Redirection vers http://208.115.196.187/fr/index.php
Fermé
wyattroux
Messages postés
3
Date d'inscription
dimanche 17 août 2014
Statut
Membre
Dernière intervention
21 août 2014
-
Modifié par wyattroux le 17/08/2014 à 17:56
lilidurhone Messages postés 43347 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 31 octobre 2024 - 21 août 2014 à 21:14
lilidurhone Messages postés 43347 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 31 octobre 2024 - 21 août 2014 à 21:14
A voir également:
- Atherossvc
- Protocole http - Guide
- Http //easywifi.config ✓ - Forum Réseau
- Windows 7 vers windows 10 - Accueil - Mise à jour
- Http //zh.ui.vmall.com/emotiondownload.php mod=restore - Forum Huawei
- Http //192.168.l.49.1 anycast setup - Forum WiFi
4 réponses
Salut,
On dirait un site (ta redirection) qui fait du reverse DNS, ou du cloud, pourquoi t'es redirigé? parce que le site sur lequel tu es a besoin de renseignements sur toi, ou veut les stocker...
"L'utilisateur de l'adresse IP 208.115.196.187 (187-196-115-208.static.reverse.lstn.net - Limestone Networks, Inc.) est situé à Dallas (United States - Texas). "
On dirait un site (ta redirection) qui fait du reverse DNS, ou du cloud, pourquoi t'es redirigé? parce que le site sur lequel tu es a besoin de renseignements sur toi, ou veut les stocker...
"L'utilisateur de l'adresse IP 208.115.196.187 (187-196-115-208.static.reverse.lstn.net - Limestone Networks, Inc.) est situé à Dallas (United States - Texas). "
lilidurhone
Messages postés
43347
Date d'inscription
lundi 25 avril 2011
Statut
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 807
21 août 2014 à 16:25
21 août 2014 à 16:25
On continue
* Télécharge ZHPDiag (de Nicolas Coolman)
https://nicolascoolman.eu ou https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/
* Au cas où le premier lien ne marcherai pas, clique sur celui de dessous
ftp://zebulon.fr/ZHPDiag2.exe
* Double clic si tu es sous windows xp(sinon clic droit afin de l'exécuter en tant qu'admin à partir de Vista)
* Laisse toi guider lors de l'installation, il se lancera automatiquement à la fin.
* Surtout, n'oublie pas d'installer son icône sur le bureau l'icône est en forme de parchemin
https://www.cjoint.com/13sp/CIvuQfap3YY_zhpdiag.png
* A l'ouverture du logiciel il te sera proposé 3 options "rechercher", "configurer" et complet
* Cliques sur "complet"
* Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
* Pour héberger le rapport, rends toi sur cjoint.com
* Clique sur choisissez un fichier va chercher le rapport dans ton PC.
* Le rapport est hébergé:
- Pour XP : C:\Documents and Settings\username\Local Settings\Application Data\ZHP
- Depuis Vista : C:\Users\username\AppData\Roaming\ZHP
* Une fois le rapport trouvé, sélectionne le, et clique sur Ouvrir
* Choisis le type de diffusion (illimitée ou 21 jours)
* Puis cliques sur créer le lien cjoint
* Une fois que tu auras obtenu le lien copies colle dans ta prochaine réponse
* Pour t'aider https://www.commentcamarche.net/faq/29493-utiliser-cjoint-pour-heberger-des-fichiers
* Télécharge ZHPDiag (de Nicolas Coolman)
https://nicolascoolman.eu ou https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/
* Au cas où le premier lien ne marcherai pas, clique sur celui de dessous
ftp://zebulon.fr/ZHPDiag2.exe
* Double clic si tu es sous windows xp(sinon clic droit afin de l'exécuter en tant qu'admin à partir de Vista)
* Laisse toi guider lors de l'installation, il se lancera automatiquement à la fin.
* Surtout, n'oublie pas d'installer son icône sur le bureau l'icône est en forme de parchemin
https://www.cjoint.com/13sp/CIvuQfap3YY_zhpdiag.png
* A l'ouverture du logiciel il te sera proposé 3 options "rechercher", "configurer" et complet
* Cliques sur "complet"
* Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
* Pour héberger le rapport, rends toi sur cjoint.com
* Clique sur choisissez un fichier va chercher le rapport dans ton PC.
* Le rapport est hébergé:
- Pour XP : C:\Documents and Settings\username\Local Settings\Application Data\ZHP
- Depuis Vista : C:\Users\username\AppData\Roaming\ZHP
* Une fois le rapport trouvé, sélectionne le, et clique sur Ouvrir
* Choisis le type de diffusion (illimitée ou 21 jours)
* Puis cliques sur créer le lien cjoint
* Une fois que tu auras obtenu le lien copies colle dans ta prochaine réponse
* Pour t'aider https://www.commentcamarche.net/faq/29493-utiliser-cjoint-pour-heberger-des-fichiers
wyattroux
Messages postés
3
Date d'inscription
dimanche 17 août 2014
Statut
Membre
Dernière intervention
21 août 2014
21 août 2014 à 17:08
21 août 2014 à 17:08
~ Rapport de ZHPDiag v2014.8.21.121 - Nicolas Coolman (21/08/2014)
~ Lancé par Alan R (21/08/2014 17:02:13)
~ Adresse du Site Web https://nicolascoolman.eu
~ Adresse du Forum https://nicolascoolman.eu
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Désactivée par l'utilisateur
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user
---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17239
GCIE: Google Chrome v36.0.1985.143 (Defaut)
---\\ Informations sur les produits Windows
~ Langage: Français
Windows 8.1, 64-bit (Build 9600)
Windows Server License Manager Script : OK
---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 2.0.2.1012
Windows Defender W8 (Activate)
---\\ Logiciels d'optimisation du système
CCleaner v4.09
---\\ Logiciels de partage PeerToPeer
---\\ Surveillance de Logiciels
Adobe Flash Player 14 Plugin
Java 7 Update 67
---\\ Informations sur le système
~ Processor: Intel64 Family 6 Model 55 Stepping 3, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3979 MB (42% free)
System Restore: Activé (Enable)
System drive C: has 653 GB (95%) free of 687 GB
---\\ Mode de connexion au système
~ Computer Name: ALAN
~ User Name: Alan R
~ All Users Names: Alan R, Administrateur,
~ Unselected Option: None
Logged in as Administrator
---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Alan R\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Alan R\AppData\Roaming\
~ %Desktop% : C:\Users\Alan R\Desktop\
~ %Favorites% : C:\Users\Alan R\Favorites\
~ %LocalAppData% : C:\Users\Alan R\AppData\Local\
~ %StartMenu% : C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 653 Go of 687 Go)
D: CD-ROM drive (Not Inserted)
---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: 41 Scanned in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.81394C91B7B5A7C799E249AE82491F13] - (.Microsoft Corporation - Explorateur Windows.) (.04/03/2014 - 13:25:49.) -- C:\Windows\Explorer.exe [2373784]
[MD5.48CFA7BE561A7BE144C29BB912055016] - (.Microsoft Corporation - Application de démarrage de Windows.) (.22/08/2013 - 10:58:29.) -- C:\Windows\System32\Wininit.exe [144384]
[MD5.8E71A5CB5312B8392D4DA4CA37BB5868] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.25/07/2014 - 11:52:06.) -- C:\Windows\System32\wininet.dll [2266624]
[MD5.306EB21E5B480AE9065EA55AC8C35936] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.22/02/2014 - 10:45:48.) -- C:\Windows\System32\Winlogon.exe [562176]
[MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - (.Microsoft Corporation - Bibliothèque de licences.) (.21/12/2013 - 09:54:07.) -- C:\Windows\System32\sppcomapi.dll [447488]
[MD5.374E27295F0A9DCAA8FC96370F9BEEA5] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.30/05/2014 - 04:03:03.) -- C:\Windows\system32\Drivers\AFD.sys [563200]
[MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.22/08/2013 - 13:43:41.) -- C:\Windows\system32\Drivers\atapi.sys [26464]
[MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) (.22/08/2013 - 12:40:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [88576]
[MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.22/08/2013 - 09:46:35.) -- C:\Windows\system32\Drivers\Cdrom.sys [164352]
[MD5.A03F362C5557E238CBFA914689C77248] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.06/03/2014 - 10:22:50.) -- C:\Windows\system32\Drivers\DfsC.sys [134144]
[MD5.498288DD5CA42C2D36D125893E968C53] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.18/03/2014 - 09:19:14.) -- C:\Windows\system32\Drivers\HDAudBus.sys [77312]
[MD5.84CFC5EFA97D0C965EDE1D56F116A541] - (.Microsoft Corporation - Pilote de port i8042.) (.22/08/2013 - 12:39:15.) -- C:\Windows\system32\Drivers\i8042prt.sys [107520]
[MD5.B7342B3C58E91107F6E946A93D9D4EFD] - (.Microsoft Corporation - IP Network Address Translator.) (.27/11/2013 - 13:02:29.) -- C:\Windows\system32\Drivers\IpNat.sys [142848]
[MD5.7A1A3F213CDB3363D179D5014272025D] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.30/04/2014 - 07:41:46.) -- C:\Windows\system32\Drivers\MRxSmb.sys [402432]
[MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) (.22/08/2013 - 12:37:02.) -- C:\Windows\system32\Drivers\netBT.sys [282624]
[MD5.1C80517BE6836A812F6A9B99B8321351] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.20/03/2014 - 04:41:24.) -- C:\Windows\system32\Drivers\ntfs.sys [2013016]
[MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Pilote de port parallèle.) (.22/08/2013 - 12:40:02.) -- C:\Windows\system32\Drivers\Parport.sys [94208]
[MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.22/08/2013 - 12:35:51.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [120832]
[MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.22/08/2013 - 20:12:11.) -- C:\Windows\system32\Drivers\rdpdr.sys [195584]
[MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) (.22/08/2013 - 14:25:35.) -- C:\Windows\system32\Drivers\tdx.sys [107520]
[MD5.4BB9BC49DEE1A319EC58274A7BBED663] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.06/03/2014 - 13:42:44.) -- C:\Windows\system32\Drivers\volsnap.sys [310616]
~ Generic Processes: Scanned in 00mn 00s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/371
~ Mes musiques (My Musics) : 1/23
~ Mes Videos (My Videos) : 1/2
~ Mes Favoris (My Favorites) : 1/4
~ Mes Documents (My Documents) : 1/16
~ Mon Bureau (My Desktop) : 1/6
~ Menu demarrer (Programs) : 1/24
~ Hidden Files: Scanned in 00mn 00s
---\\ Processus lancés
[MD5.4FBC630768570E6AC35C3DE8F6EC79F5] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe [6970168] [PID.2416]
[MD5.308F2EE28005510DE616409148CF077B] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896] [PID.3168]
[MD5.0BDAE865738D27A4D84D50591C8C9D2D] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [860488] [PID.1844]
[MD5.8DF7F2A9B72B7CA4294BB9E59FEAEFCD] - (.Microsoft Corporation - Hôte Microsoft WWA.) -- C:\Windows\syswow64\wwahost.exe [514560] [PID.1488]
[MD5.9D506DEFE177A7A4B4C88977A2FA735B] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8094720] [PID.3416]
~ Processes Running: Scanned in 00mn 02s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Alan R\AppData\Local\Google\Chrome\User Data\Default\Preferences
G0 - GCSP: Preference [User Data\Default][HomePage] https://www.google.com/?gws_rd=ssl
G2 - GCE: Preference [User Data\Default] [ahfgeienlihckogmohjhadlkjgocpleb] Google Store v.0.2 (Activé)
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Docs v.0.7 (Activé)
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Drive v.6.3 (Activé)
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] YouTube v.4.2.6 (Activé)
G2 - GCE: Preference [User Data\Default] [booedmolknjekdopkepjjeckmjkdpfgl] Extutil v.0.1 (Activé) =>PUP.Manager
G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Recherche Google v.0.0.0.20 (Activé)
G2 - GCE: Preference [User Data\Default] [eemcgdkfndhakfknompkggombfjjjeno] Bookmark Manager v.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [ennkphjdgehloodpbhlhldgbnhmacadg] Settings v.0.2 (Activé)
G2 - GCE: Preference [User Data\Default] [flpcjncodpafbgdpnkljologafpionhb] Managera v.0.1 (Activé) =>PUP.Manager
G2 - GCE: Preference [User Data\Default] [gfdkimpbcpahaombhbimeihdjnejgicl] Feedback v.1.0 (Activé)
G2 - GCE: Preference [User Data\Default] [kmendfapggjehodndflmmgagdbamhnfd] CryptoTokenExtension v.0.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [mfehgcgbbipciphmccgaenjidiccnmng] Cloud Print v.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [mfffpogegjflfpflabcdkioaeobkgjik] GaiaAuthExtension v.0.0.1, (Activé)
G2 - GCE: Preference [User Data\Default] [mgndgikekgjfcpckkfioiadnlibdjbkf] Chrome v.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [neajdppkdcdipfabeoofebfddakdcjhd] Google Network Speech v.1.0 (Activé)
G2 - GCE: Preference [User Data\Default] [nkeimhogjdpnpccoofpliimaahmaaome] Google+ Hangouts v.1.0 (Activé)
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.6.1 (Activé)
G2 - GCE: Preference [User Data\Default] [pafkbggdmjlpgkdkcbjmhmfcdpncadgh] Google Now v.1.2.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Gmail v.7 (Activé)
---\\ Liste des dossiers d'extension Google Chrome
G2 - EXT: C:\Users\Alan R\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [Google Docs]
G2 - EXT: C:\Users\Alan R\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [Google Drive]
G2 - EXT: C:\Users\Alan R\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [YouTube]
G2 - EXT: C:\Users\Alan R\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [Recherche Google]
G2 - EXT: C:\Users\Alan R\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [Google Wallet]
G2 - EXT: C:\Users\Alan R\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [Gmail]
~ Google Lines Browser: 26 Scanned in 00mn 03s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Alan R\AppData\Roaming\Mozilla\Firefox\Profiles\zb16lrul.default\prefs.js
M2 - MFEP: RegExtension {9A3B7448-C8A3-4EF3-C7D8-33FEA5854401} . (...) -- C:\Program Files (x86)\ver3BlockAndSurf\176.xpi (.not file.) =>PUP.BlockAndSurf
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll
P2 - FPN: [HKLM] [@Skype Technologies S.A..com/Skype Web Plugin] - (.Skype - Skype Web Plugin.) -- C:\Program Files (x86)\SkypeWebPlugin\3.1.15602.22612\npSkypeWebPlugin64.dll
~ Firefox Browser: 3 Scanned in 00mn 00s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.microsoft.com/fr-fr/
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = https://www.microsoft.com/fr-fr/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = www.google.com
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.9600.17239 (winblue_gdr.140724-2228)) -- C:\Windows\SysWOW64\ieframe.dll
~ IE Browser: 21 Scanned in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <-loopback> =>Hijacker.Proxy
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
~ BHO: 2 Scanned in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: (no name) - [HKLM]{ae07101b-46d4-4a98-af68-0333ea26e113} Clé orpheline
~ Toolbar: Scanned in 00mn 00s
---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [TSSSrv] . (.TOSHIBA Corporation - TOSHIBA System Settings Service.) -- C:\Program Files (x86)\TOSHIBA\System Setting\TSSSrv.exe
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_2A41EE48AB66A3CA09992BE89156F815] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - HKLM\..\Wow6432Node\Run: [AnyProtect Scanner] C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe (.not file.) =>PUP.AnyProtect
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle Corporation
O4 - HKUS\S-1-5-21-1709042038-2155373347-2631235414-1001\..\Run: [GoogleChromeAutoLaunch_2A41EE48AB66A3CA09992BE89156F815] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
~ Application: Scanned in 00mn 00s
---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ IE Control Panel: 1 Scanned in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
~ Winsock: 7 Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{73165873-0C06-44F6-BEB5-65CC1F5998A9}: DhcpNameServer = 89.2.0.1 89.2.0.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{73165873-0C06-44F6-BEB5-65CC1F5998A9}: DhcpNameServer = 89.2.0.1 89.2.0.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.2.0.1 89.2.0.2
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s
---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ SSODL: 1 Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: AtherosSvc (AtherosSvc) . (.Windows (R) Win 7 DDK provider - Windows Setup API.) - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: DTS APO Service (dts_apo_service) . (.Pas de propriétaire - dts_apo_service.) - C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc
O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) . (.TOSHIBA Corporation - TDCSrv Application.) - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA eco Utility Service (TOSHIBA eco Utility Service) . (.Toshiba Corporation - TOSHIBA eco Utility Service.) - C:\Program Files\TOSHIBA\Teco\TecoService.exe =>.Toshiba Corporation
~ Services: 8 Scanned in 00mn 10s
---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Desktop Component: 4 Scanned in 00mn 00s
---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
[MD5.F4BF3ADDDDC1AD372604F13C2B0C1F65] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [262320]
[MD5.00000000000000000000000000000000] [APT] [APSnotifierPP1] (...) -- C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe (.not file.) [0] =>PUP.AnyProtect
[MD5.00000000000000000000000000000000] [APT] [APSnotifierPP2] (...) -- C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe (.not file.) [0] =>PUP.AnyProtect
[MD5.00000000000000000000000000000000] [APT] [APSnotifierPP3] (...) -- C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe (.not file.) [0] =>PUP.AnyProtect
[MD5.E7CDBC01674477840A64965E784374DE] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [4370712]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
[MD5.16438B000BF56F2CD7FDB5E6C3B38C7E] [APT] [RTKCPL] (.Realtek Semiconductor.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13662936]
[MD5.C930517BBE90227EA16158C85E7C2865] [APT] [Synaptics TouchPad Enhancements] (.Synaptics Incorporated.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2778864]
[MD5.1608D54DC69EA7E763CDAB78F71CAFD6] [APT] [{EDA56F95-E691-40F5-9B9B-A74629DB6F03}] (.Skytech Co., Ltd..) -- C:\Users\Alan R\AppData\Roaming\sweet-page\UninstallManager.exe [1856512] =>PUP.SweetPage
[MD5.C6B8CB65A3AACABB00F3DAA371C46A3E] [APT] [CommonNotifier] (.Toshiba Europe GmbH.) -- C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [471416]
[MD5.6F8B977DD7511F96038CA4092FC7DE36] [APT] [HotKeysCmds] (.Intel Corporation.) -- C:\Windows\system32\hkcmd.exe [771056]
[MD5.1D18ACD429C734FAEA288DDCB38F94AF] [APT] [IgfxTray] (.Intel Corporation.) -- C:\Windows\system32\igfxtray.exe [391152]
[MD5.4E545DE0671C1BD788E9975950EB2D18] [APT] [Persistence] (.Intel Corporation.) -- C:\Windows\system32\igfxpers.exe [770032]
[MD5.C14294B90DD5C44D584F60884007ED59] [APT] [Service Station] (.TOSHIBA Corporation.) -- C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [699496]
[MD5.63D9BB372FAD1C9C35FE07F28E2B6D17] [APT] [TCrdMain] (.TOSHIBA Corporation.) -- C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2556768]
[MD5.002D52AEB2D5CD250910F366C2AECFC5] [APT] [TecoResident] (.TOSHIBA Corporation.) -- C:\Program Files\TOSHIBA\Teco\TecoResident.exe [179040]
[MD5.FA43294F64D95AEF875B796582BB7D2F] [APT] [TosWaitSrv] (.TOSHIBA Corporation.) -- C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [354144]
[MD5.18DBA177BD009B91D1884C9DB62BB039] [APT] [TSVU] (.TOSHIBA.) -- c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [516512]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: APSnotifierPP1 - (...) -- C:\Windows\Tasks\APSnotifierPP1.job [378] =>PUP.AnyProtect
O39 - APT: APSnotifierPP1 - (...) -- C:\Windows\System32\Tasks\APSnotifierPP1 [378] =>PUP.AnyProtect
O39 - APT: APSnotifierPP2 - (...) -- C:\Windows\Tasks\APSnotifierPP2.job [376] =>PUP.AnyProtect
O39 - APT: APSnotifierPP2 - (...) -- C:\Windows\System32\Tasks\APSnotifierPP2 [376] =>PUP.AnyProtect
O39 - APT: APSnotifierPP3 - (...) -- C:\Windows\Tasks\APSnotifierPP3.job [376] =>PUP.AnyProtect
O39 - APT: APSnotifierPP3 - (...) -- C:\Windows\System32\Tasks\APSnotifierPP3 [376] =>PUP.AnyProtect
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1074]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1074]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1078]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1078]
~ Scheduled Task: 26 Scanned in 00mn 14s
---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Browsing Enhancements [64Bits] - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Windows Desktop Update [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll
~ Active Setup: 9 Scanned in 00mn 00s
---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: C:\Windows\System32\drivers\ahcache.sys (ahcache) . (.Microsoft Corporation - Application Compatibility Cache.) - C:\Windows\System32\DRIVERS\ahcache.sys
O41 - Driver: (BasicDisplay) . (.Microsoft Corporation - Microsoft Basic Display Driver.) - C:\Windows\system32\drivers\BasicDisplay.sys
O41 - Driver: (BasicRender) . (.Microsoft Corporation - Microsoft Basic Render Driver.) - C:\Windows\system32\drivers\BasicRender.sys
O41 - Driver: cdrom.inf (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\drivers\cdrom.sys
O41 - Driver: C:\Windows\System32\drivers\dam.sys (dam) . (.Microsoft Corporation - DAM Kernel Driver.) - C:\Windows\System32\drivers\dam.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (Dfsc) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: mssmbios.inf (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
O41 - Driver: netnb.inf (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: npsvctrig.inf (npsvctrig) . (.Microsoft Corporation - Named pipe service triggers.) - C:\Windows\system32\drivers\npsvctrig.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\system32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\system32\DRIVERS\tdx.sys
O41 - Driver: C:\Windows\System32\drivers\vwififlt.sys (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\system32\DRIVERS\vwififlt.sys
~ Drivers: 32 Scanned in 00mn 00s
---\\ Logiciels installés (O42)
O42 - Logiciel: Adobe Flash Player 14 Plugin - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player Plugin
O42 - Logiciel: Atheros Driver Installation Program - (.Atheros.) [HKLM][64Bits] -- {C3A32068-8AB1-4327-BB16-BED9C6219DC7}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner
O42 - Logiciel: DTS Sound - (.DTS, Inc..) [HKLM][64Bits] -- {2C7A5AF4-1793-4B5A-89C0-021FB198EDE8}
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
O42 - Logiciel: Intel(R) Trusted Execution Engine - (.Intel Corporation.) [HKLM][64Bits] -- {176E2755-0A17-42C6-88E2-192AB2131278}
O42 - Logiciel: Intel(R) Trusted Execution Engine - (.Intel Corporation.) [HKLM][64Bits] -- {BCCACFE6-91A0-4F32-80A0-ADC0CA048C7B}
O42 - Logiciel: Intel(R) Trusted Execution Engine Driver - (.Intel Corporation.) [HKLM][64Bits] -- {3685B5E8-A0A8-494B-B035-B221547A4B63}
O42 - Logiciel: Java 7 Update 67 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F03217067FF}
O42 - Logiciel: LG PC Suite - (.LG Electronics.) [HKLM][64Bits] -- LG PC Suite
O42 - Logiciel: LG United Mobile Driver - (.LG Electronics.) [HKLM][64Bits] -- {2A3A4BD6-6CE0-4e2a-80D2-1D0FF6ACBFBA}
O42 - Logiciel: Malwarebytes Anti-Malware version 2.0.2.1012 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes Anti-Malware_is1
O42 - Logiciel: OpenOffice 4.1.0 - (.Apache Software Foundation.) [HKLM][64Bits] -- {B3B009FC-6909-4E00-9F43-FFB5CA93D606}
O42 - Logiciel: Qualcomm Atheros Bluetooth Suite (64) - (.Qualcomm Atheros.) [HKLM][64Bits] -- {A84A4FB1-D703-48DB-89E0-68B6499D2801}
O42 - Logiciel: Realtek Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {5BC2B5AB-80DE-4E83-B8CF-426902051D0A}
O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476}
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: Skype Web Plugin - (.Skype Technologies S.A..) [HKLM][64Bits] -- {69F300CB-D6BF-41DD-B7CC-983BAFF4EE15}
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey
O42 - Logiciel: TOSHIBA Desktop Assist - (.Toshiba Corporation.) [HKLM][64Bits] -- {C4CDCEF0-0A7A-4425-887C-33E39533D758}
O42 - Logiciel: TOSHIBA Display Utility - (.Toshiba Corporation.) [HKLM][64Bits] -- {5F6AC07E-50EF-422E-B56E-6521E5B35139}
O42 - Logiciel: TOSHIBA Function Key - (.Toshiba Corporation.) [HKLM][64Bits] -- {1844CFE2-EBA3-490A-8A5E-9BFC646342FD}
O42 - Logiciel: TOSHIBA Manuals - (.TOSHIBA.) [HKLM][64Bits] -- {90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}
O42 - Logiciel: TOSHIBA PC Health Monitor - (.Toshiba Corporation.) [HKLM][64Bits] -- {9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}
O42 - Logiciel: TOSHIBA Password Utility - (.Toshiba Corporation.) [HKLM][64Bits] -- {2DB90351-FBAA-472B-9F12-6E1EBBB354DE}
O42 - Logiciel: TOSHIBA Recovery Media Creator - (.Toshiba Corporation.) [HKLM][64Bits] -- {B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}
O42 - Logiciel: TOSHIBA Service Station - (.Toshiba Corporation.) [HKLM][64Bits] -- {BFE4C813-4DD4-4B1C-97F4-76A459055C8D} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Start Screen Option - (.Toshiba Corporation.) [HKLM][64Bits] -- {06B71035-F19F-4F76-9875-FFCCD4FC3F83}
O42 - Logiciel: TOSHIBA System Driver - (.Toshiba Corporation.) [HKLM][64Bits] -- {1E6A96A1-2BAB-43EF-8087-30437593C66C}
O42 - Logiciel: TOSHIBA System Settings - (.Toshiba Corporation.) [HKLM][64Bits] -- {4D57ED72-6B01-40BD-9CA9-012B8FC09CEB}
O42 - Logiciel: TOSHIBA VIDEO PLAYER - (.Toshiba Corporation.) [HKLM][64Bits] -- {FF07604E-C860-40E9-A230-E37FA41F103A}
O42 - Logiciel: TOSHIBA eco Utility - (.Toshiba Corporation.) [HKLM][64Bits] -- {94D2A899-0C34-4420-880E-AE337E635AB0} =>.Toshiba Corporation
O42 - Logiciel: Toshiba TEMPRO - (.Toshiba Europe GmbH.) [HKLM][64Bits] -- {F76F5214-83A8-4030-80C9-1EF57391D72A} =>.Toshiba Corporation
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
O42 - Logiciel: WinRAR 5.10 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver
~ Logic: 36 Scanned in 00mn 00s
---\\ HKCU & HKLM Software Keys
[HKCU\Software\AnyProtect] =>PUP.AnyProtect
[HKCU\Software\AppDataLow\Software\JavaSoft]
[HKCU\Software\AppDataLow]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\Emulators]
[HKCU\Software\Google]
[HKCU\Software\Intel]
[HKCU\Software\JavaSoft]
[HKCU\Software\LG Electronics]
[HKCU\Software\Licenses]
[HKCU\Software\Linkey] =>PUP.LinkeySearch
[HKCU\Software\LowRegistry]
[HKCU\Software\Macromedia]
[HKCU\Software\Mine]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Nosibay]
[HKCU\Software\OB]
[HKCU\Software\OpenOffice]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\Realtek]
[HKCU\Software\RegisteredApplications]
[HKCU\Software\Softonic] =>Toolbar.Conduit
[HKCU\Software\Store] =>PUP.Nosibay
[HKCU\Software\Synaptics]
[HKCU\Software\TeleCharger]
[HKCU\Software\Toshiba]
[HKCU\Software\Trolltech]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\Wow6432Node]
[HKCU\Software\ZebHelpProcess Helper]
[HKCU\Software\systweak]
[HKLM\Software\Atheros]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\DTS]
[HKLM\Software\Dolby]
[HKLM\Software\InstalledOptions]
[HKLM\Software\IntelVolatile]
[HKLM\Software\Intel]
[HKLM\Software\Khronos]
[HKLM\Software\Knowles]
[HKLM\Software\Macromedia]
[HKLM\Software\McAfee.com]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Nahimic]
[HKLM\Software\Nuance]
[HKLM\Software\ODBC]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\RTLSetup]
[HKLM\Software\Realtek]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\SRS Labs]
[HKLM\Software\Skype]
[HKLM\Software\SonicFocus]
[HKLM\Software\Synaptics]
[HKLM\Software\ToshibaBlobDelivery]
[HKLM\Software\Toshiba]
[HKLM\Software\Waves Audio]
[HKLM\Software\WinRAR]
[HKLM\Software\Wow6432Node\009f6c92-c8da-46f6-9ff4-ed570730d70a]
[HKLM\Software\Wow6432Node\9aad41c0-9453-4b6c-9eeb-545c4f6f19b8]
[HKLM\Software\Wow6432Node\Atheros]
[HKLM\Software\Wow6432Node\Classes]
[HKLM\Software\Wow6432Node\Clients]
[HKLM\Software\Wow6432Node\DTS, Inc.]
[HKLM\Software\Wow6432Node\DTS]
[HKLM\Software\Wow6432Node\GlobalUpdate]
[HKLM\Software\Wow6432Node\Google]
[HKLM\Software\Wow6432Node\Intel]
[HKLM\Software\Wow6432Node\JavaSoft]
[HKLM\Software\Wow6432Node\JreMetrics]
[HKLM\Software\Wow6432Node\Khronos]
[HKLM\Software\Wow6432Node\LG Electronics]
[HKLM\Software\Wow6432Node\Macromedia]
[HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware]
[HKLM\Software\Wow6432Node\MozillaPlugins]
[HKLM\Software\Wow6432Node\Mozilla]
[HKLM\Software\Wow6432Node\Nuance]
[HKLM\Software\Wow6432Node\ODBC]
[HKLM\Software\Wow6432Node\OpenOffice]
[HKLM\Software\Wow6432Node\Policies]
[HKLM\Software\Wow6432Node\Qualcomm Atheros]
[HKLM\Software\Wow6432Node\Realtek Semiconductor Corp.]
[HKLM\Software\Wow6432Node\Realtek]
[HKLM\Software\Wow6432Node\RegisteredApplications]
[HKLM\Software\Wow6432Node\SRS Labs]
[HKLM\Software\Wow6432Node\SkypeWebPlugin]
[HKLM\Software\Wow6432Node\Skype]
[HKLM\Software\Wow6432Node\Systweak]
[HKLM\Software\Wow6432Node\TOSHIBA]
[HKLM\Software\Wow6432Node\Toshiba Corporation]
[HKLM\Software\Wow6432Node\Tutorials] =>PUP.AgenceExclusive
[HKLM\Software\Wow6432Node\VideoLAN]
[HKLM\Software\Wow6432Node\Volatile]
[HKLM\Software\Wow6432Node\WildTangent]
[HKLM\Software\Wow6432Node\mozilla.org]
[HKLM\Software\Wow6432Node\sMedio]
[HKLM\Software\Wow6432Node]
~ Key Software: 179 Scanned in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 08/05/2014 - 18:52:32 - [] ----D C:\Program Files (x86)\Atheros
O43 - CFD: 08/05/2014 - 18:56:55 - [] ----D C:\Program Files (x86)\Bluetooth Suite
O43 - CFD: 17/08/2014 - 17:43:15 - [] ----D C:\Program Files (x86)\Common Files
O43 - CFD: 08/05/2014 - 18:50:07 - [] ----D C:\Program Files (x86)\DTS, Inc
O43 - CFD: 08/05/2014 - 19:07:51 - [] ----D C:\Program Files (x86)\eBay =>Toolbar.eBay
O43 - CFD: 21/08/2014 - 14:13:15 - [] ----D C:\Program Files (x86)\globalUpdate
O43 - CFD: 17/08/2014 - 18:28:19 - [] ----D C:\Program Files (x86)\Google
O43 - CFD: 13/08/2014 - 22:18:20 - [] --H-D C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 08/05/2014 - 18:46:03 - [] ----D C:\Program Files (x86)\Intel
O43 - CFD: 18/08/2014 - 04:01:15 - [] ----D C:\Program Files (x86)\Internet Explorer
O43 - CFD: 17/08/2014 - 17:38:27 - [] ----D C:\Program Files (x86)\Java
O43 - CFD: 13/08/2014 - 23:01:00 - [] ----D C:\Program Files (x86)\LG Electronics
O43 - CFD: 21/08/2014 - 13:56:43 - [] ----D C:\Program Files (x86)\Malwarebytes Anti-Malware
O43 - CFD: 05/12/2013 - 22:35:08 - [] ----D C:\Program Files (x86)\Microsoft Office
O43 - CFD: 22/08/2013 - 17:36:30 - [] ----D C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 29/08/2013 - 00:21:55 - [] ----D C:\Program Files (x86)\MSBuild
O43 - CFD: 11/08/2014 - 15:26:15 - [] ----D C:\Program Files (x86)\OpenOffice 4
O43 - CFD: 10/08/2014 - 00:18:54 - [0] ----D C:\Program Files (x86)\predm
O43 - CFD: 08/05/2014 - 18:53:26 - [] ----D C:\Program Files (x86)\Realtek
O43 - CFD: 29/08/2013 - 00:21:55 - [] ----D C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 21/08/2014 - 14:14:50 - [0] ----D C:\Program Files (x86)\Settings Manager =>PUP.SystemK
O43 - CFD: 21/08/2014 - 15:04:42 - [] ----D C:\Program Files (x86)\SkypeWebPlugin
O43 - CFD: 08/05/2014 - 18:49:51 - [0] --H-D C:\Program Files (x86)\Temp
O43 - CFD: 08/05/2014 - 19:07:17 - [] ----D C:\Program Files (x86)\TOSHIBA
O43 - CFD: 10/08/2014 - 00:07:51 - [] ----D C:\Program Files (x86)\TOSHIBA Games
O43 - CFD: 08/05/2014 - 19:09:08 - [] ----D C:\Program Files (x86)\Toshiba TEMPRO =>.Toshiba Corporation
O43 - CFD: 11/08/2014 - 00:14:25 - [] ----D C:\Program Files (x86)\VideoLAN
O43 - CFD: 18/08/2014 - 04:01:15 - [] ----D C:\Program Files (x86)\Windows Defender
O43 - CFD: 18/08/2014 - 04:01:15 - [] ----D C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 18/08/2014 - 04:01:15 - [] ----D C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 13/08/2014 - 20:01:23 - [] ----D C:\Program Files (x86)\Windows Multimedia Platform
O43 - CFD: 22/08/2013 - 17:36:30 - [] ----D C:\Program Files (x86)\Windows NT
O43 - CFD: 18/08/2014 - 04:01:15 - [] ----D C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 13/08/2014 - 20:01:21 - [] ----D C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 22/08/2013 - 17:36:30 - [] -SH-D C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 22/08/2013 - 17:36:30 - [] ----D C:\Program Files (x86)\WindowsPowerShell
O43 - CFD: 11/08/2014 - 15:15:01 - [] ----D C:\Program Files (x86)\WinRAR
O43 - CFD: 21/08/2014 - 17:01:58 - [] ----D C:\Program Files (x86)\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 08/05/2014 - 18:56:56 - [] ----D C:\Program Files (x86)\Common Files\Atheros
O43 - CFD: 08/05/2014 - 18:48:46 - [] ----D C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 08/05/2014 - 18:45:48 - [] ----D C:\Program Files (x86)\Common Files\Intel
O43 - CFD: 17/08/2014 - 17:43:15 - [] ----D C:\Program Files (x86)\Common Files\Java
O43 - CFD: 08/05/2014 - 18:59:28 - [] ----D C:\Program Files (x86)\Common Files\Microsoft Shared
O43 - CFD: 22/08/2013 - 17:36:33 - [] ----D C:\Program Files (x86)\Common Files\Services
O43 - CFD: 18/08/2014 - 04:01:15 - [] ----D C:\Program Files (x86)\Common Files\System
O43 - CFD: 08/05/2014 - 19:03:43 - [] ----D C:\Program Files (x86)\Common Files\Toshiba Shared
O43 - CFD: 22/08/2013 - 16:45:52 - [] -SH-D C:\ProgramData\Application Data
O43 - CFD: 02/08/2014 - 20:53:37 - [] -SH-D C:\ProgramData\Bureau
O43 - CFD: 22/08/2013 - 16:45:52 - [] -S--D C:\ProgramData\Desktop
O43 - CFD: 22/08/2013 - 16:45:52 - [] -SH-D C:\ProgramData\Documents
O43 - CFD: 09/08/2014 - 11:55:09 - [] ----D C:\ProgramData\DSearchLink =>Toolbar.DeltaSearch
O43 - CFD: 08/05/2014 - 18:42:51 - [] ----D C:\ProgramData\Intel
O43 - CFD: 21/08/2014 - 13:56:18 - [] ----D C:\ProgramData\Malwarebytes
O43 - CFD: 09/08/2014 - 11:08:08 - [] ----D C:\ProgramData\McAfee
O43 - CFD: 02/08/2014 - 20:53:37 - [] -SH-D C:\ProgramData\Menu Démarrer
O43 - CFD: 13/08/2014 - 21:31:36 - [] -S--D C:\ProgramData\Microsoft
O43 - CFD: 02/08/2014 - 20:53:37 - [] -SH-D C:\ProgramData\Modèles
O43 - CFD: 14/08/2014 - 19:05:57 - [] ----D C:\ProgramData\Mozilla
O43 - CFD: 17/08/2014 - 17:43:14 - [0] ----D C:\ProgramData\Oracle
O43 - CFD: 08/05/2014 - 19:03:12 - [] ----D C:\ProgramData\Package Cache
O43 - CFD: 08/05/2014 - 18:52:06 - [] ----D C:\ProgramData\Qualcomm Atheros
O43 - CFD: 08/05/2014 - 19:33:29 - [] ----D C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 21/08/2014 - 13:44:51 - [] ----D C:\ProgramData\RogueKiller
O43 - CFD: 08/05/2014 - 18:50:07 - [] ----D C:\ProgramData\SRS Labs
O43 - CFD: 22/08/2013 - 16:45:52 - [] -SH-D C:\ProgramData\Start Menu
O43 - CFD: 17/08/2014 - 17:43:17 - [] ----D C:\ProgramData\Sun
O43 - CFD: 21/08/2014 - 14:13:21 - [0] ----D C:\ProgramData\Systweak
O43 - CFD: 22/08/2013 - 16:45:52 - [] -SH-D C:\ProgramData\Templates
O43 - CFD: 03/08/2014 - 08:25:54 - [] ----D C:\ProgramData\Toshiba
O43 - CFD: 09/08/2014 - 11:15:02 - [] ----D C:\ProgramData\ToshibaEurope
O43 - CFD: 10/08/2014 - 00:06:45 - [] ----D C:\ProgramData\WildTangent
O43 - CFD: 03/08/2014 - 08:22:07 - [] ----D C:\Users\Alan R\AppData\Roaming\Adobe
O43 - CFD: 09/08/2014 - 12:00:40 - [0] ----D C:\Users\Alan R\AppData\Roaming\ap_logs
O43 - CFD: 13/08/2014 - 23:14:26 - [] ----D C:\Users\Alan R\AppData\Roaming\LG Electronics
O43 - CFD: 09/08/2014 - 11:11:55 - [] ----D C:\Users\Alan R\AppData\Roaming\Macromedia
O43 - CFD: 17/08/2014 - 19:19:02 - [] -S--D C:\Users\Alan R\AppData\Roaming\Microsoft
O43 - CFD: 14/08/2014 - 19:08:33 - [] ----D C:\Users\Alan R\AppData\Roaming\Mozilla
O43 - CFD: 17/08/2014 - 18:45:08 - [0] ----D C:\Users\Alan R\AppData\Roaming\Nosibay =>PUP.BubbleDock
O43 - CFD: 11/08/2014 - 14:28:19 - [] ----D C:\Users\Alan R\AppData\Roaming\OpenOffice
O43 - CFD: 17/08/2014 - 17:43:48 - [] ----D C:\Users\Alan R\AppData\Roaming\Oracle
O43 - CFD: 17/08/2014 - 18:48:28 - [0] ----D C:\Users\Alan R\AppData\Roaming\Store =>PUP.Nosibay
O43 - CFD: 17/08/2014 - 18:42:30 - [] ----D C:\Users\Alan R\AppData\Roaming\sweet-page =>PUP.SweetPage
O43 - CFD: 21/08/2014 - 14:13:21 - [0] ----D C:\Users\Alan R\AppData\Roaming\Systweak
O43 - CFD: 21/08/2014 - 14:13:26 - [] ----D C:\Users\Alan R\AppData\Roaming\vlc
O43 - CFD: 21/08/2014 - 14:12:49 - [] ----D C:\Users\Alan R\AppData\Roaming\VOPackage =>Adware.Downware
O43 - CFD: 13/08/2014 - 11:39:18 - [] ----D C:\Users\Alan R\AppData\Roaming\WinRAR
O43 - CFD: 21/08/2014 - 17:02:53 - [] ----D C:\Users\Alan R\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 03/08/2014 - 08:21:52 - [] -SH-D C:\Users\Alan R\AppData\Local\Application Data
O43 - CFD: 10/08/2014 - 00:22:02 - [] ----D C:\Users\Alan R\AppData\Local\Apps
O43 - CFD: 12/08/2014 - 01:37:31 - [0] ----D C:\Users\Alan R\AppData\Local\Deployment
O43 - CFD: 14/08/2014 - 18:28:10 - [] ----D C:\Users\Alan R\AppData\Local\Diagnostics
O43 - CFD: 13/08/2014 - 20:24:20 - [] -SH-D C:\Users\Alan R\AppData\Local\EmieSiteList
O43 - CFD: 13/08/2014 - 20:24:20 - [] -SH-D C:\Users\Alan R\AppData\Local\EmieUserList
O43 - CFD: 11/08/2014 - 14:10:45 - [] ----D C:\Users\Alan R\AppData\Local\globalUpdate
O43 - CFD: 17/08/2014 - 18:28:48 - [] ----D C:\Users\Alan R\AppData\Local\Google
O43 - CFD: 03/08/2014 - 08:21:52 - [] -SH-D C:\Users\Alan R\AppData\Local\Historique
O43 - CFD: 14/08/2014 - 14:23:05 - [] ----D C:\Users\Alan R\AppData\Local\Intel_Corporation
O43 - CFD: 13/08/2014 - 23:01:48 - [] ----D C:\Users\Alan R\AppData\Local\LG Electronics
O43 - CFD: 14/08/2014 - 19:43:15 - [] ----D C:\Users\Alan R\AppData\Local\Macromedia
O43 - CFD: 14/08/2014 - 18:28:08 - [] ----D C:\Users\Alan R\AppData\Local\Microsoft
O43 - CFD: 14/08/2014 - 19:08:34 - [] ----D C:\Users\Alan R\AppData\Local\Mozilla
O43 - CFD: 11/08/2014 - 19:58:53 - [] ----D C:\Users\Alan R\AppData\Local\Packages
O43 - CFD: 09/08/2014 - 11:47:19 - [] ----D C:\Users\Alan R\AppData\Local\Programs
O43 - CFD: 21/08/2014 - 17:02:00 - [] ----D C:\Users\Alan R\AppData\Local\Temp
O43 - CFD: 03/08/2014 - 08:21:52 - [] -SH-D C:\Users\Alan R\AppData\Local\Temporary Internet Files
O43 - CFD: 03/08/2014 - 08:24:05 - [] ----D C:\Users\Alan R\AppData\Local\TOSHIBA
O43 - CFD: 03/08/2014 - 08:22:06 - [0] ----D C:\Users\Alan R\AppData\Local\VirtualStore
O43 - CFD: 22/08/2013 - 17:36:32 - [] R---D C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 22/08/2013 - 17:36:32 - [] R---D C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 13/08/2014 - 20:21:03 - [] R---D C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 22/08/2013 - 17:36:32 - [] ----D C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 13/08/2014 - 20:21:03 - [] R---D C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 22/08/2013 - 17:36:32 - [] R---D C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 11/08/2014 - 15:23:32 - [] ----D C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
~ Program Folder: 114 Scanned in 00mn 00s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.C27B20D9AA9BE41CCBFD512AABB0E6C3] - 06/08/2014 - 23:38:18 ---A- . (.Microsoft Corporation - Mise à jour des données de compatibilité de.) -- C:\Windows\System32\aepdu.dll [697856]
O44 - LFC:[MD5.A39C4AB750E0AD4431C7B7F46AB0EBED] - 06/08/2014 - 23:39:55 ---A- . (.Microsoft Corporation - Pilote Win32 multi-utilisateurs.) -- C:\Windows\System32\win32k.sys [4148224]
O44 - LFC:[MD5.87CEF71F9D5951C9379D2F956C07C37D] - 07/08/2014 - 03:12:27 ---A- . (.Microsoft Corporation - GDI Client DLL.) -- C:\Windows\System32\gdi32.dll [1336624]
O44 - LFC:[MD5.04D10A4929B36BF831BF883FFD56E8AB] - 09/08/2014 - 10:38:40 ---A- . (...) -- C:\Windows\epplauncher.mif [2152]
O44 - LFC:[MD5.D8B85CC423236928CE06C0BFAA1A55B8] - 09/08/2014 - 10:48:04 ---A- . (.Pas de propriétaire - Registry Optimizer.) -- C:\Windows\System32\roboot64.exe [20280]
O44 - LFC:[MD5.2EF4E5EDE91EF893603E8B72890AC605] - 09/08/2014 - 10:50:35 ---A- . (.Corsica - Web Instrumentation Driver.) -- C:\Windows\System32\Drivers\webinstr.sys [57528]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 09/08/2014 - 10:50:35 --HA- . (...) -- C:\Windows\System32\Drivers\Msft_Kernel_webinstr_01009.Wdf [0]
O44 - LFC:[MD5.6FB598E8DE02D879D17B35F144A1B3BC] - 09/08/2014 - 11:03:26 ----- . (.Microsoft Corporation - Microsoft Malware Protection Signature Upda.) -- C:\Windows\System32\MpSigStub.exe [270496]
O44 - LFC:[MD5.6EFAF0D87291F9FBD7C0ED3BD56511AA] - 10/08/2014 - 23:24:56 ---A- . (.Microsoft Corporation - Crypto API32.) -- C:\Windows\System32\crypt32.dll [1943536]
O44 - LFC:[MD5.4A8D40E38BC2C57E5D630AD6994A85CB] - 10/08/2014 - 23:25:15 ---A- . (.Microsoft Corporation - Exécuteur de file d'attente d'opérations pr.) -- C:\Windows\System32\poqexec.exe [139776]
O44 - LFC:[MD5.3E245CCA42D78B9626A79FE77E111D7B] - 10/08/2014 - 23:25:49 ---A- . (.Microsoft Corporation - Cet outil collecte les fichiers journaux du.) -- C:\Windows\System32\WSCollect.exe [84480]
O44 - LFC:[MD5.389C4E97E3A498159B625A7A13EA4560] - 10/08/2014 - 23:27:20 ---A- . (.Microsoft Corporation - Direct3D 10 Rasterizer.) -- C:\Windows\System32\d3d10warp.dll [2397184]
O44 - LFC:[MD5.053472337FDD116BD010C88DB0C34DF1] - 10/08/2014 - 23:27:21 ---A- . (.Microsoft Corporation - Bibliothèque Microsoft D2D.) -- C:\Windows\System32\d2d1.dll [4604416]
O44 - LFC:[MD5.447CB6699A8EAD2BC516991738A16277] - 10/08/2014 - 23:30:46 ---A- . (.Microsoft Corporation - Windows NT Image Helper.) -- C:\Windows\System32\imagehlp.dll [75360]
O44 - LFC:[MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - 10/08/2014 - 23:30:56 ---A- . (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [447488]
O44 - LFC:[MD5.C7DFBE21051D5E44B479CBF74B968335] - 10/08/2014 - 23:31:00 ---A- . (.Microsoft Corporation - Windows Image Helper.) -- C:\Windows\System32\dbghelp.dll [1486848]
O44 - LFC:[MD5.819A1E0F89B6AC222E9D95CA000A40B1] - 10/08/2014 - 23:31:01 ---A- . (.Microsoft Corporation - Windows Symbolic Debugger Engine.) -- C:\Windows\System32\dbgeng.dll [4175360]
O44 - LFC:[MD5.C993A0B97BECD3AAF5158E3869878465] - 10/08/2014 - 23:31:07 ---A- . (.Microsoft Corporation - Service de la plateforme de protection logi.) -- C:\Windows\System32\sppsvc.exe [6353960]
O44 - LFC:[MD5.68085A085DE8E3540EE8E02CAE575B2E] - 10/08/2014 - 23:32:00 ---A- . (...) -- C:\Windows\System32\OEMLicense.dll [138240]
O44 - LFC:[MD5.0B9FBEC5714523FF76DDFEB320FE2DF2] - 10/08/2014 - 23:32:02 ---A- . (.Microsoft Corporation - DLL client de périphériques d'images fixes.) -- C:\Windows\System32\sti.dll [303616]
O44 - LFC:[MD5.A1A5E79C0D1352AFDC08328A623DA051] - 10/08/2014 - 23:32:03 ---A- . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) -- C:\Windows\System32\Drivers\rdbss.sys [408576]
O44 - LFC:[MD5.E287F157F7A0011D93179C64EF8ADCF2] - 10/08/2014 - 23:32:07 ---A- . (.Microsoft Corporation - DLL du service PNRP.) -- C:\Windows\System32\pnrpsvc.dll [376320]
O44 - LFC:[MD5.847CFF96ACB575CE73C0E2E86C6BA993] - 10/08/2014 - 23:32:07 ---A- . (.Microsoft Corporation - Fonctions de vérification de l'orthographe.) -- C:\Windows\System32\MsSpellCheckingFacility.dll [842752]
O44 - LFC:[MD5.A95838FFFAEAA7500263D491575F7E0C] - 10/08/2014 - 23:32:11 ---A- . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1214976]
O44 - LFC:[MD5.B9D968D8E2B0F9C6301CEB39CFC9B9E4] - 10/08/2014 - 23:34:32 ---A- . (.Microsoft Corporation - Power Dependency Coordinator Driver.) -- C:\Windows\System32\Drivers\pdc.sys [86872]
O44 - LFC:[MD5.0044B31F93946D5D41982314381FE431] - 10/08/2014 - 23:34:33 ---A- . (.Microsoft Corporation - Serial Class Extension V2.) -- C:\Windows\System32\Drivers\SerCx2.sys [146776]
O44 - LFC:[MD5.139CFCDCD36B1B1782FD8C0014AC9B0E] - 10/08/2014 - 23:34:34 ---A- . (.Microsoft Corporation - Intel Power Engine Plugin.) -- C:\Windows\System32\Drivers\intelpep.sys [39768]
O44 - LFC:[MD5.AD95F86C8D1843BE653F89FDE213F9E7] - 10/08/2014 - 23:38:38 ---A- . (.Microsoft Corporation - DLL d'inscription de périphérique.) -- C:\Windows\System32\deviceregistration.dll [207872]
O44 - LFC:[MD5.1C89EF529DB7DCA98E801EFDCC8437DE] - 10/08/2014 - 23:38:39 ---A- . (.Microsoft Corporation - Microsoft Bluetooth Audio Multiprofile Mana.) -- C:\Windows\System32\Drivers\BtaMPM.sys [19456]
O44 - LFC:[MD5.CD45E3FE736150D45EFDC9145DA53757] - 10/08/2014 - 23:38:40 ---A- . (.Microsoft Corporation - Background Broker Infrastructure Client Lib.) -- C:\Windows\System32\bi.dll [24064]
O44 - LFC:[MD5.FF9F658A51CAD74C25AF83038DBD735D] - 10/08/2014 - 23:38:40 ---A- . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Inter.) -- C:\Windows\System32\msieftp.dll [306688]
O44 - LFC:[MD5.B7342B3C58E91107F6E946A93D9D4EFD] - 10/08/2014 - 23:38:41 ---A- . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys [142848]
O44 - LFC:[MD5.91433B44B1EF301E7DD696EB5281BC20] - 10/08/2014 - 23:38:42 ---A- . (.Microsoft Corporation - Accès distant PPP EAP-TLS.) -- C:\Windows\System32\rastls.dll [589824]
O44 - LFC:[MD5.34F8F7A0B782798F6A9511157BCC3E32] - 10/08/2014 - 23:38:43 ---A- . (.Microsoft Corporation - WinRT Windows Graphics DLL.) -- C:\Windows\System32\Windows.Graphics.dll [273408]
O44 - LFC:[MD5.660891FFB1B22FF39AADB3F45CE15D45] - 10/08/2014 - 23:38:45 ---A- . (.Microsoft Corporation - Media Foundation Direct Show wrapper DLL.) -- C:\Windows\System32\mfds.dll [470016]
O44 - LFC:[MD5.40B228D05DB02F4A5F2452600999F53F] - 10/08/2014 - 23:38:46 ---A- . (.Microsoft Corporation - DLL source et récepteur MPEG4 Media Foundat.) -- C:\Windows\System32\mfmp4srcsnk.dll [809872]
O44 - LFC:[MD5.D65B1C952AEB864C2BAC7A770B17ECCE] - 10/08/2014 - 23:38:50 ---A- . (.Microsoft Corporation - Service Broker pour les événements système.) -- C:\Windows\System32\SystemEventsBrokerServer.dll [282112]
O44 - LFC:[MD5.32370AF583EC8B24D790E1B9201D6811] - 10/08/2014 - 23:39:01 ---A- . (.Microsoft Corporation - Microsoft DTV-DVD Video Decoder.) -- C:\Windows\System32\msmpeg2vdec.dll [3210528]
O44 - LFC:[MD5.4082B1F66087FC1D8B4759569A194391] - 11/08/2014 - 12:31:23 ---A- . (.Microsoft Corporation - Analyseur de Presse-papiers RDP.) -- C:\Windows\System32\rdpclip.exe [338944]
O44 - LFC:[MD5.E8E50E7703204AE06C6B5FEFE2F701E7] - 11/08/2014 - 12:31:23 ---A- . (.Microsoft Corporation - Infrastructure de gestion.) -- C:\Windows\System32\miutils.dll [226304]
O44 - LFC:[MD5.504092E4BA97FCEB53912BB6CD156547] - 11/08/2014 - 12:31:23 ---A- . (.Microsoft Corporation - Logiciel de transfert de fichiers.) -- C:\Windows\System32\ftp.exe [53248]
O44 - LFC:[MD5.053445AED2A855477496965B8EA16A6B] - 11/08/2014 - 12:31:29 ---A- . (.Microsoft Corporation - UI générique EAP.) -- C:\Windows\System32\eappgnui.dll [101888]
O44 - LFC:[MD5.F48C144251B36850B67AB8E6D9E20E92] - 11/08/2014 - 12:31:30 ---A- . (.Microsoft Corporation - IE ETW Collector Service.) -- C:\Windows\System32\ieetwcollector.exe [111616]
O44 - LFC:[MD5.5C8EE485EF4AEA9BCECD36A46599E5C9] - 11/08/2014 - 12:31:31 ---A- . (.Microsoft Corporation - Configuration d'homologue EAP.) -- C:\Windows\System32\eappcfg.dll [335360]
O44 - LFC:[MD5.6B06E2D11E604BE2B1A406C4CB3B90DE] - 11/08/2014 - 12:31:34 ---A- . (.Microsoft Corporation - Microsoft NVM Express Storport Miniport Dri.) -- C:\Windows\System32\Drivers\stornvme.sys [57176]
O44 - LFC:[MD5.2F5076AA4F8195B0ED7D448EDC763D86] - 11/08/2014 - 12:31:34 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Proxy.) -- C:\Windows\System32\TSWbPrxy.exe [83968]
O44 - LFC:[MD5.F4414F57DF2CECB8FC969AA43A6B0D50] - 11/08/2014 - 12:31:35 ---A- . (.Microsoft Corporation - Composants de l'application d'assistance à.) -- C:\Windows\System32\ipnathlp.dll [433664]
O44 - LFC:[MD5.63CB763FE4CEADFFF5F047332814E8F9] - 11/08/2014 - 12:31:35 ---A- . (.Microsoft Corporation - Stratégie de verrouillage Windows.) -- C:\Windows\System32\wldp.dll [44936]
O44 - LFC:[MD5.DFC4050D58565ADBEE793A8D4AEBDAE6] - 11/08/2014 - 12:31:36 ---A- . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [903168]
O44 - LFC:[MD5.433ECDE01A52691FA7ACA51C10C09B70] - 11/08/2014 - 12:31:37 ---A- . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) -- C:\Windows\System32\Drivers\usbccgp.sys [155480]
O44 - LFC:[MD5.4EFC6306A619F49A95FB83538C812461] - 11/08/2014 - 12:31:38 ---A- . (.Microsoft Corporation - Fournisseur de proxy PCSV pour périphérique.) -- C:\Windows\System32\pcsvDevice.dll [286208]
O44 - LFC:[MD5.CA56145B0F1FA54FA21C2E0A7AC9C119] - 11/08/2014 - 12:31:38 ---A- . (.Microsoft Corporation - Maintenance Scheduler.) -- C:\Windows\System32\msched.dll [132608]
O44 - LFC:[MD5.2B78788A1485F9B99A578A299DF42C02] - 11/08/2014 - 12:31:38 ---A- . (.Microsoft Corporation - Server driver.) -- C:\Windows\System32\Drivers\srv.sys [454656]
O44 - LFC:[MD5.12BF0E1F71E2EA1A52B5D1723F87BD16] - 11/08/2014 - 12:31:40 ---A- . (.Microsoft Corporation - Microsoft ThirdPartyEapDispatcher.) -- C:\Windows\System32\eapp3hst.dll [325120]
O44 - LFC:[MD5.D920A92D7F103F7C424A16FBEF0AA790] - 11/08/2014 - 12:31:41 ---A- . (.Microsoft Corporation - Plugin MF RDP.) -- C:\Windows\System32\tsmf.dll [391512]
O44 - LFC:[MD5.2BEF4B9C1CD2E090C97C0937B859C0E7] - 11/08/2014 - 12:31:43 ---A- . (.Microsoft Corporation - Intel Network Kernel Debug Extensibility Mo.) -- C:\Windows\System32\kd_02_8086.dll [171864]
O44 - LFC:[MD5.7F9AEC82D7480068C6D444D4FD8FB36F] - 11/08/2014 - 12:31:44 ---A- . (.Microsoft Corporation - Service homologue EAPHost Microsoft.) -- C:\Windows\System32\eapphost.dll [331776]
O44 - LFC:[MD5.B953A10B98ED83C2EF7C7D9153F18924] - 11/08/2014 - 12:31:44 ---A- . (.Microsoft Corporation - Windows.Networking.BackgroundTransfer DLL.) -- C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll [578560]
O44 - LFC:[MD5.0FC25089426F313B1B271FEDCB0814DB] - 11/08/2014 - 12:31:46 ---A- . (.Microsoft Corporation - Direct3D 10 to Direct3D9 Translation Runtim.) -- C:\Windows\System32\d3d10level9.dll [699840]
O44 - LFC:[MD5.03CC7C6D00212DF6D6CB5C93432410ED] - 11/08/2014 - 12:31:47 ---A- . (.Microsoft Corporation - Programme principal d'automation de l'inter.) -- C:\Windows\System32\UIAutomationCore.dll [1147904]
O44 - LFC:[MD5.1503510900836FA6A0E4FE9662FE0768] - 11/08/2014 - 12:31:51 ---A- . (.Microsoft Corporation - Composant Connexion RemoteApp et Bureau à d.) -- C:\Windows\System32\TSWorkspace.dll [1011712]
O44 - LFC:[MD5.A8AA0F50CE95FCD1CB9588DB0A961D98] - 11/08/2014 - 12:31:52 ---A- . (.Microsoft Corporation - DLL Windows.Web.Http.) -- C:\Windows\System32\Windows.Web.Http.dll [1160704]
O44 - LFC:[MD5.222D5E0C79E9C87EF0C4D02651EE765A] - 11/08/2014 - 12:31:59 ---A- . (.Microsoft Corporation - Media Foundation ASF Source and Sink DLL.) -- C:\Windows\System32\mfasfsrcsnk.dll [1067080]
O44 - LFC:[MD5.D750DA0AC7ECFF1F9C76FCAC9285E499] - 11/08/2014 - 13:09:10 ---A- . (...) -- C:\Windows\win.ini [226]
O44 - LFC:[MD5.5F84D8C3831A559CEB55F894CD24E2B5] - 11/08/2014 - 15:42:05 ---A- . (.Microsoft Corporation - Codec pour photographie Windows Media Photo.) -- C:\Windows\System32\WMPhoto.dll [393216]
O44 - LFC:[MD5.6F531F98B8601A9E7A93F8FEC393E2D1] - 11/08/2014 - 15:42:06 ---A- . (.Microsoft Corporation - Program Compatibility Assistant User Interf.) -- C:\Windows\System32\pcaui.exe [18944]
O44 - LFC:[MD5.BE94090FCBB95B6F22E952D27BD2610E] - 11/08/2014 - 15:43:18 ---A- . (.Microsoft Corporation - Client Gestion des droits Windows
~ Lancé par Alan R (21/08/2014 17:02:13)
~ Adresse du Site Web https://nicolascoolman.eu
~ Adresse du Forum https://nicolascoolman.eu
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Désactivée par l'utilisateur
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user
---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17239
GCIE: Google Chrome v36.0.1985.143 (Defaut)
---\\ Informations sur les produits Windows
~ Langage: Français
Windows 8.1, 64-bit (Build 9600)
Windows Server License Manager Script : OK
---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 2.0.2.1012
Windows Defender W8 (Activate)
---\\ Logiciels d'optimisation du système
CCleaner v4.09
---\\ Logiciels de partage PeerToPeer
---\\ Surveillance de Logiciels
Adobe Flash Player 14 Plugin
Java 7 Update 67
---\\ Informations sur le système
~ Processor: Intel64 Family 6 Model 55 Stepping 3, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3979 MB (42% free)
System Restore: Activé (Enable)
System drive C: has 653 GB (95%) free of 687 GB
---\\ Mode de connexion au système
~ Computer Name: ALAN
~ User Name: Alan R
~ All Users Names: Alan R, Administrateur,
~ Unselected Option: None
Logged in as Administrator
---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Alan R\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Alan R\AppData\Roaming\
~ %Desktop% : C:\Users\Alan R\Desktop\
~ %Favorites% : C:\Users\Alan R\Favorites\
~ %LocalAppData% : C:\Users\Alan R\AppData\Local\
~ %StartMenu% : C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 653 Go of 687 Go)
D: CD-ROM drive (Not Inserted)
---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: 41 Scanned in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.81394C91B7B5A7C799E249AE82491F13] - (.Microsoft Corporation - Explorateur Windows.) (.04/03/2014 - 13:25:49.) -- C:\Windows\Explorer.exe [2373784]
[MD5.48CFA7BE561A7BE144C29BB912055016] - (.Microsoft Corporation - Application de démarrage de Windows.) (.22/08/2013 - 10:58:29.) -- C:\Windows\System32\Wininit.exe [144384]
[MD5.8E71A5CB5312B8392D4DA4CA37BB5868] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.25/07/2014 - 11:52:06.) -- C:\Windows\System32\wininet.dll [2266624]
[MD5.306EB21E5B480AE9065EA55AC8C35936] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.22/02/2014 - 10:45:48.) -- C:\Windows\System32\Winlogon.exe [562176]
[MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - (.Microsoft Corporation - Bibliothèque de licences.) (.21/12/2013 - 09:54:07.) -- C:\Windows\System32\sppcomapi.dll [447488]
[MD5.374E27295F0A9DCAA8FC96370F9BEEA5] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.30/05/2014 - 04:03:03.) -- C:\Windows\system32\Drivers\AFD.sys [563200]
[MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.22/08/2013 - 13:43:41.) -- C:\Windows\system32\Drivers\atapi.sys [26464]
[MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) (.22/08/2013 - 12:40:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [88576]
[MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.22/08/2013 - 09:46:35.) -- C:\Windows\system32\Drivers\Cdrom.sys [164352]
[MD5.A03F362C5557E238CBFA914689C77248] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.06/03/2014 - 10:22:50.) -- C:\Windows\system32\Drivers\DfsC.sys [134144]
[MD5.498288DD5CA42C2D36D125893E968C53] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.18/03/2014 - 09:19:14.) -- C:\Windows\system32\Drivers\HDAudBus.sys [77312]
[MD5.84CFC5EFA97D0C965EDE1D56F116A541] - (.Microsoft Corporation - Pilote de port i8042.) (.22/08/2013 - 12:39:15.) -- C:\Windows\system32\Drivers\i8042prt.sys [107520]
[MD5.B7342B3C58E91107F6E946A93D9D4EFD] - (.Microsoft Corporation - IP Network Address Translator.) (.27/11/2013 - 13:02:29.) -- C:\Windows\system32\Drivers\IpNat.sys [142848]
[MD5.7A1A3F213CDB3363D179D5014272025D] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.30/04/2014 - 07:41:46.) -- C:\Windows\system32\Drivers\MRxSmb.sys [402432]
[MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) (.22/08/2013 - 12:37:02.) -- C:\Windows\system32\Drivers\netBT.sys [282624]
[MD5.1C80517BE6836A812F6A9B99B8321351] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.20/03/2014 - 04:41:24.) -- C:\Windows\system32\Drivers\ntfs.sys [2013016]
[MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Pilote de port parallèle.) (.22/08/2013 - 12:40:02.) -- C:\Windows\system32\Drivers\Parport.sys [94208]
[MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.22/08/2013 - 12:35:51.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [120832]
[MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.22/08/2013 - 20:12:11.) -- C:\Windows\system32\Drivers\rdpdr.sys [195584]
[MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) (.22/08/2013 - 14:25:35.) -- C:\Windows\system32\Drivers\tdx.sys [107520]
[MD5.4BB9BC49DEE1A319EC58274A7BBED663] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.06/03/2014 - 13:42:44.) -- C:\Windows\system32\Drivers\volsnap.sys [310616]
~ Generic Processes: Scanned in 00mn 00s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/371
~ Mes musiques (My Musics) : 1/23
~ Mes Videos (My Videos) : 1/2
~ Mes Favoris (My Favorites) : 1/4
~ Mes Documents (My Documents) : 1/16
~ Mon Bureau (My Desktop) : 1/6
~ Menu demarrer (Programs) : 1/24
~ Hidden Files: Scanned in 00mn 00s
---\\ Processus lancés
[MD5.4FBC630768570E6AC35C3DE8F6EC79F5] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe [6970168] [PID.2416]
[MD5.308F2EE28005510DE616409148CF077B] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896] [PID.3168]
[MD5.0BDAE865738D27A4D84D50591C8C9D2D] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [860488] [PID.1844]
[MD5.8DF7F2A9B72B7CA4294BB9E59FEAEFCD] - (.Microsoft Corporation - Hôte Microsoft WWA.) -- C:\Windows\syswow64\wwahost.exe [514560] [PID.1488]
[MD5.9D506DEFE177A7A4B4C88977A2FA735B] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8094720] [PID.3416]
~ Processes Running: Scanned in 00mn 02s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Alan R\AppData\Local\Google\Chrome\User Data\Default\Preferences
G0 - GCSP: Preference [User Data\Default][HomePage] https://www.google.com/?gws_rd=ssl
G2 - GCE: Preference [User Data\Default] [ahfgeienlihckogmohjhadlkjgocpleb] Google Store v.0.2 (Activé)
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Docs v.0.7 (Activé)
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Drive v.6.3 (Activé)
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] YouTube v.4.2.6 (Activé)
G2 - GCE: Preference [User Data\Default] [booedmolknjekdopkepjjeckmjkdpfgl] Extutil v.0.1 (Activé) =>PUP.Manager
G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Recherche Google v.0.0.0.20 (Activé)
G2 - GCE: Preference [User Data\Default] [eemcgdkfndhakfknompkggombfjjjeno] Bookmark Manager v.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [ennkphjdgehloodpbhlhldgbnhmacadg] Settings v.0.2 (Activé)
G2 - GCE: Preference [User Data\Default] [flpcjncodpafbgdpnkljologafpionhb] Managera v.0.1 (Activé) =>PUP.Manager
G2 - GCE: Preference [User Data\Default] [gfdkimpbcpahaombhbimeihdjnejgicl] Feedback v.1.0 (Activé)
G2 - GCE: Preference [User Data\Default] [kmendfapggjehodndflmmgagdbamhnfd] CryptoTokenExtension v.0.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [mfehgcgbbipciphmccgaenjidiccnmng] Cloud Print v.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [mfffpogegjflfpflabcdkioaeobkgjik] GaiaAuthExtension v.0.0.1, (Activé)
G2 - GCE: Preference [User Data\Default] [mgndgikekgjfcpckkfioiadnlibdjbkf] Chrome v.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [neajdppkdcdipfabeoofebfddakdcjhd] Google Network Speech v.1.0 (Activé)
G2 - GCE: Preference [User Data\Default] [nkeimhogjdpnpccoofpliimaahmaaome] Google+ Hangouts v.1.0 (Activé)
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.6.1 (Activé)
G2 - GCE: Preference [User Data\Default] [pafkbggdmjlpgkdkcbjmhmfcdpncadgh] Google Now v.1.2.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Gmail v.7 (Activé)
---\\ Liste des dossiers d'extension Google Chrome
G2 - EXT: C:\Users\Alan R\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [Google Docs]
G2 - EXT: C:\Users\Alan R\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [Google Drive]
G2 - EXT: C:\Users\Alan R\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [YouTube]
G2 - EXT: C:\Users\Alan R\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [Recherche Google]
G2 - EXT: C:\Users\Alan R\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [Google Wallet]
G2 - EXT: C:\Users\Alan R\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [Gmail]
~ Google Lines Browser: 26 Scanned in 00mn 03s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Alan R\AppData\Roaming\Mozilla\Firefox\Profiles\zb16lrul.default\prefs.js
M2 - MFEP: RegExtension {9A3B7448-C8A3-4EF3-C7D8-33FEA5854401} . (...) -- C:\Program Files (x86)\ver3BlockAndSurf\176.xpi (.not file.) =>PUP.BlockAndSurf
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll
P2 - FPN: [HKLM] [@Skype Technologies S.A..com/Skype Web Plugin] - (.Skype - Skype Web Plugin.) -- C:\Program Files (x86)\SkypeWebPlugin\3.1.15602.22612\npSkypeWebPlugin64.dll
~ Firefox Browser: 3 Scanned in 00mn 00s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.microsoft.com/fr-fr/
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = https://www.microsoft.com/fr-fr/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = www.google.com
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.9600.17239 (winblue_gdr.140724-2228)) -- C:\Windows\SysWOW64\ieframe.dll
~ IE Browser: 21 Scanned in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <-loopback> =>Hijacker.Proxy
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
~ BHO: 2 Scanned in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: (no name) - [HKLM]{ae07101b-46d4-4a98-af68-0333ea26e113} Clé orpheline
~ Toolbar: Scanned in 00mn 00s
---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [TSSSrv] . (.TOSHIBA Corporation - TOSHIBA System Settings Service.) -- C:\Program Files (x86)\TOSHIBA\System Setting\TSSSrv.exe
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_2A41EE48AB66A3CA09992BE89156F815] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - HKLM\..\Wow6432Node\Run: [AnyProtect Scanner] C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe (.not file.) =>PUP.AnyProtect
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle Corporation
O4 - HKUS\S-1-5-21-1709042038-2155373347-2631235414-1001\..\Run: [GoogleChromeAutoLaunch_2A41EE48AB66A3CA09992BE89156F815] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
~ Application: Scanned in 00mn 00s
---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ IE Control Panel: 1 Scanned in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
~ Winsock: 7 Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{73165873-0C06-44F6-BEB5-65CC1F5998A9}: DhcpNameServer = 89.2.0.1 89.2.0.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{73165873-0C06-44F6-BEB5-65CC1F5998A9}: DhcpNameServer = 89.2.0.1 89.2.0.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.2.0.1 89.2.0.2
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s
---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ SSODL: 1 Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: AtherosSvc (AtherosSvc) . (.Windows (R) Win 7 DDK provider - Windows Setup API.) - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: DTS APO Service (dts_apo_service) . (.Pas de propriétaire - dts_apo_service.) - C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc
O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) . (.TOSHIBA Corporation - TDCSrv Application.) - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA eco Utility Service (TOSHIBA eco Utility Service) . (.Toshiba Corporation - TOSHIBA eco Utility Service.) - C:\Program Files\TOSHIBA\Teco\TecoService.exe =>.Toshiba Corporation
~ Services: 8 Scanned in 00mn 10s
---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Desktop Component: 4 Scanned in 00mn 00s
---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
[MD5.F4BF3ADDDDC1AD372604F13C2B0C1F65] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [262320]
[MD5.00000000000000000000000000000000] [APT] [APSnotifierPP1] (...) -- C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe (.not file.) [0] =>PUP.AnyProtect
[MD5.00000000000000000000000000000000] [APT] [APSnotifierPP2] (...) -- C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe (.not file.) [0] =>PUP.AnyProtect
[MD5.00000000000000000000000000000000] [APT] [APSnotifierPP3] (...) -- C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe (.not file.) [0] =>PUP.AnyProtect
[MD5.E7CDBC01674477840A64965E784374DE] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [4370712]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
[MD5.16438B000BF56F2CD7FDB5E6C3B38C7E] [APT] [RTKCPL] (.Realtek Semiconductor.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13662936]
[MD5.C930517BBE90227EA16158C85E7C2865] [APT] [Synaptics TouchPad Enhancements] (.Synaptics Incorporated.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2778864]
[MD5.1608D54DC69EA7E763CDAB78F71CAFD6] [APT] [{EDA56F95-E691-40F5-9B9B-A74629DB6F03}] (.Skytech Co., Ltd..) -- C:\Users\Alan R\AppData\Roaming\sweet-page\UninstallManager.exe [1856512] =>PUP.SweetPage
[MD5.C6B8CB65A3AACABB00F3DAA371C46A3E] [APT] [CommonNotifier] (.Toshiba Europe GmbH.) -- C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [471416]
[MD5.6F8B977DD7511F96038CA4092FC7DE36] [APT] [HotKeysCmds] (.Intel Corporation.) -- C:\Windows\system32\hkcmd.exe [771056]
[MD5.1D18ACD429C734FAEA288DDCB38F94AF] [APT] [IgfxTray] (.Intel Corporation.) -- C:\Windows\system32\igfxtray.exe [391152]
[MD5.4E545DE0671C1BD788E9975950EB2D18] [APT] [Persistence] (.Intel Corporation.) -- C:\Windows\system32\igfxpers.exe [770032]
[MD5.C14294B90DD5C44D584F60884007ED59] [APT] [Service Station] (.TOSHIBA Corporation.) -- C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [699496]
[MD5.63D9BB372FAD1C9C35FE07F28E2B6D17] [APT] [TCrdMain] (.TOSHIBA Corporation.) -- C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2556768]
[MD5.002D52AEB2D5CD250910F366C2AECFC5] [APT] [TecoResident] (.TOSHIBA Corporation.) -- C:\Program Files\TOSHIBA\Teco\TecoResident.exe [179040]
[MD5.FA43294F64D95AEF875B796582BB7D2F] [APT] [TosWaitSrv] (.TOSHIBA Corporation.) -- C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [354144]
[MD5.18DBA177BD009B91D1884C9DB62BB039] [APT] [TSVU] (.TOSHIBA.) -- c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [516512]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: APSnotifierPP1 - (...) -- C:\Windows\Tasks\APSnotifierPP1.job [378] =>PUP.AnyProtect
O39 - APT: APSnotifierPP1 - (...) -- C:\Windows\System32\Tasks\APSnotifierPP1 [378] =>PUP.AnyProtect
O39 - APT: APSnotifierPP2 - (...) -- C:\Windows\Tasks\APSnotifierPP2.job [376] =>PUP.AnyProtect
O39 - APT: APSnotifierPP2 - (...) -- C:\Windows\System32\Tasks\APSnotifierPP2 [376] =>PUP.AnyProtect
O39 - APT: APSnotifierPP3 - (...) -- C:\Windows\Tasks\APSnotifierPP3.job [376] =>PUP.AnyProtect
O39 - APT: APSnotifierPP3 - (...) -- C:\Windows\System32\Tasks\APSnotifierPP3 [376] =>PUP.AnyProtect
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1074]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1074]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1078]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1078]
~ Scheduled Task: 26 Scanned in 00mn 14s
---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Browsing Enhancements [64Bits] - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Windows Desktop Update [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll
~ Active Setup: 9 Scanned in 00mn 00s
---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: C:\Windows\System32\drivers\ahcache.sys (ahcache) . (.Microsoft Corporation - Application Compatibility Cache.) - C:\Windows\System32\DRIVERS\ahcache.sys
O41 - Driver: (BasicDisplay) . (.Microsoft Corporation - Microsoft Basic Display Driver.) - C:\Windows\system32\drivers\BasicDisplay.sys
O41 - Driver: (BasicRender) . (.Microsoft Corporation - Microsoft Basic Render Driver.) - C:\Windows\system32\drivers\BasicRender.sys
O41 - Driver: cdrom.inf (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\drivers\cdrom.sys
O41 - Driver: C:\Windows\System32\drivers\dam.sys (dam) . (.Microsoft Corporation - DAM Kernel Driver.) - C:\Windows\System32\drivers\dam.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (Dfsc) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: mssmbios.inf (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
O41 - Driver: netnb.inf (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: npsvctrig.inf (npsvctrig) . (.Microsoft Corporation - Named pipe service triggers.) - C:\Windows\system32\drivers\npsvctrig.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\system32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\system32\DRIVERS\tdx.sys
O41 - Driver: C:\Windows\System32\drivers\vwififlt.sys (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\system32\DRIVERS\vwififlt.sys
~ Drivers: 32 Scanned in 00mn 00s
---\\ Logiciels installés (O42)
O42 - Logiciel: Adobe Flash Player 14 Plugin - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player Plugin
O42 - Logiciel: Atheros Driver Installation Program - (.Atheros.) [HKLM][64Bits] -- {C3A32068-8AB1-4327-BB16-BED9C6219DC7}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner
O42 - Logiciel: DTS Sound - (.DTS, Inc..) [HKLM][64Bits] -- {2C7A5AF4-1793-4B5A-89C0-021FB198EDE8}
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
O42 - Logiciel: Intel(R) Trusted Execution Engine - (.Intel Corporation.) [HKLM][64Bits] -- {176E2755-0A17-42C6-88E2-192AB2131278}
O42 - Logiciel: Intel(R) Trusted Execution Engine - (.Intel Corporation.) [HKLM][64Bits] -- {BCCACFE6-91A0-4F32-80A0-ADC0CA048C7B}
O42 - Logiciel: Intel(R) Trusted Execution Engine Driver - (.Intel Corporation.) [HKLM][64Bits] -- {3685B5E8-A0A8-494B-B035-B221547A4B63}
O42 - Logiciel: Java 7 Update 67 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F03217067FF}
O42 - Logiciel: LG PC Suite - (.LG Electronics.) [HKLM][64Bits] -- LG PC Suite
O42 - Logiciel: LG United Mobile Driver - (.LG Electronics.) [HKLM][64Bits] -- {2A3A4BD6-6CE0-4e2a-80D2-1D0FF6ACBFBA}
O42 - Logiciel: Malwarebytes Anti-Malware version 2.0.2.1012 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes Anti-Malware_is1
O42 - Logiciel: OpenOffice 4.1.0 - (.Apache Software Foundation.) [HKLM][64Bits] -- {B3B009FC-6909-4E00-9F43-FFB5CA93D606}
O42 - Logiciel: Qualcomm Atheros Bluetooth Suite (64) - (.Qualcomm Atheros.) [HKLM][64Bits] -- {A84A4FB1-D703-48DB-89E0-68B6499D2801}
O42 - Logiciel: Realtek Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {5BC2B5AB-80DE-4E83-B8CF-426902051D0A}
O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476}
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: Skype Web Plugin - (.Skype Technologies S.A..) [HKLM][64Bits] -- {69F300CB-D6BF-41DD-B7CC-983BAFF4EE15}
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey
O42 - Logiciel: TOSHIBA Desktop Assist - (.Toshiba Corporation.) [HKLM][64Bits] -- {C4CDCEF0-0A7A-4425-887C-33E39533D758}
O42 - Logiciel: TOSHIBA Display Utility - (.Toshiba Corporation.) [HKLM][64Bits] -- {5F6AC07E-50EF-422E-B56E-6521E5B35139}
O42 - Logiciel: TOSHIBA Function Key - (.Toshiba Corporation.) [HKLM][64Bits] -- {1844CFE2-EBA3-490A-8A5E-9BFC646342FD}
O42 - Logiciel: TOSHIBA Manuals - (.TOSHIBA.) [HKLM][64Bits] -- {90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}
O42 - Logiciel: TOSHIBA PC Health Monitor - (.Toshiba Corporation.) [HKLM][64Bits] -- {9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}
O42 - Logiciel: TOSHIBA Password Utility - (.Toshiba Corporation.) [HKLM][64Bits] -- {2DB90351-FBAA-472B-9F12-6E1EBBB354DE}
O42 - Logiciel: TOSHIBA Recovery Media Creator - (.Toshiba Corporation.) [HKLM][64Bits] -- {B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}
O42 - Logiciel: TOSHIBA Service Station - (.Toshiba Corporation.) [HKLM][64Bits] -- {BFE4C813-4DD4-4B1C-97F4-76A459055C8D} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Start Screen Option - (.Toshiba Corporation.) [HKLM][64Bits] -- {06B71035-F19F-4F76-9875-FFCCD4FC3F83}
O42 - Logiciel: TOSHIBA System Driver - (.Toshiba Corporation.) [HKLM][64Bits] -- {1E6A96A1-2BAB-43EF-8087-30437593C66C}
O42 - Logiciel: TOSHIBA System Settings - (.Toshiba Corporation.) [HKLM][64Bits] -- {4D57ED72-6B01-40BD-9CA9-012B8FC09CEB}
O42 - Logiciel: TOSHIBA VIDEO PLAYER - (.Toshiba Corporation.) [HKLM][64Bits] -- {FF07604E-C860-40E9-A230-E37FA41F103A}
O42 - Logiciel: TOSHIBA eco Utility - (.Toshiba Corporation.) [HKLM][64Bits] -- {94D2A899-0C34-4420-880E-AE337E635AB0} =>.Toshiba Corporation
O42 - Logiciel: Toshiba TEMPRO - (.Toshiba Europe GmbH.) [HKLM][64Bits] -- {F76F5214-83A8-4030-80C9-1EF57391D72A} =>.Toshiba Corporation
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
O42 - Logiciel: WinRAR 5.10 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver
~ Logic: 36 Scanned in 00mn 00s
---\\ HKCU & HKLM Software Keys
[HKCU\Software\AnyProtect] =>PUP.AnyProtect
[HKCU\Software\AppDataLow\Software\JavaSoft]
[HKCU\Software\AppDataLow]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\Emulators]
[HKCU\Software\Google]
[HKCU\Software\Intel]
[HKCU\Software\JavaSoft]
[HKCU\Software\LG Electronics]
[HKCU\Software\Licenses]
[HKCU\Software\Linkey] =>PUP.LinkeySearch
[HKCU\Software\LowRegistry]
[HKCU\Software\Macromedia]
[HKCU\Software\Mine]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Nosibay]
[HKCU\Software\OB]
[HKCU\Software\OpenOffice]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\Realtek]
[HKCU\Software\RegisteredApplications]
[HKCU\Software\Softonic] =>Toolbar.Conduit
[HKCU\Software\Store] =>PUP.Nosibay
[HKCU\Software\Synaptics]
[HKCU\Software\TeleCharger]
[HKCU\Software\Toshiba]
[HKCU\Software\Trolltech]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\Wow6432Node]
[HKCU\Software\ZebHelpProcess Helper]
[HKCU\Software\systweak]
[HKLM\Software\Atheros]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\DTS]
[HKLM\Software\Dolby]
[HKLM\Software\InstalledOptions]
[HKLM\Software\IntelVolatile]
[HKLM\Software\Intel]
[HKLM\Software\Khronos]
[HKLM\Software\Knowles]
[HKLM\Software\Macromedia]
[HKLM\Software\McAfee.com]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Nahimic]
[HKLM\Software\Nuance]
[HKLM\Software\ODBC]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\RTLSetup]
[HKLM\Software\Realtek]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\SRS Labs]
[HKLM\Software\Skype]
[HKLM\Software\SonicFocus]
[HKLM\Software\Synaptics]
[HKLM\Software\ToshibaBlobDelivery]
[HKLM\Software\Toshiba]
[HKLM\Software\Waves Audio]
[HKLM\Software\WinRAR]
[HKLM\Software\Wow6432Node\009f6c92-c8da-46f6-9ff4-ed570730d70a]
[HKLM\Software\Wow6432Node\9aad41c0-9453-4b6c-9eeb-545c4f6f19b8]
[HKLM\Software\Wow6432Node\Atheros]
[HKLM\Software\Wow6432Node\Classes]
[HKLM\Software\Wow6432Node\Clients]
[HKLM\Software\Wow6432Node\DTS, Inc.]
[HKLM\Software\Wow6432Node\DTS]
[HKLM\Software\Wow6432Node\GlobalUpdate]
[HKLM\Software\Wow6432Node\Google]
[HKLM\Software\Wow6432Node\Intel]
[HKLM\Software\Wow6432Node\JavaSoft]
[HKLM\Software\Wow6432Node\JreMetrics]
[HKLM\Software\Wow6432Node\Khronos]
[HKLM\Software\Wow6432Node\LG Electronics]
[HKLM\Software\Wow6432Node\Macromedia]
[HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware]
[HKLM\Software\Wow6432Node\MozillaPlugins]
[HKLM\Software\Wow6432Node\Mozilla]
[HKLM\Software\Wow6432Node\Nuance]
[HKLM\Software\Wow6432Node\ODBC]
[HKLM\Software\Wow6432Node\OpenOffice]
[HKLM\Software\Wow6432Node\Policies]
[HKLM\Software\Wow6432Node\Qualcomm Atheros]
[HKLM\Software\Wow6432Node\Realtek Semiconductor Corp.]
[HKLM\Software\Wow6432Node\Realtek]
[HKLM\Software\Wow6432Node\RegisteredApplications]
[HKLM\Software\Wow6432Node\SRS Labs]
[HKLM\Software\Wow6432Node\SkypeWebPlugin]
[HKLM\Software\Wow6432Node\Skype]
[HKLM\Software\Wow6432Node\Systweak]
[HKLM\Software\Wow6432Node\TOSHIBA]
[HKLM\Software\Wow6432Node\Toshiba Corporation]
[HKLM\Software\Wow6432Node\Tutorials] =>PUP.AgenceExclusive
[HKLM\Software\Wow6432Node\VideoLAN]
[HKLM\Software\Wow6432Node\Volatile]
[HKLM\Software\Wow6432Node\WildTangent]
[HKLM\Software\Wow6432Node\mozilla.org]
[HKLM\Software\Wow6432Node\sMedio]
[HKLM\Software\Wow6432Node]
~ Key Software: 179 Scanned in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 08/05/2014 - 18:52:32 - [] ----D C:\Program Files (x86)\Atheros
O43 - CFD: 08/05/2014 - 18:56:55 - [] ----D C:\Program Files (x86)\Bluetooth Suite
O43 - CFD: 17/08/2014 - 17:43:15 - [] ----D C:\Program Files (x86)\Common Files
O43 - CFD: 08/05/2014 - 18:50:07 - [] ----D C:\Program Files (x86)\DTS, Inc
O43 - CFD: 08/05/2014 - 19:07:51 - [] ----D C:\Program Files (x86)\eBay =>Toolbar.eBay
O43 - CFD: 21/08/2014 - 14:13:15 - [] ----D C:\Program Files (x86)\globalUpdate
O43 - CFD: 17/08/2014 - 18:28:19 - [] ----D C:\Program Files (x86)\Google
O43 - CFD: 13/08/2014 - 22:18:20 - [] --H-D C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 08/05/2014 - 18:46:03 - [] ----D C:\Program Files (x86)\Intel
O43 - CFD: 18/08/2014 - 04:01:15 - [] ----D C:\Program Files (x86)\Internet Explorer
O43 - CFD: 17/08/2014 - 17:38:27 - [] ----D C:\Program Files (x86)\Java
O43 - CFD: 13/08/2014 - 23:01:00 - [] ----D C:\Program Files (x86)\LG Electronics
O43 - CFD: 21/08/2014 - 13:56:43 - [] ----D C:\Program Files (x86)\Malwarebytes Anti-Malware
O43 - CFD: 05/12/2013 - 22:35:08 - [] ----D C:\Program Files (x86)\Microsoft Office
O43 - CFD: 22/08/2013 - 17:36:30 - [] ----D C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 29/08/2013 - 00:21:55 - [] ----D C:\Program Files (x86)\MSBuild
O43 - CFD: 11/08/2014 - 15:26:15 - [] ----D C:\Program Files (x86)\OpenOffice 4
O43 - CFD: 10/08/2014 - 00:18:54 - [0] ----D C:\Program Files (x86)\predm
O43 - CFD: 08/05/2014 - 18:53:26 - [] ----D C:\Program Files (x86)\Realtek
O43 - CFD: 29/08/2013 - 00:21:55 - [] ----D C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 21/08/2014 - 14:14:50 - [0] ----D C:\Program Files (x86)\Settings Manager =>PUP.SystemK
O43 - CFD: 21/08/2014 - 15:04:42 - [] ----D C:\Program Files (x86)\SkypeWebPlugin
O43 - CFD: 08/05/2014 - 18:49:51 - [0] --H-D C:\Program Files (x86)\Temp
O43 - CFD: 08/05/2014 - 19:07:17 - [] ----D C:\Program Files (x86)\TOSHIBA
O43 - CFD: 10/08/2014 - 00:07:51 - [] ----D C:\Program Files (x86)\TOSHIBA Games
O43 - CFD: 08/05/2014 - 19:09:08 - [] ----D C:\Program Files (x86)\Toshiba TEMPRO =>.Toshiba Corporation
O43 - CFD: 11/08/2014 - 00:14:25 - [] ----D C:\Program Files (x86)\VideoLAN
O43 - CFD: 18/08/2014 - 04:01:15 - [] ----D C:\Program Files (x86)\Windows Defender
O43 - CFD: 18/08/2014 - 04:01:15 - [] ----D C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 18/08/2014 - 04:01:15 - [] ----D C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 13/08/2014 - 20:01:23 - [] ----D C:\Program Files (x86)\Windows Multimedia Platform
O43 - CFD: 22/08/2013 - 17:36:30 - [] ----D C:\Program Files (x86)\Windows NT
O43 - CFD: 18/08/2014 - 04:01:15 - [] ----D C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 13/08/2014 - 20:01:21 - [] ----D C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 22/08/2013 - 17:36:30 - [] -SH-D C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 22/08/2013 - 17:36:30 - [] ----D C:\Program Files (x86)\WindowsPowerShell
O43 - CFD: 11/08/2014 - 15:15:01 - [] ----D C:\Program Files (x86)\WinRAR
O43 - CFD: 21/08/2014 - 17:01:58 - [] ----D C:\Program Files (x86)\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 08/05/2014 - 18:56:56 - [] ----D C:\Program Files (x86)\Common Files\Atheros
O43 - CFD: 08/05/2014 - 18:48:46 - [] ----D C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 08/05/2014 - 18:45:48 - [] ----D C:\Program Files (x86)\Common Files\Intel
O43 - CFD: 17/08/2014 - 17:43:15 - [] ----D C:\Program Files (x86)\Common Files\Java
O43 - CFD: 08/05/2014 - 18:59:28 - [] ----D C:\Program Files (x86)\Common Files\Microsoft Shared
O43 - CFD: 22/08/2013 - 17:36:33 - [] ----D C:\Program Files (x86)\Common Files\Services
O43 - CFD: 18/08/2014 - 04:01:15 - [] ----D C:\Program Files (x86)\Common Files\System
O43 - CFD: 08/05/2014 - 19:03:43 - [] ----D C:\Program Files (x86)\Common Files\Toshiba Shared
O43 - CFD: 22/08/2013 - 16:45:52 - [] -SH-D C:\ProgramData\Application Data
O43 - CFD: 02/08/2014 - 20:53:37 - [] -SH-D C:\ProgramData\Bureau
O43 - CFD: 22/08/2013 - 16:45:52 - [] -S--D C:\ProgramData\Desktop
O43 - CFD: 22/08/2013 - 16:45:52 - [] -SH-D C:\ProgramData\Documents
O43 - CFD: 09/08/2014 - 11:55:09 - [] ----D C:\ProgramData\DSearchLink =>Toolbar.DeltaSearch
O43 - CFD: 08/05/2014 - 18:42:51 - [] ----D C:\ProgramData\Intel
O43 - CFD: 21/08/2014 - 13:56:18 - [] ----D C:\ProgramData\Malwarebytes
O43 - CFD: 09/08/2014 - 11:08:08 - [] ----D C:\ProgramData\McAfee
O43 - CFD: 02/08/2014 - 20:53:37 - [] -SH-D C:\ProgramData\Menu Démarrer
O43 - CFD: 13/08/2014 - 21:31:36 - [] -S--D C:\ProgramData\Microsoft
O43 - CFD: 02/08/2014 - 20:53:37 - [] -SH-D C:\ProgramData\Modèles
O43 - CFD: 14/08/2014 - 19:05:57 - [] ----D C:\ProgramData\Mozilla
O43 - CFD: 17/08/2014 - 17:43:14 - [0] ----D C:\ProgramData\Oracle
O43 - CFD: 08/05/2014 - 19:03:12 - [] ----D C:\ProgramData\Package Cache
O43 - CFD: 08/05/2014 - 18:52:06 - [] ----D C:\ProgramData\Qualcomm Atheros
O43 - CFD: 08/05/2014 - 19:33:29 - [] ----D C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 21/08/2014 - 13:44:51 - [] ----D C:\ProgramData\RogueKiller
O43 - CFD: 08/05/2014 - 18:50:07 - [] ----D C:\ProgramData\SRS Labs
O43 - CFD: 22/08/2013 - 16:45:52 - [] -SH-D C:\ProgramData\Start Menu
O43 - CFD: 17/08/2014 - 17:43:17 - [] ----D C:\ProgramData\Sun
O43 - CFD: 21/08/2014 - 14:13:21 - [0] ----D C:\ProgramData\Systweak
O43 - CFD: 22/08/2013 - 16:45:52 - [] -SH-D C:\ProgramData\Templates
O43 - CFD: 03/08/2014 - 08:25:54 - [] ----D C:\ProgramData\Toshiba
O43 - CFD: 09/08/2014 - 11:15:02 - [] ----D C:\ProgramData\ToshibaEurope
O43 - CFD: 10/08/2014 - 00:06:45 - [] ----D C:\ProgramData\WildTangent
O43 - CFD: 03/08/2014 - 08:22:07 - [] ----D C:\Users\Alan R\AppData\Roaming\Adobe
O43 - CFD: 09/08/2014 - 12:00:40 - [0] ----D C:\Users\Alan R\AppData\Roaming\ap_logs
O43 - CFD: 13/08/2014 - 23:14:26 - [] ----D C:\Users\Alan R\AppData\Roaming\LG Electronics
O43 - CFD: 09/08/2014 - 11:11:55 - [] ----D C:\Users\Alan R\AppData\Roaming\Macromedia
O43 - CFD: 17/08/2014 - 19:19:02 - [] -S--D C:\Users\Alan R\AppData\Roaming\Microsoft
O43 - CFD: 14/08/2014 - 19:08:33 - [] ----D C:\Users\Alan R\AppData\Roaming\Mozilla
O43 - CFD: 17/08/2014 - 18:45:08 - [0] ----D C:\Users\Alan R\AppData\Roaming\Nosibay =>PUP.BubbleDock
O43 - CFD: 11/08/2014 - 14:28:19 - [] ----D C:\Users\Alan R\AppData\Roaming\OpenOffice
O43 - CFD: 17/08/2014 - 17:43:48 - [] ----D C:\Users\Alan R\AppData\Roaming\Oracle
O43 - CFD: 17/08/2014 - 18:48:28 - [0] ----D C:\Users\Alan R\AppData\Roaming\Store =>PUP.Nosibay
O43 - CFD: 17/08/2014 - 18:42:30 - [] ----D C:\Users\Alan R\AppData\Roaming\sweet-page =>PUP.SweetPage
O43 - CFD: 21/08/2014 - 14:13:21 - [0] ----D C:\Users\Alan R\AppData\Roaming\Systweak
O43 - CFD: 21/08/2014 - 14:13:26 - [] ----D C:\Users\Alan R\AppData\Roaming\vlc
O43 - CFD: 21/08/2014 - 14:12:49 - [] ----D C:\Users\Alan R\AppData\Roaming\VOPackage =>Adware.Downware
O43 - CFD: 13/08/2014 - 11:39:18 - [] ----D C:\Users\Alan R\AppData\Roaming\WinRAR
O43 - CFD: 21/08/2014 - 17:02:53 - [] ----D C:\Users\Alan R\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 03/08/2014 - 08:21:52 - [] -SH-D C:\Users\Alan R\AppData\Local\Application Data
O43 - CFD: 10/08/2014 - 00:22:02 - [] ----D C:\Users\Alan R\AppData\Local\Apps
O43 - CFD: 12/08/2014 - 01:37:31 - [0] ----D C:\Users\Alan R\AppData\Local\Deployment
O43 - CFD: 14/08/2014 - 18:28:10 - [] ----D C:\Users\Alan R\AppData\Local\Diagnostics
O43 - CFD: 13/08/2014 - 20:24:20 - [] -SH-D C:\Users\Alan R\AppData\Local\EmieSiteList
O43 - CFD: 13/08/2014 - 20:24:20 - [] -SH-D C:\Users\Alan R\AppData\Local\EmieUserList
O43 - CFD: 11/08/2014 - 14:10:45 - [] ----D C:\Users\Alan R\AppData\Local\globalUpdate
O43 - CFD: 17/08/2014 - 18:28:48 - [] ----D C:\Users\Alan R\AppData\Local\Google
O43 - CFD: 03/08/2014 - 08:21:52 - [] -SH-D C:\Users\Alan R\AppData\Local\Historique
O43 - CFD: 14/08/2014 - 14:23:05 - [] ----D C:\Users\Alan R\AppData\Local\Intel_Corporation
O43 - CFD: 13/08/2014 - 23:01:48 - [] ----D C:\Users\Alan R\AppData\Local\LG Electronics
O43 - CFD: 14/08/2014 - 19:43:15 - [] ----D C:\Users\Alan R\AppData\Local\Macromedia
O43 - CFD: 14/08/2014 - 18:28:08 - [] ----D C:\Users\Alan R\AppData\Local\Microsoft
O43 - CFD: 14/08/2014 - 19:08:34 - [] ----D C:\Users\Alan R\AppData\Local\Mozilla
O43 - CFD: 11/08/2014 - 19:58:53 - [] ----D C:\Users\Alan R\AppData\Local\Packages
O43 - CFD: 09/08/2014 - 11:47:19 - [] ----D C:\Users\Alan R\AppData\Local\Programs
O43 - CFD: 21/08/2014 - 17:02:00 - [] ----D C:\Users\Alan R\AppData\Local\Temp
O43 - CFD: 03/08/2014 - 08:21:52 - [] -SH-D C:\Users\Alan R\AppData\Local\Temporary Internet Files
O43 - CFD: 03/08/2014 - 08:24:05 - [] ----D C:\Users\Alan R\AppData\Local\TOSHIBA
O43 - CFD: 03/08/2014 - 08:22:06 - [0] ----D C:\Users\Alan R\AppData\Local\VirtualStore
O43 - CFD: 22/08/2013 - 17:36:32 - [] R---D C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 22/08/2013 - 17:36:32 - [] R---D C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 13/08/2014 - 20:21:03 - [] R---D C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 22/08/2013 - 17:36:32 - [] ----D C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 13/08/2014 - 20:21:03 - [] R---D C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 22/08/2013 - 17:36:32 - [] R---D C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 11/08/2014 - 15:23:32 - [] ----D C:\Users\Alan R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
~ Program Folder: 114 Scanned in 00mn 00s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.C27B20D9AA9BE41CCBFD512AABB0E6C3] - 06/08/2014 - 23:38:18 ---A- . (.Microsoft Corporation - Mise à jour des données de compatibilité de.) -- C:\Windows\System32\aepdu.dll [697856]
O44 - LFC:[MD5.A39C4AB750E0AD4431C7B7F46AB0EBED] - 06/08/2014 - 23:39:55 ---A- . (.Microsoft Corporation - Pilote Win32 multi-utilisateurs.) -- C:\Windows\System32\win32k.sys [4148224]
O44 - LFC:[MD5.87CEF71F9D5951C9379D2F956C07C37D] - 07/08/2014 - 03:12:27 ---A- . (.Microsoft Corporation - GDI Client DLL.) -- C:\Windows\System32\gdi32.dll [1336624]
O44 - LFC:[MD5.04D10A4929B36BF831BF883FFD56E8AB] - 09/08/2014 - 10:38:40 ---A- . (...) -- C:\Windows\epplauncher.mif [2152]
O44 - LFC:[MD5.D8B85CC423236928CE06C0BFAA1A55B8] - 09/08/2014 - 10:48:04 ---A- . (.Pas de propriétaire - Registry Optimizer.) -- C:\Windows\System32\roboot64.exe [20280]
O44 - LFC:[MD5.2EF4E5EDE91EF893603E8B72890AC605] - 09/08/2014 - 10:50:35 ---A- . (.Corsica - Web Instrumentation Driver.) -- C:\Windows\System32\Drivers\webinstr.sys [57528]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 09/08/2014 - 10:50:35 --HA- . (...) -- C:\Windows\System32\Drivers\Msft_Kernel_webinstr_01009.Wdf [0]
O44 - LFC:[MD5.6FB598E8DE02D879D17B35F144A1B3BC] - 09/08/2014 - 11:03:26 ----- . (.Microsoft Corporation - Microsoft Malware Protection Signature Upda.) -- C:\Windows\System32\MpSigStub.exe [270496]
O44 - LFC:[MD5.6EFAF0D87291F9FBD7C0ED3BD56511AA] - 10/08/2014 - 23:24:56 ---A- . (.Microsoft Corporation - Crypto API32.) -- C:\Windows\System32\crypt32.dll [1943536]
O44 - LFC:[MD5.4A8D40E38BC2C57E5D630AD6994A85CB] - 10/08/2014 - 23:25:15 ---A- . (.Microsoft Corporation - Exécuteur de file d'attente d'opérations pr.) -- C:\Windows\System32\poqexec.exe [139776]
O44 - LFC:[MD5.3E245CCA42D78B9626A79FE77E111D7B] - 10/08/2014 - 23:25:49 ---A- . (.Microsoft Corporation - Cet outil collecte les fichiers journaux du.) -- C:\Windows\System32\WSCollect.exe [84480]
O44 - LFC:[MD5.389C4E97E3A498159B625A7A13EA4560] - 10/08/2014 - 23:27:20 ---A- . (.Microsoft Corporation - Direct3D 10 Rasterizer.) -- C:\Windows\System32\d3d10warp.dll [2397184]
O44 - LFC:[MD5.053472337FDD116BD010C88DB0C34DF1] - 10/08/2014 - 23:27:21 ---A- . (.Microsoft Corporation - Bibliothèque Microsoft D2D.) -- C:\Windows\System32\d2d1.dll [4604416]
O44 - LFC:[MD5.447CB6699A8EAD2BC516991738A16277] - 10/08/2014 - 23:30:46 ---A- . (.Microsoft Corporation - Windows NT Image Helper.) -- C:\Windows\System32\imagehlp.dll [75360]
O44 - LFC:[MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - 10/08/2014 - 23:30:56 ---A- . (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [447488]
O44 - LFC:[MD5.C7DFBE21051D5E44B479CBF74B968335] - 10/08/2014 - 23:31:00 ---A- . (.Microsoft Corporation - Windows Image Helper.) -- C:\Windows\System32\dbghelp.dll [1486848]
O44 - LFC:[MD5.819A1E0F89B6AC222E9D95CA000A40B1] - 10/08/2014 - 23:31:01 ---A- . (.Microsoft Corporation - Windows Symbolic Debugger Engine.) -- C:\Windows\System32\dbgeng.dll [4175360]
O44 - LFC:[MD5.C993A0B97BECD3AAF5158E3869878465] - 10/08/2014 - 23:31:07 ---A- . (.Microsoft Corporation - Service de la plateforme de protection logi.) -- C:\Windows\System32\sppsvc.exe [6353960]
O44 - LFC:[MD5.68085A085DE8E3540EE8E02CAE575B2E] - 10/08/2014 - 23:32:00 ---A- . (...) -- C:\Windows\System32\OEMLicense.dll [138240]
O44 - LFC:[MD5.0B9FBEC5714523FF76DDFEB320FE2DF2] - 10/08/2014 - 23:32:02 ---A- . (.Microsoft Corporation - DLL client de périphériques d'images fixes.) -- C:\Windows\System32\sti.dll [303616]
O44 - LFC:[MD5.A1A5E79C0D1352AFDC08328A623DA051] - 10/08/2014 - 23:32:03 ---A- . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) -- C:\Windows\System32\Drivers\rdbss.sys [408576]
O44 - LFC:[MD5.E287F157F7A0011D93179C64EF8ADCF2] - 10/08/2014 - 23:32:07 ---A- . (.Microsoft Corporation - DLL du service PNRP.) -- C:\Windows\System32\pnrpsvc.dll [376320]
O44 - LFC:[MD5.847CFF96ACB575CE73C0E2E86C6BA993] - 10/08/2014 - 23:32:07 ---A- . (.Microsoft Corporation - Fonctions de vérification de l'orthographe.) -- C:\Windows\System32\MsSpellCheckingFacility.dll [842752]
O44 - LFC:[MD5.A95838FFFAEAA7500263D491575F7E0C] - 10/08/2014 - 23:32:11 ---A- . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1214976]
O44 - LFC:[MD5.B9D968D8E2B0F9C6301CEB39CFC9B9E4] - 10/08/2014 - 23:34:32 ---A- . (.Microsoft Corporation - Power Dependency Coordinator Driver.) -- C:\Windows\System32\Drivers\pdc.sys [86872]
O44 - LFC:[MD5.0044B31F93946D5D41982314381FE431] - 10/08/2014 - 23:34:33 ---A- . (.Microsoft Corporation - Serial Class Extension V2.) -- C:\Windows\System32\Drivers\SerCx2.sys [146776]
O44 - LFC:[MD5.139CFCDCD36B1B1782FD8C0014AC9B0E] - 10/08/2014 - 23:34:34 ---A- . (.Microsoft Corporation - Intel Power Engine Plugin.) -- C:\Windows\System32\Drivers\intelpep.sys [39768]
O44 - LFC:[MD5.AD95F86C8D1843BE653F89FDE213F9E7] - 10/08/2014 - 23:38:38 ---A- . (.Microsoft Corporation - DLL d'inscription de périphérique.) -- C:\Windows\System32\deviceregistration.dll [207872]
O44 - LFC:[MD5.1C89EF529DB7DCA98E801EFDCC8437DE] - 10/08/2014 - 23:38:39 ---A- . (.Microsoft Corporation - Microsoft Bluetooth Audio Multiprofile Mana.) -- C:\Windows\System32\Drivers\BtaMPM.sys [19456]
O44 - LFC:[MD5.CD45E3FE736150D45EFDC9145DA53757] - 10/08/2014 - 23:38:40 ---A- . (.Microsoft Corporation - Background Broker Infrastructure Client Lib.) -- C:\Windows\System32\bi.dll [24064]
O44 - LFC:[MD5.FF9F658A51CAD74C25AF83038DBD735D] - 10/08/2014 - 23:38:40 ---A- . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Inter.) -- C:\Windows\System32\msieftp.dll [306688]
O44 - LFC:[MD5.B7342B3C58E91107F6E946A93D9D4EFD] - 10/08/2014 - 23:38:41 ---A- . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys [142848]
O44 - LFC:[MD5.91433B44B1EF301E7DD696EB5281BC20] - 10/08/2014 - 23:38:42 ---A- . (.Microsoft Corporation - Accès distant PPP EAP-TLS.) -- C:\Windows\System32\rastls.dll [589824]
O44 - LFC:[MD5.34F8F7A0B782798F6A9511157BCC3E32] - 10/08/2014 - 23:38:43 ---A- . (.Microsoft Corporation - WinRT Windows Graphics DLL.) -- C:\Windows\System32\Windows.Graphics.dll [273408]
O44 - LFC:[MD5.660891FFB1B22FF39AADB3F45CE15D45] - 10/08/2014 - 23:38:45 ---A- . (.Microsoft Corporation - Media Foundation Direct Show wrapper DLL.) -- C:\Windows\System32\mfds.dll [470016]
O44 - LFC:[MD5.40B228D05DB02F4A5F2452600999F53F] - 10/08/2014 - 23:38:46 ---A- . (.Microsoft Corporation - DLL source et récepteur MPEG4 Media Foundat.) -- C:\Windows\System32\mfmp4srcsnk.dll [809872]
O44 - LFC:[MD5.D65B1C952AEB864C2BAC7A770B17ECCE] - 10/08/2014 - 23:38:50 ---A- . (.Microsoft Corporation - Service Broker pour les événements système.) -- C:\Windows\System32\SystemEventsBrokerServer.dll [282112]
O44 - LFC:[MD5.32370AF583EC8B24D790E1B9201D6811] - 10/08/2014 - 23:39:01 ---A- . (.Microsoft Corporation - Microsoft DTV-DVD Video Decoder.) -- C:\Windows\System32\msmpeg2vdec.dll [3210528]
O44 - LFC:[MD5.4082B1F66087FC1D8B4759569A194391] - 11/08/2014 - 12:31:23 ---A- . (.Microsoft Corporation - Analyseur de Presse-papiers RDP.) -- C:\Windows\System32\rdpclip.exe [338944]
O44 - LFC:[MD5.E8E50E7703204AE06C6B5FEFE2F701E7] - 11/08/2014 - 12:31:23 ---A- . (.Microsoft Corporation - Infrastructure de gestion.) -- C:\Windows\System32\miutils.dll [226304]
O44 - LFC:[MD5.504092E4BA97FCEB53912BB6CD156547] - 11/08/2014 - 12:31:23 ---A- . (.Microsoft Corporation - Logiciel de transfert de fichiers.) -- C:\Windows\System32\ftp.exe [53248]
O44 - LFC:[MD5.053445AED2A855477496965B8EA16A6B] - 11/08/2014 - 12:31:29 ---A- . (.Microsoft Corporation - UI générique EAP.) -- C:\Windows\System32\eappgnui.dll [101888]
O44 - LFC:[MD5.F48C144251B36850B67AB8E6D9E20E92] - 11/08/2014 - 12:31:30 ---A- . (.Microsoft Corporation - IE ETW Collector Service.) -- C:\Windows\System32\ieetwcollector.exe [111616]
O44 - LFC:[MD5.5C8EE485EF4AEA9BCECD36A46599E5C9] - 11/08/2014 - 12:31:31 ---A- . (.Microsoft Corporation - Configuration d'homologue EAP.) -- C:\Windows\System32\eappcfg.dll [335360]
O44 - LFC:[MD5.6B06E2D11E604BE2B1A406C4CB3B90DE] - 11/08/2014 - 12:31:34 ---A- . (.Microsoft Corporation - Microsoft NVM Express Storport Miniport Dri.) -- C:\Windows\System32\Drivers\stornvme.sys [57176]
O44 - LFC:[MD5.2F5076AA4F8195B0ED7D448EDC763D86] - 11/08/2014 - 12:31:34 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Proxy.) -- C:\Windows\System32\TSWbPrxy.exe [83968]
O44 - LFC:[MD5.F4414F57DF2CECB8FC969AA43A6B0D50] - 11/08/2014 - 12:31:35 ---A- . (.Microsoft Corporation - Composants de l'application d'assistance à.) -- C:\Windows\System32\ipnathlp.dll [433664]
O44 - LFC:[MD5.63CB763FE4CEADFFF5F047332814E8F9] - 11/08/2014 - 12:31:35 ---A- . (.Microsoft Corporation - Stratégie de verrouillage Windows.) -- C:\Windows\System32\wldp.dll [44936]
O44 - LFC:[MD5.DFC4050D58565ADBEE793A8D4AEBDAE6] - 11/08/2014 - 12:31:36 ---A- . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [903168]
O44 - LFC:[MD5.433ECDE01A52691FA7ACA51C10C09B70] - 11/08/2014 - 12:31:37 ---A- . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) -- C:\Windows\System32\Drivers\usbccgp.sys [155480]
O44 - LFC:[MD5.4EFC6306A619F49A95FB83538C812461] - 11/08/2014 - 12:31:38 ---A- . (.Microsoft Corporation - Fournisseur de proxy PCSV pour périphérique.) -- C:\Windows\System32\pcsvDevice.dll [286208]
O44 - LFC:[MD5.CA56145B0F1FA54FA21C2E0A7AC9C119] - 11/08/2014 - 12:31:38 ---A- . (.Microsoft Corporation - Maintenance Scheduler.) -- C:\Windows\System32\msched.dll [132608]
O44 - LFC:[MD5.2B78788A1485F9B99A578A299DF42C02] - 11/08/2014 - 12:31:38 ---A- . (.Microsoft Corporation - Server driver.) -- C:\Windows\System32\Drivers\srv.sys [454656]
O44 - LFC:[MD5.12BF0E1F71E2EA1A52B5D1723F87BD16] - 11/08/2014 - 12:31:40 ---A- . (.Microsoft Corporation - Microsoft ThirdPartyEapDispatcher.) -- C:\Windows\System32\eapp3hst.dll [325120]
O44 - LFC:[MD5.D920A92D7F103F7C424A16FBEF0AA790] - 11/08/2014 - 12:31:41 ---A- . (.Microsoft Corporation - Plugin MF RDP.) -- C:\Windows\System32\tsmf.dll [391512]
O44 - LFC:[MD5.2BEF4B9C1CD2E090C97C0937B859C0E7] - 11/08/2014 - 12:31:43 ---A- . (.Microsoft Corporation - Intel Network Kernel Debug Extensibility Mo.) -- C:\Windows\System32\kd_02_8086.dll [171864]
O44 - LFC:[MD5.7F9AEC82D7480068C6D444D4FD8FB36F] - 11/08/2014 - 12:31:44 ---A- . (.Microsoft Corporation - Service homologue EAPHost Microsoft.) -- C:\Windows\System32\eapphost.dll [331776]
O44 - LFC:[MD5.B953A10B98ED83C2EF7C7D9153F18924] - 11/08/2014 - 12:31:44 ---A- . (.Microsoft Corporation - Windows.Networking.BackgroundTransfer DLL.) -- C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll [578560]
O44 - LFC:[MD5.0FC25089426F313B1B271FEDCB0814DB] - 11/08/2014 - 12:31:46 ---A- . (.Microsoft Corporation - Direct3D 10 to Direct3D9 Translation Runtim.) -- C:\Windows\System32\d3d10level9.dll [699840]
O44 - LFC:[MD5.03CC7C6D00212DF6D6CB5C93432410ED] - 11/08/2014 - 12:31:47 ---A- . (.Microsoft Corporation - Programme principal d'automation de l'inter.) -- C:\Windows\System32\UIAutomationCore.dll [1147904]
O44 - LFC:[MD5.1503510900836FA6A0E4FE9662FE0768] - 11/08/2014 - 12:31:51 ---A- . (.Microsoft Corporation - Composant Connexion RemoteApp et Bureau à d.) -- C:\Windows\System32\TSWorkspace.dll [1011712]
O44 - LFC:[MD5.A8AA0F50CE95FCD1CB9588DB0A961D98] - 11/08/2014 - 12:31:52 ---A- . (.Microsoft Corporation - DLL Windows.Web.Http.) -- C:\Windows\System32\Windows.Web.Http.dll [1160704]
O44 - LFC:[MD5.222D5E0C79E9C87EF0C4D02651EE765A] - 11/08/2014 - 12:31:59 ---A- . (.Microsoft Corporation - Media Foundation ASF Source and Sink DLL.) -- C:\Windows\System32\mfasfsrcsnk.dll [1067080]
O44 - LFC:[MD5.D750DA0AC7ECFF1F9C76FCAC9285E499] - 11/08/2014 - 13:09:10 ---A- . (...) -- C:\Windows\win.ini [226]
O44 - LFC:[MD5.5F84D8C3831A559CEB55F894CD24E2B5] - 11/08/2014 - 15:42:05 ---A- . (.Microsoft Corporation - Codec pour photographie Windows Media Photo.) -- C:\Windows\System32\WMPhoto.dll [393216]
O44 - LFC:[MD5.6F531F98B8601A9E7A93F8FEC393E2D1] - 11/08/2014 - 15:42:06 ---A- . (.Microsoft Corporation - Program Compatibility Assistant User Interf.) -- C:\Windows\System32\pcaui.exe [18944]
O44 - LFC:[MD5.BE94090FCBB95B6F22E952D27BD2610E] - 11/08/2014 - 15:43:18 ---A- . (.Microsoft Corporation - Client Gestion des droits Windows
lilidurhone
Messages postés
43347
Date d'inscription
lundi 25 avril 2011
Statut
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 807
21 août 2014 à 21:14
21 août 2014 à 21:14
* Pour héberger le rapport, rends toi sur cjoint.com
* Clique sur choisissez un fichier va chercher le rapport dans ton PC.
* Le rapport est hébergé:
- Pour XP : C:\Documents and Settings\username\Local Settings\Application Data\ZHP
- Depuis Vista : C:\Users\username\AppData\Roaming\ZHP
* Une fois le rapport trouvé, sélectionne le, et clique sur Ouvrir
* Choisis le type de diffusion (illimitée ou 21 jours)
* Puis cliques sur créer le lien cjoint
* Une fois que tu auras obtenu le lien copies colle dans ta prochaine réponse
* Pour t'aider https://www.commentcamarche.net/faq/29493-utiliser-cjoint-pour-heberger-des-fichiers
* Clique sur choisissez un fichier va chercher le rapport dans ton PC.
* Le rapport est hébergé:
- Pour XP : C:\Documents and Settings\username\Local Settings\Application Data\ZHP
- Depuis Vista : C:\Users\username\AppData\Roaming\ZHP
* Une fois le rapport trouvé, sélectionne le, et clique sur Ouvrir
* Choisis le type de diffusion (illimitée ou 21 jours)
* Puis cliques sur créer le lien cjoint
* Une fois que tu auras obtenu le lien copies colle dans ta prochaine réponse
* Pour t'aider https://www.commentcamarche.net/faq/29493-utiliser-cjoint-pour-heberger-des-fichiers
lilidurhone
Messages postés
43347
Date d'inscription
lundi 25 avril 2011
Statut
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 807
18 août 2014 à 07:44
18 août 2014 à 07:44
Hello
C'est un détournement du fichier host
Roguekiller fera l'affaire
C'est un détournement du fichier host
Roguekiller fera l'affaire
wyattroux
Messages postés
3
Date d'inscription
dimanche 17 août 2014
Statut
Membre
Dernière intervention
21 août 2014
21 août 2014 à 14:00
21 août 2014 à 14:00
Bonjour,
Comme vous me l'avez conseillez j'ai utilisé Roguekiller et j'ai pris la peine de demander un rapport que je ne comprends pas ... Pourriez vous donc me dire se que cela signifie ? et si tout est arrangé comme il faut ?
RogueKiller V9.2.8.0 [Jul 11 2014] par Adlice Software
Mail : https://www.adlice.com/contact/
Remontées : https://forum.adlice.com/
Site Web : http://www.surlatoile.org/RogueKiller/
Blog : https://www.adlice.com/
Système d'exploitation : Windows 8.1 (6.3.9200 ) 64 bits version
Démarrage : Mode normal
Utilisateur : Alan R [Droits d'admin]
Mode : Suppression -- Date : 08/21/2014 13:55:13
¤¤¤ Processus malicieux : 2 ¤¤¤
[Suspicious.Path] (SVC) IePluginServices -- C:\ProgramData\IePluginServices\PluginService.exe -service[-] -> STOPPÉ
[Suspicious.Path] (SVC) servervo -- C:\Users\Alan R\AppData\Roaming\VOPackage\VOsrv.exe[-] -> STOPPÉ
¤¤¤ Entrées de registre : 22 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-1709042038-2155373347-2631235414-1001\Software\Microsoft\Windows\CurrentVersion\Run | WindApp : "C:\Users\Alan R\AppData\Roaming\Store\WindApp\WindApp Update.exe" /winstartup [x] -> SUPPRIMÉ
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-1709042038-2155373347-2631235414-1001\Software\Microsoft\Windows\CurrentVersion\Run | WindApp : "C:\Users\Alan R\AppData\Roaming\Store\WindApp\WindApp Update.exe" /winstartup -> ERROR [2]
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IePluginServices -> SUPPRIMÉ
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\servervo -> SUPPRIMÉ
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IePluginServices -> SUPPRIMÉ
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\servervo -> SUPPRIMÉ
[PUM.Proxy] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> REMPLACÉ (0)
[PUM.Proxy] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> REMPLACÉ (0)
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> REMPLACÉ (0)
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> REMPLACÉ (0)
[PUM.Proxy] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:50774;https=127.0.0.1:50774 -> SUPPRIMÉ
[PUM.Proxy] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:50774;https=127.0.0.1:50774 -> ERROR [2]
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:50774;https=127.0.0.1:50774 -> ERROR [2]
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:50774;https=127.0.0.1:50774 -> ERROR [2]
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> REMPLACÉ (0)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> REMPLACÉ (0)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> REMPLACÉ (0)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> REMPLACÉ (0)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1709042038-2155373347-2631235414-1001\Software\Microsoft\Internet Explorer\Main | Start Page : about:blank -> REMPLACÉ (https://www.msn.com/fr-fr/?ocid=iehp
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1709042038-2155373347-2631235414-1001\Software\Microsoft\Internet Explorer\Main | Start Page : about:blank -> REMPLACÉ (https://www.msn.com/fr-fr/?ocid=iehp
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-1709042038-2155373347-2631235414-1001\Software\Microsoft\Internet Explorer\Main | Search Page : https://search.safefinder.com/?st=ds&q={searchTerms} -> REMPLACÉ (https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-1709042038-2155373347-2631235414-1001\Software\Microsoft\Internet Explorer\Main | Search Page : https://search.safefinder.com/?st=ds&q={searchTerms} -> REMPLACÉ (https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
¤¤¤ Tâches planifiées : 0 ¤¤¤
¤¤¤ Fichiers : 0 ¤¤¤
¤¤¤ Fichier HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: NON CHARGE [0xc000036b]) ¤¤¤
¤¤¤ Navigateurs web : 6 ¤¤¤
[FIREFX:Addon] zb16lrul.default : Selenium Expert (Selenium IDE) [selenium-expert_selenium-ide@Samit.Badle] -> SUPPRIMÉ
[FIREFX:Addon] zb16lrul.default : BlockAndSurf [{9A3B7448-C8A3-4EF3-C7D8-33FEA5854401}] -> SUPPRIMÉ
[FIREFX:Addon] zb16lrul.default : videos MediaPlay-Air [5c8764929678437cbd90994a5a82@ac863d978ade40948f4c7f15bb3c4.com] -> SUPPRIMÉ
[CHROME:Addon] Default : Google Docs [aohghmighlieiainnegkcijnfilokake] -> SUPPRIMÉ
[CHROME:Addon] Default : videos MediaPlay-Air [iklgpchfbohgmghgfagediakopecfmbm] -> ERROR [2]
[CHROME:Addon] Default : Google Wallet [nmmhkkegccagdldgiimedpiccmgmieda] -> ERROR [2]
¤¤¤ MBR Verif : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MQ01ABD075 +++++
--- User ---
[MBR] a84dd93b5b19931ceaddbccc47850486
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 2097151 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_SCN_08212014_134634.log - RKreport_DEL_08212014_134641.log - RKreport_SCN_08212014_135334.log
Merci d'avance !
Comme vous me l'avez conseillez j'ai utilisé Roguekiller et j'ai pris la peine de demander un rapport que je ne comprends pas ... Pourriez vous donc me dire se que cela signifie ? et si tout est arrangé comme il faut ?
RogueKiller V9.2.8.0 [Jul 11 2014] par Adlice Software
Mail : https://www.adlice.com/contact/
Remontées : https://forum.adlice.com/
Site Web : http://www.surlatoile.org/RogueKiller/
Blog : https://www.adlice.com/
Système d'exploitation : Windows 8.1 (6.3.9200 ) 64 bits version
Démarrage : Mode normal
Utilisateur : Alan R [Droits d'admin]
Mode : Suppression -- Date : 08/21/2014 13:55:13
¤¤¤ Processus malicieux : 2 ¤¤¤
[Suspicious.Path] (SVC) IePluginServices -- C:\ProgramData\IePluginServices\PluginService.exe -service[-] -> STOPPÉ
[Suspicious.Path] (SVC) servervo -- C:\Users\Alan R\AppData\Roaming\VOPackage\VOsrv.exe[-] -> STOPPÉ
¤¤¤ Entrées de registre : 22 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-1709042038-2155373347-2631235414-1001\Software\Microsoft\Windows\CurrentVersion\Run | WindApp : "C:\Users\Alan R\AppData\Roaming\Store\WindApp\WindApp Update.exe" /winstartup [x] -> SUPPRIMÉ
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-1709042038-2155373347-2631235414-1001\Software\Microsoft\Windows\CurrentVersion\Run | WindApp : "C:\Users\Alan R\AppData\Roaming\Store\WindApp\WindApp Update.exe" /winstartup -> ERROR [2]
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IePluginServices -> SUPPRIMÉ
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\servervo -> SUPPRIMÉ
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IePluginServices -> SUPPRIMÉ
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\servervo -> SUPPRIMÉ
[PUM.Proxy] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> REMPLACÉ (0)
[PUM.Proxy] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> REMPLACÉ (0)
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> REMPLACÉ (0)
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> REMPLACÉ (0)
[PUM.Proxy] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:50774;https=127.0.0.1:50774 -> SUPPRIMÉ
[PUM.Proxy] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:50774;https=127.0.0.1:50774 -> ERROR [2]
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:50774;https=127.0.0.1:50774 -> ERROR [2]
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:50774;https=127.0.0.1:50774 -> ERROR [2]
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> REMPLACÉ (0)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> REMPLACÉ (0)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> REMPLACÉ (0)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> REMPLACÉ (0)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1709042038-2155373347-2631235414-1001\Software\Microsoft\Internet Explorer\Main | Start Page : about:blank -> REMPLACÉ (https://www.msn.com/fr-fr/?ocid=iehp
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1709042038-2155373347-2631235414-1001\Software\Microsoft\Internet Explorer\Main | Start Page : about:blank -> REMPLACÉ (https://www.msn.com/fr-fr/?ocid=iehp
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-1709042038-2155373347-2631235414-1001\Software\Microsoft\Internet Explorer\Main | Search Page : https://search.safefinder.com/?st=ds&q={searchTerms} -> REMPLACÉ (https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-1709042038-2155373347-2631235414-1001\Software\Microsoft\Internet Explorer\Main | Search Page : https://search.safefinder.com/?st=ds&q={searchTerms} -> REMPLACÉ (https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
¤¤¤ Tâches planifiées : 0 ¤¤¤
¤¤¤ Fichiers : 0 ¤¤¤
¤¤¤ Fichier HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: NON CHARGE [0xc000036b]) ¤¤¤
¤¤¤ Navigateurs web : 6 ¤¤¤
[FIREFX:Addon] zb16lrul.default : Selenium Expert (Selenium IDE) [selenium-expert_selenium-ide@Samit.Badle] -> SUPPRIMÉ
[FIREFX:Addon] zb16lrul.default : BlockAndSurf [{9A3B7448-C8A3-4EF3-C7D8-33FEA5854401}] -> SUPPRIMÉ
[FIREFX:Addon] zb16lrul.default : videos MediaPlay-Air [5c8764929678437cbd90994a5a82@ac863d978ade40948f4c7f15bb3c4.com] -> SUPPRIMÉ
[CHROME:Addon] Default : Google Docs [aohghmighlieiainnegkcijnfilokake] -> SUPPRIMÉ
[CHROME:Addon] Default : videos MediaPlay-Air [iklgpchfbohgmghgfagediakopecfmbm] -> ERROR [2]
[CHROME:Addon] Default : Google Wallet [nmmhkkegccagdldgiimedpiccmgmieda] -> ERROR [2]
¤¤¤ MBR Verif : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MQ01ABD075 +++++
--- User ---
[MBR] a84dd93b5b19931ceaddbccc47850486
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 2097151 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_SCN_08212014_134634.log - RKreport_DEL_08212014_134641.log - RKreport_SCN_08212014_135334.log
Merci d'avance !