Virus à nouveau

HELENE34 Messages postés 152 Date d'inscription   Statut Membre Dernière intervention   -  
jacques.gache Messages postés 34829 Statut Contributeur sécurité -
Bonjour,

Je crois que mon ordinateur a, à nouveau, un virus : il est un peu lent et hier, sur une messagerie, les pages faisaient comme des mosaîques.

En outre, ma messagerie de "la poste" ne fonctionne pas très bien depuis qu'ils ont refait leur messagerie.

Que dois-je faire pour le virus ?

Et dois-je installer un antivirus payant ?

Merci,
HELENE

4 réponses

  1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
     
    bonjour, On va faire un diagnostic de ton PC pour plus de renseignements ==>

    - Télécharge ZHPDiag sur ton bureau : https://nicolascoolman.eu
    - Laisse-toi guider lors de l'installation.
    - Ouvre ZHPDiag (icône parchemin) puis clique sur Configurer.
    - Dans les icônes qui apparaissent en bas, clique sur la loupe la plus à droite (Diagnostic avec légitimes). Dans la fenêtre qui apparaît demandant un rapport avec full options, clique sur Oui, puis patiente le temps du scan.
    - Héberge le rapport ZHPDiag.txt présent sur ton bureau sur le site ci dessous, puis copie/colle le lien fourni dans ta prochaine réponse :
    https://www.cjoint.com/

    0
  2. HELENE34 Messages postés 152 Date d'inscription   Statut Membre Dernière intervention   6
     
    Bonjour Jacques,
    je n'ai pas pû le faire avant et maintenant, je n'en peux plus. Merci beaucoup.
    HELENE

    ~ Rapport de ZHPDiag v2015.1.21.8 - Nicolas Coolman (21/01/2015)
    ~ Lancé par HELENE (24/01/2015 11:53:18)
    ~ Facebook : https://www.facebook.com/nicolascoolman1
    ~ Adresse du Forum https://nicolascoolman.eu
    ~ Traduit par Nicolas Coolman
    ~ Etat de la version : Version à jour.
    ~ Liste blanche : Désactivée par l'utilisateur
    ~ Elévation des Privilèges : OK
    ~ User Account Control (UAC): Deactivate by program

    ---\\ Navigateurs Internet
    MSIE: Internet Explorer v11.0.9600.17498
    GCIE: Google Chrome v40.0.2214.91 (Defaut)

    ---\\ Informations sur les produits Windows
    ~ Langage: Français
    Windows 8.1, 64-bit (Build 9600)
    Windows Server License Manager Script : OK
    ~ Windows(R) Operating System, OEM_DM channel
    Windows ID Activation : OK
    ~ Windows Partial Key : KBRWQ
    Windows License : OK
    ~ Windows Remaining Initializations Number : 999
    Software Protection Service (Protection logicielle) : OK
    Windows Automatic Updates : OK
    Windows Activation Technologies : OK

    ---\\ Logiciels de protection du système
    Avira Free Antivirus v14.0.7.468
    Malwarebytes Anti-Malware version 2.0.3.1025
    Windows Defender W8 (Deactivate)

    ---\\ Logiciels d'optimisation du système
    CCleaner v4.19

    ---\\ Logiciels de partage PeerToPeer

    ---\\ Surveillance de Logiciels

    ---\\ Informations sur le système
    ~ Processor: Intel64 Family 6 Model 60 Stepping 3, GenuineIntel
    ~ Operating System: 64 Bits
    Boot mode: Normal (Normal boot)
    Total RAM: 4020 MB (55% free)
    System Restore: Activé (Enable)
    System drive C: has 645 GB (94%) free of 686 GB

    ---\\ Mode de connexion au système
    ~ Computer Name: HÉLENE
    ~ User Name: HELENE
    ~ All Users Names: HomeGroupUser$, HELENE, Administrateur,
    ~ Unselected Option: None
    Logged in as Administrator

    ---\\ Variables d'environnement
    ~ System Unit : C:\
    ~ %AppZHP% : C:\Users\HELENE\AppData\Roaming\ZHP\
    ~ %AppData% : C:\Users\HELENE\AppData\Roaming\
    ~ %Desktop% : C:\Users\HELENE\Desktop\
    ~ %Favorites% : C:\Users\HELENE\Favorites\
    ~ %LocalAppData% : C:\Users\HELENE\AppData\Local\
    ~ %StartMenu% : C:\Users\HELENE\AppData\Roaming\Microsoft\Windows\Start Menu\
    ~ %Windir% : C:\Windows\
    ~ %System% : C:\Windows\System32\

    ---\\ Enumération des unités disques
    C: Hard drive, Flash drive, Thumb drive (Free 645 Go of 686 Go)
    D: CD-ROM drive (Not Inserted)

    ---\\ Etat du Centre de Sécurité Windows
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
    [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
    ~ Security Center: 41 Scanned in 00mn 00s

    ---\\ Recherche particulière de fichiers génériques
    [MD5.ACDBE1ED38167C8B01B8F63161BB2CEA] - (.Microsoft Corporation - Explorateur Windows.) (.23/08/2014 - 08:48:28.) -- C:\Windows\Explorer.exe [2374784]
    [MD5.48CFA7BE561A7BE144C29BB912055016] - (.Microsoft Corporation - Application de démarrage de Windows.) (.22/08/2013 - 10:58:29.) -- C:\Windows\System32\Wininit.exe [144384]
    [MD5.4AF089160FE082E5EA5C4AA72782DCA2] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.22/11/2014 - 02:28:21.) -- C:\Windows\System32\wininet.dll [2358272]
    [MD5.306EB21E5B480AE9065EA55AC8C35936] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.22/02/2014 - 10:45:48.) -- C:\Windows\System32\Winlogon.exe [562176]
    [MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - (.Microsoft Corporation - Bibliothèque de licences.) (.21/12/2013 - 09:54:07.) -- C:\Windows\System32\sppcomapi.dll [447488]
    [MD5.374E27295F0A9DCAA8FC96370F9BEEA5] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.30/05/2014 - 04:03:03.) -- C:\Windows\system32\Drivers\AFD.sys [563200]
    [MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.22/08/2013 - 13:43:41.) -- C:\Windows\system32\Drivers\atapi.sys [26464]
    [MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) (.22/08/2013 - 12:40:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [88576]
    [MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.22/08/2013 - 09:46:35.) -- C:\Windows\system32\Drivers\Cdrom.sys [164352]
    [MD5.A03F362C5557E238CBFA914689C77248] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.06/03/2014 - 10:22:50.) -- C:\Windows\system32\Drivers\DfsC.sys [134144]
    [MD5.D4B7ED39C7900384D9E5C1283F1E7926] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.24/07/2014 - 12:45:39.) -- C:\Windows\system32\Drivers\HDAudBus.sys [76800]
    [MD5.84CFC5EFA97D0C965EDE1D56F116A541] - (.Microsoft Corporation - Pilote de port i8042.) (.22/08/2013 - 12:39:15.) -- C:\Windows\system32\Drivers\i8042prt.sys [107520]
    [MD5.B7342B3C58E91107F6E946A93D9D4EFD] - (.Microsoft Corporation - IP Network Address Translator.) (.27/11/2013 - 13:02:29.) -- C:\Windows\system32\Drivers\IpNat.sys [142848]
    [MD5.7A1A3F213CDB3363D179D5014272025D] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.30/04/2014 - 07:41:46.) -- C:\Windows\system32\Drivers\MRxSmb.sys [402432]
    [MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) (.22/08/2013 - 12:37:02.) -- C:\Windows\system32\Drivers\netBT.sys [282624]
    [MD5.038C77D577900EE39410662478BB0D50] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/07/2014 - 16:07:52.) -- C:\Windows\system32\Drivers\ntfs.sys [2009920]
    [MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Pilote de port parallèle.) (.22/08/2013 - 12:40:02.) -- C:\Windows\system32\Drivers\Parport.sys [94208]
    [MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.22/08/2013 - 12:35:51.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [120832]
    [MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.22/08/2013 - 20:12:11.) -- C:\Windows\system32\Drivers\rdpdr.sys [195584]
    [MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) (.22/08/2013 - 14:25:35.) -- C:\Windows\system32\Drivers\tdx.sys [107520]
    [MD5.64CA2B4A49A8EAF495E435623ECCE7DB] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.19/06/2014 - 03:13:36.) -- C:\Windows\system32\Drivers\volsnap.sys [310080]
    ~ Generic Processes: Scanned in 00mn 01s

    ---\\ Etat des fichiers cachés (Caché/Total)
    ~ Mes images (My Pictures) : 2/59
    ~ Mes Videos (My Videos) : 2/22
    ~ Mes Favoris (My Favorites) : 1/9
    ~ Mes Documents (My Documents) : 6/288
    ~ Mon Bureau (My Desktop) : 1/7
    ~ Menu demarrer (Programs) : 1/30
    ~ Hidden Files: Scanned in 00mn 01s

    ---\\ Processus lancés
    [MD5.293770C94202D1EA18EE27E0D3EB6A41] - (.NVIDIA Corporation - NVIDIA GeForce Experience Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032] [PID.4076]
    [MD5.37AD6B4A4BE717669E89A32209B5D72A] - (.Pas de propriétaire - ChangeIcon MFC Application.) -- C:\Windows\SysWOW64\UMonit64.exe [53248] [PID.2292]
    [MD5.8FEDBE7A5D3E5F91FD4B96DAFA4DD197] - (.Spotify Ltd - SpotifyWebHelper.) -- C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1199576] [PID.7328]
    [MD5.86EE1EE24ACB4599CDB4F6A7D110B700] - (.Evernote - Skitch.) -- C:\Program Files (x86)\Evernote\Skitch\Skitch.exe [4864320] [PID.3680]
    [MD5.6226810F26227F083929AC5584122951] - (.Dropbox, Inc. - Dropbox.) -- C:\Users\HELENE\AppData\Roaming\Dropbox\bin\Dropbox.exe [39207112] [PID.7564]
    [MD5.A162B967A88BF374A81E01EF6E7A2655] - (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768] [PID.6404]
    [MD5.EE37DCB4EB65B8179E53036796BDD276] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592] [PID.7264]
    [MD5.BF7D15FE6CACC7CDEF6823810A12A477] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8160256] [PID.6460]
    ~ Processes Running: Scanned in 00mn 01s

    ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
    C:\Users\HELENE\AppData\Local\Google\Chrome\User Data\Default\Preferences

    ---\\ Liste des dossiers d'extension Google Chrome
    ~ Google Lines Browser: 0 Scanned in 00mn 01s

    ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
    P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
    ~ Firefox Browser: 1 Scanned in 00mn 00s

    ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
    R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?cobrand=toshiba13.msn.com&ocid=TSHDHP&pc=MATBJS
    R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.microsoft.com/fr-fr/
    R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.microsoft.com/fr-fr/
    R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = https://www.microsoft.com/fr-fr/
    R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?cobrand=toshiba13.msn.com&ocid=TSHDHP&pc=MATBJS
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = https://www.microsoft.com/fr-fr/
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.microsoft.com/fr-fr/
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.microsoft.com/fr-fr/
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.microsoft.com/fr-fr/
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.microsoft.com/fr-fr/
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.microsoft.com/fr-fr/
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
    R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.9600.17496 (winblue_r5.141121-1500)) -- C:\Windows\SysWOW64\ieframe.dll
    ~ IE Browser: 16 Scanned in 00mn 00s

    ---\\ Internet Explorer, Proxy Management (R5)
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
    ~ Proxy management: Scanned in 00mn 00s

    ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
    F2 - REG:system.ini: USERINIT=C:\Windows\System32\Userinit.exe,
    F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
    F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
    ~ Keys: Scanned in 00mn 00s

    ---\\ Hosts file redirection (O1)
    ~ Le fichier hôte est sain (The hosts file is clean) (21)
    ~ Hosts File: Scanned in 00mn 00s

    ---\\ Browser Helper Objects de navigateur (O2)
    O2 - BHO: Evernote extension [64Bits] - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} . (.Evernote Corp., 305 Walnut Street, Redwood - Evernote Clipper for Microsoft Internet Exp.) -- C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
    ~ BHO: 1 Scanned in 00mn 00s

    ---\\ Applications lancées au démarrage du système (O4)
    O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [cAudioFilterAgent] . (.Conexant Systems, Inc. - Conexant High Definition Audio Filter Agent.) -- C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe
    O4 - HKLM\..\Run: [SmartAudio] . (.Conexant Systems, Inc. - SmartAudio CPL (32bit).) -- C:\Program Files\CONEXANT\SAII\SACpl.exe
    O4 - HKLM\..\Run: [TecoResident] . (.TOSHIBA Corporation - Resident module of eco Utility.) -- C:\Program Files\TOSHIBA\Teco\TecoResident.exe
    O4 - HKLM\..\Run: [TosWaitSrv] C:\Program Files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe (.not file.)
    O4 - HKLM\..\Run: [TCrdMain] . (.TOSHIBA Corporation - TOSHIBA Function Key Main Module.) -- C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe
    O4 - HKLM\..\Run: [TSSSrv] . (.TOSHIBA Corporation - TOSHIBA System Settings Service.) -- C:\Program Files (x86)\TOSHIBA\System Setting\TSSSrv.exe
    O4 - HKLM\..\Run: [NvBackend] . (.NVIDIA Corporation - NVIDIA GeForce Experience Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
    O4 - HKLM\..\Run: [ShadowPlay] . (.NVIDIA Corporation - NVIDIA Capture Server Proxy.) -- C:\Windows\system32\nvspcap64.dll
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.)
    O4 - HKLM\..\Run: [Logitech Download Assistant] . (.Logitech, Inc. - Logitech Download Assistant.) -- C:\Windows\System32\LogiLDA.dll
    O4 - HKCU\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
    O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
    O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd
    O4 - HKCU\..\Run: [Skitch] . (.Evernote - Skitch.) -- C:\Program Files (x86)\Evernote\Skitch\Skitch.exe
    O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_967898B8C921FACC8CB5DC54DD647C0F] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    O4 - HKLM\..\Wow6432Node\Run: [TSVU] . (.TOSHIBA - TOSHIBA Display Setup Launcher.) -- c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe
    O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    O4 - HKLM\..\Wow6432Node\Run: [Avira Systray] . (.Avira Operations GmbH & Co. KG - Avira.) -- C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
    O4 - HKUS\S-1-5-21-1657216836-3940558372-332610186-1002\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
    O4 - HKUS\S-1-5-21-1657216836-3940558372-332610186-1002\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
    O4 - HKUS\S-1-5-21-1657216836-3940558372-332610186-1002\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd
    O4 - HKUS\S-1-5-21-1657216836-3940558372-332610186-1002\..\Run: [Skitch] . (.Evernote - Skitch.) -- C:\Program Files (x86)\Evernote\Skitch\Skitch.exe
    O4 - HKUS\S-1-5-21-1657216836-3940558372-332610186-1002\..\Run: [GoogleChromeAutoLaunch_967898B8C921FACC8CB5DC54DD647C0F] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    ~ Application: Scanned in 00mn 00s

    ---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
    O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
    ~ IE Control Panel: 1 Scanned in 00mn 00s

    ---\\ Winsock hijacker (Layered Service Provider) (O10)
    O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
    O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
    O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
    O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
    O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
    O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
    O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
    ~ Winsock: 7 Scanned in 00mn 00s

    ---\\ Modification Domaine/Adresses DNS (O17)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0079C065-757F-48D7-8F53-AF1916C93D14}: DhcpNameServer = 89.2.0.1 89.2.0.2
    O17 - HKLM\System\CS1\Services\Tcpip\..\{0079C065-757F-48D7-8F53-AF1916C93D14}: DhcpNameServer = 89.2.0.1 89.2.0.2
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.2.0.1 89.2.0.2
    ~ Domain: Scanned in 00mn 00s

    ---\\ Protocole additionnel (O18)
    O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
    O18 - Filter: text/xml [64Bits] - {807553E5-5146-11D5-A672-00B0D022E945} . (...) --
    ~ Protocole Additionnel: Scanned in 00mn 00s

    ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
    O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
    ~ Winlogon: Scanned in 00mn 00s

    ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
    O20 - AppInit_DLLs: . (.NVIDIA Corporation - NVIDIA shim initialization dll, Version 326.) - C:\Windows\system32\nvinitx.dll
    ~ AppInit DLL: Scanned in 00mn 00s

    ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    ~ SSODL: 1 Scanned in 00mn 00s

    ---\\ Liste des services NT non Microsoft et non désactivés (O23)
    O23 - Service: Avira Scheduler (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira Real-Time Protection (AntiVirService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: AtherosSvc (AtherosSvc) . (.Windows (R) Win 7 DDK provider - Windows Setup API.) - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
    O23 - Service: Avira Service Host (Avira.OE.ServiceHost) . (.Avira Operations GmbH & Co. KG - Avira.OE.ServiceHost.) - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
    O23 - Service: C:\Windows\system32\CxAudMsg64.exe (CxAudMsg) . (.Conexant Systems Inc. - Conexant Audio Message Service.) - C:\Windows\system32\CxAudMsg64.exe
    O23 - Service: DTS APO Service (dts_apo_service) . (.Pas de propriétaire - dts_apo_service.) - C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
    O23 - Service: GamesAppIntegrationService (GamesAppIntegrationService) . (.WildTangent - WildTangent Games App Integration Service.) - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
    O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc
    O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe
    O23 - Service: Intel(R) ME Service (Intel(R) ME Service) . (.Intel Corporation - Intel(R) ME Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
    O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Intel(R) Local Management Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    O23 - Service: NVIDIA Network Service (NvNetworkService) . (.NVIDIA Corporation - NVIDIA Network Service.) - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
    O23 - Service: NVIDIA Streamer Service (NvStreamSvc) . (.NVIDIA Corporation - NVIDIA Streamer Service.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 326.6.) - C:\Windows\system32\nvvsvc.exe
    O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
    O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) . (.TOSHIBA Corporation - TDCSrv Application.) - C:\Windows\system32\TODDSrv.exe
    O23 - Service: TOSHIBA eco Utility Service (TOSHIBA eco Utility Service) . (.Toshiba Corporation - TOSHIBA eco Utility Service.) - C:\Program Files\Toshiba\Teco\TecoService.exe =>.Toshiba Corporation
    ~ Services: 18 Scanned in 00mn 05s

    ---\\ Enumération Active Desktop & MHTML Editor (O24)
    O24 - Default MHTML Editor: Last - .(...) - (.not file.)
    ~ Desktop Component: 4 Scanned in 00mn 00s

    ---\\ Enumère les données de BootExecute (BEX) (O34)
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    ~ BEX: 1 Scanned in 00mn 00s

    ---\\ Tâches planifiées en automatique (O39)
    [MD5.D87E0BF2E8BB7E5C49E79F32F8FEAFC4] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [4826904]
    [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
    [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
    [MD5.E2D2E33E42A9C2B91791C4CCEBFCFE9D] [APT] [Resolution+ Setting Task] (.TOSHIBA Corporation.) -- C:\Program Files\Toshiba\TOSHIBA Smart View Utility\Plugins\ResolutionPlus\TosRegPermissionChg.exe [88064]
    [MD5.37AD6B4A4BE717669E89A32209B5D72A] [APT] [UMonitor Task] (...) -- C:\Windows\SysWOW64\UMonit64.exe [53248]
    [MD5.C6B8CB65A3AACABB00F3DAA371C46A3E] [APT] [CommonNotifier] (.Toshiba Europe GmbH.) -- C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [471416]
    [MD5.2B2C2D74BC62E22248787530A7AFC87F] [APT] [Service Station] (.TOSHIBA Corporation.) -- C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [655464]
    O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1086]
    O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1086]
    O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1090]
    O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1090]
    ~ Scheduled Task: 10 Scanned in 00mn 10s

    ---\\ Composants installés (ActiveSetup Installed Components) (O40)
    O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
    O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation
    O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
    O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe =>.Microsoft Corporation
    O40 - ASIC: Browsing Enhancements [64Bits] - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
    O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
    O40 - ASIC: Windows Desktop Update [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
    O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
    O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll
    ~ Active Setup: 9 Scanned in 00mn 00s

    ---\\ Pilotes lancés au démarrage du système (O41)
    O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) - C:\Windows\system32\drivers\afd.sys
    O41 - Driver: C:\Windows\System32\drivers\ahcache.sys (ahcache) . (.Microsoft Corporation - Application Compatibility Cache.) - C:\Windows\System32\DRIVERS\ahcache.sys
    O41 - Driver: (avipbb) . (.Avira Operations GmbH & Co. KG - Avira Driver for Security Enhancement.) - C:\Windows\system32\DRIVERS\avipbb.sys
    O41 - Driver: (avkmgr) . (.Avira Operations GmbH & Co. KG - Avira Manager Driver.) - C:\Windows\system32\DRIVERS\avkmgr.sys
    O41 - Driver: (BasicDisplay) . (.Microsoft Corporation - Microsoft Basic Display Driver.) - C:\Windows\system32\drivers\BasicDisplay.sys
    O41 - Driver: (BasicRender) . (.Microsoft Corporation - Microsoft Basic Render Driver.) - C:\Windows\system32\drivers\BasicRender.sys
    O41 - Driver: cdrom.inf (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\drivers\cdrom.sys
    O41 - Driver: C:\Windows\System32\drivers\dam.sys (dam) . (.Microsoft Corporation - DAM Kernel Driver.) - C:\Windows\System32\drivers\dam.sys
    O41 - Driver: C:\Windows\System32\wkssvc.dll (Dfsc) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
    O41 - Driver: mssmbios.inf (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
    O41 - Driver: netnb.inf (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
    O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
    O41 - Driver: npsvctrig.inf (npsvctrig) . (.Microsoft Corporation - Named pipe service triggers.) - C:\Windows\system32\drivers\npsvctrig.sys
    O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
    O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\system32\DRIVERS\pacer.sys
    O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
    O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\system32\DRIVERS\tdx.sys
    O41 - Driver: C:\Windows\System32\drivers\vwififlt.sys (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\system32\DRIVERS\vwififlt.sys
    O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\system32\DRIVERS\wanarp.sys
    ~ Drivers: 38 Scanned in 00mn 00s

    ---\\ Logiciels installés (O42)
    O42 - Logiciel: Aloha TriPeaks - (.WildTangent.) [HKLM][64Bits] -- WTA-c7a33ab7-400f-49d4-93f6-fdab6c4b301a =>.WildTangent
    O42 - Logiciel: Atheros Driver Installation Program - (.Atheros.) [HKLM][64Bits] -- {C3A32068-8AB1-4327-BB16-BED9C6219DC7}
    O42 - Logiciel: Avira Free Antivirus v14.0.7.468 - (.Avira.) [HKLM][64Bits] -- Avira AntiVir Desktop
    O42 - Logiciel: Avira v1.1.27.25527 - (.Avira Operations & Co. KG.) [HKLM][64Bits] -- {21388E37-9EC5-4549-95CA-95D9B2D327A4}
    O42 - Logiciel: Avira v1.1.27.25527 - (.Avira Operations & Co. KG.) [HKLM][64Bits] -- {e7c7c227-b742-4878-9425-f09bbf9951db}
    O42 - Logiciel: Bejeweled 3 - (.WildTangent.) [HKLM][64Bits] -- WTA-952392a0-4f0e-4152-ac07-b08dba3dd7b2 =>.WildTangent
    O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner
    O42 - Logiciel: Chuzzle Deluxe - (.WildTangent.) [HKLM][64Bits] -- WTA-c86161d9-6260-4542-b822-5239b4349592 =>.WildTangent
    O42 - Logiciel: Conexant HD Audio - (.Conexant.) [HKLM][64Bits] -- CNXT_AUDIO_HDA
    O42 - Logiciel: DTS Sound - (.DTS, Inc..) [HKLM][64Bits] -- {2DFA9084-CEB3-4A48-B9F7-9038FEF1B8F4}
    O42 - Logiciel: Dropbox - (.Dropbox, Inc..) [HKCU][64Bits] -- Dropbox
    O42 - Logiciel: Empress of the Deep - The Darkest Secret - (.WildTangent.) [HKLM][64Bits] -- WTA-cf6cb28a-9d08-4252-8b2f-29f3e0cee90e =>.WildTangent
    O42 - Logiciel: Evernote - (.Evernote Launcher by Toshiba Europe GmbH.) [HKLM][64Bits] -- Evernote
    O42 - Logiciel: Evernote v. 5.0.3 - (.Evernote Corp..) [HKLM][64Bits] -- {32D39568-3B77-11E3-88CE-00163E98E7D0}
    O42 - Logiciel: Genesys USB Mass Storage Device - (.Genesys Logic.) [HKLM][64Bits] -- {959B7F35-2819-40C5-A0CD-3C53B5FCC935}
    O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome
    O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
    O42 - Logiciel: Google Earth - (.Google.) [HKLM][64Bits] -- {4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}
    O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
    O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
    O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {409CB30E-E457-4008-9B1A-ED1B9EA21140}
    O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {96714280-14E6-4DF7-BACD-F797C0F17C3D}
    O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {89AFB053-A343-46EF-97E4-D593AD7184E6}
    O42 - Logiciel: Island Tribe - (.WildTangent.) [HKLM][64Bits] -- WTA-5847ce85-f1c2-4471-9b6c-c337b60cb450 =>.WildTangent
    O42 - Logiciel: Jewel Quest Solitaire 2 - (.WildTangent.) [HKLM][64Bits] -- WTA-ead25a6e-06a1-4377-a37e-84daafe9cc66 =>.WildTangent
    O42 - Logiciel: Lecteur vidéo ARTE vod - (.boutique.arte.tv.) [HKCU][64Bits] -- 3644705650.boutique.arte.tv
    O42 - Logiciel: Magic Academy - (.WildTangent.) [HKLM][64Bits] -- WTA-c8c1aed3-56c2-4227-8f4d-e067de0ff8e5 =>.WildTangent
    O42 - Logiciel: Malwarebytes Anti-Malware version 2.0.3.1025 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes Anti-Malware_is1
    O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
    O42 - Logiciel: Microsoft SkyDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- SkyDriveSetup.exe =>.Microsoft Corporation
    O42 - Logiciel: NVIDIA GeForce Experience 2.0 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience
    O42 - Logiciel: NVIDIA Graphics Driver 326.60 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver
    O42 - Logiciel: NVIDIA PhysX - (.NVIDIA Corporation.) [HKLM][64Bits] -- {7B5AA67E-FEA0-40BB-BAB5-CA56645A589C}
    O42 - Logiciel: NVIDIA PhysX System Software 9.13.0725 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX
    O42 - Logiciel: Peggle Nights - (.WildTangent.) [HKLM][64Bits] -- WTA-03a6fa03-1446-405e-909b-daa24616eaea =>.WildTangent
    O42 - Logiciel: Plants vs. Zombies - Game of the Year - (.WildTangent.) [HKLM][64Bits] -- WTA-eb738b07-afcf-419e-984b-ce2e303af02a =>.WildTangent
    O42 - Logiciel: Polar Bowler - (.WildTangent.) [HKLM][64Bits] -- WTA-b18d610d-4f5c-4631-a63f-7e204f770927 =>.WildTangent
    O42 - Logiciel: Qualcomm Atheros Bluetooth Suite (64) - (.Qualcomm Atheros.) [HKLM][64Bits] -- {A84A4FB1-D703-48DB-89E0-68B6499D2801}
    O42 - Logiciel: Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver - (.Qualcomm Atheros Inc..) [HKLM][64Bits] -- {3108C217-BE83-42E4-AE9E-A56A2A92E549}
    O42 - Logiciel: Skitch - (.Evernote Corp..) [HKLM][64Bits] -- Skitch 2.3.2.173
    O42 - Logiciel: Skype(TM) 7.0 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
    O42 - Logiciel: Spotify - (.Spotify AB.) [HKLM][64Bits] -- Spotify
    O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey
    O42 - Logiciel: TOSHIBA Addendum - (.TOSHIBA.) [HKLM][64Bits] -- {C1569944-FAD6-4B3B-85E5-C213C2FF8EFC}
    O42 - Logiciel: TOSHIBA Desktop Assist - (.Toshiba Corporation.) [HKLM][64Bits] -- {95CCACF0-010D-45F0-82BF-858643D8BC02}
    O42 - Logiciel: TOSHIBA Display Utility - (.Toshiba Corporation.) [HKLM][64Bits] -- {5F6AC07E-50EF-422E-B56E-6521E5B35139}
    O42 - Logiciel: TOSHIBA Function Key - (.Toshiba Corporation.) [HKLM][64Bits] -- {16562A90-71BC-41A0-B890-D91B0C267120}
    O42 - Logiciel: TOSHIBA Gesture Controller - (.Toshiba Corporation.) [HKLM][64Bits] -- {8C5B4504-3996-4F30-8F01-DA7A8455430B}
    O42 - Logiciel: TOSHIBA Manuals - (.TOSHIBA.) [HKLM][64Bits] -- {90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}
    O42 - Logiciel: TOSHIBA PC Health Monitor - (.Toshiba Corporation.) [HKLM][64Bits] -- {9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}
    O42 - Logiciel: TOSHIBA Password Utility - (.Toshiba Corporation.) [HKLM][64Bits] -- InstallShield_{26BB68BB-CF93-4A12-BC6D-A3B6F53AC8D9}
    O42 - Logiciel: TOSHIBA Recovery Media Creator - (.Toshiba Corporation.) [HKLM][64Bits] -- {B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}
    O42 - Logiciel: TOSHIBA Service Station - (.Toshiba Corporation.) [HKLM][64Bits] -- {FBFCEEA5-96EA-4C8E-9262-43CBBEBAE413} =>.Toshiba Corporation
    O42 - Logiciel: TOSHIBA Start Screen Option - (.Toshiba Corporation.) [HKLM][64Bits] -- {06B71035-F19F-4F76-9875-FFCCD4FC3F83}
    O42 - Logiciel: TOSHIBA System Driver - (.Toshiba Corporation.) [HKLM][64Bits] -- {1E6A96A1-2BAB-43EF-8087-30437593C66C}
    O42 - Logiciel: TOSHIBA System Settings - (.Toshiba Corporation.) [HKLM][64Bits] -- {05A55927-DB9B-4E26-BA44-828EBFF829F0}
    O42 - Logiciel: TOSHIBA VIDEO PLAYER - (.Toshiba Corporation.) [HKLM][64Bits] -- {FF07604E-C860-40E9-A230-E37FA41F103A}
    O42 - Logiciel: TOSHIBA eco Utility - (.Toshiba Corporation.) [HKLM][64Bits] -- {5944B9D4-3C2A-48DE-931E-26B31714A2F7} =>.Toshiba Corporation
    O42 - Logiciel: Toshiba TEMPRO - (.Toshiba Europe GmbH.) [HKLM][64Bits] -- {F76F5214-83A8-4030-80C9-1EF57391D72A} =>.Toshiba Corporation
    O42 - Logiciel: Update Installer for WildTangent Games App - (.WildTangent.) [HKLM][64Bits] -- {2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App =>.WildTangent
    O42 - Logiciel: Virtual Villagers 4 - The Tree of Life - (.WildTangent.) [HKLM][64Bits] -- WTA-a037fff4-2341-400a-81ba-208887991f81 =>.WildTangent
    O42 - Logiciel: WildTangent Games - (.WildTangent.) [HKLM][64Bits] -- WildTangent wildgames Master Uninstall =>.WildTangent
    O42 - Logiciel: WildTangent Games App (Toshiba Games) - (.WildTangent.) [HKLM][64Bits] -- {70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-toshiba =>.WildTangent
    O42 - Logiciel: WinRAR 5.01 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver
    ~ Logic: 59 Scanned in 00mn 00s

    ---\\ HKCU & HKLM Software Keys
    [HKCU\Software\AppDataLow]
    [HKCU\Software\Avira]
    [HKCU\Software\Classes]
    [HKCU\Software\Clients]
    [HKCU\Software\Conexant]
    [HKCU\Software\Disc Soft]
    [HKCU\Software\Evernote]
    [HKCU\Software\Google]
    [HKCU\Software\Hewlett-Packard]
    [HKCU\Software\IM Providers]
    [HKCU\Software\Intel]
    [HKCU\Software\LogiShrd]
    [HKCU\Software\Macromedia]
    [HKCU\Software\MozillaPlugins]
    [HKCU\Software\NVIDIA Corporation]
    [HKCU\Software\Netscape]
    [HKCU\Software\ODBC]
    [HKCU\Software\Piriform]
    [HKCU\Software\Policies]
    [HKCU\Software\RegisteredApplications]
    [HKCU\Software\Skype]
    [HKCU\Software\Synaptics]
    [HKCU\Software\Toshiba]
    [HKCU\Software\Trolltech]
    [HKCU\Software\WinRAR SFX]
    [HKCU\Software\WinRAR]
    [HKCU\Software\Wow6432Node]
    [HKCU\Software\ZebHelpProcess Helper]
    [HKLM\Software\AGEIA Technologies]
    [HKLM\Software\Atheros]
    [HKLM\Software\Classes]
    [HKLM\Software\Clients]
    [HKLM\Software\Cnxt_Uiu_Parms]
    [HKLM\Software\Conexant]
    [HKLM\Software\IM Providers]
    [HKLM\Software\InstalledOptions]
    [HKLM\Software\IntelVolatile]
    [HKLM\Software\Intel]
    [HKLM\Software\Khronos]
    [HKLM\Software\Logishrd]
    [HKLM\Software\Macromedia]
    [HKLM\Software\McAfee]
    [HKLM\Software\MozillaPlugins]
    [HKLM\Software\NVIDIA Corporation]
    [HKLM\Software\ODBC]
    [HKLM\Software\Piriform]
    [HKLM\Software\Policies]
    [HKLM\Software\RegisteredApplications]
    [HKLM\Software\SRS Labs]
    [HKLM\Software\Synaptics]
    [HKLM\Software\ToshibaBlobDelivery]
    [HKLM\Software\Toshiba]
    [HKLM\Software\UIU]
    [HKLM\Software\WinRAR]
    [HKLM\Software\Wow6432Node\AGEIA Technologies]
    [HKLM\Software\Wow6432Node\Atheros]
    [HKLM\Software\Wow6432Node\Avira]
    [HKLM\Software\Wow6432Node\Classes]
    [HKLM\Software\Wow6432Node\Clients]
    [HKLM\Software\Wow6432Node\DTS, Inc.]
    [HKLM\Software\Wow6432Node\DTS]
    [HKLM\Software\Wow6432Node\Disc Soft]
    [HKLM\Software\Wow6432Node\Evernote Corp.]
    [HKLM\Software\Wow6432Node\Genesys Logic]
    [HKLM\Software\Wow6432Node\Google]
    [HKLM\Software\Wow6432Node\IM Providers]
    [HKLM\Software\Wow6432Node\InstallShield]
    [HKLM\Software\Wow6432Node\Intel]
    [HKLM\Software\Wow6432Node\Khronos]
    [HKLM\Software\Wow6432Node\Macromedia]
    [HKLM\Software\Wow6432Node\McAfee]
    [HKLM\Software\Wow6432Node\MozillaPlugins]
    [HKLM\Software\Wow6432Node\Mozilla]
    [HKLM\Software\Wow6432Node\NVIDIA Corporation]
    [HKLM\Software\Wow6432Node\ODBC]
    [HKLM\Software\Wow6432Node\Policies]
    [HKLM\Software\Wow6432Node\Qualcomm Atheros Inc.]
    [HKLM\Software\Wow6432Node\Qualcomm Atheros]
    [HKLM\Software\Wow6432Node\RegisteredApplications]
    [HKLM\Software\Wow6432Node\SRS Labs]
    [HKLM\Software\Wow6432Node\Skype]
    [HKLM\Software\Wow6432Node\TOSHIBA]
    [HKLM\Software\Wow6432Node\The Silicon Realms Toolworks]
    [HKLM\Software\Wow6432Node\Toshiba Corporation]
    [HKLM\Software\Wow6432Node\Volatile]
    [HKLM\Software\Wow6432Node\WildTangent]
    [HKLM\Software\Wow6432Node\X-AVCSD]
    [HKLM\Software\Wow6432Node\sMedio]
    [HKLM\Software\Wow6432Node]
    ~ Key Software: 216 Scanned in 00mn 00s

    ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
    O43 - CFD: 09/01/2014 - 21:56:53 - [0] ----D C:\Program Files (x86)\AGEIA Technologies
    O43 - CFD: 09/01/2014 - 22:08:07 - [] ----D C:\Program Files (x86)\Atheros
    O43 - CFD: 16/12/2014 - 16:36:11 - [] ----D C:\Program Files (x86)\Avira
    O43 - CFD: 09/01/2014 - 22:07:00 - [] ----D C:\Program Files (x86)\Bluetooth Suite
    O43 - CFD: 26/09/2014 - 19:59:52 - [] ----D C:\Program Files (x86)\Common Files
    O43 - CFD: 09/01/2014 - 22:02:01 - [] ----D C:\Program Files (x86)\DTS, Inc
    O43 - CFD: 09/12/2014 - 14:08:46 - [] ----D C:\Program Files (x86)\Evernote
    O43 - CFD: 05/12/2013 - 03:58:56 - [] ----D C:\Program Files (x86)\Evernote_TLauncher
    O43 - CFD: 03/03/2014 - 20:36:52 - [] ----D C:\Program Files (x86)\Google
    O43 - CFD: 09/01/2014 - 23:09:12 - [] --H-D C:\Program Files (x86)\InstallShield Installation Information
    O43 - CFD: 09/01/2014 - 21:52:23 - [] ----D C:\Program Files (x86)\Intel
    O43 - CFD: 13/12/2014 - 11:33:35 - [] ----D C:\Program Files (x86)\Internet Explorer
    O43 - CFD: 30/10/2014 - 14:52:06 - [] ----D C:\Program Files (x86)\Malwarebytes Anti-Malware
    O43 - CFD: 28/02/2014 - 22:05:44 - [] ----D C:\Program Files (x86)\Microsoft ActiveSync
    O43 - CFD: 18/11/2014 - 13:11:24 - [] ----D C:\Program Files (x86)\Microsoft Office
    O43 - CFD: 29/07/2014 - 10:58:28 - [] ----D C:\Program Files (x86)\Microsoft Silverlight
    O43 - CFD: 26/03/2014 - 15:15:26 - [] ----D C:\Program Files (x86)\Microsoft SkyDrive =>.Microsoft Corporation
    O43 - CFD: 28/02/2014 - 22:03:40 - [] ----D C:\Program Files (x86)\Microsoft.NET
    O43 - CFD: 28/08/2013 - 23:21:55 - [] ----D C:\Program Files (x86)\MSBuild
    O43 - CFD: 18/11/2014 - 13:10:20 - [] ----D C:\Program Files (x86)\MSECache
    O43 - CFD: 29/04/2014 - 09:28:18 - [] ----D C:\Program Files (x86)\NVIDIA Corporation
    O43 - CFD: 28/08/2013 - 23:21:55 - [] ----D C:\Program Files (x86)\Reference Assemblies
    O43 - CFD: 20/12/2014 - 07:39:14 - [] R---D C:\Program Files (x86)\Skype
    O43 - CFD: 05/12/2013 - 03:58:12 - [] ----D C:\Program Files (x86)\Spotify
    O43 - CFD: 09/01/2014 - 23:09:11 - [] ----D C:\Program Files (x86)\TOSHIBA
    O43 - CFD: 09/01/2014 - 22:59:26 - [] ----D C:\Program Files (x86)\TOSHIBA Games
    O43 - CFD: 09/01/2014 - 22:33:15 - [] ----D C:\Program Files (x86)\Toshiba TEMPRO =>.Toshiba Corporation
    O43 - CFD: 09/01/2014 - 22:58:20 - [] ----D C:\Program Files (x86)\WildGames
    O43 - CFD: 07/11/2014 - 14:29:04 - [] ----D C:\Program Files (x86)\WildTangent Games
    O43 - CFD: 14/11/2014 - 10:47:07 - [] ----D C:\Program Files (x86)\Windows Defender
    O43 - CFD: 25/02/2014 - 20:07:59 - [] ----D C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
    O43 - CFD: 02/05/2014 - 21:01:15 - [] ----D C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
    O43 - CFD: 02/05/2014 - 21:01:16 - [] ----D C:\Program Files (x86)\Windows Multimedia Platform
    O43 - CFD: 22/08/2013 - 16:36:30 - [] ----D C:\Program Files (x86)\Windows NT
    O43 - CFD: 25/02/2014 - 20:07:58 - [] ----D C:\Program Files (x86)\Windows Photo Viewer
    O43 - CFD: 02/05/2014 - 21:01:15 - [] ----D C:\Program Files (x86)\Windows Portable Devices
    O43 - CFD: 22/08/2013 - 16:36:30 - [] -SH-D C:\Program Files (x86)\Windows Sidebar
    O43 - CFD: 22/08/2013 - 16:36:30 - [] ----D C:\Program Files (x86)\WindowsPowerShell
    O43 - CFD: 24/01/2015 - 11:52:02 - [] ----D C:\Program Files (x86)\ZHPDiag =>.Nicolas Coolman
    O43 - CFD: 09/01/2014 - 22:07:00 - [] ----D C:\Program Files (x86)\Common Files\Atheros
    O43 - CFD: 04/05/2014 - 19:30:31 - [] ----D C:\Program Files (x86)\Common Files\DESIGNER
    O43 - CFD: 09/01/2014 - 22:08:32 - [] ----D C:\Program Files (x86)\Common Files\InstallShield
    O43 - CFD: 09/01/2014 - 21:52:07 - [] ----D C:\Program Files (x86)\Common Files\Intel
    O43 - CFD: 18/11/2014 - 13:11:20 - [] ----D C:\Program Files (x86)\Common Files\Microsoft Shared
    O43 - CFD: 09/01/2014 - 21:48:28 - [] ----D C:\Program Files (x86)\Common Files\postureAgent
    O43 - CFD: 22/08/2013 - 16:36:33 - [] ----D C:\Program Files (x86)\Common Files\Services
    O43 - CFD: 26/09/2014 - 19:59:52 - [] ----D C:\Program Files (x86)\Common Files\Skype
    O43 - CFD: 28/02/2014 - 22:04:07 - [] ----D C:\Program Files (x86)\Common Files\System
    O43 - CFD: 09/01/2014 - 22:29:35 - [] ----D C:\Program Files (x86)\Common Files\Toshiba Shared
    O43 - CFD: 22/08/2013 - 15:45:52 - [] -SH-D C:\ProgramData\Application Data
    O43 - CFD: 30/10/2014 - 16:16:29 - [] ----D C:\ProgramData\Avira
    O43 - CFD: 22/02/2014 - 19:15:27 - [] ----D C:\ProgramData\BlueStacks
    O43 - CFD: 09/01/2014 - 22:00:10 - [] ----D C:\ProgramData\Conexant
    O43 - CFD: 27/02/2014 - 18:18:28 - [] ----D C:\ProgramData\DAEMON Tools Lite =>.DT Soft Ltd
    O43 - CFD: 22/08/2013 - 15:45:52 - [] -S--D C:\ProgramData\Desktop
    O43 - CFD: 22/08/2013 - 15:45:52 - [] -SH-D C:\ProgramData\Documents
    O43 - CFD: 09/01/2014 - 21:59:59 - [] ----D C:\ProgramData\Intel
    O43 - CFD: 29/04/2014 - 10:10:04 - [] ----D C:\ProgramData\Malwarebytes
    O43 - CFD: 29/04/2014 - 09:08:37 - [] ----D C:\ProgramData\McAfee
    O43 - CFD: 29/07/2014 - 10:58:40 - [] -S--D C:\ProgramData\Microsoft
    O43 - CFD: 26/03/2014 - 15:15:17 - [] ----D C:\ProgramData\Microsoft SkyDrive =>.Microsoft Corporation
    O43 - CFD: 29/04/2014 - 09:32:17 - [] ----D C:\ProgramData\NVIDIA
    O43 - CFD: 29/04/2014 - 09:32:58 - [] ----D C:\ProgramData\NVIDIA Corporation
    O43 - CFD: 16/12/2014 - 16:36:15 - [] ----D C:\ProgramData\Package Cache
    O43 - CFD: 09/01/2014 - 22:07:48 - [] ----D C:\ProgramData\Qualcomm Atheros
    O43 - CFD: 04/05/2014 - 19:30:31 - [] ----D C:\ProgramData\regid.1991-06.com.microsoft
    O43 - CFD: 20/12/2014 - 07:39:28 - [] ----D C:\ProgramData\Skype
    O43 - CFD: 09/01/2014 - 22:02:01 - [] ----D C:\ProgramData\SRS Labs
    O43 - CFD: 22/08/2013 - 15:45:52 - [] -SH-D C:\ProgramData\Start Menu
    O43 - CFD: 22/08/2013 - 15:45:52 - [] -SH-D C:\ProgramData\Templates
    O43 - CFD: 22/02/2014 - 16:05:36 - [] ----D C:\ProgramData\TOSHIBA
    O43 - CFD: 22/02/2014 - 16:06:02 - [] ----D C:\ProgramData\ToshibaEurope
    O43 - CFD: 22/02/2014 - 22:25:37 - [] ----D C:\ProgramData\WildTangent
    O43 - CFD: 22/08/2013 - 16:36:33 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
    O43 - CFD: 22/08/2013 - 20:12:21 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
    O43 - CFD: 02/05/2014 - 21:01:36 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    O43 - CFD: 16/12/2014 - 16:36:12 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
    O43 - CFD: 09/01/2014 - 22:02:01 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DTS, Inc
    O43 - CFD: 09/12/2014 - 14:09:06 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
    O43 - CFD: 07/11/2014 - 14:29:06 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
    O43 - CFD: 22/02/2014 - 16:07:33 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    O43 - CFD: 03/03/2014 - 20:37:06 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth =>.Google Inc
    O43 - CFD: 22/08/2013 - 16:36:33 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
    O43 - CFD: 30/10/2014 - 14:52:06 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    O43 - CFD: 01/08/2014 - 13:42:56 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
    O43 - CFD: 29/07/2014 - 10:58:37 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    O43 - CFD: 09/01/2014 - 21:56:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
    O43 - CFD: 30/12/2014 - 23:17:21 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skitch
    O43 - CFD: 26/09/2014 - 19:59:52 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    O43 - CFD: 09/01/2014 - 23:14:00 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
    O43 - CFD: 02/05/2014 - 21:01:37 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
    O43 - CFD: 22/08/2013 - 20:12:21 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
    O43 - CFD: 09/01/2014 - 23:08:53 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOSHIBA
    O43 - CFD: 09/01/2014 - 22:31:00 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOSHIBA Gesture Controller
    O43 - CFD: 27/02/2014 - 18:35:29 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    O43 - CFD: 24/01/2015 - 11:52:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP =>.Nicolas Coolman
    O43 - CFD: 22/02/2014 - 15:59:39 - [] ----D C:\Users\HELENE\AppData\Roaming\Adobe
    O43 - CFD: 08/11/2014 - 14:11:41 - [] ----D C:\Users\HELENE\AppData\Roaming\Avira
    O43 - CFD: 19/11/2014 - 10:51:01 - [] ----D C:\Users\HELENE\AppData\Roaming\DAEMON Tools Lite =>.DT Soft Ltd
    O43 - CFD: 24/01/2015 - 10:21:29 - [] ----D C:\Users\HELENE\AppData\Roaming\Dropbox
    O43 - CFD: 28/02/2014 - 22:08:30 - [] ----D C:\Users\HELENE\AppData\Roaming\Identities
    O43 - CFD: 22/02/2014 - 19:15:18 - [] ----D C:\Users\HELENE\AppData\Roaming\Macromedia
    O43 - CFD: 05/04/2014 - 14:02:50 - [] -S--D C:\Users\HELENE\AppData\Roaming\Microsoft
    O43 - CFD: 21/01/2015 - 23:05:08 - [] ----D C:\Users\HELENE\AppData\Roaming\Skype
    O43 - CFD: 25/02/2014 - 10:48:59 - [] ----D C:\Users\HELENE\AppData\Roaming\sMedio
    O43 - CFD: 30/12/2014 - 23:17:50 - [] ----D C:\Users\HELENE\AppData\Roaming\Spotify
    O43 - CFD: 22/02/2014 - 19:14:37 - [] ----D C:\Users\HELENE\AppData\Roaming\WildTangent
    O43 - CFD: 24/01/2015 - 11:53:56 - [] ----D C:\Users\HELENE\AppData\Roaming\ZHP =>.Nicolas Coolman
    O43 - CFD: 22/02/2014 - 15:57:21 - [] -SH-D C:\Users\HELENE\AppData\Local\Application Data
    O43 - CFD: 22/02/2014 - 16:06:38 - [] ----D C:\Users\HELENE\AppData\Local\Apps
    O43 - CFD: 22/02/2014 - 16:06:48 - [0] ----D C:\Users\HELENE\AppData\Local\Deployment
    O43 - CFD: 31/03/2014 - 17:42:21 - [0] ----D C:\Users\HELENE\AppData\Local\Diagnostics
    O43 - CFD: 26/09/2014 - 08:48:42 - [0] ----D C:\Users\HELENE\AppData\Local\ElevatedDiagnostics
    O43 - CFD: 06/06/2014 - 22:26:24 - [] -SH-D C:\Users\HELENE\AppData\Local\EmieSiteList
    O43 - CFD: 06/06/2014 - 22:26:24 - [] -SH-D C:\Users\HELENE\AppData\Local\EmieUserList
    O43 - CFD: 25/12/2014 - 20:11:17 - [] ----D C:\Users\HELENE\AppData\Local\Evernote
    O43 - CFD: 03/03/2014 - 20:37:05 - [] ----D C:\Users\HELENE\AppData\Local\Google
    O43 - CFD: 22/02/2014 - 15:57:21 - [] -SH-D C:\Users\HELENE\AppData\Local\Historique
    O43 - CFD: 29/04/2014 - 09:26:46 - [] ----D C:\Users\HELENE\AppData\Local\Intel_Corporation
    O43 - CFD: 29/07/2014 - 11:31:17 - [] ----D C:\Users\HELENE\AppData\Local\Microsoft
    O43 - CFD: 29/04/2014 - 09:25:54 - [] ----D C:\Users\HELENE\AppData\Local\NVIDIA
    O43 - CFD: 29/04/2014 - 09:25:07 - [] ----D C:\Users\HELENE\AppData\Local\NVIDIA Corporation
    O43 - CFD: 02/11/2014 - 19:55:02 - [] ----D C:\Users\HELENE\AppData\Local\Packages
    O43 - CFD: 29/04/2014 - 10:09:05 - [] ----D C:\Users\HELENE\AppData\Local\Programs
    O43 - CFD: 23/01/2015 - 10:23:01 - [] ----D C:\Users\HELENE\AppData\Local\Skitch
    O43 - CFD: 22/02/2014 - 16:44:28 - [] ----D C:\Users\HELENE\AppData\Local\Skype
    O43 - CFD: 22/02/2014 - 19:17:42 - [] ----D C:\Users\HELENE\AppData\Local\Spotify
    O43 - CFD: 24/01/2015 - 11:53:37 - [] ----D C:\Users\HELENE\AppData\Local\Temp
    O43 - CFD: 22/02/2014 - 15:57:21 - [] -SH-D C:\Users\HELENE\AppData\Local\Temporary Internet Files
    O43 - CFD: 22/02/2014 - 16:01:59 - [] ----D C:\Users\HELENE\AppData\Local\TOSHIBA
    O43 - CFD: 26/03/2014 - 15:08:23 - [] ----D C:\Users\HELENE\AppData\Local\VirtualStore
    O43 - CFD: 22/08/2013 - 16:36:32 - [] R---D C:\Users\HELENE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
    O43 - CFD: 22/08/2013 - 16:36:32 - [] R---D C:\Users\HELENE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    O43 - CFD: 14/11/2014 - 11:52:11 - [] R---D C:\Users\HELENE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    O43 - CFD: 13/12/2014 - 13:23:57 - [] ----D C:\Users\HELENE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
    O43 - CFD: 22/08/2013 - 16:36:32 - [] ----D C:\Users\HELENE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    O43 - CFD: 13/12/2014 - 13:24:20 - [] R---D C:\Users\HELENE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    O43 - CFD: 22/08/2013 - 16:36:32 - [] R---D C:\Users\HELENE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    O43 - CFD: 27/02/2014 - 18:35:29 - [] ----D C:\Users\HELENE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    ~ Program Folder: 139 Scanned in 00mn 00s

    ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
    O44 - LFC:[MD5.6F237EE5DDA34EAF3D9C79D4A283E250] - 14/01/2015 - 11:52:24 ---A- . (.Microsoft Corporation - Audio Engine.) -- C:\Windows\System32\AudioEng.dll [482872]
    O44 - LFC:[MD5.E24D3259769A0218FE19BB306821C2E5] - 14/01/2015 - 11:52:24 ---A- . (.Microsoft Corporation - Audio Ks Endpoint.) -- C:\Windows\System32\AUDIOKSE.dll [394120]
    O44 - LFC:[MD5.A41B72F81B389786805CC4D5767B5FBC] - 14/01/2015 - 11:52:24 ---A- . (.Microsoft Corporation - Code Integrity Module (Test).) -- C:\Windows\System32\ci.dll [531616]
    O44 - LFC:[MD5.8779FDAE68BC948B0FE152E758CC8DA7] - 14/01/2015 - 11:52:24 ---A- . (.Microsoft Corporation - Générateur de points de terminaison du serv.) -- C:\Windows\System32\AudioEndpointBuilder.dll [229888]
    O44 - LFC:[MD5.770BAA636F3B61DA7E414421444F84FD] - 14/01/2015 - 11:52:24 ---A- . (.Microsoft Corporation - Isolation graphique de périphérique audio W.) -- C:\Windows\System32\audiodg.exe [272248]
    O44 - LFC:[MD5.41C501FD9D42F3F04A8532C73E09F356] - 14/01/2015 - 11:52:24 ---A- . (.Microsoft Corporation - Media Foundation Crash Dump Encryption DLL.) -- C:\Windows\System32\EncDump.dll [108944]
    O44 - LFC:[MD5.9404704666256045F5BA9B290953B4D0] - 14/01/2015 - 11:52:24 ---A- . (.Microsoft Corporation - Rapport d'erreurs Windows.) -- C:\Windows\System32\WerFaultSecure.exe [38264]
    O44 - LFC:[MD5.61EA45A645854FE81D8A924E2D93DFFE] - 14/01/2015 - 11:52:24 ---A- . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\audiosrv.dll [911360]
    O44 - LFC:[MD5.428F083690D7AAA012338FD5A0663EE3] - 14/01/2015 - 11:52:24 ---A- . (.Microsoft Corporation - Session audio.) -- C:\Windows\System32\AudioSes.dll [500016]
    O44 - LFC:[MD5.D1E3B8D9130C70F6A3D4FDB52373FF34] - 14/01/2015 - 11:52:24 ---A- . (.Microsoft Corporation - WER Diagnostic Controller.) -- C:\Windows\System32\werdiagcontroller.dll [37888]
    O44 - LFC:[MD5.0BCDEB035B9346D3C3C6C8BB1AA7F38C] - 14/01/2015 - 11:52:24 ---A- . (.Microsoft Corporation - Windows Problem Reporting.) -- C:\Windows\System32\wermgr.exe [139984]
    O44 - LFC:[MD5.F0CB6DB513CAC393D04A0FCE0A59E1BF] - 14/01/2015 - 11:52:25 ---A- . (.Microsoft Corporation - Application Compatibility Cache.) -- C:\Windows\System32\Drivers\ahcache.sys [75776]
    O44 - LFC:[MD5.8EBC741DDE9409038262E2F317ED7CCE] - 14/01/2015 - 11:52:25 ---A- . (.Microsoft Corporation - DLL du rapport d'erreurs Windows.) -- C:\Windows\System32\wer.dll [535640]
    O44 - LFC:[MD5.2C354FA91EF605007FD11BB89EED2266] - 14/01/2015 - 11:52:25 ---A- . (.Microsoft Corporation - DLL du rapport d'incident dans le mode util.) -- C:\Windows\System32\Faultrep.dll [413248]
    O44 - LFC:[MD5.29A888F3136B2643E22113B5422B46F9] - 14/01/2015 - 11:52:25 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Proxy.) -- C:\Windows\System32\TSWbPrxy.exe [87040]
    O44 - LFC:[MD5.6DCD12586353DC6307AC781045CA13A4] - 14/01/2015 - 11:52:25 ---A- . (.Microsoft Corporation - Rapports de problèmes Windows.) -- C:\Windows\System32\WerFault.exe [465320]
    O44 - LFC:[MD5.DB32958F0E704EFBF7F15161A569E39F] - 14/01/2015 - 11:52:25 ---A- . (.Microsoft Corporation - Windows NT WebDav Minirdr.) -- C:\Windows\System32\Drivers\mrxdav.sys [140800]
    O44 - LFC:[MD5.E94EB2A95D7D016E119C4D6868788831] - 14/01/2015 - 11:52:26 ---A- . (.Microsoft Corporation - Connaissance des emplacements réseau 2.) -- C:\Windows\System32\nlasvc.dll [391680]
    O44 - LFC:[MD5.FE11972797DED38CA55E88BD3579F6A2] - 14/01/2015 - 11:52:26 ---A- . (.Microsoft Corporation - Indicateur d'état de la connectivité réseau.) -- C:\Windows\System32\ncsi.dll [360448]
    O44 - LFC:[MD5.6319232C1CE39AC35316CF51910EEEB5] - 14/01/2015 - 11:52:26 ---A- . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\System32\nlaapi.dll [86016]
    O44 - LFC:[MD5.19424364D8C03B990C4281BE53963FD0] - 14/01/2015 - 11:52:26 ---A- . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [225280]
    O44 - LFC:[MD5.93B0550500D1BD86CBAB9C4CC6B6A356] - 14/01/2015 - 11:54:09 ---A- . (.Microsoft Corporation - Outil de suppression de logiciels malveilla.) -- C:\Windows\System32\MRT.exe [113365784]
    O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 21/01/2015 - 15:03:19 ---A- . (...) -- C:\Windows\setupact.log [0]
    O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 21/01/2015 - 15:03:19 ---A- . (...) -- C:\Windows\setuperr.log [0]
    O44 - LFC:[MD5.64B401A6116BA6719E654B4ABC860EE3] - 24/01/2015 - 10:19:27 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
    O44 - LFC:[MD5.C88A13EDED1A2465944F33E6296A55F1] - 24/01/2015 - 10:39:47 ---A- . (...) -- C:\Windows\WindowsUpdate.log [795696]
    ~ Files: 26 Scanned in 01mn 41s

    ---\\ Déni du service (Local Security Authority) (O48)
    O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
    O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l'Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
    ~ LSA: 3 Scanned in 00mn 00s

    ---\\ Contrôle du Safe Boot (CSB) (O49)
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\BasicDisplay.sys . (.Microsoft Corporation - Microsoft Basic Display Driver.) -- C:\Windows\System32\Drivers\BasicDisplay.sys
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\BasicRender.sys . (.Microsoft Corporation - Microsoft Basic Render Driver.) -- C:\Windows\System32\Drivers\BasicRender.sys
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dxgkrnl.sys . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\Drivers\dxgkrnl.sys
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\FsDepends.sys . (.Microsoft Corporation - File System Dependency Manager Mini Filter Driver.) -- C:\Windows\System32\Drivers\FsDepends.sys
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d'extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\BasicDisplay.sys . (.Microsoft Corporation - Microsoft Basic Display Driver.) -- C:\Windows\System32\Drivers\BasicDisplay.sys
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\BasicRender.sys . (.Microsoft Corporation - Microsoft Basic Render Driver.) -- C:\Windows\System32\Drivers\BasicRender.sys
    O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dxgkrnl.sys . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Wind
    0
  3. HELENE34 Messages postés 152 Date d'inscription   Statut Membre Dernière intervention   6
     
    Bonjour Jacques,
    depuis que j'ai fait ce rapport, j'ai fait un autre nettoyage avec CCCLEANER et Delfix; çà va mieux mais je ne suis pas certaine que tout soit ok.

    Merci,
    HELENE
    0
  4. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
     
    bonjour, tu serait sympa de suivre les consigne je te demandais de poster le rapport de zhpdiag par le biais de cjoint https://www.cjoint.com/ et si il était demander cela c'est pas pour faire jolie, car si tu regarde bien ton rapport est pas complet , puis zhpdiag ne nettoie pas les infections , ccleaner non plus et delfix est un outils pour supprimer les outils et rapports purger la restauration système !! sans plus , donc si tu veux que l'on t'aide à nettoyer ton pc commence par nous aider en faisant se qui est demander sans plus ni moins!! merci
    0