Supprimer Iminent
drea07
-
lilidurhone Messages postés 43355 Date d'inscription Statut Contributeur sécurité Dernière intervention -
lilidurhone Messages postés 43355 Date d'inscription Statut Contributeur sécurité Dernière intervention -
Bonjour,
j'ai fait un scan avec Mbam et supprimé HKLM imminent A. J'ai vu qu'une personne avais eu le même problème et donc suivi vos prescriptions avec un scan avec adwcleaner. Voici le rapport. Quels éléments dois-je supprimer ? tout ?
Dernièrement j'ai des élévations de la température du CPU anormale. pendant le scan Mbam les CPU ont monté vers les 90° d'après Coretemp. Est ce que ça peut venir de ce virus ?
Merci d'avance
# AdwCleaner v4.203 - Rapport créé le 08/05/2015 à 10:29:07
# Mis à jour le 30/04/2015 par Xplode
# Base de données : 2015-05-05.1 [Serveur]
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (x86)
# Nom d'utilisateur : Amaury - AMAURY-PC
# Exécuté depuis : C:\Users\Amaury\Downloads\adwcleaner_4.203.exe
# Option : Scanner
Dossier Trouvé : C:\Program Files\sweetpacks bundle uninstaller
Dossier Trouvé : C:\Users\Amaury\AppData\Roaming\YourFileDownloader
Fichier Trouvé : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
Clé Trouvée : HKCU\Software\Conduit
Clé Trouvée : HKCU\Software\Softonic
Clé Trouvée : HKCU\Software\YourFileDownloader
Clé Trouvée : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Clé Trouvée : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Clé Trouvée : HKLM\SOFTWARE\Classes\FTDownloader
Clé Trouvée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Clé Trouvée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Clé Trouvée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
Clé Trouvée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
Clé Trouvée : HKLM\SOFTWARE\YourFileDownloader
Donnée Trouvée : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
-\\ Internet Explorer v11.0.9600.17728
-\\ Mozilla Firefox v37.0.2 (x86 fr)
-\\ Google Chrome v
AdwCleaner[R0].txt - [1857 octets] - [08/05/2015 10:29:07]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1917 octets] ##########
j'ai fait un scan avec Mbam et supprimé HKLM imminent A. J'ai vu qu'une personne avais eu le même problème et donc suivi vos prescriptions avec un scan avec adwcleaner. Voici le rapport. Quels éléments dois-je supprimer ? tout ?
Dernièrement j'ai des élévations de la température du CPU anormale. pendant le scan Mbam les CPU ont monté vers les 90° d'après Coretemp. Est ce que ça peut venir de ce virus ?
Merci d'avance
# AdwCleaner v4.203 - Rapport créé le 08/05/2015 à 10:29:07
# Mis à jour le 30/04/2015 par Xplode
# Base de données : 2015-05-05.1 [Serveur]
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (x86)
# Nom d'utilisateur : Amaury - AMAURY-PC
# Exécuté depuis : C:\Users\Amaury\Downloads\adwcleaner_4.203.exe
# Option : Scanner
- [ Services ] *****
- [ Fichiers / Dossiers ] *****
Dossier Trouvé : C:\Program Files\sweetpacks bundle uninstaller
Dossier Trouvé : C:\Users\Amaury\AppData\Roaming\YourFileDownloader
Fichier Trouvé : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
- [ Tâches planifiées ] *****
- [ Raccourcis ] *****
- [ Registre ] *****
Clé Trouvée : HKCU\Software\Conduit
Clé Trouvée : HKCU\Software\Softonic
Clé Trouvée : HKCU\Software\YourFileDownloader
Clé Trouvée : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Clé Trouvée : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Clé Trouvée : HKLM\SOFTWARE\Classes\FTDownloader
Clé Trouvée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Clé Trouvée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Clé Trouvée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
Clé Trouvée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
Clé Trouvée : HKLM\SOFTWARE\YourFileDownloader
Donnée Trouvée : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
- [ Navigateurs ] *****
-\\ Internet Explorer v11.0.9600.17728
-\\ Mozilla Firefox v37.0.2 (x86 fr)
-\\ Google Chrome v
AdwCleaner[R0].txt - [1857 octets] - [08/05/2015 10:29:07]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1917 octets] ##########
A voir également:
- Pc doctor dell supportassist api
- Supprimer rond bleu whatsapp - Guide
- Supprimer page word - Guide
- Supprimer pub youtube - Accueil - Streaming
- Fichier impossible à supprimer - Guide
- Supprimer compte instagram - Guide
36 réponses
j'ai Scanner, nettoyer, rapport, quitter. Restaurer.
je suppose que c'est restaurer que tu veux dire?
je suppose que c'est restaurer que tu veux dire?
Bon ben j'ai Nettoyer en fin de compte après un tour sur le forum de coolman, j'ai vu qu'il parlait d'interface de réparation quand on clique sur nettoyer donc je suppose que c'était ça que tu voulais dire.
Voici le rapport.
~ ZHPCleaner v2015.5.8.220 by Nicolas Coolman (09/05/2015)
~ Run by Amaury (Administrator) (09/05/2015 20:05:52)
~ Forum : http://forum.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Netttoyer
~ Report : C:\Users\Amaury\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Amaury\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Deactivate
~ Boot Mode : Normal (Normal boot)
~ Windows 7, 32-bit Service Pack 1 (Build 7601)
---\\ Service. (0)
~ Aucun élément malicieux trouvé.
---\\ Navigateur internet. (0)
~ Aucun élément malicieux trouvé.
---\\ Fichier hôte. (1)
~ Le fichier hôte est légitime. (21)
---\\ Tâche planifiée. (1)
SUPPRIMÉ tâche: [YourFile Update] [C:\Program Files\YourFileDownloader\YourFileUpdater.exe (Not File) ] (PUP.YourFileDownloader)
---\\ Explorateur ( Dossiers, Fichiers ). (0)
~ Aucun élément malicieux trouvé.
---\\ Base de Registres ( Clés, Valeurs, Données ). (1)
SUPPRIMÉ clé*: HKCU\Software\AppDataLow\Software\Smartbar [] (PUP.QuickShare)
---\\ Bilan de la réparation
~ Réparation réalisée avec succès.
~ Ce navigateur est absent (Opera Software)
---\\ Statistiques
~ Items scannés : 1143
~ Items trouvés : 0
~ Items annulés : 0
~ Items réparés : 2
End of clean at 20:06:13
===================
ZHPCleaner-[R]-09052015-20_06_13.txt
ZHPCleaner-[S]-08052015-20_44_35.txt
ZHPCleaner-[S]-09052015-10_19_21.txt
Voici le rapport.
~ ZHPCleaner v2015.5.8.220 by Nicolas Coolman (09/05/2015)
~ Run by Amaury (Administrator) (09/05/2015 20:05:52)
~ Forum : http://forum.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Netttoyer
~ Report : C:\Users\Amaury\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Amaury\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Deactivate
~ Boot Mode : Normal (Normal boot)
~ Windows 7, 32-bit Service Pack 1 (Build 7601)
---\\ Service. (0)
~ Aucun élément malicieux trouvé.
---\\ Navigateur internet. (0)
~ Aucun élément malicieux trouvé.
---\\ Fichier hôte. (1)
~ Le fichier hôte est légitime. (21)
---\\ Tâche planifiée. (1)
SUPPRIMÉ tâche: [YourFile Update] [C:\Program Files\YourFileDownloader\YourFileUpdater.exe (Not File) ] (PUP.YourFileDownloader)
---\\ Explorateur ( Dossiers, Fichiers ). (0)
~ Aucun élément malicieux trouvé.
---\\ Base de Registres ( Clés, Valeurs, Données ). (1)
SUPPRIMÉ clé*: HKCU\Software\AppDataLow\Software\Smartbar [] (PUP.QuickShare)
---\\ Bilan de la réparation
~ Réparation réalisée avec succès.
~ Ce navigateur est absent (Opera Software)
---\\ Statistiques
~ Items scannés : 1143
~ Items trouvés : 0
~ Items annulés : 0
~ Items réparés : 2
End of clean at 20:06:13
===================
ZHPCleaner-[R]-09052015-20_06_13.txt
ZHPCleaner-[S]-08052015-20_44_35.txt
ZHPCleaner-[S]-09052015-10_19_21.txt
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
rapport :
~ Rapport de ZHPDiag v2015.5.8.47 - Nicolas Coolman (05/05/2015)
~ Lancé par Amaury (11/05/2015 08:07:03)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Nouvelle version disponible
~ Liste blanche : Désactivée par l'utilisateur
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user
---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17728
MFIE: Mozilla Firefox 37.0.2 (Defaut)
---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows Operating System - Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : RMV82
Windows License : OK
~ Windows Remaining Initializations Number : 4
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 7 Home Premium, 32-bit Service Pack 1 (Build 7601)
---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 2.1.6.1022
Microsoft Security Client v4.7.0205.0
Windows Defender W7 (Deactivate)
---\\ Logiciels d'optimisation du système
CCleaner v5.05
---\\ Logiciels de partage PeerToPeer
---\\ Surveillance de Logiciels
Adobe Flash Player 17 NPAPI
Adobe Reader X
---\\ Informations sur le système
~ Processor: x86 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2998 MB (57% free)
System Restore: Activé (Enable)
System drive C: has 173 GB (60%) free of 287 GB
---\\ Mode de connexion au système
~ Computer Name: AMAURY-PC
~ User Name: Amaury
~ All Users Names: HomeGroupUser$, Amaury, Administrateur,
~ Unselected Option: None
Logged in as Administrator
---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Amaury\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Amaury\AppData\Roaming\
~ %Desktop% : C:\Users\Amaury\Desktop\
~ %Favorites% : C:\Users\Amaury\Favorites\
~ %LocalAppData% : C:\Users\Amaury\AppData\Local\
~ %StartMenu% : C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 173 Go of 287 Go)
D: CD-ROM drive (Not Inserted)
---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: 43 Scanned in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.C46904F2E9E121A91DDDABB48D7648C3] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.13/03/2015 - 03:20:28.) -- C:\Windows\System32\wininet.dll [1888256]
[MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.17/07/2014 - 02:39:27.) -- C:\Windows\System32\Winlogon.exe [304128]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 13:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:36:07.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 09:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 09:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 10:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 09:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:18:22.) -- C:\Windows\system32\Drivers\ntfs.sys [1212352]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:32:14.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 13:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Generic Processes: Scanned in 00mn 00s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/3
~ Mes musiques (My Musics) : 1/185
~ Mes Favoris (My Favorites) : 1/30
~ Mes Documents (My Documents) : 2/1045
~ Mon Bureau (My Desktop) : 15/82417
~ Menu demarrer (Programs) : 1/30
~ Hidden Files: Scanned in 00mn 32s
---\\ Processus lancés
[MD5.7E212E742BF06BF678AE35E9C1B74B8F] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe [6212920] [PID.4044]
[MD5.567B0B979E206C3E1E7B4422A2D0A5AD] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1602856] [PID.3668]
[MD5.A9D62C7793510D81342AC1AC50FB70F5] - (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe [495708] [PID.3756]
[MD5.C7AF01132A0DD241A1A0DBE9B62A9A1C] - (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\quickset.exe [3873648] [PID.3584]
[MD5.D50F04F005C94FA3802A6E05CFCF4A9A] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.3276]
[MD5.B7680F36C41AE21C0ECA96523443831F] - (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe [727664] [PID.3400]
[MD5.22001D1308E34153D2BCD51368E14F7B] - (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5249024] [PID.3708]
[MD5.2059A96CB2254829488A6A676AA4BA15] - (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\DpAgent.exe [842816] [PID.3460]
[MD5.0FE0EDF01CEA3BEB2E65A904BB87525E] - (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe [640376] [PID.3892]
[MD5.9A8568C7642B79F43DCEB0BDF9F49050] - (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe [542136] [PID.3768]
[MD5.CCA0C5482B8A6A275D9D49433F435DFA] - (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe [542096] [PID.3872]
[MD5.46B9C74861D98EDA9E6E56D19BEAF91A] - (.Broadcom Corporation. - Bluetooth Tray Application.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [795936] [PID.2220]
[MD5.2727208EA26F6B6DA898AB6890417214] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8208384] [PID.5276]
~ Processes Running: Scanned in 00mn 00s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Amaury\AppData\Local\Google\Chrome\User Data\Default\Preferences
---\\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 0 Scanned in 00mn 00s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFF12.DLL
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo-france.xml
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll =>.Google Inc
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=11.31.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Windows\system32\npdeployJava1.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Oracle Corporation - Next Generation Java Plug-in 11.31.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=11.31.2] - (.Oracle Corporation - Next Generation Java Plug-in 11.31.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) -- C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
~ Firefox Browser: 31 Scanned in 00mn 01s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) (No version) -- (.not file.)
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
~ IE Browser: 11 Scanned in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: DigitalPersona Fingerprint Software Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} . (.DigitalPersona, Inc. - DigitalPersona OTS Feedback.) -- C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} . (.Microsoft Corporation - Windows Live Messenger Companion Core.) -- C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
~ BHO: 14 Scanned in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Adobe PDF - [HKLM]{47833539-D0C5-4125-9FA8-0819E2EAAC93} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{47833539-D0C5-4125-9FA8-0819E2EAAC93} Clé orpheline
~ Toolbar: Scanned in 00mn 00s
---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [QuickSet] . (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [FreeFallProtection] . (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] . (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [DpAgent] . (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] . (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKCU\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
~ Application: Scanned in 00mn 00s
---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ IE Control Panel: 1 Scanned in 00mn 00s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} . (.Microsoft Corporation - Windows Live Messenger Companion core resources.) -- C:\Program Files\Windows Live\Companion\companionres.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- c:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000009\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000010\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll
~ Winsock: 10 Scanned in 00mn 00s
---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] *.dell.com
~ IE Zone Confiance: Scanned in 00mn 00s
---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} ((no name)) - http://support.euro.dell.com/systemprofiler/DellSystemLite.CAB
~ Objets ActiveX: Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s
---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ SSODL: 1 Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) . (.Andrea Electronics Corporation - Andrea filters APO access service (32-bit).) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) . (.Broadcom Corporation. - Bluetooth Support Server.) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dell Data Vault (DellDataVault) . (.Dell Inc. - Dell Data Vault Service.) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
O23 - Service: Dell Data Vault Wizard (DellDataVaultWiz) . (.Dell Inc. - Dell Data Vault Wizard.) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
O23 - Service: C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DpHost) . (.DigitalPersona, Inc. - DigitalPersona Local Host.) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) . (.Sonic Solutions - RoxWatch12 Module.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Audio Service (STacSV) . (.IDT, Inc. - IDT PC Audio.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
O23 - Service: Dell SupportAssist Agent (SupportAssistAgent) . (.Dell Inc. - Service.) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
O23 - Service: Intel(R) Management & Security Application User Notificatio (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) . (.Validity Sensors, Inc. - VFS101 VCS API Library.) - C:\Windows\system32\vcsFPService.exe
O23 - Service: DW WLAN Tray Service (wltrysvc) . (.Dell Inc. - DW WLAN Card Wireless Network Service.) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
~ Services: 19 Scanned in 00mn 06s
---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Desktop Component: 4 Scanned in 00mn 00s
---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
[MD5.3E04F1E482357B1FC8B088197C3D9FF8] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152]
[MD5.B04A4810C6CC205F9DC72DC22E4AB236] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [268464]
[MD5.1F014EA12ECB13C909DA9395E9CD3D18] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6278424]
[MD5.2BCB174FF294F83C3520D46B57DBD917] [APT] [Dell SupportAssistAgent AutoUpdate] (.Dell Inc..) -- C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [27472]
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107912]
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107912]
[MD5.79B5DD0E04130BF31AA598F2AEBB1B78] [APT] [PCDEventLauncherTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell\SupportAssist\sessionchecker.exe [433488]
[MD5.254EC04C72D02E4C8EEC08D4CF3658B1] [APT] [PCDoctorBackgroundMonitorTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell\SupportAssist\uaclauncher.exe [1189200]
[MD5.A75AE3B84B6423CE6A088E80A2BC23C2] [APT] [{4773655F-F316-4A0B-AAD8-B898B8AF2A0A}] (.Skype Technologies S.A..) -- C:\Program Files\Skype\Phone\Skype.exe [31280256]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{7A7B4145-1139-4669-8765-5936ED3BBC3A}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{A28E5010-28AC-4FF0-9EDF-0210636C319A}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [561984]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1054]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1054]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1058]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1058]
~ Scheduled Task: 16 Scanned in 00mn 05s
---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft VM - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Microsoft Corporation - Microsoft® VM.) -- C:\Windows\system32\msjava.dll
O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Disable SSL3 - {7D715857-A67C-4C2F-A929-038448584D63} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
~ Active Setup: 11 Scanned in 00mn 00s
---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys
O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys
O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
~ Drivers: 60 Scanned in 00mn 00s
---\\ Logiciels installés (O42)
O42 - Logiciel: 7-Zip 9.20 - (...) [HKLM] -- 7-Zip
O42 - Logiciel: 7Zip Bundle by Fileparade.com - (.SweetPacks LTD.) [HKLM] -- 7Zip Bundle by Fileparade.com =>PUP.SweetIM
O42 - Logiciel: AccelerometerP11 - (.STMicroelectronics.) [HKLM] -- {87434D51-51DB-4109-B68F-A829ECDCF380}
O42 - Logiciel: Adobe After Effects CS4 Third Party Content - (.Adobe Systems Incorporated.) [HKLM] -- {67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}
O42 - Logiciel: Adobe Anchor Service CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {1618734A-3957-4ADD-8199-F973763109A8}
O42 - Logiciel: Adobe Bridge CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {83877DB1-8B77-45BC-AB43-2BAC22E093E0} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe CMaps CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {94D398EB-D2FD-4FD1-B8C4-592635E8A191}
O42 - Logiciel: Adobe CSI CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0F723FC1-7606-4867-866C-CE80AD292DAF}
O42 - Logiciel: Adobe Color EU Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}
O42 - Logiciel: Adobe Color JA Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0D6013AB-A0C7-41DC-973C-E93129C9A29F}
O42 - Logiciel: Adobe Color NA Recommended Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {00ADFB20-AE75-46F4-AD2C-F48B15AC3100}
O42 - Logiciel: Adobe Color Video Profiles CS CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {63C24A08-70F3-4C8E-B9FB-9F21A903801D}
O42 - Logiciel: Adobe Creative Suite 4 Master Collection - (.Adobe Systems Incorporated.) [HKLM] -- Adobe_b2b1c7c62c4ae0a954789ed71d36a7a
O42 - Logiciel: Adobe Creative Suite 4 Master Collection - (.Adobe Systems Incorporated.) [HKLM] -- {D0EE7809-8F5E-46EF-95DC-B30DCE22653F}
O42 - Logiciel: Adobe Default Language CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {C52E3EC1-048C-45E1-8D53-10B0C6509683}
O42 - Logiciel: Adobe Encore CS4 Codecs - (.Adobe Systems Incorporated.) [HKLM] -- {FB2A5FCC-B81B-48C2-A009-7804694D83E9}
O42 - Logiciel: Adobe ExtendScript Toolkit CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F8EF2B3F-C345-4F20-8FE4-791A20333CD5} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Extension Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {054EFA56-2AC1-48F4-A883-0AB89874B972}
O42 - Logiciel: Adobe Flash Player 17 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 17 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI
O42 - Logiciel: Adobe Fonts All - (.Adobe Systems Incorporated.) [HKLM] -- {FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
O42 - Logiciel: Adobe Illustrator CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05C677A1-A161-447E-92ED-2D5B38AA0740} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {A2160D84-F2D0-47A3-AA59-CCB3CA21D558} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Application Feature Set Files (Roman) - (.Adobe Systems Incorporated.) [HKLM] -- {C950299F-BCAB-4695-B077-FC3B2748C25D} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Common Base Files - (.Adobe Systems Incorporated.) [HKLM] -- {26F72DC3-DDBE-424F-B9F0-94E5D0E5A12B} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Icon Handler - (.Adobe Systems Incorporated.) [HKLM] -- {2BA4F7B0-F38E-4AE8-80A2-E9C5956C6D6D} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Linguistics CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {931AB7EA-3656-4BB7-864D-022B09E3DD67}
O42 - Logiciel: Adobe Media Encoder CS4 Exporter - (.Adobe Systems Incorporated.) [HKLM] -- {561968FD-56A1-49FD-9ED0-F55482C7C5BC}
O42 - Logiciel: Adobe Media Encoder CS4 Importer - (.Adobe Systems Incorporated.) [HKLM] -- {8186FF34-D389-4B7E-9A2F-C197585BCFBD}
O42 - Logiciel: Adobe Output Module - (.Adobe Systems Incorporated.) [HKLM] -- {BB4E33EC-8181-4685-96F7-8554293DEC6A}
O42 - Logiciel: Adobe PDF Library Files CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F93C84A6-0DC6-42AF-89FA-776F7C377353}
O42 - Logiciel: Adobe Photoshop CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {E2E01E91-2314-42BC-B5E3-1715DAE84F98} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Photoshop CS4 Support - (.Adobe Systems Incorporated.) [HKLM] -- {73E17122-EC84-45B4-943B-735257B5CBDC} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Premiere Pro CS4 Third Party Content - (.Adobe Systems Incorporated.) [HKLM] -- {E1951CF4-91CE-46F0-A1BD-3A4A67069097}
O42 - Logiciel: Adobe Reader X (10.1.13) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AA1000000001}
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-0804-1033-1959-001802114130}
O42 - Logiciel: Adobe SGM CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}
O42 - Logiciel: Adobe SING CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {8CB16C77-9D75-4966-91E8-D785B87EC078}
O42 - Logiciel: Adobe Search for Help - (.Adobe Systems Incorporated.) [HKLM] -- {F0E64E2E-3A60-40D8-A55D-92F6831875DA}
O42 - Logiciel: Adobe Service Manager Extension - (.Adobe Systems Incorporated.) [HKLM] -- {4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
O42 - Logiciel: Adobe Setup - (.Adobe Systems Incorporated.) [HKLM] -- {6577657B-A10C-47A1-A50D-512C7748CB2C}
O42 - Logiciel: Adobe Soundbooth CS4 Codecs - (.Adobe Systems Incorporated.) [HKLM] -- {52232EF4-CC12-4C21-ABCF-ADB79618302D}
O42 - Logiciel: Adobe Type Support CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
O42 - Logiciel: Adobe Update Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05308C4E-7285-4066-BAE3-6B50DA6ED755}
O42 - Logiciel: Adobe WinSoft Linguistics Plugin - (.Adobe Systems Incorporated.) [HKLM] -- {3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
O42 - Logiciel: Adobe XMP Panels CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
O42 - Logiciel: AdobeColorCommonSetCMYK - (.Adobe Systems Incorporated.) [HKLM] -- {E5FCED12-3E77-4C0E-A305-5AEB38A52A70}
O42 - Logiciel: AdobeColorCommonSetRGB - (.Adobe Systems Incorporated.) [HKLM] -- {16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
O42 - Logiciel: Advanced Audio FX Engine - (.Creative Technology Ltd.) [HKLM] -- Advanced Audio FX Engine
O42 - Logiciel: Antidote RX v7 - (.Druide informatique inc..) [HKLM] -- {A474EA56-5DBD-4181-8230-806A4762EA7F}
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {5D09C772-ECB3-442B-9CC6-B4341C78FDC2}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {E14ADE0E-75F3-4A46-87E5-26692DD626EC}
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} =>.Apple Inc
O42 - Logiciel: ArcGIS 10.1 for Desktop - (.Environmental Systems Research Institute, Inc..) [HKLM] -- ArcGIS 10.1 for Desktop
O42 - Logiciel: ArcGIS 10.1 for Desktop - Module linguistique français - (.Environmental Systems Research Institute, Inc..) [HKLM] -- ArcGIS 10.1 for Desktop - Module linguistique français
O42 - Logiciel: ArcGIS 10.1 for Desktop - Module linguistique français - (.Environmental Systems Research Institute, Inc..) [HKLM] -- {311DA2E4-3B6A-464F-8987-C4AAE6B9386D}
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {79155F2B-9895-49D7-8612-D92580E0DE5B}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: CDBurnerXP - (.CDBurnerXP.) [HKLM] -- {7E265513-8CDA-4631-B696-F40D983F3B07}_is1
O42 - Logiciel: Canon MG5200 series MP Drivers - (...) [HKLM] -- {1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series
O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM] -- {64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {51C7AD07-C3F6-4635-8E8A-231306D810FE}
O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
O42 - Logiciel: Complément Messenger - (.Microsoft Corporation.) [HKLM] -- {6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}
O42 - Logiciel: Connect - (.Adobe Systems Incorporated.) [HKLM] -- {B29AD377-CC12-490A-A480-1452337C618D}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM] -- InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM] -- {A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
O42 - Logiciel: DW WLAN Card Utility - (.Dell Inc..) [HKLM] -- DW WLAN Card Utility
O42 - Logiciel: Dell Backup and Recovery Manager - (.Dell Inc..) [HKLM] -- {4688EB75-28E2-4731-9BCB-55E624F7CD45}
O42 - Logiciel: Dell Data Vault - (.Dell Inc..) [HKLM] -- {2E55EEFD-2162-4A7D-9158-EDB0305603A6}
O42 - Logiciel: Dell Edoc Viewer - (.Dell Inc.) [HKLM] -- {3138EAD3-700B-4A10-B617-B3F8096EE30D}
O42 - Logiciel: Dell SupportAssist - (.Dell.) [HKLM] -- PC-Doctor for Windows
O42 - Logiciel: Dell SupportAssistAgent - (.Dell.) [HKLM] -- {287348C8-8B47-4C36-AF28-441A3B7D8722}
O42 - Logiciel: Dell Touchpad - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey
O42 - Logiciel: Dell Webcam Central - (.Creative Technology Ltd.) [HKLM] -- Dell Webcam Central
O42 - Logiciel: DigitalPersona Personal 4.01 - (.DigitalPersona, Inc..) [HKLM] -- {3D8AE086-030F-4EF4-B705-63F8130B043E}
O42 - Logiciel: DirectX 9 Runtime - (.Sonic Solutions.) [HKLM] -- {AF9E97C1-7431-426D-A8D5-ABE40995C0B1}
O42 - Logiciel: EndNote X3 - (.Thomson Reuters.) [HKLM] -- {86B3F2D6-AC2B-4E88-8AE1-F2F77F781B0C}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}
O42 - Logiciel: IRIScan(TM) Direct - (.IRIScanDirect.) [HKLM] -- IRIScanDirect_is1
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
O42 - Logiciel: Java 8 Update 31 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83218031F0}
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
O42 - Logiciel: Logiciel d'archivage WinRAR - (...) [HKLM] -- WinRAR archiver
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: Malwarebytes Anti-Malware version 2.1.6.1022 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1
O42 - Logiciel: Mesh Runtime - (.Microsoft Corporation.) [HKLM] -- {8C6D6116-B724-4810-8F2D-D047E6B7D68E}
O42 - Logiciel: Microsoft Image Composite Editor - (.Microsoft Corporation.) [HKLM] -- {3D599ADA-65D9-4B51-898F-CE718DEC5DBB}
O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {D6F9CBDC-58B6-430A-8DD4-8F61CBC1ADF4}
O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Mozilla Firefox 37.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 37.0.2 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: PDF Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
O42 - Logiciel: PhotoShowExpress - (.Sonic Solutions.) [HKLM] -- {3250260C-7A95-4632-893B-89657EB5545B}
O42 - Logiciel: Photoshop Camera Raw - (.Adobe Systems Incorporated.) [HKLM] -- {CC75AB5C-2110-4A7F-AF52-708680D22FE8}
O42 - Logiciel: QuickSet32 - (.Dell Inc..) [HKLM] -- {C4972073-2BFE-475D-8441-564EA97DA161}
O42 - Logiciel: ResearchSoft Direct Export Helper - (...) [HKLM] -- ResearchSoft Direct Export Helper
O42 - Logiciel: Roxio Activation Module - (.Roxio.) [HKLM] -- {A121EEDE-C68F-461D-91AA-D48BA226AF1C}
O42 - Logiciel: Roxio BackOnTrack - (.Roxio.) [HKLM] -- {5A06423A-210C-49FB-950E-CB0EB8C5CEC7}
O42 - Logiciel: Roxio Burn - (.Roxio.) [HKLM] -- {9569E6BC-326A-432F-97AB-35263A327BF1}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {EF56258E-0326-48C5-A86C-3BAC26FC15DF}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}
O42 - Logiciel: Roxio Express Labeler 3 - (.Roxio.) [HKLM] -- {6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
O42 - Logiciel: Roxio File Backup - (.Roxio.) [HKLM] -- {60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}
O42 - Logiciel: Samsung Printer Live Update - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung Printer Live Update
O42 - Logiciel: Satsuki Decoder Pack - (.Satsuki Yatoshi'S Softs.) [HKLM] -- Satsuki Decoder Pack
O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701}
O42 - Logiciel: Skype(TM) 7.4 - (.Skype Technologies S.A..) [HKLM] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
O42 - Logiciel: Sonic CinePlayer Decoder Pack - (.Sonic Solutions.) [HKLM] -- {9A00EC4E-27E1-42C4-98DD-662F32AC8870}
O42 - Logiciel: Spotify - (...) [HKLM] -- Spotify
O42 - Logiciel: Spotify - (.Spotify AB.) [HKCU] -- Spotify
O42 - Logiciel: Suite Shared Configuration CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {842B4B72-9E8F-4962-B3C1-1C422A5C4434}
O42 - Logiciel: TuxGuitar 1.2 - (...) [HKLM] -- TuxGuitar_0
O42 - Logiciel: Validity Sensors DDK - (.Validity Sensors, Inc..) [HKLM] -- {9FCB6355-689E-4141-9714-3EEC2AE10292}
O42 - Logiciel: WIDCOMM Bluetooth Software - (.Broadcom Corporation.) [HKLM] -- {9E9D49A4-1DF4-4138-B7DB-5D87A893088E}
O42 - Logiciel: XnView 2.22 - (.Gougelet Pierre-e.) [HKLM] -- XnView_is1
O42 - Logiciel: Xvid 1.2.1 final uninstall - (.Xvid team (Koepi).) [HKLM] -- Xvid_is1
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {11E568E0-3244-4BCB-875E-F334269DFDCB}
O42 - Logiciel: kuler - (.Adobe Systems Incorporated.) [HKLM] -- {098727E1-775A-4450-B573-3F441F1CA243}
~ Logic: 44 Scanned in 00mn 00s
---\\ HKCU & HKLM Software Keys
[HKCU\Software\7-Zip]
[HKCU\Software\AC3Filter]
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow\Software\DigitalPersona]
[HKCU\Software\AppDataLow\Software\JavaSoft]
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Arobas Music]
[HKCU\Software\Broadcom]
[HKCU\Software\CG Information]
[HKCU\Software\Canneverbe Limited]
[HKCU\Software\Canon]
[HKCU\Software\Citrix]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\Creative Tech]
[HKCU\Software\CyberLink]
[HKCU\Software\DT Soft]
[HKCU\Software\Developer Express]
[HKCU\Software\DigitalPersona]
[HKCU\Software\Druide informatique inc.]
[HKCU\Software\ERDAS]
[HKCU\Software\ESRI]
[HKCU\Software\EasyBits]
[HKCU\Software\Eset]
[HKCU\Software\GNU]
[HKCU\Software\Gabest]
[HKCU\Software\Google]
[HKCU\Software\HKEY_LOCAL_MACHINE]
[HKCU\Software\Haali]
[HKCU\Software\Herac]
[HKCU\Software\IDAVLab]
[HKCU\Software\IDT]
[HKCU\Software\IM Providers]
[HKCU\Software\ISI ResearchSoft]
[HKCU\Software\Intel]
[HKCU\Software\JavaSoft]
[HKCU\Software\Lake]
[HKCU\Software\LogiShrd]
[HKCU\Software\MCAFEE]
[HKCU\Software\Macromedia]
[HKCU\Software\Macrovision]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Nero]
[HKCU\Software\Netscape]
[HKCU\Software\Northcode Inc]
[HKCU\Software\ODBC]
[HKCU\Software\PC-Doctor]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\RICOH]
[HKCU\Software\RealNetworks]
[HKCU\Software\RegisteredApplications]
[HKCU\Software\Roxio]
[HKCU\Software\SSPrint]
[HKCU\Software\STUDIO SARMADI]
[HKCU\Software\Samsung]
[HKCU\Software\Satsuki Decoder Pack]
[HKCU\Software\SecuROM]
[HKCU\Software\Skype]
[HKCU\Software\Synaptics]
[HKCU\Software\Trolltech]
[HKCU\Software\Widcomm]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\ZebHelpProcess Helper]
[HKLM\Software\ATI Technologies]
[HKLM\Software\Adobe]
[HKLM\Software\AdwCleaner]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\BcmSetup]
[HKLM\Software\Broadcom]
[HKLM\Software\Canneverbe Limited]
[HKLM\Software\Canon]
[HKLM\Software\Citrix]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Creative Tech]
[HKLM\Software\CyberLink]
[HKLM\Software\DT Soft]
[HKLM\Software\Debug]
[HKLM\Software\Dell Computer Corporation]
[HKLM\Software\Dell Inc.]
[HKLM\Software\Dell]
[HKLM\Software\DigitalPersona]
[HKLM\Software\Druide informatique inc.]
[HKLM\Software\ERDAS]
[HKLM\Software\ESRI]
[HKLM\Software\FreeFallProtection]
[HKLM\Software\GEAR Software]
[HKLM\Software\GNU]
[HKLM\Software\Gabest]
[HKLM\Software\Google]
[HKLM\Software\HaaliMkx]
[HKLM\Software\IDAVLab]
[HKLM\Software\IDT]
[HKLM\Software\IM Providers]
[HKLM\Software\ISI ResearchSoft]
[HKLM\Software\Imagineer Systems Ltd]
[HKLM\Software\InstalledOptions]
[HKLM\Software\Intel]
[HKLM\Software\InterVideo]
[HKLM\Software\JavaSoft]
[HKLM\Software\JreMetrics]
[HKLM\Software\Lake]
[HKLM\Software\Logishrd]
[HKLM\Software\MAXSOFT-OCRON]
[HKLM\Software\Macromedia]
[HKLM\Software\Macrovision]
[HKLM\Software\Malwarebytes' Anti-Malware (Trial)]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\ManageableUpdatePackage]
[HKLM\Software\McAfee.com]
[HKLM\Software\McAfeeInstaller]
[HKLM\Software\McAfee]
[HKLM\Software\MicroVision]
[HKLM\Software\MimarSinan]
[HKLM\Software\Mircrosoft]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Nero]
[HKLM\Software\Novell]
[HKLM\Software\ODBC]
[HKLM\Software\PC-Doctor]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\Python]
[HKLM\Software\RealNetworks]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Roxio]
[HKLM\Software\SSPrint]
[HKLM\Software\STMicroelectronics]
[HKLM\Software\Samsung]
[HKLM\Software\Skype]
[HKLM\Software\Sonic]
[HKLM\Software\Synaptics]
[HKLM\Software\Synthetic Aperture]
[HKLM\Software\Validity]
[HKLM\Software\Vantage Software Technologies]
[HKLM\Software\Volatile]
[HKLM\Software\Widcomm]
[HKLM\Software\WinRAR]
[HKLM\Software\Windows]
[HKLM\Software\Wise Solutions]
[HKLM\Software\XnView]
[HKLM\Software\illiminable]
[HKLM\Software\mozilla.org]
~ Key Software: 326 Scanned in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 23/09/2013 - 18:48:51 - [] ----D C:\Program Files\7-Zip
O43 - CFD: 14/10/2012 - 17:01:19 - [] ----D C:\Program Files\Adobe
O43 - CFD: 27/10/2012 - 13:10:03 - [] ----D C:\Program Files\Apple Software Update =>.Apple Inc
O43 - CFD: 23/09/2013 - 14:43:50 - [] ----D C:\Program Files\ArcGIS
O43 - CFD: 27/10/2012 - 13:09:43 - [] ----D C:\Program Files\Bonjour
O43 - CFD: 08/05/2015 - 11:47:02 - [] ----D C:\Program Files\CCleaner
O43 - CFD: 04/12/2011 - 23:56:37 - [] ----D C:\Program Files\CDBurnerXP
O43 - CFD: 07/01/2011 - 14:48:11 - [] ----D C:\Program Files\Cisco
O43 - CFD: 09/04/2013 - 08:24:59 - [] ----D C:\Program Files\Citrix
O43 - CFD: 10/05/2015 - 10:49:29 - [] ----D C:\Program Files\Common Files
O43 - CFD: 07/01/2011 - 14:52:12 - [] ----D C:\Program Files\Creative
O43 - CFD: 07/01/2011 - 14:51:48 - [] ----D C:\Program Files\Creative Live! Cam
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\CyberLink
O43 - CFD: 13/02/2015 - 17:07:18 - [] ----D C:\Program Files\Dell
O43 - CFD: 07/01/2011 - 14:41:47 - [] ----D C:\Program Files\Dell Inc
O43 - CFD: 01/04/2015 - 15:56:44 - [] ----D C:\Program Files\Dell Support Center
O43 - CFD: 07/01/2011 - 14:51:52 - [] ----D C:\Program Files\Dell Webcam
O43 - CFD: 07/01/2011 - 14:49:33 - [] ----D C:\Program Files\DigitalPersona
O43 - CFD: 05/10/2011 - 21:15:44 - [] ----D C:\Program Files\Druide
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\DVD Maker
O43 - CFD: 30/05/2013 - 16:35:59 - [] ----D C:\Program Files\EndNote X3
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\Program Files\Fichiers communs
O43 - CFD: 09/08/2013 - 08:30:00 - [] ----D C:\Program Files\Google
O43 - CFD: 18/09/2012 - 08:30:24 - [] ----D C:\Program Files\GUMBB52.tmp
O43 - CFD: 07/01/2011 - 07:38:05 - [] ----D C:\Program Files\IDT
O43 - CFD: 07/01/2011 - 14:51:50 - [] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 07/01/2011 - 14:43:38 - [] ----D C:\Program Files\Intel
O43 - CFD: 16/04/2015 - 07:41:45 - [] ----D C:\Program Files\Internet Explorer
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\iPod
O43 - CFD: 30/05/2014 - 17:24:54 - [] ----D C:\Program Files\IRIScan Direct
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\Program Files\iTunes
O43 - CFD: 01/02/2015 - 19:24:51 - [] ----D C:\Program Files\Java
O43 - CFD: 08/05/2015 - 12:02:05 - [] ----D C:\Program Files\Malwarebytes Anti-Malware
O43 - CFD: 19/08/2014 - 07:39:24 - [] ----D C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 15/01/2011 - 17:51:35 - [0] ----D C:\Program Files\Microsoft
O43 - CFD: 14/07/2009 - 11:00:58 - [] ----D C:\Program Files\Microsoft Games
O43 - CFD: 27/08/2012 - 21:15:59 - [] ----D C:\Program Files\Microsoft Office
O43 - CFD: 10/02/2012 - 09:38:04 - [] ----D C:\Program Files\Microsoft Research
O43 - CFD: 11/02/2015 - 20:53:43 - [] ----D C:\Program Files\Microsoft Security Client
O43 - CFD: 24/07/2014 - 17:05:44 - [] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 07/01/2011 - 15:02:44 - [] ----D C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 13/03/2011 - 22:40:16 - [] ----D C:\Program Files\Microsoft Visual Studio
O43 - CFD: 13/03/2011 - 22:37:09 - [] ----D C:\Program Files\Microsoft Visual Studio 8
O43 - CFD: 23/08/2012 - 08:17:10 - [] ----D C:\Program Files\Microsoft Works
O43 - CFD: 13/03/2011 - 22:40:04 - [] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 24/04/2015 - 12:09:10 - [] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 26/04/2015 - 08:23:34 - [] ----D C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 13/03/2011 - 22:40:20 - [] ----D C:\Program Files\MSBuild
O43 - CFD: 15/01/2011 - 23:49:59 - [0] ----D C:\Program Files\MSXML 4.0
O43 - CFD: 14/07/2009 - 06:52:30 - [] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 07/01/2011 - 14:58:04 - [] ----D C:\Program Files\Roxio
O43 - CFD: 03/03/2014 - 12:14:18 - [] ----D C:\Program Files\SamsungPrinterLiveUpdate
O43 - CFD: 03/03/2014 - 12:04:04 - [] ----D C:\Program Files\SamsungPrinterLiveUpdateInstaller
O43 - CFD: 05/02/2011 - 11:29:22 - [] ----D C:\Program Files\Satsuki Decoder Pack
O43 - CFD: 14/04/2015 - 08:03:39 - [] R---D C:\Program Files\Skype
O43 - CFD: 24/03/2015 - 20:36:20 - [] ----D C:\Program Files\Spotify
O43 - CFD: 07/01/2011 - 14:44:04 - [] ----D C:\Program Files\STMicroelectronics
O43 - CFD: 07/01/2011 - 16:33:50 - [] ----D C:\Program Files\Synaptics
O43 - CFD: 10/12/2011 - 19:15:54 - [] ----D C:\Program Files\Trend Micro
O43 - CFD: 25/03/2011 - 22:12:50 - [] ----D C:\Program Files\TuxGuitar-Jet
O43 - CFD: 14/07/2009 - 06:53:23 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 07/01/2011 - 14:45:49 - [] ----D C:\Program Files\Validity Sensors
O43 - CFD: 07/01/2011 - 14:46:46 - [] ----D C:\Program Files\WIDCOMM
O43 - CFD: 12/07/2013 - 07:57:37 - [] ----D C:\Program Files\Windows Defender
O43 - CFD: 12/07/2014 - 07:43:28 - [] ----D C:\Program Files\Windows Journal
O43 - CFD: 07/01/2011 - 15:03:04 - [] ----D C:\Program Files\Windows Live
O43 - CFD: 04/01/2012 - 19:59:00 - [] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 12/03/2015 - 04:25:28 - [] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 12/01/2011 - 13:59:10 - [] ----D C:\Program Files\Windows NT
O43 - CFD: 04/01/2012 - 19:58:58 - [] ----D C:\Program Files\Windows Photo Viewer
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Portable Devices
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Sidebar
O43 - CFD: 05/02/2011 - 12:44:37 - [] ----D C:\Program Files\WinRAR
O43 - CFD: 15/04/2014 - 08:21:40 - [] ----D C:\Program Files\XnView
O43 - CFD: 15/01/2011 - 22:02:09 - [] ----D C:\Program Files\Xvid
O43 - CFD: 08/05/2015 - 19:09:29 - [] ----D C:\Program Files\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 14/10/2012 - 17:01:28 - [] ----D C:\Program Files\Common Files\Adobe
O43 - CFD: 23/09/2013 - 14:47:09 - [] ----D C:\Program Files\Common Files\AnswerWorks 4.0
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\Common Files\Apple
O43 - CFD: 23/09/2013 - 14:46:20 - [] ----D C:\Program Files\Common Files\ArcGIS
O43 - CFD: 10/12/2011 - 19:52:01 - [] ----D C:\Program Files\Common Files\Bitdefender
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\Common Files\CyberLink
O43 - CFD: 23/09/2013 - 14:44:22 - [] ----D C:\Program Files\Common Files\Data Dynamics
O43 - CFD: 15/05/2014 - 11:50:28 - [] ----D C:\Program Files\Common Files\DESIGNER
O43 - CFD: 07/01/2011 - 14:51:35 - [] ----D C:\Program Files\Common Files\InstallShield
O43 - CFD: 01/02/2015 - 19:25:56 - [] ----D C:\Program Files\Common Files\Java
O43 - CFD: 28/02/2011 - 22:14:03 - [] ----D C:\Program Files\Common Files\Macrovision Shared
O43 - CFD: 05/02/2011 - 11:49:23 - [] ----D C:\Program Files\Common Files\mcafee
O43 - CFD: 23/08/2012 - 08:17:16 - [] ----D C:\Program Files\Common Files\microsoft shared
O43 - CFD: 07/01/2011 - 14:43:41 - [] ----D C:\Program Files\Common Files\postureAgent
O43 - CFD: 07/01/2011 - 14:58:20 - [] ----D C:\Program Files\Common Files\PX Storage Engine
O43 - CFD: 30/05/2013 - 16:36:04 - [] ----D C:\Program Files\Common Files\ResearchSoft
O43 - CFD: 23/12/2012 - 15:28:39 - [] ----D C:\Program Files\Common Files\Risxtd
O43 - CFD: 07/01/2011 - 14:58:36 - [] ----D C:\Program Files\Common Files\Roxio Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\Services
O43 - CFD: 08/10/2014 - 07:41:48 - [] ----D C:\Program Files\Common Files\Skype
O43 - CFD: 07/01/2011 - 14:58:00 - [] ----D C:\Program Files\Common Files\Sonic Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 07/01/2011 - 14:57:58 - [] ----D C:\Program Files\Common Files\SureThing Shared
O43 - CFD: 17/01/2012 - 16:46:20 - [0] ----D C:\Program Files\Common Files\SWF Studio
O43 - CFD: 04/01/2012 - 19:58:57 - [] ----D C:\Program Files\Common Files\System
O43 - CFD: 23/09/2013 - 14:44:09 - [] ----D C:\Program Files\Common Files\Tom Sawyer Software
O43 - CFD: 07/01/2011 - 14:58:54 - [] ----D C:\Program Files\Common Files\Windows Live
O43 - CFD: 30/05/2013 - 16:33:17 - [] ----D C:\Program Files\Common Files\Wise Installation Wizard
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
O43 - CFD: 30/07/2014 - 20:12:45 - [] ----D C:\ProgramData\Adobe
O43 - CFD: 28/02/2011 - 22:22:21 - [0] ----D C:\ProgramData\ALM
O43 - CFD: 27/10/2012 - 13:10:01 - [] ----D C:\ProgramData\Apple
O43 - CFD: 27/10/2012 - 13:10:36 - [] ----D C:\ProgramData\Apple Computer
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Application Data
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Bureau
O43 - CFD: 25/09/2011 - 22:32:17 - [] ----D C:\ProgramData\Canneverbe Limited
O43 - CFD: 01/02/2011 - 10:06:18 - [] --H-D C:\ProgramData\CanonBJ
O43 - CFD: 30/01/2014 - 16:19:41 - [] --H-D C:\ProgramData\CanonIJScan
O43 - CFD: 09/04/2013 - 08:25:17 - [] ----D C:\ProgramData\Citrix
O43 - CFD: 05/02/2011 - 11:48:10 - [] ----D C:\ProgramData\Creative
O43 - CFD: 17/01/2012 - 16:46:30 - [] ----D C:\ProgramData\CyberLink
O43 - CFD: 23/09/2013 - 14:36:26 - [] ----D C:\ProgramData\DAEMON Tools Lite =>.DT Soft Ltd
O43 - CFD: 23/08/2012 - 11:22:11 - [] ----D C:\ProgramData\Dell
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Documents
O43 - CFD: 07/01/2011 - 14:49:20 - [] ----D C:\Progr
~ Rapport de ZHPDiag v2015.5.8.47 - Nicolas Coolman (05/05/2015)
~ Lancé par Amaury (11/05/2015 08:07:03)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Nouvelle version disponible
~ Liste blanche : Désactivée par l'utilisateur
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user
---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17728
MFIE: Mozilla Firefox 37.0.2 (Defaut)
---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows Operating System - Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : RMV82
Windows License : OK
~ Windows Remaining Initializations Number : 4
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 7 Home Premium, 32-bit Service Pack 1 (Build 7601)
---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 2.1.6.1022
Microsoft Security Client v4.7.0205.0
Windows Defender W7 (Deactivate)
---\\ Logiciels d'optimisation du système
CCleaner v5.05
---\\ Logiciels de partage PeerToPeer
---\\ Surveillance de Logiciels
Adobe Flash Player 17 NPAPI
Adobe Reader X
---\\ Informations sur le système
~ Processor: x86 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2998 MB (57% free)
System Restore: Activé (Enable)
System drive C: has 173 GB (60%) free of 287 GB
---\\ Mode de connexion au système
~ Computer Name: AMAURY-PC
~ User Name: Amaury
~ All Users Names: HomeGroupUser$, Amaury, Administrateur,
~ Unselected Option: None
Logged in as Administrator
---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Amaury\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Amaury\AppData\Roaming\
~ %Desktop% : C:\Users\Amaury\Desktop\
~ %Favorites% : C:\Users\Amaury\Favorites\
~ %LocalAppData% : C:\Users\Amaury\AppData\Local\
~ %StartMenu% : C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 173 Go of 287 Go)
D: CD-ROM drive (Not Inserted)
---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: 43 Scanned in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.C46904F2E9E121A91DDDABB48D7648C3] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.13/03/2015 - 03:20:28.) -- C:\Windows\System32\wininet.dll [1888256]
[MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.17/07/2014 - 02:39:27.) -- C:\Windows\System32\Winlogon.exe [304128]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 13:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:36:07.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 09:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 09:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 10:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 09:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:18:22.) -- C:\Windows\system32\Drivers\ntfs.sys [1212352]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:32:14.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 13:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Generic Processes: Scanned in 00mn 00s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/3
~ Mes musiques (My Musics) : 1/185
~ Mes Favoris (My Favorites) : 1/30
~ Mes Documents (My Documents) : 2/1045
~ Mon Bureau (My Desktop) : 15/82417
~ Menu demarrer (Programs) : 1/30
~ Hidden Files: Scanned in 00mn 32s
---\\ Processus lancés
[MD5.7E212E742BF06BF678AE35E9C1B74B8F] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe [6212920] [PID.4044]
[MD5.567B0B979E206C3E1E7B4422A2D0A5AD] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1602856] [PID.3668]
[MD5.A9D62C7793510D81342AC1AC50FB70F5] - (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe [495708] [PID.3756]
[MD5.C7AF01132A0DD241A1A0DBE9B62A9A1C] - (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\quickset.exe [3873648] [PID.3584]
[MD5.D50F04F005C94FA3802A6E05CFCF4A9A] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.3276]
[MD5.B7680F36C41AE21C0ECA96523443831F] - (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe [727664] [PID.3400]
[MD5.22001D1308E34153D2BCD51368E14F7B] - (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5249024] [PID.3708]
[MD5.2059A96CB2254829488A6A676AA4BA15] - (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\DpAgent.exe [842816] [PID.3460]
[MD5.0FE0EDF01CEA3BEB2E65A904BB87525E] - (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe [640376] [PID.3892]
[MD5.9A8568C7642B79F43DCEB0BDF9F49050] - (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe [542136] [PID.3768]
[MD5.CCA0C5482B8A6A275D9D49433F435DFA] - (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe [542096] [PID.3872]
[MD5.46B9C74861D98EDA9E6E56D19BEAF91A] - (.Broadcom Corporation. - Bluetooth Tray Application.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [795936] [PID.2220]
[MD5.2727208EA26F6B6DA898AB6890417214] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8208384] [PID.5276]
~ Processes Running: Scanned in 00mn 00s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Amaury\AppData\Local\Google\Chrome\User Data\Default\Preferences
---\\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 0 Scanned in 00mn 00s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFF12.DLL
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo-france.xml
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll =>.Google Inc
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=11.31.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Windows\system32\npdeployJava1.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Oracle Corporation - Next Generation Java Plug-in 11.31.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=11.31.2] - (.Oracle Corporation - Next Generation Java Plug-in 11.31.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) -- C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
~ Firefox Browser: 31 Scanned in 00mn 01s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) (No version) -- (.not file.)
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
~ IE Browser: 11 Scanned in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: DigitalPersona Fingerprint Software Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} . (.DigitalPersona, Inc. - DigitalPersona OTS Feedback.) -- C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} . (.Microsoft Corporation - Windows Live Messenger Companion Core.) -- C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
~ BHO: 14 Scanned in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Adobe PDF - [HKLM]{47833539-D0C5-4125-9FA8-0819E2EAAC93} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{47833539-D0C5-4125-9FA8-0819E2EAAC93} Clé orpheline
~ Toolbar: Scanned in 00mn 00s
---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [QuickSet] . (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [FreeFallProtection] . (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] . (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [DpAgent] . (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] . (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKCU\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
~ Application: Scanned in 00mn 00s
---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ IE Control Panel: 1 Scanned in 00mn 00s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} . (.Microsoft Corporation - Windows Live Messenger Companion core resources.) -- C:\Program Files\Windows Live\Companion\companionres.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- c:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000009\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000010\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll
~ Winsock: 10 Scanned in 00mn 00s
---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] *.dell.com
~ IE Zone Confiance: Scanned in 00mn 00s
---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} ((no name)) - http://support.euro.dell.com/systemprofiler/DellSystemLite.CAB
~ Objets ActiveX: Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s
---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ SSODL: 1 Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) . (.Andrea Electronics Corporation - Andrea filters APO access service (32-bit).) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) . (.Broadcom Corporation. - Bluetooth Support Server.) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dell Data Vault (DellDataVault) . (.Dell Inc. - Dell Data Vault Service.) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
O23 - Service: Dell Data Vault Wizard (DellDataVaultWiz) . (.Dell Inc. - Dell Data Vault Wizard.) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
O23 - Service: C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DpHost) . (.DigitalPersona, Inc. - DigitalPersona Local Host.) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) . (.Sonic Solutions - RoxWatch12 Module.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Audio Service (STacSV) . (.IDT, Inc. - IDT PC Audio.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
O23 - Service: Dell SupportAssist Agent (SupportAssistAgent) . (.Dell Inc. - Service.) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
O23 - Service: Intel(R) Management & Security Application User Notificatio (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) . (.Validity Sensors, Inc. - VFS101 VCS API Library.) - C:\Windows\system32\vcsFPService.exe
O23 - Service: DW WLAN Tray Service (wltrysvc) . (.Dell Inc. - DW WLAN Card Wireless Network Service.) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
~ Services: 19 Scanned in 00mn 06s
---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Desktop Component: 4 Scanned in 00mn 00s
---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
[MD5.3E04F1E482357B1FC8B088197C3D9FF8] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152]
[MD5.B04A4810C6CC205F9DC72DC22E4AB236] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [268464]
[MD5.1F014EA12ECB13C909DA9395E9CD3D18] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6278424]
[MD5.2BCB174FF294F83C3520D46B57DBD917] [APT] [Dell SupportAssistAgent AutoUpdate] (.Dell Inc..) -- C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [27472]
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107912]
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107912]
[MD5.79B5DD0E04130BF31AA598F2AEBB1B78] [APT] [PCDEventLauncherTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell\SupportAssist\sessionchecker.exe [433488]
[MD5.254EC04C72D02E4C8EEC08D4CF3658B1] [APT] [PCDoctorBackgroundMonitorTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell\SupportAssist\uaclauncher.exe [1189200]
[MD5.A75AE3B84B6423CE6A088E80A2BC23C2] [APT] [{4773655F-F316-4A0B-AAD8-B898B8AF2A0A}] (.Skype Technologies S.A..) -- C:\Program Files\Skype\Phone\Skype.exe [31280256]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{7A7B4145-1139-4669-8765-5936ED3BBC3A}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{A28E5010-28AC-4FF0-9EDF-0210636C319A}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [561984]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1054]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1054]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1058]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1058]
~ Scheduled Task: 16 Scanned in 00mn 05s
---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft VM - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Microsoft Corporation - Microsoft® VM.) -- C:\Windows\system32\msjava.dll
O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Disable SSL3 - {7D715857-A67C-4C2F-A929-038448584D63} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
~ Active Setup: 11 Scanned in 00mn 00s
---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys
O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys
O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
~ Drivers: 60 Scanned in 00mn 00s
---\\ Logiciels installés (O42)
O42 - Logiciel: 7-Zip 9.20 - (...) [HKLM] -- 7-Zip
O42 - Logiciel: 7Zip Bundle by Fileparade.com - (.SweetPacks LTD.) [HKLM] -- 7Zip Bundle by Fileparade.com =>PUP.SweetIM
O42 - Logiciel: AccelerometerP11 - (.STMicroelectronics.) [HKLM] -- {87434D51-51DB-4109-B68F-A829ECDCF380}
O42 - Logiciel: Adobe After Effects CS4 Third Party Content - (.Adobe Systems Incorporated.) [HKLM] -- {67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}
O42 - Logiciel: Adobe Anchor Service CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {1618734A-3957-4ADD-8199-F973763109A8}
O42 - Logiciel: Adobe Bridge CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {83877DB1-8B77-45BC-AB43-2BAC22E093E0} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe CMaps CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {94D398EB-D2FD-4FD1-B8C4-592635E8A191}
O42 - Logiciel: Adobe CSI CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0F723FC1-7606-4867-866C-CE80AD292DAF}
O42 - Logiciel: Adobe Color EU Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}
O42 - Logiciel: Adobe Color JA Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0D6013AB-A0C7-41DC-973C-E93129C9A29F}
O42 - Logiciel: Adobe Color NA Recommended Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {00ADFB20-AE75-46F4-AD2C-F48B15AC3100}
O42 - Logiciel: Adobe Color Video Profiles CS CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {63C24A08-70F3-4C8E-B9FB-9F21A903801D}
O42 - Logiciel: Adobe Creative Suite 4 Master Collection - (.Adobe Systems Incorporated.) [HKLM] -- Adobe_b2b1c7c62c4ae0a954789ed71d36a7a
O42 - Logiciel: Adobe Creative Suite 4 Master Collection - (.Adobe Systems Incorporated.) [HKLM] -- {D0EE7809-8F5E-46EF-95DC-B30DCE22653F}
O42 - Logiciel: Adobe Default Language CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {C52E3EC1-048C-45E1-8D53-10B0C6509683}
O42 - Logiciel: Adobe Encore CS4 Codecs - (.Adobe Systems Incorporated.) [HKLM] -- {FB2A5FCC-B81B-48C2-A009-7804694D83E9}
O42 - Logiciel: Adobe ExtendScript Toolkit CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F8EF2B3F-C345-4F20-8FE4-791A20333CD5} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Extension Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {054EFA56-2AC1-48F4-A883-0AB89874B972}
O42 - Logiciel: Adobe Flash Player 17 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 17 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI
O42 - Logiciel: Adobe Fonts All - (.Adobe Systems Incorporated.) [HKLM] -- {FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
O42 - Logiciel: Adobe Illustrator CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05C677A1-A161-447E-92ED-2D5B38AA0740} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {A2160D84-F2D0-47A3-AA59-CCB3CA21D558} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Application Feature Set Files (Roman) - (.Adobe Systems Incorporated.) [HKLM] -- {C950299F-BCAB-4695-B077-FC3B2748C25D} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Common Base Files - (.Adobe Systems Incorporated.) [HKLM] -- {26F72DC3-DDBE-424F-B9F0-94E5D0E5A12B} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Icon Handler - (.Adobe Systems Incorporated.) [HKLM] -- {2BA4F7B0-F38E-4AE8-80A2-E9C5956C6D6D} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Linguistics CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {931AB7EA-3656-4BB7-864D-022B09E3DD67}
O42 - Logiciel: Adobe Media Encoder CS4 Exporter - (.Adobe Systems Incorporated.) [HKLM] -- {561968FD-56A1-49FD-9ED0-F55482C7C5BC}
O42 - Logiciel: Adobe Media Encoder CS4 Importer - (.Adobe Systems Incorporated.) [HKLM] -- {8186FF34-D389-4B7E-9A2F-C197585BCFBD}
O42 - Logiciel: Adobe Output Module - (.Adobe Systems Incorporated.) [HKLM] -- {BB4E33EC-8181-4685-96F7-8554293DEC6A}
O42 - Logiciel: Adobe PDF Library Files CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F93C84A6-0DC6-42AF-89FA-776F7C377353}
O42 - Logiciel: Adobe Photoshop CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {E2E01E91-2314-42BC-B5E3-1715DAE84F98} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Photoshop CS4 Support - (.Adobe Systems Incorporated.) [HKLM] -- {73E17122-EC84-45B4-943B-735257B5CBDC} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Premiere Pro CS4 Third Party Content - (.Adobe Systems Incorporated.) [HKLM] -- {E1951CF4-91CE-46F0-A1BD-3A4A67069097}
O42 - Logiciel: Adobe Reader X (10.1.13) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AA1000000001}
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-0804-1033-1959-001802114130}
O42 - Logiciel: Adobe SGM CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}
O42 - Logiciel: Adobe SING CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {8CB16C77-9D75-4966-91E8-D785B87EC078}
O42 - Logiciel: Adobe Search for Help - (.Adobe Systems Incorporated.) [HKLM] -- {F0E64E2E-3A60-40D8-A55D-92F6831875DA}
O42 - Logiciel: Adobe Service Manager Extension - (.Adobe Systems Incorporated.) [HKLM] -- {4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
O42 - Logiciel: Adobe Setup - (.Adobe Systems Incorporated.) [HKLM] -- {6577657B-A10C-47A1-A50D-512C7748CB2C}
O42 - Logiciel: Adobe Soundbooth CS4 Codecs - (.Adobe Systems Incorporated.) [HKLM] -- {52232EF4-CC12-4C21-ABCF-ADB79618302D}
O42 - Logiciel: Adobe Type Support CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
O42 - Logiciel: Adobe Update Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05308C4E-7285-4066-BAE3-6B50DA6ED755}
O42 - Logiciel: Adobe WinSoft Linguistics Plugin - (.Adobe Systems Incorporated.) [HKLM] -- {3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
O42 - Logiciel: Adobe XMP Panels CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
O42 - Logiciel: AdobeColorCommonSetCMYK - (.Adobe Systems Incorporated.) [HKLM] -- {E5FCED12-3E77-4C0E-A305-5AEB38A52A70}
O42 - Logiciel: AdobeColorCommonSetRGB - (.Adobe Systems Incorporated.) [HKLM] -- {16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
O42 - Logiciel: Advanced Audio FX Engine - (.Creative Technology Ltd.) [HKLM] -- Advanced Audio FX Engine
O42 - Logiciel: Antidote RX v7 - (.Druide informatique inc..) [HKLM] -- {A474EA56-5DBD-4181-8230-806A4762EA7F}
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {5D09C772-ECB3-442B-9CC6-B4341C78FDC2}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {E14ADE0E-75F3-4A46-87E5-26692DD626EC}
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} =>.Apple Inc
O42 - Logiciel: ArcGIS 10.1 for Desktop - (.Environmental Systems Research Institute, Inc..) [HKLM] -- ArcGIS 10.1 for Desktop
O42 - Logiciel: ArcGIS 10.1 for Desktop - Module linguistique français - (.Environmental Systems Research Institute, Inc..) [HKLM] -- ArcGIS 10.1 for Desktop - Module linguistique français
O42 - Logiciel: ArcGIS 10.1 for Desktop - Module linguistique français - (.Environmental Systems Research Institute, Inc..) [HKLM] -- {311DA2E4-3B6A-464F-8987-C4AAE6B9386D}
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {79155F2B-9895-49D7-8612-D92580E0DE5B}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: CDBurnerXP - (.CDBurnerXP.) [HKLM] -- {7E265513-8CDA-4631-B696-F40D983F3B07}_is1
O42 - Logiciel: Canon MG5200 series MP Drivers - (...) [HKLM] -- {1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series
O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM] -- {64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {51C7AD07-C3F6-4635-8E8A-231306D810FE}
O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
O42 - Logiciel: Complément Messenger - (.Microsoft Corporation.) [HKLM] -- {6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}
O42 - Logiciel: Connect - (.Adobe Systems Incorporated.) [HKLM] -- {B29AD377-CC12-490A-A480-1452337C618D}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM] -- InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM] -- {A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
O42 - Logiciel: DW WLAN Card Utility - (.Dell Inc..) [HKLM] -- DW WLAN Card Utility
O42 - Logiciel: Dell Backup and Recovery Manager - (.Dell Inc..) [HKLM] -- {4688EB75-28E2-4731-9BCB-55E624F7CD45}
O42 - Logiciel: Dell Data Vault - (.Dell Inc..) [HKLM] -- {2E55EEFD-2162-4A7D-9158-EDB0305603A6}
O42 - Logiciel: Dell Edoc Viewer - (.Dell Inc.) [HKLM] -- {3138EAD3-700B-4A10-B617-B3F8096EE30D}
O42 - Logiciel: Dell SupportAssist - (.Dell.) [HKLM] -- PC-Doctor for Windows
O42 - Logiciel: Dell SupportAssistAgent - (.Dell.) [HKLM] -- {287348C8-8B47-4C36-AF28-441A3B7D8722}
O42 - Logiciel: Dell Touchpad - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey
O42 - Logiciel: Dell Webcam Central - (.Creative Technology Ltd.) [HKLM] -- Dell Webcam Central
O42 - Logiciel: DigitalPersona Personal 4.01 - (.DigitalPersona, Inc..) [HKLM] -- {3D8AE086-030F-4EF4-B705-63F8130B043E}
O42 - Logiciel: DirectX 9 Runtime - (.Sonic Solutions.) [HKLM] -- {AF9E97C1-7431-426D-A8D5-ABE40995C0B1}
O42 - Logiciel: EndNote X3 - (.Thomson Reuters.) [HKLM] -- {86B3F2D6-AC2B-4E88-8AE1-F2F77F781B0C}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}
O42 - Logiciel: IRIScan(TM) Direct - (.IRIScanDirect.) [HKLM] -- IRIScanDirect_is1
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
O42 - Logiciel: Java 8 Update 31 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83218031F0}
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
O42 - Logiciel: Logiciel d'archivage WinRAR - (...) [HKLM] -- WinRAR archiver
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: Malwarebytes Anti-Malware version 2.1.6.1022 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1
O42 - Logiciel: Mesh Runtime - (.Microsoft Corporation.) [HKLM] -- {8C6D6116-B724-4810-8F2D-D047E6B7D68E}
O42 - Logiciel: Microsoft Image Composite Editor - (.Microsoft Corporation.) [HKLM] -- {3D599ADA-65D9-4B51-898F-CE718DEC5DBB}
O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {D6F9CBDC-58B6-430A-8DD4-8F61CBC1ADF4}
O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Mozilla Firefox 37.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 37.0.2 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: PDF Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
O42 - Logiciel: PhotoShowExpress - (.Sonic Solutions.) [HKLM] -- {3250260C-7A95-4632-893B-89657EB5545B}
O42 - Logiciel: Photoshop Camera Raw - (.Adobe Systems Incorporated.) [HKLM] -- {CC75AB5C-2110-4A7F-AF52-708680D22FE8}
O42 - Logiciel: QuickSet32 - (.Dell Inc..) [HKLM] -- {C4972073-2BFE-475D-8441-564EA97DA161}
O42 - Logiciel: ResearchSoft Direct Export Helper - (...) [HKLM] -- ResearchSoft Direct Export Helper
O42 - Logiciel: Roxio Activation Module - (.Roxio.) [HKLM] -- {A121EEDE-C68F-461D-91AA-D48BA226AF1C}
O42 - Logiciel: Roxio BackOnTrack - (.Roxio.) [HKLM] -- {5A06423A-210C-49FB-950E-CB0EB8C5CEC7}
O42 - Logiciel: Roxio Burn - (.Roxio.) [HKLM] -- {9569E6BC-326A-432F-97AB-35263A327BF1}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {EF56258E-0326-48C5-A86C-3BAC26FC15DF}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}
O42 - Logiciel: Roxio Express Labeler 3 - (.Roxio.) [HKLM] -- {6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
O42 - Logiciel: Roxio File Backup - (.Roxio.) [HKLM] -- {60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}
O42 - Logiciel: Samsung Printer Live Update - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung Printer Live Update
O42 - Logiciel: Satsuki Decoder Pack - (.Satsuki Yatoshi'S Softs.) [HKLM] -- Satsuki Decoder Pack
O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701}
O42 - Logiciel: Skype(TM) 7.4 - (.Skype Technologies S.A..) [HKLM] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
O42 - Logiciel: Sonic CinePlayer Decoder Pack - (.Sonic Solutions.) [HKLM] -- {9A00EC4E-27E1-42C4-98DD-662F32AC8870}
O42 - Logiciel: Spotify - (...) [HKLM] -- Spotify
O42 - Logiciel: Spotify - (.Spotify AB.) [HKCU] -- Spotify
O42 - Logiciel: Suite Shared Configuration CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {842B4B72-9E8F-4962-B3C1-1C422A5C4434}
O42 - Logiciel: TuxGuitar 1.2 - (...) [HKLM] -- TuxGuitar_0
O42 - Logiciel: Validity Sensors DDK - (.Validity Sensors, Inc..) [HKLM] -- {9FCB6355-689E-4141-9714-3EEC2AE10292}
O42 - Logiciel: WIDCOMM Bluetooth Software - (.Broadcom Corporation.) [HKLM] -- {9E9D49A4-1DF4-4138-B7DB-5D87A893088E}
O42 - Logiciel: XnView 2.22 - (.Gougelet Pierre-e.) [HKLM] -- XnView_is1
O42 - Logiciel: Xvid 1.2.1 final uninstall - (.Xvid team (Koepi).) [HKLM] -- Xvid_is1
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {11E568E0-3244-4BCB-875E-F334269DFDCB}
O42 - Logiciel: kuler - (.Adobe Systems Incorporated.) [HKLM] -- {098727E1-775A-4450-B573-3F441F1CA243}
~ Logic: 44 Scanned in 00mn 00s
---\\ HKCU & HKLM Software Keys
[HKCU\Software\7-Zip]
[HKCU\Software\AC3Filter]
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow\Software\DigitalPersona]
[HKCU\Software\AppDataLow\Software\JavaSoft]
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Arobas Music]
[HKCU\Software\Broadcom]
[HKCU\Software\CG Information]
[HKCU\Software\Canneverbe Limited]
[HKCU\Software\Canon]
[HKCU\Software\Citrix]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\Creative Tech]
[HKCU\Software\CyberLink]
[HKCU\Software\DT Soft]
[HKCU\Software\Developer Express]
[HKCU\Software\DigitalPersona]
[HKCU\Software\Druide informatique inc.]
[HKCU\Software\ERDAS]
[HKCU\Software\ESRI]
[HKCU\Software\EasyBits]
[HKCU\Software\Eset]
[HKCU\Software\GNU]
[HKCU\Software\Gabest]
[HKCU\Software\Google]
[HKCU\Software\HKEY_LOCAL_MACHINE]
[HKCU\Software\Haali]
[HKCU\Software\Herac]
[HKCU\Software\IDAVLab]
[HKCU\Software\IDT]
[HKCU\Software\IM Providers]
[HKCU\Software\ISI ResearchSoft]
[HKCU\Software\Intel]
[HKCU\Software\JavaSoft]
[HKCU\Software\Lake]
[HKCU\Software\LogiShrd]
[HKCU\Software\MCAFEE]
[HKCU\Software\Macromedia]
[HKCU\Software\Macrovision]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Nero]
[HKCU\Software\Netscape]
[HKCU\Software\Northcode Inc]
[HKCU\Software\ODBC]
[HKCU\Software\PC-Doctor]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\RICOH]
[HKCU\Software\RealNetworks]
[HKCU\Software\RegisteredApplications]
[HKCU\Software\Roxio]
[HKCU\Software\SSPrint]
[HKCU\Software\STUDIO SARMADI]
[HKCU\Software\Samsung]
[HKCU\Software\Satsuki Decoder Pack]
[HKCU\Software\SecuROM]
[HKCU\Software\Skype]
[HKCU\Software\Synaptics]
[HKCU\Software\Trolltech]
[HKCU\Software\Widcomm]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\ZebHelpProcess Helper]
[HKLM\Software\ATI Technologies]
[HKLM\Software\Adobe]
[HKLM\Software\AdwCleaner]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\BcmSetup]
[HKLM\Software\Broadcom]
[HKLM\Software\Canneverbe Limited]
[HKLM\Software\Canon]
[HKLM\Software\Citrix]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Creative Tech]
[HKLM\Software\CyberLink]
[HKLM\Software\DT Soft]
[HKLM\Software\Debug]
[HKLM\Software\Dell Computer Corporation]
[HKLM\Software\Dell Inc.]
[HKLM\Software\Dell]
[HKLM\Software\DigitalPersona]
[HKLM\Software\Druide informatique inc.]
[HKLM\Software\ERDAS]
[HKLM\Software\ESRI]
[HKLM\Software\FreeFallProtection]
[HKLM\Software\GEAR Software]
[HKLM\Software\GNU]
[HKLM\Software\Gabest]
[HKLM\Software\Google]
[HKLM\Software\HaaliMkx]
[HKLM\Software\IDAVLab]
[HKLM\Software\IDT]
[HKLM\Software\IM Providers]
[HKLM\Software\ISI ResearchSoft]
[HKLM\Software\Imagineer Systems Ltd]
[HKLM\Software\InstalledOptions]
[HKLM\Software\Intel]
[HKLM\Software\InterVideo]
[HKLM\Software\JavaSoft]
[HKLM\Software\JreMetrics]
[HKLM\Software\Lake]
[HKLM\Software\Logishrd]
[HKLM\Software\MAXSOFT-OCRON]
[HKLM\Software\Macromedia]
[HKLM\Software\Macrovision]
[HKLM\Software\Malwarebytes' Anti-Malware (Trial)]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\ManageableUpdatePackage]
[HKLM\Software\McAfee.com]
[HKLM\Software\McAfeeInstaller]
[HKLM\Software\McAfee]
[HKLM\Software\MicroVision]
[HKLM\Software\MimarSinan]
[HKLM\Software\Mircrosoft]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Nero]
[HKLM\Software\Novell]
[HKLM\Software\ODBC]
[HKLM\Software\PC-Doctor]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\Python]
[HKLM\Software\RealNetworks]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Roxio]
[HKLM\Software\SSPrint]
[HKLM\Software\STMicroelectronics]
[HKLM\Software\Samsung]
[HKLM\Software\Skype]
[HKLM\Software\Sonic]
[HKLM\Software\Synaptics]
[HKLM\Software\Synthetic Aperture]
[HKLM\Software\Validity]
[HKLM\Software\Vantage Software Technologies]
[HKLM\Software\Volatile]
[HKLM\Software\Widcomm]
[HKLM\Software\WinRAR]
[HKLM\Software\Windows]
[HKLM\Software\Wise Solutions]
[HKLM\Software\XnView]
[HKLM\Software\illiminable]
[HKLM\Software\mozilla.org]
~ Key Software: 326 Scanned in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 23/09/2013 - 18:48:51 - [] ----D C:\Program Files\7-Zip
O43 - CFD: 14/10/2012 - 17:01:19 - [] ----D C:\Program Files\Adobe
O43 - CFD: 27/10/2012 - 13:10:03 - [] ----D C:\Program Files\Apple Software Update =>.Apple Inc
O43 - CFD: 23/09/2013 - 14:43:50 - [] ----D C:\Program Files\ArcGIS
O43 - CFD: 27/10/2012 - 13:09:43 - [] ----D C:\Program Files\Bonjour
O43 - CFD: 08/05/2015 - 11:47:02 - [] ----D C:\Program Files\CCleaner
O43 - CFD: 04/12/2011 - 23:56:37 - [] ----D C:\Program Files\CDBurnerXP
O43 - CFD: 07/01/2011 - 14:48:11 - [] ----D C:\Program Files\Cisco
O43 - CFD: 09/04/2013 - 08:24:59 - [] ----D C:\Program Files\Citrix
O43 - CFD: 10/05/2015 - 10:49:29 - [] ----D C:\Program Files\Common Files
O43 - CFD: 07/01/2011 - 14:52:12 - [] ----D C:\Program Files\Creative
O43 - CFD: 07/01/2011 - 14:51:48 - [] ----D C:\Program Files\Creative Live! Cam
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\CyberLink
O43 - CFD: 13/02/2015 - 17:07:18 - [] ----D C:\Program Files\Dell
O43 - CFD: 07/01/2011 - 14:41:47 - [] ----D C:\Program Files\Dell Inc
O43 - CFD: 01/04/2015 - 15:56:44 - [] ----D C:\Program Files\Dell Support Center
O43 - CFD: 07/01/2011 - 14:51:52 - [] ----D C:\Program Files\Dell Webcam
O43 - CFD: 07/01/2011 - 14:49:33 - [] ----D C:\Program Files\DigitalPersona
O43 - CFD: 05/10/2011 - 21:15:44 - [] ----D C:\Program Files\Druide
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\DVD Maker
O43 - CFD: 30/05/2013 - 16:35:59 - [] ----D C:\Program Files\EndNote X3
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\Program Files\Fichiers communs
O43 - CFD: 09/08/2013 - 08:30:00 - [] ----D C:\Program Files\Google
O43 - CFD: 18/09/2012 - 08:30:24 - [] ----D C:\Program Files\GUMBB52.tmp
O43 - CFD: 07/01/2011 - 07:38:05 - [] ----D C:\Program Files\IDT
O43 - CFD: 07/01/2011 - 14:51:50 - [] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 07/01/2011 - 14:43:38 - [] ----D C:\Program Files\Intel
O43 - CFD: 16/04/2015 - 07:41:45 - [] ----D C:\Program Files\Internet Explorer
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\iPod
O43 - CFD: 30/05/2014 - 17:24:54 - [] ----D C:\Program Files\IRIScan Direct
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\Program Files\iTunes
O43 - CFD: 01/02/2015 - 19:24:51 - [] ----D C:\Program Files\Java
O43 - CFD: 08/05/2015 - 12:02:05 - [] ----D C:\Program Files\Malwarebytes Anti-Malware
O43 - CFD: 19/08/2014 - 07:39:24 - [] ----D C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 15/01/2011 - 17:51:35 - [0] ----D C:\Program Files\Microsoft
O43 - CFD: 14/07/2009 - 11:00:58 - [] ----D C:\Program Files\Microsoft Games
O43 - CFD: 27/08/2012 - 21:15:59 - [] ----D C:\Program Files\Microsoft Office
O43 - CFD: 10/02/2012 - 09:38:04 - [] ----D C:\Program Files\Microsoft Research
O43 - CFD: 11/02/2015 - 20:53:43 - [] ----D C:\Program Files\Microsoft Security Client
O43 - CFD: 24/07/2014 - 17:05:44 - [] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 07/01/2011 - 15:02:44 - [] ----D C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 13/03/2011 - 22:40:16 - [] ----D C:\Program Files\Microsoft Visual Studio
O43 - CFD: 13/03/2011 - 22:37:09 - [] ----D C:\Program Files\Microsoft Visual Studio 8
O43 - CFD: 23/08/2012 - 08:17:10 - [] ----D C:\Program Files\Microsoft Works
O43 - CFD: 13/03/2011 - 22:40:04 - [] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 24/04/2015 - 12:09:10 - [] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 26/04/2015 - 08:23:34 - [] ----D C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 13/03/2011 - 22:40:20 - [] ----D C:\Program Files\MSBuild
O43 - CFD: 15/01/2011 - 23:49:59 - [0] ----D C:\Program Files\MSXML 4.0
O43 - CFD: 14/07/2009 - 06:52:30 - [] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 07/01/2011 - 14:58:04 - [] ----D C:\Program Files\Roxio
O43 - CFD: 03/03/2014 - 12:14:18 - [] ----D C:\Program Files\SamsungPrinterLiveUpdate
O43 - CFD: 03/03/2014 - 12:04:04 - [] ----D C:\Program Files\SamsungPrinterLiveUpdateInstaller
O43 - CFD: 05/02/2011 - 11:29:22 - [] ----D C:\Program Files\Satsuki Decoder Pack
O43 - CFD: 14/04/2015 - 08:03:39 - [] R---D C:\Program Files\Skype
O43 - CFD: 24/03/2015 - 20:36:20 - [] ----D C:\Program Files\Spotify
O43 - CFD: 07/01/2011 - 14:44:04 - [] ----D C:\Program Files\STMicroelectronics
O43 - CFD: 07/01/2011 - 16:33:50 - [] ----D C:\Program Files\Synaptics
O43 - CFD: 10/12/2011 - 19:15:54 - [] ----D C:\Program Files\Trend Micro
O43 - CFD: 25/03/2011 - 22:12:50 - [] ----D C:\Program Files\TuxGuitar-Jet
O43 - CFD: 14/07/2009 - 06:53:23 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 07/01/2011 - 14:45:49 - [] ----D C:\Program Files\Validity Sensors
O43 - CFD: 07/01/2011 - 14:46:46 - [] ----D C:\Program Files\WIDCOMM
O43 - CFD: 12/07/2013 - 07:57:37 - [] ----D C:\Program Files\Windows Defender
O43 - CFD: 12/07/2014 - 07:43:28 - [] ----D C:\Program Files\Windows Journal
O43 - CFD: 07/01/2011 - 15:03:04 - [] ----D C:\Program Files\Windows Live
O43 - CFD: 04/01/2012 - 19:59:00 - [] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 12/03/2015 - 04:25:28 - [] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 12/01/2011 - 13:59:10 - [] ----D C:\Program Files\Windows NT
O43 - CFD: 04/01/2012 - 19:58:58 - [] ----D C:\Program Files\Windows Photo Viewer
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Portable Devices
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Sidebar
O43 - CFD: 05/02/2011 - 12:44:37 - [] ----D C:\Program Files\WinRAR
O43 - CFD: 15/04/2014 - 08:21:40 - [] ----D C:\Program Files\XnView
O43 - CFD: 15/01/2011 - 22:02:09 - [] ----D C:\Program Files\Xvid
O43 - CFD: 08/05/2015 - 19:09:29 - [] ----D C:\Program Files\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 14/10/2012 - 17:01:28 - [] ----D C:\Program Files\Common Files\Adobe
O43 - CFD: 23/09/2013 - 14:47:09 - [] ----D C:\Program Files\Common Files\AnswerWorks 4.0
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\Common Files\Apple
O43 - CFD: 23/09/2013 - 14:46:20 - [] ----D C:\Program Files\Common Files\ArcGIS
O43 - CFD: 10/12/2011 - 19:52:01 - [] ----D C:\Program Files\Common Files\Bitdefender
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\Common Files\CyberLink
O43 - CFD: 23/09/2013 - 14:44:22 - [] ----D C:\Program Files\Common Files\Data Dynamics
O43 - CFD: 15/05/2014 - 11:50:28 - [] ----D C:\Program Files\Common Files\DESIGNER
O43 - CFD: 07/01/2011 - 14:51:35 - [] ----D C:\Program Files\Common Files\InstallShield
O43 - CFD: 01/02/2015 - 19:25:56 - [] ----D C:\Program Files\Common Files\Java
O43 - CFD: 28/02/2011 - 22:14:03 - [] ----D C:\Program Files\Common Files\Macrovision Shared
O43 - CFD: 05/02/2011 - 11:49:23 - [] ----D C:\Program Files\Common Files\mcafee
O43 - CFD: 23/08/2012 - 08:17:16 - [] ----D C:\Program Files\Common Files\microsoft shared
O43 - CFD: 07/01/2011 - 14:43:41 - [] ----D C:\Program Files\Common Files\postureAgent
O43 - CFD: 07/01/2011 - 14:58:20 - [] ----D C:\Program Files\Common Files\PX Storage Engine
O43 - CFD: 30/05/2013 - 16:36:04 - [] ----D C:\Program Files\Common Files\ResearchSoft
O43 - CFD: 23/12/2012 - 15:28:39 - [] ----D C:\Program Files\Common Files\Risxtd
O43 - CFD: 07/01/2011 - 14:58:36 - [] ----D C:\Program Files\Common Files\Roxio Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\Services
O43 - CFD: 08/10/2014 - 07:41:48 - [] ----D C:\Program Files\Common Files\Skype
O43 - CFD: 07/01/2011 - 14:58:00 - [] ----D C:\Program Files\Common Files\Sonic Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 07/01/2011 - 14:57:58 - [] ----D C:\Program Files\Common Files\SureThing Shared
O43 - CFD: 17/01/2012 - 16:46:20 - [0] ----D C:\Program Files\Common Files\SWF Studio
O43 - CFD: 04/01/2012 - 19:58:57 - [] ----D C:\Program Files\Common Files\System
O43 - CFD: 23/09/2013 - 14:44:09 - [] ----D C:\Program Files\Common Files\Tom Sawyer Software
O43 - CFD: 07/01/2011 - 14:58:54 - [] ----D C:\Program Files\Common Files\Windows Live
O43 - CFD: 30/05/2013 - 16:33:17 - [] ----D C:\Program Files\Common Files\Wise Installation Wizard
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
O43 - CFD: 30/07/2014 - 20:12:45 - [] ----D C:\ProgramData\Adobe
O43 - CFD: 28/02/2011 - 22:22:21 - [0] ----D C:\ProgramData\ALM
O43 - CFD: 27/10/2012 - 13:10:01 - [] ----D C:\ProgramData\Apple
O43 - CFD: 27/10/2012 - 13:10:36 - [] ----D C:\ProgramData\Apple Computer
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Application Data
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Bureau
O43 - CFD: 25/09/2011 - 22:32:17 - [] ----D C:\ProgramData\Canneverbe Limited
O43 - CFD: 01/02/2011 - 10:06:18 - [] --H-D C:\ProgramData\CanonBJ
O43 - CFD: 30/01/2014 - 16:19:41 - [] --H-D C:\ProgramData\CanonIJScan
O43 - CFD: 09/04/2013 - 08:25:17 - [] ----D C:\ProgramData\Citrix
O43 - CFD: 05/02/2011 - 11:48:10 - [] ----D C:\ProgramData\Creative
O43 - CFD: 17/01/2012 - 16:46:30 - [] ----D C:\ProgramData\CyberLink
O43 - CFD: 23/09/2013 - 14:36:26 - [] ----D C:\ProgramData\DAEMON Tools Lite =>.DT Soft Ltd
O43 - CFD: 23/08/2012 - 11:22:11 - [] ----D C:\ProgramData\Dell
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Documents
O43 - CFD: 07/01/2011 - 14:49:20 - [] ----D C:\Progr
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 23/09/2013 - 18:48:51 - [] ----D C:\Program Files\7-Zip
O43 - CFD: 14/10/2012 - 17:01:19 - [] ----D C:\Program Files\Adobe
O43 - CFD: 27/10/2012 - 13:10:03 - [] ----D C:\Program Files\Apple Software Update =>.Apple Inc
O43 - CFD: 23/09/2013 - 14:43:50 - [] ----D C:\Program Files\ArcGIS
O43 - CFD: 27/10/2012 - 13:09:43 - [] ----D C:\Program Files\Bonjour
O43 - CFD: 08/05/2015 - 11:47:02 - [] ----D C:\Program Files\CCleaner
O43 - CFD: 04/12/2011 - 23:56:37 - [] ----D C:\Program Files\CDBurnerXP
O43 - CFD: 07/01/2011 - 14:48:11 - [] ----D C:\Program Files\Cisco
O43 - CFD: 09/04/2013 - 08:24:59 - [] ----D C:\Program Files\Citrix
O43 - CFD: 10/05/2015 - 10:49:29 - [] ----D C:\Program Files\Common Files
O43 - CFD: 07/01/2011 - 14:52:12 - [] ----D C:\Program Files\Creative
O43 - CFD: 07/01/2011 - 14:51:48 - [] ----D C:\Program Files\Creative Live! Cam
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\CyberLink
O43 - CFD: 13/02/2015 - 17:07:18 - [] ----D C:\Program Files\Dell
O43 - CFD: 07/01/2011 - 14:41:47 - [] ----D C:\Program Files\Dell Inc
O43 - CFD: 01/04/2015 - 15:56:44 - [] ----D C:\Program Files\Dell Support Center
O43 - CFD: 07/01/2011 - 14:51:52 - [] ----D C:\Program Files\Dell Webcam
O43 - CFD: 07/01/2011 - 14:49:33 - [] ----D C:\Program Files\DigitalPersona
O43 - CFD: 05/10/2011 - 21:15:44 - [] ----D C:\Program Files\Druide
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\DVD Maker
O43 - CFD: 30/05/2013 - 16:35:59 - [] ----D C:\Program Files\EndNote X3
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\Program Files\Fichiers communs
O43 - CFD: 09/08/2013 - 08:30:00 - [] ----D C:\Program Files\Google
O43 - CFD: 18/09/2012 - 08:30:24 - [] ----D C:\Program Files\GUMBB52.tmp
O43 - CFD: 07/01/2011 - 07:38:05 - [] ----D C:\Program Files\IDT
O43 - CFD: 07/01/2011 - 14:51:50 - [] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 07/01/2011 - 14:43:38 - [] ----D C:\Program Files\Intel
O43 - CFD: 16/04/2015 - 07:41:45 - [] ----D C:\Program Files\Internet Explorer
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\iPod
O43 - CFD: 30/05/2014 - 17:24:54 - [] ----D C:\Program Files\IRIScan Direct
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\Program Files\iTunes
O43 - CFD: 01/02/2015 - 19:24:51 - [] ----D C:\Program Files\Java
O43 - CFD: 08/05/2015 - 12:02:05 - [] ----D C:\Program Files\Malwarebytes Anti-Malware
O43 - CFD: 19/08/2014 - 07:39:24 - [] ----D C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 15/01/2011 - 17:51:35 - [0] ----D C:\Program Files\Microsoft
O43 - CFD: 14/07/2009 - 11:00:58 - [] ----D C:\Program Files\Microsoft Games
O43 - CFD: 27/08/2012 - 21:15:59 - [] ----D C:\Program Files\Microsoft Office
O43 - CFD: 10/02/2012 - 09:38:04 - [] ----D C:\Program Files\Microsoft Research
O43 - CFD: 11/02/2015 - 20:53:43 - [] ----D C:\Program Files\Microsoft Security Client
O43 - CFD: 24/07/2014 - 17:05:44 - [] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 07/01/2011 - 15:02:44 - [] ----D C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 13/03/2011 - 22:40:16 - [] ----D C:\Program Files\Microsoft Visual Studio
O43 - CFD: 13/03/2011 - 22:37:09 - [] ----D C:\Program Files\Microsoft Visual Studio 8
O43 - CFD: 23/08/2012 - 08:17:10 - [] ----D C:\Program Files\Microsoft Works
O43 - CFD: 13/03/2011 - 22:40:04 - [] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 24/04/2015 - 12:09:10 - [] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 26/04/2015 - 08:23:34 - [] ----D C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 13/03/2011 - 22:40:20 - [] ----D C:\Program Files\MSBuild
O43 - CFD: 15/01/2011 - 23:49:59 - [0] ----D C:\Program Files\MSXML 4.0
O43 - CFD: 14/07/2009 - 06:52:30 - [] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 07/01/2011 - 14:58:04 - [] ----D C:\Program Files\Roxio
O43 - CFD: 03/03/2014 - 12:14:18 - [] ----D C:\Program Files\SamsungPrinterLiveUpdate
O43 - CFD: 03/03/2014 - 12:04:04 - [] ----D C:\Program Files\SamsungPrinterLiveUpdateInstaller
O43 - CFD: 05/02/2011 - 11:29:22 - [] ----D C:\Program Files\Satsuki Decoder Pack
O43 - CFD: 14/04/2015 - 08:03:39 - [] R---D C:\Program Files\Skype
O43 - CFD: 24/03/2015 - 20:36:20 - [] ----D C:\Program Files\Spotify
O43 - CFD: 07/01/2011 - 14:44:04 - [] ----D C:\Program Files\STMicroelectronics
O43 - CFD: 07/01/2011 - 16:33:50 - [] ----D C:\Program Files\Synaptics
O43 - CFD: 10/12/2011 - 19:15:54 - [] ----D C:\Program Files\Trend Micro
O43 - CFD: 25/03/2011 - 22:12:50 - [] ----D C:\Program Files\TuxGuitar-Jet
O43 - CFD: 14/07/2009 - 06:53:23 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 07/01/2011 - 14:45:49 - [] ----D C:\Program Files\Validity Sensors
O43 - CFD: 07/01/2011 - 14:46:46 - [] ----D C:\Program Files\WIDCOMM
O43 - CFD: 12/07/2013 - 07:57:37 - [] ----D C:\Program Files\Windows Defender
O43 - CFD: 12/07/2014 - 07:43:28 - [] ----D C:\Program Files\Windows Journal
O43 - CFD: 07/01/2011 - 15:03:04 - [] ----D C:\Program Files\Windows Live
O43 - CFD: 04/01/2012 - 19:59:00 - [] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 12/03/2015 - 04:25:28 - [] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 12/01/2011 - 13:59:10 - [] ----D C:\Program Files\Windows NT
O43 - CFD: 04/01/2012 - 19:58:58 - [] ----D C:\Program Files\Windows Photo Viewer
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Portable Devices
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Sidebar
O43 - CFD: 05/02/2011 - 12:44:37 - [] ----D C:\Program Files\WinRAR
O43 - CFD: 15/04/2014 - 08:21:40 - [] ----D C:\Program Files\XnView
O43 - CFD: 15/01/2011 - 22:02:09 - [] ----D C:\Program Files\Xvid
O43 - CFD: 08/05/2015 - 19:09:29 - [] ----D C:\Program Files\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 14/10/2012 - 17:01:28 - [] ----D C:\Program Files\Common Files\Adobe
O43 - CFD: 23/09/2013 - 14:47:09 - [] ----D C:\Program Files\Common Files\AnswerWorks 4.0
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\Common Files\Apple
O43 - CFD: 23/09/2013 - 14:46:20 - [] ----D C:\Program Files\Common Files\ArcGIS
O43 - CFD: 10/12/2011 - 19:52:01 - [] ----D C:\Program Files\Common Files\Bitdefender
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\Common Files\CyberLink
O43 - CFD: 23/09/2013 - 14:44:22 - [] ----D C:\Program Files\Common Files\Data Dynamics
O43 - CFD: 15/05/2014 - 11:50:28 - [] ----D C:\Program Files\Common Files\DESIGNER
O43 - CFD: 07/01/2011 - 14:51:35 - [] ----D C:\Program Files\Common Files\InstallShield
O43 - CFD: 01/02/2015 - 19:25:56 - [] ----D C:\Program Files\Common Files\Java
O43 - CFD: 28/02/2011 - 22:14:03 - [] ----D C:\Program Files\Common Files\Macrovision Shared
O43 - CFD: 05/02/2011 - 11:49:23 - [] ----D C:\Program Files\Common Files\mcafee
O43 - CFD: 23/08/2012 - 08:17:16 - [] ----D C:\Program Files\Common Files\microsoft shared
O43 - CFD: 07/01/2011 - 14:43:41 - [] ----D C:\Program Files\Common Files\postureAgent
O43 - CFD: 07/01/2011 - 14:58:20 - [] ----D C:\Program Files\Common Files\PX Storage Engine
O43 - CFD: 30/05/2013 - 16:36:04 - [] ----D C:\Program Files\Common Files\ResearchSoft
O43 - CFD: 23/12/2012 - 15:28:39 - [] ----D C:\Program Files\Common Files\Risxtd
O43 - CFD: 07/01/2011 - 14:58:36 - [] ----D C:\Program Files\Common Files\Roxio Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\Services
O43 - CFD: 08/10/2014 - 07:41:48 - [] ----D C:\Program Files\Common Files\Skype
O43 - CFD: 07/01/2011 - 14:58:00 - [] ----D C:\Program Files\Common Files\Sonic Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 07/01/2011 - 14:57:58 - [] ----D C:\Program Files\Common Files\SureThing Shared
O43 - CFD: 17/01/2012 - 16:46:20 - [0] ----D C:\Program Files\Common Files\SWF Studio
O43 - CFD: 04/01/2012 - 19:58:57 - [] ----D C:\Program Files\Common Files\System
O43 - CFD: 23/09/2013 - 14:44:09 - [] ----D C:\Program Files\Common Files\Tom Sawyer Software
O43 - CFD: 07/01/2011 - 14:58:54 - [] ----D C:\Program Files\Common Files\Windows Live
O43 - CFD: 30/05/2013 - 16:33:17 - [] ----D C:\Program Files\Common Files\Wise Installation Wizard
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
O43 - CFD: 30/07/2014 - 20:12:45 - [] ----D C:\ProgramData\Adobe
O43 - CFD: 28/02/2011 - 22:22:21 - [0] ----D C:\ProgramData\ALM
O43 - CFD: 27/10/2012 - 13:10:01 - [] ----D C:\ProgramData\Apple
O43 - CFD: 27/10/2012 - 13:10:36 - [] ----D C:\ProgramData\Apple Computer
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Application Data
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Bureau
O43 - CFD: 25/09/2011 - 22:32:17 - [] ----D C:\ProgramData\Canneverbe Limited
O43 - CFD: 01/02/2011 - 10:06:18 - [] --H-D C:\ProgramData\CanonBJ
O43 - CFD: 30/01/2014 - 16:19:41 - [] --H-D C:\ProgramData\CanonIJScan
O43 - CFD: 09/04/2013 - 08:25:17 - [] ----D C:\ProgramData\Citrix
O43 - CFD: 05/02/2011 - 11:48:10 - [] ----D C:\ProgramData\Creative
O43 - CFD: 17/01/2012 - 16:46:30 - [] ----D C:\ProgramData\CyberLink
O43 - CFD: 23/09/2013 - 14:36:26 - [] ----D C:\ProgramData\DAEMON Tools Lite =>.DT Soft Ltd
O43 - CFD: 23/08/2012 - 11:22:11 - [] ----D C:\ProgramData\Dell
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Documents
O43 - CFD: 07/01/2011 - 14:49:20 - [] ----D C:\ProgramData\Downloaded Installations
O43 - CFD: 06/01/2015 - 15:10:21 - [] ----D C:\ProgramData\ESRI
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Favoris
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Favorites
O43 - CFD: 23/09/2013 - 14:57:18 - [] ----D C:\ProgramData\FLEXnet
O43 - CFD: 25/03/2011 - 21:26:10 - [0] ----D C:\ProgramData\Guitar Pro 6
O43 - CFD: 07/01/2011 - 14:49:33 - [] ----D C:\ProgramData\Macrovision
O43 - CFD: 19/08/2014 - 07:39:24 - [] ----D C:\ProgramData\Malwarebytes
O43 - CFD: 16/11/2012 - 19:40:59 - [] ----D C:\ProgramData\McAfee
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Menu Démarrer
O43 - CFD: 10/12/2014 - 10:25:17 - [] -S--D C:\ProgramData\Microsoft
O43 - CFD: 15/04/2015 - 19:07:22 - [] ----D C:\ProgramData\Microsoft Help
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Modèles
O43 - CFD: 04/05/2012 - 08:23:01 - [] ----D C:\ProgramData\Mozilla
O43 - CFD: 10/05/2015 - 10:49:12 - [] ----D C:\ProgramData\Nero
O43 - CFD: 01/02/2015 - 19:27:18 - [] ----D C:\ProgramData\Oracle
O43 - CFD: 01/04/2015 - 15:56:47 - [] ----D C:\ProgramData\PC-Doctor for Windows
O43 - CFD: 07/05/2015 - 18:06:46 - [] ----D C:\ProgramData\PCDr
O43 - CFD: 07/01/2011 - 14:57:48 - [] ----D C:\ProgramData\PhotoShow Shared Assets
O43 - CFD: 24/10/2013 - 08:34:45 - [] --H-D C:\ProgramData\RICOH_DRV
O43 - CFD: 07/01/2011 - 14:57:48 - [] ----D C:\ProgramData\Roxio
O43 - CFD: 03/03/2014 - 12:04:03 - [] ----D C:\ProgramData\Samsung
O43 - CFD: 02/05/2015 - 08:11:28 - [] ----D C:\ProgramData\Skype
O43 - CFD: 16/06/2011 - 21:14:34 - [] ----D C:\ProgramData\Skype Extras
O43 - CFD: 11/05/2015 - 07:47:22 - [] ----D C:\ProgramData\Sonic
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Start Menu
O43 - CFD: 07/01/2011 - 14:42:45 - [] ----D C:\ProgramData\Sun
O43 - CFD: 05/05/2015 - 13:48:55 - [] ----D C:\ProgramData\SupportAssistAgent
O43 - CFD: 07/01/2011 - 14:51:06 - [] ----D C:\ProgramData\Temp
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Templates
O43 - CFD: 30/05/2013 - 16:36:06 - [] ----D C:\ProgramData\Thomson.ResearchSoft.Installers
O43 - CFD: 07/01/2011 - 14:58:36 - [] ----D C:\ProgramData\Uninstall
O43 - CFD: 12/03/2015 - 15:04:58 - [] --H-D C:\ProgramData\{6AACA38B-2810-4B47-BDEC-D7A1F38B1531}
O43 - CFD: 23/09/2013 - 18:48:51 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
O43 - CFD: 10/05/2015 - 12:49:29 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 14/07/2009 - 06:46:36 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 28/02/2011 - 22:24:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS4
O43 - CFD: 05/10/2011 - 21:22:25 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antidote
O43 - CFD: 23/09/2013 - 14:48:04 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcGIS
O43 - CFD: 04/11/2012 - 20:30:57 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG5200 series
O43 - CFD: 07/01/2011 - 15:10:41 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 9.5
O43 - CFD: 01/04/2015 - 15:56:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
O43 - CFD: 07/01/2011 - 14:52:26 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Webcam
O43 - CFD: 07/01/2011 - 14:47:42 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DW WLAN
O43 - CFD: 30/05/2013 - 16:35:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EndNote
O43 - CFD: 07/01/2011 - 07:38:55 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 19/12/2013 - 13:12:21 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth =>.Google Inc
O43 - CFD: 30/05/2014 - 17:24:55 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IRIScan Direct
O43 - CFD: 02/06/2013 - 16:57:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
O43 - CFD: 01/02/2015 - 19:25:18 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 14/07/2009 - 06:42:30 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 08/05/2015 - 12:02:07 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
O43 - CFD: 13/09/2013 - 17:40:09 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O43 - CFD: 24/07/2014 - 11:37:55 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
O43 - CFD: 07/01/2011 - 14:58:20 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio Creator Starter
O43 - CFD: 08/10/2014 - 07:41:49 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 16/11/2012 - 22:41:05 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 14/07/2009 - 11:00:22 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 07/01/2011 - 15:02:54 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
O43 - CFD: 15/04/2014 - 08:21:40 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView
O43 - CFD: 15/01/2011 - 22:02:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
O43 - CFD: 04/07/2013 - 18:36:20 - [] ----D C:\Users\Amaury\AppData\Roaming\Adobe
O43 - CFD: 27/10/2012 - 13:12:04 - [] ----D C:\Users\Amaury\AppData\Roaming\Apple Computer
O43 - CFD: 25/09/2011 - 22:32:17 - [] ----D C:\Users\Amaury\AppData\Roaming\Canneverbe Limited
O43 - CFD: 30/01/2014 - 16:19:41 - [] ----D C:\Users\Amaury\AppData\Roaming\Canon
O43 - CFD: 12/01/2011 - 14:04:06 - [] ----D C:\Users\Amaury\AppData\Roaming\Creative
O43 - CFD: 17/01/2012 - 16:46:29 - [] ----D C:\Users\Amaury\AppData\Roaming\CyberLink
O43 - CFD: 15/11/2013 - 08:39:56 - [] ----D C:\Users\Amaury\AppData\Roaming\DAEMON Tools Lite =>.DT Soft Ltd
O43 - CFD: 24/03/2011 - 09:54:04 - [] ----D C:\Users\Amaury\AppData\Roaming\Dell
O43 - CFD: 12/01/2011 - 14:04:02 - [] ----D C:\Users\Amaury\AppData\Roaming\DigitalPersona
O43 - CFD: 05/09/2011 - 09:51:28 - [] ----D C:\Users\Amaury\AppData\Roaming\Druide
O43 - CFD: 16/05/2014 - 10:40:34 - [] ----D C:\Users\Amaury\AppData\Roaming\EndNote
O43 - CFD: 23/09/2013 - 15:04:14 - [] ----D C:\Users\Amaury\AppData\Roaming\ESRI
O43 - CFD: 25/03/2011 - 22:10:49 - [] ----D C:\Users\Amaury\AppData\Roaming\Guitar Pro 6
O43 - CFD: 12/01/2011 - 14:03:44 - [] ----D C:\Users\Amaury\AppData\Roaming\Identities
O43 - CFD: 15/01/2011 - 18:01:02 - [] ----D C:\Users\Amaury\AppData\Roaming\Macromedia
O43 - CFD: 12/01/2011 - 21:28:33 - [] ----D C:\Users\Amaury\AppData\Roaming\Macrovision
O43 - CFD: 19/08/2014 - 07:39:37 - [0] ----D C:\Users\Amaury\AppData\Roaming\Malwarebytes
O43 - CFD: 14/07/2009 - 11:00:22 - [0] ----D C:\Users\Amaury\AppData\Roaming\Media Center Programs
O43 - CFD: 06/01/2014 - 16:31:05 - [0] ----D C:\Users\Amaury\AppData\Roaming\Media Player Classic
O43 - CFD: 31/01/2015 - 17:38:39 - [] -S--D C:\Users\Amaury\AppData\Roaming\Microsoft
O43 - CFD: 15/01/2011 - 21:25:03 - [] ----D C:\Users\Amaury\AppData\Roaming\Mozilla
O43 - CFD: 27/06/2013 - 21:48:54 - [] ----D C:\Users\Amaury\AppData\Roaming\Nero
O43 - CFD: 16/07/2014 - 12:04:25 - [] ----D C:\Users\Amaury\AppData\Roaming\PCDr
O43 - CFD: 10/12/2011 - 18:47:36 - [0] ----D C:\Users\Amaury\AppData\Roaming\QuickScan
O43 - CFD: 05/02/2011 - 11:48:10 - [] ----D C:\Users\Amaury\AppData\Roaming\Reallusion
O43 - CFD: 12/01/2011 - 14:04:11 - [] ----D C:\Users\Amaury\AppData\Roaming\Roxio
O43 - CFD: 15/01/2011 - 15:47:29 - [] ----D C:\Users\Amaury\AppData\Roaming\Roxio Burn
O43 - CFD: 11/05/2015 - 08:00:01 - [] ----D C:\Users\Amaury\AppData\Roaming\Skype
O43 - CFD: 19/06/2011 - 11:48:17 - [] ----D C:\Users\Amaury\AppData\Roaming\skypePM
O43 - CFD: 05/05/2015 - 13:40:24 - [] ----D C:\Users\Amaury\AppData\Roaming\Spotify
O43 - CFD: 21/02/2011 - 12:15:29 - [] ----D C:\Users\Amaury\AppData\Roaming\WinRAR
O43 - CFD: 15/04/2014 - 08:27:51 - [] ----D C:\Users\Amaury\AppData\Roaming\XnView
O43 - CFD: 11/05/2015 - 08:08:16 - [] ----D C:\Users\Amaury\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 05/04/2015 - 11:25:56 - [0] ----D C:\Users\Amaury\AppData\Local\._LiveCode_
O43 - CFD: 28/02/2011 - 22:36:33 - [] ----D C:\Users\Amaury\AppData\Local\Adobe
O43 - CFD: 27/10/2012 - 13:10:04 - [] ----D C:\Users\Amaury\AppData\Local\Apple
O43 - CFD: 27/10/2012 - 13:11:31 - [] ----D C:\Users\Amaury\AppData\Local\Apple Computer
O43 - CFD: 12/01/2011 - 13:59:20 - [] -SH-D C:\Users\Amaury\AppData\Local\Application Data
O43 - CFD: 02/01/2014 - 16:32:12 - [] ----D C:\Users\Amaury\AppData\Local\Apps
O43 - CFD: 12/01/2011 - 14:04:08 - [] ----D C:\Users\Amaury\AppData\Local\Broadcom
O43 - CFD: 09/04/2013 - 08:24:41 - [] ----D C:\Users\Amaury\AppData\Local\Citrix
O43 - CFD: 17/01/2012 - 16:46:31 - [] ----D C:\Users\Amaury\AppData\Local\Cyberlink
O43 - CFD: 02/01/2014 - 18:29:19 - [0] ----D C:\Users\Amaury\AppData\Local\Deployment
O43 - CFD: 12/01/2011 - 14:04:02 - [] ----D C:\Users\Amaury\AppData\Local\DigitalPersona
O43 - CFD: 19/11/2014 - 21:12:56 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieBrowserModeList
O43 - CFD: 17/04/2014 - 18:45:42 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieSiteList
O43 - CFD: 17/04/2014 - 18:45:42 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieUserList
O43 - CFD: 01/02/2015 - 16:39:39 - [] ----D C:\Users\Amaury\AppData\Local\ESRI
O43 - CFD: 10/12/2011 - 20:55:23 - [] ----D C:\Users\Amaury\AppData\Local\Google
O43 - CFD: 12/01/2011 - 13:59:20 - [] -SH-D C:\Users\Amaury\AppData\Local\Historique
O43 - CFD: 24/06/2012 - 09:00:00 - [] ----D C:\Users\Amaury\AppData\Local\Macromedia
O43 - CFD: 06/05/2015 - 16:15:23 - [] ----D C:\Users\Amaury\AppData\Local\Microsoft
O43 - CFD: 12/02/2011 - 20:35:39 - [] ----D C:\Users\Amaury\AppData\Local\Microsoft Games
O43 - CFD: 13/03/2011 - 22:36:40 - [0] ----D C:\Users\Amaury\AppData\Local\Microsoft Help
O43 - CFD: 19/09/2013 - 21:20:36 - [] ----D C:\Users\Amaury\AppData\Local\Mozilla
O43 - CFD: 10/12/2011 - 16:51:20 - [0] ----D C:\Users\Amaury\AppData\Local\pcnrqyro
O43 - CFD: 11/01/2013 - 12:01:16 - [] ----D C:\Users\Amaury\AppData\Local\Programs
O43 - CFD: 27/02/2014 - 10:59:08 - [] ----D C:\Users\Amaury\AppData\Local\Skype
O43 - CFD: 05/05/2015 - 13:40:25 - [] ----D C:\Users\Amaury\AppData\Local\Spotify
O43 - CFD: 11/05/2015 - 08:06:26 - [] ----D C:\Users\Amaury\AppData\Local\Temp
O43 - CFD: 12/01/2011 - 13:59:20 - [] -SH-D C:\Users\Amaury\AppData\Local\Temporary Internet Files
O43 - CFD: 12/01/2011 - 13:59:21 - [0] ----D C:\Users\Amaury\AppData\Local\VirtualStore
O43 - CFD: 08/06/2012 - 20:12:30 - [] ----D C:\Users\Amaury\AppData\Local\Western Digital
O43 - CFD: 14/07/2009 - 06:42:04 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 12/03/2015 - 07:43:42 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 05/10/2011 - 21:15:20 - [0] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antidote
O43 - CFD: 14/07/2009 - 06:37:42 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 10/02/2012 - 09:38:05 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft ICE
O43 - CFD: 06/01/2014 - 14:08:21 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Périphériques Bluetooth
O43 - CFD: 05/02/2011 - 11:29:22 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Satsuki Decoder Pack
O43 - CFD: 12/03/2015 - 07:43:42 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 25/03/2011 - 22:12:44 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TuxGuitar 1.2
~ Program Folder: 254 Scanned in 00mn 01s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.C16DFA9241F3CE8867E7EA8806B8F5DD] - 08/05/2015 - 08:31:05 ---A- . (...) -- C:\Windows\Antidote.ini [143]
O44 - LFC:[MD5.3C21F7E95FFCA33EF1A83AA33D9663CF] - 08/05/2015 - 11:01:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23256]
O44 - LFC:[MD5.155BF99B2B87E0C298CAC3B4B8136D83] - 08/05/2015 - 11:01:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [92888]
O44 - LFC:[MD5.167BCE00050B19DA25065335645A3C7A] - 08/05/2015 - 11:01:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [51928]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 08/05/2015 - 16:21:07 ---A- . (...) -- C:\Windows\setuperr.log [0]
O44 - LFC:[MD5.6446B430C5715E693545FC52D2746D3D] - 08/05/2015 - 18:09:31 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512]
O44 - LFC:[MD5.6B12A07D3C6AFD4A3219AF5FDE01DAFB] - 09/05/2015 - 07:11:51 ---A- . (...) -- C:\Windows\PFRO.log [2746]
O44 - LFC:[MD5.C489D8B4D8C64F20CC75A93F541F7D91] - 10/05/2015 - 09:32:24 ---A- . (.Microsoft Corporation - Exécuteur de file d'attente d'opérations pr.) -- C:\Windows\System32\poqexec.exe [123904]
O44 - LFC:[MD5.744AB3C1A73A57DEED49D631F1BDEA1D] - 10/05/2015 - 09:33:12 ---A- . (.Microsoft Corporation - Extension de l'environnement des appareils.) -- C:\Windows\System32\wpdshext.dll [2311168]
O44 - LFC:[MD5.F7F135F7702E0FB3EFE89283E2BE2EBB] - 10/05/2015 - 09:34:20 ---A- . (.Microsoft Corporation - API du Gestionnaire de fenêtres du Bureau M.) -- C:\Windows\System32\dwmapi.dll [67584]
O44 - LFC:[MD5.B01B8C949EDEC1B8A856E3056BDA7C42] - 10/05/2015 - 09:34:20 ---A- . (.Microsoft Corporation - Bibliothèque principale du Gestionnaire de.) -- C:\Windows\System32\dwmcore.dll [1372160]
O44 - LFC:[MD5.A5FE03D57097A45B8E7A4A09C9B78695] - 10/05/2015 - 09:38:35 ---A- . (.Microsoft Corporation - Client ActiveX des services Bureau à distan.) -- C:\Windows\System32\mstscax.dll [5698048]
O44 - LFC:[MD5.4676AAA9DDF52A50C829FEDB4EA81E54] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Connexion Bureau à distance.) -- C:\Windows\System32\mstsc.exe [1068544]
O44 - LFC:[MD5.AF40D823F3B03C7899AEF2293F84D0D7] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Proxy.) -- C:\Windows\System32\TSWbPrxy.exe [76288]
O44 - LFC:[MD5.5E676B296B762E211D83B87635F2C330] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Remote Desktop Services Client for Microsof.) -- C:\Windows\System32\rdvidcrl.dll [855552]
O44 - LFC:[MD5.0FC6922517964E9D90DE84DC86F63E40] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Runtime de connexion RemoteApp et Bureau à.) -- C:\Windows\System32\wksprt.exe [350208]
O44 - LFC:[MD5.8DEEE20D8D30E9B0FBDCA31E58A027BD] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - Client de contrainte de quarantaine de la p.) -- C:\Windows\System32\tsgqec.dll [53248]
O44 - LFC:[MD5.A90F47CDCC0898733596B5070039FC15] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - Extension de stratégie de groupe pour la re.) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll [14336]
O44 - LFC:[MD5.2EFB1279E7BEA7D12D9F4D6508D27880] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Acces.) -- C:\Windows\System32\MsRdpWebAccess.dll [50176]
O44 - LFC:[MD5.AB5EFB103DB01C1912C9D2F545EA5621] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - WorkspaceRuntime ProxyStub DLL.) -- C:\Windows\System32\wksprtPS.dll [17920]
O44 - LFC:[MD5.C6A5FBD4977305E1FA23E02C042DB463] - 10/05/2015 - 09:38:38 ---A- . (.Microsoft Corporation - Pilote de filtre pour concentrateur USB du.) -- C:\Windows\System32\Drivers\TsUsbFlt.sys [49152]
O44 - LFC:[MD5.D60E27D4BD5A91FCD17D2CB27F86738E] - 10/05/2015 - 09:38:38 ---A- . (.Microsoft Corporation - Remote Desktop USB Redirection GP Extension.) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe [12800]
O44 - LFC:[MD5.F37167FCDB661FD4B54CAD4755ABDD61] - 10/05/2015 - 09:38:40 ---A- . (.Microsoft Corporation - Co-installateur de pilote USB générique du.) -- C:\Windows\System32\TsUsbGDCoInstaller.dll [32256]
O44 - LFC:[MD5.4FBED1107021D7405721CE55975F2C96] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1677370]
O44 - LFC:[MD5.5C81CFC2FA1D69A7B165951D1051F889] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfc009.dat [123196]
O44 - LFC:[MD5.46261007C0E5F58CB875F4AF71763ADB] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [151280]
O44 - LFC:[MD5.1034469ABB736466148909A6EE82C0C8] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfh009.dat [657384]
O44 - LFC:[MD5.2EE8285A8B6D443F9003E8531357C0C8] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [750666]
O44 - LFC:[MD5.BA63FDF7785E75B60B3D958D4B381DB3] - 10/05/2015 - 16:44:33 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [2448648]
O44 - LFC:[MD5.7FB275E0AF83B9ED8CC13F643D8DEE2A] - 11/05/2015 - 07:02:29 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.FD7E6F9DCCD7FEEBDD6E8D3F14AD24F8] - 11/05/2015 - 07:02:32 ---A- . (...) -- C:\Windows\setupact.log [392]
O44 - LFC:[MD5.04B309A1A653177994630C2773E659F1] - 11/05/2015 - 07:03:37 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [119512]
O44 - LFC:[MD5.64E95965FA54CE5B4A4E8EFEFD239125] - 11/05/2015 - 07:06:06 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1113249]
O44 - LFC:[MD5.47DE8B7A482D4BABBCC70C0199E35881] - 27/04/2015 - 19:00:30 ---A- . (.Microsoft Corporation - Microsoft Windows Diagnostics Tracking.) -- C:\Windows\System32\UtcResources.dll [36864]
O44 - LFC:[MD5.86B2AC15999BB4F8B5C84AB6154A1783] - 27/04/2015 - 19:59:36 ---A- . (.Microsoft Corporation - DLL du schéma d'audit de sécurité.) -- C:\Windows\System32\adtschema.dll [686080]
O44 - LFC:[MD5.9638DA21E965E23C85C4319F3F66D824] - 27/04/2015 - 19:59:41 ---A- . (.Microsoft Corporation - ApiSet Schema DLL.) -- C:\Windows\System32\apisetschema.dll [6656]
O44 - LFC:[MD5.D079A408CC3E22A09D1260A6F18FC0FD] - 27/04/2015 - 20:01:22 ---A- . (.Microsoft Corporation - DLL des événements d'audit de la sécurité.) -- C:\Windows\System32\msaudite.dll [146432]
O44 - LFC:[MD5.BF9BB4113E9FCDABD4C703DDD06293F3] - 27/04/2015 - 20:01:33 ---A- . (.Microsoft Corporation - Nom d'audit des objets système.) -- C:\Windows\System32\msobjs.dll [60416]
O44 - LFC:[MD5.AFFE5747054D03F8CEE18A8518A9AA34] - 27/04/2015 - 20:03:52 ---A- . (.Microsoft Corporation - Programme de stratégie d'audit.) -- C:\Windows\System32\auditpol.exe [50176]
O44 - LFC:[MD5.F286528898342F0F1EB402606750C391] - 27/04/2015 - 20:03:58 ---A- . (.Microsoft Corporation - Utilitaire de configuration des performance.) -- C:\Windows\System32\diskperf.exe [17408]
O44 - LFC:[MD5.C6D2D384B6232B0B800234C03C50979F] - 27/04/2015 - 20:04:04 ---A- . (.Microsoft Corporation - Utilitaire d'enregistrement des Performance.) -- C:\Windows\System32\logman.exe [82944]
O44 - LFC:[MD5.1667D76FBF42B24B9DE3E8B0A7CF06BE] - 27/04/2015 - 20:04:05 ---A- . (.Microsoft Corporation - Local Security Authority Process.) -- C:\Windows\System32\lsass.exe [22528]
O44 - LFC:[MD5.97B30711DC6CA0EA4EACEDCE8080A3B4] - 27/04/2015 - 20:04:12 ---A- . (.Microsoft Corporation - Utilitaire de réenregistrement de Performan.) -- C:\Windows\System32\relog.exe [37888]
O44 - LFC:[MD5.7E9A03C1B76CB8A222C9AB232B3118D9] - 27/04/2015 - 20:04:14 ---A- . (.Microsoft Corporation - Restauration du système de Microsoft® Windo.) -- C:\Windows\System32\rstrui.exe [262656]
O44 - LFC:[MD5.03CD13A169C19558F637C2F36B974BDA] - 27/04/2015 - 20:04:21 ---A- . (.Microsoft Corporation - Gestionnaire de sessions Windows.) -- C:\Windows\System32\smss.exe [69632]
O44 - LFC:[MD5.74C0EC1257698176E288DA282F318E1C] - 27/04/2015 - 20:04:24 ---A- . (.Microsoft Corporation - Moniteur de performance de la ligne de comm.) -- C:\Windows\System32\typeperf.exe [40448]
O44 - LFC:[MD5.EB058143B57ED460AC4F2DFBA104BBFF] - 27/04/2015 - 20:04:24 ---A- . (.Microsoft Corporation - Outil de rapport de suivi d'événements.) -- C:\Windows\System32\tracerpt.exe [364544]
O44 - LFC:[MD5.7A5824DC9A85FCE4334F57FF0795853E] - 27/04/2015 - 20:04:33 ---A- . (.Microsoft Corporation - API avancées Windows 32.) -- C:\Windows\System32\advapi32.dll [641536]
O44 - LFC:[MD5.79AF005633B7E41B7A194A7E7B9D3D93] - 27/04/2015 - 20:04:37 ---A- . (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll [17408]
O44 - LFC:[MD5.5DCF39695CD614B162330F5AC27C4654] - 27/04/2015 - 20:04:37 ---A- . (.Microsoft Corporation - Processus d'exécution client-serveur.) -- C:\Windows\System32\csrsrv.dll [38912]
O44 - LFC:[MD5.54A01CC4BC47B31C5CD082D064AB37BC] - 27/04/2015 - 20:04:45 ---A- . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll [550912]
O44 - LFC:[MD5.D362BFE84A44A442CB6B8CBFE6DE027D] - 27/04/2015 - 20:04:47 ---A- . (.Microsoft Corporation - DLL serveur LSA.) -- C:\Windows\System32\lsasrv.dll [1061376]
O44 - LFC:[MD5.66D6A06936088E412E29A182679F0D71] - 27/04/2015 - 20:05:11 ---A- . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll [259584]
O44 - LFC:[MD5.0B6E937863837BA3383E9CE9200DDF1E] - 27/04/2015 - 20:05:17 ---A- . (.Microsoft Corporation - Bibliothèque de chiffrement Windows.) -- C:\Windows\System32\ncrypt.dll [221184]
O44 - LFC:[MD5.C34E0F9846D0FF902CED82DB5AB104BA] - 27/04/2015 - 20:05:28 ---A- . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll [248832]
O44 - LFC:[MD5.8C45A65ED20B487085B79EEFCC08D160] - 27/04/2015 - 20:05:29 ---A- . (.Microsoft Corporation - Host for SCM/SDDL/LSA Lookup APIs.) -- C:\Windows\System32\sechost.dll [92160]
O44 - LFC:[MD5.99A508910BB06DFBE99D9AF7D6B4E950] - 27/04/2015 - 20:05:29 ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\secur32.dll [22016]
O44 - LFC:[MD5.7CC0547B9FD90649731E021DA2763086] - 27/04/2015 - 20:05:32 ---A- . (.Microsoft Corporation - Bibliothèque principale de Restauration du.) -- C:\Windows\System32\srcore.dll [400896]
O44 - LFC:[MD5.ABA025664F9F42C568B2C022AADCB18F] - 27/04/2015 - 20:05:32 ---A- . (.Microsoft Corporation - Microsoft® Windows System Restore Client Li.) -- C:\Windows\System32\srclient.dll [43008]
O44 - LFC:[MD5.ECB7366ED80E349436FC495A77EAF24C] - 27/04/2015 - 20:05:33 ---A- . (.Microsoft Corporation - LSA SSPI RPC interface DLL.) -- C:\Windows\System32\sspisrv.dll [15872]
O44 - LFC:[MD5.6C427298E65C1430D232A0529ED9B18E] - 27/04/2015 - 20:05:33 ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\sspicli.dll [100352]
O44 - LFC:[MD5.D0F574320615303ADECDCB452EBB8930] - 27/04/2015 - 20:05:34 ---A- . (.Microsoft Corporation - Bibliothèque de l'application auxiliaire de.) -- C:\Windows\System32\tdh.dll [635392]
O44 - LFC:[MD5.FCB1C8345C794FE89ABA03B4CA3131BB] - 27/04/2015 - 20:05:35 ---A- . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\TSpkg.dll [65536]
O44 - LFC:[MD5.E95DE5B790B2D16706DAC8472E51F31A] - 27/04/2015 - 20:05:39 ---A- . (.Microsoft Corporation - Microsoft Windows Diagnostics Tracking.) -- C:\Windows\System32\diagtrack.dll [851456]
O44 - LFC:[MD5.850F756363237A2EB069B9B25EF8BEC3] - 27/04/2015 - 20:05:40 ---A- . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll [172032]
O44 - LFC:[MD5.7410C9F088E4F13C981F981B52475B5E] - 27/04/2015 - 20:08:02 ---A- . (.Microsoft Corporation - DLL Couche NT.) -- C:\Windows\System32\ntdll.dll [1307648]
O44 - LFC:[MD5.6DD2A1064DD8AFBED22E71176E2AF59B] - 27/04/2015 - 20:11:53 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecdd.sys [67520]
O44 - LFC:[MD5.76C0D35167B1369C68388FEDB56A3048] - 27/04/2015 - 20:11:53 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecpkg.sys [137664]
O44 - LFC:[MD5.8D50ED3F0FBE3590AB0D43BF7B60E57A] - 27/04/2015 - 20:11:54 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntkrnlpa.exe [3989440]
O44 - LFC:[MD5.0A66C88B087249742381924AB8F9EFCC] - 27/04/2015 - 20:11:55 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntoskrnl.exe [3934144]
~ Files: 70 Scanned in 00mn 17s
---\\ Déni du service (Local Security Authority) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l'Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Notification Packages . (.DigitalPersona, Inc. - DPPwdFlt Module.) -- C:\Windows\System32\DPPWDFLT.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corp. - LiveSSP.) -- C:\Windows\System32\livessp.dll
~ LSA: 10 Scanned in 00mn 00s
---\\ Contrôle du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d'extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d'extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
~ CSB: 13 Scanned in 00mn 00s
---\\ Clé de registre Shell MountPoints2 (MPSK) (O51)
O51 - MPSK:{30236676-b194-11e1-8151-f04da2c023f1}\AutoRun\command. (...) -- E:\unlock.exe (.not file.)
O51 - MPSK:{74702b01-b586-11e3-ba34-f04da2c023f1}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)
O51 - MPSK:{d22ae3b2-20ad-11e0-a6a7-f04da2c023f1}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)
~ Keys: Scanned in 00mn 00s
---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll
O52 - TDSD: \Drivers32\"vidc.XVID"="xvidvfw.dll" . (...) -- C:\Windows\System32\xvidvfw.dll
O52 - TDSD: \Drivers32\"vidc.ffds"="ff_vfw.dll" . (...) -- C:\Windows\System32\ff_vfw.dll
O52 - TDSD: \Drivers32\"msacm.vorbis"="vorbis.acm" . (.HMS http://hp.vector.co.jp/authors/VA012897 - Ogg Vorbis CODEC for MSACM.) -- C:\Windows\System32\vorbis.acm
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"xvidvfw.dll"="Xvid MPEG-4 Video Codec" . (...) -- C:\Windows\System32\xvidvfw.dll
O52 - TDSD: \drivers.desc\"vorbis.acm"="Ogg Vorbis Audio CODEC, Based on Xiphophorus libVorbis I 20010910" . (.HMS http://hp.vector.co.jp/authors/VA012897 - Ogg Vorbis CODEC for MSACM.) -- C:\Windows\System32\vorbis.acm
~ TDSD: 8 Scanned in 00mn 00s
---\\ Enumération des clés de registre StartupReg (SMSR) (O53)
O53 - SMSR:HKLM\...\startupreg\AdobeBridge [Key] . (.Adobe Systems, Inc. - Adobe Bridge.) -- C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe =>.Adobe Systems Incorporated
O53 - SMSR:HKLM\...\startupreg\APSDaemon [Key] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
O53 - SMSR:HKLM\...\startupreg\CCleaner Monitoring [Key] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
O53 - SMSR:HKLM\...\startupreg\iTunesHelper [Key] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
O53 - SMSR:HKLM\...\startupreg\Skype [Key] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O53 - SMSR:HKLM\...\startupreg\Spotify Web Helper [Key] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe
~ SMSR Keys: 6 Scanned in 00mn 01s
---\\ Enumération des clés de registre SecurityProviders (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
~ MSCP: 2 Scanned in 00mn 00s
---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=0
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Scanned in 00mn 00s
---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145
~ MWPE Keys: 1 Scanned in 00mn 00s
---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:03/12/2009 - 07:24:38 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\System32\Drivers\Acceler.sys [41648]
O58 - SDL:29/09/2010 - 17:38:00 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\System32\Drivers\Accelern.sys [43888]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976]
O58 - SDL:14/07/2009 - 02:26:17 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [297552]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\Drivers\adpu320.sys [146512]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [14400]
O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [80256]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows fa.) -- C:\Windows\System32\Drivers\amdsbs.sys [159312]
O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [22400]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [76368]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [86608]
O58 - SDL:15/07/2011 - 16:11:46 ---A- . (.BitDefender - BitDefender AntiVirus Active Virus Control Hypervisor driver.) -- C:\Windows\System32\Drivers\avchv.sys [240184]
O58 - SDL:01/09/2011 - 11:15:08 ---A- . (.BitDefender - Active Virus Control Kernel Filtering driver.) -- C:\Windows\System32\Drivers\avckf.sys [454960]
O58 - SDL:13/07/2009 - 23:02:49 ---A- . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gigabit Ethernet..) -- C:\Windows\System32\Drivers\b57nd60x.sys [229888]
O58 - SDL:07/01/2011 - 13:47:17 ---A- . (.Broadcom Corporation - Broadcom iLine10(tm) PCI Network Adapter Proxy Protocol Driver.) -- C:\Windows\System32\Drivers\bcm42rly.sys [18424]
O58 - SDL:05/05/2010 - 20:28:38 ---A- . (.Broadcom Corporation - Broadcom 802.11 Network Adapter wireless driver.) -- C:\Windows\System32\Drivers\BCMWL6.SYS [2707448]
O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [13568]
O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [5248]
O58 - SDL:14/07/2009 - 01:57:25 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [272128]
O58 - SDL:13/07/2009 - 23:53:32 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [62336]
O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [12160]
O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [11904]
O58 - SDL:03/10/2009 - 06:24:12 ---A- . (.Broadcom Corporation. - Bluetooth Audio Device.) -- C:\Windows\System32\Drivers\btwaudio.sys [86056]
O58 - SDL:29/08/2009 - 03:15:16 ---A- . (.Broadcom Corporation. - Broadcom Bluetooth AVDT Service.) -- C:\Windows\System32\Drivers\btwavdt.sys [108072]
O58 - SDL:07/04/2009 - 23:32:50 ---A- . (.Broadcom Corporation. - Broadcom Bluetooth L2CAP Service.) -- C:\Windows\System32\Drivers\btwl2cap.sys [29472]
O58 - SDL:29/08/2009 - 03:15:12 ---A- . (.Broadcom Corporation. - Bluetooth Remote Control HID Minidriver.) -- C:\Windows\System32\Drivers\btwrchid.sys [18472]
O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbdx.sys [430080]
O58 - SDL:20/10/2009 - 10:00:00 ---A- . (.Sonic Solutions - CDR4 CD and DVD Place Holder Driver (see PxHelp).) -- C:\Windows\System32\Drivers\cdr4_xp.sys [9072]
O58 - SDL:20/10/2009 - 10:00:00 ---A- . (.Sonic Solutions - CDRAL Place Holder Driver (see PxHelp).) -- C:\Windows\System32\Drivers\cdralw2k.sys [9200]
O58 - SDL:14/07/2009 - 02:26:21 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [15952]
O58 - SDL:28/05/2009 - 17:48:20 ---A- . (.Creative Technology Ltd. - Advanced Audio FX Driver.) -- C:\Windows\System32\Drivers\CtAudDrv.sys [134144]
O58 - SDL:12/08/2010 - 17:50:20 ---A- . (.Creative Technology Ltd. - Video Class Upper Filter Driver.) -- C:\Windows\System32\Drivers\CtClsFlt.sys [146528]
O58 - SDL:30/01/2015 - 23:36:11 ---A- . (.Dell Computer Corporation - DDDriver.sys.) -- C:\Windows\System32\Drivers\DDDriver32Dcsa.sys [20688]
O58 - SDL:30/01/2015 - 23:36:11 ---A- . (.Dell Computer Corporation - DellProf.sys.) -- C:\Windows\System32\Drivers\DellProf.sys [19984]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\Drivers\djsvs.sys [70720]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712]
O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbdx.sys [3100160]
O58 - SDL:21/08/2012 - 12:01:22 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys [26840]
O58 - SDL:13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624]
O58 - SDL:17/09/2009 - 21:54:14 ---A- . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\Drivers\HECI.sys [41088]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [67152]
O58 - SDL:04/03/2010 - 19:33:26 ---A- . (.Intel Corporation - Intel Rapid Storage Technology driver - x86.) -- C:\Windows\System32\Drivers\iaStor.sys [435736]
O58 - SDL:11/03/2011 - 06:38:51 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332160]
O58 - SDL:26/08/2010 - 12:31:30 ---A- . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\Drivers\igdkmd32.sys [9024512]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [41040]
O58 - SDL:27/02/2010 - 16:31:24 ---A- . (.Intel Corporation - Intel(R) Turbo Boost Technology Driver.) -- C:\Windows\System32\Drivers\Impcd.sys [132480]
O58 - SDL:31/08/2010 - 04:15:56 ---A- . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\Drivers\IntcDAud.sys [247808]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [95824]
O58 - SDL:14/07/2009 - 02:20:37 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [89168]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [54864]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [96848]
O58 - SDL:14/04/2015 - 08:37:42 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23256]
O58 - SDL:14/04/2015 - 08:37:44 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [92888]
O58 - SDL:11/05/2015 - 07:03:37 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [119512]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7 for x86.) -- C:\Windows\System32\Drivers\megasas.sys [30800]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [235584]
O58 - SDL:14/04/2015 - 08:37:54 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [51928]
O58 - SDL:14/07/2009 - 02:20:44 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [44624]
O58 - SDL:07/01/2011 - 13:47:18 ---A- . (.CACE Technologies, Inc. - npf.sys (NT5/6 x86) Kernel Driver.) -- C:\Windows\System32\Drivers\npf.sys [50704]
O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117120]
O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [143744]
O58 - SDL:19/03/2010 - 10:00:00 ---A- . (.Sonic Solutions - Px Engine Device Driver for Windows 2000/XP.) -- C:\Windows\System32\Drivers\pxhelp20.sys [45648]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1383488]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [106064]
O58 - SDL:10/06/2011 - 05:34:52 ---A- . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.20 32-bit Driver.) -- C:\Windows\System32\Drivers\Rt86win7.sys [394856]
O58 - SDL:10/08/2009 - 20:06:08 ---A- . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/Vista/Win7.) -- C:\Windows\System32\Drivers\RtsUStor.sys [171520]
O58 - SDL:13/07/2009 - 21:50:20 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [20480]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [40016]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [77888]
O58 - SDL:20/08/2010 - 18:04:38 ---A- . (.ST Microelectronics - Disk Class Filter Driver for Accelerometer.) -- C:\Windows\System32\Drivers\stdcfltn.sys [17648]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072]
O58 - SDL:07/04/2010 - 13:35:04 ---A- . (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\Drivers\stwrt.sys [423936]
O58 - SDL:08/01/2010 - 05:46:20 ---A- . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\Windows\System32\Drivers\SynTP.sys [232624]
O58 - SDL:14/07/2009 - 02:19:10 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [16976]
O58 - SDL:14/07/2009 - 02:19:11 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [141904]
O58 - SDL:13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672]
~ Drivers: 90 Scanned in 00mn 03s
---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 05/05/2015 - 08:09:04 ---A- . (.Microsoft Corporation.) -- C:\Users\Amaury\AppData\Roaming\Spotify\d3dcompiler_43.dll [2106424]
O61 - LFC: 05/05/2015 - 08:09:05 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\ffmpegsumo.dll [990776]
O61 - LFC: 05/05/2015 - 08:09:05 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\libEGL.dll [219192]
O61 - LFC: 05/05/2015 - 08:09:05 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\libGLESv2.dll [1365560]
O61 - LFC: 05/05/2015 - 08:09:05 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\libcef.dll [40518200]
O61 - LFC: 05/05/2015 - 08:09:05 ---A- . (.Microsoft Corporation.) -- C:\Users\Amaury\AppData\Roaming\Spotify\d3dcompiler_47.dll [3457592]
O61 - LFC: 05/05/2015 - 08:09:05 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\Spotify.exe [7168568]
O61 - LFC: 05/05/2015 - 08:09:06 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\wow_helper.exe [73272]
O61 - LFC: 05/05/2015 - 08:09:06 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyCrashService.exe [778808]
O61 - LFC: 05/05/2015 - 08:09:06 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyLauncher.exe [124472]
O61 - LFC: 05/05/2015 - 08:09:06 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920]
O61 - LFC: 08/05/2015 - 08:08:59 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Adobe\Acrobat\9.0\UserCache.bin [106533]
O61 - LFC: 08/05/2015 - 08:09:06 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\ZHP\ZHPCleaner.exe [1818624] =>.Nicolas Coolman
O61 - LFC: 08/05/2015 - 08:09:08 ---A- . (...) -- C:\Users\Amaury\Downloads\adwcleaner_4.203.exe [2204160]
O61 - LFC: 08/05/2015 - 08:09:09 ---A- . (...) -- C:\Users\Amaury\Downloads\ZHPCleaner.exe [1818624] =>.Nicolas Coolman
O61 - LFC: 09/05/2015 - 08:09:09 ---A- . (...) -- C:\Users\Amaury\Downloads\ZHPCleaner(1).exe [1820160] =>.Nicolas Coolman
~ 128 Fichiers temporaires (Temporary files)
~ 5 Fichiers cookies (Cookies files)
~ Files: 16 Scanned in 00mn 26s
---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s
---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - 07/01/2011 - C:\Windows\System32\drivers\BCM42RLY.sys (BCM42RLY) .(.Broadcom Corporation - Broadcom iLine10(tm) PCI Network Adapter Pr.) - LEGACY_BCM42RLY
O64 - Services: CurCS - 14/04/2015 - C:\Windows\system32\drivers\mbam.sys (MBAMProtector) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMPROTECTOR
O64 - Services: CurCS - 11/05/2015 - C:\Windows\system32\drivers\MBAMSwissArmy.sys (MBAMSwissArmy) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMSWISSARMY
O64 - Services: CurCS - 14/04/2015 - C:\Windows\system32\drivers\mwac.sys (MBAMWebAccessControl) .(.Malwarebytes Corporation - Malwarebytes Web Access Control.) - LEGACY_MBAMWEBACCESSCONTROL
O64 - Services: CurCS - 13/07/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV
~ Legacy: 119 Scanned in 00mn 00s
---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d'événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
~ FASS Keys: 10 Scanned in 00mn 00s
---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s
---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s
---\\ Enumère les fichiers Crack & Keygen (CKF) (O82)
C:\Users\Amaury\Desktop\Adobe CS4\Master Collection\Adobe CS4\Adobe_Master_Collection_CS4_Keygen_by_Milkman.zip =>.Crack,Keygen
C:\Users\Amaury\Desktop\EndNote X6 Bld 6348\Cracked\EndNote.exe =>.Crack,Keygen
~ Files: Scanned in 01mn 07s
---\\ Enumère les service demarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d'application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [475136]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d'accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d'interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d'événements système (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [523776]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2020864]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d'application.) -- C:\Windows\System32\appinfo.dll [47104]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificat
O43 - CFD: 23/09/2013 - 18:48:51 - [] ----D C:\Program Files\7-Zip
O43 - CFD: 14/10/2012 - 17:01:19 - [] ----D C:\Program Files\Adobe
O43 - CFD: 27/10/2012 - 13:10:03 - [] ----D C:\Program Files\Apple Software Update =>.Apple Inc
O43 - CFD: 23/09/2013 - 14:43:50 - [] ----D C:\Program Files\ArcGIS
O43 - CFD: 27/10/2012 - 13:09:43 - [] ----D C:\Program Files\Bonjour
O43 - CFD: 08/05/2015 - 11:47:02 - [] ----D C:\Program Files\CCleaner
O43 - CFD: 04/12/2011 - 23:56:37 - [] ----D C:\Program Files\CDBurnerXP
O43 - CFD: 07/01/2011 - 14:48:11 - [] ----D C:\Program Files\Cisco
O43 - CFD: 09/04/2013 - 08:24:59 - [] ----D C:\Program Files\Citrix
O43 - CFD: 10/05/2015 - 10:49:29 - [] ----D C:\Program Files\Common Files
O43 - CFD: 07/01/2011 - 14:52:12 - [] ----D C:\Program Files\Creative
O43 - CFD: 07/01/2011 - 14:51:48 - [] ----D C:\Program Files\Creative Live! Cam
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\CyberLink
O43 - CFD: 13/02/2015 - 17:07:18 - [] ----D C:\Program Files\Dell
O43 - CFD: 07/01/2011 - 14:41:47 - [] ----D C:\Program Files\Dell Inc
O43 - CFD: 01/04/2015 - 15:56:44 - [] ----D C:\Program Files\Dell Support Center
O43 - CFD: 07/01/2011 - 14:51:52 - [] ----D C:\Program Files\Dell Webcam
O43 - CFD: 07/01/2011 - 14:49:33 - [] ----D C:\Program Files\DigitalPersona
O43 - CFD: 05/10/2011 - 21:15:44 - [] ----D C:\Program Files\Druide
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\DVD Maker
O43 - CFD: 30/05/2013 - 16:35:59 - [] ----D C:\Program Files\EndNote X3
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\Program Files\Fichiers communs
O43 - CFD: 09/08/2013 - 08:30:00 - [] ----D C:\Program Files\Google
O43 - CFD: 18/09/2012 - 08:30:24 - [] ----D C:\Program Files\GUMBB52.tmp
O43 - CFD: 07/01/2011 - 07:38:05 - [] ----D C:\Program Files\IDT
O43 - CFD: 07/01/2011 - 14:51:50 - [] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 07/01/2011 - 14:43:38 - [] ----D C:\Program Files\Intel
O43 - CFD: 16/04/2015 - 07:41:45 - [] ----D C:\Program Files\Internet Explorer
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\iPod
O43 - CFD: 30/05/2014 - 17:24:54 - [] ----D C:\Program Files\IRIScan Direct
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\Program Files\iTunes
O43 - CFD: 01/02/2015 - 19:24:51 - [] ----D C:\Program Files\Java
O43 - CFD: 08/05/2015 - 12:02:05 - [] ----D C:\Program Files\Malwarebytes Anti-Malware
O43 - CFD: 19/08/2014 - 07:39:24 - [] ----D C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 15/01/2011 - 17:51:35 - [0] ----D C:\Program Files\Microsoft
O43 - CFD: 14/07/2009 - 11:00:58 - [] ----D C:\Program Files\Microsoft Games
O43 - CFD: 27/08/2012 - 21:15:59 - [] ----D C:\Program Files\Microsoft Office
O43 - CFD: 10/02/2012 - 09:38:04 - [] ----D C:\Program Files\Microsoft Research
O43 - CFD: 11/02/2015 - 20:53:43 - [] ----D C:\Program Files\Microsoft Security Client
O43 - CFD: 24/07/2014 - 17:05:44 - [] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 07/01/2011 - 15:02:44 - [] ----D C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 13/03/2011 - 22:40:16 - [] ----D C:\Program Files\Microsoft Visual Studio
O43 - CFD: 13/03/2011 - 22:37:09 - [] ----D C:\Program Files\Microsoft Visual Studio 8
O43 - CFD: 23/08/2012 - 08:17:10 - [] ----D C:\Program Files\Microsoft Works
O43 - CFD: 13/03/2011 - 22:40:04 - [] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 24/04/2015 - 12:09:10 - [] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 26/04/2015 - 08:23:34 - [] ----D C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 13/03/2011 - 22:40:20 - [] ----D C:\Program Files\MSBuild
O43 - CFD: 15/01/2011 - 23:49:59 - [0] ----D C:\Program Files\MSXML 4.0
O43 - CFD: 14/07/2009 - 06:52:30 - [] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 07/01/2011 - 14:58:04 - [] ----D C:\Program Files\Roxio
O43 - CFD: 03/03/2014 - 12:14:18 - [] ----D C:\Program Files\SamsungPrinterLiveUpdate
O43 - CFD: 03/03/2014 - 12:04:04 - [] ----D C:\Program Files\SamsungPrinterLiveUpdateInstaller
O43 - CFD: 05/02/2011 - 11:29:22 - [] ----D C:\Program Files\Satsuki Decoder Pack
O43 - CFD: 14/04/2015 - 08:03:39 - [] R---D C:\Program Files\Skype
O43 - CFD: 24/03/2015 - 20:36:20 - [] ----D C:\Program Files\Spotify
O43 - CFD: 07/01/2011 - 14:44:04 - [] ----D C:\Program Files\STMicroelectronics
O43 - CFD: 07/01/2011 - 16:33:50 - [] ----D C:\Program Files\Synaptics
O43 - CFD: 10/12/2011 - 19:15:54 - [] ----D C:\Program Files\Trend Micro
O43 - CFD: 25/03/2011 - 22:12:50 - [] ----D C:\Program Files\TuxGuitar-Jet
O43 - CFD: 14/07/2009 - 06:53:23 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 07/01/2011 - 14:45:49 - [] ----D C:\Program Files\Validity Sensors
O43 - CFD: 07/01/2011 - 14:46:46 - [] ----D C:\Program Files\WIDCOMM
O43 - CFD: 12/07/2013 - 07:57:37 - [] ----D C:\Program Files\Windows Defender
O43 - CFD: 12/07/2014 - 07:43:28 - [] ----D C:\Program Files\Windows Journal
O43 - CFD: 07/01/2011 - 15:03:04 - [] ----D C:\Program Files\Windows Live
O43 - CFD: 04/01/2012 - 19:59:00 - [] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 12/03/2015 - 04:25:28 - [] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 12/01/2011 - 13:59:10 - [] ----D C:\Program Files\Windows NT
O43 - CFD: 04/01/2012 - 19:58:58 - [] ----D C:\Program Files\Windows Photo Viewer
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Portable Devices
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Sidebar
O43 - CFD: 05/02/2011 - 12:44:37 - [] ----D C:\Program Files\WinRAR
O43 - CFD: 15/04/2014 - 08:21:40 - [] ----D C:\Program Files\XnView
O43 - CFD: 15/01/2011 - 22:02:09 - [] ----D C:\Program Files\Xvid
O43 - CFD: 08/05/2015 - 19:09:29 - [] ----D C:\Program Files\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 14/10/2012 - 17:01:28 - [] ----D C:\Program Files\Common Files\Adobe
O43 - CFD: 23/09/2013 - 14:47:09 - [] ----D C:\Program Files\Common Files\AnswerWorks 4.0
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\Common Files\Apple
O43 - CFD: 23/09/2013 - 14:46:20 - [] ----D C:\Program Files\Common Files\ArcGIS
O43 - CFD: 10/12/2011 - 19:52:01 - [] ----D C:\Program Files\Common Files\Bitdefender
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\Common Files\CyberLink
O43 - CFD: 23/09/2013 - 14:44:22 - [] ----D C:\Program Files\Common Files\Data Dynamics
O43 - CFD: 15/05/2014 - 11:50:28 - [] ----D C:\Program Files\Common Files\DESIGNER
O43 - CFD: 07/01/2011 - 14:51:35 - [] ----D C:\Program Files\Common Files\InstallShield
O43 - CFD: 01/02/2015 - 19:25:56 - [] ----D C:\Program Files\Common Files\Java
O43 - CFD: 28/02/2011 - 22:14:03 - [] ----D C:\Program Files\Common Files\Macrovision Shared
O43 - CFD: 05/02/2011 - 11:49:23 - [] ----D C:\Program Files\Common Files\mcafee
O43 - CFD: 23/08/2012 - 08:17:16 - [] ----D C:\Program Files\Common Files\microsoft shared
O43 - CFD: 07/01/2011 - 14:43:41 - [] ----D C:\Program Files\Common Files\postureAgent
O43 - CFD: 07/01/2011 - 14:58:20 - [] ----D C:\Program Files\Common Files\PX Storage Engine
O43 - CFD: 30/05/2013 - 16:36:04 - [] ----D C:\Program Files\Common Files\ResearchSoft
O43 - CFD: 23/12/2012 - 15:28:39 - [] ----D C:\Program Files\Common Files\Risxtd
O43 - CFD: 07/01/2011 - 14:58:36 - [] ----D C:\Program Files\Common Files\Roxio Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\Services
O43 - CFD: 08/10/2014 - 07:41:48 - [] ----D C:\Program Files\Common Files\Skype
O43 - CFD: 07/01/2011 - 14:58:00 - [] ----D C:\Program Files\Common Files\Sonic Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 07/01/2011 - 14:57:58 - [] ----D C:\Program Files\Common Files\SureThing Shared
O43 - CFD: 17/01/2012 - 16:46:20 - [0] ----D C:\Program Files\Common Files\SWF Studio
O43 - CFD: 04/01/2012 - 19:58:57 - [] ----D C:\Program Files\Common Files\System
O43 - CFD: 23/09/2013 - 14:44:09 - [] ----D C:\Program Files\Common Files\Tom Sawyer Software
O43 - CFD: 07/01/2011 - 14:58:54 - [] ----D C:\Program Files\Common Files\Windows Live
O43 - CFD: 30/05/2013 - 16:33:17 - [] ----D C:\Program Files\Common Files\Wise Installation Wizard
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
O43 - CFD: 30/07/2014 - 20:12:45 - [] ----D C:\ProgramData\Adobe
O43 - CFD: 28/02/2011 - 22:22:21 - [0] ----D C:\ProgramData\ALM
O43 - CFD: 27/10/2012 - 13:10:01 - [] ----D C:\ProgramData\Apple
O43 - CFD: 27/10/2012 - 13:10:36 - [] ----D C:\ProgramData\Apple Computer
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Application Data
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Bureau
O43 - CFD: 25/09/2011 - 22:32:17 - [] ----D C:\ProgramData\Canneverbe Limited
O43 - CFD: 01/02/2011 - 10:06:18 - [] --H-D C:\ProgramData\CanonBJ
O43 - CFD: 30/01/2014 - 16:19:41 - [] --H-D C:\ProgramData\CanonIJScan
O43 - CFD: 09/04/2013 - 08:25:17 - [] ----D C:\ProgramData\Citrix
O43 - CFD: 05/02/2011 - 11:48:10 - [] ----D C:\ProgramData\Creative
O43 - CFD: 17/01/2012 - 16:46:30 - [] ----D C:\ProgramData\CyberLink
O43 - CFD: 23/09/2013 - 14:36:26 - [] ----D C:\ProgramData\DAEMON Tools Lite =>.DT Soft Ltd
O43 - CFD: 23/08/2012 - 11:22:11 - [] ----D C:\ProgramData\Dell
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Documents
O43 - CFD: 07/01/2011 - 14:49:20 - [] ----D C:\ProgramData\Downloaded Installations
O43 - CFD: 06/01/2015 - 15:10:21 - [] ----D C:\ProgramData\ESRI
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Favoris
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Favorites
O43 - CFD: 23/09/2013 - 14:57:18 - [] ----D C:\ProgramData\FLEXnet
O43 - CFD: 25/03/2011 - 21:26:10 - [0] ----D C:\ProgramData\Guitar Pro 6
O43 - CFD: 07/01/2011 - 14:49:33 - [] ----D C:\ProgramData\Macrovision
O43 - CFD: 19/08/2014 - 07:39:24 - [] ----D C:\ProgramData\Malwarebytes
O43 - CFD: 16/11/2012 - 19:40:59 - [] ----D C:\ProgramData\McAfee
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Menu Démarrer
O43 - CFD: 10/12/2014 - 10:25:17 - [] -S--D C:\ProgramData\Microsoft
O43 - CFD: 15/04/2015 - 19:07:22 - [] ----D C:\ProgramData\Microsoft Help
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Modèles
O43 - CFD: 04/05/2012 - 08:23:01 - [] ----D C:\ProgramData\Mozilla
O43 - CFD: 10/05/2015 - 10:49:12 - [] ----D C:\ProgramData\Nero
O43 - CFD: 01/02/2015 - 19:27:18 - [] ----D C:\ProgramData\Oracle
O43 - CFD: 01/04/2015 - 15:56:47 - [] ----D C:\ProgramData\PC-Doctor for Windows
O43 - CFD: 07/05/2015 - 18:06:46 - [] ----D C:\ProgramData\PCDr
O43 - CFD: 07/01/2011 - 14:57:48 - [] ----D C:\ProgramData\PhotoShow Shared Assets
O43 - CFD: 24/10/2013 - 08:34:45 - [] --H-D C:\ProgramData\RICOH_DRV
O43 - CFD: 07/01/2011 - 14:57:48 - [] ----D C:\ProgramData\Roxio
O43 - CFD: 03/03/2014 - 12:04:03 - [] ----D C:\ProgramData\Samsung
O43 - CFD: 02/05/2015 - 08:11:28 - [] ----D C:\ProgramData\Skype
O43 - CFD: 16/06/2011 - 21:14:34 - [] ----D C:\ProgramData\Skype Extras
O43 - CFD: 11/05/2015 - 07:47:22 - [] ----D C:\ProgramData\Sonic
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Start Menu
O43 - CFD: 07/01/2011 - 14:42:45 - [] ----D C:\ProgramData\Sun
O43 - CFD: 05/05/2015 - 13:48:55 - [] ----D C:\ProgramData\SupportAssistAgent
O43 - CFD: 07/01/2011 - 14:51:06 - [] ----D C:\ProgramData\Temp
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Templates
O43 - CFD: 30/05/2013 - 16:36:06 - [] ----D C:\ProgramData\Thomson.ResearchSoft.Installers
O43 - CFD: 07/01/2011 - 14:58:36 - [] ----D C:\ProgramData\Uninstall
O43 - CFD: 12/03/2015 - 15:04:58 - [] --H-D C:\ProgramData\{6AACA38B-2810-4B47-BDEC-D7A1F38B1531}
O43 - CFD: 23/09/2013 - 18:48:51 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
O43 - CFD: 10/05/2015 - 12:49:29 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 14/07/2009 - 06:46:36 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 28/02/2011 - 22:24:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS4
O43 - CFD: 05/10/2011 - 21:22:25 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antidote
O43 - CFD: 23/09/2013 - 14:48:04 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcGIS
O43 - CFD: 04/11/2012 - 20:30:57 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG5200 series
O43 - CFD: 07/01/2011 - 15:10:41 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 9.5
O43 - CFD: 01/04/2015 - 15:56:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
O43 - CFD: 07/01/2011 - 14:52:26 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Webcam
O43 - CFD: 07/01/2011 - 14:47:42 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DW WLAN
O43 - CFD: 30/05/2013 - 16:35:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EndNote
O43 - CFD: 07/01/2011 - 07:38:55 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 19/12/2013 - 13:12:21 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth =>.Google Inc
O43 - CFD: 30/05/2014 - 17:24:55 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IRIScan Direct
O43 - CFD: 02/06/2013 - 16:57:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
O43 - CFD: 01/02/2015 - 19:25:18 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 14/07/2009 - 06:42:30 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 08/05/2015 - 12:02:07 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
O43 - CFD: 13/09/2013 - 17:40:09 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O43 - CFD: 24/07/2014 - 11:37:55 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
O43 - CFD: 07/01/2011 - 14:58:20 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio Creator Starter
O43 - CFD: 08/10/2014 - 07:41:49 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 16/11/2012 - 22:41:05 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 14/07/2009 - 11:00:22 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 07/01/2011 - 15:02:54 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
O43 - CFD: 15/04/2014 - 08:21:40 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView
O43 - CFD: 15/01/2011 - 22:02:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
O43 - CFD: 04/07/2013 - 18:36:20 - [] ----D C:\Users\Amaury\AppData\Roaming\Adobe
O43 - CFD: 27/10/2012 - 13:12:04 - [] ----D C:\Users\Amaury\AppData\Roaming\Apple Computer
O43 - CFD: 25/09/2011 - 22:32:17 - [] ----D C:\Users\Amaury\AppData\Roaming\Canneverbe Limited
O43 - CFD: 30/01/2014 - 16:19:41 - [] ----D C:\Users\Amaury\AppData\Roaming\Canon
O43 - CFD: 12/01/2011 - 14:04:06 - [] ----D C:\Users\Amaury\AppData\Roaming\Creative
O43 - CFD: 17/01/2012 - 16:46:29 - [] ----D C:\Users\Amaury\AppData\Roaming\CyberLink
O43 - CFD: 15/11/2013 - 08:39:56 - [] ----D C:\Users\Amaury\AppData\Roaming\DAEMON Tools Lite =>.DT Soft Ltd
O43 - CFD: 24/03/2011 - 09:54:04 - [] ----D C:\Users\Amaury\AppData\Roaming\Dell
O43 - CFD: 12/01/2011 - 14:04:02 - [] ----D C:\Users\Amaury\AppData\Roaming\DigitalPersona
O43 - CFD: 05/09/2011 - 09:51:28 - [] ----D C:\Users\Amaury\AppData\Roaming\Druide
O43 - CFD: 16/05/2014 - 10:40:34 - [] ----D C:\Users\Amaury\AppData\Roaming\EndNote
O43 - CFD: 23/09/2013 - 15:04:14 - [] ----D C:\Users\Amaury\AppData\Roaming\ESRI
O43 - CFD: 25/03/2011 - 22:10:49 - [] ----D C:\Users\Amaury\AppData\Roaming\Guitar Pro 6
O43 - CFD: 12/01/2011 - 14:03:44 - [] ----D C:\Users\Amaury\AppData\Roaming\Identities
O43 - CFD: 15/01/2011 - 18:01:02 - [] ----D C:\Users\Amaury\AppData\Roaming\Macromedia
O43 - CFD: 12/01/2011 - 21:28:33 - [] ----D C:\Users\Amaury\AppData\Roaming\Macrovision
O43 - CFD: 19/08/2014 - 07:39:37 - [0] ----D C:\Users\Amaury\AppData\Roaming\Malwarebytes
O43 - CFD: 14/07/2009 - 11:00:22 - [0] ----D C:\Users\Amaury\AppData\Roaming\Media Center Programs
O43 - CFD: 06/01/2014 - 16:31:05 - [0] ----D C:\Users\Amaury\AppData\Roaming\Media Player Classic
O43 - CFD: 31/01/2015 - 17:38:39 - [] -S--D C:\Users\Amaury\AppData\Roaming\Microsoft
O43 - CFD: 15/01/2011 - 21:25:03 - [] ----D C:\Users\Amaury\AppData\Roaming\Mozilla
O43 - CFD: 27/06/2013 - 21:48:54 - [] ----D C:\Users\Amaury\AppData\Roaming\Nero
O43 - CFD: 16/07/2014 - 12:04:25 - [] ----D C:\Users\Amaury\AppData\Roaming\PCDr
O43 - CFD: 10/12/2011 - 18:47:36 - [0] ----D C:\Users\Amaury\AppData\Roaming\QuickScan
O43 - CFD: 05/02/2011 - 11:48:10 - [] ----D C:\Users\Amaury\AppData\Roaming\Reallusion
O43 - CFD: 12/01/2011 - 14:04:11 - [] ----D C:\Users\Amaury\AppData\Roaming\Roxio
O43 - CFD: 15/01/2011 - 15:47:29 - [] ----D C:\Users\Amaury\AppData\Roaming\Roxio Burn
O43 - CFD: 11/05/2015 - 08:00:01 - [] ----D C:\Users\Amaury\AppData\Roaming\Skype
O43 - CFD: 19/06/2011 - 11:48:17 - [] ----D C:\Users\Amaury\AppData\Roaming\skypePM
O43 - CFD: 05/05/2015 - 13:40:24 - [] ----D C:\Users\Amaury\AppData\Roaming\Spotify
O43 - CFD: 21/02/2011 - 12:15:29 - [] ----D C:\Users\Amaury\AppData\Roaming\WinRAR
O43 - CFD: 15/04/2014 - 08:27:51 - [] ----D C:\Users\Amaury\AppData\Roaming\XnView
O43 - CFD: 11/05/2015 - 08:08:16 - [] ----D C:\Users\Amaury\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 05/04/2015 - 11:25:56 - [0] ----D C:\Users\Amaury\AppData\Local\._LiveCode_
O43 - CFD: 28/02/2011 - 22:36:33 - [] ----D C:\Users\Amaury\AppData\Local\Adobe
O43 - CFD: 27/10/2012 - 13:10:04 - [] ----D C:\Users\Amaury\AppData\Local\Apple
O43 - CFD: 27/10/2012 - 13:11:31 - [] ----D C:\Users\Amaury\AppData\Local\Apple Computer
O43 - CFD: 12/01/2011 - 13:59:20 - [] -SH-D C:\Users\Amaury\AppData\Local\Application Data
O43 - CFD: 02/01/2014 - 16:32:12 - [] ----D C:\Users\Amaury\AppData\Local\Apps
O43 - CFD: 12/01/2011 - 14:04:08 - [] ----D C:\Users\Amaury\AppData\Local\Broadcom
O43 - CFD: 09/04/2013 - 08:24:41 - [] ----D C:\Users\Amaury\AppData\Local\Citrix
O43 - CFD: 17/01/2012 - 16:46:31 - [] ----D C:\Users\Amaury\AppData\Local\Cyberlink
O43 - CFD: 02/01/2014 - 18:29:19 - [0] ----D C:\Users\Amaury\AppData\Local\Deployment
O43 - CFD: 12/01/2011 - 14:04:02 - [] ----D C:\Users\Amaury\AppData\Local\DigitalPersona
O43 - CFD: 19/11/2014 - 21:12:56 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieBrowserModeList
O43 - CFD: 17/04/2014 - 18:45:42 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieSiteList
O43 - CFD: 17/04/2014 - 18:45:42 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieUserList
O43 - CFD: 01/02/2015 - 16:39:39 - [] ----D C:\Users\Amaury\AppData\Local\ESRI
O43 - CFD: 10/12/2011 - 20:55:23 - [] ----D C:\Users\Amaury\AppData\Local\Google
O43 - CFD: 12/01/2011 - 13:59:20 - [] -SH-D C:\Users\Amaury\AppData\Local\Historique
O43 - CFD: 24/06/2012 - 09:00:00 - [] ----D C:\Users\Amaury\AppData\Local\Macromedia
O43 - CFD: 06/05/2015 - 16:15:23 - [] ----D C:\Users\Amaury\AppData\Local\Microsoft
O43 - CFD: 12/02/2011 - 20:35:39 - [] ----D C:\Users\Amaury\AppData\Local\Microsoft Games
O43 - CFD: 13/03/2011 - 22:36:40 - [0] ----D C:\Users\Amaury\AppData\Local\Microsoft Help
O43 - CFD: 19/09/2013 - 21:20:36 - [] ----D C:\Users\Amaury\AppData\Local\Mozilla
O43 - CFD: 10/12/2011 - 16:51:20 - [0] ----D C:\Users\Amaury\AppData\Local\pcnrqyro
O43 - CFD: 11/01/2013 - 12:01:16 - [] ----D C:\Users\Amaury\AppData\Local\Programs
O43 - CFD: 27/02/2014 - 10:59:08 - [] ----D C:\Users\Amaury\AppData\Local\Skype
O43 - CFD: 05/05/2015 - 13:40:25 - [] ----D C:\Users\Amaury\AppData\Local\Spotify
O43 - CFD: 11/05/2015 - 08:06:26 - [] ----D C:\Users\Amaury\AppData\Local\Temp
O43 - CFD: 12/01/2011 - 13:59:20 - [] -SH-D C:\Users\Amaury\AppData\Local\Temporary Internet Files
O43 - CFD: 12/01/2011 - 13:59:21 - [0] ----D C:\Users\Amaury\AppData\Local\VirtualStore
O43 - CFD: 08/06/2012 - 20:12:30 - [] ----D C:\Users\Amaury\AppData\Local\Western Digital
O43 - CFD: 14/07/2009 - 06:42:04 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 12/03/2015 - 07:43:42 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 05/10/2011 - 21:15:20 - [0] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antidote
O43 - CFD: 14/07/2009 - 06:37:42 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 10/02/2012 - 09:38:05 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft ICE
O43 - CFD: 06/01/2014 - 14:08:21 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Périphériques Bluetooth
O43 - CFD: 05/02/2011 - 11:29:22 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Satsuki Decoder Pack
O43 - CFD: 12/03/2015 - 07:43:42 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 25/03/2011 - 22:12:44 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TuxGuitar 1.2
~ Program Folder: 254 Scanned in 00mn 01s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.C16DFA9241F3CE8867E7EA8806B8F5DD] - 08/05/2015 - 08:31:05 ---A- . (...) -- C:\Windows\Antidote.ini [143]
O44 - LFC:[MD5.3C21F7E95FFCA33EF1A83AA33D9663CF] - 08/05/2015 - 11:01:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23256]
O44 - LFC:[MD5.155BF99B2B87E0C298CAC3B4B8136D83] - 08/05/2015 - 11:01:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [92888]
O44 - LFC:[MD5.167BCE00050B19DA25065335645A3C7A] - 08/05/2015 - 11:01:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [51928]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 08/05/2015 - 16:21:07 ---A- . (...) -- C:\Windows\setuperr.log [0]
O44 - LFC:[MD5.6446B430C5715E693545FC52D2746D3D] - 08/05/2015 - 18:09:31 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512]
O44 - LFC:[MD5.6B12A07D3C6AFD4A3219AF5FDE01DAFB] - 09/05/2015 - 07:11:51 ---A- . (...) -- C:\Windows\PFRO.log [2746]
O44 - LFC:[MD5.C489D8B4D8C64F20CC75A93F541F7D91] - 10/05/2015 - 09:32:24 ---A- . (.Microsoft Corporation - Exécuteur de file d'attente d'opérations pr.) -- C:\Windows\System32\poqexec.exe [123904]
O44 - LFC:[MD5.744AB3C1A73A57DEED49D631F1BDEA1D] - 10/05/2015 - 09:33:12 ---A- . (.Microsoft Corporation - Extension de l'environnement des appareils.) -- C:\Windows\System32\wpdshext.dll [2311168]
O44 - LFC:[MD5.F7F135F7702E0FB3EFE89283E2BE2EBB] - 10/05/2015 - 09:34:20 ---A- . (.Microsoft Corporation - API du Gestionnaire de fenêtres du Bureau M.) -- C:\Windows\System32\dwmapi.dll [67584]
O44 - LFC:[MD5.B01B8C949EDEC1B8A856E3056BDA7C42] - 10/05/2015 - 09:34:20 ---A- . (.Microsoft Corporation - Bibliothèque principale du Gestionnaire de.) -- C:\Windows\System32\dwmcore.dll [1372160]
O44 - LFC:[MD5.A5FE03D57097A45B8E7A4A09C9B78695] - 10/05/2015 - 09:38:35 ---A- . (.Microsoft Corporation - Client ActiveX des services Bureau à distan.) -- C:\Windows\System32\mstscax.dll [5698048]
O44 - LFC:[MD5.4676AAA9DDF52A50C829FEDB4EA81E54] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Connexion Bureau à distance.) -- C:\Windows\System32\mstsc.exe [1068544]
O44 - LFC:[MD5.AF40D823F3B03C7899AEF2293F84D0D7] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Proxy.) -- C:\Windows\System32\TSWbPrxy.exe [76288]
O44 - LFC:[MD5.5E676B296B762E211D83B87635F2C330] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Remote Desktop Services Client for Microsof.) -- C:\Windows\System32\rdvidcrl.dll [855552]
O44 - LFC:[MD5.0FC6922517964E9D90DE84DC86F63E40] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Runtime de connexion RemoteApp et Bureau à.) -- C:\Windows\System32\wksprt.exe [350208]
O44 - LFC:[MD5.8DEEE20D8D30E9B0FBDCA31E58A027BD] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - Client de contrainte de quarantaine de la p.) -- C:\Windows\System32\tsgqec.dll [53248]
O44 - LFC:[MD5.A90F47CDCC0898733596B5070039FC15] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - Extension de stratégie de groupe pour la re.) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll [14336]
O44 - LFC:[MD5.2EFB1279E7BEA7D12D9F4D6508D27880] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Acces.) -- C:\Windows\System32\MsRdpWebAccess.dll [50176]
O44 - LFC:[MD5.AB5EFB103DB01C1912C9D2F545EA5621] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - WorkspaceRuntime ProxyStub DLL.) -- C:\Windows\System32\wksprtPS.dll [17920]
O44 - LFC:[MD5.C6A5FBD4977305E1FA23E02C042DB463] - 10/05/2015 - 09:38:38 ---A- . (.Microsoft Corporation - Pilote de filtre pour concentrateur USB du.) -- C:\Windows\System32\Drivers\TsUsbFlt.sys [49152]
O44 - LFC:[MD5.D60E27D4BD5A91FCD17D2CB27F86738E] - 10/05/2015 - 09:38:38 ---A- . (.Microsoft Corporation - Remote Desktop USB Redirection GP Extension.) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe [12800]
O44 - LFC:[MD5.F37167FCDB661FD4B54CAD4755ABDD61] - 10/05/2015 - 09:38:40 ---A- . (.Microsoft Corporation - Co-installateur de pilote USB générique du.) -- C:\Windows\System32\TsUsbGDCoInstaller.dll [32256]
O44 - LFC:[MD5.4FBED1107021D7405721CE55975F2C96] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1677370]
O44 - LFC:[MD5.5C81CFC2FA1D69A7B165951D1051F889] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfc009.dat [123196]
O44 - LFC:[MD5.46261007C0E5F58CB875F4AF71763ADB] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [151280]
O44 - LFC:[MD5.1034469ABB736466148909A6EE82C0C8] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfh009.dat [657384]
O44 - LFC:[MD5.2EE8285A8B6D443F9003E8531357C0C8] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [750666]
O44 - LFC:[MD5.BA63FDF7785E75B60B3D958D4B381DB3] - 10/05/2015 - 16:44:33 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [2448648]
O44 - LFC:[MD5.7FB275E0AF83B9ED8CC13F643D8DEE2A] - 11/05/2015 - 07:02:29 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.FD7E6F9DCCD7FEEBDD6E8D3F14AD24F8] - 11/05/2015 - 07:02:32 ---A- . (...) -- C:\Windows\setupact.log [392]
O44 - LFC:[MD5.04B309A1A653177994630C2773E659F1] - 11/05/2015 - 07:03:37 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [119512]
O44 - LFC:[MD5.64E95965FA54CE5B4A4E8EFEFD239125] - 11/05/2015 - 07:06:06 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1113249]
O44 - LFC:[MD5.47DE8B7A482D4BABBCC70C0199E35881] - 27/04/2015 - 19:00:30 ---A- . (.Microsoft Corporation - Microsoft Windows Diagnostics Tracking.) -- C:\Windows\System32\UtcResources.dll [36864]
O44 - LFC:[MD5.86B2AC15999BB4F8B5C84AB6154A1783] - 27/04/2015 - 19:59:36 ---A- . (.Microsoft Corporation - DLL du schéma d'audit de sécurité.) -- C:\Windows\System32\adtschema.dll [686080]
O44 - LFC:[MD5.9638DA21E965E23C85C4319F3F66D824] - 27/04/2015 - 19:59:41 ---A- . (.Microsoft Corporation - ApiSet Schema DLL.) -- C:\Windows\System32\apisetschema.dll [6656]
O44 - LFC:[MD5.D079A408CC3E22A09D1260A6F18FC0FD] - 27/04/2015 - 20:01:22 ---A- . (.Microsoft Corporation - DLL des événements d'audit de la sécurité.) -- C:\Windows\System32\msaudite.dll [146432]
O44 - LFC:[MD5.BF9BB4113E9FCDABD4C703DDD06293F3] - 27/04/2015 - 20:01:33 ---A- . (.Microsoft Corporation - Nom d'audit des objets système.) -- C:\Windows\System32\msobjs.dll [60416]
O44 - LFC:[MD5.AFFE5747054D03F8CEE18A8518A9AA34] - 27/04/2015 - 20:03:52 ---A- . (.Microsoft Corporation - Programme de stratégie d'audit.) -- C:\Windows\System32\auditpol.exe [50176]
O44 - LFC:[MD5.F286528898342F0F1EB402606750C391] - 27/04/2015 - 20:03:58 ---A- . (.Microsoft Corporation - Utilitaire de configuration des performance.) -- C:\Windows\System32\diskperf.exe [17408]
O44 - LFC:[MD5.C6D2D384B6232B0B800234C03C50979F] - 27/04/2015 - 20:04:04 ---A- . (.Microsoft Corporation - Utilitaire d'enregistrement des Performance.) -- C:\Windows\System32\logman.exe [82944]
O44 - LFC:[MD5.1667D76FBF42B24B9DE3E8B0A7CF06BE] - 27/04/2015 - 20:04:05 ---A- . (.Microsoft Corporation - Local Security Authority Process.) -- C:\Windows\System32\lsass.exe [22528]
O44 - LFC:[MD5.97B30711DC6CA0EA4EACEDCE8080A3B4] - 27/04/2015 - 20:04:12 ---A- . (.Microsoft Corporation - Utilitaire de réenregistrement de Performan.) -- C:\Windows\System32\relog.exe [37888]
O44 - LFC:[MD5.7E9A03C1B76CB8A222C9AB232B3118D9] - 27/04/2015 - 20:04:14 ---A- . (.Microsoft Corporation - Restauration du système de Microsoft® Windo.) -- C:\Windows\System32\rstrui.exe [262656]
O44 - LFC:[MD5.03CD13A169C19558F637C2F36B974BDA] - 27/04/2015 - 20:04:21 ---A- . (.Microsoft Corporation - Gestionnaire de sessions Windows.) -- C:\Windows\System32\smss.exe [69632]
O44 - LFC:[MD5.74C0EC1257698176E288DA282F318E1C] - 27/04/2015 - 20:04:24 ---A- . (.Microsoft Corporation - Moniteur de performance de la ligne de comm.) -- C:\Windows\System32\typeperf.exe [40448]
O44 - LFC:[MD5.EB058143B57ED460AC4F2DFBA104BBFF] - 27/04/2015 - 20:04:24 ---A- . (.Microsoft Corporation - Outil de rapport de suivi d'événements.) -- C:\Windows\System32\tracerpt.exe [364544]
O44 - LFC:[MD5.7A5824DC9A85FCE4334F57FF0795853E] - 27/04/2015 - 20:04:33 ---A- . (.Microsoft Corporation - API avancées Windows 32.) -- C:\Windows\System32\advapi32.dll [641536]
O44 - LFC:[MD5.79AF005633B7E41B7A194A7E7B9D3D93] - 27/04/2015 - 20:04:37 ---A- . (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll [17408]
O44 - LFC:[MD5.5DCF39695CD614B162330F5AC27C4654] - 27/04/2015 - 20:04:37 ---A- . (.Microsoft Corporation - Processus d'exécution client-serveur.) -- C:\Windows\System32\csrsrv.dll [38912]
O44 - LFC:[MD5.54A01CC4BC47B31C5CD082D064AB37BC] - 27/04/2015 - 20:04:45 ---A- . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll [550912]
O44 - LFC:[MD5.D362BFE84A44A442CB6B8CBFE6DE027D] - 27/04/2015 - 20:04:47 ---A- . (.Microsoft Corporation - DLL serveur LSA.) -- C:\Windows\System32\lsasrv.dll [1061376]
O44 - LFC:[MD5.66D6A06936088E412E29A182679F0D71] - 27/04/2015 - 20:05:11 ---A- . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll [259584]
O44 - LFC:[MD5.0B6E937863837BA3383E9CE9200DDF1E] - 27/04/2015 - 20:05:17 ---A- . (.Microsoft Corporation - Bibliothèque de chiffrement Windows.) -- C:\Windows\System32\ncrypt.dll [221184]
O44 - LFC:[MD5.C34E0F9846D0FF902CED82DB5AB104BA] - 27/04/2015 - 20:05:28 ---A- . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll [248832]
O44 - LFC:[MD5.8C45A65ED20B487085B79EEFCC08D160] - 27/04/2015 - 20:05:29 ---A- . (.Microsoft Corporation - Host for SCM/SDDL/LSA Lookup APIs.) -- C:\Windows\System32\sechost.dll [92160]
O44 - LFC:[MD5.99A508910BB06DFBE99D9AF7D6B4E950] - 27/04/2015 - 20:05:29 ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\secur32.dll [22016]
O44 - LFC:[MD5.7CC0547B9FD90649731E021DA2763086] - 27/04/2015 - 20:05:32 ---A- . (.Microsoft Corporation - Bibliothèque principale de Restauration du.) -- C:\Windows\System32\srcore.dll [400896]
O44 - LFC:[MD5.ABA025664F9F42C568B2C022AADCB18F] - 27/04/2015 - 20:05:32 ---A- . (.Microsoft Corporation - Microsoft® Windows System Restore Client Li.) -- C:\Windows\System32\srclient.dll [43008]
O44 - LFC:[MD5.ECB7366ED80E349436FC495A77EAF24C] - 27/04/2015 - 20:05:33 ---A- . (.Microsoft Corporation - LSA SSPI RPC interface DLL.) -- C:\Windows\System32\sspisrv.dll [15872]
O44 - LFC:[MD5.6C427298E65C1430D232A0529ED9B18E] - 27/04/2015 - 20:05:33 ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\sspicli.dll [100352]
O44 - LFC:[MD5.D0F574320615303ADECDCB452EBB8930] - 27/04/2015 - 20:05:34 ---A- . (.Microsoft Corporation - Bibliothèque de l'application auxiliaire de.) -- C:\Windows\System32\tdh.dll [635392]
O44 - LFC:[MD5.FCB1C8345C794FE89ABA03B4CA3131BB] - 27/04/2015 - 20:05:35 ---A- . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\TSpkg.dll [65536]
O44 - LFC:[MD5.E95DE5B790B2D16706DAC8472E51F31A] - 27/04/2015 - 20:05:39 ---A- . (.Microsoft Corporation - Microsoft Windows Diagnostics Tracking.) -- C:\Windows\System32\diagtrack.dll [851456]
O44 - LFC:[MD5.850F756363237A2EB069B9B25EF8BEC3] - 27/04/2015 - 20:05:40 ---A- . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll [172032]
O44 - LFC:[MD5.7410C9F088E4F13C981F981B52475B5E] - 27/04/2015 - 20:08:02 ---A- . (.Microsoft Corporation - DLL Couche NT.) -- C:\Windows\System32\ntdll.dll [1307648]
O44 - LFC:[MD5.6DD2A1064DD8AFBED22E71176E2AF59B] - 27/04/2015 - 20:11:53 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecdd.sys [67520]
O44 - LFC:[MD5.76C0D35167B1369C68388FEDB56A3048] - 27/04/2015 - 20:11:53 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecpkg.sys [137664]
O44 - LFC:[MD5.8D50ED3F0FBE3590AB0D43BF7B60E57A] - 27/04/2015 - 20:11:54 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntkrnlpa.exe [3989440]
O44 - LFC:[MD5.0A66C88B087249742381924AB8F9EFCC] - 27/04/2015 - 20:11:55 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntoskrnl.exe [3934144]
~ Files: 70 Scanned in 00mn 17s
---\\ Déni du service (Local Security Authority) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l'Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Notification Packages . (.DigitalPersona, Inc. - DPPwdFlt Module.) -- C:\Windows\System32\DPPWDFLT.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corp. - LiveSSP.) -- C:\Windows\System32\livessp.dll
~ LSA: 10 Scanned in 00mn 00s
---\\ Contrôle du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d'extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d'extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
~ CSB: 13 Scanned in 00mn 00s
---\\ Clé de registre Shell MountPoints2 (MPSK) (O51)
O51 - MPSK:{30236676-b194-11e1-8151-f04da2c023f1}\AutoRun\command. (...) -- E:\unlock.exe (.not file.)
O51 - MPSK:{74702b01-b586-11e3-ba34-f04da2c023f1}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)
O51 - MPSK:{d22ae3b2-20ad-11e0-a6a7-f04da2c023f1}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)
~ Keys: Scanned in 00mn 00s
---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll
O52 - TDSD: \Drivers32\"vidc.XVID"="xvidvfw.dll" . (...) -- C:\Windows\System32\xvidvfw.dll
O52 - TDSD: \Drivers32\"vidc.ffds"="ff_vfw.dll" . (...) -- C:\Windows\System32\ff_vfw.dll
O52 - TDSD: \Drivers32\"msacm.vorbis"="vorbis.acm" . (.HMS http://hp.vector.co.jp/authors/VA012897 - Ogg Vorbis CODEC for MSACM.) -- C:\Windows\System32\vorbis.acm
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"xvidvfw.dll"="Xvid MPEG-4 Video Codec" . (...) -- C:\Windows\System32\xvidvfw.dll
O52 - TDSD: \drivers.desc\"vorbis.acm"="Ogg Vorbis Audio CODEC, Based on Xiphophorus libVorbis I 20010910" . (.HMS http://hp.vector.co.jp/authors/VA012897 - Ogg Vorbis CODEC for MSACM.) -- C:\Windows\System32\vorbis.acm
~ TDSD: 8 Scanned in 00mn 00s
---\\ Enumération des clés de registre StartupReg (SMSR) (O53)
O53 - SMSR:HKLM\...\startupreg\AdobeBridge [Key] . (.Adobe Systems, Inc. - Adobe Bridge.) -- C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe =>.Adobe Systems Incorporated
O53 - SMSR:HKLM\...\startupreg\APSDaemon [Key] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
O53 - SMSR:HKLM\...\startupreg\CCleaner Monitoring [Key] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
O53 - SMSR:HKLM\...\startupreg\iTunesHelper [Key] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
O53 - SMSR:HKLM\...\startupreg\Skype [Key] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O53 - SMSR:HKLM\...\startupreg\Spotify Web Helper [Key] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe
~ SMSR Keys: 6 Scanned in 00mn 01s
---\\ Enumération des clés de registre SecurityProviders (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
~ MSCP: 2 Scanned in 00mn 00s
---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=0
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Scanned in 00mn 00s
---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145
~ MWPE Keys: 1 Scanned in 00mn 00s
---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:03/12/2009 - 07:24:38 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\System32\Drivers\Acceler.sys [41648]
O58 - SDL:29/09/2010 - 17:38:00 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\System32\Drivers\Accelern.sys [43888]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976]
O58 - SDL:14/07/2009 - 02:26:17 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [297552]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\Drivers\adpu320.sys [146512]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [14400]
O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [80256]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows fa.) -- C:\Windows\System32\Drivers\amdsbs.sys [159312]
O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [22400]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [76368]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [86608]
O58 - SDL:15/07/2011 - 16:11:46 ---A- . (.BitDefender - BitDefender AntiVirus Active Virus Control Hypervisor driver.) -- C:\Windows\System32\Drivers\avchv.sys [240184]
O58 - SDL:01/09/2011 - 11:15:08 ---A- . (.BitDefender - Active Virus Control Kernel Filtering driver.) -- C:\Windows\System32\Drivers\avckf.sys [454960]
O58 - SDL:13/07/2009 - 23:02:49 ---A- . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gigabit Ethernet..) -- C:\Windows\System32\Drivers\b57nd60x.sys [229888]
O58 - SDL:07/01/2011 - 13:47:17 ---A- . (.Broadcom Corporation - Broadcom iLine10(tm) PCI Network Adapter Proxy Protocol Driver.) -- C:\Windows\System32\Drivers\bcm42rly.sys [18424]
O58 - SDL:05/05/2010 - 20:28:38 ---A- . (.Broadcom Corporation - Broadcom 802.11 Network Adapter wireless driver.) -- C:\Windows\System32\Drivers\BCMWL6.SYS [2707448]
O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [13568]
O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [5248]
O58 - SDL:14/07/2009 - 01:57:25 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [272128]
O58 - SDL:13/07/2009 - 23:53:32 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [62336]
O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [12160]
O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [11904]
O58 - SDL:03/10/2009 - 06:24:12 ---A- . (.Broadcom Corporation. - Bluetooth Audio Device.) -- C:\Windows\System32\Drivers\btwaudio.sys [86056]
O58 - SDL:29/08/2009 - 03:15:16 ---A- . (.Broadcom Corporation. - Broadcom Bluetooth AVDT Service.) -- C:\Windows\System32\Drivers\btwavdt.sys [108072]
O58 - SDL:07/04/2009 - 23:32:50 ---A- . (.Broadcom Corporation. - Broadcom Bluetooth L2CAP Service.) -- C:\Windows\System32\Drivers\btwl2cap.sys [29472]
O58 - SDL:29/08/2009 - 03:15:12 ---A- . (.Broadcom Corporation. - Bluetooth Remote Control HID Minidriver.) -- C:\Windows\System32\Drivers\btwrchid.sys [18472]
O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbdx.sys [430080]
O58 - SDL:20/10/2009 - 10:00:00 ---A- . (.Sonic Solutions - CDR4 CD and DVD Place Holder Driver (see PxHelp).) -- C:\Windows\System32\Drivers\cdr4_xp.sys [9072]
O58 - SDL:20/10/2009 - 10:00:00 ---A- . (.Sonic Solutions - CDRAL Place Holder Driver (see PxHelp).) -- C:\Windows\System32\Drivers\cdralw2k.sys [9200]
O58 - SDL:14/07/2009 - 02:26:21 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [15952]
O58 - SDL:28/05/2009 - 17:48:20 ---A- . (.Creative Technology Ltd. - Advanced Audio FX Driver.) -- C:\Windows\System32\Drivers\CtAudDrv.sys [134144]
O58 - SDL:12/08/2010 - 17:50:20 ---A- . (.Creative Technology Ltd. - Video Class Upper Filter Driver.) -- C:\Windows\System32\Drivers\CtClsFlt.sys [146528]
O58 - SDL:30/01/2015 - 23:36:11 ---A- . (.Dell Computer Corporation - DDDriver.sys.) -- C:\Windows\System32\Drivers\DDDriver32Dcsa.sys [20688]
O58 - SDL:30/01/2015 - 23:36:11 ---A- . (.Dell Computer Corporation - DellProf.sys.) -- C:\Windows\System32\Drivers\DellProf.sys [19984]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\Drivers\djsvs.sys [70720]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712]
O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbdx.sys [3100160]
O58 - SDL:21/08/2012 - 12:01:22 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys [26840]
O58 - SDL:13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624]
O58 - SDL:17/09/2009 - 21:54:14 ---A- . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\Drivers\HECI.sys [41088]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [67152]
O58 - SDL:04/03/2010 - 19:33:26 ---A- . (.Intel Corporation - Intel Rapid Storage Technology driver - x86.) -- C:\Windows\System32\Drivers\iaStor.sys [435736]
O58 - SDL:11/03/2011 - 06:38:51 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332160]
O58 - SDL:26/08/2010 - 12:31:30 ---A- . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\Drivers\igdkmd32.sys [9024512]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [41040]
O58 - SDL:27/02/2010 - 16:31:24 ---A- . (.Intel Corporation - Intel(R) Turbo Boost Technology Driver.) -- C:\Windows\System32\Drivers\Impcd.sys [132480]
O58 - SDL:31/08/2010 - 04:15:56 ---A- . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\Drivers\IntcDAud.sys [247808]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [95824]
O58 - SDL:14/07/2009 - 02:20:37 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [89168]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [54864]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [96848]
O58 - SDL:14/04/2015 - 08:37:42 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23256]
O58 - SDL:14/04/2015 - 08:37:44 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [92888]
O58 - SDL:11/05/2015 - 07:03:37 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [119512]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7 for x86.) -- C:\Windows\System32\Drivers\megasas.sys [30800]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [235584]
O58 - SDL:14/04/2015 - 08:37:54 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [51928]
O58 - SDL:14/07/2009 - 02:20:44 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [44624]
O58 - SDL:07/01/2011 - 13:47:18 ---A- . (.CACE Technologies, Inc. - npf.sys (NT5/6 x86) Kernel Driver.) -- C:\Windows\System32\Drivers\npf.sys [50704]
O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117120]
O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [143744]
O58 - SDL:19/03/2010 - 10:00:00 ---A- . (.Sonic Solutions - Px Engine Device Driver for Windows 2000/XP.) -- C:\Windows\System32\Drivers\pxhelp20.sys [45648]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1383488]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [106064]
O58 - SDL:10/06/2011 - 05:34:52 ---A- . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.20 32-bit Driver.) -- C:\Windows\System32\Drivers\Rt86win7.sys [394856]
O58 - SDL:10/08/2009 - 20:06:08 ---A- . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/Vista/Win7.) -- C:\Windows\System32\Drivers\RtsUStor.sys [171520]
O58 - SDL:13/07/2009 - 21:50:20 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [20480]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [40016]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [77888]
O58 - SDL:20/08/2010 - 18:04:38 ---A- . (.ST Microelectronics - Disk Class Filter Driver for Accelerometer.) -- C:\Windows\System32\Drivers\stdcfltn.sys [17648]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072]
O58 - SDL:07/04/2010 - 13:35:04 ---A- . (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\Drivers\stwrt.sys [423936]
O58 - SDL:08/01/2010 - 05:46:20 ---A- . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\Windows\System32\Drivers\SynTP.sys [232624]
O58 - SDL:14/07/2009 - 02:19:10 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [16976]
O58 - SDL:14/07/2009 - 02:19:11 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [141904]
O58 - SDL:13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672]
~ Drivers: 90 Scanned in 00mn 03s
---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 05/05/2015 - 08:09:04 ---A- . (.Microsoft Corporation.) -- C:\Users\Amaury\AppData\Roaming\Spotify\d3dcompiler_43.dll [2106424]
O61 - LFC: 05/05/2015 - 08:09:05 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\ffmpegsumo.dll [990776]
O61 - LFC: 05/05/2015 - 08:09:05 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\libEGL.dll [219192]
O61 - LFC: 05/05/2015 - 08:09:05 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\libGLESv2.dll [1365560]
O61 - LFC: 05/05/2015 - 08:09:05 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\libcef.dll [40518200]
O61 - LFC: 05/05/2015 - 08:09:05 ---A- . (.Microsoft Corporation.) -- C:\Users\Amaury\AppData\Roaming\Spotify\d3dcompiler_47.dll [3457592]
O61 - LFC: 05/05/2015 - 08:09:05 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\Spotify.exe [7168568]
O61 - LFC: 05/05/2015 - 08:09:06 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\wow_helper.exe [73272]
O61 - LFC: 05/05/2015 - 08:09:06 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyCrashService.exe [778808]
O61 - LFC: 05/05/2015 - 08:09:06 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyLauncher.exe [124472]
O61 - LFC: 05/05/2015 - 08:09:06 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920]
O61 - LFC: 08/05/2015 - 08:08:59 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Adobe\Acrobat\9.0\UserCache.bin [106533]
O61 - LFC: 08/05/2015 - 08:09:06 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\ZHP\ZHPCleaner.exe [1818624] =>.Nicolas Coolman
O61 - LFC: 08/05/2015 - 08:09:08 ---A- . (...) -- C:\Users\Amaury\Downloads\adwcleaner_4.203.exe [2204160]
O61 - LFC: 08/05/2015 - 08:09:09 ---A- . (...) -- C:\Users\Amaury\Downloads\ZHPCleaner.exe [1818624] =>.Nicolas Coolman
O61 - LFC: 09/05/2015 - 08:09:09 ---A- . (...) -- C:\Users\Amaury\Downloads\ZHPCleaner(1).exe [1820160] =>.Nicolas Coolman
~ 128 Fichiers temporaires (Temporary files)
~ 5 Fichiers cookies (Cookies files)
~ Files: 16 Scanned in 00mn 26s
---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s
---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - 07/01/2011 - C:\Windows\System32\drivers\BCM42RLY.sys (BCM42RLY) .(.Broadcom Corporation - Broadcom iLine10(tm) PCI Network Adapter Pr.) - LEGACY_BCM42RLY
O64 - Services: CurCS - 14/04/2015 - C:\Windows\system32\drivers\mbam.sys (MBAMProtector) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMPROTECTOR
O64 - Services: CurCS - 11/05/2015 - C:\Windows\system32\drivers\MBAMSwissArmy.sys (MBAMSwissArmy) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMSWISSARMY
O64 - Services: CurCS - 14/04/2015 - C:\Windows\system32\drivers\mwac.sys (MBAMWebAccessControl) .(.Malwarebytes Corporation - Malwarebytes Web Access Control.) - LEGACY_MBAMWEBACCESSCONTROL
O64 - Services: CurCS - 13/07/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV
~ Legacy: 119 Scanned in 00mn 00s
---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d'événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
~ FASS Keys: 10 Scanned in 00mn 00s
---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s
---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s
---\\ Enumère les fichiers Crack & Keygen (CKF) (O82)
C:\Users\Amaury\Desktop\Adobe CS4\Master Collection\Adobe CS4\Adobe_Master_Collection_CS4_Keygen_by_Milkman.zip =>.Crack,Keygen
C:\Users\Amaury\Desktop\EndNote X6 Bld 6348\Cracked\EndNote.exe =>.Crack,Keygen
~ Files: Scanned in 01mn 07s
---\\ Enumère les service demarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d'application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [475136]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d'accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d'interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d'événements système (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [523776]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2020864]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d'application.) -- C:\Windows\System32\appinfo.dll [47104]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificat
---\\ Enumère les service demarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d'application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [475136]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d'accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d'interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d'événements système (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [523776]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2020864]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d'application.) -- C:\Windows\System32\appinfo.dll [47104]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [49664]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164864]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [71168]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [113664]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d'ordinateurs.) -- C:\Windows\System32\browser.dll [102912]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800]
~ Services: 32 Scanned in 00mn 00s
---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.825768E0D92DAD41A59BF0D16FB76F40] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.1520.bin [4248]
[MD5.946CF417E94D2C9A873D14E6FE0415A1] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2120.bin [70375]
[MD5.6236D6B734152B266EBAB93CF24E5830] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2532.bin [1698]
[MD5.5BC0BA4A5185D7B285B5F8EBE4FCB0FA] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2748.bin [456927]
[MD5.18BC0B6609141E87DE09F4C7DEA97547] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.3716.bin [4259]
[MD5.D9A90DDEBEC281317E31AAEC06FEBD48] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4140.bin [1670]
[MD5.453B258E97C86572BE40C8E28C8CB637] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4464.bin [1260]
[MD5.3F5C7469DC6A45255FA5723B270DFB56] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4664.bin [21151]
[MD5.C6E5D0B9966A3707497421164BAA017C] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4676.bin [70625]
[MD5.5999CF6DDDD5FF5F62A7DA285C5FFF3A] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4696.bin [9108]
[MD5.FAE27419C38CC9DE62F607B0FD4458D6] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.bdinstall.bin [73728]
[MD5.B76FA9566970A7E5255B0717C35B5EC9] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539329.bdinstall.bin [80408]
[MD5.33FE59A381CCF8297F7F8C38FF954D41] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539409.bdinstall.bin [90911]
~ Files: 13 Scanned in 00mn 00s
---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab
~ BCK: 18514 Scanned in 00mn 36s
---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 15/04/2015 268464 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 23/09/2013 1044816 | (FLEXnet Licensing Service) . (.Flexera Software, Inc..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Auto 22/10/2014 107912 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 22/10/2014 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 15/05/2013 553288 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SS - | Demand 24/04/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 04/09/2010 1116656 | (RoxMediaDB12OEM) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
SS - | Auto 04/09/2010 219632 | (RoxWatch12) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
SS - | Auto 18/02/2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SS - | Demand 26/08/2010 74392 | (stllssvr) . (.MicroVision Development, Inc..) - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 03/03/2009 81920 | (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 20/10/2009 595232 | (btwdins) . (.Broadcom Corporation..) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
SR - | Auto 26/02/2015 1947344 | (DellDataVault) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
SR - | Auto 26/02/2015 184016 | (DellDataVaultWiz) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
SR - | Auto 13/05/2009 322624 | (DpHost) . (.DigitalPersona, Inc..) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
SR - | Auto 04/11/2009 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 14/04/2015 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
SR - | Auto 14/04/2015 1080120 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
SR - | Auto 30/01/2015 22184 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 07/04/2010 229458 | (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
SR - | Auto 10/04/2015 19288 | (SupportAssistAgent) . (.Dell Inc..) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
SR - | Auto 04/11/2009 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 03/06/2010 1664304 | (vcsFPService) . (.Validity Sensors, Inc..) - C:\Windows\system32\vcsFPService.exe
SR - | Auto 07/01/2011 40960 | (wltrysvc) . (.Dell Inc..) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 38s
---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
~ MBR: 1 Scanned in 00mn 02s
---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by Amaury at 11/05/2015 08:11:16
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s
---\\ Scan Additionnel (O88)
Database Version : 13008 - (05/05/2015)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 41
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\7Zip Bundle by Fileparade.com] =>PUP.SweetIM^
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro^
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab^
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar^
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab^
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab^
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo^
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay^
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy^
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo^
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo^
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab^
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab^
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream^
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo^
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo^
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream^
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine^
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab^
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager^
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab^
~ Additionnel Scan: 669949 Items scanned in 00mn 29s
---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects de navigateur (O2)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
~ AMI: 5 Scanned in 00mn 00s
---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/pup-sweetim =>PUP.SweetIM
http://nicolascoolman.fr/pup-optimizerpro =>PUP.OptimizerPro
http://www.nicolascoolman.fr/blog/ =>PUP.Nosibay
http://nicolascoolman.fr/adware-onetab =>Adware.OneTab
http://nicolascoolman.fr/hijacker-findrtoolbar =>Hijacker.FindrToolbar
http://nicolascoolman.fr/hijacker-smartbar =>Hijacker.SmartBar
http://nicolascoolman.fr/pup-eorezo =>PUP.EoRezo
http://nicolascoolman.fr/pup-minibar =>PUP.Minibar
http://nicolascoolman.fr/hijacker-proxy =>Hijacker.Proxy
http://nicolascoolman.fr/adware-metastream =>Adware.MetaStream
http://nicolascoolman.fr/pup-softwareengine =>PUP.SoftwareEngine
http://nicolascoolman.fr/pup-manager =>PUP.Manager
~ MSI: 12 link(s) detected in 00mn 00s
End of the scan (1555 lines in 04mn 47s)(2.11)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d'application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [475136]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d'accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d'interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d'événements système (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [523776]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2020864]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d'application.) -- C:\Windows\System32\appinfo.dll [47104]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [49664]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164864]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [71168]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [113664]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d'ordinateurs.) -- C:\Windows\System32\browser.dll [102912]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800]
~ Services: 32 Scanned in 00mn 00s
---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.825768E0D92DAD41A59BF0D16FB76F40] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.1520.bin [4248]
[MD5.946CF417E94D2C9A873D14E6FE0415A1] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2120.bin [70375]
[MD5.6236D6B734152B266EBAB93CF24E5830] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2532.bin [1698]
[MD5.5BC0BA4A5185D7B285B5F8EBE4FCB0FA] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2748.bin [456927]
[MD5.18BC0B6609141E87DE09F4C7DEA97547] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.3716.bin [4259]
[MD5.D9A90DDEBEC281317E31AAEC06FEBD48] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4140.bin [1670]
[MD5.453B258E97C86572BE40C8E28C8CB637] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4464.bin [1260]
[MD5.3F5C7469DC6A45255FA5723B270DFB56] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4664.bin [21151]
[MD5.C6E5D0B9966A3707497421164BAA017C] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4676.bin [70625]
[MD5.5999CF6DDDD5FF5F62A7DA285C5FFF3A] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4696.bin [9108]
[MD5.FAE27419C38CC9DE62F607B0FD4458D6] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.bdinstall.bin [73728]
[MD5.B76FA9566970A7E5255B0717C35B5EC9] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539329.bdinstall.bin [80408]
[MD5.33FE59A381CCF8297F7F8C38FF954D41] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539409.bdinstall.bin [90911]
~ Files: 13 Scanned in 00mn 00s
---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab
~ BCK: 18514 Scanned in 00mn 36s
---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 15/04/2015 268464 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 23/09/2013 1044816 | (FLEXnet Licensing Service) . (.Flexera Software, Inc..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Auto 22/10/2014 107912 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 22/10/2014 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 15/05/2013 553288 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SS - | Demand 24/04/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 04/09/2010 1116656 | (RoxMediaDB12OEM) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
SS - | Auto 04/09/2010 219632 | (RoxWatch12) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
SS - | Auto 18/02/2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SS - | Demand 26/08/2010 74392 | (stllssvr) . (.MicroVision Development, Inc..) - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 03/03/2009 81920 | (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 20/10/2009 595232 | (btwdins) . (.Broadcom Corporation..) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
SR - | Auto 26/02/2015 1947344 | (DellDataVault) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
SR - | Auto 26/02/2015 184016 | (DellDataVaultWiz) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
SR - | Auto 13/05/2009 322624 | (DpHost) . (.DigitalPersona, Inc..) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
SR - | Auto 04/11/2009 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 14/04/2015 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
SR - | Auto 14/04/2015 1080120 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
SR - | Auto 30/01/2015 22184 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 07/04/2010 229458 | (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
SR - | Auto 10/04/2015 19288 | (SupportAssistAgent) . (.Dell Inc..) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
SR - | Auto 04/11/2009 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 03/06/2010 1664304 | (vcsFPService) . (.Validity Sensors, Inc..) - C:\Windows\system32\vcsFPService.exe
SR - | Auto 07/01/2011 40960 | (wltrysvc) . (.Dell Inc..) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 38s
---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
~ MBR: 1 Scanned in 00mn 02s
---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by Amaury at 11/05/2015 08:11:16
- Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s
---\\ Scan Additionnel (O88)
Database Version : 13008 - (05/05/2015)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 41
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\7Zip Bundle by Fileparade.com] =>PUP.SweetIM^
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro^
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab^
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar^
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab^
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab^
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo^
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay^
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy^
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo^
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo^
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab^
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab^
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream^
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo^
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo^
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream^
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine^
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab^
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager^
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab^
~ Additionnel Scan: 669949 Items scanned in 00mn 29s
---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects de navigateur (O2)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
~ AMI: 5 Scanned in 00mn 00s
---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/pup-sweetim =>PUP.SweetIM
http://nicolascoolman.fr/pup-optimizerpro =>PUP.OptimizerPro
http://www.nicolascoolman.fr/blog/ =>PUP.Nosibay
http://nicolascoolman.fr/adware-onetab =>Adware.OneTab
http://nicolascoolman.fr/hijacker-findrtoolbar =>Hijacker.FindrToolbar
http://nicolascoolman.fr/hijacker-smartbar =>Hijacker.SmartBar
http://nicolascoolman.fr/pup-eorezo =>PUP.EoRezo
http://nicolascoolman.fr/pup-minibar =>PUP.Minibar
http://nicolascoolman.fr/hijacker-proxy =>Hijacker.Proxy
http://nicolascoolman.fr/adware-metastream =>Adware.MetaStream
http://nicolascoolman.fr/pup-softwareengine =>PUP.SoftwareEngine
http://nicolascoolman.fr/pup-manager =>PUP.Manager
~ MSI: 12 link(s) detected in 00mn 00s
End of the scan (1555 lines in 04mn 47s)(2.11)
Avec la dernière MAJ c'est mieux. J'ai connecté le DD externe pour ce test.
~ Rapport de ZHPDiag v2015.5.8.47 - Nicolas Coolman (05/05/2015)
~ Lancé par Amaury (11/05/2015 11:08:15)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Désactivée par l'utilisateur
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user
---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17728
MFIE: Mozilla Firefox 37.0.2 (Defaut)
---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows Operating System - Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : RMV82
Windows License : OK
~ Windows Remaining Initializations Number : 4
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Vista (TM) Ultimate, 32-bit Service Pack 1 (Build 6000)
---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 2.1.6.1022
Microsoft Security Client v4.7.0205.0
---\\ Logiciels d'optimisation du système
CCleaner v5.05
---\\ Logiciels de partage PeerToPeer
---\\ Surveillance de Logiciels
Adobe Flash Player 17 NPAPI
Adobe Reader X
---\\ Informations sur le système
~ Processor: x86 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2998 MB (51% free)
System Restore: Activé (Enable)
System drive C: has 173 GB (60%) free of 287 GB
---\\ Mode de connexion au système
~ Computer Name: AMAURY-PC
~ User Name: Amaury
~ All Users Names: HomeGroupUser$, Amaury, Administrateur,
~ Unselected Option: None
Logged in as Administrator
---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Amaury\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Amaury\AppData\Roaming\
~ %Desktop% : C:\Users\Amaury\Desktop\
~ %Favorites% : C:\Users\Amaury\Favorites\
~ %LocalAppData% : C:\Users\Amaury\AppData\Local\
~ %StartMenu% : C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 173 Go of 287 Go)
D: CD-ROM drive (Not Inserted)
E: Hard drive, Flash drive, Thumb drive (Free 184 Go of 298 Go)
---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: 43 Scanned in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.C46904F2E9E121A91DDDABB48D7648C3] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.13/03/2015 - 03:20:28.) -- C:\Windows\System32\wininet.dll [1888256]
[MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.17/07/2014 - 02:39:27.) -- C:\Windows\System32\Winlogon.exe [304128]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 13:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:36:07.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 09:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 09:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 10:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 09:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:18:22.) -- C:\Windows\system32\Drivers\ntfs.sys [1212352]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:32:14.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 13:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Generic Processes: Scanned in 00mn 00s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/3
~ Mes musiques (My Musics) : 1/185
~ Mes Favoris (My Favorites) : 1/30
~ Mes Documents (My Documents) : 2/1045
~ Mon Bureau (My Desktop) : 15/82418
~ Menu demarrer (Programs) : 1/30
~ Hidden Files: Scanned in 00mn 10s
---\\ Processus lancés
[MD5.567B0B979E206C3E1E7B4422A2D0A5AD] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1602856] [PID.3668]
[MD5.A9D62C7793510D81342AC1AC50FB70F5] - (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe [495708] [PID.3756]
[MD5.C7AF01132A0DD241A1A0DBE9B62A9A1C] - (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\quickset.exe [3873648] [PID.3584]
[MD5.D50F04F005C94FA3802A6E05CFCF4A9A] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.3276]
[MD5.B7680F36C41AE21C0ECA96523443831F] - (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe [727664] [PID.3400]
[MD5.22001D1308E34153D2BCD51368E14F7B] - (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5249024] [PID.3708]
[MD5.2059A96CB2254829488A6A676AA4BA15] - (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\DpAgent.exe [842816] [PID.3460]
[MD5.0FE0EDF01CEA3BEB2E65A904BB87525E] - (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe [640376] [PID.3892]
[MD5.9A8568C7642B79F43DCEB0BDF9F49050] - (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe [542136] [PID.3768]
[MD5.CCA0C5482B8A6A275D9D49433F435DFA] - (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe [542096] [PID.3872]
[MD5.46B9C74861D98EDA9E6E56D19BEAF91A] - (.Broadcom Corporation. - Bluetooth Tray Application.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [795936] [PID.2220]
[MD5.2727208EA26F6B6DA898AB6890417214] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8208384] [PID.2124]
[MD5.F26F7A5B18C717E57E3B6B306ABEC00B] - (.Microsoft Corporation - Antimalware Service Executable.) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe [22184] [PID.824]
[MD5.FBAA145C28074C853529050914D405C6] - (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe [229458] [PID.1104]
[MD5.F44970C4137B57A5D5BD632B46113366] - (.Validity Sensors, Inc. - VFS101 VCS API Library.) -- C:\Windows\system32\vcsFPService.exe [1664304] [PID.1440]
[MD5.6F44F5C0BC6B210FE5F5A1C8D899AD0A] - (.Microsoft Corporation - Infrastructure d'extensibilité pour les ser.) -- C:\Windows\system32\WLANExt.exe [77312] [PID.1580]
[MD5.7FFF34AE69DFB80F7B190ABA31E00610] - (.Dell Inc. - DW WLAN Card Wireless Network Service.) -- C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe [40960] [PID.1636]
[MD5.04F8CD09706C9E6BD8C641DD235B3964] - (.Dell Inc. - DW WLAN Card Wireless Network Controller.) -- C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe [4539392] [PID.1692]
[MD5.0C23BF4CDDBECBACA8659A96C359E0DD] - (.DigitalPersona, Inc. - DigitalPersona Local Host.) -- C:\Program Files\DigitalPersona\Bin\DpHostW.exe [322624] [PID.1776]
[MD5.FC5B75CA6A1DA31EDD4F8D53F5540B98] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [81088] [PID.1936]
[MD5.827DBC22C96EECF6D36A13162FABAFD3] - (.Andrea Electronics Corporation - Andrea filters APO access service (32-bit).) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe [81920] [PID.1960]
[MD5.4FE5C6D40664AE07BE5105874357D2ED] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [57008] [PID.1988]
[MD5.DB5BEA73EDAF19AC68B2C0FAD0F92B1A] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [390504] [PID.2024]
[MD5.45F36763576B8AE91E809337DC7CE4E6] - (.Broadcom Corporation. - Bluetooth Support Server.) -- c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [595232] [PID.2044]
[MD5.1F79342D9EB530A48742F651E570983A] - (.Microsoft Corporation - Updates Skype Click to Call.) -- C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176] [PID.324]
[MD5.E4938E0A376CF0B9D989EE5C0A146891] - (.Microsoft Corporation - Phone Number Recognition (PNR) module.) -- C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520] [PID.328]
[MD5.5460828F8951D310B42B442877603B8D] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [268824] [PID.1408]
[MD5.ACABD09AFD92D37BED3B7BA010C03A1C] - (.Dell Inc. - Service.) -- C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [19288] [PID.2368]
[MD5.1452F52471F2DC1515DD6C35B42FF06E] - (.Microsoft Corporation - Microsoft Network Realtime Inspection Servi.) -- c:\Program Files\Microsoft Security Client\NisSrv.exe [284472] [PID.2836]
[MD5.C644FA79C4C31DC25608C3F87A62808F] - (.Dell Inc. - Dell Data Vault Wizard.) -- C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [184016] [PID.920]
[MD5.9E89C2D6945389270DE067CE51FF7425] - (.Intel Corporation - User Notification Service.) -- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2320920] [PID.1828]
[MD5.496ABDFCC9D52BF3DC0154FC56AB5D77] - (.Dell Inc. - Dell Data Vault Service.) -- C:\Program Files\Dell\DellDataVault\DellDataVault.exe [1947344] [PID.5960]
[MD5.2C49B175AEE1D4364B91B531417FE583] - (.Microsoft Corporation - Programme d'installation pour les modules W.) -- C:\Windows\servicing\TrustedInstaller.exe [204800] [PID.2668]
[MD5.CF87A1DE791347E75B98885214CED2B8] - (.Microsoft Corporation - Service de la plateforme de protection logi.) -- C:\Windows\system32\sppsvc.exe [3179520] [PID.3344]
~ Processes Running: Scanned in 00mn 01s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Amaury\AppData\Local\Google\Chrome\User Data\Default\Preferences
---\\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 0 Scanned in 00mn 00s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFF12.DLL
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo-france.xml
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll =>.Google Inc
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=11.31.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Windows\system32\npdeployJava1.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Oracle Corporation - Next Generation Java Plug-in 11.31.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=11.31.2] - (.Oracle Corporation - Next Generation Java Plug-in 11.31.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) -- C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
~ Firefox Browser: 31 Scanned in 00mn 00s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) (No version) -- (.not file.)
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
~ IE Browser: 11 Scanned in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: DigitalPersona Fingerprint Software Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} . (.DigitalPersona, Inc. - DigitalPersona OTS Feedback.) -- C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} . (.Microsoft Corporation - Windows Live Messenger Companion Core.) -- C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
~ BHO: 14 Scanned in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Adobe PDF - [HKLM]{47833539-D0C5-4125-9FA8-0819E2EAAC93} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{47833539-D0C5-4125-9FA8-0819E2EAAC93} Clé orpheline
~ Toolbar: Scanned in 00mn 00s
---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [QuickSet] . (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [FreeFallProtection] . (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] . (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [DpAgent] . (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] . (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKCU\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
~ Application: Scanned in 00mn 00s
---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ IE Control Panel: 1 Scanned in 00mn 00s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} . (.Microsoft Corporation - Windows Live Messenger Companion core resources.) -- C:\Program Files\Windows Live\Companion\companionres.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- c:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000009\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000010\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll
~ Winsock: 10 Scanned in 00mn 00s
---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] *.dell.com
~ IE Zone Confiance: Scanned in 00mn 00s
---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} ((no name)) - http://support.euro.dell.com/systemprofiler/DellSystemLite.CAB
~ Objets ActiveX: Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s
---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ SSODL: 1 Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) . (.Andrea Electronics Corporation - Andrea filters APO access service (32-bit).) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) . (.Broadcom Corporation. - Bluetooth Support Server.) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dell Data Vault (DellDataVault) . (.Dell Inc. - Dell Data Vault Service.) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
O23 - Service: Dell Data Vault Wizard (DellDataVaultWiz) . (.Dell Inc. - Dell Data Vault Wizard.) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
O23 - Service: C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DpHost) . (.DigitalPersona, Inc. - DigitalPersona Local Host.) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) . (.Sonic Solutions - RoxWatch12 Module.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Audio Service (STacSV) . (.IDT, Inc. - IDT PC Audio.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
O23 - Service: Dell SupportAssist Agent (SupportAssistAgent) . (.Dell Inc. - Service.) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
O23 - Service: Intel(R) Management & Security Application User Notificatio (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) . (.Validity Sensors, Inc. - VFS101 VCS API Library.) - C:\Windows\system32\vcsFPService.exe
O23 - Service: DW WLAN Tray Service (wltrysvc) . (.Dell Inc. - DW WLAN Card Wireless Network Service.) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
~ Services: 19 Scanned in 00mn 06s
---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Desktop Component: 4 Scanned in 00mn 00s
---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
[MD5.3E04F1E482357B1FC8B088197C3D9FF8] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152]
[MD5.B04A4810C6CC205F9DC72DC22E4AB236] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [268464]
[MD5.1F014EA12ECB13C909DA9395E9CD3D18] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6278424]
[MD5.2BCB174FF294F83C3520D46B57DBD917] [APT] [Dell SupportAssistAgent AutoUpdate] (.Dell Inc..) -- C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [27472]
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107912]
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107912]
[MD5.79B5DD0E04130BF31AA598F2AEBB1B78] [APT] [PCDEventLauncherTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell\SupportAssist\sessionchecker.exe [433488]
[MD5.254EC04C72D02E4C8EEC08D4CF3658B1] [APT] [PCDoctorBackgroundMonitorTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell\SupportAssist\uaclauncher.exe [1189200]
[MD5.C155A13687144076286989EF078112C2] [APT] [{0815057C-EFA1-4BCA-B1FE-135DCE6988D1}] (.Nicolas Coolman.) -- C:\Program Files\ZHPDiag\ZHPhep.exe [1917440]
[MD5.A75AE3B84B6423CE6A088E80A2BC23C2] [APT] [{4773655F-F316-4A0B-AAD8-B898B8AF2A0A}] (.Skype Technologies S.A..) -- C:\Program Files\Skype\Phone\Skype.exe [31280256]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{7A7B4145-1139-4669-8765-5936ED3BBC3A}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{A28E5010-28AC-4FF0-9EDF-0210636C319A}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [561984]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1054]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1054]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1058]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1058]
~ Scheduled Task: 17 Scanned in 00mn 04s
---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft VM - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Microsoft Corporation - Microsoft® VM.) -- C:\Windows\system32\msjava.dll
O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Disable SSL3 - {7D715857-A67C-4C2F-A929-038448584D63} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
~ Active Setup: 11 Scanned in 00mn 00s
---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys
O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
O41 - Driver: (MpKsl27db1ee3) . (.Microsoft Corporation - KSLDriver.) - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2698567C-ABF3-4177-B0E6-C232BD8B10E0}\MpKsl27db1ee3.sys
O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys
O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
~ Drivers: 62 Scanned in 00mn 00s
---\\ Logiciels installés (O42)
O42 - Logiciel: 7-Zip 9.20 - (...) [HKLM] -- 7-Zip
O42 - Logiciel: 7Zip Bundle by Fileparade.com - (.SweetPacks LTD.) [HKLM] -- 7Zip Bundle by Fileparade.com =>PUP.SweetIM
O42 - Logiciel: AccelerometerP11 - (.STMicroelectronics.) [HKLM] -- {87434D51-51DB-4109-B68F-A829ECDCF380}
O42 - Logiciel: Adobe After Effects CS4 Third Party Content - (.Adobe Systems Incorporated.) [HKLM] -- {67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}
O42 - Logiciel: Adobe Anchor Service CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {1618734A-3957-4ADD-8199-F973763109A8}
O42 - Logiciel: Adobe Bridge CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {83877DB1-8B77-45BC-AB43-2BAC22E093E0} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe CMaps CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {94D398EB-D2FD-4FD1-B8C4-592635E8A191}
O42 - Logiciel: Adobe CSI CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0F723FC1-7606-4867-866C-CE80AD292DAF}
O42 - Logiciel: Adobe Color EU Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}
O42 - Logiciel: Adobe Color JA Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0D6013AB-A0C7-41DC-973C-E93129C9A29F}
O42 - Logiciel: Adobe Color NA Recommended Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {00ADFB20-AE75-46F4-AD2C-F48B15AC3100}
O42 - Logiciel: Adobe Color Video Profiles CS CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {63C24A08-70F3-4C8E-B9FB-9F21A903801D}
O42 - Logiciel: Adobe Creative Suite 4 Master Collection - (.Adobe Systems Incorporated.) [HKLM] -- Adobe_b2b1c7c62c4ae0a954789ed71d36a7a
O42 - Logiciel: Adobe Creative Suite 4 Master Collection - (.Adobe Systems Incorporated.) [HKLM] -- {D0EE7809-8F5E-46EF-95DC-B30DCE22653F}
O42 - Logiciel: Adobe Default Language CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {C52E3EC1-048C-45E1-8D53-10B0C6509683}
O42 - Logiciel: Adobe Encore CS4 Codecs - (.Adobe Systems Incorporated.) [HKLM] -- {FB2A5FCC-B81B-48C2-A009-7804694D83E9}
O42 - Logiciel: Adobe ExtendScript Toolkit CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F8EF2B3F-C345-4F20-8FE4-791A20333CD5} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Extension Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {054EFA56-2AC1-48F4-A883-0AB89874B972}
O42 - Logiciel: Adobe Flash Player 17 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 17 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI
O42 - Logiciel: Adobe Fonts All - (.Adobe Systems Incorporated.) [HKLM] -- {FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
O42 - Logiciel: Adobe Illustrator CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05C677A1-A161-447E-92ED-2D5B38AA0740} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {A2160D84-F2D0-47A3-AA59-CCB3CA21D558} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Application Feature Set Files (Roman) - (.Adobe Systems Incorporated.) [HKLM] -- {C950299F-BCAB-4695-B077-FC3B2748C25D} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Common Base Files - (.Adobe Systems Incorporated.) [HKLM] -- {26F72DC3-DDBE-424F-B9F0-94E5D0E5A12B} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Icon Handler - (.Adobe Systems Incorporated.) [HKLM] -- {2BA4F7B0-F38E-4AE8-80A2-E9C5956C6D6D} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Linguistics CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {931AB7EA-3656-4BB7-864D-022B09E3DD67}
O42 - Logiciel: Adobe Media Encoder CS4 Exporter - (.Adobe Systems Incorporated.) [HKLM] -- {561968FD-56A1-49FD-9ED0-F55482C7C5BC}
O42 - Logiciel: Adobe Media Encoder CS4 Importer - (.Adobe Systems Incorporated.) [HKLM] -- {8186FF34-D389-4B7E-9A2F-C197585BCFBD}
O42 - Logiciel: Adobe Output Module - (.Adobe Systems Incorporated.) [HKLM] -- {BB4E33EC-8181-4685-96F7-8554293DEC6A}
O42 - Logiciel: Adobe PDF Library Files CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F93C84A6-0DC6-42AF-89FA-776F7C377353}
O42 - Logiciel: Adobe Photoshop CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {E2E01E91-2314-42BC-B5E3-1715DAE84F98} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Photoshop CS4 Support - (.Adobe Systems Incorporated.) [HKLM] -- {73E17122-EC84-45B4-943B-735257B5CBDC} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Premiere Pro CS4 Third Party Content - (.Adobe Systems Incorporated.) [HKLM] -- {E1951CF4-91CE-46F0-A1BD-3A4A67069097}
O42 - Logiciel: Adobe Reader X (10.1.13) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AA1000000001}
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-0804-1033-1959-001802114130}
O42 - Logiciel: Adobe SGM CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}
O42 - Logiciel: Adobe SING CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {8CB16C77-9D75-4966-91E8-D785B87EC078}
O42 - Logiciel: Adobe Search for Help - (.Adobe Systems Incorporated.) [HKLM] -- {F0E64E2E-3A60-40D8-A55D-92F6831875DA}
O42 - Logiciel: Adobe Service Manager Extension - (.Adobe Systems Incorporated.) [HKLM] -- {4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
O42 - Logiciel: Adobe Setup - (.Adobe Systems Incorporated.) [HKLM] -- {6577657B-A10C-47A1-A50D-512C7748CB2C}
O42 - Logiciel: Adobe Soundbooth CS4 Codecs - (.Adobe Systems Incorporated.) [HKLM] -- {52232EF4-CC12-4C21-ABCF-ADB79618302D}
O42 - Logiciel: Adobe Type Support CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
O42 - Logiciel: Adobe Update Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05308C4E-7285-4066-BAE3-6B50DA6ED755}
O42 - Logiciel: Adobe WinSoft Linguistics Plugin - (.Adobe Systems Incorporated.) [HKLM] -- {3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
O42 - Logiciel: Adobe XMP Panels CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
O42 - Logiciel: AdobeColorCommonSetCMYK - (.Adobe Systems Incorporated.) [HKLM] -- {E5FCED12-3E77-4C0E-A305-5AEB38A52A70}
O42 - Logiciel: AdobeColorCommonSetRGB - (.Adobe Systems Incorporated.) [HKLM] -- {16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
O42 - Logiciel: Advanced Audio FX Engine - (.Creative Technology Ltd.) [HKLM] -- Advanced Audio FX Engine
O42 - Logiciel: Antidote RX v7 - (.Druide informatique inc..) [HKLM] -- {A474EA56-5DBD-4181-8230-806A4762EA7F}
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {5D09C772-ECB3-442B-9CC6-B4341C78FDC2}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {E14ADE0E-75F3-4A46-87E5-26692DD626EC}
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} =>.Apple Inc
O42 - Logiciel: ArcGIS 10.1 for Desktop - (.Environmental Systems Research Institute, Inc..) [HKLM] -- ArcGIS 10.1 for Desktop
O42 - Logiciel: ArcGIS 10.1 for Desktop - Module linguistique français - (.Environmental Systems Research Institute, Inc..) [HKLM] -- ArcGIS 10.1 for Desktop - Module linguistique français
O42 - Logiciel: ArcGIS 10.1 for Desktop - Module linguistique français - (.Environmental Systems Research Institute, Inc..) [HKLM] -- {311DA2E4-3B6A-464F-8987-C4AAE6B9386D}
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {79155F2B-9895-49D7-8612-D92580E0DE5B}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: CDBurnerXP - (.CDBurnerXP.) [HKLM] -- {7E265513-8CDA-4631-B696-F40D983F3B07}_is1
O42 - Logiciel: Canon MG5200 series MP Drivers - (...) [HKLM] -- {1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series
O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM] -- {64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {51C7AD07-C3F6-4635-8E8A-231306D810FE}
O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
O42 - Logiciel: Complément Messenger - (.Microsoft Corporation.) [HKLM] -- {6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}
O42 - Logiciel: Connect - (.Adobe Systems Incorporated.) [HKLM] -- {B29AD377-CC12-490A-A480-1452337C618D}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM] -- InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM] -- {A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
O42 - Logiciel: DW WLAN Card Utility - (.Dell Inc..) [HKLM] -- DW WLAN Card Utility
O42 - Logiciel: Dell Backup and Recovery Manager - (.Dell Inc..) [HKLM] -- {4688EB75-28E2-4731-9BCB-55E624F7CD45}
O42 - Logiciel: Dell Data Vault - (.Dell Inc..) [HKLM] -- {2E55EEFD-2162-4A7D-9158-EDB0305603A6}
O42 - Logiciel: Dell Edoc Viewer - (.Dell Inc.) [HKLM] -- {3138EAD3-700B-4A10-B617-B3F8096EE30D}
O42 - Logiciel: Dell SupportAssist - (.Dell.) [HKLM] -- PC-Doctor for Windows
O42 - Logiciel: Dell SupportAssistAgent - (.Dell.) [HKLM] -- {287348C8-8B47-4C36-AF28-441A3B7D8722}
O42 - Logiciel: Dell Touchpad - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey
O42 - Logiciel: Dell Webcam Central - (.Creative Technology Ltd.) [HKLM] -- Dell Webcam Central
O42 - Logiciel: DigitalPersona Personal 4.01 - (.DigitalPersona, Inc..) [HKLM] -- {3D8AE086-030F-4EF4-B705-63F8130B043E}
O42 - Logiciel: DirectX 9 Runtime - (.Sonic Solutions.) [HKLM] -- {AF9E97C1-7431-426D-A8D5-ABE40995C0B1}
O42 - Logiciel: EndNote X3 - (.Thomson Reuters.) [HKLM] -- {86B3F2D6-AC2B-4E88-8AE1-F2F77F781B0C}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}
O42 - Logiciel: IRIScan(TM) Direct - (.IRIScanDirect.) [HKLM] -- IRIScanDirect_is1
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
O42 - Logiciel: Java 8 Update 31 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83218031F0}
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
O42 - Logiciel: Logiciel d'archivage WinRAR - (...) [HKLM] -- WinRAR archiver
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: Malwarebytes Anti-Malware version 2.1.6.1022 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1
O42 - Logiciel: Mesh Runtime - (.Microsoft Corporation.) [HKLM] -- {8C6D6116-B724-4810-8F2D-D047E6B7D68E}
O42 - Logiciel: Microsoft Image Composite Editor - (.Microsoft Corporation.) [HKLM] -- {3D599ADA-65D9-4B51-898F-CE718DEC5DBB}
O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {D6F9CBDC-58B6-430A-8DD4-8F61CBC1ADF4}
O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Mozilla Firefox 37.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 37.0.2 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: PDF Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
O42 - Logiciel: PhotoShowExpress - (.Sonic Solutions.) [HKLM] -- {3250260C-7A95-4632-893B-89657EB5545B}
O42 - Logiciel: Photoshop Camera Raw - (.Adobe Systems Incorporated.) [HKLM] -- {CC75AB5C-2110-4A7F-AF52-708680D22FE8}
O42 - Logiciel: QuickSet32 - (.Dell Inc..) [HKLM] -- {C4972073-2BFE-475D-8441-564EA97DA161}
O42 - Logiciel: ResearchSoft Direct Export Helper - (...) [HKLM] -- ResearchSoft Direct Export Helper
O42 - Logiciel: Roxio Activation Module - (.Roxio.) [HKLM] -- {A121EEDE-C68F-461D-91AA-D48BA226AF1C}
O42 - Logiciel: Roxio BackOnTrack - (.Roxio.) [HKLM] -- {5A06423A-210C-49FB-950E-CB0EB8C5CEC7}
O42 - Logiciel: Roxio Burn - (.Roxio.) [HKLM] -- {9569E6BC-326A-432F-97AB-35263A327BF1}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {EF56258E-0326-48C5-A86C-3BAC26FC15DF}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}
O42 - Logiciel: Roxio Express Labeler 3 - (.Roxio.) [HKLM] -- {6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
O42 - Logiciel: Roxio File Backup - (.Roxio.) [HKLM] -- {60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}
O42 - Logiciel: Samsung Printer Live Update - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung Printer Live Update
O42 - Logiciel: Satsuki Decoder Pack - (.Satsuki Yatoshi'S Softs.) [HKLM] -- Satsuki Decoder Pack
O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701}
O42 - Logiciel: Skype(TM) 7.4 - (.Skype Technologies S.A..) [HKLM] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
O42 - Logiciel: Sonic CinePlayer Decoder Pack - (.Sonic Solutions.) [HKLM] -- {9A00EC4E-27E1-42C4-98DD-662F32AC8870}
O42 - Logiciel: Spotify - (...) [HKLM] -- Spotify
O42 - Logiciel: Spotify - (.Spotify AB.) [HKCU] -- Spotify
O42 - Logiciel: Suite Shared Configuration CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {842B4B72-9E8F-4962-B3C1-1C422A5C4434}
O42 - Logiciel: TuxGuitar 1.2 - (...) [HKLM] -- TuxGuitar_0
O42 - Logiciel: Validity Sensors DDK - (.Validity Sensors, Inc..) [HKLM] -- {9FCB6355-689E-4141-9714-3EEC2AE10292}
O42 - Logiciel: WIDCOMM Bluetooth Software - (.Broadcom Corporation.) [HKLM] -- {9E9D49A4-1DF4-4138-B7DB-5D87A893088E}
O42 - Logiciel: XnView 2.22 - (.Gougelet Pierre-e.) [HKLM] -- XnView_is1
O42 - Logiciel: Xvid 1.2.1 final uninstall - (.Xvid team (Koepi).) [HKLM] -- Xvid_is1
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {11E568E0-3244-4BCB-875E-F334269DFDCB}
O42 - Logiciel: kuler - (.Adobe Systems Incorporated.) [HKLM] -- {098727E1-775A-4450-B573-3F441F1CA243}
~ Logic: 44 Scanned in 00mn 00s
---\\ HKCU & HKLM Software Keys
[HKCU\Software\7-Zip]
[HKCU\Software\AC3Filter]
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow\Software\DigitalPersona]
[HKCU\Software\AppDataLow\Software\JavaSoft]
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Arobas Music]
[HKCU\Software\Broadcom]
[HKCU\Software\CG Information]
[HKCU\Software\Canneverbe Limited]
[HKCU\Software\Canon]
[HKCU\Software\Citrix]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\Creative Tech]
[HKCU\Software\CyberLink]
[HKCU\Software\DT Soft]
[HKCU\Software\Developer Express]
[HKCU\Software\DigitalPersona]
[HKCU\Software\Druide informatique inc.]
[HKCU\Software\ERDAS]
[HKCU\Software\ESRI]
[HKCU\Software\EasyBits]
[HKCU\Software\Eset]
[HKCU\Software\GNU]
[HKCU\Software\Gabest]
[HKCU\Software\Google]
[HKCU\Software\HKEY_LOCAL_MACHINE]
[HKCU\Software\Haali]
[HKCU\Software\Herac]
[HKCU\Software\IDAVLab]
[HKCU\Software\IDT]
[HKCU\Software\IM Providers]
[HKCU\Software\ISI ResearchSoft]
[HKCU\Software\Intel\Indeo\4.1]
[HKCU\Software\Intel]
[HKCU\Software\JavaSoft]
[HKCU\Software\Lake]
[HKCU\Software\LogiShrd]
[HKCU\Software\MCAFEE]
[HKCU\Software\Macromedia]
[HKCU\Software\Macrovision]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Nero]
[HKCU\Software\Netscape]
[HKCU\Software\Northcode Inc]
[HKCU\Software\ODBC]
[HKCU\Software\PC-Doctor]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\RICOH]
[HKCU\Software\RealNetworks]
[HKCU\Software\RegisteredApplications]
[HKCU\Software\Roxio]
[HKCU\Software\SSPrint]
[HKCU\Software\STUDIO SARMADI]
[HKCU\Software\Samsung]
[HKCU\Software\Satsuki Decoder Pack]
[HKCU\Software\SecuROM]
[HKCU\Software\Skype]
[HKCU\Software\Synaptics]
[HKCU\Software\Trolltech]
[HKCU\Software\Widcomm]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\ZebHelpProcess Helper]
[HKLM\Software\ATI Technologies]
[HKLM\Software\Adobe]
[HKLM\Software\AdwCleaner]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\BcmSetup]
[HKLM\Software\Broadcom]
[HKLM\Software\Canneverbe Limited]
[HKLM\Software\Canon]
[HKLM\Software\Citrix]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Creative Tech]
[HKLM\Software\CyberLink]
[HKLM\Software\DT Soft]
[HKLM\Software\Debug]
[HKLM\Software\Dell Computer Corporation]
[HKLM\Software\Dell Inc.]
[HKLM\Software\Dell]
[HKLM\Software\DigitalPersona]
[HKLM\Software\Druide informatique inc.]
[HKLM\Software\ERDAS]
[HKLM\Software\ESRI]
[HKLM\Software\FreeFallProtection]
[HKLM\Software\GEAR Software]
[HKLM\Software\GNU]
[HKLM\Software\Gabest]
[HKLM\Software\Google]
[HKLM\Software\HaaliMkx]
[HKLM\Software\IDAVLab]
[HKLM\Software\IDT]
[HKLM\Software\IM Providers]
[HKLM\Software\ISI ResearchSoft]
[HKLM\Software\Imagineer Systems Ltd]
[HKLM\Software\InstalledOptions]
[HKLM\Software\Intel]
[HKLM\Software\InterVideo]
[HKLM\Software\JavaSoft]
[HKLM\Software\JreMetrics]
[HKLM\Software\Lake]
[HKLM\Software\Logishrd]
[HKLM\Software\MAXSOFT-OCRON]
[HKLM\Software\Macromedia]
[HKLM\Software\Macrovision]
[HKLM\Software\Malwarebytes' Anti-Malware (Trial)]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\ManageableUpdatePackage]
[HKLM\Software\McAfee.com]
[HKLM\Software\McAfeeInstaller]
[HKLM\Software\McAfee]
[HKLM\Software\MicroVision]
[HKLM\Software\MimarSinan]
[HKLM\Software\Mircrosoft]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Nero]
[HKLM\Software\Novell]
[HKLM\Software\ODBC]
[HKLM\Software\PC-Doctor]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\Python]
[HKLM\Software\RealNetworks]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Roxio]
[HKLM\Software\SSPrint]
[HKLM\Software\STMicroelectronics]
[HKLM\Software\Samsung]
[HKLM\Software\Skype]
[HKLM\Software\Sonic]
[HKLM\Software\Synaptics]
[HKLM\Software\Synthetic Aperture]
[HKLM\Software\Validity]
[HKLM\Software\Vantage Software Technologies]
[HKLM\Software\Volatile]
[HKLM\Software\Widcomm]
[HKLM\Software\WinRAR]
[HKLM\Software\Windows]
[HKLM\Software\Wise Solutions]
[HKLM\Software\XnView]
[HKLM\Software\illiminable]
[HKLM\Software\mozilla.org]
~ Key Software: 327 Scanned in 00mn 00s
~ Rapport de ZHPDiag v2015.5.8.47 - Nicolas Coolman (05/05/2015)
~ Lancé par Amaury (11/05/2015 11:08:15)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Désactivée par l'utilisateur
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user
---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17728
MFIE: Mozilla Firefox 37.0.2 (Defaut)
---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows Operating System - Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : RMV82
Windows License : OK
~ Windows Remaining Initializations Number : 4
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Vista (TM) Ultimate, 32-bit Service Pack 1 (Build 6000)
---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 2.1.6.1022
Microsoft Security Client v4.7.0205.0
---\\ Logiciels d'optimisation du système
CCleaner v5.05
---\\ Logiciels de partage PeerToPeer
---\\ Surveillance de Logiciels
Adobe Flash Player 17 NPAPI
Adobe Reader X
---\\ Informations sur le système
~ Processor: x86 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2998 MB (51% free)
System Restore: Activé (Enable)
System drive C: has 173 GB (60%) free of 287 GB
---\\ Mode de connexion au système
~ Computer Name: AMAURY-PC
~ User Name: Amaury
~ All Users Names: HomeGroupUser$, Amaury, Administrateur,
~ Unselected Option: None
Logged in as Administrator
---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Amaury\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Amaury\AppData\Roaming\
~ %Desktop% : C:\Users\Amaury\Desktop\
~ %Favorites% : C:\Users\Amaury\Favorites\
~ %LocalAppData% : C:\Users\Amaury\AppData\Local\
~ %StartMenu% : C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 173 Go of 287 Go)
D: CD-ROM drive (Not Inserted)
E: Hard drive, Flash drive, Thumb drive (Free 184 Go of 298 Go)
---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: 43 Scanned in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.C46904F2E9E121A91DDDABB48D7648C3] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.13/03/2015 - 03:20:28.) -- C:\Windows\System32\wininet.dll [1888256]
[MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.17/07/2014 - 02:39:27.) -- C:\Windows\System32\Winlogon.exe [304128]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 13:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:36:07.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 09:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 09:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 10:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 09:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:18:22.) -- C:\Windows\system32\Drivers\ntfs.sys [1212352]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:32:14.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 13:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Generic Processes: Scanned in 00mn 00s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/3
~ Mes musiques (My Musics) : 1/185
~ Mes Favoris (My Favorites) : 1/30
~ Mes Documents (My Documents) : 2/1045
~ Mon Bureau (My Desktop) : 15/82418
~ Menu demarrer (Programs) : 1/30
~ Hidden Files: Scanned in 00mn 10s
---\\ Processus lancés
[MD5.567B0B979E206C3E1E7B4422A2D0A5AD] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1602856] [PID.3668]
[MD5.A9D62C7793510D81342AC1AC50FB70F5] - (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe [495708] [PID.3756]
[MD5.C7AF01132A0DD241A1A0DBE9B62A9A1C] - (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\quickset.exe [3873648] [PID.3584]
[MD5.D50F04F005C94FA3802A6E05CFCF4A9A] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.3276]
[MD5.B7680F36C41AE21C0ECA96523443831F] - (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe [727664] [PID.3400]
[MD5.22001D1308E34153D2BCD51368E14F7B] - (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5249024] [PID.3708]
[MD5.2059A96CB2254829488A6A676AA4BA15] - (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\DpAgent.exe [842816] [PID.3460]
[MD5.0FE0EDF01CEA3BEB2E65A904BB87525E] - (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe [640376] [PID.3892]
[MD5.9A8568C7642B79F43DCEB0BDF9F49050] - (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe [542136] [PID.3768]
[MD5.CCA0C5482B8A6A275D9D49433F435DFA] - (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe [542096] [PID.3872]
[MD5.46B9C74861D98EDA9E6E56D19BEAF91A] - (.Broadcom Corporation. - Bluetooth Tray Application.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [795936] [PID.2220]
[MD5.2727208EA26F6B6DA898AB6890417214] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8208384] [PID.2124]
[MD5.F26F7A5B18C717E57E3B6B306ABEC00B] - (.Microsoft Corporation - Antimalware Service Executable.) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe [22184] [PID.824]
[MD5.FBAA145C28074C853529050914D405C6] - (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe [229458] [PID.1104]
[MD5.F44970C4137B57A5D5BD632B46113366] - (.Validity Sensors, Inc. - VFS101 VCS API Library.) -- C:\Windows\system32\vcsFPService.exe [1664304] [PID.1440]
[MD5.6F44F5C0BC6B210FE5F5A1C8D899AD0A] - (.Microsoft Corporation - Infrastructure d'extensibilité pour les ser.) -- C:\Windows\system32\WLANExt.exe [77312] [PID.1580]
[MD5.7FFF34AE69DFB80F7B190ABA31E00610] - (.Dell Inc. - DW WLAN Card Wireless Network Service.) -- C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe [40960] [PID.1636]
[MD5.04F8CD09706C9E6BD8C641DD235B3964] - (.Dell Inc. - DW WLAN Card Wireless Network Controller.) -- C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe [4539392] [PID.1692]
[MD5.0C23BF4CDDBECBACA8659A96C359E0DD] - (.DigitalPersona, Inc. - DigitalPersona Local Host.) -- C:\Program Files\DigitalPersona\Bin\DpHostW.exe [322624] [PID.1776]
[MD5.FC5B75CA6A1DA31EDD4F8D53F5540B98] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [81088] [PID.1936]
[MD5.827DBC22C96EECF6D36A13162FABAFD3] - (.Andrea Electronics Corporation - Andrea filters APO access service (32-bit).) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe [81920] [PID.1960]
[MD5.4FE5C6D40664AE07BE5105874357D2ED] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [57008] [PID.1988]
[MD5.DB5BEA73EDAF19AC68B2C0FAD0F92B1A] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [390504] [PID.2024]
[MD5.45F36763576B8AE91E809337DC7CE4E6] - (.Broadcom Corporation. - Bluetooth Support Server.) -- c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [595232] [PID.2044]
[MD5.1F79342D9EB530A48742F651E570983A] - (.Microsoft Corporation - Updates Skype Click to Call.) -- C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176] [PID.324]
[MD5.E4938E0A376CF0B9D989EE5C0A146891] - (.Microsoft Corporation - Phone Number Recognition (PNR) module.) -- C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520] [PID.328]
[MD5.5460828F8951D310B42B442877603B8D] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [268824] [PID.1408]
[MD5.ACABD09AFD92D37BED3B7BA010C03A1C] - (.Dell Inc. - Service.) -- C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [19288] [PID.2368]
[MD5.1452F52471F2DC1515DD6C35B42FF06E] - (.Microsoft Corporation - Microsoft Network Realtime Inspection Servi.) -- c:\Program Files\Microsoft Security Client\NisSrv.exe [284472] [PID.2836]
[MD5.C644FA79C4C31DC25608C3F87A62808F] - (.Dell Inc. - Dell Data Vault Wizard.) -- C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [184016] [PID.920]
[MD5.9E89C2D6945389270DE067CE51FF7425] - (.Intel Corporation - User Notification Service.) -- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2320920] [PID.1828]
[MD5.496ABDFCC9D52BF3DC0154FC56AB5D77] - (.Dell Inc. - Dell Data Vault Service.) -- C:\Program Files\Dell\DellDataVault\DellDataVault.exe [1947344] [PID.5960]
[MD5.2C49B175AEE1D4364B91B531417FE583] - (.Microsoft Corporation - Programme d'installation pour les modules W.) -- C:\Windows\servicing\TrustedInstaller.exe [204800] [PID.2668]
[MD5.CF87A1DE791347E75B98885214CED2B8] - (.Microsoft Corporation - Service de la plateforme de protection logi.) -- C:\Windows\system32\sppsvc.exe [3179520] [PID.3344]
~ Processes Running: Scanned in 00mn 01s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Amaury\AppData\Local\Google\Chrome\User Data\Default\Preferences
---\\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 0 Scanned in 00mn 00s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFF12.DLL
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo-france.xml
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll =>.Google Inc
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=11.31.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Windows\system32\npdeployJava1.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Oracle Corporation - Next Generation Java Plug-in 11.31.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=11.31.2] - (.Oracle Corporation - Next Generation Java Plug-in 11.31.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) -- C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
~ Firefox Browser: 31 Scanned in 00mn 00s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) (No version) -- (.not file.)
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
~ IE Browser: 11 Scanned in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: DigitalPersona Fingerprint Software Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} . (.DigitalPersona, Inc. - DigitalPersona OTS Feedback.) -- C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} . (.Microsoft Corporation - Windows Live Messenger Companion Core.) -- C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
~ BHO: 14 Scanned in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Adobe PDF - [HKLM]{47833539-D0C5-4125-9FA8-0819E2EAAC93} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{47833539-D0C5-4125-9FA8-0819E2EAAC93} Clé orpheline
~ Toolbar: Scanned in 00mn 00s
---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [QuickSet] . (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [FreeFallProtection] . (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] . (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [DpAgent] . (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] . (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKCU\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
~ Application: Scanned in 00mn 00s
---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ IE Control Panel: 1 Scanned in 00mn 00s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} . (.Microsoft Corporation - Windows Live Messenger Companion core resources.) -- C:\Program Files\Windows Live\Companion\companionres.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- c:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000009\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000010\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll
~ Winsock: 10 Scanned in 00mn 00s
---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] *.dell.com
~ IE Zone Confiance: Scanned in 00mn 00s
---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} ((no name)) - http://support.euro.dell.com/systemprofiler/DellSystemLite.CAB
~ Objets ActiveX: Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s
---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ SSODL: 1 Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) . (.Andrea Electronics Corporation - Andrea filters APO access service (32-bit).) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) . (.Broadcom Corporation. - Bluetooth Support Server.) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dell Data Vault (DellDataVault) . (.Dell Inc. - Dell Data Vault Service.) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
O23 - Service: Dell Data Vault Wizard (DellDataVaultWiz) . (.Dell Inc. - Dell Data Vault Wizard.) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
O23 - Service: C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DpHost) . (.DigitalPersona, Inc. - DigitalPersona Local Host.) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) . (.Sonic Solutions - RoxWatch12 Module.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Audio Service (STacSV) . (.IDT, Inc. - IDT PC Audio.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
O23 - Service: Dell SupportAssist Agent (SupportAssistAgent) . (.Dell Inc. - Service.) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
O23 - Service: Intel(R) Management & Security Application User Notificatio (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) . (.Validity Sensors, Inc. - VFS101 VCS API Library.) - C:\Windows\system32\vcsFPService.exe
O23 - Service: DW WLAN Tray Service (wltrysvc) . (.Dell Inc. - DW WLAN Card Wireless Network Service.) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
~ Services: 19 Scanned in 00mn 06s
---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Desktop Component: 4 Scanned in 00mn 00s
---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
[MD5.3E04F1E482357B1FC8B088197C3D9FF8] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152]
[MD5.B04A4810C6CC205F9DC72DC22E4AB236] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [268464]
[MD5.1F014EA12ECB13C909DA9395E9CD3D18] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6278424]
[MD5.2BCB174FF294F83C3520D46B57DBD917] [APT] [Dell SupportAssistAgent AutoUpdate] (.Dell Inc..) -- C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [27472]
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107912]
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107912]
[MD5.79B5DD0E04130BF31AA598F2AEBB1B78] [APT] [PCDEventLauncherTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell\SupportAssist\sessionchecker.exe [433488]
[MD5.254EC04C72D02E4C8EEC08D4CF3658B1] [APT] [PCDoctorBackgroundMonitorTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell\SupportAssist\uaclauncher.exe [1189200]
[MD5.C155A13687144076286989EF078112C2] [APT] [{0815057C-EFA1-4BCA-B1FE-135DCE6988D1}] (.Nicolas Coolman.) -- C:\Program Files\ZHPDiag\ZHPhep.exe [1917440]
[MD5.A75AE3B84B6423CE6A088E80A2BC23C2] [APT] [{4773655F-F316-4A0B-AAD8-B898B8AF2A0A}] (.Skype Technologies S.A..) -- C:\Program Files\Skype\Phone\Skype.exe [31280256]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{7A7B4145-1139-4669-8765-5936ED3BBC3A}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{A28E5010-28AC-4FF0-9EDF-0210636C319A}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [561984]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1054]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1054]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1058]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1058]
~ Scheduled Task: 17 Scanned in 00mn 04s
---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft VM - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Microsoft Corporation - Microsoft® VM.) -- C:\Windows\system32\msjava.dll
O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Disable SSL3 - {7D715857-A67C-4C2F-A929-038448584D63} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
~ Active Setup: 11 Scanned in 00mn 00s
---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys
O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
O41 - Driver: (MpKsl27db1ee3) . (.Microsoft Corporation - KSLDriver.) - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2698567C-ABF3-4177-B0E6-C232BD8B10E0}\MpKsl27db1ee3.sys
O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys
O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
~ Drivers: 62 Scanned in 00mn 00s
---\\ Logiciels installés (O42)
O42 - Logiciel: 7-Zip 9.20 - (...) [HKLM] -- 7-Zip
O42 - Logiciel: 7Zip Bundle by Fileparade.com - (.SweetPacks LTD.) [HKLM] -- 7Zip Bundle by Fileparade.com =>PUP.SweetIM
O42 - Logiciel: AccelerometerP11 - (.STMicroelectronics.) [HKLM] -- {87434D51-51DB-4109-B68F-A829ECDCF380}
O42 - Logiciel: Adobe After Effects CS4 Third Party Content - (.Adobe Systems Incorporated.) [HKLM] -- {67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}
O42 - Logiciel: Adobe Anchor Service CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {1618734A-3957-4ADD-8199-F973763109A8}
O42 - Logiciel: Adobe Bridge CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {83877DB1-8B77-45BC-AB43-2BAC22E093E0} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe CMaps CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {94D398EB-D2FD-4FD1-B8C4-592635E8A191}
O42 - Logiciel: Adobe CSI CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0F723FC1-7606-4867-866C-CE80AD292DAF}
O42 - Logiciel: Adobe Color EU Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}
O42 - Logiciel: Adobe Color JA Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0D6013AB-A0C7-41DC-973C-E93129C9A29F}
O42 - Logiciel: Adobe Color NA Recommended Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {00ADFB20-AE75-46F4-AD2C-F48B15AC3100}
O42 - Logiciel: Adobe Color Video Profiles CS CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {63C24A08-70F3-4C8E-B9FB-9F21A903801D}
O42 - Logiciel: Adobe Creative Suite 4 Master Collection - (.Adobe Systems Incorporated.) [HKLM] -- Adobe_b2b1c7c62c4ae0a954789ed71d36a7a
O42 - Logiciel: Adobe Creative Suite 4 Master Collection - (.Adobe Systems Incorporated.) [HKLM] -- {D0EE7809-8F5E-46EF-95DC-B30DCE22653F}
O42 - Logiciel: Adobe Default Language CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {C52E3EC1-048C-45E1-8D53-10B0C6509683}
O42 - Logiciel: Adobe Encore CS4 Codecs - (.Adobe Systems Incorporated.) [HKLM] -- {FB2A5FCC-B81B-48C2-A009-7804694D83E9}
O42 - Logiciel: Adobe ExtendScript Toolkit CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F8EF2B3F-C345-4F20-8FE4-791A20333CD5} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Extension Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {054EFA56-2AC1-48F4-A883-0AB89874B972}
O42 - Logiciel: Adobe Flash Player 17 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 17 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI
O42 - Logiciel: Adobe Fonts All - (.Adobe Systems Incorporated.) [HKLM] -- {FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
O42 - Logiciel: Adobe Illustrator CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05C677A1-A161-447E-92ED-2D5B38AA0740} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {A2160D84-F2D0-47A3-AA59-CCB3CA21D558} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Application Feature Set Files (Roman) - (.Adobe Systems Incorporated.) [HKLM] -- {C950299F-BCAB-4695-B077-FC3B2748C25D} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Common Base Files - (.Adobe Systems Incorporated.) [HKLM] -- {26F72DC3-DDBE-424F-B9F0-94E5D0E5A12B} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Icon Handler - (.Adobe Systems Incorporated.) [HKLM] -- {2BA4F7B0-F38E-4AE8-80A2-E9C5956C6D6D} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Linguistics CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {931AB7EA-3656-4BB7-864D-022B09E3DD67}
O42 - Logiciel: Adobe Media Encoder CS4 Exporter - (.Adobe Systems Incorporated.) [HKLM] -- {561968FD-56A1-49FD-9ED0-F55482C7C5BC}
O42 - Logiciel: Adobe Media Encoder CS4 Importer - (.Adobe Systems Incorporated.) [HKLM] -- {8186FF34-D389-4B7E-9A2F-C197585BCFBD}
O42 - Logiciel: Adobe Output Module - (.Adobe Systems Incorporated.) [HKLM] -- {BB4E33EC-8181-4685-96F7-8554293DEC6A}
O42 - Logiciel: Adobe PDF Library Files CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F93C84A6-0DC6-42AF-89FA-776F7C377353}
O42 - Logiciel: Adobe Photoshop CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {E2E01E91-2314-42BC-B5E3-1715DAE84F98} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Photoshop CS4 Support - (.Adobe Systems Incorporated.) [HKLM] -- {73E17122-EC84-45B4-943B-735257B5CBDC} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Premiere Pro CS4 Third Party Content - (.Adobe Systems Incorporated.) [HKLM] -- {E1951CF4-91CE-46F0-A1BD-3A4A67069097}
O42 - Logiciel: Adobe Reader X (10.1.13) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AA1000000001}
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-0804-1033-1959-001802114130}
O42 - Logiciel: Adobe SGM CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}
O42 - Logiciel: Adobe SING CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {8CB16C77-9D75-4966-91E8-D785B87EC078}
O42 - Logiciel: Adobe Search for Help - (.Adobe Systems Incorporated.) [HKLM] -- {F0E64E2E-3A60-40D8-A55D-92F6831875DA}
O42 - Logiciel: Adobe Service Manager Extension - (.Adobe Systems Incorporated.) [HKLM] -- {4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
O42 - Logiciel: Adobe Setup - (.Adobe Systems Incorporated.) [HKLM] -- {6577657B-A10C-47A1-A50D-512C7748CB2C}
O42 - Logiciel: Adobe Soundbooth CS4 Codecs - (.Adobe Systems Incorporated.) [HKLM] -- {52232EF4-CC12-4C21-ABCF-ADB79618302D}
O42 - Logiciel: Adobe Type Support CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
O42 - Logiciel: Adobe Update Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05308C4E-7285-4066-BAE3-6B50DA6ED755}
O42 - Logiciel: Adobe WinSoft Linguistics Plugin - (.Adobe Systems Incorporated.) [HKLM] -- {3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
O42 - Logiciel: Adobe XMP Panels CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
O42 - Logiciel: AdobeColorCommonSetCMYK - (.Adobe Systems Incorporated.) [HKLM] -- {E5FCED12-3E77-4C0E-A305-5AEB38A52A70}
O42 - Logiciel: AdobeColorCommonSetRGB - (.Adobe Systems Incorporated.) [HKLM] -- {16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
O42 - Logiciel: Advanced Audio FX Engine - (.Creative Technology Ltd.) [HKLM] -- Advanced Audio FX Engine
O42 - Logiciel: Antidote RX v7 - (.Druide informatique inc..) [HKLM] -- {A474EA56-5DBD-4181-8230-806A4762EA7F}
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {5D09C772-ECB3-442B-9CC6-B4341C78FDC2}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {E14ADE0E-75F3-4A46-87E5-26692DD626EC}
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} =>.Apple Inc
O42 - Logiciel: ArcGIS 10.1 for Desktop - (.Environmental Systems Research Institute, Inc..) [HKLM] -- ArcGIS 10.1 for Desktop
O42 - Logiciel: ArcGIS 10.1 for Desktop - Module linguistique français - (.Environmental Systems Research Institute, Inc..) [HKLM] -- ArcGIS 10.1 for Desktop - Module linguistique français
O42 - Logiciel: ArcGIS 10.1 for Desktop - Module linguistique français - (.Environmental Systems Research Institute, Inc..) [HKLM] -- {311DA2E4-3B6A-464F-8987-C4AAE6B9386D}
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {79155F2B-9895-49D7-8612-D92580E0DE5B}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: CDBurnerXP - (.CDBurnerXP.) [HKLM] -- {7E265513-8CDA-4631-B696-F40D983F3B07}_is1
O42 - Logiciel: Canon MG5200 series MP Drivers - (...) [HKLM] -- {1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series
O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM] -- {64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {51C7AD07-C3F6-4635-8E8A-231306D810FE}
O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
O42 - Logiciel: Complément Messenger - (.Microsoft Corporation.) [HKLM] -- {6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}
O42 - Logiciel: Connect - (.Adobe Systems Incorporated.) [HKLM] -- {B29AD377-CC12-490A-A480-1452337C618D}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM] -- InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM] -- {A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
O42 - Logiciel: DW WLAN Card Utility - (.Dell Inc..) [HKLM] -- DW WLAN Card Utility
O42 - Logiciel: Dell Backup and Recovery Manager - (.Dell Inc..) [HKLM] -- {4688EB75-28E2-4731-9BCB-55E624F7CD45}
O42 - Logiciel: Dell Data Vault - (.Dell Inc..) [HKLM] -- {2E55EEFD-2162-4A7D-9158-EDB0305603A6}
O42 - Logiciel: Dell Edoc Viewer - (.Dell Inc.) [HKLM] -- {3138EAD3-700B-4A10-B617-B3F8096EE30D}
O42 - Logiciel: Dell SupportAssist - (.Dell.) [HKLM] -- PC-Doctor for Windows
O42 - Logiciel: Dell SupportAssistAgent - (.Dell.) [HKLM] -- {287348C8-8B47-4C36-AF28-441A3B7D8722}
O42 - Logiciel: Dell Touchpad - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey
O42 - Logiciel: Dell Webcam Central - (.Creative Technology Ltd.) [HKLM] -- Dell Webcam Central
O42 - Logiciel: DigitalPersona Personal 4.01 - (.DigitalPersona, Inc..) [HKLM] -- {3D8AE086-030F-4EF4-B705-63F8130B043E}
O42 - Logiciel: DirectX 9 Runtime - (.Sonic Solutions.) [HKLM] -- {AF9E97C1-7431-426D-A8D5-ABE40995C0B1}
O42 - Logiciel: EndNote X3 - (.Thomson Reuters.) [HKLM] -- {86B3F2D6-AC2B-4E88-8AE1-F2F77F781B0C}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}
O42 - Logiciel: IRIScan(TM) Direct - (.IRIScanDirect.) [HKLM] -- IRIScanDirect_is1
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
O42 - Logiciel: Java 8 Update 31 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83218031F0}
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
O42 - Logiciel: Logiciel d'archivage WinRAR - (...) [HKLM] -- WinRAR archiver
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: Malwarebytes Anti-Malware version 2.1.6.1022 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1
O42 - Logiciel: Mesh Runtime - (.Microsoft Corporation.) [HKLM] -- {8C6D6116-B724-4810-8F2D-D047E6B7D68E}
O42 - Logiciel: Microsoft Image Composite Editor - (.Microsoft Corporation.) [HKLM] -- {3D599ADA-65D9-4B51-898F-CE718DEC5DBB}
O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {D6F9CBDC-58B6-430A-8DD4-8F61CBC1ADF4}
O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Mozilla Firefox 37.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 37.0.2 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: PDF Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
O42 - Logiciel: PhotoShowExpress - (.Sonic Solutions.) [HKLM] -- {3250260C-7A95-4632-893B-89657EB5545B}
O42 - Logiciel: Photoshop Camera Raw - (.Adobe Systems Incorporated.) [HKLM] -- {CC75AB5C-2110-4A7F-AF52-708680D22FE8}
O42 - Logiciel: QuickSet32 - (.Dell Inc..) [HKLM] -- {C4972073-2BFE-475D-8441-564EA97DA161}
O42 - Logiciel: ResearchSoft Direct Export Helper - (...) [HKLM] -- ResearchSoft Direct Export Helper
O42 - Logiciel: Roxio Activation Module - (.Roxio.) [HKLM] -- {A121EEDE-C68F-461D-91AA-D48BA226AF1C}
O42 - Logiciel: Roxio BackOnTrack - (.Roxio.) [HKLM] -- {5A06423A-210C-49FB-950E-CB0EB8C5CEC7}
O42 - Logiciel: Roxio Burn - (.Roxio.) [HKLM] -- {9569E6BC-326A-432F-97AB-35263A327BF1}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {EF56258E-0326-48C5-A86C-3BAC26FC15DF}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}
O42 - Logiciel: Roxio Express Labeler 3 - (.Roxio.) [HKLM] -- {6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
O42 - Logiciel: Roxio File Backup - (.Roxio.) [HKLM] -- {60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}
O42 - Logiciel: Samsung Printer Live Update - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung Printer Live Update
O42 - Logiciel: Satsuki Decoder Pack - (.Satsuki Yatoshi'S Softs.) [HKLM] -- Satsuki Decoder Pack
O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701}
O42 - Logiciel: Skype(TM) 7.4 - (.Skype Technologies S.A..) [HKLM] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
O42 - Logiciel: Sonic CinePlayer Decoder Pack - (.Sonic Solutions.) [HKLM] -- {9A00EC4E-27E1-42C4-98DD-662F32AC8870}
O42 - Logiciel: Spotify - (...) [HKLM] -- Spotify
O42 - Logiciel: Spotify - (.Spotify AB.) [HKCU] -- Spotify
O42 - Logiciel: Suite Shared Configuration CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {842B4B72-9E8F-4962-B3C1-1C422A5C4434}
O42 - Logiciel: TuxGuitar 1.2 - (...) [HKLM] -- TuxGuitar_0
O42 - Logiciel: Validity Sensors DDK - (.Validity Sensors, Inc..) [HKLM] -- {9FCB6355-689E-4141-9714-3EEC2AE10292}
O42 - Logiciel: WIDCOMM Bluetooth Software - (.Broadcom Corporation.) [HKLM] -- {9E9D49A4-1DF4-4138-B7DB-5D87A893088E}
O42 - Logiciel: XnView 2.22 - (.Gougelet Pierre-e.) [HKLM] -- XnView_is1
O42 - Logiciel: Xvid 1.2.1 final uninstall - (.Xvid team (Koepi).) [HKLM] -- Xvid_is1
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {11E568E0-3244-4BCB-875E-F334269DFDCB}
O42 - Logiciel: kuler - (.Adobe Systems Incorporated.) [HKLM] -- {098727E1-775A-4450-B573-3F441F1CA243}
~ Logic: 44 Scanned in 00mn 00s
---\\ HKCU & HKLM Software Keys
[HKCU\Software\7-Zip]
[HKCU\Software\AC3Filter]
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow\Software\DigitalPersona]
[HKCU\Software\AppDataLow\Software\JavaSoft]
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Arobas Music]
[HKCU\Software\Broadcom]
[HKCU\Software\CG Information]
[HKCU\Software\Canneverbe Limited]
[HKCU\Software\Canon]
[HKCU\Software\Citrix]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\Creative Tech]
[HKCU\Software\CyberLink]
[HKCU\Software\DT Soft]
[HKCU\Software\Developer Express]
[HKCU\Software\DigitalPersona]
[HKCU\Software\Druide informatique inc.]
[HKCU\Software\ERDAS]
[HKCU\Software\ESRI]
[HKCU\Software\EasyBits]
[HKCU\Software\Eset]
[HKCU\Software\GNU]
[HKCU\Software\Gabest]
[HKCU\Software\Google]
[HKCU\Software\HKEY_LOCAL_MACHINE]
[HKCU\Software\Haali]
[HKCU\Software\Herac]
[HKCU\Software\IDAVLab]
[HKCU\Software\IDT]
[HKCU\Software\IM Providers]
[HKCU\Software\ISI ResearchSoft]
[HKCU\Software\Intel\Indeo\4.1]
[HKCU\Software\Intel]
[HKCU\Software\JavaSoft]
[HKCU\Software\Lake]
[HKCU\Software\LogiShrd]
[HKCU\Software\MCAFEE]
[HKCU\Software\Macromedia]
[HKCU\Software\Macrovision]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Nero]
[HKCU\Software\Netscape]
[HKCU\Software\Northcode Inc]
[HKCU\Software\ODBC]
[HKCU\Software\PC-Doctor]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\RICOH]
[HKCU\Software\RealNetworks]
[HKCU\Software\RegisteredApplications]
[HKCU\Software\Roxio]
[HKCU\Software\SSPrint]
[HKCU\Software\STUDIO SARMADI]
[HKCU\Software\Samsung]
[HKCU\Software\Satsuki Decoder Pack]
[HKCU\Software\SecuROM]
[HKCU\Software\Skype]
[HKCU\Software\Synaptics]
[HKCU\Software\Trolltech]
[HKCU\Software\Widcomm]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\ZebHelpProcess Helper]
[HKLM\Software\ATI Technologies]
[HKLM\Software\Adobe]
[HKLM\Software\AdwCleaner]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\BcmSetup]
[HKLM\Software\Broadcom]
[HKLM\Software\Canneverbe Limited]
[HKLM\Software\Canon]
[HKLM\Software\Citrix]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Creative Tech]
[HKLM\Software\CyberLink]
[HKLM\Software\DT Soft]
[HKLM\Software\Debug]
[HKLM\Software\Dell Computer Corporation]
[HKLM\Software\Dell Inc.]
[HKLM\Software\Dell]
[HKLM\Software\DigitalPersona]
[HKLM\Software\Druide informatique inc.]
[HKLM\Software\ERDAS]
[HKLM\Software\ESRI]
[HKLM\Software\FreeFallProtection]
[HKLM\Software\GEAR Software]
[HKLM\Software\GNU]
[HKLM\Software\Gabest]
[HKLM\Software\Google]
[HKLM\Software\HaaliMkx]
[HKLM\Software\IDAVLab]
[HKLM\Software\IDT]
[HKLM\Software\IM Providers]
[HKLM\Software\ISI ResearchSoft]
[HKLM\Software\Imagineer Systems Ltd]
[HKLM\Software\InstalledOptions]
[HKLM\Software\Intel]
[HKLM\Software\InterVideo]
[HKLM\Software\JavaSoft]
[HKLM\Software\JreMetrics]
[HKLM\Software\Lake]
[HKLM\Software\Logishrd]
[HKLM\Software\MAXSOFT-OCRON]
[HKLM\Software\Macromedia]
[HKLM\Software\Macrovision]
[HKLM\Software\Malwarebytes' Anti-Malware (Trial)]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\ManageableUpdatePackage]
[HKLM\Software\McAfee.com]
[HKLM\Software\McAfeeInstaller]
[HKLM\Software\McAfee]
[HKLM\Software\MicroVision]
[HKLM\Software\MimarSinan]
[HKLM\Software\Mircrosoft]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Nero]
[HKLM\Software\Novell]
[HKLM\Software\ODBC]
[HKLM\Software\PC-Doctor]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\Python]
[HKLM\Software\RealNetworks]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Roxio]
[HKLM\Software\SSPrint]
[HKLM\Software\STMicroelectronics]
[HKLM\Software\Samsung]
[HKLM\Software\Skype]
[HKLM\Software\Sonic]
[HKLM\Software\Synaptics]
[HKLM\Software\Synthetic Aperture]
[HKLM\Software\Validity]
[HKLM\Software\Vantage Software Technologies]
[HKLM\Software\Volatile]
[HKLM\Software\Widcomm]
[HKLM\Software\WinRAR]
[HKLM\Software\Windows]
[HKLM\Software\Wise Solutions]
[HKLM\Software\XnView]
[HKLM\Software\illiminable]
[HKLM\Software\mozilla.org]
~ Key Software: 327 Scanned in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 23/09/2013 - 18:48:51 - [] ----D C:\Program Files\7-Zip
O43 - CFD: 14/10/2012 - 17:01:19 - [] ----D C:\Program Files\Adobe
O43 - CFD: 27/10/2012 - 13:10:03 - [] ----D C:\Program Files\Apple Software Update =>.Apple Inc
O43 - CFD: 23/09/2013 - 14:43:50 - [] ----D C:\Program Files\ArcGIS
O43 - CFD: 27/10/2012 - 13:09:43 - [] ----D C:\Program Files\Bonjour
O43 - CFD: 08/05/2015 - 11:47:02 - [] ----D C:\Program Files\CCleaner
O43 - CFD: 04/12/2011 - 23:56:37 - [] ----D C:\Program Files\CDBurnerXP
O43 - CFD: 07/01/2011 - 14:48:11 - [] ----D C:\Program Files\Cisco
O43 - CFD: 09/04/2013 - 08:24:59 - [] ----D C:\Program Files\Citrix
O43 - CFD: 10/05/2015 - 10:49:29 - [] ----D C:\Program Files\Common Files
O43 - CFD: 07/01/2011 - 14:52:12 - [] ----D C:\Program Files\Creative
O43 - CFD: 07/01/2011 - 14:51:48 - [] ----D C:\Program Files\Creative Live! Cam
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\CyberLink
O43 - CFD: 13/02/2015 - 17:07:18 - [] ----D C:\Program Files\Dell
O43 - CFD: 07/01/2011 - 14:41:47 - [] ----D C:\Program Files\Dell Inc
O43 - CFD: 01/04/2015 - 15:56:44 - [] ----D C:\Program Files\Dell Support Center
O43 - CFD: 07/01/2011 - 14:51:52 - [] ----D C:\Program Files\Dell Webcam
O43 - CFD: 07/01/2011 - 14:49:33 - [] ----D C:\Program Files\DigitalPersona
O43 - CFD: 05/10/2011 - 21:15:44 - [] ----D C:\Program Files\Druide
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\DVD Maker
O43 - CFD: 30/05/2013 - 16:35:59 - [] ----D C:\Program Files\EndNote X3
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\Program Files\Fichiers communs
O43 - CFD: 09/08/2013 - 08:30:00 - [] ----D C:\Program Files\Google
O43 - CFD: 18/09/2012 - 08:30:24 - [] ----D C:\Program Files\GUMBB52.tmp
O43 - CFD: 07/01/2011 - 07:38:05 - [] ----D C:\Program Files\IDT
O43 - CFD: 07/01/2011 - 14:51:50 - [] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 07/01/2011 - 14:43:38 - [] ----D C:\Program Files\Intel
O43 - CFD: 16/04/2015 - 07:41:45 - [] ----D C:\Program Files\Internet Explorer
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\iPod
O43 - CFD: 30/05/2014 - 17:24:54 - [] ----D C:\Program Files\IRIScan Direct
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\Program Files\iTunes
O43 - CFD: 01/02/2015 - 19:24:51 - [] ----D C:\Program Files\Java
O43 - CFD: 08/05/2015 - 12:02:05 - [] ----D C:\Program Files\Malwarebytes Anti-Malware
O43 - CFD: 19/08/2014 - 07:39:24 - [] ----D C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 15/01/2011 - 17:51:35 - [0] ----D C:\Program Files\Microsoft
O43 - CFD: 14/07/2009 - 11:00:58 - [] ----D C:\Program Files\Microsoft Games
O43 - CFD: 27/08/2012 - 21:15:59 - [] ----D C:\Program Files\Microsoft Office
O43 - CFD: 10/02/2012 - 09:38:04 - [] ----D C:\Program Files\Microsoft Research
O43 - CFD: 11/02/2015 - 20:53:43 - [] ----D C:\Program Files\Microsoft Security Client
O43 - CFD: 24/07/2014 - 17:05:44 - [] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 07/01/2011 - 15:02:44 - [] ----D C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 13/03/2011 - 22:40:16 - [] ----D C:\Program Files\Microsoft Visual Studio
O43 - CFD: 13/03/2011 - 22:37:09 - [] ----D C:\Program Files\Microsoft Visual Studio 8
O43 - CFD: 23/08/2012 - 08:17:10 - [] ----D C:\Program Files\Microsoft Works
O43 - CFD: 13/03/2011 - 22:40:04 - [] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 24/04/2015 - 12:09:10 - [] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 26/04/2015 - 08:23:34 - [] ----D C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 13/03/2011 - 22:40:20 - [] ----D C:\Program Files\MSBuild
O43 - CFD: 15/01/2011 - 23:49:59 - [0] ----D C:\Program Files\MSXML 4.0
O43 - CFD: 14/07/2009 - 06:52:30 - [] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 07/01/2011 - 14:58:04 - [] ----D C:\Program Files\Roxio
O43 - CFD: 03/03/2014 - 12:14:18 - [] ----D C:\Program Files\SamsungPrinterLiveUpdate
O43 - CFD: 03/03/2014 - 12:04:04 - [] ----D C:\Program Files\SamsungPrinterLiveUpdateInstaller
O43 - CFD: 05/02/2011 - 11:29:22 - [] ----D C:\Program Files\Satsuki Decoder Pack
O43 - CFD: 14/04/2015 - 08:03:39 - [] R---D C:\Program Files\Skype
O43 - CFD: 24/03/2015 - 20:36:20 - [] ----D C:\Program Files\Spotify
O43 - CFD: 07/01/2011 - 14:44:04 - [] ----D C:\Program Files\STMicroelectronics
O43 - CFD: 07/01/2011 - 16:33:50 - [] ----D C:\Program Files\Synaptics
O43 - CFD: 10/12/2011 - 19:15:54 - [] ----D C:\Program Files\Trend Micro
O43 - CFD: 25/03/2011 - 22:12:50 - [] ----D C:\Program Files\TuxGuitar-Jet
O43 - CFD: 14/07/2009 - 06:53:23 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 07/01/2011 - 14:45:49 - [] ----D C:\Program Files\Validity Sensors
O43 - CFD: 07/01/2011 - 14:46:46 - [] ----D C:\Program Files\WIDCOMM
O43 - CFD: 12/07/2013 - 07:57:37 - [] ----D C:\Program Files\Windows Defender
O43 - CFD: 12/07/2014 - 07:43:28 - [] ----D C:\Program Files\Windows Journal
O43 - CFD: 07/01/2011 - 15:03:04 - [] ----D C:\Program Files\Windows Live
O43 - CFD: 04/01/2012 - 19:59:00 - [] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 12/03/2015 - 04:25:28 - [] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 12/01/2011 - 13:59:10 - [] ----D C:\Program Files\Windows NT
O43 - CFD: 04/01/2012 - 19:58:58 - [] ----D C:\Program Files\Windows Photo Viewer
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Portable Devices
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Sidebar
O43 - CFD: 05/02/2011 - 12:44:37 - [] ----D C:\Program Files\WinRAR
O43 - CFD: 15/04/2014 - 08:21:40 - [] ----D C:\Program Files\XnView
O43 - CFD: 15/01/2011 - 22:02:09 - [] ----D C:\Program Files\Xvid
O43 - CFD: 11/05/2015 - 11:05:57 - [] ----D C:\Program Files\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 14/10/2012 - 17:01:28 - [] ----D C:\Program Files\Common Files\Adobe
O43 - CFD: 23/09/2013 - 14:47:09 - [] ----D C:\Program Files\Common Files\AnswerWorks 4.0
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\Common Files\Apple
O43 - CFD: 23/09/2013 - 14:46:20 - [] ----D C:\Program Files\Common Files\ArcGIS
O43 - CFD: 10/12/2011 - 19:52:01 - [] ----D C:\Program Files\Common Files\Bitdefender
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\Common Files\CyberLink
O43 - CFD: 23/09/2013 - 14:44:22 - [] ----D C:\Program Files\Common Files\Data Dynamics
O43 - CFD: 15/05/2014 - 11:50:28 - [] ----D C:\Program Files\Common Files\DESIGNER
O43 - CFD: 07/01/2011 - 14:51:35 - [] ----D C:\Program Files\Common Files\InstallShield
O43 - CFD: 01/02/2015 - 19:25:56 - [] ----D C:\Program Files\Common Files\Java
O43 - CFD: 28/02/2011 - 22:14:03 - [] ----D C:\Program Files\Common Files\Macrovision Shared
O43 - CFD: 05/02/2011 - 11:49:23 - [] ----D C:\Program Files\Common Files\mcafee
O43 - CFD: 23/08/2012 - 08:17:16 - [] ----D C:\Program Files\Common Files\microsoft shared
O43 - CFD: 07/01/2011 - 14:43:41 - [] ----D C:\Program Files\Common Files\postureAgent
O43 - CFD: 07/01/2011 - 14:58:20 - [] ----D C:\Program Files\Common Files\PX Storage Engine
O43 - CFD: 30/05/2013 - 16:36:04 - [] ----D C:\Program Files\Common Files\ResearchSoft
O43 - CFD: 23/12/2012 - 15:28:39 - [] ----D C:\Program Files\Common Files\Risxtd
O43 - CFD: 07/01/2011 - 14:58:36 - [] ----D C:\Program Files\Common Files\Roxio Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\Services
O43 - CFD: 08/10/2014 - 07:41:48 - [] ----D C:\Program Files\Common Files\Skype
O43 - CFD: 07/01/2011 - 14:58:00 - [] ----D C:\Program Files\Common Files\Sonic Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 07/01/2011 - 14:57:58 - [] ----D C:\Program Files\Common Files\SureThing Shared
O43 - CFD: 17/01/2012 - 16:46:20 - [0] ----D C:\Program Files\Common Files\SWF Studio
O43 - CFD: 04/01/2012 - 19:58:57 - [] ----D C:\Program Files\Common Files\System
O43 - CFD: 23/09/2013 - 14:44:09 - [] ----D C:\Program Files\Common Files\Tom Sawyer Software
O43 - CFD: 07/01/2011 - 14:58:54 - [] ----D C:\Program Files\Common Files\Windows Live
O43 - CFD: 30/05/2013 - 16:33:17 - [] ----D C:\Program Files\Common Files\Wise Installation Wizard
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
O43 - CFD: 30/07/2014 - 20:12:45 - [] ----D C:\ProgramData\Adobe
O43 - CFD: 28/02/2011 - 22:22:21 - [0] ----D C:\ProgramData\ALM
O43 - CFD: 27/10/2012 - 13:10:01 - [] ----D C:\ProgramData\Apple
O43 - CFD: 27/10/2012 - 13:10:36 - [] ----D C:\ProgramData\Apple Computer
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Application Data
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Bureau
O43 - CFD: 25/09/2011 - 22:32:17 - [] ----D C:\ProgramData\Canneverbe Limited
O43 - CFD: 01/02/2011 - 10:06:18 - [] --H-D C:\ProgramData\CanonBJ
O43 - CFD: 30/01/2014 - 16:19:41 - [] --H-D C:\ProgramData\CanonIJScan
O43 - CFD: 09/04/2013 - 08:25:17 - [] ----D C:\ProgramData\Citrix
O43 - CFD: 05/02/2011 - 11:48:10 - [] ----D C:\ProgramData\Creative
O43 - CFD: 17/01/2012 - 16:46:30 - [] ----D C:\ProgramData\CyberLink
O43 - CFD: 23/09/2013 - 14:36:26 - [] ----D C:\ProgramData\DAEMON Tools Lite =>.DT Soft Ltd
O43 - CFD: 23/08/2012 - 11:22:11 - [] ----D C:\ProgramData\Dell
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Documents
O43 - CFD: 07/01/2011 - 14:49:20 - [] ----D C:\ProgramData\Downloaded Installations
O43 - CFD: 06/01/2015 - 15:10:21 - [] ----D C:\ProgramData\ESRI
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Favoris
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Favorites
O43 - CFD: 23/09/2013 - 14:57:18 - [] ----D C:\ProgramData\FLEXnet
O43 - CFD: 25/03/2011 - 21:26:10 - [0] ----D C:\ProgramData\Guitar Pro 6
O43 - CFD: 07/01/2011 - 14:49:33 - [] ----D C:\ProgramData\Macrovision
O43 - CFD: 19/08/2014 - 07:39:24 - [] ----D C:\ProgramData\Malwarebytes
O43 - CFD: 16/11/2012 - 19:40:59 - [] ----D C:\ProgramData\McAfee
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Menu Démarrer
O43 - CFD: 10/12/2014 - 10:25:17 - [] -S--D C:\ProgramData\Microsoft
O43 - CFD: 15/04/2015 - 19:07:22 - [] ----D C:\ProgramData\Microsoft Help
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Modèles
O43 - CFD: 04/05/2012 - 08:23:01 - [] ----D C:\ProgramData\Mozilla
O43 - CFD: 10/05/2015 - 10:49:12 - [] ----D C:\ProgramData\Nero
O43 - CFD: 01/02/2015 - 19:27:18 - [] ----D C:\ProgramData\Oracle
O43 - CFD: 01/04/2015 - 15:56:47 - [] ----D C:\ProgramData\PC-Doctor for Windows
O43 - CFD: 07/05/2015 - 18:06:46 - [] ----D C:\ProgramData\PCDr
O43 - CFD: 07/01/2011 - 14:57:48 - [] ----D C:\ProgramData\PhotoShow Shared Assets
O43 - CFD: 24/10/2013 - 08:34:45 - [] --H-D C:\ProgramData\RICOH_DRV
O43 - CFD: 07/01/2011 - 14:57:48 - [] ----D C:\ProgramData\Roxio
O43 - CFD: 03/03/2014 - 12:04:03 - [] ----D C:\ProgramData\Samsung
O43 - CFD: 02/05/2015 - 08:11:28 - [] ----D C:\ProgramData\Skype
O43 - CFD: 16/06/2011 - 21:14:34 - [] ----D C:\ProgramData\Skype Extras
O43 - CFD: 11/05/2015 - 07:47:22 - [] ----D C:\ProgramData\Sonic
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Start Menu
O43 - CFD: 07/01/2011 - 14:42:45 - [] ----D C:\ProgramData\Sun
O43 - CFD: 05/05/2015 - 13:48:55 - [] ----D C:\ProgramData\SupportAssistAgent
O43 - CFD: 07/01/2011 - 14:51:06 - [] ----D C:\ProgramData\Temp
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Templates
O43 - CFD: 30/05/2013 - 16:36:06 - [] ----D C:\ProgramData\Thomson.ResearchSoft.Installers
O43 - CFD: 07/01/2011 - 14:58:36 - [] ----D C:\ProgramData\Uninstall
O43 - CFD: 12/03/2015 - 15:04:58 - [] --H-D C:\ProgramData\{6AACA38B-2810-4B47-BDEC-D7A1F38B1531}
O43 - CFD: 23/09/2013 - 18:48:51 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
O43 - CFD: 10/05/2015 - 12:49:29 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 14/07/2009 - 06:46:36 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 28/02/2011 - 22:24:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS4
O43 - CFD: 05/10/2011 - 21:22:25 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antidote
O43 - CFD: 23/09/2013 - 14:48:04 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcGIS
O43 - CFD: 04/11/2012 - 20:30:57 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG5200 series
O43 - CFD: 07/01/2011 - 15:10:41 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 9.5
O43 - CFD: 01/04/2015 - 15:56:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
O43 - CFD: 07/01/2011 - 14:52:26 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Webcam
O43 - CFD: 07/01/2011 - 14:47:42 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DW WLAN
O43 - CFD: 30/05/2013 - 16:35:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EndNote
O43 - CFD: 07/01/2011 - 07:38:55 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 19/12/2013 - 13:12:21 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth =>.Google Inc
O43 - CFD: 30/05/2014 - 17:24:55 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IRIScan Direct
O43 - CFD: 02/06/2013 - 16:57:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
O43 - CFD: 01/02/2015 - 19:25:18 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 14/07/2009 - 06:42:30 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 08/05/2015 - 12:02:07 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
O43 - CFD: 13/09/2013 - 17:40:09 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O43 - CFD: 24/07/2014 - 11:37:55 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
O43 - CFD: 07/01/2011 - 14:58:20 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio Creator Starter
O43 - CFD: 08/10/2014 - 07:41:49 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 16/11/2012 - 22:41:05 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 14/07/2009 - 11:00:22 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 07/01/2011 - 15:02:54 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
O43 - CFD: 15/04/2014 - 08:21:40 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView
O43 - CFD: 15/01/2011 - 22:02:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
O43 - CFD: 11/05/2015 - 11:05:57 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP =>.Nicolas Coolman
O43 - CFD: 04/07/2013 - 18:36:20 - [] ----D C:\Users\Amaury\AppData\Roaming\Adobe
O43 - CFD: 27/10/2012 - 13:12:04 - [] ----D C:\Users\Amaury\AppData\Roaming\Apple Computer
O43 - CFD: 25/09/2011 - 22:32:17 - [] ----D C:\Users\Amaury\AppData\Roaming\Canneverbe Limited
O43 - CFD: 30/01/2014 - 16:19:41 - [] ----D C:\Users\Amaury\AppData\Roaming\Canon
O43 - CFD: 12/01/2011 - 14:04:06 - [] ----D C:\Users\Amaury\AppData\Roaming\Creative
O43 - CFD: 17/01/2012 - 16:46:29 - [] ----D C:\Users\Amaury\AppData\Roaming\CyberLink
O43 - CFD: 15/11/2013 - 08:39:56 - [] ----D C:\Users\Amaury\AppData\Roaming\DAEMON Tools Lite =>.DT Soft Ltd
O43 - CFD: 24/03/2011 - 09:54:04 - [] ----D C:\Users\Amaury\AppData\Roaming\Dell
O43 - CFD: 12/01/2011 - 14:04:02 - [] ----D C:\Users\Amaury\AppData\Roaming\DigitalPersona
O43 - CFD: 05/09/2011 - 09:51:28 - [] ----D C:\Users\Amaury\AppData\Roaming\Druide
O43 - CFD: 16/05/2014 - 10:40:34 - [] ----D C:\Users\Amaury\AppData\Roaming\EndNote
O43 - CFD: 23/09/2013 - 15:04:14 - [] ----D C:\Users\Amaury\AppData\Roaming\ESRI
O43 - CFD: 25/03/2011 - 22:10:49 - [] ----D C:\Users\Amaury\AppData\Roaming\Guitar Pro 6
O43 - CFD: 12/01/2011 - 14:03:44 - [] ----D C:\Users\Amaury\AppData\Roaming\Identities
O43 - CFD: 15/01/2011 - 18:01:02 - [] ----D C:\Users\Amaury\AppData\Roaming\Macromedia
O43 - CFD: 12/01/2011 - 21:28:33 - [] ----D C:\Users\Amaury\AppData\Roaming\Macrovision
O43 - CFD: 19/08/2014 - 07:39:37 - [0] ----D C:\Users\Amaury\AppData\Roaming\Malwarebytes
O43 - CFD: 14/07/2009 - 11:00:22 - [0] ----D C:\Users\Amaury\AppData\Roaming\Media Center Programs
O43 - CFD: 06/01/2014 - 16:31:05 - [0] ----D C:\Users\Amaury\AppData\Roaming\Media Player Classic
O43 - CFD: 31/01/2015 - 17:38:39 - [] -S--D C:\Users\Amaury\AppData\Roaming\Microsoft
O43 - CFD: 15/01/2011 - 21:25:03 - [] ----D C:\Users\Amaury\AppData\Roaming\Mozilla
O43 - CFD: 27/06/2013 - 21:48:54 - [] ----D C:\Users\Amaury\AppData\Roaming\Nero
O43 - CFD: 16/07/2014 - 12:04:25 - [] ----D C:\Users\Amaury\AppData\Roaming\PCDr
O43 - CFD: 10/12/2011 - 18:47:36 - [0] ----D C:\Users\Amaury\AppData\Roaming\QuickScan
O43 - CFD: 05/02/2011 - 11:48:10 - [] ----D C:\Users\Amaury\AppData\Roaming\Reallusion
O43 - CFD: 12/01/2011 - 14:04:11 - [] ----D C:\Users\Amaury\AppData\Roaming\Roxio
O43 - CFD: 15/01/2011 - 15:47:29 - [] ----D C:\Users\Amaury\AppData\Roaming\Roxio Burn
O43 - CFD: 11/05/2015 - 08:00:01 - [] ----D C:\Users\Amaury\AppData\Roaming\Skype
O43 - CFD: 19/06/2011 - 11:48:17 - [] ----D C:\Users\Amaury\AppData\Roaming\skypePM
O43 - CFD: 05/05/2015 - 13:40:24 - [] ----D C:\Users\Amaury\AppData\Roaming\Spotify
O43 - CFD: 21/02/2011 - 12:15:29 - [] ----D C:\Users\Amaury\AppData\Roaming\WinRAR
O43 - CFD: 15/04/2014 - 08:27:51 - [] ----D C:\Users\Amaury\AppData\Roaming\XnView
O43 - CFD: 11/05/2015 - 11:08:46 - [] ----D C:\Users\Amaury\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 05/04/2015 - 11:25:56 - [0] ----D C:\Users\Amaury\AppData\Local\._LiveCode_
O43 - CFD: 28/02/2011 - 22:36:33 - [] ----D C:\Users\Amaury\AppData\Local\Adobe
O43 - CFD: 27/10/2012 - 13:10:04 - [] ----D C:\Users\Amaury\AppData\Local\Apple
O43 - CFD: 27/10/2012 - 13:11:31 - [] ----D C:\Users\Amaury\AppData\Local\Apple Computer
O43 - CFD: 12/01/2011 - 13:59:20 - [] -SH-D C:\Users\Amaury\AppData\Local\Application Data
O43 - CFD: 02/01/2014 - 16:32:12 - [] ----D C:\Users\Amaury\AppData\Local\Apps
O43 - CFD: 12/01/2011 - 14:04:08 - [] ----D C:\Users\Amaury\AppData\Local\Broadcom
O43 - CFD: 09/04/2013 - 08:24:41 - [] ----D C:\Users\Amaury\AppData\Local\Citrix
O43 - CFD: 17/01/2012 - 16:46:31 - [] ----D C:\Users\Amaury\AppData\Local\Cyberlink
O43 - CFD: 02/01/2014 - 18:29:19 - [0] ----D C:\Users\Amaury\AppData\Local\Deployment
O43 - CFD: 12/01/2011 - 14:04:02 - [] ----D C:\Users\Amaury\AppData\Local\DigitalPersona
O43 - CFD: 19/11/2014 - 21:12:56 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieBrowserModeList
O43 - CFD: 17/04/2014 - 18:45:42 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieSiteList
O43 - CFD: 17/04/2014 - 18:45:42 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieUserList
O43 - CFD: 01/02/2015 - 16:39:39 - [] ----D C:\Users\Amaury\AppData\Local\ESRI
O43 - CFD: 10/12/2011 - 20:55:23 - [] ----D C:\Users\Amaury\AppData\Local\Google
O43 - CFD: 12/01/2011 - 13:59:20 - [] -SH-D C:\Users\Amaury\AppData\Local\Historique
O43 - CFD: 24/06/2012 - 09:00:00 - [] ----D C:\Users\Amaury\AppData\Local\Macromedia
O43 - CFD: 06/05/2015 - 16:15:23 - [] ----D C:\Users\Amaury\AppData\Local\Microsoft
O43 - CFD: 12/02/2011 - 20:35:39 - [] ----D C:\Users\Amaury\AppData\Local\Microsoft Games
O43 - CFD: 13/03/2011 - 22:36:40 - [0] ----D C:\Users\Amaury\AppData\Local\Microsoft Help
O43 - CFD: 19/09/2013 - 21:20:36 - [] ----D C:\Users\Amaury\AppData\Local\Mozilla
O43 - CFD: 10/12/2011 - 16:51:20 - [0] ----D C:\Users\Amaury\AppData\Local\pcnrqyro
O43 - CFD: 11/01/2013 - 12:01:16 - [] ----D C:\Users\Amaury\AppData\Local\Programs
O43 - CFD: 27/02/2014 - 10:59:08 - [] ----D C:\Users\Amaury\AppData\Local\Skype
O43 - CFD: 05/05/2015 - 13:40:25 - [] ----D C:\Users\Amaury\AppData\Local\Spotify
O43 - CFD: 11/05/2015 - 11:07:54 - [] ----D C:\Users\Amaury\AppData\Local\Temp
O43 - CFD: 12/01/2011 - 13:59:20 - [] -SH-D C:\Users\Amaury\AppData\Local\Temporary Internet Files
O43 - CFD: 12/01/2011 - 13:59:21 - [0] ----D C:\Users\Amaury\AppData\Local\VirtualStore
O43 - CFD: 08/06/2012 - 20:12:30 - [] ----D C:\Users\Amaury\AppData\Local\Western Digital
O43 - CFD: 14/07/2009 - 06:42:04 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 12/03/2015 - 07:43:42 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 05/10/2011 - 21:15:20 - [0] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antidote
O43 - CFD: 14/07/2009 - 06:37:42 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 10/02/2012 - 09:38:05 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft ICE
O43 - CFD: 06/01/2014 - 14:08:21 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Périphériques Bluetooth
O43 - CFD: 05/02/2011 - 11:29:22 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Satsuki Decoder Pack
O43 - CFD: 12/03/2015 - 07:43:42 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 25/03/2011 - 22:12:44 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TuxGuitar 1.2
~ Program Folder: 255 Scanned in 00mn 00s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.C16DFA9241F3CE8867E7EA8806B8F5DD] - 08/05/2015 - 08:31:05 ---A- . (...) -- C:\Windows\Antidote.ini [143]
O44 - LFC:[MD5.3C21F7E95FFCA33EF1A83AA33D9663CF] - 08/05/2015 - 11:01:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23256]
O44 - LFC:[MD5.155BF99B2B87E0C298CAC3B4B8136D83] - 08/05/2015 - 11:01:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [92888]
O44 - LFC:[MD5.167BCE00050B19DA25065335645A3C7A] - 08/05/2015 - 11:01:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [51928]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 08/05/2015 - 16:21:07 ---A- . (...) -- C:\Windows\setuperr.log [0]
O44 - LFC:[MD5.6B12A07D3C6AFD4A3219AF5FDE01DAFB] - 09/05/2015 - 07:11:51 ---A- . (...) -- C:\Windows\PFRO.log [2746]
O44 - LFC:[MD5.C489D8B4D8C64F20CC75A93F541F7D91] - 10/05/2015 - 09:32:24 ---A- . (.Microsoft Corporation - Exécuteur de file d'attente d'opérations pr.) -- C:\Windows\System32\poqexec.exe [123904]
O44 - LFC:[MD5.744AB3C1A73A57DEED49D631F1BDEA1D] - 10/05/2015 - 09:33:12 ---A- . (.Microsoft Corporation - Extension de l'environnement des appareils.) -- C:\Windows\System32\wpdshext.dll [2311168]
O44 - LFC:[MD5.F7F135F7702E0FB3EFE89283E2BE2EBB] - 10/05/2015 - 09:34:20 ---A- . (.Microsoft Corporation - API du Gestionnaire de fenêtres du Bureau M.) -- C:\Windows\System32\dwmapi.dll [67584]
O44 - LFC:[MD5.B01B8C949EDEC1B8A856E3056BDA7C42] - 10/05/2015 - 09:34:20 ---A- . (.Microsoft Corporation - Bibliothèque principale du Gestionnaire de.) -- C:\Windows\System32\dwmcore.dll [1372160]
O44 - LFC:[MD5.A5FE03D57097A45B8E7A4A09C9B78695] - 10/05/2015 - 09:38:35 ---A- . (.Microsoft Corporation - Client ActiveX des services Bureau à distan.) -- C:\Windows\System32\mstscax.dll [5698048]
O44 - LFC:[MD5.4676AAA9DDF52A50C829FEDB4EA81E54] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Connexion Bureau à distance.) -- C:\Windows\System32\mstsc.exe [1068544]
O44 - LFC:[MD5.AF40D823F3B03C7899AEF2293F84D0D7] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Proxy.) -- C:\Windows\System32\TSWbPrxy.exe [76288]
O44 - LFC:[MD5.5E676B296B762E211D83B87635F2C330] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Remote Desktop Services Client for Microsof.) -- C:\Windows\System32\rdvidcrl.dll [855552]
O44 - LFC:[MD5.0FC6922517964E9D90DE84DC86F63E40] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Runtime de connexion RemoteApp et Bureau à.) -- C:\Windows\System32\wksprt.exe [350208]
O44 - LFC:[MD5.8DEEE20D8D30E9B0FBDCA31E58A027BD] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - Client de contrainte de quarantaine de la p.) -- C:\Windows\System32\tsgqec.dll [53248]
O44 - LFC:[MD5.A90F47CDCC0898733596B5070039FC15] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - Extension de stratégie de groupe pour la re.) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll [14336]
O44 - LFC:[MD5.2EFB1279E7BEA7D12D9F4D6508D27880] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Acces.) -- C:\Windows\System32\MsRdpWebAccess.dll [50176]
O44 - LFC:[MD5.AB5EFB103DB01C1912C9D2F545EA5621] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - WorkspaceRuntime ProxyStub DLL.) -- C:\Windows\System32\wksprtPS.dll [17920]
O44 - LFC:[MD5.C6A5FBD4977305E1FA23E02C042DB463] - 10/05/2015 - 09:38:38 ---A- . (.Microsoft Corporation - Pilote de filtre pour concentrateur USB du.) -- C:\Windows\System32\Drivers\TsUsbFlt.sys [49152]
O44 - LFC:[MD5.D60E27D4BD5A91FCD17D2CB27F86738E] - 10/05/2015 - 09:38:38 ---A- . (.Microsoft Corporation - Remote Desktop USB Redirection GP Extension.) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe [12800]
O44 - LFC:[MD5.F37167FCDB661FD4B54CAD4755ABDD61] - 10/05/2015 - 09:38:40 ---A- . (.Microsoft Corporation - Co-installateur de pilote USB générique du.) -- C:\Windows\System32\TsUsbGDCoInstaller.dll [32256]
O44 - LFC:[MD5.4FBED1107021D7405721CE55975F2C96] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1677370]
O44 - LFC:[MD5.5C81CFC2FA1D69A7B165951D1051F889] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfc009.dat [123196]
O44 - LFC:[MD5.46261007C0E5F58CB875F4AF71763ADB] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [151280]
O44 - LFC:[MD5.1034469ABB736466148909A6EE82C0C8] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfh009.dat [657384]
O44 - LFC:[MD5.2EE8285A8B6D443F9003E8531357C0C8] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [750666]
O44 - LFC:[MD5.BA63FDF7785E75B60B3D958D4B381DB3] - 10/05/2015 - 16:44:33 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [2448648]
O44 - LFC:[MD5.FD7E6F9DCCD7FEEBDD6E8D3F14AD24F8] - 11/05/2015 - 07:02:32 ---A- . (...) -- C:\Windows\setupact.log [392]
O44 - LFC:[MD5.04B309A1A653177994630C2773E659F1] - 11/05/2015 - 07:03:37 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [119512]
O44 - LFC:[MD5.6446B430C5715E693545FC52D2746D3D] - 11/05/2015 - 07:11:15 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512]
O44 - LFC:[MD5.7FB275E0AF83B9ED8CC13F643D8DEE2A] - 11/05/2015 - 09:34:21 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.44EE7EE0EF748B16713C475E20D644AA] - 11/05/2015 - 10:03:02 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1304901]
O44 - LFC:[MD5.47DE8B7A482D4BABBCC70C0199E35881] - 27/04/2015 - 19:00:30 ---A- . (.Microsoft Corporation - Microsoft Windows Diagnostics Tracking.) -- C:\Windows\System32\UtcResources.dll [36864]
O44 - LFC:[MD5.86B2AC15999BB4F8B5C84AB6154A1783] - 27/04/2015 - 19:59:36 ---A- . (.Microsoft Corporation - DLL du schéma d'audit de sécurité.) -- C:\Windows\System32\adtschema.dll [686080]
O44 - LFC:[MD5.9638DA21E965E23C85C4319F3F66D824] - 27/04/2015 - 19:59:41 ---A- . (.Microsoft Corporation - ApiSet Schema DLL.) -- C:\Windows\System32\apisetschema.dll [6656]
O44 - LFC:[MD5.D079A408CC3E22A09D1260A6F18FC0FD] - 27/04/2015 - 20:01:22 ---A- . (.Microsoft Corporation - DLL des événements d'audit de la sécurité.) -- C:\Windows\System32\msaudite.dll [146432]
O44 - LFC:[MD5.BF9BB4113E9FCDABD4C703DDD06293F3] - 27/04/2015 - 20:01:33 ---A- . (.Microsoft Corporation - Nom d'audit des objets système.) -- C:\Windows\System32\msobjs.dll [60416]
O44 - LFC:[MD5.AFFE5747054D03F8CEE18A8518A9AA34] - 27/04/2015 - 20:03:52 ---A- . (.Microsoft Corporation - Programme de stratégie d'audit.) -- C:\Windows\System32\auditpol.exe [50176]
O44 - LFC:[MD5.F286528898342F0F1EB402606750C391] - 27/04/2015 - 20:03:58 ---A- . (.Microsoft Corporation - Utilitaire de configuration des performance.) -- C:\Windows\System32\diskperf.exe [17408]
O44 - LFC:[MD5.C6D2D384B6232B0B800234C03C50979F] - 27/04/2015 - 20:04:04 ---A- . (.Microsoft Corporation - Utilitaire d'enregistrement des Performance.) -- C:\Windows\System32\logman.exe [82944]
O44 - LFC:[MD5.1667D76FBF42B24B9DE3E8B0A7CF06BE] - 27/04/2015 - 20:04:05 ---A- . (.Microsoft Corporation - Local Security Authority Process.) -- C:\Windows\System32\lsass.exe [22528]
O44 - LFC:[MD5.97B30711DC6CA0EA4EACEDCE8080A3B4] - 27/04/2015 - 20:04:12 ---A- . (.Microsoft Corporation - Utilitaire de réenregistrement de Performan.) -- C:\Windows\System32\relog.exe [37888]
O44 - LFC:[MD5.7E9A03C1B76CB8A222C9AB232B3118D9] - 27/04/2015 - 20:04:14 ---A- . (.Microsoft Corporation - Restauration du système de Microsoft® Windo.) -- C:\Windows\System32\rstrui.exe [262656]
O44 - LFC:[MD5.03CD13A169C19558F637C2F36B974BDA] - 27/04/2015 - 20:04:21 ---A- . (.Microsoft Corporation - Gestionnaire de sessions Windows.) -- C:\Windows\System32\smss.exe [69632]
O44 - LFC:[MD5.74C0EC1257698176E288DA282F318E1C] - 27/04/2015 - 20:04:24 ---A- . (.Microsoft Corporation - Moniteur de performance de la ligne de comm.) -- C:\Windows\System32\typeperf.exe [40448]
O44 - LFC:[MD5.EB058143B57ED460AC4F2DFBA104BBFF] - 27/04/2015 - 20:04:24 ---A- . (.Microsoft Corporation - Outil de rapport de suivi d'événements.) -- C:\Windows\System32\tracerpt.exe [364544]
O44 - LFC:[MD5.7A5824DC9A85FCE4334F57FF0795853E] - 27/04/2015 - 20:04:33 ---A- . (.Microsoft Corporation - API avancées Windows 32.) -- C:\Windows\System32\advapi32.dll [641536]
O44 - LFC:[MD5.79AF005633B7E41B7A194A7E7B9D3D93] - 27/04/2015 - 20:04:37 ---A- . (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll [17408]
O44 - LFC:[MD5.5DCF39695CD614B162330F5AC27C4654] - 27/04/2015 - 20:04:37 ---A- . (.Microsoft Corporation - Processus d'exécution client-serveur.) -- C:\Windows\System32\csrsrv.dll [38912]
O44 - LFC:[MD5.54A01CC4BC47B31C5CD082D064AB37BC] - 27/04/2015 - 20:04:45 ---A- . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll [550912]
O44 - LFC:[MD5.D362BFE84A44A442CB6B8CBFE6DE027D] - 27/04/2015 - 20:04:47 ---A- . (.Microsoft Corporation - DLL serveur LSA.) -- C:\Windows\System32\lsasrv.dll [1061376]
O44 - LFC:[MD5.66D6A06936088E412E29A182679F0D71] - 27/04/2015 - 20:05:11 ---A- . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll [259584]
O44 - LFC:[MD5.0B6E937863837BA3383E9CE9200DDF1E] - 27/04/2015 - 20:05:17 ---A- . (.Microsoft Corporation - Bibliothèque de chiffrement Windows.) -- C:\Windows\System32\ncrypt.dll [221184]
O44 - LFC:[MD5.C34E0F9846D0FF902CED82DB5AB104BA] - 27/04/2015 - 20:05:28 ---A- . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll [248832]
O44 - LFC:[MD5.8C45A65ED20B487085B79EEFCC08D160] - 27/04/2015 - 20:05:29 ---A- . (.Microsoft Corporation - Host for SCM/SDDL/LSA Lookup APIs.) -- C:\Windows\System32\sechost.dll [92160]
O44 - LFC:[MD5.99A508910BB06DFBE99D9AF7D6B4E950] - 27/04/2015 - 20:05:29 ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\secur32.dll [22016]
O44 - LFC:[MD5.7CC0547B9FD90649731E021DA2763086] - 27/04/2015 - 20:05:32 ---A- . (.Microsoft Corporation - Bibliothèque principale de Restauration du.) -- C:\Windows\System32\srcore.dll [400896]
O44 - LFC:[MD5.ABA025664F9F42C568B2C022AADCB18F] - 27/04/2015 - 20:05:32 ---A- . (.Microsoft Corporation - Microsoft® Windows System Restore Client Li.) -- C:\Windows\System32\srclient.dll [43008]
O44 - LFC:[MD5.ECB7366ED80E349436FC495A77EAF24C] - 27/04/2015 - 20:05:33 ---A- . (.Microsoft Corporation - LSA SSPI RPC interface DLL.) -- C:\Windows\System32\sspisrv.dll [15872]
O44 - LFC:[MD5.6C427298E65C1430D232A0529ED9B18E] - 27/04/2015 - 20:05:33 ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\sspicli.dll [100352]
O44 - LFC:[MD5.D0F574320615303ADECDCB452EBB8930] - 27/04/2015 - 20:05:34 ---A- . (.Microsoft Corporation - Bibliothèque de l'application auxiliaire de.) -- C:\Windows\System32\tdh.dll [635392]
O44 - LFC:[MD5.FCB1C8345C794FE89ABA03B4CA3131BB] - 27/04/2015 - 20:05:35 ---A- . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\TSpkg.dll [65536]
O44 - LFC:[MD5.E95DE5B790B2D16706DAC8472E51F31A] - 27/04/2015 - 20:05:39 ---A- . (.Microsoft Corporation - Microsoft Windows Diagnostics Tracking.) -- C:\Windows\System32\diagtrack.dll [851456]
O44 - LFC:[MD5.850F756363237A2EB069B9B25EF8BEC3] - 27/04/2015 - 20:05:40 ---A- . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll [172032]
O44 - LFC:[MD5.7410C9F088E4F13C981F981B52475B5E] - 27/04/2015 - 20:08:02 ---A- . (.Microsoft Corporation - DLL Couche NT.) -- C:\Windows\System32\ntdll.dll [1307648]
O44 - LFC:[MD5.6DD2A1064DD8AFBED22E71176E2AF59B] - 27/04/2015 - 20:11:53 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecdd.sys [67520]
O44 - LFC:[MD5.76C0D35167B1369C68388FEDB56A3048] - 27/04/2015 - 20:11:53 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecpkg.sys [137664]
O44 - LFC:[MD5.8D50ED3F0FBE3590AB0D43BF7B60E57A] - 27/04/2015 - 20:11:54 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntkrnlpa.exe [3989440]
O44 - LFC:[MD5.0A66C88B087249742381924AB8F9EFCC] - 27/04/2015 - 20:11:55 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntoskrnl.exe [3934144]
~ Files: 70 Scanned in 00mn 03s
---\\ Déni du service (Local Security Authority) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l'Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Notification Packages . (.DigitalPersona, Inc. - DPPwdFlt Module.) -- C:\Windows\System32\DPPWDFLT.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corp. - LiveSSP.) -- C:\Windows\System32\livessp.dll
~ LSA: 10 Scanned in 00mn 00s
---\\ Contrôle du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d'extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d'extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
~ CSB: 13 Scanned in 00mn 00s
---\\ Clé de registre Shell MountPoints2 (MPSK) (O51)
O51 - MPSK:{30236676-b194-11e1-8151-f04da2c023f1}\AutoRun\command. (...) -- E:\unlock.exe (.not file.)
O51 - MPSK:{74702b01-b586-11e3-ba34-f04da2c023f1}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)
O51 - MPSK:{d22ae3b2-20ad-11e0-a6a7-f04da2c023f1}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)
~ Keys: Scanned in 00mn 00s
---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll
O52 - TDSD: \Drivers32\"vidc.XVID"="xvidvfw.dll" . (...) -- C:\Windows\System32\xvidvfw.dll
O52 - TDSD: \Drivers32\"vidc.ffds"="ff_vfw.dll" . (...) -- C:\Windows\System32\ff_vfw.dll
O52 - TDSD: \Drivers32\"msacm.vorbis"="vorbis.acm" . (.HMS http://hp.vector.co.jp/authors/VA012897 - Ogg Vorbis CODEC for MSACM.) -- C:\Windows\System32\vorbis.acm
O52 - TDSD: \Drivers32\"vidc.iv50"="ir50_32.dll" . (.Intel Corporation - Intel Indeo® video 5.10.) -- C:\Windows\System32\ir50_32.dll
O52 - TDSD: \Drivers32\"vidc.iv41"="ir41_32.ax" . (.Intel Corporation - Intel Indeo® Video 4.5.) -- C:\Windows\System32\ir41_32.ax
O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (.Intel(R) Corporation - Pas de description.) -- C:\Windows\System32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (.Intel(R) Corporation - Pas de description.) -- C:\Windows\System32\ir32_32.dll
O52 - TDSD: \Drivers32\"msacm.iac2"="C:\Windows\system32\iac25_32.ax" . (.Intel Corporation - Indeo® audio software.) -- C:\Windows\system32\iac25_32.ax
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"xvidvfw.dll"="Xvid MPEG-4 Video Codec" . (...) -- C:\Windows\System32\xvidvfw.dll
O52 - TDSD: \drivers.desc\"vorbis.acm"="Ogg Vorbis Audio CODEC, Based on Xiphophorus libVorbis I 20010910" . (.HMS http://hp.vector.co.jp/authors/VA012897 - Ogg Vorbis CODEC for MSACM.) -- C:\Windows\System32\vorbis.acm
O52 - TDSD: \drivers.desc\"C:\Windows\system32\iac25_32.ax"="Indeo® audio software" . (.Intel Corporation - Indeo® audio software.) -- C:\Windows\system32\iac25_32.ax
~ TDSD: 14 Scanned in 00mn 00s
---\\ Enumération des clés de registre StartupReg (SMSR) (O53)
O53 - SMSR:HKLM\...\startupreg\AdobeBridge [Key] . (.Adobe Systems, Inc. - Adobe Bridge.) -- C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe =>.Adobe Systems Incorporated
O53 - SMSR:HKLM\...\startupreg\APSDaemon [Key] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
O53 - SMSR:HKLM\...\startupreg\CCleaner Monitoring [Key] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
O53 - SMSR:HKLM\...\startupreg\iTunesHelper [Key] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
O53 - SMSR:HKLM\...\startupreg\Skype [Key] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O53 - SMSR:HKLM\...\startupreg\Spotify Web Helper [Key] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe
~ SMSR Keys: 6 Scanned in 00mn 00s
---\\ Enumération des clés de registre SecurityProviders (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
~ MSCP: 2 Scanned in 00mn 00s
---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=0
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Scanned in 00mn 00s
---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145
~ MWPE Keys: 1 Scanned in 00mn 00s
---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:03/12/2009 - 07:24:38 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\System32\Drivers\Acceler.sys [41648]
O58 - SDL:29/09/2010 - 17:38:00 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\System32\Drivers\Accelern.sys [43888]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976]
O58 - SDL:14/07/2009 - 02:26:17 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [297552]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\Drivers\adpu320.sys [146512]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [14400]
O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [80256]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows fa.) -- C:\Windows\System32\Drivers\amdsbs.sys [159312]
O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [22400]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [76368]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [86608]
O58 - SDL:15/07/2011 - 16:11:46 ---A- . (.BitDefender - BitDefender AntiVirus Active Virus Control Hypervisor driver.) -- C:\Windows\System32\Drivers\avchv.sys [240184]
O58 - SDL:01/09/2011 - 11:15:08 ---A- . (.BitDefender - Active Virus Control Kernel Filtering driver.) -- C:\Windows\System32\Drivers\avckf.sys [454960]
O58 - SDL:13/07/2009 - 23:02:49 ---A- . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gigabit Ethernet..) -- C:\Windows\System32\Drivers\b57nd60x.sys [229888]
O58 - SDL:07/01/2011 - 13:47:17 ---A- . (.Broadcom Corporation - Broadcom iLine10(tm) PCI Network Adapter Proxy Protocol Driver.) -- C:\Windows\System32\Drivers\bcm42rly.sys [18424]
O58 - SDL:05/05/2010 - 20:28:38 ---A- . (.Broadcom Corporation - Broadcom 802.11 Network Adapter wireless driver.) -- C:\Windows\System32\Drivers\BCMWL6.SYS [2707448]
O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [13568]
O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [5248]
O58 - SDL:14/07/2009 - 01:57:25 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [272128]
O58 - SDL:13/07/2009 - 23:53:32 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [62336]
O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [12160]
O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [11904]
O58 - SDL:03/10/2009 - 06:24:12 ---A- . (.Broadcom Corporation. - Bluetooth Audio Device.) -- C:\Windows\System32\Drivers\btwaudio.sys [86056]
O58 - SDL:29/08/2009 - 03:15:16 ---A- . (.Broadcom Corporation. - Broadcom Bluetooth AVDT Service.) -- C:\Windows\System32\Drivers\btwavdt.sys [108072]
O58 - SDL:07/04/2009 - 23:32:50 ---A- . (.Broadcom Corporation. - Broadcom Bluetooth L2CAP Service.) -- C:\Windows\System32\Drivers\btwl2cap.sys [29472]
O58 - SDL:29/08/2009 - 03:15:12 ---A- . (.Broadcom Corporation. - Bluetooth Remote Control HID Minidriver.) -- C:\Windows\System32\Drivers\btwrchid.sys [18472]
O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbdx.sys [430080]
O58 - SDL:20/10/2009 - 10:00:00 ---A- . (.Sonic Solutions - CDR4 CD and DVD Place Holder Driver (see PxHelp).) -- C:\Windows\System32\Drivers\cdr4_xp.sys [9072]
O58 - SDL:20/10/2009 - 10:00:00 ---A- . (.Sonic Solutions - CDRAL Place Holder Driver (see PxHelp).) -- C:\Windows\System32\Drivers\cdralw2k.sys [9200]
O58 - SDL:14/07/2009 - 02:26:21 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [15952]
O58 - SDL:28/05/2009 - 17:48:20 ---A- . (.Creative Technology Ltd. - Advanced Audio FX Driver.) -- C:\Windows\System32\Drivers\CtAudDrv.sys [134144]
O58 - SDL:12/08/2010 - 17:50:20 ---A- . (.Creative Technology Ltd. - Video Class Upper Filter Driver.) -- C:\Windows\System32\Drivers\CtClsFlt.sys [146528]
O58 - SDL:30/01/2015 - 23:36:11 ---A- . (.Dell Computer Corporation - DDDriver.sys.) -- C:\Windows\System32\Drivers\DDDriver32Dcsa.sys [20688]
O58 - SDL:30/01/2015 - 23:36:11 ---A- . (.Dell Computer Corporation - DellProf.sys.) -- C:\Windows\System32\Drivers\DellProf.sys [19984]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\Drivers\djsvs.sys [70720]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712]
O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbdx.sys [3100160]
O58 - SDL:21/08/2012 - 12:01:22 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys [26840]
O58 - SDL:13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624]
O58 - SDL:17/09/2009 - 21:54:14 ---A- . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\Drivers\HECI.sys [41088]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [67152]
O58 - SDL:04/03/2010 - 19:33:26 ---A- . (.Intel Corporation - Intel Rapid Storage Technology driver - x86.) -- C:\Windows\System32\Drivers\iaStor.sys [435736]
O58 - SDL:11/03/2011 - 06:38:51 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332160]
O58 - SDL:26/08/2010 - 12:31:30 ---A- . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\Drivers\igdkmd32.sys [9024512]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [41040]
O58 - SDL:27/02/2010 - 16:31:24 ---A- . (.Intel Corporation - Intel(R) Turbo Boost Technology Driver.) -- C:\Windows\System32\Drivers\Impcd.sys [132480]
O58 - SDL:31/08/2010 - 04:15:56 ---A- . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\Drivers\IntcDAud.sys [247808]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [95824]
O58 - SDL:14/07/2009 - 02:20:37 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [89168]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [54864]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [96848]
O58 - SDL:14/04/2015 - 08:37:42 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23256]
O58 - SDL:14/04/2015 - 08:37:44 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [92888]
O58 - SDL:11/05/2015 - 07:03:37 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [119512]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7 for x86.) -- C:\Windows\System32\Drivers\megasas.sys [30800]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [235584]
O58 - SDL:14/04/2015 - 08:37:54 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [51928]
O58 - SDL:14/07/2009 - 02:20:44 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [44624]
O58 - SDL:07/01/2011 - 13:47:18 ---A- . (.CACE Technologies, Inc. - npf.sys (NT5/6 x86) Kernel Driver.) -- C:\Windows\System32\Drivers\npf.sys [50704]
O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117120]
O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [143744]
O58 - SDL:19/03/2010 - 10:00:00 ---A- . (.Sonic Solutions - Px Engine Device Driver for Windows 2000/XP.) -- C:\Windows\System32\Drivers\pxhelp20.sys [45648]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1383488]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [106064]
O58 - SDL:10/06/2011 - 05:34:52 ---A- . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.20 32-bit Driver.) -- C:\Windows\System32\Drivers\Rt86win7.sys [394856]
O58 - SDL:10/08/2009 - 20:06:08 ---A- . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/Vista/Win7.) -- C:\Windows\System32\Drivers\RtsUStor.sys [171520]
O58 - SDL:13/07/2009 - 21:50:20 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [20480]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [40016]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [77888]
O58 - SDL:20/08/2010 - 18:04:38 ---A- . (.ST Microelectronics - Disk Class Filter Driver for Accelerometer.) -- C:\Windows\System32\Drivers\stdcfltn.sys [17648]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072]
O58 - SDL:07/04/2010 - 13:35:04 ---A- . (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\Drivers\stwrt.sys [423936]
O58 - SDL:08/01/2010 - 05:46:20 ---A- . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\Windows\System32\Drivers\SynTP.sys [232624]
O58 - SDL:14/07/2009 - 02:19:10 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [16976]
O58 - SDL:14/07/2009 - 02:19:11 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [141904]
O58 - SDL:13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672]
~ Drivers: 90 Scanned in 00mn 03s
---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\ffmpegsumo.dll [990776]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\libEGL.dll [219192]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\libGLESv2.dll [1365560]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\libcef.dll [40518200]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\wow_helper.exe [73272]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (.Microsoft Corporation.) -- C:\Users\Amaury\AppData\Roaming\Spotify\d3dcompiler_43.dll [2106424]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (.Microsoft Corporation.) -- C:\Users\Amaury\AppData\Roaming\Spotify\d3dcompiler_47.dll [3457592]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\Spotify.exe [7168568]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyCrashService.exe [778808]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyLauncher.exe [124472]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920]
O61 - LFC: 08/05/2015 - 11:09:05 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Adobe\Acrobat\9.0\UserCache.bin [106533]
O61 - LFC: 08/05/2015 - 11:09:07 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\ZHP\ZHPCleaner.exe [1818624] =>.Nicolas Coolman
O61 - LFC: 08/05/2015 - 11:09:08 ---A- . (...) -- C:\Users\Amaury\Downloads\adwcleaner_4.203.exe [2204160]
O61 - LFC: 09/05/2015 - 11:09:08 ---A- . (...) -- C:\Users\Amaury\Downloads\ZHPCleaner(1).exe [1820160] =>.Nicolas Coolman
O61 - LFC: 11/05/2015 - 11:09:08 ---A- . (.Nicolas Coolman.) -- C:\Users\Amaury\Downloads\ZHPDiag2.exe [6880396] =>.Nicolas Coolman
~ 155 Fichiers temporaires (Temporary files)
~ 5 Fichiers cookies (Cookies files)
~ Files: 16 Scanned in 00mn 09s
---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s
---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - 07/01/2011 - C:\Windows\System32\drivers\BCM42RLY.sys (BCM42RLY) .(.Broadcom Corporation - Broadcom iLine10(tm) PCI Network Adapter Pr.) - LEGACY_BCM42RLY
O64 - Services: CurCS - 28/01/1746 - C:\Users\Amaury\AppData\Local\Temp\mbr.sys (mbr) .(...) - LEGACY_MBR
O64 - Services: CurCS - 13/07/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV
~ Legacy: 119 Scanned in 00mn 00s
---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d'événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
~ FASS Keys: 10 Scanned in 00mn 00s
---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s
---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s
---\\ Enumère les fichiers Crack & Keygen (CKF) (O82)
C:\Users\Amaury\Desktop\Adobe CS4\Master Collection\Adobe CS4\Adobe_Master_Collection_CS4_Keygen_by_Milkman.zip =>.Crack,Keygen
C:\Users\Amaury\Desktop\EndNote X6 Bld 6348\Cracked\EndNote.exe =>.Crack,Keygen
C:\Users\Amaury\Desktop\Adobe CS4\Master Collection\Adobe CS4\Adobe_Master_Collection_CS4_Keygen_by_Milkman.zip =>.Crack,Keygen
C:\Users\Amaury\Desktop\EndNote X6 Bld 6348\Cracked\EndNote.exe =>.Crack,Keygen
~ Files: Scanned in 00mn 49s
---\\ Enumère les service demarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d'application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [475136]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d'accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d'interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d'événements système (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [523776]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2020864]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search
O43 - CFD: 23/09/2013 - 18:48:51 - [] ----D C:\Program Files\7-Zip
O43 - CFD: 14/10/2012 - 17:01:19 - [] ----D C:\Program Files\Adobe
O43 - CFD: 27/10/2012 - 13:10:03 - [] ----D C:\Program Files\Apple Software Update =>.Apple Inc
O43 - CFD: 23/09/2013 - 14:43:50 - [] ----D C:\Program Files\ArcGIS
O43 - CFD: 27/10/2012 - 13:09:43 - [] ----D C:\Program Files\Bonjour
O43 - CFD: 08/05/2015 - 11:47:02 - [] ----D C:\Program Files\CCleaner
O43 - CFD: 04/12/2011 - 23:56:37 - [] ----D C:\Program Files\CDBurnerXP
O43 - CFD: 07/01/2011 - 14:48:11 - [] ----D C:\Program Files\Cisco
O43 - CFD: 09/04/2013 - 08:24:59 - [] ----D C:\Program Files\Citrix
O43 - CFD: 10/05/2015 - 10:49:29 - [] ----D C:\Program Files\Common Files
O43 - CFD: 07/01/2011 - 14:52:12 - [] ----D C:\Program Files\Creative
O43 - CFD: 07/01/2011 - 14:51:48 - [] ----D C:\Program Files\Creative Live! Cam
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\CyberLink
O43 - CFD: 13/02/2015 - 17:07:18 - [] ----D C:\Program Files\Dell
O43 - CFD: 07/01/2011 - 14:41:47 - [] ----D C:\Program Files\Dell Inc
O43 - CFD: 01/04/2015 - 15:56:44 - [] ----D C:\Program Files\Dell Support Center
O43 - CFD: 07/01/2011 - 14:51:52 - [] ----D C:\Program Files\Dell Webcam
O43 - CFD: 07/01/2011 - 14:49:33 - [] ----D C:\Program Files\DigitalPersona
O43 - CFD: 05/10/2011 - 21:15:44 - [] ----D C:\Program Files\Druide
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\DVD Maker
O43 - CFD: 30/05/2013 - 16:35:59 - [] ----D C:\Program Files\EndNote X3
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\Program Files\Fichiers communs
O43 - CFD: 09/08/2013 - 08:30:00 - [] ----D C:\Program Files\Google
O43 - CFD: 18/09/2012 - 08:30:24 - [] ----D C:\Program Files\GUMBB52.tmp
O43 - CFD: 07/01/2011 - 07:38:05 - [] ----D C:\Program Files\IDT
O43 - CFD: 07/01/2011 - 14:51:50 - [] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 07/01/2011 - 14:43:38 - [] ----D C:\Program Files\Intel
O43 - CFD: 16/04/2015 - 07:41:45 - [] ----D C:\Program Files\Internet Explorer
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\iPod
O43 - CFD: 30/05/2014 - 17:24:54 - [] ----D C:\Program Files\IRIScan Direct
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\Program Files\iTunes
O43 - CFD: 01/02/2015 - 19:24:51 - [] ----D C:\Program Files\Java
O43 - CFD: 08/05/2015 - 12:02:05 - [] ----D C:\Program Files\Malwarebytes Anti-Malware
O43 - CFD: 19/08/2014 - 07:39:24 - [] ----D C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 15/01/2011 - 17:51:35 - [0] ----D C:\Program Files\Microsoft
O43 - CFD: 14/07/2009 - 11:00:58 - [] ----D C:\Program Files\Microsoft Games
O43 - CFD: 27/08/2012 - 21:15:59 - [] ----D C:\Program Files\Microsoft Office
O43 - CFD: 10/02/2012 - 09:38:04 - [] ----D C:\Program Files\Microsoft Research
O43 - CFD: 11/02/2015 - 20:53:43 - [] ----D C:\Program Files\Microsoft Security Client
O43 - CFD: 24/07/2014 - 17:05:44 - [] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 07/01/2011 - 15:02:44 - [] ----D C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 13/03/2011 - 22:40:16 - [] ----D C:\Program Files\Microsoft Visual Studio
O43 - CFD: 13/03/2011 - 22:37:09 - [] ----D C:\Program Files\Microsoft Visual Studio 8
O43 - CFD: 23/08/2012 - 08:17:10 - [] ----D C:\Program Files\Microsoft Works
O43 - CFD: 13/03/2011 - 22:40:04 - [] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 24/04/2015 - 12:09:10 - [] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 26/04/2015 - 08:23:34 - [] ----D C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 13/03/2011 - 22:40:20 - [] ----D C:\Program Files\MSBuild
O43 - CFD: 15/01/2011 - 23:49:59 - [0] ----D C:\Program Files\MSXML 4.0
O43 - CFD: 14/07/2009 - 06:52:30 - [] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 07/01/2011 - 14:58:04 - [] ----D C:\Program Files\Roxio
O43 - CFD: 03/03/2014 - 12:14:18 - [] ----D C:\Program Files\SamsungPrinterLiveUpdate
O43 - CFD: 03/03/2014 - 12:04:04 - [] ----D C:\Program Files\SamsungPrinterLiveUpdateInstaller
O43 - CFD: 05/02/2011 - 11:29:22 - [] ----D C:\Program Files\Satsuki Decoder Pack
O43 - CFD: 14/04/2015 - 08:03:39 - [] R---D C:\Program Files\Skype
O43 - CFD: 24/03/2015 - 20:36:20 - [] ----D C:\Program Files\Spotify
O43 - CFD: 07/01/2011 - 14:44:04 - [] ----D C:\Program Files\STMicroelectronics
O43 - CFD: 07/01/2011 - 16:33:50 - [] ----D C:\Program Files\Synaptics
O43 - CFD: 10/12/2011 - 19:15:54 - [] ----D C:\Program Files\Trend Micro
O43 - CFD: 25/03/2011 - 22:12:50 - [] ----D C:\Program Files\TuxGuitar-Jet
O43 - CFD: 14/07/2009 - 06:53:23 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 07/01/2011 - 14:45:49 - [] ----D C:\Program Files\Validity Sensors
O43 - CFD: 07/01/2011 - 14:46:46 - [] ----D C:\Program Files\WIDCOMM
O43 - CFD: 12/07/2013 - 07:57:37 - [] ----D C:\Program Files\Windows Defender
O43 - CFD: 12/07/2014 - 07:43:28 - [] ----D C:\Program Files\Windows Journal
O43 - CFD: 07/01/2011 - 15:03:04 - [] ----D C:\Program Files\Windows Live
O43 - CFD: 04/01/2012 - 19:59:00 - [] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 12/03/2015 - 04:25:28 - [] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 12/01/2011 - 13:59:10 - [] ----D C:\Program Files\Windows NT
O43 - CFD: 04/01/2012 - 19:58:58 - [] ----D C:\Program Files\Windows Photo Viewer
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Portable Devices
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Sidebar
O43 - CFD: 05/02/2011 - 12:44:37 - [] ----D C:\Program Files\WinRAR
O43 - CFD: 15/04/2014 - 08:21:40 - [] ----D C:\Program Files\XnView
O43 - CFD: 15/01/2011 - 22:02:09 - [] ----D C:\Program Files\Xvid
O43 - CFD: 11/05/2015 - 11:05:57 - [] ----D C:\Program Files\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 14/10/2012 - 17:01:28 - [] ----D C:\Program Files\Common Files\Adobe
O43 - CFD: 23/09/2013 - 14:47:09 - [] ----D C:\Program Files\Common Files\AnswerWorks 4.0
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\Common Files\Apple
O43 - CFD: 23/09/2013 - 14:46:20 - [] ----D C:\Program Files\Common Files\ArcGIS
O43 - CFD: 10/12/2011 - 19:52:01 - [] ----D C:\Program Files\Common Files\Bitdefender
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\Common Files\CyberLink
O43 - CFD: 23/09/2013 - 14:44:22 - [] ----D C:\Program Files\Common Files\Data Dynamics
O43 - CFD: 15/05/2014 - 11:50:28 - [] ----D C:\Program Files\Common Files\DESIGNER
O43 - CFD: 07/01/2011 - 14:51:35 - [] ----D C:\Program Files\Common Files\InstallShield
O43 - CFD: 01/02/2015 - 19:25:56 - [] ----D C:\Program Files\Common Files\Java
O43 - CFD: 28/02/2011 - 22:14:03 - [] ----D C:\Program Files\Common Files\Macrovision Shared
O43 - CFD: 05/02/2011 - 11:49:23 - [] ----D C:\Program Files\Common Files\mcafee
O43 - CFD: 23/08/2012 - 08:17:16 - [] ----D C:\Program Files\Common Files\microsoft shared
O43 - CFD: 07/01/2011 - 14:43:41 - [] ----D C:\Program Files\Common Files\postureAgent
O43 - CFD: 07/01/2011 - 14:58:20 - [] ----D C:\Program Files\Common Files\PX Storage Engine
O43 - CFD: 30/05/2013 - 16:36:04 - [] ----D C:\Program Files\Common Files\ResearchSoft
O43 - CFD: 23/12/2012 - 15:28:39 - [] ----D C:\Program Files\Common Files\Risxtd
O43 - CFD: 07/01/2011 - 14:58:36 - [] ----D C:\Program Files\Common Files\Roxio Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\Services
O43 - CFD: 08/10/2014 - 07:41:48 - [] ----D C:\Program Files\Common Files\Skype
O43 - CFD: 07/01/2011 - 14:58:00 - [] ----D C:\Program Files\Common Files\Sonic Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 07/01/2011 - 14:57:58 - [] ----D C:\Program Files\Common Files\SureThing Shared
O43 - CFD: 17/01/2012 - 16:46:20 - [0] ----D C:\Program Files\Common Files\SWF Studio
O43 - CFD: 04/01/2012 - 19:58:57 - [] ----D C:\Program Files\Common Files\System
O43 - CFD: 23/09/2013 - 14:44:09 - [] ----D C:\Program Files\Common Files\Tom Sawyer Software
O43 - CFD: 07/01/2011 - 14:58:54 - [] ----D C:\Program Files\Common Files\Windows Live
O43 - CFD: 30/05/2013 - 16:33:17 - [] ----D C:\Program Files\Common Files\Wise Installation Wizard
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
O43 - CFD: 30/07/2014 - 20:12:45 - [] ----D C:\ProgramData\Adobe
O43 - CFD: 28/02/2011 - 22:22:21 - [0] ----D C:\ProgramData\ALM
O43 - CFD: 27/10/2012 - 13:10:01 - [] ----D C:\ProgramData\Apple
O43 - CFD: 27/10/2012 - 13:10:36 - [] ----D C:\ProgramData\Apple Computer
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Application Data
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Bureau
O43 - CFD: 25/09/2011 - 22:32:17 - [] ----D C:\ProgramData\Canneverbe Limited
O43 - CFD: 01/02/2011 - 10:06:18 - [] --H-D C:\ProgramData\CanonBJ
O43 - CFD: 30/01/2014 - 16:19:41 - [] --H-D C:\ProgramData\CanonIJScan
O43 - CFD: 09/04/2013 - 08:25:17 - [] ----D C:\ProgramData\Citrix
O43 - CFD: 05/02/2011 - 11:48:10 - [] ----D C:\ProgramData\Creative
O43 - CFD: 17/01/2012 - 16:46:30 - [] ----D C:\ProgramData\CyberLink
O43 - CFD: 23/09/2013 - 14:36:26 - [] ----D C:\ProgramData\DAEMON Tools Lite =>.DT Soft Ltd
O43 - CFD: 23/08/2012 - 11:22:11 - [] ----D C:\ProgramData\Dell
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Documents
O43 - CFD: 07/01/2011 - 14:49:20 - [] ----D C:\ProgramData\Downloaded Installations
O43 - CFD: 06/01/2015 - 15:10:21 - [] ----D C:\ProgramData\ESRI
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Favoris
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Favorites
O43 - CFD: 23/09/2013 - 14:57:18 - [] ----D C:\ProgramData\FLEXnet
O43 - CFD: 25/03/2011 - 21:26:10 - [0] ----D C:\ProgramData\Guitar Pro 6
O43 - CFD: 07/01/2011 - 14:49:33 - [] ----D C:\ProgramData\Macrovision
O43 - CFD: 19/08/2014 - 07:39:24 - [] ----D C:\ProgramData\Malwarebytes
O43 - CFD: 16/11/2012 - 19:40:59 - [] ----D C:\ProgramData\McAfee
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Menu Démarrer
O43 - CFD: 10/12/2014 - 10:25:17 - [] -S--D C:\ProgramData\Microsoft
O43 - CFD: 15/04/2015 - 19:07:22 - [] ----D C:\ProgramData\Microsoft Help
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\ProgramData\Modèles
O43 - CFD: 04/05/2012 - 08:23:01 - [] ----D C:\ProgramData\Mozilla
O43 - CFD: 10/05/2015 - 10:49:12 - [] ----D C:\ProgramData\Nero
O43 - CFD: 01/02/2015 - 19:27:18 - [] ----D C:\ProgramData\Oracle
O43 - CFD: 01/04/2015 - 15:56:47 - [] ----D C:\ProgramData\PC-Doctor for Windows
O43 - CFD: 07/05/2015 - 18:06:46 - [] ----D C:\ProgramData\PCDr
O43 - CFD: 07/01/2011 - 14:57:48 - [] ----D C:\ProgramData\PhotoShow Shared Assets
O43 - CFD: 24/10/2013 - 08:34:45 - [] --H-D C:\ProgramData\RICOH_DRV
O43 - CFD: 07/01/2011 - 14:57:48 - [] ----D C:\ProgramData\Roxio
O43 - CFD: 03/03/2014 - 12:04:03 - [] ----D C:\ProgramData\Samsung
O43 - CFD: 02/05/2015 - 08:11:28 - [] ----D C:\ProgramData\Skype
O43 - CFD: 16/06/2011 - 21:14:34 - [] ----D C:\ProgramData\Skype Extras
O43 - CFD: 11/05/2015 - 07:47:22 - [] ----D C:\ProgramData\Sonic
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Start Menu
O43 - CFD: 07/01/2011 - 14:42:45 - [] ----D C:\ProgramData\Sun
O43 - CFD: 05/05/2015 - 13:48:55 - [] ----D C:\ProgramData\SupportAssistAgent
O43 - CFD: 07/01/2011 - 14:51:06 - [] ----D C:\ProgramData\Temp
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Templates
O43 - CFD: 30/05/2013 - 16:36:06 - [] ----D C:\ProgramData\Thomson.ResearchSoft.Installers
O43 - CFD: 07/01/2011 - 14:58:36 - [] ----D C:\ProgramData\Uninstall
O43 - CFD: 12/03/2015 - 15:04:58 - [] --H-D C:\ProgramData\{6AACA38B-2810-4B47-BDEC-D7A1F38B1531}
O43 - CFD: 23/09/2013 - 18:48:51 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
O43 - CFD: 10/05/2015 - 12:49:29 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 14/07/2009 - 06:46:36 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 28/02/2011 - 22:24:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS4
O43 - CFD: 05/10/2011 - 21:22:25 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antidote
O43 - CFD: 23/09/2013 - 14:48:04 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcGIS
O43 - CFD: 04/11/2012 - 20:30:57 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG5200 series
O43 - CFD: 07/01/2011 - 15:10:41 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 9.5
O43 - CFD: 01/04/2015 - 15:56:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
O43 - CFD: 07/01/2011 - 14:52:26 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Webcam
O43 - CFD: 07/01/2011 - 14:47:42 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DW WLAN
O43 - CFD: 30/05/2013 - 16:35:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EndNote
O43 - CFD: 07/01/2011 - 07:38:55 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 19/12/2013 - 13:12:21 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth =>.Google Inc
O43 - CFD: 30/05/2014 - 17:24:55 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IRIScan Direct
O43 - CFD: 02/06/2013 - 16:57:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
O43 - CFD: 01/02/2015 - 19:25:18 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 14/07/2009 - 06:42:30 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 08/05/2015 - 12:02:07 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
O43 - CFD: 13/09/2013 - 17:40:09 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O43 - CFD: 24/07/2014 - 11:37:55 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
O43 - CFD: 07/01/2011 - 14:58:20 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio Creator Starter
O43 - CFD: 08/10/2014 - 07:41:49 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 16/11/2012 - 22:41:05 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 14/07/2009 - 11:00:22 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 07/01/2011 - 15:02:54 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
O43 - CFD: 15/04/2014 - 08:21:40 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView
O43 - CFD: 15/01/2011 - 22:02:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
O43 - CFD: 11/05/2015 - 11:05:57 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP =>.Nicolas Coolman
O43 - CFD: 04/07/2013 - 18:36:20 - [] ----D C:\Users\Amaury\AppData\Roaming\Adobe
O43 - CFD: 27/10/2012 - 13:12:04 - [] ----D C:\Users\Amaury\AppData\Roaming\Apple Computer
O43 - CFD: 25/09/2011 - 22:32:17 - [] ----D C:\Users\Amaury\AppData\Roaming\Canneverbe Limited
O43 - CFD: 30/01/2014 - 16:19:41 - [] ----D C:\Users\Amaury\AppData\Roaming\Canon
O43 - CFD: 12/01/2011 - 14:04:06 - [] ----D C:\Users\Amaury\AppData\Roaming\Creative
O43 - CFD: 17/01/2012 - 16:46:29 - [] ----D C:\Users\Amaury\AppData\Roaming\CyberLink
O43 - CFD: 15/11/2013 - 08:39:56 - [] ----D C:\Users\Amaury\AppData\Roaming\DAEMON Tools Lite =>.DT Soft Ltd
O43 - CFD: 24/03/2011 - 09:54:04 - [] ----D C:\Users\Amaury\AppData\Roaming\Dell
O43 - CFD: 12/01/2011 - 14:04:02 - [] ----D C:\Users\Amaury\AppData\Roaming\DigitalPersona
O43 - CFD: 05/09/2011 - 09:51:28 - [] ----D C:\Users\Amaury\AppData\Roaming\Druide
O43 - CFD: 16/05/2014 - 10:40:34 - [] ----D C:\Users\Amaury\AppData\Roaming\EndNote
O43 - CFD: 23/09/2013 - 15:04:14 - [] ----D C:\Users\Amaury\AppData\Roaming\ESRI
O43 - CFD: 25/03/2011 - 22:10:49 - [] ----D C:\Users\Amaury\AppData\Roaming\Guitar Pro 6
O43 - CFD: 12/01/2011 - 14:03:44 - [] ----D C:\Users\Amaury\AppData\Roaming\Identities
O43 - CFD: 15/01/2011 - 18:01:02 - [] ----D C:\Users\Amaury\AppData\Roaming\Macromedia
O43 - CFD: 12/01/2011 - 21:28:33 - [] ----D C:\Users\Amaury\AppData\Roaming\Macrovision
O43 - CFD: 19/08/2014 - 07:39:37 - [0] ----D C:\Users\Amaury\AppData\Roaming\Malwarebytes
O43 - CFD: 14/07/2009 - 11:00:22 - [0] ----D C:\Users\Amaury\AppData\Roaming\Media Center Programs
O43 - CFD: 06/01/2014 - 16:31:05 - [0] ----D C:\Users\Amaury\AppData\Roaming\Media Player Classic
O43 - CFD: 31/01/2015 - 17:38:39 - [] -S--D C:\Users\Amaury\AppData\Roaming\Microsoft
O43 - CFD: 15/01/2011 - 21:25:03 - [] ----D C:\Users\Amaury\AppData\Roaming\Mozilla
O43 - CFD: 27/06/2013 - 21:48:54 - [] ----D C:\Users\Amaury\AppData\Roaming\Nero
O43 - CFD: 16/07/2014 - 12:04:25 - [] ----D C:\Users\Amaury\AppData\Roaming\PCDr
O43 - CFD: 10/12/2011 - 18:47:36 - [0] ----D C:\Users\Amaury\AppData\Roaming\QuickScan
O43 - CFD: 05/02/2011 - 11:48:10 - [] ----D C:\Users\Amaury\AppData\Roaming\Reallusion
O43 - CFD: 12/01/2011 - 14:04:11 - [] ----D C:\Users\Amaury\AppData\Roaming\Roxio
O43 - CFD: 15/01/2011 - 15:47:29 - [] ----D C:\Users\Amaury\AppData\Roaming\Roxio Burn
O43 - CFD: 11/05/2015 - 08:00:01 - [] ----D C:\Users\Amaury\AppData\Roaming\Skype
O43 - CFD: 19/06/2011 - 11:48:17 - [] ----D C:\Users\Amaury\AppData\Roaming\skypePM
O43 - CFD: 05/05/2015 - 13:40:24 - [] ----D C:\Users\Amaury\AppData\Roaming\Spotify
O43 - CFD: 21/02/2011 - 12:15:29 - [] ----D C:\Users\Amaury\AppData\Roaming\WinRAR
O43 - CFD: 15/04/2014 - 08:27:51 - [] ----D C:\Users\Amaury\AppData\Roaming\XnView
O43 - CFD: 11/05/2015 - 11:08:46 - [] ----D C:\Users\Amaury\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 05/04/2015 - 11:25:56 - [0] ----D C:\Users\Amaury\AppData\Local\._LiveCode_
O43 - CFD: 28/02/2011 - 22:36:33 - [] ----D C:\Users\Amaury\AppData\Local\Adobe
O43 - CFD: 27/10/2012 - 13:10:04 - [] ----D C:\Users\Amaury\AppData\Local\Apple
O43 - CFD: 27/10/2012 - 13:11:31 - [] ----D C:\Users\Amaury\AppData\Local\Apple Computer
O43 - CFD: 12/01/2011 - 13:59:20 - [] -SH-D C:\Users\Amaury\AppData\Local\Application Data
O43 - CFD: 02/01/2014 - 16:32:12 - [] ----D C:\Users\Amaury\AppData\Local\Apps
O43 - CFD: 12/01/2011 - 14:04:08 - [] ----D C:\Users\Amaury\AppData\Local\Broadcom
O43 - CFD: 09/04/2013 - 08:24:41 - [] ----D C:\Users\Amaury\AppData\Local\Citrix
O43 - CFD: 17/01/2012 - 16:46:31 - [] ----D C:\Users\Amaury\AppData\Local\Cyberlink
O43 - CFD: 02/01/2014 - 18:29:19 - [0] ----D C:\Users\Amaury\AppData\Local\Deployment
O43 - CFD: 12/01/2011 - 14:04:02 - [] ----D C:\Users\Amaury\AppData\Local\DigitalPersona
O43 - CFD: 19/11/2014 - 21:12:56 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieBrowserModeList
O43 - CFD: 17/04/2014 - 18:45:42 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieSiteList
O43 - CFD: 17/04/2014 - 18:45:42 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieUserList
O43 - CFD: 01/02/2015 - 16:39:39 - [] ----D C:\Users\Amaury\AppData\Local\ESRI
O43 - CFD: 10/12/2011 - 20:55:23 - [] ----D C:\Users\Amaury\AppData\Local\Google
O43 - CFD: 12/01/2011 - 13:59:20 - [] -SH-D C:\Users\Amaury\AppData\Local\Historique
O43 - CFD: 24/06/2012 - 09:00:00 - [] ----D C:\Users\Amaury\AppData\Local\Macromedia
O43 - CFD: 06/05/2015 - 16:15:23 - [] ----D C:\Users\Amaury\AppData\Local\Microsoft
O43 - CFD: 12/02/2011 - 20:35:39 - [] ----D C:\Users\Amaury\AppData\Local\Microsoft Games
O43 - CFD: 13/03/2011 - 22:36:40 - [0] ----D C:\Users\Amaury\AppData\Local\Microsoft Help
O43 - CFD: 19/09/2013 - 21:20:36 - [] ----D C:\Users\Amaury\AppData\Local\Mozilla
O43 - CFD: 10/12/2011 - 16:51:20 - [0] ----D C:\Users\Amaury\AppData\Local\pcnrqyro
O43 - CFD: 11/01/2013 - 12:01:16 - [] ----D C:\Users\Amaury\AppData\Local\Programs
O43 - CFD: 27/02/2014 - 10:59:08 - [] ----D C:\Users\Amaury\AppData\Local\Skype
O43 - CFD: 05/05/2015 - 13:40:25 - [] ----D C:\Users\Amaury\AppData\Local\Spotify
O43 - CFD: 11/05/2015 - 11:07:54 - [] ----D C:\Users\Amaury\AppData\Local\Temp
O43 - CFD: 12/01/2011 - 13:59:20 - [] -SH-D C:\Users\Amaury\AppData\Local\Temporary Internet Files
O43 - CFD: 12/01/2011 - 13:59:21 - [0] ----D C:\Users\Amaury\AppData\Local\VirtualStore
O43 - CFD: 08/06/2012 - 20:12:30 - [] ----D C:\Users\Amaury\AppData\Local\Western Digital
O43 - CFD: 14/07/2009 - 06:42:04 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 12/03/2015 - 07:43:42 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 05/10/2011 - 21:15:20 - [0] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antidote
O43 - CFD: 14/07/2009 - 06:37:42 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 10/02/2012 - 09:38:05 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft ICE
O43 - CFD: 06/01/2014 - 14:08:21 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Périphériques Bluetooth
O43 - CFD: 05/02/2011 - 11:29:22 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Satsuki Decoder Pack
O43 - CFD: 12/03/2015 - 07:43:42 - [] R---D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 25/03/2011 - 22:12:44 - [] ----D C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TuxGuitar 1.2
~ Program Folder: 255 Scanned in 00mn 00s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.C16DFA9241F3CE8867E7EA8806B8F5DD] - 08/05/2015 - 08:31:05 ---A- . (...) -- C:\Windows\Antidote.ini [143]
O44 - LFC:[MD5.3C21F7E95FFCA33EF1A83AA33D9663CF] - 08/05/2015 - 11:01:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23256]
O44 - LFC:[MD5.155BF99B2B87E0C298CAC3B4B8136D83] - 08/05/2015 - 11:01:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [92888]
O44 - LFC:[MD5.167BCE00050B19DA25065335645A3C7A] - 08/05/2015 - 11:01:58 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [51928]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 08/05/2015 - 16:21:07 ---A- . (...) -- C:\Windows\setuperr.log [0]
O44 - LFC:[MD5.6B12A07D3C6AFD4A3219AF5FDE01DAFB] - 09/05/2015 - 07:11:51 ---A- . (...) -- C:\Windows\PFRO.log [2746]
O44 - LFC:[MD5.C489D8B4D8C64F20CC75A93F541F7D91] - 10/05/2015 - 09:32:24 ---A- . (.Microsoft Corporation - Exécuteur de file d'attente d'opérations pr.) -- C:\Windows\System32\poqexec.exe [123904]
O44 - LFC:[MD5.744AB3C1A73A57DEED49D631F1BDEA1D] - 10/05/2015 - 09:33:12 ---A- . (.Microsoft Corporation - Extension de l'environnement des appareils.) -- C:\Windows\System32\wpdshext.dll [2311168]
O44 - LFC:[MD5.F7F135F7702E0FB3EFE89283E2BE2EBB] - 10/05/2015 - 09:34:20 ---A- . (.Microsoft Corporation - API du Gestionnaire de fenêtres du Bureau M.) -- C:\Windows\System32\dwmapi.dll [67584]
O44 - LFC:[MD5.B01B8C949EDEC1B8A856E3056BDA7C42] - 10/05/2015 - 09:34:20 ---A- . (.Microsoft Corporation - Bibliothèque principale du Gestionnaire de.) -- C:\Windows\System32\dwmcore.dll [1372160]
O44 - LFC:[MD5.A5FE03D57097A45B8E7A4A09C9B78695] - 10/05/2015 - 09:38:35 ---A- . (.Microsoft Corporation - Client ActiveX des services Bureau à distan.) -- C:\Windows\System32\mstscax.dll [5698048]
O44 - LFC:[MD5.4676AAA9DDF52A50C829FEDB4EA81E54] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Connexion Bureau à distance.) -- C:\Windows\System32\mstsc.exe [1068544]
O44 - LFC:[MD5.AF40D823F3B03C7899AEF2293F84D0D7] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Proxy.) -- C:\Windows\System32\TSWbPrxy.exe [76288]
O44 - LFC:[MD5.5E676B296B762E211D83B87635F2C330] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Remote Desktop Services Client for Microsof.) -- C:\Windows\System32\rdvidcrl.dll [855552]
O44 - LFC:[MD5.0FC6922517964E9D90DE84DC86F63E40] - 10/05/2015 - 09:38:36 ---A- . (.Microsoft Corporation - Runtime de connexion RemoteApp et Bureau à.) -- C:\Windows\System32\wksprt.exe [350208]
O44 - LFC:[MD5.8DEEE20D8D30E9B0FBDCA31E58A027BD] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - Client de contrainte de quarantaine de la p.) -- C:\Windows\System32\tsgqec.dll [53248]
O44 - LFC:[MD5.A90F47CDCC0898733596B5070039FC15] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - Extension de stratégie de groupe pour la re.) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll [14336]
O44 - LFC:[MD5.2EFB1279E7BEA7D12D9F4D6508D27880] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Acces.) -- C:\Windows\System32\MsRdpWebAccess.dll [50176]
O44 - LFC:[MD5.AB5EFB103DB01C1912C9D2F545EA5621] - 10/05/2015 - 09:38:37 ---A- . (.Microsoft Corporation - WorkspaceRuntime ProxyStub DLL.) -- C:\Windows\System32\wksprtPS.dll [17920]
O44 - LFC:[MD5.C6A5FBD4977305E1FA23E02C042DB463] - 10/05/2015 - 09:38:38 ---A- . (.Microsoft Corporation - Pilote de filtre pour concentrateur USB du.) -- C:\Windows\System32\Drivers\TsUsbFlt.sys [49152]
O44 - LFC:[MD5.D60E27D4BD5A91FCD17D2CB27F86738E] - 10/05/2015 - 09:38:38 ---A- . (.Microsoft Corporation - Remote Desktop USB Redirection GP Extension.) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe [12800]
O44 - LFC:[MD5.F37167FCDB661FD4B54CAD4755ABDD61] - 10/05/2015 - 09:38:40 ---A- . (.Microsoft Corporation - Co-installateur de pilote USB générique du.) -- C:\Windows\System32\TsUsbGDCoInstaller.dll [32256]
O44 - LFC:[MD5.4FBED1107021D7405721CE55975F2C96] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1677370]
O44 - LFC:[MD5.5C81CFC2FA1D69A7B165951D1051F889] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfc009.dat [123196]
O44 - LFC:[MD5.46261007C0E5F58CB875F4AF71763ADB] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [151280]
O44 - LFC:[MD5.1034469ABB736466148909A6EE82C0C8] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfh009.dat [657384]
O44 - LFC:[MD5.2EE8285A8B6D443F9003E8531357C0C8] - 10/05/2015 - 12:03:40 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [750666]
O44 - LFC:[MD5.BA63FDF7785E75B60B3D958D4B381DB3] - 10/05/2015 - 16:44:33 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [2448648]
O44 - LFC:[MD5.FD7E6F9DCCD7FEEBDD6E8D3F14AD24F8] - 11/05/2015 - 07:02:32 ---A- . (...) -- C:\Windows\setupact.log [392]
O44 - LFC:[MD5.04B309A1A653177994630C2773E659F1] - 11/05/2015 - 07:03:37 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [119512]
O44 - LFC:[MD5.6446B430C5715E693545FC52D2746D3D] - 11/05/2015 - 07:11:15 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512]
O44 - LFC:[MD5.7FB275E0AF83B9ED8CC13F643D8DEE2A] - 11/05/2015 - 09:34:21 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.44EE7EE0EF748B16713C475E20D644AA] - 11/05/2015 - 10:03:02 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1304901]
O44 - LFC:[MD5.47DE8B7A482D4BABBCC70C0199E35881] - 27/04/2015 - 19:00:30 ---A- . (.Microsoft Corporation - Microsoft Windows Diagnostics Tracking.) -- C:\Windows\System32\UtcResources.dll [36864]
O44 - LFC:[MD5.86B2AC15999BB4F8B5C84AB6154A1783] - 27/04/2015 - 19:59:36 ---A- . (.Microsoft Corporation - DLL du schéma d'audit de sécurité.) -- C:\Windows\System32\adtschema.dll [686080]
O44 - LFC:[MD5.9638DA21E965E23C85C4319F3F66D824] - 27/04/2015 - 19:59:41 ---A- . (.Microsoft Corporation - ApiSet Schema DLL.) -- C:\Windows\System32\apisetschema.dll [6656]
O44 - LFC:[MD5.D079A408CC3E22A09D1260A6F18FC0FD] - 27/04/2015 - 20:01:22 ---A- . (.Microsoft Corporation - DLL des événements d'audit de la sécurité.) -- C:\Windows\System32\msaudite.dll [146432]
O44 - LFC:[MD5.BF9BB4113E9FCDABD4C703DDD06293F3] - 27/04/2015 - 20:01:33 ---A- . (.Microsoft Corporation - Nom d'audit des objets système.) -- C:\Windows\System32\msobjs.dll [60416]
O44 - LFC:[MD5.AFFE5747054D03F8CEE18A8518A9AA34] - 27/04/2015 - 20:03:52 ---A- . (.Microsoft Corporation - Programme de stratégie d'audit.) -- C:\Windows\System32\auditpol.exe [50176]
O44 - LFC:[MD5.F286528898342F0F1EB402606750C391] - 27/04/2015 - 20:03:58 ---A- . (.Microsoft Corporation - Utilitaire de configuration des performance.) -- C:\Windows\System32\diskperf.exe [17408]
O44 - LFC:[MD5.C6D2D384B6232B0B800234C03C50979F] - 27/04/2015 - 20:04:04 ---A- . (.Microsoft Corporation - Utilitaire d'enregistrement des Performance.) -- C:\Windows\System32\logman.exe [82944]
O44 - LFC:[MD5.1667D76FBF42B24B9DE3E8B0A7CF06BE] - 27/04/2015 - 20:04:05 ---A- . (.Microsoft Corporation - Local Security Authority Process.) -- C:\Windows\System32\lsass.exe [22528]
O44 - LFC:[MD5.97B30711DC6CA0EA4EACEDCE8080A3B4] - 27/04/2015 - 20:04:12 ---A- . (.Microsoft Corporation - Utilitaire de réenregistrement de Performan.) -- C:\Windows\System32\relog.exe [37888]
O44 - LFC:[MD5.7E9A03C1B76CB8A222C9AB232B3118D9] - 27/04/2015 - 20:04:14 ---A- . (.Microsoft Corporation - Restauration du système de Microsoft® Windo.) -- C:\Windows\System32\rstrui.exe [262656]
O44 - LFC:[MD5.03CD13A169C19558F637C2F36B974BDA] - 27/04/2015 - 20:04:21 ---A- . (.Microsoft Corporation - Gestionnaire de sessions Windows.) -- C:\Windows\System32\smss.exe [69632]
O44 - LFC:[MD5.74C0EC1257698176E288DA282F318E1C] - 27/04/2015 - 20:04:24 ---A- . (.Microsoft Corporation - Moniteur de performance de la ligne de comm.) -- C:\Windows\System32\typeperf.exe [40448]
O44 - LFC:[MD5.EB058143B57ED460AC4F2DFBA104BBFF] - 27/04/2015 - 20:04:24 ---A- . (.Microsoft Corporation - Outil de rapport de suivi d'événements.) -- C:\Windows\System32\tracerpt.exe [364544]
O44 - LFC:[MD5.7A5824DC9A85FCE4334F57FF0795853E] - 27/04/2015 - 20:04:33 ---A- . (.Microsoft Corporation - API avancées Windows 32.) -- C:\Windows\System32\advapi32.dll [641536]
O44 - LFC:[MD5.79AF005633B7E41B7A194A7E7B9D3D93] - 27/04/2015 - 20:04:37 ---A- . (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll [17408]
O44 - LFC:[MD5.5DCF39695CD614B162330F5AC27C4654] - 27/04/2015 - 20:04:37 ---A- . (.Microsoft Corporation - Processus d'exécution client-serveur.) -- C:\Windows\System32\csrsrv.dll [38912]
O44 - LFC:[MD5.54A01CC4BC47B31C5CD082D064AB37BC] - 27/04/2015 - 20:04:45 ---A- . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll [550912]
O44 - LFC:[MD5.D362BFE84A44A442CB6B8CBFE6DE027D] - 27/04/2015 - 20:04:47 ---A- . (.Microsoft Corporation - DLL serveur LSA.) -- C:\Windows\System32\lsasrv.dll [1061376]
O44 - LFC:[MD5.66D6A06936088E412E29A182679F0D71] - 27/04/2015 - 20:05:11 ---A- . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll [259584]
O44 - LFC:[MD5.0B6E937863837BA3383E9CE9200DDF1E] - 27/04/2015 - 20:05:17 ---A- . (.Microsoft Corporation - Bibliothèque de chiffrement Windows.) -- C:\Windows\System32\ncrypt.dll [221184]
O44 - LFC:[MD5.C34E0F9846D0FF902CED82DB5AB104BA] - 27/04/2015 - 20:05:28 ---A- . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll [248832]
O44 - LFC:[MD5.8C45A65ED20B487085B79EEFCC08D160] - 27/04/2015 - 20:05:29 ---A- . (.Microsoft Corporation - Host for SCM/SDDL/LSA Lookup APIs.) -- C:\Windows\System32\sechost.dll [92160]
O44 - LFC:[MD5.99A508910BB06DFBE99D9AF7D6B4E950] - 27/04/2015 - 20:05:29 ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\secur32.dll [22016]
O44 - LFC:[MD5.7CC0547B9FD90649731E021DA2763086] - 27/04/2015 - 20:05:32 ---A- . (.Microsoft Corporation - Bibliothèque principale de Restauration du.) -- C:\Windows\System32\srcore.dll [400896]
O44 - LFC:[MD5.ABA025664F9F42C568B2C022AADCB18F] - 27/04/2015 - 20:05:32 ---A- . (.Microsoft Corporation - Microsoft® Windows System Restore Client Li.) -- C:\Windows\System32\srclient.dll [43008]
O44 - LFC:[MD5.ECB7366ED80E349436FC495A77EAF24C] - 27/04/2015 - 20:05:33 ---A- . (.Microsoft Corporation - LSA SSPI RPC interface DLL.) -- C:\Windows\System32\sspisrv.dll [15872]
O44 - LFC:[MD5.6C427298E65C1430D232A0529ED9B18E] - 27/04/2015 - 20:05:33 ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\sspicli.dll [100352]
O44 - LFC:[MD5.D0F574320615303ADECDCB452EBB8930] - 27/04/2015 - 20:05:34 ---A- . (.Microsoft Corporation - Bibliothèque de l'application auxiliaire de.) -- C:\Windows\System32\tdh.dll [635392]
O44 - LFC:[MD5.FCB1C8345C794FE89ABA03B4CA3131BB] - 27/04/2015 - 20:05:35 ---A- . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\TSpkg.dll [65536]
O44 - LFC:[MD5.E95DE5B790B2D16706DAC8472E51F31A] - 27/04/2015 - 20:05:39 ---A- . (.Microsoft Corporation - Microsoft Windows Diagnostics Tracking.) -- C:\Windows\System32\diagtrack.dll [851456]
O44 - LFC:[MD5.850F756363237A2EB069B9B25EF8BEC3] - 27/04/2015 - 20:05:40 ---A- . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll [172032]
O44 - LFC:[MD5.7410C9F088E4F13C981F981B52475B5E] - 27/04/2015 - 20:08:02 ---A- . (.Microsoft Corporation - DLL Couche NT.) -- C:\Windows\System32\ntdll.dll [1307648]
O44 - LFC:[MD5.6DD2A1064DD8AFBED22E71176E2AF59B] - 27/04/2015 - 20:11:53 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecdd.sys [67520]
O44 - LFC:[MD5.76C0D35167B1369C68388FEDB56A3048] - 27/04/2015 - 20:11:53 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecpkg.sys [137664]
O44 - LFC:[MD5.8D50ED3F0FBE3590AB0D43BF7B60E57A] - 27/04/2015 - 20:11:54 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntkrnlpa.exe [3989440]
O44 - LFC:[MD5.0A66C88B087249742381924AB8F9EFCC] - 27/04/2015 - 20:11:55 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntoskrnl.exe [3934144]
~ Files: 70 Scanned in 00mn 03s
---\\ Déni du service (Local Security Authority) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l'Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Notification Packages . (.DigitalPersona, Inc. - DPPwdFlt Module.) -- C:\Windows\System32\DPPWDFLT.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corp. - LiveSSP.) -- C:\Windows\System32\livessp.dll
~ LSA: 10 Scanned in 00mn 00s
---\\ Contrôle du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d'extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d'extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
~ CSB: 13 Scanned in 00mn 00s
---\\ Clé de registre Shell MountPoints2 (MPSK) (O51)
O51 - MPSK:{30236676-b194-11e1-8151-f04da2c023f1}\AutoRun\command. (...) -- E:\unlock.exe (.not file.)
O51 - MPSK:{74702b01-b586-11e3-ba34-f04da2c023f1}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)
O51 - MPSK:{d22ae3b2-20ad-11e0-a6a7-f04da2c023f1}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)
~ Keys: Scanned in 00mn 00s
---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll
O52 - TDSD: \Drivers32\"vidc.XVID"="xvidvfw.dll" . (...) -- C:\Windows\System32\xvidvfw.dll
O52 - TDSD: \Drivers32\"vidc.ffds"="ff_vfw.dll" . (...) -- C:\Windows\System32\ff_vfw.dll
O52 - TDSD: \Drivers32\"msacm.vorbis"="vorbis.acm" . (.HMS http://hp.vector.co.jp/authors/VA012897 - Ogg Vorbis CODEC for MSACM.) -- C:\Windows\System32\vorbis.acm
O52 - TDSD: \Drivers32\"vidc.iv50"="ir50_32.dll" . (.Intel Corporation - Intel Indeo® video 5.10.) -- C:\Windows\System32\ir50_32.dll
O52 - TDSD: \Drivers32\"vidc.iv41"="ir41_32.ax" . (.Intel Corporation - Intel Indeo® Video 4.5.) -- C:\Windows\System32\ir41_32.ax
O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (.Intel(R) Corporation - Pas de description.) -- C:\Windows\System32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (.Intel(R) Corporation - Pas de description.) -- C:\Windows\System32\ir32_32.dll
O52 - TDSD: \Drivers32\"msacm.iac2"="C:\Windows\system32\iac25_32.ax" . (.Intel Corporation - Indeo® audio software.) -- C:\Windows\system32\iac25_32.ax
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"xvidvfw.dll"="Xvid MPEG-4 Video Codec" . (...) -- C:\Windows\System32\xvidvfw.dll
O52 - TDSD: \drivers.desc\"vorbis.acm"="Ogg Vorbis Audio CODEC, Based on Xiphophorus libVorbis I 20010910" . (.HMS http://hp.vector.co.jp/authors/VA012897 - Ogg Vorbis CODEC for MSACM.) -- C:\Windows\System32\vorbis.acm
O52 - TDSD: \drivers.desc\"C:\Windows\system32\iac25_32.ax"="Indeo® audio software" . (.Intel Corporation - Indeo® audio software.) -- C:\Windows\system32\iac25_32.ax
~ TDSD: 14 Scanned in 00mn 00s
---\\ Enumération des clés de registre StartupReg (SMSR) (O53)
O53 - SMSR:HKLM\...\startupreg\AdobeBridge [Key] . (.Adobe Systems, Inc. - Adobe Bridge.) -- C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe =>.Adobe Systems Incorporated
O53 - SMSR:HKLM\...\startupreg\APSDaemon [Key] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
O53 - SMSR:HKLM\...\startupreg\CCleaner Monitoring [Key] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
O53 - SMSR:HKLM\...\startupreg\iTunesHelper [Key] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
O53 - SMSR:HKLM\...\startupreg\Skype [Key] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O53 - SMSR:HKLM\...\startupreg\Spotify Web Helper [Key] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe
~ SMSR Keys: 6 Scanned in 00mn 00s
---\\ Enumération des clés de registre SecurityProviders (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
~ MSCP: 2 Scanned in 00mn 00s
---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=0
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Scanned in 00mn 00s
---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145
~ MWPE Keys: 1 Scanned in 00mn 00s
---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:03/12/2009 - 07:24:38 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\System32\Drivers\Acceler.sys [41648]
O58 - SDL:29/09/2010 - 17:38:00 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\System32\Drivers\Accelern.sys [43888]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976]
O58 - SDL:14/07/2009 - 02:26:17 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [297552]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\Drivers\adpu320.sys [146512]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [14400]
O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [80256]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows fa.) -- C:\Windows\System32\Drivers\amdsbs.sys [159312]
O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [22400]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [76368]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [86608]
O58 - SDL:15/07/2011 - 16:11:46 ---A- . (.BitDefender - BitDefender AntiVirus Active Virus Control Hypervisor driver.) -- C:\Windows\System32\Drivers\avchv.sys [240184]
O58 - SDL:01/09/2011 - 11:15:08 ---A- . (.BitDefender - Active Virus Control Kernel Filtering driver.) -- C:\Windows\System32\Drivers\avckf.sys [454960]
O58 - SDL:13/07/2009 - 23:02:49 ---A- . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gigabit Ethernet..) -- C:\Windows\System32\Drivers\b57nd60x.sys [229888]
O58 - SDL:07/01/2011 - 13:47:17 ---A- . (.Broadcom Corporation - Broadcom iLine10(tm) PCI Network Adapter Proxy Protocol Driver.) -- C:\Windows\System32\Drivers\bcm42rly.sys [18424]
O58 - SDL:05/05/2010 - 20:28:38 ---A- . (.Broadcom Corporation - Broadcom 802.11 Network Adapter wireless driver.) -- C:\Windows\System32\Drivers\BCMWL6.SYS [2707448]
O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [13568]
O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [5248]
O58 - SDL:14/07/2009 - 01:57:25 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [272128]
O58 - SDL:13/07/2009 - 23:53:32 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [62336]
O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [12160]
O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [11904]
O58 - SDL:03/10/2009 - 06:24:12 ---A- . (.Broadcom Corporation. - Bluetooth Audio Device.) -- C:\Windows\System32\Drivers\btwaudio.sys [86056]
O58 - SDL:29/08/2009 - 03:15:16 ---A- . (.Broadcom Corporation. - Broadcom Bluetooth AVDT Service.) -- C:\Windows\System32\Drivers\btwavdt.sys [108072]
O58 - SDL:07/04/2009 - 23:32:50 ---A- . (.Broadcom Corporation. - Broadcom Bluetooth L2CAP Service.) -- C:\Windows\System32\Drivers\btwl2cap.sys [29472]
O58 - SDL:29/08/2009 - 03:15:12 ---A- . (.Broadcom Corporation. - Bluetooth Remote Control HID Minidriver.) -- C:\Windows\System32\Drivers\btwrchid.sys [18472]
O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbdx.sys [430080]
O58 - SDL:20/10/2009 - 10:00:00 ---A- . (.Sonic Solutions - CDR4 CD and DVD Place Holder Driver (see PxHelp).) -- C:\Windows\System32\Drivers\cdr4_xp.sys [9072]
O58 - SDL:20/10/2009 - 10:00:00 ---A- . (.Sonic Solutions - CDRAL Place Holder Driver (see PxHelp).) -- C:\Windows\System32\Drivers\cdralw2k.sys [9200]
O58 - SDL:14/07/2009 - 02:26:21 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [15952]
O58 - SDL:28/05/2009 - 17:48:20 ---A- . (.Creative Technology Ltd. - Advanced Audio FX Driver.) -- C:\Windows\System32\Drivers\CtAudDrv.sys [134144]
O58 - SDL:12/08/2010 - 17:50:20 ---A- . (.Creative Technology Ltd. - Video Class Upper Filter Driver.) -- C:\Windows\System32\Drivers\CtClsFlt.sys [146528]
O58 - SDL:30/01/2015 - 23:36:11 ---A- . (.Dell Computer Corporation - DDDriver.sys.) -- C:\Windows\System32\Drivers\DDDriver32Dcsa.sys [20688]
O58 - SDL:30/01/2015 - 23:36:11 ---A- . (.Dell Computer Corporation - DellProf.sys.) -- C:\Windows\System32\Drivers\DellProf.sys [19984]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\Drivers\djsvs.sys [70720]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712]
O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbdx.sys [3100160]
O58 - SDL:21/08/2012 - 12:01:22 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys [26840]
O58 - SDL:13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624]
O58 - SDL:17/09/2009 - 21:54:14 ---A- . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\Drivers\HECI.sys [41088]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [67152]
O58 - SDL:04/03/2010 - 19:33:26 ---A- . (.Intel Corporation - Intel Rapid Storage Technology driver - x86.) -- C:\Windows\System32\Drivers\iaStor.sys [435736]
O58 - SDL:11/03/2011 - 06:38:51 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332160]
O58 - SDL:26/08/2010 - 12:31:30 ---A- . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\Drivers\igdkmd32.sys [9024512]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [41040]
O58 - SDL:27/02/2010 - 16:31:24 ---A- . (.Intel Corporation - Intel(R) Turbo Boost Technology Driver.) -- C:\Windows\System32\Drivers\Impcd.sys [132480]
O58 - SDL:31/08/2010 - 04:15:56 ---A- . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\Drivers\IntcDAud.sys [247808]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [95824]
O58 - SDL:14/07/2009 - 02:20:37 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [89168]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [54864]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [96848]
O58 - SDL:14/04/2015 - 08:37:42 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23256]
O58 - SDL:14/04/2015 - 08:37:44 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [92888]
O58 - SDL:11/05/2015 - 07:03:37 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [119512]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7 for x86.) -- C:\Windows\System32\Drivers\megasas.sys [30800]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [235584]
O58 - SDL:14/04/2015 - 08:37:54 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [51928]
O58 - SDL:14/07/2009 - 02:20:44 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [44624]
O58 - SDL:07/01/2011 - 13:47:18 ---A- . (.CACE Technologies, Inc. - npf.sys (NT5/6 x86) Kernel Driver.) -- C:\Windows\System32\Drivers\npf.sys [50704]
O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117120]
O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [143744]
O58 - SDL:19/03/2010 - 10:00:00 ---A- . (.Sonic Solutions - Px Engine Device Driver for Windows 2000/XP.) -- C:\Windows\System32\Drivers\pxhelp20.sys [45648]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1383488]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [106064]
O58 - SDL:10/06/2011 - 05:34:52 ---A- . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.20 32-bit Driver.) -- C:\Windows\System32\Drivers\Rt86win7.sys [394856]
O58 - SDL:10/08/2009 - 20:06:08 ---A- . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/Vista/Win7.) -- C:\Windows\System32\Drivers\RtsUStor.sys [171520]
O58 - SDL:13/07/2009 - 21:50:20 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [20480]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [40016]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [77888]
O58 - SDL:20/08/2010 - 18:04:38 ---A- . (.ST Microelectronics - Disk Class Filter Driver for Accelerometer.) -- C:\Windows\System32\Drivers\stdcfltn.sys [17648]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072]
O58 - SDL:07/04/2010 - 13:35:04 ---A- . (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\Drivers\stwrt.sys [423936]
O58 - SDL:08/01/2010 - 05:46:20 ---A- . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\Windows\System32\Drivers\SynTP.sys [232624]
O58 - SDL:14/07/2009 - 02:19:10 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [16976]
O58 - SDL:14/07/2009 - 02:19:11 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [141904]
O58 - SDL:13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672]
~ Drivers: 90 Scanned in 00mn 03s
---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\ffmpegsumo.dll [990776]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\libEGL.dll [219192]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\libGLESv2.dll [1365560]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\libcef.dll [40518200]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Spotify\wow_helper.exe [73272]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (.Microsoft Corporation.) -- C:\Users\Amaury\AppData\Roaming\Spotify\d3dcompiler_43.dll [2106424]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (.Microsoft Corporation.) -- C:\Users\Amaury\AppData\Roaming\Spotify\d3dcompiler_47.dll [3457592]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\Spotify.exe [7168568]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyCrashService.exe [778808]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyLauncher.exe [124472]
O61 - LFC: 05/05/2015 - 11:09:07 ---A- . (.Spotify Ltd.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920]
O61 - LFC: 08/05/2015 - 11:09:05 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\Adobe\Acrobat\9.0\UserCache.bin [106533]
O61 - LFC: 08/05/2015 - 11:09:07 ---A- . (...) -- C:\Users\Amaury\AppData\Roaming\ZHP\ZHPCleaner.exe [1818624] =>.Nicolas Coolman
O61 - LFC: 08/05/2015 - 11:09:08 ---A- . (...) -- C:\Users\Amaury\Downloads\adwcleaner_4.203.exe [2204160]
O61 - LFC: 09/05/2015 - 11:09:08 ---A- . (...) -- C:\Users\Amaury\Downloads\ZHPCleaner(1).exe [1820160] =>.Nicolas Coolman
O61 - LFC: 11/05/2015 - 11:09:08 ---A- . (.Nicolas Coolman.) -- C:\Users\Amaury\Downloads\ZHPDiag2.exe [6880396] =>.Nicolas Coolman
~ 155 Fichiers temporaires (Temporary files)
~ 5 Fichiers cookies (Cookies files)
~ Files: 16 Scanned in 00mn 09s
---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s
---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - 07/01/2011 - C:\Windows\System32\drivers\BCM42RLY.sys (BCM42RLY) .(.Broadcom Corporation - Broadcom iLine10(tm) PCI Network Adapter Pr.) - LEGACY_BCM42RLY
O64 - Services: CurCS - 28/01/1746 - C:\Users\Amaury\AppData\Local\Temp\mbr.sys (mbr) .(...) - LEGACY_MBR
O64 - Services: CurCS - 13/07/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV
~ Legacy: 119 Scanned in 00mn 00s
---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d'événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
~ FASS Keys: 10 Scanned in 00mn 00s
---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s
---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s
---\\ Enumère les fichiers Crack & Keygen (CKF) (O82)
C:\Users\Amaury\Desktop\Adobe CS4\Master Collection\Adobe CS4\Adobe_Master_Collection_CS4_Keygen_by_Milkman.zip =>.Crack,Keygen
C:\Users\Amaury\Desktop\EndNote X6 Bld 6348\Cracked\EndNote.exe =>.Crack,Keygen
C:\Users\Amaury\Desktop\Adobe CS4\Master Collection\Adobe CS4\Adobe_Master_Collection_CS4_Keygen_by_Milkman.zip =>.Crack,Keygen
C:\Users\Amaury\Desktop\EndNote X6 Bld 6348\Cracked\EndNote.exe =>.Crack,Keygen
~ Files: Scanned in 00mn 49s
---\\ Enumère les service demarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d'application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [475136]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d'accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d'interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d'événements système (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [523776]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2020864]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData
---\\ Enumère les service demarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d'application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [475136]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d'accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d'interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d'événements système (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [523776]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2020864]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d'application.) -- C:\Windows\System32\appinfo.dll [47104]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [49664]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164864]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [71168]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [113664]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d'ordinateurs.) -- C:\Windows\System32\browser.dll [102912]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800]
~ Services: 32 Scanned in 00mn 00s
---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.825768E0D92DAD41A59BF0D16FB76F40] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.1520.bin [4248]
[MD5.946CF417E94D2C9A873D14E6FE0415A1] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2120.bin [70375]
[MD5.6236D6B734152B266EBAB93CF24E5830] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2532.bin [1698]
[MD5.5BC0BA4A5185D7B285B5F8EBE4FCB0FA] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2748.bin [456927]
[MD5.18BC0B6609141E87DE09F4C7DEA97547] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.3716.bin [4259]
[MD5.D9A90DDEBEC281317E31AAEC06FEBD48] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4140.bin [1670]
[MD5.453B258E97C86572BE40C8E28C8CB637] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4464.bin [1260]
[MD5.3F5C7469DC6A45255FA5723B270DFB56] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4664.bin [21151]
[MD5.C6E5D0B9966A3707497421164BAA017C] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4676.bin [70625]
[MD5.5999CF6DDDD5FF5F62A7DA285C5FFF3A] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4696.bin [9108]
[MD5.FAE27419C38CC9DE62F607B0FD4458D6] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.bdinstall.bin [73728]
[MD5.B76FA9566970A7E5255B0717C35B5EC9] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539329.bdinstall.bin [80408]
[MD5.33FE59A381CCF8297F7F8C38FF954D41] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539409.bdinstall.bin [90911]
~ Files: 13 Scanned in 00mn 00s
---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab
~ BCK: 18538 Scanned in 00mn 40s
---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 15/04/2015 268464 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 23/09/2013 1044816 | (FLEXnet Licensing Service) . (.Flexera Software, Inc..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Auto 22/10/2014 107912 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 22/10/2014 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 15/05/2013 553288 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SS - | Auto 14/04/2015 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
SS - | Auto 14/04/2015 1080120 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
SS - | Demand 24/04/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 04/09/2010 1116656 | (RoxMediaDB12OEM) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
SS - | Auto 04/09/2010 219632 | (RoxWatch12) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
SS - | Auto 18/02/2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SS - | Demand 26/08/2010 74392 | (stllssvr) . (.MicroVision Development, Inc..) - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 03/03/2009 81920 | (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 20/10/2009 595232 | (btwdins) . (.Broadcom Corporation..) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
SR - | Auto 26/02/2015 1947344 | (DellDataVault) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
SR - | Auto 26/02/2015 184016 | (DellDataVaultWiz) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
SR - | Auto 13/05/2009 322624 | (DpHost) . (.DigitalPersona, Inc..) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
SR - | Auto 04/11/2009 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 30/01/2015 22184 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 07/04/2010 229458 | (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
SR - | Auto 10/04/2015 19288 | (SupportAssistAgent) . (.Dell Inc..) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
SR - | Auto 04/11/2009 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 03/06/2010 1664304 | (vcsFPService) . (.Validity Sensors, Inc..) - C:\Windows\system32\vcsFPService.exe
SR - | Auto 07/01/2011 40960 | (wltrysvc) . (.Dell Inc..) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 41s
---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Run by Amaury at 11/05/2015 11:10:54
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys stdcfltn.sys ACPI.sys halmacpi.dll iaStor.sys
C:\Windows\system32\DRIVERS\stdcfltn.sys ST Microelectronics Disk Class Filter Driver for Accelerometer
C:\Windows\system32\DRIVERS\iaStor.sys Intel Corporation Intel Rapid Storage Technology driver
1 ntkrnlpa!IofCallDriver[0x83671D29] >> \Device\Harddisk0\DR0[0x886826B0]
3 CLASSPNP[0x8BF9059E] >> ntkrnlpa!IofCallDriver[0x83671D29] >> [0x88682D68]
5 stdcfltn[0x8C1E7896] >> ntkrnlpa!IofCallDriver[0x83671D29] >> [0x86ABF8C8]
7 ACPI[0x8B82C3D4] >> ntkrnlpa!IofCallDriver[0x83671D29] >> \Device\Ide\IAAStorageDevice-1[0x86AE5028]
kernel: MBR read successfully
user & kernel MBR OK
~ MBR: 16 Scanned in 00mn 02s
---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by Amaury at 11/05/2015 11:10:56
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s
---\\ Scan Additionnel (O88)
Database Version : 13008 - (05/05/2015)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 41
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\7Zip Bundle by Fileparade.com] =>PUP.SweetIM^
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro^
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab^
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar^
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab^
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab^
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo^
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay^
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy^
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo^
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo^
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab^
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab^
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream^
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo^
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo^
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream^
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine^
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab^
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager^
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab^
~ Additionnel Scan: 670738 Items scanned in 02mn 21s
---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects de navigateur (O2)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
~ AMI: 5 Scanned in 00mn 00s
---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/pup-sweetim =>PUP.SweetIM
http://nicolascoolman.fr/pup-optimizerpro =>PUP.OptimizerPro
http://www.nicolascoolman.fr/blog/ =>PUP.Nosibay
http://nicolascoolman.fr/adware-onetab =>Adware.OneTab
http://nicolascoolman.fr/hijacker-findrtoolbar =>Hijacker.FindrToolbar
http://nicolascoolman.fr/hijacker-smartbar =>Hijacker.SmartBar
http://nicolascoolman.fr/pup-eorezo =>PUP.EoRezo
http://nicolascoolman.fr/pup-minibar =>PUP.Minibar
http://nicolascoolman.fr/hijacker-proxy =>Hijacker.Proxy
http://nicolascoolman.fr/adware-metastream =>Adware.MetaStream
http://nicolascoolman.fr/pup-softwareengine =>PUP.SoftwareEngine
http://nicolascoolman.fr/pup-manager =>PUP.Manager
~ MSI: 12 link(s) detected in 00mn 00s
End of the scan (1599 lines in 05mn 06s)(4.10)
---\\ Enumère les service demarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d'application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [475136]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d'accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d'interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d'événements système (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [523776]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2020864]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d'application.) -- C:\Windows\System32\appinfo.dll [47104]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [49664]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164864]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [71168]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [113664]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d'ordinateurs.) -- C:\Windows\System32\browser.dll [102912]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800]
~ Services: 32 Scanned in 00mn 00s
---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.825768E0D92DAD41A59BF0D16FB76F40] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.1520.bin [4248]
[MD5.946CF417E94D2C9A873D14E6FE0415A1] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2120.bin [70375]
[MD5.6236D6B734152B266EBAB93CF24E5830] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2532.bin [1698]
[MD5.5BC0BA4A5185D7B285B5F8EBE4FCB0FA] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2748.bin [456927]
[MD5.18BC0B6609141E87DE09F4C7DEA97547] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.3716.bin [4259]
[MD5.D9A90DDEBEC281317E31AAEC06FEBD48] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4140.bin [1670]
[MD5.453B258E97C86572BE40C8E28C8CB637] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4464.bin [1260]
[MD5.3F5C7469DC6A45255FA5723B270DFB56] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4664.bin [21151]
[MD5.C6E5D0B9966A3707497421164BAA017C] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4676.bin [70625]
[MD5.5999CF6DDDD5FF5F62A7DA285C5FFF3A] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4696.bin [9108]
[MD5.FAE27419C38CC9DE62F607B0FD4458D6] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.bdinstall.bin [73728]
[MD5.B76FA9566970A7E5255B0717C35B5EC9] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539329.bdinstall.bin [80408]
[MD5.33FE59A381CCF8297F7F8C38FF954D41] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539409.bdinstall.bin [90911]
~ Files: 13 Scanned in 00mn 00s
---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab
~ BCK: 18538 Scanned in 00mn 40s
---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 15/04/2015 268464 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 23/09/2013 1044816 | (FLEXnet Licensing Service) . (.Flexera Software, Inc..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Auto 22/10/2014 107912 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 22/10/2014 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 15/05/2013 553288 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SS - | Auto 14/04/2015 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
SS - | Auto 14/04/2015 1080120 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
SS - | Demand 24/04/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 04/09/2010 1116656 | (RoxMediaDB12OEM) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
SS - | Auto 04/09/2010 219632 | (RoxWatch12) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
SS - | Auto 18/02/2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SS - | Demand 26/08/2010 74392 | (stllssvr) . (.MicroVision Development, Inc..) - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 03/03/2009 81920 | (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 20/10/2009 595232 | (btwdins) . (.Broadcom Corporation..) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
SR - | Auto 26/02/2015 1947344 | (DellDataVault) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
SR - | Auto 26/02/2015 184016 | (DellDataVaultWiz) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
SR - | Auto 13/05/2009 322624 | (DpHost) . (.DigitalPersona, Inc..) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
SR - | Auto 04/11/2009 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 30/01/2015 22184 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 07/04/2010 229458 | (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
SR - | Auto 10/04/2015 19288 | (SupportAssistAgent) . (.Dell Inc..) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
SR - | Auto 04/11/2009 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 03/06/2010 1664304 | (vcsFPService) . (.Validity Sensors, Inc..) - C:\Windows\system32\vcsFPService.exe
SR - | Auto 07/01/2011 40960 | (wltrysvc) . (.Dell Inc..) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 41s
---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Run by Amaury at 11/05/2015 11:10:54
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys stdcfltn.sys ACPI.sys halmacpi.dll iaStor.sys
C:\Windows\system32\DRIVERS\stdcfltn.sys ST Microelectronics Disk Class Filter Driver for Accelerometer
C:\Windows\system32\DRIVERS\iaStor.sys Intel Corporation Intel Rapid Storage Technology driver
1 ntkrnlpa!IofCallDriver[0x83671D29] >> \Device\Harddisk0\DR0[0x886826B0]
3 CLASSPNP[0x8BF9059E] >> ntkrnlpa!IofCallDriver[0x83671D29] >> [0x88682D68]
5 stdcfltn[0x8C1E7896] >> ntkrnlpa!IofCallDriver[0x83671D29] >> [0x86ABF8C8]
7 ACPI[0x8B82C3D4] >> ntkrnlpa!IofCallDriver[0x83671D29] >> \Device\Ide\IAAStorageDevice-1[0x86AE5028]
kernel: MBR read successfully
user & kernel MBR OK
~ MBR: 16 Scanned in 00mn 02s
---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by Amaury at 11/05/2015 11:10:56
- Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s
---\\ Scan Additionnel (O88)
Database Version : 13008 - (05/05/2015)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 41
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\7Zip Bundle by Fileparade.com] =>PUP.SweetIM^
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro^
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab^
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar^
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab^
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab^
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo^
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay^
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy^
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo^
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo^
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab^
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab^
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream^
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo^
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo^
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream^
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine^
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab^
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager^
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab^
~ Additionnel Scan: 670738 Items scanned in 02mn 21s
---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects de navigateur (O2)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
~ AMI: 5 Scanned in 00mn 00s
---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/pup-sweetim =>PUP.SweetIM
http://nicolascoolman.fr/pup-optimizerpro =>PUP.OptimizerPro
http://www.nicolascoolman.fr/blog/ =>PUP.Nosibay
http://nicolascoolman.fr/adware-onetab =>Adware.OneTab
http://nicolascoolman.fr/hijacker-findrtoolbar =>Hijacker.FindrToolbar
http://nicolascoolman.fr/hijacker-smartbar =>Hijacker.SmartBar
http://nicolascoolman.fr/pup-eorezo =>PUP.EoRezo
http://nicolascoolman.fr/pup-minibar =>PUP.Minibar
http://nicolascoolman.fr/hijacker-proxy =>Hijacker.Proxy
http://nicolascoolman.fr/adware-metastream =>Adware.MetaStream
http://nicolascoolman.fr/pup-softwareengine =>PUP.SoftwareEngine
http://nicolascoolman.fr/pup-manager =>PUP.Manager
~ MSI: 12 link(s) detected in 00mn 00s
End of the scan (1599 lines in 05mn 06s)(4.10)
Je m'en suis rendu compte dans la matinée et mon message du 11 mai 2015 à 11:19 correspond à la dernière version 2015.5.8.47.
voilà
~ Rapport de ZHPDiag v2015.5.8.47 - Nicolas Coolman (05/05/2015)
~ Lancé par Amaury (12/05/2015 19:01:50)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Désactivée par l'utilisateur
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user
---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17728
MFIE: Mozilla Firefox 37.0.2 (Defaut)
---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows Operating System - Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : RMV82
Windows License : OK
~ Windows Remaining Initializations Number : 4
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 7 Home Premium, 32-bit Service Pack 1 (Build 7601)
---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 2.1.6.1022
Microsoft Security Client v4.7.0205.0
Windows Defender W7 (Deactivate)
---\\ Logiciels d'optimisation du système
CCleaner v5.05
---\\ Logiciels de partage PeerToPeer
---\\ Surveillance de Logiciels
Adobe Flash Player 17 NPAPI
Adobe Reader X
---\\ Informations sur le système
~ Processor: x86 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2998 MB (59% free)
System Restore: Activé (Enable)
System drive C: has 173 GB (60%) free of 287 GB
---\\ Mode de connexion au système
~ Computer Name: AMAURY-PC
~ User Name: Amaury
~ All Users Names: HomeGroupUser$, Amaury, Administrateur,
~ Unselected Option: None
Logged in as Administrator
---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Amaury\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Amaury\AppData\Roaming\
~ %Desktop% : C:\Users\Amaury\Desktop\
~ %Favorites% : C:\Users\Amaury\Favorites\
~ %LocalAppData% : C:\Users\Amaury\AppData\Local\
~ %StartMenu% : C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 173 Go of 287 Go)
D: CD-ROM drive (Not Inserted)
---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: 43 Scanned in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.C46904F2E9E121A91DDDABB48D7648C3] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.13/03/2015 - 03:20:28.) -- C:\Windows\System32\wininet.dll [1888256]
[MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.17/07/2014 - 02:39:27.) -- C:\Windows\System32\Winlogon.exe [304128]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 13:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:36:07.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 09:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 09:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 10:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 09:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:18:22.) -- C:\Windows\system32\Drivers\ntfs.sys [1212352]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:32:14.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 13:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Generic Processes: Scanned in 00mn 00s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/3
~ Mes musiques (My Musics) : 1/185
~ Mes Favoris (My Favorites) : 1/30
~ Mes Documents (My Documents) : 2/1045
~ Mon Bureau (My Desktop) : 15/82419
~ Menu demarrer (Programs) : 1/30
~ Hidden Files: Scanned in 01mn 12s
---\\ Processus lancés
[MD5.7E212E742BF06BF678AE35E9C1B74B8F] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe [6212920] [PID.3252]
[MD5.567B0B979E206C3E1E7B4422A2D0A5AD] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1602856] [PID.3888]
[MD5.A9D62C7793510D81342AC1AC50FB70F5] - (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe [495708] [PID.3976]
[MD5.C7AF01132A0DD241A1A0DBE9B62A9A1C] - (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\quickset.exe [3873648] [PID.4020]
[MD5.B7680F36C41AE21C0ECA96523443831F] - (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe [727664] [PID.2792]
[MD5.22001D1308E34153D2BCD51368E14F7B] - (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5249024] [PID.3260]
[MD5.2059A96CB2254829488A6A676AA4BA15] - (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\DpAgent.exe [842816] [PID.3660]
[MD5.0FE0EDF01CEA3BEB2E65A904BB87525E] - (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe [640376] [PID.3724]
[MD5.D50F04F005C94FA3802A6E05CFCF4A9A] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.3184]
[MD5.9A8568C7642B79F43DCEB0BDF9F49050] - (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe [542136] [PID.1196]
[MD5.CCA0C5482B8A6A275D9D49433F435DFA] - (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe [542096] [PID.3576]
[MD5.46B9C74861D98EDA9E6E56D19BEAF91A] - (.Broadcom Corporation. - Bluetooth Tray Application.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [795936] [PID.3588]
[MD5.254EC04C72D02E4C8EEC08D4CF3658B1] - (.PC-Doctor, Inc. - PC-Doctor Module.) -- C:\Program Files\Dell\SupportAssist\uaclauncher.exe [1189200] [PID.4676]
[MD5.207E54FC226446E2A218EDB400541D80] - (.Pas de propriétaire - CPU temperature and system information util.) -- C:\Users\Amaury\AppData\Local\Temp\Rar$EX36.168\Core Temp.exe [794272] [PID.4260]
[MD5.5D1BFF0FCE80F9E2E539F436710D4A79] - (.Microsoft Corporation - Preview Handler Surrogate Host.) -- C:\Windows\system32\prevhost.exe [31232] [PID.1652]
[MD5.2727208EA26F6B6DA898AB6890417214] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8208384] [PID.4332]
~ Processes Running: Scanned in 00mn 01s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Amaury\AppData\Local\Google\Chrome\User Data\Default\Preferences
---\\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 0 Scanned in 00mn 00s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFF12.DLL
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo-france.xml
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll =>.Google Inc
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=11.31.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Windows\system32\npdeployJava1.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Oracle Corporation - Next Generation Java Plug-in 11.31.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=11.31.2] - (.Oracle Corporation - Next Generation Java Plug-in 11.31.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) -- C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
~ Firefox Browser: 31 Scanned in 00mn 00s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) (No version) -- (.not file.)
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
~ IE Browser: 11 Scanned in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: DigitalPersona Fingerprint Software Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} . (.DigitalPersona, Inc. - DigitalPersona OTS Feedback.) -- C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} . (.Microsoft Corporation - Windows Live Messenger Companion Core.) -- C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
~ BHO: 14 Scanned in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Adobe PDF - [HKLM]{47833539-D0C5-4125-9FA8-0819E2EAAC93} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{47833539-D0C5-4125-9FA8-0819E2EAAC93} Clé orpheline
~ Toolbar: Scanned in 00mn 00s
---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [QuickSet] . (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [FreeFallProtection] . (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] . (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [DpAgent] . (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] . (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKCU\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
~ Application: Scanned in 00mn 00s
---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ IE Control Panel: 1 Scanned in 00mn 00s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} . (.Microsoft Corporation - Windows Live Messenger Companion core resources.) -- C:\Program Files\Windows Live\Companion\companionres.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- c:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000009\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000010\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll
~ Winsock: 10 Scanned in 00mn 00s
---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] *.dell.com
~ IE Zone Confiance: Scanned in 00mn 00s
---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} ((no name)) - http://support.euro.dell.com/systemprofiler/DellSystemLite.CAB
~ Objets ActiveX: Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s
---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ SSODL: 1 Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) . (.Andrea Electronics Corporation - Andrea filters APO access service (32-bit).) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) . (.Broadcom Corporation. - Bluetooth Support Server.) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dell Data Vault (DellDataVault) . (.Dell Inc. - Dell Data Vault Service.) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
O23 - Service: Dell Data Vault Wizard (DellDataVaultWiz) . (.Dell Inc. - Dell Data Vault Wizard.) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
O23 - Service: C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DpHost) . (.DigitalPersona, Inc. - DigitalPersona Local Host.) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) . (.Sonic Solutions - RoxWatch12 Module.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Audio Service (STacSV) . (.IDT, Inc. - IDT PC Audio.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
O23 - Service: Dell SupportAssist Agent (SupportAssistAgent) . (.Dell Inc. - Service.) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
O23 - Service: Intel(R) Management & Security Application User Notificatio (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) . (.Validity Sensors, Inc. - VFS101 VCS API Library.) - C:\Windows\system32\vcsFPService.exe
O23 - Service: DW WLAN Tray Service (wltrysvc) . (.Dell Inc. - DW WLAN Card Wireless Network Service.) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
~ Services: 19 Scanned in 00mn 07s
---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Desktop Component: 4 Scanned in 00mn 00s
---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
[MD5.3E04F1E482357B1FC8B088197C3D9FF8] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152]
[MD5.B04A4810C6CC205F9DC72DC22E4AB236] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [268464]
[MD5.1F014EA12ECB13C909DA9395E9CD3D18] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6278424]
[MD5.2BCB174FF294F83C3520D46B57DBD917] [APT] [Dell SupportAssistAgent AutoUpdate] (.Dell Inc..) -- C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [27472]
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107912]
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107912]
[MD5.79B5DD0E04130BF31AA598F2AEBB1B78] [APT] [PCDEventLauncherTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell\SupportAssist\sessionchecker.exe [433488]
[MD5.254EC04C72D02E4C8EEC08D4CF3658B1] [APT] [PCDoctorBackgroundMonitorTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell\SupportAssist\uaclauncher.exe [1189200]
[MD5.C155A13687144076286989EF078112C2] [APT] [{0815057C-EFA1-4BCA-B1FE-135DCE6988D1}] (.Nicolas Coolman.) -- C:\Program Files\ZHPDiag\ZHPhep.exe [1917440]
[MD5.A75AE3B84B6423CE6A088E80A2BC23C2] [APT] [{4773655F-F316-4A0B-AAD8-B898B8AF2A0A}] (.Skype Technologies S.A..) -- C:\Program Files\Skype\Phone\Skype.exe [31280256]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{7A7B4145-1139-4669-8765-5936ED3BBC3A}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{A28E5010-28AC-4FF0-9EDF-0210636C319A}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [561984]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1054]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1054]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1058]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1058]
~ Scheduled Task: 17 Scanned in 00mn 05s
---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft VM - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Microsoft Corporation - Microsoft® VM.) -- C:\Windows\system32\msjava.dll
O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Disable SSL3 - {7D715857-A67C-4C2F-A929-038448584D63} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
~ Active Setup: 11 Scanned in 00mn 00s
---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys
O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
O41 - Driver: (MpKsl27db1ee3) . (...) - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2698567C-ABF3-4177-B0E6-C232BD8B10E0}\MpKsl27db1ee3.sys
O41 - Driver: (MpKsl481d2377) . (.Microsoft Corporation - KSLDriver.) - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2698567C-ABF3-4177-B0E6-C232BD8B10E0}\MpKsl481d2377.sys
O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys
O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
~ Drivers: 65 Scanned in 00mn 00s
---\\ Logiciels installés (O42)
O42 - Logiciel: 7-Zip 9.20 - (...) [HKLM] -- 7-Zip
O42 - Logiciel: 7Zip Bundle by Fileparade.com - (.SweetPacks LTD.) [HKLM] -- 7Zip Bundle by Fileparade.com =>PUP.SweetIM
O42 - Logiciel: AccelerometerP11 - (.STMicroelectronics.) [HKLM] -- {87434D51-51DB-4109-B68F-A829ECDCF380}
O42 - Logiciel: Adobe After Effects CS4 Third Party Content - (.Adobe Systems Incorporated.) [HKLM] -- {67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}
O42 - Logiciel: Adobe Anchor Service CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {1618734A-3957-4ADD-8199-F973763109A8}
O42 - Logiciel: Adobe Bridge CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {83877DB1-8B77-45BC-AB43-2BAC22E093E0} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe CMaps CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {94D398EB-D2FD-4FD1-B8C4-592635E8A191}
O42 - Logiciel: Adobe CSI CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0F723FC1-7606-4867-866C-CE80AD292DAF}
O42 - Logiciel: Adobe Color EU Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}
O42 - Logiciel: Adobe Color JA Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0D6013AB-A0C7-41DC-973C-E93129C9A29F}
O42 - Logiciel: Adobe Color NA Recommended Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {00ADFB20-AE75-46F4-AD2C-F48B15AC3100}
O42 - Logiciel: Adobe Color Video Profiles CS CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {63C24A08-70F3-4C8E-B9FB-9F21A903801D}
O42 - Logiciel: Adobe Creative Suite 4 Master Collection - (.Adobe Systems Incorporated.) [HKLM] -- Adobe_b2b1c7c62c4ae0a954789ed71d36a7a
O42 - Logiciel: Adobe Creative Suite 4 Master Collection - (.Adobe Systems Incorporated.) [HKLM] -- {D0EE7809-8F5E-46EF-95DC-B30DCE22653F}
O42 - Logiciel: Adobe Default Language CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {C52E3EC1-048C-45E1-8D53-10B0C6509683}
O42 - Logiciel: Adobe Encore CS4 Codecs - (.Adobe Systems Incorporated.) [HKLM] -- {FB2A5FCC-B81B-48C2-A009-7804694D83E9}
O42 - Logiciel: Adobe ExtendScript Toolkit CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F8EF2B3F-C345-4F20-8FE4-791A20333CD5} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Extension Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {054EFA56-2AC1-48F4-A883-0AB89874B972}
O42 - Logiciel: Adobe Flash Player 17 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 17 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI
O42 - Logiciel: Adobe Fonts All - (.Adobe Systems Incorporated.) [HKLM] -- {FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
O42 - Logiciel: Adobe Illustrator CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05C677A1-A161-447E-92ED-2D5B38AA0740} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {A2160D84-F2D0-47A3-AA59-CCB3CA21D558} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Application Feature Set Files (Roman) - (.Adobe Systems Incorporated.) [HKLM] -- {C950299F-BCAB-4695-B077-FC3B2748C25D} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Common Base Files - (.Adobe Systems Incorporated.) [HKLM] -- {26F72DC3-DDBE-424F-B9F0-94E5D0E5A12B} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Icon Handler - (.Adobe Systems Incorporated.) [HKLM] -- {2BA4F7B0-F38E-4AE8-80A2-E9C5956C6D6D} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Linguistics CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {931AB7EA-3656-4BB7-864D-022B09E3DD67}
O42 - Logiciel: Adobe Media Encoder CS4 Exporter - (.Adobe Systems Incorporated.) [HKLM] -- {561968FD-56A1-49FD-9ED0-F55482C7C5BC}
O42 - Logiciel: Adobe Media Encoder CS4 Importer - (.Adobe Systems Incorporated.) [HKLM] -- {8186FF34-D389-4B7E-9A2F-C197585BCFBD}
O42 - Logiciel: Adobe Output Module - (.Adobe Systems Incorporated.) [HKLM] -- {BB4E33EC-8181-4685-96F7-8554293DEC6A}
O42 - Logiciel: Adobe PDF Library Files CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F93C84A6-0DC6-42AF-89FA-776F7C377353}
O42 - Logiciel: Adobe Photoshop CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {E2E01E91-2314-42BC-B5E3-1715DAE84F98} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Photoshop CS4 Support - (.Adobe Systems Incorporated.) [HKLM] -- {73E17122-EC84-45B4-943B-735257B5CBDC} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Premiere Pro CS4 Third Party Content - (.Adobe Systems Incorporated.) [HKLM] -- {E1951CF4-91CE-46F0-A1BD-3A4A67069097}
O42 - Logiciel: Adobe Reader X (10.1.13) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AA1000000001}
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-0804-1033-1959-001802114130}
O42 - Logiciel: Adobe SGM CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}
O42 - Logiciel: Adobe SING CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {8CB16C77-9D75-4966-91E8-D785B87EC078}
O42 - Logiciel: Adobe Search for Help - (.Adobe Systems Incorporated.) [HKLM] -- {F0E64E2E-3A60-40D8-A55D-92F6831875DA}
O42 - Logiciel: Adobe Service Manager Extension - (.Adobe Systems Incorporated.) [HKLM] -- {4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
O42 - Logiciel: Adobe Setup - (.Adobe Systems Incorporated.) [HKLM] -- {6577657B-A10C-47A1-A50D-512C7748CB2C}
O42 - Logiciel: Adobe Soundbooth CS4 Codecs - (.Adobe Systems Incorporated.) [HKLM] -- {52232EF4-CC12-4C21-ABCF-ADB79618302D}
O42 - Logiciel: Adobe Type Support CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
O42 - Logiciel: Adobe Update Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05308C4E-7285-4066-BAE3-6B50DA6ED755}
O42 - Logiciel: Adobe WinSoft Linguistics Plugin - (.Adobe Systems Incorporated.) [HKLM] -- {3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
O42 - Logiciel: Adobe XMP Panels CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
O42 - Logiciel: AdobeColorCommonSetCMYK - (.Adobe Systems Incorporated.) [HKLM] -- {E5FCED12-3E77-4C0E-A305-5AEB38A52A70}
O42 - Logiciel: AdobeColorCommonSetRGB - (.Adobe Systems Incorporated.) [HKLM] -- {16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
O42 - Logiciel: Advanced Audio FX Engine - (.Creative Technology Ltd.) [HKLM] -- Advanced Audio FX Engine
O42 - Logiciel: Antidote RX v7 - (.Druide informatique inc..) [HKLM] -- {A474EA56-5DBD-4181-8230-806A4762EA7F}
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {5D09C772-ECB3-442B-9CC6-B4341C78FDC2}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {E14ADE0E-75F3-4A46-87E5-26692DD626EC}
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} =>.Apple Inc
O42 - Logiciel: ArcGIS 10.1 for Desktop - (.Environmental Systems Research Institute, Inc..) [HKLM] -- ArcGIS 10.1 for Desktop
O42 - Logiciel: ArcGIS 10.1 for Desktop - Module linguistique français - (.Environmental Systems Research Institute, Inc..) [HKLM] -- ArcGIS 10.1 for Desktop - Module linguistique français
O42 - Logiciel: ArcGIS 10.1 for Desktop - Module linguistique français - (.Environmental Systems Research Institute, Inc..) [HKLM] -- {311DA2E4-3B6A-464F-8987-C4AAE6B9386D}
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {79155F2B-9895-49D7-8612-D92580E0DE5B}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: CDBurnerXP - (.CDBurnerXP.) [HKLM] -- {7E265513-8CDA-4631-B696-F40D983F3B07}_is1
O42 - Logiciel: Canon MG5200 series MP Drivers - (...) [HKLM] -- {1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series
O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM] -- {64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {51C7AD07-C3F6-4635-8E8A-231306D810FE}
O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
O42 - Logiciel: Complément Messenger - (.Microsoft Corporation.) [HKLM] -- {6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}
O42 - Logiciel: Connect - (.Adobe Systems Incorporated.) [HKLM] -- {B29AD377-CC12-490A-A480-1452337C618D}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM] -- InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM] -- {A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
O42 - Logiciel: DW WLAN Card Utility - (.Dell Inc..) [HKLM] -- DW WLAN Card Utility
O42 - Logiciel: Dell Backup and Recovery Manager - (.Dell Inc..) [HKLM] -- {4688EB75-28E2-4731-9BCB-55E624F7CD45}
O42 - Logiciel: Dell Data Vault - (.Dell Inc..) [HKLM] -- {2E55EEFD-2162-4A7D-9158-EDB0305603A6}
O42 - Logiciel: Dell Edoc Viewer - (.Dell Inc.) [HKLM] -- {3138EAD3-700B-4A10-B617-B3F8096EE30D}
O42 - Logiciel: Dell SupportAssist - (.Dell.) [HKLM] -- PC-Doctor for Windows
O42 - Logiciel: Dell SupportAssistAgent - (.Dell.) [HKLM] -- {287348C8-8B47-4C36-AF28-441A3B7D8722}
O42 - Logiciel: Dell Touchpad - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey
O42 - Logiciel: Dell Webcam Central - (.Creative Technology Ltd.) [HKLM] -- Dell Webcam Central
O42 - Logiciel: DigitalPersona Personal 4.01 - (.DigitalPersona, Inc..) [HKLM] -- {3D8AE086-030F-4EF4-B705-63F8130B043E}
O42 - Logiciel: DirectX 9 Runtime - (.Sonic Solutions.) [HKLM] -- {AF9E97C1-7431-426D-A8D5-ABE40995C0B1}
O42 - Logiciel: EndNote X3 - (.Thomson Reuters.) [HKLM] -- {86B3F2D6-AC2B-4E88-8AE1-F2F77F781B0C}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}
O42 - Logiciel: IRIScan(TM) Direct - (.IRIScanDirect.) [HKLM] -- IRIScanDirect_is1
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
O42 - Logiciel: Java 8 Update 31 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83218031F0}
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
O42 - Logiciel: Logiciel d'archivage WinRAR - (...) [HKLM] -- WinRAR archiver
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: Malwarebytes Anti-Malware version 2.1.6.1022 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1
O42 - Logiciel: Mesh Runtime - (.Microsoft Corporation.) [HKLM] -- {8C6D6116-B724-4810-8F2D-D047E6B7D68E}
O42 - Logiciel: Microsoft Image Composite Editor - (.Microsoft Corporation.) [HKLM] -- {3D599ADA-65D9-4B51-898F-CE718DEC5DBB}
O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {D6F9CBDC-58B6-430A-8DD4-8F61CBC1ADF4}
O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Mozilla Firefox 37.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 37.0.2 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: PDF Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
O42 - Logiciel: PhotoShowExpress - (.Sonic Solutions.) [HKLM] -- {3250260C-7A95-4632-893B-89657EB5545B}
O42 - Logiciel: Photoshop Camera Raw - (.Adobe Systems Incorporated.) [HKLM] -- {CC75AB5C-2110-4A7F-AF52-708680D22FE8}
O42 - Logiciel: QuickSet32 - (.Dell Inc..) [HKLM] -- {C4972073-2BFE-475D-8441-564EA97DA161}
O42 - Logiciel: ResearchSoft Direct Export Helper - (...) [HKLM] -- ResearchSoft Direct Export Helper
O42 - Logiciel: Roxio Activation Module - (.Roxio.) [HKLM] -- {A121EEDE-C68F-461D-91AA-D48BA226AF1C}
O42 - Logiciel: Roxio BackOnTrack - (.Roxio.) [HKLM] -- {5A06423A-210C-49FB-950E-CB0EB8C5CEC7}
O42 - Logiciel: Roxio Burn - (.Roxio.) [HKLM] -- {9569E6BC-326A-432F-97AB-35263A327BF1}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {EF56258E-0326-48C5-A86C-3BAC26FC15DF}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}
O42 - Logiciel: Roxio Express Labeler 3 - (.Roxio.) [HKLM] -- {6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
O42 - Logiciel: Roxio File Backup - (.Roxio.) [HKLM] -- {60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}
O42 - Logiciel: Samsung Printer Live Update - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung Printer Live Update
O42 - Logiciel: Satsuki Decoder Pack - (.Satsuki Yatoshi'S Softs.) [HKLM] -- Satsuki Decoder Pack
O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701}
O42 - Logiciel: Skype(TM) 7.4 - (.Skype Technologies S.A..) [HKLM] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
O42 - Logiciel: Sonic CinePlayer Decoder Pack - (.Sonic Solutions.) [HKLM] -- {9A00EC4E-27E1-42C4-98DD-662F32AC8870}
O42 - Logiciel: Spotify - (...) [HKLM] -- Spotify
O42 - Logiciel: Spotify - (.Spotify AB.) [HKCU] -- Spotify
O42 - Logiciel: Suite Shared Configuration CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {842B4B72-9E8F-4962-B3C1-1C422A5C4434}
O42 - Logiciel: TuxGuitar 1.2 - (...) [HKLM] -- TuxGuitar_0
O42 - Logiciel: Validity Sensors DDK - (.Validity Sensors, Inc..) [HKLM] -- {9FCB6355-689E-4141-9714-3EEC2AE10292}
O42 - Logiciel: WIDCOMM Bluetooth Software - (.Broadcom Corporation.) [HKLM] -- {9E9D49A4-1DF4-4138-B7DB-5D87A893088E}
O42 - Logiciel: XnView 2.22 - (.Gougelet Pierre-e.) [HKLM] -- XnView_is1
O42 - Logiciel: Xvid 1.2.1 final uninstall - (.Xvid team (Koepi).) [HKLM] -- Xvid_is1
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {11E568E0-3244-4BCB-875E-F334269DFDCB}
O42 - Logiciel: kuler - (.Adobe Systems Incorporated.) [HKLM] -- {098727E1-775A-4450-B573-3F441F1CA243}
~ Logic: 44 Scanned in 00mn 00s
---\\ HKCU & HKLM Software Keys
[HKCU\Software\7-Zip]
[HKCU\Software\AC3Filter]
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow\Software\DigitalPersona]
[HKCU\Software\AppDataLow\Software\JavaSoft]
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Arobas Music]
[HKCU\Software\Broadcom]
[HKCU\Software\CG Information]
[HKCU\Software\Canneverbe Limited]
[HKCU\Software\Canon]
[HKCU\Software\Citrix]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\Creative Tech]
[HKCU\Software\CyberLink]
[HKCU\Software\DT Soft]
[HKCU\Software\Developer Express]
[HKCU\Software\DigitalPersona]
[HKCU\Software\Druide informatique inc.]
[HKCU\Software\ERDAS]
[HKCU\Software\ESRI]
[HKCU\Software\EasyBits]
[HKCU\Software\Eset]
[HKCU\Software\GNU]
[HKCU\Software\Gabest]
[HKCU\Software\Google]
[HKCU\Software\HKEY_LOCAL_MACHINE]
[HKCU\Software\Haali]
[HKCU\Software\Herac]
[HKCU\Software\IDAVLab]
[HKCU\Software\IDT]
[HKCU\Software\IM Providers]
[HKCU\Software\ISI ResearchSoft]
[HKCU\Software\Intel]
[HKCU\Software\JavaSoft]
[HKCU\Software\Lake]
[HKCU\Software\LogiShrd]
[HKCU\Software\MCAFEE]
[HKCU\Software\Macromedia]
[HKCU\Software\Macrovision]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Nero]
[HKCU\Software\Netscape]
[HKCU\Software\Northcode Inc]
[HKCU\Software\ODBC]
[HKCU\Software\PC-Doctor]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\RICOH]
[HKCU\Software\RealNetworks]
[HKCU\Software\RegisteredApplications]
[HKCU\Software\Roxio]
[HKCU\Software\SSPrint]
[HKCU\Software\STUDIO SARMADI]
[HKCU\Software\Samsung]
[HKCU\Software\Satsuki Decoder Pack]
[HKCU\Software\SecuROM]
[HKCU\Software\Skype]
[HKCU\Software\Synaptics]
[HKCU\Software\Trolltech]
[HKCU\Software\Widcomm]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\ZebHelpProcess Helper]
[HKLM\Software\ATI Technologies]
[HKLM\Software\Adobe]
[HKLM\Software\AdwCleaner]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\BcmSetup]
[HKLM\Software\Broadcom]
[HKLM\Software\Canneverbe Limited]
[HKLM\Software\Canon]
[HKLM\Software\Citrix]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Creative Tech]
[HKLM\Software\CyberLink]
[HKLM\Software\DT Soft]
[HKLM\Software\Debug]
[HKLM\Software\Dell Computer Corporation]
[HKLM\Software\Dell Inc.]
[HKLM\Software\Dell]
[HKLM\Software\DigitalPersona]
[HKLM\Software\Druide informatique inc.]
[HKLM\Software\ERDAS]
[HKLM\Software\ESRI]
[HKLM\Software\FreeFallProtection]
[HKLM\Software\GEAR Software]
[HKLM\Software\GNU]
[HKLM\Software\Gabest]
[HKLM\Software\Google]
[HKLM\Software\HaaliMkx]
[HKLM\Software\IDAVLab]
[HKLM\Software\IDT]
[HKLM\Software\IM Providers]
[HKLM\Software\ISI ResearchSoft]
[HKLM\Software\Imagineer Systems Ltd]
[HKLM\Software\InstalledOptions]
[HKLM\Software\Intel]
[HKLM\Software\InterVideo]
[HKLM\Software\JavaSoft]
[HKLM\Software\JreMetrics]
[HKLM\Software\Lake]
[HKLM\Software\Logishrd]
[HKLM\Software\MAXSOFT-OCRON]
[HKLM\Software\Macromedia]
[HKLM\Software\Macrovision]
[HKLM\Software\Malwarebytes' Anti-Malware (Trial)]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\ManageableUpdatePackage]
[HKLM\Software\McAfee.com]
[HKLM\Software\McAfeeInstaller]
[HKLM\Software\McAfee]
[HKLM\Software\MicroVision]
[HKLM\Software\MimarSinan]
[HKLM\Software\Mircrosoft]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Nero]
[HKLM\Software\Novell]
[HKLM\Software\ODBC]
[HKLM\Software\PC-Doctor]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\Python]
[HKLM\Software\RealNetworks]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Roxio]
[HKLM\Software\SSPrint]
[HKLM\Software\STMicroelectronics]
[HKLM\Software\Samsung]
[HKLM\Software\Skype]
[HKLM\Software\Sonic]
[HKLM\Software\Synaptics]
[HKLM\Software\Synthetic Aperture]
[HKLM\Software\Validity]
[HKLM\Software\Vantage Software Technologies]
[HKLM\Software\Volatile]
[HKLM\Software\Widcomm]
[HKLM\Software\WinRAR]
[HKLM\Software\Windows]
[HKLM\Software\Wise Solutions]
[HKLM\Software\XnView]
[HKLM\Software\illiminable]
[HKLM\Software\mozilla.org]
~ Key Software: 326 Scanned in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 23/09/2013 - 18:48:51 - [] ----D C:\Program Files\7-Zip
O43 - CFD: 14/10/2012 - 17:01:19 - [] ----D C:\Program Files\Adobe
O43 - CFD: 27/10/2012 - 13:10:03 - [] ----D C:\Program Files\Apple Software Update =>.Apple Inc
O43 - CFD: 23/09/2013 - 14:43:50 - [] ----D C:\Program Files\ArcGIS
O43 - CFD: 27/10/2012 - 13:09:43 - [] ----D C:\Program Files\Bonjour
O43 - CFD: 08/05/2015 - 11:47:02 - [] ----D C:\Program Files\CCleaner
O43 - CFD: 04/12/2011 - 23:56:37 - [] ----D C:\Program Files\CDBurnerXP
O43 - CFD: 07/01/2011 - 14:48:11 - [] ----D C:\Program Files\Cisco
O43 - CFD: 09/04/2013 - 08:24:59 - [] ----D C:\Program Files\Citrix
O43 - CFD: 10/05/2015 - 10:49:29 - [] ----D C:\Program Files\Common Files
O43 - CFD: 07/01/2011 - 14:52:12 - [] ----D C:\Program Files\Creative
O43 - CFD: 07/01/2011 - 14:51:48 - [] ----D C:\Program Files\Creative Live! Cam
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\CyberLink
O43 - CFD: 13/02/2015 - 17:07:18 - [] ----D C:\Program Files\Dell
O43 - CFD: 07/01/2011 - 14:41:47 - [] ----D C:\Program Files\Dell Inc
O43 - CFD: 01/04/2015 - 15:56:44 - [] ----D C:\Program Files\Dell Support Center
O43 - CFD: 07/01/2011 - 14:51:52 - [] ----D C:\Program Files\Dell Webcam
O43 - CFD: 07/01/2011 - 14:49:33 - [] ----D C:\Program Files\DigitalPersona
O43 - CFD: 05/10/2011 - 21:15:44 - [] ----D C:\Program Files\Druide
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\DVD Maker
O43 - CFD: 30/05/2013 - 16:35:59 - [] ----D C:\Program Files\EndNote X3
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\Program Files\Fichiers communs
O43 - CFD: 09/08/2013 - 08:30:00 - [] ----D C:\Program Files\Google
O43 - CFD: 18/09/2012 - 08:30:24 - [] ----D C:\Program Files\GUMBB52.tmp
O43 - CFD: 07/01/2011 - 07:38:05 - [] ----D C:\Program Files\IDT
O43 - CFD: 07/01/2011 - 14:51:50 - [] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 07/01/2011 - 14:43:38 - [] ----D C:\Program Files\Intel
O43 - CFD: 16/04/2015 - 07:41:45 - [] ----D C:\Program Files\Internet Explorer
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\iPod
O43 - CFD: 30/05/2014 - 17:24:54 - [] ----D C:\Program Files\IRIScan Direct
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\Program Files\iTunes
O43 - CFD: 01/02/2015 - 19:24:51 - [] ----D C:\Program Files\Java
O43 - CFD: 08/05/2015 - 12:02:05 - [] ----D C:\Program Files\Malwarebytes Anti-Malware
O43 - CFD: 19/08/2014 - 07:39:24 - [] ----D C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 15/01/2011 - 17:51:35 - [0] ----D C:\Program Files\Microsoft
O43 - CFD: 14/07/2009 - 11:00:58 - [] ----D C:\Program Files\Microsoft Games
O43 - CFD: 27/08/2012 - 21:15:59 - [] ----D C:\Program Files\Microsoft Office
O43 - CFD: 10/02/2012 - 09:38:04 - [] ----D C:\Program Files\Microsoft Research
O43 - CFD: 11/02/2015 - 20:53:43 - [] ----D C:\Program Files\Microsoft Security Client
O43 - CFD: 24/07/2014 - 17:05:44 - [] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 07/01/2011 - 15:02:44 - [] ----D C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 13/03/2011 - 22:40:16 - [] ----D C:\Program Files\Microsoft Visual Studio
O43 - CFD: 13/03/2011 - 22:37:09 - [] ----D C:\Program Files\Microsoft Visual Studio 8
O43 - CFD: 23/08/2012 - 08:17:10 - [] ----D C:\Program Files\Microsoft Works
O43 - CFD: 13/03/2011 - 22:40:04 - [] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 24/04/2015 - 12:09:10 - [] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 26/04/2015 - 08:23:34 - [] ----D C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 13/03/2011 - 22:40:20 - [] ----D C:\Program Files\MSBuild
O43 - CFD: 15/01/2011 - 23:49:59 - [0] ----D C:\Program Files\MSXML 4.0
O43 - CFD: 14/07/2009 - 06:52:30 - [] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 07/01/2011 - 14:58:04 - [] ----D C:\Program Files\Roxio
O43 - CFD: 03/03/2014 - 12:14:18 - [] ----D C:\Program Files\SamsungPrinterLiveUpdate
O43 - CFD: 03/03/2014 - 12:04:04 - [] ----D C:\Program Files\SamsungPrinterLiveUpdateInstaller
O43 - CFD: 05/02/2011 - 11:29:22 - [] ----D C:\Program Files\Satsuki Decoder Pack
O43 - CFD: 14/04/2015 - 08:03:39 - [] R---D C:\Program Files\Skype
O43 - CFD: 24/03/2015 - 20:36:20 - [] ----D C:\Program Files\Spotify
O43 - CFD: 07/01/2011 - 14:44:04 - [] ----D C:\Program Files\STMicroelectronics
O43 - CFD: 07/01/2011 - 16:33:50 - [] ----D C:\Program Files\Synaptics
O43 - CFD: 10/12/2011 - 19:15:54 - [] ----D C:\Program Files\Trend Micro
O43 - CFD: 25/03/2011 - 22:12:50 - [] ----D C:\Program Files\TuxGuitar-Jet
O43 - CFD: 14/07/2009 - 06:53:23 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 07/01/2011 - 14:45:49 - [] ----D C:\Program Files\Validity Sensors
O43 - CFD: 07/01/2011 - 14:46:46 - [] ----D C:\Program Files\WIDCOMM
O43 - CFD: 12/07/2013 - 07:57:37 - [] ----D C:\Program Files\Windows Defender
O43 - CFD: 12/07/2014 - 07:43:28 - [] ----D C:\Program Files\Windows Journal
O43 - CFD: 07/01/2011 - 15:03:04 - [] ----D C:\Program Files\Windows Live
O43 - CFD: 04/01/2012 - 19:59:00 - [] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 12/03/2015 - 04:25:28 - [] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 12/01/2011 - 13:59:10 - [] ----D C:\Program Files\Windows NT
O43 - CFD: 04/01/2012 - 19:58:58 - [] ----D C:\Program Files\Windows Photo Viewer
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Portable Devices
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Sidebar
O43 - CFD: 05/02/2011 - 12:44:37 - [] ----D C:\Program Files\WinRAR
O43 - CFD: 15/04/2014 - 08:21:40 - [] ----D C:\Program Files\XnView
O43 - CFD: 15/01/2011 - 22:02:09 - [] ----D C:\Program Files\Xvid
O43 - CFD: 12/05/2015 - 19:01:08 - [] ----D C:\Program Files\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 14/10/2012 - 17:01:28 - [] ----D C:\Program Files\Common Files\Adobe
O43 - CFD: 23/09/2013 - 14:47:09 - [] ----D C:\Program Files\Common Files\AnswerWorks 4.0
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\Common Files\Apple
O43 - CFD: 23/09/2013 - 14:46:20 - [] ----D C:\Program Files\Common Files\ArcGIS
O43 - CFD: 10/12/2011 - 19:52:01 - [] ----D C:\Program Files\Common Files\Bitdefender
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\Common Files\CyberLink
O43 - CFD: 23/09/2013 - 14:44:22 - [] ----D C:\Program Files\Common Files\Data Dynamics
O43 - CFD: 15/05/2014 - 11:50:28 - [] ----D C:\Program Files\Common Files\DESIGNER
O43 - CFD: 07/01/2011 - 14:51:35 - [] ----D C:\Program Files\Common Files\InstallShield
O43 - CFD: 01/02/2015 - 19:25:56 - [] ----D C:\Program Files\Common Files\Java
O43 - CFD: 28/02/2011 - 22:14:03 - [] ----D C:\Program Files\Common Files\Macrovision Shared
O43 - CFD: 05/02/2011 - 11:49:23 - [] ----D C:\Program Files\Common Files\mcafee
O43 - CFD: 23/08/2012 - 08:17:16 - [] ----D C:\Program Files\Common Files\microsoft shared
O43 - CFD: 07/01/2011 - 14:43:41 - [] ----D C:\Program Files\Common Files\postureAgent
O43 - CFD: 07/01/2011 - 14:58:20 - [] ----D C:\Program Files\Common Files\PX Storage Engine
O43 - CFD: 30/05/2013 - 16:36:04 - [] ----D C:\Program Files\Common Files\ResearchSoft
O43 - CFD: 23/12/2012 - 15:28:39 - [] ----D C:\Program Files\Common Files\Risxtd
O43 - CFD: 07/01/2011 - 14:58:36 - [] ----D C:\Program Files\Common Files\Roxio Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\Services
O43 - CFD: 08/10/2014 - 07:41:48 - [] ----D C:\Program Files\Common Files\Skype
O43 - CFD: 07/01/2011 - 14:58:00 - [] ----D C:\Program Files\Common Files\Sonic Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 07/01/2011 - 14:57:58 - [] ----D C:\Program Files\Common Files\SureThing Shared
O43 - CFD: 17/01/2012 - 16:46:20 - [0] ----D C:\Program Files\Common Files\SWF Studio
O43 - CFD: 04/01/2012 - 19:58:57 - [] ----D C:\Program Files\Common Files\System
O43 - CFD: 23/09/2013 - 14:44:09 - [] ----D C:\Program Files\Common Files\Tom Sawyer Software
O43 - CFD: 07/01/2011 - 14:58:54 - [] ----D C:\Program Files\Common Files\Windows Live
O43 - CFD: 30/05/2013 - 16:33:17 - [] ----D C:\Program Files\Common Files\Wise Installation Wizard
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
O43 - CFD: 30/07/2014 - 20:12:45 - [] ----D C:\ProgramData\Adobe
O43 - CFD: 28/02/201
~ Rapport de ZHPDiag v2015.5.8.47 - Nicolas Coolman (05/05/2015)
~ Lancé par Amaury (12/05/2015 19:01:50)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Désactivée par l'utilisateur
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user
---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17728
MFIE: Mozilla Firefox 37.0.2 (Defaut)
---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows Operating System - Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : RMV82
Windows License : OK
~ Windows Remaining Initializations Number : 4
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 7 Home Premium, 32-bit Service Pack 1 (Build 7601)
---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 2.1.6.1022
Microsoft Security Client v4.7.0205.0
Windows Defender W7 (Deactivate)
---\\ Logiciels d'optimisation du système
CCleaner v5.05
---\\ Logiciels de partage PeerToPeer
---\\ Surveillance de Logiciels
Adobe Flash Player 17 NPAPI
Adobe Reader X
---\\ Informations sur le système
~ Processor: x86 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2998 MB (59% free)
System Restore: Activé (Enable)
System drive C: has 173 GB (60%) free of 287 GB
---\\ Mode de connexion au système
~ Computer Name: AMAURY-PC
~ User Name: Amaury
~ All Users Names: HomeGroupUser$, Amaury, Administrateur,
~ Unselected Option: None
Logged in as Administrator
---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Amaury\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Amaury\AppData\Roaming\
~ %Desktop% : C:\Users\Amaury\Desktop\
~ %Favorites% : C:\Users\Amaury\Favorites\
~ %LocalAppData% : C:\Users\Amaury\AppData\Local\
~ %StartMenu% : C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 173 Go of 287 Go)
D: CD-ROM drive (Not Inserted)
---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: 43 Scanned in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.C46904F2E9E121A91DDDABB48D7648C3] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.13/03/2015 - 03:20:28.) -- C:\Windows\System32\wininet.dll [1888256]
[MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.17/07/2014 - 02:39:27.) -- C:\Windows\System32\Winlogon.exe [304128]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 13:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:36:07.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 09:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 09:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 10:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 09:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:18:22.) -- C:\Windows\system32\Drivers\ntfs.sys [1212352]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:32:14.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 13:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Generic Processes: Scanned in 00mn 00s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/3
~ Mes musiques (My Musics) : 1/185
~ Mes Favoris (My Favorites) : 1/30
~ Mes Documents (My Documents) : 2/1045
~ Mon Bureau (My Desktop) : 15/82419
~ Menu demarrer (Programs) : 1/30
~ Hidden Files: Scanned in 01mn 12s
---\\ Processus lancés
[MD5.7E212E742BF06BF678AE35E9C1B74B8F] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe [6212920] [PID.3252]
[MD5.567B0B979E206C3E1E7B4422A2D0A5AD] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1602856] [PID.3888]
[MD5.A9D62C7793510D81342AC1AC50FB70F5] - (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe [495708] [PID.3976]
[MD5.C7AF01132A0DD241A1A0DBE9B62A9A1C] - (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\quickset.exe [3873648] [PID.4020]
[MD5.B7680F36C41AE21C0ECA96523443831F] - (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe [727664] [PID.2792]
[MD5.22001D1308E34153D2BCD51368E14F7B] - (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5249024] [PID.3260]
[MD5.2059A96CB2254829488A6A676AA4BA15] - (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\DpAgent.exe [842816] [PID.3660]
[MD5.0FE0EDF01CEA3BEB2E65A904BB87525E] - (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe [640376] [PID.3724]
[MD5.D50F04F005C94FA3802A6E05CFCF4A9A] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.3184]
[MD5.9A8568C7642B79F43DCEB0BDF9F49050] - (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe [542136] [PID.1196]
[MD5.CCA0C5482B8A6A275D9D49433F435DFA] - (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe [542096] [PID.3576]
[MD5.46B9C74861D98EDA9E6E56D19BEAF91A] - (.Broadcom Corporation. - Bluetooth Tray Application.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [795936] [PID.3588]
[MD5.254EC04C72D02E4C8EEC08D4CF3658B1] - (.PC-Doctor, Inc. - PC-Doctor Module.) -- C:\Program Files\Dell\SupportAssist\uaclauncher.exe [1189200] [PID.4676]
[MD5.207E54FC226446E2A218EDB400541D80] - (.Pas de propriétaire - CPU temperature and system information util.) -- C:\Users\Amaury\AppData\Local\Temp\Rar$EX36.168\Core Temp.exe [794272] [PID.4260]
[MD5.5D1BFF0FCE80F9E2E539F436710D4A79] - (.Microsoft Corporation - Preview Handler Surrogate Host.) -- C:\Windows\system32\prevhost.exe [31232] [PID.1652]
[MD5.2727208EA26F6B6DA898AB6890417214] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8208384] [PID.4332]
~ Processes Running: Scanned in 00mn 01s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Amaury\AppData\Local\Google\Chrome\User Data\Default\Preferences
---\\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 0 Scanned in 00mn 00s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFF12.DLL
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo-france.xml
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll =>.Google Inc
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=11.31.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Windows\system32\npdeployJava1.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Oracle Corporation - Next Generation Java Plug-in 11.31.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=11.31.2] - (.Oracle Corporation - Next Generation Java Plug-in 11.31.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) -- C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
~ Firefox Browser: 31 Scanned in 00mn 00s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.13.) (No version) -- (.not file.)
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
~ IE Browser: 11 Scanned in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: DigitalPersona Fingerprint Software Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} . (.DigitalPersona, Inc. - DigitalPersona OTS Feedback.) -- C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} . (.Microsoft Corporation - Windows Live Messenger Companion Core.) -- C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
~ BHO: 14 Scanned in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Adobe PDF - [HKLM]{47833539-D0C5-4125-9FA8-0819E2EAAC93} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{47833539-D0C5-4125-9FA8-0819E2EAAC93} Clé orpheline
~ Toolbar: Scanned in 00mn 00s
---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [QuickSet] . (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [FreeFallProtection] . (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] . (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [DpAgent] . (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] . (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKCU\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
~ Application: Scanned in 00mn 00s
---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ IE Control Panel: 1 Scanned in 00mn 00s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} . (.Microsoft Corporation - Windows Live Messenger Companion core resources.) -- C:\Program Files\Windows Live\Companion\companionres.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- c:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000009\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000010\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll
~ Winsock: 10 Scanned in 00mn 00s
---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] *.dell.com
~ IE Zone Confiance: Scanned in 00mn 00s
---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} ((no name)) - http://support.euro.dell.com/systemprofiler/DellSystemLite.CAB
~ Objets ActiveX: Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s
---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ SSODL: 1 Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) . (.Andrea Electronics Corporation - Andrea filters APO access service (32-bit).) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) . (.Broadcom Corporation. - Bluetooth Support Server.) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dell Data Vault (DellDataVault) . (.Dell Inc. - Dell Data Vault Service.) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
O23 - Service: Dell Data Vault Wizard (DellDataVaultWiz) . (.Dell Inc. - Dell Data Vault Wizard.) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
O23 - Service: C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DpHost) . (.DigitalPersona, Inc. - DigitalPersona Local Host.) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) . (.Sonic Solutions - RoxWatch12 Module.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Audio Service (STacSV) . (.IDT, Inc. - IDT PC Audio.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
O23 - Service: Dell SupportAssist Agent (SupportAssistAgent) . (.Dell Inc. - Service.) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
O23 - Service: Intel(R) Management & Security Application User Notificatio (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) . (.Validity Sensors, Inc. - VFS101 VCS API Library.) - C:\Windows\system32\vcsFPService.exe
O23 - Service: DW WLAN Tray Service (wltrysvc) . (.Dell Inc. - DW WLAN Card Wireless Network Service.) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
~ Services: 19 Scanned in 00mn 07s
---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Desktop Component: 4 Scanned in 00mn 00s
---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
[MD5.3E04F1E482357B1FC8B088197C3D9FF8] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152]
[MD5.B04A4810C6CC205F9DC72DC22E4AB236] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [268464]
[MD5.1F014EA12ECB13C909DA9395E9CD3D18] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6278424]
[MD5.2BCB174FF294F83C3520D46B57DBD917] [APT] [Dell SupportAssistAgent AutoUpdate] (.Dell Inc..) -- C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [27472]
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107912]
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107912]
[MD5.79B5DD0E04130BF31AA598F2AEBB1B78] [APT] [PCDEventLauncherTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell\SupportAssist\sessionchecker.exe [433488]
[MD5.254EC04C72D02E4C8EEC08D4CF3658B1] [APT] [PCDoctorBackgroundMonitorTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell\SupportAssist\uaclauncher.exe [1189200]
[MD5.C155A13687144076286989EF078112C2] [APT] [{0815057C-EFA1-4BCA-B1FE-135DCE6988D1}] (.Nicolas Coolman.) -- C:\Program Files\ZHPDiag\ZHPhep.exe [1917440]
[MD5.A75AE3B84B6423CE6A088E80A2BC23C2] [APT] [{4773655F-F316-4A0B-AAD8-B898B8AF2A0A}] (.Skype Technologies S.A..) -- C:\Program Files\Skype\Phone\Skype.exe [31280256]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{7A7B4145-1139-4669-8765-5936ED3BBC3A}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{A28E5010-28AC-4FF0-9EDF-0210636C319A}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [561984]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1054]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1054]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1058]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1058]
~ Scheduled Task: 17 Scanned in 00mn 05s
---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft VM - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Microsoft Corporation - Microsoft® VM.) -- C:\Windows\system32\msjava.dll
O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Disable SSL3 - {7D715857-A67C-4C2F-A929-038448584D63} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
~ Active Setup: 11 Scanned in 00mn 00s
---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys
O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
O41 - Driver: (MpKsl27db1ee3) . (...) - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2698567C-ABF3-4177-B0E6-C232BD8B10E0}\MpKsl27db1ee3.sys
O41 - Driver: (MpKsl481d2377) . (.Microsoft Corporation - KSLDriver.) - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2698567C-ABF3-4177-B0E6-C232BD8B10E0}\MpKsl481d2377.sys
O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys
O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
~ Drivers: 65 Scanned in 00mn 00s
---\\ Logiciels installés (O42)
O42 - Logiciel: 7-Zip 9.20 - (...) [HKLM] -- 7-Zip
O42 - Logiciel: 7Zip Bundle by Fileparade.com - (.SweetPacks LTD.) [HKLM] -- 7Zip Bundle by Fileparade.com =>PUP.SweetIM
O42 - Logiciel: AccelerometerP11 - (.STMicroelectronics.) [HKLM] -- {87434D51-51DB-4109-B68F-A829ECDCF380}
O42 - Logiciel: Adobe After Effects CS4 Third Party Content - (.Adobe Systems Incorporated.) [HKLM] -- {67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}
O42 - Logiciel: Adobe Anchor Service CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {1618734A-3957-4ADD-8199-F973763109A8}
O42 - Logiciel: Adobe Bridge CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {83877DB1-8B77-45BC-AB43-2BAC22E093E0} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe CMaps CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {94D398EB-D2FD-4FD1-B8C4-592635E8A191}
O42 - Logiciel: Adobe CSI CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0F723FC1-7606-4867-866C-CE80AD292DAF}
O42 - Logiciel: Adobe Color EU Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}
O42 - Logiciel: Adobe Color JA Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0D6013AB-A0C7-41DC-973C-E93129C9A29F}
O42 - Logiciel: Adobe Color NA Recommended Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {00ADFB20-AE75-46F4-AD2C-F48B15AC3100}
O42 - Logiciel: Adobe Color Video Profiles CS CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {63C24A08-70F3-4C8E-B9FB-9F21A903801D}
O42 - Logiciel: Adobe Creative Suite 4 Master Collection - (.Adobe Systems Incorporated.) [HKLM] -- Adobe_b2b1c7c62c4ae0a954789ed71d36a7a
O42 - Logiciel: Adobe Creative Suite 4 Master Collection - (.Adobe Systems Incorporated.) [HKLM] -- {D0EE7809-8F5E-46EF-95DC-B30DCE22653F}
O42 - Logiciel: Adobe Default Language CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {C52E3EC1-048C-45E1-8D53-10B0C6509683}
O42 - Logiciel: Adobe Encore CS4 Codecs - (.Adobe Systems Incorporated.) [HKLM] -- {FB2A5FCC-B81B-48C2-A009-7804694D83E9}
O42 - Logiciel: Adobe ExtendScript Toolkit CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F8EF2B3F-C345-4F20-8FE4-791A20333CD5} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Extension Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {054EFA56-2AC1-48F4-A883-0AB89874B972}
O42 - Logiciel: Adobe Flash Player 17 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 17 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI
O42 - Logiciel: Adobe Fonts All - (.Adobe Systems Incorporated.) [HKLM] -- {FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
O42 - Logiciel: Adobe Illustrator CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05C677A1-A161-447E-92ED-2D5B38AA0740} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {A2160D84-F2D0-47A3-AA59-CCB3CA21D558} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Application Feature Set Files (Roman) - (.Adobe Systems Incorporated.) [HKLM] -- {C950299F-BCAB-4695-B077-FC3B2748C25D} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Common Base Files - (.Adobe Systems Incorporated.) [HKLM] -- {26F72DC3-DDBE-424F-B9F0-94E5D0E5A12B} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Icon Handler - (.Adobe Systems Incorporated.) [HKLM] -- {2BA4F7B0-F38E-4AE8-80A2-E9C5956C6D6D} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Linguistics CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {931AB7EA-3656-4BB7-864D-022B09E3DD67}
O42 - Logiciel: Adobe Media Encoder CS4 Exporter - (.Adobe Systems Incorporated.) [HKLM] -- {561968FD-56A1-49FD-9ED0-F55482C7C5BC}
O42 - Logiciel: Adobe Media Encoder CS4 Importer - (.Adobe Systems Incorporated.) [HKLM] -- {8186FF34-D389-4B7E-9A2F-C197585BCFBD}
O42 - Logiciel: Adobe Output Module - (.Adobe Systems Incorporated.) [HKLM] -- {BB4E33EC-8181-4685-96F7-8554293DEC6A}
O42 - Logiciel: Adobe PDF Library Files CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F93C84A6-0DC6-42AF-89FA-776F7C377353}
O42 - Logiciel: Adobe Photoshop CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {E2E01E91-2314-42BC-B5E3-1715DAE84F98} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Photoshop CS4 Support - (.Adobe Systems Incorporated.) [HKLM] -- {73E17122-EC84-45B4-943B-735257B5CBDC} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Premiere Pro CS4 Third Party Content - (.Adobe Systems Incorporated.) [HKLM] -- {E1951CF4-91CE-46F0-A1BD-3A4A67069097}
O42 - Logiciel: Adobe Reader X (10.1.13) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AA1000000001}
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-0804-1033-1959-001802114130}
O42 - Logiciel: Adobe SGM CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}
O42 - Logiciel: Adobe SING CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {8CB16C77-9D75-4966-91E8-D785B87EC078}
O42 - Logiciel: Adobe Search for Help - (.Adobe Systems Incorporated.) [HKLM] -- {F0E64E2E-3A60-40D8-A55D-92F6831875DA}
O42 - Logiciel: Adobe Service Manager Extension - (.Adobe Systems Incorporated.) [HKLM] -- {4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
O42 - Logiciel: Adobe Setup - (.Adobe Systems Incorporated.) [HKLM] -- {6577657B-A10C-47A1-A50D-512C7748CB2C}
O42 - Logiciel: Adobe Soundbooth CS4 Codecs - (.Adobe Systems Incorporated.) [HKLM] -- {52232EF4-CC12-4C21-ABCF-ADB79618302D}
O42 - Logiciel: Adobe Type Support CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
O42 - Logiciel: Adobe Update Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05308C4E-7285-4066-BAE3-6B50DA6ED755}
O42 - Logiciel: Adobe WinSoft Linguistics Plugin - (.Adobe Systems Incorporated.) [HKLM] -- {3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
O42 - Logiciel: Adobe XMP Panels CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
O42 - Logiciel: AdobeColorCommonSetCMYK - (.Adobe Systems Incorporated.) [HKLM] -- {E5FCED12-3E77-4C0E-A305-5AEB38A52A70}
O42 - Logiciel: AdobeColorCommonSetRGB - (.Adobe Systems Incorporated.) [HKLM] -- {16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
O42 - Logiciel: Advanced Audio FX Engine - (.Creative Technology Ltd.) [HKLM] -- Advanced Audio FX Engine
O42 - Logiciel: Antidote RX v7 - (.Druide informatique inc..) [HKLM] -- {A474EA56-5DBD-4181-8230-806A4762EA7F}
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {5D09C772-ECB3-442B-9CC6-B4341C78FDC2}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {E14ADE0E-75F3-4A46-87E5-26692DD626EC}
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} =>.Apple Inc
O42 - Logiciel: ArcGIS 10.1 for Desktop - (.Environmental Systems Research Institute, Inc..) [HKLM] -- ArcGIS 10.1 for Desktop
O42 - Logiciel: ArcGIS 10.1 for Desktop - Module linguistique français - (.Environmental Systems Research Institute, Inc..) [HKLM] -- ArcGIS 10.1 for Desktop - Module linguistique français
O42 - Logiciel: ArcGIS 10.1 for Desktop - Module linguistique français - (.Environmental Systems Research Institute, Inc..) [HKLM] -- {311DA2E4-3B6A-464F-8987-C4AAE6B9386D}
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {79155F2B-9895-49D7-8612-D92580E0DE5B}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: CDBurnerXP - (.CDBurnerXP.) [HKLM] -- {7E265513-8CDA-4631-B696-F40D983F3B07}_is1
O42 - Logiciel: Canon MG5200 series MP Drivers - (...) [HKLM] -- {1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series
O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM] -- {64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {51C7AD07-C3F6-4635-8E8A-231306D810FE}
O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
O42 - Logiciel: Complément Messenger - (.Microsoft Corporation.) [HKLM] -- {6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}
O42 - Logiciel: Connect - (.Adobe Systems Incorporated.) [HKLM] -- {B29AD377-CC12-490A-A480-1452337C618D}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM] -- InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM] -- {A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
O42 - Logiciel: DW WLAN Card Utility - (.Dell Inc..) [HKLM] -- DW WLAN Card Utility
O42 - Logiciel: Dell Backup and Recovery Manager - (.Dell Inc..) [HKLM] -- {4688EB75-28E2-4731-9BCB-55E624F7CD45}
O42 - Logiciel: Dell Data Vault - (.Dell Inc..) [HKLM] -- {2E55EEFD-2162-4A7D-9158-EDB0305603A6}
O42 - Logiciel: Dell Edoc Viewer - (.Dell Inc.) [HKLM] -- {3138EAD3-700B-4A10-B617-B3F8096EE30D}
O42 - Logiciel: Dell SupportAssist - (.Dell.) [HKLM] -- PC-Doctor for Windows
O42 - Logiciel: Dell SupportAssistAgent - (.Dell.) [HKLM] -- {287348C8-8B47-4C36-AF28-441A3B7D8722}
O42 - Logiciel: Dell Touchpad - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey
O42 - Logiciel: Dell Webcam Central - (.Creative Technology Ltd.) [HKLM] -- Dell Webcam Central
O42 - Logiciel: DigitalPersona Personal 4.01 - (.DigitalPersona, Inc..) [HKLM] -- {3D8AE086-030F-4EF4-B705-63F8130B043E}
O42 - Logiciel: DirectX 9 Runtime - (.Sonic Solutions.) [HKLM] -- {AF9E97C1-7431-426D-A8D5-ABE40995C0B1}
O42 - Logiciel: EndNote X3 - (.Thomson Reuters.) [HKLM] -- {86B3F2D6-AC2B-4E88-8AE1-F2F77F781B0C}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}
O42 - Logiciel: IRIScan(TM) Direct - (.IRIScanDirect.) [HKLM] -- IRIScanDirect_is1
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
O42 - Logiciel: Java 8 Update 31 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83218031F0}
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
O42 - Logiciel: Logiciel d'archivage WinRAR - (...) [HKLM] -- WinRAR archiver
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: Malwarebytes Anti-Malware version 2.1.6.1022 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1
O42 - Logiciel: Mesh Runtime - (.Microsoft Corporation.) [HKLM] -- {8C6D6116-B724-4810-8F2D-D047E6B7D68E}
O42 - Logiciel: Microsoft Image Composite Editor - (.Microsoft Corporation.) [HKLM] -- {3D599ADA-65D9-4B51-898F-CE718DEC5DBB}
O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {D6F9CBDC-58B6-430A-8DD4-8F61CBC1ADF4}
O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Mozilla Firefox 37.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 37.0.2 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: PDF Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
O42 - Logiciel: PhotoShowExpress - (.Sonic Solutions.) [HKLM] -- {3250260C-7A95-4632-893B-89657EB5545B}
O42 - Logiciel: Photoshop Camera Raw - (.Adobe Systems Incorporated.) [HKLM] -- {CC75AB5C-2110-4A7F-AF52-708680D22FE8}
O42 - Logiciel: QuickSet32 - (.Dell Inc..) [HKLM] -- {C4972073-2BFE-475D-8441-564EA97DA161}
O42 - Logiciel: ResearchSoft Direct Export Helper - (...) [HKLM] -- ResearchSoft Direct Export Helper
O42 - Logiciel: Roxio Activation Module - (.Roxio.) [HKLM] -- {A121EEDE-C68F-461D-91AA-D48BA226AF1C}
O42 - Logiciel: Roxio BackOnTrack - (.Roxio.) [HKLM] -- {5A06423A-210C-49FB-950E-CB0EB8C5CEC7}
O42 - Logiciel: Roxio Burn - (.Roxio.) [HKLM] -- {9569E6BC-326A-432F-97AB-35263A327BF1}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {EF56258E-0326-48C5-A86C-3BAC26FC15DF}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}
O42 - Logiciel: Roxio Express Labeler 3 - (.Roxio.) [HKLM] -- {6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
O42 - Logiciel: Roxio File Backup - (.Roxio.) [HKLM] -- {60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}
O42 - Logiciel: Samsung Printer Live Update - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung Printer Live Update
O42 - Logiciel: Satsuki Decoder Pack - (.Satsuki Yatoshi'S Softs.) [HKLM] -- Satsuki Decoder Pack
O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701}
O42 - Logiciel: Skype(TM) 7.4 - (.Skype Technologies S.A..) [HKLM] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
O42 - Logiciel: Sonic CinePlayer Decoder Pack - (.Sonic Solutions.) [HKLM] -- {9A00EC4E-27E1-42C4-98DD-662F32AC8870}
O42 - Logiciel: Spotify - (...) [HKLM] -- Spotify
O42 - Logiciel: Spotify - (.Spotify AB.) [HKCU] -- Spotify
O42 - Logiciel: Suite Shared Configuration CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {842B4B72-9E8F-4962-B3C1-1C422A5C4434}
O42 - Logiciel: TuxGuitar 1.2 - (...) [HKLM] -- TuxGuitar_0
O42 - Logiciel: Validity Sensors DDK - (.Validity Sensors, Inc..) [HKLM] -- {9FCB6355-689E-4141-9714-3EEC2AE10292}
O42 - Logiciel: WIDCOMM Bluetooth Software - (.Broadcom Corporation.) [HKLM] -- {9E9D49A4-1DF4-4138-B7DB-5D87A893088E}
O42 - Logiciel: XnView 2.22 - (.Gougelet Pierre-e.) [HKLM] -- XnView_is1
O42 - Logiciel: Xvid 1.2.1 final uninstall - (.Xvid team (Koepi).) [HKLM] -- Xvid_is1
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {11E568E0-3244-4BCB-875E-F334269DFDCB}
O42 - Logiciel: kuler - (.Adobe Systems Incorporated.) [HKLM] -- {098727E1-775A-4450-B573-3F441F1CA243}
~ Logic: 44 Scanned in 00mn 00s
---\\ HKCU & HKLM Software Keys
[HKCU\Software\7-Zip]
[HKCU\Software\AC3Filter]
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow\Software\DigitalPersona]
[HKCU\Software\AppDataLow\Software\JavaSoft]
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Arobas Music]
[HKCU\Software\Broadcom]
[HKCU\Software\CG Information]
[HKCU\Software\Canneverbe Limited]
[HKCU\Software\Canon]
[HKCU\Software\Citrix]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\Creative Tech]
[HKCU\Software\CyberLink]
[HKCU\Software\DT Soft]
[HKCU\Software\Developer Express]
[HKCU\Software\DigitalPersona]
[HKCU\Software\Druide informatique inc.]
[HKCU\Software\ERDAS]
[HKCU\Software\ESRI]
[HKCU\Software\EasyBits]
[HKCU\Software\Eset]
[HKCU\Software\GNU]
[HKCU\Software\Gabest]
[HKCU\Software\Google]
[HKCU\Software\HKEY_LOCAL_MACHINE]
[HKCU\Software\Haali]
[HKCU\Software\Herac]
[HKCU\Software\IDAVLab]
[HKCU\Software\IDT]
[HKCU\Software\IM Providers]
[HKCU\Software\ISI ResearchSoft]
[HKCU\Software\Intel]
[HKCU\Software\JavaSoft]
[HKCU\Software\Lake]
[HKCU\Software\LogiShrd]
[HKCU\Software\MCAFEE]
[HKCU\Software\Macromedia]
[HKCU\Software\Macrovision]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Nero]
[HKCU\Software\Netscape]
[HKCU\Software\Northcode Inc]
[HKCU\Software\ODBC]
[HKCU\Software\PC-Doctor]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\RICOH]
[HKCU\Software\RealNetworks]
[HKCU\Software\RegisteredApplications]
[HKCU\Software\Roxio]
[HKCU\Software\SSPrint]
[HKCU\Software\STUDIO SARMADI]
[HKCU\Software\Samsung]
[HKCU\Software\Satsuki Decoder Pack]
[HKCU\Software\SecuROM]
[HKCU\Software\Skype]
[HKCU\Software\Synaptics]
[HKCU\Software\Trolltech]
[HKCU\Software\Widcomm]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\ZebHelpProcess Helper]
[HKLM\Software\ATI Technologies]
[HKLM\Software\Adobe]
[HKLM\Software\AdwCleaner]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\BcmSetup]
[HKLM\Software\Broadcom]
[HKLM\Software\Canneverbe Limited]
[HKLM\Software\Canon]
[HKLM\Software\Citrix]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Creative Tech]
[HKLM\Software\CyberLink]
[HKLM\Software\DT Soft]
[HKLM\Software\Debug]
[HKLM\Software\Dell Computer Corporation]
[HKLM\Software\Dell Inc.]
[HKLM\Software\Dell]
[HKLM\Software\DigitalPersona]
[HKLM\Software\Druide informatique inc.]
[HKLM\Software\ERDAS]
[HKLM\Software\ESRI]
[HKLM\Software\FreeFallProtection]
[HKLM\Software\GEAR Software]
[HKLM\Software\GNU]
[HKLM\Software\Gabest]
[HKLM\Software\Google]
[HKLM\Software\HaaliMkx]
[HKLM\Software\IDAVLab]
[HKLM\Software\IDT]
[HKLM\Software\IM Providers]
[HKLM\Software\ISI ResearchSoft]
[HKLM\Software\Imagineer Systems Ltd]
[HKLM\Software\InstalledOptions]
[HKLM\Software\Intel]
[HKLM\Software\InterVideo]
[HKLM\Software\JavaSoft]
[HKLM\Software\JreMetrics]
[HKLM\Software\Lake]
[HKLM\Software\Logishrd]
[HKLM\Software\MAXSOFT-OCRON]
[HKLM\Software\Macromedia]
[HKLM\Software\Macrovision]
[HKLM\Software\Malwarebytes' Anti-Malware (Trial)]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\ManageableUpdatePackage]
[HKLM\Software\McAfee.com]
[HKLM\Software\McAfeeInstaller]
[HKLM\Software\McAfee]
[HKLM\Software\MicroVision]
[HKLM\Software\MimarSinan]
[HKLM\Software\Mircrosoft]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Nero]
[HKLM\Software\Novell]
[HKLM\Software\ODBC]
[HKLM\Software\PC-Doctor]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\Python]
[HKLM\Software\RealNetworks]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Roxio]
[HKLM\Software\SSPrint]
[HKLM\Software\STMicroelectronics]
[HKLM\Software\Samsung]
[HKLM\Software\Skype]
[HKLM\Software\Sonic]
[HKLM\Software\Synaptics]
[HKLM\Software\Synthetic Aperture]
[HKLM\Software\Validity]
[HKLM\Software\Vantage Software Technologies]
[HKLM\Software\Volatile]
[HKLM\Software\Widcomm]
[HKLM\Software\WinRAR]
[HKLM\Software\Windows]
[HKLM\Software\Wise Solutions]
[HKLM\Software\XnView]
[HKLM\Software\illiminable]
[HKLM\Software\mozilla.org]
~ Key Software: 326 Scanned in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 23/09/2013 - 18:48:51 - [] ----D C:\Program Files\7-Zip
O43 - CFD: 14/10/2012 - 17:01:19 - [] ----D C:\Program Files\Adobe
O43 - CFD: 27/10/2012 - 13:10:03 - [] ----D C:\Program Files\Apple Software Update =>.Apple Inc
O43 - CFD: 23/09/2013 - 14:43:50 - [] ----D C:\Program Files\ArcGIS
O43 - CFD: 27/10/2012 - 13:09:43 - [] ----D C:\Program Files\Bonjour
O43 - CFD: 08/05/2015 - 11:47:02 - [] ----D C:\Program Files\CCleaner
O43 - CFD: 04/12/2011 - 23:56:37 - [] ----D C:\Program Files\CDBurnerXP
O43 - CFD: 07/01/2011 - 14:48:11 - [] ----D C:\Program Files\Cisco
O43 - CFD: 09/04/2013 - 08:24:59 - [] ----D C:\Program Files\Citrix
O43 - CFD: 10/05/2015 - 10:49:29 - [] ----D C:\Program Files\Common Files
O43 - CFD: 07/01/2011 - 14:52:12 - [] ----D C:\Program Files\Creative
O43 - CFD: 07/01/2011 - 14:51:48 - [] ----D C:\Program Files\Creative Live! Cam
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\CyberLink
O43 - CFD: 13/02/2015 - 17:07:18 - [] ----D C:\Program Files\Dell
O43 - CFD: 07/01/2011 - 14:41:47 - [] ----D C:\Program Files\Dell Inc
O43 - CFD: 01/04/2015 - 15:56:44 - [] ----D C:\Program Files\Dell Support Center
O43 - CFD: 07/01/2011 - 14:51:52 - [] ----D C:\Program Files\Dell Webcam
O43 - CFD: 07/01/2011 - 14:49:33 - [] ----D C:\Program Files\DigitalPersona
O43 - CFD: 05/10/2011 - 21:15:44 - [] ----D C:\Program Files\Druide
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\DVD Maker
O43 - CFD: 30/05/2013 - 16:35:59 - [] ----D C:\Program Files\EndNote X3
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\Program Files\Fichiers communs
O43 - CFD: 09/08/2013 - 08:30:00 - [] ----D C:\Program Files\Google
O43 - CFD: 18/09/2012 - 08:30:24 - [] ----D C:\Program Files\GUMBB52.tmp
O43 - CFD: 07/01/2011 - 07:38:05 - [] ----D C:\Program Files\IDT
O43 - CFD: 07/01/2011 - 14:51:50 - [] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 07/01/2011 - 14:43:38 - [] ----D C:\Program Files\Intel
O43 - CFD: 16/04/2015 - 07:41:45 - [] ----D C:\Program Files\Internet Explorer
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\iPod
O43 - CFD: 30/05/2014 - 17:24:54 - [] ----D C:\Program Files\IRIScan Direct
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\Program Files\iTunes
O43 - CFD: 01/02/2015 - 19:24:51 - [] ----D C:\Program Files\Java
O43 - CFD: 08/05/2015 - 12:02:05 - [] ----D C:\Program Files\Malwarebytes Anti-Malware
O43 - CFD: 19/08/2014 - 07:39:24 - [] ----D C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 15/01/2011 - 17:51:35 - [0] ----D C:\Program Files\Microsoft
O43 - CFD: 14/07/2009 - 11:00:58 - [] ----D C:\Program Files\Microsoft Games
O43 - CFD: 27/08/2012 - 21:15:59 - [] ----D C:\Program Files\Microsoft Office
O43 - CFD: 10/02/2012 - 09:38:04 - [] ----D C:\Program Files\Microsoft Research
O43 - CFD: 11/02/2015 - 20:53:43 - [] ----D C:\Program Files\Microsoft Security Client
O43 - CFD: 24/07/2014 - 17:05:44 - [] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 07/01/2011 - 15:02:44 - [] ----D C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 13/03/2011 - 22:40:16 - [] ----D C:\Program Files\Microsoft Visual Studio
O43 - CFD: 13/03/2011 - 22:37:09 - [] ----D C:\Program Files\Microsoft Visual Studio 8
O43 - CFD: 23/08/2012 - 08:17:10 - [] ----D C:\Program Files\Microsoft Works
O43 - CFD: 13/03/2011 - 22:40:04 - [] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 24/04/2015 - 12:09:10 - [] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 26/04/2015 - 08:23:34 - [] ----D C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 13/03/2011 - 22:40:20 - [] ----D C:\Program Files\MSBuild
O43 - CFD: 15/01/2011 - 23:49:59 - [0] ----D C:\Program Files\MSXML 4.0
O43 - CFD: 14/07/2009 - 06:52:30 - [] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 07/01/2011 - 14:58:04 - [] ----D C:\Program Files\Roxio
O43 - CFD: 03/03/2014 - 12:14:18 - [] ----D C:\Program Files\SamsungPrinterLiveUpdate
O43 - CFD: 03/03/2014 - 12:04:04 - [] ----D C:\Program Files\SamsungPrinterLiveUpdateInstaller
O43 - CFD: 05/02/2011 - 11:29:22 - [] ----D C:\Program Files\Satsuki Decoder Pack
O43 - CFD: 14/04/2015 - 08:03:39 - [] R---D C:\Program Files\Skype
O43 - CFD: 24/03/2015 - 20:36:20 - [] ----D C:\Program Files\Spotify
O43 - CFD: 07/01/2011 - 14:44:04 - [] ----D C:\Program Files\STMicroelectronics
O43 - CFD: 07/01/2011 - 16:33:50 - [] ----D C:\Program Files\Synaptics
O43 - CFD: 10/12/2011 - 19:15:54 - [] ----D C:\Program Files\Trend Micro
O43 - CFD: 25/03/2011 - 22:12:50 - [] ----D C:\Program Files\TuxGuitar-Jet
O43 - CFD: 14/07/2009 - 06:53:23 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 07/01/2011 - 14:45:49 - [] ----D C:\Program Files\Validity Sensors
O43 - CFD: 07/01/2011 - 14:46:46 - [] ----D C:\Program Files\WIDCOMM
O43 - CFD: 12/07/2013 - 07:57:37 - [] ----D C:\Program Files\Windows Defender
O43 - CFD: 12/07/2014 - 07:43:28 - [] ----D C:\Program Files\Windows Journal
O43 - CFD: 07/01/2011 - 15:03:04 - [] ----D C:\Program Files\Windows Live
O43 - CFD: 04/01/2012 - 19:59:00 - [] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 12/03/2015 - 04:25:28 - [] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 12/01/2011 - 13:59:10 - [] ----D C:\Program Files\Windows NT
O43 - CFD: 04/01/2012 - 19:58:58 - [] ----D C:\Program Files\Windows Photo Viewer
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Portable Devices
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\Windows Sidebar
O43 - CFD: 05/02/2011 - 12:44:37 - [] ----D C:\Program Files\WinRAR
O43 - CFD: 15/04/2014 - 08:21:40 - [] ----D C:\Program Files\XnView
O43 - CFD: 15/01/2011 - 22:02:09 - [] ----D C:\Program Files\Xvid
O43 - CFD: 12/05/2015 - 19:01:08 - [] ----D C:\Program Files\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 14/10/2012 - 17:01:28 - [] ----D C:\Program Files\Common Files\Adobe
O43 - CFD: 23/09/2013 - 14:47:09 - [] ----D C:\Program Files\Common Files\AnswerWorks 4.0
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\Common Files\Apple
O43 - CFD: 23/09/2013 - 14:46:20 - [] ----D C:\Program Files\Common Files\ArcGIS
O43 - CFD: 10/12/2011 - 19:52:01 - [] ----D C:\Program Files\Common Files\Bitdefender
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\Common Files\CyberLink
O43 - CFD: 23/09/2013 - 14:44:22 - [] ----D C:\Program Files\Common Files\Data Dynamics
O43 - CFD: 15/05/2014 - 11:50:28 - [] ----D C:\Program Files\Common Files\DESIGNER
O43 - CFD: 07/01/2011 - 14:51:35 - [] ----D C:\Program Files\Common Files\InstallShield
O43 - CFD: 01/02/2015 - 19:25:56 - [] ----D C:\Program Files\Common Files\Java
O43 - CFD: 28/02/2011 - 22:14:03 - [] ----D C:\Program Files\Common Files\Macrovision Shared
O43 - CFD: 05/02/2011 - 11:49:23 - [] ----D C:\Program Files\Common Files\mcafee
O43 - CFD: 23/08/2012 - 08:17:16 - [] ----D C:\Program Files\Common Files\microsoft shared
O43 - CFD: 07/01/2011 - 14:43:41 - [] ----D C:\Program Files\Common Files\postureAgent
O43 - CFD: 07/01/2011 - 14:58:20 - [] ----D C:\Program Files\Common Files\PX Storage Engine
O43 - CFD: 30/05/2013 - 16:36:04 - [] ----D C:\Program Files\Common Files\ResearchSoft
O43 - CFD: 23/12/2012 - 15:28:39 - [] ----D C:\Program Files\Common Files\Risxtd
O43 - CFD: 07/01/2011 - 14:58:36 - [] ----D C:\Program Files\Common Files\Roxio Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\Services
O43 - CFD: 08/10/2014 - 07:41:48 - [] ----D C:\Program Files\Common Files\Skype
O43 - CFD: 07/01/2011 - 14:58:00 - [] ----D C:\Program Files\Common Files\Sonic Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 07/01/2011 - 14:57:58 - [] ----D C:\Program Files\Common Files\SureThing Shared
O43 - CFD: 17/01/2012 - 16:46:20 - [0] ----D C:\Program Files\Common Files\SWF Studio
O43 - CFD: 04/01/2012 - 19:58:57 - [] ----D C:\Program Files\Common Files\System
O43 - CFD: 23/09/2013 - 14:44:09 - [] ----D C:\Program Files\Common Files\Tom Sawyer Software
O43 - CFD: 07/01/2011 - 14:58:54 - [] ----D C:\Program Files\Common Files\Windows Live
O43 - CFD: 30/05/2013 - 16:33:17 - [] ----D C:\Program Files\Common Files\Wise Installation Wizard
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
O43 - CFD: 30/07/2014 - 20:12:45 - [] ----D C:\ProgramData\Adobe
O43 - CFD: 28/02/201
---\\ Enumère les service demarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d'application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [475136]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d'accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d'interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d'événements système (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [523776]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2020864]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d'application.) -- C:\Windows\System32\appinfo.dll [47104]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [49664]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164864]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [71168]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [113664]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d'ordinateurs.) -- C:\Windows\System32\browser.dll [102912]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800]
~ Services: 32 Scanned in 00mn 00s
---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.825768E0D92DAD41A59BF0D16FB76F40] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.1520.bin [4248]
[MD5.946CF417E94D2C9A873D14E6FE0415A1] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2120.bin [70375]
[MD5.6236D6B734152B266EBAB93CF24E5830] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2532.bin [1698]
[MD5.5BC0BA4A5185D7B285B5F8EBE4FCB0FA] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2748.bin [456927]
[MD5.18BC0B6609141E87DE09F4C7DEA97547] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.3716.bin [4259]
[MD5.D9A90DDEBEC281317E31AAEC06FEBD48] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4140.bin [1670]
[MD5.453B258E97C86572BE40C8E28C8CB637] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4464.bin [1260]
[MD5.3F5C7469DC6A45255FA5723B270DFB56] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4664.bin [21151]
[MD5.C6E5D0B9966A3707497421164BAA017C] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4676.bin [70625]
[MD5.5999CF6DDDD5FF5F62A7DA285C5FFF3A] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4696.bin [9108]
[MD5.FAE27419C38CC9DE62F607B0FD4458D6] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.bdinstall.bin [73728]
[MD5.B76FA9566970A7E5255B0717C35B5EC9] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539329.bdinstall.bin [80408]
[MD5.33FE59A381CCF8297F7F8C38FF954D41] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539409.bdinstall.bin [90911]
~ Files: 13 Scanned in 00mn 00s
---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab
~ BCK: 18514 Scanned in 00mn 46s
---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 15/04/2015 268464 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 23/09/2013 1044816 | (FLEXnet Licensing Service) . (.Flexera Software, Inc..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Auto 22/10/2014 107912 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 22/10/2014 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 15/05/2013 553288 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SS - | Demand 24/04/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 04/09/2010 1116656 | (RoxMediaDB12OEM) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
SS - | Auto 04/09/2010 219632 | (RoxWatch12) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
SS - | Auto 18/02/2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SS - | Demand 26/08/2010 74392 | (stllssvr) . (.MicroVision Development, Inc..) - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 03/03/2009 81920 | (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 20/10/2009 595232 | (btwdins) . (.Broadcom Corporation..) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
SR - | Auto 26/02/2015 1947344 | (DellDataVault) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
SR - | Auto 26/02/2015 184016 | (DellDataVaultWiz) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
SR - | Auto 13/05/2009 322624 | (DpHost) . (.DigitalPersona, Inc..) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
SR - | Auto 04/11/2009 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 14/04/2015 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
SR - | Auto 14/04/2015 1080120 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
SR - | Auto 30/01/2015 22184 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 07/04/2010 229458 | (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
SR - | Auto 10/04/2015 19288 | (SupportAssistAgent) . (.Dell Inc..) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
SR - | Auto 04/11/2009 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 03/06/2010 1664304 | (vcsFPService) . (.Validity Sensors, Inc..) - C:\Windows\system32\vcsFPService.exe
SR - | Auto 07/01/2011 40960 | (wltrysvc) . (.Dell Inc..) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 48s
---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Run by Amaury at 12/05/2015 19:07:00
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys stdcfltn.sys ACPI.sys halmacpi.dll iaStor.sys
C:\Windows\system32\DRIVERS\stdcfltn.sys ST Microelectronics Disk Class Filter Driver for Accelerometer
C:\Windows\system32\DRIVERS\iaStor.sys Intel Corporation Intel Rapid Storage Technology driver
1 ntkrnlpa!IofCallDriver[0x83639D29] >> \Device\Harddisk0\DR0[0x88687AC8]
3 CLASSPNP[0x8BF9B59E] >> ntkrnlpa!IofCallDriver[0x83639D29] >> [0x88687020]
5 stdcfltn[0x8C1E2896] >> ntkrnlpa!IofCallDriver[0x83639D29] >> [0x86AC0A80]
7 ACPI[0x8B89C3D4] >> ntkrnlpa!IofCallDriver[0x83639D29] >> \Device\Ide\IAAStorageDevice-1[0x85D51028]
kernel: MBR read successfully
user & kernel MBR OK
~ MBR: 16 Scanned in 00mn 02s
---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by Amaury at 12/05/2015 19:07:02
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s
---\\ Scan Additionnel (O88)
Database Version : 13008 - (05/05/2015)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 41
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\7Zip Bundle by Fileparade.com] =>PUP.SweetIM^
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro^
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab^
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar^
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab^
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab^
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo^
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay^
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy^
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo^
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo^
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab^
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab^
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream^
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo^
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo^
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream^
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine^
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab^
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager^
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab^
~ Additionnel Scan: 670815 Items scanned in 00mn 34s
---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects de navigateur (O2)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
~ AMI: 5 Scanned in 00mn 00s
---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/pup-sweetim =>PUP.SweetIM
http://nicolascoolman.fr/pup-optimizerpro =>PUP.OptimizerPro
http://www.nicolascoolman.fr/blog/ =>PUP.Nosibay
http://nicolascoolman.fr/adware-onetab =>Adware.OneTab
http://nicolascoolman.fr/hijacker-findrtoolbar =>Hijacker.FindrToolbar
http://nicolascoolman.fr/hijacker-smartbar =>Hijacker.SmartBar
http://nicolascoolman.fr/pup-eorezo =>PUP.EoRezo
http://nicolascoolman.fr/pup-minibar =>PUP.Minibar
http://nicolascoolman.fr/hijacker-proxy =>Hijacker.Proxy
http://nicolascoolman.fr/adware-metastream =>Adware.MetaStream
http://nicolascoolman.fr/pup-softwareengine =>PUP.SoftwareEngine
http://nicolascoolman.fr/pup-manager =>PUP.Manager
~ MSI: 12 link(s) detected in 00mn 00s
End of the scan (1577 lines in 05mn 50s)(2.11)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d'application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [475136]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d'accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d'interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d'événements système (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [523776]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2020864]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d'application.) -- C:\Windows\System32\appinfo.dll [47104]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [49664]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164864]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [71168]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [113664]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d'ordinateurs.) -- C:\Windows\System32\browser.dll [102912]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800]
~ Services: 32 Scanned in 00mn 00s
---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.825768E0D92DAD41A59BF0D16FB76F40] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.1520.bin [4248]
[MD5.946CF417E94D2C9A873D14E6FE0415A1] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2120.bin [70375]
[MD5.6236D6B734152B266EBAB93CF24E5830] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2532.bin [1698]
[MD5.5BC0BA4A5185D7B285B5F8EBE4FCB0FA] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2748.bin [456927]
[MD5.18BC0B6609141E87DE09F4C7DEA97547] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.3716.bin [4259]
[MD5.D9A90DDEBEC281317E31AAEC06FEBD48] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4140.bin [1670]
[MD5.453B258E97C86572BE40C8E28C8CB637] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4464.bin [1260]
[MD5.3F5C7469DC6A45255FA5723B270DFB56] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4664.bin [21151]
[MD5.C6E5D0B9966A3707497421164BAA017C] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4676.bin [70625]
[MD5.5999CF6DDDD5FF5F62A7DA285C5FFF3A] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4696.bin [9108]
[MD5.FAE27419C38CC9DE62F607B0FD4458D6] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.bdinstall.bin [73728]
[MD5.B76FA9566970A7E5255B0717C35B5EC9] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539329.bdinstall.bin [80408]
[MD5.33FE59A381CCF8297F7F8C38FF954D41] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539409.bdinstall.bin [90911]
~ Files: 13 Scanned in 00mn 00s
---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab
~ BCK: 18514 Scanned in 00mn 46s
---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 15/04/2015 268464 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 23/09/2013 1044816 | (FLEXnet Licensing Service) . (.Flexera Software, Inc..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Auto 22/10/2014 107912 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 22/10/2014 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 15/05/2013 553288 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SS - | Demand 24/04/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 04/09/2010 1116656 | (RoxMediaDB12OEM) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
SS - | Auto 04/09/2010 219632 | (RoxWatch12) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
SS - | Auto 18/02/2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SS - | Demand 26/08/2010 74392 | (stllssvr) . (.MicroVision Development, Inc..) - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 03/03/2009 81920 | (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 20/10/2009 595232 | (btwdins) . (.Broadcom Corporation..) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
SR - | Auto 26/02/2015 1947344 | (DellDataVault) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
SR - | Auto 26/02/2015 184016 | (DellDataVaultWiz) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
SR - | Auto 13/05/2009 322624 | (DpHost) . (.DigitalPersona, Inc..) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
SR - | Auto 04/11/2009 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 14/04/2015 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
SR - | Auto 14/04/2015 1080120 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
SR - | Auto 30/01/2015 22184 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 07/04/2010 229458 | (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
SR - | Auto 10/04/2015 19288 | (SupportAssistAgent) . (.Dell Inc..) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
SR - | Auto 04/11/2009 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 03/06/2010 1664304 | (vcsFPService) . (.Validity Sensors, Inc..) - C:\Windows\system32\vcsFPService.exe
SR - | Auto 07/01/2011 40960 | (wltrysvc) . (.Dell Inc..) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 48s
---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Run by Amaury at 12/05/2015 19:07:00
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys stdcfltn.sys ACPI.sys halmacpi.dll iaStor.sys
C:\Windows\system32\DRIVERS\stdcfltn.sys ST Microelectronics Disk Class Filter Driver for Accelerometer
C:\Windows\system32\DRIVERS\iaStor.sys Intel Corporation Intel Rapid Storage Technology driver
1 ntkrnlpa!IofCallDriver[0x83639D29] >> \Device\Harddisk0\DR0[0x88687AC8]
3 CLASSPNP[0x8BF9B59E] >> ntkrnlpa!IofCallDriver[0x83639D29] >> [0x88687020]
5 stdcfltn[0x8C1E2896] >> ntkrnlpa!IofCallDriver[0x83639D29] >> [0x86AC0A80]
7 ACPI[0x8B89C3D4] >> ntkrnlpa!IofCallDriver[0x83639D29] >> \Device\Ide\IAAStorageDevice-1[0x85D51028]
kernel: MBR read successfully
user & kernel MBR OK
~ MBR: 16 Scanned in 00mn 02s
---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by Amaury at 12/05/2015 19:07:02
- Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s
---\\ Scan Additionnel (O88)
Database Version : 13008 - (05/05/2015)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 41
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\7Zip Bundle by Fileparade.com] =>PUP.SweetIM^
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro^
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab^
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar^
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab^
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab^
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo^
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay^
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy^
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo^
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo^
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab^
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab^
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream^
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo^
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo^
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream^
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine^
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab^
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager^
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab^
~ Additionnel Scan: 670815 Items scanned in 00mn 34s
---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects de navigateur (O2)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
~ AMI: 5 Scanned in 00mn 00s
---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/pup-sweetim =>PUP.SweetIM
http://nicolascoolman.fr/pup-optimizerpro =>PUP.OptimizerPro
http://www.nicolascoolman.fr/blog/ =>PUP.Nosibay
http://nicolascoolman.fr/adware-onetab =>Adware.OneTab
http://nicolascoolman.fr/hijacker-findrtoolbar =>Hijacker.FindrToolbar
http://nicolascoolman.fr/hijacker-smartbar =>Hijacker.SmartBar
http://nicolascoolman.fr/pup-eorezo =>PUP.EoRezo
http://nicolascoolman.fr/pup-minibar =>PUP.Minibar
http://nicolascoolman.fr/hijacker-proxy =>Hijacker.Proxy
http://nicolascoolman.fr/adware-metastream =>Adware.MetaStream
http://nicolascoolman.fr/pup-softwareengine =>PUP.SoftwareEngine
http://nicolascoolman.fr/pup-manager =>PUP.Manager
~ MSI: 12 link(s) detected in 00mn 00s
End of the scan (1577 lines in 05mn 50s)(2.11)