~ ZHPDiag v2017.3.17.47 Par Nicolas Coolman (2017/03/17) ~ Démarré par SAMIA (Administrator) (2017/03/18 20:09:14) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Etat de la version: Version OK ~ Mode: Scanner ~ Rapport: C:\Users\SAMIA\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\SAMIA\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Deactivate ~ Démarrage du système: Normal (Normal boot) Windows 7 Professional, 32-bit (Build 7600) =>.Microsoft Corporation ---\\ Navigateurs Internet (2) - 2s ~ MFIE: Mozilla Firefox 47.0.2 (x86 fr) ~ MSIE: Internet Explorer v8.0.7600.16385 ---\\ Informations sur les produits Windows (9) - 0s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK Windows Activation Technologies : KO ~ Windows Operating System - Windows(R) 7, OEM_SLP channel System Locked Preinstallation (OEM_SLP) : OK ~ Windows Partial Key : 6P6GT Windows License : OK ~ Windows Remaining Initializations Number : 3 ---\\ Surveillance de Logiciels (1) - 6s ~ Adobe Flash Player 25 NPAPI (Surveillance) ---\\ Logiciels de partage P2P (1) - 7s ~ µTorrent v3.3.0.29677 (P2P) ---\\ Informations sur le système (6) - 0s ~ Operating System: x86 Family 6 Model 37 Stepping 5, GenuineIntel ~ Operating System: 32-bit ~ Boot mode: Normal (Normal boot) Total RAM: 1955.692 MB (7% free) : ATTENTION =>Warning RAM System Restore: Activé (Enable) System drive C: has 23 GB (17%) free of 129 GB : OK =>.Disk Space ---\\ Mode de connexion au système (3) - 0s ~ Computer Name: SAMIA-PC ~ User Name: SAMIA ~ Logged in as Administrator ---\\ Enumération des unités disques (3) - 0s ~ Drive C: has 23 GB free of 129 GB (System) ~ Drive D: has 55 GB free of 104 GB ~ Drive S: has 22 GB free of 60 GB ---\\ Etat du Centre de Sécurité Windows (10) - 1s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK ---\\ Recherche particulière de fichiers génériques (50) - 20s [MD5.15BC38A7492BEFE831966ADB477CF76F] - 14/07/2009 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [2613248] =>.Microsoft Corporation [MD5.51138BEEA3E2C21EC44D0932C71762A8] - 14/07/2009 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [44544] =>.Microsoft Corporation [MD5.B5C5DCAD3899512020D135600129D665] - 14/07/2009 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [96256] =>.Microsoft Corporation [MD5.0D874F3BC751CC2198AF2E6783FB8B35] - 14/07/2009 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [977920] =>.Microsoft Corporation [MD5.8EC6A4AB12B8F3759E21F8E3A388F2CF] - 14/07/2009 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [285696] =>.Microsoft Corporation [MD5.58C94EAE54BF0C5E2B80B2E5E7744D4C] - 14/07/2009 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [193024] =>.Microsoft Corporation [MD5.6D5A49D6479EB753C7879F73A4C35E0F] - 14/07/2009 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [269824] =>.Microsoft Corporation [MD5.D8714A5FB3141F8226D16861F20C5AC4] - 30/07/2009 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [19968] =>.Microsoft Corporation [MD5.DDC040FDB01EF1712A6B13E52AFB104C] - 14/07/2009 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [338944] =>.Microsoft Corporation [MD5.338C86357871C167A96AB976519BF59E] - 14/07/2009 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [21584] =>.Microsoft Windows® [MD5.77EA11B065E0A8AB902D78145CA51E10] - 14/07/2009 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [70656] =>.Microsoft Corporation [MD5.BA6E70AA0E6091BC39DE29477D866A77] - 14/07/2009 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [108544] =>.Microsoft Corporation [MD5.8E09E52EE2E3CEB199EF3DD99CF9E3FB] - 14/07/2009 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [78336] =>.Microsoft Corporation [MD5.717A2207FD6F13AD3E664C7D5A43C7BF] - 14/07/2009 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [108544] =>.Microsoft Corporation [MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - 14/07/2009 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [80896] =>.Microsoft Corporation [MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - 14/07/2009 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [101888] =>.Microsoft Corporation [MD5.F4A054BE78AF7F410129C4B64B07DC9B] - 14/07/2009 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [123392] =>.Microsoft Corporation [MD5.DD52A733BF4CA5AF84562A5E2F963B91] - 14/07/2009 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [187904] =>.Microsoft Corporation [MD5.3795DCD21F740EE799FB7223234215AF] - 14/07/2009 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [1210432] =>.Microsoft Windows® [MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - 14/07/2009 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [79360] =>.Microsoft Corporation [MD5.D9F91EAFEC2815365CBE6D167E4E332A] - 14/07/2009 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [78848] =>.Microsoft Corporation [MD5.C5FF95883FFEF704D50C40D21CFB3AB5] - 14/07/2009 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [133120] =>.Microsoft Corporation [MD5.3E21C083B8A01CB70BA1F09303010FCE] - 14/07/2009 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [71168] =>.Microsoft Corporation [MD5.CB39E896A2A83702D1737BFD402B3542] - 14/07/2009 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [74240] =>.Microsoft Corporation [MD5.58DF9D2481A56EDDE167E51B334D44FD] - 14/07/2009 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [245328] =>.Microsoft Windows® [MD5.15BC38A7492BEFE831966ADB477CF76F] - 16/01/2017 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [317400] =>.Microsoft Corporation [MD5.51138BEEA3E2C21EC44D0932C71762A8] - 16/01/2017 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [317400] =>.Microsoft Corporation [MD5.B5C5DCAD3899512020D135600129D665] - 16/01/2017 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [317400] =>.Microsoft Corporation [MD5.0D874F3BC751CC2198AF2E6783FB8B35] - 16/01/2017 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [317400] =>.Microsoft Corporation [MD5.8EC6A4AB12B8F3759E21F8E3A388F2CF] - 16/01/2017 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [317400] =>.Microsoft Corporation [MD5.58C94EAE54BF0C5E2B80B2E5E7744D4C] - 16/01/2017 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [317400] =>.Microsoft Corporation [MD5.6D5A49D6479EB753C7879F73A4C35E0F] - 16/01/2017 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [317400] =>.Microsoft Corporation [MD5.D8714A5FB3141F8226D16861F20C5AC4] - 16/01/2017 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [317400] =>.Microsoft Corporation [MD5.DDC040FDB01EF1712A6B13E52AFB104C] - 16/01/2017 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [317400] =>.Microsoft Corporation [MD5.338C86357871C167A96AB976519BF59E] - 16/01/2017 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [317400] =>.Microsoft Windows® [MD5.77EA11B065E0A8AB902D78145CA51E10] - 16/01/2017 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [317400] =>.Microsoft Corporation [MD5.BA6E70AA0E6091BC39DE29477D866A77] - 16/01/2017 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [317400] =>.Microsoft Corporation [MD5.8E09E52EE2E3CEB199EF3DD99CF9E3FB] - 16/01/2017 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [317400] =>.Microsoft Corporation [MD5.717A2207FD6F13AD3E664C7D5A43C7BF] - 16/01/2017 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [317400] =>.Microsoft Corporation [MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - 16/01/2017 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [317400] =>.Microsoft Corporation [MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - 16/01/2017 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [317400] =>.Microsoft Corporation [MD5.F4A054BE78AF7F410129C4B64B07DC9B] - 16/01/2017 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [317400] =>.Microsoft Corporation [MD5.DD52A733BF4CA5AF84562A5E2F963B91] - 16/01/2017 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [317400] =>.Microsoft Corporation [MD5.3795DCD21F740EE799FB7223234215AF] - 16/01/2017 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [317400] =>.Microsoft Windows® [MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - 16/01/2017 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [317400] =>.Microsoft Corporation [MD5.D9F91EAFEC2815365CBE6D167E4E332A] - 16/01/2017 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [317400] =>.Microsoft Corporation [MD5.C5FF95883FFEF704D50C40D21CFB3AB5] - 16/01/2017 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [317400] =>.Microsoft Corporation [MD5.3E21C083B8A01CB70BA1F09303010FCE] - 16/01/2017 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [317400] =>.Microsoft Corporation [MD5.CB39E896A2A83702D1737BFD402B3542] - 16/01/2017 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [317400] =>.Microsoft Corporation [MD5.58DF9D2481A56EDDE167E51B334D44FD] - 16/01/2017 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [317400] =>.Microsoft Windows® ---\\ Liste des services NT non Microsoft et non désactivés (7) - 16s O23 - Service: Apple Devices Service (AppleSrv) . (...) - C:\ProgramData\Apple\Apple Application\DeviceCfg.dll (.not file.) O23 - Service: ed2k idle service (ed2kidle) . (...) - C:\Program Files\amuleC1\ed2k.exe (.not file.) =>Adware.aMULEcustom O23 - Service: (GubedZL) . (...) - C:\Program Files\Gubed\GubedZL.dll =>.Superfluous.Elex.GubZL O23 - Service: YAC Service (iSafeService) . (.Elex do Brasil Participações Ltda - iSafeSvc.) - C:\Program Files\Elex-tech\YAC\iSafeSvc.exe =>.Superfluous.Elex =>.Superfluous.Elex O23 - Service: Kyubey (Kyubey) . (...) - C:\Users\SAMIA\AppData\Roaming\Kyubey\Kyubey.exe =>PUP.Optional.CrossRider O23 - Service: (WinSAPSvc) . (.Windows - Window.) - C:\Users\SAMIA\AppData\Roaming\WinSAPSvc\WinSAP.dll =>PUP.Optional.Youndoo O23 - Service: WinSnare (WinSnare) . (.InterSect Alliance Pty Ltd - SNARE Service.) - C:\Users\SAMIA\AppData\Roaming\WinSnare\WinSnare.dll =>.Superfluous.WinSnare ---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (55) - 264s SS - Disabl [17/06/2013] [ 821048] ABBYY FineReader 11 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.11.0) . (.ABBYY InfoPoisk LLC.) - C:\Program Files\ABBYY FineReader 11\NetworkLicenseServer.exe =>.ABBYY PRODUCTION LLC® SS - Disabl [18/03/2010] [ 113152] ArcSoft Connect Daemon (ACDaemon) . (.ArcSoft Inc..) - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe =>.ArcSoft, Inc.® SS - Disabl [19/03/2012] [ 43072] ArcSoft Exchange Service (ADExchange) . (.ArcSoft, Inc..) - C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe =>.ArcSoft, Inc.® SS - Disabl [16/03/2017] [ 271960] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated® SS - Disabl [18/11/2009] [ 87968] Andrea RT Filters Service (AERTFilters) . (.Andrea Electronics Corporation.) - C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe =>.Andrea Electronics® SS - Disabl [06/01/2011] [ 138400] Atheros Bt&Wlan Coex Agent (Atheros Bt&Wlan Coex Agent) . (.Atheros.) - C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe =>.Atheros SS - Disabl [06/01/2011] [ 56480] AtherosSvc (AtherosSvc) . (.Atheros Commnucations.) - C:\Program Files\Bluetooth Suite\adminservice.exe =>.Atheros Commnucations SS - Disabl [19/12/2016] [ 451072] Convxxxx (Convxxxx) . (...) - C:\Users\SAMIA\AppData\Roaming\ehadh\UvConverter.exe =>Adware.CornerSunshine SS - Disabl [16/03/2016] [ 236728] DeskTop DispalyName (DeskTop_F) . (.DeskTopService.) - C:\ProgramData\desktopfind\desktop154.exe =>.Adlegend Limited® SS - Disabl [09/08/2011] [ 6750056] DisplayLinkManager (DisplayLinkService) . (.DisplayLink Corp..) - C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe =>.DISPLAYLINK® SS - Disabl [17/11/2005] [ 1527900] Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) . (.MAGIX®.) - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe =>.MAGIX® SS - Disabl [16/03/2017] [ 110256] Update Service(FirefoxU) (FirefoxU) . (...) - C:\Program Files\Firefox\bin\FirefoxUpdate.exe {45A8458D05878B9FE97F9367F3956CDE} SS - Disabl [10/01/2017] [ 94768] FLService (FLService) . (.New Softwares.net.) - C:\Windows\System32\WinFLService.exe =>.NewSoftwares.net, Inc SDN. BHD.® SR - Auto [16/01/2017] [ 125952] (GubedZL) . (...) - C:\Program Files\Gubed\GubedZL.dll =>.Superfluous.Elex.GubZL SS - Disabl [23/05/2011] [ 1098296] HP Connection Manager 4 Service (hpCMSrv) . (.Hewlett-Packard Development Company L.P..) - C:\Program Files\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe =>.Hewlett-Packard Company® SS - Disabl [20/06/2012] [ 523680] hpHotkeyMonitor (hpHotkeyMonitor) . (.Hewlett-Packard Company.) - C:\Program Files\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe =>.Hewlett-Packard Company® SS - Disabl [16/05/2012] [ 997792] HP Software Framework Service (hpqwmiex) . (.Hewlett-Packard Company.) - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe =>.Hewlett-Packard Company® SR - Auto [19/08/2016] [ 131024] YAC Service (iSafeService) . (.Elex do Brasil Participações Ltda.) - C:\Program Files\Elex-tech\YAC\iSafeSvc.exe =>.Superfluous.Elex =>.Superfluous.Elex SR - Demand [13/02/2017] [ 459264] iThemes5 (iThemes5) . (...) - C:\Program Files\Common Files\Services\iThemes.dll =>Adware.Mikey SR - Auto [17/03/2017] [ 113152] Kyubey (Kyubey) . (...) - C:\Users\SAMIA\AppData\Roaming\Kyubey\Kyubey.exe =>PUP.Optional.CrossRider SS - Disabl [10/01/2017] [ 146888] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation® SS - Disabl [18/03/2016] [ 1922600] PandoraService (PanService) . (.Pandora.TV.) - C:\Program Files\PANDORA.TV\PanService\KMPService.exe {2BF6AC6C0932526A56D17EB4F2C776C5} =>.Pandora.TV SS - Disabl [14/07/2016] [ 789240] qkseeService (qkseeService) . (.Qksee Pvt Ltd..) - C:\Program Files\qksee\qkseeSvc.exe {4BC79824EA659062C37E9D47340A7EA2} =>.Superfluous.TaiwanShuiMu SS - Disabl [12/01/2012] [ 372736] RalinkRegistryWriter (RalinkRegistryWriter) . (.Ralink Technology, Corp..) - C:\Program Files\Ralink\Common\RaRegistry.exe =>.Ralink Technology, Corp. SS - Disabl [18/08/2011] [ 625728] Ralink UPnP Media Server (RaMediaServer) . (...) - C:\Program Files\Ralink\Common\RaMediaServer.exe =>.Ralink Technology Corporation® SS - Disabl [16/01/2017] [ 317400] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Updater\Updater.exe =>.Skype Software Sarl® SS - Disabl [16/01/2017] [ 317400] Updater Service for EazelBar (Updater Service for EazelBar) . (...) - C:\Program Files\EazelBar\ToolbarUpdaterService.exe SR - Auto [16/01/2017] [ 317400] (WinSAPSvc) . (.Windows.) - C:\Users\SAMIA\AppData\Roaming\WinSAPSvc\WinSAP.dll =>PUP.Optional.Youndoo SR - Auto [16/01/2017] [ 317400] WinSnare (WinSnare) . (.InterSect Alliance Pty Ltd.) - C:\Users\SAMIA\AppData\Roaming\WinSnare\WinSnare.dll =>.Superfluous.WinSnare SS - Demand [16/01/2017] [ 317400] WiseHDInfo (WiseHDInfo) . (.wisecleaner.com.) - C:\Windows\WiseHDInfo32.dll =>.Lespeed Technology Ltd.® SS - Disabl [16/01/2017] [ 317400] ABBYY FineReader 11 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.11.0) . (.ABBYY InfoPoisk LLC.) - C:\Program Files\ABBYY FineReader 11\NetworkLicenseServer.exe =>.ABBYY PRODUCTION LLC® SS - Disabl [16/01/2017] [ 317400] ArcSoft Connect Daemon (ACDaemon) . (.ArcSoft Inc..) - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe =>.ArcSoft, Inc.® SS - Disabl [16/01/2017] [ 317400] ArcSoft Exchange Service (ADExchange) . (.ArcSoft, Inc..) - C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe =>.ArcSoft, Inc.® SS - Disabl [16/01/2017] [ 317400] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated® SS - Disabl [16/01/2017] [ 317400] Andrea RT Filters Service (AERTFilters) . (.Andrea Electronics Corporation.) - C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe =>.Andrea Electronics® SS - Disabl [16/01/2017] [ 317400] Atheros Bt&Wlan Coex Agent (Atheros Bt&Wlan Coex Agent) . (.Atheros.) - C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe =>.Atheros SS - Disabl [16/01/2017] [ 317400] AtherosSvc (AtherosSvc) . (.Atheros Commnucations.) - C:\Program Files\Bluetooth Suite\adminservice.exe =>.Atheros Commnucations SS - Disabl [16/01/2017] [ 317400] Convxxxx (Convxxxx) . (...) - C:\Users\SAMIA\AppData\Roaming\ehadh\UvConverter.exe =>Adware.CornerSunshine SS - Disabl [16/01/2017] [ 317400] DeskTop DispalyName (DeskTop_F) . (.DeskTopService.) - C:\ProgramData\desktopfind\desktop154.exe =>.Adlegend Limited® SS - Disabl [16/01/2017] [ 317400] DisplayLinkManager (DisplayLinkService) . (.DisplayLink Corp..) - C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe =>.DISPLAYLINK® SS - Disabl [16/01/2017] [ 317400] Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) . (.MAGIX®.) - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe =>.MAGIX® SS - Disabl [16/01/2017] [ 317400] Update Service(FirefoxU) (FirefoxU) . (...) - C:\Program Files\Firefox\bin\FirefoxUpdate.exe {45A8458D05878B9FE97F9367F3956CDE} SS - Disabl [16/01/2017] [ 317400] FLService (FLService) . (.New Softwares.net.) - C:\Windows\System32\WinFLService.exe =>.NewSoftwares.net, Inc SDN. BHD.® SR - Auto [16/01/2017] [ 317400] (GubedZL) . (...) - C:\Program Files\Gubed\GubedZL.dll =>.Superfluous.Elex.GubZL SS - Disabl [16/01/2017] [ 317400] HP Connection Manager 4 Service (hpCMSrv) . (.Hewlett-Packard Development Company L.P..) - C:\Program Files\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe =>.Hewlett-Packard Company® SS - Disabl [16/01/2017] [ 317400] hpHotkeyMonitor (hpHotkeyMonitor) . (.Hewlett-Packard Company.) - C:\Program Files\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe =>.Hewlett-Packard Company® SS - Disabl [16/01/2017] [ 317400] HP Software Framework Service (hpqwmiex) . (.Hewlett-Packard Company.) - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe =>.Hewlett-Packard Company® SR - Auto [16/01/2017] [ 317400] YAC Service (iSafeService) . (.Elex do Brasil Participações Ltda.) - C:\Program Files\Elex-tech\YAC\iSafeSvc.exe =>.Superfluous.Elex =>.Superfluous.Elex SR - Demand [16/01/2017] [ 317400] iThemes5 (iThemes5) . (...) - C:\Program Files\Common Files\Services\iThemes.dll =>Adware.Mikey SR - Auto [16/01/2017] [ 317400] Kyubey (Kyubey) . (...) - C:\Users\SAMIA\AppData\Roaming\Kyubey\Kyubey.exe =>PUP.Optional.CrossRider SS - Disabl [16/01/2017] [ 317400] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation® SS - Disabl [16/01/2017] [ 317400] PandoraService (PanService) . (.Pandora.TV.) - C:\Program Files\PANDORA.TV\PanService\KMPService.exe {2BF6AC6C0932526A56D17EB4F2C776C5} =>.Pandora.TV SS - Disabl [16/01/2017] [ 317400] qkseeService (qkseeService) . (.Qksee Pvt Ltd..) - C:\Program Files\qksee\qkseeSvc.exe {4BC79824EA659062C37E9D47340A7EA2} =>.Superfluous.TaiwanShuiMu SS - Disabl [16/01/2017] [ 317400] RalinkRegistryWriter (RalinkRegistryWriter) . (.Ralink Technology, Corp..) - C:\Program Files\Ralink\Common\RaRegistry.exe =>.Ralink Technology, Corp. SS - Disabl [16/01/2017] [ 317400] Ralink UPnP Media Server (RaMediaServer) . (...) - C:\Program Files\Ralink\Common\RaMediaServer.exe =>.Ralink Technology Corporation® ---\\ Tâches planifiées en automatique (37) - 29s O39 - APT: Unknown - (.Facebook.) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-635114891-1663833559-3594687183-1000Core.job [317400] =>.Facebook O39 - APT: Unknown - (...) -- C:\Windows\Tasks\Wise Care 365.job [317400] O39 - APT: Unknown - (...) -- C:\Windows\Tasks\Wise Turbo Checker.job [317400] O39 - APT: Unknown - (.Adobe Inc..) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [317400] =>.Adobe Inc. O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\Browser Updater Task(Core) [317400] =>Adware.Suspect O39 - APT: Unknown - (.Legitimate.) -- C:\Windows\System32\Tasks\ESTsoft RunAsStdUser 8592113Task [317400] O39 - APT: Unknown - (.Facebook.) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-635114891-1663833559-3594687183-1000Core [317400] =>.Facebook O39 - APT: Unknown - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-635114891-1663833559-3594687183-1000Core [317400] =>.Google Inc. O39 - APT: Unknown - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-635114891-1663833559-3594687183-1000UA [317400] =>.Google Inc. O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\Milimili [317400] O39 - APT: Unknown - (.Microsoft Corporation.) -- C:\Windows\System32\Tasks\SidebarExecute [317400] =>.Microsoft Corporation O39 - APT: Unknown - (.Unknow.) -- C:\Windows\System32\Tasks\WinTOOL [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\Wise Care 365 [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\Wise Turbo Checker [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{0CE6150A-5097-4DC4-8AF8-FB4D5BA0053E} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{560987BC-A363-4B9C-85F1-31E533505213} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{618D5AB7-E0DC-460D-B4B1-42CA7EA0F117} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{694995E0-ABB7-4263-9393-FDAABD39B39E} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{728C0936-7981-4963-A611-180BCE92D3FF} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{7A89CC97-0319-481C-8B32-401258632154} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{7BF54B40-2E46-4150-80BD-15B686104BF0} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{7DC51881-F05D-41CC-8B54-22BAAB1FDF5C} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{8251BCF8-8099-40F2-B9BF-0486E0848C07} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{84E4A694-6346-4F7F-8ED8-8304B2A64F4B} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{8AC7BE81-767D-4CDB-8857-F56425FADDF6} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{93067F04-082F-4C9F-94D2-93E97C14A7F0} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{93F89FFB-EE6C-4936-85ED-669FDA2C511E} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{9DCB1D24-74A5-4829-89E2-138B86236E85} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{AB5B47E9-9086-4C31-8C55-7E4FB658FA4E} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{AE42E2E5-6561-4BAA-872F-2037FD3E8649} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{AE606BBB-0825-46A5-B3E7-5553B4F7CD31} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{B311F66A-D454-4CBA-A049-C0BFB3E913A7} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{BB9CE8ED-B386-444C-9A24-C85F14002E7D} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{C82DF981-CBB8-439B-A892-DBAED35D67E0} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{DC972A52-DD6D-4335-9683-6DE3C3CFCF3F} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{F0ACC36E-78FE-4084-B3A1-2D69DFD316BC} [317400] O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{F4102D0A-3FC8-41FA-976E-408350D1ACD5} [317400] ---\\ Applications lancées au démarrage du système (13) - 1s O4 - HKLM\..\Run: [HPOSD] . (.Hewlett-Packard Development Company, L.P. - HP On Screen Display.) -- C:\Program Files\Hewlett-Packard\HP On Screen Display\HPOSD.exe =>.Hewlett-Packard Company® O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe =>.Realtek Semiconductor Corp® O4 - HKLM\..\Run: [AthBtTray] . (.Atheros Commnucations - Bluetooth Suite Common Rescource.) -- C:\Program Files\Bluetooth Suite\AthBtTray.exe =>.Atheros Commnucations O4 - HKCU\..\Run: [WinFLTray] . (.New Softwares.net - Folder Lock.) -- C:\Windows\System32\WinFLTray.exe =>.NewSoftwares.net, Inc SDN. BHD.® O4 - HKCU\..\Run: [FLBackup] C:\Program Files\NewSoftware's\Folder Lock\FLComServCtrl.exe (.not file.) O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe =>.Tonec Inc. O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-635114891-1663833559-3594687183-1000\..\Run: [WinFLTray] . (.New Softwares.net - Folder Lock.) -- C:\Windows\System32\WinFLTray.exe =>.NewSoftwares.net, Inc SDN. BHD.® O4 - HKUS\S-1-5-21-635114891-1663833559-3594687183-1000\..\Run: [FLBackup] C:\Program Files\NewSoftware's\Folder Lock\FLComServCtrl.exe (.not file.) O4 - HKUS\S-1-5-21-635114891-1663833559-3594687183-1000\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe =>.Tonec Inc. ---\\ Processus lancés (30) - 6s [MD5.A538AB8CC647D3C67C628805083FBFF8] - (.Elex do Brasil Participações Ltda - iSafeSvc.) -- C:\Program Files\Elex-tech\YAC\iSafeSvc.exe [131024] [PID.1040] =>.Superfluous.Elex [MD5.EBA35D35628CEB8ACAA2302F9698A8D0] - (.Elex do Brasil Participações Ltda - iSafeSvc2.) -- C:\Program Files\Elex-tech\YAC\iSafeSvc2.exe [131024] [PID.1100] =>.Superfluous.Elex [MD5.C72865DE00C0B7E4B4C3DEBCB347FC36] - (.AVAST Software - Avast Settings Backup.) -- C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [797264] [PID.796] =>.AVAST Software s.r.o.® [MD5.5DF50035AE8E50C89D22494CCAE77B34] - (...) -- C:\Users\SAMIA\AppData\Roaming\Kyubey\Kyubey.exe [113152] [PID.1728] =>PUP.Optional.CrossRider [MD5.41B6C3A0388A7A3F2791291A861E8D0C] - (.Elex do Brasil Participações Ltda - YACTray.) -- C:\Program Files\Elex-tech\YAC\iSafeTray.exe [427000] [PID.2828] =>.Superfluous.Elex [MD5.8A3B69683E63808719D24E1C68C21CC7] - (.Hewlett-Packard Development Company, L.P. - HP On Screen Display.) -- C:\Program Files\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960] [PID.3896] =>.Hewlett-Packard Company® [MD5.53239ADD6E16C0E38D649D1B3705AC73] - (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe [6253160] [PID.3924] =>.Realtek Semiconductor Corp® [MD5.D31AAE4CEFF63566506A837305A9DDEA] - (.Atheros Commnucations - Bluetooth Suite Common Rescource.) -- C:\Program Files\Bluetooth Suite\AthBtTray.exe [302240] [PID.3936] =>.Atheros Commnucations [MD5.01EB118D88553BF51929542D65C1ECD0] - (.New Softwares.net - Folder Lock.) -- C:\Windows\System32\WinFLTray.exe [336432] [PID.1012] =>.NewSoftwares.net, Inc SDN. BHD.® [MD5.1C81E83FD611CC82291AE3CBFFC43112] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe [3997752] [PID.2300] =>.Tonec Inc. [MD5.B289C20C10B241F6016FECD92B267098] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe [275512] [PID.3360] =>.Tonec Inc.® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.5208] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.5232] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.5288] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.5756] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.5988] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.5996] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.6004] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.6012] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.7640] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.4380] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.8028] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.3100] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.5464] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.6240] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.2796] =>.Google Inc® [MD5.D81E507C4C6F04A38EB71056AD449D1E] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\SAMIA\Desktop\ZHPDiag3.exe [2709504] [PID.7200] =>.Nicolas Coolman [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.7568] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.4364] =>.Google Inc® [MD5.38372AA4CC9FBD0EB7A26FC7B5F24562] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe [945496] [PID.8144] =>.Google Inc® ---\\ Google Chrome, Démarrage,Recherche,Extensions (5) - 2s G2 - GCE: Preference [User Data\Default] [dlfienamagdnkekbbbocojppncdambda] [http://www.predictad.com/update/chrome/?si=9580&ve] Complitly plugin for chrome =>Hijacker.Browser G2 - GCE: Preference [User Data\Default] [lifbcibllhkdhoafpjfnlhfpfgnpldfl] Skype =>.Skype Technologies G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [ooepecapjfnpoblcjpgibomhcnlgbnbj] [http://update.toolbar.widdit.com/chrome/?si=39030&] NetScout Toolbar =>Hijacker.Browser G2 - GCE: Preference [User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc. ---\\ Comodo Dragon, Démarrage,Recherche,Extensions (1) - 0s C2 - CDE: Preference [User Data\Default] [fmbdpmllpkfodckedbomjbbehcbjnlon] suaffewueb =>PUP.Optional.SafeWeb ---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (5) - 11s M0 - MFSP: prefs.js [SAMIA - 8nlychy6.default-1467880386418] http://www.nicesearches.com?type=hp&ts=1476214798&from=3a211011&uid=st320lt020-9yg142_w04391e8&z=921bec3f81a7191f0e6a7e7g7z1m5qaodg3z2m4teb P2 - EXT FILE: (.Firefox Hotfix - Firefox Hotfix: avoid updates that wou.) -- C:\Users\SAMIA\AppData\Roaming\Mozilla\Firefox\Profiles\8nlychy6.default-1467880386418\extensions\firefox-hotfix@mozilla.org.xpi =>.Firefox Hotfix P2 - EXT FILE: (.Adblock Plus - Ads were yesterday!.) -- C:\Users\SAMIA\AppData\Roaming\Mozilla\Firefox\Profiles\8nlychy6.default-1467880386418\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Adblock Plus P2 - EXT FILE: (.nuesearch - nuesearch Search.) -- C:\Users\SAMIA\AppData\Roaming\Mozilla\Firefox\Profiles\8nlychy6.default-1467880386418\searchplugins\nuesearch.xml =>Hijacker.Browser P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\NPSWF32_25_0_0_127.dll =>.Adobe Systems Incorporated ---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (12) - 2s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.nuesearch.com/ =>Hijacker.Browser R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.nuesearch.com/ =>Hijacker.Browser R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.nuesearch.com/ =>Hijacker.Browser R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nuesearch.com/ =>Hijacker.Browser R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nuesearch.com/ =>Hijacker.Browser R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ =>.Google Inc. R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ =>.Google Inc. R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ =>.Google Inc. R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = http://en.eazel.com/ R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} Orphan =>.Superfluous.Orphan R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} Orphan =>.Superfluous.Orphan R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer ---\\ Internet Explorer,Proxy Management (5) - 0s R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft ---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=C:\Windows\system32\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation ---\\ Etude du fichier hosts (1) - 1s ~ Le fichier hôte est sain (The hosts file is clean) (46) ---\\ Browser Helper Object de navigateur (BHO) (10) - 1s O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files\Internet Download Manager\IDMIECC.dll =>.Tonec Inc.® O2 - BHO: Complitly - {0FB6A909-6086-458F-BD92-1F8EE10042A0} . (.SimplyGen - Complitly - Helps you search the web.) -- C:\Users\SAMIA\AppData\Roaming\Complitly\Complitly.dll {637C1CA85BD9CFDF391BEA85B27078DD} =>PUP.Optional.PredictAd O2 - BHO: KMP Media Toolbar BHO - {4B4D5056-3700-A76A-76A7-7A786E7484D7} (.Orphan.) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre7\bin\ssv.dll =>.Oracle America, Inc.® O2 - BHO: NetScout Toolbar - {7bb92ae5-1774-4fa5-9d16-1245f2c19011} . (.Simplytech Ltd. - Simplytech toolbar.) -- C:\Users\SAMIA\AppData\Roaming\NetScoutToolbar\NetScoutToolbar.dll =>.Superfluous.SimplyTech O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} . (.Atheros Commnucations - Bluetooth IE PlugIn.) -- C:\Program Files\Bluetooth Suite\IEPlugIn.dll =>.Atheros Commnucations O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} . (.Ask.com - Ask.com Search Assistant.) -- C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL =>Toolbar.Ask O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre7\bin\jp2ssv.dll =>.Oracle America, Inc.® O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} (.Orphan.) =>Toolbar.AskTBar O2 - BHO: EazelBar Helper - {FE478DC2-E4AD-4197-8F80-5E456BEBC57F} . (.2011(c) - Toolbar.) -- C:\Program Files\EazelBar\Toolbar32.dll ---\\ Internet Explorer, Barre d'outil (6) - 2s O3 - Toolbar: 0x56504D4B00376AA776A77A786E7484D7 - [HKCU]{4B4D5056-3700-A76A-76A7-7A786E7484D7} . (...) -- (.not file.) O3 - Toolbar: 0xB93D06FEC04E3E408DD8394C54984B2C - [HKCU]{FE063DB9-4EC0-403E-8DD8-394C54984B2C} . (...) -- (.not file.) O3 - Toolbar: EazelBar - [HKLM]{EBD839AE-B08C-4fb7-859B-F54AF16C159F} . (.2011(c) - Toolbar.) -- C:\Program Files\EazelBar\Toolbar32.dll O3 - Toolbar: (no name) - [HKLM]{7bb92ae5-1774-4fa5-9d16-1245f2c19011} (.Orphan.) O3 - Toolbar: (no name) - [HKLM]{FE063DB9-4EC0-403e-8DD8-394C54984B2C} (.Orphan.) (.not file.) O3 - Toolbar: (no name) - [HKLM]{4B4D5056-3700-A76A-76A7-7A786E7484D7} (.Orphan.) (.not file.) ---\\ Raccourcis Global Startup (96) - 66s O4 - GS\Desktop [Administrateur]: Arrêter.lnk . (.Microsoft Corporation - Outil d’arrêt et d’annotation Windows.) C:\Windows\System32\shutdown.exe -s -t 00 -f =>.Microsoft Corporation O4 - GS\Desktop [Administrateur]: Format Factory.lnk . (.Free Time - FormatFactory.) C:\Program Files\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time O4 - GS\Desktop [Administrateur]: GIC 2.1.lnk . (.Agence Nationale du Cadastre - .) D:\GIC 2.1.exe O4 - GS\Desktop [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Hipmy\Application\chrome.exe =>.Google Inc® O4 - GS\Desktop [Administrateur]: Microsoft Office Word 2007.lnk . (...) C:\Windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe =>.Microsoft Corporation® O4 - GS\Desktop [Administrateur]: Your Unin-staller!.lnk . (.URSoft,Inc - Your Uninstaller! - New way to uninstall pr.) C:\Program Files\Your Uninstaller! 7\urmain.exe =>.URSoft, Inc.® O4 - GS\Desktop [Administrateur]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\SAMIA\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Administrateur]: Citybus.lnk . (...) C:\Program Files\MyPlayCity.com\Citybus\Citybus.exe O4 - GS\Quicklaunch [Administrateur]: Foxit Reader 5.1.lnk . (...) C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader.exe =>.Foxit Corporation® O4 - GS\Quicklaunch [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Hipmy\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Administrateur]: Gourmania.lnk . (...) C:\Program Files\MyPlayCity.com\Gourmania\Gourmania.exe O4 - GS\Quicklaunch [Administrateur]: Launch Internet Explorer Browser.lnk . (...) C:\Program Files\Internet Explorer\iexplore.exe http://www.mylucky123.com/ =>Hijacker.MyLucky123 O4 - GS\Quicklaunch [Administrateur]: Matchmaker - Joining Hearts.lnk . (...) C:\Program Files\MyPlayCity.com\Matchmaker - Joining Hearts\Matchmaker - Joining Hearts.exe O4 - GS\Quicklaunch [Administrateur]: Nero Express.lnk . (.Nero AG - Nero Burning ROM.) C:\Program Files\Nero\Nero Core\nero.exe /w =>.Nero AG O4 - GS\Quicklaunch [Administrateur]: Pageant Princess.lnk . (...) C:\Program Files\MyPlayCity.com\Pageant Princess\Pageant Princess.exe O4 - GS\Quicklaunch [Administrateur]: uTorrent Turbo Accelerator.lnk . (.WebSpeeders LLC - uTorrent Turbo Accelerator.) C:\Program Files\uTorrent Turbo Accelerator\uTorrent Turbo Accelerator.exe O4 - GS\Quicklaunch [Administrateur]: uTorrent Turbo Booster.lnk . (.DownloadBoosters LLC - uTorrent Turbo Booster.) C:\Program Files\uTorrent Turbo Booster\uTorrent Turbo Booster.exe O4 - GS\sendTo [Administrateur]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\sendTo [Administrateur]: Format Factory.lnk . (.Free Time - FormatFactory.) C:\Program Files\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time O4 - GS\sendTo [Administrateur]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Phone\Skype.exe /sendto: =>.Skype Software Sarl® O4 - GS\TaskBar [Administrateur]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files\Internet Download Manager\IDMan.exe =>.Tonec Inc. O4 - GS\TaskBar [Administrateur]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Firefox\Firefox.exe http://www.mylucky123.com/ =>Hijacker.MyLucky123 O4 - GS\TaskBar [Administrateur]: On-Screen Keyboard.lnk . (.Microsoft Corporation - Accessibilité au Clavier visuel.) C:\Windows\system32\osk.exe =>.Microsoft Corporation O4 - GS\TaskBar [Administrateur]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation O4 - GS\Programs [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Hipmy\Application\chrome.exe =>.Google Inc® O4 - GS\Programs [Administrateur]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Explorer\iexplore.exe http://www.mylucky123.com/ =>Hijacker.MyLucky123 O4 - GS\Desktop [SAMIA]: Arrêter.lnk . (.Microsoft Corporation - Outil d’arrêt et d’annotation Windows.) C:\Windows\System32\shutdown.exe -s -t 00 -f =>.Microsoft Corporation O4 - GS\Desktop [SAMIA]: Format Factory.lnk . (.Free Time - FormatFactory.) C:\Program Files\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time O4 - GS\Desktop [SAMIA]: GIC 2.1.lnk . (.Agence Nationale du Cadastre - .) D:\GIC 2.1.exe O4 - GS\Desktop [SAMIA]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Hipmy\Application\chrome.exe =>.Google Inc® O4 - GS\Desktop [SAMIA]: Microsoft Office Word 2007.lnk . (...) C:\Windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe =>.Microsoft Corporation® O4 - GS\Desktop [SAMIA]: Your Unin-staller!.lnk . (.URSoft,Inc - Your Uninstaller! - New way to uninstall pr.) C:\Program Files\Your Uninstaller! 7\urmain.exe =>.URSoft, Inc.® O4 - GS\Desktop [SAMIA]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\SAMIA\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [SAMIA]: Citybus.lnk . (...) C:\Program Files\MyPlayCity.com\Citybus\Citybus.exe O4 - GS\Quicklaunch [SAMIA]: Foxit Reader 5.1.lnk . (...) C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader.exe =>.Foxit Corporation® O4 - GS\Quicklaunch [SAMIA]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Hipmy\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [SAMIA]: Gourmania.lnk . (...) C:\Program Files\MyPlayCity.com\Gourmania\Gourmania.exe O4 - GS\Quicklaunch [SAMIA]: Launch Internet Explorer Browser.lnk . (...) C:\Program Files\Internet Explorer\iexplore.exe http://www.mylucky123.com/ =>Hijacker.MyLucky123 O4 - GS\Quicklaunch [SAMIA]: Matchmaker - Joining Hearts.lnk . (...) C:\Program Files\MyPlayCity.com\Matchmaker - Joining Hearts\Matchmaker - Joining Hearts.exe O4 - GS\Quicklaunch [SAMIA]: Nero Express.lnk . (.Nero AG - Nero Burning ROM.) C:\Program Files\Nero\Nero Core\nero.exe /w =>.Nero AG O4 - GS\Quicklaunch [SAMIA]: Pageant Princess.lnk . (...) C:\Program Files\MyPlayCity.com\Pageant Princess\Pageant Princess.exe O4 - GS\Quicklaunch [SAMIA]: uTorrent Turbo Accelerator.lnk . (.WebSpeeders LLC - uTorrent Turbo Accelerator.) C:\Program Files\uTorrent Turbo Accelerator\uTorrent Turbo Accelerator.exe O4 - GS\Quicklaunch [SAMIA]: uTorrent Turbo Booster.lnk . (.DownloadBoosters LLC - uTorrent Turbo Booster.) C:\Program Files\uTorrent Turbo Booster\uTorrent Turbo Booster.exe O4 - GS\sendTo [SAMIA]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\sendTo [SAMIA]: Format Factory.lnk . (.Free Time - FormatFactory.) C:\Program Files\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time O4 - GS\sendTo [SAMIA]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Phone\Skype.exe /sendto: =>.Skype Software Sarl® O4 - GS\TaskBar [SAMIA]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files\Internet Download Manager\IDMan.exe =>.Tonec Inc. O4 - GS\TaskBar [SAMIA]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Firefox\Firefox.exe http://www.mylucky123.com/ =>Hijacker.MyLucky123 O4 - GS\TaskBar [SAMIA]: On-Screen Keyboard.lnk . (.Microsoft Corporation - Accessibilité au Clavier visuel.) C:\Windows\system32\osk.exe =>.Microsoft Corporation O4 - GS\TaskBar [SAMIA]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation O4 - GS\Programs [SAMIA]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Hipmy\Application\chrome.exe =>.Google Inc® O4 - GS\Programs [SAMIA]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Explorer\iexplore.exe http://www.mylucky123.com/ =>Hijacker.MyLucky123 O4 - GS\CommonDesktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Firefox\Firefox.exe http://www.mylucky123.com/ =>Hijacker.MyLucky123 O4 - GS\CommonDesktop [Public]: PdfGrabber 7.0.lnk . (.PixelPlanet - .) C:\Program Files\PixelPlanet\PdfGrabber 7.0\PdfGrabber.exe -LANGID 1033 =>.PixelPlanet O4 - GS\CommonDesktop [Public]: WebCam Companion 3.lnk . (.ArcSoft Inc. - ArcSoft WebCam Companion.) C:\Program Files\ArcSoft\WebCam Companion 3\uWebCam.exe =>.ArcSoft, Inc.® O4 - GS\CommonDesktop [Public]: WebcamMax.lnk . (.CoolwareMax - WebcamMax.) C:\Program Files\WebcamMax\WebcamMax.exe =>.CoolwareMax O4 - GS\Programs [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Hipmy\Application\chrome.exe =>.Google Inc® O4 - GS\Programs [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Explorer\iexplore.exe http://www.mylucky123.com/ =>Hijacker.MyLucky123 O4 - GS\Accessories [Public]: Command Prompt.lnk . (.Microsoft Corporation - Interpréteur de commandes Windows.) C:\Windows\system32\cmd.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Internet Explorer (No Add-ons).lnk . (...) C:\Program Files\Internet Explorer\iexplore.exe http://www.nuesearch.com/ =>Hijacker.Browser O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - Éditeur de caractères privés.) C:\Windows\system32\eudcedit.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Bluetooth File Transfer Wizard.lnk . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Calculatrice de Windows.) C:\Windows\system32\calc.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Afficher le commutateur.) C:\Windows\system32\displayswitch.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Accessoire du panneau de saisie mathématiqu.) C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Centre de mobilité Windows.) C:\Windows\system32\mblctr.exe /open =>.Microsoft Corporation O4 - GS\Accessories [Public]: NetworkProjection.lnk . (.Microsoft Corporation - Connect to a Network Projector.) C:\Windows\system32\NetProj.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Magnétophone Windows.) C:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Pense-bête.) C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) C:\Windows\System32\mobsync.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\system32\rundll32.exe %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut =>.Microsoft Corporation O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Application Windows Wordpad.) C:\Program Files\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Table des caractères.) C:\Windows\system32\charmap.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Défragmenteur de disque Microsoft®.) C:\Windows\system32\dfrgui.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Gestionnaire de nettoyage de disque pour Wi.) C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Moniteur de ressources et de performances.) C:\Windows\system32\perfmon.exe /res =>.Microsoft Corporation O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - Informations système.) C:\Windows\system32\msinfo32.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Restauration du système de Microsoft® Windo.) C:\Windows\system32\rstrui.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\Windows\system32\taskschd.msc /s =>..Microsoft Corporation O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Application post-migration de transfert de.) C:\Windows\system32\migwiz\postmig.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Application Transfert de fichiers et paramè.) C:\Windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Hipmy\Application\chrome.exe http://www.mylucky123.com/ =>Hijacker.MyLucky123 O4 - GS\ProgramsCommon [Public]: Media Center.lnk . (.Microsoft Corporation - Windows Media Center.) C:\Windows\ehome\ehshell.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Firefox\Firefox.exe =>.Mengmeng Wang® O4 - GS\ProgramsCommon [Public]: Sidebar.lnk . (.Microsoft Corporation - Gadgets du Bureau Windows.) C:\Program Files\Windows Sidebar\sidebar.exe /showgadgets =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Windows Anytime Upgrade.lnk . (.Microsoft Corporation - Interface utilisateur de Mise à niveau expr.) C:\Windows\system32\WindowsAnytimeUpgradeUI.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Windows DVD Maker.lnk . (.Microsoft Corporation - Création de DVD Windows.) C:\Program Files\DVD Maker\DVDMaker.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Windows Movie Maker 2.6.lnk . (.Microsoft Corporation - Windows Movie Maker.) C:\Windows\Installer\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}\MOVIEMK.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: XPS Viewer.lnk . (.Microsoft Corporation - Visionneuse XPS.) C:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation ---\\ Modification Domaine/Adresses DNS (2) - 1s O17 - HKLM\System\CCS\Services\Tcpip\..\{927246CB-5465-4EFD-96FE-13C846FA57EE}: NameServer = 208.67.222.222,208.67.220.220 =>.OpenDNS DNS O17 - HKLM\System\CCS\Services\Tcpip\..\{F47E92EF-878E-47F0-926F-921D64027441}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress ---\\ Protocole additionnel (24) - 2s O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation® O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL =>.Microsoft Corporation® ---\\ Clés de registre d'extension image (7) - 1s [HKEY_CLASSES_ROOT\.bmp]""="qkseeViewer.bmp" =>.Superfluous.TaiwanShuiMu [HKEY_CLASSES_ROOT\.gif]""="qkseeViewer.gif" =>.Superfluous.TaiwanShuiMu [HKEY_CLASSES_ROOT\.ico]""="qkseeViewer.ico" =>.Superfluous.TaiwanShuiMu [HKEY_CLASSES_ROOT\.jpe]""="qkseeViewer.jpg" =>.Superfluous.TaiwanShuiMu [HKEY_CLASSES_ROOT\.png]""="qkseeViewer.png" =>.Superfluous.TaiwanShuiMu [HKEY_CLASSES_ROOT\.tif]""="qkseeViewer.tif" =>.Superfluous.TaiwanShuiMu [HKEY_CLASSES_ROOT\.tiff]""="qkseeViewer.tif" =>.Superfluous.TaiwanShuiMu ---\\ Logiciels installés (73) - 305s O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKLM] -- uTorrent =>.BitTorrent Inc® O42 - Logiciel: 7-Zip 16.02 - (.Igor Pavlov.) [HKLM] -- {23170F69-40C1-2701-1602-000001000000} =>.Igor Pavlov O42 - Logiciel: Adobe Flash Player 25 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Flash Player 25 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated® O42 - Logiciel: amuleC - (.amuleC.) [HKLM] -- {19539992-061C-4E8B-9053-07B175303AF4} =>Adware.aMULEcustom O42 - Logiciel: amulesw - (.amules.) [HKLM] -- {13D7C2E9-08E7-4889-94FF-87E707184E53} O42 - Logiciel: ArcSoft Perfect365 - (.ArcSoft, Inc..) [HKLM] -- {5B5E949E-3924-45E3-9229-84E8270BED68} =>.ArcSoft, Inc. O42 - Logiciel: Atheros Driver Installation Program - (.Atheros.) [HKLM] -- {C3A32068-8AB1-4327-BB16-BED9C6219DC7} =>.Atheros O42 - Logiciel: Chicken Invaders 4 - Ultimate Omelette version 4.00ra - (.My Company, Inc..) [HKLM] -- {A4AD4CBF-D102-49FA-BE8D-0C233106994B}_is1 O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM] -- {64BF0187-F3D2-498B-99EA-163AF9AE6EC9} =>.Cisco Systems, Inc. O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {51C7AD07-C3F6-4635-8E8A-231306D810FE} =>.Cisco Systems, Inc. O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {ED5776D5-59B4-46B7-AF81-5F2D94D7C640} =>.Cisco Systems, Inc. O42 - Logiciel: Citybus - (.MyPlayCity, Inc..) [HKLM] -- Citybus_is1 =>.MyPlayCity, Inc. O42 - Logiciel: Complitly - (.Complitly.) [HKLM] -- {4FFBB818-B13C-11E0-931D-B2664824019B}_is1 =>PUP.Optional.PredictAd O42 - Logiciel: deskapp - (.deskapp.) [HKLM] -- {7DBE4CA5-2DEE-4B98-A137-7D3D4F7E31B1} O42 - Logiciel: doPDF 7.3 printer - (.Softland.) [HKLM] -- doPDF 7 printer_is1 =>.Softland S.R.L.® O42 - Logiciel: EazelBar - (.EazelBar.) [HKLM] -- EazelBar O42 - Logiciel: Facebook Video Calling 3.1.0.521 - (.Skype Limited.) [HKLM] -- {2091F234-EB58-4B80-8C96-8EB78C808CF7} =>.Skype Limited O42 - Logiciel: Firebird SQL Server - MAGIX Edition - (.MAGIX AG.) [HKLM] -- Firebird SQL Server UK =>.Magix AG® O42 - Logiciel: FormatFactory 3.00 - (.Free Time.) [HKLM] -- FormatFactory =>.Free Time O42 - Logiciel: Foxit Reader 5.1 - (.Foxit Corporation.) [HKLM] -- Foxit Reader_is1 =>.Foxit Corporation® O42 - Logiciel: Google Chrome - (.Google Inc..) [HKCU] -- Google Chrome =>.Google Inc® O42 - Logiciel: Gourmania - (.MyPlayCity, Inc..) [HKLM] -- Gourmania_is1 =>.MyPlayCity, Inc. O42 - Logiciel: HP On Screen Display - (.Hewlett-Packard Company.) [HKLM] -- {ED1BD69A-07E3-418C-91F1-D856582581BF} =>.Hewlett-Packard Company O42 - Logiciel: HP Webcam - (.Roxio.) [HKLM] -- {1D61E881-43CD-447B-9E6B-D2C6138B2862} =>.Sonic Solutions® O42 - Logiciel: HSPA USB Modem - (.HSPA.) [HKLM] -- InstallShield_{06ADE2A0-E46A-4A84-A211-64CF50520185} =>.HSPA O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel Corporation® O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM] -- Internet Download Manager =>.Tonec Inc.® O42 - Logiciel: Java Auto Updater - (.Sun Microsystems, Inc..) [HKLM] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Sun Microsystems, Inc. O42 - Logiciel: Java(TM) SE Runtime Environment 6 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160000} =>.Sun Microsystems, Inc. O42 - Logiciel: K-Lite Codec Pack 7.5.0 (Full) - (.KLite Inc.) [HKLM] -- KLiteCodecPack_is1 =>.KLite Inc O42 - Logiciel: KMP Media Toolbar - (.APN, LLC.) [HKLM] -- {4B4D5056-3700-A76A-76A7-A758B70C0A00} =>Adware.Bandoo O42 - Logiciel: KMP Service - (.KMP.) [HKLM] -- 4F6D5E84-5826-4394-9F40-3A9A19165651_is1 O42 - Logiciel: l'application GIC (Gestion de l'Information Cadastrale) - (..) [HKLM] -- ST6UNST #1 O42 - Logiciel: LAV Filters 0.55.3 - (.Hendrik Leppkes.) [HKLM] -- lavfilters_is1 =>.Hendrik Leppkes O42 - Logiciel: MAGIX 3D Maker (embeded) - (.MAGIX AG.) [HKLM] -- MAGIX 3D Maker UK =>.Magix AG® O42 - Logiciel: MAGIX Movie Edit Pro 15 Plus Download version 8.0.5.8 (UK) - (.MAGIX AG.) [HKLM] -- MAGIX Movie Edit Pro 15 Plus Download version UK =>.Magix AG® O42 - Logiciel: MAGIX Screenshare 4.3.6.1987 (UK) - (.MAGIX AG.) [HKLM] -- MAGIX Screenshare UK =>.Magix AG® O42 - Logiciel: Matchmaker - Joining Hearts - (.GamesPub Ltd..) [HKLM] -- Matchmaker - Joining Hearts_is1 O42 - Logiciel: Media Player Classic - Home Cinema v1.4.2499.0 - (.MPC-HC Team.) [HKLM] -- {2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1 =>.MPC-HC Team O42 - Logiciel: Microsoft XML Parser - (.Microsoft Corporation.) [HKLM] -- {C7340571-7773-4A8C-9EBC-4E4243B38C76} =>.Microsoft Corporation O42 - Logiciel: Mozilla Firefox 47.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 47.0.2 (x86 fr) =>.Mozilla Corporation® O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService =>.Mozilla O42 - Logiciel: MpcStar 4.2 - (.www.mpcstar.com.) [HKLM] -- MpcStar =>.www.mpcstar.com O42 - Logiciel: MSXML 4.0 SP3 Parser - (.Microsoft Corporation.) [HKLM] -- {196467F1-C11F-4F76-858B-5812ADC83B94} =>.Microsoft Corporation O42 - Logiciel: Nero 8 Micro v8.0.3.0 - (.www.nero.com.) [HKLM] -- Nero8030_Micro_is1 O42 - Logiciel: neroxml - (.Nero AG.) [HKLM] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B} =>.Nero AG O42 - Logiciel: NetScout Toolbar 2.1 - (.NetScout Toolbar.) [HKLM] -- {3147d692-3d9d-4f1a-8f44-d6d68554d532}_is1 O42 - Logiciel: Pageant Princess - (.MyPlayCity, Inc..) [HKLM] -- Pageant Princess_is1 =>.MyPlayCity, Inc. O42 - Logiciel: PdfGrabber 7.0 (32bit) - (.PixelPlanet.) [HKLM] -- {01517A48-9217-431B-821C-F89F53918E3D} =>.PixelPlanet O42 - Logiciel: PixelPlanet PdfPrinter 6 (32bit) - (.PixelPlanet.) [HKLM] -- {B8E88489-A304-45F1-9717-242035DE167D} =>.PixelPlanet O42 - Logiciel: qksee - (.Taiwan Shui Mu Chih Ching Technology Limited.) [HKLM] -- qksee {4BC79824EA659062C37E9D47340A7EA2} =>.Superfluous.TaiwanShuiMu O42 - Logiciel: Ralink RT2870 Wireless LAN Card - (.Ralink.) [HKLM] -- {28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D} =>.Ralink Technology Corporation® O42 - Logiciel: Recuva - (.Piriform.) [HKLM] -- Recuva =>.Piriform Ltd® O42 - Logiciel: Renesas Electronics USB 3.0 Host Controller Driver - (.Renesas Electronics Corporation.) [HKLM] -- InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996} =>.Renesas Electronics Corporation O42 - Logiciel: SimpleTV 0.4.6 r - (.SergeyVS.) [HKLM] -- {290A2821-B1F8-4565-B49A-25F349A5B5CB}_is1 O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM] -- {873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B} =>.Microsoft Corporation O42 - Logiciel: Skype™ 7.32 - (.Skype Technologies S.A..) [HKLM] -- {FC965A47-4839-40CA-B618-18F486F042C6} =>.Skype Technologies S.A. O42 - Logiciel: SubtitleCreator - (.Erik Vullings.) [HKLM] -- SubtitleCreator O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey =>.Synaptics Incorporated O42 - Logiciel: The KMPlayer (remove only) - (.KMP Media co., Ltd.) [HKLM] -- The KMPlayer O42 - Logiciel: Transparent Image Converter 1.1 - (.Microsoft.) [HKLM] -- {DBBA30DF-C284-4684-84AB-FF66F35D568C} =>.Microsoft O42 - Logiciel: TransparentImageConverter 1.0 - (.Microsoft.) [HKLM] -- {0EDDA73E-0E26-45AF-A631-3A5596002D49} =>.Microsoft O42 - Logiciel: Ulead VideoStudio 11 - (..) [HKLM] -- InstallShield_{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9} O42 - Logiciel: uTorrent Turbo Accelerator - (.WebSpeeders LLC.) [HKLM] -- uTorrent Turbo Accelerator O42 - Logiciel: VideoStudio - (.InterVideo Digital Technology Corporation.) [HKLM] -- {F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9} O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM] -- VLC media player =>.VideoLAN O42 - Logiciel: VobSub v2.23 (Remove Only) - (..) [HKLM] -- VobSub O42 - Logiciel: WebcamMax - (..) [HKLM] -- WebcamMax O42 - Logiciel: WinRAR archiver - (.RarLab.) [HKLM] -- WinRAR archiver =>.RarLab O42 - Logiciel: WinSnare - (.WinSnare.) [HKLM] -- {FC5A2575-5D95-4466-A08A-8908998E49D0} =>.Superfluous.WinSnare O42 - Logiciel: YAC(Yet Another Cleaner!) - (.ELEX DO BRASIL PARTICIPAÇÕES LTDA.) [HKLM] -- iSafe =>.Superfluous.Elex O42 - Logiciel: Your Uninstaller! 7 - (.URSoft, Inc..) [HKLM] -- YU2010_is1 =>.URSoft, Inc.® ---\\ HKCU & HKLM Software Keys (255) - 307s HKLM\SOFTWARE\7-Zip =>.Igor Pavlov HKLM\SOFTWARE\ABBYY =>.ABBYY Software HKLM\SOFTWARE\ACE Compression Software =>.ACE Compression Software HKLM\SOFTWARE\Ahead =>.Ahead HKLM\SOFTWARE\amule-custom =>Adware.aMULEcustom HKLM\SOFTWARE\Apple Computer, Inc. =>.Apple Computer, Inc. HKLM\SOFTWARE\Apple Inc. =>.Apple Inc. HKLM\SOFTWARE\ArcSoft =>.ArcSoft HKLM\SOFTWARE\AskTBar HKLM\SOFTWARE\AskToolbar =>Toolbar.Ask HKLM\SOFTWARE\ATHEROS =>.Qualcomm Atheros HKLM\SOFTWARE\ATI Technologies =>.ATI Technologies HKLM\SOFTWARE\Atodoentcoikse HKLM\SOFTWARE\AVAST Software =>.AVAST Software HKLM\SOFTWARE\AviSynth =>.Ben Rudiak-Gold HKLM\SOFTWARE\b1.org =>PUP.Optional.SearchB1org HKLM\SOFTWARE\Babylon =>Adware.Babylon HKLM\SOFTWARE\Baidu =>.Baidu HKLM\SOFTWARE\Baidu Security =>.Baidu Technology HKLM\SOFTWARE\Baidu_Drp_pos =>.Baidu Technology HKLM\SOFTWARE\BCL Technologies =>.BCL Technologies HKLM\SOFTWARE\Bunndle =>.Unknow HKLM\SOFTWARE\Business Objects =>.Business Objects HKLM\SOFTWARE\C07ft5Y =>.Total War Game HKLM\SOFTWARE\Chedot =>PUP.Optional.ChedotBrowser HKLM\SOFTWARE\Chromium =>.Chromium HKLM\SOFTWARE\Chtydrerpuing HKLM\SOFTWARE\CloudOPTInfo =>.Baidu Technology HKLM\SOFTWARE\co.ao.qws HKLM\SOFTWARE\Debug =>.Legitimate HKLM\SOFTWARE\DisplayLink =>.DisplayLink HKLM\SOFTWARE\DivXNetworks =>.DivXNetworks HKLM\SOFTWARE\DVDVideoSoft =>.DVDVideoSoft HKLM\SOFTWARE\EazelBar HKLM\SOFTWARE\Elex-tech =>.Superfluous.Elex HKLM\SOFTWARE\ESTsoft =>.ESTsoft HKLM\SOFTWARE\Explorer HKLM\SOFTWARE\ExtractNow HKLM\SOFTWARE\Firefox =>.Mozilla Corporation HKLM\SOFTWARE\Foxit Software =>.Foxit Software HKLM\SOFTWARE\Gabest =>.Gabest HKLM\SOFTWARE\GameHouse =>.GameHouse HKLM\SOFTWARE\GN2 HKLM\SOFTWARE\Google =>.Google HKLM\SOFTWARE\HaaliMkx =>.Haali Media HKLM\SOFTWARE\hdcode =>.Legitimate HKLM\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard HKLM\SOFTWARE\Hipmy HKLM\SOFTWARE\Hisarah HKLM\SOFTWARE\hohosearchSoftware =>.Superfluous.HohoSearch HKLM\SOFTWARE\HP =>.HP HKLM\SOFTWARE\HSPA =>.HSPA HKLM\SOFTWARE\Huawei technologies =>.Huawei Technologies HKLM\SOFTWARE\IDT =>.IDT HKLM\SOFTWARE\illiminable =>.illiminable HKLM\SOFTWARE\IM Providers =>.IM Providers HKLM\SOFTWARE\InstalledOptions =>.Installed Options HKLM\SOFTWARE\Insyde =>.Insyde HKLM\SOFTWARE\Intel =>.Intel HKLM\SOFTWARE\Internet Download Manager =>.Tonec Inc HKLM\SOFTWARE\InterSect Alliance =>.Superfluous.InterSect HKLM\SOFTWARE\InterVideo =>.InterVideo HKLM\SOFTWARE\iThemes =>.iThemes HKLM\SOFTWARE\JavaSoft =>.JavaSoft HKLM\SOFTWARE\JreMetrics =>.JreMetrics HKLM\SOFTWARE\KMPlayer =>.KMPlayer HKLM\SOFTWARE\Licenses =>.Microsoft Corporation HKLM\SOFTWARE\macrium =>.Macrium HKLM\SOFTWARE\Macromedia =>.Macromedia HKLM\SOFTWARE\Magix =>.Magix HKLM\SOFTWARE\Mozilla =>.Mozilla HKLM\SOFTWARE\mozilla.org =>.mozilla.org HKLM\SOFTWARE\MozillaPlugins =>.MozillaPlugins HKLM\SOFTWARE\MpcStar =>.MPCstar HKLM\SOFTWARE\Nero =>.Ahead Corporation HKLM\SOFTWARE\NewSoftware's HKLM\SOFTWARE\nuesearchSoftware =>.Nuesearch Software HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions HKLM\SOFTWARE\Outlose HKLM\SOFTWARE\Pandora.TV =>.Pandora.TV HKLM\SOFTWARE\PerformerSoft =>.Superfluous.PerformerSoft HKLM\SOFTWARE\PIP =>Toolbar.Ask HKLM\SOFTWARE\Piriform =>.Piriform HKLM\SOFTWARE\PoINT HKLM\SOFTWARE\qksee =>.Superfluous.TaiwanShuiMu HKLM\SOFTWARE\qkseeSvc =>.Superfluous.TaiwanShuiMu HKLM\SOFTWARE\RaLink =>.Ralink HKLM\SOFTWARE\Realtek =>.Realtek Semiconductor Corp. HKLM\SOFTWARE\Reejach HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation HKLM\SOFTWARE\Roxio =>.Roxio HKLM\SOFTWARE\RtWLan =>.Realtek Semiconductor Corp. HKLM\SOFTWARE\ScreenShot HKLM\SOFTWARE\simplitec =>.Simplitec HKLM\SOFTWARE\SimplyGen =>PUP.Optional.PredictAd HKLM\SOFTWARE\Skype =>.Skype HKLM\SOFTWARE\Softland =>.Softland HKLM\SOFTWARE\SoftwareUpdater =>PUP.Optional.SoftwareUpdater HKLM\SOFTWARE\Sonic =>.Sonic HKLM\SOFTWARE\SubtitleCreator HKLM\SOFTWARE\Synaptics =>.Synaptics HKLM\SOFTWARE\Systweak =>.Superfluous.Systweak HKLM\SOFTWARE\Tarma Installer =>.Superfluous.Tarma HKLM\SOFTWARE\Tencent =>.Superfluous.Tencent HKLM\SOFTWARE\ThinPrint =>.ThinPrint HKLM\SOFTWARE\Toolrain HKLM\SOFTWARE\TopLang =>.TopLang HKLM\SOFTWARE\Ulead Systems =>.Ulead Systems HKLM\SOFTWARE\UpdatesWuApp HKLM\SOFTWARE\uTorrent Turbo Accelerator HKLM\SOFTWARE\UvConv HKLM\SOFTWARE\VideoLAN =>.VideoLAN HKLM\SOFTWARE\Vittalia =>PUP.Optional.Vittalia HKLM\SOFTWARE\VMware, Inc. =>.VMware, Inc. HKLM\SOFTWARE\VobSub HKLM\SOFTWARE\Volatile =>.Microsoft Corporation HKLM\SOFTWARE\WebcamMax =>.WebcamMax HKLM\SOFTWARE\WinArcher =>PUP.Optional.Youndoo HKLM\SOFTWARE\WinSaberSvc =>.Superfluous.WinSaber HKLM\SOFTWARE\WiseCleaner =>.wisecleaner HKLM\SOFTWARE\Wondershare =>.Wondershare HKLM\SOFTWARE\Wow6432Node =>.Microsoft Corporation HKLM\SOFTWARE\Xara =>.Xara Group Ltd. HKCU\SOFTWARE\1ClickDownload =>PUP.Optional.1ClickDownloader HKCU\SOFTWARE\7-Zip =>.Igor Pavlov HKCU\SOFTWARE\ABBYY =>.ABBYY Software HKCU\SOFTWARE\Adobe =>.Adobe HKCU\SOFTWARE\Ahead =>.Ahead HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation HKCU\SOFTWARE\Apple Computer, Inc. =>.Apple Computer, Inc. HKCU\SOFTWARE\ARAR HKCU\SOFTWARE\ArcSoft =>.ArcSoft HKCU\SOFTWARE\Atheros =>.Qualcomm Atheros HKCU\SOFTWARE\Avast Software =>.AVAST Software HKCU\SOFTWARE\Baidu =>.Baidu HKCU\SOFTWARE\Baidu Security =>.Baidu Technology HKCU\SOFTWARE\Bangkiss HKCU\SOFTWARE\BitTorrent HKCU\SOFTWARE\BrowserTemp =>.Legitimate HKCU\SOFTWARE\Business Objects =>.Business Objects HKCU\SOFTWARE\Camfrog =>.Camshare LC HKCU\SOFTWARE\Caphyon =>.Caphyon HKCU\SOFTWARE\Chedot =>PUP.Optional.ChedotBrowser HKCU\SOFTWARE\Chromium =>.Chromium HKCU\SOFTWARE\ClipMagic HKCU\SOFTWARE\Complitly =>PUP.Optional.PredictAd HKCU\SOFTWARE\DelphineSoft =>.DelphineSoft HKCU\SOFTWARE\deskapp HKCU\SOFTWARE\DivXNetworks =>.DivXNetworks HKCU\SOFTWARE\DownloadAstro =>.Download Astro HKCU\SOFTWARE\DownloadManager =>.DownloadManager HKCU\SOFTWARE\DRAR HKCU\SOFTWARE\drpsu =>.Driver PackSolution HKCU\SOFTWARE\DRPSu Updater HKCU\SOFTWARE\DVDVideoSoft =>.DVDVideoSoft HKCU\SOFTWARE\EazelBar HKCU\SOFTWARE\ESTsoft =>.ESTsoft HKCU\SOFTWARE\Explorer HKCU\SOFTWARE\ExtractNow HKCU\SOFTWARE\Facebook =>.Facebook HKCU\SOFTWARE\Firefox =>.Mozilla Corporation HKCU\SOFTWARE\FortCryptoExtension HKCU\SOFTWARE\Foxit Software =>.Foxit Software HKCU\SOFTWARE\FreeTime =>.FreeTime Inc HKCU\SOFTWARE\Gabest =>.Gabest HKCU\SOFTWARE\GameHouse =>.GameHouse HKCU\SOFTWARE\GetData =>.GetData HKCU\SOFTWARE\GN2 HKCU\SOFTWARE\GNU =>.GNU HKCU\SOFTWARE\Google =>.Google HKCU\SOFTWARE\GotClip Downloader HKCU\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard HKCU\SOFTWARE\Hipmy HKCU\SOFTWARE\Hisarah HKCU\SOFTWARE\IM Providers =>.IM Providers HKCU\SOFTWARE\Intel =>.Intel HKCU\SOFTWARE\iWesoft =>.iWesoft HKCU\SOFTWARE\JavaSoft =>.JavaSoft HKCU\SOFTWARE\JollyBear =>.JollyBear Games Inc HKCU\SOFTWARE\KLS Soft HKCU\SOFTWARE\KMPlayer =>.KMPlayer HKCU\SOFTWARE\KRyLack HKCU\SOFTWARE\LAV =>.LAV Inc HKCU\SOFTWARE\Lenovo =>.Lenovo HKCU\SOFTWARE\Licenses =>.Microsoft Corporation HKCU\SOFTWARE\Likasoft HKCU\SOFTWARE\macrium =>.Macrium HKCU\SOFTWARE\Macromedia =>.Macromedia HKCU\SOFTWARE\madFlac =>.Free-Codecs HKCU\SOFTWARE\Magix =>.Magix HKCU\SOFTWARE\MAGIX AG =>.MAGIX AG HKCU\SOFTWARE\MainConcept =>.MainConcept AG HKCU\SOFTWARE\MainConcept (Consumer) =>.MainConcept AG HKCU\SOFTWARE\MediaInfo =>.Jérôme Martinez HKCU\SOFTWARE\MJTNET HKCU\SOFTWARE\MONOGRAM =>.MOO Software HKCU\SOFTWARE\Mozilla =>.Mozilla HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins HKCU\SOFTWARE\NATATA eBook HKCU\SOFTWARE\Nero =>.Ahead Corporation HKCU\SOFTWARE\Netscape =>.Netscape HKCU\SOFTWARE\NetScoutToolbar HKCU\SOFTWARE\NewSoftware's HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions HKCU\SOFTWARE\Outlose HKCU\SOFTWARE\PerformerSoft =>.Superfluous.PerformerSoft HKCU\SOFTWARE\PictureMall =>.PictureMall Inc. HKCU\SOFTWARE\Piriform =>.Piriform HKCU\SOFTWARE\PixelPlanet =>.PixelPlanet HKCU\SOFTWARE\PopCap HKCU\SOFTWARE\QtProject =>.QtProject HKCU\SOFTWARE\RealNetworks =>.RealNetworks HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp. HKCU\SOFTWARE\SecuROM =>.SecuROM HKCU\SOFTWARE\SimpleTV by SergeyVS#3 HKCU\SOFTWARE\SimplyTech =>.Superfluous.SimplyTech HKCU\SOFTWARE\Skype =>.Skype HKCU\SOFTWARE\SkypeRS =>.Skype Technologies HKCU\SOFTWARE\SMADΔV HKCU\SOFTWARE\Smart PC Solutions =>.Superfluous.SmartPCSolutions HKCU\SOFTWARE\SmartTweak =>.SmartTweak HKCU\SOFTWARE\Softland =>.Softland HKCU\SOFTWARE\Sony Creative Software =>.Sony Creative Software HKCU\SOFTWARE\Synaptics =>.Synaptics HKCU\SOFTWARE\Sysinternals =>.Sysinternals HKCU\SOFTWARE\TechSmith =>.TechSmith HKCU\SOFTWARE\Tencent =>.Superfluous.Tencent HKCU\SOFTWARE\Teorex =>.Teorex HKCU\SOFTWARE\Toolrain HKCU\SOFTWARE\ToomkyGames HKCU\SOFTWARE\TopLang =>.TopLang HKCU\SOFTWARE\TreeCardGames =>.TreeCardGames HKCU\SOFTWARE\Trolltech =>.Trolltech HKCU\SOFTWARE\Ulead =>.Ulead Systems HKCU\SOFTWARE\Ulead Systems =>.Ulead Systems HKCU\SOFTWARE\UniPDF HKCU\SOFTWARE\URSoft =>.URSoft HKCU\SOFTWARE\uTorrent Turbo Accelerator HKCU\SOFTWARE\uTorrent Turbo Booster HKCU\SOFTWARE\VideoConverter-Media =>.ZJMedia Digital Technology Ltd. HKCU\SOFTWARE\Vittalia =>PUP.Optional.Vittalia HKCU\SOFTWARE\Winamp =>.Nullsoft Inc. HKCU\SOFTWARE\WinRAR =>.WinRAR HKCU\SOFTWARE\WinRAR SFX =>.RarLab HKCU\SOFTWARE\WinSnare =>.Superfluous.WinSnare HKCU\SOFTWARE\Wondershare =>.Wondershare HKCU\SOFTWARE\Xara =>.Xara Group Ltd. HKCU\SOFTWARE\Xilisoft =>.Xilisoft HKCU\SOFTWARE\Yahoo =>.Yahoo! Inc. HKCU\SOFTWARE\ZHP =>.Nicolas Coolman HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation HKCU\SOFTWARE\AppDataLow\Software\AskToolbar =>Toolbar.Ask HKCU\SOFTWARE\AppDataLow\Software\JavaSoft =>.JavaSoft HKCU\SOFTWARE\AppDataLow\Software\Simplytech =>.Superfluous.SimplyTech HKCU\SOFTWARE\AppDataLow\Software\ThinPrint =>.ThinPrint ---\\ Contenu des dossiers Programmes (499) - 402s O43 - CFD: 28/06/2016 - [0] D -- C:\Program Files\2qhoyf2t =>.Superfluous.Empty O43 - CFD: 18/01/2017 - [0] D -- C:\Program Files\587F9BF4_jumpeasy O43 - CFD: 20/01/2017 - [] D -- C:\Program Files\5881DB8C_jumpeasy O43 - CFD: 16/03/2017 - [0] D -- C:\Program Files\58CAD6C9_cacayima O43 - CFD: 17/03/2017 - [0] D -- C:\Program Files\58CC46B5_cacayima O43 - CFD: 01/06/2016 - [] D -- C:\Program Files\7-Zip =>.Igor Pavlov O43 - CFD: 13/05/2016 - [] D -- C:\Program Files\ABBYY FineReader 11 =>.ABBYY Software O43 - CFD: 17/03/2017 - [] D -- C:\Program Files\amulell =>Adware.aMULEcustom O43 - CFD: 05/03/2016 - [] D -- C:\Program Files\Android =>.Android O43 - CFD: 26/12/2016 - [0] D -- C:\Program Files\ARAR O43 - CFD: 13/05/2016 - [0] D -- C:\Program Files\Archivarius 3000 O43 - CFD: 02/09/2015 - [] D -- C:\Program Files\ArcSoft =>.ArcSoft O43 - CFD: 08/09/2013 - [] D -- C:\Program Files\AskTBar =>Toolbar.AskTBar O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\Atheros =>.Qualcomm Atheros O43 - CFD: 17/03/2017 - [] D -- C:\Program Files\AVAST Software =>.AVAST Software s.r.o.® O43 - CFD: 07/03/2016 - [] D -- C:\Program Files\baidu =>.Baidu O43 - CFD: 11/01/2014 - [] D -- C:\Program Files\Baidu Security =>.Baidu Technology O43 - CFD: 13/08/2013 - [] D -- C:\Program Files\Betcat =>PUP.Optional.Betcat O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\Bluetooth Suite =>.ASUSTeK O43 - CFD: 03/02/2017 - [] D -- C:\Program Files\BrowserProtect =>PUP.Optional.Eazel O43 - CFD: 03/03/2013 - [] D -- C:\Program Files\Buku Dominoes O43 - CFD: 30/07/2014 - [0] D -- C:\Program Files\Cheat Engine 6.1 =>.Dark Byte O43 - CFD: 18/05/2013 - [] D -- C:\Program Files\Chicken Invaders 4 - Ultimate Omelette O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\Cisco =>.Cisco Systems, Inc. O43 - CFD: 17/03/2017 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation O43 - CFD: 27/12/2013 - [] D -- C:\Program Files\Complitly =>PUP.Optional.PredictAd O43 - CFD: 09/10/2016 - [] D -- C:\Program Files\DANSYS O43 - CFD: 17/03/2017 - [0] D -- C:\Program Files\deskapp O43 - CFD: 27/12/2016 - [0] D -- C:\Program Files\Disney Interactive Studios =>.Disney Interactive Studios O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\DisplayLink Core Software =>.DISPLAYLINK® O43 - CFD: 07/05/2016 - [] D -- C:\Program Files\DRAR O43 - CFD: 31/10/2012 - [] D -- C:\Program Files\DVD Maker =>.Aone Software O43 - CFD: 19/06/2013 - [] D -- C:\Program Files\EazelBar O43 - CFD: 02/12/2016 - [0] D -- C:\Program Files\Elcomsoft Password Recovery =>.Elcomsoft Co. Ltd. O43 - CFD: 12/06/2016 - [] D -- C:\Program Files\Elex-tech =>.Superfluous.Elex O43 - CFD: 02/08/2015 - [] D -- C:\Program Files\Empire Interactive =>.Empire Interactive O43 - CFD: 26/12/2016 - [] D -- C:\Program Files\ESTsoft =>.ESTsoft Corp.® O43 - CFD: 03/02/2017 - [] AD -- C:\Program Files\Explorer O43 - CFD: 26/12/2016 - [0] D -- C:\Program Files\ExtractNow O43 - CFD: 29/10/2012 - [0] SHD -- C:\Program Files\Fichiers communs =>.Microsoft Corporation O43 - CFD: 27/07/2014 - [] D -- C:\Program Files\File Lock O43 - CFD: 16/03/2017 - [] AD -- C:\Program Files\Firefox =>.Mozilla Corporation O43 - CFD: 29/10/2012 - [] D -- C:\Program Files\Foxit Software =>.Foxit Software O43 - CFD: 26/12/2016 - [0] D -- C:\Program Files\Free RAR Password Recovery O43 - CFD: 07/06/2013 - [] D -- C:\Program Files\FreeTime =>.FreeTime O43 - CFD: 08/08/2013 - [] D -- C:\Program Files\Gabest =>.Gabest O43 - CFD: 01/06/2016 - [] D -- C:\Program Files\Google =>.Google O43 - CFD: 18/01/2017 - [] D -- C:\Program Files\Gubed =>.Superfluous.Elex.GubZL O43 - CFD: 23/12/2016 - [0] D -- C:\Program Files\Gubed_WMI =>.Superfluous.Elex.GubZL O43 - CFD: 25/06/2014 - [0] D -- C:\Program Files\GUMB7D9.tmp O43 - CFD: 31/10/2012 - [] D -- C:\Program Files\Hewlett-Packard =>.Hewlett-Packard O43 - CFD: 16/03/2017 - [] D -- C:\Program Files\Hipmy =>.Google Inc® O43 - CFD: 12/06/2016 - [] D -- C:\Program Files\Hisarah {3ACD4267DE28E9001E7E9080D51397EA} O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\Hp =>.Hewlett-Packard O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\HP USB Docking Video =>.Hewlett-Packard O43 - CFD: 13/01/2013 - [] D -- C:\Program Files\HSPA USB Modem =>.Legitimate O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\IDT =>.IDT O43 - CFD: 27/12/2016 - [] HD -- C:\Program Files\InstallShield Installation Information =>.InstallShield Software O43 - CFD: 22/01/2013 - [] D -- C:\Program Files\Intel =>.Intel Corporation O43 - CFD: 14/01/2017 - [] D -- C:\Program Files\Internet Download Manager =>.Tonec Inc O43 - CFD: 16/03/2017 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation O43 - CFD: 25/09/2013 - [] D -- C:\Program Files\Java =>.Oracle O43 - CFD: 16/08/2013 - [] D -- C:\Program Files\K-Lite Codec Pack =>.KLite Inc O43 - CFD: 14/01/2017 - [] D -- C:\Program Files\KLS Soft O43 - CFD: 13/05/2016 - [0] D -- C:\Program Files\Kodi =>.XBMC Foundation O43 - CFD: 13/11/2016 - [] D -- C:\Program Files\Lenovo =>.Lenovo O43 - CFD: 26/10/2013 - [] D -- C:\Program Files\MAGIX =>.Magix O43 - CFD: 29/10/2012 - [] D -- C:\Program Files\Media Player Classic - Home Cinema O43 - CFD: 30/12/2016 - [] D -- C:\Program Files\Microsoft =>.Microsoft Corporation O43 - CFD: 08/07/2016 - [] D -- C:\Program Files\Microsoft Games =>.Microsoft Corporation O43 - CFD: 29/10/2012 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation O43 - CFD: 29/10/2012 - [] D -- C:\Program Files\Microsoft Visual Studio =>.Microsoft Corporation O43 - CFD: 29/10/2012 - [] D -- C:\Program Files\Microsoft Visual Studio 8 =>.Microsoft Corporation O43 - CFD: 29/10/2012 - [] D -- C:\Program Files\Microsoft Works =>.Microsoft Corporation O43 - CFD: 29/02/2016 - [] D -- C:\Program Files\Microsoft.NET =>.Microsoft Corporation O43 - CFD: 08/02/2017 - [] D -- C:\Program Files\MIO =>.Mio O43 - CFD: 16/03/2017 - [] D -- C:\Program Files\MK O43 - CFD: 27/12/2016 - [0] D -- C:\Program Files\MobiConnect O43 - CFD: 27/12/2016 - [0] D -- C:\Program Files\MON BEBE ar O43 - CFD: 22/01/2013 - [] D -- C:\Program Files\Movie Maker 2.6 =>.Microsoft Corporation O43 - CFD: 10/01/2017 - [] D -- C:\Program Files\Mozilla Firefox =>.Mozilla O43 - CFD: 10/01/2017 - [] D -- C:\Program Files\Mozilla Maintenance Service =>.Mozilla O43 - CFD: 31/01/2015 - [] D -- C:\Program Files\MpcStar =>.MPCstar O43 - CFD: 29/10/2012 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation O43 - CFD: 28/09/2013 - [] D -- C:\Program Files\MSXML 4.0 =>.Microsoft Corporation O43 - CFD: 21/05/2013 - [] D -- C:\Program Files\MyPlayCity.com =>.MyPlayCity.com O43 - CFD: 17/03/2017 - [] D -- C:\Program Files\n1 O43 - CFD: 29/10/2012 - [] D -- C:\Program Files\Nero =>.Ahead Corporation O43 - CFD: 02/06/2013 - [] D -- C:\Program Files\NetScoutToolbar O43 - CFD: 02/11/2013 - [] D -- C:\Program Files\NewSoftware's =>.NewSoftware's O43 - CFD: 14/07/2016 - [] D -- C:\Program Files\Outlose {6009BF5A82E83C9DE59D277D83443973} O43 - CFD: 23/10/2013 - [] D -- C:\Program Files\PANDORA.TV =>.Pandora.TV O43 - CFD: 27/12/2016 - [0] D -- C:\Program Files\PC Speed Maximizer =>.Superfluous.PCSpeedMaximizer O43 - CFD: 22/02/2017 - [] D -- C:\Program Files\Phone =>.Skype Software Sarl® O43 - CFD: 21/06/2016 - [0] D -- C:\Program Files\PhotoScissors O43 - CFD: 08/05/2016 - [] D -- C:\Program Files\PixelPlanet =>.PixelPlanet O43 - CFD: 16/07/2016 - [] D -- C:\Program Files\Pro Evolution Soccer 2016 =>.Games Software O43 - CFD: 28/12/2016 - [0] D -- C:\Program Files\Protected Search O43 - CFD: 16/03/2017 - [] D -- C:\Program Files\qksee {4BC79824EA659062C37E9D47340A7EA2} =>.Superfluous.TaiwanShuiMu O43 - CFD: 15/04/2016 - [] D -- C:\Program Files\QQBrowser =>.Superfluous.Tencent O43 - CFD: 02/05/2014 - [] D -- C:\Program Files\Ralink =>.Ralink O43 - CFD: 13/07/2014 - [0] D -- C:\Program Files\RAR Password Cracker =>.DNSoft O43 - CFD: 30/07/2014 - [0] D -- C:\Program Files\RAR Password Unlocker =>.DNSoft O43 - CFD: 01/05/2014 - [] D -- C:\Program Files\Realtek =>.Realtek O43 - CFD: 15/11/2016 - [] D -- C:\Program Files\Recuva =>.Piriform O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation O43 - CFD: 30/07/2014 - [0] D -- C:\Program Files\RegClean Pro =>PUP.Optional.RegistryPowerCleaner O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\Renesas Electronics =>.Renesas Electronics Corporation® O43 - CFD: 01/03/2017 - [] D -- C:\Program Files\reports O43 - CFD: 19/12/2016 - [] D -- C:\Program Files\SearchesToYesbnd {221318A741FC08D36E03B7D7459DF07E} =>Adware.YesSearches O43 - CFD: 12/07/2014 - [] D -- C:\Program Files\SecurityXploded =>.SecurityXploded O43 - CFD: 09/10/2016 - [] D -- C:\Program Files\SFK O43 - CFD: 13/11/2016 - [] D -- C:\Program Files\SHAREit =>.Lenovo Group Limited O43 - CFD: 30/03/2016 - [] D -- C:\Program Files\SimpleTV O43 - CFD: 28/09/2013 - [] D -- C:\Program Files\simplitec =>.Simplitec O43 - CFD: 02/02/2017 - [] D -- C:\Program Files\Skype =>.Skype O43 - CFD: 21/04/2016 - [] D -- C:\Program Files\Smadav =>.SmadAV O43 - CFD: 08/08/2014 - [] D -- C:\Program Files\Smadav 2013 Rev. 9.4.1 O43 - CFD: 20/04/2016 - [] D -- C:\Program Files\Smart PC Solutions =>.Smart PC Solutions O43 - CFD: 07/06/2013 - [] D -- C:\Program Files\SmartTweak Software O43 - CFD: 12/01/2017 - [] D -- C:\Program Files\Softland =>.Softland S.R.L.® O43 - CFD: 02/07/2014 - [] D -- C:\Program Files\SoftwareUpdater O43 - CFD: 16/06/2013 - [] D -- C:\Program Files\SubtitleCreator O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\Synaptics =>.Synaptics Incorporated® O43 - CFD: 16/03/2017 - [] HD -- C:\Program Files\Temp =>.Microsoft Corporation O43 - CFD: 01/05/2016 - [] D -- C:\Program Files\Tencent =>.Superfluous.Tencent O43 - CFD: 17/02/2017 - [] D -- C:\Program Files\The KMPlayer =>.The KMPlayer Team O43 - CFD: 29/06/2016 - [] D -- C:\Program Files\Toolrain =>.Sivi Technology Limited® O43 - CFD: 16/04/2016 - [0] D -- C:\Program Files\TV 3L PC O43 - CFD: 01/06/2016 - [] D -- C:\Program Files\TXQQBrowser =>.Superfluous.Tencent O43 - CFD: 13/05/2016 - [] D -- C:\Program Files\Ulead Systems =>.Ulead Systems O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation O43 - CFD: 16/04/2016 - [0] D -- C:\Program Files\UniPDF =>.UniPDF.com O43 - CFD: 02/02/2017 - [] D -- C:\Program Files\Updater =>.Skype Software Sarl® O43 - CFD: 05/06/2013 - [] D -- C:\Program Files\uTorrent Turbo Accelerator O43 - CFD: 27/12/2013 - [] D -- C:\Program Files\uTorrent Turbo Booster O43 - CFD: 17/12/2016 - [0] D -- C:\Program Files\UvConverter =>Adware.CornerSunshine O43 - CFD: 16/04/2016 - [0] D -- C:\Program Files\VeryPDF PDF2Word v3.1 O43 - CFD: 27/08/2015 - [] D -- C:\Program Files\Video to Video =>.Media Converters O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\VideoLAN =>.VideoLan Team O43 - CFD: 01/10/2013 - [] D -- C:\Program Files\VMware =>.VMware O43 - CFD: 13/08/2013 - [0] D -- C:\Program Files\Web Cake =>PUP.Optional.WebCake O43 - CFD: 02/10/2013 - [] D -- C:\Program Files\WebcamMax =>.CoolwareMax O43 - CFD: 09/02/2017 - [] D -- C:\Program Files\WinArcher =>PUP.Optional.Youndoo O43 - CFD: 31/10/2012 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation O43 - CFD: 31/10/2012 - [] D -- C:\Program Files\Windows Journal =>.Microsoft Corporation O43 - CFD: 31/10/2012 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation O43 - CFD: 10/11/2013 - [] D -- C:\Program Files\Windows Media Components O43 - CFD: 31/10/2012 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation O43 - CFD: 29/10/2012 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation O43 - CFD: 31/10/2012 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation O43 - CFD: 17/03/2017 - [] D -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation O43 - CFD: 02/12/2013 - [] D -- C:\Program Files\WinRar =>.WinRAR O43 - CFD: 12/08/2016 - [] D -- C:\Program Files\WinSaber =>.Superfluous.WinSaber O43 - CFD: 23/03/2016 - [] D -- C:\Program Files\Winsere =>Adware.YesSearches O43 - CFD: 20/02/2017 - [] D -- C:\Program Files\WinSnare(4.1.0) =>.Superfluous.WinSnare O43 - CFD: 17/03/2017 - [] D -- C:\Program Files\WinSnare(4.3.3) =>.Superfluous.WinSnare O43 - CFD: 23/03/2016 - [] D -- C:\Program Files\WinTaske =>Adware.YesSearches O43 - CFD: 27/12/2016 - [0] D -- C:\Program Files\WinZipper =>.Superfluous.TaiwanShuiMu O43 - CFD: 13/05/2016 - [] D -- C:\Program Files\Wise =>.Legitimate O43 - CFD: 16/04/2016 - [] D -- C:\Program Files\Wondershare =>.Wondershare O43 - CFD: 13/05/2016 - [0] D -- C:\Program Files\XBMC =>.XBMC O43 - CFD: 30/07/2014 - [] D -- C:\Program Files\Your Uninstaller! 7 =>.Ursoftware O43 - CFD: 07/03/2016 - [] D -- C:\Program Files\عارض رموز أيقونات برامج الأندرويد O43 - CFD: 01/06/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip =>.Igor Pavlov O43 - CFD: 07/12/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 11 =>.ABBYY Software O43 - CFD: 30/10/2012 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation O43 - CFD: 29/10/2012 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools O43 - CFD: 26/12/2016 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced RAR Repair O43 - CFD: 09/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Application Cadastrale O43 - CFD: 31/10/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft =>.ArcSoft O43 - CFD: 30/10/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft Connect =>.ArcSoft O43 - CFD: 31/10/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft TotalMedia Extreme 2 =>.ArcSoft O43 - CFD: 30/10/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft WebCam Companion 3 =>.Labtec O43 - CFD: 18/05/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Chicken Invaders 4 - Ultimate Omelette O43 - CFD: 12/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\doPDF 7 O43 - CFD: 02/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Empire Interactive =>.Empire Interactive O43 - CFD: 02/11/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Folder Lock O43 - CFD: 29/10/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader 5.1 O43 - CFD: 08/07/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation O43 - CFD: 19/12/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro =>.Google Inc. O43 - CFD: 30/10/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP =>.Hewlett-Packard O43 - CFD: 30/10/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support =>.Hewlett-Packard O43 - CFD: 13/01/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HSPA USB Modem =>.Legitimate O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager =>.Tonec Inc O43 - CFD: 16/08/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack =>.KLite Inc O43 - CFD: 27/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LAV Filters =>.Hendrik Leppkes O43 - CFD: 26/10/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX =>.Magix O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation O43 - CFD: 29/10/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Player Classic - Home Cinema O43 - CFD: 29/10/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office =>.Microsoft Corporation O43 - CFD: 13/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MpcStar =>.MPCstar O43 - CFD: 16/03/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPlayCity.com =>.MyPlayCity.com O43 - CFD: 29/10/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero =>.Ahead Corporation O43 - CFD: 23/10/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PANDORATV =>.PandoraTV O43 - CFD: 08/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PixelPlanet =>.PixelPlanet O43 - CFD: 28/06/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qksee =>.Superfluous.TaiwanShuiMu O43 - CFD: 02/05/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ralink Wireless =>.Rarink O43 - CFD: 15/11/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva =>.Piriform O43 - CFD: 30/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SimpleTV O43 - CFD: 28/09/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\simplitec =>.Simplitec O43 - CFD: 01/06/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype =>.Skype O43 - CFD: 08/07/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation O43 - CFD: 13/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SubtitleCreator O43 - CFD: 14/07/2009 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC =>.Wacom Technology O43 - CFD: 10/11/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ulead VideoStudio 11 =>.Pinnacle Systems, Inc. O43 - CFD: 02/06/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uTorrent Turbo Accelerator O43 - CFD: 23/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team O43 - CFD: 08/08/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VobSub O43 - CFD: 30/10/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebcamMax =>.CoolwareMax O43 - CFD: 02/12/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR O43 - CFD: 30/07/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Your Uninstaller! 7 =>.Ursoftware O43 - CFD: 04/04/2014 - [] D -- C:\ProgramData\42441d23bcf7cfcd O43 - CFD: 07/12/2013 - [] D -- C:\ProgramData\ABBYY =>.ABBYY Software O43 - CFD: 29/08/2015 - [] D -- C:\ProgramData\Adobe =>.Adobe O43 - CFD: 23/10/2013 - [] D -- C:\ProgramData\APN =>Toolbar.Ask O43 - CFD: 16/03/2017 - [] D -- C:\ProgramData\Apple =>.Apple Inc. O43 - CFD: 01/06/2016 - [] D -- C:\ProgramData\Apple Computer =>.Apple Inc. O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation O43 - CFD: 10/01/2016 - [] D -- C:\ProgramData\ArcSoft =>.ArcSoft O43 - CFD: 23/10/2013 - [] D -- C:\ProgramData\AskPartnerNetwork =>Toolbar.YahooPartner O43 - CFD: 30/10/2012 - [] D -- C:\ProgramData\Atheros =>.Qualcomm Atheros O43 - CFD: 18/03/2017 - [] D -- C:\ProgramData\AVAST Software =>.AVAST Software O43 - CFD: 28/05/2013 - [0] D -- C:\ProgramData\Babylon =>Adware.Babylon O43 - CFD: 07/03/2016 - [] D -- C:\ProgramData\Baidu =>.Baidu O43 - CFD: 19/05/2014 - [] D -- C:\ProgramData\Baidu Security =>.Baidu Technology O43 - CFD: 07/03/2016 - [] D -- C:\ProgramData\BlueStacksSetup =>.BlueStack Systems, Inc. O43 - CFD: 29/10/2012 - [0] SHD -- C:\ProgramData\Bureau =>.Microsoft Corporation O43 - CFD: 15/07/2016 - [] D -- C:\ProgramData\BwinpB O43 - CFD: 30/10/2012 - [] D -- C:\ProgramData\CyberLink =>.CyberLink Corporation O43 - CFD: 27/12/2016 - [] D -- C:\ProgramData\DatacardService =>.Entriq, Inc. O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation O43 - CFD: 15/04/2016 - [] D -- C:\ProgramData\desktopfind =>HackTool.WinActivator O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation O43 - CFD: 26/12/2016 - [] D -- C:\ProgramData\ESTsoft =>.ESTsoft O43 - CFD: 29/10/2012 - [0] SHD -- C:\ProgramData\Favoris =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Favorites =>.Microsoft Corporation O43 - CFD: 09/02/2017 - [0] D -- C:\ProgramData\gadgj O43 - CFD: 31/10/2012 - [] D -- C:\ProgramData\Hewlett-Packard =>.Hewlett-Packard O43 - CFD: 19/06/2016 - [0] D -- C:\ProgramData\Hisarah O43 - CFD: 29/12/2013 - [0] D -- C:\ProgramData\IDM =>.IDM O43 - CFD: 04/04/2014 - [] D -- C:\ProgramData\InstallMate =>.Superfluous.Tarma O43 - CFD: 31/10/2012 - [] D -- C:\ProgramData\InterAction studios O43 - CFD: 21/05/2013 - [] D -- C:\ProgramData\iWin =>.iWin O43 - CFD: 03/11/2012 - [] D -- C:\ProgramData\JollyBear O43 - CFD: 19/12/2016 - [] D -- C:\ProgramData\JwinpJ O43 - CFD: 14/01/2017 - [] D -- C:\ProgramData\KLS Soft O43 - CFD: 02/12/2016 - [] D -- C:\ProgramData\KRyLack Software =>.KRyLack Software O43 - CFD: 28/12/2016 - [0] D -- C:\ProgramData\Lenovo =>.Lenovo O43 - CFD: 13/04/2014 - [] D -- C:\ProgramData\Log =>.Unknow O43 - CFD: 29/06/2016 - [] D -- C:\ProgramData\lwinpl O43 - CFD: 12/01/2017 - [] D -- C:\ProgramData\Macrium =>.Macrium O43 - CFD: 26/10/2013 - [] D -- C:\ProgramData\MAGIX =>.Magix O43 - CFD: 29/10/2012 - [0] SHD -- C:\ProgramData\Menu Démarrer =>.Microsoft Corporation O43 - CFD: 10/12/2016 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation O43 - CFD: 22/01/2013 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation O43 - CFD: 15/02/2015 - [] D -- C:\ProgramData\MobiConnect O43 - CFD: 29/10/2012 - [0] SHD -- C:\ProgramData\Modèles =>.Microsoft Corporation O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Mozilla =>.Mozilla Corporation O43 - CFD: 18/08/2016 - [0] D -- C:\ProgramData\Outlose O43 - CFD: 09/06/2016 - [] D -- C:\ProgramData\owinpo O43 - CFD: 13/01/2017 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation O43 - CFD: 16/04/2016 - [] D -- C:\ProgramData\PixelPlanet =>.PixelPlanet O43 - CFD: 18/05/2013 - [] D -- C:\ProgramData\PlayFirst O43 - CFD: 27/05/2014 - [] D -- C:\ProgramData\PopCap Games =>.PopCap Games O43 - CFD: 19/12/2016 - [] D -- C:\ProgramData\QQBrowser =>.Superfluous.SpeedBrowser O43 - CFD: 02/05/2014 - [] D -- C:\ProgramData\Ralink Driver =>.Ralink O43 - CFD: 28/09/2013 - [] D -- C:\ProgramData\simplitec =>.Simplitec O43 - CFD: 22/02/2017 - [] D -- C:\ProgramData\Skype =>.Skype O43 - CFD: 07/01/2017 - [] D -- C:\ProgramData\Softland =>.Softland O43 - CFD: 28/08/2013 - [] D -- C:\ProgramData\Sony =>.Sony O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation O43 - CFD: 18/05/2013 - [] D -- C:\ProgramData\SugarGames O43 - CFD: 30/10/2012 - [] D -- C:\ProgramData\Sun =>.Oracle O43 - CFD: 11/08/2014 - [] D -- C:\ProgramData\Synaptics =>.Synaptics O43 - CFD: 02/03/2014 - [] D -- C:\ProgramData\Tarma Installer =>.Superfluous.Tarma O43 - CFD: 18/03/2017 - [] AD -- C:\ProgramData\Temp =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation O43 - CFD: 23/03/2016 - [] D -- C:\ProgramData\Tencent =>.Superfluous.Tencent O43 - CFD: 02/09/2013 - [] D -- C:\ProgramData\The-Dogies O43 - CFD: 06/07/2016 - [0] D -- C:\ProgramData\Toolrain O43 - CFD: 15/11/2012 - [] D -- C:\ProgramData\TreeCardGames =>.TreeCardGames O43 - CFD: 19/12/2016 - [0] D -- C:\ProgramData\ttff O43 - CFD: 23/03/2016 - [] D -- C:\ProgramData\TXQMPC O43 - CFD: 10/11/2013 - [] D -- C:\ProgramData\Ulead Systems =>.Ulead Systems O43 - CFD: 30/10/2012 - [] D -- C:\ProgramData\Uninstall =>.Unknow O43 - CFD: 23/06/2016 - [] D -- C:\ProgramData\VMware =>.VMware O43 - CFD: 18/05/2013 - [] D -- C:\ProgramData\WebcamMax =>.CoolwareMax O43 - CFD: 06/01/2017 - [0] D -- C:\ProgramData\WinSAPSvc =>PUP.Optional.Youndoo O43 - CFD: 13/02/2017 - [] D -- C:\ProgramData\wintools O43 - CFD: 30/10/2012 - [] D -- C:\ProgramData\{D3B41B92-9BC2-43EB-916A-4FA9E8191837} O43 - CFD: 29/08/2015 - [] D -- C:\Program Files\Common Files\Adobe =>.Adobe O43 - CFD: 29/10/2012 - [] D -- C:\Program Files\Common Files\Ahead =>.Ahead Software O43 - CFD: 02/09/2015 - [] D -- C:\Program Files\Common Files\ArcSoft =>.ArcSoft O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\Common Files\Atheros =>.Qualcomm Atheros O43 - CFD: 17/03/2017 - [] D -- C:\Program Files\Common Files\AV =>.Avast O43 - CFD: 08/05/2016 - [] D -- C:\Program Files\Common Files\BCL Technologies =>.BCL Technologies O43 - CFD: 09/10/2016 - [] D -- C:\Program Files\Common Files\Business Objects =>.Business Objects O43 - CFD: 29/10/2012 - [] D -- C:\Program Files\Common Files\DESIGNER =>.Designer O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\Common Files\InstallShield =>.InstallShield O43 - CFD: 21/01/2013 - [] D -- C:\Program Files\Common Files\Intel =>.Intel Corporation O43 - CFD: 25/09/2013 - [] D -- C:\Program Files\Common Files\Java =>.Oracle O43 - CFD: 28/09/2013 - [] D -- C:\Program Files\Common Files\MAGIX Services =>.MAGIX_Software_GmbH O43 - CFD: 26/10/2013 - [] D -- C:\Program Files\Common Files\MAGIX Shared =>.MAGIX AG O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\Common Files\microsoft shared =>.Microsoft Corporation O43 - CFD: 08/05/2016 - [] D -- C:\Program Files\Common Files\PixelPlanet =>.PixelPlanet O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\Common Files\Roxio Shared =>.Roxio O43 - CFD: 14/02/2017 - [] D -- C:\Program Files\Common Files\Services =>.Microsoft Corporation O43 - CFD: 02/02/2017 - [] D -- C:\Program Files\Common Files\Skype =>.Skype O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Common Files\SpeechEngines =>.Microsoft Corporation O43 - CFD: 31/10/2012 - [] D -- C:\Program Files\Common Files\System =>.Microsoft Corporation O43 - CFD: 30/10/2012 - [] D -- C:\Program Files\Common Files\Telespree =>.Telespree Communications O43 - CFD: 23/03/2016 - [] D -- C:\Program Files\Common Files\Tencent =>.Superfluous.Tencent O43 - CFD: 10/11/2013 - [] D -- C:\Program Files\Common Files\Ulead Systems =>.Ulead Systems O43 - CFD: 01/10/2013 - [] D -- C:\Program Files\Common Files\VMware =>.VMware O43 - CFD: 22/01/2013 - [] D -- C:\Program Files\Common Files\Windows Live =>.Microsoft Corporation O43 - CFD: 26/10/2013 - [] D -- C:\Program Files\Common Files\xara =>.Xara O43 - CFD: 08/05/2016 - [] D -- C:\Program Files\Common Files\XpressUpdate =>.PixelPlanet O43 - CFD: 07/12/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\ABBYY =>.ABBYY Software O43 - CFD: 30/10/2012 - [] D -- C:\Users\SAMIA\AppData\Roaming\Adobe =>.Adobe O43 - CFD: 17/03/2017 - [] D -- C:\Users\SAMIA\AppData\Roaming\aMule =>Adware.aMULEcustom O43 - CFD: 13/05/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\Archivarius 3000 O43 - CFD: 02/09/2015 - [] D -- C:\Users\SAMIA\AppData\Roaming\ArcSoft =>.ArcSoft O43 - CFD: 17/03/2017 - [] D -- C:\Users\SAMIA\AppData\Roaming\AVAST Software =>.AVAST Software O43 - CFD: 28/05/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\Babylon =>Adware.Babylon O43 - CFD: 07/03/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\Baidu =>.Baidu O43 - CFD: 11/01/2014 - [] D -- C:\Users\SAMIA\AppData\Roaming\Baidu Security =>.Baidu Technology O43 - CFD: 17/08/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\Betcat =>PUP.Optional.Betcat O43 - CFD: 18/06/2013 - [0] D -- C:\Users\SAMIA\AppData\Roaming\BitTorrent O43 - CFD: 21/09/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\CityBus O43 - CFD: 21/06/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\ClipMagic O43 - CFD: 27/12/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\Complitly =>PUP.Optional.PredictAd O43 - CFD: 05/04/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\CoSoSys O43 - CFD: 27/08/2015 - [] D -- C:\Users\SAMIA\AppData\Roaming\Digiarty =>.Digiarty O43 - CFD: 02/07/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\Disney Interactive Studios =>.Disney Interactive Studios O43 - CFD: 18/03/2017 - [] D -- C:\Users\SAMIA\AppData\Roaming\DMCache =>.DMCache O43 - CFD: 21/01/2013 - [0] D -- C:\Users\SAMIA\AppData\Roaming\DRPSu =>.Driver PackSolution O43 - CFD: 15/01/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\dvdcss =>.VideoLan Team O43 - CFD: 05/10/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\eCyber =>.Superfluous.Elex O43 - CFD: 19/12/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\ehadh O43 - CFD: 12/06/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\Elex-tech =>.Superfluous.Elex O43 - CFD: 26/12/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\ESTsoft =>.ESTsoft O43 - CFD: 29/01/2017 - [] D -- C:\Users\SAMIA\AppData\Roaming\Firefox =>.Mozilla Corporation O43 - CFD: 29/09/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\Foxit Software =>.Foxit Software O43 - CFD: 19/12/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\Google =>.Google O43 - CFD: 30/10/2012 - [0] D -- C:\Users\SAMIA\AppData\Roaming\Hewlett-Packard =>.Hewlett-Packard O43 - CFD: 31/10/2012 - [] D -- C:\Users\SAMIA\AppData\Roaming\hpqLog =>.Hewlett-Packard O43 - CFD: 29/10/2012 - [] D -- C:\Users\SAMIA\AppData\Roaming\Identities =>.Microsoft Corporation O43 - CFD: 02/12/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\IDM =>.IDM O43 - CFD: 02/05/2014 - [] D -- C:\Users\SAMIA\AppData\Roaming\InstallShield =>.InstallShield O43 - CFD: 26/12/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\iWesoft =>.iWesoft O43 - CFD: 21/05/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\iWin =>.iWin O43 - CFD: 03/03/2017 - [] D -- C:\Users\SAMIA\AppData\Roaming\Kyubey =>PUP.Optional.CrossRider O43 - CFD: 30/10/2012 - [] D -- C:\Users\SAMIA\AppData\Roaming\Macromedia =>.Macromedia O43 - CFD: 27/08/2015 - [] D -- C:\Users\SAMIA\AppData\Roaming\MAGIX =>.Magix O43 - CFD: 14/07/2009 - [0] D -- C:\Users\SAMIA\AppData\Roaming\Media Center Programs =>.Microsoft Corporation O43 - CFD: 14/04/2014 - [] D -- C:\Users\SAMIA\AppData\Roaming\Media Player Classic =>.Microsoft Corporation O43 - CFD: 17/12/2016 - [] SD -- C:\Users\SAMIA\AppData\Roaming\Microsoft =>.Microsoft Corporation O43 - CFD: 15/05/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\Mozilla =>.Mozilla Corporation O43 - CFD: 29/02/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\mysites123 =>PUP.Optional.Mysites123 O43 - CFD: 01/11/2012 - [] D -- C:\Users\SAMIA\AppData\Roaming\Nero =>.Ahead Corporation O43 - CFD: 02/06/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\NetScoutToolbar O43 - CFD: 30/10/2012 - [] D -- C:\Users\SAMIA\AppData\Roaming\PerformerSoft =>.Superfluous.PerformerSoft O43 - CFD: 16/04/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\PixelPlanet =>.PixelPlanet O43 - CFD: 18/05/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\PlayFirst O43 - CFD: 28/08/2013 - [0] D -- C:\Users\SAMIA\AppData\Roaming\Publish Providers =>.Unknow O43 - CFD: 29/06/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\qksee =>.Superfluous.TaiwanShuiMu O43 - CFD: 03/06/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\Real =>.RealNetworks Inc. O43 - CFD: 05/07/2014 - [] D -- C:\Users\SAMIA\AppData\Roaming\RegistryKeys =>.Microsoft Corporation O43 - CFD: 30/10/2012 - [] D -- C:\Users\SAMIA\AppData\Roaming\Roxio Log Files =>.Roxio O43 - CFD: 03/07/2016 - [] RHD -- C:\Users\SAMIA\AppData\Roaming\SecuROM =>.SecuROM O43 - CFD: 30/10/2012 - [] D -- C:\Users\SAMIA\AppData\Roaming\Sierra Wireless =>.Sierra Wireless Inc O43 - CFD: 14/02/2017 - [] D -- C:\Users\SAMIA\AppData\Roaming\SimpleTV V03 O43 - CFD: 28/09/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\simplitec =>.Simplitec O43 - CFD: 30/10/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\Skype =>.Skype O43 - CFD: 07/07/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\Smadav =>.SmadAV O43 - CFD: 07/01/2017 - [] D -- C:\Users\SAMIA\AppData\Roaming\Softland =>.Softland O43 - CFD: 20/02/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\SolSuite O43 - CFD: 28/08/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\Sony =>.Sony O43 - CFD: 22/01/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\Synaptics =>.Synaptics O43 - CFD: 30/07/2014 - [0] D -- C:\Users\SAMIA\AppData\Roaming\Systweak =>.Superfluous.Systweak O43 - CFD: 23/03/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\Tencent =>.Superfluous.Tencent O43 - CFD: 29/05/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\TigerPlayer O43 - CFD: 06/04/2014 - [] D -- C:\Users\SAMIA\AppData\Roaming\ToomkyGames.com O43 - CFD: 12/08/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\TSv O43 - CFD: 10/11/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\Ulead Systems =>.Ulead Systems O43 - CFD: 30/07/2014 - [] D -- C:\Users\SAMIA\AppData\Roaming\URSoft =>.URSoft O43 - CFD: 02/12/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\uTorrent O43 - CFD: 27/12/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\uTorrent Turbo Booster O43 - CFD: 14/02/2017 - [] D -- C:\Users\SAMIA\AppData\Roaming\vlc =>.VideoLan Team O43 - CFD: 23/06/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\VMware =>.VMware O43 - CFD: 17/08/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\Web Cake =>PUP.Optional.WebCake O43 - CFD: 14/08/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\WebCake =>PUP.Optional.WebCake O43 - CFD: 30/10/2012 - [] D -- C:\Users\SAMIA\AppData\Roaming\WebcamMax =>.CoolwareMax O43 - CFD: 26/11/2015 - [] D -- C:\Users\SAMIA\AppData\Roaming\Wildfire O43 - CFD: 01/11/2012 - [] D -- C:\Users\SAMIA\AppData\Roaming\WinRAR =>.WinRAR O43 - CFD: 17/03/2017 - [] D -- C:\Users\SAMIA\AppData\Roaming\WinSAPSvc =>PUP.Optional.Youndoo O43 - CFD: 01/03/2017 - [] D -- C:\Users\SAMIA\AppData\Roaming\WinSnare =>.Superfluous.WinSnare O43 - CFD: 12/06/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\WinZiper =>.Superfluous.WinZipper O43 - CFD: 23/03/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\XBMC =>.XBMC O43 - CFD: 26/08/2015 - [] D -- C:\Users\SAMIA\AppData\Roaming\Xilisoft =>.Xilisoft O43 - CFD: 16/04/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\YCanPDF =>.YCanPDF O43 - CFD: 18/03/2017 - [] D -- C:\Users\SAMIA\AppData\Roaming\ZHP =>.Nicolas Coolman O43 - CFD: 09/06/2016 - [] D -- C:\Users\SAMIA\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108 O43 - CFD: 11/12/2013 - [] D -- C:\Users\SAMIA\AppData\Local\ABBYY =>.ABBYY Software O43 - CFD: 01/04/2016 - [] D -- C:\Users\SAMIA\AppData\Local\Adobe =>.Adobe O43 - CFD: 29/10/2012 - [0] SHD -- C:\Users\SAMIA\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 31/10/2012 - [] D -- C:\Users\SAMIA\AppData\Local\ArcSoft =>.ArcSoft O43 - CFD: 10/01/2017 - [] D -- C:\Users\SAMIA\AppData\Local\AxCrypt =>.AxCrypt O43 - CFD: 28/05/2013 - [] D -- C:\Users\SAMIA\AppData\Local\Babylon =>Adware.Babylon O43 - CFD: 07/03/2016 - [] D -- C:\Users\SAMIA\AppData\Local\BlueStacks =>.BlueStack Systems, Inc. O43 - CFD: 30/10/2012 - [] D -- C:\Users\SAMIA\AppData\Local\BMExplorer =>.BMExplorer O43 - CFD: 09/07/2016 - [] D -- C:\Users\SAMIA\AppData\Local\CEF =>.CEF O43 - CFD: 16/03/2017 - [] D -- C:\Users\SAMIA\AppData\Local\CentBrowser =>.Cent Studio O43 - CFD: 26/02/2017 - [] D -- C:\Users\SAMIA\AppData\Local\Chedot O43 - CFD: 04/04/2014 - [] D -- C:\Users\SAMIA\AppData\Local\Comodo =>.Comodo O43 - CFD: 27/12/2016 - [] D -- C:\Users\SAMIA\AppData\Local\CrashDumps =>.Microsoft Corporation O43 - CFD: 29/05/2013 - [0] D -- C:\Users\SAMIA\AppData\Local\Diagnostics =>.Microsoft Corporation O43 - CFD: 08/05/2016 - [] D -- C:\Users\SAMIA\AppData\Local\Downloaded Installations =>.Microsoft Corporation O43 - CFD: 18/12/2015 - [] D -- C:\Users\SAMIA\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation O43 - CFD: 23/10/2013 - [] D -- C:\Users\SAMIA\AppData\Local\ExtractNow O43 - CFD: 29/05/2013 - [] D -- C:\Users\SAMIA\AppData\Local\Facebook =>.Facebook O43 - CFD: 29/01/2017 - [] D -- C:\Users\SAMIA\AppData\Local\Firefox =>.Mozilla Corporation O43 - CFD: 10/01/2017 - [] D -- C:\Users\SAMIA\AppData\Local\FortStandalone O43 - CFD: 01/04/2016 - [] D -- C:\Users\SAMIA\AppData\Local\Geckofx =>.Geckofx O43 - CFD: 10/11/2016 - [] D -- C:\Users\SAMIA\AppData\Local\Google =>.Google O43 - CFD: 30/10/2012 - [] D -- C:\Users\SAMIA\AppData\Local\Hewlett-Packard =>.Hewlett-Packard O43 - CFD: 30/10/2012 - [] D -- C:\Users\SAMIA\AppData\Local\Hewlett-Packard_Developme =>.Hewlett-Packard O43 - CFD: 10/12/2016 - [] D -- C:\Users\SAMIA\AppData\Local\Hipmy O43 - CFD: 12/06/2016 - [] D -- C:\Users\SAMIA\AppData\Local\Hisarah O43 - CFD: 29/10/2012 - [0] SHD -- C:\Users\SAMIA\AppData\Local\Historique =>.Microsoft Corporation O43 - CFD: 26/12/2016 - [] D -- C:\Users\SAMIA\AppData\Local\iWesoft =>.iWesoft O43 - CFD: 03/11/2012 - [] D -- C:\Users\SAMIA\AppData\Local\JollyBear O43 - CFD: 28/12/2016 - [0] D -- C:\Users\SAMIA\AppData\Local\Lenovo =>.Lenovo O43 - CFD: 06/01/2013 - [] D -- C:\Users\SAMIA\AppData\Local\Macromedia =>.Macromedia O43 - CFD: 28/09/2013 - [] D -- C:\Users\SAMIA\AppData\Local\Magix =>.Magix O43 - CFD: 29/08/2015 - [] D -- C:\Users\SAMIA\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 23/07/2013 - [] D -- C:\Users\SAMIA\AppData\Local\Microsoft Games =>.Microsoft Corporation O43 - CFD: 29/10/2012 - [0] D -- C:\Users\SAMIA\AppData\Local\Microsoft Help =>.Microsoft Corporation O43 - CFD: 10/01/2017 - [] D -- C:\Users\SAMIA\AppData\Local\Microsoft_Corporation =>.Microsoft Corporation O43 - CFD: 28/07/2014 - [] D -- C:\Users\SAMIA\AppData\Local\Mozilla =>.Mozilla Corporation O43 - CFD: 14/07/2016 - [] D -- C:\Users\SAMIA\AppData\Local\Outlose O43 - CFD: 07/06/2013 - [0] D -- C:\Users\SAMIA\AppData\Local\PackageAware =>PUP.Optional.BearShare O43 - CFD: 26/06/2013 - [] D -- C:\Users\SAMIA\AppData\Local\Programs =>.Microsoft Corporation O43 - CFD: 07/06/2013 - [] D -- C:\Users\SAMIA\AppData\Local\PutLockerDownloader =>PUP.Optional.PutLocker O43 - CFD: 30/10/2012 - [] D -- C:\Users\SAMIA\AppData\Local\Roxio =>.Roxio O43 - CFD: 01/06/2016 - [0] D -- C:\Users\SAMIA\AppData\Local\Skype =>.Skype O43 - CFD: 01/04/2016 - [] D -- C:\Users\SAMIA\AppData\Local\Smart_PC_Soft =>.Smart PC Soft O43 - CFD: 28/08/2013 - [] D -- C:\Users\SAMIA\AppData\Local\Sony =>.Sony O43 - CFD: 16/06/2013 - [] D -- C:\Users\SAMIA\AppData\Local\SubtitleCreator O43 - CFD: 18/03/2017 - [] AD -- C:\Users\SAMIA\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 29/10/2012 - [0] SHD -- C:\Users\SAMIA\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 29/06/2016 - [] D -- C:\Users\SAMIA\AppData\Local\Toolrain O43 - CFD: 04/04/2014 - [] D -- C:\Users\SAMIA\AppData\Local\Torch =>.Superfluous.Torch O43 - CFD: 30/10/2012 - [] D -- C:\Users\SAMIA\AppData\Local\VirtualStore =>.Microsoft Corporation O43 - CFD: 12/06/2015 - [] D -- C:\Users\SAMIA\AppData\Local\VMware =>.VMware O43 - CFD: 22/01/2013 - [0] D -- C:\Users\SAMIA\AppData\Local\WMTools Downloaded Files =>.WMTools O43 - CFD: 28/09/2013 - [] D -- C:\Users\SAMIA\AppData\Local\Xara =>.Xara O43 - CFD: 26/06/2013 - [0] D -- C:\Users\SAMIA\AppData\Local\Programs\Common =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] RD -- C:\Users\SAMIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation O43 - CFD: 29/10/2012 - [] RD -- C:\Users\SAMIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools O43 - CFD: 17/03/2017 - [] D -- C:\Users\SAMIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC =>Adware.aMULEcustom O43 - CFD: 07/06/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory =>.FormatFactory O43 - CFD: 05/07/2014 - [] D -- C:\Users\SAMIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FTDownloader.com =>PUP.Optional.Downware O43 - CFD: 24/05/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation O43 - CFD: 08/03/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager =>.Tonec Inc O43 - CFD: 14/07/2009 - [] RD -- C:\Users\SAMIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation O43 - CFD: 09/10/2016 - [] RD -- C:\Users\SAMIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation O43 - CFD: 23/10/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer =>.The KMPlayer Team O43 - CFD: 30/12/2016 - [] D -- C:\Users\SAMIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Transparent Image Converter O43 - CFD: 02/12/2013 - [] D -- C:\Users\SAMIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 29/10/2012 - [0] SHD -- C:\Users\Default\AppData\Local\Historique =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 29/10/2012 - [0] SHD -- C:\Users\Default User\AppData\Local\Historique =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 16/03/2017 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\CrashDumps =>.Microsoft Corporation O43 - CFD: 20/01/2017 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Firefox =>.Mozilla Corporation O43 - CFD: 01/06/2016 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Google =>.Google O43 - CFD: 21/02/2015 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 16/10/2013 - [0] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\temp =>.Microsoft Corporation O43 - CFD: 20/10/2014 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Adobe =>.Adobe O43 - CFD: 14/12/2016 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\aMule =>Adware.aMULEcustom O43 - CFD: 20/10/2014 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\AVAST Software =>.AVAST Software O43 - CFD: 20/01/2017 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Firefox =>.Mozilla Corporation O43 - CFD: 29/10/2012 - [0] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\hpqLog =>.Hewlett-Packard O43 - CFD: 14/12/2016 - [] SD -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation O43 - CFD: 20/01/2017 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Mozilla =>.Mozilla Corporation O43 - CFD: 12/03/2016 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Softland =>.Softland O43 - CFD: 18/01/2017 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Tencent =>.Superfluous.Tencent O43 - CFD: 23/06/2016 - [0] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\VMware =>.VMware ---\\ ShellIconOverlayIdentifiers (SIOI) (4) - 1s O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation O106 - SIOI: IDM Shell Extension [IDM Shell Extension] - {CDC95B92-E27C-4745-A8C5-64A52A78855D}. (.Tonec Inc. - Internet Download Manager module.) -- C:\Program Files\Internet Download Manager\IDMShellExt.dll =>.Tonec Inc.® O106 - SIOI: [Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81}. (.Microsoft Corporation - IU de cache côté client.) -- C:\Windows\System32\cscui.dll =>.Microsoft Corporation O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation ---\\ Enumération des clés StartupReg (17) - 6s O53 - SMSR:HKLM\...\startupreg\Archivarius 3000 [Key] . (...) -- C:\Program Files\Archivarius 3000\Archivarius3000.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\ArcSoft Connection Service [Key] . (.ArcSoft Inc. - ArcSoft Connect Daemon.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe =>.ArcSoft Inc. O53 - SMSR:HKLM\...\startupreg\AtherosBtStack [Key] . (.Atheros Communications - Serveur Stack Bluetooth.) -- C:\Program Files\Bluetooth Suite\BtvStack.exe =>.Atheros Communications O53 - SMSR:HKLM\...\startupreg\Google Update [Key] . (.Google Inc. - Google Update Core.) -- C:\Users\SAMIA\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe =>.Google Inc. O53 - SMSR:HKLM\...\startupreg\HotKeysCmds [Key] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe =>.Intel Corporation O53 - SMSR:HKLM\...\startupreg\HPConnectionManager [Key] . (.Hewlett-Packard Development Company L.P. - HPCMDelayStart Application.) -- C:\Program Files\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe =>.Hewlett-Packard Development Company L.P. O53 - SMSR:HKLM\...\startupreg\HSPALauncher [Key] . (.Copyright (C) 2010 - HSDPALauncher MFC Application.) -- C:\Program Files\HSPA USB Modem\HSPALauncher.exe O53 - SMSR:HKLM\...\startupreg\IgfxTray [Key] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxtray.exe =>.Intel Corporation O53 - SMSR:HKLM\...\startupreg\NUSB3MON [Key] . (.Renesas Electronics Corporation - USB 3.0 Monitor.) -- c:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe =>.Renesas Electronics Corporation O53 - SMSR:HKLM\...\startupreg\PC Speed Maximizer [Key] . (...) -- C:\Program Files\PC Speed Maximizer\SPMLauncher.exe (.not file.) =>.Superfluous.PCSpeedMaximizer O53 - SMSR:HKLM\...\startupreg\Persistence [Key] . (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe =>.Intel Corporation O53 - SMSR:HKLM\...\startupreg\PixelPlanet PdfPrinter-Monitor [Key] . (.PixelPlanet GmbH - PixelPlanet PdfPrinter Monitor.) -- C:\Program Files\Common Files\PixelPlanet\PdfPrinter 6\PdfPrinterMonitor.exe =>.PixelPlanet GmbH O53 - SMSR:HKLM\...\startupreg\QLBController [Key] . (.Hewlett-Packard Company - QLBController.) -- C:\Program Files\Hewlett-Packard\HP Hotkey Support\QLBController.exe =>.Hewlett-Packard Company O53 - SMSR:HKLM\...\startupreg\Skype [Key] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Phone\Skype.exe =>.Skype Technologies S.A. O53 - SMSR:HKLM\...\startupreg\SynTPEnh [Key] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe =>.Synaptics Incorporated O53 - SMSR:HKLM\...\startupreg\TrayServer [Key] . (.MAGIX AG - Trayserver.) -- C:\Program Files\MAGIX\Movie_Edit_Pro_15_Plus_Download_version\TrayServer.exe =>.MAGIX AG O53 - SMSR:HKLM\...\startupreg\vmware-tray [Key] . (...) -- C:\Program Files\VMware\VMware Workstation\vmware-tray.exe (.not file.) ---\\ Liste des pilotes du système (88) - 124s O58 - SDL:2009/07/14 02:26:15 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:26:17 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:26:15 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\drivers\adpu320.sys [317400] =>.Microsoft Windows® O58 - SDL:2005/02/23 14:58:56 A . (.Arcsoft, Inc. - Arcsoft(R) ASPI Shell.) -- C:\Windows\System32\drivers\afc.sys [317400] =>.ArcSoft, Inc. O58 - SDL:2009/07/14 02:26:15 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:26:15 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:26:15 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:26:15 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:26:15 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/08/13 11:45:56 A . (...) -- C:\Windows\System32\drivers\ArcHlp.sys [317400] =>.ArcSoft, Inc.® O58 - SDL:2009/07/14 02:26:15 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [317400] =>.Microsoft Windows® O58 - SDL:2011/02/22 12:15:16 A . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driv.) -- C:\Windows\System32\drivers\athr.sys [317400] =>.Atheros Communications, Inc. O58 - SDL:2009/07/13 23:02:49 A . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gi.) -- C:\Windows\System32\drivers\b57nd60x.sys [317400] =>.Broadcom Corporation O58 - SDL:2014/02/24 03:32:28 A . (.Baidu, Inc. - Baidu Antivirus Hook Base.) -- C:\Windows\System32\drivers\Bhbase.sys [317400] =>.Baidu Online Network Technology (Beijing)Co., Ltd® O58 - SDL:2009/07/13 23:53:28 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [317400] =>.Brother Industries, Ltd. O58 - SDL:2009/07/13 23:53:28 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [317400] =>.Brother Industries, Ltd. O58 - SDL:2009/07/14 01:57:25 A . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [317400] =>.Brother Industries Ltd. O58 - SDL:2009/07/13 23:53:32 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [317400] =>.Brother Industries Ltd. O58 - SDL:2009/07/13 23:53:33 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [317400] =>.Brother Industries Ltd. O58 - SDL:2009/07/13 23:53:33 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [317400] =>.Brother Industries Ltd. O58 - SDL:2011/01/06 20:05:10 A . (.Atheros - Atheros A2DP driver.) -- C:\Windows\System32\drivers\btath_a2dp.sys [317400] =>.Atheros O58 - SDL:2011/01/06 20:05:10 A . (.Atheros - Atheros BUS driver.) -- C:\Windows\System32\drivers\btath_bus.sys [317400] =>.Atheros O58 - SDL:2011/01/06 20:05:12 A . (.Atheros - Atheros FILTER driver.) -- C:\Windows\System32\drivers\btath_flt.sys [317400] =>.Atheros O58 - SDL:2011/01/06 20:05:12 A . (.Atheros - Atheros HCRP driver.) -- C:\Windows\System32\drivers\btath_hcrp.sys [317400] =>.Atheros O58 - SDL:2011/01/06 20:05:14 A . (.Atheros - Atheros FILTER driver.) -- C:\Windows\System32\drivers\btath_lwflt.sys [317400] =>.Atheros O58 - SDL:2011/01/06 20:05:14 A . (.Atheros - Atheros AVRCP driver.) -- C:\Windows\System32\drivers\btath_rcp.sys [317400] =>.Atheros O58 - SDL:2011/01/06 20:05:14 A . (.Atheros - BtFilter Driver.) -- C:\Windows\System32\drivers\btfilter.sys [317400] =>.Atheros O58 - SDL:2009/07/13 23:02:48 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbdx.sys [317400] =>.Broadcom Corporation O58 - SDL:2009/07/14 02:26:21 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [317400] =>.Microsoft Windows® O58 - SDL:2008/08/29 17:54:40 A . (.Mobile Connector - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\cmusbser.sys [317400] =>.Mobile Connector O58 - SDL:2009/07/14 02:20:28 A . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\drivers\djsvs.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:28 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/13 23:02:48 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbdx.sys [317400] =>.Broadcom Corporation O58 - SDL:2007/07/20 10:40:44 A . (.TopLang Software - File Lock Kernel.) -- C:\Windows\System32\drivers\FLockXP.sys [317400] O58 - SDL:2009/07/13 23:54:14 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [317400] =>.Hauppauge Computer Works, Inc. O58 - SDL:2009/09/18 03:54:14 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\drivers\HECI.sys [317400] =>.Intel Corporation O58 - SDL:2011/07/18 08:11:42 A . (.Hewlett-Packard Company - Keyboard Filter Driver.) -- C:\Windows\System32\drivers\HpqKbFiltr.sys [317400] =>.Hewlett-Packard Company® O58 - SDL:2009/07/14 02:20:28 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:36 A . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\drivers\iaStorV.sys [317400] =>.Microsoft Windows® O58 - SDL:2016/10/17 16:35:48 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\drivers\idmwfp.sys [317400] =>.Tonec Inc.® O58 - SDL:2011/06/26 18:50:48 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd32.sys [317400] =>.Intel Corporation O58 - SDL:2009/07/14 02:20:36 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [317400] =>.Microsoft Windows® O58 - SDL:2010/10/15 01:27:18 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\drivers\IntcDAud.sys [317400] =>.Intel(R) Corporation O58 - SDL:2016/05/23 03:41:44 A . (.Elex do Brasil Participações Ltda - iSafe Kernel Boot Driver.) -- C:\Windows\System32\drivers\iSafeKrnlBoot.sys [317400] =>.Superfluous.Elex O58 - SDL:2016/05/19 07:42:01 A . (.Elex do Brasil Participações Ltda - iSafeNetFilter SDK WFP Driver (WPP).) -- C:\Windows\System32\drivers\iSafeNetFilter.sys [317400] =>.Superfluous.Elex O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:37 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:44 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:44 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:44 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:19:04 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:19:04 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [317400] =>.Microsoft Windows® O58 - SDL:2010/10/26 11:08:08 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.20 32-bit Dr.) -- C:\Windows\System32\drivers\Rt86win7.sys [317400] =>.Realtek Semiconductor Corp® O58 - SDL:2011/09/17 10:17:08 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHDA.sys [317400] =>.Realtek Semiconductor Corp® O58 - SDL:2011/02/22 19:21:54 A . (.Realtek - Realtek 8136/8168/8169 NDIS6 32-bit Driver.) -- C:\Windows\System32\drivers\Rtlh86.sys [317400] =>.Realtek Semiconductor Corp® O58 - SDL:2011/02/15 11:37:10 A . (.Realtek Semiconductor Corp. - Realtek Pcie CardReader Driver for 2K/XP/Vi.) -- C:\Windows\System32\drivers\RtsPStor.sys [317400] =>.Realtek Semiconductor Corp® O58 - SDL:2009/07/13 21:50:20 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [317400] =>.Macrovision Corporation, Macrovision Europe Limited, O58 - SDL:2009/07/14 02:19:04 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:19:04 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:19:04 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [317400] =>.Microsoft Windows® O58 - SDL:2011/09/15 18:34:40 A . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\Windows\System32\drivers\SynTP.sys [317400] =>.Synaptics Incorporated® O58 - SDL:2016/03/23 19:42:04 A . (.Tencent - Tencent TS888 (电脑管家主动防御模块).) -- C:\Windows\System32\drivers\TS888.sys [317400] =>.Superfluous.Tencent O58 - SDL:2009/07/14 02:19:10 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [317400] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:19:11 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [317400] =>.Microsoft Windows® O58 - SDL:2012/04/15 22:32:14 A . (.Windows (R) Win 7 DDK provider - WebcamMax Capture.) -- C:\Windows\System32\drivers\wcmvcam.sys [317400] =>.Superfluous.TenkiTechnology O58 - SDL:2009/07/13 22:40:41 A . (...) -- C:\Windows\System32\ANSI.SYS [317400] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:44 A . (...) -- C:\Windows\System32\country.sys [317400] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:40 A . (...) -- C:\Windows\System32\HIMEM.SYS [317400] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:43 A . (...) -- C:\Windows\System32\KEY01.SYS [317400] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:43 A . (...) -- C:\Windows\System32\KEYBOARD.SYS [317400] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:23 A . (...) -- C:\Windows\System32\NTDOS.SYS [317400] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:31 A . (...) -- C:\Windows\System32\NTDOS404.SYS [317400] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:35 A . (...) -- C:\Windows\System32\NTDOS411.SYS [317400] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:39 A . (...) -- C:\Windows\System32\NTDOS412.SYS [317400] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:27 A . (...) -- C:\Windows\System32\NTDOS804.SYS [317400] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:11 A . (...) -- C:\Windows\System32\NTIO.SYS [317400] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:15 A . (...) -- C:\Windows\System32\NTIO404.SYS [317400] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:17 A . (...) -- C:\Windows\System32\NTIO411.SYS [317400] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:19 A . (...) -- C:\Windows\System32\NTIO412.SYS [317400] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:13 A . (...) -- C:\Windows\System32\NTIO804.SYS [317400] =>.Microsoft Corporation O58 - SDL:2016/03/23 22:58:15 A . (.电脑管家 - 电脑管家-TSSK Driver.) -- C:\Windows\System32\TSSK.sys [317400] =>.Superfluous.Tencent O58 - SDL:2017/01/10 19:00:34 A . (...) -- C:\Windows\System32\WinFLAdrv.sys [317400] =>.Newsoftwares.net, Inc SDN BHD® O58 - SDL:2013/11/02 14:25:37 A . (.NewSoftwares.net, Inc. - Virtual Encryption Driver.) -- C:\Windows\System32\WinVDEdrv.sys [317400] =>.NewSoftwares.net Inc. SDN. BHD.® O58 - SDL:2013/11/02 14:25:39 A . (...) -- C:\Windows\System32\WinVDEdrv6.sys [317400] =>.NewSoftwares.net Inc. SDN. BHD.® ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (4) - 382s O61 - LFC: 2017/03/17 10:22:38 A . (..) -- C:\Users\SAMIA\AppData\Roaming\Kyubey\Kyubey.exe [113152] =>PUP.Optional.CrossRider O61 - LFC: 2017/03/17 19:29:17 RA . (..) -- C:\Users\SAMIA\AppData\Roaming\Microsoft\Installer\{13D7C2E9-08E7-4889-94FF-87E707184E53}\_9B2B26538957EA274EE23D.exe [32606] O61 - LFC: 2017/03/17 10:25:00 A . (.Windows.) -- C:\Users\SAMIA\AppData\Roaming\WinSAPSvc\WinSAP.dll [218624] =>PUP.Optional.Youndoo O61 - LFC: 2017/03/17 13:30:52 A . (.InterSect Alliance Pty Ltd.) -- C:\Users\SAMIA\AppData\Roaming\WinSnare\WinSnare.dll [647168] =>.Superfluous.WinSnare ---\\ Associations Shell Spawning (10) - 7s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe =>.Microsoft Corporation O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® ---\\ Menu de démarrage Internet (11) - 4s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- c:\program files\mozilla firefox\firefox.exe =>.Mozilla Corporation® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- c:\users\samia\appdata\local\google\chrome\application\chrome.exe =>.Google Inc® O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\SAMIA\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Users\SAMIA\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Hipmy\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\SAMIA\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc. ---\\ Recherche d'infection sur les navigateurs (8) - 48s O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/ =>.Bing.com O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Delta Search) - http://www.delta-search.com/ =>.Superfluous.DeltaSearch O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} [DefaultScope] - (startpageing123) - http://www.startpageing123.com/ =>Hijacker.StartpageIng123 O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Goo) - http://www.google.com/ =>.Google Inc. O69 - SBI: SearchScopes [HKCU] {9359F63D-427F-4B89-B9C9-2FEA1975C7A9} - (Ask Search) - http://websearch.ask.com/ =>Toolbar.Ask O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Web Search) - http://search.certified-toolbar.com?si=39030&st=bs&tid=619&q={searchTerms} =>PUP.Optional.CertifiedToolbar O69 - SBI: SearchScopes [HKLM] {33BB0A4E-99AF-4226-BDF6-49120163DE86} [DefaultScope] - (startpageing123) - http://www.startpageing123.com/ =>Hijacker.StartpageIng123 O69 - SBI: SearchScopes [HKLM] {afdbddaa-5d3f-42ee-b79c-185a7020515b} - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com ---\\ Enumère les services démarrés par Svchost (33) - 14s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [317400] =>.Microsoft Corporation O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\audiosrv.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du se.) -- C:\Windows\System32\termsrv.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\System32\mmcss.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\KMSVC.DLL [317400] =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [317400] =>.Microsoft Corporation O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [317400] =>.Microsoft Corporation ---\\ Liste des exceptions du parefeu Windows (12) - 67s O87 - FAEL: "{3953A1AE-FD99-427A-8CA3-2F9B1DCE0B43}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Protected Search\ProtectedSearch.exe (.not file.) =>PUP.Optional.ProtectedSearch O87 - FAEL: "{B6DC9765-F0BD-4DDE-A0F4-91D54682D800}" [Out-None-P17-TRUE] .(...) -- C:\Program Files\Protected Search\ProtectedSearch.exe (.not file.) =>PUP.Optional.ProtectedSearch O87 - FAEL: "TCP Query User{11AE4372-083E-4CD5-987F-4FC4AE7EA967}F:\moto\motogp urt 3\wplotsp.exe" [In-None-P6-TRUE] .(...) -- F:\moto\motogp urt 3\wplotsp.exe (.not file.) O87 - FAEL: "UDP Query User{17E4D6E6-18E3-47B9-903E-38FCB3BE6F55}F:\moto\motogp urt 3\wplotsp.exe" [In-None-P17-TRUE] .(...) -- F:\moto\motogp urt 3\wplotsp.exe (.not file.) O87 - FAEL: "TCP Query User{1F379382-03EF-482F-AB71-2AFBB50B3AD8}C:\users\samia\appdata\local\temp\ir_ext_temp_0\autoplay\docs\rtmpgw.exe" [In-None-P6-TRUE] .(...) -- C:\users\samia\appdata\local\temp\ir_ext_temp_0\autoplay\docs\rtmpgw.exe (.not file.) =>.Temporary file not necessary O87 - FAEL: "UDP Query User{101A4036-E61A-4CC8-9F5A-0C69C6AF233C}C:\users\samia\appdata\local\temp\ir_ext_temp_0\autoplay\docs\rtmpgw.exe" [In-None-P17-TRUE] .(...) -- C:\users\samia\appdata\local\temp\ir_ext_temp_0\autoplay\docs\rtmpgw.exe (.not file.) =>.Temporary file not necessary O87 - FAEL: "{E7F8D43B-AED9-456B-AB4D-4E021068AE2D}" [In-None-P17-TRUE] .(...) -- C:\ProgramData\Outlose\Outlose.exe (.not file.) O87 - FAEL: "{0BC7E82B-2D94-4C8F-ADCD-E8BF714A30A7}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Firefox\bin\FirefoxUpdate.exe {45A8458D05878B9FE97F9367F3956CDE} O87 - FAEL: "{6253A42D-C1DA-44A2-8805-3F7AA9408529}" [In-None-P6-TRUE] .(...) -- C:\Program Files\MIO\loader\st320lt020-9yg142_w04391e8.exe O87 - FAEL: "{7BBBF655-49C4-48CA-BB05-99139F3C0160}" [In-None-P17-TRUE] .(...) -- C:\Program Files\MIO\loader\st320lt020-9yg142_w04391e8.exe O87 - FAEL: "{1466E8C7-2EDE-48C6-8EB2-E8784347346F}" [In-None-P6-TRUE] .(...) -- C:\Program Files\MIO\loader\st320lt020-9yg142_w04391e8.dat O87 - FAEL: "{DCD01DC8-A4D4-43B8-BAB6-2061AFB300A6}" [In-None-P17-TRUE] .(...) -- C:\Program Files\MIO\loader\st320lt020-9yg142_w04391e8.dat ---\\ Enumère les codes produits des logiciels (2) - 18s O90 - PUC: "5752A5CF59D566440AA8988099E8940D" . (.WinSnare.) -- C:\Windows\Installer\{FC5A2575-5D95-4466-A08A-8908998E49D0}\_853F67D554F05449430E7E.exe =>.Superfluous.WinSnare O90 - PUC: "F39E5917C417B4041A46F88010121C6E" . (.UvConverter.) =>Adware.CornerSunshine ---\\ Recherche des packages WindowsInstaller (5) - 30s [MD5.] [WIS][2017/03/17 13:56:48] (.WinSnare - Windows Installer.) -- C:\Windows\Installer\24085.msi [317400] =>.Superfluous.WinSnare [MD5.] [WIS][2017/03/10 10:16:56] (.amuleC - Windows Installer.) -- C:\Windows\Installer\24096.msi [317400] =>Adware.aMULEcustom [MD5.] [WIS][2014/01/04 04:30:44] (.APN, LLC - Ask.com ® - Install Builder.) -- C:\Windows\Installer\31c5b.msi [317400] =>Adware.Bandoo [MD5.] [WIS][2016/11/16 10:11:05] (.amuleC - Windows Installer.) -- C:\Windows\Installer\a1ce8.msi [317400] =>Adware.aMULEcustom [MD5.] [WIS][2012/10/30 21:00:04] (.Ask.com - InstallShield® 2010 - Premier Edition 16.) -- C:\Windows\Installer\a2383a.msi [317400] =>Toolbar.Ask ---\\ Liste des émulateurs de CD/DVD (MBR Hook) (10) - 21s HKLM\SOFTWARE\Microsoft\Tracing\amt_mysites123_RASAPI32 =>PUP.Optional.Mysites123 HKLM\SOFTWARE\Microsoft\Tracing\amt_mysites123_RASMANCS =>PUP.Optional.Mysites123 HKLM\SOFTWARE\Microsoft\Tracing\ApnStub_RASAPI32 =>Toolbar.Ask HKLM\SOFTWARE\Microsoft\Tracing\ApnStub_RASMANCS =>Toolbar.Ask HKLM\SOFTWARE\Microsoft\Tracing\AskPartnerCobrandingTool_RASAPI32 =>Toolbar.AskBar HKLM\SOFTWARE\Microsoft\Tracing\AskPartnerCobrandingTool_RASMANCS =>Toolbar.AskBar HKLM\SOFTWARE\Microsoft\Tracing\chedot_RASAPI32 =>PUP.Optional.ChedotBrowser HKLM\SOFTWARE\Microsoft\Tracing\chedot_RASMANCS =>PUP.Optional.ChedotBrowser HKLM\SOFTWARE\Microsoft\Tracing\conduitinstaller_RASAPI32 =>.Superfluous.Conduit HKLM\SOFTWARE\Microsoft\Tracing\conduitinstaller_RASMANCS =>.Superfluous.Conduit ---\\ Scan Additionnel (144) - 16s HKLM\SYSTEM\CurrentControlSet\Services\ed2kidle =>Adware.aMULEcustom HKLM\SYSTEM\CurrentControlSet\Services\GubedZL =>.Superfluous.Elex.GubZL C:\Program Files\Gubed\GubedZL.dll =>.Superfluous.Elex.GubZL HKLM\SYSTEM\CurrentControlSet\Services\iSafeService =>.Superfluous.Elex C:\Program Files\Elex-tech\YAC\iSafeSvc.exe =>.Superfluous.Elex HKLM\SYSTEM\CurrentControlSet\Services\Kyubey =>PUP.Optional.CrossRider C:\Users\SAMIA\AppData\Roaming\Kyubey\Kyubey.exe =>PUP.Optional.CrossRider HKLM\SYSTEM\CurrentControlSet\Services\WinSAPSvc =>PUP.Optional.Youndoo C:\Users\SAMIA\AppData\Roaming\WinSAPSvc\WinSAP.dll =>PUP.Optional.Youndoo HKLM\SYSTEM\CurrentControlSet\Services\WinSnare =>.Superfluous.WinSnare C:\Users\SAMIA\AppData\Roaming\WinSnare\WinSnare.dll =>.Superfluous.WinSnare HKLM\SYSTEM\CurrentControlSet\Services\Convxxxx =>Adware.CornerSunshine C:\Users\SAMIA\AppData\Roaming\ehadh\UvConverter.exe =>Adware.CornerSunshine HKLM\SYSTEM\CurrentControlSet\Services\iThemes5 =>Adware.Mikey C:\Program Files\Common Files\Services\iThemes.dll =>Adware.Mikey HKLM\SYSTEM\CurrentControlSet\Services\qkseeService =>.Superfluous.TaiwanShuiMu C:\Program Files\qksee\qkseeSvc.exe =>.Superfluous.TaiwanShuiMu C:\Windows\System32\Tasks\Browser Updater Task(Core) =>Adware.Suspect C:\Users\SAMIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlfienamagdnkekbbbocojppncdambda =>Hijacker.Browser C:\Users\SAMIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooepecapjfnpoblcjpgibomhcnlgbnbj =>Hijacker.Browser C:\Users\SAMIA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fmbdpmllpkfodckedbomjbbehcbjnlon =>PUP.Optional.SafeWeb C:\Users\SAMIA\AppData\Roaming\Mozilla\Firefox\Profiles\8nlychy6.default-1467880386418\searchplugins\nuesearch.xml =>Hijacker.Browser C:\Users\SAMIA\AppData\Roaming\Complitly\Complitly.dll =>PUP.Optional.PredictAd HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0} =>PUP.Optional.PredictAd HKLM\Software\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0} =>PUP.Optional.PredictAd HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0} =>PUP.Optional.PredictAd HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0} =>PUP.Optional.PredictAd HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4B4D5056-3700-A76A-76A7-7A786E7484D7} =>.Superfluous.Orphan HKLM\Software\Classes\CLSID\{4B4D5056-3700-A76A-76A7-7A786E7484D7} =>.Superfluous.Orphan HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B4D5056-3700-A76A-76A7-7A786E7484D7} =>.Superfluous.Orphan HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B4D5056-3700-A76A-76A7-7A786E7484D7} =>.Superfluous.Orphan C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL =>Toolbar.Ask HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CB65201-89C4-402c-BA80-02D8C59F9B1D} =>Toolbar.Ask HKLM\Software\Classes\CLSID\{9CB65201-89C4-402c-BA80-02D8C59F9B1D} =>Toolbar.Ask HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CB65201-89C4-402c-BA80-02D8C59F9B1D} =>Toolbar.Ask HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CB65201-89C4-402c-BA80-02D8C59F9B1D} =>Toolbar.Ask HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403e-8DD8-394C54984B2C} =>Toolbar.AskTBar HKLM\Software\Classes\CLSID\{FE063DB1-4EC0-403e-8DD8-394C54984B2C} =>Toolbar.AskTBar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB1-4EC0-403e-8DD8-394C54984B2C} =>Toolbar.AskTBar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB1-4EC0-403e-8DD8-394C54984B2C} =>Toolbar.AskTBar HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\qksee =>.Superfluous.TaiwanShuiMu HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19539992-061C-4E8B-9053-07B175303AF4} =>Adware.aMULEcustom HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4B4D5056-3700-A76A-76A7-A758B70C0A00} =>Adware.Bandoo HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4FFBB818-B13C-11E0-931D-B2664824019B}_is1 =>PUP.Optional.PredictAd HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FC5A2575-5D95-4466-A08A-8908998E49D0} =>.Superfluous.WinSnare HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\qksee =>.Superfluous.TaiwanShuiMu HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19539992-061C-4E8B-9053-07B175303AF4} =>Adware.aMULEcustom HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4B4D5056-3700-A76A-76A7-A758B70C0A00} =>Adware.Bandoo HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4FFBB818-B13C-11E0-931D-B2664824019B}_is1 =>PUP.Optional.PredictAd HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FC5A2575-5D95-4466-A08A-8908998E49D0} =>.Superfluous.WinSnare C:\Program Files\2qhoyf2t =>.Superfluous.Empty C:\Program Files\amulell =>Adware.aMULEcustom C:\Program Files\AskTBar =>Toolbar.AskTBar C:\Program Files\Betcat =>PUP.Optional.Betcat C:\Program Files\BrowserProtect =>PUP.Optional.Eazel C:\Program Files\Complitly =>PUP.Optional.PredictAd C:\Program Files\Gubed =>.Superfluous.Elex.GubZL C:\Program Files\Gubed_WMI =>.Superfluous.Elex.GubZL C:\Program Files\PC Speed Maximizer =>.Superfluous.PCSpeedMaximizer C:\Program Files\qksee =>.Superfluous.TaiwanShuiMu C:\Program Files\RegClean Pro =>PUP.Optional.RegistryPowerCleaner C:\Program Files\SearchesToYesbnd =>Adware.YesSearches C:\Program Files\UvConverter =>Adware.CornerSunshine C:\Program Files\Web Cake =>PUP.Optional.WebCake C:\Program Files\WinArcher =>PUP.Optional.Youndoo C:\Program Files\WinSaber =>.Superfluous.WinSaber C:\Program Files\Winsere =>Adware.YesSearches C:\Program Files\WinSnare(4.1.0) =>.Superfluous.WinSnare C:\Program Files\WinSnare(4.3.3) =>.Superfluous.WinSnare C:\Program Files\WinTaske =>Adware.YesSearches C:\Program Files\WinZipper =>.Superfluous.TaiwanShuiMu C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qksee =>.Superfluous.TaiwanShuiMu C:\ProgramData\APN =>Toolbar.Ask C:\ProgramData\AskPartnerNetwork =>Toolbar.YahooPartner C:\ProgramData\Babylon =>Adware.Babylon C:\ProgramData\desktopfind =>HackTool.WinActivator C:\ProgramData\InstallMate =>.Superfluous.Tarma C:\ProgramData\QQBrowser =>.Superfluous.SpeedBrowser C:\ProgramData\Tarma Installer =>.Superfluous.Tarma C:\ProgramData\Tencent =>.Superfluous.Tencent C:\ProgramData\WinSAPSvc =>PUP.Optional.Youndoo C:\Program Files\Common Files\Tencent =>.Superfluous.Tencent C:\Users\SAMIA\AppData\Roaming\aMule =>Adware.aMULEcustom C:\Users\SAMIA\AppData\Roaming\Babylon =>Adware.Babylon C:\Users\SAMIA\AppData\Roaming\Betcat =>PUP.Optional.Betcat C:\Users\SAMIA\AppData\Roaming\Complitly =>PUP.Optional.PredictAd C:\Users\SAMIA\AppData\Roaming\eCyber =>.Superfluous.Elex C:\Users\SAMIA\AppData\Roaming\Elex-tech =>.Superfluous.Elex C:\Users\SAMIA\AppData\Roaming\Kyubey =>PUP.Optional.CrossRider C:\Users\SAMIA\AppData\Roaming\mysites123 =>PUP.Optional.Mysites123 C:\Users\SAMIA\AppData\Roaming\PerformerSoft =>.Superfluous.PerformerSoft C:\Users\SAMIA\AppData\Roaming\qksee =>.Superfluous.TaiwanShuiMu C:\Users\SAMIA\AppData\Roaming\Systweak =>.Superfluous.Systweak C:\Users\SAMIA\AppData\Roaming\Tencent =>.Superfluous.Tencent C:\Users\SAMIA\AppData\Roaming\Web Cake =>PUP.Optional.WebCake C:\Users\SAMIA\AppData\Roaming\WebCake =>PUP.Optional.WebCake C:\Users\SAMIA\AppData\Roaming\WinSAPSvc =>PUP.Optional.Youndoo C:\Users\SAMIA\AppData\Roaming\WinSnare =>.Superfluous.WinSnare C:\Users\SAMIA\AppData\Roaming\WinZiper =>.Superfluous.WinZipper C:\Users\SAMIA\AppData\Local\Babylon =>Adware.Babylon C:\Users\SAMIA\AppData\Local\PackageAware =>PUP.Optional.BearShare C:\Users\SAMIA\AppData\Local\PutLockerDownloader =>PUP.Optional.PutLocker C:\Users\SAMIA\AppData\Local\Torch =>.Superfluous.Torch C:\Users\SAMIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC =>Adware.aMULEcustom C:\Users\SAMIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FTDownloader.com =>PUP.Optional.Downware C:\Windows\System32\Config\systemprofile\AppData\Roaming\aMule =>Adware.aMULEcustom C:\Windows\System32\Config\systemprofile\AppData\Roaming\Tencent =>.Superfluous.Tencent HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PC Speed Maximizer =>.Superfluous.PCSpeedMaximizer C:\Windows\System32\drivers\iSafeKrnlBoot.sys =>.Superfluous.Elex C:\Windows\System32\drivers\iSafeNetFilter.sys =>.Superfluous.Elex C:\Windows\System32\drivers\TS888.sys =>.Superfluous.Tencent C:\Windows\System32\drivers\wcmvcam.sys =>.Superfluous.TenkiTechnology C:\Windows\System32\TSSK.sys =>.Superfluous.Tencent HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} =>.Superfluous.DeltaSearch HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} =>Hijacker.StartpageIng123 HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9359F63D-427F-4B89-B9C9-2FEA1975C7A9} =>Toolbar.Ask HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} =>PUP.Optional.CertifiedToolbar HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} =>Hijacker.StartpageIng123 [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{3953A1AE-FD99-427A-8CA3-2F9B1DCE0B43} =>PUP.Optional.ProtectedSearch [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{B6DC9765-F0BD-4DDE-A0F4-91D54682D800} =>PUP.Optional.ProtectedSearch C:\Windows\Installer\{FC5A2575-5D95-4466-A08A-8908998E49D0}\_853F67D554F05449430E7E.exe =>.Superfluous.WinSnare HKLM\Software\Classes\Installer\Products\5752A5CF59D566440AA8988099E8940D =>.Superfluous.WinSnare HKLM\Software\Classes\Installer\Features\5752A5CF59D566440AA8988099E8940D =>.Superfluous.WinSnare HKLM\Software\Classes\Installer\Products\F39E5917C417B4041A46F88010121C6E =>Adware.CornerSunshine HKLM\Software\Classes\Installer\Features\F39E5917C417B4041A46F88010121C6E =>Adware.CornerSunshine C:\Windows\Installer\24085.msi =>.Superfluous.WinSnare C:\Windows\Installer\24096.msi =>Adware.aMULEcustom C:\Windows\Installer\31c5b.msi =>Adware.Bandoo C:\Windows\Installer\a1ce8.msi =>Adware.aMULEcustom C:\Windows\Installer\a2383a.msi =>Toolbar.Ask HKLM\SOFTWARE\Microsoft\Tracing\amt_mysites123_RASAPI32 =>PUP.Optional.Mysites123 HKLM\SOFTWARE\Microsoft\Tracing\amt_mysites123_RASMANCS =>PUP.Optional.Mysites123 HKLM\SOFTWARE\Microsoft\Tracing\ApnStub_RASAPI32 =>Toolbar.Ask HKLM\SOFTWARE\Microsoft\Tracing\ApnStub_RASMANCS =>Toolbar.Ask HKLM\SOFTWARE\Microsoft\Tracing\AskPartnerCobrandingTool_RASAPI32 =>Toolbar.AskBar HKLM\SOFTWARE\Microsoft\Tracing\AskPartnerCobrandingTool_RASMANCS =>Toolbar.AskBar HKLM\SOFTWARE\Microsoft\Tracing\chedot_RASAPI32 =>PUP.Optional.ChedotBrowser HKLM\SOFTWARE\Microsoft\Tracing\chedot_RASMANCS =>PUP.Optional.ChedotBrowser HKLM\SOFTWARE\Microsoft\Tracing\conduitinstaller_RASAPI32 =>.Superfluous.Conduit HKLM\SOFTWARE\Microsoft\Tracing\conduitinstaller_RASMANCS =>.Superfluous.Conduit C:\Users\SAMIA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_download.weatherblink.com_0.localstorage =>.Superfluous.MindSpark C:\Users\SAMIA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_download.weatherblink.com_0.localstorage-journal =>.Superfluous.MindSpark C:\Users\SAMIA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.nuesearch.com_0.localstorage =>Hijacker.Browser C:\Users\SAMIA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.nuesearch.com_0.localstorage-journal =>Hijacker.Browser ---\\ Récapitulatif des éléments trouvés sur votre station (56) - 0s https://nicolascoolman.eu/2017/03/10/adware-amulecustom/ =>Adware.aMULEcustom https://nicolascoolman.eu/2017/02/18/superfluous-elex-gubzl/ =>.Superfluous.Elex.GubZL https://www.anti-malware.top/2016/05/18/superfluous-elex/ =>.Superfluous.Elex https://nicolascoolman.eu/2017/03/11/pup-optional-crossrider/ =>PUP.Optional.CrossRider https://nicolascoolman.eu/2017/03/11/superfluous-youndoo/ =>PUP.Optional.Youndoo https://nicolascoolman.eu/2017/01/12/superfluous-winsnare/ =>.Superfluous.WinSnare https://www.anti-malware.top/2016/09/06/adware-cornersunshine/ =>Adware.CornerSunshine https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Adware.Mikey https://www.anti-malware.top/2016/05/05/superfluous-taiwanshuimu/ =>.Superfluous.TaiwanShuiMu https://nicolascoolman.eu/2017/03/02/adware-suspect/ =>Adware.Suspect https://nicolascoolman.eu/2017/02/02/hijacker-browser-2/ =>Hijacker.Browser https://www.nicolascoolman.com/fr/pup-safeweb/ =>PUP.Optional.SafeWeb https://www.nicolascoolman.com/fr/adware-predictad/ =>PUP.Optional.PredictAd https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.SimplyTech https://nicolascoolman.eu/2017/02/28/toolbar-ask/ =>Toolbar.Ask https://www.nicolascoolman.com/fr/les-toolbars/ =>Toolbar.AskTBar https://www.anti-malware.top/2016/10/18/hijacker-mylucky123/ =>Hijacker.MyLucky123 https://nicolascoolman.eu/2017/02/23/adware-bandoo/ =>Adware.Bandoo https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.SearchB1org https://nicolascoolman.eu/2017/03/03/adware-babylon/ =>Adware.Babylon https://www.nicolascoolman.com/fr/pup-optional-chedotbrowser/ =>PUP.Optional.ChedotBrowser https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.HohoSearch https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.InterSect https://www.anti-malware.top/2016/05/03/pup-optional-performersoft/ =>.Superfluous.PerformerSoft https://www.nicolascoolman.com/fr/pup-software-updater/ =>PUP.Optional.SoftwareUpdater https://www.nicolascoolman.com/fr/pup-systweak/ =>.Superfluous.Systweak https://www.nicolascoolman.com/fr/pup-tarma/ =>.Superfluous.Tarma https://nicolascoolman.eu/2017/02/23/tencentadressbar/ =>.Superfluous.Tencent https://www.nicolascoolman.com/fr/pup-vittalia/ =>PUP.Optional.Vittalia https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.WinSaber https://www.nicolascoolman.com/fr/pup-1clickdownloader/ =>PUP.Optional.1ClickDownloader https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.SmartPCSolutions https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Empty https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.Betcat https://www.nicolascoolman.com/fr/hijacker-eazel/ =>PUP.Optional.Eazel https://www.nicolascoolman.com/fr/rogue-pcspeedmaximizer/ =>.Superfluous.PCSpeedMaximizer https://www.nicolascoolman.com/fr/rogue-registrypowercleaner/ =>PUP.Optional.RegistryPowerCleaner https://www.anti-malware.top/2016/05/12/adware-yessearches/ =>Adware.YesSearches https://www.nicolascoolman.com/fr/adware-webcake/ =>PUP.Optional.WebCake https://www.nicolascoolman.com/fr/les-toolbars/ =>Toolbar.YahooPartner https://nicolascoolman.eu/2017/01/13/hacktool-winactivator/ =>HackTool.WinActivator https://www.anti-malware.top/2016/07/28/superfluousspeedbrowser/ =>.Superfluous.SpeedBrowser https://www.nicolascoolman.com/fr/pup-optional-mysites123 =>PUP.Optional.Mysites123 https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.WinZipper https://www.nicolascoolman.com/fr/pup-bearshare/ =>PUP.Optional.BearShare https://www.nicolascoolman.com/fr/spyware-putlocker/ =>PUP.Optional.PutLocker https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Torch https://www.nicolascoolman.com/fr/adware-downware/ =>PUP.Optional.Downware https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.TenkiTechnology https://www.nicolascoolman.com/fr/toolbar-deltasearch/ =>.Superfluous.DeltaSearch https://nicolascoolman.eu/2017/03/06/hijacker-startpageing123/ =>Hijacker.StartpageIng123 https://www.nicolascoolman.com/fr/pup-certifiedtoolbar/ =>PUP.Optional.CertifiedToolbar https://www.nicolascoolman.com/fr/spyware-protectedsearch/ =>PUP.Optional.ProtectedSearch https://www.nicolascoolman.com/fr/les-toolbars/ =>Toolbar.AskBar https://nicolascoolman.eu/2017/02/06/superfluous-conduit/ =>.Superfluous.Conduit https://nicolascoolman.eu/2017/01/15/superfluous-mindspark/ =>.Superfluous.MindSpark ~ Unselected Options: O82, O82, ~ End of the scan, 51619 items in 36mn54s (1738)(0)