~ ZHPDiag v2021.2.13.278 Par Nicolas Coolman (2021/02/13) ~ Démarré par karuna (Administrator) (2021/02/14 15:01:54) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Certificate ZHPDiag: Legal ~ Etat de la version: Version OK ~ Mode: Scanner ~ Rapport: C:\Users\Admin\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\Admin\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ Démarrage du système: Normal (Normal boot) Windows 10 Pro, 32-bit (Build 18362) =>.Microsoft Corporation ---\\ NAVIGATEURS INTERNET (3) - 0s ~ GCIE: Google Chrome v88.0.4324.150 ~ MSIE: Internet Explorer v11.175.18362.0 ~ OBIE: Microsoft Edge v88.0.705.68 ---\\ INFORMATIONS SUR LES PRODUITS WINDOWS (3) - 3s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK ---\\ LOGICIELS DE PROTECTION (2) - 11s Malwarebytes version 3.3.1.2183 v3.3.1.2183 (Protection) Windows Defender W10 (Activate) (Protection) ---\\ LOGICIELS D'OPTIMISATION (1) - 11s ~ CCleaner v5.76 (Optimisation) ---\\ INFORMATIONS SUR LE SYSTÈME (6) - 0s ~ Operating System: x86 Family 6 Model 142 Stepping 9, GenuineIntel ~ Operating System: 32-bit ~ Boot mode: Normal (Normal boot) Total RAM: 2289.572 MB (13% free) : OK =>.RAM Value System Restore: Activé (Enable) System drive C: has 431 GB (90%) free of 476 GB : OK =>.Disk Space ---\\ MODE DE CONNEXION AU SYSTÈME (3) - 0s ~ Computer Name: KARUNA007 ~ User Name: karuna ~ Logged in as Administrator ---\\ ÉNUMÉRATION DES UNITÉS DE STOCKAGE (1) - 0s ~ Drive C: has 431 GB free of 476 GB (System) ---\\ ÉTAT DU CENTRE DE SÉCURITÉ WINDOWS (7) - 0s [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK ---\\ RECHERCHE PARTICULIÈRE DE FICHIERS GÉNÉRIQUES (25) - 8s [MD5.33B132BE164983BA14F732253E786DFE] - 11/06/2019 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [3915752] =>.Microsoft Windows® [MD5.D0432468FA4B7F66166C430E1334DBDA] - 19/03/2019 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [61952] [Unsigned] =>.Microsoft Corporation [MD5.892A73A1CB162CEA5DDABE9042D8ED53] - 19/03/2019 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [278896] =>.Microsoft® [MD5.7A34BD9A3AA1AD23517F2BCBA1A696CC] - 11/06/2019 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [4537344] [Unsigned] =>.Microsoft Corporation [MD5.52B91F8DA4956FB791C308ADC45D9280] - 19/03/2019 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [684544] [Unsigned] =>.Microsoft Corporation [MD5.7D18FCFFD1B2E35D5D1B11E6EA742DF6] - 19/03/2019 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [287232] [Unsigned] =>.Microsoft Corporation [MD5.23E73E7D3B304E661DC14F8D7217872C] - 19/03/2019 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [588256] =>.Microsoft Windows® [MD5.3924AAC30B8DD5C566F88427D6053784] - 19/03/2019 - (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [2373120] [Unsigned] =>.Microsoft Corporation [MD5.4BB305AEED92BB280760B127548E1DC2] - 19/03/2019 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [19968] [Unsigned] =>.Microsoft Corporation [MD5.F1B155F0B9067865C08D0553AFACFE09] - 19/03/2019 - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\Windows\System32\drivers\AFD.sys [513336] =>.Microsoft Windows® [MD5.73CA63D7C50A440078609C61DD46569E] - 19/03/2019 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [23056] =>.Microsoft Windows® [MD5.07ABEA108AD82B38B37A08FA2CD048ED] - 19/03/2019 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [74752] [Unsigned] =>.Microsoft Corporation [MD5.C0705BA4CBFA86BE41DA3B37BA1239B3] - 19/03/2019 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [125952] [Unsigned] =>.Microsoft Corporation [MD5.C37ECB5AC2CFECE6B439C57F13E4A3F8] - 19/03/2019 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [114176] [Unsigned] =>.Microsoft Corporation [MD5.2471039AA5EBF56E41886482C4E3EB13] - 19/03/2019 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [91648] [Unsigned] =>.Microsoft Corporation [MD5.19E04AC22DA35C44050878077D497CB9] - 19/03/2019 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [99328] [Unsigned] =>.Microsoft Corporation [MD5.163B48681978DC53BAF0518DA1C63188] - 19/03/2019 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [187392] [Unsigned] =>.Microsoft Corporation [MD5.3E4BD8BFC7CA733A63B2394BB8724911] - 19/03/2019 - (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\Windows\System32\drivers\MRxSmb.sys [462648] =>.Microsoft Windows® [MD5.8C06E89C711952AB8DA4F64E76CF0F78] - 11/06/2019 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [247808] [Unsigned] =>.Microsoft Corporation [MD5.D33068E4FD00AE207CA16F632114631D] - 11/06/2019 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [2204472] =>.Microsoft Windows® [MD5.DD3C8E703762361BE2BB7DD002B82B3D] - 19/03/2019 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [82944] [Unsigned] =>.Microsoft Corporation [MD5.6A5EFB03BCBFD104E0613E954E14AA8F] - 19/03/2019 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [79872] [Unsigned] =>.Microsoft Corporation [MD5.B4851372629221D4038B96FABC5D6030] - 19/03/2019 - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\Windows\System32\drivers\rdpdr.sys [131072] [Unsigned] =>.Microsoft Corporation [MD5.A95F668D4DB65A080BFC574D5954D550] - 19/03/2019 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [95544] =>.Microsoft Windows® [MD5.CB2361370D7105144F1F4B5F185A4AA0] - 19/03/2019 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [356152] =>.Microsoft Windows® ---\\ LISTE DES SERVICES (Non désactivés) (64) - 7s O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\System32\DriverStore\FileRepository\ct334123.inf_x86_f8c501d7d775b475\B333740\atiesrxx.exe =>.Advanced Micro Devices, Inc.® O23 - Service: C:\Windows\System32\AudioEndpointBuilder.dll (AudioEndpointBuilder) . (.Microsoft Corporation - Générateur de points de terminaison du serv.) - C:\Windows\System32\AudioEndpointBuilder.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\audiosrv.dll (Audiosrv) . (.Microsoft Corporation - Service Audio Windows.) - C:\Windows\System32\audiosrv.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\BFE.DLL (BFE) . (.Microsoft Corporation - Moteur de filtrage de base.) - C:\Windows\System32\BFE.DLL [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\bisrv.dll (BrokerInfrastructure) . (.Microsoft Corporation - Process State Manager (PSM) Service.) - C:\Windows\System32\psmsrv.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\cdpusersvc.dll (CDPUserSvc) . (.Microsoft Corporation - Composants utilisateur Microsoft (R) CDP.) - C:\Windows\System32\CDPUserSvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: Service pour utilisateur de plateforme d’appareils connecté (CDPUserSvc_4e5b6b) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher® O23 - Service: Service Microsoft Office « Démarrer en un clic » (ClickToRunSvc) . (.Microsoft Corporation - Microsoft Office Click-to-Run (SxS).) - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe =>.Microsoft® O23 - Service: C:\Windows\System32\coremessaging.dll (CoreMessagingRegistrar) . (.Microsoft Corporation - Microsoft CoreMessaging Dll.) - C:\Windows\System32\coremessaging.dll =>.Microsoft Windows® O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) . (.Intel Corporation - IntelCpHDCPSvc Executable.) - C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_x86_772bc7bcc8c1c0c4\IntelCpHDCPSvc.exe =>.Intel(R) pGFX® O23 - Service: C:\Windows\System32\cryptsvc.dll (CryptSvc) . (.Microsoft Corporation - Services de chiffrement.) - C:\Windows\System32\cryptsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\dhcpcore.dll (Dhcp) . (.Microsoft Corporation - Service client DHCP.) - C:\Windows\System32\dhcpcore.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\diagtrack.dll (DiagTrack) . (.Microsoft Corporation - Suivi des diagnostics Microsoft Windows.) - C:\Windows\System32\diagtrack.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\dispbroker.desktop.dll (DispBrokerDesktopSvc) . (.Microsoft Corporation - Courtier d'affichage du bureau.) - C:\Windows\System32\DispBroker.Desktop.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\dnsapi.dll (Dnscache) . (.Microsoft Corporation - Service de résolution du cache DNS.) - C:\Windows\System32\dnsrslvr.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\dosvc.dll (DoSvc) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher® O23 - Service: C:\Windows\System32\dusmsvc.dll (DusmSvc) . (.Microsoft Corporation - Service Consommation des données.) - C:\Windows\System32\dusmsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: Service Mise à jour de Microsoft Edge (edgeupdate) (edgeupdate) . (.Microsoft Corporation - Microsoft Edge Update.) - C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe =>.Microsoft® O23 - Service: ESIF Upper Framework Service (esifsvc) . (.Intel Corporation - Intel(R) Dynamic Platform and Thermal Frame.) - C:\Windows\System32\Intel\DPTF\esif_uf.exe =>.Intel Corporation® O23 - Service: C:\Windows\System32\wevtsvc.dll (EventLog) . (.Microsoft Corporation - Service journal des événements.) - C:\Windows\System32\wevtsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: @comres.dll,-2450 (EventSystem) . (.Microsoft Corporation - COM+.) - C:\Windows\System32\es.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\FntCache.dll (FontCache) . (.Microsoft Corporation - Service de cache de police Windows.) - C:\Windows\System32\FntCache.dll [Unsigned] =>.Microsoft Corporation O23 - Service: @gpapi.dll,-112 (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) - C:\Windows\System32\gpsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google LLC - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google LLC® O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_x86_772bc7bcc8c1c0c4\igfxCUIService.exe =>.Intel(R) pGFX® O23 - Service: C:\Windows\System32\iphlpsvc.dll (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) - C:\Windows\System32\iphlpsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\srvsvc.dll (LanmanServer) . (.Microsoft Corporation - DLL du service Serveur.) - C:\Windows\System32\srvsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wkssvc.dll (LanmanWorkstation) . (.Microsoft Corporation - DLL du service Station de travail.) - C:\Windows\System32\wkssvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\lsm.dll (LSM) . (.Microsoft Corporation - Service du gestionnaire de session locale.) - C:\Windows\System32\lsm.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\moshost.dll (MapsBroker) . (.Microsoft Corporation - Gestionnaire des cartes téléchargées.) - C:\Windows\System32\moshost.dll [Unsigned] =>.Microsoft Corporation O23 - Service: Mobile Broadband HL Service (Mobile Broadband HL Service) . (.Huawei Technologies Co.,Ltd. - .) - C:\Program Files\MobileBrServ\mbbservice.exe =>.Huawei Technologies Co.,Ltd.® O23 - Service: C:\Windows\System32\FirewallAPI.dll (mpssvc) . (.Microsoft Corporation - Service de protection Microsoft.) - C:\Windows\System32\MPSSVC.dll [Unsigned] =>.Microsoft Corporation O23 - Service: NitroPDFDriverCreatorReadSpool11 (NitroDriverReadSpool11) . (.Nitro Software, Inc. - Nitro PDF Spool Service.) - C:\Program Files\Nitro\Pro 11\NitroPDFDriverService11.exe =>.Nitro Software, Inc.® O23 - Service: C:\Windows\System32\nlasvc.dll (NlaSvc) . (.Microsoft Corporation - Connaissance des emplacements réseau 2.) - C:\Windows\System32\nlasvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: Nalpeiron Licensing Service (nlsX86cc) . (.Nalpeiron Ltd. - This service enables products that use the.) - C:\Windows\System32\NLSSRV32.EXE =>.Nitro Software, Inc.® O23 - Service: C:\Windows\System32\nsisvc.dll (nsi) . (.Microsoft Corporation - Serveur RPC de l’interface du magasin résea.) - C:\Windows\System32\nsisvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\APHostRes.dll (OneSyncSvc) . (.Microsoft Corporation - Accounts Host Service.) - C:\Windows\System32\APHostService.dll [Unsigned] =>.Microsoft Corporation O23 - Service: Hôte de synchronisation_4e5b6b (OneSyncSvc_4e5b6b) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher® O23 - Service: C:\Windows\System32\umpo.dll (Power) . (.Microsoft Corporation - Service d’alimentation en mode utilisateur.) - C:\Windows\System32\umpo.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\profsvc.dll (ProfSvc) . (.Microsoft Corporation - ProfSvc.) - C:\Windows\System32\profsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\rasmans.dll (RasMan) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) - C:\Windows\System32\rasmans.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\RpcEpMap.dll (RpcEptMapper) . (.Microsoft Corporation - Mappeur de point de terminaison RPC.) - C:\Windows\System32\RpcEpMap.dll [Unsigned] =>.Microsoft Corporation O23 - Service: @combase.dll,-5010 (RpcSs) . (.Microsoft Corporation - Distributed COM Services.) - C:\Windows\System32\rpcss.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\schedsvc.dll (Schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) - C:\Windows\System32\schedsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\Sens.dll (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) - C:\Windows\System32\Sens.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\shsvcs.dll (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) - C:\Windows\System32\shsvcs.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\spoolsv.exe,-1 (Spooler) . (.Microsoft Corporation - Application sous-système spouleur.) - C:\Windows\System32\spoolsv.exe [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\sppsvc.exe,-101 (sppsvc) . (.Microsoft Corporation - Service de la plateforme de protection logi.) - C:\Windows\System32\sppsvc.exe =>.Microsoft Windows® O23 - Service: C:\Windows\System32\wiaservc.dll (StiSvc) . (.Microsoft Corporation - Service de périphériques d’images fixes.) - C:\Windows\System32\wiaservc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\sysmain.dll (SysMain) . (.Microsoft Corporation - Hôte de Service SysMain.) - C:\Windows\System32\sysmain.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\SystemEventsBrokerServer.dll (SystemEventsBroker) . (.Microsoft Corporation - Service Broker pour les événements système.) - C:\Windows\System32\SystemEventsBrokerServer.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\themeservice.dll (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) - C:\Windows\System32\themeservice.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\usermgr.dll (UserManager) . (.Microsoft Corporation - UserMgr.) - C:\Windows\System32\usermgr.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\usosvc.dll (UsoSvc) . (.Microsoft Corporation - Mettre à jour la session du service Orchest.) - C:\Windows\System32\usosvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wcmsvc.dll (Wcmsvc) . (.Microsoft Corporation - DLL du service de gestion des connexions Wi.) - C:\Windows\System32\wcmsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) . (.Microsoft Corporation - Antimalware Service Executable.) - C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2001.7-0\MsMpEng.exe =>.Microsoft® O23 - Service: Windows Defender Helper Service (WinDefender) . (...) - C:\Windows\windefender.exe [Unsigned] O23 - Service: C:\Windows\System32\wbem\WMIsvc.dll (winmgmt) . (.Microsoft Corporation - WMI.) - C:\Windows\System32\wbem\WMIsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wlansvc.dll (Wlansvc) . (.Microsoft Corporation - DLL du service de configuration automatique.) - C:\Windows\System32\wlansvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wpnservice.dll (WpnService) . (.Microsoft Corporation - Service du système de notifications Push Wi.) - C:\Windows\System32\WpnService.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\WpnUserService.dll (WpnUserService) . (.Microsoft Corporation - Service utilisateur de notifications Push W.) - C:\Windows\System32\WpnUserService.dll [Unsigned] =>.Microsoft Corporation O23 - Service: Service utilisateur de notifications Push Windows_4e5b6b (WpnUserService_4e5b6b) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher® O23 - Service: C:\Windows\System32\wscsvc.dll (wscsvc) . (.Microsoft Corporation - Service Centre de sécurité de Windows.) - C:\Windows\System32\wscsvc.dll =>.Microsoft Windows Publisher® O23 - Service: C:\Windows\System32\SearchIndexer.exe,-103 (WSearch) . (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - C:\Windows\System32\SearchIndexer.exe [Unsigned] =>.Microsoft Corporation ---\\ SERVICES NON MICROSOFT (SR=Démarré,SS=Stoppé) (65) - 21s SR - Boot [19/03/2019] [ 85816] (3ware) . (.LSI.) - C:\Windows\System32\drivers\3ware.sys =>.Microsoft Windows® SR - System [26/09/2019] [ 29632] 9a3c1ac4a8bba090 service (9a3c1ac4a8bba090) . (.FsFilter Network.) - C:\Windows\System32\drivers\9a3c1ac4a8bba090.sys =>Trojan.Agent =>Trojan.Agent SR - Boot [19/03/2019] [ 1038352] (ADP80XX) . (.PMC-Sierra.) - C:\Windows\System32\drivers\adp80xx.sys =>.Microsoft Windows® SR - Auto [04/10/2018] [ 408552] (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\DriverStore\FileRepository\ct334123.inf_x86_f8c501d7d775b475\B333740\atiesrxx.exe =>.Advanced Micro Devices, Inc.® SR - Demand [04/10/2018] [42515432] (amdkmdag) . (.Advanced Micro Devices, Inc..) - C:\Windows\System32\DriverStore\FileRepository\ct334123.inf_x86_f8c501d7d775b475\B333740\atikmdag.sys =>.Advanced Micro Devices, Inc.® SR - Demand [04/10/2018] [ 457192] (amdkmdap) . (.Advanced Micro Devices, Inc..) - C:\Windows\System32\DriverStore\FileRepository\ct334123.inf_x86_f8c501d7d775b475\B333740\atikmpag.sys =>.Advanced Micro Devices, Inc.® SR - Boot [19/03/2019] [ 75280] (amdsata) . (.Advanced Micro Devices.) - C:\Windows\System32\drivers\amdsata.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 215560] (amdsbs) . (.AMD Technologies Inc..) - C:\Windows\System32\drivers\amdsbs.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 23080] (amdxata) . (.Advanced Micro Devices.) - C:\Windows\System32\drivers\amdxata.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 116752] Adaptec SAS/SATA-II RAID S (arcsas) . (.PMC-Sierra, Inc..) - C:\Windows\System32\drivers\arcsas.sys =>.Microsoft Windows® SR - Demand [19/03/2019] [ 3228672] Qualcomm Atheros Extensi (athr) . (.Qualcomm Atheros Communications, Inc..) - C:\Windows\System32\drivers\athw8.sys [Unsigned] =>.Qualcomm Atheros Communications, Inc. SR - Demand [19/03/2019] [ 8192] bcmfn2 Service (bcmfn2) . (...) - C:\Windows\System32\drivers\bcmfn2.sys [Unsigned] =>.Broadcom Corporation SS - Demand [27/08/2016] [ 284112] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_x86_772bc7bcc8c1c0c4\IntelCpHeciSvc.exe =>.Intel(R) pGFX® SR - Auto [27/08/2016] [ 359888] Intel(R) Content Protection HDCP Service (cplspcon) . (.Intel Corporation.) - C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_x86_772bc7bcc8c1c0c4\IntelCpHDCPSvc.exe =>.Intel(R) pGFX® SR - Demand [02/08/2017] [ 59272] (dptf_cpu) . (.Intel Corporation.) - C:\Windows\System32\drivers\dptf_cpu.sys =>.Intel Corporation® SR - Auto [02/08/2017] [ 1856048] ESIF Upper Framework Service (esifsvc) . (.Intel Corporation.) - C:\Windows\System32\Intel\DPTF\esif_uf.exe =>.Intel Corporation® SR - Demand [02/08/2017] [ 286088] (esif_lf) . (.Intel Corporation.) - C:\Windows\System32\drivers\esif_lf.sys =>.Intel Corporation® SS - Demand [04/02/2021] [ 1156720] Google Chrome Elevation Service (GoogleChromeElevationServi (GoogleChromeElevationService) . (.Google LLC.) - C:\Program Files\Google\Chrome\Application\88.0.4324.150\elevation_service.exe =>.Google LLC® SR - Demand [19/03/2019] [ 22016] Intel SoC GPIO Controller Driv (GPIO) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaiogpio.sys [Unsigned] =>.Intel Corporation SR - Auto [27/12/2020] [ 155592] Service Google Update (gupdate) (gupdate) . (.Google LLC.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google LLC® SS - Demand [27/12/2020] [ 155592] Service Google Update (gupdatem) (gupdatem) . (.Google LLC.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google LLC® SR - Boot [19/03/2019] [ 56848] (HpSAMD) . (.Hewlett-Packard Company.) - C:\Windows\System32\drivers\HpSAMD.sys =>.Microsoft Windows® SR - Demand [19/03/2019] [ 28672] Intel Serial IO GPIO Controlle (iagpio) . (.Intel(R) Corporation.) - C:\Windows\System32\drivers\iagpio.sys [Unsigned] =>.Intel(R) Corporation SR - Demand [19/03/2019] [ 73728] Intel(R) Serial IO I2C Host Cont (iai2c) . (.Intel(R) Corporation.) - C:\Windows\System32\drivers\iai2c.sys [Unsigned] =>.Intel(R) Corporation SR - Demand [19/03/2019] [ 57856] Intel(R) Atom(TM) Proces (iaioi2c) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaioi2c.sys [Unsigned] =>.Intel Corporation SR - Boot [19/03/2019] [ 693048] Intel Chipset SATA RAI (iaStorAVC) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaStorAVC.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 333624] Intel RAID Controller Wi (iaStorV) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaStorV.sys =>.Microsoft Windows® SR - Demand [27/08/2016] [ 9666512] (igfx) . (.Intel Corporation.) - C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_x86_772bc7bcc8c1c0c4\igdkmd32.sys =>.Intel(R) pGFX® SR - Auto [27/08/2016] [ 261072] Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) . (.Intel Corporation.) - C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_x86_772bc7bcc8c1c0c4\igfxCUIService.exe =>.Intel(R) pGFX® SR - Demand [07/12/2015] [ 46584] Intel WiDi Audio Device (intaud_WaveExtensible) . (.Intel Corporation.) - C:\Windows\System32\drivers\intelaud.sys =>.Intel(R) Wireless Display® SR - Demand [01/04/2016] [ 659432] Son Intel(R) pour écrans (IntcDAud) . (.Intel(R) Corporation.) - C:\Windows\System32\drivers\IntcDAud.sys =>.Intel(R) OWR® SR - Boot [19/03/2019] [ 121144] (ItSas35i) . (.Avago Technologies.) - C:\Windows\System32\drivers\ItSas35i.sys =>.Microsoft Windows® SR - Demand [07/12/2015] [ 37880] IWD Bus Enumerator (iwdbus) . (.Intel Corporation.) - C:\Windows\System32\drivers\iwdbus.sys =>.Intel(R) Wireless Display® SR - System [00/00/0000] [ 0] (jzqtejrj) . (...) - C:\Windows\system32\drivers\jzqtejrj.sys (.not file.) [Unsigned] SR - Demand [19/03/2019] [ 102912] NDIS Miniport Drive (L1C) . (.Qualcomm Atheros Co., Ltd..) - C:\Windows\System32\drivers\L1C63x86.sys [Unsigned] =>.Qualcomm Atheros Co., Ltd. SR - Boot [19/03/2019] [ 94008] (LSI_SAS) . (.LSI Corporation.) - C:\Windows\System32\drivers\lsi_sas.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 103224] (LSI_SAS2i) . (.LSI Corporation.) - C:\Windows\System32\drivers\lsi_sas2i.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 106296] (LSI_SAS3i) . (.Avago Technologies.) - C:\Windows\System32\drivers\lsi_sas3i.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 69432] (LSI_SSS) . (.LSI Corporation.) - C:\Windows\System32\drivers\lsi_sss.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 52024] (megasas) . (.Avago Technologies.) - C:\Windows\System32\drivers\megasas.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 64312] (megasas2i) . (.Avago Technologies.) - C:\Windows\System32\drivers\MegaSas2i.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 79160] (megasas35i) . (.Avago Technologies.) - C:\Windows\System32\drivers\megasas35i.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 464696] (megasr) . (.LSI Corporation, Inc..) - C:\Windows\System32\drivers\megasr.sys =>.Microsoft Windows® SR - Demand [03/08/2018] [ 192560] Intel(R) Management Engine Interfac (MEI) . (.Intel Corporation.) - C:\Windows\System32\drivers\TeeDriverW8.sys =>.Intel(R) Embedded Subsystems and IP Blocks Group® SR - Auto [24/03/2016] [ 242264] Mobile Broadband HL Service (Mobile Broadband HL Service) . (.Huawei Technologies Co.,Ltd..) - C:\Program Files\MobileBrServ\mbbservice.exe =>.Huawei Technologies Co.,Ltd.® SR - Boot [19/03/2019] [ 58376] (mvumis) . (.Marvell Semiconductor, Inc..) - C:\Windows\System32\drivers\mvumis.sys =>.Microsoft Windows® SR - Auto [08/09/2016] [ 281280] NitroPDFDriverCreatorReadSpool11 (NitroDriverReadSpool11) . (.Nitro Software, Inc..) - C:\Program Files\Nitro\Pro 11\NitroPDFDriverService11.exe =>.Nitro Software, Inc.® SS - Demand [08/09/2016] [ 405696] NitroUpdateService (NitroUpdateService) . (.Nitro Software, Inc..) - C:\Program Files\Nitro\Pro 11\Nitro_UpdateService.exe =>.Nitro Software, Inc.® SR - Auto [08/09/2016] [ 71872] Nalpeiron Licensing Service (nlsX86cc) . (.Nalpeiron Ltd..) - C:\Windows\System32\NLSSRV32.EXE =>.Nitro Software, Inc.® SR - Boot [19/03/2019] [ 119312] (nvraid) . (.NVIDIA Corporation.) - C:\Windows\System32\drivers\nvraid.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 142352] (nvstor) . (.NVIDIA Corporation.) - C:\Windows\System32\drivers\nvstor.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 51512] (percsas2i) . (.Avago Technologies.) - C:\Windows\System32\drivers\percsas2i.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 59192] (percsas3i) . (.Avago Technologies.) - C:\Windows\System32\drivers\percsas3i.sys =>.Microsoft Windows® SR - Demand [19/03/2019] [ 554496] Realtek RT640 NT Dri (rt640x86) . (.Realtek.) - C:\Windows\System32\drivers\rt640x86.sys [Unsigned] =>.Realtek SR - Demand [19/03/2019] [ 6755840] Realtek Wir (RTWlanE01) . (.Realtek Semiconductor Corporation.) - C:\Windows\System32\drivers\rtwlane01.sys [Unsigned] =>.Realtek Semiconductor Corporation SR - Boot [19/03/2019] [ 41488] (SiSRaid2) . (.Silicon Integrated Systems Corp..) - C:\Windows\System32\drivers\sisraid2.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 79368] (SiSRaid4) . (.Silicon Integrated Systems.) - C:\Windows\System32\drivers\sisraid4.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 27152] (stexstor) . (.Promise Technology, Inc..) - C:\Windows\System32\drivers\stexstor.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 150056] (vsmraid) . (.VIA Technologies Inc.,Ltd.) - C:\Windows\System32\drivers\vsmraid.sys =>.Microsoft Windows® SR - Boot [19/03/2019] [ 277008] VIA StorX Storage RAID Co (VSTXRAID) . (.VIA Corporation.) - C:\Windows\System32\drivers\VSTXRAID.SYS =>.Microsoft Windows® SR - Auto [00/00/0000] [ 0] Windows Defender Helper Service (WinDefender) . (...) - C:\Windows\windefender.exe [Unsigned] SR - Demand [00/00/0000] [ 0] Winmon (Winmon) . (...) - C:\Windows\System32\drivers\Winmon.sys [Unsigned] SR - Demand [00/00/0000] [ 0] WinmonFS (WinmonFS) . (...) - C:\Windows\System32\drivers\WinmonFS.sys [Unsigned] SR - System [26/09/2019] [ 28368] WinmonProcessMonitor (WinmonProcessMonitor) . (...) - C:\Windows\System32\drivers\WinmonProcessMonitor.sys [Unsigned] SR - Demand [11/05/2018] [ 30848] HP Wireless Button Driver Service (WirelessButtonDriver86) . (.HP.) - C:\Windows\System32\drivers\WirelessButtonDriver86.sys =>.HP Inc.® ---\\ TÂCHES PLANIFIÉES EN AUTOMATIQUE (Registre) (28) - 27s O38 - TASK: {04A30B0F-D508-484E-A85E-13DC045ADF22}[\AdvancedWindowsManager] - (...) -- C:\Program Files\AdvancedWindowsManager\Windows Installer\AdvancedWindowsManager.exe [7915656] =>SUP.Optional.Microleaves O38 - TASK: {16422B8C-41E7-41FA-8E1C-5B4423AC8B60}[\Online Application V2G5] - (.WORKGROUP\DESKTOP-JUT5U8P$ - Application.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [199864] =>SUP.Optional.Microleaves O38 - TASK: {2683A8EF-4C80-45D9-B89E-D93DB6B22109}[\Updater_Online_Application] - (.Microleaves - Online Application Updater 2.7.0 © Microle.) -- C:\Program Files\Microleaves\Online Application\Online Application Updater.exe [908144] =>SUP.Optional.Microleaves O38 - TASK: {3A6E199C-76C0-44E9-9849-89E22E326F54}[\AdvancedUpdater] - (.AdvancedWindowsManager - Windows Updater 4.98.0.) -- C:\Program Files\AdvancedWindowsManager\Windows Installer\Windows Updater.exe [895112] =>SUP.Optional.Microleaves O38 - TASK: {505A37CE-2914-4C4A-ACA9-4508495406EC}[\Online Application V2G1] - (.WORKGROUP\DESKTOP-JUT5U8P$ - Application.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [199864] =>SUP.Optional.Microleaves O38 - TASK: {917B663F-BA82-4E5B-943A-8E474592BB8D}[\Online Application V2G4] - (.WORKGROUP\DESKTOP-JUT5U8P$ - Application.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [199864] =>SUP.Optional.Microleaves O38 - TASK: {91D7D478-9D78-4BA1-BF79-4F55E78BED30}[\CCleaner Update] - (.Piriform Software Ltd - CCleaner emergency updater.) -- C:\Program Files\CCleaner\CCUpdate.exe [686384] =>.Piriform Software Ltd O38 - TASK: {96AC2760-A0ED-4BB2-9513-BB00FC94CCBD}[\GoogleUpdateTaskMachineCore] - (.Google LLC - Programme d'installation de Google.) -- C:\Program Files\Google\Update\GoogleUpdate.exe [155592] =>.Google LLC O38 - TASK: {AA060A0B-6F7E-4F03-9435-EE2DD15AFD94}[\GoogleUpdateTaskMachineUA] - (.Google LLC - Programme d'installation de Google.) -- C:\Program Files\Google\Update\GoogleUpdate.exe [155592] =>.Google LLC O38 - TASK: {B96901BA-FC06-4C31-AD2F-626ECA5690AC}[\Online Application V2G6] - (.WORKGROUP\DESKTOP-JUT5U8P$ - Application.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [199864] =>SUP.Optional.Microleaves O38 - TASK: {C38CF05C-C269-4936-908D-80FD5DA7FF5F}[\Online Application V2G3] - (.WORKGROUP\DESKTOP-JUT5U8P$ - Application.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [199864] =>SUP.Optional.Microleaves O38 - TASK: {C9234B9F-09CA-41E3-B65F-E0EF1141C763}[\Online Application V2G2] - (.WORKGROUP\DESKTOP-JUT5U8P$ - Application.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [199864] =>SUP.Optional.Microleaves O38 - TASK: {C9E4FAC6-3C28-4A42-A77D-3017BFA94EA8}[\CCleanerSkipUAC] - (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe [26913848] =>.Piriform Software Ltd O38 - TASK: {E20A2567-69D8-4145-97AC-D8C9D3036DE2}[\csrss] - (.KARUNA007\karuna - .) -- C:\Windows\rss\csrss.exe [3998720] =>Trojan.Dropper C:\Windows\System32\Tasks\AdvancedWindowsManager - (...) -- C:\Program Files\AdvancedWindowsManager\Windows Installer\AdvancedWindowsManager.exe [] =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\Online Application V2G5 - (.WORKGROUP\DESKTOP-JUT5U8P$.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [1 61.1] =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\Updater_Online_Application - (.Microleaves.) -- C:\Program Files\Microleaves\Online Application\Online Application Updater.exe [/silentall -nofreqcheck./silentall] =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\AdvancedUpdater - (.AdvancedWindowsManager.) -- C:\Program Files\AdvancedWindowsManager\Windows Installer\Windows Updater.exe [/silentall -nofreqcheck./silentall] =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\Online Application V2G1 - (.WORKGROUP\DESKTOP-JUT5U8P$.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [1 69.1] =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\Online Application V2G4 - (.WORKGROUP\DESKTOP-JUT5U8P$.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [1 60.1] =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\CCleaner Update - (.Piriform Software Ltd.) -- C:\Program Files\CCleaner\CCUpdate.exe [] =>.Piriform Software Ltd C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore - (.Google LLC.) -- C:\Program Files\Google\Update\GoogleUpdate.exe [/c] =>.Google LLC C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA - (.Google LLC.) -- C:\Program Files\Google\Update\GoogleUpdate.exe [/ua ./ua] =>.Google LLC C:\Windows\System32\Tasks\Online Application V2G6 - (.WORKGROUP\DESKTOP-JUT5U8P$.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [1 62.1] =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\Online Application V2G3 - (.WORKGROUP\DESKTOP-JUT5U8P$.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [1 71.1] =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\Online Application V2G2 - (.WORKGROUP\DESKTOP-JUT5U8P$.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [1 70.1] =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\CCleanerSkipUAC - (.Piriform Software Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [$(Arg0)] =>.Piriform Software Ltd C:\Windows\System32\Tasks\csrss - (.KARUNA007\karuna.) -- C:\Windows\rss\csrss.exe [] =>Trojan.Dropper ---\\ APPLICATIONS LANCÉES AU DÉMARRAGE DU SYSTÈME (20) - 7s O4 - HKLM\..\Run: [SecurityHealth] . (.Microsoft Corporation - Windows Security notification icon.) -- C:\Windows\System32\SecurityHealthSystray.exe [Unsigned] =>.Microsoft Corporation O4 - HKLM\..\Run: [ShutdownTime] . (. - ShutdownTime.) -- C:\Program Files\ShutdownTime\ShutdownTime.exe [Unsigned] O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft® O4 - HKCU\..\Run: [HiddenTree] . (...) -- C:\Windows\rss\csrss.exe [Unsigned] =>Trojan.Dropper O4 - HKCU\..\Run: [2761879] . (. - .) -- C:\Users\Admin\AppData\Local\Temp\is-GDLG0.tmp\Jboulette.exe (.Not File.) =>.SUP.Orphan O4 - HKCU\..\Run: [CloudNet] . (...) -- C:\Users\Admin\AppData\Roaming\87dd3c26406f\87dd3c26406f.exe [Unsigned] =>Adware.MSIL O4 - HKCU\..\Run: [AutumnPond] . (...) -- C:\Windows\rss\csrss.exe [Unsigned] =>Trojan.Dropper O4 - HKCU\..\Run: [E09FXLRD_155961937] . (.Microsoft Corporation - Microsoft Encarta Dictionaries.) -- C:\Program Files\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\EDICT.EXE =>.Microsoft Corporation® O4 - HKCU\..\Run: [CCleaner Smart Cleaning] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Software Ltd® O4 - HKCU\..\RunOnce: [Application Restart #1] . (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google LLC® O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\System32\OneDriveSetup.exe =>.Microsoft Corporation® O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\System32\OneDriveSetup.exe =>.Microsoft Corporation® O4 - HKUS\S-1-5-21-1174500970-2113145075-2524796768-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft® O4 - HKUS\S-1-5-21-1174500970-2113145075-2524796768-1001\..\Run: [HiddenTree] . (...) -- C:\Windows\rss\csrss.exe [Unsigned] =>Trojan.Dropper O4 - HKUS\S-1-5-21-1174500970-2113145075-2524796768-1001\..\Run: [2761879] . (. - .) -- C:\Users\Admin\AppData\Local\Temp\is-GDLG0.tmp\Jboulette.exe (.Not File.) =>.SUP.Orphan O4 - HKUS\S-1-5-21-1174500970-2113145075-2524796768-1001\..\Run: [CloudNet] . (...) -- C:\Users\Admin\AppData\Roaming\87dd3c26406f\87dd3c26406f.exe [Unsigned] =>Adware.MSIL O4 - HKUS\S-1-5-21-1174500970-2113145075-2524796768-1001\..\Run: [AutumnPond] . (...) -- C:\Windows\rss\csrss.exe [Unsigned] =>Trojan.Dropper O4 - HKUS\S-1-5-21-1174500970-2113145075-2524796768-1001\..\Run: [E09FXLRD_155961937] . (.Microsoft Corporation - Microsoft Encarta Dictionaries.) -- C:\Program Files\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\EDICT.EXE =>.Microsoft Corporation® O4 - HKUS\S-1-5-21-1174500970-2113145075-2524796768-1001\..\Run: [CCleaner Smart Cleaning] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Software Ltd® O4 - HKUS\S-1-5-21-1174500970-2113145075-2524796768-1001\..\RunOnce: [Application Restart #1] . (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google LLC® ---\\ PROCESSUS LANCÉS (34) - 20s [MD5.65878A41D5F25F4FF478A46E25E7A173] - (.AMD - AMD External Events Service Module.) -- C:\Windows\System32\DriverStore\FileRepository\ct334123.inf_x86_f8c501d7d775b475\B333740\atiesrxx.exe [408552] [PID.1808] =>.Advanced Micro Devices, Inc.® [MD5.2FF2B77D1FD8566E901708B6B00983B7] - (.Intel Corporation - igfxCUIService Module.) -- C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_x86_772bc7bcc8c1c0c4\igfxCUIService.exe [261072] [PID.592] =>.Intel(R) pGFX® [MD5.85A0AB7596492813A5F54873FAE35887] - (.Intel Corporation - IntelCpHDCPSvc Executable.) -- C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_x86_772bc7bcc8c1c0c4\IntelCpHDCPSvc.exe [359888] [PID.2672] =>.Intel(R) pGFX® [MD5.C39890462F95BD1AAB5B7A40BB192612] - (.Intel Corporation - Intel(R) Dynamic Platform and Thermal Frame.) -- C:\Windows\System32\Intel\DPTF\esif_uf.exe [1856048] [PID.2700] =>.Intel Corporation® [MD5.6306EA46EA071CC08FAD7D9DDAABFE8A] - (...) -- C:\Program Files\MobileBrServ\mbbservice.exe [242264] [PID.2748] =>.Huawei Technologies Co.,Ltd.® [MD5.AB17C0C9A1D2C374C0CDA3C2FD4796C3] - (.Nalpeiron Ltd. - This service enables products that use the.) -- C:\Windows\System32\NLSSRV32.EXE [71872] [PID.2780] =>.Nitro Software, Inc.® [MD5.20E9186D1E985027A2445AA7C00EE011] - (.Nitro Software, Inc. - Nitro PDF Spool Service.) -- C:\Program Files\Nitro\Pro 11\NitroPDFDriverService11.exe [281280] [PID.2788] =>.Nitro Software, Inc.® [MD5.3446688DDA102D365D85C9FBF30D4EE1] - (.Intel Corporation - IntelCpHeciSvc Executable.) -- C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_x86_772bc7bcc8c1c0c4\IntelCpHeciSvc.exe [284112] [PID.3184] =>.Intel(R) pGFX® [MD5.E8DE6E81B27B60A15B07D63B51F88D2B] - (.Google LLC - Google Crash Handler.) -- C:\Program Files\Google\Update\1.3.36.72\GoogleCrashHandler.exe [292680] [PID.2684] =>.Google LLC® [MD5.46B217B22CA5D4FB530352B18D163D0A] - (. - Application.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [199864] [PID.3784] =>SUP.Optional.Microleaves [MD5.46B217B22CA5D4FB530352B18D163D0A] - (. - Application.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [199864] [PID.3540] =>SUP.Optional.Microleaves [MD5.46B217B22CA5D4FB530352B18D163D0A] - (. - Application.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [199864] [PID.1576] =>SUP.Optional.Microleaves [MD5.46B217B22CA5D4FB530352B18D163D0A] - (. - Application.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [199864] [PID.1592] =>SUP.Optional.Microleaves [MD5.BBD8A3AA491F7AB2160E2506FBF9D482] - (.AMD - AMD External Events Client Module.) -- C:\Windows\System32\DriverStore\FileRepository\ct334123.inf_x86_f8c501d7d775b475\B333740\atieclxx.exe [608232] [PID.8172] =>.Advanced Micro Devices, Inc.® [MD5.C80A089BB96C59C6FF6634011BCF2BFA] - (.Intel Corporation - Intel(R) Dynamic Platform and Thermal Frame.) -- C:\Windows\Temp\DPTF\esif_assist.exe [419880] [PID.3576] =>.Intel Corporation® [MD5.4E7CF58298BE95FB1AC2B41182AAFDA7] - (...) -- C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe [487224] [PID.5592] =>.Microsoft Windows® [MD5.B876D2457EFD1D3A8881D5EF27E2354B] - (...) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.35.152.0_x86__kzf8qxf38zg5c\SkypeBackgroundHost.exe [157184] [PID.8576] [Unsigned] =>.Microsoft Corporation [MD5.2C08B4B8082990CE39B4DAA124ED119E] - (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe [26913848] [PID.9944] =>.Piriform Software Ltd® [MD5.89437D48EA0E9B83A0A7E636EE46179B] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2057320] [PID.4888] =>.Google LLC® [MD5.89437D48EA0E9B83A0A7E636EE46179B] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2057320] [PID.3572] =>.Google LLC® [MD5.89437D48EA0E9B83A0A7E636EE46179B] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2057320] [PID.9456] =>.Google LLC® [MD5.89437D48EA0E9B83A0A7E636EE46179B] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2057320] [PID.9492] =>.Google LLC® [MD5.89437D48EA0E9B83A0A7E636EE46179B] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2057320] [PID.9664] =>.Google LLC® [MD5.57A73708323934022D3B2B0B77534928] - (...) -- C:\Program Files\AdvancedWindowsManager\Windows Installer\AdvancedWindowsManager.exe [7915656] [PID.8996] =>SUP.Optional.Microleaves [MD5.89437D48EA0E9B83A0A7E636EE46179B] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2057320] [PID.12036] =>.Google LLC® [MD5.46B217B22CA5D4FB530352B18D163D0A] - (. - Application.) -- C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [199864] [PID.8552] =>SUP.Optional.Microleaves [MD5.792B6BE7316B964E7AC58EC248957EB3] - (...) -- C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18114.19418.0_x86__8wekyb3d8bbwe\Microsoft.Photos.exe [478720] [PID.11552] [Unsigned] =>.Microsoft Corporation [MD5.89437D48EA0E9B83A0A7E636EE46179B] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2057320] [PID.7364] =>.Google LLC® [MD5.89437D48EA0E9B83A0A7E636EE46179B] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2057320] [PID.11424] =>.Google LLC® [MD5.89437D48EA0E9B83A0A7E636EE46179B] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2057320] [PID.3772] =>.Google LLC® [MD5.89437D48EA0E9B83A0A7E636EE46179B] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2057320] [PID.6720] =>.Google LLC® [MD5.89437D48EA0E9B83A0A7E636EE46179B] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2057320] [PID.5916] =>.Google LLC® [MD5.89437D48EA0E9B83A0A7E636EE46179B] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2057320] [PID.5640] =>.Google LLC® [MD5.1CD2274D0A3EE56E6D0B20239B78DC0C] - (.Nicolas Coolman - ZHPSuite.) -- C:\Users\Admin\Desktop\ZHPSuite.exe [3481224] [PID.6464] [Unsigned] =>.Nicolas Coolman ---\\ CHROME, Démarrage, Recherche, Extensions (11) - 2s G2 - GCE: Preference [karuna][User Data\Default\Extensions] [aapocclcgogkmnckokdopfmhonfmgoek] =>.Google Inc. {Slides} G2 - GCE: Preference [karuna][User Data\Default\Extensions] [aohghmighlieiainnegkcijnfilokake] =>.Google Inc. {Docs} G2 - GCE: Preference [karuna][User Data\Default\Extensions] [apdfllckaahabafndbhieahigkjlhalf] http://drive.google.com/ =>.Google Inc. {Drive} G2 - GCE: Preference [karuna][User Data\Default\Extensions] [blpcfgokakmgnkcojhhkbfbldkacnbeo] http://www.youtube.com =>.Youtube {Youtube} G2 - GCE: Preference [karuna][User Data\Default\Extensions] [felcaaldnbdncclmgdcncolpebgiejap] =>.Google Inc. {Sheets} G2 - GCE: Preference [karuna][User Data\Default\Extensions] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] =>.Google Inc. {Docs hors connexion} G2 - GCE: Preference [karuna][User Data\Default\Extensions] [nmmhkkegccagdldgiimedpiccmgmieda] =>.Google Inc. {Wallet} G2 - GCE: Preference [karuna][User Data\Default\Extensions] [pjkljhegncpnkpknbcohdijeoejaedia] http://mail.google.com/ =>.Google Inc. {Gmail} G2 - GCE: Preference [karuna][User Data\Default\Extensions] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc. G2 - GCE: Preference [karuna][User Data\Default\Local Extension Settings] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] =>.Google Inc. {Docs hors connexion} G2 - GCE: Preference [karuna][User Data\Default\Sync Extension Settings] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] =>.Google Inc. {Chrome Media Router} ---\\ FIREFOX, Plugins,Démarrage,Recherche,Extensions (14) - 2s C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\btw0t5l1.default\bookmarkbackups =>Mozilla Corporation C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\btw0t5l1.default\crashes =>Mozilla Corporation C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\btw0t5l1.default\datareporting =>Mozilla Corporation C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\btw0t5l1.default\extensions =>Mozilla Corporation C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\btw0t5l1.default\gmp =>Mozilla Corporation C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\btw0t5l1.default\gmp-gmpopenh264 =>Mozilla Corporation C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\btw0t5l1.default\gmp-widevinecdm =>Mozilla Corporation C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\btw0t5l1.default\minidumps =>Mozilla Corporation C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\btw0t5l1.default\saved-telemetry-pings =>Mozilla Corporation C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\btw0t5l1.default\security_state =>Mozilla Corporation C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\btw0t5l1.default\sessionstore-backups =>Mozilla Corporation C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\btw0t5l1.default\shader-cache =>Mozilla Corporation C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\btw0t5l1.default\storage =>Mozilla Corporation C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\btw0t5l1.default\weave =>Mozilla Corporation ---\\ INTERNET EXPLORER,Démarrage,Recherche,URLSearchHook (12) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/? =>SUP.Optional.Linkury R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%68%65%6c%70%65%72%62%61%72.%63%6f%6d/? =>SUP.Optional.Linkury R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%68%65%6c%70%65%72%62%61%72.%63%6f%6d/? =>SUP.Optional.Linkury R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%68%65%6c%70%65%72%62%61%72.%63%6f%6d/? =>SUP.Optional.Linkury R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://%66%65%65%64.%68%65%6c%70%65%72%62%61%72.%63%6f%6d/? =>SUP.Optional.Linkury R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.18362.1 (WinBuild.160101.0800)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation ---\\ INTERNET EXPLORER, Site de confiance et site sensible (1) - 0s ~ Microsoft Internet Explorer Restricted Site(s) Domains: 0(Good) / 0(Bad) ---\\ MICROSOFT EDGE, Plugin,Favoris,Démarrage,Recherche,Extension (1) - 1s E2 - GCE: Preference [karuna][User Data\Default\Local Extension Settings] [jdiccldimpdaibmpdkjnbmckianbfold] =>.Microsoft Corporation ---\\ INTERNET EXPLORER,Proxy Management (3) - 0s R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 =>.Default.Value R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft ---\\ INTERNET EXPLORER,IniFiles, Autoloading Programs (3) - 0s F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=C:\Windows\system32\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation ---\\ ÉTUDE DU FICHIER HOSTS (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (21) ---\\ BROWSER HELPER OBJECT DE NAVIGATEUR (BHO) (2) - 1s O2 - BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} . (.Microsoft Corporation - IEToEdge BHO.) -- C:\Program Files\Microsoft\Edge\Application\88.0.705.68\BHO\ie_to_edge_bho.dll =>.Microsoft® O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} . (.Microsoft Corporation - Skype for Business.) -- C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll =>.Microsoft® ---\\ RACCOURCIS GLOBAL STARTUP (70) - 25s O4 - GS\Desktop [karuna]: 6 Service et Prestation.jpg - Raccourci.lnk . (...) C:\Users\Admin\Downloads\6 Service et Prestation.jpg [Unsigned] O4 - GS\Desktop [karuna]: 7 Engagement et Concept.jpg - Raccourci.lnk . (...) C:\Users\Admin\Downloads\7 Engagement et Concept.jpg [Unsigned] O4 - GS\Desktop [karuna]: Access.lnk . (.Microsoft Corporation - Microsoft Access.) C:\Program Files\Microsoft Office\root\Office16\MSACCESS.EXE =>.Microsoft® O4 - GS\Desktop [karuna]: Carte de présentation photos.jpeg - Raccourci.lnk . (...) C:\Users\Admin\Downloads\Carte de présentation photos.jpeg [Unsigned] O4 - GS\Desktop [karuna]: Carte de visite.jpeg - Raccourci.lnk . (...) C:\Users\Admin\Downloads\Carte de visite.jpeg [Unsigned] O4 - GS\Desktop [karuna]: Carte présentation CI.jpeg - Raccourci.lnk . (...) C:\Users\Admin\Downloads\Carte présentation CI.jpeg [Unsigned] O4 - GS\Desktop [karuna]: Cuisine Revue - Février-Avril 2021@PresseFr.pdf - Raccourci (2).lnk . (...) C:\Users\Admin\Downloads\Cuisine Revue - Février-Avril 2021@PresseFr.pdf [Unsigned] O4 - GS\Desktop [karuna]: Excel.lnk . (.Microsoft Corporation - Microsoft Excel.) C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE =>.Microsoft® O4 - GS\Desktop [karuna]: Gourmand - 12 Janvier 2021@PresseFr.pdf - Raccourci.lnk . (...) C:\Users\Admin\Downloads\Gourmand - 12 Janvier 2021@PresseFr.pdf [Unsigned] O4 - GS\Desktop [karuna]: Maintenance.jpeg - Raccourci.lnk . (...) C:\Users\Admin\Downloads\Maintenance.jpeg [Unsigned] O4 - GS\Desktop [karuna]: Outlook.lnk . (.Microsoft Corporation - Microsoft Outlook.) C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE =>.Microsoft® O4 - GS\Desktop [karuna]: Partenaires CI-Industriel.jpg - Raccourci.lnk . (...) C:\Users\Admin\Downloads\Partenaires CI-Industriel.jpg [Unsigned] O4 - GS\Desktop [karuna]: Pensez à l'entretien.jpeg - Raccourci.lnk . (...) C:\Users\Admin\Downloads\Pensez à l'entretien.jpeg [Unsigned] O4 - GS\Desktop [karuna]: PowerPoint.lnk . (.Microsoft Corporation - Microsoft PowerPoint.) C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXE =>.Microsoft® O4 - GS\Desktop [karuna]: Project.lnk . (.Microsoft Corporation - Microsoft Project.) C:\Program Files\Microsoft Office\root\Office16\WINPROJ.EXE =>.Microsoft® O4 - GS\Desktop [karuna]: Présentation CI-Industriel.jpg - Raccourci.lnk . (...) C:\Users\Admin\Downloads\Présentation CI-Industriel.jpg [Unsigned] O4 - GS\Desktop [karuna]: Publisher.lnk . (.Microsoft Corporation - Microsoft Publisher.) C:\Program Files\Microsoft Office\root\Office16\MSPUB.EXE =>.Microsoft® O4 - GS\Desktop [karuna]: Stanley Clarke Discografia 34 Cd's.rar - Raccourci.lnk . (...) C:\Users\Admin\Downloads\Stanley Clarke Discografia 34 Cd's.rar [Unsigned] O4 - GS\Desktop [karuna]: Tourniquets 2.jpeg - Raccourci.lnk . (...) C:\Users\Admin\Downloads\Tourniquets 2.jpeg [Unsigned] O4 - GS\Desktop [karuna]: Tourniquets.jpeg - Raccourci.lnk . (...) C:\Users\Admin\Downloads\Tourniquets.jpeg [Unsigned] O4 - GS\Desktop [karuna]: Visio.lnk . (.Microsoft Corporation - Microsoft Visio.) C:\Program Files\Microsoft Office\root\Office16\VISIO.EXE =>.Microsoft® O4 - GS\Desktop [karuna]: Word.lnk . (.Microsoft Corporation - Microsoft Word.) C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE =>.Microsoft® O4 - GS\Desktop [karuna]: ZHPSuite.lnk . (.Nicolas Coolman - ZHPSuite.) C:\Users\Admin\AppData\Roaming\ZHP\ZHPSuite.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [karuna]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google LLC® O4 - GS\Quicklaunch [karuna]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files\Microsoft\Edge\Application\msedge.exe =>.Microsoft® O4 - GS\sendTo [karuna]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\sendTo [karuna]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - Transfère les fichiers entre l.) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation O4 - GS\TaskBar [karuna]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google LLC® O4 - GS\TaskBar [karuna]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files\Microsoft\Edge\Application\msedge.exe --profile-directory=Default =>.Microsoft® O4 - GS\TaskBar [karuna]: Nitro Pro.lnk . (.Nitro PDF - Nitro Pro.) C:\Program Files\Nitro\Pro 11\NitroPDF.exe =>.Nitro Software, Inc.® O4 - GS\Startup [karuna]: stream-all.dat.lnk . (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) C:\Windows\system32\wscript.exe /E:vbscript "C:\Users\Admin\AppData\Roaming\stream-all.dat.vbs" =>.Microsoft Corporation O4 - GS\Programs [karuna]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft® O4 - GS\CommonDesktop [Public]: Achat de consommables - HP ColorLaserJet MFP M178-M181.lnk . (.HP Inc. - DesktopSureSupply.) C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\Bin\hpqDTSS.exe =>.HP Inc® O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Software Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Software Ltd® O4 - GS\CommonDesktop [Public]: Dicos Encarta.lnk . (.Microsoft Corporation - Microsoft Encarta Dictionaries.) C:\Program Files\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\EDICT.EXE =>.Microsoft Corporation® O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google LLC® O4 - GS\CommonDesktop [Public]: HP ColorLaserJet MFP M178-M181-HP Scan.lnk . (.HP Inc. - HPScan.) C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\Bin\HPScan.exe =>.HP Inc® O4 - GS\CommonDesktop [Public]: HP ColorLaserJet MFP M178-M181.lnk . (.HP Inc. - HP Printer Assistant.) C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\Bin\HP ColorLaserJet MFP M178-M181.exe -Start UDCDevicePage =>.HP Inc® O4 - GS\CommonDesktop [Public]: Malwarebytes.lnk . (.Malwarebytes - Malwarebytes.) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe =>.Malwarebytes Corporation® O4 - GS\CommonDesktop [Public]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files\Microsoft\Edge\Application\msedge.exe =>.Microsoft® O4 - GS\CommonDesktop [Public]: Microsoft Encarta 2009 - Collection DVD.lnk . (.Microsoft Corporation - Microsoft Encarta.) C:\Program Files\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\ENCARTA.EXE =>.Microsoft Corporation® O4 - GS\CommonDesktop [Public]: Microsoft Encarta Junior 2009.lnk . (.Microsoft Corporation - Microsoft Encarta.) C:\Program Files\Microsoft Encarta\Microsoft Encarta Junior 2009\ENCARTA.EXE =>.Microsoft Corporation® O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft® O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft® O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Math Input Panel Accessory.) C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\Windows\system32\quickassist.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture d’écran.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Enregistreur d’actions.) C:\Windows\system32\psr.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Application Windows Wordpad.) C:\Program Files\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Table des caractères.) C:\Windows\system32\charmap.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Access.lnk . (.Microsoft Corporation - Microsoft Access.) C:\Program Files\Microsoft Office\root\Office16\MSACCESS.EXE =>.Microsoft® O4 - GS\ProgramsCommon [Public]: Excel.lnk . (.Microsoft Corporation - Microsoft Excel.) C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE =>.Microsoft® O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google LLC - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google LLC® O4 - GS\ProgramsCommon [Public]: I.R.I.S OCR Registration.lnk . (...) C:\Program Files\HP\IdrsOCR_15.2.10.1114\IRISRegistrationApp.exe =>.IMAGE RECOGNITION INTEGRATED SYSTEMS SA® O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\Windows\System32\Control.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Microsoft Edge.lnk . (.Microsoft Corporation - Microsoft Edge.) C:\Program Files\Microsoft\Edge\Application\msedge.exe =>.Microsoft® O4 - GS\ProgramsCommon [Public]: Nitro Pro.lnk . (.Nitro PDF - Nitro Pro.) C:\Program Files\Nitro\Pro 11\NitroPDF.exe =>.Nitro Software, Inc.® O4 - GS\ProgramsCommon [Public]: OneNote.lnk . (.Microsoft Corporation - Microsoft OneNote.) C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE =>.Microsoft® O4 - GS\ProgramsCommon [Public]: Outlook.lnk . (.Microsoft Corporation - Microsoft Outlook.) C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE =>.Microsoft® O4 - GS\ProgramsCommon [Public]: PowerPoint.lnk . (.Microsoft Corporation - Microsoft PowerPoint.) C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXE =>.Microsoft® O4 - GS\ProgramsCommon [Public]: Project.lnk . (.Microsoft Corporation - Microsoft Project.) C:\Program Files\Microsoft Office\root\Office16\WINPROJ.EXE =>.Microsoft® O4 - GS\ProgramsCommon [Public]: Publisher.lnk . (.Microsoft Corporation - Microsoft Publisher.) C:\Program Files\Microsoft Office\root\Office16\MSPUB.EXE =>.Microsoft® O4 - GS\ProgramsCommon [Public]: Skype for Business.lnk . (.Microsoft Corporation - Skype for Business.) C:\Program Files\Microsoft Office\root\Office16\lync.exe =>.Microsoft® O4 - GS\ProgramsCommon [Public]: Visio.lnk . (.Microsoft Corporation - Microsoft Visio.) C:\Program Files\Microsoft Office\root\Office16\VISIO.EXE =>.Microsoft® O4 - GS\ProgramsCommon [Public]: Word.lnk . (.Microsoft Corporation - Microsoft Word.) C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE =>.Microsoft® ---\\ MODIFICATION DOMAINE/ADRESSES (DNS) (5) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8 192.168.100.1 =>.Local IP Adress O17 - HKLM\System\CCS\Services\Tcpip\..\{15644826-0670-4877-9541-26de8452e934}: DhcpNameServer = 8.8.8.8 192.168.100.1 =>.Local IP Adress O17 - HKLM\System\CCS\Services\Tcpip\..\{617ba99e-e11b-4302-a177-db38f7fa9f4d}: DhcpNameServer = 192.168.8.1 192.168.8.1 =>.Local IP Adress O17 - HKLM\System\CCS\Services\Tcpip\..\{90ae78cb-733f-4644-a7f7-6405989bb469}: DhcpNameServer = 192.168.8.1 192.168.8.1 =>.Local IP Adress O17 - HKLM\System\CCS\Services\Tcpip\..\{ce6bd561-06c4-4ba8-ad4a-6b583407f634}: DhcpNameServer = 192.168.8.1 192.168.8.1 =>.Local IP Adress ---\\ PROTOCOLE ADDITIONNEL (27) - 3s O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} . (.Microsoft Corporation - Microsoft Office component.) -- C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL =>.Microsoft® O18 - Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} . (.Microsoft Corporation - Microsoft Office component.) -- C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL =>.Microsoft® O18 - Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} . (.Microsoft Corporation - Microsoft Office component.) -- C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL =>.Microsoft® O18 - Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} . (.Microsoft Corporation - Microsoft Office component.) -- C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL =>.Microsoft® O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll [Unsigned] =>.Microsoft Corporation O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation O18 - Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\MSOXMLMF.DLL =>.Microsoft® ---\\ REGISTRE AppInit_DLLs et Winlogon Notify (1) - 0s O20 - Winlogon : UserInit . (.Microsoft Corporation - Application d’ouverture de session Userinit.) - C:\Windows\system32\userinit.exe =>.Microsoft Corporation ---\\ CLÉ DE REGISTRE EXPLORER StartupApproved (26) - 2s [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:OneDrive =>.Microsoft Corporation [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:GYRAOYF82DJ05V0 [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:KZPM18D0WU5DIBN [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:HiddenTree [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:2761879 [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:6909900 [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:9959551 [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:CloudNet =>Adware.MSIL [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:AutumnPond [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:E09FXLRD_155961937 [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder]:stream-all.dat.lnk [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder]:Facebook Gameroom.lnk [HKEY_USERS\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:OneDrive =>.Microsoft Corporation [HKEY_USERS\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:GYRAOYF82DJ05V0 [HKEY_USERS\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:KZPM18D0WU5DIBN [HKEY_USERS\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:HiddenTree [HKEY_USERS\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:2761879 [HKEY_USERS\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:6909900 [HKEY_USERS\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:9959551 [HKEY_USERS\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:CloudNet =>Adware.MSIL [HKEY_USERS\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:AutumnPond [HKEY_USERS\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:E09FXLRD_155961937 [HKEY_USERS\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder]:stream-all.dat.lnk [HKEY_USERS\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder]:Facebook Gameroom.lnk [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:SecurityHealth =>.Microsoft Corporation [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:ShutdownTime ---\\ COMPOSANTS ACTIVESETUP INSTALLÉS (ASIC) (6) - 3s O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll [Unsigned] =>.Microsoft Corporation O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Utilitaire d’installation du Lecteur Window.) -- C:\Windows\System32\unregmp2.exe [Unsigned] =>.Microsoft Corporation O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe [Unsigned] =>.Microsoft Corporation O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft Corporation® O40 - ASIC: Google Chrome - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google LLC - Google Chrome Installer.) -- C:\Program Files\Google\Chrome\Application\88.0.4324.150\Installer\chrmstp.exe =>.Google LLC® O40 - ASIC: Microsoft Edge - {9459C573-B17A-45AE-9F64-1857B5D58CEE} . (.Microsoft Corporation - Microsoft Edge Installer.) -- C:\Program Files\Microsoft\Edge\Application\88.0.705.68\Installer\setup.exe =>.Microsoft® ---\\ LOGICIELS INSTALLÉS (44) - 45s O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner =>.Piriform Software Ltd® O42 - Logiciel: Étude pour l'amélioration du produit HP ColorLaserJet MFP M178-M181 - (.HP Inc..) [HKLM] -- {4F247767-1045-4C1F-97E0-BB1EC951AA33} [Unsigned] =>.HP Inc. O42 - Logiciel: Google Chrome - (.Google LLC.) [HKLM] -- Google Chrome =>.Google LLC® O42 - Logiciel: HP Color LaserJet MFP M178-M181 Aide - (.HP.) [HKLM] -- {BC6B7CFE-E6DB-4965-B675-77F481CDD500} [Unsigned] =>.HP O42 - Logiciel: HP Dropbox Plugin - (.HP.) [HKLM] -- {52A85078-4C57-4CCE-B0BA-BAF9BD8D7280} [Unsigned] =>.HP O42 - Logiciel: HP EmailSMTP Plugin - (.HP.) [HKLM] -- {9A13E849-C7B9-4117-B239-35D192089870} [Unsigned] =>.HP O42 - Logiciel: HP FTP Plugin - (.HP.) [HKLM] -- {637B84EC-424B-4327-B5CD-D0A7AF205A0F} [Unsigned] =>.HP O42 - Logiciel: HP Google Drive Plugin - (.HP.) [HKLM] -- {A0F1CD58-A2CD-4B6B-9541-A05B795A1D0D} [Unsigned] =>.HP O42 - Logiciel: HP OneDrive Plugin - (.HP.) [HKLM] -- {70B4FEAE-DC27-4EAA-8893-CCE4A2743C97} [Unsigned] =>.HP O42 - Logiciel: HP SharePoint Plugin - (.HP.) [HKLM] -- {4D8DFFAA-9064-4C96-A65F-6C0C5AF9DA80} [Unsigned] =>.HP O42 - Logiciel: I.R.I.S OCR - (.HP Inc..) [HKLM] -- {3024AD3F-2F9B-47FA-BF3E-D598D535A793} [Unsigned] =>.HP Inc. O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} [Unsigned] =>.Intel Corporation O42 - Logiciel: Logiciel de base du périphérique HP ColorLaserJet MFP M178-M181 - (.HP Inc..) [HKLM] -- {43295FA9-66E6-424C-BF13-50AE1ADBDA96} [Unsigned] =>.HP Inc. O42 - Logiciel: Malwarebytes version 3.3.1.2183 - (.Malwarebytes.) [HKLM] -- {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1 =>.Malwarebytes Corporation® O42 - Logiciel: Microsoft Edge - (.Microsoft Corporation.) [HKLM] -- Microsoft Edge =>.Microsoft® O42 - Logiciel: Microsoft Edge Update - (.Microsoft Corporation.) [HKLM] -- Microsoft Edge Update [Unsigned] =>.Microsoft Corporation O42 - Logiciel: Microsoft Encarta 2009 - Collection - (.Microsoft Corporation.) [HKLM] -- {09180081-2C94-4A67-8E55-8483C019C7D2} [Unsigned] =>.Microsoft Corporation O42 - Logiciel: Microsoft Office Professionnel Plus 2019 - fr-fr - (.Microsoft Corporation.) [HKLM] -- ProPlus2019Retail - fr-fr =>.Microsoft® O42 - Logiciel: Microsoft OneDrive - (.Microsoft Corporation.) [HKCU] -- OneDriveSetup.exe =>.Microsoft® O42 - Logiciel: Microsoft Project - fr-fr - (.Microsoft Corporation.) [HKLM] -- ProjectPro2019Retail - fr-fr =>.Microsoft® O42 - Logiciel: Microsoft Visio - fr-fr - (.Microsoft Corporation.) [HKLM] -- VisioPro2019Retail - fr-fr =>.Microsoft® O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (.Microsoft Corporation.) [HKLM] -- {9A25302D-30C0-39D9-BD6F-21E6EC160475} [Unsigned] =>.Microsoft Corporation O42 - Logiciel: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 - (.Microsoft Corporation.) [HKLM] -- {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} [Unsigned] =>.Microsoft Corporation O42 - Logiciel: Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 - (.Microsoft Corporation.) [HKLM] -- {33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} =>.Microsoft® O42 - Logiciel: Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 - (.Microsoft Corporation.) [HKLM] -- {B175520C-86A2-35A7-8619-86DC379688B9} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 - (.Microsoft Corporation.) [HKLM] -- {BD95A8CD-1D9F-35AD-981A-3E7925026EBB} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 - (.Microsoft Corporation.) [HKLM] -- {61087a79-ac85-455c-934d-1fa22cc64f36} =>.Microsoft® O42 - Logiciel: Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40660 - (.Microsoft Corporation.) [HKLM] -- {7DAD0258-515C-3DD4-8964-BD714199E0F7} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40660 - (.Microsoft Corporation.) [HKLM] -- {E30D8B21-D82D-3211-82CC-0F0A5D1495E8} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 - (.Microsoft Corporation.) [HKLM] -- {7e9fae12-5bbf-47fb-b944-09c49e75c061} =>.Microsoft Corporation® O42 - Logiciel: Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 - (.Microsoft Corporation.) [HKLM] -- {2757496A-3E74-320A-B007-36120A9F126D} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 - (.Microsoft Corporation.) [HKLM] -- {39E15475-23F2-345D-8977-B5DC47A94E26} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Mobile Broadband HL Service - (.Huawei Technologies Co.,Ltd.) [HKLM] -- Mobile Broadband HL Service =>.Huawei Technologies Co.,Ltd.® O42 - Logiciel: Nitro Pro - (.Nitro.) [HKLM] -- {806A20D6-5AC4-4186-BBEF-5165B5D027E2} [Unsigned] =>.Nitro O42 - Logiciel: Office 16 Click-to-Run Extensibility Component - (.Microsoft Corporation.) [HKLM] -- {90160000-008C-0000-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Office 16 Click-to-Run Licensing Component - (.Microsoft Corporation.) [HKLM] -- {90160000-007E-0000-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Office 16 Click-to-Run Localization Component - (.Microsoft Corporation.) [HKLM] -- {90160000-008C-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Online Application - (.Microleaves.) [HKLM] -- {5266F634-7B7D-4537-BDDC-98DD6CFCBAA1} [Unsigned] =>SUP.Optional.Microleaves (Hidden) O42 - Logiciel: pdfreader2009 version 19.25 (32-bit) - (..) [HKLM] -- {C3169F1B-4F1C-4C38-909B-FDA4E1F5EE34}_is1 [Unsigned] O42 - Logiciel: PetGame - (..) [HKCU] -- PetGame [Unsigned] O42 - Logiciel: ShutdownTime version 1.0 - (.MAL.) [HKLM] -- ShutdownTime_is1 [Unsigned] =>Adware.ICLoader O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM] -- VLC media player [Unsigned] =>.VideoLAN O42 - Logiciel: Windows Installer - (.AdvancedWindowsManager.) [HKLM] -- {8DA41662-F681-47F9-B114-9657FC5799EF} [Unsigned] =>SUP.Optional.Microleaves O42 - Logiciel: WinRAR 5.70 beta 1 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver =>.win.rar GmbH® ---\\ CLÉ DE REGISTRE SOFTWARE HKCU & HKLM (92) - 45s HKCU\Software\GCleaner =>.SUP.Various HKLM\SOFTWARE\AdvancedWindowsManager =>SUP.Optional.Microleaves HKLM\SOFTWARE\AMD =>.AMD HKLM\SOFTWARE\ATI =>.ATI HKLM\SOFTWARE\ATI Technologies =>.ATI Technologies HKLM\SOFTWARE\Auslogics =>SUP.Optional.Auslogics HKLM\SOFTWARE\Caphyon =>.Caphyon HKLM\SOFTWARE\CVSM =>.Legitimate HKLM\SOFTWARE\DefaultUserEnvironment =>.Microsoft Corporation HKLM\SOFTWARE\EaseUS =>.EaseUS Software HKLM\SOFTWARE\Google =>.Google HKLM\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard HKLM\SOFTWARE\HP =>.HP HKLM\SOFTWARE\IM Providers =>.IM Providers HKLM\SOFTWARE\Intel =>.Intel HKLM\SOFTWARE\Khronos =>.Khronos HKLM\SOFTWARE\Macromedia =>.Macromedia HKLM\SOFTWARE\Microleaves =>SUP.Optional.Microleaves HKLM\SOFTWARE\Mozilla =>.Mozilla HKLM\SOFTWARE\mozilla.org =>.mozilla.org HKLM\SOFTWARE\MozillaPlugins =>.MozillaPlugins HKLM\SOFTWARE\mtAppxeetouQ HKLM\SOFTWARE\mtQuoteex =>PUP.Optional.Graftor HKLM\SOFTWARE\Nalpeiron =>.Nalpeiron HKLM\SOFTWARE\Nitro =>.Nitro HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions HKLM\SOFTWARE\OEM =>.OEM HKLM\SOFTWARE\Partner =>.Google Inc. HKLM\SOFTWARE\Piriform =>.Piriform HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation HKLM\SOFTWARE\VideoLAN =>.VideoLan Team HKLM\SOFTWARE\Windows =>.Microsoft Corporation HKLM\SOFTWARE\WinRAR =>.WinRAR HKLM\SOFTWARE\Wow6432Node =>.Microsoft Corporation HKLM\SOFTWARE\WOW6432Node\ATI =>.ATI HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation HKCU\SOFTWARE\ATI =>.ATI HKCU\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o HKCU\SOFTWARE\BugSplat =>.Bugsplat Game HKCU\SOFTWARE\Chromium =>.Chromium HKCU\SOFTWARE\CraveSoftware HKCU\SOFTWARE\EpicNet Inc. =>Adware.MSIL HKCU\SOFTWARE\Google =>.Google HKCU\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard HKCU\SOFTWARE\HP =>.HP HKCU\SOFTWARE\IM Providers =>.IM Providers HKCU\SOFTWARE\InstallPack HKCU\SOFTWARE\Mozilla =>.Mozilla HKCU\SOFTWARE\mtAppxeetouQ HKCU\SOFTWARE\Netscape =>.Netscape HKCU\SOFTWARE\Nitro =>.Nitro HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions HKCU\SOFTWARE\Picture HKCU\SOFTWARE\Piriform =>.Piriform HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation HKCU\SOFTWARE\Rtp =>.RTP Software HKCU\SOFTWARE\SetupCompany HKCU\SOFTWARE\W10DigitalLicense HKCU\SOFTWARE\WinRAR =>.WinRAR HKCU\SOFTWARE\WinRAR SFX =>.RarLab HKCU\SOFTWARE\ZHP =>.Nicolas Coolman HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation HKU\.DEFAULT\SOFTWARE\ATI =>.ATI HKU\.DEFAULT\SOFTWARE\Caphyon =>.Caphyon HKU\.DEFAULT\SOFTWARE\Piriform =>.Piriform HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\AppDataLow =>.Microsoft Corporation HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\ATI =>.ATI HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\BugSplat =>.Bugsplat Game HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Chromium =>.Chromium HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\CraveSoftware HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\EpicNet Inc. =>Adware.MSIL HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\GCleaner =>.SUP.Various HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Google =>.Google HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\HP =>.HP HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\IM Providers =>.IM Providers HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\InstallPack HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Mozilla =>.Mozilla HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\mtAppxeetouQ HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Netscape =>.Netscape HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Nitro =>.Nitro HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\ODBC =>.DB Connectivity Solutions HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Picture HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Piriform =>.Piriform HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\RegisteredApplications =>.Microsoft Corporation HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\Rtp =>.RTP Software HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\SetupCompany HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\W10DigitalLicense HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\WinRAR =>.WinRAR HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\WinRAR SFX =>.RarLab HKU\S-1-5-21-1174500970-2113145075-2524796768-1001\SOFTWARE\ZHP =>.Nicolas Coolman ---\\ CONTENU DES DOSSIERS PROGRAMMES (173) - 30s O43 - CFD: 26/09/2019 - [] D -- C:\Program Files\A6NPQWEG5J [Unsigned] =>Adware.Wizzcaster O43 - CFD: 08/02/2020 - [] D -- C:\Program Files\AdvancedWindowsManager =>SUP.Optional.Microleaves O43 - CFD: 25/09/2019 - [] D -- C:\Program Files\AMD =>.Advanced Micro Devices, Inc.® O43 - CFD: 14/02/2021 - [] D -- C:\Program Files\CCleaner =>.Piriform Ltd O43 - CFD: 26/09/2019 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation O43 - CFD: 26/09/2019 - [] D -- C:\Program Files\CRLKA0ZK0D [Unsigned] =>Adware.Wizzcaster O43 - CFD: 27/11/2020 - [] D -- C:\Program Files\EaseUS =>.EaseUS Software O43 - CFD: 25/09/2019 - [0] SHD -- C:\Program Files\Fichiers communs =>.Microsoft Corporation O43 - CFD: 27/12/2020 - [] D -- C:\Program Files\Google =>.Google LLC® O43 - CFD: 03/02/2021 - [] D -- C:\Program Files\HP =>.Hewlett-Packard O43 - CFD: 25/09/2019 - [] D -- C:\Program Files\Intel =>.Intel Corporation O43 - CFD: 11/06/2019 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation O43 - CFD: 27/12/2020 - [] D -- C:\Program Files\Malwarebytes =>.Malwarebytes O43 - CFD: 26/09/2019 - [] D -- C:\Program Files\Microleaves =>SUP.Optional.Microleaves O43 - CFD: 12/12/2020 - [] D -- C:\Program Files\Microsoft =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\Program Files\Microsoft Encarta =>.Microsoft Corporation O43 - CFD: 13/11/2020 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\Program Files\Microsoft Office 15 =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\Program Files\Microsoft.NET =>.Microsoft Corporation O43 - CFD: 26/09/2019 - [] D -- C:\Program Files\Mirror O43 - CFD: 10/09/2020 - [] D -- C:\Program Files\MobileBrServ =>.Huawei Technologies Co.,Ltd O43 - CFD: 19/03/2019 - [0] D -- C:\Program Files\ModifiableWindowsApps =>.Microsoft Corporation O43 - CFD: 28/12/2020 - [0] D -- C:\Program Files\Mozilla Firefox =>.Mozilla O43 - CFD: 11/06/2019 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\Program Files\Nitro =>.Nitro O43 - CFD: 11/06/2019 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation O43 - CFD: 26/09/2019 - [] D -- C:\Program Files\ShutdownTime [Unsigned] =>Adware.Wizzcaster O43 - CFD: 25/09/2019 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation O43 - CFD: 04/06/2020 - [] D -- C:\Program Files\UNP =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\Program Files\VideoLAN =>.VideoLan Team O43 - CFD: 27/09/2019 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Windows Defender Advanced Threat Protection =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Windows Security =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] SHD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\Program Files\WinRAR =>.win.rar GmbH® O43 - CFD: 19/03/2019 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools O43 - CFD: 27/12/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd O43 - CFD: 03/02/2021 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP =>.Hewlett-Packard O43 - CFD: 19/03/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation O43 - CFD: 27/12/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes =>.Malwarebytes O43 - CFD: 25/09/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Encarta =>.Microsoft Corporation O43 - CFD: 08/10/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team O43 - CFD: 25/09/2019 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR O43 - CFD: 26/09/2019 - [] D -- C:\ProgramData\955Q332N6WZZ0UCLAQUKHPXFD O43 - CFD: 26/09/2019 - [] D -- C:\ProgramData\Adobe =>.Adobe O43 - CFD: 12/02/2020 - [] D -- C:\ProgramData\AdvancedWindowsManager =>SUP.Optional.Microleaves O43 - CFD: 25/09/2019 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation O43 - CFD: 31/01/2020 - [] D -- C:\ProgramData\AppxeetouQ =>PUP.Optional.AppToU O43 - CFD: 04/12/2019 - [] D -- C:\ProgramData\AppxeetouQs =>PUP.Optional.AppToU O43 - CFD: 25/09/2019 - [0] SHD -- C:\ProgramData\Bureau =>.Microsoft Corporation O43 - CFD: 19/12/2019 - [] D -- C:\ProgramData\CloudPrinter =>SUP.Optional.Linkury O43 - CFD: 25/09/2019 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation O43 - CFD: 27/11/2020 - [] D -- C:\ProgramData\EaseUS Todo PCTrans =>.EaseUS Software O43 - CFD: 03/02/2021 - [] D -- C:\ProgramData\HP =>.Hewlett-Packard O43 - CFD: 26/02/2020 - [] D -- C:\ProgramData\karuna O43 - CFD: 26/09/2019 - [] D -- C:\ProgramData\Logic Cramble =>PUP.Optional.LogicHandler O43 - CFD: 27/12/2020 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes O43 - CFD: 25/09/2019 - [0] SHD -- C:\ProgramData\Menu Démarrer =>.Microsoft Corporation O43 - CFD: 29/09/2019 - [] D -- C:\ProgramData\Microleaves =>SUP.Optional.Microleaves O43 - CFD: 19/01/2021 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [0] SHD -- C:\ProgramData\Modèles =>.Microsoft Corporation O43 - CFD: 12/12/2020 - [] D -- C:\ProgramData\Mozilla =>.Mozilla Corporation O43 - CFD: 25/09/2019 - [] D -- C:\ProgramData\Nitro =>.Nitro O43 - CFD: 26/09/2019 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\ProgramData\Packages =>.Microsoft Corporation O43 - CFD: 29/11/2019 - [] D -- C:\ProgramData\Quoteex =>PUP.Optional.Graftor O43 - CFD: 26/09/2019 - [] D -- C:\ProgramData\Quoteexs =>PUP.Optional.Graftor O43 - CFD: 14/02/2021 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [0] D -- C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation O43 - CFD: 27/11/2020 - [] D -- C:\ProgramData\SystemAcCrux O43 - CFD: 26/09/2019 - [] D -- C:\ProgramData\USOPrivate =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\ProgramData\USOShared =>.Microsoft Corporation O43 - CFD: 27/09/2019 - [0] SHD -- C:\ProgramData\{14512558-1451-1451-145125586927} O43 - CFD: 26/09/2019 - [] D -- C:\Program Files\Common Files\Adobe =>.Adobe O43 - CFD: 25/09/2019 - [] D -- C:\Program Files\Common Files\DESIGNER =>.Designer O43 - CFD: 25/09/2019 - [] D -- C:\Program Files\Common Files\Intel =>.Intel Corporation O43 - CFD: 03/05/2020 - [] D -- C:\Program Files\Common Files\Microsoft Shared =>.Microsoft Corporation O43 - CFD: 29/11/2019 - [] D -- C:\Program Files\Common Files\NewSanjob O43 - CFD: 25/09/2019 - [] D -- C:\Program Files\Common Files\Nitro =>.Nitro O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Common Files\Services =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] D -- C:\Program Files\Common Files\System =>.Microsoft Corporation O43 - CFD: 08/10/2020 - [] D -- C:\Users\Admin\AppData\Roaming\87dd3c26406f O43 - CFD: 25/09/2019 - [] D -- C:\Users\Admin\AppData\Roaming\Adobe =>.Adobe O43 - CFD: 25/09/2019 - [] D -- C:\Users\Admin\AppData\Roaming\Downloaded Installations =>.Microsoft Corporation O43 - CFD: 26/09/2019 - [] D -- C:\Users\Admin\AppData\Roaming\EpicNet Inc =>Adware.MSIL O43 - CFD: 28/10/2019 - [0] D -- C:\Users\Admin\AppData\Roaming\ftxcdvj5ou2 O43 - CFD: 26/09/2019 - [] D -- C:\Users\Admin\AppData\Roaming\InstallPack O43 - CFD: 26/09/2019 - [] D -- C:\Users\Admin\AppData\Roaming\Microleaves =>SUP.Optional.Microleaves O43 - CFD: 19/01/2021 - [] SD -- C:\Users\Admin\AppData\Roaming\Microsoft =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\Users\Admin\AppData\Roaming\Mozilla =>.Mozilla Corporation O43 - CFD: 03/02/2021 - [] D -- C:\Users\Admin\AppData\Roaming\Nitro =>.Nitro O43 - CFD: 26/09/2019 - [] D -- C:\Users\Admin\AppData\Roaming\ScreenToGif =>.ScreenToGif O43 - CFD: 15/10/2020 - [] D -- C:\Users\Admin\AppData\Roaming\vlc =>.VideoLan Team O43 - CFD: 28/10/2019 - [0] D -- C:\Users\Admin\AppData\Roaming\wbo2rhywr4e O43 - CFD: 23/11/2019 - [] D -- C:\Users\Admin\AppData\Roaming\WinRAR =>.WinRAR O43 - CFD: 03/02/2021 - [] D -- C:\Users\Admin\AppData\Roaming\WinScan2PDF O43 - CFD: 14/02/2021 - [] D -- C:\Users\Admin\AppData\Roaming\ZHP =>.Nicolas Coolman O43 - CFD: 26/09/2019 - [] D -- C:\Users\Admin\AppData\Local\Adobe =>.Adobe O43 - CFD: 26/09/2019 - [] D -- C:\Users\Admin\AppData\Local\AdvinstAnalytics =>.SUP.Various O43 - CFD: 11/09/2020 - [] D -- C:\Users\Admin\AppData\Local\AMD =>.AMD O43 - CFD: 25/09/2019 - [0] SHD -- C:\Users\Admin\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\Users\Admin\AppData\Local\CEF =>.CEF O43 - CFD: 28/03/2020 - [] D -- C:\Users\Admin\AppData\Local\Comms =>.Microsoft Corporation O43 - CFD: 26/09/2019 - [] D -- C:\Users\Admin\AppData\Local\ConnectedDevicesPlatform =>.Microsoft Corporation O43 - CFD: 12/12/2020 - [] D -- C:\Users\Admin\AppData\Local\D3DSCache =>.Legitimate O43 - CFD: 26/11/2020 - [] D -- C:\Users\Admin\AppData\Local\Diagnostics =>.Microsoft Corporation O43 - CFD: 26/11/2020 - [] D -- C:\Users\Admin\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation O43 - CFD: 27/12/2020 - [0] D -- C:\Users\Admin\AppData\Local\Facebook =>.Facebook O43 - CFD: 26/09/2019 - [] D -- C:\Users\Admin\AppData\Local\Google =>.Google O43 - CFD: 25/09/2019 - [0] SHD -- C:\Users\Admin\AppData\Local\Historique =>.Microsoft Corporation O43 - CFD: 03/02/2021 - [] D -- C:\Users\Admin\AppData\Local\HP =>.Hewlett-Packard O43 - CFD: 03/02/2021 - [] D -- C:\Users\Admin\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 26/09/2019 - [] D -- C:\Users\Admin\AppData\Local\MicrosoftEdge =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\Users\Admin\AppData\Local\Mozilla =>.Mozilla Corporation O43 - CFD: 26/09/2019 - [0] D -- C:\Users\Admin\AppData\Local\NitroSpoolDir =>.Unknown O43 - CFD: 22/11/2019 - [] D -- C:\Users\Admin\AppData\Local\OneDrive =>.Microsoft Corporation O43 - CFD: 12/01/2021 - [] D -- C:\Users\Admin\AppData\Local\Packages =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [0] D -- C:\Users\Admin\AppData\Local\PeerDistRepub =>.Microsoft Corporation O43 - CFD: 03/02/2021 - [] D -- C:\Users\Admin\AppData\Local\PlaceholderTileLogoFolder =>.Microsoft Corporation O43 - CFD: 26/09/2019 - [] D -- C:\Users\Admin\AppData\Local\Programs =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\Users\Admin\AppData\Local\Publishers =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\Users\Admin\AppData\Local\speech =>.Microsoft Corporation O43 - CFD: 27/12/2020 - [] D -- C:\Users\Admin\AppData\Local\SquirrelTemp =>.Squirrels O43 - CFD: 14/02/2021 - [] D -- C:\Users\Admin\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [0] SHD -- C:\Users\Admin\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 02/01/2021 - [] D -- C:\Users\Admin\AppData\Local\VirtualStore =>.Microsoft Corporation O43 - CFD: 26/09/2019 - [] D -- C:\Users\Admin\AppData\Local\Windows_10_Mini_Digital_L O43 - CFD: 14/02/2021 - [] D -- C:\Users\Admin\AppData\Local\ZHP =>.Nicolas Coolman O43 - CFD: 26/09/2019 - [0] D -- C:\Users\Admin\AppData\Local\Programs\Common =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] SD -- C:\Users\Admin\AppData\LocalLow\Microsoft =>.Microsoft Corporation O43 - CFD: 12/12/2020 - [0] D -- C:\Users\Admin\AppData\LocalLow\Mozilla =>.Mozilla Corporation O43 - CFD: 03/02/2021 - [] D -- C:\Users\Admin\Desktop\Adobe Acrobat O43 - CFD: 19/03/2019 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools O43 - CFD: 19/03/2019 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation O43 - CFD: 27/12/2020 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR O43 - CFD: 08/02/2020 - [] D -- C:\Users\Default\AppData\Local\AdvinstAnalytics O43 - CFD: 25/09/2019 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [0] SHD -- C:\Users\Default\AppData\Local\Historique =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 08/02/2020 - [] D -- C:\Users\Default User\AppData\Local\AdvinstAnalytics O43 - CFD: 25/09/2019 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [0] SHD -- C:\Users\Default User\AppData\Local\Historique =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 19/03/2019 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 08/02/2020 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\AdvinstAnalytics O43 - CFD: 25/09/2019 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\D3DSCache =>.Legitimate O43 - CFD: 02/11/2019 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 25/09/2019 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Packages =>.Microsoft Corporation O43 - CFD: 26/09/2019 - [0] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\PeerDistRepub =>.Microsoft Corporation O43 - CFD: 27/11/2020 - [] SD -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation O43 - CFD: 04/12/2019 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Mozilla =>.Mozilla Corporation ---\\ ShellIconOverlayIdentifiers (SIOI) (2) - 0s O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll [Unsigned] =>.Microsoft Corporation O106 - SIOI: [Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81}. (.Microsoft Corporation - IU de cache côté client.) -- C:\Windows\System32\cscui.dll [Unsigned] =>.Microsoft Corporation ---\\ RACCOURCIS DES MENUS CONTEXTUELS (SCMH) (27) - 4s O108 - CMH1: EPP - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Extension Microsoft Security Client Shell.) -- C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows® O108 - CMH1: ModernSharing - {e2bf9676-5f8f-435c-97eb-11607a5bedf7} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation O108 - CMH1: NPShellExtension - {9C4B85B8-956C-49BF-9BA5-101384E562B2} . (.Nitro PDF - Nitro Pro ShellExtension.) -- C:\Program Files\Nitro\Pro 11\NPShellExtension.dll =>.Nitro Software, Inc.® O108 - CMH1: Open With - {09799AFB-AD67-11d1-ABCD-00C04FC30936} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows® O108 - CMH1: Open With EncryptionMenu - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows® O108 - CMH1: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation O108 - CMH1: WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH® O108 - CMH1: WorkFolders - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extension d’environnement de Dossiers de tr.) -- C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation O108 - CMH2: OpenContainingFolderMenu - {37ea3a21-7493-4208-a011-7f9ea79ce9f5} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows® O108 - CMH2: WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH® O108 - CMH3: CopyAsPathMenu - {f3d06e7c-1e45-4a26-847e-f9fcdee59be0} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows® O108 - CMH3: SendTo - {7BA4C740-9E81-11CF-99D3-00AA004AE837} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows® O108 - CMH4: EncryptionMenu - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows® O108 - CMH4: EPP - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Extension Microsoft Security Client Shell.) -- C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows® O108 - CMH4: Offline Files - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Microsoft Corporation - IU de cache côté client.) -- C:\Windows\System32\cscui.dll [Unsigned] =>.Microsoft Corporation O108 - CMH4: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation O108 - CMH4: WorkFolders - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extension d’environnement de Dossiers de tr.) -- C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation O108 - CMH5: New - {D969A300-E7FF-11d0-A93B-00A0C90F2719} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows® O108 - CMH5: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation O108 - CMH5: WorkFolders - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extension d’environnement de Dossiers de tr.) -- C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation O108 - CMH6: Library Location - {3dad6c5d-2167-4cae-9914-f99e41c12cfa} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows® O108 - CMH6: Offline Files - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Microsoft Corporation - IU de cache côté client.) -- C:\Windows\System32\cscui.dll [Unsigned] =>.Microsoft Corporation O108 - CMH6: PintoStartScreen - {470C0EBD-5D73-4d58-9CED-E91E22E23282} . (.Microsoft Corporation - Programme de résolution d’applications.) -- C:\Windows\System32\appresolver.dll =>.Microsoft Windows® O108 - CMH6: WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH® O108 - CMH7: EnhancedStorageShell - {2854F705-3548-414C-A113-93E27C808C85} . (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll [Unsigned] =>.Microsoft Corporation O108 - CMH7: EPP - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Extension Microsoft Security Client Shell.) -- C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows® O108 - CMH7: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation ---\\ IMAGE FILE EXECUTION OPTIONS (IFEO) (17) - 2s O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\\3] =>.Microsoft Windows® O50 - IFEO:C:\Windows\System32\drvinst.exe - (.Microsoft Corporation - Module d’installation de pilotes.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\ie4uinit.exe - (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - Outil d’installation sans assistance d’IE 7.) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Microsoft Management Console.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Hôte des applications HTML de Microsoft(R).) [MitigationOptions\\256] [Unsigned] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation Host.) [MitigationOptions\\1118481] [Unsigned] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\\2097152] [Unsigned] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\\4294967296] =>.Microsoft Windows® O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\spoolsv.exe - (.Microsoft Corporation - Application sous-système spouleur.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\spoolsv.exe - (.Microsoft Corporation - Application sous-système spouleur.) [MitigationOptions\\2097152] [Unsigned] =>.Microsoft Corporation O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Processus hôte pour les services Windows.) [MinimumStackCommitInBytes\\32768] =>.Microsoft Windows Publisher® O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\\3] [Unsigned] =>.Microsoft Corporation ---\\ LISTE DES PILOTES DU SYSTÈME (409) - 56s O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - 1394 OpenHCI Driver.) -- C:\Windows\System32\drivers\1394ohci.sys [190464] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\drivers\3ware.sys [85816] =>.Microsoft Windows® O58 - SDL:2019/09/26 15:34:45 A . (.FsFilter Network - NT FsFilter SYS.) -- C:\Windows\System32\drivers\9a3c1ac4a8bba090.sys [29632] =>Trojan.Agent (Rootkit.Necurs) O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Pilote ACPI pour NT.) -- C:\Windows\System32\drivers\acpi.sys [603960] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - ACPI Devices Driver.) -- C:\Windows\System32\drivers\AcpiDev.sys [14336] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:36 A . (.Microsoft Corporation - ACPIEx Driver.) -- C:\Windows\System32\drivers\acpiex.sys [96272] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - ACPI Processor Aggregator Device Driver.) -- C:\Windows\System32\drivers\acpipagr.sys [9216] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:24 A . (.Microsoft Corporation - ACPI Power Metering Driver.) -- C:\Windows\System32\drivers\acpipmi.sys [11264] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - ACPI Wake Alarm.) -- C:\Windows\System32\drivers\acpitime.sys [9216] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:36 A . (.Microsoft Corporation - Audio KMDF Class Extension.) -- C:\Windows\System32\drivers\Acx01000.sys [241664] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\Windows\System32\drivers\adp80xx.sys [1038352] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\Windows\System32\drivers\afd.sys [513336] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:45 A . (.Microsoft Corporation - AF_UNIX socket provider.) -- C:\Windows\System32\drivers\afunix.sys [29696] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:48 A . (.Microsoft Corporation - Gestionnaire d'appels RAS Agile Vpn Minipor.) -- C:\Windows\System32\drivers\agilevpn.sys [93696] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:36 A . (.Microsoft Corporation - Application Compatibility Cache.) -- C:\Windows\System32\drivers\ahcache.sys [231936] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:17 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\amdk8.sys [156680] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:17 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\amdppm.sys [159544] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [75280] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [215560] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [23080] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:14 A . (.Microsoft Corporation - AppID Driver.) -- C:\Windows\System32\drivers\appid.sys [161592] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:14 A . (.Microsoft Corporation - Applocker Filter.) -- C:\Windows\System32\drivers\applockerfltr.sys [13312] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 08:19:02 A . (.Microsoft Corporation - Microsoft Application Virtualization Stream.) -- C:\Windows\System32\drivers\AppVStrm.sys [91960] =>.Microsoft Windows® O58 - SDL:2019/03/19 08:19:02 A . (.Microsoft Corporation - Microsoft Application Virtualization VE Man.) -- C:\Windows\System32\drivers\AppvVemgr.sys [118584] =>.Microsoft Windows® O58 - SDL:2019/03/19 08:19:02 A . (.Microsoft Corporation - Microsoft Application Virtualization VFS Fi.) -- C:\Windows\System32\drivers\AppvVfs.sys [111416] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [116752] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:48 A . (.Microsoft Corporation - MS Remote Access serial network driver.) -- C:\Windows\System32\drivers\asyncmac.sys [20480] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [23056] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - ATAPI Driver Extension.) -- C:\Windows\System32\drivers\ataport.sys [157200] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:20 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\Windows\System32\drivers\athw8.sys [3228672] [Unsigned] =>.Qualcomm Atheros Communications, Inc. O58 - SDL:2019/03/19 03:40:21 A . (.Microsoft Corporation - BAM Kernel Driver.) -- C:\Windows\System32\drivers\bam.sys [57144] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Battery Class Driver.) -- C:\Windows\System32\drivers\battc.sys [35128] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:20 A . (. - BCM Function 2 Device Driver.) -- C:\Windows\System32\drivers\bcmfn2.sys [8192] [Unsigned] =>.Broadcom Corporation O58 - SDL:2019/03/19 03:39:46 A . (.Microsoft Corporation - BEEP Driver.) -- C:\Windows\System32\drivers\beep.sys [7168] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:02 A . (.Microsoft Corporation - Windows Bind Filter Driver.) -- C:\Windows\System32\drivers\bindflt.sys [89912] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:40 A . (.Microsoft Corporation - NT Lan Manager Datagram Receiver Driver.) -- C:\Windows\System32\drivers\bowser.sys [76800] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:59 A . (.Microsoft Corporation - MAC Bridge Driver.) -- C:\Windows\System32\drivers\bridge.sys [96256] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:20 A . (.Microsoft Corporation - Microsoft Bluetooth Audio Multiprofile Mana.) -- C:\Windows\System32\drivers\BtaMPM.sys [27648] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:20 A . (.Microsoft Corporation - Bluetooth A2DP Driver.) -- C:\Windows\System32\drivers\BthA2dp.sys [165888] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:18 A . (.Microsoft Corporation - Extension de bus Bluetooth.) -- C:\Windows\System32\drivers\bthenum.sys [92672] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:20 A . (.Microsoft Corporation - Bluetooth Hands-Free Audio and Call Control.) -- C:\Windows\System32\drivers\BthHfEnum.sys [94720] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:18 A . (.Microsoft Corporation - Bluetooth Transport Extensibility Miniport.) -- C:\Windows\System32\drivers\BthMini.SYS [25600] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:23 A . (.Microsoft Corporation - Bluetooth Communications Driver.) -- C:\Windows\System32\drivers\bthmodem.sys [52736] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Bluetooth Personal Area Networking.) -- C:\Windows\System32\drivers\bthpan.sys [99840] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:18 A . (.Microsoft Corporation - Pilote de bus Bluetooth.) -- C:\Windows\System32\drivers\bthport.sys [1086464] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:18 A . (.Microsoft Corporation - Pilote de Miniport Bluetooth.) -- C:\Windows\System32\drivers\BTHUSB.SYS [70144] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Button Converter Driver.) -- C:\Windows\System32\drivers\buttonconverter.sys [29696] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:21 A . (.Microsoft Corporation - Charge Arbiration Driver.) -- C:\Windows\System32\drivers\CAD.sys [53560] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:56 A . (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\cdfs.sys [74752] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\cdrom.sys [125952] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:02 A . (.Microsoft Corporation - Event Aggregation Kernel Mode Library.) -- C:\Windows\System32\drivers\CEA.sys [61752] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:21 A . (.Microsoft Corporation - Consumer IR Class Driver for eHome.) -- C:\Windows\System32\drivers\circlass.sys [39424] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - SCSI Class System Dll.) -- C:\Windows\System32\drivers\Classpnp.sys [353808] =>.Microsoft Windows® O58 - SDL:2019/04/02 00:00:53 A . (.Microsoft Corporation - Cloud Files Mini Filter Driver.) -- C:\Windows\System32\drivers\cldflt.sys [350720] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:36 A . (.Microsoft Corporation - Common Log File System Driver.) -- C:\Windows\System32\drivers\clfs.sys [277520] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:52 A . (.Microsoft Corporation - CLIP Service.) -- C:\Windows\System32\drivers\ClipSp.sys [824120] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Control Method Battery Driver.) -- C:\Windows\System32\drivers\CmBatt.sys [26624] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:36 A . (.Microsoft Corporation - Noyau Gestionnaire de configuration Configu.) -- C:\Windows\System32\drivers\cmimcext.sys [25616] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:27 A . (.Microsoft Corporation - Kernel Cryptography, Next Generation.) -- C:\Windows\System32\drivers\cng.sys [553152] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:03 A . (.Microsoft Corporation - CNG Hardware Assist algorithm provider.) -- C:\Windows\System32\drivers\cnghwassist.sys [32568] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:02 A . (.Microsoft Corporation - Console Driver.) -- C:\Windows\System32\drivers\condrv.sys [44560] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Crash Dump Driver.) -- C:\Windows\System32\drivers\crashdmp.sys [80696] =>.Microsoft Windows® O58 - SDL:2019/03/19 08:19:00 A . (.Microsoft Corporation - Windows Client Side Caching Driver.) -- C:\Windows\System32\drivers\csc.sys [431616] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:21 A . (.Microsoft Corporation - DAM Kernel Driver.) -- C:\Windows\System32\drivers\dam.sys [81208] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:20 A . (.Microsoft Corporation - Xbox Device Authentication Driver.) -- C:\Windows\System32\drivers\devauthe.sys [36352] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:19 A . (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\dfsc.sys [114176] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - PnP Disk Driver.) -- C:\Windows\System32\drivers\disk.sys [77624] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:29 A . (.Microsoft Corporation - Crash Dump Disk Driver.) -- C:\Windows\System32\drivers\Diskdump.sys [31032] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:29 A . (.Microsoft Corporation - Boot Over USB Dump Driver.) -- C:\Windows\System32\drivers\Dmpusbstor.sys [11264] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Mémoire dynamique.) -- C:\Windows\System32\drivers\dmvsc.sys [49464] =>.Microsoft Windows® O58 - SDL:2017/08/02 23:25:36 A . (.Intel Corporation - DPTF CPU Device (32-Bit).) -- C:\Windows\System32\drivers\dptf_cpu.sys [59272] =>.Intel Corporation® O58 - SDL:2019/03/19 03:39:23 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\Windows\System32\drivers\drmk.sys [70144] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:23 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\Windows\System32\drivers\drmkaud.sys [14696] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:14 A . (.Microsoft Corporation - ATAPI Dump Driver.) -- C:\Windows\System32\drivers\Dumpata.sys [30736] =>.Microsoft Windows® O58 - SDL:2019/03/19 08:18:58 A . (.Microsoft Corporation - Bitlocker Drive Encryption Crashdump Filter.) -- C:\Windows\System32\drivers\dumpfve.sys [75480] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - SD Crashdump Port Driver.) -- C:\Windows\System32\drivers\dumpsd.sys [158520] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:03 A . (.Microsoft Corporation - SD Host Controller Crashdump Port Driver.) -- C:\Windows\System32\drivers\dumpsdport.sys [23040] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:29 A . (.Microsoft Corporation - Storport Dump Driver.) -- C:\Windows\System32\drivers\Dumpstorport.sys [28680] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:24 A . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\drivers\dxgkrnl.sys [2763792] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:24 A . (.Microsoft Corporation - DirectX Graphics MMS.) -- C:\Windows\System32\drivers\dxgmms1.sys [344376] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:24 A . (.Microsoft Corporation - DirectX Graphics MMS.) -- C:\Windows\System32\drivers\dxgmms2.sys [691000] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:59 A . (.Microsoft Corporation - Enhanced Storage Class driver for IEEE 1667.) -- C:\Windows\System32\drivers\EhStorClass.sys [69944] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:21 A . (.Microsoft Corporation - Microsoft driver for storage devices suppor.) -- C:\Windows\System32\drivers\EhStorTcgDrv.sys [97808] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Error Device Driver.) -- C:\Windows\System32\drivers\errdev.sys [9728] [Unsigned] =>.Microsoft Corporation O58 - SDL:2017/08/02 23:25:36 A . (.Intel Corporation - DPTF Zone (32-Bit).) -- C:\Windows\System32\drivers\esif_lf.sys [286088] =>.Intel Corporation® O58 - SDL:2019/03/19 03:39:32 A . (.Microsoft Corporation - Microsoft Extended FAT File System.) -- C:\Windows\System32\drivers\exfat.sys [306176] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:32 A . (.Microsoft Corporation - Fast FAT File System Driver.) -- C:\Windows\System32\drivers\fastfat.sys [319800] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Floppy Disk Controller Driver.) -- C:\Windows\System32\drivers\fdc.sys [26112] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:36 A . (.Microsoft Corporation - Windows sandboxing and encryption filter.) -- C:\Windows\System32\drivers\filecrypt.sys [45568] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:14 A . (.Microsoft Corporation - FileInfo Filter Driver.) -- C:\Windows\System32\drivers\fileinfo.sys [69944] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:14 A . (.Microsoft Corporation - File Trace Filter Driver.) -- C:\Windows\System32\drivers\filetrace.sys [29184] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Floppy Driver.) -- C:\Windows\System32\drivers\flpydisk.sys [20992] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Gestionnaire de filtres de système de fichi.) -- C:\Windows\System32\drivers\fltMgr.sys [309264] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:36 A . (.Microsoft Corporation - File System Dependency Manager Mini Filter.) -- C:\Windows\System32\drivers\fsdepends.sys [53048] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - File System Recognizer Driver.) -- C:\Windows\System32\drivers\fs_rec.sys [28168] =>.Microsoft Windows® O58 - SDL:2019/03/19 08:18:58 A . (.Microsoft Corporation - BitLocker Drive Encryption Driver.) -- C:\Windows\System32\drivers\fvevol.sys [650040] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:36 A . (.Microsoft Corporation - FWP/IPsec Kernel-Mode API.) -- C:\Windows\System32\drivers\FWPKCLNT.SYS [331280] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:32 A . (.Microsoft Corporation - GPU Energy Kernel Driver.) -- C:\Windows\System32\drivers\gpuenergydrv.sys [8192] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:21 A . (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\hdaudbus.sys [91648] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:23 A . (.Microsoft Corporation - High Definition Audio Function Driver.) -- C:\Windows\System32\drivers\HdAudio.sys [357376] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Hid Battery Driver.) -- C:\Windows\System32\drivers\hidbatt.sys [30008] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote de miniport Bluetooth pour les périp.) -- C:\Windows\System32\drivers\hidbth.sys [99840] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:18 A . (.Microsoft Corporation - Bibliothèque Hid Class.) -- C:\Windows\System32\drivers\hidclass.sys [142336] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - I2C HID Miniport Driver.) -- C:\Windows\System32\drivers\hidi2c.sys [39424] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - HID Button over Interrupt Driver.) -- C:\Windows\System32\drivers\hidinterrupt.sys [40248] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:23 A . (.Microsoft Corporation - Infrared Miniport Driver for Input Devices.) -- C:\Windows\System32\drivers\hidir.sys [38912] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:18 A . (.Microsoft Corporation - Hid Parsing Library.) -- C:\Windows\System32\drivers\hidparse.sys [31232] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - SPI HID Miniport Driver.) -- C:\Windows\System32\drivers\hidspi.sys [41984] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:18 A . (.Microsoft Corporation - USB Miniport Driver for Input Devices.) -- C:\Windows\System32\drivers\hidusb.sys [31232] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [56848] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - HTTP Pile du protocole.) -- C:\Windows\System32\drivers\http.sys [882488] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:41:17 A . (.Microsoft Corporation - Microsoft Hyper-V Socket Provider.) -- C:\Windows\System32\drivers\hvsocket.sys [105784] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Hardware Policy Driver.) -- C:\Windows\System32\drivers\hwpolicy.sys [28176] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Microsoft VMBus Synthetic Keyboard Driver.) -- C:\Windows\System32\drivers\hyperkbd.sys [21304] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Microsoft VMBus Video Device Miniport Drive.) -- C:\Windows\System32\drivers\HyperVideo.sys [33808] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [99328] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:20 A . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\Windows\System32\drivers\iagpio.sys [28672] [Unsigned] =>.Intel(R) Corporation O58 - SDL:2019/03/19 03:39:20 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\Windows\System32\drivers\iai2c.sys [73728] [Unsigned] =>.Intel(R) Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Intel Corporation - Intel(R) Atom(TM) Processor GPIO Controller.) -- C:\Windows\System32\drivers\iaiogpio.sys [22016] [Unsigned] =>.Intel Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Intel Corporation - Intel(R) Atom(TM) Processor I2C Controller.) -- C:\Windows\System32\drivers\iaioi2c.sys [57856] [Unsigned] =>.Intel Corporation O58 - SDL:2019/03/19 03:39:27 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\Windows\System32\drivers\iaStorAVC.sys [693048] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:27 A . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\drivers\iaStorV.sys [333624] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:02 A . (.Microsoft Corporation - Indirect displays kernel-mode filter driver.) -- C:\Windows\System32\drivers\IndirectKmd.sys [32768] [Unsigned] =>.Microsoft Corporation O58 - SDL:2016/04/01 15:23:20 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\drivers\IntcDAud.sys [659432] =>.Intel(R) OWR® O58 - SDL:2015/12/07 18:53:18 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\Windows\System32\drivers\intelaud.sys [46584] =>.Intel(R) Wireless Display® O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - Intel PCI IDE Driver.) -- C:\Windows\System32\drivers\intelide.sys [17424] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:17 A . (.Microsoft Corporation - Intel Power Engine Plugin.) -- C:\Windows\System32\drivers\intelpep.sys [244712] =>.Microsoft® O58 - SDL:2019/03/19 03:39:20 A . (.Microsoft Corporation - Intel Power Limit Driver.) -- C:\Windows\System32\drivers\intelpmax.sys [19456] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:17 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\intelppm.sys [173368] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Filtre de contrôle de taux d’E/S.) -- C:\Windows\System32\drivers\iorate.sys [45064] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:48 A . (.Microsoft Corporation - IP FILTER DRIVER.) -- C:\Windows\System32\drivers\ipfltdrv.sys [63488] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - PILOT IPMI WMI.) -- C:\Windows\System32\drivers\IPMIDrv.sys [90936] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:02 A . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\ipnat.sys [187392] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:34 A . (.Microsoft Corporation - IPT Driver.) -- C:\Windows\System32\drivers\ipt.sys [39944] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - Pilote de bus PNP ISA.) -- C:\Windows\System32\drivers\isapnp.sys [47928] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Avago Technologies - Avago SAS Gen3.5 Driver (StorPort).) -- C:\Windows\System32\drivers\ItSas35i.sys [121144] =>.Microsoft Windows® O58 - SDL:2015/12/07 18:53:18 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\Windows\System32\drivers\iwdbus.sys [37880] =>.Intel(R) Wireless Display® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote de la classe Clavier.) -- C:\Windows\System32\drivers\kbdclass.sys [51000] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote de filtre clavier HID.) -- C:\Windows\System32\drivers\kbdhid.sys [33280] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Microsoft Kernel Debugger Network Miniport.) -- C:\Windows\System32\drivers\kdnic.sys [26424] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:18 A . (.Microsoft Corporation - Network Power Dependency Broker.) -- C:\Windows\System32\drivers\KNetPwrDepBroker.sys [23040] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:35 A . (.Microsoft Corporation - Kernel CSA Library.) -- C:\Windows\System32\drivers\ks.sys [313856] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:36 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\drivers\ksecdd.sys [108048] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:27 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\drivers\ksecpkg.sys [142856] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Qualcomm Atheros Co., Ltd. - Qualcomm Atheros Ar81xx series PCI-E Gigabi.) -- C:\Windows\System32\drivers\L1C63x86.sys [102912] [Unsigned] =>.Qualcomm Atheros Co., Ltd. O58 - SDL:2019/03/19 03:40:32 A . (.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) -- C:\Windows\System32\drivers\lltdio.sys [49664] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [94008] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2i.sys [103224] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas3i.sys [106296] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sss.sys [69432] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:37 A . (.Microsoft Corporation - Pilote de filtre de virtualisation de fichi.) -- C:\Windows\System32\drivers\luafv.sys [103424] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - MA-USB Host Controller Driver.) -- C:\Windows\System32\drivers\mausbhost.sys [425784] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - MA-USB IP Driver.) -- C:\Windows\System32\drivers\mausbip.sys [46392] =>.Microsoft Windows® O58 - SDL:2017/11/29 09:11:26 A . (...) -- C:\Windows\System32\drivers\mbae.sys [59896] =>.Malwarebytes Corporation® O58 - SDL:2019/06/11 20:43:18 A . (.Microsoft Corporation - Windows Mobile Broadband Class Extension.) -- C:\Windows\System32\drivers\MbbCx.sys [274432] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:46 A . (.Microsoft Corporation - Medium changer class driver.) -- C:\Windows\System32\drivers\mcd.sys [17408] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [52024] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\MegaSas2i.sys [64312] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas35i.sys [79160] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\megasr.sys [464696] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:20 A . (.Microsoft Corporation - Pilote de transport Microsoft Bluetooth Avr.) -- C:\Windows\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys [46080] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Legacy Bluetooth LE Bus Enumerator.) -- C:\Windows\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys [73216] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:34 A . (.Microsoft Corporation - MMCSS Driver.) -- C:\Windows\System32\drivers\mmcss.sys [37888] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:41:15 A . (.Microsoft Corporation - Pilote de périphérique modem.) -- C:\Windows\System32\drivers\modem.sys [32256] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:24 A . (.Microsoft Corporation - Monitor Driver.) -- C:\Windows\System32\drivers\monitor.sys [47104] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote de la classe Souris.) -- C:\Windows\System32\drivers\mouclass.sys [48440] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote de filtre souris HID.) -- C:\Windows\System32\drivers\mouhid.sys [24576] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Gestionnaire des points de montage.) -- C:\Windows\System32\drivers\mountmgr.sys [85512] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:00 A . (.Microsoft Corporation - Microsoft Protection Service Driver.) -- C:\Windows\System32\drivers\mpsdrv.sys [56832] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:41:18 A . (.Microsoft Corporation - Windows NT WebDav Minirdr.) -- C:\Windows\System32\drivers\mrxdav.sys [122880] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:19 A . (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\Windows\System32\drivers\mrxsmb.sys [462648] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:19 A . (.Microsoft Corporation - Longhorn SMB 2.0 Redirector.) -- C:\Windows\System32\drivers\mrxsmb20.sys [206136] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Mailslot driver.) -- C:\Windows\System32\drivers\msfs.sys [25088] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:52 A . (.Microsoft Corporation - GPIO Class Extension Driver.) -- C:\Windows\System32\drivers\msgpioclx.sys [140088] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - GPIO Button Driver.) -- C:\Windows\System32\drivers\msgpiowin32.sys [40248] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:03 A . (.Microsoft Corporation - Pass-through HID to KMDF Filter Driver.) -- C:\Windows\System32\drivers\mshidkmdf.sys [6144] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:48 A . (.Microsoft Corporation - Pilote direct pour interface HID-UMDF.) -- C:\Windows\System32\drivers\mshidumdf.sys [9216] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:02 A . (.Microsoft Corporation - Hardware Notification Class Extension Drive.) -- C:\Windows\System32\drivers\mshwnclx.sys [19968] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - ISA Driver.) -- C:\Windows\System32\drivers\msisadrv.sys [16696] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Microsoft iSCSI Initiator Driver.) -- C:\Windows\System32\drivers\msiscsi.sys [240144] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:35 A . (.Microsoft Corporation - MS KS Server.) -- C:\Windows\System32\drivers\mskssrv.sys [25600] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:45 A . (.Microsoft Corporation - Pilote de protocole LLDP (Link Layer Discov.) -- C:\Windows\System32\drivers\mslldp.sys [60928] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:35 A . (.Microsoft Corporation - MS Proxy Clock.) -- C:\Windows\System32\drivers\mspclock.sys [8192] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:35 A . (.Microsoft Corporation - MS Proxy Quality Manager.) -- C:\Windows\System32\drivers\mspqm.sys [8192] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Kernel Remote Procedure Call Provider.) -- C:\Windows\System32\drivers\msrpc.sys [193544] =>.Microsoft Windows® O58 - SDL:2019/03/19 08:18:57 A . (.Microsoft Corporation - Pilote du filtre de système de fichiers du.) -- C:\Windows\System32\drivers\mssecflt.sys [222008] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - System Management BIOS Driver.) -- C:\Windows\System32\drivers\mssmbios.sys [35128] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:35 A . (.Microsoft Corporation - WDM Tee/Communication Transform Filter.) -- C:\Windows\System32\drivers\mstee.sys [9216] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Pilote HID multipoint Microsoft.) -- C:\Windows\System32\drivers\MTConfig.sys [11776] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:19 A . (.Microsoft Corporation - Pilote de fournisseur UNC multiples.) -- C:\Windows\System32\drivers\mup.sys [104760] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\drivers\mvumis.sys [58376] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - NDIS (Network Driver Interface Specificatio.) -- C:\Windows\System32\drivers\ndis.sys [1071120] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:41:11 A . (.Microsoft Corporation - Microsoft NDIS Packet Capture Filter Driver.) -- C:\Windows\System32\drivers\ndiscap.sys [35328] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:44 A . (.Microsoft Corporation - Microsoft Network Adapter Multiplexor.) -- C:\Windows\System32\drivers\NdisImPlatform.sys [109568] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:48 A . (.Microsoft Corporation - NDIS 3.0 connection wrapper driver.) -- C:\Windows\System32\drivers\ndistapi.sys [20992] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Pilote d’E/S du mode utilisateur NDIS.) -- C:\Windows\System32\drivers\ndisuio.sys [50688] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:45 A . (.Microsoft Corporation - Énumérateur de cartes réseau virtuelles Mic.) -- C:\Windows\System32\drivers\NdisVirtualBus.sys [15872] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:48 A . (.Microsoft Corporation - MS PPP Framing Driver (Strong Encryption).) -- C:\Windows\System32\drivers\ndiswan.sys [166912] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:48 A . (.Microsoft Corporation - NDIS Proxy.) -- C:\Windows\System32\drivers\ndproxy.sys [206848] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:53 A . (.Microsoft Corporation - Windows Network Data Usage Monitoring Drive.) -- C:\Windows\System32\drivers\Ndu.sys [105984] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Network Adapter Class Extension for WDF.) -- C:\Windows\System32\drivers\NetAdapterCx.sys [130560] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:43 A . (.Microsoft Corporation - NetBIOS interface driver.) -- C:\Windows\System32\drivers\netbios.sys [47928] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:42 A . (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netbt.sys [247808] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Network I/O Subsystem.) -- C:\Windows\System32\drivers\netio.sys [398352] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Miniport NDIS virtuel.) -- C:\Windows\System32\drivers\netvsc.sys [166712] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - NPFS Driver.) -- C:\Windows\System32\drivers\npfs.sys [58368] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Named pipe service triggers.) -- C:\Windows\System32\drivers\npsvctrig.sys [19968] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\drivers\nsiproxy.sys [29696] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:35 A . (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [2204472] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:36 A . (.Microsoft Corporation - NTOS extension host driver.) -- C:\Windows\System32\drivers\ntosext.sys [17448] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - NULL Driver.) -- C:\Windows\System32\drivers\null.sys [5120] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [119312] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [142352] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:42 A . (.Microsoft Corporation - Pilote de miniport WiFi natif.) -- C:\Windows\System32\drivers\nwifi.sys [498176] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:02 A . (.Microsoft Corporation - Planificateur de paquets QoS.) -- C:\Windows\System32\drivers\pacer.sys [133136] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\parport.sys [82944] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:36 A . (.Microsoft Corporation - Partition driver.) -- C:\Windows\System32\drivers\partmgr.sys [136504] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - Pilote parallèle VDM.) -- C:\Windows\System32\drivers\parvdm.sys [9216] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - Énumérateur Plug-and-Play PCI pour NT.) -- C:\Windows\System32\drivers\pci.sys [321848] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\pciide.sys [14888] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - PCI IDE Bus Driver Extension.) -- C:\Windows\System32\drivers\pciidex.sys [42000] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:21 A . (.Microsoft Corporation - Pilote de bus PCMCIA.) -- C:\Windows\System32\drivers\pcmcia.sys [98320] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:16 A . (.Microsoft Corporation - Performance Counters for Windows Driver.) -- C:\Windows\System32\drivers\pcw.sys [43536] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:36 A . (.Microsoft Corporation - Power Dependency Coordinator Driver.) -- C:\Windows\System32\drivers\pdc.sys [142864] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:40 A . (.Microsoft Corporation - Protected Environment Authentication and Au.) -- C:\Windows\System32\drivers\PEAuth.sys [692736] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\percsas2i.sys [51512] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\percsas3i.sys [59192] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:41:11 A . (.Microsoft Corporation - Pilote du moniteur de paquets.) -- C:\Windows\System32\drivers\PktMon.sys [79888] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:24 A . (.Microsoft Corporation - Pilote mémoire Plug and Play.) -- C:\Windows\System32\drivers\pnpmem.sys [13312] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:03 A . (.Microsoft Corporation - Port Device Class Configuration Filter Driv.) -- C:\Windows\System32\drivers\portcfg.sys [18944] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:23 A . (.Microsoft Corporation - Port Class (Class Driver for Port/Miniport.) -- C:\Windows\System32\drivers\portcls.sys [279552] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:17 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\processr.sys [166712] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:59 A . (.Microsoft Corporation - Process Launch Monitor driver.) -- C:\Windows\System32\drivers\ProcLaunchMon.sys [26888] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:45 A . (.Microsoft Corporation - Pilote du support de Microsoft Quality Wind.) -- C:\Windows\System32\drivers\qwavedrv.sys [32768] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:36 A . (.Microsoft Corporation - RAM Disk Driver.) -- C:\Windows\System32\drivers\ramdisk.sys [33592] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:48 A . (.Microsoft Corporation - RAS Automatic Connection Driver.) -- C:\Windows\System32\drivers\rasacd.sys [12288] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:48 A . (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\rasl2tp.sys [79872] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:48 A . (.Microsoft Corporation - RAS PPPoE mini-port/call-manager driver.) -- C:\Windows\System32\drivers\raspppoe.sys [67584] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:48 A . (.Microsoft Corporation - Peer-to-Peer Tunneling Protocol.) -- C:\Windows\System32\drivers\raspptp.sys [73728] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:48 A . (.Microsoft Corporation - RAS SSTP Miniport Call Manager.) -- C:\Windows\System32\drivers\rassstp.sys [65536] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:36 A . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) -- C:\Windows\System32\drivers\rdbss.sys [361784] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Microsoft RDP Bus Device driver.) -- C:\Windows\System32\drivers\rdpbus.sys [21504] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:41:11 A . (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\Windows\System32\drivers\rdpdr.sys [131072] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:41:09 A . (.Microsoft Corporation - Microsoft RDP Video Miniport driver.) -- C:\Windows\System32\drivers\rdpvideominiport.sys [23864] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:41:18 A . (.Microsoft Corporation - ReadyBoost Driver.) -- C:\Windows\System32\drivers\rdyboost.sys [218936] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Bluetooth RFCOMM Driver.) -- C:\Windows\System32\drivers\rfcomm.sys [160256] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Transport d’ordinateur virtuel Microsoft Re.) -- C:\Windows\System32\drivers\RfxVmt.sys [31744] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:24 A . (.Microsoft Corporation - ResourceHub Proxy Driver.) -- C:\Windows\System32\drivers\rhproxy.sys [76800] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:41:02 A . (.Microsoft Corporation - Reliable Multicast Transport.) -- C:\Windows\System32\drivers\rmcast.sys [122368] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:48 A . (.Microsoft Corporation - Remote NDIS Miniport.) -- C:\Windows\System32\drivers\RNDISMP.sys [25600] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:17 A . (.Microsoft Corporation - Remote NDIS Miniport.) -- C:\Windows\System32\drivers\rndismp6.sys [32256] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:41:15 A . (.Microsoft Corporation - Legacy Non-Pnp Modem Device Driver.) -- C:\Windows\System32\drivers\rootmdm.sys [8704] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:33 A . (.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) -- C:\Windows\System32\drivers\rspndr.sys [64000] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:27 A . (.Realtek - Realtek 8125/8136/8168/8169 NDIS 6.40 32-bi.) -- C:\Windows\System32\drivers\rt640x86.sys [554496] [Unsigned] =>.Realtek O58 - SDL:2019/03/19 03:39:34 RA . (.Realtek - Realtek PCIe GBE Family Controller Flight.) -- C:\Windows\System32\drivers\rteth.sys [45568] [Unsigned] =>.Realtek O58 - SDL:2019/03/19 03:39:20 A . (.Realtek Semiconductor Corporation - Realtek PCIE NDIS Driver 69350 29887.) -- C:\Windows\System32\drivers\rtwlane01.sys [6755840] [Unsigned] =>.Realtek Semiconductor Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - SBP-2 Protocol Driver.) -- C:\Windows\System32\drivers\sbp2port.sys [88072] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:53 A . (.Microsoft Corporation - Pilote de filtre de lecteur de carte à puce.) -- C:\Windows\System32\drivers\scfilter.sys [35840] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:46 A . (.Microsoft Corporation - SCSI Port Driver.) -- C:\Windows\System32\drivers\scsiport.sys [144696] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote du bus numérique sécurisé (SD).) -- C:\Windows\System32\drivers\sdbus.sys [235320] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:36 A . (.Microsoft Corporation - SD Host Controller Port Driver.) -- C:\Windows\System32\drivers\sdport.sys [78136] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote de classe de stockage SD.) -- C:\Windows\System32\drivers\sdstor.sys [76088] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:03 A . (.Microsoft Corporation - Serial Class Extension.) -- C:\Windows\System32\drivers\SerCx.sys [65336] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:03 A . (.Microsoft Corporation - Serial Class Extension V2.) -- C:\Windows\System32\drivers\SerCx2.sys [129336] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - Serial Port Enumerator.) -- C:\Windows\System32\drivers\serenum.sys [17920] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - Pilote de périphérique série.) -- C:\Windows\System32\drivers\serial.sys [76800] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\drivers\sermouse.sys [20992] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - SCSI Floppy Driver.) -- C:\Windows\System32\drivers\sfloppy.sys [13312] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [41488] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [79368] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Sleep Study Helper.) -- C:\Windows\System32\drivers\SleepStudyHelper.sys [30008] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:53 A . (.Microsoft Corporation - Smart Card Driver Library.) -- C:\Windows\System32\drivers\smclib.sys [17920] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Storage Spaces Dump Driver.) -- C:\Windows\System32\drivers\spacedump.sys [162320] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Storage Spaces Driver.) -- C:\Windows\System32\drivers\spaceport.sys [504632] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:03 A . (.Microsoft Corporation - SPB Class Extension.) -- C:\Windows\System32\drivers\SpbCx.sys [64312] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:19 A . (.Microsoft Corporation - Pilote de serveur SMB 2.0.) -- C:\Windows\System32\drivers\srv2.sys [658432] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:19 A . (.Microsoft Corporation - Server Network driver.) -- C:\Windows\System32\drivers\srvnet.sys [223744] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\Windows\System32\drivers\stexstor.sys [27152] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - MS AHCI Storport Miniport Driver.) -- C:\Windows\System32\drivers\storahci.sys [143672] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - Microsoft NVM Express Storport Miniport Dri.) -- C:\Windows\System32\drivers\stornvme.sys [105784] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:36 A . (.Microsoft Corporation - Microsoft Storage Port Driver.) -- C:\Windows\System32\drivers\storport.sys [538424] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:03 A . (.Microsoft Corporation - Filtre de qualité de service de stockage.) -- C:\Windows\System32\drivers\storqosflt.sys [73744] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:17 A . (.Microsoft Corporation - MS UFS Storport Miniport Driver.) -- C:\Windows\System32\drivers\storufs.sys [44560] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Storage VSC Driver.) -- C:\Windows\System32\drivers\storvsc.sys [29496] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:46 A . (.Microsoft Corporation - WDM CODEC Class Device Driver 2.0.) -- C:\Windows\System32\drivers\stream.sys [54784] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - VSC vidéo Synth3D RemoteFX Microsoft.) -- C:\Windows\System32\drivers\Synth3dVsc.sys [50688] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:46 A . (.Microsoft Corporation - SCSI Tape Class Driver.) -- C:\Windows\System32\drivers\tape.sys [23552] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:40 A . (.Microsoft Corporation - Export driver for kernel mode TPM API.) -- C:\Windows\System32\drivers\tbs.sys [23864] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:36 A . (.Microsoft Corporation - Pilote TCP/IP.) -- C:\Windows\System32\drivers\tcpip.sys [2245944] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:43 A . (.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) -- C:\Windows\System32\drivers\tcpipreg.sys [41984] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - TDI Wrapper.) -- C:\Windows\System32\drivers\tdi.sys [32784] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:53 A . (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [95544] =>.Microsoft Windows® O58 - SDL:2018/08/03 01:41:38 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\drivers\TeeDriverW8.sys [192560] =>.Intel(R) Embedded Subsystems and IP Blocks Group® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Terminal Server Input Driver.) -- C:\Windows\System32\drivers\terminpt.sys [33832] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:19 A . (.Microsoft Corporation - Kernel Transaction Manager Driver.) -- C:\Windows\System32\drivers\tm.sys [100392] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote de périphérique TPM.) -- C:\Windows\System32\drivers\tpm.sys [191800] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:36 A . (.Microsoft Corporation - Pilote de filtre pour concentrateur USB du.) -- C:\Windows\System32\drivers\TsUsbFlt.sys [50688] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Remote Desktop Generic USB Driver.) -- C:\Windows\System32\drivers\TsUsbGD.sys [27136] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 08:19:02 A . (.Microsoft Corporation - Concentrateur USB du Bureau à distance.) -- C:\Windows\System32\drivers\tsusbhub.sys [89600] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:43 A . (.Microsoft Corporation - Pilote d’interface de tunnel Microsoft.) -- C:\Windows\System32\drivers\tunnel.sys [100864] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - Microsoft Uasp Driver.) -- C:\Windows\System32\drivers\uaspstor.sys [57656] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:03 A . (.Microsoft Corporation - USB Connector Manager KMDF Class Extension.) -- C:\Windows\System32\drivers\UcmCx.sys [112128] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:03 A . (.Microsoft Corporation - UCM-TCPCI KMDF Class Extension.) -- C:\Windows\System32\drivers\UcmTcpciCx.sys [129024] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - UCM-UCSI ACPI Client Driver.) -- C:\Windows\System32\drivers\UcmUcsiAcpiClient.sys [23552] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:03 A . (.Microsoft Corporation - UCM-UCSI KMDF Class Extension.) -- C:\Windows\System32\drivers\UcmUcsiCx.sys [78848] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:36 A . (.Microsoft Corporation - USB Controller Extension.) -- C:\Windows\System32\drivers\Ucx01000.sys [196408] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:36 A . (.Microsoft Corporation - "udecx.DRIVER".) -- C:\Windows\System32\drivers\Udecx.sys [35328] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:41:15 A . (.Microsoft Corporation - UDF File System Driver.) -- C:\Windows\System32\drivers\udfs.sys [262144] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 08:18:56 A . (.Microsoft Corporation - Microsoft User Experience Virtualization Ag.) -- C:\Windows\System32\drivers\UevAgentDriver.sys [35640] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:03 A . (.Microsoft Corporation - USB Function Driver Class Extension.) -- C:\Windows\System32\drivers\ufx01000.sys [239928] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - UFX Synopsys Client Driver.) -- C:\Windows\System32\drivers\ufxsynopsys.sys [140600] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Generic pass-through driver.) -- C:\Windows\System32\drivers\umpass.sys [9216] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:03 A . (.Microsoft Corporation - USB Role-Switch Class Extension.) -- C:\Windows\System32\drivers\urscx01000.sys [54072] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:48 A . (.Microsoft Corporation - Remote NDIS USB Driver.) -- C:\Windows\System32\drivers\usb8023.sys [15872] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:17 A . (.Microsoft Corporation - Remote NDIS USB Driver.) -- C:\Windows\System32\drivers\usb80236.sys [15872] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:23 A . (.Microsoft Corporation - USB Audio Class Driver.) -- C:\Windows\System32\drivers\USBAUDIO.sys [134144] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:23 A . (.Microsoft Corporation - Microsoft USB Audio Class 2.0 Driver.) -- C:\Windows\System32\drivers\usbaudio2.sys [177152] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:36 A . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\Windows\System32\drivers\USBCAMD.sys [27136] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:36 A . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\Windows\System32\drivers\USBCAMD2.sys [27136] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) -- C:\Windows\System32\drivers\usbccgp.sys [133432] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:23 A . (.Microsoft Corporation - USB Consumer IR Driver for eHome.) -- C:\Windows\System32\drivers\usbcir.sys [89088] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Universal Serial Bus Driver.) -- C:\Windows\System32\drivers\usbd.sys [25400] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - EHCI eUSB Miniport Driver.) -- C:\Windows\System32\drivers\usbehci.sys [73016] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote de concentrateur USB par défaut.) -- C:\Windows\System32\drivers\usbhub.sys [384824] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote de concentrateur USB3.) -- C:\Windows\System32\drivers\USBHUB3.SYS [481080] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - OHCI USB Miniport Driver.) -- C:\Windows\System32\drivers\usbohci.sys [21504] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:03 A . (...) -- C:\Windows\System32\drivers\UsbPmApi.sys [32256] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote de port USB 1.1 & 2.0.) -- C:\Windows\System32\drivers\usbport.sys [381240] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:24 A . (.Microsoft Corporation - USB Printer driver.) -- C:\Windows\System32\drivers\usbprint.sys [23040] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:24 A . (.Microsoft Corporation - USB Scanner Driver.) -- C:\Windows\System32\drivers\usbscan.sys [38912] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - USB Serial Driver.) -- C:\Windows\System32\drivers\usbser.sys [58880] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote de classe de stockage de masse USB.) -- C:\Windows\System32\drivers\USBSTOR.SYS [105784] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - UHCI USB Miniport Driver.) -- C:\Windows\System32\drivers\usbuhci.sys [24576] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:24 A . (.Microsoft Corporation - USB Video Class Driver.) -- C:\Windows\System32\drivers\usbvideo.sys [246584] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Pilote XHCI USB.) -- C:\Windows\System32\drivers\USBXHCI.SYS [425272] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - Virtual Drive Root Enumerator.) -- C:\Windows\System32\drivers\vdrvroot.sys [55608] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Extension du vérificateur de pilotes.) -- C:\Windows\System32\drivers\VerifierExt.sys [235024] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:18 A . (.Microsoft Corporation - VHD Miniport Driver.) -- C:\Windows\System32\drivers\vhdmp.sys [564240] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Virtual HID Framework (VHF) Driver.) -- C:\Windows\System32\drivers\vhf.sys [28672] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:17 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\viac7.sys [145408] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:19 A . (.Microsoft Corporation - Video Port Driver.) -- C:\Windows\System32\drivers\videoprt.sys [35840] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:41:17 A . (.Microsoft Corporation - Hyper-V VMBus KMCL.) -- C:\Windows\System32\drivers\vmbkmcl.sys [70968] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Pilote enfant de bus VMBus sous Microsoft H.) -- C:\Windows\System32\drivers\vmbus.sys [103224] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Microsoft VMBus HID Miniport.) -- C:\Windows\System32\drivers\VMBusHID.sys [28472] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Virtual Machine Generation Counter.) -- C:\Windows\System32\drivers\vmgencounter.sys [18744] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Virtual Machine Guest Infrastructure Driver.) -- C:\Windows\System32\drivers\vmgid.sys [17208] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Microsoft S3 Emulated Device Cap Driver.) -- C:\Windows\System32\drivers\vms3cap.sys [15160] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Pilote de filtre de stockage virtuel.) -- C:\Windows\System32\drivers\vmstorfl.sys [42808] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Pilote du gestionnaire de volumes.) -- C:\Windows\System32\drivers\volmgr.sys [66872] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:56 A . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volum.) -- C:\Windows\System32\drivers\volmgrx.sys [308752] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:19 A . (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [356152] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Volume driver.) -- C:\Windows\System32\drivers\volume.sys [14136] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR X86-32.) -- C:\Windows\System32\drivers\vsmraid.sys [150056] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:26 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\drivers\VSTXRAID.SYS [277008] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:42 A . (.Microsoft Corporation - Virtual Wireless Bus Driver.) -- C:\Windows\System32\drivers\vwifibus.sys [20992] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:42 A . (.Microsoft Corporation - Virtual WiFi Filter Driver.) -- C:\Windows\System32\drivers\vwififlt.sys [61952] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:42 A . (.Microsoft Corporation - Virtual WiFi Miniport Driver.) -- C:\Windows\System32\drivers\vwifimp.sys [34816] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:26 A . (.Microsoft Corporation - Pilote de tablette Wacom à stylet série.) -- C:\Windows\System32\drivers\wacompen.sys [21504] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:48 A . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) -- C:\Windows\System32\drivers\wanarp.sys [65024] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:52 A . (.Microsoft Corporation - Watchdog Driver.) -- C:\Windows\System32\drivers\watchdog.sys [47104] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:26 A . (.Microsoft Corporation - Windows Container Isolation FS Filter Drive.) -- C:\Windows\System32\drivers\wcifs.sys [149304] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:02 A . (.Microsoft Corporation - Windows Container Name Virtualization FS Fi.) -- C:\Windows\System32\drivers\wcnfs.sys [70656] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:43 A . (.Microsoft Corporation - Microsoft antimalware boot driver.) -- C:\Windows\System32\drivers\WdBoot.sys [38280] =>.Microsoft® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Runtime de l’infrastructure de pilotes en m.) -- C:\Windows\System32\drivers\Wdf01000.sys [606736] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:43 A . (.Microsoft Corporation - Microsoft antimalware file system filter dr.) -- C:\Windows\System32\drivers\WdFilter.sys [268768] =>.Microsoft® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Kernel Mode Driver Framework Loader.) -- C:\Windows\System32\drivers\WdfLdr.sys [47656] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:42 A . (.Microsoft Corporation - WDI Driver Framework Driver.) -- C:\Windows\System32\drivers\WdiWiFi.sys [654848] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:07 A . (.Microsoft Corporation - WDM Companion Filter.) -- C:\Windows\System32\drivers\WdmCompanionFilter.sys [17720] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:43 A . (.Microsoft Corporation - Windows Defender Network Stream Filter.) -- C:\Windows\System32\drivers\WdNisDrv.sys [47584] =>.Microsoft® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - Windows Error Reporting Kernel Driver.) -- C:\Windows\System32\drivers\werkernel.sys [41272] =>.Microsoft Windows® O58 - SDL:2019/06/11 20:43:26 A . (.Microsoft Corporation - WFP NDIS 6.30 Lightweight Filter Driver.) -- C:\Windows\System32\drivers\wfplwfs.sys [91656] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:14 A . (.Microsoft Corporation - Wim file system Driver.) -- C:\Windows\System32\drivers\wimmount.sys [31248] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:03 A . (.Microsoft Corporation - Windows Trusted Runtime Interface Driver.) -- C:\Windows\System32\drivers\WindowsTrustedRT.sys [55784] =>.Microsoft® O58 - SDL:2019/03/19 03:39:30 A . (.Microsoft Corporation - Windows Trusted Runtime Service Proxy Drive.) -- C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys [15336] =>.Microsoft® O58 - SDL:2019/03/19 03:41:16 A . (.Microsoft Corporation - Windows Hypervisor Interface Driver.) -- C:\Windows\System32\drivers\winhv.sys [26936] =>.Microsoft Windows® O58 - SDL:2019/09/26 15:34:15 A . (...) -- C:\Windows\System32\drivers\WinmonProcessMonitor.sys [28368] [Unsigned] =>Trojan.Agent O58 - SDL:2019/06/11 20:43:19 A . (.Microsoft Corporation - Pilote NAT Windows.) -- C:\Windows\System32\drivers\winnat.sys [195584] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:27 A . (.Microsoft Corporation - Windows QUIC Driver.) -- C:\Windows\System32\drivers\winquic.sys [164664] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:39:29 A . (.Microsoft Corporation - Windows WinUSB Class Driver.) -- C:\Windows\System32\drivers\winusb.sys [78848] [Unsigned] =>.Microsoft Corporation O58 - SDL:2018/05/11 15:37:44 A . (.HP - HP Wireless Button Driver.) -- C:\Windows\System32\drivers\WirelessButtonDriver86.sys [30848] =>.HP Inc.® O58 - SDL:2019/03/19 03:39:27 A . (.Microsoft Corporation - Windows Management Interface for ACPI.) -- C:\Windows\System32\drivers\wmiacpi.sys [12288] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - WMILIB WMI support library Dll.) -- C:\Windows\System32\drivers\wmilib.sys [17424] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:14 A . (.Microsoft Corporation - Filtre de superposition Windows.) -- C:\Windows\System32\drivers\wof.sys [177976] =>.Microsoft Windows® O58 - SDL:2019/03/19 08:18:57 A . (.Microsoft Corporation - Windows Portable Device Upper Class Filter.) -- C:\Windows\System32\drivers\WpdUpFltr.sys [24376] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:17 A . (.Microsoft Corporation - WPP Trace Recorder.) -- C:\Windows\System32\drivers\WppRecorder.sys [32776] =>.Microsoft Windows® O58 - SDL:2019/03/19 03:40:21 A . (.Microsoft Corporation - Couche IFS Winsock2.) -- C:\Windows\System32\drivers\ws2ifsl.sys [16896] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:36 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\drivers\WUDFPf.sys [87552] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:36 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\drivers\WUDFRd.sys [207360] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:20 A . (.Microsoft Corporation - Game Input Protocol Driver.) -- C:\Windows\System32\drivers\xboxgip.sys [254976] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:39:20 A . (.Microsoft Corporation - XINPUT filter driver for HID.) -- C:\Windows\System32\drivers\xinputhid.sys [36864] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:45 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\ANSI.SYS [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:45 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\country.sys [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:45 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\HIMEM.SYS [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:45 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\KEY01.SYS [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:45 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\KEYBOARD.SYS [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:46 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\NTDOS.SYS [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:46 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\NTDOS404.SYS [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:46 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\NTDOS411.SYS [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:46 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\NTDOS412.SYS [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:46 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\NTDOS804.SYS [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:46 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\NTIO.SYS [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:46 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\NTIO404.SYS [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:46 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\NTIO411.SYS [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:46 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\NTIO412.SYS [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:46 A . (.Microsoft Corporation - Windows Win16 Application Launcher.) -- C:\Windows\System32\NTIO804.SYS [8960] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:26 A . (.Microsoft Corporation - Full/Desktop Multi-User Win32 Driver.) -- C:\Windows\System32\win32k.sys [324096] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:24 A . (.Microsoft Corporation - Pilote du noyau Base Win32k.) -- C:\Windows\System32\win32kbase.sys [2066432] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/06/11 20:43:26 A . (.Microsoft Corporation - Full/Desktop Win32k Kernel Driver.) -- C:\Windows\System32\win32kfull.sys [2799616] [Unsigned] =>.Microsoft Corporation O58 - SDL:2019/03/19 03:40:02 A . (.Microsoft Corporation - Win32k non session driver.) -- C:\Windows\System32\win32kns.sys [20480] [Unsigned] =>.Microsoft Corporation ---\\ ASSOCIATION Shell Spawning (10) - 1s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe [Unsigned] =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe [Unsigned] =>.Microsoft Corporation O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft® O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- C:\Windows\System32\WScript.exe "%1" %* =>.Default.Value O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe [Unsigned] =>.Microsoft Corporation O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S =>.Default.Value ---\\ MENU DE DÉMARRAGE INTERNET (12) - 2s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google LLC® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files\Microsoft\Edge\Application\msedge.exe =>.Microsoft® O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google LLC O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Show IE Icon Utility.) -- C:\Windows\System32\ie4ushowIE.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google LLC O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google LLC O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Show IE Icon Utility.) -- C:\Windows\System32\ie4ushowIE.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation ---\\ RECHERCHE D'INFECTION SUR NAVIGATEURS (3) - 20s O69 - SBI: SearchScopes [HKCU]{ielnksrch} [DefaultScope] - (Search the web) - http://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/? =>SUP.Optional.Linkury O69 - SBI: SearchScopes [HKLM]ielnksrch - (Search the web) - http://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/? =>SUP.Optional.Linkury O69 - SBI: SearchScopes [HKLM]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com ---\\ ÉNUMÈRE LES SERVICES DÉMARRÉS PAR Svchost (49) - 14s O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [183296] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [183296] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [210944] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [1120256] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [738304] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [705024] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [24064] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114176] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [90624] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [657920] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [189952] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [347136] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [413184] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [88576] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\Windows\System32\XblGameSave.dll [788992] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL Windows Management Service.) -- C:\Windows\System32\Windows.Internal.Management.dll [645632] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: InstallService (InstallService) . (.Microsoft Corporation - InstallService.) -- C:\Windows\System32\InstallService.dll [1721344] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\Windows\System32\Windows.SharedPC.AccountManager.dll [169984] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: LxpSvc (LxpSvc) . (.Microsoft Corporation - Fournit une prise en charge de l'infrastruc.) -- C:\Windows\System32\LanguageOverlayServer.dll [223744] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: TroubleshootingSvc (TroubleshootingSvc) . (.Microsoft Corporation - MitigationClient.) -- C:\Windows\System32\MitigationClient.dll [306688] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: PushToInstall (PushToInstall) . (.Microsoft Corporation - PushToInstall.) -- C:\Windows\System32\PushToInstall.dll [193536] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: XboxGipSvc (XboxGipSvc) . (.Microsoft Corporation - Xbox Gip Management Service.) -- C:\Windows\System32\XboxGipSvc.dll [55296] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [126976] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Service Configuration du réseau.) -- C:\Windows\System32\NetSetupSvc.dll [230912] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\Windows\System32\DeviceSetupManager.dll [207360] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: WManSvc (WManSvc) . (.Microsoft Corporation - DLL du Service de gestion de Windows.) -- C:\Windows\System32\Windows.Management.Service.dll [594944] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\Windows\System32\NcaSvc.dll [140800] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\Windows\System32\XblAuthManager.dll [673280] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: NaturalAuthentication (NaturalAuthentication) . (.Microsoft Corporation - Service d’authentification naturelle.) -- C:\Windows\System32\NaturalAuth.dll [307712] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Service du système de notifications Push Wi.) -- C:\Windows\System32\WpnService.dll [224256] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [90112] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\Windows\System32\rasmans.dll [798720] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [403456] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [57344] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [531456] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [252416] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [1004032] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [197120] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service de géolocalisation.) -- C:\Windows\System32\lfsvc.dll [38912] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\Windows\System32\wlidsvc.dll [1662976] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Mettre à jour la session du service Orchest.) -- C:\Windows\System32\usosvc.dll [403456] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\Windows\System32\usermgr.dll [1068544] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\Windows\System32\XboxNetApiSvc.dll [1004032] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: TokenBroker (TokenBroker) . (.Microsoft Corporation - Broker à jetons.) -- C:\Windows\System32\TokenBroker.dll [1244672] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [53248] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Paramètres de vol.) -- C:\Windows\System32\flightsettings.dll [728576] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\Windows\System32\dmwappushsvc.dll [48128] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [160768] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [412160] [Unsigned] =>.Microsoft Corporation ---\\ LISTE DES EXCEPTIONS PAREFEU WINDOWS (32) - 21s O87 - FAEL: "{4F2DAB17-1FA1-4FAA-9D4C-160A1BBD04B1}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Mozilla Firefox\firefox.exe [Unsigned] (.not file.) =>.SUP.Orphan O87 - FAEL: "{7704A6BE-3298-4458-83E5-01C1EF3418F9}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Windows 10 Activator Ultimate 2019 1.0\Windows 10 Activator Ultimate 2019 1.0.exe [Unsigned] (.not file.) =>.SUP.Orphan O87 - FAEL: "{19631EEA-69DF-4411-B6D5-88C515E0CB5F}" [In-None-P6-TRUE] .(...) -- C:\Windows\rss\csrss.exe [Unsigned] =>Trojan.Dropper O87 - FAEL: "{38F466C9-99FD-4F00-A17B-086AD450F9DD}" [In-None-P6-TRUE] .(...) -- C:\Users\Admin\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe [Unsigned] (.not file.) =>Adware.MSIL O87 - FAEL: "TCP Query User{D050AB32-543C-4A67-B75D-5D1D43EDDFCF}C:\windows\files\bin\kmss.exe" [In-None-P6-TRUE] .(...) -- C:\windows\files\bin\kmss.exe [Unsigned] (.not file.) =>.SUP.Orphan O87 - FAEL: "UDP Query User{98621FF2-BAA7-41A2-8C1B-7E45DC07055D}C:\windows\files\bin\kmss.exe" [In-None-P17-TRUE] .(...) -- C:\windows\files\bin\kmss.exe [Unsigned] (.not file.) =>.SUP.Orphan O87 - FAEL: "TCP Query User{55CB4C6C-0042-410C-B8A7-6A23083E9F5E}C:\windows\files\bin\kmss.exe" [In-None-P6-TRUE] .(...) -- C:\windows\files\bin\kmss.exe [Unsigned] (.not file.) =>.SUP.Orphan O87 - FAEL: "UDP Query User{5080CDD6-99E6-491C-90EE-8692D18CF9D1}C:\windows\files\bin\kmss.exe" [In-None-P17-TRUE] .(...) -- C:\windows\files\bin\kmss.exe [Unsigned] (.not file.) =>.SUP.Orphan O87 - FAEL: "{525F4224-9035-4253-8392-47C551665350}" [In-None-P17-TRUE] .(...) -- C:\Users\karuna\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe [Unsigned] (.not file.) =>Adware.MSIL O87 - FAEL: "{9D497136-B0E3-4F47-82B1-78D0825FF5ED}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe [Unsigned] =>Trojan.Dropper O87 - FAEL: "{6550BFD4-D99C-464C-A4E2-3D5349489931}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe [Unsigned] =>Trojan.Dropper O87 - FAEL: "{3EB3EECC-3128-4891-AE7F-C4AFFD2D1A45}" [In-None-P17-TRUE] .(...) -- C:\Users\karuna\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe [Unsigned] (.not file.) =>Adware.MSIL O87 - FAEL: "{F6B5F559-394E-4EE2-8AAA-15BAABEB0B59}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe [Unsigned] =>Trojan.Dropper O87 - FAEL: "{36FC847F-768E-4B24-AEDB-4C2746FEA251}" [In-None-P17-TRUE] .(...) -- C:\Users\karuna\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe [Unsigned] (.not file.) =>Adware.MSIL O87 - FAEL: "{099D0143-3114-4DEA-9B86-5A5914A4982D}" [In-None-P17-TRUE] .(...) -- C:\Users\karuna\AppData\Roaming\87dd3c26406f\87dd3c26406f.exe [Unsigned] (.not file.) =>.SUP.Orphan O87 - FAEL: "{4359A4B0-D145-4139-B302-775F9D561ED2}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe [Unsigned] =>Trojan.Dropper O87 - FAEL: "{FDC59FCE-E421-4DB8-8836-D8B7927FEAA9}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe [Unsigned] =>Trojan.Dropper O87 - FAEL: "{7382945C-70BB-4CD7-9E6F-B98FECFB93F6}" [In-None-P17-TRUE] .(...) -- C:\Users\karuna\AppData\Roaming\87dd3c26406f\87dd3c26406f.exe [Unsigned] (.not file.) =>.SUP.Orphan O87 - FAEL: "{8998E9E0-4E78-468A-8736-7FD8496666BF}" [In-None-P17-TRUE] .(...) -- C:\Users\karuna\AppData\Roaming\87dd3c26406f\87dd3c26406f.exe [Unsigned] (.not file.) =>.SUP.Orphan O87 - FAEL: "{145B72A6-EACC-41F0-BA5F-BFCEDDB7700E}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe [Unsigned] =>Trojan.Dropper O87 - FAEL: "{6F6295FF-9B1C-4C0B-BF6F-E5057AED2B0F}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe [Unsigned] =>Trojan.Dropper O87 - FAEL: "{EF87AED9-D7DF-4679-A5A3-E3B1638FDA0C}" [In-None-P17-TRUE] .(...) -- C:\Users\karuna\AppData\Roaming\87dd3c26406f\87dd3c26406f.exe [Unsigned] (.not file.) =>.SUP.Orphan O87 - FAEL: "{F9ED30F6-9D4A-4C26-8E49-6B4393B6019D}" [In-None-P17-TRUE] .(...) -- C:\Users\karuna\AppData\Roaming\87dd3c26406f\87dd3c26406f.exe [Unsigned] (.not file.) =>.SUP.Orphan O87 - FAEL: "{D510B66E-7518-4AA5-AD73-0773F04D2B07}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe [Unsigned] =>Trojan.Dropper O87 - FAEL: "{4BF84853-6807-4235-AB4A-C6B08D32046A}" [In-None-P17-TRUE] .(...) -- C:\Users\karuna\AppData\Roaming\87dd3c26406f\87dd3c26406f.exe [Unsigned] (.not file.) =>.SUP.Orphan O87 - FAEL: "{7D233DC5-5E10-4031-8638-C5F2E81B7A66}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe [Unsigned] =>Trojan.Dropper O87 - FAEL: "{2B01B189-20D0-4CDF-AFD6-47838D6AE1BC}" [In-None-P17-TRUE] .(.HP Inc. - EWSProxy.) -- C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\bin\EWSProxy.exe =>.HP Inc® O87 - FAEL: "{13BEE30D-4AB6-446C-AC76-B9E278CA4208}" [In-None-P17-TRUE] .(.HP Inc. - DigitalWizards.) -- C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\bin\DigitalWizards.exe =>.HP Inc® O87 - FAEL: "{0A25AD7E-5CFD-4C37-8A17-1E5FD2124BE8}" [In-None-P17-TRUE] .(.HP Inc. - FaxPrinterUtility.) -- C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\bin\FaxPrinterUtility.exe =>.HP Inc® O87 - FAEL: "{33ADF503-B3DF-407C-A036-D2CEA742772A}" [In-None-P17-TRUE] .(.HP Inc. - DeviceSetup.exe.) -- C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\Bin\DeviceSetup.exe =>.HP Inc® O87 - FAEL: "{D854F0A6-ED1D-4389-9572-39C7058C6A51}" [In-None-P17-TRUE] .(.HP Inc. - HPNetworkCommunicatorCom.) -- C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\Bin\HPNetworkCommunicatorCom.exe =>.HP Inc® O87 - FAEL: "{E6FE5B6A-D206-4878-BF02-8BA7F6F5787A}" [In-None-P17-TRUE] .(.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google LLC® ---\\ CODES PRODUITS LOGICIELS (25) - 3s O90 - PUC: "00006109C80000000000000000F01FEC" [HKLM] . (.Office 16 Click-to-Run Extensibility Component.) =>.Microsoft Corporation O90 - PUC: "00006109C800C0400000000000F01FEC" [HKLM] . (.Office 16 Click-to-Run Localization Component.) =>.Microsoft Corporation O90 - PUC: "00006109E70000000000000000F01FEC" [HKLM] . (.Office 16 Click-to-Run Licensing Component.) =>.Microsoft Corporation O90 - PUC: "12B8D03ED28D112328CCF0A0D541598E" [HKLM] . (.Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40660.) =>.Microsoft Corporation O90 - PUC: "1800819049C276A4E85548380C917C2D" [HKLM] . (.Microsoft Encarta 2009 - Collection.) -- C:\Windows\Installer\{09180081-2C94-4A67-8E55-8483C019C7D2}\ENC.ICO =>.Microsoft Corporation O90 - PUC: "1D5E3C0FEDA1E123187686FED06E995A" [HKLM] . (.Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219.) =>.bl.org O90 - PUC: "26614AD8186F9F741B416975CF7599FE" [HKLM] . (.Windows Installer.) -- C:\Windows\Installer\{8DA41662-F681-47F9-B114-9657FC5799EF}\logo.exe =>.Microsoft Corporation O90 - PUC: "436F6625D7B77354DBCD89DDC6CFAB1A" [HKLM] . (.Online Application.) -- C:\Windows\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}\online.exe =>SUP.Optional.Microleaves O90 - PUC: "57451E932F32D54398775BCD749AE462" [HKLM] . (.Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706.) =>.Microsoft Corporation O90 - PUC: "6D02A6084CA56814BBFE15565B0D722E" [HKLM] . (.Nitro Pro.) -- C:\Windows\Installer\{806A20D6-5AC4-4186-BBEF-5165B5D027E2}\Professional.ico =>.Nitro O90 - PUC: "767742F45401F1C4790EBBE19C15AA33" [HKLM] . (.Étude pour l'amélioration du produit HP ColorLaserJet MFP M178-M181.) -- C:\Windows\Installer\{4F247767-1045-4C1F-97E0-BB1EC951AA33}\ARP_Icon =>.Hewlett-Packard O90 - PUC: "8520DAD7C5154DD39846DB1714990E7F" [HKLM] . (.Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40660.) =>.Microsoft Corporation O90 - PUC: "85DC1F0ADC2AB6B459140AB597A5D1D0" [HKLM] . (.HP Google Drive Plugin.) -- C:\Windows\Installer\{A0F1CD58-A2CD-4B6B-9541-A05B795A1D0D}\HPScan.ico =>.Google Inc. O90 - PUC: "87058A2575C4ECC40BABAB9FDBD82708" [HKLM] . (.HP Dropbox Plugin.) -- C:\Windows\Installer\{52A85078-4C57-4CCE-B0BA-BAF9BD8D7280}\HPScan.ico =>.WINSE O90 - PUC: "948E31A99B7C71142B93531D29808907" [HKLM] . (.HP EmailSMTP Plugin.) -- C:\Windows\Installer\{9A13E849-C7B9-4117-B239-35D192089870}\HPScan.ico =>.Hewlett-Packard O90 - PUC: "9AF592346E66C424FB3105EAA1BDAD69" [HKLM] . (.Logiciel de base du périphérique HP ColorLaserJet MFP M178-M181.) -- C:\Windows\Installer\{43295FA9-66E6-424C-BF13-50AE1ADBDA96}\ARP_Icon =>.Hewlett-Packard O90 - PUC: "A694757247E3A0230B706321A0F921D6" [HKLM] . (.Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706.) =>.Microsoft Corporation O90 - PUC: "AAFFD8D4460969C46AF5C6C0A59FAD08" [HKLM] . (.HP SharePoint Plugin.) -- C:\Windows\Installer\{4D8DFFAA-9064-4C96-A65F-6C0C5AF9DA80}\HPScan.ico =>.Hewlett-Packard O90 - PUC: "C025571B2A687A53689168CD7369889B" [HKLM] . (.Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030.) =>.Microsoft Corporation O90 - PUC: "CE48B736B42472345BDC0D7AFA02A5F0" [HKLM] . (.HP FTP Plugin.) -- C:\Windows\Installer\{637B84EC-424B-4327-B5CD-D0A7AF205A0F}\HPScan.ico =>.Hewlett-Packard O90 - PUC: "D20352A90C039D93DBF6126ECE614057" [HKLM] . (.Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17.) =>.bl.org O90 - PUC: "DC8A59DBF9D1DA5389A1E3975220E6BB" [HKLM] . (.Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030.) =>.Microsoft Corporation O90 - PUC: "EAEF4B0772CDAAE48839CC4E2A47C379" [HKLM] . (.HP OneDrive Plugin.) -- C:\Windows\Installer\{70B4FEAE-DC27-4EAA-8893-CCE4A2743C97}\HPScan.ico =>.Hewlett-Packard O90 - PUC: "EFC7B6CBBD6E56946B57774F18DC5D00" [HKLM] . (.HP Color LaserJet MFP M178-M181 Aide.) -- C:\Windows\Installer\{BC6B7CFE-E6DB-4965-B675-77F481CDD500}\ARPPRODUCTICON.exe =>.Hewlett-Packard O90 - PUC: "F3DA4203B9F2AF74FBE35D895D537A39" [HKLM] . (.I.R.I.S OCR.) ---\\ PACKAGES WINDOWS INSTALLER (13) - 14s [MD5.BAB85911E99F454B8231466E33969F7C] [WIS][2017/11/02 12:18:13] (.Microleaves - Online Application.) -- C:\Windows\Installer\1615503.msi [2806272] =>SUP.Optional.Microleaves [MD5.425E95273CB010D2E33D8BE17D68912C] [WIS][2020/02/21 09:21:42] (.AdvancedWindowsManager - Windows Installer.) -- C:\Windows\Installer\1b898a99.msi [3421184] =>SUP.Optional.Microleaves [MD5.C2B6995855EDC777AB7FD80E6AFE7BF8] [WIS][2020/01/22 18:58:56] (.HP Inc. - HP ColorLaserJet MFP M178-M181 Basic Device.) -- C:\Windows\Installer\c52cd.msi [4923392] =>.HP Inc. [MD5.41CA1DB79A5A236315EF578ABACE0AFA] [WIS][2020/01/22 18:59:02] (.HP - HP Scan Dropbox destination plugin.) -- C:\Windows\Installer\c52d1.msi [1560576] =>.HP [MD5.059BABAC6CEDB7BC57401295E77DC7D6] [WIS][2020/01/22 18:59:03] (.HP - HP Scan EmailSMTP destination plugin.) -- C:\Windows\Installer\c52d5.msi [2400256] =>.HP [MD5.4A1700A41F70E5119EDB56D183F7127F] [WIS][2020/01/22 18:59:03] (.HP - HP Scan FTP destination plugin.) -- C:\Windows\Installer\c52d9.msi [1863680] =>.HP [MD5.126921E9CB74B009D45EF7FAF2CF83B7] [WIS][2020/01/22 18:59:04] (.HP - HP Scan Google Drive destination plugin.) -- C:\Windows\Installer\c52dd.msi [1564672] =>.HP [MD5.593F021DF6F9652123DEE6885C2321D3] [WIS][2020/01/22 18:59:04] (.HP - HP Scan OneDrive destination plugin.) -- C:\Windows\Installer\c52e1.msi [1560576] =>.HP [MD5.09A72F5129632A230AB9353F7266320D] [WIS][2020/01/22 18:59:04] (.HP - HP Scan SharePoint destination plugin.) -- C:\Windows\Installer\c52e5.msi [1937408] =>.HP [MD5.95F801FF8A769C53765A2D583184FEFA] [WIS][2020/01/22 18:59:06] (.HP - HP Color LaserJet MFP M178-M181 Help.) -- C:\Windows\Installer\c52ea.msi [695296] =>.HP [MD5.EF81203833D0288978B3473E1157F82A] [WIS][2020/01/22 18:58:59] (.HP Inc. - I.R.I.S OCR.) -- C:\Windows\Installer\c52ef.msi [90112] =>.HP Inc. [MD5.987448BC36129FEDB65A39FE89052E5E] [WIS][2020/01/22 18:59:02] (.HP Inc. - Product Improvement Study for HP ColorLaser.) -- C:\Windows\Installer\c52f4.msi [294912] =>.HP Inc. [MD5.C71F9A212E884D44CC59E823998C0B25] [WIS][2016/10/14 03:38:53] (.Nitro - Nitro Pro 11.0.1.10.) -- C:\Windows\Installer\e56d8.msi [120840192] =>.Nitro ---\\ RECHERCHE DE CLÉS DE REGISTRE Tracing (4) - 6s HKLM\SOFTWARE\Microsoft\Tracing\CloudPrinter_RASAPI32 =>SUP.Optional.Linkury HKLM\SOFTWARE\Microsoft\Tracing\CloudPrinter_RASMANCS =>SUP.Optional.Linkury HKLM\SOFTWARE\Microsoft\Tracing\Quoteex_RASAPI32 =>PUP.Optional.Graftor HKLM\SOFTWARE\Microsoft\Tracing\Quoteex_RASMANCS =>PUP.Optional.Graftor ---\\ FEATURE CONTROL. (216) - 0s [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:infopath.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:UNPUXHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:msoasb.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:mbam.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:mbamtray.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:CCleaner.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPfewgsrv.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGUI.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGuiIT.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLgPad.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLOGON.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:Scale_for_R3.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:ieuser.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK]:YahooMusicEngine.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:devenv.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:dexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:helppane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS]:msfeedssync.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG]:msiexec.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:cs.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:waol.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:wm.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS]:helppane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS]:wlmail.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:mspub.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:winword.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:visio.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:winproj.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:powerpnt.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:outlook.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:onenote.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:excel.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:msaccess.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:outlook.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:sidebar.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING]:communicator.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msimn.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:winmail.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:msimn.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:outlook.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:winmail.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:infopath.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:winword.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:powerpnt.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:excel.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE]:HelpPane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_ENABLE_HTTP2]:mspub.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_ENABLE_HTTP2]:winword.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_ENABLE_HTTP2]:visio.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_ENABLE_HTTP2]:winproj.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_ENABLE_HTTP2]:powerpnt.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_ENABLE_HTTP2]:outlook.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_ENABLE_HTTP2]:onenote.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_ENABLE_HTTP2]:excel.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_ENABLE_HTTP2]:msoasb.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_ENABLE_HTTP2]:msaccess.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD]:msn.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:LICLUA.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OSE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:VSTOInstaller.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OSPPREARM.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:LICLUA.EXE =>.Legitimate ---\\ OBSERVATEURS des évènements (138) - 106s Application.Warning: AutoEnrollment (103) ~Numéro: 22901 ~Date: 02/14/2021 02:22:01 PM ~ID: 64 ~Description: Système local70 04 3c 28 93 39 60 37 92 da 92 8f 73 f5 50 86 60 3f bf 27 ~Suggestion: Installer le Kit de développement logiciel (SDK). Application.Error: Application Error (14) ~Numéro: 22874 ~Date: 02/14/2021 12:49:42 PM ~ID: 1000 ~Description: Nom de l’application défaillante %1, version : %2, horodatage : 0x68f17365 Nom du module défaillant : %4, version : %5, horodatage : 0x601fde60 Code d’exception : 0xc0000005 Décalage d’erreur : 0x0007e78d ID du processus défaillant : 0x22c4 Heure de ~Suggestion: Réparer ou réinstaller l'application. Application.Warning: Microsoft-Windows-AppModel-State (132) ~Numéro: 22852 ~Date: 02/13/2021 02:36:34 PM ~ID: 20 ~Description: LocalStateMicrosoft.MicrosoftEdge_8wekyb3d8bbwe-2147024894 ~Suggestion: Aucune Application.Warning: Windows Search Service (18) ~Numéro: 22407 ~Date: 02/06/2021 07:41:23 PM ~ID: 3036 ~Description: Impossible de terminer l’analyse dans la source de contenu <%2>.Contexte : Application , Catalogue SystemIndexDétails : Une erreur interne s’est produite dans les Services HTTP Microsoft Windows (HRESULT : 0x80072ee4) (0x80072ee4) ~Suggestion: https://www.repairwin.com/fix-windows-event-3036-search-content-source-cannot-accessed-solved/ Application.Error: Microsoft-Windows-CAPI2 (1) ~Numéro: 21727 ~Date: 02/03/2021 01:25:44 PM ~ID: 513 ~Description: Les services de chiffrement ont échoué lors du traitement de l’appel OnIdentity() dans l’objet System Writer.%1. Application.Warning: MsiInstaller (24) ~Numéro: 21622 ~Date: 02/03/2021 11:56:27 AM ~ID: 1015 ~Description: La connexion au serveur est impossible. Erreur : 0x800401F0 Application.Error: ESENT (22) ~Numéro: 21517 ~Date: 02/03/2021 11:39:22 AM ~ID: 482 ~Description: %1 (%2) %3Une tentative d’écriture dans le fichier « %4 » à l’adresse relative %5 de %6 octets a échoué après %10 secondes en indiquant l’erreur système %8 : « %9 ». L’opération d’écriture échouera en indiquant l’erreur %7. Si le problème persiste, c Application.Warning: Dwminit (1) ~Numéro: 21510 ~Date: 02/03/2021 11:21:32 AM ~ID: 0 ~Description: Le processus Gestionnaire de fenêtrage a été quitté. (Code de sortie du processus : %1, nombre de redémarrages : %2, ID de périphérique d’affichage principal : %3) ~Suggestion: Exécuter l'utilitaire de résolution des problèmes des applications Windows. Application.Warning: Chrome (2) ~Numéro: 21005 ~Date: 01/31/2021 04:03:30 PM ~ID: 256 ~Description: %1!S! Application.Warning: Microsoft-Windows-Spell-Checking (3) ~Numéro: 21004 ~Date: 01/31/2021 04:03:29 PM ~ID: 16 ~Description: Le fichier %1 n’est pas Unicode (UTF-16LE). Il a été déplacé vers %2. Application.Error: Application Hang (5) ~Numéro: 19758 ~Date: 01/17/2021 12:11:24 PM ~ID: 1002 ~Description: Le programme %1 version %2 a cessé d'interagir avec Windows et a été fermé. Pour voir si plus d'informations sur le problème sont disponibles, vérifiez l'historique des problèmes dans le Panneau de configuration Sécurité et maintenance. ID de proces ~Suggestion: Essayer les commandes suivantes ipconfig /release et ipconfig / renew. Application.Warning: Software Protection Platform Service (1) ~Numéro: 19179 ~Date: 01/12/2021 12:45:37 PM ~ID: 8233 ~Description: Le moteur de règles a signalé l’échec d’une tentative d’activation de licences en volume. Motif :0xC004F074 IdApp = %2, IdSku = 2ca2bf3f-949e-446a-82c7-e25a15ec78c4 Déclencheur=TimerEvent Application.Error: SideBySide (2) ~Numéro: 18150 ~Date: 12/27/2020 03:58:55 PM ~ID: 59 ~Description: La création du contexte d’activation a échoué pour « %11 ». Erreur dans le fichier de manifeste ou de stratégie « %12 » à la ligne %13. Syntaxe XML non valide. System.Warning: DCOM (269) ~Numéro: 29684 ~Date: 02/14/2021 03:09:08 PM ~ID: 10016 ~Description: par défaut de l’ordinateurLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}KARUNA007karunaS-1-5-21-1174500970-2113145075-2524796768-1001LocalHost (avec LRPC)Microsoft.Windows.ShellExperienceHost_10.0.18362.14 ~Suggestion: Vérifier les autorisations pour l'accès DCOM System.Error: Service Control Manager (21) ~Numéro: 29671 ~ID: 7031 ~Description: Le service %1 s’est terminé de manière inattendue. Ceci s’est produit %2 fois. L’action corrective suivante va être effectuée dans %3 millisecondes : %5. System.Error: TPM (66) ~Numéro: 29657 ~Date: 02/14/2021 12:44:50 PM ~ID: 15 ~Description: Le pilote de périphérique du module de plateforme sécurisée (TPM) a rencontré une erreur irrécupérable dans le matériel TPM, susceptible d’empêcher l’utilisation des services TPM (comme le chiffrement de données). Pour obtenir de l’aide, contactez le System.Warning: Microsoft-Windows-Kernel-Processor-Power (168) ~Numéro: 29624 ~Date: 02/12/2021 10:22:34 PM ~ID: 37 ~Description: La vitesse du processeur logique Hyper-V %2 est limitée par le microprogramme du système. Le processeur a connu cet état de performances réduites pendant %3 secondes depuis le dernier rapport. System.Error: BugCheck (37) ~Numéro: 29610 ~Date: 02/12/2021 10:22:07 PM ~ID: 1001 ~Description: 0x0000009f (0x00000004, 0x0000012c, 0x8e8a0900, 0x8482cdc4)C:\Windows\MEMORY.DMP9ff36a60-3139-4fe1-b6e7-962967f65564 System.Warning: Microsoft-Windows-Kernel-PnP (42) ~Numéro: 29584 ~Date: 02/12/2021 10:21:22 PM ~ID: 219 ~Description: Le chargement du pilote %5 a échoué pour le périphérique %2. ~Suggestion: Vérifier que le pilote a bien été chargé dans les informations système System.Error: EventLog (39) ~Numéro: 29570 ~Date: 02/12/2021 10:21:39 PM ~ID: 6008 ~Description: L’arrêt système précédant à %1 le %2 n’était pas prévu. System.Error: RasMan (1) ~Numéro: 29559 ~Date: 02/12/2021 09:59:53 PM ~ID: 20030 ~Description: Le Gestionnaire des connexions d’accès à distance n’a pas réussi à démarrer, car il n’a pas pu charger une ou plusieurs DLL de communication. Assurez-vous que votre matériel de communication est installé, puis redémarrez le service du Gestionnaire de System.Warning: Microsoft-Windows-DNS-Client (29) ~Numéro: 29496 ~Date: 02/12/2021 08:33:07 PM ~ID: 1014 ~Description: La résolution du nom %1 a expiré lorsqu’aucun des serveurs DNS configurés n’a répondu. ~Suggestion: https://social.technet.microsoft.com/wiki/contents/articles/3336.event-id-1014-microsoft-windows-dns-client.aspx System.Error: Microsoft-Windows-Kernel-General (1) ~Numéro: 28888 ~Date: 02/06/2021 07:27:51 PM ~ID: 6 ~Description: 0xc000014d118\??\C:\Users\Admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat System.Error: disk (1348) ~Numéro: 27545 ~Date: 02/01/2021 04:12:36 PM ~ID: 11 ~Description: Le pilote a détecté une erreur du contrôleur sur %1. System.Warning: BTHUSB (22) ~Numéro: 25763 ~Date: 01/29/2021 11:15:00 AM ~ID: 34 ~Description: La carte locale ne prend pas en charge un état de contrôleur Low Energy important pour la prise en charge du mode périphérique. Le masque d’état pris en charge requis au minimum est %2, a reçu %3. La fonctionnalité du rôle périphérique Low Energy n System.Error: Tcpip (1) ~Numéro: 25046 ~Date: 01/20/2021 10:38:10 AM ~ID: 4199 ~Description: Le système a détecté un conflit d’adresses pour l’adresse IP %2 avec le système d’adresse physique réseau %3. En conséquence les opérations réseau sur se système peuvent être interrompues. ---\\ SCAN ADDITIONNEL (82) - 20s HKLM\SYSTEM\CurrentControlSet\Services\9a3c1ac4a8bba090 =>Trojan.Agent C:\Windows\System32\drivers\9a3c1ac4a8bba090.sys =>Trojan.Agent C:\Program Files\AdvancedWindowsManager\Windows Installer\AdvancedWindowsManager.exe =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\AdvancedWindowsManager =>SUP.Optional.Microleaves C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\Online Application V2G5 =>SUP.Optional.Microleaves C:\Program Files\Microleaves\Online Application\Online Application Updater.exe =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\Updater_Online_Application =>SUP.Optional.Microleaves C:\Program Files\AdvancedWindowsManager\Windows Installer\Windows Updater.exe =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\AdvancedUpdater =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\Online Application V2G1 =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\Online Application V2G4 =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\Online Application V2G6 =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\Online Application V2G3 =>SUP.Optional.Microleaves C:\Windows\System32\Tasks\Online Application V2G2 =>SUP.Optional.Microleaves C:\Windows\rss\csrss.exe =>Trojan.Dropper C:\Windows\System32\Tasks\csrss =>Trojan.Dropper C:\Users\Admin\AppData\Roaming\87dd3c26406f\87dd3c26406f.exe =>Adware.MSIL HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ShutdownTime_is1 =>Adware.ICLoader HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1} =>SUP.Optional.Microleaves HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8DA41662-F681-47F9-B114-9657FC5799EF} =>SUP.Optional.Microleaves HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShutdownTime_is1 =>Adware.ICLoader HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1} =>SUP.Optional.Microleaves HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8DA41662-F681-47F9-B114-9657FC5799EF} =>SUP.Optional.Microleaves C:\Program Files\A6NPQWEG5J\uninstaller.exe =>Adware.Wizzcaster C:\Program Files\A6NPQWEG5J =>Adware.Wizzcaster C:\Program Files\CRLKA0ZK0D\uninstaller.exe =>Adware.Wizzcaster C:\Program Files\CRLKA0ZK0D =>Adware.Wizzcaster C:\Program Files\ShutdownTime =>Adware.Wizzcaster C:\ProgramData\AdvancedWindowsManager =>SUP.Optional.Microleaves C:\ProgramData\AppxeetouQ =>PUP.Optional.AppToU C:\ProgramData\AppxeetouQs =>PUP.Optional.AppToU C:\ProgramData\CloudPrinter =>SUP.Optional.Linkury C:\ProgramData\Logic Cramble =>PUP.Optional.LogicHandler C:\ProgramData\Microleaves =>SUP.Optional.Microleaves C:\ProgramData\Quoteex =>PUP.Optional.Graftor C:\ProgramData\Quoteexs =>PUP.Optional.Graftor C:\Users\Admin\AppData\Roaming\EpicNet Inc =>Adware.MSIL C:\Users\Admin\AppData\Roaming\Microleaves =>SUP.Optional.Microleaves C:\Users\Admin\AppData\Local\AdvinstAnalytics =>.SUP.Various C:\Windows\System32\drivers\WinmonProcessMonitor.sys =>Trojan.Agent HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch} =>SUP.Optional.Linkury HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\ielnksrch =>SUP.Optional.Linkury [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{19631EEA-69DF-4411-B6D5-88C515E0CB5F} =>Trojan.Dropper [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{38F466C9-99FD-4F00-A17B-086AD450F9DD} =>Adware.MSIL [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{525F4224-9035-4253-8392-47C551665350} =>Adware.MSIL [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{9D497136-B0E3-4F47-82B1-78D0825FF5ED} =>Trojan.Dropper [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{6550BFD4-D99C-464C-A4E2-3D5349489931} =>Trojan.Dropper [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{3EB3EECC-3128-4891-AE7F-C4AFFD2D1A45} =>Adware.MSIL [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{F6B5F559-394E-4EE2-8AAA-15BAABEB0B59} =>Trojan.Dropper [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{36FC847F-768E-4B24-AEDB-4C2746FEA251} =>Adware.MSIL [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{4359A4B0-D145-4139-B302-775F9D561ED2} =>Trojan.Dropper [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{FDC59FCE-E421-4DB8-8836-D8B7927FEAA9} =>Trojan.Dropper [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{145B72A6-EACC-41F0-BA5F-BFCEDDB7700E} =>Trojan.Dropper [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{6F6295FF-9B1C-4C0B-BF6F-E5057AED2B0F} =>Trojan.Dropper [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{D510B66E-7518-4AA5-AD73-0773F04D2B07} =>Trojan.Dropper [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{7D233DC5-5E10-4031-8638-C5F2E81B7A66} =>Trojan.Dropper C:\Windows\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}\online.exe =>SUP.Optional.Microleaves HKLM\SOFTWARE\Wow6432Node\Classes\Installer\Products\436F6625D7B77354DBCD89DDC6CFAB1A =>SUP.Optional.Microleaves HKLM\SOFTWARE\Wow6432Node\Classes\Installer\Features\436F6625D7B77354DBCD89DDC6CFAB1A =>SUP.Optional.Microleaves C:\Windows\Installer\1615503.msi =>SUP.Optional.Microleaves C:\Windows\Installer\1b898a99.msi =>SUP.Optional.Microleaves HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\CloudPrinter_RASAPI32 =>SUP.Optional.Linkury HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\CloudPrinter_RASMANCS =>SUP.Optional.Linkury HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quoteex_RASAPI32 =>PUP.Optional.Graftor HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quoteex_RASMANCS =>PUP.Optional.Graftor C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\File System\000 =>.SUP.Temporary.Chrome C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\File System\001 =>.SUP.Temporary.Chrome C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\File System\002 =>.SUP.Temporary.Chrome C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\File System\003 =>.SUP.Temporary.Chrome C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\File System\004 =>.SUP.Temporary.Chrome C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\File System\005 =>.SUP.Temporary.Chrome C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\File System\006 =>.SUP.Temporary.Chrome C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\File System\007 =>.SUP.Temporary.Chrome C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\File System\008 =>.SUP.Temporary.Chrome C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\File System\009 =>.SUP.Temporary.Chrome C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\File System\010 =>.SUP.Temporary.Chrome HKCU\Software\GCleaner =>.SUP.Various C:\Windows\windefender.exe =>Trojan.Agent C:\Windows\System32\Drivers\Winmon.sys =>Trojan.Agent C:\Windows\System32\Drivers\WinmonFS.sys =>Trojan.Agent C:\Windows\System32\Tasks\Auslogics\BoostSpeed =>SUP.Optional.AuslogicsBoostSpeed ---\\ RÉCAPITULATIF DES ÉLÉMENTS TROUVÉS (18) - 0s https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/ =>Trojan.Agent https://nicolascoolman.eu/2017/12/24/sup-microleaves/ =>SUP.Optional.Microleaves https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/ =>Trojan.Dropper https://nicolascoolman.eu/2017/09/12/origine-lignes-orphelines/ =>.SUP.Orphan https://nicolascoolman.eu/2017/09/13/adware-msil/ =>Adware.MSIL https://nicolascoolman.eu/2017/09/07/pup-optional-salus/ =>SUP.Optional.Linkury https://nicolascoolman.eu/2018/06/12/adware-icloader/ =>Adware.ICLoader https://nicolascoolman.eu/forum/Topic/auslogics-logiciel-potentiellement-superflu-lps/ =>SUP.Optional.Auslogics https://nicolascoolman.eu/2017/03/30/adware-graftor/ =>PUP.Optional.Graftor https://nicolascoolman.eu/forum/Topic/logiciels-potentiellement-superflus-lps/ =>.SUP.Various https://nicolascoolman.eu/2017/09/15/adware-wizzcaster/ =>Adware.Wizzcaster https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/ =>PUP.Optional.AppToU https://nicolascoolman.eu/2017/01/04/pup-optional-logichandler/ =>PUP.Optional.LogicHandler https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/ =>Rootkit.Necurs https://nicolascoolman.eu/forum/Topic/warning-eventlogapp-evenement-dapplication/ =>Warning.EventLogApp https://nicolascoolman.eu/forum/Topic/warning-eventlogsys-evenement-systeme/ =>Warning.EventLogSys https://nicolascoolman.eu/forum/Topic/logiciels-potentiellement-superflus-lps/ =>.SUP.Temporary.Chrome https://nicolascoolman.eu/2019/05/04/sup-auslogics-boostspeed/ =>SUP.Optional.AuslogicsBoostSpeed ---\\ NUMEROS DE SÉRIE [0162D526592B9173711119385E8C24DB] [08/09/2016] (.Nitro Software, Inc..) - C:\Program Files\Nitro\Pro 11\Nitro_UpdateService.exe =>.Nitro Software, Inc. [0162D526592B9173711119385E8C24DB] [08/09/2016] (.Nitro Software, Inc..) - C:\Program Files\Nitro\Pro 11\NitroPDF.exe =>.Nitro Software, Inc. [0162D526592B9173711119385E8C24DB] [08/09/2016] (.Nitro Software, Inc..) - C:\Program Files\Nitro\Pro 11\NitroPDFDriverService11.exe =>.Nitro Software, Inc. [0162D526592B9173711119385E8C24DB] [08/09/2016] (.Nitro Software, Inc..) - C:\Program Files\Nitro\Pro 11\NPShellExtension.dll =>.Nitro Software, Inc. [0162D526592B9173711119385E8C24DB] [08/09/2016] (.Nitro Software, Inc..) - C:\Windows\System32\NLSSRV32.EXE =>.Nitro Software, Inc. [02FA994D660DE659EE9037ECB437D766] [06/01/2021] (.Piriform Software Ltd.) - C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Software Ltd [02FA994D660DE659EE9037ECB437D766] [06/01/2021] (.Piriform Software Ltd.) - C:\Program Files\CCleaner\uninst.exe =>.Piriform Software Ltd [037E56A19D56788E01F12630951BF5CC] [22/01/2020] (.HP Inc.) - C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\Bin\DeviceSetup.exe =>.HP Inc [037E56A19D56788E01F12630951BF5CC] [22/01/2020] (.HP Inc.) - C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\bin\DigitalWizards.exe =>.HP Inc [037E56A19D56788E01F12630951BF5CC] [22/01/2020] (.HP Inc.) - C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\bin\EWSProxy.exe =>.HP Inc [037E56A19D56788E01F12630951BF5CC] [22/01/2020] (.HP Inc.) - C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\bin\FaxPrinterUtility.exe =>.HP Inc [037E56A19D56788E01F12630951BF5CC] [22/01/2020] (.HP Inc.) - C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\Bin\HP ColorLaserJet MFP M178-M181.exe =>.HP Inc [037E56A19D56788E01F12630951BF5CC] [22/01/2020] (.HP Inc.) - C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\Bin\HPNetworkCommunicatorCom.exe =>.HP Inc [037E56A19D56788E01F12630951BF5CC] [22/01/2020] (.HP Inc.) - C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\Bin\hpqDTSS.exe =>.HP Inc [037E56A19D56788E01F12630951BF5CC] [22/01/2020] (.HP Inc.) - C:\Program Files\HP\HP ColorLaserJet MFP M178-M181\Bin\HPScan.exe =>.HP Inc [037E56A19D56788E01F12630951BF5CC] [28/01/2021] (.HP Inc.) - C:\Users\Admin\Documents\Driver MFP M180n_LJM178-M181_UW_3_1_Full_WebPack_44.7.2712.exe =>.HP Inc [044E3BF58976880FFD074448A8F7A058] [27/12/2020] (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes\Anti-Malware\unins000.exe =>.Malwarebytes Corporation [044E3BF58976880FFD074448A8F7A058] [29/11/2017] (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe =>.Malwarebytes Corporation [044E3BF58976880FFD074448A8F7A058] [29/11/2017] (.Malwarebytes Corporation.) - C:\Windows\System32\drivers\mbae.sys =>.Malwarebytes Corporation [05FA56539456871559D29EE4082B71F8] [11/05/2018] (.HP Inc..) - C:\Windows\System32\drivers\WirelessButtonDriver86.sys =>.HP Inc. [06AEA76BAC46A9E8CFE6D29E45AAF033] [05/02/2021] (.Google LLC.) - C:\Program Files\Google\Update\1.3.36.72\GoogleCrashHandler.exe =>.Google LLC [06AEA76BAC46A9E8CFE6D29E45AAF033] [27/12/2020] (.Google LLC.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google LLC [0C15BE4A15BB0903C901B1D6C265302F] [04/02/2021] (.Google LLC.) - C:\Program Files\Google\Chrome\Application\88.0.4324.150\elevation_service.exe =>.Google LLC [0C15BE4A15BB0903C901B1D6C265302F] [04/02/2021] (.Google LLC.) - C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google LLC [0C15BE4A15BB0903C901B1D6C265302F] [10/02/2021] (.Google LLC.) - C:\Program Files\Google\Chrome\Application\88.0.4324.150\Installer\chrmstp.exe =>.Google LLC [0C15BE4A15BB0903C901B1D6C265302F] [10/02/2021] (.Google LLC.) - C:\Program Files\Google\Chrome\Application\88.0.4324.150\Installer\setup.exe =>.Google LLC [0C15BE4A15BB0903C901B1D6C265302F] [21/01/2021] (.Google LLC.) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\SwReporter\88.253.200\software_reporter_tool.exe =>.Google LLC [0F37E651F81D43B2A618664D80C4862D] [26/09/2019] (.BlockChain Advances Ltd.) - C:\Windows\System32\drivers\9a3c1ac4a8bba090.sys =>Trojan.Agent [1044F31AE1F93A0BB95F19AB9FAAC6BB] [10/02/2021] (.ESET, spol. s r.o..) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\SwReporter\88.253.200\edls_32.dll =>.ESET, spol. s r.o. [1044F31AE1F93A0BB95F19AB9FAAC6BB] [10/02/2021] (.ESET, spol. s r.o..) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\SwReporter\88.253.200\em000_32.dll =>.ESET, spol. s r.o. [1044F31AE1F93A0BB95F19AB9FAAC6BB] [10/02/2021] (.ESET, spol. s r.o..) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\SwReporter\88.253.200\em001_32.dll =>.ESET, spol. s r.o. [1044F31AE1F93A0BB95F19AB9FAAC6BB] [10/02/2021] (.ESET, spol. s r.o..) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\SwReporter\88.253.200\em005_32.dll =>.ESET, spol. s r.o. [3076987EC0BD5C2DAC3253BA1392737C] [06/03/2017] (.IMAGE RECOGNITION INTEGRATED SYSTEMS SA.) - C:\Program Files\HP\IdrsOCR_15.2.10.1114\IRISRegistrationApp.exe =>.IMAGE RECOGNITION INTEGRATED SYSTEMS SA [330000B7E741A34024FC3AB6E700020000B7E7] [07/12/2015] (.Intel(R) Wireless Display.) - C:\Windows\System32\drivers\intelaud.sys =>.Intel(R) Wireless Display [330000B7E741A34024FC3AB6E700020000B7E7] [07/12/2015] (.Intel(R) Wireless Display.) - C:\Windows\System32\drivers\iwdbus.sys =>.Intel(R) Wireless Display [330000B85395C584DD5249B00800020000B853] [01/04/2016] (.Intel(R) OWR.) - C:\Windows\System32\drivers\IntcDAud.sys =>.Intel(R) OWR [330000B898AA86B5A39E5A1BBD00020000B898] [27/08/2016] (.Intel(R) pGFX.) - C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_x86_772bc7bcc8c1c0c4\igdkmd32.sys =>.Intel(R) pGFX [330000B898AA86B5A39E5A1BBD00020000B898] [27/08/2016] (.Intel(R) pGFX.) - C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_x86_772bc7bcc8c1c0c4\igfxCUIService.exe =>.Intel(R) pGFX [330000B898AA86B5A39E5A1BBD00020000B898] [27/08/2016] (.Intel(R) pGFX.) - C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_x86_772bc7bcc8c1c0c4\IntelCpHDCPSvc.exe =>.Intel(R) pGFX [330000B898AA86B5A39E5A1BBD00020000B898] [27/08/2016] (.Intel(R) pGFX.) - C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_x86_772bc7bcc8c1c0c4\IntelCpHeciSvc.exe =>.Intel(R) pGFX [369FE1949CB565D9EC6EE9151A873149] [21/02/2020] (.MICROLEAVES LTD.) - C:\Program Files\AdvancedWindowsManager\Windows Installer\AdvancedWindowsManager.exe =>SUP.Optional.Microleaves [4C1A3D7C5BDAEF3E1166416AFE8138E9] [24/03/2016] (.Huawei Technologies Co.,Ltd..) - C:\Program Files\MobileBrServ\mbbservice.exe =>.Huawei Technologies Co.,Ltd. [4C1A3D7C5BDAEF3E1166416AFE8138E9] [24/03/2016] (.Huawei Technologies Co.,Ltd..) - C:\Program Files\MobileBrServ\uninstall.exe =>.Huawei Technologies Co.,Ltd. [529E3F9FCF7D58D520D607AB74395002] [28/01/2019] (.win.rar GmbH.) - C:\Program Files\WinRAR\Rar.exe =>.win.rar GmbH [529E3F9FCF7D58D520D607AB74395002] [28/01/2019] (.win.rar GmbH.) - C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH [529E3F9FCF7D58D520D607AB74395002] [28/01/2019] (.win.rar GmbH.) - C:\Program Files\WinRAR\uninstall.exe =>.win.rar GmbH [56000001757376CD78AD000C9A000000000175] [03/08/2018] (.Intel(R) Embedded Subsystems and IP Blocks Group.) - C:\Windows\System32\drivers\TeeDriverW8.sys =>.Intel(R) Embedded Subsystems and IP Blocks Group [65628C146ACE93037FC58659F14BD35F] [10/02/2021] (.ESET, spol. s r.o..) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\SwReporter\88.253.200\em002_32.dll =>.ESET, spol. s r.o. [65628C146ACE93037FC58659F14BD35F] [10/02/2021] (.ESET, spol. s r.o..) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\SwReporter\88.253.200\em003_32.dll =>.ESET, spol. s r.o. [65628C146ACE93037FC58659F14BD35F] [10/02/2021] (.ESET, spol. s r.o..) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\SwReporter\88.253.200\em004_32.dll =>.ESET, spol. s r.o. [72DCD35B1DBBF28F0F9848EC766A1BDF] [04/10/2018] (.Advanced Micro Devices, Inc..) - C:\Program Files\AMD\CCC2\Install\ccc2_install.exe =>.Advanced Micro Devices, Inc. [72DCD35B1DBBF28F0F9848EC766A1BDF] [04/10/2018] (.Advanced Micro Devices, Inc..) - C:\Windows\System32\DriverStore\FileRepository\ct334123.inf_x86_f8c501d7d775b475\B333740\atieclxx.exe =>.Advanced Micro Devices, Inc. [72DCD35B1DBBF28F0F9848EC766A1BDF] [04/10/2018] (.Advanced Micro Devices, Inc..) - C:\Windows\System32\DriverStore\FileRepository\ct334123.inf_x86_f8c501d7d775b475\B333740\atiesrxx.exe =>.Advanced Micro Devices, Inc. [72DCD35B1DBBF28F0F9848EC766A1BDF] [04/10/2018] (.Advanced Micro Devices, Inc..) - C:\Windows\System32\DriverStore\FileRepository\ct334123.inf_x86_f8c501d7d775b475\B333740\atikmdag.sys =>.Advanced Micro Devices, Inc. [72DCD35B1DBBF28F0F9848EC766A1BDF] [04/10/2018] (.Advanced Micro Devices, Inc..) - C:\Windows\System32\DriverStore\FileRepository\ct334123.inf_x86_f8c501d7d775b475\B333740\atikmpag.sys =>.Advanced Micro Devices, Inc. [7CD3DA2B7C277D2DF1261CB3BCABB96C] [02/11/2017] (.MICROLEAVES LTD.) - C:\Program Files\Microleaves\Online Application\Online Application Updater.exe =>SUP.Optional.Microleaves [7CD3DA2B7C277D2DF1261CB3BCABB96C] [02/11/2017] (.MICROLEAVES LTD.) - C:\Program Files\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe =>SUP.Optional.Microleaves ~ Unselected Options: O82, ~ End of the scan, 9400 items in 10mn55s (2008)(0)