~ ZHPDiag v2018.6.22.140 Par Nicolas Coolman (2018/06/22) ~ Démarré par Acer (Administrator) (2018/06/23 09:59:00) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Certificate ZHPDiag: Legal ~ Etat de la version: Version OK ~ Mode: Scanner ~ Rapport: C:\Users\Acer\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\Acer\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ Démarrage du système: Normal (Normal boot) Windows 10 Home, 32-bit (Build 16299) =>.Microsoft Corporation ---\\ NAVIGATEURS INTERNET (3) - 0s ~ GCIE: Google Chrome v67.0.3396.87 ~ MSIE: Microsoft Edge v40 ~ MSIE: Internet Explorer v11.309.16299.0 ---\\ INFORMATIONS SUR LES PRODUITS WINDOWS (7) - 3s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK ~ Windows(R) Operating System, RETAIL channel Windows ID Activation : OK ~ Windows Partial Key : 8HVX7 ~ Windows Remaining Initializations Number : 1001 Windows Automatic Updates : OK ---\\ LOGICIELS DE PROTECTION (1) - 8s Windows Defender W10 (Activate) (Protection) ---\\ SURVEILLANCE LOGICIEL (1) - 8s ~ Adobe Acrobat Reader DC - Français (Surveillance) ---\\ INFORMATIONS SUR LE SYSTÈME (6) - 0s ~ Operating System: x86 Family 6 Model 15 Stepping 13, GenuineIntel ~ Operating System: 32-bit ~ Boot mode: Normal (Normal boot) Total RAM: 2882.78 MB (46% free) : OK =>.RAM Value System Restore: Activé (Enable) System drive C: has 20 GB (26%) free of 75 GB : OK =>.Disk Space ---\\ MODE DE CONNEXION AU SYSTÈME (3) - 0s ~ Computer Name: DESKTOP-VR15SLC ~ User Name: Acer ~ Logged in as Administrator ---\\ ÉNUMÉRATION DES UNITÉS DE STOCKAGE (2) - 0s ~ Drive C: has 20 GB free of 75 GB (System) ~ Drive I: has 337 GB free of 953 GB ---\\ ÉTAT DU CENTRE DE SÉCURITÉ WINDOWS (7) - 0s [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK ---\\ RECHERCHE PARTICULIÈRE DE FICHIERS GÉNÉRIQUES (24) - 3s [MD5.E79CC4B9A9EAA1E5D801742C093043A9] - 10/02/2018 - (.Microsoft Corporation - Explorateur Windows.) -- C:\WINDOWS\Explorer.exe [3485392] =>.Microsoft Windows® [MD5.BFEF0511D30F8866AF6595FC21460856] - 29/09/2017 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [63488] =>.Microsoft Corporation [MD5.127B9C203C5A3D65783BB7E7A833FF47] - 29/09/2017 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\WINDOWS\System32\Wininit.exe [269192] =>.Microsoft Windows Publisher® [MD5.A1A4E4801135FA34943B550E63D47972] - 01/03/2018 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\WINDOWS\System32\wininet.dll [2869760] =>.Microsoft Corporation [MD5.26FBE96E2899C3BA494C9B61EF3005F0] - 01/01/2018 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\WINDOWS\System32\Winlogon.exe [613376] =>.Microsoft Corporation [MD5.10204B5E7BFF059D87848F0BD0E0F0E9] - 10/02/2018 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\WINDOWS\System32\sppcomapi.dll [403968] =>.Microsoft Corporation [MD5.66342F3BB289A5A370127F8385512A84] - 10/02/2018 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\WINDOWS\System32\dnsapi.dll [597160] =>.Microsoft Windows® [MD5.3B34C7B9D7E22AEF58DF0CFC4C7CC82D] - 30/09/2017 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\WINDOWS\System32\fr-FR\user32.dll.mui [19968] =>.Microsoft Corporation [MD5.44D77F1BA55AD3CFDC3B64F62C83766C] - 10/02/2018 - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [506264] =>.Microsoft Windows® [MD5.25E93AC838DBBA1757501C9F3B85DC74] - 29/09/2017 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [22936] =>.Microsoft Windows® [MD5.813041DC9CF434D539372C50F6B72F0E] - 29/09/2017 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [73728] =>.Microsoft Corporation [MD5.17CD2948AC64E0E17111566FF2D05A25] - 29/09/2017 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [116736] =>.Microsoft Corporation [MD5.4335F9E2BAF27AE67C66A9E766F6496B] - 01/01/2018 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [111616] =>.Microsoft Corporation [MD5.79FFBEEF3CEBCD265E865EF7BADB3BC1] - 29/09/2017 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [68608] =>.Microsoft Corporation [MD5.97B6AFF4BDDA95434490E82D48EDD028] - 29/09/2017 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [89600] =>.Microsoft Corporation [MD5.CA3B20720265F619DAE5B5F563BC2BEC] - 29/09/2017 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [185856] =>.Microsoft Corporation [MD5.5F866C99CE1E65AC2E8C01E722B80B2F] - 10/02/2018 - (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [434072] =>.Microsoft Windows® [MD5.EB4037039C67DA01046DCF3518231A7E] - 01/01/2018 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [236544] =>.Microsoft Corporation [MD5.109F81235FBB151DE8A90AA935C1BDD2] - 01/01/2018 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\WINDOWS\System32\drivers\ntfs.sys [1995672] =>.Microsoft Windows® [MD5.ADA500A1BF37FA0659AD08AC70EE9C0F] - 29/09/2017 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\WINDOWS\System32\drivers\Parport.sys [81920] =>.Microsoft Corporation [MD5.729ABF4C4A4624BF153B261675223508] - 29/09/2017 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [79872] =>.Microsoft Corporation [MD5.C6F1CFFAC6A26102DF039BA7B8243051] - 01/01/2018 - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [131072] =>.Microsoft Corporation [MD5.1855CAF9D9C29DE064920077293186D4] - 01/01/2018 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [96152] =>.Microsoft Windows® [MD5.134523B18C89C4E1E46C4AA5CA048F49] - 14/12/2017 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\WINDOWS\System32\drivers\volsnap.sys [353688] =>.Microsoft Windows® ---\\ LISTE DES SERVICES (Non désactivés) (65) - 2s O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated® O23 - Service: C:\Windows\System32\AudioEndpointBuilder.dll (AudioEndpointBuilder) . (.Microsoft Corporation - Générateur de points de terminaison du serv.) - C:\Windows\System32\AudioEndpointBuilder.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\audiosrv.dll (Audiosrv) . (.Microsoft Corporation - Service Audio Windows.) - C:\Windows\System32\audiosrv.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\BFE.DLL (BFE) . (.Microsoft Corporation - Moteur de filtrage de base.) - C:\Windows\System32\BFE.DLL =>.Microsoft Corporation O23 - Service: C:\Windows\System32\bisrv.dll (BrokerInfrastructure) . (.Microsoft Corporation - Service d’infrastructure des tâches en arri.) - C:\Windows\System32\bisrv.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\cdpusersvc.dll (CDPUserSvc) . (.Microsoft Corporation - Composants utilisateur Microsoft (R) CDP.) - C:\Windows\System32\CDPUserSvc.dll =>.Microsoft Corporation O23 - Service: Service pour utilisateur de plateforme d’appareils connecté (CDPUserSvc_62bd91) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher® O23 - Service: C:\Windows\System32\coremessaging.dll (CoreMessagingRegistrar) . (.Microsoft Corporation - Microsoft CoreMessaging Dll.) - C:\Windows\System32\coremessaging.dll =>.Microsoft Windows® O23 - Service: C:\Windows\System32\cryptsvc.dll (CryptSvc) . (.Microsoft Corporation - Services de chiffrement.) - C:\Windows\System32\cryptsvc.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\das.dll (DeviceAssociationService) . (.Microsoft Corporation - Service d’association de périphérique.) - C:\Windows\System32\das.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\dhcpcore.dll (Dhcp) . (.Microsoft Corporation - Service client DHCP.) - C:\Windows\System32\dhcpcore.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\diagtrack.dll (DiagTrack) . (.Microsoft Corporation - Suivi des diagnostics Microsoft Windows.) - C:\Windows\System32\diagtrack.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\dnsapi.dll (Dnscache) . (.Microsoft Corporation - Service de résolution du cache DNS.) - C:\Windows\System32\dnsrslvr.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\dosvc.dll (DoSvc) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher® O23 - Service: C:\Windows\System32\dusmsvc.dll (DusmSvc) . (.Microsoft Corporation - Service Consommation des données.) - C:\Windows\System32\dusmsvc.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wevtsvc.dll (EventLog) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher® O23 - Service: @comres.dll,-2450 (EventSystem) . (.Microsoft Corporation - COM+.) - C:\Windows\System32\es.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\fhsvc.dll (fhsvc) . (.Microsoft Corporation - Service d’historique des fichiers.) - C:\Windows\System32\fhsvc.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\FntCache.dll (FontCache) . (.Microsoft Corporation - Service de cache de police Windows.) - C:\Windows\System32\FntCache.dll =>.Microsoft Corporation O23 - Service: @gpapi.dll,-112 (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) - C:\Windows\System32\gpsvc.dll =>.Microsoft Corporation O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc® O23 - Service: Service HP CUE DeviceDiscovery (hpqddsvc) . (...) - C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (.not file.) O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) . (.Copyright CANON INC. 2006-2013 - Inkjet Printer/Scanner/Fax Extended Survey.) - C:\Program Files\Canon\IJPLM\ijplmsvc.exe =>.Canon Inc.® O23 - Service: C:\Windows\System32\iphlpsvc.dll (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) - C:\Windows\System32\iphlpsvc.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\srvsvc.dll (LanmanServer) . (.Microsoft Corporation - DLL du service Serveur.) - C:\Windows\System32\srvsvc.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wkssvc.dll (LanmanWorkstation) . (.Microsoft Corporation - DLL du service Station de travail.) - C:\Windows\System32\wkssvc.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\lsm.dll (LSM) . (.Microsoft Corporation - Service du gestionnaire de session locale.) - C:\Windows\System32\lsm.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\moshost.dll (MapsBroker) . (.Microsoft Corporation - Gestionnaire des cartes téléchargées.) - C:\Windows\System32\moshost.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\FirewallAPI.dll (MpsSvc) . (.Microsoft Corporation - Service de protection Microsoft.) - C:\Windows\System32\MPSSVC.dll =>.Microsoft Corporation O23 - Service: (Net Driver HPZ12) . (.HP Inc. - Dot4Net Module.) - C:\Windows\System32\HPZinw12.dll =>.HP Inc. O23 - Service: C:\Windows\System32\nlasvc.dll (NlaSvc) . (.Microsoft Corporation - Connaissance des emplacements réseau 2.) - C:\Windows\System32\nlasvc.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\nsisvc.dll (nsi) . (.Microsoft Corporation - Serveur RPC de l’interface du magasin résea.) - C:\Windows\System32\nsisvc.dll =>.Microsoft Corporation O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 309.0.) - C:\Windows\System32\nvvsvc.exe =>.NVIDIA Corporation® O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) . (.NVIDIA Corporation - NVIDIA Settings Update Manager.) - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe =>.NVIDIA Corporation® O23 - Service: C:\Windows\System32\APHostRes.dll (OneSyncSvc) . (.Microsoft Corporation - Accounts Host Service.) - C:\Windows\System32\APHostService.dll =>.Microsoft Corporation O23 - Service: Hôte de synchronisation_62bd91 (OneSyncSvc_62bd91) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher® O23 - Service: (Pml Driver HPZ12) . (.HP Inc. - PmlDrv Module.) - C:\Windows\System32\HPZipm12.dll =>.HP Inc. O23 - Service: C:\Windows\System32\umpo.dll (Power) . (.Microsoft Corporation - Service d’alimentation en mode utilisateur.) - C:\Windows\System32\umpo.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\profsvc.dll (ProfSvc) . (.Microsoft Corporation - ProfSvc.) - C:\Windows\System32\profsvc.dll =>.Microsoft Corporation O23 - Service: Corel License Validation Service V2, Powered by arvato (PSI_SVC_2) . (.arvato digital services llc - PsiService PsiService.) - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe =>.Arvato Digital Services Canada Inc® O23 - Service: C:\Windows\System32\rasmans.dll (RasMan) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) - C:\Windows\System32\rasmans.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\RpcEpMap.dll (RpcEptMapper) . (.Microsoft Corporation - Mappeur de point de terminaison RPC.) - C:\Windows\System32\RpcEpMap.dll =>.Microsoft Corporation O23 - Service: C:\WINDOWS\System32\Locator.exe,-2 (RpcLocator) . (.Microsoft Corporation - Localisateur d’appels de procédure distante.) - C:\Windows\System32\Locator.exe =>.Microsoft Corporation O23 - Service: @combase.dll,-5010 (RpcSs) . (.Microsoft Corporation - Distributed COM Services.) - C:\Windows\System32\rpcss.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\schedsvc.dll (Schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) - C:\Windows\System32\schedsvc.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\SecurityHealthAgent.dll (SecurityHealthService) . (.Microsoft Corporation - Windows Security Health Service.) - C:\Windows\System32\SecurityHealthService.exe =>.Microsoft Windows Publisher® O23 - Service: C:\Windows\System32\Sens.dll (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) - C:\Windows\System32\Sens.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\shsvcs.dll (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) - C:\Windows\System32\shsvcs.dll =>.Microsoft Corporation O23 - Service: C:\WINDOWS\System32\spoolsv.exe,-1 (Spooler) . (.Microsoft Corporation - Application sous-système spouleur.) - C:\Windows\System32\spoolsv.exe =>.Microsoft Corporation O23 - Service: C:\WINDOWS\System32\sppsvc.exe,-101 (sppsvc) . (.Microsoft Corporation - Service de la plateforme de protection logi.) - C:\Windows\System32\sppsvc.exe =>.Microsoft Windows® O23 - Service: C:\Windows\System32\wiaservc.dll (StiSvc) . (.Microsoft Corporation - Service de périphériques d’images fixes.) - C:\Windows\System32\wiaservc.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\sysmain.dll (SysMain) . (.Microsoft Corporation - Hôte de service Superfetch.) - C:\Windows\System32\sysmain.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\SystemEventsBrokerServer.dll (SystemEventsBroker) . (.Microsoft Corporation - Service Broker pour les événements système.) - C:\Windows\System32\SystemEventsBrokerServer.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\themeservice.dll (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) - C:\Windows\System32\themeservice.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\usermgr.dll (UserManager) . (.Microsoft Corporation - UserMgr.) - C:\Windows\System32\usermgr.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wcmsvc.dll (Wcmsvc) . (.Microsoft Corporation - DLL du service de gestion des connexions Wi.) - C:\Windows\System32\wcmsvc.dll =>.Microsoft Corporation O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) . (.Microsoft Corporation - Antimalware Service Executable.) - C:\ProgramData\Microsoft\Windows Defender\Platform\4.16.17656.18052-0\MsMpEng.exe =>.Microsoft Corporation® O23 - Service: C:\Windows\System32\wbem\WMIsvc.dll (winmgmt) . (.Microsoft Corporation - WMI.) - C:\Windows\System32\wbem\WMIsvc.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wlansvc.dll (Wlansvc) . (.Microsoft Corporation - DLL du service de configuration automatique.) - C:\Windows\System32\wlansvc.dll =>.Microsoft Corporation O23 - Service: C:\WINDOWS\System32\wbem\wmiapsrv.exe,-110 (wmiApSrv) . (.Microsoft Corporation - Adaptateur inverse de performance WMI.) - C:\Windows\System32\wbem\WmiApSrv.exe =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wpnservice.dll (WpnService) . (.Microsoft Corporation - Service du système de notifications Push Wi.) - C:\Windows\System32\WpnService.dll =>.Microsoft Corporation O23 - Service: C:\Windows\System32\WpnUserService.dll (WpnUserService) . (.Microsoft Corporation - Service utilisateur de notifications Push W.) - C:\Windows\System32\WpnUserService.dll =>.Microsoft Corporation O23 - Service: Service utilisateur de notifications Push Windows_62bd91 (WpnUserService_62bd91) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher® O23 - Service: C:\Windows\System32\wscsvc.dll (wscsvc) . (.Microsoft Corporation - Service Centre de sécurité de Windows.) - C:\Windows\System32\wscsvc.dll =>.Microsoft Corporation O23 - Service: C:\WINDOWS\System32\SearchIndexer.exe,-103 (WSearch) . (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - C:\Windows\System32\SearchIndexer.exe =>.Microsoft Corporation ---\\ SERVICES NON MICROSOFT (SR=Démarré,SS=Stoppé) (9) - 5s SR - Auto [09/02/2018] [ 83984] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated® SS - Auto [25/02/2018] [ 153168] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc® SS - Demand [25/02/2018] [ 153168] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc® SR - Auto [14/05/2013] [ 140936] Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) . (.Copyright CANON INC. 2006-2013.) - C:\Program Files\Canon\IJPLM\ijplmsvc.exe =>.Canon Inc.® SS - Auto [15/06/2016] [ 45568] (Net Driver HPZ12) . (.HP Inc..) - C:\Windows\System32\HPZinw12.dll =>.HP Inc. SR - Auto [31/01/2015] [ 633672] NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\System32\nvvsvc.exe =>.NVIDIA Corporation® SS - Auto [31/01/2015] [ 1258312] NVIDIA Update Service Daemon (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe =>.NVIDIA Corporation® SS - Auto [15/06/2016] [ 55808] (Pml Driver HPZ12) . (.HP Inc..) - C:\Windows\System32\HPZipm12.dll =>.HP Inc. SR - Auto [30/04/2014] [ 277360] Corel License Validation Service V2, Powered by arvato (PSI_SVC_2) . (.arvato digital services llc.) - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe =>.Arvato Digital Services Canada Inc® ---\\ TÂCHES PLANIFIÉES EN AUTOMATIQUE (Registre) (8) - 9s O38 - TASK: {2A4AFDB5-3A40-4EB4-AFC2-AE4B4C826910}[\GoogleUpdateTaskMachineUA] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc. O38 - TASK: {2E1AC83A-E39C-4E43-AFA4-30BE0692EE25}[\Adobe Acrobat Update Task] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1183256] =>.Adobe Systems Incorporated O38 - TASK: {2F775C5F-4D3A-480A-8807-BDEB2EF66463}[\CCleanerSkipUAC] - (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe [8003664] =>.Piriform Ltd O38 - TASK: {D9247B4A-E4B3-4D59-83B7-02928F564AE4}[\GoogleUpdateTaskMachineCore] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc. C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [/ua ./ua] =>.Google Inc. C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task - (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [] =>.Adobe Systems Incorporated C:\WINDOWS\System32\Tasks\CCleanerSkipUAC - (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [$(Arg0)] =>.Piriform Ltd C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [/c] =>.Google Inc. ---\\ APPLICATIONS LANCÉES AU DÉMARRAGE DU SYSTÈME (13) - 3s O4 - HKLM\..\Run: [SecurityHealth] . (.Microsoft Corporation - Windows Defender notification icon.) -- C:\Program Files\Windows Defender\MSASCuiL.exe =>.Microsoft Windows® O4 - HKLM\..\Run: [CanonQuickMenu] . (.CANON INC. - Canon Quick Menu.) -- C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE =>.Canon Inc.® O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe =>.Realtek Semiconductor Corp.® O4 - HKLM\..\Run: [Suite graphique CorelDRAW 1c] . (.Corel Corporation - Registration.) -- C:\Program Files\Corel\Corel Graphics 11\Register\registration.exe =>.Corel Corporation O4 - HKLM\..\Run: [Path] . (...) -- C:\Program Files\ZOOM\Edit_Share\bin\ZOOM Edit&Share startup.exe O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Acer\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - HKCU\..\Run: [MultiScreen] . (. - MultiScreen Application.) -- C:\Program Files\MultiScreen\MultiScreen.exe O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd® O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\System32\OneDriveSetup.exe =>.Microsoft Windows® O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\System32\OneDriveSetup.exe =>.Microsoft Windows® O4 - HKUS\S-1-5-21-1701276704-2331144504-2702073659-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Acer\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - HKUS\S-1-5-21-1701276704-2331144504-2702073659-1001\..\Run: [MultiScreen] . (. - MultiScreen Application.) -- C:\Program Files\MultiScreen\MultiScreen.exe O4 - HKUS\S-1-5-21-1701276704-2331144504-2702073659-1001\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd® ---\\ PROCESSUS LANCÉS (20) - 5s [MD5.ABB859A74C9C2CB016830CDE069169C0] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 309.0.) -- C:\Windows\System32\nvvsvc.exe [633672] [PID.7128] =>.NVIDIA Corporation® [MD5.CA805DA983594B01F3554464B2E5158F] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [83984] [PID.7660] =>.Adobe Systems, Incorporated® [MD5.C5E4602D85029C666A42890A3B2DFA45] - (.Copyright CANON INC. 2006-2013 - Inkjet Printer/Scanner/Fax Extended Survey.) -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe [140936] [PID.7884] =>.Canon Inc.® [MD5.16783D49B6931414BAD1B2368ADD9656] - (.arvato digital services llc - PsiService PsiService.) -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [277360] [PID.7348] =>.Arvato Digital Services Canada Inc® [MD5.6C718849D436A7CCEBED72538F8BD04B] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files\Google\Update\1.3.33.17\GoogleCrashHandler.exe [288848] [PID.11924] =>.Google Inc® [MD5.36579CDF07A94F2F69E1A0F77D5151F4] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [863888] [PID.4996] =>.NVIDIA Corporation® [MD5.ABB859A74C9C2CB016830CDE069169C0] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 309.0.) -- C:\Windows\System32\nvvsvc.exe [633672] [PID.5352] =>.NVIDIA Corporation® [MD5.FDDE1CE78E5E507C0169FD526D4D3BCE] - (...) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x86__kzf8qxf38zg5c\SkypeHost.exe [75264] [PID.2024] =>.Skype Technologies [MD5.286E368B6F8A266D7B0BC15CAD2C1C4B] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [1458008] [PID.1948] =>.Google Inc® [MD5.286E368B6F8A266D7B0BC15CAD2C1C4B] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [1458008] [PID.2044] =>.Google Inc® [MD5.286E368B6F8A266D7B0BC15CAD2C1C4B] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [1458008] [PID.11056] =>.Google Inc® [MD5.286E368B6F8A266D7B0BC15CAD2C1C4B] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [1458008] [PID.7628] =>.Google Inc® [MD5.286E368B6F8A266D7B0BC15CAD2C1C4B] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [1458008] [PID.7316] =>.Google Inc® [MD5.286E368B6F8A266D7B0BC15CAD2C1C4B] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [1458008] [PID.7856] =>.Google Inc® [MD5.286E368B6F8A266D7B0BC15CAD2C1C4B] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [1458008] [PID.10284] =>.Google Inc® [MD5.286E368B6F8A266D7B0BC15CAD2C1C4B] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [1458008] [PID.5536] =>.Google Inc® [MD5.286E368B6F8A266D7B0BC15CAD2C1C4B] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [1458008] [PID.2072] =>.Google Inc® [MD5.286E368B6F8A266D7B0BC15CAD2C1C4B] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [1458008] [PID.9156] =>.Google Inc® [MD5.286E368B6F8A266D7B0BC15CAD2C1C4B] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [1458008] [PID.11312] =>.Google Inc® [MD5.8B8C86F77C353E1F1584CA4A7192754A] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Acer\Downloads\ZHPDiag3.exe [3144576] [PID.4740] =>.Nicolas Coolman ---\\ CHROME, Démarrage, Recherche, Extensions (21) - 1s G0 - GCSP: Preferences [User Data\Default][HomePage] http://apis.google.com =>.Google Inc. G0 - GCSP: Preferences [User Data\Default][HomePage] http://clients5.google.com =>.Google Inc. G0 - GCSP: Preferences [User Data\Default][HomePage] http://fonts.gstatic.com =>.Google Inc. G0 - GCSP: Preferences [User Data\Default][HomePage] http://lh3.googleusercontent.com =>.Google Inc. G0 - GCSP: Preferences [User Data\Default][HomePage] http://notifications.google.com =>.Google Inc. G0 - GCSP: Preferences [User Data\Default][HomePage] http://ogs.google.com =>.Google Inc. G0 - GCSP: Preferences [User Data\Default][HomePage] http://play.google.com =>.Google Inc. G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com =>.Google Inc. G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.fr =>.Google Inc. G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.gstatic.com =>.Google Inc. G2 - GCE: Preference [Acer][User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] =>.Google Inc. {Slides} G2 - GCE: Preference [Acer][User Data\Default] [aohghmighlieiainnegkcijnfilokake] =>.Google Inc. {Docs} G2 - GCE: Preference [Acer][User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] http://drive.google.com/ =>.Google Inc. {Drive} G2 - GCE: Preference [Acer][User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] http://www.youtube.com =>.Youtube {Youtube} G2 - GCE: Preference [Acer][User Data\Default] [efaidnbmnnnibpcajpcglclefindmkaj] =>.Adobe Inc. {Acrobat} G2 - GCE: Preference [Acer][User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] =>.Google Inc. {Sheets} G2 - GCE: Preference [Acer][User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] =>.Google Inc. {Docs hors connexion} G2 - GCE: Preference [Acer][User Data\Default] [gighmmpiobklfepjocnamgkkbiglidom] Michael Gundlach =>.Wladimir Palant {AdBlock} G2 - GCE: Preference [Acer][User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] =>.Google Inc. {Wallet} G2 - GCE: Preference [Acer][User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] http://mail.google.com/ =>.Google Inc. {Gmail} G2 - GCE: Preference [Acer][User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc. ---\\ FIREFOX, Plugins,Démarrage,Recherche,Extensions (2) - 2s P2 - EXT FILE: (.\u0421\u043E\u0432\u0435\u0442\u043D\u - Находит нужные вам товары и услуги по .) -- C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\1xnz5edo.default\extensions\sovetnik-yandex@yandex.ru.xpi P2 - EXT FILE: (.Визуальные закладки - Визуальные закладки – это страница, на.) -- C:\Users\Acer\AppData\Roaming\Mozilla\Firefox\Profiles\1xnz5edo.default\extensions\vb@yandex.ru.xpi ---\\ INTERNET EXPLORER,Démarrage,Recherche,URLSearchHook (11) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = preserve =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.16299.15 (WinBuild.160101.0800)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 0 ---\\ INTERNET EXPLORER, Site de confiance et site sensible (1) - 0s ~ Microsoft Internet Explorer Restricted Site(s) Domains: 0(Good) / 0(Bad) ---\\ INTERNET EXPLORER,Proxy Management (7) - 0s R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 =>.Default.Value R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 =>.Default.Value R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 =>.Default.Value R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll R5 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 =>.Default.Value R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft ---\\ INTERNET EXPLORER,IniFiles, Autoloading Programs (3) - 0s F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=C:\WINDOWS\system32\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation ---\\ ÉTUDE DU FICHIER HOSTS (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (21) ---\\ RACCOURCIS GLOBAL STARTUP (131) - 11s O4 - GS\Desktop [Acer]: 0-photos de famille.lnk . (...) I:\0-IMAGES-RESTAURATION\0-photos de famille O4 - GS\Desktop [Acer]: 0-TOUT CLAUDINE.lnk . (...) I:\0-TOUT CE QUI CONCERNE CLAUDINE O4 - GS\Desktop [Acer]: 0-TOUT CE QUI CONCERNE JL.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL O4 - GS\Desktop [Acer]: DD 2016-11 (I).lnk . (...) I:\ O4 - GS\Desktop [Acer]: Folder Marker.lnk . (.ArcticLine Software - Folder Marker Free - Tool for folder icon c.) C:\Program Files\Folder Marker\FolderMarker.exe =>.ArcticLine Software® O4 - GS\Desktop [Acer]: Launch Image Scan Tool.lnk . (.Acresso Software Inc. - InstallShield.) C:\WINDOWS\Installer\{F0ACDDA3-1DC3-43C0-84E6-43E927C3E2F7}\Image_Scan_Tool.ex_E1EFFBF60DEB4BB7A6F5ADFF64DE6C73.exe =>.Acresso Software Inc. O4 - GS\Desktop [Acer]: LE LIVRE d'Henri Le Leuch.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\0-LIVRE 04 HENRI\LE LIVRE d'Henri Le Leuch.odt O4 - GS\Desktop [Acer]: LE LIVRE GRAND-PERE.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\0-LIVRE 01 GRAND PERE\LIVRES-VERSIONS\LE LIVRE2 31-03-2016.odt O4 - GS\Desktop [Acer]: LIVIDE.2011.BRRip.XviD.HS - Raccourci.lnk . (...) D:\DCIM\111_PANA\{www.scenetime.com}LIVIDE.2011.BRRip.XviD.HS\LIVIDE.2011.BRRip.XviD.HS.AVI O4 - GS\Desktop [Acer]: LIVRE 03 VOILE.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\0-LIVRE 03 VOILE O4 - GS\Desktop [Acer]: LIVRE 04 HENRI.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\LIVRE 04 HENRI O4 - GS\Desktop [Acer]: LIVRE ARMEE.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\0-LIVRE 02 ARMEE\VERSION 10 corrigée O4 - GS\Desktop [Acer]: LIVRE-DISCOS.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\LIVRE 06 DISCOS\LIVRE-DISCOS.odt O4 - GS\Desktop [Acer]: LIVRE-MANICK.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\LIVRE 05 MANICK\LIVRE-MANICK vide.odt O4 - GS\Desktop [Acer]: Ma musique.lnk . (...) I:\1-MUSIQUE et GUITARES JL O4 - GS\Desktop [Acer]: Mes anciens documents.lnk . (...) J:\Documents and Settings\prout\Mes documents O4 - GS\Desktop [Acer]: SHADOWS 2017.lnk . (...) J:\Documents and Settings\prout\Mes documents\Ma musique\2017-BACKTRACKS\SHADOWS 2017 O4 - GS\Desktop [Acer]: SHADOWS golden.lnk . (...) C:\Users\Acer\Music\The Shadows\Golden Greats [Single Disc] O4 - GS\Desktop [Acer]: TRAVAIL GUITARE.lnk . (...) I:\1-MUSIQUE et GUITARES JL\0-APPRENTISSAGE O4 - GS\Desktop [Acer]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Acer\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Acer]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Acer]: Windows Movie Maker.lnk . (.Microsoft Corporation - Movie Maker.) C:\Program Files\Windows Live\Photo Gallery\MovieMaker.exe =>.Microsoft Corporation® O4 - GS\sendTo [Acer]: Destinataire de télécopie.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\sendTo [Acer]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\sendTo [Acer]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation O4 - GS\TaskBar [Acer]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Programs [Acer]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Acer\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - GS\Desktop [Administrateur]: 0-photos de famille.lnk . (...) I:\0-IMAGES-RESTAURATION\0-photos de famille O4 - GS\Desktop [Administrateur]: 0-TOUT CLAUDINE.lnk . (...) I:\0-TOUT CE QUI CONCERNE CLAUDINE O4 - GS\Desktop [Administrateur]: 0-TOUT CE QUI CONCERNE JL.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL O4 - GS\Desktop [Administrateur]: DD 2016-11 (I).lnk . (...) I:\ O4 - GS\Desktop [Administrateur]: Folder Marker.lnk . (.ArcticLine Software - Folder Marker Free - Tool for folder icon c.) C:\Program Files\Folder Marker\FolderMarker.exe =>.ArcticLine Software® O4 - GS\Desktop [Administrateur]: Launch Image Scan Tool.lnk . (.Acresso Software Inc. - InstallShield.) C:\WINDOWS\Installer\{F0ACDDA3-1DC3-43C0-84E6-43E927C3E2F7}\Image_Scan_Tool.ex_E1EFFBF60DEB4BB7A6F5ADFF64DE6C73.exe =>.Acresso Software Inc. O4 - GS\Desktop [Administrateur]: LE LIVRE d'Henri Le Leuch.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\0-LIVRE 04 HENRI\LE LIVRE d'Henri Le Leuch.odt O4 - GS\Desktop [Administrateur]: LE LIVRE GRAND-PERE.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\0-LIVRE 01 GRAND PERE\LIVRES-VERSIONS\LE LIVRE2 31-03-2016.odt O4 - GS\Desktop [Administrateur]: LIVIDE.2011.BRRip.XviD.HS - Raccourci.lnk . (...) D:\DCIM\111_PANA\{www.scenetime.com}LIVIDE.2011.BRRip.XviD.HS\LIVIDE.2011.BRRip.XviD.HS.AVI O4 - GS\Desktop [Administrateur]: LIVRE 03 VOILE.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\0-LIVRE 03 VOILE O4 - GS\Desktop [Administrateur]: LIVRE 04 HENRI.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\LIVRE 04 HENRI O4 - GS\Desktop [Administrateur]: LIVRE ARMEE.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\0-LIVRE 02 ARMEE\VERSION 10 corrigée O4 - GS\Desktop [Administrateur]: LIVRE-DISCOS.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\LIVRE 06 DISCOS\LIVRE-DISCOS.odt O4 - GS\Desktop [Administrateur]: LIVRE-MANICK.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\LIVRE 05 MANICK\LIVRE-MANICK vide.odt O4 - GS\Desktop [Administrateur]: Ma musique.lnk . (...) I:\1-MUSIQUE et GUITARES JL O4 - GS\Desktop [Administrateur]: Mes anciens documents.lnk . (...) J:\Documents and Settings\prout\Mes documents O4 - GS\Desktop [Administrateur]: SHADOWS 2017.lnk . (...) J:\Documents and Settings\prout\Mes documents\Ma musique\2017-BACKTRACKS\SHADOWS 2017 O4 - GS\Desktop [Administrateur]: SHADOWS golden.lnk . (...) C:\Users\Acer\Music\The Shadows\Golden Greats [Single Disc] O4 - GS\Desktop [Administrateur]: TRAVAIL GUITARE.lnk . (...) I:\1-MUSIQUE et GUITARES JL\0-APPRENTISSAGE O4 - GS\Desktop [Administrateur]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Acer\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Administrateur]: Windows Movie Maker.lnk . (.Microsoft Corporation - Movie Maker.) C:\Program Files\Windows Live\Photo Gallery\MovieMaker.exe =>.Microsoft Corporation® O4 - GS\sendTo [Administrateur]: Destinataire de télécopie.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\sendTo [Administrateur]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\sendTo [Administrateur]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation O4 - GS\TaskBar [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Programs [Administrateur]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Acer\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - GS\Desktop [WDAGUtilityAccount]: 0-photos de famille.lnk . (...) I:\0-IMAGES-RESTAURATION\0-photos de famille O4 - GS\Desktop [WDAGUtilityAccount]: 0-TOUT CLAUDINE.lnk . (...) I:\0-TOUT CE QUI CONCERNE CLAUDINE O4 - GS\Desktop [WDAGUtilityAccount]: 0-TOUT CE QUI CONCERNE JL.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL O4 - GS\Desktop [WDAGUtilityAccount]: DD 2016-11 (I).lnk . (...) I:\ O4 - GS\Desktop [WDAGUtilityAccount]: Folder Marker.lnk . (.ArcticLine Software - Folder Marker Free - Tool for folder icon c.) C:\Program Files\Folder Marker\FolderMarker.exe =>.ArcticLine Software® O4 - GS\Desktop [WDAGUtilityAccount]: Launch Image Scan Tool.lnk . (.Acresso Software Inc. - InstallShield.) C:\WINDOWS\Installer\{F0ACDDA3-1DC3-43C0-84E6-43E927C3E2F7}\Image_Scan_Tool.ex_E1EFFBF60DEB4BB7A6F5ADFF64DE6C73.exe =>.Acresso Software Inc. O4 - GS\Desktop [WDAGUtilityAccount]: LE LIVRE d'Henri Le Leuch.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\0-LIVRE 04 HENRI\LE LIVRE d'Henri Le Leuch.odt O4 - GS\Desktop [WDAGUtilityAccount]: LE LIVRE GRAND-PERE.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\0-LIVRE 01 GRAND PERE\LIVRES-VERSIONS\LE LIVRE2 31-03-2016.odt O4 - GS\Desktop [WDAGUtilityAccount]: LIVIDE.2011.BRRip.XviD.HS - Raccourci.lnk . (...) D:\DCIM\111_PANA\{www.scenetime.com}LIVIDE.2011.BRRip.XviD.HS\LIVIDE.2011.BRRip.XviD.HS.AVI O4 - GS\Desktop [WDAGUtilityAccount]: LIVRE 03 VOILE.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\0-LIVRE 03 VOILE O4 - GS\Desktop [WDAGUtilityAccount]: LIVRE 04 HENRI.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\LIVRE 04 HENRI O4 - GS\Desktop [WDAGUtilityAccount]: LIVRE ARMEE.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\0-LIVRE 02 ARMEE\VERSION 10 corrigée O4 - GS\Desktop [WDAGUtilityAccount]: LIVRE-DISCOS.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\LIVRE 06 DISCOS\LIVRE-DISCOS.odt O4 - GS\Desktop [WDAGUtilityAccount]: LIVRE-MANICK.lnk . (...) I:\0-TOUT CE QUI CONCERNE JL\LIVRE 05 MANICK\LIVRE-MANICK vide.odt O4 - GS\Desktop [WDAGUtilityAccount]: Ma musique.lnk . (...) I:\1-MUSIQUE et GUITARES JL O4 - GS\Desktop [WDAGUtilityAccount]: Mes anciens documents.lnk . (...) J:\Documents and Settings\prout\Mes documents O4 - GS\Desktop [WDAGUtilityAccount]: SHADOWS 2017.lnk . (...) J:\Documents and Settings\prout\Mes documents\Ma musique\2017-BACKTRACKS\SHADOWS 2017 O4 - GS\Desktop [WDAGUtilityAccount]: SHADOWS golden.lnk . (...) C:\Users\Acer\Music\The Shadows\Golden Greats [Single Disc] O4 - GS\Desktop [WDAGUtilityAccount]: TRAVAIL GUITARE.lnk . (...) I:\1-MUSIQUE et GUITARES JL\0-APPRENTISSAGE O4 - GS\Desktop [WDAGUtilityAccount]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Acer\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [WDAGUtilityAccount]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [WDAGUtilityAccount]: Windows Movie Maker.lnk . (.Microsoft Corporation - Movie Maker.) C:\Program Files\Windows Live\Photo Gallery\MovieMaker.exe =>.Microsoft Corporation® O4 - GS\sendTo [WDAGUtilityAccount]: Destinataire de télécopie.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\sendTo [WDAGUtilityAccount]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\sendTo [WDAGUtilityAccount]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation O4 - GS\TaskBar [WDAGUtilityAccount]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Programs [WDAGUtilityAccount]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Acer\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - GS\CommonDesktop [Public]: Audacity.lnk . (...) J:\Documents and Settings\prout\Mes documents\Ma musique\Audacity\audacity.exe O4 - GS\CommonDesktop [Public]: Canon Quick Menu.lnk . (.CANON INC. - Canon Quick Menu.) C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE =>.Canon Inc.® O4 - GS\CommonDesktop [Public]: CCleaner (1).lnk . (.Piriform Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd® O4 - GS\CommonDesktop [Public]: Corel FastFlick 2018 (1).lnk . (.Corel TW Corp. - FastFlick.) C:\Program Files\Corel\Corel VideoStudio 2018\MWizard.exe =>.Corel Corporation® O4 - GS\CommonDesktop [Public]: EasyBCD 2.3.lnk . (.NeoSmart Technologies - EasyBCD.) C:\Program Files\NeoSmart Technologies\EasyBCD\EasyBCD.exe =>.NeoSmart Technologies® O4 - GS\CommonDesktop [Public]: FreeMi UPnP Media Server (1).lnk . (.Stéphane Mitermite - FreeMi UPnP Media Server.) C:\Program Files\FreeMi UPnP Media Server\FreeMi UPnP Media Server.exe =>.Stéphane Mitermite O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\CommonDesktop [Public]: Live Screen Capture (1).lnk . (.Corel TW Corp. - Live Screen Capture.) C:\Program Files\Corel\Corel VideoStudio 2018\VSSCap.exe =>.Corel Corporation® O4 - GS\CommonDesktop [Public]: MyHeritage Family Tree Builder (1).lnk . (.MyHeritage - MyHeritage Family Tree Builder Genealogy So.) C:\Program Files\MyHeritage\Bin\MyHeritage.exe =>.MyHeritage (USA) Inc.® O4 - GS\CommonDesktop [Public]: OpenOffice 4.1.5 (1).lnk . (.Apache Software Foundation - OpenOffice 4.1.5.) C:\Program Files\OpenOffice 4\program\soffice.exe =>.Apache Software Foundation O4 - GS\CommonDesktop [Public]: SD Card Formatter.lnk . (.Flexera Software LLC - InstallShield.) C:\WINDOWS\Installer\{10C16E01-F739-4093-89A7-E570589FA0F6}\NewShortcut11_9F21041712364E7FBB19D6D84D3AFF1D.exe =>.Tuxera Inc® O4 - GS\CommonDesktop [Public]: TuxGuitar.lnk . (...) X:\Program_Files\tuxguitar-1.5\tuxguitar.exe O4 - GS\CommonDesktop [Public]: VLC media player (1).lnk . (.VideoLAN - VLC media player.) C:\Program Files\VideoLAN\VLC\vlc.exe =>.VideoLAN® O4 - GS\CommonDesktop [Public]: Windows Movie Maker.lnk . (.Microsoft Corporation - Movie Maker.) C:\Program Files\Windows Live\Photo Gallery\MovieMaker.exe =>.Microsoft Corporation® O4 - GS\CommonDesktop [Public]: YT Player.lnk . (.Youtomato - YT Player.) C:\Program Files\Youtomato\YT Downloader\YTPlayer.exe =>.Youtomato O4 - GS\CommonDesktop [Public]: ZOOM Edit&Share.lnk . (.Copyright (C) 2012 ZOOM Corporation - ZOOM Edit&Share.) C:\Program Files\ZOOM\Edit_Share\bin\ZOOM Edit&Share.exe O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Acer\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation O4 - GS\Startup [Public]: HP Digital Imaging Monitor (1).lnk . (...) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe =>.Hewlett-Packard O4 - GS\Startup [Public]: HP Digital Imaging Monitor.lnk . (...) X:\Program_Files\HP\Digital_Imaging\bin\hpqtra08.exe O4 - GS\Startup [Public]: Microsoft Office.lnk . (.Microsoft Corporation - Microsoft Office XP component.) C:\Program Files\Microsoft Office\Office10\OSA.EXE -b -l =>.Microsoft Corporation® O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Accessoire du panneau de saisie mathématiqu.) C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\WINDOWS\system32\quickassist.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture d’écran.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Enregistreur d’actions.) C:\WINDOWS\system32\psr.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Application Windows Wordpad.) C:\Program Files\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - Visionneuse XPS.) C:\WINDOWS\system32\xpsrchvw.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Table des caractères.) C:\WINDOWS\system32\charmap.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Acrobat Reader DC.lnk . (.Flexera Software LLC - InstallShield.) C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}\SC_Reader.ico =>.Flexera Software LLC O4 - GS\ProgramsCommon [Public]: Assistant Mise à jour de Windows 10.lnk . (.Microsoft Corporation - Assistant Mise à jour de Windows 10.) C:\Windows10Upgrade\Windows10UpgraderApp.exe =>.Microsoft Corporation® O4 - GS\ProgramsCommon [Public]: Audacity.lnk . (...) J:\Documents and Settings\prout\Mes documents\Ma musique\Audacity\audacity.exe O4 - GS\ProgramsCommon [Public]: Enregistrement OCR I.R.I.S. (1).lnk . (...) C:\Program Files\HP\Digital Imaging\DocProc\regipe.exe =>.Hewlett-Packard O4 - GS\ProgramsCommon [Public]: Enregistrement OCR I.R.I.S..lnk . (...) X:\Program_Files\HP\Digital_Imaging\DocProc\regipe.exe O4 - GS\ProgramsCommon [Public]: Google Chrome (1).lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\WINDOWS\System32\Control.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Microsoft Excel.lnk . (...) C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\xlicons.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Microsoft Word.lnk . (...) C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\wordicon.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Movie Maker (1).lnk . (.Microsoft Corporation - Movie Maker.) C:\Program Files\Windows Live\Photo Gallery\MovieMaker.exe =>.Microsoft Corporation® O4 - GS\ProgramsCommon [Public]: Movie Maker.lnk . (.Microsoft Corporation - Movie Maker.) C:\Program Files\Windows Live\Photo Gallery\MovieMaker.exe =>.Microsoft Corporation® O4 - GS\ProgramsCommon [Public]: Photo Gallery (1).lnk . (.Microsoft Corporation - Photo Gallery.) C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe =>.Microsoft Corporation® O4 - GS\ProgramsCommon [Public]: Photo Gallery.lnk . (.Microsoft Corporation - Photo Gallery.) C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe =>.Microsoft Corporation® O4 - GS\ProgramsCommon [Public]: VideoStudio Notification (1).lnk . (...) C:\Program Files\Corel\Corel VideoStudio 2018\VSComServer.exe =>.Corel Corporation® O4 - GS\ProgramsCommon [Public]: VideoStudio Notification.lnk . (...) X:\Program_Files\Corel\Corel_VideoStudio_2018\VSComServer.exe O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation ---\\ MODIFICATION DOMAINE/ADRESSES (DNS) (3) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254 =>.Local IP Adress O17 - HKLM\System\CCS\Services\Tcpip\..\{31308398-6b1b-4936-8cb9-b34a01dd1975}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress O17 - HKLM\System\CCS\Services\Tcpip\..\{d8569347-aa42-405b-a1dd-a7ba565bdc6a}: DhcpNameServer = 192.168.0.254 =>.Local IP Adress ---\\ PROTOCOLE ADDITIONNEL (22) - 1s O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} . (.Microsoft Corporation - Microsoft SharePoint Portal Server Object M.) -- C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL =>.Microsoft Corporation O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation O18 - Handler: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} . (.Microsoft Corporation - Microsoft Office XP Web Components.) -- C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.DLL =>.Microsoft Corporation® O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll =>.Microsoft Corporation O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll =>.Microsoft Corporation O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Photo Gallery Album Download Protocol Handl.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll =>.Microsoft Corporation® ---\\ REGISTRE AppInit_DLLs et Winlogon Notify (1) - 0s O20 - Winlogon : UserInit . (.Microsoft Corporation - Application d’ouverture de session Userinit.) - C:\Windows\system32\userinit.exe =>.Microsoft Corporation ---\\ COMPOSANTS ACTIVESETUP INSTALLÉS (ASIC) (5) - 1s O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Utilitaire d’installation du Lecteur Window.) -- C:\Windows\System32\unregmp2.exe =>.Microsoft Corporation O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft Corporation® O40 - ASIC: Google Chrome - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google Inc. - Google Chrome Installer.) -- C:\Program Files\Google\Chrome\Application\67.0.3396.87\Installer\chrmstp.exe =>.Google Inc® ---\\ LOGICIELS INSTALLÉS (48) - 11s O42 - Logiciel: 32 Bit HP CIO Components Installer - (.HP.) [HKLM] -- {13DA9C7C-EBFB-40D0-94A1-55B42883DF21} =>.HP O42 - Logiciel: Adobe Acrobat Reader DC - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AC0F074E4100} =>.Adobe Systems Incorporated O42 - Logiciel: Canon IJ Scan Utility - (.Canon Inc..) [HKLM] -- Canon_IJ_Scan_Utility =>.Canon Inc.® O42 - Logiciel: Canon Inkjet Printer/Scanner/Fax Extended Survey Program - (.Canon Inc..) [HKLM] -- CANONIJPLM100 =>.Canon Inc.® O42 - Logiciel: Canon MG2400 series MP Drivers - (.Canon Inc..) [HKLM] -- {1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2400_series =>.Canon Inc.® O42 - Logiciel: Canon Quick Menu - (.Canon Inc..) [HKLM] -- CanonQuickMenu =>.Canon Inc.® O42 - Logiciel: Corel Graphics Suite 11 - (.Corel Corporation.) [HKLM] -- {A7B78C41-6594-438B-B607-DD1710472C7F} =>.Corel Corporation O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} =>.Microsoft O42 - Logiciel: EasyBCD 2.3 - (.NeoSmart Technologies.) [HKLM] -- EasyBCD =>.NeoSmart Technologies® O42 - Logiciel: Enregistrement utilisateur de Canon MG2400 series - (.‭Canon Inc..) [HKLM] -- Enregistrement utilisateur de Canon MG2400 series =>.Canon Inc.® O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome =>.Google Inc® O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc. O42 - Logiciel: ImageScanTool V2.0.2 - (.$Uw Bedrijfsnaam.) [HKLM] -- {F0ACDDA3-1DC3-43C0-84E6-43E927C3E2F7} O42 - Logiciel: Microsoft Office XP Professional avec FrontPage - (.Microsoft Corporation.) [HKLM] -- {9028040C-6000-11D3-8CFE-0050048383C9} =>.Microsoft Corporation O42 - Logiciel: Microsoft OneDrive - (.Microsoft Corporation.) [HKCU] -- OneDriveSetup.exe =>.Microsoft Corporation® O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8} =>.Microsoft Corporation O42 - Logiciel: Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 - (.Microsoft Corporation.) [HKLM] -- {33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} =>.Microsoft Corporation® O42 - Logiciel: Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 - (.Microsoft Corporation.) [HKLM] -- {B175520C-86A2-35A7-8619-86DC379688B9} =>.Microsoft Corporation O42 - Logiciel: Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 - (.Microsoft Corporation.) [HKLM] -- {BD95A8CD-1D9F-35AD-981A-3E7925026EBB} =>.Microsoft Corporation O42 - Logiciel: Movie Maker - (.Microsoft Corporation.) [HKLM] -- {38F03569-A636-4CF3-BDDE-032C8C251304} =>.Microsoft Corporation O42 - Logiciel: Movie Maker - (.Microsoft Corporation.) [HKLM] -- {DD67BE4B-7E62-4215-AFA3-F123A800A389} =>.Microsoft Corporation O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} =>.Microsoft O42 - Logiciel: MSVCRT110 - (.Microsoft.) [HKLM] -- {8E14DDC8-EA60-4E18-B3E3-1937104D5BDA} =>.Microsoft O42 - Logiciel: NVIDIA Install Application - (.NVIDIA Corporation.) [HKLM] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer =>.NVIDIA Corporation O42 - Logiciel: Panneau de configuration NVIDIA 309.08 - (.NVIDIA Corporation.) [HKLM] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel =>.NVIDIA Corporation O42 - Logiciel: Photo Common - (.Microsoft Corporation.) [HKLM] -- {CAA0F57A-BA8C-4AD8-AA03-F32B0E4F5623} =>.Microsoft Corporation O42 - Logiciel: Photo Gallery - (.Microsoft Corporation.) [HKLM] -- {07AAB66E-4718-422D-9218-4AFB3C922A71} =>.Microsoft Corporation O42 - Logiciel: Photo Gallery - (.Microsoft Corporation.) [HKLM] -- {C992FFE0-AC32-4FA9-BC9A-F1637B9E655D} =>.Microsoft Corporation O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp.® O42 - Logiciel: SD Card Formatter - (.SD Association.) [HKLM] -- {10C16E01-F739-4093-89A7-E570589FA0F6} =>.SD Association O42 - Logiciel: Suite graphique CorelDRAW 11 - (.Corel Corporation.) [HKLM] -- InstallShield_{A7B78C41-6594-438B-B607-DD1710472C7F} =>.Corel Corporation O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {41C61308-6CFD-4D54-AB6A-7136ED08A18E} =>.Microsoft Corporation O42 - Logiciel: Windows Live Essentials - (.Microsoft Corporation.) [HKLM] -- {66B5819D-DE70-42BE-B40F-978FBA12452E} =>.Microsoft Corporation O42 - Logiciel: Windows Live Essentials - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite =>.Microsoft Corporation® O42 - Logiciel: Windows Live Installer - (.Microsoft Corporation.) [HKLM] -- {659CB81C-B54E-4DF1-B618-F35777393A54} =>.Microsoft Corporation O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM] -- {BAD27F0E-5165-49A5-BE66-AF5BF73F2FEE} =>.Microsoft Corporation O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {BAD984EE-790E-4513-A428-3BE2D426DCA7} =>.Microsoft Corporation O42 - Logiciel: Windows Live Photo Common - (.Microsoft Corporation.) [HKLM] -- {1D6432B4-E24D-405E-A4AB-D7E6D088CBC9} =>.Microsoft Corporation O42 - Logiciel: Windows Live PIMT Platform - (.Microsoft Corporation.) [HKLM] -- {B2611F8A-EFE7-4E88-875D-19F0EFAE87E4} =>.Microsoft Corporation O42 - Logiciel: Windows Live SOXE - (.Microsoft Corporation.) [HKLM] -- {CDC1AB00-01FF-4FC7-816A-16C67F0923C0} =>.Microsoft Corporation O42 - Logiciel: Windows Live SOXE Definitions - (.Microsoft Corporation.) [HKLM] -- {D1893000-EA77-493C-8DDD-E262436E959B} =>.Microsoft Corporation O42 - Logiciel: Windows Live UX Platform - (.Microsoft Corporation.) [HKLM] -- {00F9DB8C-65D7-4D47-AB5F-F698EE38580D} =>.Microsoft Corporation O42 - Logiciel: Windows Live UX Platform Language Pack - (.Microsoft Corporation.) [HKLM] -- {6522F5F9-411B-4513-A75B-CEA00395F032} =>.Microsoft Corporation O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM] -- {A2DC527D-FA79-46E9-973F-920897CA55E9} =>.Microsoft Corporation O42 - Logiciel: Windows Live Writer Resources - (.Microsoft Corporation.) [HKLM] -- {0F974770-76EB-4C38-986E-E7BDD9C0DFC4} =>.Microsoft Corporation O42 - Logiciel: Windows Movie Maker 2018 - (.www.topwin-movie-maker.com.) [HKLM] -- {3CC29C1A-B5FE-457B-8F22-32A2557A92C7}}_is1 O42 - Logiciel: YT Downloader 4 - (.Youtomato.) [HKLM] -- YT Downloader_is1 =>.Youtomato O42 - Logiciel: ZOOM Edit&Share for Windows - (.ZOOM Corporation.) [HKLM] -- {E99B8E1C-262D-49E6-9A84-D2AC486B2648} =>.ZOOM Corporation ---\\ CLÉ DE REGISTRE SOFTWARE HKCU & HKLM (118) - 11s HKLM\SOFTWARE\Adobe =>.Adobe HKLM\SOFTWARE\AVAST Software =>.AVAST Software HKLM\SOFTWARE\Canon =>.Canon HKLM\SOFTWARE\Corel =>.Corel HKLM\SOFTWARE\Dolby =>.Dolby HKLM\SOFTWARE\DTS =>.Creative Technology HKLM\SOFTWARE\Fortemedia =>.Lugert Europe HKLM\SOFTWARE\Google =>.Google HKLM\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard HKLM\SOFTWARE\Intel =>.Intel HKLM\SOFTWARE\JavaSoft =>.JavaSoft HKLM\SOFTWARE\Khronos =>.Khronos HKLM\SOFTWARE\Knowles =>.Knowles Electronics HKLM\SOFTWARE\Macromedia =>.Macromedia HKLM\SOFTWARE\Mozilla =>.Mozilla HKLM\SOFTWARE\mozilla.org =>.mozilla.org HKLM\SOFTWARE\MozillaPlugins =>.MozillaPlugins HKLM\SOFTWARE\NeoSmart Technologies =>.NeoSmart Technologies HKLM\SOFTWARE\Nuance =>.Nuance HKLM\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions HKLM\SOFTWARE\OEM =>.OEM HKLM\SOFTWARE\Partner =>.Google Inc. HKLM\SOFTWARE\Realtek =>.Realtek Semiconductor Corp. HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation HKLM\SOFTWARE\SonicFocus =>.Sonic Focus HKLM\SOFTWARE\SoundResearch =>.Sound Research HKLM\SOFTWARE\SRS Labs =>.SRS Labs HKLM\SOFTWARE\Volatile =>.Microsoft Corporation HKLM\SOFTWARE\WOW6432Node =>.Microsoft Corporation HKLM\SOFTWARE\ZOOM =>.ZOOM HKCU\SOFTWARE\Adobe =>.Adobe HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation HKCU\SOFTWARE\ArcticLine =>.ArcticLine HKCU\SOFTWARE\ASProtect =>.ASPack Software HKCU\SOFTWARE\Browser Cleanup =>.Avast Software s.r.o HKCU\SOFTWARE\Canon =>.Canon HKCU\SOFTWARE\Chromium =>.Chromium HKCU\SOFTWARE\Corel =>.Corel HKCU\SOFTWARE\DRP HKCU\SOFTWARE\Google =>.Google HKCU\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard HKCU\SOFTWARE\InstallShield =>.InstallShield HKCU\SOFTWARE\InterVideo =>.InterVideo HKCU\SOFTWARE\JavaSoft =>.JavaSoft HKCU\SOFTWARE\Local AppWizard-Generated Applications =>.ZWCAD HKCU\SOFTWARE\Macromedia =>.Macromedia HKCU\SOFTWARE\MainConcept =>.MainConcept AG HKCU\SOFTWARE\Malwarebytes =>.Malwarebytes HKCU\SOFTWARE\Mozilla =>.Mozilla HKCU\SOFTWARE\MultiScreen HKCU\SOFTWARE\MyHeritage.com =>.MyHeritage.com HKCU\SOFTWARE\Netscape =>.Netscape HKCU\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions HKCU\SOFTWARE\OpenOffice =>.SourceForge HKCU\SOFTWARE\Opera Software =>.Opera Software HKCU\SOFTWARE\Piriform =>.Piriform HKCU\SOFTWARE\QtProject =>.QtProject HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp. HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation HKCU\SOFTWARE\SubSystems =>.Sub Systems Inc HKCU\SOFTWARE\SyncEngines =>.Microsoft Corporation HKCU\SOFTWARE\The Complete Genealogy Reporter =>.Legitimate HKCU\SOFTWARE\Ulead =>.Ulead Systems HKCU\SOFTWARE\Ulead Systems =>.Ulead Systems HKCU\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation HKCU\SOFTWARE\Youtomato =>.Youtomato HKCU\SOFTWARE\ZHP =>.Nicolas Coolman HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation HKCU\SOFTWARE\AppDataLow\Software\Canon =>.Canon HKU\.DEFAULT\SOFTWARE\Canon =>.Canon HKU\.DEFAULT\SOFTWARE\Corel =>.Corel HKU\.DEFAULT\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard HKU\.DEFAULT\SOFTWARE\Netscape =>.Netscape HKU\.DEFAULT\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation HKU\.DEFAULT\SOFTWARE\Opera Software =>.Opera Software HKU\.DEFAULT\SOFTWARE\Piriform =>.Piriform HKU\.DEFAULT\SOFTWARE\Protexis =>.Protexis Inc. HKU\.DEFAULT\SOFTWARE\RegisteredApplications =>.Microsoft Corporation HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Adobe =>.Adobe HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\AppDataLow =>.Microsoft Corporation HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\ArcticLine =>.ArcticLine HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\ASProtect =>.ASPack Software HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Browser Cleanup =>.Avast Software s.r.o HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Canon =>.Canon HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Chromium =>.Chromium HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Corel =>.Corel HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\DRP HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Google =>.Google HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\InstallShield =>.InstallShield HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\InterVideo =>.InterVideo HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\JavaSoft =>.JavaSoft HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Local AppWizard-Generated Applications =>.ZWCAD HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Macromedia =>.Macromedia HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\MainConcept =>.MainConcept AG HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Malwarebytes =>.Malwarebytes HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Mozilla =>.Mozilla HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\MultiScreen HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\MyHeritage.com =>.MyHeritage.com HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Netscape =>.Netscape HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\ODBC =>.DB Connectivity Solutions HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\OpenOffice =>.SourceForge HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Opera Software =>.Opera Software HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Piriform =>.Piriform HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\QtProject =>.QtProject HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Realtek =>.Realtek Semiconductor Corp. HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\RegisteredApplications =>.Microsoft Corporation HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\SubSystems =>.Sub Systems Inc HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\SyncEngines =>.Microsoft Corporation HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\The Complete Genealogy Reporter =>.Legitimate HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Ulead =>.Ulead Systems HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Ulead Systems =>.Ulead Systems HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\Youtomato =>.Youtomato HKU\S-1-5-21-1701276704-2331144504-2702073659-1001\SOFTWARE\ZHP =>.Nicolas Coolman ---\\ CONTENU DES DOSSIERS PROGRAMMES (208) - 11s O43 - CFD: 22/04/2018 - [] D -- C:\Program Files\35mm Film Scanner =>.35mm Film Scanner O43 - CFD: 25/02/2018 - [] D -- C:\Program Files\Adobe =>.Adobe Systems, Incorporated® O43 - CFD: 17/03/2018 - [] D -- C:\Program Files\Canon =>.Canon Inc.® O43 - CFD: 23/02/2018 - [] HD -- C:\Program Files\CanonBJ =>.Canon Inc. O43 - CFD: 25/02/2018 - [] D -- C:\Program Files\CCleaner =>.Piriform Ltd O43 - CFD: 15/04/2018 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation O43 - CFD: 03/03/2018 - [] D -- C:\Program Files\Corel =>.Corel Corporation O43 - CFD: 23/02/2018 - [] D -- C:\Program Files\CorelDRAW Graphics Suite 11 =>.Microsoft Corporation® O43 - CFD: 12/02/2018 - [0] SHD -- C:\Program Files\Fichiers communs =>.Microsoft Corporation O43 - CFD: 02/03/2018 - [] D -- C:\Program Files\Folder Marker =>.ArcticLine Software® O43 - CFD: 25/02/2018 - [] D -- C:\Program Files\FreeMi UPnP Media Server =>.Stéphane Mitermite O43 - CFD: 25/02/2018 - [] D -- C:\Program Files\Google =>.Google Inc® O43 - CFD: 03/03/2018 - [] D -- C:\Program Files\Haali =>.Haali O43 - CFD: 23/02/2018 - [] HD -- C:\Program Files\InstallShield Installation Information =>.InstallShield O43 - CFD: 14/03/2018 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation O43 - CFD: 13/04/2018 - [] D -- C:\Program Files\KMSpico =>HackTool.KMSpico O43 - CFD: 15/04/2018 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation O43 - CFD: 23/02/2018 - [] D -- C:\Program Files\Microsoft SQL Server Compact Edition =>.Microsoft Corporation O43 - CFD: 29/09/2017 - [] D -- C:\Program Files\Microsoft.NET =>.Microsoft Corporation O43 - CFD: 23/02/2018 - [] D -- C:\Program Files\MonitorDriver =>.Monitor Driver O43 - CFD: 13/03/2018 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation O43 - CFD: 23/02/2018 - [] D -- C:\Program Files\MultiScreen O43 - CFD: 23/02/2018 - [] D -- C:\Program Files\MyHeritage =>.BugSplat® O43 - CFD: 20/03/2018 - [] D -- C:\Program Files\NeoSmart Technologies =>.NeoSmart Technologies O43 - CFD: 21/03/2018 - [] D -- C:\Program Files\NVIDIA Corporation =>.nVidia Corporation O43 - CFD: 23/02/2018 - [] D -- C:\Program Files\OpenOffice 4 =>.OpenOffice.org O43 - CFD: 14/04/2018 - [] D -- C:\Program Files\Opera =>.Opera Software O43 - CFD: 17/03/2018 - [] D -- C:\Program Files\Realtek =>.Realtek O43 - CFD: 13/03/2018 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation O43 - CFD: 12/05/2018 - [] D -- C:\Program Files\SDA =>.Tuxera Inc® O43 - CFD: 23/02/2018 - [] D -- C:\Program Files\tuxguitar-1.5 =>.Tux Guitar O43 - CFD: 13/02/2016 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation O43 - CFD: 23/02/2018 - [] D -- C:\Program Files\VideoLAN =>.VideoLan Team O43 - CFD: 14/03/2018 - [] RD -- C:\Program Files\Windows Defender =>.Microsoft Corporation O43 - CFD: 23/02/2018 - [] D -- C:\Program Files\Windows Live =>.Microsoft Corporation O43 - CFD: 13/03/2018 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation O43 - CFD: 14/03/2018 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation O43 - CFD: 21/03/2018 - [] D -- C:\Program Files\Windows Movie Maker =>.Microsoft Corporation O43 - CFD: 29/09/2017 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation O43 - CFD: 13/03/2018 - [] D -- C:\Program Files\windows nt =>.Microsoft Corporation O43 - CFD: 30/09/2017 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation O43 - CFD: 29/09/2017 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation O43 - CFD: 29/09/2017 - [] D -- C:\Program Files\Windows Security =>.Microsoft Corporation O43 - CFD: 29/09/2017 - [] SHD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation O43 - CFD: 22/06/2018 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation O43 - CFD: 29/09/2017 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation O43 - CFD: 23/03/2018 - [] D -- C:\Program Files\Youtomato =>.Youtomato O43 - CFD: 24/04/2018 - [] D -- C:\Program Files\ZOOM =>.ZOOM O43 - CFD: 22/04/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\35mm Film Scanner =>.35mm Film Scanner O43 - CFD: 29/09/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation O43 - CFD: 14/03/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation O43 - CFD: 14/03/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG2400 series Manual =>.Canon Inc. O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities =>.Canon Inc. O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel VideoStudio 2018 =>.Pinnacle Systems, Inc. O43 - CFD: 17/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enregistrement utilisateur de Canon MG2400 series =>.Canon Inc. O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Folder Marker O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeMi UPnP Media Server =>.Stéphane Mitermite O43 - CFD: 30/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP =>.Hewlett-Packard O43 - CFD: 29/09/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MultiScreen O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyHeritage.com =>.MyHeritage.com O43 - CFD: 20/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSmart Technologies =>.NeoSmart Technologies O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation =>.nVidia Corporation O43 - CFD: 13/03/2018 - [] SD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.5 =>.SourceForge O43 - CFD: 15/04/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office =>.Microsoft Corporation O43 - CFD: 12/05/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SD Association =>.SD Association O43 - CFD: 15/04/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation O43 - CFD: 15/04/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Suite graphique CorelDRAW 11 O43 - CFD: 14/03/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation O43 - CFD: 13/02/2016 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC =>.Wacom Technology O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuxGuitar =>.Tux Guitar O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team O43 - CFD: 21/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker =>.Microsoft Corporation O43 - CFD: 14/04/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YT Downloader O43 - CFD: 24/04/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZOOM =>.ZOOM O43 - CFD: 15/04/2018 - [] D -- C:\ProgramData\Adobe =>.Adobe O43 - CFD: 13/03/2018 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation O43 - CFD: 18/03/2018 - [] D -- C:\ProgramData\AVAST Software =>.AVAST Software O43 - CFD: 12/02/2018 - [0] SHD -- C:\ProgramData\Bureau =>.Microsoft Corporation O43 - CFD: 23/02/2018 - [] HD -- C:\ProgramData\CanonBJ =>.Canon Inc. O43 - CFD: 03/03/2018 - [] HD -- C:\ProgramData\CanonIJMIG =>.Canon Inc. O43 - CFD: 01/06/2018 - [] D -- C:\ProgramData\CanonIJPLM =>.Canon Inc. O43 - CFD: 23/02/2018 - [] HD -- C:\ProgramData\CanonIJQuickMenu =>.Canon Inc. O43 - CFD: 03/03/2018 - [] HD -- C:\ProgramData\CanonIJScan =>.Canon Inc. O43 - CFD: 17/03/2018 - [] D -- C:\ProgramData\CanonIJWSpt =>.Canon Inc. O43 - CFD: 30/10/2015 - [0] D -- C:\ProgramData\Comms =>.Microsoft Corporation O43 - CFD: 04/03/2018 - [] D -- C:\ProgramData\Corel =>.Corel Corporation O43 - CFD: 13/03/2018 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation O43 - CFD: 20/03/2018 - [] D -- C:\ProgramData\Hewlett-Packard =>.Hewlett-Packard O43 - CFD: 25/02/2018 - [] D -- C:\ProgramData\HP =>.Hewlett-Packard O43 - CFD: 25/02/2018 - [] D -- C:\ProgramData\HP Product Assistant =>.Hewlett-Packard O43 - CFD: 12/02/2018 - [] D -- C:\ProgramData\InstallShield =>.InstallShield O43 - CFD: 31/05/2018 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes O43 - CFD: 12/02/2018 - [0] SHD -- C:\ProgramData\Menu Démarrer =>.Microsoft Corporation O43 - CFD: 15/04/2018 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation O43 - CFD: 12/02/2018 - [0] SHD -- C:\ProgramData\Modèles =>.Microsoft Corporation O43 - CFD: 23/02/2018 - [] D -- C:\ProgramData\MyHeritage =>.MyHeritage O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\NVIDIA =>.nVidia Corporation O43 - CFD: 12/02/2018 - [] D -- C:\ProgramData\NVIDIA Corporation =>.nVidia Corporation O43 - CFD: 24/02/2018 - [] D -- C:\ProgramData\Oracle =>.Oracle O43 - CFD: 23/02/2018 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation O43 - CFD: 03/03/2018 - [] D -- C:\ProgramData\Protexis =>.Protexis Inc. O43 - CFD: 29/09/2017 - [0] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation O43 - CFD: 29/09/2017 - [0] D -- C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation O43 - CFD: 02/03/2018 - [] D -- C:\ProgramData\UniqueId =>.Microsoft Corporation O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\USOPrivate =>.Microsoft Corporation O43 - CFD: 13/03/2018 - [] D -- C:\ProgramData\USOShared =>.Microsoft Corporation O43 - CFD: 25/02/2018 - [] D -- C:\Program Files\Common Files\Adobe =>.Adobe O43 - CFD: 17/03/2018 - [] D -- C:\Program Files\Common Files\AVAST Software =>.AVAST Software O43 - CFD: 23/02/2018 - [] D -- C:\Program Files\Common Files\Corel =>.Corel Corporation O43 - CFD: 15/04/2018 - [] D -- C:\Program Files\Common Files\Designer =>.Designer O43 - CFD: 25/02/2018 - [] D -- C:\Program Files\Common Files\Hewlett-Packard =>.Hewlett-Packard O43 - CFD: 25/02/2018 - [] D -- C:\Program Files\Common Files\HP =>.Hewlett-Packard O43 - CFD: 23/02/2018 - [] D -- C:\Program Files\Common Files\InstallShield =>.InstallShield O43 - CFD: 15/04/2018 - [] D -- C:\Program Files\Common Files\microsoft shared =>.Microsoft Corporation O43 - CFD: 03/03/2018 - [] D -- C:\Program Files\Common Files\Protexis =>.Protexis Inc. O43 - CFD: 29/09/2017 - [] D -- C:\Program Files\Common Files\Services =>.Microsoft Corporation O43 - CFD: 30/09/2017 - [] D -- C:\Program Files\Common Files\system =>.Microsoft Corporation O43 - CFD: 23/02/2018 - [] D -- C:\Program Files\Common Files\Windows Live =>.Microsoft Corporation O43 - CFD: 25/02/2018 - [] D -- C:\Users\Acer\AppData\Roaming\Adobe =>.Adobe O43 - CFD: 02/03/2018 - [] D -- C:\Users\Acer\AppData\Roaming\ArcticLine =>.ArcticLine O43 - CFD: 28/05/2018 - [] D -- C:\Users\Acer\AppData\Roaming\audacity =>.Audacity O43 - CFD: 03/03/2018 - [] D -- C:\Users\Acer\AppData\Roaming\Canon =>.Canon O43 - CFD: 03/03/2018 - [] D -- C:\Users\Acer\AppData\Roaming\Corel =>.Corel Corporation O43 - CFD: 18/03/2018 - [] D -- C:\Users\Acer\AppData\Roaming\DRPNPS O43 - CFD: 23/02/2018 - [] D -- C:\Users\Acer\AppData\Roaming\dvdcss =>.VideoLan Team O43 - CFD: 03/03/2018 - [] D -- C:\Users\Acer\AppData\Roaming\HP =>.Hewlett-Packard O43 - CFD: 04/03/2018 - [] D -- C:\Users\Acer\AppData\Roaming\HpUpdate =>.Hewlett-Packard O43 - CFD: 23/02/2018 - [] D -- C:\Users\Acer\AppData\Roaming\InstallShield =>.InstallShield O43 - CFD: 12/02/2018 - [] D -- C:\Users\Acer\AppData\Roaming\Macromedia =>.Macromedia O43 - CFD: 02/06/2018 - [] SD -- C:\Users\Acer\AppData\Roaming\Microsoft =>.Microsoft Corporation O43 - CFD: 23/02/2018 - [] D -- C:\Users\Acer\AppData\Roaming\Mozilla =>.Mozilla Corporation O43 - CFD: 26/02/2018 - [] D -- C:\Users\Acer\AppData\Roaming\MyHeritage =>.MyHeritage O43 - CFD: 23/02/2018 - [] D -- C:\Users\Acer\AppData\Roaming\OpenOffice =>.SourceForge O43 - CFD: 17/03/2018 - [] D -- C:\Users\Acer\AppData\Roaming\Opera Software =>.Opera Software O43 - CFD: 23/02/2018 - [0] D -- C:\Users\Acer\AppData\Roaming\The Complete Genealogy Reporter - FTB =>.Legitimate O43 - CFD: 03/03/2018 - [] D -- C:\Users\Acer\AppData\Roaming\Ulead Systems =>.Ulead Systems O43 - CFD: 21/05/2018 - [] D -- C:\Users\Acer\AppData\Roaming\vlc =>.VideoLan Team O43 - CFD: 14/04/2018 - [] D -- C:\Users\Acer\AppData\Roaming\Youtomato =>.Youtomato O43 - CFD: 23/06/2018 - [] D -- C:\Users\Acer\AppData\Roaming\ZHP =>.Nicolas Coolman O43 - CFD: 12/02/2018 - [0] D -- C:\Users\Acer\AppData\Local\ActiveSync =>.Microsoft Corporation O43 - CFD: 14/04/2018 - [] D -- C:\Users\Acer\AppData\Local\Adobe =>.Adobe O43 - CFD: 13/03/2018 - [0] SHD -- C:\Users\Acer\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 23/02/2018 - [] D -- C:\Users\Acer\AppData\Local\Audacity =>.Audacity O43 - CFD: 25/02/2018 - [] D -- C:\Users\Acer\AppData\Local\CEF =>.CEF O43 - CFD: 15/03/2018 - [] D -- C:\Users\Acer\AppData\Local\Comms =>.Microsoft Corporation O43 - CFD: 15/03/2018 - [] D -- C:\Users\Acer\AppData\Local\ConnectedDevicesPlatform =>.Microsoft Corporation O43 - CFD: 12/03/2018 - [0] D -- C:\Users\Acer\AppData\Local\CrashDumps =>.Microsoft Corporation O43 - CFD: 17/03/2018 - [0] D -- C:\Users\Acer\AppData\Local\DBG =>.DBG O43 - CFD: 20/04/2018 - [0] D -- C:\Users\Acer\AppData\Local\Diagnostics =>.Microsoft Corporation O43 - CFD: 12/05/2018 - [] D -- C:\Users\Acer\AppData\Local\Downloaded Installations =>.Microsoft Corporation O43 - CFD: 08/06/2018 - [0] D -- C:\Users\Acer\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation O43 - CFD: 01/03/2018 - [] D -- C:\Users\Acer\AppData\Local\Google =>.Google O43 - CFD: 13/03/2018 - [0] SHD -- C:\Users\Acer\AppData\Local\Historique =>.Microsoft Corporation O43 - CFD: 20/03/2018 - [] D -- C:\Users\Acer\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 12/02/2018 - [] D -- C:\Users\Acer\AppData\Local\MicrosoftEdge =>.Microsoft Corporation O43 - CFD: 23/02/2018 - [] D -- C:\Users\Acer\AppData\Local\Mozilla =>.Mozilla Corporation O43 - CFD: 20/03/2018 - [] D -- C:\Users\Acer\AppData\Local\NeoSmart_Technologies =>.NeoSmart Technologies O43 - CFD: 17/03/2018 - [] D -- C:\Users\Acer\AppData\Local\Opera Software =>.Opera Software O43 - CFD: 14/04/2018 - [] D -- C:\Users\Acer\AppData\Local\Packages =>.Microsoft Corporation O43 - CFD: 22/03/2018 - [0] D -- C:\Users\Acer\AppData\Local\PlaceholderTileLogoFolder =>.Microsoft Corporation O43 - CFD: 12/02/2018 - [] D -- C:\Users\Acer\AppData\Local\Programs =>.Microsoft Corporation O43 - CFD: 12/02/2018 - [] D -- C:\Users\Acer\AppData\Local\Publishers =>.Microsoft Corporation O43 - CFD: 20/04/2018 - [] D -- C:\Users\Acer\AppData\Local\speech =>.Microsoft Corporation O43 - CFD: 25/02/2018 - [] D -- C:\Users\Acer\AppData\Local\Stéphane_Mitermite =>.Stéphane Mitermite O43 - CFD: 23/06/2018 - [] D -- C:\Users\Acer\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 13/03/2018 - [0] SHD -- C:\Users\Acer\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 13/03/2018 - [] D -- C:\Users\Acer\AppData\Local\TileDataLayer =>.Microsoft Corporation O43 - CFD: 23/02/2018 - [] D -- C:\Users\Acer\AppData\Local\VirtualStore =>.Microsoft Corporation O43 - CFD: 23/06/2018 - [] D -- C:\Users\Acer\AppData\Local\ZHP =>.Nicolas Coolman O43 - CFD: 12/02/2018 - [0] D -- C:\Users\Acer\AppData\Local\Programs\Common =>.Microsoft Corporation O43 - CFD: 25/02/2018 - [] D -- C:\Users\Acer\AppData\LocalLow\Adobe =>.Adobe O43 - CFD: 23/02/2018 - [0] D -- C:\Users\Acer\AppData\LocalLow\Canon Easy-WebPrint EX =>.Canon Inc. O43 - CFD: 23/02/2018 - [0] D -- C:\Users\Acer\AppData\LocalLow\Canon Easy-WebPrint EX2 =>.Canon Inc. O43 - CFD: 13/03/2018 - [] SD -- C:\Users\Acer\AppData\LocalLow\Microsoft =>.Microsoft Corporation O43 - CFD: 17/03/2018 - [0] D -- C:\Users\Acer\AppData\LocalLow\Mozilla =>.Mozilla Corporation O43 - CFD: 06/03/2018 - [0] D -- C:\Users\Acer\Desktop\CD SHADOWS O43 - CFD: 16/06/2018 - [] RD -- C:\Users\Acer\Desktop\FILMS 35mm O43 - CFD: 03/03/2018 - [] D -- C:\Users\Acer\Desktop\VideoStudio2018 O43 - CFD: 29/09/2017 - [] RD -- C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation O43 - CFD: 13/03/2018 - [] RD -- C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation O43 - CFD: 14/03/2018 - [] RD -- C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools O43 - CFD: 13/03/2018 - [] D -- C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter =>.Mike Matsnev O43 - CFD: 29/09/2017 - [] D -- C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation O43 - CFD: 14/03/2018 - [] RD -- C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation O43 - CFD: 29/09/2017 - [] RD -- C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation O43 - CFD: 29/09/2017 - [] RD -- C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation O43 - CFD: 13/03/2018 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 12/02/2018 - [0] SHD -- C:\Users\Default\AppData\Local\Historique =>.Microsoft Corporation O43 - CFD: 30/09/2017 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 29/09/2017 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 13/03/2018 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 13/03/2018 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 12/02/2018 - [0] SHD -- C:\Users\Default User\AppData\Local\Historique =>.Microsoft Corporation O43 - CFD: 30/09/2017 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 29/09/2017 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 13/03/2018 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 17/03/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\AVAST Software =>.AVAST Software O43 - CFD: 14/03/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\DataSharing =>.DataSharing O43 - CFD: 13/04/2018 - [0] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\DBG =>.DBG O43 - CFD: 16/03/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 13/06/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Packages =>.Microsoft Corporation O43 - CFD: 14/03/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\TokenBroker O43 - CFD: 13/03/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Adobe =>.Adobe O43 - CFD: 13/03/2018 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation ---\\ DERNIERS FICHIERS CRÉÉS DANS WINDOWS Prefetcher (4) - 18s O45 - LFCP:[MD5.7CA84FBB687C76630E33F90BEFAF2457] 31/05/2018 A -- C:\WINDOWS\Prefetch\REIMAGE.EXE-4681D307.pf =>.SUP.ReimageRepair O45 - LFCP:[MD5.40439580EA2AE23A018DB73FFEB74082] 31/05/2018 A -- C:\WINDOWS\Prefetch\REIMAGEPACKAGE.EXE-7368C646.pf =>.SUP.ReimageRepair O45 - LFCP:[MD5.9572F5228D0BC8FB1CF71121FF8B6642] 31/05/2018 A -- C:\WINDOWS\Prefetch\REIMAGEREPAIR.EXE-C047F994.pf =>.SUP.ReimageRepair O45 - LFCP:[MD5.99CAD3EA1FD1B480F74D9FABD5CA7AA9] 14/04/2018 A -- C:\WINDOWS\Prefetch\YTDOWNLOADER.EXE-A331A5FF.pf =>Adware.YTDownloader ---\\ ShellIconOverlayIdentifiers (SIOI) (1) - 0s O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation ---\\ RACCOURCIS DES MENUS CONCEPTUELS (SCMH) (24) - 2s O108 - CMH1: EPP - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Extension Microsoft Security Client Shell.) -- C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows® O108 - CMH1: ModernSharing - {e2bf9676-5f8f-435c-97eb-11607a5bedf7} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation O108 - CMH1: Open With - {09799AFB-AD67-11d1-ABCD-00C04FC30936} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows® O108 - CMH1: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation O108 - CMH1: WorkFolders - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extension d’environnement de Dossiers de tr.) -- C:\Windows\System32\WorkfoldersShell.dll =>.Microsoft Corporation O108 - CMH1: Youtomato.YTConverter - {3A0058EA-C412-4426-8EF7-50C39B4DD51D} . (.Youtomato - Windows Shell Extension.) -- C:\Program Files\Youtomato\YT Downloader\YTC_WS.dll =>.Youtomato O108 - CMH1: Youtomato.YTPlayer - {0C671AE6-FB74-4582-AF90-3ABF895450B7} . (.Youtomato - Windows Shell Extension.) -- C:\Program Files\Youtomato\YT Downloader\YTP_WS.dll =>.Youtomato O108 - CMH2: OpenContainingFolderMenu - {37ea3a21-7493-4208-a011-7f9ea79ce9f5} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows® O108 - CMH3: CopyAsPathMenu - {f3d06e7c-1e45-4a26-847e-f9fcdee59be0} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows® O108 - CMH3: SendTo - {7BA4C740-9E81-11CF-99D3-00AA004AE837} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows® O108 - CMH4: EPP - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Extension Microsoft Security Client Shell.) -- C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows® O108 - CMH4: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation O108 - CMH4: WorkFolders - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extension d’environnement de Dossiers de tr.) -- C:\Windows\System32\WorkfoldersShell.dll =>.Microsoft Corporation O108 - CMH5: New - {D969A300-E7FF-11d0-A93B-00A0C90F2719} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows® O108 - CMH5: NvCplDesktopContext - {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} . (.NVIDIA Corporation - .) -- C:\Windows\System32\nvshext.dll =>.NVIDIA Corporation® O108 - CMH5: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation O108 - CMH5: WorkFolders - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extension d’environnement de Dossiers de tr.) -- C:\Windows\System32\WorkfoldersShell.dll =>.Microsoft Corporation O108 - CMH6: Library Location - {3dad6c5d-2167-4cae-9914-f99e41c12cfa} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows® O108 - CMH6: PintoStartScreen - {470C0EBD-5D73-4d58-9CED-E91E22E23282} . (.Microsoft Corporation - Programme de résolution d’applications.) -- C:\Windows\System32\appresolver.dll =>.Microsoft Windows® O108 - CMH6: Youtomato.YTConverter - {3A0058EA-C412-4426-8EF7-50C39B4DD51D} . (.Youtomato - Windows Shell Extension.) -- C:\Program Files\Youtomato\YT Downloader\YTC_WS.dll =>.Youtomato O108 - CMH6: Youtomato.YTPlayer - {0C671AE6-FB74-4582-AF90-3ABF895450B7} . (.Youtomato - Windows Shell Extension.) -- C:\Program Files\Youtomato\YT Downloader\YTP_WS.dll =>.Youtomato O108 - CMH7: EnhancedStorageShell - {2854F705-3548-414C-A113-93E27C808C85} . (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation O108 - CMH7: EPP - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Extension Microsoft Security Client Shell.) -- C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows® O108 - CMH7: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation ---\\ IMAGE FILE EXECUTION OPTIONS (IFEO) (19) - 4s O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\\3] =>.Microsoft Windows® O50 - IFEO:C:\Windows\System32\drvinst.exe - (.Microsoft Corporation - Module d’installation de pilotes.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\ie4uinit.exe - (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) [MitigationOptions\\256] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - Outil d’installation sans assistance d’IE 7.) [MitigationOptions\\256] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Microsoft Management Console.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\MRT.exe - (.Microsoft Corporation - Outil de suppression de logiciels malveilla.) [CFGOptions\\1] =>.Microsoft Corporation® O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Hôte des applications HTML de Microsoft(R).) [MitigationOptions\\256] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation Host.) [MitigationOptions\\1118481] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\\2097152] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\\4294967296] =>.Microsoft Windows® O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\spoolsv.exe - (.Microsoft Corporation - Application sous-système spouleur.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\spoolsv.exe - (.Microsoft Corporation - Application sous-système spouleur.) [MitigationOptions\\2097152] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Processus hôte pour les services Windows.) [MinimumStackCommitInBytes\\32768] =>.Microsoft Windows Publisher® O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Processus hôte pour les services Windows.) [MitigationAuditOptions\\17660905521152] =>.Microsoft Windows Publisher® O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation ---\\ LISTE DES PILOTES DU SYSTÈME (61) - 15s O58 - SDL:2017/09/29 13:49:09 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [85912] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:09 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1037344] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:09 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [75160] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:09 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [215448] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:09 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [22936] =>.Microsoft Windows® O58 - SDL:2018/04/18 18:27:54 A . (.Apple Inc. - Apple Mobile Device USB Device.) -- C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [29344] =>.WDKTestCert build,131474841775766162® O58 - SDL:2017/09/29 13:49:09 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [116632] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:09 A . (. - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [8192] =>.Broadcom Corporation O58 - SDL:2012/09/25 09:52:04 A . (. - IEEE-1284.4-1999 Driver.) -- C:\WINDOWS\System32\drivers\Dot4.sys [137632] =>.Hewlett-Packard Company® O58 - SDL:2012/09/25 09:52:04 A . (. - IEEE-1284.4 Print Class Driver.) -- C:\WINDOWS\System32\drivers\Dot4Prt.sys [22432] =>.Hewlett-Packard Company® O58 - SDL:2017/09/29 13:49:09 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [55840] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:05 A . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iagpio.sys [28672] =>.Intel(R) Corporation O58 - SDL:2017/09/29 13:49:05 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\WINDOWS\System32\drivers\iai2c.sys [74240] =>.Intel(R) Corporation O58 - SDL:2017/09/29 13:49:10 A . (.Intel Corporation - Intel(R) Atom(TM) Processor GPIO Controller.) -- C:\WINDOWS\System32\drivers\iaiogpio.sys [22016] =>.Intel Corporation O58 - SDL:2017/09/29 13:49:09 A . (.Intel Corporation - Intel(R) Atom(TM) Processor I2C Controller.) -- C:\WINDOWS\System32\drivers\iaioi2c.sys [57856] =>.Intel Corporation O58 - SDL:2017/09/29 13:49:10 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [525208] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:10 A . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [333720] =>.Microsoft Windows® O58 - SDL:2015/06/18 04:25:00 A . (.Logitech, Inc. - Logitech HID Filter Driver..) -- C:\WINDOWS\System32\drivers\LHidFilt.Sys [53904] =>.Logitech Inc® O58 - SDL:2015/06/18 04:25:00 A . (.Logitech, Inc. - Logitech Mouse Filter Driver..) -- C:\WINDOWS\System32\drivers\LMouFilt.Sys [47632] =>.Logitech Inc® O58 - SDL:2018/03/17 17:13:49 A . (.Logitech, Inc. - Logitech Non-Plug and Play Driver..) -- C:\WINDOWS\System32\drivers\LNonPnP.sys [16400] =>.Logitech® O58 - SDL:2018/03/17 17:39:32 A . (...) -- C:\WINDOWS\System32\drivers\lpsport.sys [55160] =>.AVG Technologies CZ, s.r.o.® O58 - SDL:2017/09/29 13:49:09 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [93216] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:09 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [102808] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:09 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [84376] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:09 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [69528] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:09 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [52120] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:09 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\MegaSas2i.sys [56728] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:09 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [464792] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:10 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [58264] =>.Microsoft Windows® O58 - SDL:2014/05/20 04:32:37 A . (.NVIDIA Corporation - NVIDIA HDMI Audio Driver.) -- C:\WINDOWS\System32\drivers\nvhda32v.sys [162592] =>.NVIDIA Corporation® O58 - SDL:2015/01/31 04:51:54 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\WINDOWS\System32\drivers\nvlddmkm.sys [10964624] =>.NVIDIA Corporation® O58 - SDL:2017/09/29 13:49:08 A . (.NVIDIA Corporation - NVIDIA MCP Networking Function Driver..) -- C:\WINDOWS\System32\drivers\nvmf6232.sys [291456] =>.NVIDIA Corporation O58 - SDL:2017/09/29 13:49:10 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [119192] =>.Microsoft Windows® O58 - SDL:2010/04/09 03:32:54 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvrd32.sys [139368] =>.NVIDIA Corporation® O58 - SDL:2017/09/29 13:49:10 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [141344] =>.Microsoft Windows® O58 - SDL:2010/04/09 03:32:56 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor32.sys [215656] =>.NVIDIA Corporation® O58 - SDL:2017/09/29 13:49:10 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [51608] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:10 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [54680] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:19 RA . (.Realtek - Realtek PCIe GBE Family Controller Flight.) -- C:\WINDOWS\System32\drivers\rteth.sys [47616] =>.Realtek O58 - SDL:2018/03/07 23:06:22 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RTKVHDA.sys [4699072] =>.Realtek Semiconductor Corp.® O58 - SDL:2018/02/27 12:58:51 A . (.Realsil Semiconductor Corporation - RTS USB READER Driver.) -- C:\WINDOWS\System32\drivers\RtsUer.sys [311744] =>.Realtek Semiconductor Corp.® O58 - SDL:2017/09/29 13:49:10 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [41368] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:10 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [78368] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:10 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [27032] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:10 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR X86-32.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [149912] =>.Microsoft Windows® O58 - SDL:2017/09/29 13:49:10 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [276000] =>.Microsoft Windows® O58 - SDL:2018/03/13 00:20:08 A . (...) -- C:\WINDOWS\System32\ANSI.SYS [9029] =>.Microsoft Corporation O58 - SDL:2018/03/13 00:20:08 A . (...) -- C:\WINDOWS\System32\country.sys [27097] =>.Microsoft Corporation O58 - SDL:2018/03/13 00:20:08 A . (...) -- C:\WINDOWS\System32\HIMEM.SYS [4768] =>.Microsoft Corporation O58 - SDL:2018/03/13 00:20:09 A . (...) -- C:\WINDOWS\System32\KEY01.SYS [42809] =>.Microsoft Corporation O58 - SDL:2018/03/13 00:20:09 A . (...) -- C:\WINDOWS\System32\KEYBOARD.SYS [42537] =>.Microsoft Corporation O58 - SDL:2018/03/13 00:20:09 A . (...) -- C:\WINDOWS\System32\NTDOS.SYS [27866] =>.Microsoft Corporation O58 - SDL:2018/03/13 00:20:08 A . (...) -- C:\WINDOWS\System32\NTDOS404.SYS [29146] =>.Microsoft Corporation O58 - SDL:2018/03/13 00:20:08 A . (...) -- C:\WINDOWS\System32\NTDOS411.SYS [29370] =>.Microsoft Corporation O58 - SDL:2018/03/13 00:20:08 A . (...) -- C:\WINDOWS\System32\NTDOS412.SYS [29274] =>.Microsoft Corporation O58 - SDL:2018/03/13 00:20:08 A . (...) -- C:\WINDOWS\System32\NTDOS804.SYS [29146] =>.Microsoft Corporation O58 - SDL:2018/03/13 00:20:10 A . (...) -- C:\WINDOWS\System32\NTIO.SYS [33968] =>.Microsoft Corporation O58 - SDL:2018/03/13 00:20:09 A . (...) -- C:\WINDOWS\System32\NTIO404.SYS [34688] =>.Microsoft Corporation O58 - SDL:2018/03/13 00:20:09 A . (...) -- C:\WINDOWS\System32\NTIO411.SYS [35776] =>.Microsoft Corporation O58 - SDL:2018/03/13 00:20:09 A . (...) -- C:\WINDOWS\System32\NTIO412.SYS [35552] =>.Microsoft Corporation O58 - SDL:2018/03/13 00:20:09 A . (...) -- C:\WINDOWS\System32\NTIO804.SYS [34688] =>.Microsoft Corporation ---\\ DERNIERS FICHIERS MODIFIÉS OU CRÉÉS (Utilisateur) (1) - 43s O61 - LFC: 2018/06/09 11:18:52 A . (..) -- C:\Users\Acer\Downloads\Apache_OpenOffice_4.1.5_Win_x86_install_fr.exe [132403128] ---\\ ASSOCIATION Shell Spawning (10) - 0s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- C:\Windows\System32\WScript.exe "%1" %* =>.Default.Value O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe =>.Microsoft Corporation O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S =>.Default.Value ---\\ MENU DE DÉMARRAGE INTERNET (8) - 0s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation ---\\ RECHERCHE D'INFECTION SUR LES NAVIGATEURS (2) - 9s O69 - SBI: SearchScopes [HKCU]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com O69 - SBI: SearchScopes [HKLM]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com ---\\ ÉNUMÈRE LES SERVICES DÉMARRÉS PAR Svchost (48) - 1s O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [182272] =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [182272] =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [207872] =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [1136128] =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [732672] =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [725504] =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [24064] =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [117760] =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [116224] =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [91136] =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [695808] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [183808] =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [317440] =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [339456] =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [79872] =>.Microsoft Corporation O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\Windows\System32\XblGameSave.dll [788992] =>.Microsoft Corporation O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\Windows\System32\Windows.SharedPC.AccountManager.dll [143360] =>.Microsoft Corporation O83 - Search Svchost Services: PushToInstall (PushToInstall) . (.Microsoft Corporation - PushToInstall.) -- C:\Windows\System32\PushToInstall.dll [187392] =>.Microsoft Corporation O83 - Search Svchost Services: XboxGipSvc (XboxGipSvc) . (.Microsoft Corporation - Xbox Gip Management Service.) -- C:\Windows\System32\XboxGipSvc.dll [46592] =>.Microsoft Corporation O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Service Configuration du réseau.) -- C:\Windows\System32\NetSetupSvc.dll [215552] =>.Microsoft Corporation O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [331264] =>.Microsoft Corporation O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\Windows\System32\dmwappushsvc.dll [49664] =>.Microsoft Corporation O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Paramètres de vol.) -- C:\Windows\System32\flightsettings.dll [654336] =>.Microsoft Corporation O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL Windows Management Service.) -- C:\Windows\System32\Windows.Internal.Management.dll [516608] =>.Microsoft Corporation O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\Windows\System32\XblAuthManager.dll [656896] =>.Microsoft Corporation O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\Windows\System32\DeviceSetupManager.dll [189952] =>.Microsoft Corporation O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\Windows\System32\NcaSvc.dll [146432] =>.Microsoft Corporation O83 - Search Svchost Services: NaturalAuthentication (NaturalAuthentication) . (.Microsoft Corporation - Service d’authentification naturelle.) -- C:\Windows\System32\NaturalAuth.dll [297472] =>.Microsoft Corporation O83 - Search Svchost Services: InstallService (InstallService) . (.Microsoft Corporation - InstallService.) -- C:\Windows\System32\InstallService.dll [1008640] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [53760] =>.Microsoft Corporation O83 - Search Svchost Services: TokenBroker (TokenBroker) . (.Microsoft Corporation - Broker à jetons.) -- C:\Windows\System32\TokenBroker.dll [915968] =>.Microsoft Corporation O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\Windows\System32\XboxNetApiSvc.dll [931328] =>.Microsoft Corporation O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Service du système de notifications Push Wi.) -- C:\Windows\System32\WpnService.dll [245248] =>.Microsoft Corporation O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\Windows\System32\wlidsvc.dll [1652224] =>.Microsoft Corporation O83 - Search Svchost Services: Irmon (Irmon) . (.Microsoft Corporation - Moniteur infrarouge.) -- C:\Windows\System32\irmon.dll [20480] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [92672] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\Windows\System32\rasmans.dll [830976] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [403456] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [57856] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [533504] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [252928] =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [2341888] =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [1003008] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [565248] =>.Microsoft Corporation O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\Windows\System32\usermgr.dll [769536] =>.Microsoft Corporation O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service de géolocalisation.) -- C:\Windows\System32\lfsvc.dll [37888] =>.Microsoft Corporation O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Mettre à jour la session Orchestrator Core.) -- C:\Windows\System32\usocore.dll [943616] =>.Microsoft Corporation O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [107008] =>.Microsoft Corporation ---\\ CODES PRODUITS LOGICIELS (32) - 1s O90 - PUC: "0003981D77AEC394D8DD2E2634E659B9" [HKLM] . (.Windows Live SOXE Definitions.) =>.Microsoft Corporation O90 - PUC: "00BA1CDCFF107CF418A6616CF790320C" [HKLM] . (.Windows Live SOXE.) =>.Microsoft Corporation O90 - PUC: "077479F0BE6783C489E67EDB9D0CFD4C" [HKLM] . (.Windows Live Writer Resources.) =>.Microsoft Corporation O90 - PUC: "0EFF299C23CA9AF4CBA91F36B7E956D5" [HKLM] . (.Photo Gallery.) =>.CyberLink Corporation O90 - PUC: "10E61C01937F3904987A5E0785F90A6F" [HKLM] . (.SD Card Formatter.) -- C:\WINDOWS\Installer\{10C16E01-F739-4093-89A7-E570589FA0F6}\ARPPRODUCTICON.exe =>.Legitimate O90 - PUC: "14C87B7A4956B8346B70DD710174C2F7" [HKLM] . (.Corel Graphics Suite 11.) -- C:\WINDOWS\Installer\{A7B78C41-6594-438B-B607-DD1710472C7F}\ARPPRODUCTICON.exe =>.Corel Corporation O90 - PUC: "1D034B0FAA6BD374B960AAD30DF10D8B" [HKLM] . (.Microsoft SQL Server 2005 Compact Edition [ENU].) -- C:\WINDOWS\Installer\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}\ProductIcon =>.Microsoft Corporation O90 - PUC: "3ADDCA0F3CD10C34486E349E723C2E7F" [HKLM] . (.ImageScanTool V2.0.2.) -- C:\WINDOWS\Installer\{F0ACDDA3-1DC3-43C0-84E6-43E927C3E2F7}\ARPPRODUCTICON.exe O90 - PUC: "4B2346D1D42EE5044ABA7D6E0D88BC9C" [HKLM] . (.Windows Live Photo Common.) =>.CyberLink Corporation O90 - PUC: "68AB67CA7DA76301B744CAF070E41400" [HKLM] . (.Adobe Acrobat Reader DC - Français.) -- C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}\SC_Reader.ico =>.Adobe Inc. O90 - PUC: "7BD4C90EC03660F46A13E87A329932FA" [HKLM] . (.D3DX10.) =>.Microsoft Corporation O90 - PUC: "80316C14DFC645D4BAA61763DE801AE8" [HKLM] . (.Windows Live Communications Platform.) =>.Legitimate O90 - PUC: "8CDD41E806AE81E43B3E917301D4B5AD" [HKLM] . (.MSVCRT110.) =>.Advanced Micro Devices Inc O90 - PUC: "96530F83636A3FC4DBED30C2C8523140" [HKLM] . (.Movie Maker.) =>.CyberLink Corporation O90 - PUC: "9F5F2256B11431547AB5EC0A30590F23" [HKLM] . (.Windows Live UX Platform Language Pack.) =>.Legitimate O90 - PUC: "A089CE062ADB6BC44A720BA745894BAC" [HKLM] . (.Google Update Helper.) =>.Google Inc. O90 - PUC: "A6C64DD86500CEF47BA082BB611A1FF1" [HKLM] . (.MSVCRT.) =>.Advanced Micro Devices Inc O90 - PUC: "A75F0AACC8AB8DA4AA303FB2E0F46532" [HKLM] . (.Photo Common.) =>.CyberLink Corporation O90 - PUC: "A8F1162B7EFE88E478D5910FFEEA784E" [HKLM] . (.Windows Live PIMT Platform.) =>.Legitimate O90 - PUC: "B4EB76DD26E75124FA3A1F328A003A98" [HKLM] . (.Movie Maker.) =>.CyberLink Corporation O90 - PUC: "C025571B2A687A53689168CD7369889B" [HKLM] . (.Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030.) =>.Microsoft Corporation O90 - PUC: "C040820900063D11C8EF00054038389C" [HKLM] . (.Microsoft Office XP Professional avec FrontPage.) -- C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\misc.exe,6 =>.Microsoft Corporation O90 - PUC: "C18BC956E45B1FD46B813F757793A345" [HKLM] . (.Windows Live Installer.) =>.Microsoft Corporation O90 - PUC: "C1E8B99ED2626E94A9482DCA84B66284" [HKLM] . (.ZOOM Edit&Share for Windows.) -- C:\WINDOWS\Installer\{E99B8E1C-262D-49E6-9A84-D2AC486B2648}\ARPPRODUCTICON.exe O90 - PUC: "C7C9AD31BFBE0D04491A554B8238FD12" [HKLM] . (.32 Bit HP CIO Components Installer.) =>.Hewlett-Packard O90 - PUC: "C8BD9F007D5674D4BAF56F89EE8385D0" [HKLM] . (.Windows Live UX Platform.) =>.Legitimate O90 - PUC: "D725CD2A97AF9E6479F3298079AC559E" [HKLM] . (.Windows Live Writer.) =>.Microsoft Corporation O90 - PUC: "D9185B6607EDEB244BF079F8AB2154E2" [HKLM] . (.Windows Live Essentials.) =>.Microsoft Corporation O90 - PUC: "DC8A59DBF9D1DA5389A1E3975220E6BB" [HKLM] . (.Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030.) =>.Microsoft Corporation O90 - PUC: "E0F72DAB56155A94EB66FAB57FF3F2EE" [HKLM] . (.Windows Live Mail.) =>.Microsoft Corporation O90 - PUC: "E66BAA708174D2242981A4BFC329A217" [HKLM] . (.Photo Gallery.) =>.CyberLink Corporation O90 - PUC: "EE489DABE09731544A82B32E4D62CD7A" [HKLM] . (.Windows Live Messenger.) =>.Microsoft Corporation ---\\ PACKAGES WINDOWS INSTALLER (46) - 49s [MD5.1504667BA3C10D841C0B76B6412FAFB5] [WIS][2015/03/17 10:41:29] (.Adobe Systems Incorporated.) -- C:\WINDOWS\Installer\11388f.msi [2805760] =>.Adobe Systems Incorporated [MD5.50EA7A4D9481B12A97070942F474D918] [WIS][2018/05/17 08:02:13] (.Google Inc. - Google Update Helper.) -- C:\WINDOWS\Installer\17b7dbc6.msi [40960] =>.Google Inc. [MD5.9191F3F96350E60419ED4959753B9776] [WIS][2018/04/22 16:01:01] (.35mm Film Scanner - ImageScanTool V2.0.2.) -- C:\WINDOWS\Installer\17f2bcc3.msi [1452544] [MD5.6296FC2C28AD26C88C00EEB4D81E2421] [WIS][2005/03/01 13:17:56] (.Corel Corporation - Corel Graphics Suite 11.) -- C:\WINDOWS\Installer\19057ea.msi [7264256] =>.Corel Corporation [MD5.964D65F544B7F505D04C0B245172AEDE] [WIS][2018/05/12 09:09:54] (.SD Association - SD Card Formatter.) -- C:\WINDOWS\Installer\20441c63.msi [4166144] =>.SD Association [MD5.5ED28C20AB6633098B5687B93D1B2B5D] [WIS][2017/12/12 05:24:08] (.OpenOffice - OpenOffice 4.1.5.) -- C:\WINDOWS\Installer\2c6a44.msi [2314240] =>.OpenOffice [MD5.72BF0B7142646F1CD0FA7C872DB106D6] [WIS][2018/02/25 10:26:54] (.Google Inc. - Google Update Helper.) -- C:\WINDOWS\Installer\3abdf61.msi [26112] =>.Google Inc. [MD5.1504667BA3C10D841C0B76B6412FAFB5] [WIS][2015/03/17 10:41:29] (.Adobe Systems Incorporated.) -- C:\WINDOWS\Installer\3abdfe9.msi [2805760] =>.Adobe Systems Incorporated [MD5.F0EE2E7F283866A2A0FEA9BE2D12A979] [WIS][2018/02/25 10:36:50] (.Google Inc. - Google Update Helper.) -- C:\WINDOWS\Installer\3b8d09c.msi [40960] =>.Google Inc. [MD5.1F727D1F27A78BA35C14A5F3244D602F] [WIS][2011/04/25 20:17:49] (.Hewlett-Packard - 32 Bit HP CIO Components Installer Package.) -- C:\WINDOWS\Installer\3c1978f.msi [351232] =>.Hewlett-Packard [MD5.C4F6A053F1F0D59FA745582AD8EF04DD] [WIS][2011/04/30 00:46:01] (.Hewlett-Packard - Hewlett-Packard.) -- C:\WINDOWS\Installer\3c19795.msi [820736] =>.Hewlett-Packard [MD5.9C45894B3746C6ADD6FAAC2A10982302] [WIS][2012/09/15 09:21:34] (. - .) -- C:\WINDOWS\Installer\3c1979b.msi [910848] [MD5.7A5E2C241E135927BC2BE5ACA4F0F967] [WIS][2012/05/28 04:42:03] (. - .) -- C:\WINDOWS\Installer\3c197a1.msi [374272] [MD5.CCA680016D44D283B4831137F98B135B] [WIS][2008/10/17 19:29:32] (. - .) -- C:\WINDOWS\Installer\3c197a7.msi [519680] [MD5.6FAD5BA687EAD0D8CFD2279131B4D454] [WIS][2011/04/30 01:04:13] (. - .) -- C:\WINDOWS\Installer\3c197ad.msi [396288] [MD5.189A755EF7032F277AB8C3FC875E3A00] [WIS][2011/05/13 02:04:42] (. - .) -- C:\WINDOWS\Installer\3c197b3.msi [2642944] [MD5.A8164E730902C734656F9174B87EBCE9] [WIS][2012/08/31 12:32:56] (. - .) -- C:\WINDOWS\Installer\3c197b9.msi [475136] [MD5.4077DCF468E8C32336A5F336FDE880A4] [WIS][2009/11/18 10:46:23] (. - .) -- C:\WINDOWS\Installer\3c197bf.msi [618496] [MD5.AEDECB28DB336B91C5C0AE51F0791FA6] [WIS][2011/05/13 01:40:42] (. - .) -- C:\WINDOWS\Installer\3c197c9.msi [502272] [MD5.1A570F658FC8CE354337604D03802D79] [WIS][2011/04/29 23:24:50] (. - .) -- C:\WINDOWS\Installer\3c197cf.msi [585728] [MD5.C133F19570415BEC44B8403A15BD4E9A] [WIS][2011/04/29 21:01:06] (.Builds the Destinations MSI - Builds the Destinations MSI.) -- C:\WINDOWS\Installer\3c197d5.msi [523776] =>.Builds the Destinations MSI [MD5.EE12A71E4984E3FF597100189AB08898] [WIS][2011/04/30 04:08:51] (. - .) -- C:\WINDOWS\Installer\3c197dc.msi [699904] [MD5.090BC981A8B34A8C5372739673CE654A] [WIS][2011/04/29 20:35:14] (. - .) -- C:\WINDOWS\Installer\3c197e2.msi [678912] [MD5.4E0D0B78CAACEE696FFCBEA7064D33B6] [WIS][2011/04/29 18:05:11] (. - .) -- C:\WINDOWS\Installer\3c197ef.msi [613888] [MD5.DBC3E9FEC5B6EC34BA4EC555EC22B4E0] [WIS][2011/04/29 22:44:02] (. - .) -- C:\WINDOWS\Installer\3c197f5.msi [491008] [MD5.93E1339E697FD5B9D72945CCD0910660] [WIS][2011/04/29 21:31:13] (. - .) -- C:\WINDOWS\Installer\3c197fe.msi [829440] [MD5.3F0108ED639664C6E06A5A46B0692A28] [WIS][2011/04/30 03:50:19] (. - .) -- C:\WINDOWS\Installer\3c19804.msi [465920] [MD5.AFCAD6EDAA31F82E1DB585C7FA0F7A04] [WIS][2011/04/30 02:10:25] (. - .) -- C:\WINDOWS\Installer\3c1980a.msi [761344] [MD5.BDE0D76EF26B78395DB2A35F77A98995] [WIS][2014/08/14 18:53:54] (.Hewlett-Packard - HP Update.) -- C:\WINDOWS\Installer\3c1981d.msi [966656] =>.Hewlett-Packard [MD5.47B0AA320574385709E33C05BA0F95AB] [WIS][2018/04/24 20:13:28] (.ZOOM Corporation - ZOOM Edit&Share.) -- C:\WINDOWS\Installer\559e1e9.msi [67707392] =>.ZOOM Corporation [MD5.AC56D724E0D390F14B1E8EBA4FCFBDC3] [WIS][2018/03/03 12:13:27] (.Corel Corporation - Setup.) -- C:\WINDOWS\Installer\573ab2.msi [4430308] =>.Corel Corporation [MD5.1669BC2FCCB29878E053650D8F116047] [WIS][2018/03/03 12:19:43] (.Corel Corporation - VSPro.) -- C:\WINDOWS\Installer\573ab5.msi [258085888] =>.Corel Corporation [MD5.00491B2B1A2B8487B343F254C27A44D2] [WIS][2018/03/03 12:14:39] (.Corel Corporation - Share.) -- C:\WINDOWS\Installer\573ab8.msi [61321728] =>.Corel Corporation [MD5.2EA4DF36C12957F59FAC6B34AA53B53C] [WIS][2018/03/03 12:13:22] (.Corel Corporation - IPM_VS_Pro.) -- C:\WINDOWS\Installer\573abb.msi [18604032] =>.Corel Corporation [MD5.FEE0FFAE6E54F46C09FFD99B4347D80A] [WIS][2018/03/02 16:28:26] (.Corel Corporation - Contents.) -- C:\WINDOWS\Installer\573abf.msi [688118784] =>.Corel Corporation [MD5.6CAD9986FD4E0C681655F71E8025C856] [WIS][2018/03/03 12:21:50] (.Corel Corporation - VSPro.) -- C:\WINDOWS\Installer\573acd.msi [106856808] =>.Corel Corporation [MD5.84FF7F4507FE8E6E9F0C34283DF7CD3E] [WIS][2018/03/02 15:39:15] (.Corel Corporation - ICA.) -- C:\WINDOWS\Installer\573ad0.msi [3932160] =>.Corel Corporation [MD5.11EC9544C8352690C7E1B064F8619649] [WIS][2018/03/02 16:29:16] (.Corel Corporation - Corel Update Helper v2 x86.) -- C:\WINDOWS\Installer\573ad3.msi [12300288] =>.Corel Corporation [MD5.7F9BBDB60B98B6AB6A09446AFADA65CB] [WIS][2018/02/28 13:54:39] (.Adobe Systems Incorporated - Adobe ARM Installer.) -- C:\WINDOWS\Installer\5ada768.msi [884736] =>.Adobe Systems Incorporated [MD5.EEE80A51E432E9B65B50AA2602793C58] [WIS][2018/03/04 15:51:52] (.HP Inc. - 32 Bit HP CIO Components Installer Package.) -- C:\WINDOWS\Installer\c666c7.msi [417792] =>.HP Inc. [MD5.6296FC2C28AD26C88C00EEB4D81E2421] [WIS][2005/03/01 14:17:56] (.Corel Corporation - Corel Graphics Suite 11.) -- C:\WINDOWS\Installer\fc135b.msi [7264256] =>.Corel Corporation [MD5.D40212D89A47E51A1C01FA71536DF45E] [WIS][2018/02/02 22:50:44] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\113890.msp [103342080] =>.Adobe Systems, Incorporated [MD5.E05CA6506E1D5ECE25152018D3FF00CE] [WIS][2018/05/12 08:05:37] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\139256c7.msp [7094272] =>.Adobe Systems, Incorporated [MD5.D40212D89A47E51A1C01FA71536DF45E] [WIS][2018/02/02 22:50:44] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\3abdfea.msp [103342080] =>.Adobe Systems, Incorporated [MD5.04B537B3AB3D8FD3121C2F07CB853532] [WIS][2018/02/23 15:25:32] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\3c198ea.msp [103350272] =>.Adobe Systems, Incorporated [MD5.04B537B3AB3D8FD3121C2F07CB853532] [WIS][2018/02/23 15:25:32] (.Adobe Systems, Incorporated.) -- C:\WINDOWS\Installer\4299ab0.msp [103350272] =>.Adobe Systems, Incorporated ---\\ FEATURE CONTROLE. (153) - 1s [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_AJAX_CONNECTIONEVENTS]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:infopath.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:UNPUXHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:MyHeritage.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:MWizard.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:vstudio.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPfewgsrv.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGUI.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGuiIT.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLgPad.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLOGON.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:Scale_for_R3.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NAVIGATION_SOUNDS]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:ieuser.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK]:YahooMusicEngine.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:devenv.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:dexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:helppane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS]:msfeedssync.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG]:msiexec.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:cs.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:waol.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:wm.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IVIEWOBJECTDRAW_DMLT9_WITH_GDI]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS]:helppane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS]:wlmail.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:outlook.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:sidebar.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_NINPUT_LEGACYMODE]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING]:communicator.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msimn.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:winmail.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SPELLCHECKING]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_STATUS_BAR_THROTTLING]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:msimn.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:outlook.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:winmail.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:excel.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:infopath.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:powerpnt.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:winword.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD]:msn.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBSOCKET]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XDOMAINREQUEST]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XMLHTTP]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:mshta.exe =>.Legitimate ---\\ SCAN ADDITIONNEL (15) - 7s C:\Program Files\KMSpico =>HackTool.KMSpico C:\WINDOWS\Prefetch\REIMAGE.EXE-4681D307.pf =>.SUP.ReimageRepair C:\WINDOWS\Prefetch\REIMAGEPACKAGE.EXE-7368C646.pf =>.SUP.ReimageRepair C:\WINDOWS\Prefetch\REIMAGEREPAIR.EXE-C047F994.pf =>.SUP.ReimageRepair C:\WINDOWS\Prefetch\YTDOWNLOADER.EXE-A331A5FF.pf =>Adware.YTDownloader C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\File System\000 =>.SUP.Temporary.Chrome C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\File System\001 =>.SUP.Temporary.Chrome C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\File System\002 =>.SUP.Temporary.Chrome C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\File System\003 =>.SUP.Temporary.Chrome C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\File System\004 =>.SUP.Temporary.Chrome C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\File System\005 =>.SUP.Temporary.Chrome C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\File System\006 =>.SUP.Temporary.Chrome C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\File System\007 =>.SUP.Temporary.Chrome C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\File System\008 =>.SUP.Temporary.Chrome C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\File System\009 =>.SUP.Temporary.Chrome ---\\ RÉCAPITULATIF DES ÉLÉMENTS TROUVÉS SUR VOTRE STATION (4) - 0s https://nicolascoolman.eu/2017/02/16/hacktool-kmspico/ =>HackTool.KMSpico https://nicolascoolman.eu/2017/01/27/superfluous-reimagerepair/ =>.SUP.ReimageRepair https://nicolascoolman.eu/2017/09/12/adware-ytdownloader/ =>Adware.YTDownloader https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Temporary.Chrome ~ Unselected Options: O82, ~ End of the scan, 10312 items in 03mn51s (1283)(0)