Virus aidez moi s il vous plait

Résolu/Fermé
kaori64 Messages postés 75 Date d'inscription lundi 21 juillet 2008 Statut Membre Dernière intervention 29 décembre 2015 - 17 déc. 2013 à 14:33
loumax91 Messages postés 3183 Date d'inscription mardi 14 juin 2011 Statut Contributeur sécurité Dernière intervention 14 avril 2019 - 22 déc. 2013 à 21:32
Bonjour,

Bonjour, lorsque je l'allume mon ordi il met des mises à jour qui traine en longueur et lorsque que je finis par l éteindre pour le rallumer une fenêtre en anglais avec marquer system recovery options me bloque
Mon fils jouant et téléchargeant des jeux je me demande si mon ordi n à pas attrapé un virus ! Pourriez vous m aider en sachant que je suis vraiment débutante en informatique ! Merci beaucoup





43 réponses

loumax91 Messages postés 3183 Date d'inscription mardi 14 juin 2011 Statut Contributeur sécurité Dernière intervention 14 avril 2019 478
21 déc. 2013 à 07:55
Bonjour kaori64,

Je vais prendre la suite, fais ce qui suis dans l'ordre indiqué.

1) A désinstaller via > menu démarrer > panneau de configuration > programmes et fonctionnalités :
-BearShare =>PUP.BearShare

Il est aussi préférable pour la désinfection, de désinstaller ces deux logiciels de P2P:
-Vuze
-eMule
Les risques sécuritaires du peer-to-peer en 10 points

--------------2)

▶ Attention :

/!\ Ce script est exclusivement réservé à l'utilisateur actuel du sujet, vous ne devez en aucun cas l'utiliser de votre propre chef sur un autre pc, sous risque d'endommager le système /!\


⇒ Ce script va cibler certains éléments à supprimer :

¶ Ferme toutes tes applications en cours
¶ Ouvre ce lien, sélectionne et copie toutes les lignes.

¶ Lance ZHPFix via le raccourci sur ton Bureau, (Si tu es sous Vista ou Windows 7 ou Windows 8 n'oublie pas clic droit → en tant qu'administrateur")
¶ Si tu obtiens le message "Voulez-vous autoriser le programme suivant..."Tu réponds Oui"
¶ Clique sur le bouton "IMPORTER"
¶ Les lignes se collent automatiquement dans ZHPFix, sinon colle les lignes

Clique sur le bouton « GO » pour lancer le nettoyage
¶ A la demande, confirme le nettoyage des données en cliquant sur [OK]
¶ Patiente le temps du traitement.
¶ ZHPFix va te demander si tu souhaites vider ta corbeille, clique sur oui (le traitement peut être long suivant la quantité de données à supprimer)
¶ Un rapport nommé ZHPFixReport.txt sera créé et sauvegardé sur le bureau

Fais redémarrer le PC
¶ Copie/colle la totalité du rapport dans ta prochaine réponse
Pour t'aider

1
kaori64 Messages postés 75 Date d'inscription lundi 21 juillet 2008 Statut Membre Dernière intervention 29 décembre 2015
17 déc. 2013 à 14:35
Pour info l'ordi est un Pc Windows 7
0
Marou81 Messages postés 4175 Date d'inscription mercredi 13 janvier 2010 Statut Membre Dernière intervention 18 mars 2014 198
17 déc. 2013 à 17:41
Bonjour,


Bienvenue sur CCM !
Nous allons essayer de régler ton problème ensemble. D'abord, quelques rappels :

▶ N'ouvre pas d'autres sujets pour le même problème (que ce soit sur ce forum ou sur un autre)
▶ N'hésite pas à poser des questions en cas de besoin ;)
▶ Sois patient(e) quand tu postes un message, je ne réponds pas instantanément : je suis bénévole et je ne suis pas en permanence devant mon ordinateur. Mais rassure toi, je ne laisse jamais tomber personne ;)
▶ La désinfection (si nécessaire) va se dérouler en plusieurs étapes. Même si les symptômes de l'infection disparaissent, la désinfection ne sera terminée que quand je te le confirmerai --> Merci de revenir jusqu'au bout, sinon ce qu'on a fait n'aura servi à rien.


Commence par utiliser ce logiciel de diagnostic, ça me permettra de t'aider :

▶ Télécharge ZHPDiag (de Nicolas Coolman)
▶ Lance le (si tu es sous Windows Vista ou Windows 7, fais le par un clic-droit --> Exécuter en temps qu'administrateur)
▶ Laisse toi guider lors de l'installation (pense à cocher la case pour créer un raccourci sur le Bureau). Il se lancera automatiquement à la fin de l'installation.
▶ Vérifie si tu trouves une icône "UAC" en haut à droite de ZHPDiag : si c'est le cas clique dessus, sinon passe à l'étape suivante.
▶ Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
▶ Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
▶ Rends toi sur ce site, clique sur "Parcourir", sélectionne le rapport de ZHPDiag et clique sur Envoyer le fichier. Patiente pendant l'envoi du fichier, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum.
0
kaori64 Messages postés 75 Date d'inscription lundi 21 juillet 2008 Statut Membre Dernière intervention 29 décembre 2015
17 déc. 2013 à 19:43
mille merci pour ton aide
voila le rapport
j'ai fais un copier coller et ensuite j'ai envoyé car en faisant parcourir il ne me le prenais pas
voici le lien donné après l'envoie
https://pjjoint.malekal.com/files.php?id=ZHPDiag_20131217_l15w11y10z13b7
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Marou81 Messages postés 4175 Date d'inscription mercredi 13 janvier 2010 Statut Membre Dernière intervention 18 mars 2014 198
17 déc. 2013 à 19:47
Bonsoir,

Beaucoup de choses à retirer à ce que je vois.

Utilise cet outil de désinfection spécifique aux logiciels publicitaires :

▶ Télécharge AdwCleaner (de Xplode) sur ton Bureau.
▶ Lance le, clique sur Suppression puis patiente le temps du scan.
▶ Une fois la suppression terminée, un message de prévention va s'afficher, je te conseille de le lire attentivement (n'hésite pas à me poser des questions si tu n'as pas compris certaines choses dans ce message).
▶ Ensuite, le rapport s'ouvrira : poste le dans ta prochaine réponse.

Puis utilise JRT : http://www.bleepingcomputer.com/download/junkware-removal-tool
Lance le programme puis appuie sur une touche.
Laisse l'outil travailler et envoie moi rapport.

Enfin Utilise ce logiciel de désinfection généraliste :

▶ Télécharge et installe Malwarebytes' Anti-Malware
▶ A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée. Par contre, il n'est pas nécessaire d'activer l'essai gratuit pour la protection.
▶ Lance MBAM et laisse les Mises à jour se télécharger (sinon fais les manuellement au lancement du programme)
▶ Puis va dans l'onglet "Recherche", coche "Exécuter un examen complet" puis "Rechercher"
▶ Sélectionne tes disques durs puis clique sur "Lancer l'examen"
▶ A la fin de l'analyse, clique sur Afficher les résultats
▶ Coche tous les éléments détectés puis clique sur Supprimer la sélection
▶ S'il t'est demandé de redémarrer l'ordinateur, accepte.
▶ Poste dans ta prochaine réponse le rapport apparaissant après la suppression.

Reposte à nouveau un rapport ZHPDiag quand tout sera fait. A+
0
kaori64 Messages postés 75 Date d'inscription lundi 21 juillet 2008 Statut Membre Dernière intervention 29 décembre 2015
17 déc. 2013 à 19:58
bonsoir Marou81
j'ai bien lu le message mais c'est mon beau fils de 13 ans qui est fan de jeux de guerre et qui utilise mon ordi pour télécharger des jeux ou jouer en ligne qui devrait le lire!!!lol
voila le premier rapport
# AdwCleaner v3.015 - Rapport créé le 17/12/2013 à 19:51:30
# Mis à jour le 10/12/2013 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : OLIVIER - OLIVIER-PC
# Exécuté depuis : C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CR7JDI66\adwcleaner.exe
# Option : Nettoyer

***** [ Services ] *****


***** [ Fichiers / Dossiers ] *****

Dossier Supprimé : C:\ProgramData\Babylon
Dossier Supprimé : C:\ProgramData\BonanzaDealsLive
Dossier Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
Dossier Supprimé : C:\Program Files (x86)\BonanzaDeals
Dossier Supprimé : C:\Program Files (x86)\BonanzaDealsLive
Dossier Supprimé : C:\Program Files (x86)\Conduit
Dossier Supprimé : C:\Program Files (x86)\myfree codec
Dossier Supprimé : C:\Program Files (x86)\MyPC Backup
Dossier Supprimé : C:\Program Files (x86)\PC Speed Maximizer
Dossier Supprimé : C:\Program Files (x86)\Vuze_Remote
Dossier Supprimé : C:\Program Files (x86)\Vuze
Dossier Supprimé : C:\Users\OLIVIER\AppData\Local\BonanzaDealsLive
Dossier Supprimé : C:\Users\OLIVIER\AppData\Local\PackageAware
Dossier Supprimé : C:\Users\OLIVIER\AppData\Local\torch
Dossier Supprimé : C:\Users\OLIVIER\AppData\LocalLow\Conduit
Dossier Supprimé : C:\Users\OLIVIER\AppData\LocalLow\Delta
Dossier Supprimé : C:\Users\OLIVIER\AppData\LocalLow\Vuze_Remote
Dossier Supprimé : C:\Users\OLIVIER\AppData\Roaming\BabSolution
Dossier Supprimé : C:\Users\OLIVIER\AppData\Roaming\Babylon
Dossier Supprimé : C:\Users\OLIVIER\AppData\Roaming\file scout
Dossier Supprimé : C:\Users\OLIVIER\AppData\Roaming\Mysearchdial
Dossier Supprimé : C:\Users\OLIVIER\AppData\Roaming\Systweak
Dossier Supprimé : C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
Dossier Supprimé : C:\Users\OLIVIER\Documents\PC Speed Maximizer
Fichier Supprimé : C:\Windows\System32\roboot64.exe
Fichier Supprimé : C:\Users\OLIVIER\AppData\Local\mysearchdial-speeddial.crx
Fichier Supprimé : C:\Users\OLIVIER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pflphaooapbgpeakohlggbpidpppgdff_0.localstorage
Fichier Supprimé : C:\Windows\Tasks\MySearchDial.job
Fichier Supprimé : C:\Windows\System32\Tasks\MySearchDial

***** [ Raccourcis ] *****


***** [ Registre ] *****

Clé Supprimée : HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Clé Supprimée : HKCU\Software\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Clé Supprimée : HKLM\SOFTWARE\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Clé Supprimée : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Valeur Supprimée : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Valeur Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Clé Supprimée : HKLM\SOFTWARE\Classes\*\shell\filescout
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\DiscoveryHelper.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\GIFAnimator.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\IMTrProgress.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\IMWeb.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\WMHelper.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\BrowserConnection.Loader
Clé Supprimée : HKLM\SOFTWARE\Classes\BrowserConnection.Loader.1
Clé Supprimée : HKLM\SOFTWARE\Classes\DiscoveryHelper.iMesh6Discovery
Clé Supprimée : HKLM\SOFTWARE\Classes\DiscoveryHelper.iMesh6Discovery.1
Clé Supprimée : HKLM\SOFTWARE\Classes\imweb.imwebcontrol
Clé Supprimée : HKLM\SOFTWARE\Classes\Prod.cap
Clé Supprimée : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Clé Supprimée : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\updateBatBrowse_RASAPI32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\updateBatBrowse_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BonanzaDealsLive.exe
Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [DataMngr]
Clé Supprimée : HKCU\Software\808cdebc3eec49
Clé Supprimée : HKLM\SOFTWARE\808cdebc3eec49
Clé Supprimée : HKLM\SOFTWARE\Classes\Toolbar.CT2504091
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{1FC41815-FA4C-4F8B-B143-2C045C8EA2FC}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{21493C1F-D071-496A-9C27-450578888291}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{403A885F-CB00-40C1-BDC1-EB09053194F7}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{55C1727F-5535-4C2A-9601-8C2458608B48}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{756C097C-6BDB-45DE-A8F1-83E01AB86BA4}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{A7DDCBDE-5C86-415C-8A37-763AE183E7E4}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{2656B92B-0207-4AFB-BEBF-F5FD231ECD39}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{27BF8F8D-58B8-D41C-F913-B7EEB57EF6F6}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{34CB0620-E343-4772-BBA8-D3074BC47516}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{3BF72F68-72D8-461D-A884-329D936C5581}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{412CD209-DDA4-4275-8C79-55F1C93FBD47}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{59570C1F-B692-48C9-91B4-7809E6945287}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{63A0F7FA-2C95-4D7E-AF25-EFCC303D20A1}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{6559E502-6EE1-46B8-A83C-F3A45BDA23EE}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{78E9D883-93CD-4072-BEF3-38EE581E2839}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{83AC1413-FCE4-4A46-9DD5-4F31F306E71F}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{A2858A72-758F-4486-B6A1-7F1DCC0924FA}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{B6F8DA9F-2696-419E-A8A3-19BE41EF51BD}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{B939CF93-F2CB-443D-956C-DC523D85C9DB}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{BA14329E-9550-4989-B3F2-9732E92D17CC}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{C63CA8A4-AB4E-49E5-A6C0-33FC86D80205}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{C6A7847E-8931-4A9A-B4EF-72A91E3CCF4D}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{DD0F1D24-E250-4E93-966C-65615720AEFB}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{EC1277BB-1C71-4C0D-BA6D-BFEA16E773A6}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{30344103-727C-4AB4-A467-7768A3F0C5BF}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{5E8CD073-21DF-4117-9BBD-D03C45D36CAE}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{B37B4BA6-334E-72C1-B57E-6AFE8F8A5AF3}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{B77AD4AC-C1C2-B293-7737-71E13A11FFEA}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{CA1CE38C-F04C-471F-B9F3-083C58165C10}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{E773F2CF-5E6E-FF2B-81A1-AC581A26B2B2}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{252C2315-CCE0-4446-8DA7-C00292A690BA}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{403A885F-CB00-40C1-BDC1-EB09053194F7}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{55C1727F-5535-4C2A-9601-8C2458608B48}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{96F7FABC-5789-EFA4-B6ED-1272F4C1D27B}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{C4C4F1F4-3074-4CB6-9FB8-0A64273166F0}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B939CF93-F2CB-443D-956C-DC523D85C9DB}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA14329E-9550-4989-B3F2-9732E92D17CC}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B939CF93-F2CB-443D-956C-DC523D85C9DB}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA14329E-9550-4989-B3F2-9732E92D17CC}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30344103-727C-4AB4-A467-7768A3F0C5BF}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B939CF93-F2CB-443D-956C-DC523D85C9DB}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA14329E-9550-4989-B3F2-9732E92D17CC}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424C-BB9F-74C6899B9F92}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B6F8DA9F-2696-419E-A8A3-19BE41EF51BD}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{30344103-727C-4AB4-A467-7768A3F0C5BF}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\59a3bad5-456d-4cad-a01c-436f72a7eda2
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}
Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
Valeur Supprimée : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
Valeur Supprimée : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\CLSID\{B939CF93-F2CB-443D-956C-DC523D85C9DB}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{5E8CD073-21DF-4117-9BBD-D03C45D36CAE}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{88CCA982-C030-4B27-8FBC-201189970FDE}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{B37B4BA6-334E-72C1-B57E-6AFE8F8A5AF3}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{B77AD4AC-C1C2-B293-7737-71E13A11FFEA}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{CA1CE38C-F04C-471F-B9F3-083C58165C10}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{E773F2CF-5E6E-FF2B-81A1-AC581A26B2B2}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B939CF93-F2CB-443D-956C-DC523D85C9DB}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}
Clé Supprimée : HKCU\Software\APN DTX
Clé Supprimée : HKCU\Software\BabSolution
Clé Supprimée : HKCU\Software\BabylonToolbar
Clé Supprimée : HKCU\Software\BonanzaDealsLive
Clé Supprimée : HKCU\Software\Conduit
Clé Supprimée : HKCU\Software\DataMngr
[#] Clé Supprimée : HKCU\Software\DataMngr_Toolbar
Clé Supprimée : HKCU\Software\filescout
Clé Supprimée : HKCU\Software\InstallCore
Clé Supprimée : HKCU\Software\Myfree Codec
Clé Supprimée : HKCU\Software\Softonic
Clé Supprimée : HKCU\Software\torch
Clé Supprimée : HKCU\Software\Vittalia
Clé Supprimée : HKCU\Software\YahooPartnerToolbar
Clé Supprimée : HKCU\Software\AppDataLow\Toolbar
Clé Supprimée : HKCU\Software\AppDataLow\Software\Conduit
Clé Supprimée : HKCU\Software\AppDataLow\Software\Vuze_Remote
Clé Supprimée : HKLM\Software\Babylon
Clé Supprimée : HKLM\Software\BonanzaDealsLive
Clé Supprimée : HKLM\Software\Conduit
Clé Supprimée : HKLM\Software\DataMngr
Clé Supprimée : HKLM\Software\Myfree Codec
Clé Supprimée : HKLM\Software\systweak
Clé Supprimée : HKLM\Software\torch
Clé Supprimée : HKLM\Software\Vuze_Remote
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Results Toolbar
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Vuze_Remote Toolbar
Clé Supprimée : [x64] HKLM\SOFTWARE\DataMngr
Donnée Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\BEARSH~1\Mediabar\Datamngr\x64\datamngr.dll
Donnée Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\BEARSH~1\Mediabar\Datamngr\x64\IEBHO.dll

***** [ Navigateurs ] *****

-\\ Internet Explorer v10.0.9200.16736

Paramètre Restauré : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Paramètre Restauré : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
Paramètre Restauré : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

*************************

AdwCleaner[R0].txt - [18475 octets] - [17/12/2013 19:49:07]
AdwCleaner[S0].txt - [15841 octets] - [17/12/2013 19:51:30]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [15902 octets] ##########
0
Marou81 Messages postés 4175 Date d'inscription mercredi 13 janvier 2010 Statut Membre Dernière intervention 18 mars 2014 198
18 déc. 2013 à 01:33
Bonsoir,

Me manque le rapport avec Junk Removal Tool (JRT) et le rapport MalwareBytes.

Merci de me les poster.

Bonne soirée
0
kaori64 Messages postés 75 Date d'inscription lundi 21 juillet 2008 Statut Membre Dernière intervention 29 décembre 2015
18 déc. 2013 à 06:32
Marou81 bonjour
En faite lorsque j'ai voulu télécharger JRT j'ai télécharger carrément autre autre chose et je me suis retrouvé avec des tas de " merde" veuillez m'excuser du langage mais je commence à saturer contre l'informatique et pourtant je sais " en général " déjouer les pièges !
Bref j'ai du tout enlever et nettoyer je fais des ce matin le JRT en espérant télécharger le bon logiciel! Et je vous envoie le Rapport. Merci pour votre patience! Et veuillez m'excuser :(
0
kaori64 Messages postés 75 Date d'inscription lundi 21 juillet 2008 Statut Membre Dernière intervention 29 décembre 2015
18 déc. 2013 à 07:40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by OLIVIER on 18/12/2013 at 7:05:03,53
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services

Successfully stopped: [Service] isafekrnl
Successfully deleted: [Service] isafekrnl
Successfully stopped: [Service] isafeservice
Successfully deleted: [Service] isafeservice



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{6e47d688-85ec-465a-9946-ec58220f14fc}



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\dynconie
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2412809502-3528070081-3099643911-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\isafe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\torchsetupfull_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\torchsetupfull_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6e47d688-85ec-465a-9946-ec58220f14fc}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{6e47d688-85ec-465a-9946-ec58220f14fc}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6e47d688-85ec-465a-9946-ec58220f14fc}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Users\OLIVIER\AppData\Roaming\isafe"
Successfully deleted: [Folder] "C:\Users\OLIVIER\appdata\locallow\datamngr"
Failed to delete: [Folder] "C:\Program Files (x86)\bearshare applications"
Failed to delete: [Folder] "C:\Program Files (x86)\isafe"
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{0058B1A3-F594-4C57-94D6-143FE51CF1C1}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{01CDD472-7A47-400A-B6FE-29049C01BE68}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{0207A8A0-05DA-4C10-9593-1571F20A9F7D}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{0297132A-3D58-4603-B9A9-625C52BA7BED}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{02B68318-0D08-4028-9932-7DFCE3DEE88D}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{02C82B0C-04B0-45AF-82C7-CB78F850E7C0}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{03A5549D-C628-4130-860A-7DB28F2E10C2}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{03DC4935-758D-4C1A-8536-83B66ACA88DF}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{0705B025-C63B-4D5F-BCD8-2DF730A52D3E}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{07189563-F059-4A75-80FC-554C46A512B0}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{0AF75C85-B1E0-49B7-8720-013C4DA53F9F}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{0C1074F8-6538-43FB-92EC-4EE9D4A671AB}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{0E723C47-EE18-4121-92EE-DF6DAD690F0A}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{1066E753-8868-47FF-823B-B383C122C8C8}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{10BCA8F4-81B4-4A57-BB28-AB2C334C41CD}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{111FBE43-1CC8-4F9C-B397-9304EC244A4F}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{123050BC-98E2-44FB-BC2F-6C1E7125D86A}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{12AF8CB2-AA43-4965-9C44-A5DEE5F962DE}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{136E6889-3C0B-4E27-8766-4B8440ECA51E}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{15509689-D4B1-4591-847B-AFC9E7F62C7B}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{163EEB0A-1315-410D-AAB7-507E19C2D055}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{17D8463C-01E3-4A87-B676-9D14DFE97A66}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{198CAF62-A428-4DD0-912D-441D2FFB5099}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{1A9936AC-67BD-4E0D-BAEB-653D15DE3426}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{1CF26AB5-E1B9-4000-AF38-DAF27F878A96}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{1D5A14FF-2982-45C4-97EF-5669E59C6CE7}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{1D5BD3DB-3000-4E01-BB95-E23E250887C7}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{1E020E3F-246C-46F3-B420-3B4D2FEA8835}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{1E1EBC32-2DA1-46EE-80A2-2E733A45E25F}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{1ED6CF36-4438-47BD-8BBF-C48A4A3D62B0}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{1EE0AE78-3A57-40C5-85D1-860EAAB98D55}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{20242948-D90F-4A27-B2C7-0ABE1EB0995F}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{210D770E-87EC-44AD-8C64-3D236A4A5CDC}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{23769E46-8E73-4DF4-9D65-89CD23EFFF29}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{23F8881E-9ED6-4CB8-ADB4-53C47ACBCFE2}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{241EB2FD-F315-496E-B26A-71EB69FD1AC3}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{281C0D8F-6FF1-43F3-B637-517E4828A300}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{28E5516E-E2E4-41AC-B59C-D9B1EECA185C}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{2983579B-9F9C-4056-B931-53C6A1DA4A82}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{2AB7D144-8A4B-4692-802D-80B6369B9C04}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{2F8FF237-3DD4-4B84-B04F-1F2992498654}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{306D6654-5604-4949-A894-403B648A6BB4}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{31190C30-5FAE-4F61-855E-E88BC6556946}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{3123D36D-B933-4BD6-9FE2-BAE06CB6B21D}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{32CB87B0-BDC3-4D04-ACDF-8FE704779634}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{32D382CA-CCFB-44B7-B5C2-71757ABFD32F}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{330863B5-BA4F-466F-8521-78CFB3ADCF0F}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{3319E9F7-D09C-4173-B35C-3F4148EE8610}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{35D0D3E1-7F1A-44D4-9D96-A9F5A4C765E5}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{37936DFB-F156-4B74-B121-04B521D3DC41}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{3E07A18A-BF7F-4113-B202-1515174D75EE}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{3EECB20C-D317-4112-8626-A68C6DC9A3C8}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{3F145E59-B02E-4880-9928-56AD0FBE59DE}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{3F27BFCF-0855-4809-AFF4-B94D69BFF969}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{408337F5-34F1-434E-B45C-7A361C78BD05}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{437108FF-E97F-466A-830B-F607C3218581}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{443974AB-4EB9-45A0-B530-C5BDE5D75E60}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{49C6F347-BCD5-4C48-9E5E-1C93E710397F}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{4B24997F-E506-4128-ABD6-0CCF05880411}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{4B97F8D1-AE3D-4785-8098-7BB4E86E86BA}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{4C781FA4-833A-49F5-A7D2-F02422B5F439}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{4D0D87C2-3D65-49E6-BDA5-D5767F817CD2}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{4D1A4EB5-0683-45A5-A539-294807E9C832}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{51E07EB8-57C1-43F3-A84C-9E70AB814D93}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{562E689F-3511-4653-B1DA-C3DF11116670}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{57AC5F5E-5B86-48DA-8865-FE2D26C58B79}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{58CAF411-B79D-4DC5-86AE-94A069933D58}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{5D38FC87-0C53-435E-8D53-90865BDB5939}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{5DC6413F-C017-4973-A4DC-9678248CBF54}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{5DC8EC76-8C17-47AB-A79D-E7E5204DE890}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{5E2948E8-4124-4589-A299-E35CC51B039E}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{606A36C9-105A-4238-866A-67131509246A}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{60F289B5-7881-42DF-8299-50301068A4EB}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{638E901E-5D48-4D1B-97C4-6E6B6065F4C6}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{65448391-C710-4B1F-B9AD-2170E88E90BA}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{65DAD74F-B258-464E-8298-4CB9D291BD1A}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{66FC14B4-5996-42ED-BBFB-5CF9D8D49587}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{671A742A-014D-4BE3-BCC5-597B7FD725CC}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{679E033D-C420-455D-ACA7-23A81CB4B2CC}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{684B6E14-7326-4324-8388-B021E3483B33}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{69C86ABA-3DA8-4F82-B1AD-663B78DDC67E}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{6CE4A776-D84D-428C-A687-DB7E20291FAF}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{6D14115B-D598-4863-AC80-14A59D43F78F}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{6D4CC943-7F5F-4807-8228-A0D5FCBCDC72}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{6D5C69B6-EF3D-48B7-B638-E4FFC935B7C1}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{6D77F145-C187-4D01-9DB4-3CFF83361089}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{71EECE90-A894-4F68-8EEF-3AFBC435ED11}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{72392D03-FF9C-4012-A682-060CDFE29655}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{74326333-5991-482F-B31F-7C43BCC5F297}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{74555D24-3102-4D46-8F6E-A0D4E646C604}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{751626DD-BC76-4F8A-B10C-3137C76CF8AE}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{75BD731D-FE67-4C7E-85AB-DC2953FE919E}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{76312901-DCCA-4E25-878E-31323AB8ACE7}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{7668C3CB-7CB1-466C-ACE4-006F78500E06}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{78070E88-9BC6-4D07-A5C5-FE32B7DEFBB7}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{78754D8F-0448-4979-ADFD-BFE04D984B25}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{795795A2-C66A-42A9-84C6-C44D7F72A629}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{7BC8DBC5-B7CD-41B6-826D-9DA8613B53B5}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{7C293018-8C9C-4452-AEA1-1CF8A17C615D}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{7D26107D-EDB0-43D3-A871-C9196397CF49}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{7DADD46F-0CAC-450C-965B-614E9B5C0A77}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{809B55B9-D94F-491B-80F0-3A7E0F8C8700}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{81D03BDD-E15B-4E68-BB3F-BE45357AFD09}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{824325AC-83D9-413B-906E-2E0B84795199}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{82EA5C87-DC32-41CC-BDDB-AB0B5B7CC4EC}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8342DB26-F26D-4A8C-A26E-0C5D4484705E}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8353D2C6-3DEA-4E99-A45A-9EE712C9302F}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{83B15D46-1EC9-4D98-86FA-FAF021E21611}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8411D530-235E-4E94-809F-E9F973C0C281}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{86F601F6-7B4F-4177-916F-AF6BBFC6CFDA}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{87D4BB53-F3D0-48C8-BD16-CEEA942F66FF}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{87EAEDA1-587A-45F4-923E-05D44BC8345B}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{880CB189-9F9F-4B3C-A1D6-373489F4F1B1}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8839FF8B-D19D-4AE6-AF7E-956F3C74CC48}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8A5CEB40-B527-45A7-96FE-EFF3E86939AA}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8A9D0E52-DEC4-405B-AF44-8C3BEC44CDB0}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8AEC7EDF-635A-4A26-A57F-D8C8BD8EB210}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8AF12AB8-37D1-49C0-BE47-8646049B6D3B}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8B642A4C-0A98-4934-A0D1-C538BEAA6406}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8BDB6FF4-CA10-42E3-85BD-6C61947DE011}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8C3F4EC4-46AB-41FA-9B08-00663A021F83}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8EFA0A92-7CEF-4C8D-BD12-9FE70CD4937A}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8F3602A0-5A02-4E14-ACE9-6DE04CB660D1}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8F76D905-05B3-499C-86A4-84A3DAF4FDB9}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8F86564E-504E-4D5D-84B6-760DBF5306D2}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{8FB04277-98EB-41CC-B186-DF352FD522FE}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{93BDF7DC-CAE0-476A-8A84-33274C7946E0}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{950560E8-FBD3-4434-BAD9-390BBE4CCAE4}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{95C2CAA3-EDE1-41B4-90DE-2DF567B9533E}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{98782DBB-9D76-4679-B621-F32D0DD77463}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{9B11DF95-C76E-45E1-8ACA-DE5D55AFCDD5}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{9C531D47-D497-44D8-923C-372930BB9A53}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{9D063625-961F-4743-9278-53F5F293E280}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{9D92E8C1-8A08-41D4-AF9D-2FD5ACF10530}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{9D99F9B9-3845-45EE-B62B-643B3564D83E}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{9DE32DCA-BD38-476C-B7C8-202B16F28BF4}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{9FDF43B1-800E-45C8-9575-79A483806881}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{9FE60003-DCE1-4679-8ED7-34B7E23EEC65}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{9FEF0B37-FCEA-43FC-BC76-44AD0D5D79C2}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{A1928696-D9C1-4E9F-A57C-FECF256E36B4}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{A3789602-2DEC-4F61-AFD4-C971EE538A2D}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{A4689C3A-B9EA-41CA-90C2-748CD7D11A72}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{A574197A-4E8D-424D-923C-8DC67D59E9D3}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{A5ACD419-3293-45D0-AF18-808582A8011E}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{A674D5FE-8D9B-4D35-A224-D25E22F6BE51}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{A7C8ABFF-1784-4E26-8CB7-2B5340C92B52}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{A8FC80D4-4E48-4A0A-BB1C-78894BD38375}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{A952F8F5-1A67-4536-BED0-80D3429FB4AF}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{A9E3D3BD-31B7-468C-ABE3-5EACF5BA455B}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{A9E78E23-92F2-4A01-BDD0-160D913C2BD9}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{AA424CB1-489A-439E-80E1-2E39C54116B3}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{ABE8A411-6759-4A21-A83A-20BF5DA417B7}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{AC14B497-4129-44C6-AE0F-30553BEAFA4D}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{AC4A9CBF-B2C6-4F27-820F-F4C2286A3147}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{AC9980A7-F5C3-465E-BAA3-92710CF78CED}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{ACB4A839-36F5-434B-A5A6-AEC1029B048D}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{AE6DA00A-1125-4F66-ADB5-385D4C6CAD8F}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{AF325606-5A5C-4A63-AD79-E96C2BB7E464}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{B06C77AB-6B31-4BB5-84FF-E5DEB7DD5336}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{B0CF44E9-1053-434D-90CE-E60A55F5374F}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{B2D2F396-6060-4769-A932-466B9F04D3DF}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{B3EF4ED6-F657-4619-BE4D-DC7615140543}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{B48B6A40-516B-40C6-8BA7-A30D4BC67805}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{B49361C5-14AE-4ABB-998A-77B1E973036B}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{B5B1D254-9401-41C6-A59D-B9E2F626DF2B}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{B606DEE0-56B3-4E59-BC80-01E739B3B940}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{B60854D3-E7C3-4288-A84F-7F5C15073539}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{B7A0D26D-C21C-4913-9AD1-48EA8B522CCD}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{B81828FF-F7D9-477D-A8F7-F67B1238B20F}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{B8AB4EDD-FA00-4770-83E4-D1AD310567B3}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{B97A7853-E5C5-4D1C-A009-51C3D9946D2C}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{BB80BDB9-E752-4D1B-9AFD-507E5A33B353}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{BD1EE274-FB88-4C2E-9213-E1876B8AC655}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{BF069B5F-795D-40C1-913B-14F9DBF96AAB}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{C08F11FD-5D61-4683-91DA-08394DB72CD8}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{C3483449-E80B-4A47-BF1D-9587B1EE44EF}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{C4AD6B9E-4FF7-4166-AB2E-8EFF61E18054}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{C513059A-DE0A-498C-92EF-0129ABEE0EF2}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{C53928A9-E17D-4376-9A2D-9EA7C4ECE436}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{C65273A8-D277-42E9-BCED-33D0CF6BED4B}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{C9C69FDD-F5A0-455F-B559-20BE3CF732E2}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{C9F6BBE9-32CE-4192-9AE2-846896F503EA}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{CB855B1B-9651-4E22-A422-92F32F75AF59}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{CD97444C-3A88-4CC3-8DF2-35F0C5137F33}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{CE5A5D54-9418-4366-9CBD-AECADAC63C1D}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{CEFCBC65-2389-4B45-94C5-6AF39B9CBFE2}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{CFBFD4E6-8175-48E9-B87D-EA64A8896EAB}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{D0303C0A-ED7A-4226-BDE8-DC924FB41CA7}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{D0DC0F72-9E4F-490A-9E23-ECFB2F6BF0B2}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{D24290BB-A7FE-419C-A56F-FDED155A9904}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{D2DD3ADD-5B38-4056-AE75-97E774214A5A}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{D2E3A063-C1B0-4E61-89E7-F78EBDB08D2B}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{D3C07AF0-E964-478E-9CCE-C4E53F7A82DC}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{D516E4DA-A204-4BB3-A07E-968BA567CBF0}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{D7EA5167-AA9E-4E03-9365-8761BA52BD43}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{DB0D6333-6396-4361-984B-634BA2EA6F9A}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{DB17E3BB-20CE-49BE-801B-D0DAEF99C783}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{DCFC335E-43EF-42E3-8D64-FAC3667AA0AD}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{DD54B1A8-3A06-4B73-80F2-856EA981812B}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{DDA445E2-4237-44C9-9762-E824DB02A248}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{DE510CE0-9300-421B-AF33-414E103E3B6F}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{DEAB7590-5206-4659-9C3B-69A0FDDA51D0}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{DF2A3C11-0470-485C-88C8-915508B775E4}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{DFE1FBF8-9B0E-451B-89E6-4CE18ED487D8}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{E0382C7F-BF24-402A-BABD-067DEF05B731}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{E191D183-1CFE-4EB8-8EA8-094932EF5491}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{E2B1D8F8-0C51-48B7-9F2D-B3C2F7111D5F}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{E45AC75D-E9A1-490B-B8B1-48C74F3634EA}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{E5DF41E8-617A-4256-901D-5F441F7026DE}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{E690FAF7-A223-4C5B-9DCC-2A4A7594F0C7}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{E7459270-F7D2-4B42-B2A6-AB552BABB4C6}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{E8B923DE-44CC-4464-95D1-AB79508B3C23}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{EB96885F-433C-49D6-8A79-4D7E5E7196C3}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{EBADAB3E-97CE-413A-81C9-7A4AD7753BD6}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{EC1DBB43-844A-4AF5-B9DA-27FCDBE12FBF}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{ECDC5171-BD1C-49E4-9799-F937EB684789}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{F0638A9B-488F-4599-A207-87D5CFC4AAC7}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{F15154C1-23C2-45BF-9528-4F94ABC793BF}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{F4FA0E3A-2F9A-4516-97C5-28C8F917FBBA}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{F5BCAB2F-6BE0-4A96-A18A-046FE76333B0}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{F6B93B41-2C75-4C1B-A5FB-9F290423737D}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{F70E81C3-E356-4D01-8474-98BC9B4CA9C0}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{F7BAA201-C816-4668-B2A6-95B5AA37722B}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{F8216AFB-754C-4D4D-83B7-8B3A1D0C426A}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{F877A896-9232-42CC-A9D4-7815E2EDF060}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{F9E671D8-99AF-4887-A673-A7C76E66E979}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{FA008C7E-4D3A-44C0-96D1-3F1BCAFCEAF8}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{FB2313D9-3080-4364-8872-26DC2193BEAD}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{FC04F07D-3127-4EB7-A35D-4E3B2539C59C}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{FD2F390B-2ED7-46CC-8D7D-FF0B841D4E02}
Successfully deleted: [Empty Folder] C:\Users\OLIVIER\appdata\local\{FFF320DD-4103-4703-AF63-B0ECAA320B81}



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18/12/2013 at 7:26:00,41
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
0
kaori64 Messages postés 75 Date d'inscription lundi 21 juillet 2008 Statut Membre Dernière intervention 29 décembre 2015
18 déc. 2013 à 10:27
Malwarebytes Anti-Malware (Essai) 1.75.0.1300
www.malwarebytes.org

Version de la base de données: v2013.12.17.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16750
OLIVIER :: OLIVIER-PC [administrateur]

Protection: Activé

18/12/2013 07:43:22
mbam-log-2013-12-18 (07-43-22).txt

Type d'examen: Examen complet (C:\|D:\|E:\|)
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 407523
Temps écoulé: 1 heure(s), 35 minute(s), 20 seconde(s)

Processus mémoire détecté(s): 4
C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe (PUP.Optional.SearchDonkey.A) -> 4840 -> Suppression au redémarrage.
C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe (PUP.Optional.SearchDonkey.A) -> 4184 -> Suppression au redémarrage.
C:\ProgramData\RHelpers\IeHelper\IeHelper.exe (PUP.Optional.SearchDonkey.A) -> 4788 -> Suppression au redémarrage.
C:\ProgramData\Updater\updater.exe (Trojan.Agent) -> 2304 -> Suppression au redémarrage.

Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Clé(s) du Registre détectée(s): 3
HKCR\CLSID\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E} (PUP.Optional.BearshareTB.A) -> Mis en quarantaine et supprimé avec succès.
HKCR\BearShareIEHelper.DNSGuard (PUP.Optional.BearshareTB.A) -> Mis en quarantaine et supprimé avec succès.
HKCR\BearShareIEHelper.DNSGuard.1 (PUP.Optional.BearshareTB.A) -> Mis en quarantaine et supprimé avec succès.

Valeur(s) du Registre détectée(s): 2
HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Updater (Trojan.Agent) -> Données: C:\ProgramData\Updater\updater.exe -> Mis en quarantaine et supprimé avec succès.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Updater (Trojan.Agent) -> Données: C:\ProgramData\Updater\Updater.exe -> Mis en quarantaine et supprimé avec succès.

Elément(s) de données du Registre détecté(s): 3
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL (PUP.Optional.NationZoom.A) -> Mauvais: (http://ww7.nationzoom.com Bon: (http://www.google.com) -> Mis en quarantaine et réparé avec succès
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.NationZoom.A) -> Mauvais: (http://ww7.nationzoom.com Bon: (http://www.google.com) -> Mis en quarantaine et réparé avec succès
HKLM\Software\Microsoft\Internet Explorer\Main|Default_Page_URL (PUP.Optional.NationZoom.A) -> Mauvais: (http://ww7.nationzoom.com Bon: (http://www.google.com) -> Mis en quarantaine et réparé avec succès

Dossier(s) détecté(s): 8
C:\Users\OLIVIER\AppData\Local\Temp\mt_ffx\Delta (PUP.Optional.Delta.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\mt_ffx\Delta\delta (PUP.Optional.Delta.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\mt_ffx\Delta\delta\1.8.10.0 (PUP.Optional.Delta.A) -> Mis en quarantaine et supprimé avec succès.
C:\ProgramData\RHelpers\ChromeHelper (PUP.Optional.Searchagent) -> Suppression au redémarrage.
C:\ProgramData\RHelpers\FirefoxHelper (PUP.Optional.Searchagent) -> Suppression au redémarrage.
C:\ProgramData\RHelpers\IeHelper (PUP.Optional.Searchagent) -> Suppression au redémarrage.
C:\Users\OLIVIER\AppData\Roaming\newnext.me (PUP.Optional.NextLive.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Roaming\newnext.me\cache (PUP.Optional.NextLive.A) -> Mis en quarantaine et supprimé avec succès.

Fichier(s) détecté(s): 59
C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe (PUP.Optional.SearchDonkey.A) -> Suppression au redémarrage.
C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe (PUP.Optional.SearchDonkey.A) -> Suppression au redémarrage.
C:\ProgramData\RHelpers\IeHelper\IeHelper.exe (PUP.Optional.SearchDonkey.A) -> Suppression au redémarrage.
C:\AdwCleaner\Quarantine\C\Users\OLIVIER\AppData\Roaming\BabSolution\Shared\BabMaint.exe.vir (PUP.Optional.Babylon.A) -> Mis en quarantaine et supprimé avec succès.
C:\AdwCleaner\Quarantine\C\Users\OLIVIER\AppData\Roaming\Desk 365\components\component_libcef_1.1364.1123.exe.vir (PUP.Optional.Desk365.A) -> Mis en quarantaine et supprimé avec succès.
C:\AdwCleaner\Quarantine\C\Users\OLIVIER\AppData\Roaming\file scout\filescout.exe.vir (PUP.Optional.FileScout.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E178JMJ1\wajam_download[1].exe (PUP.Optional.Wajam) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HXHQFFZM\vbmz10[1].exe (MSIL.Solimba) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LNF6QDY3\wajam_install[1].exe (PUP.Optional.Wajam) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\896A.tmp (PUP.Optional.FileScout.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\GetCC.dll (MSIL.Solimba) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\ICReinstall_FlvPlayerSetup.exe (PUP.Optional.InstallCore) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\UpdateTask.exe.1833167 (PUP.Optional.MySearchDial.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\vbmz10.exe (MSIL.Solimba) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\8F6D6840-BAB0-7891-AD81-29D330AB821E\CrxInstaller.dll (PUP.Optional.Babylon.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\8F6D6840-BAB0-7891-AD81-29D330AB821E\MyBabylonTB.exe (PUP.Optional.Delta) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus1358\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus152F\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus1CA9\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus2290\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus25CB\BUSolution.dll (PUP.Optional.BabSolution.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus2810\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus2FCB\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus3212\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus397E\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus5C75\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus5FCB\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus71F0\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus71F1\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus7721\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus7776\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus7F9E\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus8005\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus897\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\bus9F6D\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\busB4E5\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\busBB74\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\busBC8F\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\busD7A9\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\busDAE4\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\busE885\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\busEB07\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\busEF7\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\busEF87\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\busFD19\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\is1668783924\DeltaTB.exe (PUP.Optional.Delta.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\is609929163\104401586_stp.EXE (PUP.Optional.InstallCore) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\is609929163\91677065_stp.EXE (PUP.Optional.InstallCore) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\is609929163\91677275_stp\BatBrowseSetup.exe (PUP.Optional.BatBrowse.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\is609929163\91677289_stp\rcpsetup_adppi5_adppi5.exe (PUP.Optional.RegCleanerPro) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\is609929163\91677294_stp\bd.exe (PUP.Optional.BonanzaDeals.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Local\Temp\upd77A1\BabMaint.x (PUP.Optional.Babylon.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\Downloads\installer_samsung_kies_French.exe (PUP.Optional.InstallCore.A) -> Mis en quarantaine et supprimé avec succès.
C:\Windows\Temp\BonanzaDealsLive.exe3330de98 (PUP.Optional.BonanzaDeals.A) -> Mis en quarantaine et supprimé avec succès.
C:\Windows\Temp\goopdate.dll3330de98 (PUP.Optional.BonanzaDeals.A) -> Mis en quarantaine et supprimé avec succès.
C:\ProgramData\Updater\updater.exe (Trojan.Agent) -> Suppression au redémarrage.
C:\Users\OLIVIER\AppData\Roaming\newnext.me\nengine.cookie (PUP.Optional.NextLive.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Roaming\newnext.me\nengine.dll (PUP.Optional.NextLive.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\OLIVIER\AppData\Roaming\newnext.me\cache\spark.bin (PUP.Optional.NextLive.A) -> Mis en quarantaine et supprimé avec succès.

(fin)
0
kaori64 Messages postés 75 Date d'inscription lundi 21 juillet 2008 Statut Membre Dernière intervention 29 décembre 2015
18 déc. 2013 à 10:32
~ Rapport de ZHPDiag v2013.12.14.22 - Nicolas Coolman (14/12/2013)
~ Lancé par OLIVIER (18/12/2013 10:28:30)
~ Adresse du Site Web https://nicolascoolman.webs.com/
~ Forums gratuits d'Assistance à la désinfection : https://nicolascoolman.webs.com/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v10.0.9200.16750 (Defaut)
OBIE: Safari v5.33.21.1

---\\ Informations sur les produits Windows
~ Langage: Français
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 9YQTR
Windows License : OK
~ Windows Remaining Initializations Number : 3
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft Security Client v4.4.0304.0
Windows Defender W7

---\\ Logiciels d'optimisation du système

---\\ Logiciels de partage PeerToPeer
eMule
Vuze v4.3 =>P2P.Azureus

---\\ Surveillance de Logiciels
Adobe Flash Player 11 Plugin
Adobe Reader 9.5.5 MUI
Java 7 Update 45

---\\ Informations sur le système
~ Processor: Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 4061 MB (47% free)
System Restore: Activé (Enable)
System drive C: has 13 GB (17%) free of 75 GB

---\\ Mode de connexion au système
~ Computer Name: OLIVIER-PC
~ User Name: OLIVIER
~ All Users Names: OLIVIER, LogMeInRemoteUser, HomeGroupUser$, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\OLIVIER\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\OLIVIER\AppData\Roaming\
~ %Desktop% : C:\Users\OLIVIER\Desktop\
~ %Favorites% : C:\Users\OLIVIER\Favorites\
~ %LocalAppData% : C:\Users\OLIVIER\AppData\Local\
~ %StartMenu% : C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 13 Go of 75 Go)
D: Hard drive, Flash drive, Thumb drive (Free 209 Go of 209 Go)
E: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
~ Security Center: 49 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.E7099336BF7531B6FCC920DCB5101259] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.25/10/2013 - 07:19:22.) -- C:\Windows\System32\wininet.dll [2241536]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.20/11/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/09/2013 - 02:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 2/13
~ Mes musiques (My Musics) : 47/232
~ Mes Favoris (My Favorites) : 1/33
~ Mes Documents (My Documents) : 2/1880
~ Mon Bureau (My Desktop) : 3/220
~ Menu demarrer (Programs) : 1/43
~ Hidden Files: Scanned in 00mn 06s



---\\ Processus lancés
[MD5.1971D838A88F58D59543E9B3CDA5FFC4] - (.ASUS - SmartLogon Application.) -- C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [305720] [PID.1980]
[MD5.BA2B4E07561CF877F61B0EEED654BC96] - (...) -- C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe [53888] [PID.2028]
[MD5.F4DCD4912B185C3AAEB92A7040832AD1] - (.Pas de propriétaire - ALU.) -- C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [51768] [PID.2036]
[MD5.A65BE6B71BDD85BB0BBB0F25E03AE586] - (.Pas de propriétaire - Wireless Console 3.) -- C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1593344] [PID.2044]
[MD5.7D677B93A0CFA26C8A4029ABA71C2EA6] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe [20472992] [PID.2792]
[MD5.5AEBF6FA9805C9101220AA4FB4FA17E7] - (.ASUS - HControlUser.) -- C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [105016] [PID.2920]
[MD5.EBA7FEB924D04E718870B6E1E07D2465] - (.ASUS - ATKOSD2.) -- C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [8493624] [PID.2980]
[MD5.29B129E019D5935C55541629677C2A69] - (.ASUS - ATK Media.) -- C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [159744] [PID.3000]
[MD5.D1D5DAB39DCB4BE0359943738D87409B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [532040] [PID.1660]
[MD5.F4F7C86191A981C804326E2EF6F3604F] - (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [41056] [PID.1920]
[MD5.53D96678FB89F056D5285101481297D9] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [421160] [PID.2384]
[MD5.D3AC38E80E928CC61A22650E04423BB8] - (.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [979328] [PID.1068]
[MD5.5B6E8E09BE6401A7E022F52FDFCB2FF8] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336] [PID.868]
[MD5.3ECCDD3FE310DD8F82D085447089ADB0] - (.ASUSTek Computer Inc. - ADSMTray.) -- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [272952] [PID.368]
[MD5.5C396DDE6AAFFB64ABC0E0FD88F53553] - (.ASUS - AsScrPro.) -- C:\Windows\AsScrPro.exe [3054136] [PID.2780]
[MD5.74EF10CD035DE51171C98E60E53AE221] - (.CyberLink - CyberLink MediaLibray Service.) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [104936] [PID.3100]
[MD5.83170B8E03213093B065A9638E146499] - (.OpenOffice.org - OpenOffice.org 3.1.) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe [7424000] [PID.3144]
[MD5.873867A02F0E83F18CF871E776B651DC] - (.OpenOffice.org - OpenOffice.org 3.1.) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin [7418368] [PID.3716]
[MD5.9ED469260687108F5F8FD544D56ABC54] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\IEXPLORE.exe [770736] [PID.4876]
[MD5.2330B5A4A3824F042DC96D524893A6B5] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8295936] [PID.7124]
[MD5.D7F82B30ED318E591E27C9C323846DD5] - (.ASUS - SmartLogon Application.) -- C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe [428600] [PID.1132]
[MD5.18E5C2F937F9DEB8C282DF66A3761925] - (.ASUS - ASLDR Service.) -- C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe [84536] [PID.1172]
[MD5.7C157574A181B19B9DCF5F339E25337E] - (.Pas de propriétaire - GFNEXSrv.) -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208] [PID.1252]
[MD5.A434FB7C05F244E8E46C23F8075082ED] - (.ASUS - HControl.) -- C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe [178744] [PID.1680]
[MD5.D62088F1C4E7B3477AD2A5F8F5C6DEF3] - (.Pas de propriétaire - Atouch64.) -- C:\Program Files (x86)\ASUS\ATK Hotkey\Atouch64.exe [301624] [PID.1708]
[MD5.ABDD5AD016AFFD34AD40E944CE94BF59] - (.SEIKO EPSON CORPORATION - eEBAPI Core Process module.) -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe [94208] [PID.1896]
[MD5.B33CF4DE909A5B30F526D82053A63C8E] - (.ABBYY - ABBYY network license server.) -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048] [PID.1864]
[MD5.20F6F19FE9E753F2780DC2FA083AD597] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [37664] [PID.2112]
[MD5.F2060A34C8A75BC24A9222EB4F8C07BD] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe [349472] [PID.2308]
[MD5.65085456FD9A74D7F1A999520C299ECB] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376] [PID.2496]
[MD5.E0D7732F2D2E24B2DB3F67B6750295B8] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512] [PID.2584]
[MD5.11F714F85530A2BD134074DC30E99FCA] - (.Microsoft Corporation - Machine Debug Manager.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.exe [322120] [PID.2988]
[MD5.FD306FBCCE7ADB1077B709742E7148E9] - (...) -- C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe [71096] [PID.324]
[MD5.205E1B699FD3F2F9B036EEA2EC30C620] - (...) -- C:\Windows\SysWOW64\PnkBstrA.exe [76888] [PID.3492]
[MD5.149126216A694E6BA84E92ECA77AAE3B] - (.ASUS - ATKOSD.) -- C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe [2488888] [PID.4500]
[MD5.AA11E1368EEB237DD100BAC6AFFE1C57] - (.ASUS - KBFiltr.) -- C:\Program Files (x86)\ASUS\ATK Hotkey\KBFiltr.exe [113208] [PID.4924]
[MD5.4A7C441D99D86704D194E7678873B95D] - (.ASUS - WDC.) -- C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe [174648] [PID.4832]
[MD5.C0BF554D2277F7A4C735D475ADE2E3B2] - (.ASUSTek Computer Inc. - ADSMSrv.) -- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [225280] [PID.4644]
~ Processes Running: Scanned in 00mn 01s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ww7.nationzoom.com =>Hijacker.NationZoom
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ww7.nationzoom.com =>Hijacker.NationZoom
~ IE Browser: 24 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: (no name) [64Bits] - [HKLM]{9421DD08-935F-4701-A9CA-22DF90AC4EA6} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{21FA44EF-376D-4D53-9B0F-8A89D3229068} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: BearShare.lnk . (...) -- C:\Program Files (x86)\BearShare Applications\BearShare\BearShare.exe (.not file.) =>PUP.BearShare
O4 - GS\Desktop [Public]: Driver Detective.lnk . (.PC Drivers Headquarters - Driver Detective.) -- C:\Program Files (x86)\PC Drivers HeadQuarters\Driver Detective\DriversHQ.DriverDetective.Client.exe
O4 - GS\Desktop [Public]: eMule.lnk . (.https://www.emule-project.net/home/perl/general.cgi?l=1 - eMule.) -- C:\Program Files (x86)\eMule\emule.exe
O4 - GS\Desktop [Public]: Epson Easy Photo Print.lnk . (.SEIKO EPSON CORPORATION - Pas de description.) -- C:\Program Files (x86)\Epson Software\Easy Photo Print\EPQuicker.exe
O4 - GS\Desktop [Public]: EPSON Scan.lnk . (.SEIKO EPSON CORP. - EPSON Scan.) -- C:\Windows\twain_32\escndv\escndv.exe
O4 - GS\Desktop [Public]: Game Park Console.lnk . (.Oberon Media - Game Park Console.) -- C:\Program Files (x86)\ASUS\Game Park\GameConsole\GameParkConsole.exe
O4 - GS\Desktop [Public]: Guide d'utilisation EPSON SX235 Series.lnk . (...) -- C:\Program Files (x86)\Epson Software\Epson Manual\EPSON SX235 Series\fr\Useg\index.htm
O4 - GS\Desktop [Public]: Guide réseau EPSON SX235 Series.lnk . (...) -- C:\Program Files (x86)\Epson Software\Epson Manual\EPSON SX235 Series\fr\Netg\index.htm
O4 - GS\Desktop [Public]: Safari.lnk . (...) -- C:\Windows\Installer\{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}\SafariIco.exe
O4 - GS\Desktop [Public]: Vuze.lnk . (...) -- C:\Program Files (x86)\Vuze\Azureus.exe (.not file.) =>P2P.Azureus
O4 - GS\Desktop [Public]: YAC.lnk . (...) -- C:\Program Files (x86)\iSafe\iStart.exe (.not file.) =>Trojan.Staser
O4 - GS\Program [Public]: HD VDeck.lnk . (.VIA - VIA HD Audio CPL.) -- C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
O4 - GS\Program [Public]: Safari.lnk . (...) -- C:\Windows\Installer\{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}\SafariIco.exe
O4 - GS\Program [Public]: Vuze.lnk . (...) -- C:\Program Files (x86)\Vuze\Azureus.exe (.not file.) =>P2P.Azureus
O4 - GS\QuickLaunch [OLIVIER]: Apple Safari.lnk . (...) -- C:\Windows\Installer\{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}\SafariIco.exe
O4 - GS\QuickLaunch [OLIVIER]: BearShare.lnk . (...) -- C:\Program Files (x86)\BearShare Applications\BearShare\BearShare.exe (.not file.) =>PUP.BearShare
O4 - GS\QuickLaunch [OLIVIER]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch [OLIVIER]: MP Manager.lnk . (.MPMAN - MP Manager.) -- C:\Users\OLIVIER\AppData\Roaming\MPMAN\MP Manager\MP Manager.exe
O4 - GS\QuickLaunch [OLIVIER]: Vuze.lnk . (...) -- C:\Program Files (x86)\Vuze\Azureus.exe (.not file.) =>P2P.Azureus
O4 - GS\TaskBar [OLIVIER]: BearShare.lnk . (...) -- C:\Program Files (x86)\BearShare Applications\BearShare\BearShare.exe (.not file.) =>PUP.BearShare
O4 - GS\TaskBar [OLIVIER]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\TaskBar [OLIVIER]: LifeFrame.lnk . (.ASUS - LifeFrame3.) -- C:\Program Files (x86)\ASUS\ASUS LifeFrame3\LifeFrame.exe
O4 - GS\TaskBar [OLIVIER]: Safari.lnk . (.Apple Inc. - Safari.) -- C:\Program Files (x86)\Safari\Safari.exe
O4 - GS\Program [OLIVIER]: Create Amazing Presentations.lnk - Clé orpheline
O4 - GS\Program [OLIVIER]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\SystemTools [OLIVIER]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\Desktop [OLIVIER]: cpam marie.lnk . (...) -- C:\Users\OLIVIER\Desktop\justificatifs assedic\cpam marie
O4 - GS\Desktop [OLIVIER]: Create Amazing Presentations.lnk - Clé orpheline
O4 - GS\Desktop [OLIVIER]: Downloader.lnk . (.Metaboli - Metaboli Downloader.) -- C:\Program Files (x86)\Downloader\Downloader.exe
O4 - GS\Desktop [OLIVIER]: Kies Air Discovery Service.lnk . (.Oracle Corporation - Java(TM) Web Start Launcher.) -- C:\Windows\SysWOW64\javaws.exe
O4 - GS\Desktop [OLIVIER]: MP Manager.lnk . (.MPMAN - MP Manager.) -- C:\Users\OLIVIER\AppData\Roaming\MPMAN\MP Manager\MP Manager.exe
O4 - GS\Desktop [OLIVIER]: Sniper Elite.lnk . (...) -- C:\Program Files (x86)\Microids\Sniper Elite\SniperElite.exe
~ Global Startup: 104 Legitimates Filtered in 00mn 12s



---\\ Applications lancées au démarrage du sytème (O4)
O4 - GS\Startup [Public]: FancyStart daemon.lnk . (...) -- C:\Windows\Installer\{60D6618B-153F-4353-8185-908E676E5888}\_DCE9A4DB2A5F2786140FA3.exe
O4 - GS\Startup [OLIVIER]: OpenOffice.org 3.1.lnk . (...) -- C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O4 - HKLM\..\Run: [EeeStorageBackup] . (...) -- C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
O4 - HKLM\..\Run: [AmIcoSinglun64] . (.AlcorMicro Co., Ltd. - Single LUN Icon Utility for VID 058F PID 63.) -- C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
O4 - HKLM\..\Run: [ETDWare] . (.ELAN Microelectronic Corp. - ETD Control Center.) -- C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [LogMeIn GUI] . (.LogMeIn, Inc. - LogMeIn Desktop Application.) -- C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- C:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHLE.exe =>.Epson Seiko Corporation
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [UpdateLBPShortCut] . (.CyberLink Corp. - MUI StartMenu Application.) -- C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe
O4 - HKLM\..\Wow6432Node\Run: [UpdateP2GoShortCut] . (.CyberLink Corp. - MUI StartMenu Application.) -- C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe
O4 - HKLM\..\Wow6432Node\Run: [HDAudDeck] . (.VIA - VIA HD Audio CPL.) -- C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
O4 - HKLM\..\Wow6432Node\Run: [HControlUser] . (.ASUS - HControlUser.) -- C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Wow6432Node\Run: [ATKOSD2] . (.ASUS - ATKOSD2.) -- C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Wow6432Node\Run: [ATKMEDIA] . (.ASUS - ATK Media.) -- C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated
O4 - HKLM\..\Wow6432Node\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKLM\..\Wow6432Node\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files (x86)\QuickTime\QTTask.exe
O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
O4 - HKLM\..\Wow6432Node\Run: [EEventManager] . (.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle Corporation
O4 - HKLM\..\Wow6432Node\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe (.not file.)
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-2412809502-3528070081-3099643911-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-2412809502-3528070081-3099643911-1000\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHLE.exe =>.Epson Seiko Corporation
O4 - HKUS\S-1-5-21-2412809502-3528070081-3099643911-1000\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKUS\S-1-5-21-2412809502-3528070081-3099643911-1000\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (.not file.)
~ Application: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{38490F1A-161F-4C41-BC7A-7462AA63753E}: NameServer = 50.7.75.30,76.73.6.110
O17 - HKLM\System\CCS\Services\Tcpip\..\{3CF02565-8980-4BEE-A6D1-AFF689EC460D}: NameServer = 50.7.75.30,76.73.6.110
O17 - HKLM\System\CCS\Services\Tcpip\..\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 50.7.75.30,76.73.6.110
O17 - HKLM\System\CCS\Services\Tcpip\..\{C9B8F153-2557-44B7-B5F6-23D99EDF6144}: NameServer = 50.7.75.30,76.73.6.110
O17 - HKLM\System\CCS\Services\Tcpip\..\{38490F1A-161F-4C41-BC7A-7462AA63753E}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{3CF02565-8980-4BEE-A6D1-AFF689EC460D}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{38490F1A-161F-4C41-BC7A-7462AA63753E}: NameServer = 50.7.75.30,76.73.6.110
O17 - HKLM\System\CS1\Services\Tcpip\..\{3CF02565-8980-4BEE-A6D1-AFF689EC460D}: NameServer = 50.7.75.30,76.73.6.110
O17 - HKLM\System\CS1\Services\Tcpip\..\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 50.7.75.30,76.73.6.110
O17 - HKLM\System\CS1\Services\Tcpip\..\{C9B8F153-2557-44B7-B5F6-23D99EDF6144}: NameServer = 50.7.75.30,76.73.6.110
O17 - HKLM\System\CS1\Services\Tcpip\..\{38490F1A-161F-4C41-BC7A-7462AA63753E}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{3CF02565-8980-4BEE-A6D1-AFF689EC460D}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{38490F1A-161F-4C41-BC7A-7462AA63753E}: NameServer = 50.7.75.30,76.73.6.110
O17 - HKLM\System\CS2\Services\Tcpip\..\{3CF02565-8980-4BEE-A6D1-AFF689EC460D}: NameServer = 50.7.75.30,76.73.6.110
O17 - HKLM\System\CS2\Services\Tcpip\..\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 50.7.75.30,76.73.6.110
O17 - HKLM\System\CS2\Services\Tcpip\..\{C9B8F153-2557-44B7-B5F6-23D99EDF6144}: NameServer = 50.7.75.30,76.73.6.110
O17 - HKLM\System\CS2\Services\Tcpip\..\{38490F1A-161F-4C41-BC7A-7462AA63753E}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{3CF02565-8980-4BEE-A6D1-AFF689EC460D}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
[MD5.61107991ADF94ED8D464CD1052E5D35B] [APT] [{5503F5CC-E190-4985-B2B6-8F984D232AB4}] (...) -- C:\Program Files (x86)\asus\VirtualCamera\VirCam.exe [858680]
[MD5.61107991ADF94ED8D464CD1052E5D35B] [APT] [{9514D1AA-B7A8-4AF2-8430-8554A24D2D4B}] (...) -- C:\Program Files (x86)\asus\VirtualCamera\VirCam.exe [858680]
~ Scheduled Task: 20 Legitimates Filtered in 00mn 05s



---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: (drksmaaw) . (. - .) - C:\Windows\system32\drivers\drksmaaw.sys (.not file.)
O41 - Driver: (euiplnkm) . (. - .) - C:\Windows\system32\drivers\euiplnkm.sys (.not file.)
O41 - Driver: (exjwdcdr) . (. - .) - C:\Windows\system32\drivers\exjwdcdr.sys (.not file.)
O41 - Driver: (iSafeNetFilter) . (. - .) - C:\Program Files (x86)\iSafe\iSafeNetFilter.sys (.not file.) =>Trojan.Staser
~ Drivers: 72 Legitimates Filtered in 00mn 00s



---\\ Logiciels installés (O42)
O42 - Logiciel: BearShare - (.Musiclab, LLC.) [HKLM][64Bits] -- BearShare =>PUP.BearShare
O42 - Logiciel: BearShare - (.Musiclab, LLC.) [HKLM][64Bits] -- {5F624839-947D-46EA-BD63-FD847C1AC6F1} =>PUP.BearShare
O42 - Logiciel: Search-Results Toolbar - (.APN LLC.) [HKLM][64Bits] -- bearsharetoolbarguid =>PUP.SearchResults
O42 - Logiciel: YAC - (.ELEX DO BRASIL PARTICIPAÇÕES LTDA.) [HKLM][64Bits] -- iSafe =>Trojan.Staser
~ Logic: 31 Legitimates Filtered in 00mn 00s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\BearShare] =>PUP.BearShare
[HKCU\Software\BrowseForTheCause] =>Adware.BrowseForTheCause
[HKCU\Software\bearsharetoolbarguid] =>PUP.BearShare
[HKLM\Software\Wow6432Node\BearShareSRTB] =>PUP.BearShare
[HKLM\Software\Wow6432Node\Lonely Cat Games]
[HKLM\Software\Wow6432Node\MC2]
[HKLM\Software\Wow6432Node\VBMZ] =>PUP.Duuqu
[HKLM\Software\Wow6432Node\supWPM] =>PUP.WpManager
~ Key Software: 330 Legitimates Filtered in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 18/12/2013 - 07:12:23 - [0] ----D C:\Program Files (x86)\iSafe =>Trojan.Staser
O43 - CFD: 15/05/2010 - 20:25:05 - [0] ----D C:\Program Files (x86)\Piggly Christmas Edition
O43 - CFD: 14/12/2013 - 18:21:24 - [0,004] ----D C:\ProgramData\18135
O43 - CFD: 15/12/2012 - 09:03:16 - [0,079] ----D C:\ProgramData\BearShare =>PUP.BearShare
O43 - CFD: 18/12/2013 - 10:22:50 - [0] ----D C:\ProgramData\RHelpers =>PUP.SearchDonkey
O43 - CFD: 17/12/2013 - 23:47:53 - [0,107] ----D C:\ProgramData\TubeDimmer =>PUP.TubeDimmer
O43 - CFD: 18/12/2013 - 10:22:50 - [1,213] ----D C:\ProgramData\Updater =>PUP.CrossRider
O43 - CFD: 17/12/2013 - 21:18:36 - [0] ----D C:\ProgramData\WPM =>PUP.WpManager
O43 - CFD: 15/12/2012 - 09:05:50 - [9,269] --H-D C:\ProgramData\{3F488B3A-CAFC-4177-973B-B562F6436A81}
O43 - CFD: 19/11/2013 - 11:04:01 - [1,063] ----D C:\Users\OLIVIER\AppData\Roaming\0V1L2Z2Z1T1I1L1T
O43 - CFD: 14/12/2013 - 19:11:25 - [90,703] ----D C:\Users\OLIVIER\AppData\Local\BearShare =>PUP.BearShare
O43 - CFD: 17/12/2013 - 20:09:29 - [1,224] ----D C:\Users\OLIVIER\AppData\Local\genienext
~ Program Folder: 203 Legitimates Filtered in 00mn 59s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.EA8743913B8C902F14AC06B51B39C75D] - 17/12/2013 - 21:17:54 ---A- . (...) -- C:\Windows\System32\AutoRunFilter.ini [2234]
O44 - LFC:[MD5.465CD6EC0C8C03E3F13C22904E700B40] - 17/12/2013 - 23:46:21 ---A- . (...) -- C:\Windows\System32\ServiceFilter.ini [1969]
O44 - LFC:[MD5.E934C42C33C8A973F3647F36BDC8E00D] - 18/12/2013 - 06:45:34 ---A- . (...) -- C:\Windows\IE11_main.log [38135]
~ Files: 47 Legitimates Filtered in 00mn 10s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 18 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 5 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.FC0E8778C000291CAF60EB88C011E931] - 11/10/2011 - 22:41:07 ---A- . (...) -- C:\Windows\System32\Drivers\atksgt.sys [314016]
O58 - SDL:[MD5.DEF365F0F6E017888C4B869D3BA4B8E0] - 06/09/2010 - 08:19:54 ---A- . (.Devguru Co., Ltd - Device Error Recovery SDK(x64).) -- C:\Windows\System32\Drivers\dgderdrv.sys [20552]
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
O58 - SDL:[MD5.5CD1005B9BC241C3AB8501D5FBF09FD4] - 12/06/2009 - 04:41:55 ---A- . (.ELAN Microelectronic Corp. - ETD Control Center.) -- C:\Windows\System32\Drivers\ETD.sys [112128]
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
O58 - SDL:[MD5.E63EF8C3271D014F14E2469CE75FECB4] - 20/07/2009 - 10:29:39 ---A- . (.Pas de propriétaire - Keyboard Filter Driver.) -- C:\Windows\System32\Drivers\kbfiltr.sys [15416]
O58 - SDL:[MD5.156AB2E56DC3CA0B582E3362E07CDED7] - 11/10/2011 - 22:41:06 ---A- . (...) -- C:\Windows\System32\Drivers\lirsgt.sys [43680]
O58 - SDL:[MD5.085435AE1A124361304044029B5CC644] - 18/06/2009 - 21:18:10 ---A- . (.Windows (R) Win 7 DDK provider - ASUS CopyProtect driver.) -- C:\Windows\System32\Drivers\lullaby.sys [15928]
O58 - SDL:[MD5.19D8F6FF8344C47872BA351D04A190DD] - 05/06/2009 - 11:15:55 ---A- . (.Pas de propriétaire - USBCAMD for Sonix UVC.) -- C:\Windows\System32\Drivers\sncduvc.sys [42176]
O58 - SDL:[MD5.1D8474722CDFFBB8FCA5FA12C50A05A2] - 05/06/2009 - 11:15:55 ---A- . (.Pas de propriétaire - UVC Camera Streaming Driver.) -- C:\Windows\System32\Drivers\snp2uvc.sys [1806400]
O58 - SDL:[MD5.0B3F6C8F93C5C25977EA5A8B2E656357] - 21/06/2013 - 01:07:52 ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudbus.sys [103448]
O58 - SDL:[MD5.AAF6F247F1DC370C593B4430974EAD9C] - 20/08/2013 - 07:02:12 ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudmdm.sys [204568]
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
O58 - SDL:[MD5.CE4B6956E4E12492715A53076E58761F] - 06/09/2010 - 08:11:32 ---A- . (.Teruten Inc - File System Mini Filter Drvier.) -- C:\Windows\System32\Drivers\TFsExDisk.sys [16392]
O58 - SDL:[MD5.CD03479F2DA26500B203ED075C146A7A] - 19/04/2010 - 19:47:42 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\Drivers\usbaapl64.sys [50688]
O58 - SDL:[MD5.CE4B6956E4E12492715A53076E58761F] - 06/09/2010 - 08:11:32 ---A- . (.Teruten Inc - File System Mini Filter Drvier.) -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys [16392]
O58 - SDL:[MD5.DDEE99DC54EFA20BD5A442CD733C4462] - 18/07/2013 - 06:34:28 ---A- . (...) -- C:\Windows\SysWOW64\FsUsbExDisk.Sys [37344]
~ Drivers: 18 Legitimates Filtered in 00mn 03s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.html> <TorchHTML>[HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 11 Legitimates Filtered in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- c:\program files\internet explorer\iexplore.exe
O68 - StartMenuInternet: <Safari.exe> <Safari>[HKLM\..\Shell\open\Command] (.Apple Inc. - Safari.) -- c:\program files (x86)\safari\safari.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - https://www.google.com/?gws_rd=ssl
O69 - SBI: SearchScopes [HKCU] {E46DF5BD-A1BA-404D-8559-76D7831EBE25} [DefaultScope] - (Google) - https://www.google.com/?gws_rd=ssl
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.1FE339E72FE03A27DD9D5A9A357CFE7D] [SPRF][10/09/2009] (...) -- C:\ProgramData\FullRemove.exe [131368]
[MD5.C49A588C476A6FAA2FA5E98EE8A5F533] [SPRF][19/11/2013] (.Setup © - Setup.) -- C:\Users\OLIVIER\AppData\Local\Temp\98330uninstall.exe [305152]
[MD5.6D73A5291FBA8E712D6D9DE89E2FFF25] [SPRF][15/12/2012] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\apnuserid.dat [16]
[MD5.2387337BA1E0B0249BA90F55B2BA2521] [SPRF][15/12/2012] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\appid.dat [4]
[MD5.858D895AD40DE9779E78C39A116F9553] [SPRF][19/11/2013] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\BackupSetup.exe [10355400]
[MD5.84CB697C4C0E036A78838CE641B27154] [SPRF][15/12/2012] (.Musiclab, LLC - BearShare.) -- C:\Users\OLIVIER\AppData\Local\Temp\BearShare_setup.exe [2482000] =>PUP.BearShare
[MD5.5BB7F9160A555D16C1C4C8914C976043] [SPRF][15/12/2012] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\BundleSweetIMSetup.exe [9] =>PUP.SweetIM
[MD5.0B3E54C8ADCF731FBA2AF1A9E6B5B6AE] [SPRF][04/06/2002] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\iiuninst.exe [163891]
[MD5.1AC48C0EDB3D9124E6D1EE6979EE2D60] [SPRF][09/12/2012] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\Installhelper.dll [1629872]
[MD5.D2B48C62D4E77881DF37119BBADB8A0F] [SPRF][15/12/2012] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\MybabylonTB.exe [11] =>PUP.Babylon
[MD5.876758374902C84D0DB998E31FDCD08C] [SPRF][21/03/2011] (.Pas de propriétaire - Toolbar Offer.) -- C:\Users\OLIVIER\AppData\Local\Temp\Offer100.exe [15168]
[MD5.1B80378EA920FCD0EA146B28C3DBA2AE] [SPRF][15/12/2012] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\propsys.dll [6]
[MD5.0D26EF8C01E3E1C77877C303A9317F69] [SPRF][10/12/2013] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\Quarantine.exe [360051]
[MD5.466C4732BC4B126B94B0E69C6B5A2348] [SPRF][28/11/2013] (.Pas de propriétaire - SendMsg.) -- C:\Users\OLIVIER\AppData\Local\Temp\SendMsg.dll [9216]
[MD5.F5E79060D099AB8D02BB3B3FF0574C4E] [SPRF][17/12/2013] (.UpdaterResponse - Pas de description.) -- C:\Users\OLIVIER\AppData\Local\Temp\setup{276A8860-14EF-42E4-A1F5-8207C34846FB}.exe [1170808]
[MD5.5405413FFF79B8D9C747AA900F60F082] [SPRF][19/11/2013] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\Sqlite3.dll [599419]
[MD5.72412B526BCC716382E62B7939DCFD8F] [SPRF][06/05/2012] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\SRAssetsHelper.dll [1085952]
[MD5.C81E728D9D4C2F636F067F89CC14862C] [SPRF][15/12/2012] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\sysid.dat [1]
[MD5.ACFA9609894A2E0DCD015F00549A78F2] [SPRF][15/12/2012] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\thanks.bat [99]
[MD5.EE753E9B64DAFA9574CB540C76550126] [SPRF][15/12/2012] (.Torch Media Inc. - Torch Browser.) -- C:\Users\OLIVIER\AppData\Local\Temp\TorchSetupFull.exe [32279008]
[MD5.B804CB981CD938A14888362BCB4313FF] [SPRF][15/12/2012] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\trackid.dat [6]
[MD5.B85FAF58E8FC8EAC30E1EA65A252BD11] [SPRF][28/06/2010] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\t_7kd69i.dll [3584]
[MD5.B0F6507F8666E89DD9F192313D88EB98] [SPRF][16/06/2013] (.Babylon Ltd. - Uninstaller Application.) -- C:\Users\OLIVIER\AppData\Local\Temp\uninst1.exe [389632] =>PUP.Babylon
[MD5.32C2EAC8B02BADB7A20E92C94DDF8D3E] [SPRF][17/12/2013] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\Unipack_Installer.exe [168556]
[MD5.1E06C7ED88DC3D9BA01DE0EC66247FFB] [SPRF][19/10/2012] (.Unity Technologies ApS - Unity Web Player Installer.) -- C:\Users\OLIVIER\AppData\Local\Temp\UnityWebPlayer7053396035010009672.exe [591224]
[MD5.CBA63BC3C9979EACF13567754A1CC1CA] [SPRF][20/09/2013] (...) -- C:\Users\OLIVIER\AppData\Local\Temp\Xvid.dll [20992]
[MD5.F26FCE8D559985732F365C065F4F0A7F] [SPRF][31/10/2013] (...) -- C:\Users\OLIVIER\AppData\Roaming\TheHunterSettings_live.bin [7909]
[MD5.C0E253C5C4124C8B881CA44828839F5E] [SPRF][25/07/2013] (.The GIMP Team - GIMP Setup.) -- C:\Users\OLIVIER\Desktop\the-gimp_2-8-6_fr_10178.exe [90139696]
~ Files: 61 Legitimates Filtered in 00mn 16s



---\\ Liste des exceptions du parefeu (FirewallRules) (O87)
O87 - FAEL: "TCP Query User{74905083-A028-4D90-BDF2-6A5A9CDF5F28}C:\program files (x86)\microids\sniper elite\sniperelite.exe" | In - Private - P6 - TRUE | .(...) -- C:\program files (x86)\microids\sniper elite\sniperelite.exe
O87 - FAEL: "UDP Query User{12554C29-272E-4FF5-BA91-A0769A2E74A3}C:\program files (x86)\microids\sniper elite\sniperelite.exe" | In - Private - P17 - TRUE | .(...) -- C:\program files (x86)\microids\sniper elite\sniperelite.exe
O87 - FAEL: "{A619BDED-1A52-456D-8EE8-831BAFAE95FA}" |In - Domain - P6 - TRUE | .(...) -- C:\Program Files (x86)\BearShare Applications\BearShare\BearShare.exe (.not file.) =>PUP.BearShare
O87 - FAEL: "{52B1C9D6-26CB-40CD-BD8F-3B599118A12B}" |In - Domain - P17 - TRUE | .(...) -- C:\Program Files (x86)\BearShare Applications\BearShare\BearShare.exe (.not file.) =>PUP.BearShare
O87 - FAEL: "{07000037-F7F5-4056-9C67-397BD0E588FE}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\BearShare Applications\BearShare\BearShare.exe (.not file.) =>PUP.BearShare
O87 - FAEL: "{7D9B0BCD-0A29-4FC2-A55E-AAF710952731}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\BearShare Applications\BearShare\BearShare.exe (.not file.) =>PUP.BearShare
O87 - FAEL: "{402E3F91-3B6C-46F6-9861-955D2EDE1B6C}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\BearShare Applications\Mediabar\Datamngr\SRTOOL~1\dtUser.exe (.not file.) =>PUP.BearShare
O87 - FAEL: "{EE4AD70C-63A0-43CD-A6F1-10ADD8F8EDB6}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\BearShare Applications\Mediabar\Datamngr\SRTOOL~1\dtUser.exe (.not file.) =>PUP.BearShare
O87 - FAEL: "{D72891E1-6085-4B19-8A59-B0F0E2AE786B}" |In - Public - P6 - TRUE | .(...) -- C:\Program Files (x86)\BearShare Applications\BearShare\BearShare.exe (.not file.) =>PUP.BearShare
O87 - FAEL: "{52F98D08-358A-4FB9-B63D-238B2099F4D4}" |In - Public - P17 - TRUE | .(...) -- C:\Program Files (x86)\BearShare Applications\BearShare\BearShare.exe (.not file.) =>PUP.BearShare
~ Firewall: 246 Legitimates Filtered in 00mn 02s



---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.EB3DB5F7DB015BB71CDF18D4BF73CDDB] [WIS][15/12/2012] (.Musiclab, LLC - BearShare.) -- C:\Windows\Installer\1b34bb.msi [335872] =>PUP.BearShare
~ WIS: 98 Legitimates Filtered in 00mn 15s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 14/12/2013 257416 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Auto 07/11/2010 136176 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 07/11/2010 136176 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 24/08/2012 194032 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
SS - | Auto 05/09/2013 171680 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SS - | Demand 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

SR - | Auto 14/05/2009 759048 | (ABBYY.Licensing.FineReader.Sprint.9.0) . (.ABBYY.) - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
SR - | Demand 31/03/2008 225280 | (ADSMService) . (.ASUSTek Computer Inc..) - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
SR - | Auto 17/09/2009 359552 | (AFBAgent) . (.ASUSTeK Computer Inc..) - C:\Windows\system32\FBAgent.exe
SR - | Auto 25/05/2011 37664 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 16/06/2009 84536 | (ASLDRService) . (.ASUS.) - C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
SR - | Auto 08/08/2007 94208 | (ATKGFNEXSrv) . (...) - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
SR - | Auto 06/04/2011 349472 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
SR - | Auto 19/12/2006 94208 | (EpsonBidirectionalService) . (.SEIKO EPSON CORPORATION.) - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
SR - | Demand 07/06/2011 934176 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 17/12/2013 376144 | (LMIGuardianSvc) . (.LogMeIn, Inc..) - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
SR - | Auto 17/12/2013 226640 | (LMIMaint) . (.LogMeIn, Inc..) - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
SR - | Auto 08/11/2010 407424 | (LogMeIn) . (.LogMeIn, Inc..) - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
SR - | Auto 04/04/2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
SR - | Auto 04/04/2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
SR - | Auto 23/10/2013 23808 | (MsMpSvc) . (.Microsoft Corporation.) - C:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 20/10/2008 71096 | (NMSAccessU) . (...) - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
SR - | Auto 15/09/2009 44312 | (OberonGameConsoleService) . (...) - C:\Program Files (x86)\Asus\Game Park\GameConsole\OberonGameConsoleService.exe
SR - | Auto 10/07/1658 0 | (PnkBstrA) . (...) - C:\Windows\system32\PnkBstrA.exe
SR - | Auto 22/09/2010 249136 | (SeaPort) . (.Microsoft Corporation.) - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

~ Services: Scanned in 00mn 17s



---\\ Scan Additionnel (O88)
Database Version : 13013 - (14/12/2013)
Clés trouvées (Keys found) : 10
Valeurs trouvées (Values found) : 7
Dossiers trouvés (Folders found) : 8
Fichiers trouvés (Files found) : 12

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\BearShare] =>PUP.BearShare^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5F624839-947D-46EA-BD63-FD847C1AC6F1}] =>PUP.BearShare^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\bearsharetoolbarguid] =>PUP.SearchResults^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iSafe] =>Trojan.Staser^
[HKLM\Software\Classes\AppID\BearShare.exe] =>PUP.BearShare
[HKCU\Software\BrowseForTheCause] =>Adware.BrowseForTheCause
[HKLM\Software\Wow6432Node\VBMZ] =>Toolbar.Conduit
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E47D688-85EC-465A-9946-EC58220F14FC}] =>PUP.SearchResults
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E47D688-85EC-465A-9946-EC58220F14FC}] =>PUP.SearchResults
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\bearsharetoolbarguid] =>PUP.SearchResults
C:\Program Files (x86)\iSafe =>Trojan.Staser^
C:\ProgramData\BearShare =>PUP.BearShare^
C:\ProgramData\RHelpers =>PUP.SearchDonkey^
C:\ProgramData\TubeDimmer =>PUP.TubeDimmer^
C:\ProgramData\Updater =>PUP.CrossRider^
C:\ProgramData\WPM =>PUP.WpManager^
C:\Users\OLIVIER\AppData\Local\BearShare =>PUP.BearShare^
C:\Program Files (x86)\BearShare Applications =>PUP.BearShare
[HKCU\Software\BearShare] =>PUP.BearShare^
[HKCU\Software\bearsharetoolbarguid] =>PUP.BearShare^
[HKLM\Software\Wow6432Node\BearShareSRTB] =>PUP.BearShare^
[HKLM\Software\Wow6432Node\supWPM] =>PUP.WpManager^
C:\Users\OLIVIER\AppData\Local\Temp\BearShare_setup.exe =>PUP.BearShare^
C:\Users\OLIVIER\AppData\Local\Temp\BundleSweetIMSetup.exe =>PUP.SweetIM^
C:\Users\OLIVIER\AppData\Local\Temp\MybabylonTB.exe =>PUP.Babylon^
C:\Users\OLIVIER\AppData\Local\Temp\uninst1.exe =>PUP.Babylon^
C:\Windows\Installer\1b34bb.msi =>PUP.BearShare^
C:\Users\OLIVIER\AppData\Local\Temp\GoogleToolbarInstaller1.log =>PUP.Babylon
C:\Users\OLIVIER\AppData\Local\Temp\GoogleToolbarInstaller2.log =>PUP.Babylon
~ Additionnel Scan: 349570 Items scanned in 00mn 46s



---\\ Récapitulatif des détections trouvées sur votre station
~ http://nicolascoolman.webs.com/apps/blog/show/38126906-hijacker-nationzoom =>Hijacker.NationZoom
~ http://nicolascoolman.webs.com/apps/blog/show/26705717-pup-bearshare =>PUP.BearShare
~ http://nicolascoolman.webs.com/apps/blog/show/32771797-trojan-staser =>Trojan.Staser
~ http://nicolascoolman.webs.com/apps/blog/show/30319724-pup-searchresults =>PUP.SearchResults
~ http://nicolascoolman.webs.com/apps/blog/show/26627928-adware-browseforthecause =>Adware.BrowseForTheCause
~ http://nicolascoolman.webs.com/apps/blog/show/37752731-pup-duuqu =>PUP.Duuqu
~ http://nicolascoolman.webs.com/apps/blog/show/38737316-pup-wpmanager =>PUP.WpManager
~ http://nicolascoolman.webs.com/apps/blog/show/38839825-pup-searchdonkey =>PUP.SearchDonkey
~ http://nicolascoolman.webs.com/apps/blog/show/37242682-pup-tubedimmer =>PUP.TubeDimmer
~ http://nicolascoolman.webs.com/apps/blog/show/27583526-pup-crossrider =>PUP.CrossRider
~ http://nicolascoolman.webs.com/apps/blog/show/29216159-pup-sweetim =>PUP.SweetIM
~ http://nicolascoolman.webs.com/apps/blog/show/26627369-toolbar-babylon =>PUP.Babylon
~ http://nicolascoolman.webs.com/apps/blog/show/29507721-toolbar-conduit =>Toolbar.Conduit
~ MSI: 13 link(s) detected in 00mn 46s



~ 1223 Legitimates filtered by white list
End of the scan (594 lines in 03mn 37s)(0)
0
kaori64 Messages postés 75 Date d'inscription lundi 21 juillet 2008 Statut Membre Dernière intervention 29 décembre 2015
18 déc. 2013 à 10:33
voila tous les rapports ont été effectués , j'attends votre message pour faire d'autres manip si nécessaire! encore merci
0
Marou81 Messages postés 4175 Date d'inscription mercredi 13 janvier 2010 Statut Membre Dernière intervention 18 mars 2014 198
18 déc. 2013 à 12:28
Bonjour,

Ton ordinateur est infecté par un rogue, c'est à dire un logiciel qui affiche de fausses alertes pour te faire peur et te pousser à payer (plus d'infos ici)... Ignore les fausses alertes du rogue et ne paye surtout pas, je vais t'aider à t'en débarrasser. Pour commencer, utilise cet outil :

▶ Télécharge RogueKiller (de Tigzy) sur le Bureau
▶ Quitte tous tes programmes en cours
▶ Lance le (si tu utilises Windows Vista ou 7 : fais un clic-droit dessus et choisis "Exécuter en tant qu'administrateur")
▶ Patiente pendant le pre-scan, puis clique sur le bouton "Scan"
▶ A la fin, vérifie que tous les éléments sont cochés puis clique sur "Suppression"
▶ Un rapport (RKreport.txt) doit être créé sur le Bureau, poste le dans ta prochaine réponse.
0
kaori64 Messages postés 75 Date d'inscription lundi 21 juillet 2008 Statut Membre Dernière intervention 29 décembre 2015
18 déc. 2013 à 13:38
RogueKiller V8.7.12 [Dec 14 2013] par Tigzy
mail : tigzyRK<at>gmail<dot>com
Remontees : http://www.adlice.com/forum/
Site Web : https://www.luanagames.com/index.fr.html
Blog : https://www.adlice.com/

Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Demarrage : Mode normal
Utilisateur : OLIVIER [Droits d'admin]
Mode : Suppression -- Date : 12/18/2013 13:37:37
| ARK || FAK || MBR |

¤¤¤ Processus malicieux : 0 ¤¤¤

¤¤¤ Entrees de registre : 8 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> SUPPRIMÉ
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> SUPPRIMÉ
[HJ POL][PUM] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REMPLACÉ (2)
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> REMPLACÉ (1)
[HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : ConsentPromptBehaviorAdmin (0) -> REMPLACÉ (2)
[HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : EnableLUA (0) -> REMPLACÉ (1)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REMPLACÉ (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REMPLACÉ (0)

¤¤¤ Tâches planifiées : 0 ¤¤¤

¤¤¤ Entrées Startup : 0 ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

¤¤¤ Driver : [NON CHARGE 0x0] ¤¤¤

¤¤¤ Ruches Externes: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ Fichier HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ MBR Verif: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Hitachi HTS545032B9A300 +++++
--- User ---
[MBR] dacefda7334427c4ba596b95f4a2421b
[BSP] 430eaf6ed8558d670d2c84579f07828f : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 2048 | Size: 14997 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 30716280 | Size: 76308 Mo
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 186996600 | Size: 213935 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Termine : << RKreport[0]_D_12182013_133737.txt >>
RKreport[0]_S_12182013_133701.txt
0
Marou81 Messages postés 4175 Date d'inscription mercredi 13 janvier 2010 Statut Membre Dernière intervention 18 mars 2014 198
18 déc. 2013 à 13:41
Re,

▶ Télécharge TDSSKiller (de Kaspersky Labs) sur ton Bureau.
▶ Lance le (si tu utilises Windows Vista ou 7 : fais un clic-droit dessus et choisis "Exécuter en tant qu'administrateur")
▶ Clique sur Start Scan pour démarrer l'analyse.
▶ Si des éléments néfastes sont identifiés par l'outil, vérifie que Cure est bien coché. S'il indique "suspicious", laisse l'option Skip.
▶ Ensuite, clique sur Continue puis sur Reboot Now si nécessaire.
▶ Un rapport s'ouvrira au redémarrage de l'ordinateur.
▶ Copie/colle son contenu dans ta prochaine réponse (il se trouve également sous C:\TDSSKiller.N°deversion_Date_Heure_log.txt)
0
kaori64 Messages postés 75 Date d'inscription lundi 21 juillet 2008 Statut Membre Dernière intervention 29 décembre 2015
18 déc. 2013 à 13:46
aucun objet détecté et je n'ai pas de rapport
0
kaori64 Messages postés 75 Date d'inscription lundi 21 juillet 2008 Statut Membre Dernière intervention 29 décembre 2015
18 déc. 2013 à 13:51
je ne sais pas si cela a un rapport avec les virus mais j'ai une icone sur mon bureau qui s'appelle create amazing prestations et je souhaiterais la supprimer et lorsque je me rend sur programmes et fonctionnalitées celle ci n'y est pas !
0
Marou81 Messages postés 4175 Date d'inscription mercredi 13 janvier 2010 Statut Membre Dernière intervention 18 mars 2014 198
Modifié par Marou81 le 18/12/2013 à 20:20
Bonsoir,

Tu peux la supprimer en appuyant sur l'icone clique droit supprimer.

En tout cas ton pc est désinfecté :)

On finalise télécharge SFTGC : http://www.archive-host.com

Clique droit pour ouvrir le programme.
Ferme tout tes programmes en cours
Lance go et attend

Poste moi le rapport

Puis télécharge DelFix, lance le programme puis coche suppression outils désinfection.

A te relire

Merci d'avoir suivi mes conseils étape par étape. N'oubliez pas de mettre sujet résolu.
0
kaori64 Messages postés 75 Date d'inscription lundi 21 juillet 2008 Statut Membre Dernière intervention 29 décembre 2015
19 déc. 2013 à 07:54
bonjour marou 81
voici le rapport
Rapport de SFTGC (Pierre13) du Jeudi 19 Décembre 2013 à 07:54:02 version : 2.0.0.60
Mis à jour le 27/11/2013
Outil lancé en Mode normal et En tant qu'administrateur
Windows 7 Home Premium Service Pack 1 64 bits

Tool start in C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CR7JDI66

3161 éléments supprimés => 3.1 Go libérés. (3 mn 33 s)

C:\Users\OLIVIER\AppData\Local\Temp\+~JF1503323247768531796.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF1547205132019644763.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF182990191504418232.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF3078640304317927069.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF3497374641971454166.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF3549436159947490408.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF4724905637730436523.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF5119368462291852961.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF562916955927143160.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF5761478838466916823.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF5915675642387095076.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF6339392248883449775.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF6361246061666923977.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF7034002643464960422.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF859285986030817967.tmp
C:\Users\OLIVIER\AppData\Local\Temp\+~JF8698058189913579706.tmp
C:\Users\OLIVIER\AppData\Local\Temp\030114450000088c0mp99e5wgu
C:\Users\OLIVIER\AppData\Local\Temp\030114450000088c81pl2z3efz
C:\Users\OLIVIER\AppData\Local\Temp\030114450000088c9ailz87pi1
C:\Users\OLIVIER\AppData\Local\Temp\030114450000088cls7z61nzca
C:\Users\OLIVIER\AppData\Local\Temp\030114450000088cmftkzy3ujw
C:\Users\OLIVIER\AppData\Local\Temp\030114450000088ct3levwr74e
C:\Users\OLIVIER\AppData\Local\Temp\030114460000088cabhxazn4gg
C:\Users\OLIVIER\AppData\Local\Temp\030114460000088cfvatc4aqoy
C:\Users\OLIVIER\AppData\Local\Temp\030114470000088c8bdu3ejmhg
C:\Users\OLIVIER\AppData\Local\Temp\030114470000088cc614rhlkei
C:\Users\OLIVIER\AppData\Local\Temp\030114470000088cpjyor1hg8m
C:\Users\OLIVIER\AppData\Local\Temp\030114480000088cca7jtk81dp
C:\Users\OLIVIER\AppData\Local\Temp\030114480000088cjzxdadek6x
C:\Users\OLIVIER\AppData\Local\Temp\030114480000088com3pkcw8sz
C:\Users\OLIVIER\AppData\Local\Temp\030114480000088cqmbqvdpojc
C:\Users\OLIVIER\AppData\Local\Temp\04130640-00000980-t6vtfgabsv
C:\Users\OLIVIER\AppData\Local\Temp\0517dmwg.tmp
C:\Users\OLIVIER\AppData\Local\Temp\06t7w0ma.tmp
C:\Users\OLIVIER\AppData\Local\Temp\07121824-00001bb4-zhh2025jf8
C:\Users\OLIVIER\AppData\Local\Temp\08311720-000016e8-sijdjl63hs
C:\Users\OLIVIER\AppData\Local\Temp\0v068fgt.tmp
C:\Users\OLIVIER\AppData\Local\Temp\10-05-SAP-0983_xm-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\10224_1124170671383_1440605766_30292067_7179224_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\1116.tmp
C:\Users\OLIVIER\AppData\Local\Temp\11FB.dir
C:\Users\OLIVIER\AppData\Local\Temp\11FB.tmp
C:\Users\OLIVIER\AppData\Local\Temp\1360.tmp
C:\Users\OLIVIER\AppData\Local\Temp\14A6.tmp
C:\Users\OLIVIER\AppData\Local\Temp\1807879.Uninstall
C:\Users\OLIVIER\AppData\Local\Temp\1861.tmp
C:\Users\OLIVIER\AppData\Local\Temp\18647_1184788506791_1440605766_30418639_2239186_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\18C9.tmp
C:\Users\OLIVIER\AppData\Local\Temp\19F9.tmp
C:\Users\OLIVIER\AppData\Local\Temp\19j8m04i.tmp
C:\Users\OLIVIER\AppData\Local\Temp\19yr3bfc.tmp
C:\Users\OLIVIER\AppData\Local\Temp\1dnkphgo.tmp
C:\Users\OLIVIER\AppData\Local\Temp\2131373-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\22443_1301881435423_1482070012_865927_7231243_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\2264377116.od
C:\Users\OLIVIER\AppData\Local\Temp\2356CEA5-48CC-408F-B7A7-9BF806E30ABC.Diagnose.Admin.0.etl
C:\Users\OLIVIER\AppData\Local\Temp\23F2.tmp
C:\Users\OLIVIER\AppData\Local\Temp\24218_1394906187141_1066780043_31139407_3868915_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\2482.tmp
C:\Users\OLIVIER\AppData\Local\Temp\24BC.tmp
C:\Users\OLIVIER\AppData\Local\Temp\24CC.tmp
C:\Users\OLIVIER\AppData\Local\Temp\26093_409839282428_543897428_5025836_2441611_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\26093_409839282428_543897428_5025836_2441611_n-2.jpg
C:\Users\OLIVIER\AppData\Local\Temp\26608_389369359172_758509172_3658334_3714834_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\27026_395106367280_798522280_3585389_115106_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\27092_388049644556_831609556_3737084_221305_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\27092_388049989556_831609556_3737100_1004269_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\29064_10150197672190228_859475227_12654346_6053672_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\29963_1277326740189_1440605766_30597230_2067723_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\2B99.tmp
C:\Users\OLIVIER\AppData\Local\Temp\2C05.tmp
C:\Users\OLIVIER\AppData\Local\Temp\2E54.tmp
C:\Users\OLIVIER\AppData\Local\Temp\2kx0fkyx.tmp
C:\Users\OLIVIER\AppData\Local\Temp\30204_10150185784505018_677290017_12097541_5603109_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\30501_1461471697516_1255146230_31309335_2456266_s-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\31059_393998889077_583804077_3852787_4938117_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\31059_393998974077_583804077_3852800_4230963_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\31059_393998974077_583804077_3852800_4230963_n-2.jpg
C:\Users\OLIVIER\AppData\Local\Temp\31059_393998989077_583804077_3852803_7295532_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\319439706.Uninstall
C:\Users\OLIVIER\AppData\Local\Temp\319475055.Uninstall
C:\Users\OLIVIER\AppData\Local\Temp\31C3.tmp
C:\Users\OLIVIER\AppData\Local\Temp\32AA.tmp
C:\Users\OLIVIER\AppData\Local\Temp\34284_10150217990305364_563145363_13214292_174186_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\34783_1320854188348_1440605766_30706103_3248758_n-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\366B.tmp
C:\Users\OLIVIER\AppData\Local\Temp\37A2.tmp
C:\Users\OLIVIER\AppData\Local\Temp\388D.tmp
C:\Users\OLIVIER\AppData\Local\Temp\3C45.dir
C:\Users\OLIVIER\AppData\Local\Temp\3C45.tmp
C:\Users\OLIVIER\AppData\Local\Temp\3DC7A0C6-0CCE-40F9-AA99-D699F107589F.Diagnose.Admin.0.etl
C:\Users\OLIVIER\AppData\Local\Temp\3DC7A0C6-0CCE-40F9-AA99-D699F107589F.Repair.Admin.1.etl
C:\Users\OLIVIER\AppData\Local\Temp\3DC7A0C6-0CCE-40F9-AA99-D699F107589F.Verify.Admin.2.etl
C:\Users\OLIVIER\AppData\Local\Temp\3dcf2df1-2a83-477c-a7dd-858967792357
C:\Users\OLIVIER\AppData\Local\Temp\3nr9pe5b.tmp
C:\Users\OLIVIER\AppData\Local\Temp\4.tmp
C:\Users\OLIVIER\AppData\Local\Temp\417E.tmp
C:\Users\OLIVIER\AppData\Local\Temp\44DC.tmp
C:\Users\OLIVIER\AppData\Local\Temp\4805.tmp
C:\Users\OLIVIER\AppData\Local\Temp\4A1D.tmp
C:\Users\OLIVIER\AppData\Local\Temp\4D96.tmp
C:\Users\OLIVIER\AppData\Local\Temp\5347.tmp
C:\Users\OLIVIER\AppData\Local\Temp\54ez6whs.tmp
C:\Users\OLIVIER\AppData\Local\Temp\585C.tmp
C:\Users\OLIVIER\AppData\Local\Temp\58D3.tmp
C:\Users\OLIVIER\AppData\Local\Temp\5EAE.dir
C:\Users\OLIVIER\AppData\Local\Temp\5EAE.tmp
C:\Users\OLIVIER\AppData\Local\Temp\5eddc231-1827-4ae5-9963-3004768a5852
C:\Users\OLIVIER\AppData\Local\Temp\62C7.tmp
C:\Users\OLIVIER\AppData\Local\Temp\66cas56j.tmp
C:\Users\OLIVIER\AppData\Local\Temp\68DC.tmp
C:\Users\OLIVIER\AppData\Local\Temp\69A4.tmp
C:\Users\OLIVIER\AppData\Local\Temp\6C3C.tmp
C:\Users\OLIVIER\AppData\Local\Temp\7077.tmp
C:\Users\OLIVIER\AppData\Local\Temp\718b73339a145044064f
C:\Users\OLIVIER\AppData\Local\Temp\71E5.tmp
C:\Users\OLIVIER\AppData\Local\Temp\72C2.tmp
C:\Users\OLIVIER\AppData\Local\Temp\7551.tmp
C:\Users\OLIVIER\AppData\Local\Temp\763A.tmp
C:\Users\OLIVIER\AppData\Local\Temp\7787.tmp
C:\Users\OLIVIER\AppData\Local\Temp\77AA.tmp
C:\Users\OLIVIER\AppData\Local\Temp\7894.tmp
C:\Users\OLIVIER\AppData\Local\Temp\79DD.tmp
C:\Users\OLIVIER\AppData\Local\Temp\7C4C.tmp
C:\Users\OLIVIER\AppData\Local\Temp\7C6A.tmp
C:\Users\OLIVIER\AppData\Local\Temp\7D62.tmp
C:\Users\OLIVIER\AppData\Local\Temp\7FB3.tmp
C:\Users\OLIVIER\AppData\Local\Temp\7zpnlaxv.tmp
C:\Users\OLIVIER\AppData\Local\Temp\8063563073-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\8127114208-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\8127114208-2.jpg
C:\Users\OLIVIER\AppData\Local\Temp\8197325898-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\821B.tmp
C:\Users\OLIVIER\AppData\Local\Temp\8239.tmp
C:\Users\OLIVIER\AppData\Local\Temp\841482D4-95B7-4450-B438-98FA5913644C.Diagnose.Admin.0.etl
C:\Users\OLIVIER\AppData\Local\Temp\8604.tmp
C:\Users\OLIVIER\AppData\Local\Temp\864F.tmp
C:\Users\OLIVIER\AppData\Local\Temp\8819593246-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\8848863535-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\8DD4.tmp
C:\Users\OLIVIER\AppData\Local\Temp\8F6D6840-BAB0-7891-AD81-29D330AB821E
C:\Users\OLIVIER\AppData\Local\Temp\8swyhjah.tmp
C:\Users\OLIVIER\AppData\Local\Temp\9135.tmp
C:\Users\OLIVIER\AppData\Local\Temp\92D.tmp
C:\Users\OLIVIER\AppData\Local\Temp\96ED.tmp
C:\Users\OLIVIER\AppData\Local\Temp\97FD.tmp
C:\Users\OLIVIER\AppData\Local\Temp\9833.tmp
C:\Users\OLIVIER\AppData\Local\Temp\98330uninstall.exe
C:\Users\OLIVIER\AppData\Local\Temp\9E2D00F8-BAB0-7891-BAD9-6EB056F1CF9E
C:\Users\OLIVIER\AppData\Local\Temp\9EAF.dir
C:\Users\OLIVIER\AppData\Local\Temp\9EAF.tmp
C:\Users\OLIVIER\AppData\Local\Temp\9hcgkhz4.tmp
C:\Users\OLIVIER\AppData\Local\Temp\A7DE.tmp
C:\Users\OLIVIER\AppData\Local\Temp\ABBYY Licensing Install.log
C:\Users\OLIVIER\AppData\Local\Temp\ABBYY-Licensing-FineReader-Sprint-9.0.rollback
C:\Users\OLIVIER\AppData\Local\Temp\ABBYY.Sprint.Registrator.log
C:\Users\OLIVIER\AppData\Local\Temp\AbbyyMsiLog.txt
C:\Users\OLIVIER\AppData\Local\Temp\ABP_InstallChecker.exe
C:\Users\OLIVIER\AppData\Local\Temp\ABP_TB0001.exe
C:\Users\OLIVIER\AppData\Local\Temp\ACC9.tmp
C:\Users\OLIVIER\AppData\Local\Temp\ADA1.dir
C:\Users\OLIVIER\AppData\Local\Temp\ADA1.tmp
C:\Users\OLIVIER\AppData\Local\Temp\adb.log
C:\Users\OLIVIER\AppData\Local\Temp\Administrateur.bmp
C:\Users\OLIVIER\AppData\Local\Temp\AdobeARM.log
C:\Users\OLIVIER\AppData\Local\Temp\AdobeARM_NotLocked.log
C:\Users\OLIVIER\AppData\Local\Temp\AdwCleaner.jpg
C:\Users\OLIVIER\AppData\Local\Temp\AEA6.tmp
C:\Users\OLIVIER\AppData\Local\Temp\amline_data.xml
C:\Users\OLIVIER\AppData\Local\Temp\amline_settings.xml
C:\Users\OLIVIER\AppData\Local\Temp\anglet_20101010_1930-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\apnPixel.txt
C:\Users\OLIVIER\AppData\Local\Temp\apnuserid.dat
C:\Users\OLIVIER\AppData\Local\Temp\appid.dat
C:\Users\OLIVIER\AppData\Local\Temp\atl80.dll
C:\Users\OLIVIER\AppData\Local\Temp\au-descriptor-1.7.0_25-b16.xml
C:\Users\OLIVIER\AppData\Local\Temp\au-descriptor-1.7.0_45-b18.xml
C:\Users\OLIVIER\AppData\Local\Temp\AUCHECK_CORE.txt
C:\Users\OLIVIER\AppData\Local\Temp\AUCHECK_PARSER.txt
C:\Users\OLIVIER\AppData\Local\Temp\AZU2370891698471747715.tmp
C:\Users\OLIVIER\AppData\Local\Temp\AZU3228269950078327842.tmp
C:\Users\OLIVIER\AppData\Local\Temp\AZU4360259967274669941.tmp
C:\Users\OLIVIER\AppData\Local\Temp\AZU5239355265561087701.tmp
C:\Users\OLIVIER\AppData\Local\Temp\Azureus4.6.0.2.jar
C:\Users\OLIVIER\AppData\Local\Temp\b01d42a6-0948-4bd0-8dea-54d68f50a791
C:\Users\OLIVIER\AppData\Local\Temp\B55.tmp
C:\Users\OLIVIER\AppData\Local\Temp\B579.tmp
C:\Users\OLIVIER\AppData\Local\Temp\B9A3.tmp
C:\Users\OLIVIER\AppData\Local\Temp\BAB4.tmp
C:\Users\OLIVIER\AppData\Local\Temp\BackupSetup.exe
C:\Users\OLIVIER\AppData\Local\Temp\BB4C.tmp
C:\Users\OLIVIER\AppData\Local\Temp\BD5E.tmp
C:\Users\OLIVIER\AppData\Local\Temp\BearShare.ico
C:\Users\OLIVIER\AppData\Local\Temp\BearShare.ini
C:\Users\OLIVIER\AppData\Local\Temp\BearSharePreview
C:\Users\OLIVIER\AppData\Local\Temp\bearsharetoolbarguid-manifest.xml
C:\Users\OLIVIER\AppData\Local\Temp\BearShare_setup.exe
C:\Users\OLIVIER\AppData\Local\Temp\BED9.tmp
C:\Users\OLIVIER\AppData\Local\Temp\BFHUpdater.log
C:\Users\OLIVIER\AppData\Local\Temp\BFHUpdaterLauncher.log
C:\Users\OLIVIER\AppData\Local\Temp\BingBarInstallerLogs
C:\Users\OLIVIER\AppData\Local\Temp\bouton_bid_big_1-1.gif
C:\Users\OLIVIER\AppData\Local\Temp\bouton_bid_big_1-2.gif
C:\Users\OLIVIER\AppData\Local\Temp\bouton_bid_big_1-3.gif
C:\Users\OLIVIER\AppData\Local\Temp\BP4FUpdater.log
C:\Users\OLIVIER\AppData\Local\Temp\BP4FUpdaterLauncher.log
C:\Users\OLIVIER\AppData\Local\Temp\BundleSweetIMSetup.exe
C:\Users\OLIVIER\AppData\Local\Temp\bus1358
C:\Users\OLIVIER\AppData\Local\Temp\bus1358.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus152F
C:\Users\OLIVIER\AppData\Local\Temp\bus152F.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus1CA9
C:\Users\OLIVIER\AppData\Local\Temp\bus1CA9.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus2290
C:\Users\OLIVIER\AppData\Local\Temp\bus2290.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus25CB
C:\Users\OLIVIER\AppData\Local\Temp\bus25CB.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus2810
C:\Users\OLIVIER\AppData\Local\Temp\bus2810.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus2FCB
C:\Users\OLIVIER\AppData\Local\Temp\bus2FCB.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus3212
C:\Users\OLIVIER\AppData\Local\Temp\bus3212.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus397E
C:\Users\OLIVIER\AppData\Local\Temp\bus397E.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus43E1
C:\Users\OLIVIER\AppData\Local\Temp\bus43E1.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus5C75
C:\Users\OLIVIER\AppData\Local\Temp\bus5C75.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus5FCB
C:\Users\OLIVIER\AppData\Local\Temp\bus5FCB.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus642F
C:\Users\OLIVIER\AppData\Local\Temp\bus642F.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus71F0
C:\Users\OLIVIER\AppData\Local\Temp\bus71F0.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus71F1
C:\Users\OLIVIER\AppData\Local\Temp\bus71F1.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus7721
C:\Users\OLIVIER\AppData\Local\Temp\bus7721.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus7776
C:\Users\OLIVIER\AppData\Local\Temp\bus7776.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus7F9E
C:\Users\OLIVIER\AppData\Local\Temp\bus7F9E.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus8005
C:\Users\OLIVIER\AppData\Local\Temp\bus8005.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus8403
C:\Users\OLIVIER\AppData\Local\Temp\bus8403.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus897
C:\Users\OLIVIER\AppData\Local\Temp\bus897.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus9795
C:\Users\OLIVIER\AppData\Local\Temp\bus9795.tmp
C:\Users\OLIVIER\AppData\Local\Temp\bus9F6D
C:\Users\OLIVIER\AppData\Local\Temp\bus9F6D.tmp
C:\Users\OLIVIER\AppData\Local\Temp\busB4E5
C:\Users\OLIVIER\AppData\Local\Temp\busB4E5.tmp
C:\Users\OLIVIER\AppData\Local\Temp\busBB74
C:\Users\OLIVIER\AppData\Local\Temp\busBB74.tmp
C:\Users\OLIVIER\AppData\Local\Temp\busBC72
C:\Users\OLIVIER\AppData\Local\Temp\busBC72.tmp
C:\Users\OLIVIER\AppData\Local\Temp\busBC8F
C:\Users\OLIVIER\AppData\Local\Temp\busBC8F.tmp
C:\Users\OLIVIER\AppData\Local\Temp\busD7A9
C:\Users\OLIVIER\AppData\Local\Temp\busD7A9.tmp
C:\Users\OLIVIER\AppData\Local\Temp\busDAE4
C:\Users\OLIVIER\AppData\Local\Temp\busDAE4.tmp
C:\Users\OLIVIER\AppData\Local\Temp\busE885
C:\Users\OLIVIER\AppData\Local\Temp\busE885.tmp
C:\Users\OLIVIER\AppData\Local\Temp\busEB07
C:\Users\OLIVIER\AppData\Local\Temp\busEB07.tmp
C:\Users\OLIVIER\AppData\Local\Temp\busEF7
C:\Users\OLIVIER\AppData\Local\Temp\busEF7.tmp
C:\Users\OLIVIER\AppData\Local\Temp\busEF87
C:\Users\OLIVIER\AppData\Local\Temp\busEF87.tmp
C:\Users\OLIVIER\AppData\Local\Temp\busFD19
C:\Users\OLIVIER\AppData\Local\Temp\busFD19.tmp
C:\Users\OLIVIER\AppData\Local\Temp\C211.tmp
C:\Users\OLIVIER\AppData\Local\Temp\C27B.tmp
C:\Users\OLIVIER\AppData\Local\Temp\C4A7E483-847E-4117-9A54-7A34625DF96F.Diagnose.Admin.0.etl
C:\Users\OLIVIER\AppData\Local\Temp\C5BE.tmp
C:\Users\OLIVIER\AppData\Local\Temp\C76F.tmp
C:\Users\OLIVIER\AppData\Local\Temp\C7EC.tmp
C:\Users\OLIVIER\AppData\Local\Temp\C894.tmp
C:\Users\OLIVIER\AppData\Local\Temp\C90E.tmp
C:\Users\OLIVIER\AppData\Local\Temp\CFG392.tmp
C:\Users\OLIVIER\AppData\Local\Temp\Cleaning.ico
C:\Users\OLIVIER\AppData\Local\Temp\cm3qbcme.tmp
C:\Users\OLIVIER\AppData\Local\Temp\connect_result.log
C:\Users\OLIVIER\AppData\Local\Temp\CRX_75DAF8CB7768
C:\Users\OLIVIER\AppData\Local\Temp\CRX_DF399A9B283A
C:\Users\OLIVIER\AppData\Local\Temp\cvfra3ip.tmp
C:\Users\OLIVIER\AppData\Local\Temp\CVRA71C.tmp.cvr
C:\Users\OLIVIER\AppData\Local\Temp\D0F2.tmp
C:\Users\OLIVIER\AppData\Local\Temp\D31D.tmp
C:\Users\OLIVIER\AppData\Local\Temp\D4E0.tmp
C:\Users\OLIVIER\AppData\Local\Temp\D522.tmp
C:\Users\OLIVIER\AppData\Local\Temp\D605.tmp
C:\Users\OLIVIER\AppData\Local\Temp\D61.tmp
C:\Users\OLIVIER\AppData\Local\Temp\D67B.tmp
C:\Users\OLIVIER\AppData\Local\Temp\D74E.tmp
C:\Users\OLIVIER\AppData\Local\Temp\D94CB95F.TMP
C:\Users\OLIVIER\AppData\Local\Temp\dat6484.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat6495.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat6496.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat64A7.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat64B7.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat64C8.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat64D8.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat6A.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat6D84.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat6D85.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat6D95.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat6D96.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat6DA7.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat6DE6.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat6DF7.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat7B.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat7C.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat872E.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat8739.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat873E.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat874A.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat874B.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat874F.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat875F.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat8770.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat8781.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat87B0.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat8D.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat9603.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat9613.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat9624.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat9634.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat9645.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat9646.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat9657.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat9D.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dat9E.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datAF.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datamngr.dll.318557146
C:\Users\OLIVIER\AppData\Local\Temp\datB5B3.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datB5C3.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datB5D4.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datB5D5.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datB5E6.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datB5F6.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datB607.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datBE13.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datBE24.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datBE34.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datBE35.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datBE46.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datBE56.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datBE57.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datE91E.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datE93E.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datE94F.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datE95F.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datE960.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datE981.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datE991.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datEB96.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datEBA6.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datEBE6.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datEBF6.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datEBF7.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datEC46.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datEC57.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datF193.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datF1B3.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datF1C4.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datF1F4.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datF204.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datF215.tmp
C:\Users\OLIVIER\AppData\Local\Temp\datF225.tmp
C:\Users\OLIVIER\AppData\Local\Temp\DBAA.tmp
C:\Users\OLIVIER\AppData\Local\Temp\DBED.tmp
C:\Users\OLIVIER\AppData\Local\Temp\dd_vstor40_x64MSI47EC.txt
C:\Users\OLIVIER\AppData\Local\Temp\dd_vstor40_x64UI47EC.txt
C:\Users\OLIVIER\AppData\Local\Temp\DE0E.tmp
C:\Users\OLIVIER\AppData\Local\Temp\default-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\DF28.tmp
C:\Users\OLIVIER\AppData\Local\Temp\DMI132A.tmp
C:\Users\OLIVIER\AppData\Local\Temp\DMI1479.tmp
C:\Users\OLIVIER\AppData\Local\Temp\DMI264C.tmp
C:\Users\OLIVIER\AppData\Local\Temp\DMI271C.tmp
C:\Users\OLIVIER\AppData\Local\Temp\DMI2BBD.tmp
C:\Users\OLIVIER\AppData\Local\Temp\DMI2FC8.tmp
C:\Users\OLIVIER\AppData\Local\Temp\DMI34B6.tmp
C:\Users\OLIVIER\AppData\Local\Temp\DMI62B5.tmp
C:\Users\OLIVIER\AppData\Local\Temp\DMIC7DD.tmp
C:\Users\OLIVIER\AppData\Local\Temp\DMIFDBF.tmp
C:\Users\OLIVIER\AppData\Local\Temp\Donate.ico
C:\Users\OLIVIER\AppData\Local\Temp\E1F0.tmp
C:\Users\OLIVIER\AppData\Local\Temp\E2BF.tmp
C:\Users\OLIVIER\AppData\Local\Temp\e4jC9E8.tmp_dir6323
C:\Users\OLIVIER\AppData\Local\Temp\e4jECCE.tmp_dir25040
C:\Users\OLIVIER\AppData\Local\Temp\E79A.tmp
C:\Users\OLIVIER\AppData\Local\Temp\E8F6.tmp
C:\Users\OLIVIER\AppData\Local\Temp\E91A.tmp
C:\Users\OLIVIER\AppData\Local\Temp\EAB9.tmp
C:\Users\OLIVIER\AppData\Local\Temp\Easy Photo Print2EPQuicker.log
C:\Users\OLIVIER\AppData\Local\Temp\EBBF.tmp
C:\Users\OLIVIER\AppData\Local\Temp\EFA4.tmp
C:\Users\OLIVIER\AppData\Local\Temp\error.dmp
C:\Users\OLIVIER\AppData\Local\Temp\error.log
C:\Users\OLIVIER\AppData\Local\Temp\ev_1191362-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\ev_1218703-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\ev_1242364-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\ev_1463831-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\ez4ty3w2.tmp
C:\Users\OLIVIER\AppData\Local\Temp\E_S3147.tmp
C:\Users\OLIVIER\AppData\Local\Temp\E_SBA90.tmp
C:\Users\OLIVIER\AppData\Local\Temp\E_SF719.tmp
C:\Users\OLIVIER\AppData\Local\Temp\F48B.tmp
C:\Users\OLIVIER\AppData\Local\Temp\F99A.tmp
C:\Users\OLIVIER\AppData\Local\Temp\FEA7.tmp
C:\Users\OLIVIER\AppData\Local\Temp\FFF5.tmp
C:\Users\OLIVIER\AppData\Local\Temp\flaD2A9.tmp
C:\Users\OLIVIER\AppData\Local\Temp\flaDE94.tmp
C:\Users\OLIVIER\AppData\Local\Temp\FXSTIFFDebugLogFile.txt
C:\Users\OLIVIER\AppData\Local\Temp\g5jhzgv0.tmp
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(201302081623401AE0).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(2013051010022619FC).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(2013051416452322B0).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(20130515071006788).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(20130915100940199C).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(2013091510173020C8).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(201309151024392964).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(201310210852001F9C).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(2013102108560127BC).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(201310310851516A7C).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(201311041559385D4).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(2013110510403932D4).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(20131107140341F6C).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(201311191032532CB0).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(20131119103602326C).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(201311191057471804).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(201311191104282594).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(2013111911095010F8).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(2013111911273317D8).log
C:\Users\OLIVIER\AppData\Local\Temp\GimmeSetup(201311191150465C4).log
C:\Users\OLIVIER\AppData\Local\Temp\go9876.html
C:\Users\OLIVIER\AppData\Local\Temp\Google Toolbar
C:\Users\OLIVIER\AppData\Local\Temp\GoogleToolbarInstaller1.log
C:\Users\OLIVIER\AppData\Local\Temp\GoogleToolbarInstaller2.log
C:\Users\OLIVIER\AppData\Local\Temp\gyz1g0f6.tmp
C:\Users\OLIVIER\AppData\Local\Temp\hc9v1hgt.tmp
C:\Users\OLIVIER\AppData\Local\Temp\HomeGroupUser$.bmp
C:\Users\OLIVIER\AppData\Local\Temp\hsperfdata_OLIVIER
C:\Users\OLIVIER\AppData\Local\Temp\i4j4228186112154286186.tmp
C:\Users\OLIVIER\AppData\Local\Temp\ibtmp7c69303
C:\Users\OLIVIER\AppData\Local\Temp\ibtmp92fd302
C:\Users\OLIVIER\AppData\Local\Temp\ibtmp94d3285
C:\Users\OLIVIER\AppData\Local\Temp\ibtmpa27e462
C:\Users\OLIVIER\AppData\Local\Temp\ibtmpc2f8301
C:\Users\OLIVIER\AppData\Local\Temp\ibtmpdd36304
C:\Users\OLIVIER\AppData\Local\Temp\ic3tjlqg.tmp
C:\Users\OLIVIER\AppData\Local\Temp\iiuninst.exe
C:\Users\OLIVIER\AppData\Local\Temp\ijuzgv95.tmp
C:\Users\OLIVIER\AppData\Local\Temp\install.log
C:\Users\OLIVIER\AppData\Local\Temp\Installhelper.dll
C:\Users\OLIVIER\AppData\Local\Temp\Invité.bmp
C:\Users\OLIVIER\AppData\Local\Temp\is1373634743
C:\Users\OLIVIER\AppData\Local\Temp\is1668783924
C:\Users\OLIVIER\AppData\Local\Temp\is256538528
C:\Users\OLIVIER\AppData\Local\Temp\iSa4A4A.tmp
C:\Users\OLIVIER\AppData\Local\Temp\iSaD2BA.tmp
C:\Users\OLIVIER\AppData\Local\Temp\jar_cache1964487704287109564.tmp
C:\Users\OLIVIER\AppData\Local\Temp\JAUReg.log
C:\Users\OLIVIER\AppData\Local\Temp\java_install.log
C:\Users\OLIVIER\AppData\Local\Temp\java_install_reg.log
C:\Users\OLIVIER\AppData\Local\Temp\java_install_sp.log
C:\Users\OLIVIER\AppData\Local\Temp\jawshtml.html
C:\Users\OLIVIER\AppData\Local\Temp\jinstall.cfg
C:\Users\OLIVIER\AppData\Local\Temp\jre-6u19-windows-i586-iftw-rv.exe
C:\Users\OLIVIER\AppData\Local\Temp\jre-6u21-windows-i586-iftw-rv.exe
C:\Users\OLIVIER\AppData\Local\Temp\jre-6u22-windows-i586-iftw-rv.exe
C:\Users\OLIVIER\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe
C:\Users\OLIVIER\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe
C:\Users\OLIVIER\AppData\Local\Temp\jre-6u39-windows-i586-iftw.exe
C:\Users\OLIVIER\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\OLIVIER\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\OLIVIER\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\OLIVIER\AppData\Local\Temp\JRT.txt
C:\Users\OLIVIER\AppData\Local\Temp\jusched.log
C:\Users\OLIVIER\AppData\Local\Temp\KB2461678_20110903_190145591-Microsoft .NET Framework 4 Client Profile FRA Language Pack-MSP1.txt
C:\Users\OLIVIER\AppData\Local\Temp\KB2461678_20110903_190145591-Microsoft .NET Framework 4 Client Profile-MSP0.txt
C:\Users\OLIVIER\AppData\Local\Temp\KB2461678_20110903_190145591.html
C:\Users\OLIVIER\AppData\Local\Temp\KiesInstall.Log
C:\Users\OLIVIER\AppData\Local\Temp\KiesLiveupdateTemp
C:\Users\OLIVIER\AppData\Local\Temp\KiesSilentUpdateAgent.log
C:\Users\OLIVIER\AppData\Local\Temp\LogMeInRemoteUser.bmp
C:\Users\OLIVIER\AppData\Local\Temp\logs
C:\Users\OLIVIER\AppData\Local\Temp\lunchbtn-1.jpg
C:\Users\OLIVIER\AppData\Local\Temp\lunchbtn-2.jpg
C:\Users\OLIVIER\AppData\Local\Temp\lunchbtn-3.jpg
C:\Users\OLIVIER\AppData\LocalLow\bearsharetoolbarguid
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\desktop.ini
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\Low\desktop.ini
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\Low\History.IE5
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\Low\History.IE5\container.dat
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\Low\History.IE5\desktop.ini
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\History.IE5\container.dat
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012013111820131125
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012013120220131209
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012013120920131216
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012013121720131218
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012013121820131219
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012013121920131220
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012013121920131220\container.dat
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012013121820131219\container.dat
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012013121720131218\container.dat
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012013120920131216\container.dat
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012013120220131209\container.dat
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\BatBrowse_iels
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Sqm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\PrivacIE\Low
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\ProgramData\Microsoft\Search Enhancement Pack\Search Box Extension
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\ProgramData\Microsoft\Search Enhancement Pack\Search Helper
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Sqm\iesqmdata0.sqm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Sqm\iesqmdata1.sqm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Sqm\iesqmdata2.sqm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Sqm\iesqmdata3.sqm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Sqm\iesqmdata4.sqm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Sqm\iesqmdata5.sqm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Sqm\iesqmdata6.sqm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Sqm\iesqmdata7.sqm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Sqm\iesqmdata8.sqm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\desktop.ini
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1QBYLGBQ
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\9MTE7OXF
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\container.dat
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\desktop.ini
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GRCUZ0JK
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PY5W9U5P
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PY5W9U5P\desktop.ini
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GRCUZ0JK\desktop.ini
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\9MTE7OXF\desktop.ini
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1QBYLGBQ\desktop.ini
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\4A72F430-B40C-4D36-A068-CE33ADA5ADF9.dat
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF0001.tmp
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF0002.tmp
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{6579F1C8-49E9-4963-9759-AB7CCAC967D8}.tmp
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{BB9B3AB7-9EF1-4F14-859F-2A9CBD58F71D}.tmp
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{EDEE83A8-3F75-4571-90F2-FEEA5DDF55CB}.tmp
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS0000.tmp
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS0001.tmp
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0440S6AI
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3GZN3BP4
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\400PUU3X
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5RVNTKDV
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\866BGOB1
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C56WBHXF
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\container.dat
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E178JMJ1
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HAF4IULZ
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HXHQFFZM
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I6HQFYPR
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KT1TDKIB
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NT8EVCCR
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O2OE2916
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OKIETGDP
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QXR8Y62V
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QYMD1F45
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V9BC1R9D
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VW6PY79R
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3CGXHEK
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\-aO_JnhitSs[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\-fcFjVZzv1m[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\-ppZ84nZkgy[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\01net-barre-flottante[1].css
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\02_table_espace_perso[1].css
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\02_table_identification[1].css
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\04_common_de[1].css
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\05888c121940302cc74773a8fdc2f511[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\06_print[1].css
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1076413_582668199_282837569_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1076856_1027808858_1345003374_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1085839_100002594535824_750528552_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1085919_100000867467699_316211049_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\11106[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1115819_100000921831222_370279446_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1116825_100005282644800_301935284_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1117275_1770388471_3183788_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1117920_609752657_963854242_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1117961_1253933144_176309566_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1118304_100001640861499_553411198_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1118305_667099329_1202984324_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1119054_551659768_477945767_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1119240_1428857509_775695625_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\11OAE6dPMcK[1].css
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1209819_350132835112651_1801550499_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1254011023@Top,Top1,Right,Position1,Position2,Position3,Position4,x01,x02,TopLeft[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1391636_10202222707908485_1367590968_a[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1440_900[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1440_900[2].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1456321925@x88[1].htm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1456321925@x95[1].htm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1456508_10152153066769017_414640310_n[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1471169_758557247504994_1024483652_n[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1475864_758557090838343_220842325_n[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1480549_10202151540944340_483002236_n[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1510800_689869584380280_1481102720_n[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1525166_758557154171670_575393310_n[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1526997_781643841861262_1761752942_n[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1553d4da21de2187[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\161671_100000481566152_639281698_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\172-51098458t[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\174079_1361216423_1390371530_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\174079_1361216423_1390371530_q[2].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\174476_1158278722_6630561_q[2].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\185661_10150103062413599_4146197_a[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\188029_411009519000619_1762900780_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\1ymuehES2GT[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\2011619376@x95[1].htm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\2013_06_26_CCM_system_test03_juillet13[1].gif
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\211489_1639323116_3946958_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\211518_616236482_1007930652_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\227s[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\261053_537372953_1052026168_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\273331_583804077_333056242_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\274299_100004758271382_1693690202_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\274936_631011527_1491635355_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\276058_100003026194698_1150347175_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\276380_598003372_222520696_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\276900_221589874536338_3825625_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\2sQDHOjfSsa[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\3-728x90_FR_HIVERN_2013[1].swf
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\308999_457206137684912_18525055_s[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\34055042-4ca78587s[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\34060910-4a3e0be6s[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\36469[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\371663_576895124_2091682488_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\3Nma3JOGQ-3[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\41372_1238280900_294839954_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\41472_1188550995_272_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\41627_703556472_2193_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\41661_1640325555_4084_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\4300ae64-546c-4bbe-9026-6779b3684fb8_32[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\4300ae64-546c-4bbe-9026-6779b3684fb9_18[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\4499[1].gif
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\45397ef5454ae6e682d49fff3e6ec047[1].htm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\468x60_manpower27086[1].gif
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\49151_1820564250_75_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\49217_1164384156_5583_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\49302_100003585043479_1237428809_q[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\4WSewcWboV8[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\5-banners-bg[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\5863689-52af0433t[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\5863698-52b092a7s[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\5c3f2ced0937fa14bbb011bc8087f94f[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\5Sgn-3WKnie[1].css
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\5vdmAFTChHH[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\635221973887556372_tree[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\69-4b5e3ee0s[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\6evVkCOGPlz[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\73-104-222[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\79jfpchNoD9[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\7CM4iHx2wqm[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\800000206960[1].gif
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\800000206960[2].gif
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\800000206960[3].gif
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\800000206960[4].gif
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\800000206960[5].gif
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\851564_539993092729178_1922155812_n[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\851564_605100996176091_564455213_n[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\851579_384013675036040_1524257448_n[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\9782100511778tiny[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\9782100525690tiny[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\98616-15[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\9aHbm0MBaJo[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\9IWDuu39Vw0[1].css
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\a37078527a34983a6fe994cc25edffa3[1].htm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\adBar[1].css
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\adks_NationZoom[1].exe
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\adperf_launch_1.0.0_scrambled[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\ads[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\ads[2].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\adtrk[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\adwcleaner_1[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\affich-29316054-virus-aidez-moi-s-il-vous-plait[1].htm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\ai[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\ajax-loaderForum[1].gif
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\animations_2g3XS0rRrCQcqjUAbWvw4w2[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\ANX_async_usersync[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\arc.xd[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\AudioPlayer_IbSj2ROBoiFlNpwTMGi7Ug2[1].css
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\ave3S-m6qr4jSZadbi-bnq[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\AXbdtQOFsWr[1].css
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\bba035bbf2d39cb56832aa0cb5eadaf8[1].htm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\bg-h2-carrousel-actu[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\bg_input[1].gif
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\bg_spinner[1].jpg
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\bg_whiteOpa50[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\blank[1].htm
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\bluemanmxl[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\blue_cube[1].gif
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\bl_typ10_midd[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\BoVxv34AKD4[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\BraILklg7c4[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\btn-more-games-origindark[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\btn_bandeau_back[1].gif
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\btn_donate_LG[1].gif
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\bundle-bundle_jquery_ui_adapte_head[1].css
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\buttons[1].png
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\B_600x300_1[1].gif
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\c0a_Ru1-lYrwgcvupVT3jTdFkw2[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\c3a_UrstjKT1QN8Wi3sp7mSbWA2[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\CA1S78LQ
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\CA6W1X9T
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\CA8C4E68
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\CA8Z0C1W
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\Candy[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\CAOHCG2Q
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\CAX939H2
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\cb=gapi[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\cb=gapi[2].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\cb=gapi[3].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\cb=gapi[4].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\cedexis[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\CFDKbxtNEGO[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\chat[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\cL0p8ezyTfT[1].css
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\clientstring[1].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\clientstring[2].js
C:\Users\OLIVIER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU6C1KCI\clientstring[3].js
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\- Black eyes peas - I gotta feeling.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\100NIKON.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\11F6F962-2A06-4CD7-B988-CB6F3B373CAF-1 - Copie.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\137___04.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\2013-06-28 11.04.23.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\28AD78D6-1767-4EAB-AF37-A81F4C523F0B.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\6677Game.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\Adh_telereg.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\AK000107.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\AK000108.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\AK000109.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\AK000110.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\AK000111.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\AK000113.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\AK000119.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\AK000126.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\AK000127.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\AK000130.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\app.config.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\arret de travail fevrier.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\Attestation-Vierge-a-imprimer---page-1.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\Attestation-Vierge-a-imprimer---page-2.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\AttestationCESU.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\atur ecole.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\black_ops_2_bg_by_bobbygfx-d5mv31w.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\Brouillo inscription chomage 4nov2013.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\Camera.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\cpam marie.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\devoir informatique Romain.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\Documents.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\download.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\démo skorpion.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\f arthur.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\Faune.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\free style dimanche.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\guide micr crèche.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\hip hop skorpion 2.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\hip hop skorpion.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\hoff 2013.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\Images.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\IMG_3000.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\IMG_3001.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\IMG_3009.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\index.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\justificatifs assedic.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\Kies.exe.config.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\Kies.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\LanguagePack.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\les clés hip hop.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\Les garçons.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\lettre envoyée mr Farhat rar du 03.05.13.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\lettre pole emploi.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\LifeFrame.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\MANUAL.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\MARSEILLAISE.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\mbam-log-2013-12-18 (07-43-22).lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\Melle Alves Marie Christine.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\Mes images.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\Netg.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\OLIVIER CV 2011.lnk
C:\Users\OLIVIER\AppData\Roaming\Microsoft\Windows\Recent\OLIVIER CV 2013.lnk
C:\Users\OLIVIER\
0
kaori64 Messages postés 75 Date d'inscription lundi 21 juillet 2008 Statut Membre Dernière intervention 29 décembre 2015
19 déc. 2013 à 08:04
pour delfix il me demande de l'ouvrir sur un programme ?!
0