Harcelée par FllexibleShooppeR ...

edesv -  
bazfile Messages postés 58524 Date d'inscription   Statut Modérateur Dernière intervention   -
Bonjour,

Ayez pitié de moi s'il vous plait !!! 1 semaine que je suis harcelée par ce foutu "Ad by FllexibleShooppeR", je suis au bout du rouleau ...

J'ai tout tenté: malware, ccleaner, supprimer le dossier de mon "C:" ... RIEN ne fonctionne :'(

Quelqu'un aurait la gentillesse de bien vouloir m'aider??

Merci beaucoup !!!!!

18 réponses

  1. bazfile Messages postés 58524 Date d'inscription   Statut Modérateur Dernière intervention   20 280
     
    Bonsoir,
    Télécharge et installe ZHPdiag, ouvre ZHPdiag clique sur Configurer puis sur la loupe sans + ni -, l'analyse commence quand elle sera terminé tu auras sur ton bureau un fichier texte nommé ZHPdiag tu le postes sur www.cjoint.com puis tu mets le lien généré par cjoint dans ta réponse.
    Tutoriel pour cjoint : https://www.commentcamarche.net/faq/29493-utiliser-cjoint-pour-heberger-des-fichiers
    0
  2. edesv
     
    Merci bazfile !!!!!

    Voici le lien du rapport:

    http://cjoint.com/?DJjvOMyM0oI
    0
  3. Known001 Messages postés 2652 Statut Membre 331
     
    Ok

    Le PC est infecté de malware

    Utilise adwcleaner
    https://toolslib.net/downloads/finish/1/

    1 - On scan
    2 - On nettoye
    3 - Quand le pc aura redémarré, fermer le rapport qui s'ouvre et l'héberger sur cjoint.com (le rapport se trouve dans c:\adwcleaner\adwcleaner[S0].txt
    0
  4. edesv
     
    http://cjoint.com/?DJjv4uz61m0

    Voilà le rapport ...
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Known001 Messages postés 2652 Statut Membre 331
     
    Un nouveau rapport ZHP diag stp afin de comparer par rapport a avant
    0
  7. bazfile Messages postés 58524 Date d'inscription   Statut Modérateur Dernière intervention   20 280
     
    Fait un nouveau rapport ZHPdiag afin de vérifier s'il reste des choses.
    0
  8. edesv
     
    http://cjoint.com/?DJjwh10xIqz

    voili voilou !!!!
    0
  9. edesv
     
    (ce bordel de fllexibleshoopper m'embête toujors :( )
    0
    1. bazfile Messages postés 58524 Date d'inscription   Statut Modérateur Dernière intervention   20 280
       
      Tu t'es trompé tu m'as envoyé une nouvelle fois le premier rapport ZHPdiag, donc fait un nouveau rapport ZHPdiag et envoie-le moi.
      0
  10. edesv
     
    zut désolée!

    http://cjoint.com/?DJjwvNbO4s4
    0
  11. edesv
     
    c'est pas possible grrr c'est tojours le même ou je rêve?????
    0
  12. Known001 Messages postés 2652 Statut Membre 331
     
    Tu as des chevaux de troie

    Maintenant on va s'occuper de malware bit anti-malware
    https://fr.malwarebytes.com/mwb-download/?language=fr

    Lors de l'installation, decocher "la version pro essai de 14 jours"

    Une fois installé l'executer puis aller dans les paramètres (settings) pour changer la langue sur français

    Ensuite aller dans Examen
    choisir examen personnalisé puis examiner maintenant.
    Cocher toutes les cases à gauche
    Cocher C:

    Puis lancer l'examen.
    Il va mettre la base à jour avant de commencer l'analyse

    A la fin de l'analyse, il faudra TOUT mettre EN QUARANTAINE.

    Vu que cela va prendre du temps je propose de le laisser travailler et donc ne pas s'en servir pendant cette période afin de ne pas le perturber

    poste le rapport analyse sur cjoint ensuite

    Pour le rapport malwarebits il faut aller dans
    Historique
    menu de gauche il y a Journaux de l'application
    puis tu ouvre le journal d'examen correspondant à l'analyse. puis il ya une option exporter, tu clique dessus et tu choisi "fichier texte .txt" et tu enregistre le rapport et tu l'héberge sur cjoint.com
    0
  13. bazfile Messages postés 58524 Date d'inscription   Statut Modérateur Dernière intervention   20 280
     
    Re,
    Clique sur ce lien : https://www.cjoint.com/?3JjwSS6Zjtt dans la page qui s'ouvre il y a un script, copie toutes les lignes qui vont de Script ZHPFix jusqu'à EmptyTemp.
    Ensuite ouvre ZHPfix il est sur ton bureau, son icône est une seringue il s'est installé en même temps que ZHPdiag.
    Une fois ZHPfix ouvert tu cliques sur Importer, les lignes copiées précédemment apparaissent dans la fenêtre de ZHPfix il ne te reste plus qu'à cliquer sur GO, valide le nettoyage des données ainsi que le message de nettoyage de la Corbeille, une fois que ZHPfix aura terminé, un rapport apparaîtra à l'écran, envoie-le moi via https://www.cjoint.com/ met son lien dans ta réponse, puis vérifie et dis-moi si tes problèmes sont toujours présents ou pas.
    0
  14. edesv
     
    http://cjoint.com/?DJki2J0FfI3

    Voilà le rapport suite à la manip sur ZHPfix ... Et ce foutu fllexibleshoopper est toujours là :(
    0
  15. edesv
     
    bon je croise les doigts, depuis que j'ai réinitialisé le navigateur pu de problème!!! merci !!!
    0
  16. edesv
     
    ~ Rapport de ZHPDiag v2014.10.8.142 - Nicolas Coolman (05/10/2014)
    ~ Lancé par admin (09/10/2014 22:16:02)
    ~ Adresse du Site Web http://nicolascoolman.fr
    ~ Adresse du Forum http://forum.nicolascoolman.fr
    ~ Traduit par Nicolas Coolman
    ~ Etat de la version : Version à jour.
    ~ Liste blanche : Désactivée par l'utilisateur
    ~ Elévation des Privilèges : OK
    ~ User Account Control (UAC): Activate by user

    ---\\ Navigateurs Internet
    MSIE: Internet Explorer v11.0.9600.17280
    GCIE: Google Chrome v36.0.1985.143 (Defaut)

    ---\\ Informations sur les produits Windows
    ~ Langage: Français
    Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)
    Windows Server License Manager Script : OK
    ~ Windows Operating System - Windows(R) 7, OEM_SLP channel
    System Locked Preinstallation (OEM_SLP) : OK
    Windows ID Activation : OK
    ~ Windows Partial Key : 7QJB7
    Windows License : OK
    ~ Windows Remaining Initializations Number : 3
    Software Protection Service (Protection logicielle) : OK
    Windows Automatic Updates : OK
    Windows Activation Technologies : OK

    ---\\ Logiciels de protection du système
    Norton Internet Security v16.8.3.6
    Windows Defender W7 (Deactivate)

    ---\\ Logiciels d'optimisation du système
    CCleaner v4.18

    ---\\ Logiciels de partage PeerToPeer

    ---\\ Surveillance de Logiciels
    Adobe Flash Player 15 ActiveX
    Adobe Reader 9.1 MUI

    ---\\ Informations sur le système
    ~ Processor: Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
    ~ Operating System: 64 Bits
    Boot mode: Normal (Normal boot)
    Total RAM: 4095 MB (75% free)
    System Restore: Activé (Enable)
    System drive C: has 346 GB (75%) free of 458 GB

    ---\\ Mode de connexion au système
    ~ Computer Name: ADMIN-PC
    ~ User Name: admin
    ~ All Users Names: UpdatusUser, Administrateur, admin,
    ~ Unselected Option: None
    Logged in as Administrator

    ---\\ Variables d'environnement
    ~ System Unit : C:\
    ~ %AppZHP% : C:\Users\admin\AppData\Roaming\ZHP\
    ~ %AppData% : C:\Users\admin\AppData\Roaming\
    ~ %Desktop% : C:\Users\admin\Desktop\
    ~ %Favorites% : C:\Users\admin\Favorites\
    ~ %LocalAppData% : C:\Users\admin\AppData\Local\
    ~ %StartMenu% : C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\
    ~ %Windir% : C:\Windows\
    ~ %System% : C:\Windows\System32\

    ---\\ Enumération des unités disques
    C: Hard drive, Flash drive, Thumb drive (Free 346 Go of 458 Go)
    D: Hard drive, Flash drive, Thumb drive (Free 458 Go of 458 Go)
    E: CD-ROM drive (Not Inserted)
    F: Floppy drive, Flash card reader, USB Key (Not Inserted)
    G: Floppy drive, Flash card reader, USB Key (Not Inserted)
    H: Floppy drive, Flash card reader, USB Key (Not Inserted)
    I: Floppy drive, Flash card reader, USB Key (Not Inserted)

    ---\\ Etat du Centre de Sécurité Windows
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
    [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
    ~ Security Center: 46 Scanned in 00mn 00s

    ---\\ Recherche particulière de fichiers génériques
    [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
    [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
    [MD5.39EBB9708453036A74C30C9A294023FF] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.18/08/2014 - 22:15:13.) -- C:\Windows\System32\wininet.dll [2310656]
    [MD5.88AB9B72B4BF3963A0DE0820B4B0B06C] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.04/03/2014 - 10:43:50.) -- C:\Windows\System32\Winlogon.exe [455168]
    [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
    [MD5.FA886682CFC5D36718D3E436AACF10B9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:45:52.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
    [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
    [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
    [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
    [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
    [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
    [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
    [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
    [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
    [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
    [MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:37:55.) -- C:\Windows\system32\Drivers\ntfs.sys [1684928]
    [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
    [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
    [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
    [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
    [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
    ~ Generic Processes: Scanned in 00mn 00s

    ---\\ Etat des fichiers cachés (Caché/Total)
    ~ Mes images (My Pictures) : 1/375
    ~ Mes Videos (My Videos) : 1/3
    ~ Mes Favoris (My Favorites) : 1/31
    ~ Mes Documents (My Documents) : 1/10
    ~ Mon Bureau (My Desktop) : 1/7
    ~ Menu demarrer (Programs) : 1/22
    ~ Hidden Files: Scanned in 00mn 00s

    ---\\ Processus lancés
    [MD5.64C89DB40949FD0E7C8FF303676A91F1] - (.Symantec Corporation - Symantec Service Framework.) -- C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe [117648] [PID.2592]
    [MD5.81A13F7583FBA1D0A9787688428EF7A8] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8112128] [PID.1796]
    [MD5.5A19667A580B1CE886EAF968B9743F45] - (.NVIDIA Corporation - Stereo Vision Control Panel API Server.) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [383264] [PID.808]
    [MD5.8F0DE4FEF8201E306F9938B0905AC96A] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [135664] [PID.1712]
    [MD5.816FD5A6F3C2F3D600900096632FC60E] - (.Acer Incorporated - Global Registration Service.) -- C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe [1150496] [PID.2540]
    [MD5.4789E020D2617046862D1790FC235FF6] - (.NVIDIA Corporation - NVIDIA Settings Update Manager.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [1260320] [PID.2704]
    ~ Processes Running: Scanned in 00mn 00s

    ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
    C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
    G0 - GCSP: Preference [User Data\Default][StartupURLs] http://www.google.com
    G2 - GCE: Preference [User Data\Default] [ahfgeienlihckogmohjhadlkjgocpleb] Google Store v.0.2 (Activé)
    G2 - GCE: Preference [User Data\Default] [eemcgdkfndhakfknompkggombfjjjeno] Bookmark Manager v.0.1 (Activé)
    G2 - GCE: Preference [User Data\Default] [ehjldlodmkdlooagebfnaghgmkfccipn] Lasaoren New Tab v.0.3.8, (Désactivé) =>PUP.Lasaoren
    G2 - GCE: Preference [User Data\Default] [ennkphjdgehloodpbhlhldgbnhmacadg] Settings v.0.2 (Activé)
    G2 - GCE: Preference [User Data\Default] [eolhkfkhgcfmajkadgofbklgepcelnlk] BTD5 Bloons Tower Defense 5 v.219 (Activé)
    G2 - GCE: Preference [User Data\Default] [gfdkimpbcpahaombhbimeihdjnejgicl] Feedback v.1.0 (Activé)
    G2 - GCE: Preference [User Data\Default] [jliolpcnkmolaaecncdfeofombdekjcp] Search the current site v.235 (Désactivé)
    G2 - GCE: Preference [User Data\Default] [kmendfapggjehodndflmmgagdbamhnfd] CryptoTokenExtension v.0.0.1 (Activé)
    G2 - GCE: Preference [User Data\Default] [llnofjfijelilpjdibjjmldcpdenmbfh] Cleaner Facebook v.135 (Désactivé)
    G2 - GCE: Preference [User Data\Default] [mfehgcgbbipciphmccgaenjidiccnmng] Cloud Print v.0.1 (Activé)
    G2 - GCE: Preference [User Data\Default] [mgndgikekgjfcpckkfioiadnlibdjbkf] Chrome v.0.1 (Activé)
    G2 - GCE: Preference [User Data\Default] [neajdppkdcdipfabeoofebfddakdcjhd] Google Network Speech v.1.0 (Activé)
    G2 - GCE: Preference [User Data\Default] [nkeimhogjdpnpccoofpliimaahmaaome] Google+ Hangouts v.1.0 (Activé)
    G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.6.1 (Activé)
    G2 - GCE: Preference [User Data\Default] [pafkbggdmjlpgkdkcbjmhmfcdpncadgh] Google Now v.1.2.0.1 (Activé)

    ---\\ Liste des dossiers d'extension Google Chrome
    G2 - EXT: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehjldlodmkdlooagebfnaghgmkfccipn [Lasaoren New Tab] =>PUP.Lasaoren
    G2 - EXT: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\eolhkfkhgcfmajkadgofbklgepcelnlk [BTD5 Bloons Tower Defense 5]
    G2 - EXT: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jliolpcnkmolaaecncdfeofombdekjcp [Search the current site]
    G2 - EXT: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\llnofjfijelilpjdibjjmldcpdenmbfh [Cleaner Facebook]
    G2 - EXT: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [Google Wallet]
    ~ Google Lines Browser: 21 Scanned in 00mn 05s

    ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
    P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
    ~ Firefox Browser: 1 Scanned in 00mn 00s

    ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
    R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
    R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
    R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
    R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
    R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
    R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.9600.17239 (winblue_gdr.140724-2228)) -- C:\Windows\SysWOW64\ieframe.dll
    R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
    R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
    ~ IE Browser: 18 Scanned in 00mn 00s

    ---\\ Internet Explorer, Proxy Management (R5)
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
    ~ Proxy management: Scanned in 00mn 00s

    ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
    F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
    F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
    F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
    ~ Keys: Scanned in 00mn 00s

    ---\\ Hosts file redirection (O1)
    ~ Le fichier hôte est sain (The hosts file is clean) (21)
    ~ Hosts File: Scanned in 00mn 00s

    ---\\ Browser Helper Objects de navigateur (O2)
    O2 - BHO: AcroIEHelperStub [64Bits] - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) [64Bits] - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline
    O2 - BHO: Symantec NCO BHO [64Bits] - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} . (.Symantec Corporation - coIEPlugIn.) -- C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention [64Bits] - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} . (.Symantec Corporation - IPS Browser Helper DLL.) -- C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\IPSBHO.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\ssv.dll
    O2 - BHO: (no name) [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} Clé orpheline
    O2 - BHO: Google Toolbar Helper [64Bits] - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
    ~ BHO: 9 Scanned in 00mn 00s

    ---\\ Internet Explorer Toolbars (O3)
    O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
    O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
    ~ Toolbar: Scanned in 00mn 00s

    ---\\ Autres liens utilisateurs (O4)
    O4 - GS\Desktop [Public]: PB Boutique Accessoire.lnk . (...) -- C:\Program Files (x86)\PB Accessory Store\StartUrl.exe (.not file.)
    ~ Global Startup: 1 Scanned in 00mn 00s

    ---\\ Applications lancées au démarrage du système (O4)
    O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp
    O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd
    O4 - HKLM\..\Wow6432Node\Run: [NortonOnlineBackupReminder] . (.Symantec Corporation - Norton Online Backup Service.) -- C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe =>.Symantec Corporation
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
    O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation
    O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
    O4 - HKUS\S-1-5-21-237725772-2824485578-759933294-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd
    ~ Application: Scanned in 00mn 00s

    ---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
    O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
    ~ IE Control Panel: 1 Scanned in 00mn 00s

    ---\\ Winsock hijacker (Layered Service Provider) (O10)
    O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
    O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
    O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
    O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
    O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
    O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
    ~ Winsock: 6 Scanned in 00mn 00s

    ---\\ Modification Domaine/Adresses DNS (O17)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{BE05B85D-9BF2-45EC-A27E-8A2B4957965A}: DhcpNameServer = 192.168.1.1 192.168.1.1
    O17 - HKLM\System\CS1\Services\Tcpip\..\{BE05B85D-9BF2-45EC-A27E-8A2B4957965A}: DhcpNameServer = 192.168.1.1 192.168.1.1
    O17 - HKLM\System\CS2\Services\Tcpip\..\{BE05B85D-9BF2-45EC-A27E-8A2B4957965A}: DhcpNameServer = 192.168.1.1 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
    ~ Domain: Scanned in 00mn 00s

    ---\\ Protocole additionnel (O18)
    O18 - Handler: wlmailhtml [64Bits] - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (...) --
    O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
    ~ Protocole Additionnel: Scanned in 00mn 00s

    ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    ~ SSODL: 1 Scanned in 00mn 00s

    ---\\ Liste des services NT non Microsoft et non désactivés (O23)
    O23 - Service: Performance Optimizer (892cc6a3) . (...) - c:\progra~3\perfor~1\PerformanceOptimizerSvc.dll (.not file.) =>PUP.PerformanceOptimizer
    O23 - Service: ForceWare Intelligent Application Manager (IAM) (ForceWare Intelligent Application Manager (IAM)) . (.Pas de propriétaire - app_filter Module.) - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
    O23 - Service: GRegService (Greg_Service) . (.Acer Incorporated - Global Registration Service.) - C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe
    O23 - Service: Norton Internet Security (Norton Internet Security) . (.Symantec Corporation - Symantec Service Framework.) - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe
    O23 - Service: ForceWare IP service (nSvcIp) . (.Pas de propriétaire - NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 311.0.) - C:\Windows\system32\nvvsvc.exe
    O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) . (.NVIDIA Corporation - NVIDIA Settings Update Manager.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) . (.NVIDIA Corporation - Stereo Vision Control Panel API Server.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    ~ Services: 7 Scanned in 00mn 02s

    ---\\ Enumération Active Desktop & MHTML Editor (O24)
    O24 - Default MHTML Editor: Last - .(...) - (.not file.)
    ~ Desktop Component: 4 Scanned in 00mn 00s

    ---\\ Enumère les données de BootExecute (BEX) (O34)
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    ~ BEX: 1 Scanned in 00mn 00s

    ---\\ Tâches planifiées en automatique (O39)
    [MD5.4ECFCAAE5CB380F58934F0DCF5F64E7F] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [267440]
    [MD5.F308D7378BF60B91DA495FCAA1C216E7] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [4811032]
    [MD5.8F0DE4FEF8201E306F9938B0905AC96A] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [135664]
    [MD5.8F0DE4FEF8201E306F9938B0905AC96A] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [135664]
    [MD5.00000000000000000000000000000000] [APT] [WIN-fdfEfEfAfC] (...) -- C:\Users\admin\AppData\Roaming\~xvxydtp.exe (.not file.) [0]
    [MD5.00000000000000000000000000000000] [APT] [WIN-fIGbfFfEGCfFGEGbfCfE] (...) -- C:\Users\admin\AppData\Roaming\~zecprxm.exe (.not file.) [0]
    [MD5.00000000000000000000000000000000] [APT] [WIN-GGfIfEGCfEGbGffIfCfEGC] (...) -- C:\Users\admin\AppData\Roaming\~ufroakf.exe (.not file.) [0]
    [MD5.00000000000000000000000000000000] [APT] [{3218524C-9531-4A6A-920E-166C98D46ABB}] (...) -- C:\Users\admin\AppData\Roaming\vi-view\UninstallManager.exe (.not file.) [0] =>Hijacker.MyhomeViview
    [MD5.7F59E4F51DA9C9C6B29B881D8DD92400] [APT] [Burn Notification] (.Acer.) -- C:\Program Files\Packard Bell\Packard Bell Recovery Management\NotificationCenter\Notification.exe [675840]
    O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
    O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
    O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1066]
    O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1066]
    O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1070]
    O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1070]
    ~ Scheduled Task: 16 Scanned in 00mn 01s

    ---\\ Composants installés (ActiveSetup Installed Components) (O40)
    O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
    O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation
    O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
    O40 - ASIC: Internet Explorer [64Bits] - {2D46B6DC-2207-486B-B523-A557E6D54B47} . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\system32\cmd.exe =>.Microsoft Corporation
    O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe =>.Microsoft Corporation
    O40 - ASIC: Browsing Enhancements [64Bits] - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
    O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
    O40 - ASIC: Windows Desktop Update [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
    O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
    O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
    ~ Active Setup: 10 Scanned in 00mn 00s

    ---\\ Pilotes lancés au démarrage du système (O41)
    O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
    O41 - Driver: (BHDrvx64) . (.Symantec Corporation - BASH Driver.) - C:\Windows\system32\Drivers\NISx64\1008030.006\BHDrvx64.sys
    O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\system32\DRIVERS\blbdrive.sys
    O41 - Driver: (ccHP) . (.Symantec Corporation - Common Client Hash Provider Driver.) - C:\Windows\system32\Drivers\NISx64\1008030.006\ccHPx64.sys
    O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\drivers\cdrom.sys
    O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
    O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
    O41 - Driver: (IDSVia64) . (.Symantec Corporation - IDS Core Driver.) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\IDSVia64.sys
    O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
    O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
    O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
    O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
    O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
    O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
    O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
    O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
    O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
    O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\Windows\System32\DRIVERS\serial.sys
    O41 - Driver: (SRTSPX) . (.Symantec Corporation - Symantec AutoProtect.) - C:\Windows\system32\drivers\NISx64\1008030.006\SRTSPX64.sys
    O41 - Driver: (SymIM) . (.Symantec Corporation - NDIS 6.0 Filter Driver for Windows Vista.) - C:\Windows\System32\DRIVERS\SymIMv.sys
    O41 - Driver: (SYMTDI) . (.Symantec Corporation - Network Dispatch Driver.) - C:\Windows\system32\Drivers\NISx64\1008030.006\SYMTDI.sys
    O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
    O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys
    O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
    O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
    O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
    ~ Drivers: 78 Scanned in 00mn 00s

    ---\\ Logiciels installés (O42)
    O42 - Logiciel: Acrobat.com - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {287ECFA4-719A-2143-A09B-D6A12DE54E40}
    O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM][64Bits] -- Adobe AIR
    O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM][64Bits] -- {A2BCA9F1-566C-4805-97D1-7FDC93386723}
    O42 - Logiciel: Adobe Flash Player 15 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX
    O42 - Logiciel: Adobe Photoshop Elements 7.0 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Photoshop Elements 7 =>.Adobe Systems Incorporated
    O42 - Logiciel: Adobe Photoshop Elements 7.0 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {5511C07D-A83C-45AD-92B6-42DF99729A3C} =>.Adobe Systems Incorporated
    O42 - Logiciel: Adobe Photoshop Elements 7.0 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {CB6075D9-F912-40AE-BEA6-E590DA24F16B} =>.Adobe Systems Incorporated
    O42 - Logiciel: Adobe Reader 9.1 MUI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-FFFF-7B44-A91000000001}
    O42 - Logiciel: Advertising Center - (.Nero AG.) [HKLM][64Bits] -- {b2ec4a38-b545-4a00-8214-13fe0e915e6d}
    O42 - Logiciel: Alice Greenfingers - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}
    O42 - Logiciel: Amazonia - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11273477}
    O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner
    O42 - Logiciel: Choice Guard - (.Microsoft Corporation.) [HKLM][64Bits] -- {8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
    O42 - Logiciel: Dairy Dash - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115053100}
    O42 - Logiciel: Dream Day First Home - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}
    O42 - Logiciel: Farm Frenzy 2 - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}
    O42 - Logiciel: GIMP 2.6.12-2 - (.The GIMP Team.) [HKLM][64Bits] -- WinGimp-2.0_is1
    O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome
    O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {18455581-E099-4BA8-BC6B-F34B2F06600C}
    O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F}
    O42 - Logiciel: Heroes of Hellas - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}
    O42 - Logiciel: Identity Card - (.Packard Bell.) [HKLM][64Bits] -- Identity Card
    O42 - Logiciel: Java 7 Update 67 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F03217067FF}
    O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM][64Bits] -- {4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
    O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
    O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM][64Bits] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
    O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM][64Bits] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
    O42 - Logiciel: Merriam Websters Spell Jam - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}
    O42 - Logiciel: Metaboli - (.Packard Bell.) [HKLM][64Bits] -- Metaboli
    O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
    O42 - Logiciel: Microsoft Works - (.Microsoft Corporation.) [HKLM][64Bits] -- {0214A441-A4AB-43A8-8DEF-2F73C5364673}
    O42 - Logiciel: Mises à jour NVIDIA 1.11.3 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update
    O42 - Logiciel: NVIDIA Drivers - (.NVIDIA Corporation.) [HKLM][64Bits] -- NVIDIA Drivers
    O42 - Logiciel: NVIDIA ForceWare Network Access Manager - (...) [HKLM][64Bits] -- InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}
    O42 - Logiciel: NVIDIA ForceWare Network Access Manager - (.NVIDIA Corporation.) [HKLM][64Bits] -- {7CFA46E3-CC2F-4355-82AE-6012DC3633FD}
    O42 - Logiciel: NVIDIA Pilote 3D Vision 311.06 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision
    O42 - Logiciel: NVIDIA Pilote graphique 311.06 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver
    O42 - Logiciel: NVIDIA Stereoscopic 3D Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- NVIDIAStereo
    O42 - Logiciel: Nero 9 Essentials - (.Nero AG.) [HKLM][64Bits] -- {db7aa853-5c26-43a5-85c9-6d6329fc379a}
    O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM][64Bits] -- {bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}
    O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM][64Bits] -- {f4041dce-3fe1-4e18-8a9e-9de65231ee36}
    O42 - Logiciel: Nero DiscSpeed - (.Nero AG.) [HKLM][64Bits] -- {869200db-287a-4dc0-b02b-2b6787fbcd4c}
    O42 - Logiciel: Nero DiscSpeed Help - (.Nero AG.) [HKLM][64Bits] -- {cc019e3f-59d2-4486-8d4b-878105b62a71}
    O42 - Logiciel: Nero DriveSpeed - (.Nero AG.) [HKLM][64Bits] -- {33cf58f5-48d8-4575-83d6-96f574e4d83a}
    O42 - Logiciel: Nero DriveSpeed Help - (.Nero AG.) [HKLM][64Bits] -- {e5c7d048-f9b4-4219-b323-8bdb01a2563d}
    O42 - Logiciel: Nero Express Help - (.Nero AG.) [HKLM][64Bits] -- {83202942-84b3-4c50-8622-b8c0aa2d2885}
    O42 - Logiciel: Nero InfoTool - (.Nero AG.) [HKLM][64Bits] -- {fbcdfd61-7dcf-4e71-9226-873ba0053139}
    O42 - Logiciel: Nero InfoTool Help - (.Nero AG.) [HKLM][64Bits] -- {20400dbd-e6db-45b8-9b6b-1dd7033818ec}
    O42 - Logiciel: Nero Installer - (.Nero AG.) [HKLM][64Bits] -- {e8a80433-302b-4ff1-815d-fcc8eac482ff}
    O42 - Logiciel: Nero Online Upgrade - (.Nero AG.) [HKLM][64Bits] -- {dba84796-8503-4ff0-af57-1747dd9a166d}
    O42 - Logiciel: Nero StartSmart - (.Nero AG.) [HKLM][64Bits] -- {7748ac8c-18e3-43bb-959b-088faea16fb2}
    O42 - Logiciel: Nero StartSmart Help - (.Nero AG.) [HKLM][64Bits] -- {2348b586-c9ae-46ce-936c-a68e9426e214}
    O42 - Logiciel: Nero StartSmart OEM - (.Nero AG.) [HKLM][64Bits] -- {4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}
    O42 - Logiciel: NeroExpress - (.Nero AG.) [HKLM][64Bits] -- {595a3116-40bb-4e0f-a2e8-d7951da56270}
    O42 - Logiciel: Norton Internet Security - (.Symantec Corporation.) [HKLM][64Bits] -- NIS
    O42 - Logiciel: Norton Online Backup - (.Symantec.) [HKLM][64Bits] -- {C57BCDE1-7CB9-467D-B3BA-7E119916CDC1} =>.Symantec Corporation
    O42 - Logiciel: Packard Bell GameZone Console - (.Oberon Media, Inc..) [HKLM][64Bits] -- {9242564e-02e9-4ea8-9d2d-351f6f728e1c}_is1
    O42 - Logiciel: Packard Bell InfoCentre - (.Packard Bell.) [HKLM][64Bits] -- Packard Bell InfoCentre
    O42 - Logiciel: Packard Bell Recovery Management - (.Acer Incorporated.) [HKLM][64Bits] -- {7F811A54-5A09-4579-90E1-C93498E230D9}
    O42 - Logiciel: Packard Bell Registration - (.Packard Bell.) [HKLM][64Bits] -- Packard Bell Registration
    O42 - Logiciel: Packard Bell ScreenSaver - (.Packard Bell Incorporated.) [HKLM][64Bits] -- Packard Bell Screensaver
    O42 - Logiciel: Packard Bell Software Suite SE - (.Packard Bell.) [HKLM][64Bits] -- Packard Bell Software Suite SE
    O42 - Logiciel: Packard Bell Updater - (.Packard Bell.) [HKLM][64Bits] -- {EE171732-BEB4-4576-887D-CB62727F01CA}
    O42 - Logiciel: PhotoFiltre 7 - (...) [HKCU][64Bits] -- PhotoFiltre 7
    O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
    O42 - Logiciel: SketchUp 2014 - (.Trimble Navigation Limited.) [HKLM][64Bits] -- {FFF3FC8A-02ED-4581-9D08-7BFDA09242DC}
    O42 - Logiciel: Star Defender 4 - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114803710}
    O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
    O42 - Logiciel: Welcome Center - (.Packard Bell.) [HKLM][64Bits] -- Packard Bell Welcome Center
    O42 - Logiciel: WiFi Station - (.Hercules.) [HKLM][64Bits] -- {DECE22F4-EEDD-4615-BC56-2F4827FAD64B}
    O42 - Logiciel: eBay Worldwide - (.OEM.) [HKLM][64Bits] -- {AAF89271-2594-468D-B578-96B2E30C41C4} =>Toolbar.eBay
    O42 - Logiciel: neroxml - (.Nero AG.) [HKLM][64Bits] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B}
    ~ Logic: 30 Scanned in 00mn 00s

    ---\\ HKCU & HKLM Software Keys
    [HKCU\Software\Acer]
    [HKCU\Software\Adobe]
    [HKCU\Software\AppDataLow\Software\Google]
    [HKCU\Software\AppDataLow\Software\JavaSoft]
    [HKCU\Software\AppDataLow]
    [HKCU\Software\BugSplat]
    [HKCU\Software\Classes]
    [HKCU\Software\Clients]
    [HKCU\Software\Google]
    [HKCU\Software\IM Providers]
    [HKCU\Software\JavaSoft]
    [HKCU\Software\Local AppWizard-Generated Applications]
    [HKCU\Software\Macromedia]
    [HKCU\Software\MozillaPlugins]
    [HKCU\Software\Mozilla]
    [HKCU\Software\NVIDIA Corporation]
    [HKCU\Software\Netscape]
    [HKCU\Software\Norton]
    [HKCU\Software\ODBC]
    [HKCU\Software\OEM]
    [HKCU\Software\Piriform]
    [HKCU\Software\Policies]
    [HKCU\Software\Realtek]
    [HKCU\Software\SketchUp]
    [HKCU\Software\TeleCharger]
    [HKCU\Software\Trolltech]
    [HKCU\Software\Wow6432Node]
    [HKCU\Software\ZebHelpProcess Helper]
    [HKLM\Software\<company>]
    [HKLM\Software\ATI Technologies]
    [HKLM\Software\Acer]
    [HKLM\Software\Audible]
    [HKLM\Software\BrowserChoice]
    [HKLM\Software\Classes]
    [HKLM\Software\Clients]
    [HKLM\Software\Google]
    [HKLM\Software\Intel]
    [HKLM\Software\Khronos]
    [HKLM\Software\Macromedia]
    [HKLM\Software\MozillaPlugins]
    [HKLM\Software\NVIDIA Corporation]
    [HKLM\Software\ODBC]
    [HKLM\Software\OEM]
    [HKLM\Software\OemSetup]
    [HKLM\Software\Piriform]
    [HKLM\Software\Policies]
    [HKLM\Software\Realtek]
    [HKLM\Software\RegisteredApplications]
    [HKLM\Software\SRS Labs]
    [HKLM\Software\Sonic]
    [HKLM\Software\Symantec]
    [HKLM\Software\Waves Audio]
    [HKLM\Software\Wow6432Node\AVGO]
    [HKLM\Software\Wow6432Node\Acer Incorporated]
    [HKLM\Software\Wow6432Node\Adobe]
    [HKLM\Software\Wow6432Node\AdvanceElite] =>PUP.AdvanceElite
    [HKLM\Software\Wow6432Node\AdwCleaner]
    [HKLM\Software\Wow6432Node\Audible]
    [HKLM\Software\Wow6432Node\Classes]
    [HKLM\Software\Wow6432Node\Clients]
    [HKLM\Software\Wow6432Node\Digital River]
    [HKLM\Software\Wow6432Node\Google]
    [HKLM\Software\Wow6432Node\Hercules]
    [HKLM\Software\Wow6432Node\Intel]
    [HKLM\Software\Wow6432Node\JavaSoft]
    [HKLM\Software\Wow6432Node\JreMetrics]
    [HKLM\Software\Wow6432Node\Khronos]
    [HKLM\Software\Wow6432Node\Licenses]
    [HKLM\Software\Wow6432Node\Macromedia]
    [HKLM\Software\Wow6432Node\Macrovision]
    [HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware]
    [HKLM\Software\Wow6432Node\MozillaPlugins]
    [HKLM\Software\Wow6432Node\Mozilla]
    [HKLM\Software\Wow6432Node\NVIDIA Corporation]
    [HKLM\Software\Wow6432Node\Nero]
    [HKLM\Software\Wow6432Node\Norton]
    [HKLM\Software\Wow6432Node\ODBC]
    [HKLM\Software\Wow6432Node\OEM]
    [HKLM\Software\Wow6432Node\Oberon Media]
    [HKLM\Software\Wow6432Node\OldTimer Tools]
    [HKLM\Software\Wow6432Node\Packard Bell]
    [HKLM\Software\Wow6432Node\Policies]
    [HKLM\Software\Wow6432Node\RegisteredApplications]
    [HKLM\Software\Wow6432Node\SketchUp]
    [HKLM\Software\Wow6432Node\Sonic]
    [HKLM\Software\Wow6432Node\Symantec]
    [HKLM\Software\Wow6432Node\VideoLAN]
    [HKLM\Software\Wow6432Node\WinU]
    [HKLM\Software\Wow6432Node\XnView]
    [HKLM\Software\Wow6432Node]
    ~ Key Software: 195 Scanned in 00mn 00s

    ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
    O43 - CFD: 03/08/2013 - 10:13:53 - [] ----D C:\Program Files (x86)\Adobe
    O43 - CFD: 09/10/2014 - 21:50:16 - [] ----D C:\Program Files (x86)\AdvanceElite =>PUP.AdvanceElite
    O43 - CFD: 29/08/2014 - 15:35:19 - [] ----D C:\Program Files (x86)\Common Files
    O43 - CFD: 08/10/2014 - 09:40:50 - [0] ----D C:\Program Files (x86)\FlexibbloeShopper =>PUP.FlexibleShoper
    O43 - CFD: 26/07/2014 - 22:23:29 - [] ----D C:\Program Files (x86)\GIMP-2.0
    O43 - CFD: 26/07/2014 - 20:38:39 - [] ----D C:\Program Files (x86)\Google
    O43 - CFD: 03/08/2013 - 11:13:54 - [] ----D C:\Program Files (x86)\Hercules
    O43 - CFD: 03/08/2013 - 11:13:52 - [] --H-D C:\Program Files (x86)\InstallShield Installation Information
    O43 - CFD: 11/09/2014 - 08:27:17 - [] ----D C:\Program Files (x86)\Internet Explorer
    O43 - CFD: 29/08/2014 - 15:34:50 - [] ----D C:\Program Files (x86)\Java
    O43 - CFD: 03/08/2013 - 10:19:20 - [] ----D C:\Program Files (x86)\Microsoft
    O43 - CFD: 03/08/2013 - 10:25:53 - [] ----D C:\Program Files (x86)\Microsoft Office
    O43 - CFD: 15/08/2009 - 02:37:57 - [] ----D C:\Program Files (x86)\Microsoft Office Suite Activation Assistant
    O43 - CFD: 25/07/2014 - 23:00:26 - [] ----D C:\Program Files (x86)\Microsoft Silverlight
    O43 - CFD: 03/08/2013 - 10:20:08 - [] ----D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
    O43 - CFD: 03/08/2013 - 10:26:17 - [] ----D C:\Program Files (x86)\Microsoft Visual Studio 8
    O43 - CFD: 25/07/2014 - 23:15:50 - [] ----D C:\Program Files (x86)\Microsoft Works
    O43 - CFD: 26/07/2014 - 06:12:33 - [] ----D C:\Program Files (x86)\Microsoft.NET
    O43 - CFD: 19/08/2014 - 21:30:35 - [] ----D C:\Program Files (x86)\Movie Maker 2.6
    O43 - CFD: 14/07/2009 - 07:32:38 - [] ----D C:\Program Files (x86)\MSBuild
    O43 - CFD: 26/07/2014 - 23:29:38 - [0] ----D C:\Program Files (x86)\MSXML 4.0
    O43 - CFD: 15/08/2009 - 02:51:34 - [] ----D C:\Program Files (x86)\Nero
    O43 - CFD: 15/08/2009 - 02:56:20 - [] ----D C:\Program Files (x86)\Norton Internet Security
    O43 - CFD: 15/08/2009 - 02:55:39 - [] ----D C:\Program Files (x86)\NortonInstaller
    O43 - CFD: 26/07/2014 - 00:08:38 - [] ----D C:\Program Files (x86)\NVIDIA Corporation
    O43 - CFD: 03/08/2013 - 10:02:53 - [] ----D C:\Program Files (x86)\OEM
    O43 - CFD: 03/08/2013 - 10:28:31 - [] ----D C:\Program Files (x86)\Packard Bell
    O43 - CFD: 09/10/2014 - 20:22:31 - [] ----D C:\Program Files (x86)\Packard Bell GameZone
    O43 - CFD: 13/08/2014 - 17:18:32 - [] ----D C:\Program Files (x86)\PhotoFiltre 7
    O43 - CFD: 14/07/2009 - 07:32:38 - [] ----D C:\Program Files (x86)\Reference Assemblies
    O43 - CFD: 26/08/2014 - 10:38:01 - [] ----D C:\Program Files (x86)\SketchUp
    O43 - CFD: 15/08/2009 - 02:59:22 - [] ----D C:\Program Files (x86)\Symantec
    O43 - CFD: 03/08/2013 - 09:46:56 - [0] --H-D C:\Program Files (x86)\Temp
    O43 - CFD: 14/07/2009 - 06:57:06 - [0] --H-D C:\Program Files (x86)\Uninstall Information
    O43 - CFD: 29/07/2014 - 09:07:28 - [] ----D C:\Program Files (x86)\VideoLAN
    O43 - CFD: 29/07/2014 - 08:05:19 - [] ----D C:\Program Files (x86)\Windows Defender
    O43 - CFD: 03/08/2013 - 10:20:52 - [] ----D C:\Program Files (x86)\Windows Live
    O43 - CFD: 03/08/2013 - 10:19:04 - [] ----D C:\Program Files (x86)\Windows Live SkyDrive
    O43 - CFD: 26/07/2014 - 20:05:07 - [] ----D C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
    O43 - CFD: 29/07/2014 - 08:06:12 - [] ----D C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
    O43 - CFD: 14/07/2009 - 07:32:38 - [] ----D C:\Program Files (x86)\Windows NT
    O43 - CFD: 26/07/2014 - 20:05:07 - [] ----D C:\Program Files (x86)\Windows Photo Viewer
    O43 - CFD: 26/07/2014 - 20:05:07 - [] ----D C:\Program Files (x86)\Windows Portable Devices
    O43 - CFD: 26/07/2014 - 20:05:07 - [] ----D C:\Program Files (x86)\Windows Sidebar
    O43 - CFD: 09/10/2014 - 21:32:56 - [] ----D C:\Program Files (x86)\ZHPDiag =>.Nicolas Coolman
    O43 - CFD: 03/08/2013 - 10:15:38 - [] ----D C:\Program Files (x86)\Common Files\Adobe
    O43 - CFD: 15/08/2009 - 02:55:14 - [] ----D C:\Program Files (x86)\Common Files\Adobe AIR
    O43 - CFD: 26/07/2014 - 12:05:55 - [] ----D C:\Program Files (x86)\Common Files\DESIGNER
    O43 - CFD: 15/08/2009 - 02:18:31 - [] ----D C:\Program Files (x86)\Common Files\InstallShield
    O43 - CFD: 29/08/2014 - 15:35:19 - [] ----D C:\Program Files (x86)\Common Files\Java
    O43 - CFD: 03/08/2013 - 10:15:24 - [] ----D C:\Program Files (x86)\Common Files\Macrovision Shared
    O43 - CFD: 09/10/2014 - 20:19:34 - [] ----D C:\Program Files (x86)\Common Files\microsoft shared
    O43 - CFD: 15/08/2009 - 02:52:57 - [] ----D C:\Program Files (x86)\Common Files\Nero
    O43 - CFD: 15/08/2009 - 02:25:21 - [] ----D C:\Program Files (x86)\Common Files\Oberon Media
    O43 - CFD: 03/08/2013 - 10:15:01 - [] ----D C:\Program Files (x86)\Common Files\PX Storage Engine
    O43 - CFD: 14/07/2009 - 05:20:08 - [] ----D C:\Program Files (x86)\Common Files\Services
    O43 - CFD: 03/08/2013 - 10:15:01 - [] ----D C:\Program Files (x86)\Common Files\Sonic Shared
    O43 - CFD: 14/07/2009 - 05:20:08 - [] ----D C:\Program Files (x86)\Common Files\SpeechEngines
    O43 - CFD: 26/07/2014 - 20:05:07 - [] ----D C:\Program Files (x86)\Common Files\System
    O43 - CFD: 03/08/2013 - 10:17:18 - [] ----D C:\Program Files (x86)\Common Files\Windows Live
    O43 - CFD: 15/08/2009 - 02:55:14 - [] ----D C:\ProgramData\Adobe
    O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Application Data
    O43 - CFD: 23/05/2010 - 13:36:05 - [] ----D C:\ProgramData\AWEM
    O43 - CFD: 08/11/2009 - 12:23:16 - [] -SH-D C:\ProgramData\Bureau
    O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Desktop
    O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Documents
    O43 - CFD: 08/10/2014 - 09:40:51 - [] ----D C:\ProgramData\e78fde8bd75a7092
    O43 - CFD: 28/10/2010 - 20:10:55 - [] ----D C:\ProgramData\eMule
    O43 - CFD: 09/11/2009 - 19:24:42 - [] ----D C:\ProgramData\EPSON
    O43 - CFD: 26/12/2009 - 21:11:05 - [] ----D C:\ProgramData\FarmFrenzy2
    O43 - CFD: 08/11/2009 - 12:23:16 - [] -SH-D C:\ProgramData\Favoris
    O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Favorites
    O43 - CFD: 21/12/2009 - 19:16:23 - [] ----D C:\ProgramData\FLEXnet
    O43 - CFD: 31/07/2010 - 16:43:16 - [] ----D C:\ProgramData\Friends Games
    O43 - CFD: 15/08/2009 - 02:48:45 - [] ----D C:\ProgramData\Google
    O43 - CFD: 08/10/2014 - 10:31:41 - [] ----D C:\ProgramData\Malwarebytes
    O43 - CFD: 21/06/2011 - 19:25:42 - [] ----D C:\ProgramData\McAfee
    O43 - CFD: 21/06/2011 - 19:25:42 - [] ----D C:\ProgramData\McAfee Security Scan
    O43 - CFD: 08/11/2009 - 12:23:16 - [] -SH-D C:\ProgramData\Menu Démarrer
    O43 - CFD: 09/09/2010 - 19:37:00 - [] ----D C:\ProgramData\MGS
    O43 - CFD: 29/07/2014 - 23:34:55 - [] -S--D C:\ProgramData\Microsoft
    O43 - CFD: 15/08/2014 - 00:46:55 - [] ----D C:\ProgramData\Microsoft Help
    O43 - CFD: 08/11/2009 - 12:23:16 - [] -SH-D C:\ProgramData\Modèles
    O43 - CFD: 15/08/2009 - 02:50:44 - [] ----D C:\ProgramData\Nero
    O43 - CFD: 15/08/2009 - 02:56:11 - [] ----D C:\ProgramData\Norton
    O43 - CFD: 15/08/2009 - 02:55:39 - [] ----D C:\ProgramData\NortonInstaller
    O43 - CFD: 09/10/2014 - 21:51:36 - [] ----D C:\ProgramData\NVIDIA
    O43 - CFD: 02/12/2012 - 21:39:20 - [] ----D C:\ProgramData\NVIDIA Corporation
    O43 - CFD: 15/08/2009 - 02:59:01 - [] ----D C:\ProgramData\OEM
    O43 - CFD: 29/08/2014 - 15:35:32 - [0] ----D C:\ProgramData\Oracle
    O43 - CFD: 15/08/2009 - 02:46:02 - [] ----D C:\ProgramData\Packard Bell
    O43 - CFD: 26/08/2014 - 10:38:02 - [] ----D C:\ProgramData\SketchUp
    O43 - CFD: 04/03/2013 - 20:42:03 - [] ----D C:\ProgramData\Skype
    O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Start Menu
    O43 - CFD: 03/09/2010 - 17:52:03 - [] ----D C:\ProgramData\Sun
    O43 - CFD: 15/08/2009 - 02:59:22 - [] ----D C:\ProgramData\Symantec
    O43 - CFD: 24/02/2013 - 21:47:13 - [0] ---AD C:\ProgramData\TEMP
    O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Templates
    O43 - CFD: 09/11/2009 - 19:35:49 - [] ----D C:\ProgramData\UDL
    O43 - CFD: 07/08/2014 - 17:34:46 - [] ----D C:\Users\admin\AppData\Roaming\Adobe
    O43 - CFD: 24/07/2014 - 21:08:30 - [] ----D C:\Users\admin\AppData\Roaming\Google
    O43 - CFD: 05/10/2014 - 19:53:26 - [] ----D C:\Users\admin\AppData\Roaming\gtk-2.0
    O43 - CFD: 03/08/2013 - 10:04:20 - [] ----D C:\Users\admin\AppData\Roaming\Identities
    O43 - CFD: 03/08/2013 - 11:13:32 - [] ----D C:\Users\admin\AppData\Roaming\InstallShield
    O43 - CFD: 03/08/2013 - 10:28:31 - [] ----D C:\Users\admin\AppData\Roaming\Macromedia
    O43 - CFD: 14/07/2009 - 09:44:38 - [0] ----D C:\Users\admin\AppData\Roaming\Media Center Programs
    O43 - CFD: 01/09/2014 - 11:01:42 - [] -S--D C:\Users\admin\AppData\Roaming\Microsoft
    O43 - CFD: 26/08/2014 - 10:40:12 - [] ----D C:\Users\admin\AppData\Roaming\NVIDIA
    O43 - CFD: 29/08/2014 - 15:36:04 - [] ----D C:\Users\admin\AppData\Roaming\Oracle
    O43 - CFD: 13/08/2014 - 17:19:30 - [] ----D C:\Users\admin\AppData\Roaming\PhotoFiltre 7
    O43 - CFD: 26/08/2014 - 10:39:52 - [] ----D C:\Users\admin\AppData\Roaming\SketchUp
    O43 - CFD: 30/07/2014 - 20:45:37 - [] ----D C:\Users\admin\AppData\Roaming\Template
    O43 - CFD: 29/09/2014 - 21:54:32 - [] ----D C:\Users\admin\AppData\Roaming\vlc
    O43 - CFD: 09/10/2014 - 20:01:54 - [] ----D C:\Users\admin\AppData\Roaming\winservices =>Trojan.Trojan.Inject.RRE
    O43 - CFD: 09/10/2014 - 20:27:44 - [] ----D C:\Users\admin\AppData\Roaming\XnView
    O43 - CFD: 09/10/2014 - 22:16:17 - [] ----D C:\Users\admin\AppData\Roaming\ZHP =>.Nicolas Coolman
    O43 - CFD: 07/08/2014 - 17:35:06 - [] ----D C:\Users\admin\AppData\Local\Adobe
    O43 - CFD: 03/08/2013 - 10:01:56 - [] -SH-D C:\Users\admin\AppData\Local\Application Data
    O43 - CFD: 25/08/2014 - 11:17:16 - [0] ----D C:\Users\admin\AppData\Local\Diagnostics
    O43 - CFD: 25/07/2014 - 05:29:33 - [0] ----D C:\Users\admin\AppData\Local\ElevatedDiagnostics
    O43 - CFD: 26/07/2014 - 20:38:56 - [] ----D C:\Users\admin\AppData\Local\Google
    O43 - CFD: 03/08/2013 - 10:01:56 - [] -SH-D C:\Users\admin\AppData\Local\Historique
    O43 - CFD: 22/09/2014 - 21:11:51 - [] ----D C:\Users\admin\AppData\Local\Microsoft
    O43 - CFD: 03/08/2013 - 10:25:31 - [0] ----D C:\Users\admin\AppData\Local\Microsoft Help
    O43 - CFD: 03/08/2013 - 10:05:20 - [] ----D C:\Users\admin\AppData\Local\Packard Bell
    O43 - CFD: 28/07/2014 - 08:45:48 - [] ----D C:\Users\admin\AppData\Local\Programs
    O43 - CFD: 09/09/2014 - 19:50:53 - [] ----D C:\Users\admin\AppData\Local\Symantec
    O43 - CFD: 09/10/2014 - 22:15:56 - [] ----D C:\Users\admin\AppData\Local\Temp
    O43 - CFD: 03/08/2013 - 10:01:56 - [] -SH-D C:\Users\admin\AppData\Local\Temporary Internet Files
    O43 - CFD: 03/08/2013 - 10:04:38 - [] ----D C:\Users\admin\AppData\Local\VirtualStore
    O43 - CFD: 19/08/2014 - 21:31:16 - [0] ----D C:\Users\admin\AppData\Local\WMTools Downloaded Files
    O43 - CFD: 14/07/2009 - 06:54:32 - [] R---D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    O43 - CFD: 15/08/2014 - 09:34:46 - [] R---D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    O43 - CFD: 14/07/2009 - 06:49:38 - [] R---D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    O43 - CFD: 13/08/2014 - 17:18:32 - [0] ----D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoFiltre 7
    O43 - CFD: 28/09/2014 - 08:23:37 - [] R---D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    ~ Program Folder: 136 Scanned in 00mn 00s

    ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
    O44 - LFC:[MD5.6C2FD88D90A8FF7B3BD0A2B84CF5E26F] - 09/10/2014 - 20:50:42 ---A- . (...) -- C:\Windows\win.ini [580]
    O44 - LFC:[MD5.0D4BCDE2A9F260C0281E67AEC5BCBF39] - 09/10/2014 - 20:51:18 ---A- . (...) -- C:\Windows\PFRO.log [5844]
    O44 - LFC:[MD5.DC4953E8FBAA1858E587364A17C7D2B1] - 09/10/2014 - 20:51:27 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
    O44 - LFC:[MD5.D74E3C688AA4F552EB9F55CB8EA67170] - 09/10/2014 - 20:51:36 ---A- . (...) -- C:\Windows\setupact.log [56]
    O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 09/10/2014 - 20:51:36 ---A- . (...) -- C:\Windows\setuperr.log [0]
    O44 - LFC:[MD5.3066B2710C2A071B948DA4212B4F4F60] - 09/10/2014 - 20:55:40 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1136755]
    O44 - LFC:[MD5.FF4A03C73F3EBF7D68DDA7727770166F] - 09/10/2014 - 21:03:01 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512]
    O44 - LFC:[MD5.8D46C7BCDF7FBAAC8666D6640ADA930E] - 25/09/2014 - 03:08:38 ---A- . (.Microsoft Corporation - DirectShow DVD PlayBack Runtime..) -- C:\Windows\System32\qdvd.dll [371712]
    O44 - LFC:[MD5.A07D57B070344E94DEC6D375382A9327] - 26/09/2014 - 09:43:45 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1668256]
    O44 - LFC:[MD5.AF728991203DD85E4EF066687B85CC0E] - 26/09/2014 - 09:43:45 ---A- . (...) -- C:\Windows\System32\perfc009.dat [121802]
    O44 - LFC:[MD5.5516070C7E2AC0685A49B97067DDD47A] - 26/09/2014 - 09:43:45 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [149844]
    O44 - LFC:[MD5.93259C536132AE0C8C750708A7BE8336] - 26/09/2014 - 09:43:45 ---A- . (...) -- C:\Windows\System32\perfh009.dat [653930]
    O44 - LFC:[MD5.9144BCC329551024131F32A6ECE7AFEA] - 26/09/2014 - 09:43:45 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [747320]
    ~ Files: 13 Scanned in 00mn 01s

    ---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
    O45 - LFCP:[MD5.FC26A244DBA8D68CD998459BCA4E250C] - 09/10/2014 - 20:32:40 ---A- - C:\Windows\Prefetch\ADVANCEELITE.BROWSERADAPTER.E-9CFA4F20.pf =>PUP.AdvanceElite
    O45 - LFCP:[MD5.FDB7E5DA05C62E1D5AA1C98FECF44165] - 09/10/2014 - 20:32:40 ---A- - C:\Windows\Prefetch\ADVANCEELITE.BROWSERADAPTER64-9D472E02.pf =>PUP.AdvanceElite
    O45 - LFCP:[MD5.320F341A69F321A9364A395D9043A987] - 09/10/2014 - 19:24:21 ---A- - C:\Windows\Prefetch\ADVANCEELITE.FIRSTRUN.EXE-BCA9AD67.pf =>PUP.AdvanceElite
    O45 - LFCP:[MD5.C3516829254192C8E448A9450CACEE69] - 09/10/2014 - 19:21:18 ---A- - C:\Windows\Prefetch\ADVANCEELITE.MG.EXE-E51D62FB.pf =>PUP.AdvanceElite
    O45 - LFCP:[MD5.3A679CC1979F738224BEF66A9C2539EA] - 09/10/2014 - 20:28:40 ---A- - C:\Windows\Prefetch\ADVANCEELITE.PURBROWSE64.EXE-5313B63E.pf =>PUP.AdvanceElite
    O45 - LFCP:[MD5.610F4FBACE6B59C57FE3F6F0E09C8EFF] - 09/10/2014 - 19:23:20 ---A- - C:\Windows\Prefetch\ADVANCEELITE_SETUP.EXE-98A4E459.pf =>PUP.AdvanceElite
    O45 - LFCP:[MD5.0D1B1106A0A138C6A19336B498EA3951] - 08/10/2014 - 13:58:23 ---A- - C:\Windows\Prefetch\ISAFE.EXE-8FF402A6.pf =>Trojan.Staser
    O45 - LFCP:[MD5.C38AC871932A9572683455B0FB1F9AD7] - 09/10/2014 - 19:21:12 ---A- - C:\Windows\Prefetch\ISAFESVC.EXE-16C94C52.pf =>Trojan.Staser
    O45 - LFCP:[MD5.D0A31CF756CD0888842F93398E0E0EAF] - 08/10/2014 - 10:44:31 ---A- - C:\Windows\Prefetch\ISAFESVC2.EXE-7A948BFC.pf =>Trojan.Staser
    O45 - LFCP:[MD5.8E98E9F0C76F6F5A10FC18A8ED3776B7] - 09/10/2014 - 19:01:24 ---A- - C:\Windows\Prefetch\ISAFETHLP.EXE-1851603E.pf =>Trojan.Staser
    O45 - LFCP:[MD5.4E066A9CE3D6B08EBD517CA1EBC14763] - 09/10/2014 - 19:20:56 ---A- - C:\Windows\Prefetch\ISAFETHLP64.EXE-4BB01B40.pf =>Trojan.Staser
    O45 - LFCP:[MD5.650BC7A305A41753570900C705014EDA] - 08/10/2014 - 10:44:39 ---A- - C:\Windows\Prefetch\ISAFETRAY.EXE-7465A95E.pf =>Trojan.Staser
    O45 - LFCP:[MD5.41D3D938E14B3AD187001A605593D624] - 08/10/2014 - 19:00:45 ---A- - C:\Windows\Prefetch\ISAFEUPDATE.EXE-E0FBE37D.pf =>Trojan.Staser
    O45 - LFCP:[MD5.28272C16C344D685630D353F3202DACC] - 09/10/2014 - 20:25:43 ---A- - C:\Windows\Prefetch\UPDATEADVANCEELITE.EXE-6F05D0AF.pf =>PUP.AdvanceElite
    O45 - LFCP:[MD5.AB2B840AF9CCE8539303D744AF8639F0] - 09/10/2014 - 20:24:33 ---A- - C:\Windows\Prefetch\UTILADVANCEELITE.EXE-02C676B7.pf =>PUP.AdvanceElite
    O45 - LFCP:[MD5.E10895B1A489C7D6A58464A003B1C3E5] - 08/10/2014 - 10:44:04 ---A- - C:\Windows\Prefetch\YET_ANOTHER_CLEANER_SK_580381-3E7A5706.pf =>PUP.YetAnotherCleaner
    ~ Prefetcher: 16 Scanned in 00mn 00s

    ---\\ Déni du service (Local Security Authority) (O48)
    O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
    O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l'Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
    O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll
    O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
    O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll
    O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll
    O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll
    O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll
    ~ LSA: 8 Scanned in 00mn 00s

    ---\\ Contrôle du Safe Boot (CSB) (O49)
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\SymEFA.sys . (...) -- C:\Windows\System32\Drivers\SymEFA.sys (.not file.)
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d'extension du gestionnaire de volumes.) --
    -1