Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

[Résolu] Nouvelle infection


fredorp59

Messages recommandés

Bonjour,

 

J'ai des infections de Norton Security PUA.FormatFactory, PUA.Downloader et,PUA.OpenCandy, voici le rapport ZHP Diag :

 

 

~ ZHPDiag v2017.10.20.184 Par Nicolas Coolman (2017/10/20)
~ Démarré par rpgis (Administrator) (2017/10/22 17:52:01)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Legal
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\rpgis\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\rpgis\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
Windows 10 Home, 64-bit (Build 15063) =>.Microsoft Corporation

---\\ Navigateurs Internet (4) - 0s
~ GCIE: Google Chrome v62.0.3202.62
~ MFIE: Mozilla Firefox 56.0.1 (x64 en-US)
~ MSIE: Microsoft Edge v40
~ MSIE: Internet Explorer v11.674.15063.0

---\\ Informations sur les produits Windows (icon_cool.gif - 0s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
~ Windows® Operating System, OEM_DM channel
Windows ID Activation : OK
~ Windows Partial Key : 7XMK3
Windows License : OK
~ Windows Remaining Initializations Number : 1001
Windows Automatic Updates : OK

---\\ Logiciels de protection (3) - 6s
Norton Security v22.9.3.13 (Protection)
Malwarebytes version 3.2.2.2029 v3.2.2.2029 (Protection)
Windows Defender (Deactivate)

---\\ Logiciels d'optimisation (1) - 6s
~ CCleaner v5.35 (Optimize)

---\\ Informations sur le système (6) - 0s
~ Operating System: Intel64 Family 6 Model 158 Stepping 9, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 6249.128 MB (21% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 311 GB (65%) free of 476 GB : OK =>.Disk Space

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: DESKTOP-UO4GK42
~ User Name: rpgis
~ Logged in as Administrator

---\\ Enumération des unités disques (3) - 0s
~ Drive C: has 311 GB free of 476 GB (System)
~ Drive D: has 474 GB free of 476 GB
~ Drive F: has 6 GB free of 7 GB

---\\ Etat du Centre de Sécurité Windows (7) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Recherche particulière de fichiers génériques (25) - 2s
[MD5.01078D46C77CE0D7DC584A29062A799D] - 11/05/2017 - (.Microsoft Corporation - Explorateur Windows.) -- C:\WINDOWS\Explorer.exe [4848952] =>.Microsoft Windows®
[MD5.ECB702B8C5650381C0784F1EEABB97BC] - 11/05/2017 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [68608] =>.Microsoft Corporation
[MD5.0242626678C83AE788C655C1990A3CC3] - 11/05/2017 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\WINDOWS\System32\Wininit.exe [318232] =>.Microsoft Windows Publisher®
[MD5.57DA6FA5B8E23F33EA6D19F37CD73DD8] - 11/05/2017 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\WINDOWS\System32\wininet.dll [3307008] =>.Microsoft Corporation
[MD5.9CDA170849A4F66F4D68B3DBB3AC8394] - 11/05/2017 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\WINDOWS\System32\Winlogon.exe [706560] =>.Microsoft Corporation
[MD5.50CDF68A8EA8A2A9165CD573FA6C42D8] - 11/05/2017 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\WINDOWS\System32\sppcomapi.dll [414208] =>.Microsoft Corporation
[MD5.6AFA66A457759C1FEC29A52612A67043] - 11/05/2017 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\WINDOWS\System32\dnsapi.dll [661224] =>.Microsoft Windows®
[MD5.1F4909406532C2FFCBD3683A65F7198F] - 11/05/2017 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\WINDOWS\Syswow64\dnsapi.dll [508344] =>.Microsoft Windows®
[MD5.70E14A01193D817004C0F88E767BC59B] - 11/05/2017 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\WINDOWS\System32\fr-FR\user32.dll.mui [19968] =>.Microsoft Corporation
[MD5.5A6D591D56791BA63CE73FCAD60D89A1] - 11/05/2017 - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [610720] =>.Microsoft Windows®
[MD5.01733BEEE02E51F712330D5909BD701C] - 11/05/2017 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [29088] =>.Microsoft Windows®
[MD5.B6E5AD7C83A5254DEE9D86023C0E5A81] - 11/05/2017 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [93184] =>.Microsoft Corporation
[MD5.ABE77AD954BC3D72F559CF0C381E50BC] - 11/05/2017 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [160256] =>.Microsoft Corporation
[MD5.185A4519B7764F4DEF714D890A7A9FD2] - 11/05/2017 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [150528] =>.Microsoft Corporation
[MD5.02B9639D9997E95CDF2F4C4F3BDCC73D] - 11/05/2017 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [86528] =>.Microsoft Corporation
[MD5.C6C8315E3262FAE460529C6DA2951682] - 11/05/2017 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [115200] =>.Microsoft Corporation
[MD5.DCC05E5EAA580C97F13B434FAFACED85] - 11/05/2017 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [214528] =>.Microsoft Corporation
[MD5.F2AD1B72C5A6475FB5FF332E1980DF88] - 11/05/2017 - (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [467352] =>.Microsoft Windows®
[MD5.BAD3C424788BC071C3EC82CFCDA954D2] - 11/05/2017 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [305152] =>.Microsoft Corporation
[MD5.CDB804F3EA333459FE3C21D61767CBB1] - 11/05/2017 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2327448] =>.Microsoft Windows®
[MD5.2CC6C325B271C7CA60F374F8F868CB45] - 11/05/2017 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\WINDOWS\System32\drivers\Parport.sys [97792] =>.Microsoft Corporation
[MD5.5279EC98F6218D29EADDFECCC0D80E9A] - 11/05/2017 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [107008] =>.Microsoft Corporation
[MD5.53A01D3FDB701AC5D9DDE4140227E3D9] - 11/05/2017 - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [183296] =>.Microsoft Corporation
[MD5.D74756DD1518D28A09CDA99696273FA4] - 11/05/2017 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [119712] =>.Microsoft Windows®
[MD5.E3429DBBEA3965BB96E24B16EF4A2551] - 11/05/2017 - (.Microsoft Corporation - Volume Shadow Copy driver.) -- C:\WINDOWS\System32\drivers\volsnap.sys [397216] =>.Microsoft Windows®

---\\ Liste des services NT non Microsoft et non désactivés (14) - 1s
O23 - Service: CCDMonitorService (CCDMonitorService) . (.Acer Incorporated - CCD Monitor Service.) - C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe =>.Acer Incorporated®
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) . (.Intel® Corporation - Intel® PROSet/Wireless Event Log Service.) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe =>.Intel Corporation-Wireless Connectivity Solutions®
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation - IAStorDataSvc.) - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe =>.Intel® Rapid Storage Technology®
O23 - Service: @oem15.inf,%SERVICE_NAME%;Intel Bluetooth Service (ibtsiva) . (...) - C:\WINDOWS\System32\ibtsiva (.not file.) =>.Intel Corporation
O23 - Service: Intel® Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel® Dynamic Application Loader Host In.) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
O23 - Service: Intel® Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Intel® Local Management Service.) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
O23 - Service: Malwarebytes Service (MBAMService) . (.Malwarebytes - Malwarebytes Service.) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation®
O23 - Service: Norton Security (NS) . (.Symantec Corporation - Norton Security.) - C:\Program Files (x86)\Norton Security\Engine\22.9.3.13\NS.exe =>.Symantec Corporation®
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) . (.NVIDIA Corporation - NVIDIA Container.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation®
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) . (.NVIDIA Corporation - NVIDIA Container.) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe =>.NVIDIA Corporation®
O23 - Service: NVIDIA Wireless Controller Service (NVIDIA Wireless Controller Service) . (.NVIDIA Corporation - NVIDIA Wireless Controller Service.) - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe =>.NVIDIA Corporation®
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) . (.Intel® Corporation - Intel® PROSet/Wireless Registry Service.) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe =>.Intel Corporation-Wireless Connectivity Solutions®
O23 - Service: Intel® PROSet/Wireless Zero Configuration Service (ZeroConfigService) . (.Intel® Corporation - Intel® PROSet/Wireless Zero Configure Servi.) - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe =>.Intel Corporation-Wireless Connectivity Solutions®

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (22) - 21s
SR - Auto [11/05/2017] [ 326160] CCDMonitorService (CCDMonitorService) . (.Acer Incorporated.) - C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe =>.Acer Incorporated®
SR - Auto [11/05/2017] [ 326160] Intel® PROSet/Wireless Event Log (EvtEng) . (.Intel® Corporation.) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe =>.Intel Corporation-Wireless Connectivity Solutions®
SS - Auto [11/05/2017] [ 326160] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [11/05/2017] [ 326160] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SR - Auto [11/05/2017] [ 326160] Intel® Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe =>.Intel® Rapid Storage Technology®
SR - Auto [11/05/2017] [ 326160] @oem15.inf,%SERVICE_NAME%;Intel Bluetooth Service (ibtsiva) . (...) - C:\WINDOWS\System32\ibtsiva =>.Intel Corporation
SS - Demand [11/05/2017] [ 326160] Intel® Capability Licensing Service TCP IP Interface (Intel® Capability Licensing Service TCP IP Interface) . (.Intel® Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe =>.Intel® Trusted Connect Service®
SR - Auto [11/05/2017] [ 326160] Intel® Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
SR - Auto [11/05/2017] [ 326160] Intel® Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
SR - Auto [11/05/2017] [ 326160] Malwarebytes Service (MBAMService) . (.Malwarebytes.) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation®
SS - Demand [11/05/2017] [ 326160] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation®
SS - Demand [11/05/2017] [ 326160] Wireless PAN DHCP Server (MyWiFiDHCPDNS) . (.Copyright © 2005-2010 by Achal Dhir.) - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe =>.Intel Corporation-Wireless Connectivity Solutions®
SR - Auto [11/05/2017] [ 326160] Norton Security (NS) . (.Symantec Corporation.) - C:\Program Files (x86)\Norton Security\Engine\22.9.3.13\NS.exe =>.Symantec Corporation®
SR - Auto [11/05/2017] [ 326160] NVIDIA LocalSystem Container (NvContainerLocalSystem) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation®
SS - Demand [11/05/2017] [ 326160] NVIDIA NetworkService Container (NvContainerNetworkService) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation®
SR - Auto [11/05/2017] [ 326160] NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe =>.NVIDIA Corporation®
SR - Auto [11/05/2017] [ 326160] NVIDIA Wireless Controller Service (NVIDIA Wireless Controller Service) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe =>.NVIDIA Corporation®
SR - Demand [11/05/2017] [ 326160] Quick Access Service (QASvc) . (.Acer Incorporated.) - C:\Program Files\Acer\Acer Quick Access\QASvc.exe =>.Acer Incorporated®
SR - Auto [11/05/2017] [ 326160] Intel® PROSet/Wireless Registry Service (RegSrvc) . (.Intel® Corporation.) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe =>.Intel Corporation-Wireless Connectivity Solutions®
SR - Demand [11/05/2017] [ 326160] Steam Client Service (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe =>.Valve®
SS - Demand [11/05/2017] [ 326160] User Experience Improvement Program (UEIPSvc) . (.acer.) - C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe =>.Acer Incorporated®
SS - Auto [11/05/2017] [ 326160] Intel® PROSet/Wireless Zero Configuration Service (ZeroConfigService) . (.Intel® Corporation.) - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe =>.Intel Corporation-Wireless Connectivity Solutions®

---\\ Tâches planifiées en automatique (Registre) (106) - 6s
O38 - TASK: {00BBC35E-A8B3-4C07-A05F-7E94306F4978} [64Bits][\AcerCMUpdateTask2.1.16258] - (.Copyright © 2016 by Acer - AWC.) -- C:\Program Files (x86)\Acer\Amundsen\2.1.16258\AWC.exe [152880] =>.Acer Incorporated®
O38 - TASK: {01906D0C-97C2-4CF3-AF9D-E92DC2A5EC03} [64Bits][\Norton WSC Integration] - (.Symantec Corporation - WSCStub.) -- C:\Program Files (x86)\Norton Security\Engine\22.9.3.13\WSCStub.exe [3800320] =>.Symantec Corporation®
O38 - TASK: {03A27619-8317-4B76-8A4A-AC204C77F591} [64Bits][\Microsoft\Windows\Windows Media Sharing\UpdateLibrary] - (.Microsoft Corporation - Application de configuration du service Par.) -- C:\Program Files\Windows Media Player\wmpnscfg.exe [70144] =>.Microsoft Corporation
O38 - TASK: {05C35C43-30B0-478C-A045-7452BCE45E4E} [64Bits][\Microsoft\Windows\Defrag\ScheduledDefrag] - (.Microsoft Corp. - Module de défragmenteur de disque.) -- C:\WINDOWS\system32\defrag.exe [185856] =>.Microsoft Corp.
O38 - TASK: {0C518199-F01B-42CF-9CB7-16710B002812} [64Bits][\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask] - (.Microsoft Corporation - MDMAgent.) -- C:\WINDOWS\system32\MDMAgent.exe [68096] =>.Microsoft Corporation
O38 - TASK: {0CC2C164-C391-4AE1-AC44-61014D23FC1F} [64Bits][\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization] - (.Microsoft Corp. - Module de défragmenteur de disque.) -- C:\WINDOWS\system32\defrag.exe [185856] =>.Microsoft Corp.
O38 - TASK: {0DB3E91F-53BC-42A7-9654-5E8D3B42C90A} [64Bits][\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] - (.NVIDIA Corporation - NVIDIA crash and telemetry reporter.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [704960] =>.NVIDIA Corporation®
O38 - TASK: {128B5809-9822-4C3D-AA86-FEDA050E0B15} [64Bits][\FubToolByPLD] - (.Copyright © 2015 - FubTracking.) -- C:\OEM\Preload\FubTool\FubTool.exe [30976] =>.Acer Incorporated®
O38 - TASK: {186E3FCA-A925-48F1-88BF-0AD9D9289626} [64Bits][\Microsoft\Windows\Autochk\Proxy] - (.Microsoft Corporation - DLL de proxy Autochk.) -- C:\Windows\System32\acproxy.dll [13312] =>.Microsoft Corporation
O38 - TASK: {19A83AC3-5FF2-48A6-99D4-35106658F876} [64Bits][\Microsoft\Windows\Subscription\LicenseAcquisition] - (.Microsoft Corporation - Acquire License From Store.) -- C:\WINDOWS\System32\ClipRenew.exe [137112] =>.Microsoft Windows®
O38 - TASK: {19E2AF7D-A62A-4277-823F-596B74A2D3C1} [64Bits][\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display] - (.Microsoft Corporation - MusNotificationBroker.) -- C:\WINDOWS\System32\MusNotification.exe [306176] =>.Microsoft Corporation
O38 - TASK: {1DA63A5E-CB3B-4723-8D45-DB7901C7C450} [64Bits][\Microsoft\Office\Microsoft Office Touchless Attach Notification] - (.Microsoft Office - Task used to notify user of attached Office.) -- %CommonProgramFiles%\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [0]
O38 - TASK: {208FAF3B-9A74-4CDC-A1BC-FCA88CA2D342} [64Bits][\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector] - (.Microsoft Corporation - Module de diagnostics des erreurs de disque.) -- C:\Windows\System32\dfdts.dll [45568] =>.Microsoft Corporation
O38 - TASK: {240478A4-B7D2-43B1-AF21-626C77E72C1F} [64Bits][\Microsoft\Windows\DiskFootprint\Diagnostics] - (.Microsoft Corporation - DiskSnapshot.exe.) -- C:\WINDOWS\system32\disksnapshot.exe [82944] =>.Microsoft Corporation
O38 - TASK: {2428A321-608D-4F4B-87B1-AE80E598DDEF} [64Bits][\Norton Security\Norton Security Autofix] - (.Symantec Corporation - Symantec Error Reporting.) -- C:\Program Files (x86)\Norton Security\Engine\22.9.3.13\symerr.exe [102008] =>.Symantec Corporation®
O38 - TASK: {2532DB2F-A598-4946-BA1F-6EBE9D19C34C} [64Bits][\Microsoft\Windows\Location\WindowsActionDialog] - (.Microsoft Corporation - Service Broker pour la boîte de dialogue Ac.) -- C:\WINDOWS\System32\WindowsActionDialog.exe [59392] =>.Microsoft Corporation
O38 - TASK: {32EA0F6D-CE47-408E-BA6D-1B03323D4E70} [64Bits][\Software Update Application] - (.Acer Incorporated - ListCheck.) -- C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [472992] =>.Acer Incorporated®
O38 - TASK: {32FB9C81-1DD9-438E-B532-B56C508C7487} [64Bits][\Quick Access] - (.Acer Incorporated - QALauncher.) -- C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [421792] =>.Acer Incorporated®
O38 - TASK: {33C04DDB-DE68-4033-8570-ADDDBFF99E1B} [64Bits][\Microsoft\Windows\NlaSvc\WiFiTask] - (.Microsoft Corporation - Tâche sans fil en arrière-plan.) -- C:\WINDOWS\System32\WiFiTask.exe [459168] =>.Microsoft Windows®
O38 - TASK: {3619A588-C82A-437E-AAB3-F0AE62D9596A} [64Bits][\Microsoft\Windows\UPnP\UPnPHostConfig] - (.Microsoft Corporation - Outil de configuration du Gestionnaire de c.) -- C:\Windows\System32\sc.exe [68608] =>.Microsoft Corporation
O38 - TASK: {36F2987D-B423-430F-BDAB-35931B371DB7} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Resume On Boot] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [34304] =>.Microsoft Corporation
O38 - TASK: {3AEEF4D4-C4A8-42A1-8A1E-80CA054C2E9C} [64Bits][\Microsoft\Windows\SystemRestore\SR] - (.Microsoft Corporation - Tâches de fond de la protection du système.) -- C:\WINDOWS\system32\srtasks.exe [57856] =>.Microsoft Corporation
O38 - TASK: {3E757B5E-55B1-4F43-820F-3CA89C3FB296} [64Bits][\Microsoft\Windows\WindowsUpdate\Scheduled Start] - (.Microsoft Corporation. - Cette tâche permet de démarrer le service W.) -- wuauserv [0] =>.Microsoft Corporation.
O38 - TASK: {3EA82649-A360-4898-A6FB-C273024D1364} [64Bits][\Microsoft\Windows\Shell\FamilySafetyMonitor] - (.Microsoft Corporation - Moniteur du contrôle parental.) -- C:\WINDOWS\System32\wpcmon.exe [1763376] =>.Microsoft Windows®
O38 - TASK: {3FA71E5E-0D4E-4AAA-B8F4-F663FE2383E3} [64Bits][\CCleanerSkipUAC] - (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe [7685808] =>.Piriform Ltd®
O38 - TASK: {403BE5A2-50B1-4353-B7A8-1B4CB760F5CD} [64Bits][\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot] - (.Microsoft Corporation - MusNotificationBroker.) -- C:\WINDOWS\System32\MusNotification.exe [306176] =>.Microsoft Corporation
O38 - TASK: {4051EB0B-2917-432F-B9F9-431C7E3C9181} [64Bits][\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask] - (.Microsoft Corporation - Serveur COM d’assistance à distance Windows.) -- C:\Windows\System32\raserver.exe [128512] =>.Microsoft Corporation
O38 - TASK: {4A5D4628-E32A-4422-9B01-D37DD4C1CE75} [64Bits][\Microsoft\Windows\WwanSvc\NotificationTask] - (.Microsoft Corporation - Tâche sans fil en arrière-plan.) -- C:\WINDOWS\System32\WiFiTask.exe [459168] =>.Microsoft Windows®
O38 - TASK: {4B6926D3-D490-4D93-82CE-D109F1D1BC80} [64Bits][\Microsoft\Windows\WindowsUpdate\sih] - (.Microsoft Corporation - Client SIH.) -- C:\WINDOWS\System32\sihclient.exe [229888] =>.Microsoft Corporation
O38 - TASK: {4E36EDFC-DC44-4641-9779-B06826BBE396} [64Bits][\Microsoft\Windows\Windows Defender\Windows Defender Verification] - (.Microsoft Corporation - Microsoft Malware Protection Command Line U.) -- C:\Program Files\Windows Defender\MpCmdRun.exe [438032] =>.Microsoft Corporation®
O38 - TASK: {5010C4B7-1314-4A40-8FDA-19E7BB61FBA8} [64Bits][\Microsoft\Windows\Sysmain\WsSwapAssessmentTask] - (.Microsoft Corporation - Hôte de service Superfetch.) -- C:\Windows\System32\sysmain.dll [972800] =>.Microsoft Corporation
O38 - TASK: {52C4776E-11B1-402C-A230-0A0306A146C4} [64Bits][\Microsoft\Windows\Customer Experience Improvement Program\Consolidator] - (.Microsoft Corporation - Consolidateur SQM Windows.) -- C:\WINDOWS\System32\wsqmcons.exe [77824] =>.Microsoft Corporation
O38 - TASK: {583AF58E-7E68-490D-9CA5-3FC7942CF0CE} [64Bits][\Microsoft\Office\Office Automatic Updates] - (.Microsoft Corporation - Microsoft Office Click-to-Run Client.) -- C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [17335976] =>.Microsoft Corporation®
O38 - TASK: {5BC5A21F-4785-41A6-B4B1-62FB9B08FABD} [64Bits][\Microsoft\Windows\Workplace Join\Automatic-Device-Join] - (.Microsoft Corporation - Outil de ligne de commande DSREG.) -- C:\WINDOWS\System32\dsregcmd.exe [659968] =>.Microsoft Corporation
O38 - TASK: {5C326114-085E-444C-9B7A-D3E2E59C549E} [64Bits][\Microsoft\Windows\Device Information\Device] - (.Microsoft Corporation - Device Census.) -- C:\WINDOWS\system32\devicecensus.exe [34720] =>.Microsoft Windows®
O38 - TASK: {5D81326C-D6EC-49A0-AAB5-D8A874E06E83} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Reboot] - (.Microsoft Corporation - MusNotificationBroker.) -- C:\WINDOWS\System32\MusNotification.exe [306176] =>.Microsoft Corporation
O38 - TASK: {6082397F-CFD7-4414-8706-9A6EA646160C} [64Bits][\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] - (.NVIDIA Corporation - NVIDIA driver profile updater.) -- C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [628672] =>.NVIDIA Corporation®
O38 - TASK: {61BD468E-F5F2-4D36-8B7A-8521069DF8E9} [64Bits][\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup] - (.Microsoft Corporation - DLL du client de déploiement d’AppX.) -- C:\Windows\System32\AppxDeploymentClient.dll [654976] =>.Microsoft Windows®
O38 - TASK: {61CDA81A-77C4-45FA-9EBD-567FED3707F4} [64Bits][\ACC] - (.© All rights reserved - LiveUpdate Checker.) -- C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [2920752] =>.Acer Incorporated®
O38 - TASK: {6772AC65-7600-4DF2-9BD5-F17292FAAE4B} [64Bits][\Microsoft\Windows\Speech\SpeechModelDownloadTask] - (.Microsoft Corporation - Speech Model Download Executable.) -- C:\Windows\System32\speech_onecore\Common\SpeechModelDownload.exe [162816] =>.Microsoft Corporation
O38 - TASK: {6858E356-EBEB-4CB9-B0C1-73B2A93360B6} [64Bits][\OneDrive Standalone Update Task-S-1-5-21-3999692886-1327927999-3827528074-1001] - (.Microsoft Corporation - Standalone Updater.) -- C:\Users\rpgis\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe [2292936] =>.Microsoft Corporation®
O38 - TASK: {6F84D817-E42B-4535-8C8C-AAB5C01884A0} [64Bits][\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] - (.NVIDIA Corporation - NVIDIA nodejs launcher.) -- C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [781248] =>.NVIDIA Corporation®
O38 - TASK: {70E0A093-79B7-461E-A9C7-B67CD7B1511E} [64Bits][\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload] - (.Microsoft Corporation - Microsoft Feedback SIUF Deployment Manager.) -- C:\WINDOWS\system32\dmclient.exe [89600] =>.Microsoft Corporation
O38 - TASK: {737DE1FD-A985-4580-A568-4712AA2DE261} [64Bits][\Remediation\AntimalwareMigrationTask] - (.Symantec Corporation - WSCStub.) -- C:\Program Files\Common Files\AV\Norton Security\Upgrade.exe [3800320] =>.Symantec Corporation®
O38 - TASK: {7508389C-FF71-4BE4-AD8A-5F56FB645036} [64Bits][\Microsoft\Windows\ApplicationData\CleanupTemporaryState] - (.Microsoft Corporation - Windows Application Data API Server.) -- C:\Windows\System32\Windows.Storage.ApplicationData.dll [328616] =>.Microsoft Windows®
O38 - TASK: {78F76D6D-0B70-46A9-8DEB-4FCB650A6627} [64Bits][\Microsoft\Windows\SharedPC\Account Cleanup] - (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\WINDOWS\System32\Windows.SharedPC.AccountManager.dll [192512] =>.Microsoft Corporation
O38 - TASK: {799AC654-A37D-49AA-B0F3-433D7D5EBBD9} [64Bits][\Microsoft\Windows\WCM\WiFiTask] - (.Microsoft Corporation - Tâche sans fil en arrière-plan.) -- C:\WINDOWS\System32\WiFiTask.exe [459168] =>.Microsoft Windows®
O38 - TASK: {7C57F1FA-F0C0-4C0A-B450-7A448B979E10} [64Bits][\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance] - (.Microsoft Corporation - Microsoft Malware Protection Command Line U.) -- C:\Program Files\Windows Defender\MpCmdRun.exe [438032] =>.Microsoft Corporation®
O38 - TASK: {80E5FB01-DF9C-493E-B826-DD7094E7A8DB} [64Bits][\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver] - (.Microsoft Corporation - Outil de résolution des défaillances disque.) -- C:\WINDOWS\system32\DFDWiz.exe [51200] =>.Microsoft Corporation
O38 - TASK: {829C695F-E874-432A-9A9F-7862D04236B9} [64Bits][\Microsoft\Windows\ApplicationData\DsSvcCleanup] - (.Microsoft Corporation - Data Sharing Service Maintenance Driver.) -- C:\WINDOWS\system32\dstokenclean.exe [12800] =>.Microsoft Corporation
O38 - TASK: {87488988-70F6-44C5-A1BD-E328BE17C205} [64Bits][\Microsoft\Windows\AppID\PolicyConverter] - (.Microsoft Corporation - AppID Policy Converter Task.) -- C:\WINDOWS\system32\appidpolicyconverter.exe [159744] =>.Microsoft Corporation
O38 - TASK: {88209412-5377-4AA1-B01E-F5D5A6F39E21} [64Bits][\Microsoft\Windows\SpacePort\SpaceAgentTask] - (.Microsoft Corporation - Paramètres des espaces de stockage.) -- C:\WINDOWS\system32\SpaceAgent.exe [129536] =>.Microsoft Corporation
O38 - TASK: {88D1B06D-FABE-44C1-BB35-C27FC074B47F} [64Bits][\Microsoft\Windows\Subscription\EnableLicenseAcquisition] - (.Microsoft Corporation - Acquire License From Store.) -- C:\WINDOWS\System32\ClipRenew.exe [137112] =>.Microsoft Windows®
O38 - TASK: {88E18EB0-E633-47C9-8FE5-84CEAB8F5EF7} [64Bits][\microsoft\windows\applicationdata\appuriverifierdaily] - (.Microsoft Corporation - Vérificateur de l’inscription des gestionna.) -- C:\WINDOWS\system32\AppHostRegistrationVerifier.exe [105472] =>.Microsoft Corporation
O38 - TASK: {896ED842-4861-49E9-A2C1-0AE31689F876} [64Bits][\Microsoft\Windows\Clip\License Validation] - (.Microsoft Corporation - Client License Platform migration tool.) -- C:\WINDOWS\System32\ClipUp.exe [1347640] =>.Microsoft Windows Publisher®
O38 - TASK: {8A83DF8B-133E-4C70-AA59-6BB6CCBD0347} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Maintenance Install] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [34304] =>.Microsoft Corporation
O38 - TASK: {8EE52AD7-9F81-40D3-AE0C-9F5DB09BC56F} [64Bits][\Microsoft\Windows\DiskCleanup\SilentCleanup] - (.Microsoft Corporation - Gestionnaire de nettoyage de disque pour Wi.) -- C:\WINDOWS\system32\cleanmgr.exe [217088] =>.Microsoft Corporation
O38 - TASK: {91962D27-F34F-4BFE-B221-436400154F70} [64Bits][\ACCAgent] - (.© All rights reserved - LiveUpdate Agent.) -- C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [41264] =>.Acer Incorporated®
O38 - TASK: {936FF605-A684-4476-8E62-E051A903B3D3} [64Bits][\Microsoft\Windows\Time Zone\SynchronizeTimeZone] - (.Microsoft Corporation - TimeZone Sync Task.) -- C:\WINDOWS\system32\tzsync.exe [60928] =>.Microsoft Corporation
O38 - TASK: {938954E2-DAFB-4BCD-8740-6AC11EBFE13C} [64Bits][\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck] - (.Microsoft Corporation - AppID Certificate Store Verification Task.) -- C:\WINDOWS\system32\appidcertstorecheck.exe [19456] =>.Microsoft Corporation
O38 - TASK: {95F7441D-F4DE-4103-8791-34DEA0DB80C0} [64Bits][\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange] - (.Microsoft Corporation - Moteur de filtrage de base.) -- C:\Windows\System32\bfe.dll [815616] =>.Microsoft Corporation
O38 - TASK: {96386055-E360-4097-A842-6CAFBBCBBECA} [64Bits][\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration] - (.Microsoft Corporation - This task initiates Office Background Task .) -- C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [24264] =>.Microsoft Corporation®
O38 - TASK: {9CF304F4-4D08-4DBB-A568-102240A2160B} [64Bits][\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser] - (.Microsoft Corporation - Tâche de l’analyseur d’expérience de compte.) -- C:\WINDOWS\System32\MbaeParserTask.exe [112640] =>.Microsoft Corporation
O38 - TASK: {A0CC0801-8FC9-42DA-96DF-5A39991DA975} [64Bits][\Intel PTT EK Recertification] - (.Intel® Corporation - Intel®PTT EK Recertification Service.) -- C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [909112] =>.Intel® Trusted Connect Service®
O38 - TASK: {A3B18A5B-BD1D-4FE8-A5A8-94AC3C0DF5C3} [64Bits][\Norton Security\Norton Security Error Processor] - (.Symantec Corporation - Symantec Error Reporting.) -- C:\Program Files (x86)\Norton Security\Engine\22.9.3.13\symerr.exe [102008] =>.Symantec Corporation®
O38 - TASK: {A7DF6252-A35D-4ED0-9010-90495DAADE6B} [64Bits][\UbtFrameworkService] - (.TODO: <Company name> - TriggerFramework.) -- C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [216296] =>.Acer Incorporated®
O38 - TASK: {A8C13BD9-8193-477D-BBA5-A8AD8C03295A} [64Bits][\AcerCloud] - (.Acer - Acer Portal.) -- C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2418392] =>.Acer Incorporated®
O38 - TASK: {AADC0EFE-9ECA-44F4-B730-DB1EFCED41E6} [64Bits][\App Explorer] - (.SweetLabs, Inc - Host App Service Updater.) -- C:\Users\rpgis\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [10364320] =>.SweetLabs Inc.®
O38 - TASK: {AD1CE073-2081-452E-999D-80E07106DBF1} [64Bits][\BacKGroundAgent] - (.Acer Incorporated - Background Agent.) -- C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [65752] =>.Acer Incorporated®
O38 - TASK: {B0B01AAA-FF6C-4441-B75E-44A24B0B37CD} [64Bits][\Microsoft\Windows\DUSM\dusmtask] - (.Microsoft Corporation - DUSM Task.) -- C:\WINDOWS\System32\dusmtask.exe [35840] =>.Microsoft Corporation
O38 - TASK: {B0BD1BE6-EF8F-46E6-BD29-D7ADE53D597B} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Policy Install] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [34304] =>.Microsoft Corporation
O38 - TASK: {B5EA650A-8EE9-4BA5-BAA0-2A8ACE00500D} [64Bits][\Microsoft\Windows\SpacePort\SpaceManagerTask] - (.Microsoft Corporation - Storage Spaces Manager.) -- C:\WINDOWS\system32\spaceman.exe [34816] =>.Microsoft Corporation
O38 - TASK: {B75044EF-500D-4F16-A3DA-4B1F272B7A82} [64Bits][\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] - (.NVIDIA Corporation - NVIDIA telemetry monitor.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [436160] =>.NVIDIA Corporation®
O38 - TASK: {BC201A8F-9A7D-4AE2-8A04-D16E9A093607} [64Bits][\DashlaneUpgradeCheck] - (. - DashlaneUpgradeCheck.) -- Dashlane Upgrade Service [0]
O38 - TASK: {BCC432F2-7A57-4195-881F-9013CF46F613} [64Bits][\Microsoft\Windows\MUI\LPRemove] - (.Microsoft Corporation - MUI Language pack cleanup.) -- C:\WINDOWS\system32\lpremove.exe [66560] =>.Microsoft Corporation
O38 - TASK: {BD69C6ED-AD55-467C-B787-533200C3B376} [64Bits][\Microsoft\XblGameSave\XblGameSaveTask] - (.Microsoft Corporation - XblGameSave Standby Task.) -- C:\WINDOWS\System32\XblGameSaveTask.exe [31744] =>.Microsoft Corporation
O38 - TASK: {BEAF8A6C-47E0-4E84-840B-3A61426B5AAD} [64Bits][\Microsoft\Windows\Application Experience\StartupAppTask] - (.Microsoft Corporation - DLL de tâche d’analyse de démarrage.) -- C:\Windows\System32\Startupscan.dll [19968] =>.Microsoft Corporation
O38 - TASK: {C05E2FFD-7D0D-4F6B-952B-A3318F829D19} [64Bits][\Microsoft\Windows\Management\Provisioning\Cellular] - (.Microsoft Corporation - Provisioning package runtime processing too.) -- C:\WINDOWS\system32\ProvTool.exe [68608] =>.Microsoft Corporation
O38 - TASK: {C162FF56-952F-4ABA-AE13-AA8CB0F4C087} [64Bits][\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers] - (.Microsoft Corporation - Module d’installation de pilotes.) -- C:\WINDOWS\System32\drvinst.exe [158720] =>.Microsoft Corporation
O38 - TASK: {C3EF35FA-9D2F-487A-BCB6-09395FA7907C} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Combined Scan Download Install] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [34304] =>.Microsoft Corporation
O38 - TASK: {C42799B6-75B2-42CF-8197-3BE332E05553} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Schedule Scan] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [34304] =>.Microsoft Corporation
O38 - TASK: {C97B639A-C1BF-4E0C-ACFD-CF5B27B65B3C} [64Bits][\Microsoft\Windows\Windows Error Reporting\QueueReporting] - (.Microsoft Corporation - Windows Problem Reporting.) -- C:\WINDOWS\system32\wermgr.exe [182688] =>.Microsoft Windows®
O38 - TASK: {CA2196E8-37A7-43E0-9884-572A6AC7202A} [64Bits][\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] - (.NVIDIA Corporation - NVIDIA driver profile updater.) -- C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [628672] =>.NVIDIA Corporation®
O38 - TASK: {CD19BC8A-E9FE-49ED-92A5-0E1194F69F00} [64Bits][\Microsoft\XblGameSave\XblGameSaveTaskLogon] - (.Microsoft Corporation - XblGameSave Standby Task.) -- C:\WINDOWS\System32\XblGameSaveTask.exe [31744] =>.Microsoft Corporation
O38 - TASK: {CDC553D2-B5AD-4AF3-BB6D-5AA47466C1F9} [64Bits][\Microsoft\Windows\Management\Provisioning\Logon] - (.Microsoft Corporation - Provisioning package runtime processing too.) -- C:\WINDOWS\system32\ProvTool.exe [68608] =>.Microsoft Corporation
O38 - TASK: {CFE9501D-B60F-45DB-B48F-19C572F7F30E} [64Bits][\microsoft\windows\applicationdata\appuriverifierinstall] - (.Microsoft Corporation - Vérificateur de l’inscription des gestionna.) -- C:\WINDOWS\system32\AppHostRegistrationVerifier.exe [105472] =>.Microsoft Corporation
O38 - TASK: {D0789B47-6351-4842-AC51-71790977ECB5} [64Bits][\GoogleUpdateTaskMachineUA] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc®
O38 - TASK: {D2C50CE0-7E9B-4F0D-A2A4-95AC59829444} [64Bits][\Microsoft\Windows\Bluetooth\UninstallDeviceTask] - (.Microsoft Corporation - Tâche de désinstallation du périphérique Bl.) -- C:\Windows\System32\BthUdTask.exe [40448] =>.Microsoft Corporation
O38 - TASK: {D4B8C2D2-25FB-4857-B837-C21F449F3F8F} [64Bits][\GoogleUpdateTaskMachineCore] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc®
O38 - TASK: {D4CE9A2B-2C30-405B-AEEE-4D503BE8F091} [64Bits][\Norton Security\Norton Security Error Analyzer] - (.Symantec Corporation - Symantec Error Reporting.) -- C:\Program Files (x86)\Norton Security\Engine\22.9.3.13\symerr.exe [102008] =>.Symantec Corporation®
O38 - TASK: {D5EBF28C-A33D-4CBA-8355-0F457EE12498} [64Bits][\Microsoft\Windows\Application Experience\ProgramDataUpdater] - (.Microsoft Corporation - Microsoft Compatibility Telemetry.) -- C:\WINDOWS\system32\compattelrunner.exe [96672] =>.Microsoft Windows®
O38 - TASK: {DE280E27-41E3-43DD-8D0C-7D14FBD3A6ED} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Refresh Settings] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [34304] =>.Microsoft Corporation
O38 - TASK: {E11183CC-FCAC-479E-B422-6A72654C14EA} [64Bits][\Microsoft\Windows\Location\Notifications] - (.Microsoft Corporation - Notification d'emplacement.) -- C:\WINDOWS\System32\LocationNotificationWindows.exe [66560] =>.Microsoft Corporation
O38 - TASK: {E3316482-7B6B-45F9-A54D-09C327750D03} [64Bits][\Microsoft\Windows\UNP\RunCampaignManager] - (.Microsoft Corporation - UNP CampaignManager.) -- C:\WINDOWS\System32\UNP\UNPCampaignManager.exe [1039712] =>.Microsoft Windows®
O38 - TASK: {E762DE9B-A8EE-41A5-9FF2-1928FDF0987B} [64Bits][\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] - (.NVIDIA Corporation - NVIDIA crash and telemetry reporter.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [704960] =>.NVIDIA Corporation®
O38 - TASK: {E85A93EE-BDCE-47F2-A4AE-74CAEC6A8B99} [64Bits][\Microsoft\Windows\rempl\shell] - (.Microsoft Corporation - remsh.) -- C:\Program Files\rempl\remsh.exe [707064] =>.Microsoft Corporation®
O38 - TASK: {EC11A6F7-343D-49E9-A974-A3716157F2C1} [64Bits][\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser] - (.Microsoft Corporation - Microsoft Compatibility Telemetry.) -- C:\WINDOWS\system32\compattelrunner.exe [96672] =>.Microsoft Windows®
O38 - TASK: {EC7C31D7-189F-4D19-893C-DCB15F04ED9A} [64Bits][\Microsoft\Windows\rempl\shell-unlock] - (.Microsoft Corporation - remsh.) -- C:\Program Files\rempl\remsh.exe [707064] =>.Microsoft Corporation®
O38 - TASK: {ECCD9C16-9DE6-485A-A847-2607D1342E8F} [64Bits][\ACCBackgroundApplication] - (.©All rights reserved - ACCStd.) -- C:\Program Files (x86)\Acer\Care Center\ACCStd.exe [4645168] =>.Acer Incorporated®
O38 - TASK: {F050E734-38F6-4230-9C8B-0157ECB59B0B} [64Bits][\Microsoft\Windows\Windows Defender\Windows Defender Cleanup] - (.Microsoft Corporation - Microsoft Malware Protection Command Line U.) -- C:\Program Files\Windows Defender\MpCmdRun.exe [438032] =>.Microsoft Corporation®
O38 - TASK: {F26FB719-F2BE-4CA0-A91A-FC5867D19B1C} [64Bits][\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan] - (.Microsoft Corporation - Microsoft Malware Protection Command Line U.) -- C:\Program Files\Windows Defender\MpCmdRun.exe [438032] =>.Microsoft Corporation®
O38 - TASK: {F76780F7-A50A-4B06-9A0A-5DC4BEDC8542} [64Bits][\Microsoft\Office\Office ClickToRun Service Monitor] - (.Microsoft Corporation - Microsoft Office Click-to-Run Client.) -- C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [17335976] =>.Microsoft Corporation®
O38 - TASK: {F88E01C2-99E3-4AF6-BFAA-7ACC8EF521D4} [64Bits][\Microsoft\Windows\Feedback\Siuf\DmClient] - (.Microsoft Corporation - Microsoft Feedback SIUF Deployment Manager.) -- C:\WINDOWS\system32\dmclient.exe [89600] =>.Microsoft Corporation
O38 - TASK: {F9015704-44A7-4962-B811-A4C0206CF851} [64Bits][\Microsoft\Windows\WindowsUpdate\sihboot] - (.Microsoft Corporation - Client SIH.) -- C:\WINDOWS\System32\sihclient.exe [229888] =>.Microsoft Corporation
O38 - TASK: {F90E53C9-A6A1-4188-83F3-ADD7EA11F00F} [64Bits][\Microsoft\Office\OfficeBackgroundTaskHandlerLogon] - (.Microsoft Corporation - This task initiates Office Background Task .) -- C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [24264] =>.Microsoft Corporation®
O38 - TASK: {FB6B2ABA-C322-4436-9D29-FC4FEFCB153A} [64Bits][\DivXUpdate] - (.DivX, LLC - DivX Update.) -- C:\Program Files (x86)\Common Files\DivX Shared\DivX Update\DivXUpdate.exe [68568] =>.DivX, LLC®

---\\ Applications lancées au démarrage du système (12) - 1s
O4 - HKLM\..\Run: [securityHealth] . (.Microsoft Corporation - Windows Defender notification icon.) -- C:\Program Files\Windows Defender\MSASCuiL.exe =>.Microsoft Windows®
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp.®
O4 - HKLM\..\Run: [iAStorIcon] . (.Intel Corporation - Delayed launcher.) -- C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe =>.Intel Corporation
O4 - HKLM\..\Run: [shadowPlay] . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\system32\rundll32.exe =>.Microsoft Corporation
O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\rpgis\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - HKCU\..\Run: [steam] . (.Valve Corporation - Steam Client Bootstrapper.) -- C:\Program Files (x86)\Steam\steam.exe =>.Valve®
O4 - HKLM\..\Wow6432Node\Run: [DivXMediaServer] . (.DivX, LLC - DivX Media Server Launcher.) -- C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe =>.DivX, LLC®
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
O4 - HKUS\S-1-5-21-3999692886-1327927999-3827528074-1000\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
O4 - HKUS\S-1-5-21-3999692886-1327927999-3827528074-1000\..\RunOnce: [WAB Migrate] . (.Microsoft Corporation - Windows Contacts.) -- C:\Program Files\Windows Mail\wab.exe =>.Microsoft Corporation

---\\ Google Chrome, Démarrage,Recherche,Extensions (17) - 0s
G0 - GCSP: Preferences [user Data\Default][HomePage]
G0 - GCSP: Preferences [user Data\Default][HomePage] http://cdn.mxpnl.com
G0 - GCSP: Preferences [user Data\Default][HomePage]
G0 - GCSP: Preferences [user Data\Default][HomePage]
G0 - GCSP: Preferences [user Data\Default][HomePage] http://www.piriform.com
G0 - GCSP: Preferences [user Data\Default][HomePage]
G0 - GCSP: Preferences [user Data\Default][HomePage]
G0 - GCSP: Preferences [user Data\Default][HomePage]
G0 - GCSP: Preferences [user Data\Default][HomePage]
G2 - GCE: Preference [user Data\Default] [aohghmighlieiainnegkcijnfilokake] Docs =>.Legitimate
G2 - GCE: Preference [user Data\Default] [apdfllckaahabafndbhieahigkjlhalf]
G2 - GCE: Preference [user Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo]
G2 - GCE: Preference [user Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] =>.Google Inc. {Sheets}
G2 - GCE: Preference [user Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] =>.Google Inc. {Docs hors connexion}
G2 - GCE: Preference [user Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] =>.Google Inc. {Wallet}
G2 - GCE: Preference [user Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia]
G2 - GCE: Preference [user Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (24) - 2s
M0 - MFSP: prefs.js [rpgis - kqpq3guk.default]
P2 - EXT FILE: (.mozfr.org - Français Language Pack.) -- C:\Users\rpgis\AppData\Roaming\Mozilla\Firefox\Profiles\kqpq3guk.default\extensions\[email protected] =>.mozfr.org
P2 - EXT FILE: (.Adblock Plus - Ads were yesterday!.) -- C:\Users\rpgis\AppData\Roaming\Mozilla\Firefox\Profiles\kqpq3guk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Adblock Plus
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] =>.Mozilla Corporation
P2 - EXT: (.Amazon - Amazon Assistant for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\[email protected] =>.Amazon
P2 - EXT: (.mozfr.org - Français Language Pack.) -- C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\[email protected] =>.mozfr.org
P2 - EXT: (.Mozilla - Mozilla Partner Defaults.) -- C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\[email protected] =>.Mozilla
P2 - EXT: (.Amazon - Amazon Assistant for Firefox.) -- C:\Users\rpgis\AppData\Roaming\Mozilla\Firefox\Profiles\kqpq3guk.default\extensions\[email protected] =>.Amazon
P2 - EXT: (.Mozilla - Mozilla Partner Defaults.) -- C:\Users\rpgis\AppData\Roaming\Mozilla\Firefox\Profiles\kqpq3guk.default\extensions\[email protected] =>.Mozilla
P2 - EXT: (.Mindspark - EasyPDFCombine.) -- C:\Users\rpgis\AppData\Roaming\Mozilla\Firefox\Profiles\kqpq3guk.default\extensions\[email protected] =>.SUP.MindSpark
P2 - EXT: (.Mindspark - ProductivityBoss.) -- C:\Users\rpgis\AppData\Roaming\Mozilla\Firefox\Profiles\kqpq3guk.default\extensions\[email protected] =>.SUP.MindSpark
P2 - EXT: (.Mindspark - Search Extension by Ask.) -- C:\Users\rpgis\AppData\Roaming\Mozilla\Firefox\Profiles\kqpq3guk.default\extensions\[email protected] =>.SUP.MindSpark
C:\Users\rpgis\AppData\Roaming\Mozilla\Firefox\Profiles\kqpq3guk.default\EasyPDFCombine_ce =>.SUP.MindSpark
C:\Users\rpgis\AppData\Roaming\Mozilla\Firefox\Profiles\kqpq3guk.default\ProductivityBoss_e5 =>.SUP.MindSpark

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (16) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.15063.608 (WinBuild.160101.0800)) -- C:\Windows\SysWOW64\ieframe.dll =>.Microsoft Corporation

---\\ Internet Explorer,Proxy Management (3) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=

---\\ Etude du fichier hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ Browser Helper Object de navigateur (BHO) (1) - 0s
O2 - BHO: Lync Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} (.Orphan.)

---\\ Raccourcis Global Startup (65) - 5s
O4 - GS\Desktop [Administrateur]: Assistant Mise à niveau de Windows 10.lnk . (.Microsoft Corporation - Assistant Mise à jour de Windows 10.) C:\Windows10Upgrade\Windows10UpgraderApp.exe /ClientID "Win10Upgrade:VNL:OobeRs1Rs2:{}" =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Administrateur]: GIMP 2.lnk . (.Spencer Kimball, Peter Mattis and the GIMP Developmen - GNU Image Manipulation Program.) C:\Program Files\GIMP 2\bin\gimp-2.8.exe =>.Jernej Simončič®
O4 - GS\Quicklaunch [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\sendTo [Administrateur]: Destinataire de télécopie.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrateur]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrateur]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrateur]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\Startup [Administrateur]: Envoyer à OneNote.lnk . (.Microsoft Corporation - Send to OneNote Tool.) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE /tsr =>.Microsoft Corporation®
O4 - GS\Programs [Administrateur]: FileHippo App Manager.lnk . (.Copyright © 2014 - FileHippo.AppManager.) C:\Program Files (x86)\FileHippo.com\FileHippo.AppManager.exe =>.Well Known Media Ltd®
O4 - GS\Programs [Administrateur]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\rpgis\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Desktop [defaultuser0]: Assistant Mise à niveau de Windows 10.lnk . (.Microsoft Corporation - Assistant Mise à jour de Windows 10.) C:\Windows10Upgrade\Windows10UpgraderApp.exe /ClientID "Win10Upgrade:VNL:OobeRs1Rs2:{}" =>.Microsoft Corporation®
O4 - GS\Quicklaunch [defaultuser0]: GIMP 2.lnk . (.Spencer Kimball, Peter Mattis and the GIMP Developmen - GNU Image Manipulation Program.) C:\Program Files\GIMP 2\bin\gimp-2.8.exe =>.Jernej Simončič®
O4 - GS\Quicklaunch [defaultuser0]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\sendTo [defaultuser0]: Destinataire de télécopie.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [defaultuser0]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [defaultuser0]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [defaultuser0]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\Startup [defaultuser0]: Envoyer à OneNote.lnk . (.Microsoft Corporation - Send to OneNote Tool.) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE /tsr =>.Microsoft Corporation®
O4 - GS\Programs [defaultuser0]: FileHippo App Manager.lnk . (.Copyright © 2014 - FileHippo.AppManager.) C:\Program Files (x86)\FileHippo.com\FileHippo.AppManager.exe =>.Well Known Media Ltd®
O4 - GS\Programs [defaultuser0]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\rpgis\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Desktop [rpgis]: Assistant Mise à niveau de Windows 10.lnk . (.Microsoft Corporation - Assistant Mise à jour de Windows 10.) C:\Windows10Upgrade\Windows10UpgraderApp.exe /ClientID "Win10Upgrade:VNL:OobeRs1Rs2:{}" =>.Microsoft Corporation®
O4 - GS\Quicklaunch [rpgis]: GIMP 2.lnk . (.Spencer Kimball, Peter Mattis and the GIMP Developmen - GNU Image Manipulation Program.) C:\Program Files\GIMP 2\bin\gimp-2.8.exe =>.Jernej Simončič®
O4 - GS\Quicklaunch [rpgis]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\sendTo [rpgis]: Destinataire de télécopie.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [rpgis]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [rpgis]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [rpgis]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\Startup [rpgis]: Envoyer à OneNote.lnk . (.Microsoft Corporation - Send to OneNote Tool.) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE /tsr =>.Microsoft Corporation®
O4 - GS\Programs [rpgis]: FileHippo App Manager.lnk . (.Copyright © 2014 - FileHippo.AppManager.) C:\Program Files (x86)\FileHippo.com\FileHippo.AppManager.exe =>.Well Known Media Ltd®
O4 - GS\Programs [rpgis]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\rpgis\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\CommonDesktop [Public]: eBay.lnk . (.Copyright © 2015 - eBay3.) C:\ProgramData\PPiP\source\ab805e40\eBay3.exe =>.Acer Incorporated®
O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\CommonDesktop [Public]: Spotify.lnk . (...) C:\Windows\Installer\{8CADF0CB-E834-4019-9B11-B84E051F2A8E}\_9D1830ED8329FF90DEB5BA.exe Spotify 16Q4.uri
O4 - GS\Programs [Public]: FileHippo App Manager.lnk . (.Copyright © 2014 - FileHippo.AppManager.) C:\Program Files (x86)\FileHippo.com\FileHippo.AppManager.exe =>.Well Known Media Ltd®
O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\rpgis\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\WINDOWS\system32\quickassist.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture d’écran.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Enregistreur d’actions.) C:\WINDOWS\system32\psr.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Application Windows Wordpad.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - Visionneuse XPS.) C:\WINDOWS\system32\xpsrchvw.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Table des caractères.) C:\WINDOWS\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Access 2016.lnk . (.Microsoft Corporation - Microsoft Access.) C:\Program Files (x86)\Microsoft Office\root\Office16\MSACCESS.EXE =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: App Explorer.lnk . (.SweetLabs, Inc - Host App Service.) C:\Users\rpgis\AppData\Local\Host App Service\Engine\HostAppService.exe /OPEN"4efc125e5bdfe64bf86cc73a85a9d56ebf10231c" =>.SweetLabs Inc.®
O4 - GS\ProgramsCommon [Public]: Assistant Mise à niveau de Windows 10.lnk . (.Microsoft Corporation - Assistant Mise à jour de Windows 10.) C:\Windows10Upgrade\Windows10UpgraderApp.exe /ClientID "Win10Upgrade:VNL:OobeRs1Rs2:{}" =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Dashlane.lnk . (.Dashlane, Inc. - DashlaneDownloader.) C:\Program Files (x86)\Dashlane\Upgrade\DashlaneDownloader.exe =>.Dashlane®
O4 - GS\ProgramsCommon [Public]: Excel 2016.lnk . (.Microsoft Corporation - Microsoft Excel.) C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: GIMP 2.lnk . (.Spencer Kimball, Peter Mattis and the GIMP Developmen - GNU Image Manipulation Program.) C:\Program Files\GIMP 2\bin\gimp-2.8.exe =>.Jernej Simončič®
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\WINDOWS\System32\Control.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: MiracastView.lnk . (.Microsoft Corporation - MiracastView.) C:\WINDOWS\MiracastView\MiracastView.exe =>.Microsoft Windows®
O4 - GS\ProgramsCommon [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\ProgramsCommon [Public]: OneNote 2016.lnk . (.Microsoft Corporation - Microsoft OneNote.) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Outlook 2016.lnk . (.Microsoft Corporation - Microsoft Outlook.) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: PowerPoint 2016.lnk . (.Microsoft Corporation - Microsoft PowerPoint.) C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: PrintDialog.lnk . (.Microsoft Corporation - Print Dialog.) C:\WINDOWS\PrintDialog\PrintDialog.exe =>.Microsoft Windows®
O4 - GS\ProgramsCommon [Public]: Publisher 2016.lnk . (.Microsoft Corporation - Microsoft Publisher.) C:\Program Files (x86)\Microsoft Office\root\Office16\MSPUB.EXE =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Word 2016.lnk . (.Microsoft Corporation - Microsoft Word.) C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE =>.Microsoft Corporation®

---\\ Modification Domaine/Adresses DNS (2) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{b63c82ec-3730-41ca-8717-eadb060fe6be}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress

---\\ Protocole additionnel (26) - 1s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation
O18 - Handler: mso-minsb-roaming.16 [64Bits] - {83C25742-A9F7-49FB-9138-434302C88D07} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL =>.Microsoft Corporation®
O18 - Handler: mso-minsb.16 [64Bits] - {42089D2D-912D-4018-9087-2B87803E93FB} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL =>.Microsoft Corporation®
O18 - Handler: osf-roaming.16 [64Bits] - {42089D2D-912D-4018-9087-2B87803E93FB} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL =>.Microsoft Corporation®
O18 - Handler: osf.16 [64Bits] - {5504BE45-A83B-4808-900A-3A5C36E7F77A} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL =>.Microsoft Corporation®
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation

---\\ ASIC (ActiveSetup Installed Components) (5) - 0s
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Utilitaire d’installation du Lecteur Window.) -- C:\Windows\System32\unregmp2.exe =>.Microsoft Corporation
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft Corporation®

---\\ Logiciels installés (98) - 7s
O42 - Logiciel: abFiles - (.Acer Incorporated.) [HKLM][64Bits] -- {13885028-098C-4799-9B71-27DAC96502D5} =>.Acer Incorporated®
O42 - Logiciel: abPhoto - (.Acer Incorporated.) [HKLM][64Bits] -- {B5AD89F2-03D3-4206-8487-018298007DD0} =>.Acer Incorporated®
O42 - Logiciel: Acer Care Center - (.Acer Incorporated.) [HKLM][64Bits] -- {1AF41E84-3408-499A-8C93-8891F0612719} =>.Acer Incorporated
O42 - Logiciel: Acer Configuration Manager - (.Acer.) [HKLM][64Bits] -- {414D554E-4453-454E-0201-000000016258} =>.Acer
O42 - Logiciel: Acer Portal - (.Acer Incorporated.) [HKLM][64Bits] -- {A5AD0B17-F34D-49BE-A157-C8B3D52ACD13} =>.Acer Incorporated®
O42 - Logiciel: Acer Quick Access - (.Acer Incorporated.) [HKLM][64Bits] -- {8BBF04F1-C68A-441C-B5EF-446EE9960EAF} =>.Acer Incorporated
O42 - Logiciel: Acer UEIP Framework - (.Acer Incorporated.) [HKLM][64Bits] -- {12A718F2-2357-4D41-9E1F-18583A4745F7} =>.Acer Incorporated
O42 - Logiciel: Ansel - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel =>.NVIDIA Corporation
O42 - Logiciel: AOP Framework - (.Acer Incorporated.) [HKLM][64Bits] -- {4A37A114-702F-4055-A4B6-16571D4A5353} =>.Acer Incorporated®
O42 - Logiciel: App Explorer - (.SweetLabs.) [HKCU][64Bits] -- Host App Service =>.SweetLabs Inc.®
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Ltd®
O42 - Logiciel: Configuration DivX - (.DivX, LLC.) [HKLM][64Bits] -- DivX Setup =>.DivX, LLC®
O42 - Logiciel: CyberLink PowerDVD 12 - (.CyberLink Corp..) [HKLM][64Bits] -- {B46BEA36-0B71-4A4E-AE41-87241643FA0A} =>.CyberLink Corp.®
O42 - Logiciel: CyberLink PowerDVD 12 - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A} =>.CyberLink Corp.®
O42 - Logiciel: Dashlane Upgrade Service - (.Dashlane, Inc..) [HKLM][64Bits] -- Dashlane Upgrade Service =>.Dashlane®
O42 - Logiciel: Diablo II - (..) [HKLM][64Bits] -- Diablo II
O42 - Logiciel: DriverSetupUtility - (.Acer Incorporated.) [HKLM][64Bits] -- {2B51C83A-465D-4EA9-9CDC-1ED95ED09AC6} =>.Acer Incorporated
O42 - Logiciel: FileHippo App Manager - (.FileHippo.com.) [HKLM][64Bits] -- FileHippo.com =>.FileHippo.com
O42 - Logiciel: GIMP 2.8.22 - (.The GIMP Team.) [HKLM][64Bits] -- GIMP-2_is1 =>.Jernej Simončič®
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Inc®
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>.Google Inc.
O42 - Logiciel: Intel® Chipset Device Software - (.Intel Corporation.) [HKLM][64Bits] -- {81520FC5-3518-40E9-9803-70CE8A801D07} =>.Intel Corporation
O42 - Logiciel: Intel® Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {1CEAC85D-2590-4760-800F-8DE5E91F3700} =>.Intel Corporation
O42 - Logiciel: Intel® Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {6574B7E5-BC77-4EE6-8319-C18FD8B0C960} =>.Intel Corporation
O42 - Logiciel: Intel® Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {AC4709F9-831D-4EDD-B8E8-83AC7C563B66} =>.Intel Corporation
O42 - Logiciel: Intel® PRO/Wireless Driver - (.Intel Corporation.) [HKLM][64Bits] -- {edcc2d98-dba0-4914-ba46-6dae7352cea9} =>.Intel Corporation
O42 - Logiciel: Intel® Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {409CB30E-E457-4008-9B1A-ED1B9EA21140} =>.Intel Corporation - pGFX®
O42 - Logiciel: Intel® Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {EBE12EC7-60DF-41C2-AAC8-0B2586F15C96} =>.Intel Corporation
O42 - Logiciel: Intel® Wireless Bluetooth® - (.Intel Corporation.) [HKLM][64Bits] -- {D6E2E7ED-9F5F-41AF-97FE-3B99804F0B7D} =>.Intel Corporation
O42 - Logiciel: Intel® PROSet/Wireless WiFi Software - (.Intel Corporation.) [HKLM][64Bits] -- {11BD5062-5227-4A48-91AF-904B1802EEA8} =>.Intel Corporation
O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {75FE588B-F158-4BB3-A283-A8D18E522A52} =>.Intel Corporation
O42 - Logiciel: KB4023057 - (.Microsoft Corporation.) [HKLM][64Bits] -- {0C050BEE-16BE-4998-8959-2A421433DB6E} =>.Microsoft Corporation
O42 - Logiciel: Logiciel Intel® PROSet/Wireless - (.Intel Corporation.) [HKLM][64Bits] -- {544ecb18-5d76-44bb-ac33-8d06719e39e7} =>.Intel Corporation-Wireless Connectivity Solutions®
O42 - Logiciel: Logiciel pour périphérique à chipset Intel® - (.Intel® Corporation.) [HKLM][64Bits] -- {bb0592a7-5772-4736-9d55-2402740085db} =>.Intel® Software and Firmware Products®
O42 - Logiciel: Malwarebytes version 3.2.2.2029 - (.Malwarebytes.) [HKLM][64Bits] -- {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1 =>.Malwarebytes Corporation®
O42 - Logiciel: Microsoft OneDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- OneDriveSetup.exe =>.Microsoft Corporation®
O42 - Logiciel: Microsoft VC++ redistributables repacked. - (.Intel Corporation.) [HKLM][64Bits] -- {1AB26641-D555-4648-B08B-676F707A0B1B} =>.Intel Corporation
O42 - Logiciel: Microsoft VC++ redistributables repacked. - (.Intel Corporation.) [HKLM][64Bits] -- {6CAEAB4F-2B43-485A-B7F9-AFC2D88BD7A3} =>.Intel Corporation
O42 - Logiciel: Mises à jour NVIDIA 2.13.0.21 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update =>.NVIDIA Corporation
O42 - Logiciel: Mozilla Firefox 56.0.1 (x64 en-US) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 56.0.1 (x64 en-US) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService =>.Mozilla
O42 - Logiciel: Norton Security - (.Symantec Corporation.) [HKLM][64Bits] -- NS =>.Symantec Corporation®
O42 - Logiciel: NVIDIA Backend - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvBackend =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Display Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Display Container LS - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainerLS =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Display Session Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplaySessionContainer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Display Watchdog Plugin - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayPluginWatchdog =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Elevated User Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.UserElevated =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA GeForce Experience 3.1.0.52 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Install Application - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA LocalSystem Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.LocalSystem =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Logiciel système PhysX 9.17.0524 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Message Bus for NvContainer - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.MessageBus =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA NetworkService Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NetworkService =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Optimus Update 2.13.0.21 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Pilote 3D Vision 387.92 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Pilote audio HD : 1.3.35.1 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Pilote du contrôleur 3D Vision 369.04 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Pilote graphique 387.92 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA ShadowPlay 2.13.0.21 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay =>.NVIDIA Corporation
O42 - Logiciel: Nvidia Share - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_OSC =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Stereoscopic 3D Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- NVIDIAStereo =>.NVIDIA Corporation®
O42 - Logiciel: NVIDIA Update Core - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA User Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.User =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Virtual Audio 3.30.2 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Virtual Host Controller - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Watchdog Plugin for NvContainer - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvPlugin.Watchdog =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Wireless Controller Service - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService =>.NVIDIA Corporation
O42 - Logiciel: NvNodejs - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs =>.NVIDIA Corporation
O42 - Logiciel: NvTelemetry - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry =>.NVIDIA Corporation
O42 - Logiciel: Office 16 Click-to-Run Extensibility Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-008C-0000-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Office 16 Click-to-Run Extensibility Component 64-bit Registration - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-00DD-0000-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Office 16 Click-to-Run Licensing Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-008F-0000-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Office 16 Click-to-Run Localization Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-008C-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Panneau de configuration NVIDIA 387.92 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel =>.NVIDIA Corporation
O42 - Logiciel: PCSX2 - Playstation 2 Emulator - (..) [HKLM][64Bits] -- pcsx2
O42 - Logiciel: PCSX2 - Playstation 2 Emulator - (..) [HKLM][64Bits] -- pcsx2-r5350
O42 - Logiciel: Pcsx2 0.9.6 - (.Default Company Name.) [HKLM][64Bits] -- {0E2B767B-EA6A-489B-BF83-8083FE1DB661}
O42 - Logiciel: PlugY, The Survival Kit - (..) [HKLM][64Bits] -- PlugY, The Survival Kit
O42 - Logiciel: Realtek Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {5BC2B5AB-80DE-4E83-B8CF-426902051D0A} =>.Realtek Semiconductor Corp.®
O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp.®
O42 - Logiciel: Serious Sam FE Patch Français - (.Guillaume BOURET.) [HKLM][64Bits] -- {B4BFBC4D-953A-456C-A1A3-7D8868FBD932}
O42 - Logiciel: Serious Sam: The First Encounter - (..) [HKLM][64Bits] -- {815050E5-F545-11D4-9569-004095812ACC}
O42 - Logiciel: SHIELD Streaming - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv =>.NVIDIA Corporation
O42 - Logiciel: SHIELD Wireless Controller Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController =>.NVIDIA Corporation
O42 - Logiciel: Spotify Weblink - (.Acer.) [HKLM][64Bits] -- {8CADF0CB-E834-4019-9B11-B84E051F2A8E} =>.Acer
O42 - Logiciel: SpywareBlaster 5.5 - (.BrightFort LLC.) [HKLM][64Bits] -- SpywareBlaster_is1 =>.BrightFort LLC
O42 - Logiciel: Steam - (.Valve Corporation.) [HKLM][64Bits] -- Steam =>.Valve®
O42 - Logiciel: UsbFix By El Desaparecido - (.El Desaparecido - SosVirus.org.) [HKLM][64Bits] -- Usbfix
O42 - Logiciel: VC80CRTRedist - 8.0.50727.6195 - (.DivX, Inc.) [HKLM][64Bits] -- {933B4015-4618-4716-A828-5289FC03165F} =>.DivX, Inc
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
O42 - Logiciel: Vulkan Run Time Libraries 1.0.61.0 - (.LunarG, Inc..) [HKLM][64Bits] -- VulkanRT1.0.61.0 {09268FAA1AD6894D179E5B87A2F06462} =>.LunarG, Inc.
O42 - Logiciel: Windows 10 Update and Privacy Settings - (.Microsoft Corporation.) [HKLM][64Bits] -- {4DFCD818-036A-4229-A67D-CF17DC461D92} =>.Microsoft Corporation
O42 - Logiciel: WinRAR 5.50 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH®
O42 - Logiciel: ZebHelpProcess 2015 - (.Nicolas Coolman.) [HKLM][64Bits] -- ZebHelpProcess_is1 =>.Nicolas Coolman

---\\ HKCU & HKLM Software Keys (76) - 7s
HKLM\SOFTWARE\Wow6432Node\AdwCleaner =>.Malwarebytes
HKLM\SOFTWARE\Wow6432Node\AGEIA Technologies =>.AGEIA Technologies
HKLM\SOFTWARE\Wow6432Node\Battle.net =>.Games Software
HKLM\SOFTWARE\Wow6432Node\Blizzard Entertainment =>.Blizzard Entertainment
HKLM\SOFTWARE\Wow6432Node\Borland =>.Borland
HKLM\SOFTWARE\Wow6432Node\Clearfi =>.Samsung Electronics
HKLM\SOFTWARE\Wow6432Node\Croteam =>.Croteam
HKLM\SOFTWARE\Wow6432Node\CyberLink =>.CyberLink Corporation
HKLM\SOFTWARE\Wow6432Node\DashlaneUpgrade =>.Dashlane, Inc
HKLM\SOFTWARE\Wow6432Node\DivX =>.DivX Inc.
HKLM\SOFTWARE\Wow6432Node\GameSpy =>.GameSpy
HKLM\SOFTWARE\Wow6432Node\Google =>.Google
HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel
HKLM\SOFTWARE\Wow6432Node\Khronos =>.Khronos
HKLM\SOFTWARE\Wow6432Node\Lake =>.Lake Sofware
HKLM\SOFTWARE\Wow6432Node\Licenses =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\Wow6432Node\MimarSinan =>.Mimar Sinan
HKLM\SOFTWARE\Wow6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\Norton =>.Symantec Corporation
HKLM\SOFTWARE\Wow6432Node\Nuance =>.Nuance
HKLM\SOFTWARE\Wow6432Node\NVIDIA Corporation =>.nVidia Corporation
HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Wow6432Node\OEM =>.OEM
HKLM\SOFTWARE\Wow6432Node\PCSX2
HKLM\SOFTWARE\Wow6432Node\PlugY, The Survival Kit
HKLM\SOFTWARE\Wow6432Node\Realtek =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp. =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\SpywareBlaster =>.Javacool Software
HKLM\SOFTWARE\Wow6432Node\SRS Labs =>.SRS Labs
HKLM\SOFTWARE\Wow6432Node\Symantec =>.Symantec
HKLM\SOFTWARE\Wow6432Node\Valve =>.Valve
HKLM\SOFTWARE\Wow6432Node\WOW6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Acer =>.Acer
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\Battle.net =>.Games Software
HKCU\SOFTWARE\Blizzard Entertainment =>.Blizzard Entertainment
HKCU\SOFTWARE\Borland =>.Borland
HKCU\SOFTWARE\Chromium =>.Chromium
HKCU\SOFTWARE\CroTeam =>.Croteam
HKCU\SOFTWARE\DivX =>.DivX Inc.
HKCU\SOFTWARE\DivXNetworks =>.DivXNetworks
HKCU\SOFTWARE\Emulators =>.Open Source
HKCU\SOFTWARE\Enterbrain =>.Enterbrain
HKCU\SOFTWARE\FileHippo.com =>.FileHippo.com
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\Host App Service =>.SUP.SweetLabs
HKCU\SOFTWARE\JaboSoft =>.JaboSoft
HKCU\SOFTWARE\Licenses =>.Microsoft Corporation
HKCU\SOFTWARE\Local AppWizard-Generated Applications =>.ZWCAD
HKCU\SOFTWARE\Malwarebytes =>.Malwarebytes
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\N64 Emulation =>.Games Software
HKCU\SOFTWARE\Netscape =>.Netscape
HKCU\SOFTWARE\Norton =>.Symantec Corporation
HKCU\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKCU\SOFTWARE\OEM =>.OEM
HKCU\SOFTWARE\PCSX2
HKCU\SOFTWARE\Piriform =>.Piriform
HKCU\SOFTWARE\PS2Eplugin
HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\SpywareBlaster =>.Javacool Software
HKCU\SOFTWARE\The Silicon Realms Toolworks =>.The Silicon Realms Toolworks
HKCU\SOFTWARE\Valve =>.Valve
HKCU\SOFTWARE\WinRAR =>.WinRAR
HKCU\SOFTWARE\WinRAR SFX =>.RarLab
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZebHelpProcess Helper =>.Nicolas Coolman
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKCU\SOFTWARE\AppDataLow\Software\Norton =>.Symantec Corporation

---\\ Contenu des dossiers Programmes (212) - 9s
O43 - CFD: 15/06/2017 - [] D -- C:\Program Files\Acer =>.Acer Incorporated®
O43 - CFD: 20/10/2017 - [] AD -- C:\Program Files\CCleaner =>.Piriform Ltd
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 15/06/2017 - [] D -- C:\Program Files\DriverSetupUtility =>.Acer Incorporated®
O43 - CFD: 19/10/2017 - [0] SHD -- C:\Program Files\Fichiers communs =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] AD -- C:\Program Files\GIMP 2 =>.Jernej Simončič®
O43 - CFD: 20/10/2017 - [] AD -- C:\Program Files\Intel =>.Intel Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files\Malwarebytes =>.Malwarebytes
O43 - CFD: 15/06/2017 - [] D -- C:\Program Files\Microsoft Office 15 =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] D -- C:\Program Files\NortonInstaller =>.Symantec
O43 - CFD: 21/10/2017 - [] D -- C:\Program Files\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files\Realtek =>.Realtek
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] AD -- C:\Program Files\rempl =>.Microsoft Corporation®
O43 - CFD: 15/06/2017 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] AD -- C:\Program Files\UNP =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\Program Files\VideoLAN =>.VideoLan Team
O43 - CFD: 11/07/2017 - [] RD -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 20/03/2017 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files\Windows Security =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] SHD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] AD -- C:\Program Files\WinRAR =>.win.rar GmbH®
O43 - CFD: 21/10/2017 - [] D -- C:\Program Files (x86)\Acer =>.Acer Incorporated®
O43 - CFD: 22/10/2017 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] D -- C:\Program Files (x86)\Croteam =>.Croteam
O43 - CFD: 15/06/2017 - [] D -- C:\Program Files (x86)\CyberLink =>.CyberLink Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\Program Files (x86)\Dashlane =>.Dashlane®
O43 - CFD: 22/10/2017 - [] D -- C:\Program Files (x86)\Diablo II =>.Blizzard Entertainment
O43 - CFD: 22/10/2017 - [] D -- C:\Program Files (x86)\DivX =>.DivX
O43 - CFD: 22/10/2017 - [] D -- C:\Program Files (x86)\FileHippo.com =>.Well Known Media Ltd®
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 21/10/2017 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield
O43 - CFD: 15/06/2017 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] AD -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] AD -- C:\Program Files (x86)\Mozilla Firefox =>.Mozilla
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] AD -- C:\Program Files (x86)\Norton Security =>.Symantec
O43 - CFD: 15/06/2017 - [] D -- C:\Program Files (x86)\NortonInstaller =>.Symantec
O43 - CFD: 21/10/2017 - [] D -- C:\Program Files (x86)\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files (x86)\Pcsx2
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files (x86)\PCSX2 1.0.0
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files (x86)\PCSX2 1.4.0
O43 - CFD: 15/06/2017 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] AD -- C:\Program Files (x86)\SpywareBlaster =>.Javacool Software
O43 - CFD: 22/10/2017 - [] D -- C:\Program Files (x86)\Steam =>.Steam Games
O43 - CFD: 15/06/2017 - [] D -- C:\Program Files (x86)\SymSilent =>.Symantec Corporation®
O43 - CFD: 15/06/2017 - [0] HD -- C:\Program Files (x86)\Temp =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [0] HD -- C:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] D -- C:\Program Files (x86)\VulkanRT =>.LunarG, Inc
O43 - CFD: 11/07/2017 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 20/03/2017 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] SHD -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] AD -- C:\Program Files (x86)\ZebHelpProcess =>.Nicolas Coolman
O43 - CFD: 18/03/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer =>.Acer
O43 - CFD: 20/10/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 20/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd
O43 - CFD: 20/10/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 12 =>.CyberLink Corporation
O43 - CFD: 21/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo II =>.Blizzard Entertainment
O43 - CFD: 22/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX =>.DivX
O43 - CFD: 20/10/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel =>.Intel Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes =>.Malwarebytes
O43 - CFD: 20/10/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security =>.Symantec
O43 - CFD: 21/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 21/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office 2016 =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCSX2
O43 - CFD: 21/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serious Sam
O43 - CFD: 20/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster =>.Javacool Software
O43 - CFD: 18/03/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam =>.Steam Games
O43 - CFD: 18/03/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team
O43 - CFD: 22/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 20/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP =>.Nicolas Coolman
O43 - CFD: 20/10/2017 - [] D -- C:\ProgramData\Acer =>.Acer
O43 - CFD: 20/10/2017 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\ProgramData\Blizzard Entertainment =>.Blizzard Entertainment
O43 - CFD: 19/10/2017 - [0] SHD -- C:\ProgramData\Bureau =>.Microsoft Corporation
O43 - CFD: 15/06/2017 - [] D -- C:\ProgramData\CLSK =>.CLSK
O43 - CFD: 16/07/2016 - [0] D -- C:\ProgramData\Comms =>.Microsoft Corporation
O43 - CFD: 15/06/2017 - [] D -- C:\ProgramData\CyberLink =>.CyberLink Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\ProgramData\Dashlane =>.Dashlane
O43 - CFD: 22/10/2017 - [] D -- C:\ProgramData\DivX =>.DivX
O43 - CFD: 21/10/2017 - [] D -- C:\ProgramData\Doctor Web =>.Doctor Web Ltd
O43 - CFD: 20/10/2017 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 15/06/2017 - [] D -- C:\ProgramData\DriverSetupUtility
O43 - CFD: 15/06/2017 - [] D -- C:\ProgramData\install_clap =>.Microsoft Corporation
O43 - CFD: 15/06/2017 - [] D -- C:\ProgramData\Intel =>.Intel Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\ProgramData\IsolatedStorage =>.id Software
O43 - CFD: 20/10/2017 - [] D -- C:\ProgramData\Licenses =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes
O43 - CFD: 19/10/2017 - [0] SHD -- C:\ProgramData\Menu Démarrer =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [0] SHD -- C:\ProgramData\Modèles =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\ProgramData\Norton =>.Symantec Corporation
O43 - CFD: 15/06/2017 - [] D -- C:\ProgramData\NortonInstaller =>.Symantec
O43 - CFD: 22/10/2017 - [] D -- C:\ProgramData\NVIDIA =>.nVidia Corporation
O43 - CFD: 21/10/2017 - [] D -- C:\ProgramData\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 19/10/2017 - [] HD -- C:\ProgramData\O949
O43 - CFD: 19/10/2017 - [] D -- C:\ProgramData\OEM =>.OEM
O43 - CFD: 22/10/2017 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 15/06/2017 - [] D -- C:\ProgramData\PPiP
O43 - CFD: 21/10/2017 - [] AD -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 15/06/2017 - [] D -- C:\ProgramData\Roaming =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [0] D -- C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] AD -- C:\ProgramData\Temp =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\ProgramData\USOPrivate =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\ProgramData\USOShared =>.Microsoft Corporation
O43 - CFD: 20/03/2017 - [] D -- C:\ProgramData\WindowsHolographicDevices =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] HD -- C:\ProgramData\{72725B64-F17C-4EB1-9CF0-3729C6F52EB5}
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files (x86)\Common Files\Borland Shared =>.Borland
O43 - CFD: 21/10/2017 - [] AD -- C:\Program Files (x86)\Common Files\DESIGNER =>.Designer
O43 - CFD: 22/10/2017 - [] D -- C:\Program Files (x86)\Common Files\DivX Shared =>.DivX
O43 - CFD: 21/10/2017 - [] D -- C:\Program Files (x86)\Common Files\InstallShield =>.InstallShield
O43 - CFD: 15/06/2017 - [] D -- C:\Program Files (x86)\Common Files\Intel Corporation =>.Intel Corporation
O43 - CFD: 21/10/2017 - [] AD -- C:\Program Files (x86)\Common Files\Microsoft Shared =>.Microsoft Corporation
O43 - CFD: 15/06/2017 - [] D -- C:\Program Files (x86)\Common Files\PostureAgent =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\Program Files (x86)\Common Files\Steam =>.Steam Games
O43 - CFD: 21/10/2017 - [0] D -- C:\Program Files (x86)\Common Files\SWF Studio =>.SWF Studio
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files (x86)\Common Files\Symantec Shared =>.Symantec Corporation
O43 - CFD: 20/03/2017 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\Users\rpgis\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Roaming\DivX =>.DivX
O43 - CFD: 19/10/2017 - [] D -- C:\Users\rpgis\AppData\Roaming\Intel =>.Intel Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\Users\rpgis\AppData\Roaming\Intel Corporation =>.Intel Corporation
O43 - CFD: 22/10/2017 - [] SD -- C:\Users\rpgis\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Users\rpgis\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 21/10/2017 - [0] D -- C:\Users\rpgis\AppData\Roaming\NVIDIA =>.nVidia Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Roaming\vlc =>.VideoLan Team
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Roaming\WinRAR =>.WinRAR
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 19/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\AOP SDK =>.Acer Inc.
O43 - CFD: 20/10/2017 - [0] SHD -- C:\Users\rpgis\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\Blizzard Entertainment =>.Blizzard Entertainment
O43 - CFD: 19/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\CareCenter =>.Acer Inc.
O43 - CFD: 20/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\CEF =>.CEF
O43 - CFD: 21/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\clear.fi =>.CyberLink Corporation
O43 - CFD: 21/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\Comms =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\ConnectedDevicesPlatform =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [0] D -- C:\Users\rpgis\AppData\Local\DBG =>.DBG
O43 - CFD: 20/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\DivX =>.DivX
O43 - CFD: 21/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\DOSBox =>.DOSBox Team
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\Google =>.Google
O43 - CFD: 20/10/2017 - [0] SHD -- C:\Users\rpgis\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\Host App Service =>.SUP.SweetLabs
O43 - CFD: 21/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\MicrosoftEdge =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 20/10/2017 - [0] D -- C:\Users\rpgis\AppData\Local\NetworkTiles =>.NetworkTiles
O43 - CFD: 21/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\NVIDIA =>.nVidia Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\Publishers =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\Steam =>.Steam Games
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [0] SHD -- C:\Users\rpgis\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\TileDataLayer =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] D -- C:\Users\rpgis\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 20/10/2017 - [0] D -- C:\Users\rpgis\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 11/07/2017 - [] RD -- C:\Users\rpgis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] RD -- C:\Users\rpgis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] RD -- C:\Users\rpgis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 21/10/2017 - [] D -- C:\Users\rpgis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Diablo II =>.Blizzard Entertainment
O43 - CFD: 18/03/2017 - [] D -- C:\Users\rpgis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Users\rpgis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pcsx2
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlugY, The Survival Kit
O43 - CFD: 21/10/2017 - [] RD -- C:\Users\rpgis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] RD -- C:\Users\rpgis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] RD -- C:\Users\rpgis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\Users\rpgis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 20/10/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 15/06/2017 - [] D -- C:\Users\Default\AppData\Local\Host App Service =>.SUP.SweetLabs
O43 - CFD: 20/03/2017 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 15/06/2017 - [] D -- C:\Users\Default User\AppData\Local\Host App Service =>.SUP.SweetLabs
O43 - CFD: 20/03/2017 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\acer =>.Acer

---\\ ShellIconOverlayIdentifiers (SIOI) (12) - 0s
O106 - SIOI: OverlayExcluded Class [ OverlayExcluded] - {4433A54A-1AC8-432F-90FC-85F045CF383C}. (.Symantec Corporation - Backup Shell.) -- C:\Program Files (x86)\Norton Security\Engine32\22.9.3.13\bushell.dll =>.Symantec Corporation®
O106 - SIOI: OverlayPending Class [ OverlayPending] - {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}. (.Symantec Corporation - Backup Shell.) -- C:\Program Files (x86)\Norton Security\Engine32\22.9.3.13\bushell.dll =>.Symantec Corporation®
O106 - SIOI: OverlayProtected Class [ OverlayProtected] - {476D0EA3-80F9-48B5-B70B-05E677C9C148}. (.Symantec Corporation - Backup Shell.) -- C:\Program Files (x86)\Norton Security\Engine32\22.9.3.13\bushell.dll =>.Symantec Corporation®
O106 - SIOI: ACloudSynced Class [ ACloudSynced] - {5CCE71FA-9F61-4F24-9CD1-98D819B40D68}. (.Acer Incorporated - abBox Shell Extension.) -- C:\Program Files (x86)\Acer\shellext\Win32\shellext_win.dll =>.Acer Incorporated®
O106 - SIOI: ACloudSyncing Class [ ACloudSyncing] - {C1E1456F-C2D8-4C96-870D-35F1E13941EE}. (.Acer Incorporated - abBox Shell Extension.) -- C:\Program Files (x86)\Acer\shellext\Win32\shellext_win.dll =>.Acer Incorporated®
O106 - SIOI: ACloudToBeSynced Class [ ACloudToBeSynced] - {307523FA-DDC0-4068-983F-2A6B34627744}. (.Acer Incorporated - abBox Shell Extension.) -- C:\Program Files (x86)\Acer\shellext\Win32\shellext_win.dll =>.Acer Incorporated®
O106 - SIOI: ErrorOverlayHandler Class [ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\rpgis\AppData\Local\Microsoft\OneDrive\17.3.7073.1013\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SharedOverlayHandler Class [ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\rpgis\AppData\Local\Microsoft\OneDrive\17.3.7073.1013\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SharedSyncingOverlayHandler Class [ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\rpgis\AppData\Local\Microsoft\OneDrive\17.3.7073.1013\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: UpToDateOverlayHandler Class [ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\rpgis\AppData\Local\Microsoft\OneDrive\17.3.7073.1013\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SyncingOverlayHandler Class [ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\rpgis\AppData\Local\Microsoft\OneDrive\17.3.7073.1013\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: ReadOnlyOverlayHandler Class [ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\rpgis\AppData\Local\Microsoft\OneDrive\17.3.7073.1013\FileSyncShell.dll =>.Microsoft Corporation®

---\\ Image File Execution Options (18) - 1s
O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\\3] =>.Microsoft Windows®
O50 - IFEO:C:\WINDOWS\System32\drvinst.exe - (.Microsoft Corporation - Module d’installation de pilotes.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\ie4uinit.exe - (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - Outil d’installation sans assistance d’IE 7.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Microsoft Management Console.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\MRT.exe - (.Microsoft Corporation - Outil de suppression de logiciels malveilla.) [CFGOptions\\1] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Hôte des applications HTML de Microsoft®.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation Host.) [MitigationOptions\\1118481] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\\4294967296] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Application sous-système spouleur.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Application sous-système spouleur.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Processus hôte pour les services Windows.) [MinimumStackCommitInBytes\\32768] =>.Microsoft Windows Publisher®
O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation

---\\ Liste des pilotes du système (61) - 9s
O58 - SDL:2017/03/18 22:56:25 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107424] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135512] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83352] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259488] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [27040] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [132000] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Windows ® Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [9728] =>.Windows ® Win 7 DDK provider
O58 - SDL:2017/03/18 22:56:23 A . (.QLogic Corporation - QLogic Gigabit Ethernet VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [533920] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Chelsio Communications - Chelsio iSCSI Crash Dump Driver.) -- C:\WINDOWS\System32\drivers\cht4dx64.sys [102816] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Chelsio Communications - Chelsio iSCSI VMiniport Driver.) -- C:\WINDOWS\System32\drivers\cht4sx64.sys [347032] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Chelsio Communications - Virtual Bus Driver for Chelsio ® T4 Chipset.) -- C:\WINDOWS\System32\drivers\cht4vx64.sys [2104224] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:23 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3419040] =>.Microsoft Windows®
O58 - SDL:2011/10/31 17:12:34 A . (.Hewlett-Packard. - USB HID Upper Filter Driver.) -- C:\WINDOWS\System32\drivers\HPMoA407.sys [25088] =>.Hewlett-Packard.
O58 - SDL:2017/03/18 22:56:25 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64416] =>.Microsoft Windows®
O58 - SDL:2012/06/14 09:37:22 A . (.Hewlett-Packard. - USB HID Filter Driver.) -- C:\WINDOWS\System32\drivers\HPubA407.sys [18944] =>.Hewlett-Packard.
O58 - SDL:2017/03/18 22:56:28 A . (.Intel® Corporation - Intel® Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iagpio.sys [33280] =>.Intel® Corporation
O58 - SDL:2017/03/18 22:56:28 A . (.Intel® Corporation - Intel® Serial IO I2C Driver.) -- C:\WINDOWS\System32\drivers\iai2c.sys [81408] =>.Intel® Corporation
O58 - SDL:2017/03/18 22:56:28 A . (.Intel Corporation - Intel® Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [70656] =>.Intel Corporation
O58 - SDL:2017/03/18 22:56:28 A . (.Intel Corporation - Intel® Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [85504] =>.Intel Corporation
O58 - SDL:2017/03/18 22:56:28 A . (.Intel Corporation - Intel® Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [165376] =>.Intel Corporation
O58 - SDL:2017/03/18 22:56:28 A . (.Intel Corporation - Intel® Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [168448] =>.Intel Corporation
O58 - SDL:2017/03/18 22:56:23 A . (.Intel Corporation - Intel® Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group®
O58 - SDL:2017/03/18 22:56:19 A . (.Intel Corporation - Intel® Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [113152] =>.Intel Corporation
O58 - SDL:2016/09/20 11:04:30 A . (.Intel Corporation - Intel® Rapid Storage Technology driver -.) -- C:\WINDOWS\System32\drivers\iaStorA.sys [795640] =>.Intel® Rapid Storage Technology®
O58 - SDL:2017/03/18 22:56:26 A . (.Intel Corporation - Intel® Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [673184] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:26 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412064] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [526240] =>.Microsoft Windows®
O58 - SDL:2016/10/06 11:51:52 A . (.Intel Corporation - Intel® Wireless Bluetooth® Filter Drive.) -- C:\WINDOWS\System32\drivers\ibtusb.sys [179472] =>.Intel Corporation-Wireless Connectivity Solutions®
O58 - SDL:2017/03/18 22:56:25 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [108960] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [123808] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [103328] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82848] =>.Microsoft Windows®
O58 - SDL:2017/10/04 13:15:42 A . (...) -- C:\WINDOWS\System32\drivers\mbae64.sys [77440] =>.Malwarebytes Corporation®
O58 - SDL:2017/10/20 17:22:36 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [252232] =>.Malwarebytes Corporation®
O58 - SDL:2017/03/18 22:56:25 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59808] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\MegaSas2i.sys [64416] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575904] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [842656] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63904] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [108960] =>.Microsoft Windows®
O58 - SDL:2016/09/13 06:08:46 A . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\WINDOWS\System32\drivers\Netwtw04.sys [7308560] =>.Intel Corporation-Wireless Connectivity Solutions®
O58 - SDL:2017/10/09 14:20:22 A . (.NVIDIA Corporation - NVIDIA HDMI Audio Driver.) -- C:\WINDOWS\System32\drivers\nvhda64v.sys [225208] =>.NVIDIA Corporation®
O58 - SDL:2017/03/18 22:56:25 A . (.NVIDIA Corporation - NVIDIA® nForce RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150432] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.NVIDIA Corporation - NVIDIA® nForce Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166304] =>.Microsoft Windows®
O58 - SDL:2016/10/25 22:19:37 A . (.NVIDIA Corporation - NVIDIA Virtual Audio Driver.) -- C:\WINDOWS\System32\drivers\nvvad64v.sys [46016] =>.NVIDIA Corporation®
O58 - SDL:2017/10/06 15:35:55 A . (.NVIDIA Corporation - Virtual USB Host Controller driver.) -- C:\WINDOWS\System32\drivers\nvvhci.sys [57792] =>.NVIDIA Corporation®
O58 - SDL:2017/03/18 22:56:25 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58784] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [61848] =>.Microsoft Windows®
O58 - SDL:2016/08/01 03:42:40 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.40 64-bit Dr.) -- C:\WINDOWS\System32\drivers\rt640x64.sys [943112] =>.Realtek Semiconductor Corp.®
O58 - SDL:2016/10/14 02:22:06 A . (.Realtek Semiconductor Corp. - Realtek® High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RTKVHD64.sys [5361672] =>.Realtek Semiconductor Corp.®
O58 - SDL:2016/08/05 03:09:48 A . (.Realsil Semiconductor Corporation - RTS USB READER Driver.) -- C:\WINDOWS\System32\drivers\RtsUer.sys [418784] =>.Realtek Semiconductor Corp.®
O58 - SDL:2017/03/18 22:56:26 A . (...) -- C:\WINDOWS\System32\drivers\SDFRd.sys [31128] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44960] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81824] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31136] =>.Microsoft Windows®
O58 - SDL:2017/06/15 15:11:19 A . (.Symantec Corporation - Symantec Event Library.) -- C:\WINDOWS\System32\drivers\SYMEVENT64x86.SYS [100592] =>.Symantec Corporation®
O58 - SDL:2016/09/06 14:59:28 A . (.Intel Corporation - Intel® Management Engine Interface.) -- C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys [204896] =>.Intel® Embedded Subsystems and IP Blocks Group®
O58 - SDL:2017/03/18 22:56:25 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166816] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305568] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [32160] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [64920] =>.Microsoft Windows®

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (4) - 30s
O61 - LFC: 2017/10/20 16:13:07 RA . (..) -- C:\Users\rpgis\AppData\Roaming\Microsoft\Installer\{0E2B767B-EA6A-489B-BF83-8083FE1DB661}\_3DDFBC2CECDECFF328EC5D.exe [12862]
O61 - LFC: 2017/10/21 21:09:13 A . (..) -- C:\Users\rpgis\Desktop\Jeux vidéo\ffobjet\ffobjet\ffobjet.exe [613376]
O61 - LFC: 2017/10/21 00:05:28 A . (..) -- C:\Users\rpgis\Documents\Dolphin Emulator\Wii\sys\uid.sys [12]
O61 - LFC: 2017/10/21 12:35:58 A . (..) -- C:\Users\rpgis\Downloads\2017\octobre\zyrwu861.exe [159797072] {06D1FA3F75BBBE0FB9CD5D15E6E6B852}

---\\ Associations Shell Spawning (11) - 0s
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\WINDOWS\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\WINDOWS\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.EXE =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (...) -- %1" %*
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®

---\\ Menu de démarrage Internet (12) - 0s
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox> [64Bits][HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O68 - StartMenuInternet: <Google Chrome> <Google Chrome> [64Bits][HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer> [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox> [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <Google Chrome> <Google Chrome> [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer> [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox> [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <Google Chrome> <Google Chrome> [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer> [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox> [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <Google Chrome> <Google Chrome> [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer> [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

---\\ Recherche d'infection sur les navigateurs (119) - 4s
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.mywebsearch.prevKwdEnabled", true); =>PUP.Optional.MyWebSearch
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.BUTTON_STRUCTURE", "[{\"b\":223772299,\"c\":\"mindspark.magnify\",\"p\":\"L.0\[...] =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.browser.startup.homepage.prev", "http://hp.myway.com/productivityboss/ttab02/i[...] =>.SUP.MindSpark
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.browser.startup.homepage.savedPrev", "true"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.browser.startup.homepage.tb", "http://hp.myway.com/easypdfcombine/ttab02/index[...] =>.SUP.MindSpark
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.browser.startup.page.savedPrev", 1); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.browser.startup.page.tb", 1); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.browser.version.last", "56.0"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.coId", "ba90d7764b494bdd9740cd6d49c12df0"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.competitorDNS", "{\"comment\":\"refresh every 1 week (7*24*60*60*1000)\",\"ref[...] =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.firefoxSearchExtensionEnabled", "true"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.firstKnownVersion", "7.800.11.13915"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.homepage", "http://hp.myway.com/easypdfcombine/ttab02/index.html?coId=ba90d776[...] =>.SUP.MindSpark
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.hp.guardType", "HPR"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.initialized", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.installType", "XPI"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.installation.dlpCountryCode", "FR"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.installation.installDate", "2017102003"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.installation.partnerId", "^BSB^xdm029^TTAB02^fr"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.installation.partnerSubId", "COKN7qyt_9YCFSQW0wodMWwOLQ"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.installation.pixelUrl", "http://free.easypdfcombine.com/install_pixels.jhtml?p[...] =>.SUP.MindSpark
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.installation.success", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.installation.toolbarDataSource", "[\"COOKIE\",\"LOCAL_STORAGE\"]"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.installation.toolbarId", "62998B80-C9C2-42F3-8397-39E0A3E1359E"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.lastActivePing", "1508680611205"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.lastKnownVersion", "7.800.11.13915"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.lssState", "{\"previousLocales\":[\"fr\",\"fr-FR\",\"en-US\",\"en\"],\"support[...] =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.options.defaultSearch", false); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.options.homePageEnabled", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.options.keywordEnabled", false); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.options.tabEnabled", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.partnerPixelFired", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.productDeliveryOption.language", "en"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.productDeliveryOption.newTabURL", "http://hp.myway.com/easypdfcombine/ttab02/i[...] =>.SUP.MindSpark
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.productDeliveryOption.type", "ToolTab"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.successUrl", "http://easypdfcombine.dl.tb.ask.com/installComplete.jhtml"); =>.SUP.MindSpark
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.toolbarCollapsed", false); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.uninstallSurveyUrl", "http://easypdfcombine.dl.myway.com/uninstall.jhtml?surve[...] =>.SUP.MindSpark
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._ceMembers_.uninstallTasks", "{\"prefBranchesToDelete\":[\"extensions.toolbar.mindspark._c[...] =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.BUTTON_STRUCTURE", "[{\"b\":224233618,\"c\":\"mindspark.magnify\",\"p\":\"L.0\[...] =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.browser.startup.homepage.prev", "http://www.google.fr/"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.browser.startup.homepage.savedPrev", "true"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.browser.startup.homepage.tb", "http://hp.myway.com/productivityboss/ttab02/ind[...] =>.SUP.MindSpark
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.browser.startup.page.savedPrev", 1); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.browser.startup.page.tb", 1); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.browser.version.last", "56.0"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.coId", "87b57d48a677450ca066e05ec674ee8c"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.competitorDNS", "{\"comment\":\"refresh every 1 week (7*24*60*60*1000)\",\"ref[...] =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.firefoxSearchExtensionEnabled", "true"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.firstKnownVersion", "7.800.11.15141"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.homepage", "http://hp.myway.com/productivityboss/ttab02/index.html?coId=87b57d[...] =>.SUP.MindSpark
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.hp.enabled", false); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.hp.guardType", "HPR"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.initialized", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.installType", "XPI"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.installation.dlpCountryCode", "FR"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.installation.installDate", "2017102003"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.installation.partnerId", "^BYM^xdm009^TTAB02^fr"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.installation.pixelUrl", "http://www.productivityboss.com/install_pixels.jhtml?[...] =>.SUP.MindSpark
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.installation.success", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.installation.toolbarDataSource", "[\"COOKIE\",\"LOCAL_STORAGE\"]"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.installation.toolbarId", "A59B2D47-95BF-4D8B-BC3B-C82652458CAD"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.lastActivePing", "1508680611332"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.lastKnownVersion", "7.800.11.15141"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.lssState", "{\"previousLocales\":[\"fr\",\"fr-FR\",\"en-US\",\"en\"],\"support[...] =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.options.defaultSearch", false); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.options.homePageEnabled", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.options.keywordEnabled", false); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.options.tabEnabled", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.partnerPixelFired", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.productDeliveryOption.language", "en"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.productDeliveryOption.newTabURL", "http://hp.myway.com/productivityboss/ttab02[...] =>.SUP.MindSpark
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.productDeliveryOption.type", "ToolTab"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.successUrl", "http://productivityboss.dl.tb.ask.com/installComplete.jhtml"); =>.SUP.MindSpark
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.toolbarCollapsed", false); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.uninstallSurveyUrl", "http://productivityboss.dl.myway.com/uninstall.jhtml?sur[...] =>.SUP.MindSpark
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._e5Members_.uninstallTasks", "{\"prefBranchesToDelete\":[\"extensions.toolbar.mindspark._e[...] =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.BUTTON_STRUCTURE", "[{\"b\":232532496,\"c\":\"mindspark.magnify\",\"p\":\"L.0\[...] =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.browser.search.defaultenginename.prev", "Bing"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.browser.search.defaultenginename.savedPrev", "true"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.browser.search.defaultenginename.tb", "Ask Web Search"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.browser.search.selectedEngine.prev", "Bing"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.browser.search.selectedEngine.savedPrev", "true"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.browser.search.selectedEngine.tb", "Ask Web Search"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.browser.version.last", "56.0"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.coId", "ba90d7764b494bdd9740cd6d49c12df0"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.competitorDNS", "{\"comment\":\"refresh every 1 week (7*24*60*60*1000)\",\"ref[...] =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.firefoxSearchExtensionEnabled", "false"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.firstKnownVersion", "7.800.11.11538"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.homepage", "http://home.tb.ask.com/index.jhtml?n=780BD6C7&ptb=62998B80-C9C2-42[...] =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.hp.enabled", false); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.initialized", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.installType", "XPI"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.installation.dlpCountryCode", "FR"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.installation.installDate", "2017102003"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.installation.partnerId", "^BSB^xdm029^TTAB02^fr"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.installation.partnerSubId", "COKN7qyt_9YCFSQW0wodMWwOLQ"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.installation.success", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.installation.toolbarDataSource", "[\"COOKIE\",\"LOCAL_STORAGE\"]"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.installation.toolbarId", "62998B80-C9C2-42F3-8397-39E0A3E1359E"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.lastActivePing", "1508680611636"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.lastKnownVersion", "7.800.11.11538"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.lssState", "{\"previousLocales\":[\"fr\",\"fr-FR\",\"en-US\",\"en\"],\"support[...] =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.options.defaultSearch", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.options.homePageEnabled", false); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.options.keywordEnabled", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.options.tabEnabled", false); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.productDeliveryOption.language", "en"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.productDeliveryOption.type", "DefaultSearch"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.successUrl", "#installed=CPC"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.toolbar.ownSearch", true); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.toolbarCollapsed", false); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.uninstallSurveyUrl", "https://www.research.net/r/BZBDLY5?c=<!--toolbarID-->"); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark._j5Members_.uninstallTasks", "{\"prefBranchesToDelete\":[\"extensions.toolbar.mindspark._j[...] =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark.hp.enabled", false); =>Adware.Bandoo
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("extensions.toolbar.mindspark.lastInstalled", "[email protected]"); =>.SUP.MindSpark
O69 - SBI: prefs.js [rpgis - kqpq3guk.default] user_pref("keyword.URL", "http://int.search.tb.ask.com/search/GGmain.jhtml?st=kwd&ptb=62998B80-C9C2-42F3-8397-39E0A3E1359E&n=783a8[...] =>Toolbar.Ask
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (@ieframe.dll,-12512) -
O69 - SBI: SearchScopes [HKLM] [64Bits]{8EA5B5CE-7C5E-44DE-AF37-6DC423C7015D} [DefaultScope] - (Bing) -

---\\ Enumère les services démarrés par Svchost (47) - 1s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [189952] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [189952] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\WINDOWS\System32\srvsvc.dll [303104] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\WINDOWS\System32\gpsvc.dll [1269248] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\WINDOWS\System32\ikeext.dll [934912] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\WINDOWS\System32\iphlpsvc.dll [996864] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\WINDOWS\system32\seclogon.dll [31232] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\WINDOWS\System32\appinfo.dll [138752] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\WINDOWS\System32\iscsiexe.dll [150016] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\WINDOWS\System32\eapsvc.dll [108032] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\WINDOWS\System32\schedsvc.dll [877568] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\System32\wbem\WMIsvc.dll [221696] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\WINDOWS\System32\browser.dll [133120] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\System32\profsvc.dll [413184] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\WINDOWS\System32\sessenv.dll [385536] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\WINDOWS\System32\wercplsupport.dll [93184] =>.Microsoft Corporation
O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\WINDOWS\System32\Windows.SharedPC.AccountManager.dll [192512] =>.Microsoft Corporation
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\WINDOWS\System32\XblGameSave.dll [1135104] =>.Microsoft Corporation
O83 - Search Svchost Services: NaturalAuthentication (NaturalAuthentication) . (.Microsoft Corporation - Service d’authentification naturelle.) -- C:\WINDOWS\System32\NaturalAuth.dll [723968] =>.Microsoft Corporation
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\WINDOWS\System32\wlidsvc.dll [2153984] =>.Microsoft Corporation
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\WINDOWS\System32\usermgr.dll [877568] =>.Microsoft Corporation
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\WINDOWS\System32\XblAuthManager.dll [1015296] =>.Microsoft Corporation
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL Windows Management Service.) -- C:\WINDOWS\System32\Windows.Internal.Management.dll [536064] =>.Microsoft Corporation
O83 - Search Svchost Services: xbgm (xbgm) . (.Microsoft Corporation - Xbox Game Monitoring Service.) -- C:\WINDOWS\System32\xbgmsvc.dll [301216] =>.Microsoft Windows Publisher®
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\WINDOWS\System32\themeservice.dll [69632] =>.Microsoft Corporation
O83 - Search Svchost Services: TokenBroker (TokenBroker) . (.Microsoft Corporation - Token Broker.) -- C:\WINDOWS\System32\TokenBroker.dll [1052672] =>.Microsoft Corporation
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service de géolocalisation.) -- C:\WINDOWS\System32\lfsvc.dll [43520] =>.Microsoft Corporation
O83 - Search Svchost Services: Irmon (Irmon) . (.Microsoft Corporation - Moniteur infrarouge.) -- C:\WINDOWS\System32\irmon.dll [24576] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\WINDOWS\System32\rasauto.dll [104448] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\WINDOWS\System32\rasmans.dll [874496] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\WINDOWS\System32\mprdim.dll [490496] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\WINDOWS\System32\sens.dll [69632] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\WINDOWS\System32\ipnathlp.dll [537600] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\WINDOWS\System32\tapisrv.dll [306688] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\WINDOWS\System32\wuaueng.dll [2446336] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\WINDOWS\System32\qmgr.dll [1159680] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\System32\shsvcs.dll [612864] =>.Microsoft Corporation
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\WINDOWS\System32\dmwappushsvc.dll [55296] =>.Microsoft Corporation
O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Paramètres de vol.) -- C:\WINDOWS\System32\flightsettings.dll [699904] =>.Microsoft Corporation
O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Service du système de notifications Push Wi.) -- C:\WINDOWS\System32\WpnService.dll [276480] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\WINDOWS\System32\bdesvc.dll [385536] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\WINDOWS\System32\XboxNetApiSvc.dll [1067008] =>.Microsoft Corporation
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Mettre à jour la session Orchestrator Core.) -- C:\WINDOWS\System32\usocore.dll [684032] =>.Microsoft Corporation
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Service Configuration du réseau.) -- C:\WINDOWS\System32\NetSetupSvc.dll [261632] =>.Microsoft Corporation
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [233984] =>.Microsoft Corporation
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\WINDOWS\System32\ncasvc.dll [167424] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxGipSvc (XboxGipSvc) . (.Microsoft Corporation - Xbox Gip Management Service.) -- C:\WINDOWS\System32\XboxGipSvc.dll [18944] =>.Microsoft Corporation

---\\ Scan Additionnel (7) - 0s
C:\Users\rpgis\AppData\Roaming\Mozilla\Firefox\Profiles\kqpq3guk.default\extensions\[email protected] =>.SUP.MindSpark
C:\Users\rpgis\AppData\Roaming\Mozilla\Firefox\Profiles\kqpq3guk.default\extensions\[email protected] =>.SUP.MindSpark
C:\Users\rpgis\AppData\Roaming\Mozilla\Firefox\Profiles\kqpq3guk.default\extensions\[email protected] =>.SUP.MindSpark
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.SUP.Orphan
C:\Users\rpgis\AppData\Local\Host App Service =>.SUP.SweetLabs
C:\Users\Default\AppData\Local\Host App Service =>.SUP.SweetLabs
C:\Users\Default User\AppData\Local\Host App Service =>.SUP.SweetLabs

---\\ Récapitulatif des éléments trouvés sur votre station (6) - 1s







~ Unselected Options: O82,
~ End of the scan, 27201 items in 02mn07s (1150)(0)

 

Edit de Notpa :

 

Masqué long long rapport pour faciliter la lecture.

Pour les rapports volumineux, merci de les stocker sur un hébergeur comme CJoint et de coller le lien dans la réponse.

Merci

Modifié par fredorp59
Lien vers le commentaire
Partager sur d’autres sites

Voici la fin du rapport, désolé, problème d'internet

 

---\\ Récapitulatif des éléments trouvés sur votre station (6) - 1s







~ Unselected Options: O82,
~ End of the scan, 27201 items in 02mn07s (1150)(0)

Modifié par fredorp59
Lien vers le commentaire
Partager sur d’autres sites

Bonsoir,

 

Télécharger ZHPcleaner de Nicolas Coolman: https://www.nicolascoolman.com/fr/download/zhpcleaner/ sur le bureau. (à ne pas confondre avec ZhpDiag... )

 

https://www.nicolascoolman.com/fr/download/zhpcleaner/

 

Il ne nécessite aucune installation.

 

 

Le lancer par double-clic sous XP et par clic droit/exécuter en tant qu'administrateur sous Windows Vista/7/8/10

 

Cliquer sur Scanner puis sur Nettoyer.

 

Le rapport de réparation sera généré sur le bureau: poste-le dans ta réponse stp.

 

 

31-03-2015-22-40-15-4a9ae6e.jpg

 

@++

  • Upvote 1
Lien vers le commentaire
Partager sur d’autres sites

Ok, déjà pas mal de saletés liquidées.

 

Poursuis avec les deux outils suivants stp:

 

1) Télécharge Junkware Removal Tool et enregistre-le sur le bureau: http://downloads.malwarebytes.org/file/jrt

 

http://www.bleepingcomputer.com/download/junkware-removal-tool/

 

 

02-12-2015-18-16-59-4da348c.jpg

 

Sous XP, double-clique sur l'icône et presse une touche lorsque cela sera demandé.

 

Sous Vista/7/8, clic droit/exécuter en tant qu'administrateur.

 

Prendre patience pendant que JRT tourne.

 

Afin de ne pas fausser le rapport, ne passer l'outil qu'une seule fois svp!

 

 

Si l'antivirus fait des siennes: désactive-le provisoirement. Si tu ne sais pas comment faire, reporte-toi à cet article.

 

Poste le rapport généré à la fin de l'analyse.

 

>>>Si le rapport est long, l'héberger ici: http://cjoint.com ou http://dl.free.fr/

 

copier-raccourci-cjoint-52aa897.jpg

 

 

-----------------------------

sfleche.1275-1bcbbf.gif*** Si tu as une ancienne version d'AdwCleaner, lance-le et clique sur désinstaller.*** Onglet fichier/désinstaller

 

2) Télécharge AdwCleaner de MalwareBytes.

 

https://toolslib.net/downloads/viewdownload/1-adwcleaner/

 

https://www.malwarebytes.com/adwcleaner/

 

Enregistre-le sur le bureau (et pas ailleurs).

 

Afin de ne pas fausser le rapport, ne passer l'outil qu'une seule fois svp!

 

 

Si tu es sous XP double clique sur AdwCleaner pour lancer l'outil.

Si tu es sous Vista/Seven, clique droit sur AdwCleaner et choisis exécuter en tant qu'administrateur.

 

Clique sur Scanner et laisse travailler l'outil.

 

Cliquer sur Nettoyer, le bouton sera alors accessible.

 

Le rapport va s'ouvrir en fichier texte; copie la totalité de son contenu et colle-le dans ta réponse.

 

Le rapport est en outre sauvegardé sous C:\AdwCleaner[C1]

 

NB: Si l'outil "cale" en mode normal, le lancer en mode sans échec: http://www.vista-xp.fr/forum/topic93.html

 

A lire absolument: http://www.vista-xp.fr/forum/topic5482.html

http://www.vista-xp.fr/forum/topic10389.html

 

-------------------------

 

@++

  • Upvote 1
Lien vers le commentaire
Partager sur d’autres sites

Bonjour,

 

1)

  • Désactiver l'anti virus avant ! et lire ces instructions.
  • Sous IE9, IE10 ou IE11, le filtre SmartScreen déclenche une alerte. Cliquer sur Actions puis sur Exécuter quand même

     

    Autre lien pour SFT: https://1fichier.com/?4h9ckh00nx

    • Télécharger SFT.exe
    • Si l'antivirus fait des siennes: désactive-le provisoirement. Si tu ne sais pas comment faire, reporte-toi à cet article.
    • Enregistrer le fichier sur le bureau.
    • Sous XP, double cliquer sur le fichier.
    • Sous les autres versions de Windows, faire un clic droit sur le fichier et choisir Exécuter en temps qu'administrateur.
    16110108203922119714597908.jpg
    • Pour lancer le nettoyage, il suffit de cliquer sur Go. Patienter...
    • A la fin, un message vous demandera si vous voulez vider la corbeille.
    16103103291622119714596748.jpg
    • A la fin du nettoyage, un rapport va s'ouvrir.
    • Ce rapport est enregistré sur le bureau (SFTGC.txt)
Héberger sur http://cjoint.com pour ne pas planter le sujet. ou http://dl.free.fr/

 

Réactiver la protection antivirale.

 

--------------------------

 

2) Télécharger MBAM sur le bureau.

Faire un clic droit sur le fichier et choisir Exécuter en tant qu'administrateur pour lancer l'installation.

 

Dernières captures d'écran MBAM 3.05 : https://1fichier.com/?bpkmx5a1xp

 

 

Décocher la case concernant l'essai gratuit. N'apparait plus dans les versions 3.x mais on peut la désactiver dans l'interface du logiciel si on ne veut garder que la version Free.

 

 

Après l'installation, lancer MBAM (clic droit sur l'icône et choisir Exécuter en tant qu'administrateur.)

 

Patienter le temps de la mise à jour des bases.

 

16100101353022119714528022.jpg

 

Examen "Menaces" + Recherche de Rootkits:

 

Dans l'onglet Paramètres > Sous-onglet Détection et Protection, Options de détection, cochez la case située devant Recherche de Rootkits.

 

16100101353422119714528024.jpg

 

Cliquez sur l'onglet Analyse, sélectionner si besoin Analyse des menaces puis cliquez sur Lancer l'analyse >>. Si une mise à jour est disponible, cliquez sur le bouton Mettre à jour maintenant.

Un Examen "Menaces" va démarrer.

 

16100101353222119714528023.jpg

 

Avec certaines infections, vous pouvez voir l'affichage de ce message:

 

'Malwarebytes n'a pas pu charger le pilote Anti-Rootkit DDA'

 

Cliquez sur 'Oui' sur ce message, pour permettre le chargement du pilote après un redémarrage.

Laissez l'ordinateur redémarrer. Continuez avec le reste de ces instructions.

 

Si MBAM a trouvé des malwares :

 

Quand l'examen est terminé, cliquer sur Supprimer la sélection ==>> A ne pas oublier !!

Attendez l'affichage du message vous invitant à faire redémarrer le PC, puis cliquez sur Oui.

Le rapport de trouve dans l'Historique de MBAM, le prendre après le redémarrage.

 

Comment obtenir les rapports d'examen:

 

(Exporter le rapport et l'enregistrer en format txt)

•Après le redémarrage, quand vous êtes de retour sur le Bureau, ouvrez de nouveau MBAM.

•Cliquez sur l'onglet Historique > Journaux de l'application. (Scan log)

 

16100406580022119714534820.jpg

 

•Faites un double clic sur le Journal d'examen dont les date et heure correspondent à l'analyse qui vient d'être effectuée.

•Cliquez sur Exporter.

•Cliquez sur Fichier texte (*.txt)

 

16100406580222119714534821.jpg

 

•Dans la boîte de dialogue 'Enregistrer le fichier' qui s'est ouverte, cliquez sur le Bureau.

•Dans la zone Nom du fichier: saisissez un nom pour votre journal d'examen.

 

16100406580422119714534822.jpg

 

•Une boîte de message intitulée Fichier enregistré doit apparaître et vous annoncer que "Votre fichier a été exporté avec succès".

 

16100406581922119714534824.jpg

•Cliquez sur OK

•Attachez ce fichier dans votre prochaine réponse.

 

@++

  • Upvote 1
Lien vers le commentaire
Partager sur d’autres sites

Bonjour,

 

Voici le rapport SFT : http://www.cjoint.com/c/GJyogrsmVvd

 

Et celui de malwarebytes :http://www.cjoint.com/c/GJyohVgbdId

 

J'ai mit en quarantaine les éléments et supprimer de malwarebytes.

Modifié par fredorp59
Lien vers le commentaire
Partager sur d’autres sites

Re,

 

C'est bien et ça a l'air presque propre.

 

Fais les vérifications de mises à jour de tes applications à l'aide de l'utilitaire Kaspersky Software Updater: http://forum.zebulon.fr/kaspersky-software-updater-t217191.html?p=1812832

 

Après avoir fait le nécessaire, refais un scan ZhpDiag et héberge son rapport sur Cjoint.com stp: http://www.cjoint.com/ Colle le lien obtenu dans ta réponse.

 

@++

  • Upvote 1
Lien vers le commentaire
Partager sur d’autres sites

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...