~ ZHPDiag v2016.1.31.23 Par Nicolas Coolman (2016/01/30) ~ Démarré par Salah (Administrator) (2022/08/05 12:12:49) ~ Site: http://www.nicolascoolman.fr ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Etat de la version: Pas de fichier réseau ~ Mode: Scanner ~ Rapport: C:\Users\Salah\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\Salah\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ Démarrage du système: Normal (Normal boot) Windows 8.1 Pro, 64-bit (Build 9600) ---\\ Navigateurs Internet (3) - 1s GCIE: Google Chrome v103.0.5060.134 MFIE: Mozilla Firefox 102.0.1 (x64 en-US) MSIE: Internet Explorer v11.0.9600.20477 ---\\ Informations sur les produits Windows (8) - 0s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK ~ Windows(R) Operating System, RETAIL channel Windows ID Activation : OK ~ Windows Partial Key : WXBCY Windows License : OK ~ Windows Remaining Initializations Number : 1000 Windows Automatic Updates : OK ---\\ Logiciels de protection (1) - 16s Windows Defender (Deactivate) ---\\ Logiciels de protection et autres (Superflus) (1) - 17s SpyHunter v4.13.6.4253 ---\\ Surveillance de Logiciels (1) - 17s Adobe Acrobat Reader DC ---\\ Informations sur le système (6) - 0s ~ Operating System: Intel64 Family 6 Model 69 Stepping 1, GenuineIntel ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 4129.068 MB (16% free) System Restore: Activé (Enable) System drive C: has 15 GB () free of 159 GB =>Alerte espace disque inférieur à 20 Go ---\\ Mode de connexion au système (3) - 0s ~ Computer Name: SALAH ~ User Name: Salah ~ Logged in as Administrator ---\\ Enumération des unités disques (4) - 0s ~ Drive C: has 15 GB free of 159 GB (System) ~ Drive E: has 13 GB free of 67 GB ~ Drive F: has 31 GB free of 156 GB ~ Drive G: has 35 GB free of 92 GB ---\\ Etat du Centre de Sécurité Windows (11) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ---\\ Recherche particulière de fichiers génériques (25) - 2s [MD5.ED6B4C95E2A6D67480B9DBB8A8E7D9B4] - 27/08/2016 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [2755504] =>.Microsoft Windows® [MD5.6C308D32AFA41D26CE2A0EA8F7B79565] - 21/11/2014 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [54784] =>.Microsoft Corporation [MD5.D9516405E05F24EDCD90B1988FAF3948] - 14/01/2017 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [146944] =>.Microsoft Corporation [MD5.8FF82C7F2D30431FB66870E47A9CDA89] - 01/07/2022 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [4858880] =>.Microsoft Corporation [MD5.30B8FF833FB3D892DAB4827E00F530B2] - 31/07/2019 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [571392] =>.Microsoft Corporation [MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - 20/11/2014 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [447488] =>.Microsoft Corporation [MD5.162153407C84BE73A374D8EDC19D52C9] - 18/03/2021 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [656896] =>.Microsoft Corporation [MD5.E7AC2E85E8A46347EECC6A264A64AE24] - 18/03/2021 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\Syswow64\dnsapi.dll [499712] =>.Microsoft Corporation [MD5.E37F897ED7B5AFF79B1398258DB96BD9] - 20/11/2014 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [19456] =>.Microsoft Corporation [MD5.61E51A106389B469777BF631E24DDE6A] - 29/04/2022 - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\Windows\System32\drivers\AFD.sys [558592] =>.Microsoft Corporation [MD5.06CCC2EF0F9153D8BBCAEC38633F49AF] - 21/09/2021 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [26896] {33000002ED2C45E4C145CF48440000000002ED} =>.Microsoft Corporation [MD5.C17B61862B3C0D795A3FC68622D6729B] - 09/02/2019 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [88576] =>.Microsoft Corporation [MD5.49258DBF1106BB617D3A446E9E06B61A] - 10/02/2022 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [165376] =>.Microsoft Corporation [MD5.D1049D4D1311D43F6FCF180CAA5BF78B] - 02/01/2018 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [138752] =>.Microsoft Corporation [MD5.D4B7ED39C7900384D9E5C1283F1E7926] - 21/11/2014 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [76800] =>.Microsoft Corporation [MD5.49EE0AE9E5B64FFBBD06D55C4984B598] - 04/11/2014 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [108544] =>.Microsoft Corporation [MD5.7F7C7A956FA188FBFD5FD0A17AB06188] - 23/06/2022 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [142336] =>.Microsoft Corporation [MD5.BC33794017D8A34BF49825B628F16FAE] - 16/05/2022 - (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\Windows\System32\drivers\MRxSmb.sys [402944] =>.Microsoft Corporation [MD5.4B83CD148138302CBC1E0ED0A8094F2F] - 15/09/2020 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [281088] =>.Microsoft Corporation [MD5.7B728234C1665DC5777193B169135463] - 10/05/2022 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [2012464] {330000033C89C66A7B45BB1FBD00000000033C} =>.Microsoft Corporation [MD5.57DCE4FB0467986AE78E1C6FC5240D32] - 11/08/2016 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [96256] =>.Microsoft Corporation [MD5.F9C180ABACAECAD81CCE519127C36E10] - 13/06/2022 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [112640] =>.Microsoft Corporation [MD5.57B60DC668977AF0F806F25F525CE1D5] - 11/07/2019 - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\Windows\System32\drivers\rdpdr.sys [195072] =>.Microsoft Corporation [MD5.5B0C9698FCEC17593E2D3F9DFBC5C004] - 06/08/2021 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [107520] =>.Microsoft Corporation [MD5.17F7B0F2298D97F4B6C7A69511033D3D] - 14/03/2016 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [316760] =>.Microsoft Windows® ---\\ Liste des services NT non Microsoft et non désactivés (13) - 5s O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Inc. - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe {011F39A2261A993DD15176DA6FE4FBEA} O23 - Service: AVG Antivirus (AVG Antivirus) . (.AVG Technologies CZ, s.r.o. - AVG Service.) - C:\Program Files\AVG\Antivirus\AVGSvc.exe {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. O23 - Service: AVG Tools (AVG Tools) . (.AVG Technologies CZ, s.r.o. - AVG Antivirus.) - C:\Program Files\AVG\Antivirus\avgToolsSvc.exe {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. O23 - Service: (AvgWscReporter) . (.AVG Technologies CZ, s.r.o. - AVG remediation exe.) - C:\Program Files\AVG\Antivirus\wsc_proxy.exe {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O23 - Service: ComboCleaner.Guard (ComboCleaner.Guard) . (.RCS LT - ComboCleaner.Guard.) - C:\Program Files (x86)\Combo Cleaner\ComboCleaner.Guard.exe {077C2D20443D4B34CFB3B739A08B3B33} O23 - Service: ComboCleaner.WinService (ComboCleaner.WinService) . (.RCS LT - ComboCleaner.WinService.) - C:\Program Files (x86)\Combo Cleaner\ComboCleaner.WinService.exe {077C2D20443D4B34CFB3B739A08B3B33} O23 - Service: EaseUS UPDATE SERVICE (EaseUS UPDATE SERVICE) . (...) - C:\Program Files (x86)\EaseUS\ENS\ensserver.exe {0686ED403EC1BF441C8F335C841EEA00} O23 - Service: SpyHunter 5 Kernel (EsgShKernel) . (.EnigmaSoft Limited - SpyHunter product..) - C:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exe {0A64EFC7170E63B64A6E390EEB577FE9} =>.Superfluous.SpyHunter O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google LLC - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe {06AEA76BAC46A9E8CFE6D29E45AAF033} O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) . (...) - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (.not file.) O23 - Service: Malwarebytes Service (MBAMService) . (.Malwarebytes - Malwarebytes Service.) - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe {00A657F778B31AE523D667131718D16EB2} =>.Malwarebytes O23 - Service: SpyHunter 5 Kernel Monitor (ShMonitor) . (.EnigmaSoft Limited - SpyHunter product..) - C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe {0A64EFC7170E63B64A6E390EEB577FE9} =>.Superfluous.SpyHunter O23 - Service: SpyHunter 4 Service (SpyHunter 4 Service) . (.Enigma Software Group USA, LLC. - Service scanner interface.) - C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe =>.Superfluous.SpyHunter ---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (27) - 47s SR - Auto [17/11/2021] [ 169728] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Inc..) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe {011F39A2261A993DD15176DA6FE4FBEA} SR - Auto [02/08/2022] [ 625960] AVG Antivirus (AVG Antivirus) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files\AVG\Antivirus\AVGSvc.exe {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. SR - Auto [02/08/2022] [ 625448] AVG Tools (AVG Tools) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files\AVG\Antivirus\avgToolsSvc.exe {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. SS - Demand [02/08/2022] [ 8543840] avgbIDSAgent (avgbIDSAgent) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files\AVG\Antivirus\aswidsagent.exe {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. SR - Auto [02/08/2022] [ 109480] (AvgWscReporter) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files\AVG\Antivirus\wsc_proxy.exe {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. SR - Demand [16/08/2021] [ 162456] Service Brave Update (brave) (brave) . (.BraveSoftware Inc..) - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe {05488AD7E4BABA7F93E3323C0573BF3C} SS - Demand [16/08/2021] [ 162456] Service Brave Update (bravem) (bravem) . (.BraveSoftware Inc..) - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe {05488AD7E4BABA7F93E3323C0573BF3C} SS - Demand [24/07/2022] [ 74056] @C:\Program Files (x86)\Google\Chrome Remote Desktop\105.0. (chromoting) . (.Google LLC.) - C:\Program Files (x86)\Google\Chrome Remote Desktop\105.0.5195.5\remoting_host.exe {0E4418E2DEDE36DD2974C3443AFB5CE5} SS - Auto [05/11/2021] [ 143488] ComboCleaner.Guard (ComboCleaner.Guard) . (.RCS LT.) - C:\Program Files (x86)\Combo Cleaner\ComboCleaner.Guard.exe {077C2D20443D4B34CFB3B739A08B3B33} SS - Auto [05/11/2021] [ 151168] ComboCleaner.WinService (ComboCleaner.WinService) . (.RCS LT.) - C:\Program Files (x86)\Combo Cleaner\ComboCleaner.WinService.exe {077C2D20443D4B34CFB3B739A08B3B33} SS - Disabl [10/08/2021] [ 397688] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe {5600000C3BF9A3682289A06F40000000000C3B} =>.Intel Corporation SR - Auto [15/11/2021] [ 27784] EaseUS UPDATE SERVICE (EaseUS UPDATE SERVICE) . (...) - C:\Program Files (x86)\EaseUS\ENS\ensserver.exe {0686ED403EC1BF441C8F335C841EEA00} SR - Auto [25/07/2022] [17435528] SpyHunter 5 Kernel (EsgShKernel) . (.EnigmaSoft Limited.) - C:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exe {0A64EFC7170E63B64A6E390EEB577FE9} =>.Superfluous.SpyHunter SS - Demand [18/07/2022] [ 1646920] Google Chrome Elevation Service (GoogleChromeElevationServi (GoogleChromeElevationService) . (.Google LLC.) - C:\Program Files\Google\Chrome\Application\103.0.5060.134\elevation_service.exe {0E4418E2DEDE36DD2974C3443AFB5CE5} SR - Auto [08/08/2021] [ 156232] Service Google Update (gupdate) (gupdate) . (.Google LLC.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe {06AEA76BAC46A9E8CFE6D29E45AAF033} SS - Demand [08/08/2021] [ 156232] Service Google Update (gupdatem) (gupdatem) . (.Google LLC.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe {06AEA76BAC46A9E8CFE6D29E45AAF033} SS - Disabl [10/08/2021] [ 352624] Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation.) - C:\Windows\System32\igfxCUIService.exe =>.Intel Corporation SS - Demand [02/12/2021] [ 375440] Kaspersky Password Manager Service (kpm_launch_service) . (.AO Kaspersky Lab.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe {067CE8A9F2E02AC7D49304F85E9474E1} =>.AO Kaspersky Lab SS - Demand [02/07/2021] [ 447104] Kaspersky VPN Secure Connection Service 5.3 (KSDE5.3) . (.AO Kaspersky Lab.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.3\ksde.exe {013C6684E0F39030C05FA36B42AF33CA} =>.AO Kaspersky Lab SR - Auto [31/07/2022] [ 8680192] Malwarebytes Service (MBAMService) . (.Malwarebytes.) - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe {00A657F778B31AE523D667131718D16EB2} =>.Malwarebytes SS - Disabl [24/07/2022] [ 232824] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe {0C1CD3EEA47EDDA7A032573B014D0AFD} =>.Mozilla Foundation SS - Demand [10/04/2022] [ 269616] Realtek Audio Service (RtkAudioService) . (.Realtek Semiconductor.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe {045D9B6716C516EF45A1216DFD9F3060} =>.Realtek Semiconductor SR - Auto [25/07/2022] [ 533896] SpyHunter 5 Kernel Monitor (ShMonitor) . (.EnigmaSoft Limited.) - C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe {0A64EFC7170E63B64A6E390EEB577FE9} =>.Superfluous.SpyHunter SR - Auto [07/05/2013] [ 770432] SpyHunter 4 Service (SpyHunter 4 Service) . (.Enigma Software Group USA, LLC..) - C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe =>.Superfluous.SpyHunter SS - Demand [11/09/2017] [ 33224] SHAREit Hotspot Service (uSHAREitSvc) . (.SHAREit Technologies Co.Ltd.) - C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.Service.exe {3E04076D4B53A8436FD2665B5029C627} SR - Demand [12/08/2021] [ 1300352] (WindscribeService) . (.Windscribe Limited.) - C:/Program Files (x86)/Windscribe/WindscribeService.exe {0F5EE43BEEA50ED5F0EC765BF65B1350} ---\\ Tâches planifiées en automatique (31) - 7s [MD5.94BDBDBE803CFB6D0AE5F2B5E79AF789] [APT] [Adobe Acrobat Update Task] (.Adobe Inc..) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564424] {011F39A2261A993DD15176DA6FE4FBEA} [MD5.9D417AA752B8BE318D9EDC551D604516] [APT] [Antivirus Emergency Update] (.AVG Technologies CZ, s.r.o..) -- C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [4965672] {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. [MD5.00000000000000000000000000000000] [APT] [ASC_PerformanceMonitor] (...) -- C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe (.not file.) [0] [MD5.F03A53B0E5E11909962854C3F04E10F7] [APT] [BraveSoftwareUpdateTaskMachineCore] (.BraveSoftware Inc..) -- C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162456] {05488AD7E4BABA7F93E3323C0573BF3C} =>PUP.Optional.Boxore [MD5.F03A53B0E5E11909962854C3F04E10F7] [APT] [BraveSoftwareUpdateTaskMachineUA] (.BraveSoftware Inc..) -- C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162456] {05488AD7E4BABA7F93E3323C0573BF3C} =>PUP.Optional.Boxore [MD5.DED6DFE4CA4C85EE1F762A34C5C09CBE] [APT] [Driver Booster Scheduler] (.IObit.) -- C:\Program Files (x86)\IObit\Driver Booster\9.3.0\Scheduler.exe [156696] {008BA1F172FD50BA8D4C11B74FFAC8A282} =>.IObit [MD5.AD725B6408337A34228E56CD54426BE4] [APT] [Driver Booster SkipUAC (Salah)] (.IObit.) -- C:\Program Files (x86)\IObit\Driver Booster\9.3.0\DriverBooster.exe [8662600] {008BA1F172FD50BA8D4C11B74FFAC8A282} =>.IObit [MD5.61FD206F904C8FA8A41C0621A652D37E] [APT] [Driver Booster Update] (.IObit.) -- C:\Program Files (x86)\IObit\Driver Booster\9.3.0\AutoUpdate.exe [2462744] {008BA1F172FD50BA8D4C11B74FFAC8A282} =>.IObit [MD5.A48C3952A1385226E286C3750BA9627E] [APT] [DualSafe Password Manager Init SkipUAC(Salah)] (.iTop Inc..) -- C:\Program Files (x86)\DualSafe Password Manager\DPMInit.exe [2927432] {031C59BCEE5E23FC713C1FF882CE5668} [MD5.A48C3952A1385226E286C3750BA9627E] [APT] [DualSafe Password Manager Task] (.iTop Inc..) -- C:\Program Files (x86)\DualSafe Password Manager\DPMInit.exe [2927432] {031C59BCEE5E23FC713C1FF882CE5668} [MD5.5A25AEBDD889EFDA40F2A57297A32422] [APT] [GoogleUpdateTaskMachineCore] (.Google LLC.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232] {06AEA76BAC46A9E8CFE6D29E45AAF033} [MD5.5A25AEBDD889EFDA40F2A57297A32422] [APT] [GoogleUpdateTaskMachineUA] (.Google LLC.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232] {06AEA76BAC46A9E8CFE6D29E45AAF033} [MD5.8D378511687195B80BF1D824A63F9999] [APT] [klcp_update] (...) -- C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1907712] [MD5.00000000000000000000000000000000] [APT] [SpyHunter4Startup] (...) -- C:\Program Files (x86)\Enigma Software Group\SpyHunter\Spyhunter4.exe (.not file.) [0] =>.Superfluous.Enigma [MD5.84786123B44E1C871A458403C82519AE] [APT] [Sump Task (One-Time)] (.IObit.) -- C:\Program Files (x86)\IObit\Advanced SystemCare\sump.exe [1795832] {008BA1F172FD50BA8D4C11B74FFAC8A282} =>.IObit [MD5.F6581588A946EBBA00E69E8779DE5357] [APT] [AVG\Overseer] (.AVG Technologies.) -- C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2287472] {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies O39 - APT: Adobe Acrobat Update Task - (.Adobe Inc..) -- C:\Windows\System32\Tasks\Adobe Acrobat Update Task [4476] O39 - APT: Antivirus Emergency Update - (.AVG Technologies CZ, s.r.o..) -- C:\Windows\System32\Tasks\Antivirus Emergency Update [3904] =>.AVG Technologies CZ, s.r.o. O39 - APT: ASC_PerformanceMonitor - (...) -- C:\Windows\System32\Tasks\ASC_PerformanceMonitor [3202] (.Orphean.) O39 - APT: BraveSoftwareUpdateTaskMachineCore - (.BraveSoftware Inc..) -- C:\Windows\System32\Tasks\BraveSoftwareUpdateTaskMachineCore [3384] =>PUP.Optional.Boxore O39 - APT: BraveSoftwareUpdateTaskMachineUA - (.BraveSoftware Inc..) -- C:\Windows\System32\Tasks\BraveSoftwareUpdateTaskMachineUA [3512] =>PUP.Optional.Boxore O39 - APT: Driver Booster Scheduler - (.IObit.) -- C:\Windows\System32\Tasks\Driver Booster Scheduler [3088] =>.IObit O39 - APT: Driver Booster SkipUAC (Salah) - (.IObit.) -- C:\Windows\System32\Tasks\Driver Booster SkipUAC (Salah) [3188] =>.IObit O39 - APT: Driver Booster Update - (.IObit.) -- C:\Windows\System32\Tasks\Driver Booster Update [3080] =>.IObit O39 - APT: DualSafe Password Manager Init SkipUAC(Salah) - (.iTop Inc..) -- C:\Windows\System32\Tasks\DualSafe Password Manager Init SkipUAC(Salah) [3010] O39 - APT: DualSafe Password Manager Task - (.iTop Inc..) -- C:\Windows\System32\Tasks\DualSafe Password Manager Task [3264] O39 - APT: GoogleUpdateTaskMachineCore - (.Google LLC.) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [3376] O39 - APT: GoogleUpdateTaskMachineUA - (.Google LLC.) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [3504] O39 - APT: klcp_update - (...) -- C:\Windows\System32\Tasks\klcp_update [3242] O39 - APT: SpyHunter4Startup - (...) -- C:\Windows\System32\Tasks\SpyHunter4Startup [3332] (.Orphean.) =>.Superfluous.Enigma O39 - APT: Sump Task (One-Time) - (.IObit.) -- C:\Windows\System32\Tasks\Sump Task (One-Time) [3256] =>.IObit ---\\ Processus lancés (67) - 18s [MD5.85CD5B92052C3D285CC91244C593A1AC] - (.Enigma Software Group USA, LLC. - Service scanner interface.) -- C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe [770432] [PID.944] =>.Superfluous.SpyHunter [MD5.437A1C97D7A8A11006C4458408DE4A9E] - (.Adobe Inc. - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728] [PID.1348] {011F39A2261A993DD15176DA6FE4FBEA} [MD5.7A7CE854A3DC44D92AD12D901A8EB262] - (...) -- C:\Program Files (x86)\EaseUS\ENS\ensserver.exe [27784] [PID.1652] {0686ED403EC1BF441C8F335C841EEA00} [MD5.B0F4846466C6F8301094CFBC7B21B937] - (.EnigmaSoft Limited - SpyHunter product..) -- C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe [533896] [PID.1784] {0A64EFC7170E63B64A6E390EEB577FE9} =>.Superfluous.SpyHunter [MD5.567234C51B41589821559B3EFD76C81D] - (.Malwarebytes - Malwarebytes Service.) -- C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8680192] [PID.2028] {00A657F778B31AE523D667131718D16EB2} =>.Malwarebytes [MD5.B6B844CBA41F7C190A001941A9A34E9A] - (.Google LLC - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler.exe [306872] [PID.3448] {06AEA76BAC46A9E8CFE6D29E45AAF033} [MD5.71E73162F75EF1C1094F8E8AC5E9BED3] - (.Google LLC - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler64.exe [405688] [PID.3456] {06AEA76BAC46A9E8CFE6D29E45AAF033} [MD5.2F178DBA2EE3A15B5A821F36FBB15AAD] - (.Windscribe Limited - Manages the firewall and controls the VPN t.) -- C:\Program Files (x86)\Windscribe\WindscribeService.exe [1300352] [PID.4208] {0F5EE43BEEA50ED5F0EC765BF65B1350} [MD5.75CA8458D560E6F26A7EE0475E650458] - (.AVG Technologies CZ, s.r.o. - AVG remediation exe.) -- C:\Program Files\AVG\Antivirus\wsc_proxy.exe [109480] [PID.3712] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. [MD5.52D90C8C1C2D4ADC0100696571CF972A] - (.AVG Technologies CZ, s.r.o. - AVG Service.) -- C:\Program Files\AVG\Antivirus\AVGSvc.exe [625960] [PID.4644] {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. [MD5.ADD0D51C8D6B5D4182EC00D87767345A] - (.AVG Technologies CZ, s.r.o. - AVG Antivirus.) -- C:\Program Files\AVG\Antivirus\avgToolsSvc.exe [625448] [PID.7756] {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. [MD5.0037D0CED407AEEF9CB19D012528581A] - (.AVG Technologies CZ, s.r.o. - AVG Antivirus engine server.) -- C:\Program Files\AVG\Antivirus\aswEngSrv.exe [668968] [PID.7308] {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. [MD5.5A25AEBDD889EFDA40F2A57297A32422] - (.Google LLC - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232] [PID.3288] {06AEA76BAC46A9E8CFE6D29E45AAF033} [MD5.A51D4A05996CA71B377C3A4CD5B3C70D] - (.Malwarebytes - Malwarebytes Tray Application.) -- C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe [7458872] [PID.4380] {00A657F778B31AE523D667131718D16EB2} =>.Malwarebytes [MD5.5A25AEBDD889EFDA40F2A57297A32422] - (.Google LLC - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232] [PID.5948] {06AEA76BAC46A9E8CFE6D29E45AAF033} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.5344] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.7220] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.9352] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.8908] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.4592] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.9960] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.1496] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.1924] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.9788] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.8548] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.7544] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.8496] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.8944] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.8196] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.4816] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.5888] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.6548] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.C8595C17B7AE1BBFEA6B86C8497DEEFE] - (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11102816] [PID.8792] {0BFCFAC08E216A1C1FDAA6B77BB2D66E} =>.Realtek Semiconductor [MD5.BA0EADEF9FA3D5D378B964ABF5CE4C49] - (.Windscribe Limited - Windscribe GUI.) -- C:\Program Files (x86)\Windscribe\Windscribe.exe [5461888] [PID.9552] {0F5EE43BEEA50ED5F0EC765BF65B1350} [MD5.D8D059CBEEE92089630FF27A7662ED76] - (.AVG Technologies CZ, s.r.o. - AVG Antivirus.) -- C:\Program Files\AVG\Antivirus\AVGUI.exe [18715944] [PID.9728] {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. [MD5.51A9CAC9C4E8DA44FFD7502BE17604EE] - (.Google - Software Reporter Tool.) -- C:\Users\Salah\AppData\Local\Google\Chrome\User Data\SwReporter\102.286.200\software_reporter_tool.exe [14687048] [PID.5188] {0E4418E2DEDE36DD2974C3443AFB5CE5} =>.Google [MD5.51A9CAC9C4E8DA44FFD7502BE17604EE] - (.Google - Software Reporter Tool.) -- c:\Users\Salah\AppData\Local\Google\Chrome\user data\swreporter\102.286.200\software_reporter_tool.exe [14687048] [PID.5504] {0E4418E2DEDE36DD2974C3443AFB5CE5} =>.Google [MD5.688289773E52BD5A05D3131A5008A518] - (.Windscribe Limited - Windscribe Engine.) -- C:\Program Files (x86)\Windscribe\WindscribeEngine.exe [4709248] [PID.6928] {0F5EE43BEEA50ED5F0EC765BF65B1350} [MD5.51A9CAC9C4E8DA44FFD7502BE17604EE] - (.Google - Software Reporter Tool.) -- c:\Users\Salah\AppData\Local\Google\Chrome\user data\swreporter\102.286.200\software_reporter_tool.exe [14687048] [PID.2352] {0E4418E2DEDE36DD2974C3443AFB5CE5} =>.Google [MD5.D8D059CBEEE92089630FF27A7662ED76] - (.AVG Technologies CZ, s.r.o. - AVG Antivirus.) -- C:\Program Files\AVG\Antivirus\AVGUI.exe [18715944] [PID.7408] {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. [MD5.D8D059CBEEE92089630FF27A7662ED76] - (.AVG Technologies CZ, s.r.o. - AVG Antivirus.) -- C:\Program Files\AVG\Antivirus\AVGUI.exe [18715944] [PID.2044] {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. [MD5.D8D059CBEEE92089630FF27A7662ED76] - (.AVG Technologies CZ, s.r.o. - AVG Antivirus.) -- C:\Program Files\AVG\Antivirus\AVGUI.exe [18715944] [PID.9384] {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. [MD5.0DF14C520291989038F242A4A39AE22B] - (.Tonec Inc. - Internet Download Manager Native Messaging.) -- C:\Program Files (x86)\Internet Download Manager\IDMMsgHost.exe [39168] [PID.7628] {06C5078AA528BBD3B8668AB10B035F94} =>.Tonec Inc. [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.4672] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.7876] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.51A9CAC9C4E8DA44FFD7502BE17604EE] - (.Google - Software Reporter Tool.) -- c:\Users\Salah\AppData\Local\Google\Chrome\user data\swreporter\102.286.200\software_reporter_tool.exe [14687048] [PID.4964] {0E4418E2DEDE36DD2974C3443AFB5CE5} =>.Google [MD5.5A25AEBDD889EFDA40F2A57297A32422] - (.Google LLC - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232] [PID.2204] {06AEA76BAC46A9E8CFE6D29E45AAF033} [MD5.69CF9EDD97C07C51E62158E636C3AAAD] - (.Google LLC - Google Chrome Installer.) -- C:\Program Files (x86)\Google\Update\Install\{40D27826-CC91-4D78-B28E-600C6262F4CE}\104.0.5112.79_103.0.5060.134_chrome_updater.exe [34966616] [PID.3804] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.1DEDB5C1D41B3F1FF020551F144DEA02] - (.Adobe Systems Incorporated - Adobe RdrCEF.) -- C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\acrocef_1\RdrCEF.exe [6474240] [PID.5956] {045296F8FCD829A75DC94294F5A415A4} =>.Adobe Systems Incorporated [MD5.3CEBA5314C4416EDC42730F29F97986A] - (.Google LLC - Google Chrome Installer.) -- C:\Program Files (x86)\Google\Update\Install\{40D27826-CC91-4D78-B28E-600C6262F4CE}\CR_80A47.tmp\setup.exe [4560200] [PID.6328] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.3CEBA5314C4416EDC42730F29F97986A] - (.Google LLC - Google Chrome Installer.) -- C:\Program Files (x86)\Google\Update\Install\{40D27826-CC91-4D78-B28E-600C6262F4CE}\CR_80A47.tmp\setup.exe [4560200] [PID.4484] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.F03A53B0E5E11909962854C3F04E10F7] - (.BraveSoftware Inc. - BraveSoftware Update.) -- C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162456] [PID.7700] {05488AD7E4BABA7F93E3323C0573BF3C} [MD5.F03A53B0E5E11909962854C3F04E10F7] - (.BraveSoftware Inc. - BraveSoftware Update.) -- C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162456] [PID.5696] {05488AD7E4BABA7F93E3323C0573BF3C} [MD5.B10F2D0AAEE9AA446FD7564E63ECA3B8] - (.Brave Software, Inc. - Brave Installer.) -- C:\Program Files (x86)\BraveSoftware\Update\Install\{20CFCA98-C89B-49D6-B812-4AF9FEC17637}\brave_installer-delta-x64.exe [42221408] [PID.3576] {07F9F5D6998011AC8A9F6F2D92DB62AC} [MD5.4542050B0E8EDC5D66C1D9F1D086D3F4] - (.Brave Software, Inc. - Brave Installer.) -- C:\Program Files (x86)\BraveSoftware\Update\Install\{20CFCA98-C89B-49D6-B812-4AF9FEC17637}\CR_0C4B8.tmp\setup.exe [3126624] [PID.5924] {07F9F5D6998011AC8A9F6F2D92DB62AC} [MD5.4542050B0E8EDC5D66C1D9F1D086D3F4] - (.Brave Software, Inc. - Brave Installer.) -- C:\Program Files (x86)\BraveSoftware\Update\Install\{20CFCA98-C89B-49D6-B812-4AF9FEC17637}\CR_0C4B8.tmp\setup.exe [3126624] [PID.6056] {07F9F5D6998011AC8A9F6F2D92DB62AC} [MD5.60DA13EC9FBD16FF328E2521E8DD4191] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [636792] [PID.3680] {0C1CD3EEA47EDDA7A032573B014D0AFD} =>.Mozilla Corporation [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.7456] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.60DA13EC9FBD16FF328E2521E8DD4191] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [636792] [PID.7852] {0C1CD3EEA47EDDA7A032573B014D0AFD} =>.Mozilla Corporation [MD5.1DEDB5C1D41B3F1FF020551F144DEA02] - (.Adobe Systems Incorporated - Adobe RdrCEF.) -- C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\acrocef_1\RdrCEF.exe [6474240] [PID.628] {045296F8FCD829A75DC94294F5A415A4} =>.Adobe Systems Incorporated [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.2828] {0E4418E2DEDE36DD2974C3443AFB5CE5} [MD5.1DEDB5C1D41B3F1FF020551F144DEA02] - (.Adobe Systems Incorporated - Adobe RdrCEF.) -- C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\acrocef_1\RdrCEF.exe [6474240] [PID.9260] {045296F8FCD829A75DC94294F5A415A4} =>.Adobe Systems Incorporated [MD5.1DEDB5C1D41B3F1FF020551F144DEA02] - (.Adobe Systems Incorporated - Adobe RdrCEF.) -- C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\acrocef_1\RdrCEF.exe [6474240] [PID.6172] {045296F8FCD829A75DC94294F5A415A4} =>.Adobe Systems Incorporated [MD5.FF9CE0FC9E3B4BC22001764A9EFE4741] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Salah\AppData\Roaming\ZHP\ZHPDiag3.exe [2105344] [PID.2360] =>.Nicolas Coolman [MD5.1DEDB5C1D41B3F1FF020551F144DEA02] - (.Adobe Systems Incorporated - Adobe RdrCEF.) -- C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\acrocef_1\RdrCEF.exe [6474240] [PID.9712] {045296F8FCD829A75DC94294F5A415A4} =>.Adobe Systems Incorporated [MD5.60DA13EC9FBD16FF328E2521E8DD4191] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [636792] [PID.6372] {0C1CD3EEA47EDDA7A032573B014D0AFD} =>.Mozilla Corporation [MD5.54042EE229F73413B52E1DCFCC9CD4E4] - (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [2673480] [PID.6888] {0E4418E2DEDE36DD2974C3443AFB5CE5} ---\\ Google Chrome, Démarrage,Recherche,Extensions (19) - 1s G2 - GCE: Preference [User Data\Default] [aabcgdmkeabbnleenpncegpcngjpnjkc] Easy Auto Refresh G2 - GCE: Preference [User Data\Default] [cfhdojbkjhnklbpkdaibdccddilifddb] __MSG_name_releasebuild__ =>.AdblocPlus Plugin G2 - GCE: Preference [User Data\Default] [dagcmkpagjlhakfdhnbomgmjdpkdklff] Mendeley Web Importer G2 - GCE: Preference [User Data\Default] [dmghijelimhndkbmpgbldicpogfkceaj] Dark Mode G2 - GCE: Preference [User Data\Default] [efaidnbmnnnibpcajpcglclefindmkaj] __MSG_web2pdfExtnName__ G2 - GCE: Preference [User Data\Default] [eiimnmioipafcokbfikbljfdeojpcgbh] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [ekhagklcjbdpajgpjgmbionohlpdbjgc] Zotero Connector G2 - GCE: Preference [User Data\Default] [fcfhplploccackoneaefokcmbjfbkenj] __MSG_name__ G2 - GCE: Preference [User Data\Default] [fngmhnnpilhplaeedifhccceomclgfbg] EditThisCookie G2 - GCE: Preference [User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [hlkenndednhfkekhgcdicdfddnkalmdm] Cookie-Editor G2 - GCE: Preference [User Data\Default] [hmooaemjmediafeacjplpbpenjnpcneg] __MSG_name__ G2 - GCE: Preference [User Data\Default] [ifipmflagepipjokmbdecpmjbibjnakm] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [ihcjicgdanjaechkgeegckofjjedodee] Malwarebytes Browser Guard G2 - GCE: Preference [User Data\Default] [inomeogfingihgjfjlpeplalcfajhgai] Chrome Remote Desktop G2 - GCE: Preference [User Data\Default] [ngpampappnmepgilojfohadhhmbhlaek] IDM Integration Module G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [okpidcojinmlaakglciglbpcpajaibco] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [oofgbpoabipfcfjapgnbbjjaenockbdp] SetupVPN - Lifetime Free VPN ---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (1) - 1s P2 - EXT FILE: (...) -- C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles\33hxqk1i.default-release\extensions\{c3c10168-4186-445c-9c5b-63f12b8e2c87}.xpi ---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (17) - 1s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 ---\\ Internet Explorer,Proxy Management (4) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation ---\\ Etude du fichier hosts (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (1) ---\\ Browser Helper Object de navigateur (BHO) (4) - 0s O2 - BHO: IDM Helper [64Bits] - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll {06C5078AA528BBD3B8668AB10B035F94} =>.Internet Download Manager, Tonec Inc. O2 - BHO: IEToEdge BHO [64Bits] - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} . (.Microsoft Corporation - IEToEdge BHO.) -- C:\Program Files (x86)\Microsoft\Edge\Application\103.0.1264.77\BHO\ie_to_edge_bho.dll {33000002D0E7EB7C2EF6CE23E10000000002D0} =>.Microsoft Corporation O2 - BHO: Skype for Business Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} . (.Microsoft Corporation - Skype for Business.) -- C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll {33000001529B409F5056997588000000000152} =>.Microsoft Corporation O2 - BHO: Microsoft SkyDrive Pro Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} . (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL {33000001797C2E574E52E1CAD6000100000179} =>.Microsoft Corporation ---\\ Applications lancées au démarrage du système (5) - 1s O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe {0BFCFAC08E216A1C1FDAA6B77BB2D66E} =>.Realtek Semiconductor O4 - HKLM\..\Run: [Combo Cleaner] . (.RCS LT - Combo Cleaner.) -- C:\Program Files (x86)\Combo Cleaner\ComboCleaner.exe {077C2D20443D4B34CFB3B739A08B3B33} O4 - HKLM\..\Run: [AVGUI.exe] . (.AVG Technologies CZ, s.r.o. - AVG AvLaunch component.) -- C:\Program Files\AVG\Antivirus\AvLaunch.exe {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. O4 - HKCU\..\Run: [Windscribe] . (.Windscribe Limited - Windscribe GUI.) -- C:\Program Files (x86)\Windscribe\Windscribe.exe {0F5EE43BEEA50ED5F0EC765BF65B1350} O4 - HKUS\S-1-5-21-552229666-3490754607-3588674639-1001\..\Run: [Windscribe] . (.Windscribe Limited - Windscribe GUI.) -- C:\Program Files (x86)\Windscribe\Windscribe.exe {0F5EE43BEEA50ED5F0EC765BF65B1350} ---\\ Raccourcis Global Startup (65) - 21s O4 - GS\Desktop [Administrateur]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files (x86)\Internet Download Manager\IDMan.exe {06C5078AA528BBD3B8668AB10B035F94} =>.Tonec Inc. O4 - GS\Desktop [Administrateur]: LDMultiPlayer4.lnk . (...) G:\LDPlayer\LDPlayer4.0\dnmultiplayer.exe {0D65082368F94330123C9A853A2FDEBF} O4 - GS\Desktop [Administrateur]: LDPlayer4.lnk . (...) G:\LDPlayer\LDPlayer4.0\dnplayer.exe {0D65082368F94330123C9A853A2FDEBF} O4 - GS\Desktop [Administrateur]: Mendeley Reference Manager.lnk . (.Mendeley - Mendeley Reference Manager.) C:\Users\Salah\AppData\Local\Programs\Mendeley Reference Manager\Mendeley Reference Manager.exe {0F4449449E40AF223998039A4E4606A8} O4 - GS\Desktop [Administrateur]: Multi-Drive.lnk . (...) C:\Program Files (x86)\Nox\bin\MultiPlayerManager.exe {0D69176C2B8BE472C5BAADE5F93D6AA8} O4 - GS\Desktop [Administrateur]: Nox.lnk . (.Duodian Technology Co. Ltd. - NoxPlayer.) C:\Program Files (x86)\Nox\bin\Nox.exe {0D69176C2B8BE472C5BAADE5F93D6AA8} O4 - GS\Desktop [Administrateur]: PDFMate Free PDF Merger.lnk . (.AnvSoft Inc. - PDFMate Free PDF Merger.) C:\Program Files (x86)\AnvSoft\PDFMate Free PDF Merger\PDFMergeFree.exe =>.Anvsoft Inc.® O4 - GS\Desktop [Administrateur]: SpyHunter.lnk . (...) C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter4.exe =>.Superfluous.SpyHunter O4 - GS\Desktop [Administrateur]: Start Tor Browser.lnk . (...) C:\Users\Salah\Desktop\Tor Browser\Browser\firefox.exe O4 - GS\Desktop [Administrateur]: Telegram.lnk . (.Telegram FZ-LLC - Telegram Desktop.) C:\Users\Salah\AppData\Roaming\Telegram Desktop\Telegram.exe {1F3216F428F850BE2C66CAA056F6D821} O4 - GS\Desktop [Administrateur]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) C:\Users\Salah\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman O4 - GS\Desktop [Administrateur]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Salah\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Administrateur]: Brave.lnk . (.Brave Software, Inc. - .) C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe O4 - GS\Quicklaunch [Administrateur]: Google Chrome.lnk . (.Google LLC - .) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O4 - GS\Quicklaunch [Administrateur]: Wondershare Recoverit.lnk . (.Copyright © 2021 Wondershare. All rights reserved. - Wondershare Recoverit.) C:\Program Files (x86)\Wondershare\Recoverit\recoveritassist.exe {059917FD7718808BC34BE224E415216F} O4 - GS\TaskBar [Administrateur]: Acrobat Reader DC.lnk . (.Adobe Systems Incorporated - Adobe Acrobat Reader DC.) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe {045296F8FCD829A75DC94294F5A415A4} =>.Adobe Systems Incorporated O4 - GS\TaskBar [Administrateur]: Brave.lnk . (.Brave Software, Inc. - .) C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe O4 - GS\TaskBar [Administrateur]: Driver Booster 9.lnk . (.IObit - Driver Booster.) C:\Program Files (x86)\IObit\Driver Booster\9.3.0\DriverBooster.exe {008BA1F172FD50BA8D4C11B74FFAC8A282} =>.IObit O4 - GS\TaskBar [Administrateur]: Google Chrome.lnk . (.Google LLC - .) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O4 - GS\Desktop [Salah]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files (x86)\Internet Download Manager\IDMan.exe {06C5078AA528BBD3B8668AB10B035F94} =>.Tonec Inc. O4 - GS\Desktop [Salah]: LDMultiPlayer4.lnk . (...) G:\LDPlayer\LDPlayer4.0\dnmultiplayer.exe {0D65082368F94330123C9A853A2FDEBF} O4 - GS\Desktop [Salah]: LDPlayer4.lnk . (...) G:\LDPlayer\LDPlayer4.0\dnplayer.exe {0D65082368F94330123C9A853A2FDEBF} O4 - GS\Desktop [Salah]: Mendeley Reference Manager.lnk . (.Mendeley - Mendeley Reference Manager.) C:\Users\Salah\AppData\Local\Programs\Mendeley Reference Manager\Mendeley Reference Manager.exe {0F4449449E40AF223998039A4E4606A8} O4 - GS\Desktop [Salah]: Multi-Drive.lnk . (...) C:\Program Files (x86)\Nox\bin\MultiPlayerManager.exe {0D69176C2B8BE472C5BAADE5F93D6AA8} O4 - GS\Desktop [Salah]: Nox.lnk . (.Duodian Technology Co. Ltd. - NoxPlayer.) C:\Program Files (x86)\Nox\bin\Nox.exe {0D69176C2B8BE472C5BAADE5F93D6AA8} O4 - GS\Desktop [Salah]: PDFMate Free PDF Merger.lnk . (.AnvSoft Inc. - PDFMate Free PDF Merger.) C:\Program Files (x86)\AnvSoft\PDFMate Free PDF Merger\PDFMergeFree.exe =>.Anvsoft Inc.® O4 - GS\Desktop [Salah]: SpyHunter.lnk . (...) C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter4.exe =>.Superfluous.SpyHunter O4 - GS\Desktop [Salah]: Start Tor Browser.lnk . (...) C:\Users\Salah\Desktop\Tor Browser\Browser\firefox.exe O4 - GS\Desktop [Salah]: Telegram.lnk . (.Telegram FZ-LLC - Telegram Desktop.) C:\Users\Salah\AppData\Roaming\Telegram Desktop\Telegram.exe {1F3216F428F850BE2C66CAA056F6D821} O4 - GS\Desktop [Salah]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) C:\Users\Salah\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman O4 - GS\Desktop [Salah]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Salah\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Salah]: Brave.lnk . (.Brave Software, Inc. - .) C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe O4 - GS\Quicklaunch [Salah]: Google Chrome.lnk . (.Google LLC - .) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O4 - GS\Quicklaunch [Salah]: Wondershare Recoverit.lnk . (.Copyright © 2021 Wondershare. All rights reserved. - Wondershare Recoverit.) C:\Program Files (x86)\Wondershare\Recoverit\recoveritassist.exe {059917FD7718808BC34BE224E415216F} O4 - GS\TaskBar [Salah]: Acrobat Reader DC.lnk . (.Adobe Systems Incorporated - Adobe Acrobat Reader DC.) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe {045296F8FCD829A75DC94294F5A415A4} =>.Adobe Systems Incorporated O4 - GS\TaskBar [Salah]: Brave.lnk . (.Brave Software, Inc. - .) C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe O4 - GS\TaskBar [Salah]: Driver Booster 9.lnk . (.IObit - Driver Booster.) C:\Program Files (x86)\IObit\Driver Booster\9.3.0\DriverBooster.exe {008BA1F172FD50BA8D4C11B74FFAC8A282} =>.IObit O4 - GS\TaskBar [Salah]: Google Chrome.lnk . (.Google LLC - .) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O4 - GS\CommonDesktop [Public]: Acrobat Reader DC.lnk . (.Adobe Systems Incorporated - Adobe Acrobat Reader DC.) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe {045296F8FCD829A75DC94294F5A415A4} =>.Adobe Systems Incorporated O4 - GS\CommonDesktop [Public]: AVG AntiVirus Gratuit.lnk . (.AVG Technologies CZ, s.r.o. - .) C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe =>.AVG Technologies CZ, s.r.o. O4 - GS\CommonDesktop [Public]: Brave.lnk . (.Brave Software, Inc. - .) C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe O4 - GS\CommonDesktop [Public]: Combo Cleaner.lnk . (.RCS LT - Combo Cleaner.) C:\Program Files (x86)\Combo Cleaner\ComboCleaner.exe {077C2D20443D4B34CFB3B739A08B3B33} O4 - GS\CommonDesktop [Public]: DriversCloud.com - Démarrer la détection.lnk . (.CybelSoft - .) C:\Program Files (x86)\Cybelsoft\DriversCloud.com\DriversCloud.exe =>.CybelSoft O4 - GS\CommonDesktop [Public]: DualSafe Password Manager.lnk . (.iTop Inc. - DualSafe Password Manager.) C:\Program Files (x86)\DualSafe Password Manager\Dualsafe.exe {031C59BCEE5E23FC713C1FF882CE5668} O4 - GS\CommonDesktop [Public]: EaseUS Data Recovery Wizard.lnk . (.CHENGDU YIWO Tech Development Co., Ltd - EaseUS Data Recovery Wizard.) C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRW.exe {0686ED403EC1BF441C8F335C841EEA00} =>.CHENGDU YIWO Tech Development Co., Ltd O4 - GS\CommonDesktop [Public]: Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe {0C1CD3EEA47EDDA7A032573B014D0AFD} =>.Mozilla Corporation O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google LLC - .) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O4 - GS\CommonDesktop [Public]: GridinSoft Anti-Malware.lnk . (.Gridinsoft LLC - Anti-Malware (64-bit).) C:\Program Files\GridinSoft Anti-Malware\gsam.exe {02BC413E2B79BE5ACA8FF03002D417EA} O4 - GS\CommonDesktop [Public]: Intel Processor Diagnostic Tool 64bit.lnk . (...) C:\Windows\Installer\{6E05E656-6ED8-49DE-AA9C-C4677F7086C5}\_9646D14DCE12B8A9BAF003.exe O4 - GS\CommonDesktop [Public]: IP-TV Player.lnk . (.ADSL Club LLC - IP-TV Player.) C:\Program Files (x86)\IP-TV Player\IpTvPlayer.exe {5155BAB0E61C3A47C12B07CE0E5CE253} O4 - GS\CommonDesktop [Public]: Kaspersky Password Manager.lnk . (.AO Kaspersky Lab - Kaspersky Password Manager.) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe {067CE8A9F2E02AC7D49304F85E9474E1} =>.AO Kaspersky Lab O4 - GS\CommonDesktop [Public]: Kaspersky VPN.lnk . (.AO Kaspersky Lab - Kaspersky Secure Connection.) C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.3\ksdeui.exe {013C6684E0F39030C05FA36B42AF33CA} =>.AO Kaspersky Lab O4 - GS\CommonDesktop [Public]: Malwarebytes.lnk . (.Malwarebytes - .) C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbam.exe =>.Malwarebytes O4 - GS\CommonDesktop [Public]: Mendeley Desktop.lnk . (.Mendeley Ltd. - MendeleyDesktop.) C:\Program Files (x86)\Mendeley Desktop\MendeleyDesktop.exe =>.Mendeley Ltd. O4 - GS\CommonDesktop [Public]: SpyHunter5.lnk . (.EnigmaSoft Limited - SpyHunter product..) C:\Program Files\EnigmaSoft\SpyHunter\SpyHunter5.exe {0A64EFC7170E63B64A6E390EEB577FE9} =>.Superfluous.SpyHunter O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files\VideoLAN\VLC\vlc.exe {0407ABB64E9990180789EACB81F5F914} =>.VideoLAN O4 - GS\CommonDesktop [Public]: Windows IPTV Player.lnk . (.Xtream Codes LTD - Windows IPTV Player.) C:\Program Files (x86)\Xtream Codes LTD\Windows IPTV Player\WindowsIPTVPlayer.exe O4 - GS\CommonDesktop [Public]: Windscribe.lnk . (.Windscribe Limited - Windscribe Launcher.) C:\Program Files (x86)\Windscribe\WindscribeLauncher.exe {0F5EE43BEEA50ED5F0EC765BF65B1350} O4 - GS\CommonDesktop [Public]: Wise Data Recovery.lnk . (.WiseCleaner.com - WiseDataRecovery.) C:\Program Files (x86)\Wise\Wise Data Recovery\WiseDataRecovery.exe {2E4A279BDE2EB688E8AB30F5904FA875} =>.WiseCleaner.com O4 - GS\CommonDesktop [Public]: Wondershare Recoverit.lnk . (.Copyright © 2021 Wondershare. All rights reserved. - Wondershare Recoverit.) C:\Program Files (x86)\Wondershare\Recoverit\recoveritassist.exe {059917FD7718808BC34BE224E415216F} O4 - GS\CommonDesktop [Public]: Zotero.lnk . (.Corporation for Digital Scholarship - Zotero.) C:\Program Files (x86)\Zotero\zotero.exe {2E6C425FF275DACF2CD83F84DA4478A7} O4 - GS\Programs [Public]: Documents.lnk . (...) C:\Users\Salah\Documents O4 - GS\Programs [Public]: Mendeley Reference Manager.lnk . (.Mendeley - Mendeley Reference Manager.) C:\Users\Salah\AppData\Local\Programs\Mendeley Reference Manager\Mendeley Reference Manager.exe {0F4449449E40AF223998039A4E4606A8} O4 - GS\Programs [Public]: Pictures.lnk . (...) C:\Users\Salah\Pictures O4 - GS\Programs [Public]: Start Tor Browser.lnk . (...) C:\Users\Salah\Desktop\Tor Browser\Browser\firefox.exe ---\\ Modification Domaine/Adresses DNS (2) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 41.110.32.3 8.8.8.8 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2583775E-0A36-485B-9C5D-B0A07C960ECA}: DhcpNameServer = 41.110.32.3 8.8.8.8 ---\\ Protocole additionnel (20) - 1s O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll =>.Microsoft Corporation O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation® O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation O18 - Handler: osf [64Bits] - {D924BDC6-C83A-4BD5-90D0-095128A113D1} . (.Microsoft Corporation - Microsoft Office 2013 component.) -- C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL {330000014096A9EE7056FECC07000100000140} =>.Microsoft Corporation O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Filter: text/xml [64Bits] - {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL =>.Microsoft Corporation® ---\\ Liste des clés Explorer StartupApproved (10) - 0s [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:Windscribe [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:ExpressVPN4 [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:IDMan [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:Advanced SystemCare [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder]:programs.bat [HKEY_USERS\S-1-5-21-552229666-3490754607-3588674639-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:Windscribe [HKEY_USERS\S-1-5-21-552229666-3490754607-3588674639-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:ExpressVPN4 [HKEY_USERS\S-1-5-21-552229666-3490754607-3588674639-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:IDMan [HKEY_USERS\S-1-5-21-552229666-3490754607-3588674639-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:Advanced SystemCare [HKEY_USERS\S-1-5-21-552229666-3490754607-3588674639-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder]:programs.bat ---\\ Logiciels installés (77) - 37s O42 - Logiciel: Active@ File Recovery 19 - (.LSoft Technologies Inc.) [HKLM][64Bits] -- {177608F6-F029-4301-B176-15BA7C605B73}_is1 {009B0B01566558DCBCB2A5EEC9558E1BB6} =>.LSoft Technologies Inc O42 - Logiciel: Adobe Acrobat Reader DC - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1033-7B44-AC0F074E4100} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001824458876} =>.Adobe Systems Incorporated O42 - Logiciel: Advanced SystemCare - (.IObit.) [HKLM][64Bits] -- Advanced SystemCare_is1 {008BA1F172FD50BA8D4C11B74FFAC8A282} =>.IObit O42 - Logiciel: AMD Catalyst Install Manager - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {7EE99C20-7415-1077-FEE9-8B0CA42F98D6} =>.Advanced Micro Devices, Inc. O42 - Logiciel: AVG AntiVirus Gratuit - (.AVG Technologies.) [HKLM][64Bits] -- AVG Antivirus {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies O42 - Logiciel: Brave - (.Auteurs de Brave.) [HKLM][64Bits] -- BraveSoftware Brave-Browser {05488AD7E4BABA7F93E3323C0573BF3C} O42 - Logiciel: Broadcom Bluetooth Drivers - (.Broadcom Corporation.) [HKLM][64Bits] -- {0A1B4690-E176-4533-8058-939480AEE1D0} =>.Broadcom Corporation O42 - Logiciel: Chrome Remote Desktop Host - (.Google LLC.) [HKLM][64Bits] -- {1FFC43DF-028F-473A-90D6-B9AF536306DA} O42 - Logiciel: Combo Cleaner - (.RCS LT.) [HKLM][64Bits] -- {8C9F8853-52F7-46F3-BC78-98001D3FF40C} O42 - Logiciel: Combo Cleaner - (.RCS LT.) [HKLM][64Bits] -- InstallShield_{8C9F8853-52F7-46F3-BC78-98001D3FF40C} {077C2D20443D4B34CFB3B739A08B3B33} O42 - Logiciel: DriversCloud.com - (.Cybelsoft.) [HKLM][64Bits] -- {C825674B-9D11-4148-B939-EA3564741D54} =>.CybelSoft O42 - Logiciel: DualSafe Password Manager - (.iTop Inc..) [HKLM][64Bits] -- DualSafe Password Manager_is1 {0E22F15724FA09F07FBBF2A05306BB27} O42 - Logiciel: Google Chrome - (.Google LLC.) [HKLM][64Bits] -- Google Chrome {0E4418E2DEDE36DD2974C3443AFB5CE5} O42 - Logiciel: GridinSoft Anti-Malware - (.Gridinsoft LLC.) [HKLM][64Bits] -- GridinSoft Anti-Malware {02BC413E2B79BE5ACA8FF03002D417EA} O42 - Logiciel: Hola Browser 1.193.446 - (.Hola Networks Ltd..) [HKLM][64Bits] -- Hola Browser {3BE54518045FEF7A1954AC675CE01ED5} =>.Hola Networks Ltd. O42 - Logiciel: HP Support Solutions Framework - (.HP Inc..) [HKLM][64Bits] -- {8EB6580E-9833-451A-ADAA-12C9B4FFD1E1} O42 - Logiciel: HP Wireless Button Driver - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {EFA01423-3857-468C-B7B6-F30AA08E50BC} =>.Hewlett-Packard Company O42 - Logiciel: Intel Processor Diagnostic Tool 64bit - (.Intel Corporation.) [HKLM][64Bits] -- {6E05E656-6ED8-49DE-AA9C-C4677F7086C5} =>.Intel Corporation O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {1CEAC85D-2590-4760-800F-8DE5E91F3700} {56000001757376CD78AD000C9A000000000175} =>.Intel Corporation O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {BB1BE37B-355C-4FCD-990D-D1D0E84AA422} =>.Intel Corporation O42 - Logiciel: Intel(R) Management Engine Driver - (.Intel Corporation.) [HKLM][64Bits] -- {8812825D-384E-4D71-BC02-111A4125F48E} =>.Intel Corporation O42 - Logiciel: Intel(R) ME UninstallLegacy - (.Intel Corporation.) [HKLM][64Bits] -- {E9B9A1A5-6398-4C99-8FDE-10794F6505C5} =>.Intel Corporation O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} {5600000C3BF9A3682289A06F40000000000C3B} =>.Intel Corporation O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM][64Bits] -- Internet Download Manager {06C5078AA528BBD3B8668AB10B035F94} =>.Tonec Inc. O42 - Logiciel: Internet Download Manager 6.39.5 - (.LRepacks.) [HKLM][64Bits] -- Internet Download Manager_is1 O42 - Logiciel: IP-TV Player 50.2 - (.ADSL Club LLC.) [HKLM][64Bits] -- IP-TV_Player O42 - Logiciel: Kaspersky Password Manager - (.Kaspersky Lab.) [HKLM][64Bits] -- {B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611} =>.Kaspersky Lab O42 - Logiciel: Kaspersky Password Manager - (.Kaspersky Lab.) [HKLM][64Bits] -- InstallWIX_{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611} =>.Kaspersky Lab O42 - Logiciel: Kaspersky VPN - (.Kaspersky.) [HKLM][64Bits] -- {FF2A12B8-AEB7-48C0-95C8-E2E3D67DFCB2} O42 - Logiciel: Kaspersky VPN - (.Kaspersky.) [HKLM][64Bits] -- InstallWIX_{FF2A12B8-AEB7-48C0-95C8-E2E3D67DFCB2} O42 - Logiciel: K-Lite Codec Pack 16.8.7 Basic - (.KLCP.) [HKLM][64Bits] -- KLiteCodecPack_is1 O42 - Logiciel: LDPlayer - (.XUANZHI INTERNATIONAL CO., LIMITED.) [HKLM][64Bits] -- LDPlayer4 {0D65082368F94330123C9A853A2FDEBF} O42 - Logiciel: Malwarebytes version 4.5.12.204 - (.Malwarebytes.) [HKLM][64Bits] -- {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1 {00A657F778B31AE523D667131718D16EB2} =>.Malwarebytes O42 - Logiciel: Mediatek Bluetooth - (.Mediatek.) [HKLM][64Bits] -- {1C41AEAE-7DD5-29D6-FA5F-D1E8A12ECE4E} =>.Mediatek O42 - Logiciel: Mendeley Desktop 1.19.8 - (.Mendeley Ltd..) [HKLM][64Bits] -- Mendeley Desktop =>.Mendeley Ltd. O42 - Logiciel: Mendeley Reference Manager 2.67.0 - (.Mendeley.) [HKCU][64Bits] -- b4b58389-01e4-5dfd-9842-aad36733657a {0F4449449E40AF223998039A4E4606A8} O42 - Logiciel: Microsoft Access MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0015-040C-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Microsoft DCF MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0090-040C-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Microsoft Edge - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Edge {33000002CFA02590E31304EF150000000002CF} =>.Microsoft Corporation O42 - Logiciel: Microsoft Edge Update - (...) [HKLM][64Bits] -- Microsoft Edge Update O42 - Logiciel: Microsoft Edge WebView2 Runtime - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft EdgeWebView {33000002CFA02590E31304EF150000000002CF} =>.Microsoft Corporation O42 - Logiciel: Microsoft Excel MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0016-040C-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Microsoft Groove MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00BA-040C-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Microsoft InfoPath MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0044-040C-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Microsoft Lync MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-012B-040C-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Microsoft OneNote MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00A1-040C-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Microsoft Outlook MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001A-040C-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Microsoft PowerPoint MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0018-040C-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Microsoft Publisher MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0019-040C-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Microsoft Word MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001B-040C-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Mozilla Firefox (x64 en-US) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 102.0.1 (x64 en-US) {0C1CD3EEA47EDDA7A032573B014D0AFD} =>.Mozilla O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService =>.Mozilla O42 - Logiciel: NoxPlayer - (.Duodian Technology Co. Ltd..) [HKLM][64Bits] -- Nox {050CC1BE6229543A97864D6672FEEB00} O42 - Logiciel: PDFMate Free PDF Merger 1.0.9 - (.pdfmate.com.) [HKLM][64Bits] -- PDFMate Free PDF Merger_is1 =>.Anvsoft Inc.® O42 - Logiciel: Ralink RT2860 Wireless LAN Card - (.Ralink.) [HKLM][64Bits] -- {8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0} =>.Ralink O42 - Logiciel: Realtek Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {5BC2B5AB-80DE-4E83-B8CF-426902051D0A} {0320BE3EB866526927F999B97B04346E} =>.Realtek Semiconductor Corp. O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} {050D30A415301D62B5797ADDA45FDF94} =>.Realtek O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} {04DF4D56733AE38D598EA004DD2D9C51} =>.Realtek Semiconductor Corp. O42 - Logiciel: RegRun Reanimator - (.Greatis Software, LLC..) [HKLM][64Bits] -- UnHackMe Update - Reanimator_is1 O42 - Logiciel: Security Update for Skype for Business 2015 (KB3191937) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-012B-040C-0000-0000000FF1CE}_Office15.PROPLUS_{51ACADB4-830D-41A6-82C5-C7AE9437E349} =>.Microsoft Corporation® O42 - Logiciel: SHAREit - (.SHAREit Technologies Co.Ltd.) [HKLM][64Bits] -- www.ushareit.com_is1 O42 - Logiciel: SoftPerfect WiFi Guard version 2.0.0 - (.SoftPerfect.) [HKLM][64Bits] -- {38AFD787-4D2E-4442-92D2-7739F5F92CF4}_is1 =>.SoftPerfect O42 - Logiciel: SpyHunter - (.Enigma Software Group USA, LLC.) [HKLM][64Bits] -- {4941BFEB-62C0-47A2-801E-998FC469CC2C} =>.Superfluous.SpyHunter O42 - Logiciel: SpyHunter 5 - (.EnigmaSoft Limited.) [HKLM][64Bits] -- SpyHunter5 {0A64EFC7170E63B64A6E390EEB577FE9} =>.Superfluous.SpyHunter O42 - Logiciel: Telegram Desktop version 4.0.2 - (.Telegram FZ-LLC.) [HKCU][64Bits] -- {53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1 O42 - Logiciel: Update for Skype for Business 2015 (KB4484289) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{F97B139A-D8BF-46FF-A6F6-50710FED8644} =>.Microsoft Corporation® O42 - Logiciel: Update for Skype for Business 2015 (KB4484289) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{F97B139A-D8BF-46FF-A6F6-50710FED8644} =>.Microsoft Corporation® O42 - Logiciel: Update for Skype for Business 2015 (KB4484289) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-012B-040C-0000-0000000FF1CE}_Office15.PROPLUS_{F97B139A-D8BF-46FF-A6F6-50710FED8644} =>.Microsoft Corporation® O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN O42 - Logiciel: Windows IPTV Player - (.Xtream Codes LTD.) [HKLM][64Bits] -- {D1F0A04F-B987-4373-9E26-40DC6F1F9906} O42 - Logiciel: Windscribe - (.Windscribe Limited.) [HKLM][64Bits] -- {fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1 {0F5EE43BEEA50ED5F0EC765BF65B1350} O42 - Logiciel: WinRAR 6.02 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver {731D40AE3F3A1FB2BC3D8395} =>.win.rar GmbH O42 - Logiciel: Wise Data Recovery 6.0.4 - (.WiseCleaner.com, Inc..) [HKLM][64Bits] -- Wise Data Recovery_is1 {2E4A279BDE2EB688E8AB30F5904FA875} =>.WiseCleaner.com, Inc. O42 - Logiciel: Wondershare Recoverit 7.3.2.3 - (.lrepacks.ru.) [HKLM][64Bits] -- Wondershare Recoverit_is1 O42 - Logiciel: Wondershare Recoverit(Build 10.2.1.4) - (.Wondershare Software Co.,Ltd..) [HKLM][64Bits] -- {829555DC-31E5-4FEA-B350-8FCF24CECD95}_is1 =>.Wondershare Software Co.,Ltd. O42 - Logiciel: Zotero - (.Corporation for Digital Scholarship.) [HKLM][64Bits] -- Zotero 6.0.7 (x86 en-US) {2E6C425FF275DACF2CD83F84DA4478A7} ---\\ HKCU & HKLM Software Keys (115) - 37s HKLM\SOFTWARE\Wow6432Node\Adobe HKLM\SOFTWARE\Wow6432Node\Applogon HKLM\SOFTWARE\Wow6432Node\ATI Technologies HKLM\SOFTWARE\Wow6432Node\AVG HKLM\SOFTWARE\Wow6432Node\Bluestacks HKLM\SOFTWARE\Wow6432Node\BraveSoftware HKLM\SOFTWARE\Wow6432Node\Caphyon HKLM\SOFTWARE\Wow6432Node\Chromium HKLM\SOFTWARE\Wow6432Node\DigitalWave HKLM\SOFTWARE\Wow6432Node\DualSafe Password Manager HKLM\SOFTWARE\Wow6432Node\DuoDianOnline HKLM\SOFTWARE\Wow6432Node\DVDVideoSoft HKLM\SOFTWARE\Wow6432Node\EnigmaSoftwareGroup =>.Superfluous.Enigma HKLM\SOFTWARE\Wow6432Node\Freemake HKLM\SOFTWARE\Wow6432Node\Google HKLM\SOFTWARE\Wow6432Node\Greatis HKLM\SOFTWARE\Wow6432Node\GridinSoft HKLM\SOFTWARE\Wow6432Node\GuidGuid13 HKLM\SOFTWARE\Wow6432Node\Hewlett-Packard HKLM\SOFTWARE\Wow6432Node\iBoysoft HKLM\SOFTWARE\Wow6432Node\Icaros HKLM\SOFTWARE\Wow6432Node\IM Providers HKLM\SOFTWARE\Wow6432Node\iMyFone HKLM\SOFTWARE\Wow6432Node\Intel HKLM\SOFTWARE\Wow6432Node\Internet Download Manager HKLM\SOFTWARE\Wow6432Node\IObit HKLM\SOFTWARE\Wow6432Node\iTop Screen Recorder HKLM\SOFTWARE\Wow6432Node\iTop Screenshot HKLM\SOFTWARE\Wow6432Node\iTop VPN HKLM\SOFTWARE\Wow6432Node\IVT Corporation HKLM\SOFTWARE\Wow6432Node\KasperskyLab HKLM\SOFTWARE\Wow6432Node\Khronos HKLM\SOFTWARE\Wow6432Node\KLCodecPack HKLM\SOFTWARE\Wow6432Node\LAV HKLM\SOFTWARE\Wow6432Node\McAfee HKLM\SOFTWARE\Wow6432Node\mcafeeupdater HKLM\SOFTWARE\Wow6432Node\Mediatek HKLM\SOFTWARE\Wow6432Node\Mendeley Ltd. HKLM\SOFTWARE\Wow6432Node\Mozilla HKLM\SOFTWARE\Wow6432Node\MozillaPlugins HKLM\SOFTWARE\Wow6432Node\Nemu HKLM\SOFTWARE\Wow6432Node\Nuance HKLM\SOFTWARE\Wow6432Node\ODBC HKLM\SOFTWARE\Wow6432Node\Privax HKLM\SOFTWARE\Wow6432Node\Realtek HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp. HKLM\SOFTWARE\Wow6432Node\Remo Software HKLM\SOFTWARE\Wow6432Node\SHAREit Technologies HKLM\SOFTWARE\Wow6432Node\Tenorshare HKLM\SOFTWARE\Wow6432Node\WafCX HKLM\SOFTWARE\Wow6432Node\WiseCleaner HKLM\SOFTWARE\Wow6432Node\WnRecoverMaster6 HKLM\SOFTWARE\Wow6432Node\Wondershare HKLM\SOFTWARE\Wow6432Node\Wow6432Node HKLM\SOFTWARE\Wow6432Node\Xtream Codes LTD HKLM\SOFTWARE\Wow6432Node\Zotero HKLM\SOFTWARE\Wow6432Node\zotero.org HKLM\SOFTWARE\Wow6432Node\RegisteredApplications HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\AnvSoft HKCU\SOFTWARE\AnyDataRecovery HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\AVG HKCU\SOFTWARE\b4b58389-01e4-5dfd-9842-aad36733657a =>PUP.Optional.CrossRider HKCU\SOFTWARE\BcmSetup HKCU\SOFTWARE\BraveSoftware HKCU\SOFTWARE\BugSplat HKCU\SOFTWARE\Changzhi HKCU\SOFTWARE\ChangZhi2 HKCU\SOFTWARE\Chromium HKCU\SOFTWARE\CleverFiles HKCU\SOFTWARE\CocCoc HKCU\SOFTWARE\DownloadManager HKCU\SOFTWARE\DRP HKCU\SOFTWARE\DuoDianApp HKCU\SOFTWARE\DVDVideoSoft HKCU\SOFTWARE\Freemake HKCU\SOFTWARE\Gabest HKCU\SOFTWARE\Google HKCU\SOFTWARE\Greatis HKCU\SOFTWARE\HP HKCU\SOFTWARE\Icaros HKCU\SOFTWARE\IM Providers HKCU\SOFTWARE\Intel HKCU\SOFTWARE\Intel Corporation HKCU\SOFTWARE\Internet Download Manager HKCU\SOFTWARE\Jihosoft HKCU\SOFTWARE\KasperskyLab HKCU\SOFTWARE\KasperskyLabSetup HKCU\SOFTWARE\Licenses HKCU\SOFTWARE\Malwarebytes HKCU\SOFTWARE\Mendeley Ltd. HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\nwjs HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\Psiphon3 HKCU\SOFTWARE\Realtek HKCU\SOFTWARE\ReConnect HKCU\SOFTWARE\RegisteredApplications HKCU\SOFTWARE\Remo Software HKCU\SOFTWARE\Spoon HKCU\SOFTWARE\Stellar HKCU\SOFTWARE\TelegramDesktop HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\VB and VBA Program Settings HKCU\SOFTWARE\Windscribe HKCU\SOFTWARE\WinRAR HKCU\SOFTWARE\WinRAR SFX HKCU\SOFTWARE\Wondershare HKCU\SOFTWARE\Wow6432Node HKCU\SOFTWARE\XuanZhi HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\ZHP HKCU\SOFTWARE\AppDataLow\Software ---\\ Contenu des dossiers Programmes (243) - 38s O43 - CFD: 09/08/2021 - [] D -- C:\Program Files (x86)\Adobe {011F39A2261A993DD15176DA6FE4FBEA} O43 - CFD: 26/06/2022 - [] D -- C:\Program Files (x86)\AnvSoft =>.Anvsoft Inc.® O43 - CFD: 06/06/2022 - [] D -- C:\Program Files (x86)\Bignox {050CC1BE6229543A97864D6672FEEB00} O43 - CFD: 08/05/2022 - [0] D -- C:\Program Files (x86)\Bitwar O43 - CFD: 16/08/2021 - [] D -- C:\Program Files (x86)\BraveSoftware {05488AD7E4BABA7F93E3323C0573BF3C} O43 - CFD: 24/07/2022 - [] D -- C:\Program Files (x86)\Combo Cleaner {077C2D20443D4B34CFB3B739A08B3B33} O43 - CFD: 25/07/2022 - [] D -- C:\Program Files (x86)\Common Files O43 - CFD: 05/08/2022 - [] D -- C:\Program Files (x86)\DualSafe Password Manager {031C59BCEE5E23FC713C1FF882CE5668} O43 - CFD: 01/05/2022 - [] D -- C:\Program Files (x86)\EaseUS {0686ED403EC1BF441C8F335C841EEA00} O43 - CFD: 25/07/2022 - [] D -- C:\Program Files (x86)\Enigma Software Group =>.Superfluous.SpyHunter =>.Superfluous.Enigma O43 - CFD: 02/12/2021 - [0] D -- C:\Program Files (x86)\Freemake O43 - CFD: 05/08/2022 - [] D -- C:\Program Files (x86)\Google {06AEA76BAC46A9E8CFE6D29E45AAF033} O43 - CFD: 10/01/2022 - [] D -- C:\Program Files (x86)\Greatis {7841C41E12C5B095D4B8B1ACAF87AA8A} O43 - CFD: 28/05/2022 - [] D -- C:\Program Files (x86)\Hewlett-Packard =>.Hewlett-Packard® O43 - CFD: 02/03/2022 - [] D -- C:\Program Files (x86)\iBoysoft O43 - CFD: 21/12/2021 - [] D -- C:\Program Files (x86)\iBoysoft Software O43 - CFD: 24/07/2022 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information O43 - CFD: 28/05/2022 - [] D -- C:\Program Files (x86)\Intel {5600000C3BF9A3682289A06F40000000000C3B} O43 - CFD: 10/04/2022 - [] D -- C:\Program Files (x86)\Internet Download Manager {06C5078AA528BBD3B8668AB10B035F94} O43 - CFD: 09/03/2022 - [] D -- C:\Program Files (x86)\Internet Explorer O43 - CFD: 04/03/2022 - [] D -- C:\Program Files (x86)\IObit {008BA1F172FD50BA8D4C11B74FFAC8A282} O43 - CFD: 14/08/2021 - [] D -- C:\Program Files (x86)\IP-TV Player {5155BAB0E61C3A47C12B07CE0E5CE253} O43 - CFD: 19/03/2022 - [] D -- C:\Program Files (x86)\K-Lite Codec Pack O43 - CFD: 13/04/2022 - [] D -- C:\Program Files (x86)\Kaspersky Lab {013C6684E0F39030C05FA36B42AF33CA} O43 - CFD: 11/03/2022 - [] D -- C:\Program Files (x86)\Mendeley Desktop O43 - CFD: 15/06/2022 - [] D -- C:\Program Files (x86)\Microsoft {33000002D0E7EB7C2EF6CE23E10000000002D0} O43 - CFD: 09/08/2021 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services =>.Microsoft Corporation® O43 - CFD: 09/08/2021 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation® O43 - CFD: 09/08/2021 - [] D -- C:\Program Files (x86)\Microsoft SQL Server O43 - CFD: 09/08/2021 - [] D -- C:\Program Files (x86)\Microsoft.NET O43 - CFD: 10/08/2021 - [] D -- C:\Program Files (x86)\Mozilla Firefox O43 - CFD: 24/07/2022 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service {0C1CD3EEA47EDDA7A032573B014D0AFD} O43 - CFD: 06/06/2022 - [] D -- C:\Program Files (x86)\Nox {0D69176C2B8BE472C5BAADE5F93D6AA8} O43 - CFD: 23/07/2022 - [0] D -- C:\Program Files (x86)\PowerControl O43 - CFD: 07/01/2022 - [] D -- C:\Program Files (x86)\Ralink Corporation =>.Ralink Technology Corporation® O43 - CFD: 05/05/2022 - [] D -- C:\Program Files (x86)\Realtek {0320BE3EB866526927F999B97B04346E} O43 - CFD: 02/09/2016 - [] D -- C:\Program Files (x86)\SentExplore {7841C41E12C5B095D4B8B1ACAF87AA8A} O43 - CFD: 28/10/2021 - [] D -- C:\Program Files (x86)\SHAREit Technologies {3E04076D4B53A8436FD2665B5029C627} O43 - CFD: 21/12/2021 - [] D -- C:\Program Files (x86)\Tenorshare O43 - CFD: 01/05/2022 - [] D -- C:\Program Files (x86)\UltData - Windows O43 - CFD: 20/09/2021 - [] D -- C:\Program Files (x86)\VyprVPN O43 - CFD: 09/08/2021 - [] D -- C:\Program Files (x86)\Windows Defender O43 - CFD: 09/08/2021 - [] D -- C:\Program Files (x86)\Windows Mail O43 - CFD: 09/08/2021 - [] D -- C:\Program Files (x86)\Windows Media Player O43 - CFD: 21/11/2014 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Windows NT O43 - CFD: 21/11/2014 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation® O43 - CFD: 21/11/2014 - [] D -- C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 22/08/2013 - [] SHD -- C:\Program Files (x86)\Windows Sidebar O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\WindowsPowerShell O43 - CFD: 15/08/2021 - [] D -- C:\Program Files (x86)\Windscribe {0F5EE43BEEA50ED5F0EC765BF65B1350} O43 - CFD: 10/05/2022 - [] D -- C:\Program Files (x86)\Wise {2E4A279BDE2EB688E8AB30F5904FA875} O43 - CFD: 11/05/2022 - [] D -- C:\Program Files (x86)\Wondershare {0A9F96AABFB5DAC0F29F565D33FF1AF6} O43 - CFD: 14/08/2021 - [] D -- C:\Program Files (x86)\Xtream Codes LTD O43 - CFD: 20/05/2022 - [] D -- C:\Program Files (x86)\Zotero {0B1F8CD59E64746BEAE153ECCA21066B} O43 - CFD: 21/11/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 14/07/2022 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 04/03/2022 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Active@ File Recovery O43 - CFD: 14/07/2022 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 04/03/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare O43 - CFD: 26/06/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnvSoft O43 - CFD: 02/08/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG O43 - CFD: 22/05/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriversCloud.com O43 - CFD: 05/08/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DualSafe Password Manager O43 - CFD: 01/05/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS O43 - CFD: 25/07/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EnigmaSoft O43 - CFD: 23/07/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GridinSoft Anti-Malware O43 - CFD: 14/04/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager O43 - CFD: 19/03/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack O43 - CFD: 29/01/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Password Manager O43 - CFD: 22/08/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 11/03/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mendeley Desktop O43 - CFD: 15/06/2022 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 O43 - CFD: 04/03/2022 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reanimator O43 - CFD: 28/10/2021 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SHAREit O43 - CFD: 04/03/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftPerfect WiFi Guard O43 - CFD: 06/09/2021 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp O43 - CFD: 21/11/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 10/08/2021 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN O43 - CFD: 12/08/2021 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windscribe O43 - CFD: 23/07/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 10/05/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Data Recovery O43 - CFD: 11/05/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare O43 - CFD: 11/05/2022 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare Recoverit O43 - CFD: 09/08/2021 - [] D -- C:\ProgramData\Adobe O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 02/08/2022 - [] D -- C:\ProgramData\AVG O43 - CFD: 08/08/2021 - [0] SHD -- C:\ProgramData\Bureau O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 23/11/2021 - [0] D -- C:\ProgramData\DigitalWave.ApplicationUpdater_files O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 22/07/2022 - [] D -- C:\ProgramData\driverscloud.com O43 - CFD: 25/07/2022 - [] D -- C:\ProgramData\EnigmaSoft Limited O43 - CFD: 02/12/2021 - [] D -- C:\ProgramData\Freemake O43 - CFD: 25/08/2021 - [] D -- C:\ProgramData\Golden Frog, GmbH O43 - CFD: 24/07/2022 - [] D -- C:\ProgramData\GridinSoft O43 - CFD: 28/05/2022 - [] D -- C:\ProgramData\Hewlett-Packard O43 - CFD: 09/08/2021 - [0] D -- C:\ProgramData\IDM O43 - CFD: 07/01/2022 - [] D -- C:\ProgramData\Intel O43 - CFD: 22/07/2022 - [] D -- C:\ProgramData\IObit O43 - CFD: 14/08/2021 - [] D -- C:\ProgramData\IP-TV Player O43 - CFD: 22/07/2022 - [] D -- C:\ProgramData\iTop O43 - CFD: 22/07/2022 - [] D -- C:\ProgramData\iTop VPN O43 - CFD: 13/04/2022 - [] D -- C:\ProgramData\Kaspersky Lab O43 - CFD: 29/01/2022 - [] D -- C:\ProgramData\Kaspersky Lab Setup Files O43 - CFD: 02/03/2022 - [] RASHD -- C:\ProgramData\Key-Base O43 - CFD: 24/07/2022 - [] D -- C:\ProgramData\Malwarebytes O43 - CFD: 09/08/2021 - [] D -- C:\ProgramData\McAfee O43 - CFD: 08/08/2021 - [0] SHD -- C:\ProgramData\Menu Démarrer O43 - CFD: 22/07/2022 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 15/06/2022 - [] D -- C:\ProgramData\Microsoft Help O43 - CFD: 08/08/2021 - [0] SHD -- C:\ProgramData\Modèles O43 - CFD: 24/07/2022 - [] D -- C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 O43 - CFD: 28/05/2022 - [] D -- C:\ProgramData\Package Cache O43 - CFD: 06/09/2021 - [] D -- C:\ProgramData\Privax O43 - CFD: 22/07/2022 - [] D -- C:\ProgramData\ProductData O43 - CFD: 22/07/2022 - [] D -- C:\ProgramData\Qualcomm Atheros O43 - CFD: 10/06/2022 - [] D -- C:\ProgramData\Ralink Driver O43 - CFD: 09/08/2021 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 22/07/2022 - [] D -- C:\ProgramData\SystemAcCrux O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 16/12/2021 - [] D -- C:\ProgramData\Wondershare O43 - CFD: 22/07/2022 - [] D -- C:\ProgramData\{150F4013-6884-4350-8DDC-6BFCB4C5DC15} O43 - CFD: 27/01/2022 - [0] D -- C:\ProgramData\{20F10810-CBFA-2E53-81B5-CBD13DCB04CE} O43 - CFD: 22/12/2021 - [0] D -- C:\ProgramData\{7CAF6CAE-C307-668F-8B27-72406E7D1A5E} O43 - CFD: 04/03/2022 - [] D -- C:\ProgramData\{F86B0233-9A85-4589-8AAF-524CC4F8211B} O43 - CFD: 09/08/2021 - [] D -- C:\Program Files (x86)\Common Files\Adobe O43 - CFD: 09/08/2021 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER O43 - CFD: 28/05/2022 - [] D -- C:\Program Files (x86)\Common Files\DVDVideoSoft O43 - CFD: 08/08/2021 - [] D -- C:\Program Files (x86)\Common Files\Intel O43 - CFD: 04/03/2022 - [] D -- C:\Program Files (x86)\Common Files\IObit O43 - CFD: 10/08/2021 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Common Files\Services O43 - CFD: 11/05/2022 - [] D -- C:\Program Files (x86)\Common Files\System O43 - CFD: 25/07/2022 - [] D -- C:\Program Files (x86)\Common Files\Wise Installation Wizard O43 - CFD: 09/08/2021 - [] D -- C:\Users\Salah\AppData\Roaming\Adobe O43 - CFD: 26/06/2022 - [] D -- C:\Users\Salah\AppData\Roaming\Anvsoft O43 - CFD: 02/08/2022 - [] D -- C:\Users\Salah\AppData\Roaming\AVG O43 - CFD: 02/08/2022 - [] D -- C:\Users\Salah\AppData\Roaming\ChangZhi2 O43 - CFD: 22/05/2022 - [] D -- C:\Users\Salah\AppData\Roaming\Cybelsoft O43 - CFD: 14/08/2021 - [] D -- C:\Users\Salah\AppData\Roaming\Dat O43 - CFD: 02/12/2021 - [] D -- C:\Users\Salah\AppData\Roaming\Digiarty O43 - CFD: 03/08/2022 - [] D -- C:\Users\Salah\AppData\Roaming\DMCache O43 - CFD: 28/05/2022 - [] D -- C:\Users\Salah\AppData\Roaming\DVDVideoSoft O43 - CFD: 16/12/2021 - [] D -- C:\Users\Salah\AppData\Roaming\EaseUS O43 - CFD: 28/05/2022 - [0] D -- C:\Users\Salah\AppData\Roaming\Hewlett-Packard O43 - CFD: 29/01/2022 - [] D -- C:\Users\Salah\AppData\Roaming\Hola =>PUP.Optional.HolaSearch O43 - CFD: 28/05/2022 - [] D -- C:\Users\Salah\AppData\Roaming\hpqLog O43 - CFD: 27/01/2022 - [] D -- C:\Users\Salah\AppData\Roaming\iBeesoft O43 - CFD: 14/04/2022 - [] D -- C:\Users\Salah\AppData\Roaming\IDM O43 - CFD: 08/04/2022 - [] D -- C:\Users\Salah\AppData\Roaming\IDM Backup Manager O43 - CFD: 08/04/2022 - [] D -- C:\Users\Salah\AppData\Roaming\IDMGrabber O43 - CFD: 08/04/2022 - [] D -- C:\Users\Salah\AppData\Roaming\IDMidmmzcc5 O43 - CFD: 08/04/2022 - [0] D -- C:\Users\Salah\AppData\Roaming\IDMScheduler O43 - CFD: 16/12/2021 - [] D -- C:\Users\Salah\AppData\Roaming\iLikeVideoRecovery O43 - CFD: 14/02/2022 - [] D -- C:\Users\Salah\AppData\Roaming\IObit O43 - CFD: 14/08/2021 - [] D -- C:\Users\Salah\AppData\Roaming\IP-TV Player O43 - CFD: 10/08/2021 - [] D -- C:\Users\Salah\AppData\Roaming\iTop Screen Recorder O43 - CFD: 10/08/2021 - [] D -- C:\Users\Salah\AppData\Roaming\iTop Screenshot O43 - CFD: 02/08/2022 - [] D -- C:\Users\Salah\AppData\Roaming\lddownloader O43 - CFD: 20/06/2022 - [] D -- C:\Users\Salah\AppData\Roaming\Mendeley Reference Manager O43 - CFD: 25/07/2022 - [] SD -- C:\Users\Salah\AppData\Roaming\Microsoft O43 - CFD: 27/08/2021 - [] D -- C:\Users\Salah\AppData\Roaming\Mozilla O43 - CFD: 06/06/2022 - [] D -- C:\Users\Salah\AppData\Roaming\NoxSrv O43 - CFD: 18/01/2022 - [] D -- C:\Users\Salah\AppData\Roaming\Remo O43 - CFD: 19/08/2021 - [] D -- C:\Users\Salah\AppData\Roaming\SFVIP-Player O43 - CFD: 01/08/2022 - [] D -- C:\Users\Salah\AppData\Roaming\Telegram Desktop O43 - CFD: 21/12/2021 - [] D -- C:\Users\Salah\AppData\Roaming\TSMonitor O43 - CFD: 01/10/2021 - [] D -- C:\Users\Salah\AppData\Roaming\TunnelBear O43 - CFD: 29/07/2022 - [] D -- C:\Users\Salah\AppData\Roaming\vlc O43 - CFD: 14/08/2021 - [] D -- C:\Users\Salah\AppData\Roaming\WindowsIPTVPlayer O43 - CFD: 09/08/2021 - [] D -- C:\Users\Salah\AppData\Roaming\WinRAR O43 - CFD: 10/05/2022 - [] D -- C:\Users\Salah\AppData\Roaming\Wise Data Recovery O43 - CFD: 01/05/2022 - [] D -- C:\Users\Salah\AppData\Roaming\Wondershare O43 - CFD: 02/08/2022 - [] D -- C:\Users\Salah\AppData\Roaming\XuanZhi O43 - CFD: 05/08/2022 - [] D -- C:\Users\Salah\AppData\Roaming\ZHP O43 - CFD: 12/05/2022 - [] D -- C:\Users\Salah\AppData\Roaming\Zotero O43 - CFD: 12/05/2022 - [] D -- C:\Users\Salah\AppData\Local\@mendeley-internaldesktop-reference-manager-updater O43 - CFD: 06/02/2022 - [] D -- C:\Users\Salah\AppData\Local\Adobe O43 - CFD: 27/01/2022 - [] D -- C:\Users\Salah\AppData\Local\AnyRecover O43 - CFD: 08/08/2021 - [0] SHD -- C:\Users\Salah\AppData\Local\Application Data O43 - CFD: 02/08/2022 - [] D -- C:\Users\Salah\AppData\Local\AVG O43 - CFD: 16/08/2021 - [] D -- C:\Users\Salah\AppData\Local\BraveSoftware O43 - CFD: 06/02/2022 - [] D -- C:\Users\Salah\AppData\Local\cache O43 - CFD: 25/08/2021 - [] D -- C:\Users\Salah\AppData\Local\CEF O43 - CFD: 02/03/2022 - [] D -- C:\Users\Salah\AppData\Local\CleverFiles O43 - CFD: 25/07/2022 - [] D -- C:\Users\Salah\AppData\Local\CrashDumps O43 - CFD: 27/01/2022 - [] D -- C:\Users\Salah\AppData\Local\CrashRpt =>.Superfluous.CrashReports O43 - CFD: 28/07/2022 - [] D -- C:\Users\Salah\AppData\Local\Diagnostics O43 - CFD: 02/03/2022 - [] D -- C:\Users\Salah\AppData\Local\DiskDrill O43 - CFD: 05/08/2022 - [] D -- C:\Users\Salah\AppData\Local\DualSafe Password Manager O43 - CFD: 15/05/2022 - [0] D -- C:\Users\Salah\AppData\Local\ElevatedDiagnostics O43 - CFD: 08/08/2021 - [] SHD -- C:\Users\Salah\AppData\Local\EmieBrowserModeList O43 - CFD: 01/09/2021 - [0] SHD -- C:\Users\Salah\AppData\Local\EmieSiteList O43 - CFD: 01/09/2021 - [0] SHD -- C:\Users\Salah\AppData\Local\EmieUserList O43 - CFD: 18/08/2021 - [] D -- C:\Users\Salah\AppData\Local\ExpressVPN O43 - CFD: 02/12/2021 - [] D -- C:\Users\Salah\AppData\Local\FreemakeVideoConverter O43 - CFD: 09/08/2021 - [] D -- C:\Users\Salah\AppData\Local\Google O43 - CFD: 14/08/2021 - [] D -- C:\Users\Salah\AppData\Local\HeIn6 O43 - CFD: 08/08/2021 - [0] SHD -- C:\Users\Salah\AppData\Local\Historique O43 - CFD: 28/05/2022 - [] D -- C:\Users\Salah\AppData\Local\HP O43 - CFD: 01/10/2021 - [] D -- C:\Users\Salah\AppData\Local\IsolatedStorage O43 - CFD: 18/08/2021 - [] D -- C:\Users\Salah\AppData\Local\luminati O43 - CFD: 21/08/2021 - [] D -- C:\Users\Salah\AppData\Local\mbam O43 - CFD: 11/03/2022 - [] D -- C:\Users\Salah\AppData\Local\Mendeley Ltd O43 - CFD: 22/07/2022 - [] D -- C:\Users\Salah\AppData\Local\Microsoft O43 - CFD: 19/06/2022 - [] D -- C:\Users\Salah\AppData\Local\Microsoft Help O43 - CFD: 27/08/2021 - [] D -- C:\Users\Salah\AppData\Local\Mozilla O43 - CFD: 07/06/2022 - [] D -- C:\Users\Salah\AppData\Local\Nox O43 - CFD: 06/06/2022 - [] D -- C:\Users\Salah\AppData\Local\NoxSrv O43 - CFD: 19/07/2022 - [] D -- C:\Users\Salah\AppData\Local\Packages O43 - CFD: 27/01/2022 - [] D -- C:\Users\Salah\AppData\Local\PreviewWindow O43 - CFD: 11/03/2022 - [] D -- C:\Users\Salah\AppData\Local\Programs O43 - CFD: 15/06/2022 - [] D -- C:\Users\Salah\AppData\Local\Psiphon3 O43 - CFD: 24/07/2022 - [] D -- C:\Users\Salah\AppData\Local\RCS_LT O43 - CFD: 28/10/2021 - [] D -- C:\Users\Salah\AppData\Local\SHAREit Technologies O43 - CFD: 05/08/2022 - [] D -- C:\Users\Salah\AppData\Local\Temp O43 - CFD: 08/08/2021 - [0] SHD -- C:\Users\Salah\AppData\Local\Temporary Internet Files O43 - CFD: 01/10/2021 - [] D -- C:\Users\Salah\AppData\Local\TunnelBear O43 - CFD: 27/01/2022 - [] D -- C:\Users\Salah\AppData\Local\unali-19804281 O43 - CFD: 27/01/2022 - [] D -- C:\Users\Salah\AppData\Local\unali-19804484 O43 - CFD: 21/01/2022 - [] D -- C:\Users\Salah\AppData\Local\unali-242808468 O43 - CFD: 21/01/2022 - [] D -- C:\Users\Salah\AppData\Local\unali-242812390 O43 - CFD: 10/01/2022 - [] D -- C:\Users\Salah\AppData\Local\UnHackMe O43 - CFD: 22/07/2022 - [] D -- C:\Users\Salah\AppData\Local\VirtualStore O43 - CFD: 13/01/2022 - [] D -- C:\Users\Salah\AppData\Local\WiFi Guard O43 - CFD: 12/08/2021 - [] D -- C:\Users\Salah\AppData\Local\Windscribe O43 - CFD: 16/12/2021 - [] D -- C:\Users\Salah\AppData\Local\Wondershare O43 - CFD: 11/05/2022 - [] D -- C:\Users\Salah\AppData\Local\Yandex O43 - CFD: 15/01/2022 - [] D -- C:\Users\Salah\AppData\Local\ZHP O43 - CFD: 12/05/2022 - [] D -- C:\Users\Salah\AppData\Local\Zotero O43 - CFD: 21/11/2014 - [] RD -- C:\Users\Salah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 21/11/2014 - [] RD -- C:\Users\Salah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 12/05/2022 - [] RD -- C:\Users\Salah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 08/04/2022 - [] D -- C:\Users\Salah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager O43 - CFD: 02/08/2022 - [] D -- C:\Users\Salah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LDPlayer4 O43 - CFD: 22/08/2013 - [] D -- C:\Users\Salah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 25/07/2022 - [] D -- C:\Users\Salah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter =>.Superfluous.SpyHunter O43 - CFD: 22/07/2022 - [] RD -- C:\Users\Salah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 21/11/2014 - [] RD -- C:\Users\Salah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 13/02/2022 - [] D -- C:\Users\Salah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop O43 - CFD: 09/08/2021 - [] D -- C:\Users\Salah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ---\\ ShellIconOverlayIdentifiers (SIOI) (4) - 0s O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) [ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL {33000001797C2E574E52E1CAD6000100000179} =>.Microsoft Corporation O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) [ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL {33000001797C2E574E52E1CAD6000100000179} =>.Microsoft Corporation O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 3 (InSync) [ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL {33000001797C2E574E52E1CAD6000100000179} =>.Microsoft Corporation O106 - SIOI: AVG [00avg] - {472083B1-C522-11CF-8763-00608CC02F24}. (.AVG Technologies CZ, s.r.o. - AVG Shell Extension.) -- C:\Program Files\AVG\Antivirus\x86\ashShell.dll {073499E1104F5E75E721A7F15473BB1F} =>.AVG Technologies CZ, s.r.o. ---\\ Liste des pilotes du système (85) - 21s O58 - SDL:2013/08/22 13:43:41 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\drivers\3ware.sys [108896] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:41 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\Windows\System32\drivers\adp80xx.sys [782176] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:41 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [79200] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:41 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [259424] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:40 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [25952] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:41 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [114016] =>.Microsoft Windows® O58 - SDL:2010/01/05 03:23:20 A . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driv.) -- C:\Windows\System32\drivers\athurx.sys [1847296] =>.Atheros Communications, Inc. O58 - SDL:2022/08/02 17:33:49 A . (.AVG Technologies CZ, s.r.o. - AVG Anti Rootkit Disk Filter.) -- C:\Windows\System32\drivers\avgArDisk.sys [42000] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O58 - SDL:2022/08/02 17:33:49 A . (.AVG Technologies CZ, s.r.o. - AVG Anti Rootkit.) -- C:\Windows\System32\drivers\avgArPot.sys [235736] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O58 - SDL:2022/08/02 17:33:41 A . (.AVG Technologies CZ, s.r.o. - AVG IDS Application Activity Monitor Driver.) -- C:\Windows\System32\drivers\avgbidsdriver.sys [389208] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O58 - SDL:2022/08/02 17:35:14 A . (.AVG Technologies CZ, s.r.o. - AVG Application Activity Monitor Helper Dri.) -- C:\Windows\System32\drivers\avgbidsh.sys [258128] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O58 - SDL:2022/08/02 17:35:14 A . (.AVG Technologies CZ, s.r.o. - AVG Universal Driver.) -- C:\Windows\System32\drivers\avgbuniv.sys [105560] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O58 - SDL:2022/08/02 17:34:33 A . (.AVG Technologies CZ, s.r.o. - AVG Keyboard Filter Driver.) -- C:\Windows\System32\drivers\avgKbd.sys [48144] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O58 - SDL:2022/08/02 17:35:01 A . (.AVG Technologies CZ, s.r.o. - AVG File System Filter.) -- C:\Windows\System32\drivers\avgMonFlt.sys [275176] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O58 - SDL:2022/08/02 17:34:33 A . (.AVG Technologies CZ, s.r.o. - AVG Network Security Driver.) -- C:\Windows\System32\drivers\avgNetHub.sys [554080] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O58 - SDL:2022/08/02 17:34:37 A . (.AVG Technologies CZ, s.r.o. - AVG Antivirus.) -- C:\Windows\System32\drivers\avgRdr2.sys [114112] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O58 - SDL:2022/08/02 17:35:03 A . (.AVG Technologies CZ, s.r.o. - AVG Revert.) -- C:\Windows\System32\drivers\avgRvrt.sys [89176] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O58 - SDL:2022/08/02 17:33:48 A . (.AVG Technologies CZ, s.r.o. - AVG Antivirus.) -- C:\Windows\System32\drivers\avgSnx.sys [860024] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O58 - SDL:2022/08/02 17:36:39 A . (.AVG Technologies CZ, s.r.o. - AVG Self Protection.) -- C:\Windows\System32\drivers\avgSP.sys [670904] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O58 - SDL:2022/08/02 17:35:15 A . (.AVG Technologies CZ, s.r.o. - AVG Stream Filter.) -- C:\Windows\System32\drivers\avgStm.sys [221656] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O58 - SDL:2022/08/02 17:35:22 A . (.AVG Technologies CZ, s.r.o. - AVG VM Monitor.) -- C:\Windows\System32\drivers\avgVmm.sys [324984] {03EC0C9015079FAB8A6F3FC9F839311C} =>.AVG Technologies CZ, s.r.o. O58 - SDL:2013/08/13 00:25:46 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\drivers\bcmfn2.sys [17624] =>.Broadcom Corporation® O58 - SDL:2020/12/04 15:15:28 A . (.Bitdefender - BDDCI filter driver.) -- C:\Windows\System32\drivers\bddci.sys [802976] {0A5905DAB5BC122356B9F8BCEFCAAFDA} =>.BitDefender O58 - SDL:2013/08/22 13:43:41 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [531296] =>.Microsoft Windows® O58 - SDL:2022/07/31 12:35:38 A . (.EnigmaSoft Limited - SpyHunter Guard.) -- C:\Windows\System32\drivers\EnigmaFileMonDriver.sys [76744] {0A64EFC7170E63B64A6E390EEB577FE9} O58 - SDL:2013/08/22 13:43:45 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3357024] =>.Microsoft Windows® O58 - SDL:2022/07/31 11:29:04 A . (.Malwarebytes - Malwarebytes Anti-Ransomware Protection.) -- C:\Windows\System32\drivers\farflt.sys [192960] {33000000DC341A520FBBCF3D8C0000000000DC} =>.Malwarebytes O58 - SDL:2022/07/11 11:59:18 A . (...) -- C:\Windows\System32\drivers\GSDriver64.sys [48464] {33000000433A68189E33902987000000000043} O58 - SDL:2022/07/11 11:59:18 A . (.GridinSoft LLC - GridinSoft Internet Security Driver.) -- C:\Windows\System32\drivers\gsInetSecurity.sys [107784] {020CD424A7487F24C381DCC4CFEFA858} O58 - SDL:2021/09/30 01:41:30 A . (.BitDefender LLC - BitDefender Gonzales FileSystem Driver.) -- C:\Windows\System32\drivers\gzflt.sys [176008] {33000000B5213FCA1E4AA03DE40000000000B5} =>.BitDefender LLC O58 - SDL:2018/09/05 21:01:44 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\Windows\System32\drivers\hmatap.sys [45560] {03099740813BBAA46B9E69161800C46E} =>.The OpenVPN Project O58 - SDL:2013/08/22 13:43:45 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [64352] =>.Microsoft Windows® O58 - SDL:2013/07/30 19:47:35 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568] =>.Intel Corporation - Software and Firmware Products® O58 - SDL:2013/07/25 20:05:39 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320] =>.Intel Corporation - Software and Firmware Products® O58 - SDL:2021/08/10 07:25:15 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver -.) -- C:\Windows\System32\drivers\iaStorA.sys [1469952] {330000B97FAEF583F53CC47FCD00020000B97F} =>.Intel Corporation O58 - SDL:2013/08/10 01:39:30 A . (.Intel Corporation - Intel Rapid Storage Technology driver (inbo.) -- C:\Windows\System32\drivers\iaStorAV.sys [651248] =>.Intel Corporation - Intel® Rapid Storage Technology® O58 - SDL:2013/08/22 13:43:45 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [412000] =>.Microsoft Windows® O58 - SDL:2018/12/20 01:05:20 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\drivers\idmwfp.sys [229296] {7828C7315808BC8717710E13FA3C0B24} =>.Tonec Inc. O58 - SDL:2021/08/10 07:26:26 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd64.sys [4961640] {5600000C3BF9A3682289A06F40000000000C3B} =>.Intel Corporation O58 - SDL:2015/11/17 18:39:19 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\Windows\System32\drivers\intelaud.sys [51704] {330000B7E741A34024FC3AB6E700020000B7E7} =>.Intel Corporation O58 - SDL:2015/11/17 18:39:19 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\Windows\System32\drivers\iwdbus.sys [39920] {330000B7E741A34024FC3AB6E700020000B7E7} =>.Intel Corporation O58 - SDL:2021/02/19 21:09:00 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\Windows\System32\drivers\kltap.sys [55592] {632A7292CC35B3207DDA7B403F36EF9E} =>.The OpenVPN Project O58 - SDL:2013/08/22 13:43:44 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [109408] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:45 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [93536] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:44 A . (.LSI Corporation - LSI SAS Gen3 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas3.sys [81760] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:45 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sss.sys [82784] =>.Microsoft Windows® O58 - SDL:2022/07/24 22:24:23 A . (.Malwarebytes - Malwarebytes Anti-Exploit.) -- C:\Windows\System32\drivers\mbae64.sys [158640] {33000000DC341A520FBBCF3D8C0000000000DC} =>.Malwarebytes O58 - SDL:2022/07/31 11:29:10 A . (.Malwarebytes - Malwarebytes Real-Time Protection.) -- C:\Windows\System32\drivers\mbam.sys [74704] {33000000DC341A520FBBCF3D8C0000000000DC} =>.Malwarebytes O58 - SDL:2022/07/31 11:28:57 A . (.Malwarebytes - Malwarebytes Chameleon.) -- C:\Windows\System32\drivers\MbamChameleon.sys [223176] {33000000C45021BA6ED85A72AD0000000000C4} =>.Malwarebytes O58 - SDL:2022/07/25 08:24:41 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- C:\Windows\System32\drivers\mbamswissarmy.sys [239544] {33000000DC341A520FBBCF3D8C0000000000DC} =>.Malwarebytes O58 - SDL:2013/08/22 13:43:45 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [56672] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:45 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\megasr.sys [575840] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:49 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\drivers\mvumis.sys [63840] =>.Microsoft Windows® O58 - SDL:2022/07/31 11:29:00 A . (.Malwarebytes - Malwarebytes Web Protection.) -- C:\Windows\System32\drivers\mwac.sys [181992] {00A657F778B31AE523D667131718D16EB2} =>.Malwarebytes O58 - SDL:2014/04/09 21:06:16 A . (.Ralink Technology, Corp. - Ralink 802.11 Wireless Adapter Driver.) -- C:\Windows\System32\drivers\netr28x.sys [2514120] =>.Mediatek Inc.® O58 - SDL:2020/06/10 13:40:56 A . (.WireGuard LLC - Nlwt Driver.) -- C:\Windows\System32\drivers\nlwt.sys [29888] {7B0F7049634BD8FD7F77A580} O58 - SDL:2013/08/22 13:43:31 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [150368] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:32 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [168288] =>.Microsoft Windows® O58 - SDL:2021/09/19 15:59:55 A . (...) -- C:\Windows\System32\drivers\rkflt.sys [42056] {08355BFD0507F280FFF7333A0E701393} O58 - SDL:2009/02/12 15:11:26 A . (.EldoS Corporation - RawDisk Driver. Allows write access to file.) -- C:\Windows\System32\drivers\rsdrvx64.sys [26024] =>.EldoS Corporation® O58 - SDL:2021/08/12 14:20:04 A . (.Realtek - Realtek 8125/8136/8168/8169 NDIS 6.30 64-bi.) -- C:\Windows\System32\drivers\Rt630x64.sys [1140712] {0BFCFAC08E216A1C1FDAA6B77BB2D66E} =>.Realtek O58 - SDL:2021/08/10 07:24:34 A . (.Ralink Technology, Corp. - Ralink Bluetooth Adapter.) -- C:\Windows\System32\drivers\rtbth.sys [1210480] =>.MEDIATEK INC.® O58 - SDL:2022/04/10 13:51:18 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHD64.sys [5954144] {0BFCFAC08E216A1C1FDAA6B77BB2D66E} =>.Realtek Semiconductor Corp. O58 - SDL:2020/05/24 23:02:26 A . (.Realtek Semiconductor Corp. - Realtek Pcie CardReader Driver for 2K/XP/Vi.) -- C:\Windows\System32\drivers\RtsP2Stor.sys [347224] {04DF4D56733AE38D598EA004DD2D9C51} =>.Realtek Semiconductor Corp. O58 - SDL:2013/08/22 16:35:09 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] =>.Macrovision Corporation, Macrovision Europe Limited, O58 - SDL:2013/08/22 13:43:31 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [44896] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:32 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [81760] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:32 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\Windows\System32\drivers\stexstor.sys [31072] =>.Microsoft Windows® O58 - SDL:2021/06/17 18:13:04 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver.) -- C:\Windows\System32\drivers\tap-tb-0901.sys [38656] =>.TunnelBear, Inc.® O58 - SDL:2021/06/15 10:38:24 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\Windows\System32\drivers\tap0901.sys [28160] =>.The OpenVPN Project O58 - SDL:2020/07/09 20:06:58 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\Windows\System32\drivers\tap0901cn.sys [38216] {0BB125B299BF587BDC90DB83A2A825BA} =>.The OpenVPN Project O58 - SDL:2021/06/28 07:44:42 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\Windows\System32\drivers\tapexpressvpn.sys [36208] {07A0ED6DDF2FFED5914CCF4CAB68B414} =>.The OpenVPN Project O58 - SDL:2020/06/09 10:25:46 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\Windows\System32\drivers\tapnordvpn.sys [35592] {1C71DEFE3284E66D55131E70} =>.The OpenVPN Project O58 - SDL:2021/06/15 10:38:24 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver.) -- C:\Windows\System32\drivers\tapvyprvpn.sys [44896] =>.Golden Frog, GmbH® O58 - SDL:2021/08/12 14:18:32 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\Windows\System32\drivers\tapwindscribe0901.sys [48544] {0AF4B47E1A5EEDA06DB90E772E799A07} =>.The OpenVPN Project O58 - SDL:2017/11/28 04:27:38 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\drivers\TeeDriverW8x64.sys [206488] {56000001757376CD78AD000C9A000000000175} =>.Intel Corporation O58 - SDL:2021/09/19 15:59:55 A . (...) -- C:\Windows\System32\drivers\truesight.sys [38032] {08355BFD0507F280FFF7333A0E701393} O58 - SDL:2021/10/01 04:09:06 A . (.Bitdefender - Trufos Kernel Module.) -- C:\Windows\System32\drivers\Trufos.sys [615840] {33000000B5213FCA1E4AA03DE40000000000B5} =>.BitDefender O58 - SDL:2021/09/21 06:53:20 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [19720] {33000002ED2C45E4C145CF48440000000002ED} =>.VIA Technologies, Inc. O58 - SDL:2013/08/22 13:43:34 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [168800] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:34 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\drivers\VSTXRAID.SYS [305504] =>.Microsoft Windows® O58 - SDL:2021/08/12 14:18:32 A . (...) -- C:\Windows\System32\drivers\WindscribeSplitTunnel.sys [25384] {0AF4B47E1A5EEDA06DB90E772E799A07} O58 - SDL:2021/08/12 14:18:32 A . (.WireGuard LLC - Wintun Driver.) -- C:\Windows\System32\drivers\windtun420.sys [38312] {0AF4B47E1A5EEDA06DB90E772E799A07} O58 - SDL:2021/03/09 18:41:08 A . (...) -- C:\Windows\System32\pwdrvio.sys [37336] =>.MiniTool Solution Ltd® O58 - SDL:2019/11/08 10:15:12 A . (...) -- C:\Windows\System32\pwdspio.sys [12504] =>.MiniTool Solution Ltd® ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (6) - 114s O61 - LFC: 2022/08/02 17:21:21 A . (.XUANZHI CHINA.) -- C:\Users\Salah\Downloads\Programs\LDPlayer4_fr_com.facebook.lite_8110_ld.exe [3346760] {0D65082368F94330123C9A853A2FDEBF} O61 - LFC: 2022/08/02 17:31:27 A . (..) -- C:\Users\Salah\AppData\Roaming\XuanZhi\ldopengl32x.dll [72672] {0D65082368F94330123C9A853A2FDEBF} O61 - LFC: 2022/08/05 09:27:44 A . (..) -- C:\Users\Salah\AppData\LocalLow\IGDump\rdjgiulczvcmlkrzfvdljcojqqxciorz\sample.dll [541384] {00A657F778B31AE523D667131718D16EB2} O61 - LFC: 2022/08/03 12:27:28 A . (..) -- C:\Users\Salah\AppData\LocalLow\IGDump\fogcfbtkhbetvfstxdwvwaswozbhvrdc\sample.dll [541384] {00A657F778B31AE523D667131718D16EB2} O61 - LFC: 2022/08/05 11:55:49 A . (..) -- C:\Users\Salah\AppData\Local\Google\Chrome\User Data\Default\Sync Data\Nigori.bin [737] O61 - LFC: 2022/08/03 13:25:09 A . (..) -- C:\Users\Salah\AppData\Local\Adobe\Acrobat\DC\ProtectedView\UserCache.bin [84495] ---\\ Associations Shell Spawning (10) - 1s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe {33000001797C2E574E52E1CAD6000100000179} =>.Microsoft Corporation O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe =>.Microsoft Corporation O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S ---\\ Menu de démarrage Internet (20) - 1s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Brave Software, Inc. - Brave Browser.) -- C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe {05488AD7E4BABA7F93E3323C0573BF3C} O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe {0C1CD3EEA47EDDA7A032573B014D0AFD} =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe {0E4418E2DEDE36DD2974C3443AFB5CE5} O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe {33000001797C2E574E52E1CAD6000100000179} =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe {33000002D0E7EB7C2EF6CE23E10000000002D0} =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Brave Software, Inc. - Brave Browser.) -- C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Brave Software, Inc. - Brave Browser.) -- C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Brave Software, Inc. - Brave Browser.) -- C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google LLC - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation ---\\ Recherche d'infection sur les navigateurs (2) - 10s O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ ---\\ Enumère les services démarrés par Svchost (36) - 2s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [214528] =>.Microsoft Corporation O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [158720] =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [158720] =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\system32\srvsvc.dll [329728] =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [1381376] =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [1077248] =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [929280] =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\system32\seclogon.dll [31744] =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [110080] =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\system32\iscsiexe.dll [151040] =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [110592] =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\system32\schedsvc.dll [1265152] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [231936] =>.Microsoft Corporation O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\system32\mmcss.dll [71168] =>.Microsoft Corporation O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [135168] =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [230400] =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [346112] =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [87040] =>.Microsoft Corporation O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\system32\kmsvc.dll [101376] =>.Microsoft Corporation O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [349184] =>.Microsoft Corporation O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service d’infrastructure de localisation Wi.) -- C:\Windows\System32\GeofenceMonitorService.dll [522240] =>.Microsoft Corporation O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\Windows\system32\wlidsvc.dll [1639424] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\system32\themeservice.dll [59392] =>.Microsoft Corporation O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\Windows\System32\DeviceSetupManager.dll [206848] =>.Microsoft Corporation O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\Windows\System32\ncasvc.dll [166912] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [102912] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\Windows\System32\rasmans.dll [543232] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [233472] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\sens.dll [73728] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [452608] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [313856] =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\system32\wuaueng.dll [3722240] =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [936448] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [640000] =>.Microsoft Corporation O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [187904] =>.Microsoft Corporation O83 - Search Svchost Services: MsKeyboardFilter (MsKeyboardFilter) . (.Microsoft Corporation - SvcHost Service for Microsoft Keyboard Filt.) -- C:\Windows\System32\KeyboardFilterSvc.dll [93008] {33000001733031072665B8B9B3000000000173} =>.Microsoft Corporation ---\\ Liste des exceptions du parefeu Windows (10) - 3s O87 - FAEL: "{7A23D776-363E-4931-96C2-77DE52E5E29B}" [In-None-P6-TRUE] .(.ADSL Club LLC - IP-TV Player.) -- C:\Program Files (x86)\IP-TV Player\IpTvPlayer.exe {5155BAB0E61C3A47C12B07CE0E5CE253} O87 - FAEL: "{302CE7A9-7C06-47A7-B0FB-1E41CCD2B31C}" [In-None-P17-TRUE] .(.ADSL Club LLC - IP-TV Player.) -- C:\Program Files (x86)\IP-TV Player\IpTvPlayer.exe {5155BAB0E61C3A47C12B07CE0E5CE253} O87 - FAEL: "TCP Query User{A961B341-7D6E-4B64-85FE-39ADDD9A2C40}C:\program files\hola\app\chromium\hola_cr.exe" [In-None-P6-TRUE] .(.Hola VPN Ltd. - Hola Browser.) -- C:\program files\hola\app\chromium\hola_cr.exe {3BE54518045FEF7A1954AC675CE01ED5} O87 - FAEL: "UDP Query User{05292741-4BE3-459B-B139-80EBD5B0BB57}C:\program files\hola\app\chromium\hola_cr.exe" [In-None-P17-TRUE] .(.Hola VPN Ltd. - Hola Browser.) -- C:\program files\hola\app\chromium\hola_cr.exe {3BE54518045FEF7A1954AC675CE01ED5} O87 - FAEL: "{655A3F11-D20B-476D-97E9-0E945DE55294}" [In-None-P6-TRUE] .(.SHAREit Technologies Co.Ltd - SHAREit.) -- C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe {3E04076D4B53A8436FD2665B5029C627} O87 - FAEL: "{B47EAC16-ED46-45B6-BA94-53F7FBF6B257}" [In-None-P17-TRUE] .(.SHAREit Technologies Co.Ltd - SHAREit.) -- C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe {3E04076D4B53A8436FD2665B5029C627} O87 - FAEL: "TCP Query User{69E9EF2B-09E2-493B-AD2A-1E1B0E8CB406}C:\program files\hola\app\chromium\hola_cr.exe" [In-None-P6-TRUE] .(.Hola VPN Ltd. - Hola Browser.) -- C:\program files\hola\app\chromium\hola_cr.exe {3BE54518045FEF7A1954AC675CE01ED5} O87 - FAEL: "UDP Query User{026901FB-F56E-4F7B-A5ED-7298918D4CE9}C:\program files\hola\app\chromium\hola_cr.exe" [In-None-P17-TRUE] .(.Hola VPN Ltd. - Hola Browser.) -- C:\program files\hola\app\chromium\hola_cr.exe {3BE54518045FEF7A1954AC675CE01ED5} O87 - FAEL: "{A566E74D-C214-4EB3-947F-A37A14D9C32B}" [In-None-P6-TRUE] .(...) -- C:\Users\Salah\Downloads\Programs\4ddig-for-windows.exe (.not file.) O87 - FAEL: "{CBE0B0F1-4F7C-4A6B-A314-29B5590E5D1A}" [In-None-P17-TRUE] .(...) -- C:\Users\Salah\Downloads\Programs\4ddig-for-windows.exe (.not file.) ---\\ Scan Additionnel (18) - 0s HKLM\SYSTEM\CurrentControlSet\Services\EsgShKernel =>.Superfluous.SpyHunter C:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exe =>.Superfluous.SpyHunter HKLM\SYSTEM\CurrentControlSet\Services\ShMonitor =>.Superfluous.SpyHunter C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe =>.Superfluous.SpyHunter C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe =>PUP.Optional.Boxore C:\Windows\System32\Tasks\BraveSoftwareUpdateTaskMachineCore =>PUP.Optional.Boxore C:\Windows\System32\Tasks\BraveSoftwareUpdateTaskMachineUA =>PUP.Optional.Boxore C:\Windows\System32\Tasks\SpyHunter4Startup =>.Superfluous.Enigma HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyHunter5 =>.Superfluous.SpyHunter HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4941BFEB-62C0-47A2-801E-998FC469CC2C} =>.Superfluous.SpyHunter HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SpyHunter5 =>.Superfluous.SpyHunter HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4941BFEB-62C0-47A2-801E-998FC469CC2C} =>.Superfluous.SpyHunter HKLM\SOFTWARE\Wow6432Node\EnigmaSoftwareGroup =>.Superfluous.Enigma HKCU\SOFTWARE\b4b58389-01e4-5dfd-9842-aad36733657a =>PUP.Optional.CrossRider C:\Program Files (x86)\Enigma Software Group =>.Superfluous.Enigma C:\Users\Salah\AppData\Roaming\Hola =>PUP.Optional.HolaSearch C:\Users\Salah\AppData\Local\CrashRpt =>.Superfluous.CrashReports C:\Users\Salah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter =>.Superfluous.SpyHunter ---\\ Récapitulatif des éléments trouvés sur votre station (6) - 0s http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.SpyHunter http://www.nicolascoolman.fr/?p=90 =>PUP.Optional.Boxore http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.Enigma http://www.nicolascoolman.fr/?p=180 =>PUP.Optional.CrossRider http://www.nicolascoolman.fr/?p=1161 =>PUP.Optional.HolaSearch http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.CrashReports ~ End of the scan, 40208 items in 00h06mn17s (1023)(0)