 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [411960] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:41 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [566800] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:16 A . (.Microsoft Corporation - Indirect displays kernel-mode filter driver.) -- C:\WINDOWS\System32\drivers\IndirectKmd.sys [46592] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:09:25 A . (.Microsoft Corporation - Intel PCI IDE Driver.) -- C:\WINDOWS\System32\drivers\intelide.sys [19984] =>.Microsoft®
O58 - SDL:2020/03/12 16:09:24 A . (.Microsoft Corporation - Intel Power Engine Plugin.) -- C:\WINDOWS\System32\drivers\intelpep.sys [355000] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:34 A . (.Microsoft Corporation - Intel Power Limit Driver.) -- C:\WINDOWS\System32\drivers\intelpmax.sys [28672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:09:24 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\WINDOWS\System32\drivers\intelppm.sys [224056] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:45 A . (.Microsoft Corporation - Filtre de contrôle de taux d’E/S.) -- C:\WINDOWS\System32\drivers\iorate.sys [56632] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:45:02 A . (.Microsoft Corporation - IP FILTER DRIVER.) -- C:\WINDOWS\System32\drivers\ipfltdrv.sys [90624] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - PILOT IPMI WMI.) -- C:\WINDOWS\System32\drivers\IPMIDrv.sys [110904] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:16 A . (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\ipnat.sys [224768] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:49 A . (.Microsoft Corporation - IPT Driver.) -- C:\WINDOWS\System32\drivers\ipt.sys [54584] =>.Microsoft Windows®
O58 - SDL:2019/08/20 21:24:51 A . (.Microsoft Corporation - Pilote de bus PNP ISA.) -- C:\WINDOWS\System32\drivers\isapnp.sys [23352] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:39 A . (.Avago Technologies - Avago SAS Gen3.5 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\ItSas35i.sys [148520] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Pilote de la classe Clavier.) -- C:\WINDOWS\System32\drivers\kbdclass.sys [70968] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Pilote de filtre clavier HID.) -- C:\WINDOWS\System32\drivers\kbdhid.sys [46592] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Microsoft Kernel Debugger Network Miniport.) -- C:\WINDOWS\System32\drivers\kdnic.sys [32568] =>.Microsoft Windows®
O58 - SDL:2020/05/18 16:31:33 A . (.Microsoft Corporation - Network Power Dependency Broker.) -- C:\WINDOWS\System32\drivers\KNetPwrDepBroker.sys [30720] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/08/20 21:26:23 A . (.Microsoft Corporation - Kernel CSA Library.) -- C:\WINDOWS\System32\drivers\ks.sys [455680] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/08/20 21:26:09 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\WINDOWS\System32\drivers\ksecdd.sys [146744] =>.Microsoft Windows®
O58 - SDL:2020/07/30 10:30:22 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\WINDOWS\System32\drivers\ksecpkg.sys [179512] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:52 A . (.Microsoft Corporation - Kernel Streaming WOW Thunk Service.) -- C:\WINDOWS\System32\drivers\ksthunk.sys [29184] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:48 A . (.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) -- C:\WINDOWS\System32\drivers\lltdio.sys [72192] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:39 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [109064] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [124448] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [128528] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82960] =>.Microsoft Windows®
O58 - SDL:2019/08/20 21:26:23 A . (.Microsoft Corporation - Pilote de filtre de virtualisation de fichi.) -- C:\WINDOWS\System32\drivers\luafv.sys [141312] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - MA-USB Host Controller Driver.) -- C:\WINDOWS\System32\drivers\mausbhost.sys [535864] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - MA-USB IP Driver.) -- C:\WINDOWS\System32\drivers\mausbip.sys [62264] =>.Microsoft Windows®
O58 - SDL:2019/11/17 02:35:16 A . (.Microsoft Corporation - Windows Mobile Broadband Class Extension.) -- C:\WINDOWS\System32\drivers\MbbCx.sys [359424] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:33 A . (.Microsoft Corporation - Medium changer class driver.) -- C:\WINDOWS\System32\drivers\mcd.sys [24576] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59920] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\MegaSas2i.sys [75280] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas35i.sys [94736] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [576016] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:33 A . (.Microsoft Corporation - Pilote de transport Microsoft Bluetooth Avr.) -- C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys [64512] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Legacy Bluetooth LE Bus Enumerator.) -- C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys [97280] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:41 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [1150480] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:47 A . (.Microsoft Corporation - MMCSS Driver.) -- C:\WINDOWS\System32\drivers\mmcss.sys [53760] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:45:53 A . (.Microsoft Corporation - Pilote de périphérique modem.) -- C:\WINDOWS\System32\drivers\modem.sys [46592] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:09:24 A . (.Microsoft Corporation - Monitor Driver.) -- C:\WINDOWS\System32\drivers\monitor.sys [69632] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Pilote de la classe Souris.) -- C:\WINDOWS\System32\drivers\mouclass.sys [66872] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Pilote de filtre souris HID.) -- C:\WINDOWS\System32\drivers\mouhid.sys [35840] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/17 02:37:27 A . (.Microsoft Corporation - Gestionnaire des points de montage.) -- C:\WINDOWS\System32\drivers\mountmgr.sys [113160] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:15 A . (.Microsoft Corporation - Microsoft Protection Service Driver.) -- C:\WINDOWS\System32\drivers\mpsdrv.sys [80384] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/10/11 17:45:24 A . (.Microsoft Corporation - Windows NT WebDav Minirdr.) -- C:\WINDOWS\System32\drivers\mrxdav.sys [158208] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/06/17 00:28:33 A . (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\WINDOWS\System32\drivers\mrxsmb.sys [561464] =>.Microsoft®
O58 - SDL:2020/03/12 16:10:21 A . (.Microsoft Corporation - Longhorn SMB 2.0 Redirector.) -- C:\WINDOWS\System32\drivers\mrxsmb20.sys [260920] =>.Microsoft®
O58 - SDL:2019/08/20 21:26:07 A . (.Microsoft Corporation - Mailslot driver.) -- C:\WINDOWS\System32\drivers\msfs.sys [43536] =>.Microsoft®
O58 - SDL:2019/10/01 21:53:51 A . (.Microsoft Corporation - GPIO Class Extension Driver.) -- C:\WINDOWS\System32\drivers\msgpioclx.sys [182288] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - GPIO Button Driver.) -- C:\WINDOWS\System32\drivers\msgpiowin32.sys [54072] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:16 A . (.Microsoft Corporation - Pass-through HID to KMDF Filter Driver.) -- C:\WINDOWS\System32\drivers\mshidkmdf.sys [8704] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:18 A . (.Microsoft Corporation - Pilote direct pour interface HID-UMDF.) -- C:\WINDOWS\System32\drivers\mshidumdf.sys [12288] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:16 A . (.Microsoft Corporation - Hardware Notification Class Extension Drive.) -- C:\WINDOWS\System32\drivers\mshwnclx.sys [28672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/08/20 21:24:51 A . (.Microsoft Corporation - ISA Driver.) -- C:\WINDOWS\System32\drivers\msisadrv.sys [19256] =>.Microsoft®
O58 - SDL:2019/11/17 02:35:14 A . (.Microsoft Corporation - Microsoft iSCSI Initiator Driver.) -- C:\WINDOWS\System32\drivers\msiscsi.sys [292664] =>.Microsoft®
O58 - SDL:2019/08/20 21:26:23 A . (.Microsoft Corporation - MS KS Server.) -- C:\WINDOWS\System32\drivers\mskssrv.sys [34816] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:45:00 A . (.Microsoft Corporation - Pilote de protocole LLDP (Link Layer Discov.) -- C:\WINDOWS\System32\drivers\mslldp.sys [78848] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:52 A . (.Microsoft Corporation - MS Proxy Clock.) -- C:\WINDOWS\System32\drivers\mspclock.sys [11264] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:52 A . (.Microsoft Corporation - MS Proxy Quality Manager.) -- C:\WINDOWS\System32\drivers\mspqm.sys [11264] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/17 02:37:29 A . (.Microsoft Corporation - Kernel Remote Procedure Call Provider.) -- C:\WINDOWS\System32\drivers\msrpc.sys [372752] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - System Management BIOS Driver.) -- C:\WINDOWS\System32\drivers\mssmbios.sys [48440] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:52 A . (.Microsoft Corporation - WDM Tee/Communication Transform Filter.) -- C:\WINDOWS\System32\drivers\mstee.sys [12800] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:39 A . (.Microsoft Corporation - Pilote HID multipoint Microsoft.) -- C:\WINDOWS\System32\drivers\MTConfig.sys [16384] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/08/20 21:26:11 A . (.Microsoft Corporation - Pilote de fournisseur UNC multiples.) -- C:\WINDOWS\System32\drivers\mup.sys [129848] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [64016] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:41 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [153616] =>.Microsoft Windows®
O58 - SDL:2020/03/12 16:10:11 A . (.Microsoft Corporation - NDIS (Network Driver Interface Specificatio.) -- C:\WINDOWS\System32\drivers\ndis.sys [1482040] =>.Microsoft®
O58 - SDL:2019/03/19 06:45:50 A . (.Microsoft Corporation - Microsoft NDIS Packet Capture Filter Driver.) -- C:\WINDOWS\System32\drivers\ndiscap.sys [56320] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:10:38 A . (.Microsoft Corporation - Microsoft Network Adapter Multiplexor.) -- C:\WINDOWS\System32\drivers\NdisImPlatform.sys [135168] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/10/11 17:44:34 A . (.Microsoft Corporation - NDIS 3.0 connection wrapper driver.) -- C:\WINDOWS\System32\drivers\ndistapi.sys [28672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:35 A . (.Microsoft Corporation - Pilote d’E/S du mode utilisateur NDIS.) -- C:\WINDOWS\System32\drivers\ndisuio.sys [70656] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:45:00 A . (.Microsoft Corporation - Énumérateur de cartes réseau virtuelles Mic.) -- C:\WINDOWS\System32\drivers\NdisVirtualBus.sys [22016] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:10:39 A . (.Microsoft Corporation - MS PPP Framing Driver (Strong Encryption).) -- C:\WINDOWS\System32\drivers\ndiswan.sys [206336] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:45:50 A . (.Microsoft Corporation - RDMA Sample Driver.) -- C:\WINDOWS\System32\drivers\NDKPing.sys [63488] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/10/11 17:44:34 A . (.Microsoft Corporation - NDIS Proxy.) -- C:\WINDOWS\System32\drivers\ndproxy.sys [244736] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:45:32 A . (.Microsoft Corporation - Windows Network Data Usage Monitoring Drive.) -- C:\WINDOWS\System32\drivers\Ndu.sys [132096] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:36 A . (.Microsoft Corporation - Network Adapter Class Extension for WDF.) -- C:\WINDOWS\System32\drivers\NetAdapterCx.sys [187904] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:58 A . (.Microsoft Corporation - NetBIOS interface driver.) -- C:\WINDOWS\System32\drivers\netbios.sys [64824] =>.Microsoft Windows®
O58 - SDL:2019/08/20 21:26:28 A . (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netbt.sys [337408] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/17 02:37:28 A . (.Microsoft Corporation - Network I/O Subsystem.) -- C:\WINDOWS\System32\drivers\netio.sys [586768] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:44 A . (.Microsoft Corporation - Miniport NDIS virtuel.) -- C:\WINDOWS\System32\drivers\netvsc.sys [246072] =>.Microsoft Windows®
O58 - SDL:2019/08/20 21:26:08 A . (.Microsoft Corporation - NPFS Driver.) -- C:\WINDOWS\System32\drivers\npfs.sys [87048] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Named pipe service triggers.) -- C:\WINDOWS\System32\drivers\npsvctrig.sys [27136] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/17 02:37:29 A . (.Microsoft Corporation - NSI Proxy.) -- C:\WINDOWS\System32\drivers\nsiproxy.sys [48128] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:10:10 A . (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2698040] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:53 A . (.Microsoft Corporation - NTOS extension host driver.) -- C:\WINDOWS\System32\drivers\ntosext.sys [20496] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:35 A . (.Microsoft Corporation - NULL Driver.) -- C:\WINDOWS\System32\drivers\null.sys [7680] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - Pilote de périphérique NVDIMM.) -- C:\WINDOWS\System32\drivers\nvdimm.sys [158520] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150544] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166408] =>.Microsoft Windows®
O58 - SDL:2019/10/11 17:43:12 A . (.Microsoft Corporation - Pilote de miniport WiFi natif.) -- C:\WINDOWS\System32\drivers\nwifi.sys [702464] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:15 A . (.Microsoft Corporation - Planificateur de paquets QoS.) -- C:\WINDOWS\System32\drivers\pacer.sys [160784] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - Pilote de port parallèle.) -- C:\WINDOWS\System32\drivers\parport.sys [108032] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/04/18 00:31:21 A . (.Microsoft Corporation - Partition driver.) -- C:\WINDOWS\System32\drivers\partmgr.sys [178192] =>.Microsoft®
O58 - SDL:2020/04/18 00:30:30 A . (.Microsoft Corporation - Énumérateur Plug-and-Play PCI pour NT.) -- C:\WINDOWS\System32\drivers\pci.sys [437560] =>.Microsoft®
O58 - SDL:2020/03/12 16:09:25 A . (.Microsoft Corporation - Generic PCI IDE Bus Driver.) -- C:\WINDOWS\System32\drivers\pciide.sys [16912] =>.Microsoft®
O58 - SDL:2020/03/12 16:09:25 A . (.Microsoft Corporation - PCI IDE Bus Driver Extension.) -- C:\WINDOWS\System32\drivers\pciidex.sys [56632] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:34 A . (.Microsoft Corporation - Pilote de bus PCMCIA.) -- C:\WINDOWS\System32\drivers\pcmcia.sys [127504] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:33 A . (.Microsoft Corporation - Performance Counters for Windows Driver.) -- C:\WINDOWS\System32\drivers\pcw.sys [58384] =>.Microsoft Windows®
O58 - SDL:2020/03/12 16:09:32 A . (.Microsoft Corporation - Power Dependency Coordinator Driver.) -- C:\WINDOWS\System32\drivers\pdc.sys [180232] =>.Microsoft®
O58 - SDL:2019/08/20 21:24:59 A . (.Microsoft Corporation - Protected Environment Authentication and Au.) -- C:\WINDOWS\System32\drivers\PEAuth.sys [817152] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58896] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [68624] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:45:50 A . (.Microsoft Corporation - Pilote du moniteur de paquets.) -- C:\WINDOWS\System32\drivers\PktMon.sys [96056] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - Pilote de mémoire persistante.) -- C:\WINDOWS\System32\drivers\pmem.sys [127800] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:38 A . (.Microsoft Corporation - Pilote mémoire Plug and Play.) -- C:\WINDOWS\System32\drivers\pnpmem.sys [17408] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:18 A . (.Microsoft Corporation - Port Device Class Configuration Filter Driv.) -- C:\WINDOWS\System32\drivers\portcfg.sys [25600] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:37 A . (.Microsoft Corporation - Port Class (Class Driver for Port/Miniport.) -- C:\WINDOWS\System32\drivers\portcls.sys [390656] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:09:24 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\WINDOWS\System32\drivers\processr.sys [208696] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:15 A . (.Microsoft Corporation - Process Launch Monitor driver.) -- C:\WINDOWS\System32\drivers\ProcLaunchMon.sys [36248] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:45:00 A . (.Microsoft Corporation - Pilote du support de Microsoft Quality Wind.) -- C:\WINDOWS\System32\drivers\qwavedrv.sys [53760] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:49 A . (.Microsoft Corporation - RAM Disk Driver.) -- C:\WINDOWS\System32\drivers\ramdisk.sys [41784] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:45:02 A . (.Microsoft Corporation - RAS Automatic Connection Driver.) -- C:\WINDOWS\System32\drivers\rasacd.sys [19968] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:45:02 A . (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\rasl2tp.sys [112128] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:45:02 A . (.Microsoft Corporation - RAS PPPoE mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\raspppoe.sys [87552] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:45:02 A . (.Microsoft Corporation - Peer-to-Peer Tunneling Protocol.) -- C:\WINDOWS\System32\drivers\raspptp.sys [103424] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:45:02 A . (.Microsoft Corporation - RAS SSTP Miniport Call Manager.) -- C:\WINDOWS\System32\drivers\rassstp.sys [85504] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/04/18 00:31:22 A . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) -- C:\WINDOWS\System32\drivers\rdbss.sys [456504] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Microsoft RDP Bus Device driver.) -- C:\WINDOWS\System32\drivers\rdpbus.sys [28672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/08/20 21:27:13 A . (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [167936] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:11:19 A . (.Microsoft Corporation - Microsoft RDP Video Miniport driver.) -- C:\WINDOWS\System32\drivers\rdpvideominiport.sys [32056] =>.Microsoft®
O58 - SDL:2019/03/19 06:45:56 A . (.Microsoft Corporation - ReadyBoost Driver.) -- C:\WINDOWS\System32\drivers\rdyboost.sys [294928] =>.Microsoft Windows®
O58 - SDL:2020/03/12 16:10:00 A . (.Microsoft Corporation - Pilote du système de fichiers ReFS NT.) -- C:\WINDOWS\System32\drivers\refs.sys [1972536] =>.Microsoft®
O58 - SDL:2019/12/13 21:19:08 A . (.Microsoft Corporation - Pilote du système de fichiers ReFS NT.) -- C:\WINDOWS\System32\drivers\refsv1.sys [986936] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Bluetooth RFCOMM Driver.) -- C:\WINDOWS\System32\drivers\rfcomm.sys [211456] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:44 A . (.Microsoft Corporation - Transport d’ordinateur virtuel Microsoft Re.) -- C:\WINDOWS\System32\drivers\RfxVmt.sys [41472] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:38 A . (.Microsoft Corporation - ResourceHub Proxy Driver.) -- C:\WINDOWS\System32\drivers\rhproxy.sys [113152] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:45:43 A . (.Microsoft Corporation - Reliable Multicast Transport.) -- C:\WINDOWS\System32\drivers\rmcast.sys [159232] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:45:02 A . (.Microsoft Corporation - Remote NDIS Miniport.) -- C:\WINDOWS\System32\drivers\RNDISMP.sys [37376] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:45:53 A . (.Microsoft Corporation - Legacy Non-Pnp Modem Device Driver.) -- C:\WINDOWS\System32\drivers\rootmdm.sys [13824] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:48 A . (.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) -- C:\WINDOWS\System32\drivers\rspndr.sys [89088] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2015/07/15 03:57:56 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.40 64-bit Dr.) -- C:\WINDOWS\System32\drivers\rt640x64.sys [887552] =>.Realtek Semiconductor Corp®
O58 - SDL:2019/03/19 06:43:49 RA . (.Realtek - Realtek PCIe GBE Family Controller Flight.) -- C:\WINDOWS\System32\drivers\rteth.sys [57856] [Unsigned] =>.Realtek
O58 - SDL:2019/03/19 06:43:39 A . (.Microsoft Corporation - SBP-2 Protocol Driver.) -- C:\WINDOWS\System32\drivers\sbp2port.sys [117288] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:30 A . (.Microsoft Corporation - Pilote de filtre de lecteur de carte à puce.) -- C:\WINDOWS\System32\drivers\scfilter.sys [45056] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/04/18 00:30:30 A . (.Microsoft Corporation - Pilote de bus de mémoire de classe stockage.) -- C:\WINDOWS\System32\drivers\scmbus.sys [151352] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:33 A . (.Microsoft Corporation - SCSI Port Driver.) -- C:\WINDOWS\System32\drivers\scsiport.sys [187408] =>.Microsoft Windows®
O58 - SDL:2020/04/18 00:30:31 A . (.Microsoft Corporation - Pilote du bus numérique sécurisé (SD).) -- C:\WINDOWS\System32\drivers\sdbus.sys [297272] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:38 A . (.Microsoft Corporation - SDF Reflector.) -- C:\WINDOWS\System32\drivers\SDFRd.sys [33592] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:49 A . (.Microsoft Corporation - SD Host Controller Port Driver.) -- C:\WINDOWS\System32\drivers\sdport.sys [105784] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Pilote de classe de stockage SD.) -- C:\WINDOWS\System32\drivers\sdstor.sys [103736] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:18 A . (.Microsoft Corporation - Serial Class Extension.) -- C:\WINDOWS\System32\drivers\SerCx.sys [84792] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:18 A . (.Microsoft Corporation - Serial Class Extension V2.) -- C:\WINDOWS\System32\drivers\SerCx2.sys [170808] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - Serial Port Enumerator.) -- C:\WINDOWS\System32\drivers\serenum.sys [27648] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - Pilote de périphérique série.) -- C:\WINDOWS\System32\drivers\serial.sys [89600] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\WINDOWS\System32\drivers\sermouse.sys [29696] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/04/18 00:30:30 A . (.Microsoft Corporation - SCSI Floppy Driver.) -- C:\WINDOWS\System32\drivers\sfloppy.sys [18944] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:45:32 A . (.Microsoft Corporation - System Guard Runtime Monitor Agent Driver.) -- C:\WINDOWS\System32\drivers\SgrmAgent.sys [89096] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [45072] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81936] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:36 A . (.Microsoft Corporation - Sleep Study Helper.) -- C:\WINDOWS\System32\drivers\SleepStudyHelper.sys [38200] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:39 A . (.Microsemi Corportation - Storport Miniport Driver for SmartRAID/Smar.) -- C:\WINDOWS\System32\drivers\SmartSAMD.sys [220176] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:30 A . (.Microsoft Corporation - Smart Card Driver Library.) -- C:\WINDOWS\System32\drivers\smclib.sys [21504] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/07/30 10:28:39 A . (.Microsoft Corporation - Storage Spaces Dump Driver.) -- C:\WINDOWS\System32\drivers\spacedump.sys [204608] =>.Microsoft®
O58 - SDL:2020/07/30 10:28:39 A . (.Microsoft Corporation - Storage Spaces Driver.) -- C:\WINDOWS\System32\drivers\spaceport.sys [656696] =>.Microsoft®
O58 - SDL:2019/03/19 14:02:50 A . (.Microsoft Corporation - Holographic Spatial Graph Filter.) -- C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [76088] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:18 A . (.Microsoft Corporation - SPB Class Extension.) -- C:\WINDOWS\System32\drivers\SpbCx.sys [85816] =>.Microsoft Windows®
O58 - SDL:2020/04/18 00:31:23 A . (.Microsoft Corporation - Pilote de serveur SMB 2.0.) -- C:\WINDOWS\System32\drivers\srv2.sys [772096] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/06/17 00:28:33 A . (.Microsoft Corporation - Server Network driver.) -- C:\WINDOWS\System32\drivers\srvnet.sys [309248] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2017/05/18 23:17:28 A . (.Samsung Electronics Co., Ltd. - SAMSUNG USB Composite Device Driver.) -- C:\WINDOWS\System32\drivers\ssudbus.sys [131984] =>.Samsung Electronics Co., Ltd.®
O58 - SDL:2017/05/18 23:17:30 A . (.Samsung Electronics Co., Ltd. - SAMSUNG Android Modem Device Driver.) -- C:\WINDOWS\System32\drivers\ssudmdm.sys [166288] =>.Samsung Electronics Co., Ltd.®
O58 - SDL:2019/03/19 06:43:39 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31240] =>.Microsoft Windows®
O58 - SDL:2020/03/12 16:09:25 A . (.Microsoft Corporation - MS AHCI Storport Miniport Driver.) -- C:\WINDOWS\System32\drivers\storahci.sys [174392] =>.Microsoft®
O58 - SDL:2020/03/12 16:09:25 A . (.Microsoft Corporation - Microsoft NVM Express Storport Miniport Dri.) -- C:\WINDOWS\System32\drivers\stornvme.sys [141840] =>.Microsoft®
O58 - SDL:2020/05/18 16:31:45 A . (.Microsoft Corporation - Microsoft Storage Port Driver.) -- C:\WINDOWS\System32\drivers\storport.sys [637480] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:18 A . (.Microsoft Corporation - Filtre de qualité de service de stockage.) -- C:\WINDOWS\System32\drivers\storqosflt.sys [93200] =>.Microsoft Windows®
O58 - SDL:2020/05/18 16:31:27 A . (.Microsoft Corporation - MS UFS Storport Miniport Driver.) -- C:\WINDOWS\System32\drivers\storufs.sys [59192] =>.Microsoft®
O58 - SDL:2019/10/11 17:43:07 A . (.Microsoft Corporation - Storage VSC Driver.) -- C:\WINDOWS\System32\drivers\storvsc.sys [43536] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:33 A . (.Microsoft Corporation - WDM CODEC Class Device Driver 2.0.) -- C:\WINDOWS\System32\drivers\stream.sys [82432] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:44 A . (.Microsoft Corporation - VSC vidéo Synth3D RemoteFX Microsoft.) -- C:\WINDOWS\System32\drivers\Synth3dVsc.sys [66560] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:33 A . (.Microsoft Corporation - SCSI Tape Class Driver.) -- C:\WINDOWS\System32\drivers\tape.sys [33280] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:09:34 A . (.Microsoft Corporation - Export driver for kernel mode TPM API.) -- C:\WINDOWS\System32\drivers\tbs.sys [29712] =>.Microsoft®
O58 - SDL:2020/05/18 16:35:24 A . (.Microsoft Corporation - Pilote TCP/IP.) -- C:\WINDOWS\System32\drivers\tcpip.sys [2986808] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:58 A . (.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) -- C:\WINDOWS\System32\drivers\tcpipreg.sys [54784] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:36 A . (.Microsoft Corporation - TDI Wrapper.) -- C:\WINDOWS\System32\drivers\tdi.sys [39440] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:45:32 A . (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [132616] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Terminal Server Input Driver.) -- C:\WINDOWS\System32\drivers\terminpt.sys [41488] =>.Microsoft Windows®
O58 - SDL:2019/10/01 21:54:54 A . (.Microsoft Corporation - Kernel Transaction Manager Driver.) -- C:\WINDOWS\System32\drivers\tm.sys [141840] =>.Microsoft®
O58 - SDL:2020/05/18 16:31:28 A . (.Microsoft Corporation - Pilote de périphérique TPM.) -- C:\WINDOWS\System32\drivers\tpm.sys [250696] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:49 A . (.Microsoft Corporation - Pilote de filtre pour concentrateur USB du.) -- C:\WINDOWS\System32\drivers\TsUsbFlt.sys [65024] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/18 16:31:26 A . (.Microsoft Corporation - Remote Desktop Generic USB Driver.) -- C:\WINDOWS\System32\drivers\TsUsbGD.sys [35328] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/17 02:39:21 A . (.Microsoft Corporation - Pilote d’interface de tunnel Microsoft.) -- C:\WINDOWS\System32\drivers\tunnel.sys [128512] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/10/11 17:43:06 A . (.Microsoft Corporation - Microsoft Uasp Driver.) -- C:\WINDOWS\System32\drivers\uaspstor.sys [79376] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:18 A . (.Microsoft Corporation - USB Connector Manager KMDF Class Extension.) -- C:\WINDOWS\System32\drivers\UcmCx.sys [160256] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:18 A . (.Microsoft Corporation - UCM-TCPCI KMDF Class Extension.) -- C:\WINDOWS\System32\drivers\UcmTcpciCx.sys [186368] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - UCM-UCSI ACPI Client Driver.) -- C:\WINDOWS\System32\drivers\UcmUcsiAcpiClient.sys [34816] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:18 A . (.Microsoft Corporation - UCM-UCSI KMDF Class Extension.) -- C:\WINDOWS\System32\drivers\UcmUcsiCx.sys [111104] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:49 A . (.Microsoft Corporation - USB Controller Extension.) -- C:\WINDOWS\System32\drivers\Ucx01000.sys [244024] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:49 A . (.Microsoft Corporation - "udecx.DRIVER".) -- C:\WINDOWS\System32\drivers\Udecx.sys [51200] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/12/13 21:19:37 A . (.Microsoft Corporation - UDF File System Driver.) -- C:\WINDOWS\System32\drivers\udfs.sys [342528] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:18 A . (.Microsoft Corporation - USB Function Driver Class Extension.) -- C:\WINDOWS\System32\drivers\ufx01000.sys [311096] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - UFX Synopsys Client Driver.) -- C:\WINDOWS\System32\drivers\ufxsynopsys.sys [181048] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Generic pass-through driver.) -- C:\WINDOWS\System32\drivers\umpass.sys [13312] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:18 A . (.Microsoft Corporation - USB Role-Switch Class Extension.) -- C:\WINDOWS\System32\drivers\urscx01000.sys [74552] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:45:02 A . (.Microsoft Corporation - Remote NDIS USB Driver.) -- C:\WINDOWS\System32\drivers\usb8023.sys [24576] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:37 A . (.Microsoft Corporation - USB Audio Class Driver.) -- C:\WINDOWS\System32\drivers\USBAUDIO.sys [198656] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/08/20 21:24:50 A . (.Microsoft Corporation - Microsoft USB Audio Class 2.0 Driver.) -- C:\WINDOWS\System32\drivers\usbaudio2.sys [257536] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:38 A . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\WINDOWS\System32\drivers\USBCAMD2.sys [39936] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:09:25 A . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) -- C:\WINDOWS\System32\drivers\usbccgp.sys [183608] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:37 A . (.Microsoft Corporation - USB Consumer IR Driver for eHome.) -- C:\WINDOWS\System32\drivers\usbcir.sys [107008] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Universal Serial Bus Driver.) -- C:\WINDOWS\System32\drivers\usbd.sys [33592] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - EHCI eUSB Miniport Driver.) -- C:\WINDOWS\System32\drivers\usbehci.sys [100664] =>.Microsoft Windows®
O58 - SDL:2016/08/13 07:51:02 A . (.Advanced Micro Devices, Inc - AMD USB Filter Driver.) -- C:\WINDOWS\System32\drivers\usbfilter.sys [65080] =>.Advanced Micro Devices, Inc.®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Pilote de concentrateur USB par défaut.) -- C:\WINDOWS\System32\drivers\usbhub.sys [545592] =>.Microsoft Windows®
O58 - SDL:2020/05/18 16:31:27 A . (.Microsoft Corporation - Pilote de concentrateur USB3.) -- C:\WINDOWS\System32\drivers\USBHUB3.SYS [634680] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - OHCI USB Miniport Driver.) -- C:\WINDOWS\System32\drivers\usbohci.sys [30208] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/10/11 17:43:35 A . (...) -- C:\WINDOWS\System32\drivers\UsbPmApi.sys [53248] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Pilote de port USB 1.1 & 2.0.) -- C:\WINDOWS\System32\drivers\usbport.sys [475144] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:37 A . (.Microsoft Corporation - USB Printer driver.) -- C:\WINDOWS\System32\drivers\usbprint.sys [34304] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/01/18 01:37:23 A . (.Microsoft Corporation - USB Scanner Driver.) -- C:\WINDOWS\System32\drivers\usbscan.sys [49152] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - USB Serial Driver.) -- C:\WINDOWS\System32\drivers\usbser.sys [79360] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Pilote de classe de stockage de masse USB.) -- C:\WINDOWS\System32\drivers\USBSTOR.SYS [134968] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - UHCI USB Miniport Driver.) -- C:\WINDOWS\System32\drivers\usbuhci.sys [39936] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/05/18 16:31:26 A . (.Microsoft Corporation - USB Video Class Driver.) -- C:\WINDOWS\System32\drivers\usbvideo.sys [306496] =>.Microsoft®
O58 - SDL:2020/06/17 00:28:04 A . (.Microsoft Corporation - Pilote XHCI USB.) -- C:\WINDOWS\System32\drivers\USBXHCI.SYS [531768] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - Virtual Drive Root Enumerator.) -- C:\WINDOWS\System32\drivers\vdrvroot.sys [60216] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:35 A . (.Microsoft Corporation - Extension du vérificateur de pilotes.) -- C:\WINDOWS\System32\drivers\VerifierExt.sys [321040] =>.Microsoft Windows®
O58 - SDL:2020/02/13 01:38:42 A . (.Microsoft Corporation - VHD Miniport Driver.) -- C:\WINDOWS\System32\drivers\vhdmp.sys [804872] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - Virtual HID Framework (VHF) Driver.) -- C:\WINDOWS\System32\drivers\vhf.sys [39936] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/11/17 02:35:14 A . (.Microsoft Corporation - Microsoft Hyper-V Virtualization Infrastruc.) -- C:\WINDOWS\System32\drivers\Vid.sys [551736] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:38 A . (.Microsoft Corporation - Video Port Driver.) -- C:\WINDOWS\System32\drivers\videoprt.sys [47104] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/10/11 17:45:24 A . (.Microsoft Corporation - Hyper-V VMBus KMCL.) -- C:\WINDOWS\System32\drivers\vmbkmcl.sys [100664] =>.Microsoft®
O58 - SDL:2020/03/12 16:09:26 A . (.Microsoft Corporation - Pilote enfant de bus VMBus sous Microsoft H.) -- C:\WINDOWS\System32\drivers\vmbus.sys [151568] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Microsoft VMBus HID Miniport.) -- C:\WINDOWS\System32\drivers\VMBusHID.sys [36152] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Virtual Machine Generation Counter.) -- C:\WINDOWS\System32\drivers\vmgencounter.sys [22328] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:44 A . (.Microsoft Corporation - Virtual Machine Guest Infrastructure Driver.) -- C:\WINDOWS\System32\drivers\vmgid.sys [18232] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Microsoft S3 Emulated Device Cap Driver.) -- C:\WINDOWS\System32\drivers\vms3cap.sys [17208] =>.Microsoft Windows®
O58 - SDL:2019/10/11 17:43:07 A . (.Microsoft Corporation - Pilote de filtre de stockage virtuel.) -- C:\WINDOWS\System32\drivers\vmstorfl.sys [52752] =>.Microsoft®
O58 - SDL:2020/04/18 00:30:30 A . (.Microsoft Corporation - Pilote du gestionnaire de volumes.) -- C:\WINDOWS\System32\drivers\volmgr.sys [89912] =>.Microsoft®
O58 - SDL:2019/03/19 06:45:38 A . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volum.) -- C:\WINDOWS\System32\drivers\volmgrx.sys [388112] =>.Microsoft Windows®
O58 - SDL:2020/03/12 16:09:36 A . (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\WINDOWS\System32\drivers\volsnap.sys [429880] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:39 A . (.Microsoft Corporation - Volume driver.) -- C:\WINDOWS\System32\drivers\volume.sys [16696] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:44 A . (.Microsoft Corporation - Virtual PCI Bus.) -- C:\WINDOWS\System32\drivers\vpci.sys [83768] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:40 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166928] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:40 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305672] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:55 A . (.Microsoft Corporation - Virtual Wireless Bus Driver.) -- C:\WINDOWS\System32\drivers\vwifibus.sys [27648] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:55 A . (.Microsoft Corporation - Virtual WiFi Filter Driver.) -- C:\WINDOWS\System32\drivers\vwififlt.sys [77312] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:55 A . (.Microsoft Corporation - Virtual WiFi Miniport Driver.) -- C:\WINDOWS\System32\drivers\vwifimp.sys [50176] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:39 A . (.Microsoft Corporation - Pilote de tablette Wacom à stylet série.) -- C:\WINDOWS\System32\drivers\wacompen.sys [31744] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/10/11 17:44:34 A . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) -- C:\WINDOWS\System32\drivers\wanarp.sys [92672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:06 A . (.Microsoft Corporation - Watchdog Driver.) -- C:\WINDOWS\System32\drivers\watchdog.sys [66048] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/03/12 16:09:55 A . (.Microsoft Corporation - Windows Container Isolation FS Filter Drive.) -- C:\WINDOWS\System32\drivers\wcifs.sys [201744] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:16 A . (.Microsoft Corporation - Windows Container Name Virtualization FS Fi.) -- C:\WINDOWS\System32\drivers\wcnfs.sys [92672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:57 A . (.Microsoft Corporation - Microsoft antimalware boot driver.) -- C:\WINDOWS\System32\drivers\WdBoot.sys [46472] =>.Microsoft®
O58 - SDL:2020/05/18 16:35:21 A . (.Microsoft Corporation - Runtime de l’infrastructure de pilotes en m.) -- C:\WINDOWS\System32\drivers\Wdf01000.sys [847168] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:57 A . (.Microsoft Corporation - Microsoft antimalware file system filter dr.) -- C:\WINDOWS\System32\drivers\WdFilter.sys [333784] =>.Microsoft®
O58 - SDL:2020/05/18 16:35:21 A . (.Microsoft Corporation - Kernel Mode Driver Framework Loader.) -- C:\WINDOWS\System32\drivers\WdfLdr.sys [58696] =>.Microsoft®
O58 - SDL:2019/10/11 17:43:12 A . (.Microsoft Corporation - WDI Driver Framework Driver.) -- C:\WINDOWS\System32\drivers\WdiWiFi.sys [931840] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:21 A . (.Microsoft Corporation - WDM Companion Filter.) -- C:\WINDOWS\System32\drivers\WdmCompanionFilter.sys [21816] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:57 A . (.Microsoft Corporation - Windows Defender Network Stream Filter.) -- C:\WINDOWS\System32\drivers\WdNisDrv.sys [62432] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:35 A . (.Microsoft Corporation - Windows Error Reporting Kernel Driver.) -- C:\WINDOWS\System32\drivers\werkernel.sys [50488] =>.Microsoft Windows®
O58 - SDL:2019/08/20 21:25:32 A . (.Microsoft Corporation - WFP NDIS 6.30 Lightweight Filter Driver.) -- C:\WINDOWS\System32\drivers\wfplwfs.sys [180536] =>.Microsoft Windows®
O58 - SDL:2020/02/13 01:39:18 A . (.Microsoft Corporation - Wim file system Driver.) -- C:\WINDOWS\System32\drivers\wimmount.sys [37392] =>.Microsoft®
O58 - SDL:2019/03/19 06:44:18 A . (.Microsoft Corporation - Windows Trusted Runtime Interface Driver.) -- C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [75752] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Windows Trusted Runtime Service Proxy Drive.) -- C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [17896] =>.Microsoft®
O58 - SDL:2019/03/19 06:45:54 A . (.Microsoft Corporation - Windows Hypervisor Interface Driver.) -- C:\WINDOWS\System32\drivers\winhv.sys [32568] =>.Microsoft Windows®
O58 - SDL:2019/11/17 02:41:13 A . (.Microsoft Corporation - Windows Hypervisor Root Interface Driver.) -- C:\WINDOWS\System32\drivers\winhvr.sys [84488] =>.Microsoft®
O58 - SDL:2019/03/19 06:43:41 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [37928] =>.Microsoft Windows®
O58 - SDL:2020/05/18 16:31:45 A . (.Microsoft Corporation - Pilote NAT Windows.) -- C:\WINDOWS\System32\drivers\winnat.sys [251392] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/08/20 21:26:00 A . (.Microsoft Corporation - Windows QUIC Driver.) -- C:\WINDOWS\System32\drivers\winquic.sys [205112] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:43 A . (.Microsoft Corporation - Windows WinUSB Class Driver.) -- C:\WINDOWS\System32\drivers\winusb.sys [105472] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:41 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [77832] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:43:41 A . (.Microsoft Corporation - Windows Management Interface for ACPI.) -- C:\WINDOWS\System32\drivers\wmiacpi.sys [19456] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:36 A . (.Microsoft Corporation - WMILIB WMI support library Dll.) -- C:\WINDOWS\System32\drivers\wmilib.sys [20496] =>.Microsoft Windows®
O58 - SDL:2019/10/11 17:43:51 A . (.Microsoft Corporation - Filtre de superposition Windows.) -- C:\WINDOWS\System32\drivers\wof.sys [225080] =>.Microsoft®
O58 - SDL:2019/03/19 14:02:52 A . (.Microsoft Corporation - Windows Portable Device Upper Class Filter.) -- C:\WINDOWS\System32\drivers\WpdUpFltr.sys [31248] =>.Microsoft Windows®
O58 - SDL:2019/03/19 06:44:36 A . (.Microsoft Corporation - WPP Trace Recorder.) -- C:\WINDOWS\System32\drivers\WppRecorder.sys [39976] =>.Microsoft Windows®
O58 - SDL:2019/10/01 21:54:54 A . (.Microsoft Corporation - Couche IFS Winsock2.) -- C:\WINDOWS\System32\drivers\ws2ifsl.sys [25088] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:37 A . (.Microsoft Corporation - Web Services Print Device Driver.) -- C:\WINDOWS\System32\drivers\WSDPrint.sys [24576] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/01/18 01:37:23 A . (.Microsoft Corporation - Web Service Based Scan Device Driver.) -- C:\WINDOWS\System32\drivers\WSDScan.sys [26112] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:53 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\WINDOWS\System32\drivers\WUDFPf.sys [134656] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:53 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\WINDOWS\System32\drivers\WUDFRd.sys [297984] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/08/20 21:24:49 A . (.Microsoft Corporation - Game Input Protocol Driver.) -- C:\WINDOWS\System32\drivers\xboxgip.sys [324608] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:43:33 A . (.Microsoft Corporation - XINPUT filter driver for HID.) -- C:\WINDOWS\System32\drivers\xinputhid.sys [48128] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2015/08/14 05:03:34 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\athw10x.sys [4322440] [Unsigned] =>.Qualcomm Atheros Communications, Inc.
O58 - SDL:2020/07/30 10:30:03 A . (.Microsoft Corporation - Full/Desktop Multi-User Win32 Driver.) -- C:\WINDOWS\System32\win32k.sys [550400] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/07/30 10:29:31 A . (.Microsoft Corporation - Pilote du noyau Base Win32k.) -- C:\WINDOWS\System32\win32kbase.sys [2716672] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/07/30 10:30:03 A . (.Microsoft Corporation - Full/Desktop Win32k Kernel Driver.) -- C:\WINDOWS\System32\win32kfull.sys [3727360] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2019/03/19 06:44:15 A . (.Microsoft Corporation - Win32k non session driver.) -- C:\WINDOWS\System32\win32kns.sys [30208] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2010/12/03 14:22:54 A . (.OpenLibSys.org - MemDriver.) -- C:\WINDOWS\SysWOW64\MemDriverx64.sys [12928] =>.ASUSTeK Computer Inc.®
O58 - SDL:2020/07/30 10:32:04 A . (.Microsoft Corporation - Full/Desktop Multi-User Win32 Driver.) -- C:\WINDOWS\SysWOW64\win32k.sys [324096] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2020/07/30 10:32:04 A . (.Microsoft Corporation - Full/Desktop Win32k Kernel Driver.) -- C:\WINDOWS\SysWOW64\win32kfull.sys [2799104] [Unsigned] =>.Microsoft Corporation
O58 - SDL:2007/12/15 17:38:46 A . (.OpenLibSys.org - WinRing0.) -- C:\WINDOWS\SysWOW64\WinRing0.sys [14672] =>.Noriyuki MIYAZAKI®

---\\ ASSOCIATION Shell Spawning (10) - 2s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe [Unsigned] =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe [Unsigned] =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft®
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- C:\Windows\System32\WScript.exe "%1" %* =>.Default.Value
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe [Unsigned] =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S =>.Default.Value

---\\ MENU DE DÉMARRAGE INTERNET (16) - 2s
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Piriform Software - CCleaner Browser.) -- C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe =>.Piriform Software Ltd®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft®
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Piriform Software - CCleaner Browser.) -- C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe =>.Piriform Software
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Show IE Icon Utility.) -- C:\WINDOWS\System32\ie4ushowIE.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Piriform Software - CCleaner Browser.) -- C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe =>.Piriform Software
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Piriform Software - CCleaner Browser.) -- C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe =>.Piriform Software
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Show IE Icon Utility.) -- C:\WINDOWS\System32\ie4ushowIE.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation

---\\ RECHERCHE D'INFECTION SUR NAVIGATEURS (5) - 11s
O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Web Search (Yahoo! Provided)) - http://fr.search.yahoo.com/ =>.Yahoo! Inc.
O69 - SBI: SearchScopes [HKCU] [64Bits]{26080cad-4adc-49ac-8c63-eda16e595cbd} - (Search Provided by Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKCU] [64Bits]{e5badea7-e1c2-fbf1-87ac-061d1440d15b} - (Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Web Search (Yahoo! Provided)) - http://fr.search.yahoo.com/ =>.Yahoo! Inc.
O69 - SBI: SearchScopes [HKLM] [64Bits]{e5badea7-e1c2-fbf1-87ac-061d1440d15b} - (Bing) - http://www.bing.com/ =>.Bing.com

---\\ ÉNUMÈRE LES SERVICES DÉMARRÉS PAR Svchost (49) - 8s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [192512] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [192512] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [280064] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [1261568] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [1042944] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [832000] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [31232] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [151040] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [110080] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [858112] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [231424] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [490496] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [483328] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [124928] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: PushToInstall (PushToInstall) . (.Microsoft Corporation - PushToInstall.) -- C:\Windows\System32\PushToInstall.dll [269824] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: InstallService (InstallService) . (.Microsoft Corporation - InstallService.) -- C:\Windows\System32\InstallService.dll [2467840] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: TroubleshootingSvc (TroubleshootingSvc) . (.Microsoft Corporation - MitigationClient.) -- C:\Windows\System32\MitigationClient.dll [394752] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: LxpSvc (LxpSvc) . (.Microsoft Corporation - Fournit une prise en charge de l'infrastruc.) -- C:\Windows\System32\LanguageOverlayServer.dll [317952] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\Windows\System32\Windows.SharedPC.AccountManager.dll [239104] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\Windows\System32\XblGameSave.dll [1263616] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL Windows Management Service.) -- C:\Windows\System32\Windows.Internal.Management.dll [931840] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [67072] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: WManSvc (WManSvc) . (.Microsoft Corporation - DLL du Service de gestion de Windows.) -- C:\Windows\System32\Windows.Management.Service.dll [922624] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: TokenBroker (TokenBroker) . (.Microsoft Corporation - Broker à jetons.) -- C:\Windows\System32\TokenBroker.dll [1500160] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service de géolocalisation.) -- C:\Windows\System32\lfsvc.dll [47104] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [104448] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\Windows\System32\rasmans.dll [912896] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [500224] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [73728] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [629760] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [309248] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [3109376] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [1583104] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [252928] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\Windows\System32\dmwappushsvc.dll [58368] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Paramètres de vol.) -- C:\Windows\System32\flightsettings.dll [893952] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Service Configuration du réseau.) -- C:\Windows\System32\NetSetupSvc.dll [336896] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Service du système de notifications Push Wi.) -- C:\Windows\System32\WpnService.dll [263168] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\Windows\System32\XboxNetApiSvc.dll [1268224] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Mettre à jour la session du service Orchest.) -- C:\Windows\System32\usosvc.dll [544256] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\Windows\System32\usermgr.dll [1284608] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\Windows\System32\DeviceSetupManager.dll [265728] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\Windows\System32\wlidsvc.dll [2157056] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxGipSvc (XboxGipSvc) . (.Microsoft Corporation - Xbox Gip Management Service.) -- C:\Windows\System32\XboxGipSvc.dll [72704] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\Windows\System32\NcaSvc.dll [170496] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [182272] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\Windows\System32\XblAuthManager.dll [1063936] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: NaturalAuthentication (NaturalAuthentication) . (.Microsoft Corporation - Service d’authentification naturelle.) -- C:\Windows\System32\NaturalAuth.dll [831488] [Unsigned] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [526336] [Unsigned] =>.Microsoft Corporation

---\\ LISTE DES EXCEPTIONS PAREFEU WINDOWS (12) - 17s
O87 - FAEL: "{90839865-C252-423B-9462-8FF039173977}" [In-None-P6-TRUE] .(.TeamViewer GmbH - TeamViewer 11.) -- C:\Program Files (x86)\TeamViewer\TeamViewer.exe =>.TeamViewer®
O87 - FAEL: "{330795B2-535F-4A6E-81A3-514B70F3AFF1}" [In-None-P17-TRUE] .(.TeamViewer GmbH - TeamViewer 11.) -- C:\Program Files (x86)\TeamViewer\TeamViewer.exe =>.TeamViewer®
O87 - FAEL: "{8354D7DE-F9E7-4178-8ADB-B3D4A7529C8D}" [In-None-P6-TRUE] .(.TeamViewer GmbH - TeamViewer 11.) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer®
O87 - FAEL: "{B181FC74-6B2B-43A3-8C9F-5D26C2088844}" [In-None-P17-TRUE] .(.TeamViewer GmbH - TeamViewer 11.) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer®
O87 - FAEL: "{6004CE6B-BE40-420D-ABA8-B0D6B840FD87}" [In-None-P17-TRUE] .(.Zhuhai Kingsoft Office Software Co.,Ltd - WPS Office service program for service such.) -- C:\Program Files (x86)\Kingsoft\WPS Office\10.2.0.7646\office6\wpscloudsvr.exe =>.Zhuhai Kingsoft Office Software Co., Ltd.®
O87 - FAEL: "{FF0523ED-8614-4CB5-8A77-E0A7F7633E6C}" [In-None-P17-TRUE] .(.Zoom Video Communications, Inc. - Zoom Meetings.) -- C:\Users\melvi\AppData\Roaming\Zoom\bin\Zoom.exe =>.Zoom Video Communications, Inc.®
O87 - FAEL: "{3329F37E-44EF-49F6-A570-30B6C9ADD246}" [In-None-P6-TRUE] .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe =>.Skype Software Sarl®
O87 - FAEL: "{9510CB95-E285-4FAD-AC62-965EA8DC238B}" [Out-None-P6-TRUE] .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe =>.Skype Software Sarl®
O87 - FAEL: "{4E33BA17-A366-440B-BD3D-8E7142C4B6AF}" [In-None-P17-TRUE] .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe =>.Skype Software Sarl®
O87 - FAEL: "{03B902AB-0EF2-4911-AD97-62F84B16F158}" [Out-None-P17-TRUE] .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe =>.Skype Software Sarl®
O87 - FAEL: "{8DD85CA7-BBCC-41B3-9EFC-2317C72C62E4}" [In-None-P17-TRUE] .(.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®
O87 - FAEL: "{7F81E1DF-9FC3-452F-8FED-1E93407C48A6}" [In-None-P17-TRUE] .(.Piriform Software - CCleaner Browser.) -- C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe =>.Piriform Software Ltd®

---\\ CODES PRODUITS LOGICIELS (62) - 5s
O90 - PUC: "00002109110000000000000000F01FEC" [HKLM] . (.Microsoft Office Professional Plus 2007.) =>.Microsoft Corporation
O90 - PUC: "000061090900C0400000000000F01FEC" [HKLM] . (.Microsoft DCF MUI (French) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109110000000000000000F01FEC" [HKLM] . (.Microsoft Office Professional Plus 2016.) =>.Microsoft Corporation
O90 - PUC: "000061091A00C0400000000000F01FEC" [HKLM] . (.Microsoft OneNote MUI (French) 2016.) =>.Microsoft Corporation
O90 - PUC: "000061091E00C0400000000000F01FEC" [HKLM] . (.Microsoft Office OSM MUI (French) 2016.) =>.Microsoft Corporation
O90 - PUC: "000061092E00C0400000000000F01FEC" [HKLM] . (.Microsoft Office OSM UX MUI (French) 2016.) =>.Microsoft Corporation
O90 - PUC: "000061094400C0400000000000F01FEC" [HKLM] . (.Microsoft InfoPath MUI (French) 2016.) =>.Microsoft Corporation
O90 - PUC: "000061095100C0400000000000F01FEC" [HKLM] . (.Microsoft Access MUI (French) 2016.) =>.Microsoft Corporation
O90 - PUC: "000061096100C0400000000000F01FEC" [HKLM] . (.Microsoft Excel MUI (French) 2016.) =>.Microsoft Corporation
O90 - PUC: "000061098100C0400000000000F01FEC" [HKLM] . (.Microsoft PowerPoint MUI (French) 2016.) =>.Microsoft Corporation
O90 - PUC: "000061099100C0400000000000F01FEC" [HKLM] . (.Microsoft Publisher MUI (French) 2016.) =>.bl.org
O90 - PUC: "00006109A100C0400000000000F01FEC" [HKLM] . (.Microsoft Outlook MUI (French) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109A20000000100000000F01FEC" [HKLM] . (.Microsoft Office 64-bit Components 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109A200C0400100000000F01FEC" [HKLM] . (.Microsoft Office Shared 64-bit MUI (French) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109AB00C0400000000000F01FEC" [HKLM] . (.Microsoft Groove MUI (French) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109B100C0400000000000F01FEC" [HKLM] . (.Microsoft Word MUI (French) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109B210C0400000000000F01FEC" [HKLM] . (.Microsoft Skype for Business MUI (French) 2016.) =>.Skype Technologies
O90 - PUC: "00006109C200C0400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing (French) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109E600C0400000000000F01FEC" [HKLM] . (.Microsoft Office Shared MUI (French) 2016.) =>.Microsoft Corporation
O90 - PUC: "00006109F10010400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing Tools 2016 - اللغة العربية.) -- C:\WINDOWS\Installer\{90160000-001F-0401-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00006109F10031400000000000F01FEC" [HKLM] . (.Taalprogramma's voor Microsoft Office 2016 - Nederlands.) -- C:\WINDOWS\Installer\{90160000-001F-0413-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00006109F10070400000000000F01FEC" [HKLM] . (.Microsoft Office Korrekturhilfen 2016 – Deutsch.) -- C:\WINDOWS\Installer\{90160000-001F-0407-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00006109F10090400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing Tools 2016 - English.) -- C:\WINDOWS\Installer\{90160000-001F-0409-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00006109F100A0C00000000000F01FEC" [HKLM] . (.Herramientas de corrección de Microsoft Office 2016: español.) -- C:\WINDOWS\Installer\{90160000-001F-0C0A-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00006109F100C0400000000000F01FEC" [HKLM] . (.Outils de vérification linguistique 2016 de Microsoft Office - Français.) -- C:\WINDOWS\Installer\{90160000-001F-040C-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "007B601F8FFB56033B50413DA64D5093" [HKLM] . (.Microsoft Visual C++ 2017 x64 Additional Runtime - 14.15.26706.) =>.Microsoft Corporation
O90 - PUC: "02366FDE5A8AC769B19684D4DA281234" [HKLM] . (.AMD Software.) -- C:\WINDOWS\Installer\{EDF66320-A8A5-967C-1B69-484DAD822143}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "0E50B6D8754FC804D9314539438DAF1E" [HKLM] . (.Device Setup.) -- C:\windows\Installer\{8D6B05E0-F457-408C-9D13-549334D8FAE1}\_6FEFF9B68218417F98F549.exe =>.Epson/Seico
O90 - PUC: "12B8D03ED28D112328CCF0A0D541598E" [HKLM] . (.Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40660.) =>.Microsoft Corporation
O90 - PUC: "1616DA6174E21FB4AA779064FE9EE380" [HKLM] . (.Update for Windows 10 for x64-based Systems (KB4023057).) =>.Microsoft Corporation
O90 - PUC: "1926E8D15D0BCE53481466615F760A7F" [HKLM] . (.Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219.) =>.bl.org
O90 - PUC: "1BF4A48A307DBD84980E866B94D98210" [HKLM] . (.Qualcomm Atheros Bluetooth Suite (64).) -- C:\Windows\Installer\{A84A4FB1-D703-48DB-89E0-68B6499D2801}\ARPPRODUCTICON.exe =>.bl.org
O90 - PUC: "1D5E3C0FEDA1E123187686FED06E995A" [HKLM] . (.Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219.) =>.bl.org
O90 - PUC: "28F0C0E92094FDA49B55CA6896A617FD" [HKLM] . (.AMD Settings.) -- C:\WINDOWS\Installer\{9E0C0F82-4902-4ADF-B955-AC86696A71DF}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "2A077E75FAB2AAC4AB3ADB98E622453D" [HKLM] . (.AudioWizard.) -- C:\Windows\Installer\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}\ARPPRODUCTICON.exe =>.Microsoft Corporation
O90 - PUC: "44DB0475D85BA123FA0CD6D35465DDC6" [HKLM] . (.Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40660.) =>.Microsoft Corporation
O90 - PUC: "4A59177C8BECEE83DB6D4CC64B95FEE6" [HKLM] . (.Microsoft Visual C++ 2017 x64 Minimum Runtime - 14.15.26706.) =>.Microsoft Corporation
O90 - PUC: "50FA96906FF400C4496034952983EDD0" [HKLM] . (.ASUS Splendid Video Enhancement Technology.) -- C:\Windows\Installer\{0969AF05-4FF6-4C00-9406-43599238DE0D}\_853F67D554F05449430E7E.exe =>.ASUSTeK
O90 - PUC: "57451E932F32D54398775BCD749AE462" [HKLM] . (.Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706.) =>.Microsoft Corporation
O90 - PUC: "5E3E958AF26CAFB4FAD1B2590E1366FA" [HKLM] . (.ASUS USB Charger Plus.) -- C:\Windows\Installer\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}\_853F67D554F05449430E7E.exe =>.ASUSTeK
O90 - PUC: "6070B4C9A9F9FB744B71A011F15CB240" [HKLM] . (.ASUS Device Activation.) -- C:\WINDOWS\Installer\{9C4B0706-9F9A-47BF-B417-0A111FC52B04}\MyIcon =>.ASUSTeK
O90 - PUC: "6A6823D4BA6FA894284A4E0F0425F9D3" [HKLM] . (.ASUS Smart Gesture.) -- C:\WINDOWS\Installer\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}\_853F67D554F05449430E7E.exe =>.ASUSTeK
O90 - PUC: "76E045AFC590B1A479ABD445D7CEA94F" [HKLM] . (.ASUS Live Update.) -- C:\WINDOWS\Installer\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}\MyIcon2 =>.ASUSTeK
O90 - PUC: "7C9F8B73BF303523781852719CD9C700" [HKLM] . (.Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030.) =>.Microsoft Corporation
O90 - PUC: "8520DAD7C5154DD39846DB1714990E7F" [HKLM] . (.Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40660.) =>.Microsoft Corporation
O90 - PUC: "93BAD29AC2E44034A96BCB446EB8552E" [HKLM] . (.CCleaner Update Helper.)
O90 - PUC: "94D5651900D06F045B083B73F82E9815" [HKLM] . (.AMD Settings.) -- C:\WINDOWS\Installer\{91565D49-0D00-40F6-B580-B3378FE28951}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "A089CE062ADB6BC44A720BA745894BAC" [HKLM] . (.Google Update Helper.) =>.Google Inc.
O90 - PUC: "A2DBB7082C4BB0302CF29DF74A06FF97" [HKLM] . (.AMD Problem Report Wizard.) -- C:\WINDOWS\Installer\{807BBD2A-B4C2-030B-C22F-D97FA460FF79}\ARPPRODUCTICON.exe =>.bl.org
O90 - PUC: "A694757247E3A0230B706321A0F921D6" [HKLM] . (.Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706.) =>.Microsoft Corporation
O90 - PUC: "C025571B2A687A53689168CD7369889B" [HKLM] . (.Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030.) =>.Microsoft Corporation
O90 - PUC: "C3AEB2FCAE628F23AAB933F1E743AB79" [HKLM] . (.Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030.) =>.Microsoft Corporation
O90 - PUC: "CE6380BC270BD863282B3D74B09F7570" [HKLM] . (.Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40660.) =>.Microsoft Corporation
O90 - PUC: "D20352A90C039D93DBF6126ECE614057" [HKLM] . (.Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17.) =>.bl.org
O90 - PUC: "DC8A59DBF9D1DA5389A1E3975220E6BB" [HKLM] . (.Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030.) =>.Microsoft Corporation
O90 - PUC: "E031DE7C15788424BA890D95DCE9E7AA" [HKLM] . (.LibreOffice 5.4.2.2.) -- C:\WINDOWS\Installer\{C7ED130E-8751-4248-AB98-D059CD9E7EAA}\soffice.ico =>.Open Source
O90 - PUC: "E19212F84440D1B49B9F34077AE343D6" [HKLM] . (.WinFlash.) -- C:\Windows\Installer\{8F21291E-0444-4B1D-B9F9-4370A73E346D}\MyIcon =>.ASUSTeK
O90 - PUC: "E339C5BAD7C503D43B41C9384AB949EB" [HKLM] . (.ATK Package.) -- C:\Windows\Installer\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}\_6FEFF9B68218417F98F549.exe =>.ASUSTeK
O90 - PUC: "EFEE0228DC83E77358593193D847A0EC" [HKLM] . (.Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17.) =>.bl.org
O90 - PUC: "FA1E79461C2C29D409DD94EE3C2F3F5B" [HKLM] . (.AMD WVR64.) -- C:\WINDOWS\Installer\{6497E1AF-C2C1-4D92-90DD-49EEC3F2F3B5}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "74E9D1CB72981AA48A197736CB42577B" [HKCU] . (.Skype Meetings App.) -- %APPDATA%\Microsoft\Installer\{BC1D9E47-8927-4AA1-A891-7763BC2475B7}\Icon_Setup =>.Skype Technologies
O90 - PUC: "74E9D1CB72981AA48A197736CB42577B" [HKU] . (.Skype Meetings App.) -- %APPDATA%\Microsoft\Installer\{BC1D9E47-8927-4AA1-A891-7763BC2475B7}\Icon_Setup =>.Skype Technologies

---\\ PACKAGES WINDOWS INSTALLER (19) - 24s
[MD5.903CCF535AE60B4D1BAAB42D40E9CDEB] [WIS][2020/07/11 12:59:53] (.Piriform Software - CCleaner Update Helper.) -- C:\WINDOWS\Installer\119645.msi [32768] =>.Piriform Software
[MD5.449D20C0A6BEEAD14917818FE3315130] [WIS][2017/07/26 21:19:02] (.Advanced Micro Devices, Inc. - AMD Software (64 bit).) -- C:\WINDOWS\Installer\1c66b93.msi [37830144] =>.Advanced Micro Devices, Inc.
[MD5.265B92D5D3B44A9449ECE896764B6AB0] [WIS][2017/07/26 21:07:30] (.Advanced Micro Devices, Inc. - AMD Problem Report Wizard (64 bit).) -- C:\WINDOWS\Installer\1c66d23.msi [11851776] =>.Advanced Micro Devices, Inc.
[MD5.BF76587BB4DB8B2E37C82F9469F4BF19] [WIS][2017/03/03 20:59:34] (.InstallShield.) -- C:\WINDOWS\Installer\36c0d.msi [3870224] =>.InstallShield
[MD5.8BC87D4A96BD0E0C983DCEFEEF84EDEA] [WIS][2015/12/17 11:44:36] (.ASUS.) -- C:\WINDOWS\Installer\36c11.msi [544768] =>.ASUS
[MD5.045AC03CBFD95E5448F5802EFF6A3256] [WIS][2019/08/16 17:54:12] (.Advanced Micro Devices, Inc. - AMD Settings.) -- C:\WINDOWS\Installer\4e09fe3.msi [24027220] =>.Advanced Micro Devices, Inc.
[MD5.65112C5010E5645CD5137F7A46BB7280] [WIS][2019/08/16 17:57:20] (.Advanced Micro Devices, Inc. - AMD Settings.) -- C:\WINDOWS\Installer\4e09fe4.msi [96555288] =>.Advanced Micro Devices, Inc.
[MD5.65112C5010E5645CD5137F7A46BB7280] [WIS][2019/08/16 17:57:20] (.Advanced Micro Devices, Inc. - AMD Settings.) -- C:\WINDOWS\Installer\4e09fe7.msi [96555288] =>.Advanced Micro Devices, Inc.
[MD5.B64579A738049B159FFA337D4D7B9BBA] [WIS][2019/08/16 17:58:02] (.Advanced Micro Devices, Inc. - AMD WVR64.) -- C:\WINDOWS\Installer\4e09feb.msi [15418595] =>.Advanced Micro Devices, Inc.
[MD5.44C8B3D90F42F263036FF2AB61AC0392] [WIS][2017/11/08 18:36:29] (.The Document Foundation - LibreOffice 5.4.) -- C:\WINDOWS\Installer\540f7de0.msi [223789056] =>.The Document Foundation
[MD5.1766B021B0BAB4F82259974154C5A920] [WIS][2020/03/31 16:28:42] (.Google LLC - Google Update Helper.) -- C:\WINDOWS\Installer\5cc7dd02.msi [40960] =>.Google LLC
[MD5.48AC97725A03D2F5049CE30D53DF19EA] [WIS][2017/03/09 10:26:32] (.ASUS.) -- C:\WINDOWS\Installer\5e8d77f7.msi [501248] =>.ASUS
[MD5.A4086EA98B5915E968A13D5529DD3EAF] [WIS][2016/07/07 09:35:07] (.ASUSTek COMPUTER INC. - Device Setup.) -- C:\WINDOWS\Installer\7b808.msi [3041792] =>.ASUSTek COMPUTER INC.
[MD5.A5C50145FE76EEB10FD371549BFC8DB6] [WIS][2018/06/05 17:31:30] (.ASUSTeK COMPUTER INC..) -- C:\WINDOWS\Installer\833d14f.msi [1292800] =>.ASUSTeK COMPUTER INC.
[MD5.D22BB4DC490DACC6BFAE2581B7AB19A9] [WIS][2016/08/01 08:31:14] (.ASUSTeK COMPUTER INC..) -- C:\WINDOWS\Installer\d592.msi [1644544] =>.ASUSTeK COMPUTER INC.
[MD5.271C140DAB40864C201AD4EEA7AC6850] [WIS][2015/12/02 12:08:52] (.ASUS.) -- C:\WINDOWS\Installer\e7b3.msi [11616256] =>.ASUS
[MD5.FA7372278E8CCB85959431F88A488CC5] [WIS][2017/03/03 21:07:42] (.ICEpower a/s - AudioWizard.) -- C:\WINDOWS\Installer\eb7c.msi [6227968] =>.ICEpower a/s
[MD5.0128BBE153B9A5F28730DAB63376FCE0] [WIS][2015/05/25 07:20:24] (.ASUS.) -- C:\WINDOWS\Installer\eb80.msi [9694720] =>.ASUS
[MD5.0397E6F094D1FCE55580B0E98C0137E3] [WIS][2019/03/12 22:03:32] (.ASUSTeK COMPUTER INC..) -- C:\WINDOWS\Installer\f728f73.msi [4840960] =>.ASUSTeK COMPUTER INC.

---\\ RECHERCHE DE CLÉS DE REGISTRE Tracing (4) - 1s
HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASAPI32 =>SUP.Optional.ByteFence
HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASMANCS =>SUP.Optional.ByteFence
HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 =>SUP.Optional.ByteFence
HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS =>SUP.Optional.ByteFence

---\\ FEATURE CONTROL. (873) - 5s
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:infopath.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPfewgsrv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGUI.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGuiIT.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLgPad.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLOGON.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:Scale_for_R3.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:ieuser.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK]:YahooMusicEngine.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:devenv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:dexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:helppane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS]:msfeedssync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG]:msiexec.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:cs.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:waol.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:wm.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS]:helppane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS]:wlmail.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:outlook.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:sidebar.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING]:communicator.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msimn.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:winmail.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:msimn.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:outlook.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:winmail.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:excel.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:infopath.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:powerpnt.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:winword.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD]:msn.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:ONENOTEM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Microsoft.Mashup.Container.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Microsoft.Mashup.Container.NetFX40.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Microsoft.Mashup.Container.NetFX45.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:lync99.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:ONENOTE.EXE =>.Legitimate

---\\ OBSERVATEURS des évènements (141) - 115s

Application.Warning: ESENT (467)
~Numéro: 13620
~Date: 08/17/2020 08:42:12 AM
~ID: 508
~Description: %1 (%2) %3Une demande d’écriture dans le fichier « %4 » à l’adresse relative %5 pour %6 octets a réussi, mais a duré anormalement longtemps (%7 secondes) pour être traitée par le système d’exploitation. Ce problème est probablement dû à du matériel d
~Suggestion: Aucune

Application.Warning: Software Protection Platform Service (48)
~Numéro: 13602
~Date: 08/17/2020 08:29:26 AM
~ID: 8233
~Description: Le moteur de règles a signalé l’échec d’une tentative d’activation de licences en volume. Motif :0x8007232B IdApp = %2, IdSku = d450596f-894d-49e0-966a-fd39ed4c4c64 Déclencheur=NetworkAvailable

Application.Warning: Windows Search Service (2)
~Numéro: 13561
~Date: 08/17/2020 08:11:25 AM
~ID: 3036
~Description: Impossible de terminer l’analyse dans la source de contenu <%2>.Contexte : Application , Catalogue SystemIndexDétails : Le filtrage du document n’a pu s’achever car le serveur de document n’a pas répondu dans le délai imparti. Essayez d’analyser le s
~Suggestion: https://www.repairwin.com/fix-windows-event-3036-search-content-source-cannot-accessed-solved/

Application.Error: Application Error (8)
~Numéro: 13534
~Date: 08/14/2020 12:25:24 PM
~ID: 1000
~Description: Nom de l’application défaillante %1, version : %2, horodatage : 0x32d6c210 Nom du module défaillant : %4, version : %5, horodatage : 0xea13e855 Code d’exception : 0xc0000409 Décalage d’erreur : 0x0000000000008596 ID du processus défaillant : 0x2d10 H
~Suggestion: Réparer ou réinstaller l'application.

Application.Error: Microsoft-Windows-Spell-Checking (1)
~Numéro: 13433
~Date: 08/05/2020 02:06:07 PM
~ID: 31
~Description: Impossible de mettre à jour la liste de mots personnalisée utilisateur %1 : %2. La vérification de l’orthographe reste disponible, mais cette liste de mots utilisateur n’est pas mise à jour.

Application.Warning: Microsoft-Windows-System-Restore (2)
~Numéro: 13275
~Date: 07/30/2020 11:37:57 AM
~ID: 8303
~Description: Scoping unsuccessful for shadowcopy %1 with error %2.
~Suggestion: Exécuter la commande chkdsk / f

Application.Warning: Microsoft-Windows-RestartManager (2)
~Numéro: 12690
~Date: 07/11/2020 01:30:58 PM
~ID: 10010
~Description: Impossible de redémarrer l’application « %3 » (pid %2) - %9.
~Suggestion: Redémarrer manuellement l'application ou le service

Application.Error: VSS (19)
~Numéro: 12495
~Date: 07/11/2020 01:09:21 PM
~ID: 8193
~Description: Erreur du service de cliché instantané des volumes : erreur lors de l’appel de la routine %1. hr = %2.
~Suggestion: Utiliser la procédure de reconstruction du VSS

Application.Error: Office 2016 Licensing Service (43)
~Numéro: 12294
~Date: 07/11/2020 12:19:10 PM
~ID: 0
~Description: Subscription licensing service failed: -1073422302

Application.Warning: Microsoft-Windows-WMI (16)
~Numéro: 12064
~Date: 07/07/2020 02:14:30 PM
~ID: 63
~Description: Un fournisseur, %1, a été inscrit dans l’espace de noms Windows Management Instrumentation %2, afin d’utiliser le compte LocalSystem. Ce compte bénéficie de privilèges et le fournisseur peut provoquer une violation de sécurité s’il ne représente pas
~Suggestion: Généralement LocalSystem n'est pas nécessaire et le contexte de sécurité NetworkServiceHost est plus approprié.

Application.Error: Microsoft Office 12 (1)
~Numéro: 11877
~Date: 07/04/2020 05:28:00 PM
~ID: 2000
~Description: Microsoft Office ExcelÉchec lors du dernier démarrage de Excel. Le redémarrer en mode sans échec vous permettra de corriger ou d'isoler ce problème afin de pouvoir démarrer le programme correctement. Certaines fonctionnalités seront peut-être désacti

Application.Error: Microsoft-Windows-User Profiles Service (1)
~Numéro: 11691
~Date: 06/18/2020 09:53:54 PM
~ID: 1552
~Description: La ruche utilisateur est chargée par un autre processus (verrouillage de Registre) Nom du processus : %1, PID : %2, PID ProfSvc : %3.
~Suggestion: Vérifier les paramètres de connexion.

Application.Warning: Wlclntfy (2)
~Numéro: 11687
~Date: 06/18/2020 09:53:48 PM
~ID: 6006
~Description: Le traitement de l’événement de notification (%3) par l’abonné aux notifications Winlogon <%1> a duré %2 secondes.
~Suggestion: Supprimer la valeur de registre GpNetworkStartTimeoutPolicyValue de la clé HKLM\SOFTWARE\Policies\Microsoft\Windows\System

Application.Error: Application Hang (1)
~Numéro: 11651
~Date: 06/17/2020 12:09:49 AM
~ID: 1002
~Description: Le programme %1 version %2 a cessé d'interagir avec Windows et a été fermé. Pour voir si plus d'informations sur le problème sont disponibles, vérifiez l'historique des problèmes dans le Panneau de configuration Sécurité et maintenance. ID de proces
~Suggestion: Essayer les commandes suivantes ipconfig /release et ipconfig / renew.

Application.Error: Microsoft-Windows-Perflib (3)
~Numéro: 10718
~Date: 05/18/2020 05:08:31 PM
~ID: 1020
~Description: La taille de la mémoire tampon obligatoire est supérieure à la taille de la mémoire tampon transmise à la fonction de collecte de la DLL Compteur extensible « %1 » pour le service « %2 ». La taille de la mémoire tampon donnée était de %3 et la taille
~Suggestion: Régénérer la liste des compteurs de performances

System.Warning: DCOM (344)
~Numéro: 19349
~Date: 08/17/2020 08:46:28 AM
~ID: 10016
~Description: propres à l’applicationLocalActivation{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}{15C20B67-12E7-4BB6-92BB-7AFF07997402}ASUS-MELVINmelviS-1-5-21-2913167448-2319757323-3006012701-1001LocalHost (avec LRPC)Non disponibleNon disponible
~Suggestion: Vérifier les autorisations pour l'accès DCOM

System.Warning: Microsoft-Windows-DNS-Client (61)
~Numéro: 19269
~Date: 08/17/2020 08:08:06 AM
~ID: 1014
~Description: La résolution du nom %1 a expiré lorsqu’aucun des serveurs DNS configurés n’a répondu.
~Suggestion: https://social.technet.microsoft.com/wiki/contents/articles/3336.event-id-1014-microsoft-windows-dns-client.aspx

System.Warning: BTHUSB (164)
~Numéro: 19264
~Date: 08/17/2020 08:07:46 AM
~ID: 34
~Description: La carte locale ne prend pas en charge un état de contrôleur Low Energy important pour la prise en charge du mode périphérique. Le masque d’état pris en charge requis au minimum est %2, a reçu %3. La fonctionnalité du rôle périphérique Low Energy n

System.Error: Microsoft-Windows-HAL (6)
~Numéro: 18875
~Date: 07/31/2020 12:16:12 AM
~ID: 13
~Description: Le temporisateur de surveillance du système a été déclenché.

System.Error: Service Control Manager (48)
~Numéro: 18733
~Date: 07/30/2020 10:21:17 AM
~ID: 7011
~Description: Le dépassement de délai (%1 millisecondes) a été atteint lors de l’attente de la réponse transactionnelle du service %2.
~Suggestion: https://support.microsoft.com/fr-fr/help/922918/a-service-does-not-start-and-events-7000-and-7011-are-logged-in-window

System.Warning: Microsoft-Windows-Time-Service (10)
~Numéro: 18500
~Date: 07/14/2020 01:56:53 AM
~ID: 134
~Description: NtpClient n'a pas pu définir d'homologue manuel utilisable comme source de temps en raison d'une erreur de résolution DNS sur "%3". NtpClient réessaiera dans %2 minutes, puis doublera l'intervalle d'attente pour les tentatives suivantes. L'erreur éta
~Suggestion: Resynchroniser le client avec l'homologue de source de temps

System.Error: Ntfs (2)
~Numéro: 18032
~Date: 07/07/2020 08:34:53 PM
~ID: 55
~Description: Une défaillance a été détectée dans la structure du système de fichiers sur le volume %1. La table MFT (Master File Table) contient un enregistrement de fichier endommagé. Le numéro de référence du fichier est 0x9000000000009. Le nom du fichier est

System.Warning: Microsoft-Windows-WLAN-AutoConfig (1)
~Numéro: 15955
~Date: 05/13/2020 02:57:35 PM
~ID: 4003
~Description: Le service de configuration automatique de réseau WLAN a détecté une connectivité limitée, en tentant une récupération automatique. Type de récupération : 4 Code d’erreur : 0x0 Motif de déclenchement : 3 Famille IP : 0
~Suggestion: Vérifier les paramètres d'économie d'énergie

System.Warning: Display (3)
~Numéro: 14659
~Date: 05/03/2020 09:47:34 AM
~ID: 4101
~Description: Le pilote d’affichage %1 ne répondait plus.

System.Warning: Microsoft-Windows-WHEA-Logger (1)
~Numéro: 14586
~Date: 05/02/2020 07:09:45 PM
~ID: 19
~Description: Une erreur matérielle corrigée s’est produite. Signalée par le composant : cœur du processeur Source de l’erreur : 1 Type d’erreur : 8 ID APIC du processeur : 2 Pour plus d’informations, consultez les détails de cette entrée.

---\\ SCAN ADDITIONNEL (56) - 23s
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC} =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\HowToRemove =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\niridos =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\rocodo =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\uninst.exe =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\uninstp.dat =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\HowToRemove\chromium-min.jpg =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\HowToRemove\control panel-min-min.JPG =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\HowToRemove\down.png =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\HowToRemove\ff menu.JPG =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\HowToRemove\ff search engine-min.png =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\HowToRemove\HowToRemove.html =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\HowToRemove\hp-min ff.png =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\HowToRemove\hp-min ie.png =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\HowToRemove\search engine.gif =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\HowToRemove\setup pages.gif =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\HowToRemove\sp-min.png =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\HowToRemove\start-min.jpg =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{65585304-41F0-3FBC-2C68-1A540800E6CC}\HowToRemove\up.png =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4} =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\fesese =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\todato =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\uninst.exe =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\uninstp.dat =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\chromium-min.jpg =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\control panel-min-min.JPG =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\down.png =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\ff menu.JPG =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\ff search engine-min.png =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\HowToRemove.html =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\hp-min ff.png =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\hp-min ie.png =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\search engine.gif =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\setup pages.gif =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\sp-min.png =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\start-min.jpg =>PUP.Optional.WinYahoo
C:\Users\melvi\AppData\Local\{A8209E7C-8C88-F2C4-E110-D72CC5782BB4}\HowToRemove\up.png =>PUP.Optional.WinYahoo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4944A184-19C4-7004-A844-008478C4D304} =>Adware.YahooPowered
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>Heuristic.Suspect
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BC0F54CF-EC8F-854F-5D0F-F5CF8D8F264F} =>Adware.YahooPowered
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4944A184-19C4-7004-A844-008478C4D304} =>Adware.YahooPowered
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>Heuristic.Suspect
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BC0F54CF-EC8F-854F-5D0F-F5CF8D8F264F} =>Adware.YahooPowered
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 =>.SUP.Orphan
HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} =>.SUP.Orphan
HKLM\Software\Classes\lnkfile\shellex\ContextMenuHandlers\WinRAR32 =>.SUP.Orphan
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32 =>.SUP.Orphan
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceService_RASAPI32 =>SUP.Optional.ByteFence
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceService_RASMANCS =>SUP.Optional.ByteFence
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFence_RASAPI32 =>SUP.Optional.ByteFence
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFence_RASMANCS =>SUP.Optional.ByteFence
C:\Users\melvi\AppData\Local\Google\Chrome\User Data\Default\File System\000 =>.SUP.Temporary.Chrome
C:\Users\melvi\AppData\Local\Google\Chrome\User Data\Default\File System\001 =>.SUP.Temporary.Chrome
HKU\S-1-5-21-2913167448-2319757323-3006012701-1001\Software\csastats =>Adware.InstallCore
HKCU\Software\csastats =>Adware.InstallCore

---\\ RÉCAPITULATIF DES ÉLÉMENTS TROUVÉS (11) - 0s
https://nicolascoolman.eu/forum/Topic/winyahoo-logiciel-optionnel-potentiellement-indesirable-pup-lpi/ =>PUP.Optional.WinYahoo
https://nicolascoolman.eu/2017/09/12/origine-lignes-orphelines/ =>.SUP.Orphan
https://nicolascoolman.eu/forum/Topic/yahoopowered-logiciel-publicitaire-adware-2/ =>Adware.YahooPowered
https://nicolascoolman.eu/wp-content/uploads/2019/01/Informations-Sécurité-Zone-antimalware.jpg =>Heuristic.Suspect
https://nicolascoolman.eu/2017/10/04/adware-trymedia/ =>PUP.Optional.Trymedia
https://nicolascoolman.eu/2017/10/06/adware-vitruvian/ =>PUP.Optional.WordAnchor
https://nicolascoolman.eu/2017/09/19/adware-installcore-3/ =>Adware.InstallCore
https://nicolascoolman.eu/2017/03/13/superfluous-bytefence/ =>SUP.Optional.ByteFence
https://nicolascoolman.eu/forum/Topic/warning-eventlogapp-evenement-dapplication/ =>Warning.EventLogApp
https://nicolascoolman.eu/forum/Topic/warning-eventlogsys-evenement-systeme/ =>Warning.EventLogSys
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Temporary.Chrome

---\\ NUMEROS DE SÉRIE
[01000000000115372421A8] [15/12/2007] (.Noriyuki MIYAZAKI.) - C:\WINDOWS\SysWOW64\WinRing0.sys =>.Noriyuki MIYAZAKI
[0195C200D3BEB4976805ACD3973BB6DF] [22/10/2019] (.Adobe Inc..) - C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe =>.Adobe Inc.
[024FD22ED89C8823D79C2A09A4E6423F] [07/08/2019] (.ASUSTek Computer Inc..) - C:\WINDOWS\System32\drivers\AsRadioControl.sys =>.ASUSTek Computer Inc.
[02E17C176AE552051DD78F0214E647AE] [15/06/2017] (.LunarG, Inc..) - C:\Program Files (x86)\VulkanRT\1.0.51.0\UninstallVulkanRT.exe =>.LunarG, Inc.
[02FA994D660DE659EE9037ECB437D766] [11/07/2020] (.Piriform Software Ltd.) - C:\Program Files (x86)\CCleaner Browser\Update\1.7.913.0\CCleanerBrowserCrashHandler.exe =>.Piriform Software Ltd
[02FA994D660DE659EE9037ECB437D766] [11/07/2020] (.Piriform Software Ltd.) - C:\Program Files (x86)\CCleaner Browser\Update\1.7.913.0\CCleanerBrowserCrashHandler64.exe =>.Piriform Software Ltd
[02FA994D660DE659EE9037ECB437D766] [11/07/2020] (.Piriform Software Ltd.) - C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe =>.Piriform Software Ltd
[02FA994D660DE659EE9037ECB437D766] [12/08/2020] (.Piriform Software Ltd.) - C:\Program Files (x86)\CCleaner Browser\Application\84.0.5275.108\Installer\chrmstp.exe =>.Piriform Software Ltd
[02FA994D660DE659EE9037ECB437D766] [17/06/2020] (.Piriform Software Ltd.) - C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Software Ltd
[02FA994D660DE659EE9037ECB437D766] [17/06/2020] (.Piriform Software Ltd.) - C:\Program Files\CCleaner\uninst.exe =>.Piriform Software Ltd
[02FA994D660DE659EE9037ECB437D766] [28/07/2020] (.Piriform Software Ltd.) - C:\Program Files (x86)\CCleaner Browser\Application\84.0.5275.108\elevation_service.exe =>.Piriform Software Ltd
[02FA994D660DE659EE9037ECB437D766] [28/07/2020] (.Piriform Software Ltd.) - C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe =>.Piriform Software Ltd
[02FA994D660DE659EE9037ECB437D766] [28/07/2020] (.Piriform Software Ltd.) - C:\Program Files (x86)\CCleaner Browser\CCleanerBrowserUninstall.exe =>.Piriform Software Ltd
[03B471CD4D7FFEC29A3B20B2CB0F5F54] [21/07/2016] (.LunarG, Inc..) - C:\Program Files (x86)\VulkanRT\1.0.21.0\UninstallVulkanRT.exe =>.LunarG, Inc.
[0510C6B2FF7AB71C786EF572239B1243] [07/07/2020] (.Zoom Video Communications, Inc..) - C:\Users\melvi\AppData\Roaming\Zoom\bin\Zoom.exe =>.Zoom Video Communications, Inc.
[0510C6B2FF7AB71C786EF572239B1243] [07/07/2020] (.Zoom Video Communications, Inc..) - C:\Users\melvi\AppData\Roaming\Zoom\uninstall\Installer.exe =>.Zoom Video Communications, Inc.
[0678BE9B85D65AC22E0BE99D3FBB4DA3] [27/11/2018] (.Synaptics Incorporated.) - C:\WINDOWS\System32\drivers\CHDRT64.sys =>.Synaptics Incorporated
[06AEA76BAC46A9E8CFE6D29E45AAF033] [31/03/2020] (.Google LLC.) - C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe =>.Google LLC
[06AEA76BAC46A9E8CFE6D29E45AAF033] [31/03/2020] (.Google LLC.) - C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe =>.Google LLC
[06B922A8397E632FE5348DA267275B4F] [11/04/2018] (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe =>.Adobe Systems Incorporated
[06F24D9F4DB07BD7ECAD067F5EE26C29] [26/07/2019] (.Adobe Inc..) - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HDBox\Uninstaller.exe =>.Adobe Inc.
[07EC0CF3D333673B2602D410FE0C4D21] [16/08/2019] (.Advanced Micro Devices, Inc..) - C:\Program Files\AMD\CNext\CNext\atiacm64.dll =>.Advanced Micro Devices, Inc.
[07EC0CF3D333673B2602D410FE0C4D21] [16/08/2019] (.Advanced Micro Devices, Inc..) - C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
[07EC0CF3D333673B2602D410FE0C4D21] [18/09/2019] (.Advanced Micro Devices, Inc..) - C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atiesrxx.exe =>.Advanced Micro Devices, Inc.
[07EC0CF3D333673B2602D410FE0C4D21] [18/09/2019] (.Advanced Micro Devices, Inc..) - C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atikmdag.sys =>.Advanced Micro Devices, Inc.
[07EC0CF3D333673B2602D410FE0C4D21] [18/09/2019] (.Advanced Micro Devices, Inc..) - C:\Windows\System32\DriverStore\FileRepository\c0346830.inf_amd64_f723e13ffb3b2652\B345901\atikmpag.sys =>.Advanced Micro Devices, Inc.
[08B8D3C136349C70F4D85813400F1D6C] [28/09/2017] (.The Document Foundation.) - C:\Program Files (x86)\LibreOffice 5\program\soffice.exe =>.The Document Foundation
[0A2851E5F0FFDB46E2C9CB6610E6512F] [11/12/2018] (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe =>.Adobe Systems Incorporated
[0A5C0955B9E3AC705430FCAC2EDEEDD0] [22/10/2019] (.Node.js Foundation.) - C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\libs\node.exe =>.Node.js Foundation
[0B00C13079D2BA01D2B678B422C2CC1D] [09/03/2017] (.ASUSTeK Computer Inc..) - C:\WINDOWS\System32\drivers\AsusTP.sys =>.ASUSTeK Computer Inc.
[0C15BE4A15BB0903C901B1D6C265302F] [08/08/2020] (.Google LLC.) - C:\Program Files (x86)\Google\Chrome\Application\84.0.4147.125\elevation_service.exe =>.Google LLC
[0C15BE4A15BB0903C901B1D6C265302F] [08/08/2020] (.Google LLC.) - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC
[0C15BE4A15BB0903C901B1D6C265302F] [12/08/2020] (.Google LLC.) - C:\Program Files (x86)\Google\Chrome\Application\84.0.4147.125\Installer\chrmstp.exe =>.Google LLC
[0C15BE4A15BB0903C901B1D6C265302F] [12/08/2020] (.Google LLC.) - C:\Program Files (x86)\Google\Chrome\Application\84.0.4147.125\Installer\setup.exe =>.Google LLC
[0C15BE4A15BB0903C901B1D6C265302F] [13/08/2020] (.Google LLC.) - C:\Users\melvi\AppData\Local\Google\Chrome\User Data\SwReporter\84.240.200\software_reporter_tool.exe =>.Google LLC
[0D2CACCD3E9EEC06738410BA31BF6595] [13/08/2020] (.Adobe Inc..) - C:\Users\melvi\AppData\Local\Google\Chrome\User Data\PepperFlash\32.0.0.414\pepflashplayer.dll =>.Adobe Inc.
[0E4C1A84EE436C73F30978E7D4C34C0B] [18/05/2017] (.Samsung Electronics Co., Ltd..) - C:\WINDOWS\System32\DRIVERS\ssudbus.sys =>.Samsung Electronics Co., Ltd.
[0E4C1A84EE436C73F30978E7D4C34C0B] [18/05/2017] (.Samsung Electronics Co., Ltd..) - C:\WINDOWS\System32\DRIVERS\ssudmdm.sys =>.Samsung Electronics Co., Ltd.
[0EFFC52BBBF345BBA2BD28BF99E9D861] [01/08/2016] (.ASUSTeK Computer Inc..) - C:\Program Files (x86)\ASUS\WinFlash\WinFlash.exe =>.ASUSTeK Computer Inc.
[0EFFC52BBBF345BBA2BD28BF99E9D861] [05/06/2018] (.ASUSTeK Computer Inc..) - C:\Program Files (x86)\ASUS\ASUS Device Activation\DevActSvc.exe =>.ASUSTeK Computer Inc.
[0EFFC52BBBF345BBA2BD28BF99E9D861] [14/12/2015] (.ASUSTeK Computer Inc..) - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe =>.ASUSTeK Computer Inc.
[0EFFC52BBBF345BBA2BD28BF99E9D861] [14/12/2015] (.ASUSTeK Computer Inc..) - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe =>.ASUSTeK Computer Inc.
[0EFFC52BBBF345BBA2BD28BF99E9D861] [19/08/2015] (.ASUSTeK Computer Inc..) - C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys =>.ASUSTeK Computer Inc.
[0EFFC52BBBF345BBA2BD28BF99E9D861] [26/11/2015] (.ASUSTeK Computer Inc..) - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe =>.ASUSTeK Computer Inc.
[0F23B7C915815D3501B34506B754CF06] [09/03/2017] (.ASUSTeK Computer Inc..) - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe =>.ASUSTeK Computer Inc.
[0F23B7C915815D3501B34506B754CF06] [09/03/2017] (.ASUSTeK Computer Inc..) - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe =>.ASUSTeK Computer Inc.
[0F23B7C915815D3501B34506B754CF06] [09/03/2017] (.ASUSTeK Computer Inc..) - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe =>.ASUSTeK Computer Inc.
[0F5C689DC0717374609E20ED097B19D9] [27/11/2018] (.ICEpower a/s.) - C:\Windows\System32\DriverStore\FileRepository\x40plmwa.inf_amd64_09e65ea70153c3a6\ICEsoundService64.exe =>.ICEpower a/s
[1044F31AE1F93A0BB95F19AB9FAAC6BB] [17/08/2020] (.ESET, spol. s r.o..) - C:\Users\melvi\AppData\Local\Google\Chrome\User Data\SwReporter\84.240.200\edls_64.dll =>.ESET, spol. s r.o.
[1044F31AE1F93A0BB95F19AB9FAAC6BB] [17/08/2020] (.ESET, spol. s r.o..) - C:\Users\melvi\AppData\Local\Google\Chrome\User Data\SwReporter\84.240.200\em000_64.dll =>.ESET, spol. s r.o.
[1044F31AE1F93A0BB95F19AB9FAAC6BB] [17/08/2020] (.ESET, spol. s r.o..) - C:\Users\melvi\AppData\Local\Google\Chrome\User Data\SwReporter\84.240.200\em001_64.dll =>.ESET, spol. s r.o.
[1044F31AE1F93A0BB95F19AB9FAAC6BB] [17/08/2020] (.ESET, spol. s r.o..) - C:\Users\melvi\AppData\Local\Google\Chrome\User Data\SwReporter\84.240.200\em002_64.dll =>.ESET, spol. s r.o.
[1044F31AE1F93A0BB95F19AB9FAAC6BB] [17/08/2020] (.ESET, spol. s r.o..) - C:\Users\melvi\AppData\Local\Google\Chrome\User Data\SwReporter\84.240.200\em003_64.dll =>.ESET, spol. s r.o.
[1044F31AE1F93A0BB95F19AB9FAAC6BB] [17/08/2020] (.ESET, spol. s r.o..) - C:\Users\melvi\AppData\Local\Google\Chrome\User Data\SwReporter\84.240.200\em004_64.dll =>.ESET, spol. s r.o.
[1044F31AE1F93A0BB95F19AB9FAAC6BB] [17/08/2020] (.ESET, spol. s r.o..) - C:\Users\melvi\AppData\Local\Google\Chrome\User Data\SwReporter\84.240.200\em005_64.dll =>.ESET, spol. s r.o.
[12D5C9E2949D48ABACCD3514F0FB22AD] [03/12/2010] (.ASUSTeK Computer Inc..) - C:\WINDOWS\SysWOW64\MemDriverx64.sys =>.ASUSTeK Computer Inc.
[13222A5DCCF716DF5AF9C87084412DD9] [09/07/2015] (.Realtek Semiconductor Corp.) - C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe =>.Realtek Semiconductor Corp
[13222A5DCCF716DF5AF9C87084412DD9] [15/07/2015] (.Realtek Semiconductor Corp.) - C:\WINDOWS\System32\drivers\rt640x64.sys =>.Realtek Semiconductor Corp
[14F8FDD167F92402B1570B5DC495C815] [30/07/2017] (.Google Inc.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc
[167DB6F0182412A5F7E507AD73FD4A04] [20/06/2018] (.Conexant Systems LLC.) - C:\Program Files\CONEXANT\SAII\SmartAudio.exe =>.Conexant Systems LLC
[167DB6F0182412A5F7E507AD73FD4A04] [24/11/2017] (.Conexant Systems LLC.) - C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe =>.Conexant Systems LLC
[167DB6F0182412A5F7E507AD73FD4A04] [27/11/2018] (.Conexant Systems LLC.) - C:\Program Files\CONEXANT\CNXT_AUDIO_HDA\UIU64a.exe =>.Conexant Systems LLC
[19D2BBA6922F3C7A0242B54C040F8B11] [27/10/2016] (.Conexant Systems, Inc..) - C:\Windows\System32\SASrv.exe =>.Conexant Systems, Inc.
[330000017BB47778D9105DF03500000000017B] [18/07/2020] (.Skype Software Sarl.) - C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe =>.Skype Software Sarl
[3DD79449EA86A17D1AED3D553A987DDF] [31/01/2019] (.Qualcomm Atheros.) - C:\WINDOWS\System32\drivers\AdminService.exe =>.Qualcomm Atheros
[3DD79449EA86A17D1AED3D553A987DDF] [31/01/2019] (.Qualcomm Atheros.) - C:\WINDOWS\System32\drivers\btfilter.sys =>.Qualcomm Atheros
[404BDAD0A11E76838B11556FAF5CC25B] [11/11/2016] (.Zhuhai Kingsoft Office Software Co.,Ltd.) - C:\Program Files (x86)\Kingsoft\WPS Office\10.1.0.5644\utility\uninst.exe =>.Zhuhai Kingsoft Office Software Co.,Ltd
[40AA58FE8BB685678752F08E5A27F7A3] [18/09/2017] (.ASUSTek Computer Inc..) - C:\Program Files (x86)\ASUS\Giftbox\asusgiftbox.exe =>.ASUSTek Computer Inc.
[40AA58FE8BB685678752F08E5A27F7A3] [18/09/2017] (.ASUSTek Computer Inc..) - C:\Program Files (x86)\ASUS\Giftbox\uninstall.exe =>.ASUSTek Computer Inc.
[4CD9E755850C1372B48DC182A7308BAB] [13/08/2016] (.Advanced Micro Devices, Inc..) - C:\WINDOWS\System32\DRIVERS\usbfilter.sys =>.Advanced Micro Devices, Inc.
[4CD9E755850C1372B48DC182A7308BAB] [18/08/2016] (.Advanced Micro Devices, Inc..) - C:\WINDOWS\System32\drivers\amdkmafd.sys =>.Advanced Micro Devices, Inc.
[4CE26AB7B08A86A56200DE244E294BA5] [20/10/2014] (.Conexant Systems, Inc..) - C:\WINDOWS\system32\CxAudMsg64.exe =>.Conexant Systems, Inc.
[529E3F9FCF7D58D520D607AB74395002] [26/03/2020] (.win.rar GmbH.) - C:\Program Files\WinRAR\Rar.exe =>.win.rar GmbH
[529E3F9FCF7D58D520D607AB74395002] [26/03/2020] (.win.rar GmbH.) - C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH
[529E3F9FCF7D58D520D607AB74395002] [26/03/2020] (.win.rar GmbH.) - C:\Program Files\WinRAR\uninstall.exe =>.win.rar GmbH
[56729300C78306C4267CA44A10ADCD03] [12/05/2016] (.TeamViewer.) - C:\Program Files (x86)\TeamViewer\TeamViewer.exe =>.TeamViewer
[56729300C78306C4267CA44A10ADCD03] [12/05/2016] (.TeamViewer.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer
[56729300C78306C4267CA44A10ADCD03] [12/05/2016] (.TeamViewer.) - C:\Program Files (x86)\TeamViewer\uninstall.exe =>.TeamViewer
[5CA430E4777412A8230BF839F782D4F7] [12/06/2017] (.Advanced Micro Devices Inc..) - C:\WINDOWS\System32\DRIVERS\amdkmcsp.sys =>.Advanced Micro Devices Inc.
[5CA430E4777412A8230BF839F782D4F7] [12/06/2017] (.Advanced Micro Devices Inc..) - C:\WINDOWS\System32\drivers\amdpsp.sys =>.Advanced Micro Devices Inc.
[60864463BBBC2E4E67D42771E4CBD9A5] [31/01/2020] (.Zhuhai Kingsoft Office Software Co., Ltd..) - C:\Program Files (x86)\Kingsoft\WPS Office\10.2.0.7646\office6\wpscloudsvr.exe =>.Zhuhai Kingsoft Office Software Co., Ltd.
[60864463BBBC2E4E67D42771E4CBD9A5] [31/01/2020] (.Zhuhai Kingsoft Office Software Co., Ltd..) - C:\Program Files (x86)\Kingsoft\WPS Office\10.2.0.7646\utility\uninst.exe =>.Zhuhai Kingsoft Office Software Co., Ltd.
[60864463BBBC2E4E67D42771E4CBD9A5] [31/01/2020] (.Zhuhai Kingsoft Office Software Co., Ltd..) - C:\Program Files (x86)\Kingsoft\WPS Office\wpscloudsvr.exe =>.Zhuhai Kingsoft Office Software Co., Ltd.
[72DCD35B1DBBF28F0F9848EC766A1BDF] [18/09/2019] (.Advanced Micro Devices, Inc..) - C:\WINDOWS\System32\drivers\amdkmpfd.sys =>.Advanced Micro Devices, Inc.
[72DCD35B1DBBF28F0F9848EC766A1BDF] [20/07/2017] (.Advanced Micro Devices, Inc..) - C:\Program Files\AMD\CIM\Bin64\RadeonInstaller.exe =>.Advanced Micro Devices, Inc.
[7D08D9BC130726DE26EE4EF28E133084] [01/04/2015] (.ASUSTeK Computer Inc..) - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe =>.ASUSTeK Computer Inc.
[7D08D9BC130726DE26EE4EF28E133084] [21/05/2015] (.ASUSTeK Computer Inc..) - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe =>.ASUSTeK Computer Inc.
[7D08D9BC130726DE26EE4EF28E133084] [25/05/2015] (.ASUSTeK Computer Inc..) - C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe =>.ASUSTeK Computer Inc.
[7D08D9BC130726DE26EE4EF28E133084] [25/05/2015] (.ASUSTeK Computer Inc..) - C:\WINDOWS\System32\DRIVERS\AiCharger.sys =>.ASUSTeK Computer Inc.

~ Unselected Options:
~ End of the scan, 11882 items in 12mn55s (2977)(0)

Publicité


Signaler le contenu de ce document

Publicité