Aller au contenu

BXavier52

Membres
  • Compteur de contenus

    11
  • Inscription

  • Dernière visite

Autres informations

  • Votre config
    windows7 et 8, linux
  • Mes langues
    français

Visiteurs récents du profil

1 208 visualisations du profil

BXavier52's Achievements

Junior Member

Junior Member (3/12)

0

Réputation sur la communauté

  1. voici un exemple qui m'a été donné précédemment mais je ne sais pas si c'est bien le même logiciel que celui dont je suis victime : https://www.netvizor.net/
  2. le logiciel a été fourni par mon patron de l'époque, que j'ai quitté car il aimait dire : c'est beau de dire la vérité mais il faut encore pouvoir le prouver. Les recherches que j'ai faites m'ont montré qu'avec leur logiciel, il suffit de connaître l'adresse d'un ordinateur pour le surveiller.
  3. Bonjour, aujourd'hui 14 janvier 2020, je suis toujours espionné, j'ai des rapports obtenus avec wireshark. Je suis prêt à partager les dommages et intérêts que je pourrais obtenir lors d'un procès avec la personne qui saura étudier les fichiers et trouver la preuve de cet espionnage.
  4. Bonjour, j'ai toujours le même problème d'espionnage. J'ai des rapports obtenus avec wireshark. Si une personne veut bien les examiner, je suis prêt à partager avec elle les dommages et intérêts que j'obtiendrais lors d'un procès.
  5. Bonjour, Un keylogger en ligne a été installé sur mon ordinateur soit par mail soit par l'intermédiaire de fichiers que je ramenais sur une clé USB. Tout ce que je fais est épié, que ce soit sous Linux ou Windows. Il semble que ces personnes vont consulter un site internet et en plus des rapports sur les touches du clavier utilisées voient les copies d'écran qui seraient envoyées régulièrement par leur logiciel espion. J'ai besoin d'aide pour identifier leur espion et leur site, bloquer leur espionnage. J'ai déjà été dans le forum sécurité et j'ai reçu le conseil de venir ici. Note : afin d'être certain de leurs méfaits, je me suis envoyé depuis mon domicile un message d'une adresse mail personnelle à une autre adresse mail personnelle à plusieurs reprises, où je les insultais. Elles ont réagi en me menaçant de m'accuser de calomnie (à distance et pas en face bien sûr). J'ai fait d'autres vérifications depuis mon domicile et à chaque fois elles ont suivi.
  6. bonjour, il semble que grâce à ce keylogger, elle ait obtenu l'adresse ip de mon domicile et que maintenant elle me suit même si je prends une nouvelle machine. Formater ne servirait à rien, ce qu'il faut c'est trouver la "signature" de son programme sur mon ordinateur personnel, ensuite la comparer à celle de l'ordinateur au bureau et enfin porter plainte.
  7. bonjour, il n'y a rien de branché sur mon ordinateur au bureau, et tous les rapports que j'ai mis concernent mon ordinateur personnel, chez moi. Il est infecté d'ailleurs elle est au courant que j'ai fait appel à de l'aide pour mettre fin à son espionnage. KVRT ne trouve rien sur mon ordinateur, au bureau, il n'a trouvé rien également sur un ordinateur, et trois fichiers suspects sur un autre ordinateur (processhacker.sys). Je pense qu'il n'arrive pas à stopper ce keylogger. Je viens de tester eTrustPestPatrol chez moi, il trouve très vite deux méchants : NetVisor5.3 et SpyAgent6. Mais ne permet pas de les détruire dans sa version d'essai. Cliquer sur Buy now amène à une page en erreur 404 : Server Error in '/' Application.The resource cannot be found. Je fais tourner actuellement HouseCall de Trend MIcor et vous tiens au courant.
  8. bonjour, le lien pour le rapport adwcleaner est http://cjoint.com/?EDqtOD438kl pour le rapport sftgc : http://cjoint.com/?3DqtQiah9HT pour le rapport mbam : http://cjoint.com/?3DqtRvDeZ3Z j'ai malheureusement écrasé le rapport de jrt (à force de l'entendre dire qu'elle me suit à la trace y compris chez moi, je suis très stressé).
  9. bonjour, désolé pour le long rapport mais je n'ai trouvé que les boutons insérer un lien ou insérer une image. et encore une fois merci, le rapport de ZHPix : Rapport de ZHPFix 2015.3.18.4 par Nicolas Coolman, Update du 18/03/2015 Fichier d'export Registre : Run by Xavier at 09/04/2015 19:40:27 High Elevated Privileges : OK Windows 7 Business Edition, 64-bit Service Pack 1 (Build 7601) Corbeille vidée (00mn 02s) Dossier Prefetcher vidé Réparation des raccourcis navigateur ========== Logiciels ========== ABSENT Uninstall Process: c:\users\xavier\appdata\roaming\digita~1\update~1\update~1.exe ABSENT Uninstall Process: c:\users\xavier\appdata\roaming\1h1q1v1n1n1o1r\file opener packages\uninstaller.exe ABSENT Uninstall Process: c:\program files (x86)\tweaks\fileopener\uninstall.exe ========== Clés du Registre ========== SUPPRIMÉ Logiciel Key: [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Digital Sites] SUPPRIMÉ Logiciel Key: [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\File Opener Packages] SUPPRIMÉ Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Tweaks FileOpener] SUPPRIMÉ: Service: cae99edb SUPPRIMÉ: HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} SUPPRIMÉ: HKCU\Software\Super Optimizer SUPPRIMÉ: HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6 SUPPRIMÉ: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\tencentdl_RASAPI32 SUPPRIMÉ: HKLM\Software\Wow6432Node\{1146AC44-2F03-4431-B4FD-889BC837521F} Branche de Base de Registres IFEO non infectée ! ========== Valeurs du Registre ========== SUPPRIMÉ: {C508843B-FD61-4AD6-847F-0797B09F4F7F} ProxyFix : Configuration proxy supprimée avec succès SUPPRIMÉ ProxyServer Value SUPPRIMÉ ProxyEnable Value SUPPRIMÉ EnableHttp1_1 Value SUPPRIMÉ ProxyHttp1.1 Value SUPPRIMÉ ProxyOverride Value Aucune Valeur Standard Profile: FirewallRaz : Aucune Valeur Domain Profile: FirewallRaz : SUPPRIMÉ: FirewallRaz (Private) : {5F0F8171-72EC-4C74-9B67-5CFDD6B1C9E0} SUPPRIMÉ: FirewallRaz (Private) : {7CA1D337-5D16-4242-9A60-DF3A7AE7FBCA} SUPPRIMÉ: FirewallRaz (Private) : {65C8BB38-90F2-410E-BC7A-7042FC0BAC1D} SUPPRIMÉ: FirewallRaz (Private) : {4B4ACE09-3FE2-4FE8-8EF5-B8EBBA353A65} SUPPRIMÉ: FirewallRaz (Private) : {B863678E-516C-424A-82E8-BE7EAA99A7D3} SUPPRIMÉ: FirewallRaz (Private) : {42EBE49D-B7A5-4003-B57F-C506C0260B11} SUPPRIMÉ: FirewallRaz (Private) : {30BDDCBD-0785-4591-82E5-90D7531AD053} SUPPRIMÉ: FirewallRaz (Private) : {F7C027DE-079A-46BE-B4B8-DF5074F4F2B6} ========== Dossiers ========== Aucun dossiers CLSID Local utilisateur vide SUPPRIMÉS Temporaires Windows (249) SUPPRIMÉS Flash Cookies (0) ========== Fichiers ========== SUPPRIMÉ: c:\users\xavier\appdata\roaming\mozilla\firefox\profiles\ntm8v7b7.default\searchplugins\search-provided-by-yahoo.xml SUPPRIMÉ: c:\users\public\desktop\fileopener.lnk SUPPRIMÉ: c:\program files (x86)\tweaks\fileopener\fileopener.exe SUPPRIMÉ: c:\users\xavier\appdata\local\temp\supoptsetup.exe SUPPRIMÉS Temporaires Windows (1236) (1 169 699 391 octets) SUPPRIMÉS Flash Cookies (0) (0 octets) ========== Autre ========== NON TRAITÉ < NON TRAITÉ < ========== Récapitulatif ========== 10 : Clés du Registre 17 : Valeurs du Registre 3 : Dossiers 6 : Fichiers 3 : Logiciels 2 : Autre End of clean in 01mn 00s ========== Chemin de fichier rapport ========== C:\Users\Xavier\AppData\Roaming\ZHP\ZHPFix[R1].txt - 09/04/2015 19:40:30 [3351] Le rapport de ZHPCleaner : ~ ZHPCleaner v2015.4.9.162 by Nicolas Coolman (09/04/2015) ~ Run by Xavier (Administrator) (09/04/2015 19:54:29) ~ Forum : http://forum.nicolascoolman.fr ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Type : Netttoyer ~ Report : C:\Users\Xavier\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\Xavier\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) ~ Windows 7, 64-bit Service Pack 1 (Build 7601) ---\\ Service. (0) ~ Aucun élément malicieux trouvé. ---\\ Navigateur internet. (0) ~ Aucun élément malicieux trouvé. ---\\ Fichier hôte. (1) ~ Le fichier hôte est légitime. (21) ---\\ Tâche planifiée. (0) ~ Aucun élément malicieux trouvé. ---\\ Explorateur ( Dossiers, Fichiers ). (20) DEPLACÉ fichier: C:\Windows\Philips\SPC500NC\Monitor.exe [PixArt Imaging Incorporation - Registry Monitor] (Heuristic.Salus) DEPLACÉ fichier****: C:\Windows\System32\drivers\Monitor.sys [Microsoft Corporation - Monitor Driver] (Heuristic.Salus) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{0A4F02F3-B537-47D3-BB92-EB32D7A2441D} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{0BD23C06-7D77-4633-B536-A03E959969DC} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{3DE81912-9F9E-4009-B143-4BC770CF6C20} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{505D969B-9687-4326-9757-1437AB111D4C} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{7B3A88B6-B126-4B02-ABA0-A28B96161D14} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{80BFC537-B0EC-40B6-A106-368908560A9E} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{84B9E286-EA8D-4778-860D-9D9349945639} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{8A7899A0-D6FD-418B-B7EF-87760DBF94D7} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{9D10FB68-BF9B-43DE-BF6C-177CDA33E563} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{A8B38E43-0C44-4E46-B5B6-D1497DD3D5C5} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{A992837D-2411-4B7C-9B45-0E21FB99BDC8} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{B70D4D06-E867-43A6-A388-EE737DFCD983} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{BB625879-CA45-4405-9375-78B7762A3128} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{D34C3FC1-891F-49BA-8B7C-A85207A517AC} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{D3F44CB6-45D7-49BA-947D-969B077EC7FC} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{EBBCF9FE-5E38-4060-803E-71D874EC8B26} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin\{F039856A-C81E-4F43-B913-A204C79AC9C0} (Adware.Agent) DEPLACÉ dossier: C:\Windows\System32\AI_RecycleBin (Adware.Agent) ---\\ Base de Registres ( Clés, Valeurs, Données ). (3) SUPPRIMÉ donnée: HKCR\jsfile\Shell\Open\Command\\Default [bad : [js] "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"] (Broken.OpenCommand) SUPPRIMÉ valeur: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SPC500NC_Monitor [C:\Windows\Philips\SPC500NC\Monitor.exe] () SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Conduit [] (Toolbar.Conduit) ---\\ Bilan de la réparation ~ Réparation réalisée avec succès. ~ Ce navigateur est absent (Google Chrome) ~ Ce navigateur est absent (Opera Software) ---\\ Statistiques ~ Items scannés : 69510 ~ Items trouvés : 0 ~ Items réparés : 23 End of clean at 20:02:49 =================== ZHPCleaner-[R]-09042015-20_02_49.txt ZHPCleaner--09042015-19_54_12.txt
  10. bonsoir, voici le rapport ci -desssous, merci pour votre réponse. ~ Rapport de ZHPDiag v2015.4.6.36 - Nicolas Coolman (29/03/2015) ~ Lancé par Xavier (07/04/2015 18:39:49) ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ Adresse du Forum http://forum.nicolascoolman.fr ~ Traduit par Nicolas Coolman ~ Etat de la version : Version à jour. ~ Liste blanche : Désactivée par l'utilisateur ~ Elévation des Privilèges : OK ~ User Account Control (UAC): Activate by user ---\\ Navigateurs Internet MSIE: Internet Explorer v11.0.9600.17691 MFIE: Mozilla Firefox 36.0.4 (Defaut) ---\\ Informations sur les produits Windows ~ Langage: Français Windows Server License Manager Script : OK ~ Windows Operating System - Windows® 7, RETAIL channel Windows ID Activation : OK ~ Windows Partial Key : JFQBJ Windows License : OK ~ Windows Remaining Initializations Number : 4 Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK Windows 7 Professional, 64-bit Service Pack 1 (Build 7601) ---\\ Logiciels de protection du système McAfee Security Scan Plus v3.0.285.6 Windows Defender W7 (Activate) ---\\ Logiciels d'optimisation du système ---\\ Logiciels de partage PeerToPeer ---\\ Surveillance de Logiciels Adobe Flash Player 17 NPAPI Adobe Reader XI ---\\ Informations sur le système ~ Processor: Intel64 Family 6 Model 15 Stepping 11, GenuineIntel ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 3326 MB (58% free) System Restore: Activé (Enable) System drive C: has 165 GB (67%) free of 244 GB ---\\ Mode de connexion au système ~ Computer Name: VOSTRO400 ~ User Name: Xavier ~ All Users Names: Xavier, Jean, HomeGroupUser$, Administrateur, ~ Unselected Option: None Logged in as Administrator ---\\ Variables d'environnement ~ System Unit : C:\ ~ %AppZHP% : C:\Users\Xavier\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\Xavier\AppData\Roaming\ ~ %Desktop% : C:\Users\Xavier\Desktop\ ~ %Favorites% : C:\Users\Xavier\Favorites\ ~ %LocalAppData% : C:\Users\Xavier\AppData\Local\ ~ %StartMenu% : C:\Users\Xavier\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumération des unités disques C: Hard drive, Flash drive, Thumb drive (Free 165 Go of 244 Go) D: Hard drive, Flash drive, Thumb drive (Free 189 Go of 244 Go) E: Hard drive, Flash drive, Thumb drive (Free 239 Go of 244 Go) F: CD-ROM drive (Not Inserted) G: CD-ROM drive (Not Inserted) J: Floppy drive, Flash card reader, USB Key (Not Inserted) K: Floppy drive, Flash card reader, USB Key (Not Inserted) L: Floppy drive, Flash card reader, USB Key (Not Inserted) M: Floppy drive, Flash card reader, USB Key (Not Inserted) ---\\ Etat du Centre de Sécurité Windows [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowMyGames: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ~ Security Center: 41 Scanned in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808] [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024] [MD5.36F99BD8A0F09BDBB7850A138845A014] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.20/02/2015 - 02:28:25.) -- C:\Windows\System32\wininet.dll [2358784] [MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.17/07/2014 - 03:07:24.) -- C:\Windows\System32\Winlogon.exe [455168] [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448] [MD5.FA886682CFC5D36718D3E436AACF10B9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:45:52.) -- C:\Windows\system32\Drivers\AFD.sys [497152] [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128] [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160] [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456] [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400] [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368] [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472] [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224] [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208] [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632] [MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:37:55.) -- C:\Windows\system32\Drivers\ntfs.sys [1684928] [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280] [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536] [MD5.1B6163C503398B23FF8B939C67747683] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.20/11/2010 - 12:06:41.) -- C:\Windows\system32\Drivers\rdpdr.sys [165888] [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184] [MD5.70988118145F5F10EF24720B97F35F65] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:46:26.) -- C:\Windows\system32\Drivers\tdx.sys [119296] [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808] ~ Generic Processes: Scanned in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 1/319 ~ Mes musiques (My Musics) : 1/3 ~ Mes Videos (My Videos) : 1/5 ~ Mes Favoris (My Favorites) : 1/26 ~ Mes Documents (My Documents) : 1/9878 ~ Mon Bureau (My Desktop) : 1/17 ~ Menu demarrer (Programs) : 1/25 ~ Hidden Files: Scanned in 00mn 07s ---\\ Processus lancés [MD5.4AEE8446E8A922EC25C9300A766AC38A] - (.Hewlett-Packard Company - Pas de description.) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128] [PID.3684] [MD5.A2C1288BD3DEDE03B2327E5972678C2E] - (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe [271808] [PID.3920] [MD5.E96DD1ABAC2BE889CF521EA2192BFD1D] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8196608] [PID.4684] [MD5.C1342DDE1D9D33B670DC91F146AFEBAA] - (.Emsisoft GmbH - Online Armor Component.) -- C:\Program Files (x86)\Online Armor\OAcat.exe [584864] [PID.1312] [MD5.FC5B75CA6A1DA31EDD4F8D53F5540B98] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [81088] [PID.1692] [MD5.58FBDA10FC403CF9F82ABD0A68129BA3] - (.ESET - ESET Service.) -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1349576] [PID.1768] [MD5.0BBA0B66C14AE56FCB516062395DE0B4] - (.Nuance Communications, Inc. - PDFPROFILTSRV.EXE.) -- C:\Program Files (x86)\Nuance\PDF Professional 8\PDFProFiltSrv.exe [135056] [PID.1892] [MD5.B8DA594F2ADE8B7AE8647D30213344FA] - (.Zemana Ltd. - Zemana AntiMalware.) -- C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [10340720] [PID.1300] [MD5.C245E08EC469A52A622EFDC9787A0DCC] - (.Adobe Systems Incorporated - Adobe Photoshop Elements 10.0 (component).) -- C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624] [PID.4924] [MD5.ADA0C09E8AEDC17F11D8E1731986A88A] - (.Hewlett-Packard Company - LightScribe Service.) -- C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728] [PID.3164] [MD5.51138BEEA3E2C21EC44D0932C71762A8] - (...) -- ysWOW64\rundll32.exe [0] [PID.3520] ~ Processes Running: Scanned in 00mn 00s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Users\Xavier\AppData\Roaming\Mozilla\Firefox\Profiles\ntm8v7b7.default\prefs.js M3 - MFPP: Plugins - [Xavier] -- C:\Users\Xavier\AppData\Roaming\Mozilla\Firefox\Profiles\ntm8v7b7.default\searchplugins\duckduckgo-html.xml M3 - MFPP: Plugins - [Xavier] -- C:\Users\Xavier\AppData\Roaming\Mozilla\Firefox\Profiles\ntm8v7b7.default\searchplugins\duckduckgo.xml M3 - MFPP: Plugins - [Xavier] -- C:\Users\Xavier\AppData\Roaming\Mozilla\Firefox\Profiles\ntm8v7b7.default\searchplugins\search-provided-by-yahoo.xml =>PUP.Optional M0 - MFSP: prefs.js [Xavier - ntm8v7b7.default] http://fr.yhs4.search.yahoo.comz0EtCzzzy0F0ByDyEtDyByC2QtN0A0LzutB%26cr%3D1291938040%26a%3Dwny_ggfc_15_15%26os%3DWindows 7 Professional M2 - MFEP: prefs.js [Xavier - ntm8v7b7.default\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}] [] Garmin Communicator v4.2.0.0 (..) M2 - MFEP: Extension [Xavier - ntm8v7b7.default] {1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi M2 - MFEP: Extension [Xavier - ntm8v7b7.default] {410b6160-ff00-11dc-95ff-0800200c9a66}.xpi M2 - MFEP: Extension [Xavier - ntm8v7b7.default] {5514CFC3-D9A8-4f1a-8DF1-930EBFB59901}.xpi M2 - MFEP: Extension [Xavier - ntm8v7b7.default] {c151d79e-e61b-4a90-a887-5a46d38fba99}.xpi P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll P2 - FPN: [HKLM] [@microsoft.com/OfficeAuthz,version=14.0] - (.Microsoft Corporation - Office Authorization plug-in for NPAPI browsers.) -- C:\Program Files\Microsoft Office\Office14\NPAUTHZ.dll P2 - FPN: [HKLM] [adobe.com/AdobeAAMDetect] - (.Adobe Systems - A plugin to detect whether the Adobe Application Manager is installed.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll P2 - FPN: [HKLM] [adobe.com/AdobeExManDetect] - (.Adobe Systems - A plugin to detect whether the Adobe Extension Manager is installed on.) -- C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll ~ Firefox Browser: 14 Scanned in 00mn 00s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.yhs4.search.yahoo.comzzzy0F0ByDyEtDyByC2QtN0A0LzutB%26cr%3D1291938040%26a%3Dwny_ggfc_15_15%26os%3DWindows 7 Professional R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.9600.17631 (winblue_r7.150111-1500)) -- C:\Windows\SysWOW64\ieframe.dll R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1 ~ IE Browser: 17 Scanned in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=c:\windows\system32\userinit.exe F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Hosts file redirection (O1) ~ Le fichier hôte est sain (The hosts file is clean) (21) ~ Hosts File: Scanned in 00mn 00s ---\\ Browser Helper Objects de navigateur (O2) O2 - BHO: PlusIEEventHelper Class [64Bits] - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} . (.Zeon Corporation - PlusIEContextMenu.dll.) -- C:\Program Files (x86)\Nuance\PDF Professional 8\Bin\PlusIEContextMenu.dll O2 - BHO: Java Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java Platform SE binary.) -- C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll O2 - BHO: Logitech SetPoint [64Bits] - {AF949550-9094-4807-95EC-D1C317803333} . (.Logitech, Inc. - Logitech SetPoint.) -- C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.dll O2 - BHO: Gaaiho PDF Conversion Toolbar Helper [64Bits] - {C7DA0384-42AA-428c-B832-88AC343DE1A8} . (.Zeon Corporation - ZeonIEFavClient.dll.) -- C:\Program Files (x86)\Nuance\PDF Professional 8\bin\GZeonIEFavClient.dll O2 - BHO: Java Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java Platform SE binary.) -- C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll ~ BHO: 8 Scanned in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\Desktop [Public]: FileOpener.lnk . (...) -- C:\Program Files (x86)\Tweaks\FileOpener\fileopener.exe =>Adware.InstallCore O4 - GS\Desktop [Xavier]: Super Optimizer.lnk . (...) -- C:\Program Files (x86)\Super Optimizer\SuperOptimizer.exe (.not file.) =>PUP.SuperOptimizer ~ Global Startup: 2 Scanned in 00mn 02s ---\\ Applications lancées au démarrage du système (O4) O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe =>.Adobe Systems Incorporated O4 - HKLM\..\Run: [egui] . (.ESET - ESET Main GUI.) -- C:\Program Files\ESET\ESET Smart Security\egui.exe O4 - HKLM\..\Run: [igfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [Zemana AntiMalware] . (.Zemana Ltd. - Zemana AntiMalware.) -- C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe O4 - HKLM\..\Run: [sPC500NC_Monitor] . (.PixArt Imaging Incorporation - Registry Monitor.) -- C:\Windows\Philips\SPC500NC\Monitor.exe O4 - HKLM\..\Run: [EvtMgr6] . (.Logitech, Inc. - Logitech SetPoint Event Manager (UNICODE).) -- C:\Program Files\Logitech\SetPointP\SetPoint.exe O4 - HKLM\..\Run: [@OnlineArmor GUI] . (.Emsisoft GmbH - Online Armor Component.) -- C:\Program Files (x86)\Online Armor\oaui.exe O4 - HKCU\..\Run: [HP Photosmart 5520 series (NET)] . (.Hewlett-Packard Co. - ScanToPCActivationApp.) -- C:\Program Files\HP\HP Photosmart 5520 series\Bin\ScanToPCActivationApp.exe =>.Hewlett-Packard Co O4 - HKCU\..\Run: [LightScribe Control Panel] . (.Hewlett-Packard Company - Pas de description.) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe O4 - HKCU\..\Run: [CAHeadless] . (.Adobe Systems Incorporated - ElementsAutoAnalyzer.) -- C:\Program Files (x86)\Adobe\Elements 10 Organizer\CAHeadless\ElementsAutoAnalyzer.exe O4 - HKCU\..\Run: [super Optimizer] . (.SUPER PC TOOLS LIMITED - Super Optimizer Launcher.) -- C:\Program Files (x86)\Super Optimizer\SupOptLauncher.exe =>PUP.SuperOptimizer O4 - HKCU\..\RunOnce: [DigitalSites] . (...) -- C:\Users\Xavier\AppData\Roaming\DigitalSites\UpdateProc\bkup.dat =>Hijacker.DSite O4 - HKLM\..\Wow6432Node\Run: [iSUSPM] . (.Flexera Software LLC. - Common Software Manager.) -- C:\ProgramData\FLEXnet\Connect\11\isuspm.exe O4 - HKLM\..\Wow6432Node\Run: [RIMBBLaunchAgent.exe] . (.BlackBerry Limited - Launch Agent Service.) -- C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe O4 - HKLM\..\Wow6432Node\Run: [RIM PeerManager] . (.Research In Motion Limited - BlackBerry Link Peer Manager.) -- C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\PeerManager.exe O4 - HKLM\..\Wow6432Node\Run: [CompeGPSDev] Clé orpheline O4 - HKLM\..\Wow6432Node\Run: [Raptr] . (.Raptr, Inc - Raptr Desktop App.) -- C:\Program Files (x86)\Raptr\raptrstub.exe O4 - HKLM\..\Wow6432Node\Run: [startCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe =>.Advanced Micro Devices, Inc O4 - HKLM\..\Wow6432Node\Run: [ZALFree] . (.Zemana Ltd. - Zemana AntiLogger Free.) -- C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe O4 - HKLM\..\Wow6432Node\Run: [HP Software Update] . (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe =>.Hewlett-Packard Co O4 - HKLM\..\Wow6432Node\Run: [sunJavaUpdateSched] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle Corporation O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated O4 - HKLM\..\Wow6432Node\Run: [Nuance PDF Converter Professional 8-reminder] . (.Nuance Communications, Inc. - Ereg (Unicode version).) -- C:\Program Files (x86)\Nuance\PDF Professional 8\Ereg\Ereg.exe O4 - HKLM\..\Wow6432Node\Run: [AdobeCS6ServiceManager] . (.Adobe Systems Incorporated - Adobe CS6 Service Manager.) -- C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe O4 - HKLM\..\Wow6432Node\Run: [PDFProHook] . (.Nuance Communications, Inc. - PdfPro8Hook.exe.) -- C:\Program Files (x86)\Nuance\PDF Professional 8\pdfpro8hook.exe O4 - HKLM\..\Wow6432Node\Run: [PDF8 Registry Controller] . (.Nuance Communications, Inc. - REGISTRYCONTROLLER.EXE.) -- C:\Program Files (x86)\Nuance\PDF Professional 8\RegistryController.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\Run: [sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation O4 - HKUS\.DEFAULT\..\RunOnce: [sPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-18\..\RunOnce: [sPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-2707899105-3410696614-3828018765-1001\..\Run: [HP Photosmart 5520 series (NET)] . (.Hewlett-Packard Co. - ScanToPCActivationApp.) -- C:\Program Files\HP\HP Photosmart 5520 series\Bin\ScanToPCActivationApp.exe =>.Hewlett-Packard Co O4 - HKUS\S-1-5-21-2707899105-3410696614-3828018765-1001\..\Run: [LightScribe Control Panel] . (.Hewlett-Packard Company - Pas de description.) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe O4 - HKUS\S-1-5-21-2707899105-3410696614-3828018765-1001\..\Run: [CAHeadless] . (.Adobe Systems Incorporated - ElementsAutoAnalyzer.) -- C:\Program Files (x86)\Adobe\Elements 10 Organizer\CAHeadless\ElementsAutoAnalyzer.exe O4 - HKUS\S-1-5-21-2707899105-3410696614-3828018765-1001\..\Run: [super Optimizer] . (.SUPER PC TOOLS LIMITED - Super Optimizer Launcher.) -- C:\Program Files (x86)\Super Optimizer\SupOptLauncher.exe =>PUP.SuperOptimizer O4 - HKUS\S-1-5-21-2707899105-3410696614-3828018765-1001\..\RunOnce: [DigitalSites] . (...) -- C:\Users\Xavier\AppData\Roaming\DigitalSites\UpdateProc\bkup.dat =>Hijacker.DSite ~ Application: Scanned in 00mn 00s ---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5) O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no ~ IE Control Panel: 1 Scanned in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: &Envoyer à OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files (x86)\MICROS~2\Office14\ONBttnIE.dll =>.Microsoft Corporation O9 - Extra button: Notes &liées OneNote [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files (x86)\MICROS~2\Office14\ONBTTN~1.dll =>.Microsoft Corporation ~ IE Extra Buttons: Scanned in 00mn 00s ---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll ~ Winsock: 6 Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{877691C8-3335-4518-9A29-3E1B9E9CC6F6}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{877691C8-3335-4518-9A29-3E1B9E9CC6F6}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{877691C8-3335-4518-9A29-3E1B9E9CC6F6}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll O20 - Winlogon Notify: LBTWlgn . (.Logitech, Inc. - Logitech Bluetooth Service.) -- c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll ~ Winlogon: Scanned in 00mn 00s ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. ~ SSODL: 1 Scanned in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: Adobe Active File Monitor V10 (AdobeActiveFileMonitor10.0) . (.Adobe Systems Incorporated - Adobe Photoshop Elements 10.0 (component).) - C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe =>.Adobe Systems Incorporated O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: SuperOptimizer Stats (cae99edb) . (...) - c:\Program Files (x86)\Super Optimizer\SupOptStats.dll =>PUP.SuperOptimizer O23 - Service: ESET Service (ekrn) . (.ESET - ESET Service.) - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) . (.Hewlett-Packard Company - LightScribe Service.) - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe O23 - Service: Online Armor Helper Service (OAcat) . (.Emsisoft GmbH - Online Armor Component.) - C:\Program Files (x86)\Online Armor\OAcat.exe O23 - Service: PDFProFiltSrv (PDFProFiltSrv) . (.Nuance Communications, Inc. - PDFPROFILTSRV.EXE.) - C:\Program Files (x86)\Nuance\PDF Professional 8\PDFProFiltSrv.exe O23 - Service: BlackBerry Link Communication Manager (RIM Tunnel Service) . (.Research In Motion Limited - BlackBerry Link Communication Manager.) - C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe O23 - Service: Online Armor (SvcOnlineArmor) . (.Emsisoft GmbH - Online Armor Component.) - C:\Program Files (x86)\Online Armor\oasrv.exe O23 - Service: ZAM Controller Service (ZAMSvc) . (.Zemana Ltd. - Zemana AntiMalware.) - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe ~ Services: 10 Scanned in 00mn 05s ---\\ Enumération Active Desktop & MHTML Editor (O24) O24 - Default MHTML Editor: Last - .(...) - (.not file.) ~ Desktop Component: 4 Scanned in 00mn 00s ---\\ Enumère les données de BootExecute (BEX) (O34) O34 - HKLM BootExecute: (autocheck autochk *) - File not found ~ BEX: 1 Scanned in 00mn 00s ---\\ Tâches planifiées en automatique (O39) [MD5.3E04F1E482357B1FC8B088197C3D9FF8] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152] [MD5.B0FE8D243A4EC6727D7EC5019C4B26B1] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [268464] [MD5.320681DF28D82CDCA7E3EED0846625DB] [APT] [AdobeAAMUpdater-1.0-Vostro400-Xavier] (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904] [MD5.8C00F21245E7BD211BE8149046BB427B] [APT] [super Optimizer Schedule] (.SUPER PC TOOLS LIMITED.) -- C:\Program Files (x86)\Super Optimizer\SupOptLauncher.exe [676912] =>PUP.SuperOptimizer [MD5.BC5BA6E67A12249B65D7B28D495BD85B] [APT] [{0E02B814-6569-4BA9-AB97-1D6021E2F12B}] (...) -- C:\Program Files (x86)\CartoExploreur\CartoExploreur.exe [1904640] [MD5.00000000000000000000000000000000] [APT] [{1B46E4E4-E753-4438-A70E-3F519C9F6212}] (...) -- F:\AUTORUN.exe (.not file.) [0] [MD5.F551BFB265A7D8B5CE4E009D4DE48F7A] [APT] [{386BC34D-1AA5-4249-8BAC-D0B723CFEB98}] (...) -- C:\Program Files (x86)\UltraCover\Uninstal.exe [74970] [MD5.C155A13687144076286989EF078112C2] [APT] [{50FE4D0D-72AF-43CC-A740-14F45DA5A8FB}] (.Nicolas Coolman.) -- C:\Program Files (x86)\ZHPDiag\ZHPhep.exe [1917440] [MD5.3E03160FED07E178F905B5B2FC6438CB] [APT] [{79515168-A5C2-4F16-B1C9-004A2E28A215}] (.Nicolas Coolman.) -- C:\Users\Xavier\Downloads\ZHPDiag2.exe [6877287] [MD5.00000000000000000000000000000000] [APT] [{B790FD8E-C378-4535-99E4-1FB5EAF72527}] (...) -- C:\Program Files (x86)\Vsoft\Imprim'Covers\IC2.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{D2AD2C93-964A-4C3C-9854-0A52A297E968}] (...) -- C:\Program Files (x86)\Vsoft\Imprim'Covers\IC2.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{F17B2755-57C5-4F69-BECB-A587DC47E7D9}] (...) -- C:\Program Files (x86)\Vsoft\Imprim'Covers\IC2.exe (.not file.) [0] O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002] O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002] ~ Scheduled Task: 13 Scanned in 00mn 01s ---\\ Composants installés (ActiveSetup Installed Components) (O40) O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll O40 - ASIC: Internet Explorer [64Bits] - {2D46B6DC-2207-486B-B523-A557E6D54B47} . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\system32\cmd.exe =>.Microsoft Corporation O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe =>.Microsoft Corporation O40 - ASIC: Browsing Enhancements [64Bits] - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation O40 - ASIC: Windows Desktop Update [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll ~ Active Setup: 10 Scanned in 00mn 00s ---\\ Pilotes lancés au démarrage du système (O41) O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys O41 - Driver: C:\Windows\System32\cscsvc.dll (CSC) . (.Microsoft Corporation - Windows Client Side Caching Driver.) - C:\Windows\System32\drivers\csc.sys O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys O41 - Driver: (eamonm) . (.ESET - Amon monitor.) - C:\Windows\System32\DRIVERS\eamonm.sys O41 - Driver: (ehdrv) . (.ESET - ESET Helper driver.) - C:\Windows\System32\DRIVERS\ehdrv.sys O41 - Driver: (EpfwLWF) . (.ESET - Epfw NDIS LightWeight Filter.) - C:\Windows\System32\DRIVERS\EpfwLWF.sys O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys O41 - Driver: (OADevice) . (...) - C:\Windows\sysWow64\Drivers\OADriver.sys O41 - Driver: (oahlpXX) . (...) - C:\Windows\syswow64\drivers\oahlp64.sys O41 - Driver: (OAmon) . (.Emsisoft - TDI Helper Driver.) - C:\Windows\sysWOW64\Drivers\OAmon.sys O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys O41 - Driver: (ZAM) . (.Zemana Ltd. - Zemana AntiMalware.) - C:\Windows\system32\drivers\zam64.sys ~ Drivers: 81 Scanned in 00mn 00s ---\\ Logiciels installés (O42) O42 - Logiciel: 7-Zip 9.20 (x64 edition) - (.Igor Pavlov.) [HKLM][64Bits] -- {23170F69-40C1-2702-0920-000001000000} O42 - Logiciel: AMD Accelerated Video Transcoding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {1D1CB210-D05E-5BF4-F998-2B1903EE4323} O42 - Logiciel: AMD Catalyst Install Manager - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {F2A7CE36-57BF-5C86-952D-90DBF3746D82} O42 - Logiciel: AMD Drag and Drop Transcoding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {1664D45E-FA92-8C52-92E9-E8ADB04A18ED} O42 - Logiciel: AMD Wireless Display v3.0 - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {0A2E1907-D0DE-0D01-CA64-CB0AB0BFE539} O42 - Logiciel: AMD Wireless Display v3.0 - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {426582A8-202F-D13C-8BD5-F00551BAFC93} O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {FE23D063-934D-4829-A0D8-00634CE79B4A} O42 - Logiciel: Adobe Dreamweaver CS6 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {A4ED5E53-7AA0-11E1-BF04-B2D4D4A5360E} O42 - Logiciel: Adobe Flash Player 16 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Flash Player 17 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI O42 - Logiciel: Adobe Help Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 O42 - Logiciel: Adobe Help Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AF37176A-78CA-545B-34EF-8B6A21514DD1} O42 - Logiciel: Adobe Premiere Elements 10 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- PremElem100 =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {26F481C6-8DBE-4F8B-9D8D-715081C23ADE} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 Content - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Premiere Elements 10 Content =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 Content - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {9C8D1290-0A4C-446C-AD86-0590812660CC} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 Content 1 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Premiere Elements 10 Content 1 =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 Content 1 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {340C0246-975B-420F-8ADD-DEA69B16FDEE} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 Content 2 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Premiere Elements 10 Content 2 =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 Content 2 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {D66A42BA-3747-4628-9CE4-9E7C18C3ED95} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 Content 3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Premiere Elements 10 Content 3 =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 Content 3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {99C7D73D-E201-4D03-B8A4-5EDBA529B505} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 HD Content 1 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Premiere Elements 10 HD Content 1 =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 HD Content 1 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {5D037ECA-B00A-466F-848C-D21B4DB69DEA} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 HD Content 2 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Premiere Elements 10 HD Content 2 =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 HD Content 2 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {D1CE6204-061A-43B5-830F-6A8A35C4E0C6} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 HD Content 3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Premiere Elements 10 HD Content 3 =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Premiere Elements 10 HD Content 3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {4F29521F-7338-4D15-8691-8FEEB987780C} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Reader XI (11.0.10) - Français - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1036-7B44-AB0000000001} O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001802114130} O42 - Logiciel: Adobe Widget Browser - (.Adobe Systems Incorporated..) [HKLM][64Bits] -- com.adobe.WidgetBrowser O42 - Logiciel: Adobe Widget Browser - (.Adobe Systems Incorporated..) [HKLM][64Bits] -- {EFBE6DD5-B224-96E5-72B9-68D328CB12A6} O42 - Logiciel: Advanced Port Scanner v1.3 - (...) [HKLM][64Bits] -- Advanced Port Scanner v1.3 O42 - Logiciel: AntiLogger Free version 1.8.2.198 - (.Zemana Ltd..) [HKLM][64Bits] -- {A80DB23D-0618-405B-89D9-28F99814E287}_is1 O42 - Logiciel: BB10 WebWorks SDK - (.BlackBerry Limited.) [HKLM][64Bits] -- BB10 WebWorks SDK O42 - Logiciel: BlackBerry Link - (.BlackBerry Ltd..) [HKLM][64Bits] -- BlackBerry_10_Desktop O42 - Logiciel: BlackBerry Link - (.BlackBerry Ltd..) [HKLM][64Bits] -- {BFCCD594-EC47-4485-B3E8-DC38316A09DD} O42 - Logiciel: CDBurnerXP - (.CDBurnerXP.) [HKLM][64Bits] -- {7E265513-8CDA-4631-B696-F40D983F3B07}_is1 O42 - Logiciel: CartoExploreur - (...) [HKLM][64Bits] -- CartoExploreur O42 - Logiciel: CartoExploreur 3 3.20 - (.Bayo.) [HKLM][64Bits] -- CartoExploreur 3_is1 O42 - Logiciel: Catalyst Control Center - Branding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {11087D24-567D-7D88-69C6-D7A08B5F4C47} O42 - Logiciel: CompeGPS LAND 7.7.0 - (.CompeGPS TEAM, S.L..) [HKLM][64Bits] -- CompeGPS_is1 O42 - Logiciel: CompeGPSDownloader version 1.21 - (.CompeGPS TEAM, S.L..) [HKLM][64Bits] -- CompeGPSDownloader_is1 O42 - Logiciel: ESET Smart Security - (.ESET, spol s r. o..) [HKLM][64Bits] -- {704355EB-2F26-4E8A-8CD2-88061763C7E2} O42 - Logiciel: Extended Update - (.Extended Update.) [HKCU][64Bits] -- Digital Sites =>PUP.Dealply O42 - Logiciel: FastStone Image Viewer 4.8 - (.FastStone Soft.) [HKLM][64Bits] -- FastStone Image Viewer O42 - Logiciel: File Opener Packages - (...) [HKCU][64Bits] -- File Opener Packages =>Adware.InstallCore O42 - Logiciel: FileOpener - (.Tweaks.) [HKLM][64Bits] -- Tweaks FileOpener =>Adware.InstallCore O42 - Logiciel: FileZilla Client 3.9.0.5 - (.Tim Kosse.) [HKLM][64Bits] -- FileZilla Client O42 - Logiciel: GIGABYTE OC_GURU II - (.GIGABYTE Technology Co.,Ltd..) [HKLM][64Bits] -- InstallShield_{EA298EC1-2B8F-4DA9-8C5B-BC1FCBBAD72F} O42 - Logiciel: GIMP 2.8.14 - (.The GIMP Team.) [HKLM][64Bits] -- GIMP-2_is1 O42 - Logiciel: GPL Ghostscript - (.Artifex Software Inc..) [HKLM][64Bits] -- GPL Ghostscript 9.09 O42 - Logiciel: Garmin USB Drivers - (.Garmin Ltd or its subsidiaries.) [HKLM][64Bits] -- {3D5D6CFC-3097-425A-8D8F-7EAF5D57641D} O42 - Logiciel: Garmin WebUpdater - (.Garmin Ltd or its subsidiaries.) [HKLM][64Bits] -- {AE1EC58E-B2AC-4959-A4C2-C38202A25239} O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} O42 - Logiciel: HP Photo Creations - (.HP Photo Creations Powered by RocketLife.) [HKLM][64Bits] -- HP Photo Creations O42 - Logiciel: HP Photosmart 5520 series Aide - (.Hewlett Packard.) [HKLM][64Bits] -- {CB08AF0F-D14B-4570-83CD-2567CE63CC5F} =>.Hewlett-Packard Co O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM][64Bits] -- {6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5} O42 - Logiciel: ImageScanTool V2.0.2 - (.Nom de votre société.) [HKLM][64Bits] -- {F0ACDDA3-1DC3-43C0-84E6-43E927C3E2F7} O42 - Logiciel: InPixio Photo Clip Professional - (.Micro Application.) [HKLM][64Bits] -- {61CDE0F2-8BEC-475F-90E8-D700C2FAE1EF} O42 - Logiciel: Inkscape 0.48.4 - (...) [HKLM][64Bits] -- Inkscape O42 - Logiciel: Intel® Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM][64Bits] -- HDMI O42 - Logiciel: Java 8 Update 31 - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83218031F0} O42 - Logiciel: LauncherMA - (.Micro Application.) [HKLM][64Bits] -- {C06EFB22-B5DB-46C5-9215-BCB5C19C0858} O42 - Logiciel: LibreOffice 4.1 Help Pack (French) - (.The Document Foundation.) [HKLM][64Bits] -- {587DB54D-A5D6-40D0-ABA5-C9969F8F245E} O42 - Logiciel: LibreOffice 4.1.5.3 - (.The Document Foundation.) [HKLM][64Bits] -- {E77773E5-944A-453F-97F3-46767AE0A253} O42 - Logiciel: LightScribe Applications - (.LightScribe.) [HKLM][64Bits] -- {16F5ADDD-6EFD-411A-9013-8DD2C629FE53} O42 - Logiciel: LightScribe System Software - (.LightScribe.) [HKLM][64Bits] -- {F132000C-1CBA-458F-BF2F-FD43D59410F9} O42 - Logiciel: LightScribe Template Labeler - (.LightScribe.) [HKLM][64Bits] -- {8A03241E-7A3C-401D-B0CE-B3096F50AE6F} O42 - Logiciel: Logiciel de base du périphérique HP Photosmart 5520 series - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {AE156AE1-BE7E-4B6D-A77C-0B9CA0C0E59C} =>.Hewlett-Packard Co O42 - Logiciel: Logitech SetPoint 6.52 - (.Logitech.) [HKLM][64Bits] -- sp6 O42 - Logiciel: MFCDLL Shared Library - Retail Version - (.Unknown.) [HKLM][64Bits] -- {51D569E2-8A28-11D2-B962-006097C4DE24} O42 - Logiciel: MSXML 3.0 - (.Microsoft Corporation.) [HKLM][64Bits] -- {930E3A4D-70B7-4D0D-AF8D-0B351A9B55BE} O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM][64Bits] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71} O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM][64Bits] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC} O42 - Logiciel: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM][64Bits] -- McAfee Security Scan O42 - Logiciel: Memory-Map European Edition - (.Memory-Map.) [HKLM][64Bits] -- {3724743C-C279-4ACA-A451-56479745208A} O42 - Logiciel: Memory-Map Navigator - (.Memory-Map, Inc..) [HKLM][64Bits] -- {94F756A3-32CB-483A-8174-400C0A3124A1} O42 - Logiciel: Micro Application SWF Easy - (.SourceTec Software Co., LTD.) [HKLM][64Bits] -- {C8F4800F-52F4-4115-BE64-FF1C23604E87}_is1 O42 - Logiciel: Microsoft ® C Runtime Library - (.Unknown.) [HKLM][64Bits] -- {51D569E0-8A28-11D2-B962-006097C4DE24} O42 - Logiciel: Microsoft ® C++ Runtime Library - (.Unknown.) [HKLM][64Bits] -- {51D569E3-8A28-11D2-B962-006097C4DE24} O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} O42 - Logiciel: Momentics IDE 2.0 for BlackBerry - (.BlackBerry Limited.) [HKLM][64Bits] -- {3868BD79-4108-4DFD-837E-81C0CBEA3584} O42 - Logiciel: Mozilla Firefox 36.0.4 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 36.0.4 (x86 fr) O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService O42 - Logiciel: Mozilla Thunderbird 31.1.2 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Thunderbird 31.1.2 (x86 fr) =>.Mozilla Corporation O42 - Logiciel: Nuance PDF Converter Professional 8 - (.Nuance Communications, Inc..) [HKLM][64Bits] -- {E645E501-5E3D-4DA2-9A47-BDC0C8A74336} O42 - Logiciel: Nuance PDF Converter Professional 8 Update x64 - (.Nuance Communications, Inc..) [HKLM][64Bits] -- {45AE5880-34A1-4575-92A6-11D0DC182F24} O42 - Logiciel: OgcDrv 2.13 - (.Bayo.) [HKLM][64Bits] -- OgcDrv_is1 O42 - Logiciel: Online Armor 7.0 - (.Emsisoft GmbH.) [HKLM][64Bits] -- OnlineArmor_is1 O42 - Logiciel: OpenConcerto version 1.3.2 - (.ILM Informatique.) [HKLM][64Bits] -- {B67942FB-16E0-40C0-B0DC-D91B3589278B}_is1 O42 - Logiciel: Oxemis Video Library - (.Oxemis.) [HKLM][64Bits] -- {26FA9805-3EF5-4769-A19A-C0C8BAFB93EA} O42 - Logiciel: PRE10STI64Installer - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {9F06F464-479A-403E-AF92-70CBB8D674A1} O42 - Logiciel: PhotoMizer - (.Engelmann Media GmbH.) [HKLM][64Bits] -- {A00F8237-F496-44D2-0001-E3CCF8CD58AE} O42 - Logiciel: PowerLine Utility - (.TP-LINK.) [HKLM][64Bits] -- {762E248A-F922-42D6-B577-A47B0AB558D2} O42 - Logiciel: PrintPratic - (.Micro Application.) [HKLM][64Bits] -- PrintPratic O42 - Logiciel: PrtScr 1.5 - (.FireStarter.) [HKLM][64Bits] -- PrtScr_is1 O42 - Logiciel: Qualcomm USB Drivers For Windows - (.QUALCOMM Incorporated.) [HKLM][64Bits] -- {D9FB7F91-9687-4B09-894D-072903CADEA4} O42 - Logiciel: Raptr - (...) [HKLM][64Bits] -- Raptr O42 - Logiciel: Réseau Antilles Bayo 0008-Q1 - (.Bayo.) [HKLM][64Bits] -- Réseau Antilles Bayo_is1 O42 - Logiciel: Réseau Antilles BdAlti 2003-Q1 - (.Bayo.) [HKLM][64Bits] -- Réseau Antilles BdAlti_is1 O42 - Logiciel: Réseau Antilles BdNyme 2003-Q1 - (.Bayo.) [HKLM][64Bits] -- Réseau Antilles BdNyme_is1 O42 - Logiciel: Réseau France Bayo 0016-Q0 - (.Bayo.) [HKLM][64Bits] -- Réseau France Bayo_is1 O42 - Logiciel: Réseau France BdAlti 2005-Q3 - (.Bayo.) [HKLM][64Bits] -- Réseau France BdAlti_is1 O42 - Logiciel: Réseau France BdNyme 2004-Q4 - (.Bayo.) [HKLM][64Bits] -- Réseau France BdNyme_is1 O42 - Logiciel: Réseau Guyane Bayo 0005-Q0 - (.Bayo.) [HKLM][64Bits] -- Réseau Guyane Bayo_is1 O42 - Logiciel: Réseau Guyane BdAlti 2003-Q1 - (.Bayo.) [HKLM][64Bits] -- Réseau Guyane BdAlti_is1 O42 - Logiciel: Réseau Guyane BdNyme 2003-Q1 - (.Bayo.) [HKLM][64Bits] -- Réseau Guyane BdNyme_is1 O42 - Logiciel: Réseau Reunion Bayo 0007-Q0 - (.Bayo.) [HKLM][64Bits] -- Réseau Reunion Bayo_is1 O42 - Logiciel: Réseau Reunion BdAlti 2003-Q1 - (.Bayo.) [HKLM][64Bits] -- Réseau Reunion BdAlti_is1 O42 - Logiciel: Réseau Reunion BdNyme 2003-Q1 - (.Bayo.) [HKLM][64Bits] -- Réseau Reunion BdNyme_is1 O42 - Logiciel: Sage Start Comptabilité - (.Sage.) [HKLM][64Bits] -- {4FDE7114-EE73-447D-A7DA-90BEBCCA2A4E} O42 - Logiciel: SanityCheck 3.00 - (.Resplendence Software Projects Sp..) [HKLM][64Bits] -- SanityCheck_is1 O42 - Logiciel: Scribus 1.4.3 (64bit) - (.The Scribus Team.) [HKLM][64Bits] -- Scribus 1.4.3 O42 - Logiciel: Serif PhotoPlus X6 - (.Serif (Europe) Ltd.) [HKLM][64Bits] -- {CCD2C5E4-F484-4499-BCB3-61E787416757} O42 - Logiciel: SmartSound Common Data - (.SmartSound Software Inc..) [HKLM][64Bits] -- InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8} O42 - Logiciel: SmartSound Common Data - (.SmartSound Software Inc..) [HKLM][64Bits] -- {B8A2869E-30CA-40C5-9CF8-BD7354E57EF8} O42 - Logiciel: SmartSound Premiere Elements 10 x64 Plugin - (.SmartSound Software Inc..) [HKLM][64Bits] -- {3DAE9A67-DD8D-4EDB-91F7-7B5132B1864D} O42 - Logiciel: SmartSound Sonicfire Pro 5 - (.SmartSound Software Inc..) [HKLM][64Bits] -- InstallShield_{1D273D91-D7D5-4036-8B84-EB4615FF5F81} O42 - Logiciel: SmartSound Sonicfire Pro 5 - (.SmartSound Software Inc..) [HKLM][64Bits] -- {1D273D91-D7D5-4036-8B84-EB4615FF5F81} O42 - Logiciel: Sophos Virus Removal Tool - (.Sophos Limited.) [HKLM][64Bits] -- {B829E117-D072-41EA-9606-9826A38D34C1} O42 - Logiciel: Super Optimizer v3.2 - (.Super PC Tools ltd.) [HKLM][64Bits] -- Super Optimizer_is1 =>PUP.SuperPCTools O42 - Logiciel: SureThing CD Labeler 4 SE - (...) [HKLM][64Bits] -- MVApplication1 O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN O42 - Logiciel: Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1 - (.Garmin.) [HKLM][64Bits] -- 98157A226B40B173301B0F53C8E98C47805D5152 O42 - Logiciel: Zemana AntiMalware version 2.7.2.440 - (.Zemana Ltd..) [HKLM][64Bits] -- {8F0CD7D1-42F3-4195-95CD-833578D45057}_is1 O42 - Logiciel: andriod_usb_driver - (.andriod.) [HKLM][64Bits] -- andriod_usb_driver_is1 O42 - Logiciel: eReg - (.Logitech, Inc..) [HKLM][64Bits] -- {3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C} ~ Logic: 89 Scanned in 00mn 00s ---\\ HKCU & HKLM Software Keys [HKCU\Software\7-Zip] [HKCU\Software\AMD] [HKCU\Software\ATI] [HKCU\Software\AVS4YOU] [HKCU\Software\Adobe] [HKCU\Software\AppDataLow\Software\JavaSoft] [HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}] [HKCU\Software\AppDataLow] [HKCU\Software\Bayo] [HKCU\Software\BlackBerry Limited] [HKCU\Software\BottleTech] [HKCU\Software\Brother Industries, Ltd.] [HKCU\Software\Canneverbe Limited] [HKCU\Software\Chromium] [HKCU\Software\Classes] [HKCU\Software\Clients] [HKCU\Software\ComodoGroup] [HKCU\Software\CompeGPSDownloader] [HKCU\Software\CoverSearch] [HKCU\Software\ESET] [HKCU\Software\Engelmann Media] [HKCU\Software\Extended Systems] [HKCU\Software\FLEXnet] [HKCU\Software\Famatech] [HKCU\Software\GO-Soft] [HKCU\Software\GPL Ghostscript] [HKCU\Software\Garmin] [HKCU\Software\Gladinet] [HKCU\Software\Google] [HKCU\Software\HP] [HKCU\Software\Hewlett-Packard] [HKCU\Software\Imprimante PDF Sage] [HKCU\Software\InstallShield] [HKCU\Software\Intel] [HKCU\Software\JavaSoft] [HKCU\Software\Jomigo] [HKCU\Software\Leadertech] [HKCU\Software\LightScribe] [HKCU\Software\Local AppWizard-Generated Applications] [HKCU\Software\Logitech] [HKCU\Software\MCAFEE] [HKCU\Software\Macromedia] [HKCU\Software\MainConcept] [HKCU\Software\Memory-Map] [HKCU\Software\MicroVision] [HKCU\Software\MozillaPlugins] [HKCU\Software\Mozilla] [HKCU\Software\Netscape] [HKCU\Software\NewBlue] [HKCU\Software\ODBC] [HKCU\Software\OnlineArmor] [HKCU\Software\Oxemis] [HKCU\Software\PC SOFT] [HKCU\Software\Policies] [HKCU\Software\PrtScr] [HKCU\Software\Raptr] [HKCU\Software\Redemption] [HKCU\Software\Research In Motion] [HKCU\Software\Resplendence Sp] [HKCU\Software\Sage] [HKCU\Software\ScanSoft] [HKCU\Software\SecuROM] [HKCU\Software\Serif] [HKCU\Software\SourceTec] [HKCU\Software\Super Optimizer] =>PUP.SuperOptimizer [HKCU\Software\TeamViewer] [HKCU\Software\The Document Foundation] [HKCU\Software\Trolltech] [HKCU\Software\VB and VBA Program Settings] [HKCU\Software\Visan] [HKCU\Software\Wow6432Node] [HKCU\Software\ZEON] [HKCU\Software\ZebHelpProcess Helper] [HKCU\Software\Zemana] [HKLM\Software\7-Zip] [HKLM\Software\AMD] [HKLM\Software\ATI Technologies] [HKLM\Software\ATI] [HKLM\Software\Adobe] [HKLM\Software\Alienware] [HKLM\Software\Canneverbe Limited] [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\Conduit] =>Toolbar.Conduit [HKLM\Software\ESET] [HKLM\Software\FileZilla 3] [HKLM\Software\Foolish IT] [HKLM\Software\HP] [HKLM\Software\Intel] [HKLM\Software\KeyCryptSDK] [HKLM\Software\Khronos] [HKLM\Software\Logitech] [HKLM\Software\Macromedia] [HKLM\Software\MozillaPlugins] [HKLM\Software\Mozilla] [HKLM\Software\ODBC] [HKLM\Software\Policies] [HKLM\Software\RegisteredApplications] [HKLM\Software\ScanSoft] [HKLM\Software\Serif] [HKLM\Software\Software] [HKLM\Software\Sonic] [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6] =>PUP.CrossRider [HKLM\Software\Wow6432Node\685D6D1C-D73A-4F37-B7E5E53660311DDB] [HKLM\Software\Wow6432Node\AMD] [HKLM\Software\Wow6432Node\ATI Technologies] [HKLM\Software\Wow6432Node\ATI] [HKLM\Software\Wow6432Node\AVS4YOU] [HKLM\Software\Wow6432Node\Adobe] [HKLM\Software\Wow6432Node\Apple Inc.] [HKLM\Software\Wow6432Node\Artifex] [HKLM\Software\Wow6432Node\Avanquest] [HKLM\Software\Wow6432Node\Avid] [HKLM\Software\Wow6432Node\Bayo] [HKLM\Software\Wow6432Node\BottleTech] [HKLM\Software\Wow6432Node\Canneverbe Limited] [HKLM\Software\Wow6432Node\Citrix] [HKLM\Software\Wow6432Node\Classes] [HKLM\Software\Wow6432Node\Clients] [HKLM\Software\Wow6432Node\ComodoGroup] [HKLM\Software\Wow6432Node\Comodo] [HKLM\Software\Wow6432Node\CompeGPS] [HKLM\Software\Wow6432Node\Data Fellows] [HKLM\Software\Wow6432Node\ESET] [HKLM\Software\Wow6432Node\Emsisoft] [HKLM\Software\Wow6432Node\Engelmann Media] [HKLM\Software\Wow6432Node\Extended Systems] [HKLM\Software\Wow6432Node\FileZilla 3] [HKLM\Software\Wow6432Node\Funk Software, Inc.] [HKLM\Software\Wow6432Node\GPL Ghostscript] [HKLM\Software\Wow6432Node\Garmin] [HKLM\Software\Wow6432Node\Google] [HKLM\Software\Wow6432Node\Hewlett-Packard] [HKLM\Software\Wow6432Node\InstallShield] [HKLM\Software\Wow6432Node\Intel] [HKLM\Software\Wow6432Node\JavaSoft] [HKLM\Software\Wow6432Node\Jomigo] [HKLM\Software\Wow6432Node\JreMetrics] [HKLM\Software\Wow6432Node\KasperskyLab] [HKLM\Software\Wow6432Node\Khronos] [HKLM\Software\Wow6432Node\LibreOffice] [HKLM\Software\Wow6432Node\Licenses] [HKLM\Software\Wow6432Node\LightScribeApplications] [HKLM\Software\Wow6432Node\LightScribeTemplateLabeler] [HKLM\Software\Wow6432Node\LightScribe] [HKLM\Software\Wow6432Node\Logitech] [HKLM\Software\Wow6432Node\Macromedia] [HKLM\Software\Wow6432Node\Memory-Map] [HKLM\Software\Wow6432Node\Micro Application] [HKLM\Software\Wow6432Node\MicroVision] [HKLM\Software\Wow6432Node\MozillaPlugins] [HKLM\Software\Wow6432Node\Mozilla] [HKLM\Software\Wow6432Node\ODBC] [HKLM\Software\Wow6432Node\Online Armor] [HKLM\Software\Wow6432Node\Philips] [HKLM\Software\Wow6432Node\Policies] [HKLM\Software\Wow6432Node\RegisteredApplications] [HKLM\Software\Wow6432Node\Research In Motion] [HKLM\Software\Wow6432Node\RocketLife] [HKLM\Software\Wow6432Node\Sage] [HKLM\Software\Wow6432Node\ScanSoft] [HKLM\Software\Wow6432Node\Serif] [HKLM\Software\Wow6432Node\SmartSound Software] [HKLM\Software\Wow6432Node\Solvusoft] [HKLM\Software\Wow6432Node\Sonic] [HKLM\Software\Wow6432Node\Sophos] [HKLM\Software\Wow6432Node\TeamViewer] [HKLM\Software\Wow6432Node\The Document Foundation] [HKLM\Software\Wow6432Node\VideoLAN] [HKLM\Software\Wow6432Node\Visan] [HKLM\Software\Wow6432Node\ZEON] [HKLM\Software\Wow6432Node\andriod_usb_driver] [HKLM\Software\Wow6432Node\mozilla.org] [HKLM\Software\Wow6432Node] [HKLM\Software\ZEON] [HKLM\Software\Zemana] [HKLM\Software\ZmnGlobalSDK] ~ Key Software: 400 Scanned in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 16/02/2015 - 22:30:15 - [] ----D C:\Program Files (x86)\35mm Film Scanner O43 - CFD: 03/08/2013 - 22:50:39 - [] ----D C:\Program Files (x86)\Adobe O43 - CFD: 16/03/2015 - 22:23:21 - [] ----D C:\Program Files (x86)\Advanced Port Scanner O43 - CFD: 14/03/2015 - 23:09:49 - [] ----D C:\Program Files (x86)\AMD O43 - CFD: 14/03/2015 - 23:12:04 - [] ----D C:\Program Files (x86)\AMD AVT O43 - CFD: 09/02/2014 - 22:35:12 - [] ----D C:\Program Files (x86)\andriod_usb_driver O43 - CFD: 15/12/2014 - 22:31:25 - [0] ----D C:\Program Files (x86)\AVS4YOU O43 - CFD: 26/01/2014 - 11:38:56 - [] ----D C:\Program Files (x86)\Bayo O43 - CFD: 29/03/2014 - 14:33:51 - [] ----D C:\Program Files (x86)\BlackBerry O43 - CFD: 06/04/2015 - 14:48:25 - [] ----D C:\Program Files (x86)\CartoExploreur O43 - CFD: 13/02/2015 - 22:49:23 - [] ----D C:\Program Files (x86)\CDBurnerXP O43 - CFD: 18/03/2015 - 23:05:54 - [] ----D C:\Program Files (x86)\Common Files O43 - CFD: 10/03/2015 - 23:38:36 - [] ----D C:\Program Files (x86)\Comodo O43 - CFD: 23/11/2014 - 14:06:53 - [] ----D C:\Program Files (x86)\CompeGPS O43 - CFD: 06/04/2014 - 18:33:49 - [] ----D C:\Program Files (x86)\CompeGPSDownloader O43 - CFD: 15/12/2014 - 22:31:44 - [] ----D C:\Program Files (x86)\DVD-GO! O43 - CFD: 07/02/2015 - 20:19:54 - [] ----D C:\Program Files (x86)\Engelmann Media O43 - CFD: 11/08/2013 - 21:21:19 - [] ----D C:\Program Files (x86)\FastStone Image Viewer O43 - CFD: 16/10/2014 - 19:11:04 - [] ----D C:\Program Files (x86)\FileZilla FTP Client O43 - CFD: 22/09/2014 - 22:15:19 - [] ----D C:\Program Files (x86)\Garmin O43 - CFD: 14/03/2015 - 22:47:46 - [] ----D C:\Program Files (x86)\GIGABYTE O43 - CFD: 01/04/2015 - 23:01:41 - [] ----D C:\Program Files (x86)\Google O43 - CFD: 28/01/2014 - 22:59:55 - [] ----D C:\Program Files (x86)\gs O43 - CFD: 02/08/2013 - 21:09:50 - [] ----D C:\Program Files (x86)\HP O43 - CFD: 02/08/2013 - 21:10:06 - [] ----D C:\Program Files (x86)\HP Photo Creations O43 - CFD: 28/01/2014 - 23:11:30 - [] ----D C:\Program Files (x86)\Inkscape O43 - CFD: 07/02/2015 - 20:18:31 - [] ----D C:\Program Files (x86)\InPixio Photo Clip Professional O43 - CFD: 14/03/2015 - 22:48:26 - [] --H-D C:\Program Files (x86)\InstallShield Installation Information O43 - CFD: 14/03/2015 - 21:57:02 - [] ----D C:\Program Files (x86)\Internet Explorer O43 - CFD: 16/02/2015 - 23:19:30 - [] ----D C:\Program Files (x86)\Java O43 - CFD: 07/04/2015 - 18:26:53 - [] ----D C:\Program Files (x86)\KeyCryptSDK O43 - CFD: 01/04/2014 - 22:02:16 - [] ----D C:\Program Files (x86)\LibreOffice 4 O43 - CFD: 06/12/2013 - 20:10:58 - [] ----D C:\Program Files (x86)\LibreOffice 4.0 O43 - CFD: 30/11/2013 - 23:14:57 - [] ----D C:\Program Files (x86)\LightScribe O43 - CFD: 30/11/2013 - 23:19:09 - [] ----D C:\Program Files (x86)\LightScribe Template Labeler O43 - CFD: 18/12/2013 - 20:42:39 - [] ----D C:\Program Files (x86)\Maestria O43 - CFD: 06/04/2015 - 14:48:01 - [] ----D C:\Program Files (x86)\McAfee Security Scan O43 - CFD: 03/08/2013 - 14:48:18 - [] ----D C:\Program Files (x86)\Memory-Map O43 - CFD: 07/02/2015 - 20:19:21 - [] ----D C:\Program Files (x86)\Micro Application O43 - CFD: 19/01/2014 - 16:27:02 - [] ----D C:\Program Files (x86)\Microsoft Analysis Services O43 - CFD: 19/01/2014 - 16:30:37 - [] ----D C:\Program Files (x86)\Microsoft Office O43 - CFD: 10/08/2014 - 16:41:51 - [] ----D C:\Program Files (x86)\Microsoft Silverlight O43 - CFD: 19/01/2014 - 16:30:37 - [] ----D C:\Program Files (x86)\Microsoft.NET O43 - CFD: 26/03/2015 - 22:38:38 - [] ----D C:\Program Files (x86)\Mozilla Firefox O43 - CFD: 31/03/2015 - 23:17:28 - [] ----D C:\Program Files (x86)\Mozilla Maintenance Service O43 - CFD: 08/10/2014 - 20:57:55 - [] ----D C:\Program Files (x86)\Mozilla Thunderbird =>.Mozilla Corporation O43 - CFD: 14/07/2009 - 07:32:38 - [] ----D C:\Program Files (x86)\MSBuild O43 - CFD: 03/08/2013 - 19:36:53 - [0] ----D C:\Program Files (x86)\MSXML 4.0 O43 - CFD: 03/08/2013 - 10:12:14 - [] ----D C:\Program Files (x86)\Nuance O43 - CFD: 04/04/2015 - 09:56:39 - [] ----D C:\Program Files (x86)\Online Armor O43 - CFD: 17/07/2014 - 22:46:19 - [] ----D C:\Program Files (x86)\OpenConcerto O43 - CFD: 15/09/2014 - 19:29:39 - [] ----D C:\Program Files (x86)\Oxemis O43 - CFD: 13/02/2014 - 22:38:08 - [] ----D C:\Program Files (x86)\PrtScr O43 - CFD: 09/02/2014 - 16:51:39 - [] ----D C:\Program Files (x86)\QUALCOMM Incorporated O43 - CFD: 26/03/2015 - 20:14:39 - [] ----D C:\Program Files (x86)\Raptr O43 - CFD: 14/07/2009 - 07:32:38 - [] ----D C:\Program Files (x86)\Reference Assemblies O43 - CFD: 22/03/2014 - 15:42:06 - [] ----D C:\Program Files (x86)\Research In Motion O43 - CFD: 03/08/2013 - 22:07:31 - [] ----D C:\Program Files (x86)\SmartSound Software O43 - CFD: 10/03/2015 - 23:26:34 - [] ----D C:\Program Files (x86)\Sophos O43 - CFD: 07/04/2015 - 18:34:06 - [] ----D C:\Program Files (x86)\Super Optimizer =>PUP.SuperOptimizer O43 - CFD: 13/02/2015 - 22:52:46 - [] ----D C:\Program Files (x86)\SureThing O43 - CFD: 04/08/2013 - 19:00:18 - [] ----D C:\Program Files (x86)\TP-LINK O43 - CFD: 07/04/2015 - 18:25:55 - [] ----D C:\Program Files (x86)\Tweaks O43 - CFD: 15/09/2014 - 19:41:05 - [] ----D C:\Program Files (x86)\UltraCover O43 - CFD: 14/07/2009 - 06:57:06 - [0] --H-D C:\Program Files (x86)\Uninstall Information O43 - CFD: 03/08/2013 - 20:00:26 - [] ----D C:\Program Files (x86)\VideoLAN O43 - CFD: 03/08/2013 - 19:16:55 - [] ----D C:\Program Files (x86)\Windows Defender O43 - CFD: 03/08/2013 - 09:08:44 - [] ----D C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation O43 - CFD: 14/03/2015 - 22:37:38 - [] ----D C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation O43 - CFD: 14/07/2009 - 07:32:38 - [] ----D C:\Program Files (x86)\Windows NT O43 - CFD: 03/08/2013 - 09:08:43 - [] ----D C:\Program Files (x86)\Windows Photo Viewer O43 - CFD: 03/08/2013 - 09:08:44 - [] ----D C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 03/08/2013 - 09:08:44 - [] ----D C:\Program Files (x86)\Windows Sidebar O43 - CFD: 18/03/2015 - 23:06:43 - [] ----D C:\Program Files (x86)\Zemana AntiLogger Free O43 - CFD: 18/03/2015 - 23:10:00 - [] ----D C:\Program Files (x86)\Zemana AntiMalware O43 - CFD: 29/03/2014 - 14:35:41 - [] --H-D C:\Program Files (x86)\Zero G Registry O43 - CFD: 07/04/2015 - 18:39:22 - [] ----D C:\Program Files (x86)\ZHPDiag =>.Nicolas Coolman O43 - CFD: 03/08/2013 - 22:49:41 - [] ----D C:\Program Files (x86)\Common Files\Adobe O43 - CFD: 03/08/2013 - 22:32:12 - [] ----D C:\Program Files (x86)\Common Files\Adobe AIR O43 - CFD: 14/03/2015 - 22:58:09 - [] ----D C:\Program Files (x86)\Common Files\ATI Technologies O43 - CFD: 12/09/2014 - 19:00:13 - [] ----D C:\Program Files (x86)\Common Files\AVSMedia O43 - CFD: 26/01/2014 - 11:38:28 - [0] ----D C:\Program Files (x86)\Common Files\Bayo O43 - CFD: 22/05/2014 - 19:00:18 - [] ----D C:\Program Files (x86)\Common Files\DESIGNER O43 - CFD: 07/02/2015 - 20:19:54 - [] ----D C:\Program Files (x86)\Common Files\HDX4 O43 - CFD: 14/03/2015 - 00:02:54 - [] ----D C:\Program Files (x86)\Common Files\InstallShield O43 - CFD: 16/02/2015 - 23:19:03 - [] ----D C:\Program Files (x86)\Common Files\Java O43 - CFD: 25/08/2014 - 19:12:05 - [] ----D C:\Program Files (x86)\Common Files\LightScribe O43 - CFD: 04/08/2013 - 18:17:33 - [] ----D C:\Program Files (x86)\Common Files\LogiShrd O43 - CFD: 19/01/2014 - 18:43:04 - [] ----D C:\Program Files (x86)\Common Files\microsoft shared O43 - CFD: 07/02/2015 - 20:04:29 - [] ----D C:\Program Files (x86)\Common Files\MSSoap O43 - CFD: 03/08/2013 - 22:00:54 - [] ----D C:\Program Files (x86)\Common Files\PX Storage Engine O43 - CFD: 26/08/2014 - 06:08:15 - [] ----D C:\Program Files (x86)\Common Files\Research in Motion O43 - CFD: 18/12/2013 - 20:42:48 - [] ----D C:\Program Files (x86)\Common Files\SAGE O43 - CFD: 03/08/2013 - 10:12:15 - [] ----D C:\Program Files (x86)\Common Files\ScanSoft Shared O43 - CFD: 14/07/2009 - 05:20:08 - [] ----D C:\Program Files (x86)\Common Files\Services O43 - CFD: 03/08/2013 - 22:00:54 - [] ----D C:\Program Files (x86)\Common Files\Sonic Shared O43 - CFD: 03/08/2013 - 10:25:36 - [] ----D C:\Program Files (x86)\Common Files\SourceTec O43 - CFD: 14/07/2009 - 05:20:08 - [] ----D C:\Program Files (x86)\Common Files\SpeechEngines O43 - CFD: 13/02/2015 - 22:52:41 - [] ----D C:\Program Files (x86)\Common Files\SureThing Shared O43 - CFD: 19/01/2014 - 18:37:48 - [] ----D C:\Program Files (x86)\Common Files\System O43 - CFD: 09/02/2014 - 17:08:26 - [] ----D C:\Program Files (x86)\Common Files\Tencent =>Adware.TencentAddressBar O43 - CFD: 03/08/2013 - 12:44:47 - [] ----D C:\Program Files (x86)\Common Files\Wise Installation Wizard O43 - CFD: 26/08/2014 - 06:08:13 - [] ----D C:\Program Files (x86)\Common Files\XCPCSync.OEM O43 - CFD: 19/01/2014 - 11:05:37 - [] ----D C:\ProgramData\Adobe O43 - CFD: 14/03/2015 - 23:12:05 - [] ----D C:\ProgramData\AMD O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Application Data O43 - CFD: 14/03/2015 - 23:12:12 - [] ----D C:\ProgramData\ATI O43 - CFD: 07/02/2015 - 20:18:09 - [] ----D C:\ProgramData\Avanquest O43 - CFD: 07/02/2015 - 20:20:13 - [] ----D C:\ProgramData\Avanquest Software O43 - CFD: 29/07/2013 - 22:24:56 - [] -SH-D C:\ProgramData\Bureau O43 - CFD: 28/02/2014 - 20:19:20 - [] ----D C:\ProgramData\Canneverbe Limited O43 - CFD: 14/03/2015 - 22:46:27 - [] ----D C:\ProgramData\Comodo O43 - CFD: 06/04/2015 - 14:44:09 - [] ----D C:\ProgramData\CompeGPS O43 - CFD: 06/04/2014 - 18:33:49 - [] ----D C:\ProgramData\CompeGPSDownloader O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Desktop O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Documents O43 - CFD: 02/08/2013 - 22:11:34 - [] ----D C:\ProgramData\Downloaded Installations O43 - CFD: 12/09/2014 - 19:24:56 - [] ----D C:\ProgramData\DVD-GO! O43 - CFD: 10/01/2015 - 20:09:43 - [] ----D C:\ProgramData\ESET O43 - CFD: 10/03/2015 - 23:11:24 - [] ----D C:\ProgramData\F-Secure O43 - CFD: 29/07/2013 - 22:24:56 - [] -SH-D C:\ProgramData\Favoris O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Favorites O43 - CFD: 02/08/2013 - 21:46:34 - [] ----D C:\ProgramData\FLEXnet O43 - CFD: 02/08/2013 - 21:09:04 - [] ----D C:\ProgramData\HP O43 - CFD: 02/08/2013 - 21:10:05 - [] ----D C:\ProgramData\HP Photo Creations O43 - CFD: 30/11/2013 - 23:10:56 - [] ----D C:\ProgramData\LightScribe O43 - CFD: 04/08/2013 - 18:20:03 - [] ----D C:\ProgramData\Logishrd O43 - CFD: 04/08/2013 - 18:16:42 - [] ----D C:\ProgramData\Logitech O43 - CFD: 02/08/2013 - 21:46:34 - [] ----D C:\ProgramData\Macrovision O43 - CFD: 06/04/2015 - 14:48:04 - [] ----D C:\ProgramData\McAfee O43 - CFD: 06/04/2015 - 14:48:15 - [] ----D C:\ProgramData\McAfee Security Scan O43 - CFD: 03/08/2013 - 14:57:41 - [] ----D C:\ProgramData\Memory-Map-License O43 - CFD: 29/07/2013 - 22:24:56 - [] -SH-D C:\ProgramData\Menu Démarrer O43 - CFD: 03/08/2013 - 10:24:42 - [] ----D C:\ProgramData\Micro Application O43 - CFD: 26/12/2014 - 19:40:38 - [] -S--D C:\ProgramData\Microsoft O43 - CFD: 15/03/2015 - 00:33:58 - [] ----D C:\ProgramData\Microsoft Help O43 - CFD: 29/07/2013 - 22:24:56 - [] -SH-D C:\ProgramData\Modèles O43 - CFD: 02/08/2013 - 19:09:24 - [] ----D C:\ProgramData\Mozilla O43 - CFD: 03/08/2013 - 10:13:34 - [] ----D C:\ProgramData\Nuance O43 - CFD: 31/03/2015 - 23:20:20 - [] ----D C:\ProgramData\OnlineArmor O43 - CFD: 16/02/2015 - 23:19:35 - [] ----D C:\ProgramData\Oracle O43 - CFD: 14/03/2015 - 23:06:56 - [] ----D C:\ProgramData\Package Cache O43 - CFD: 03/08/2013 - 22:36:06 - [] ----D C:\ProgramData\regid.1986-12.com.adobe O43 - CFD: 22/03/2014 - 15:43:09 - [] ----D C:\ProgramData\Research In Motion O43 - CFD: 18/12/2013 - 20:42:50 - [] ----D C:\ProgramData\Sage O43 - CFD: 09/02/2014 - 17:21:34 - [] ----D C:\ProgramData\Shuame O43 - CFD: 03/08/2013 - 22:07:49 - [] ----D C:\ProgramData\SmartSound Software Inc O43 - CFD: 26/03/2015 - 22:33:18 - [] ----D C:\ProgramData\Soluto O43 - CFD: 14/03/2015 - 22:01:54 - [] ----D C:\ProgramData\Sophos O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Start Menu O43 - CFD: 03/08/2013 - 15:07:51 - [] ----D C:\ProgramData\Sun O43 - CFD: 01/04/2015 - 23:11:39 - [0] ---AD C:\ProgramData\TEMP O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Templates O43 - CFD: 09/02/2014 - 17:08:42 - [] ----D C:\ProgramData\Tencent =>Adware.TencentAddressBar O43 - CFD: 02/08/2013 - 21:46:34 - [] ----D C:\ProgramData\Zeon O43 - CFD: 16/02/2015 - 22:30:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\35mm Film Scanner O43 - CFD: 03/08/2013 - 15:06:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip O43 - CFD: 12/03/2014 - 20:20:42 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 03/08/2013 - 09:40:37 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 16/03/2015 - 22:29:46 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Anti Keylogger Lite O43 - CFD: 16/03/2015 - 22:23:19 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Port Scanner O43 - CFD: 14/03/2015 - 23:11:16 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center O43 - CFD: 14/03/2015 - 23:01:11 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Gaming Evolved O43 - CFD: 09/02/2014 - 22:35:12 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\andriod_usb_driver O43 - CFD: 07/02/2015 - 20:04:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Applications Serif O43 - CFD: 26/01/2014 - 11:38:32 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bayo O43 - CFD: 26/08/2014 - 06:08:24 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry O43 - CFD: 06/04/2015 - 14:48:25 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CartoExploreur O43 - CFD: 18/03/2015 - 23:05:53 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo O43 - CFD: 23/11/2014 - 14:06:28 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CompeGPS O43 - CFD: 07/02/2015 - 20:19:54 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Engelmann Media O43 - CFD: 10/01/2015 - 20:09:43 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET O43 - CFD: 11/08/2013 - 21:21:19 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Image Viewer O43 - CFD: 07/04/2015 - 18:25:57 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileOpener =>Adware.InstallCore O43 - CFD: 16/10/2014 - 19:11:03 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client O43 - CFD: 14/07/2009 - 17:35:46 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 22/09/2014 - 22:15:20 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin O43 - CFD: 28/01/2014 - 23:00:04 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ghostscript O43 - CFD: 14/03/2015 - 22:47:49 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGABYTE O43 - CFD: 02/08/2013 - 21:10:06 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP O43 - CFD: 07/02/2015 - 20:18:31 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InPixio Photo Clip Professional O43 - CFD: 16/02/2015 - 23:18:40 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java O43 - CFD: 01/04/2014 - 22:02:20 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1 O43 - CFD: 25/08/2014 - 19:12:06 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling O43 - CFD: 04/08/2013 - 18:17:26 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech O43 - CFD: 14/07/2009 - 06:57:09 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 06/04/2015 - 14:48:14 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus O43 - CFD: 03/08/2013 - 14:48:26 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Memory-Map O43 - CFD: 07/02/2015 - 20:19:21 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Micro Application O43 - CFD: 19/01/2014 - 16:31:23 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office O43 - CFD: 24/07/2014 - 20:19:00 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight O43 - CFD: 29/03/2014 - 14:41:07 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Momentics O43 - CFD: 03/08/2013 - 13:01:57 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nuance PDF Converter Professional 8 O43 - CFD: 31/03/2015 - 20:09:14 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Armor O43 - CFD: 17/07/2014 - 22:46:21 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenConcerto O43 - CFD: 15/09/2014 - 19:29:43 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oxemis O43 - CFD: 13/02/2014 - 22:38:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrtScr O43 - CFD: 18/12/2013 - 20:42:50 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sage O43 - CFD: 01/04/2015 - 22:38:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SanityCheck O43 - CFD: 28/01/2014 - 23:49:52 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scribus 1.4.3 O43 - CFD: 03/08/2013 - 22:07:47 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartSound O43 - CFD: 10/03/2015 - 23:26:40 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos O43 - CFD: 06/04/2015 - 14:48:03 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 07/04/2015 - 18:26:51 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Super Optimizer =>PUP.SuperOptimizer O43 - CFD: 13/02/2015 - 22:52:47 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SureThing O43 - CFD: 14/07/2009 - 17:35:18 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 04/08/2013 - 19:00:18 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK O43 - CFD: 28/01/2014 - 23:10:04 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN O43 - CFD: 18/03/2015 - 23:06:43 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiLogger Free O43 - CFD: 18/03/2015 - 23:09:54 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware O43 - CFD: 07/04/2015 - 18:39:22 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP =>.Nicolas Coolman O43 - CFD: 15/09/2014 - 19:42:18 - [] ----D C:\Users\Xavier\AppData\Roaming\ Preferences Gifour O43 - CFD: 07/04/2015 - 18:26:00 - [] ----D C:\Users\Xavier\AppData\Roaming\1H1Q1V1N1N1O1R =>Adware.InstallCore O43 - CFD: 06/02/2014 - 23:39:57 - [] ----D C:\Users\Xavier\AppData\Roaming\Adobe O43 - CFD: 14/03/2015 - 23:04:11 - [] ----D C:\Users\Xavier\AppData\Roaming\ATI O43 - CFD: 10/02/2014 - 00:01:06 - [] ----D C:\Users\Xavier\AppData\Roaming\baidu O43 - CFD: 10/02/2014 - 00:01:15 - [] ----D C:\Users\Xavier\AppData\Roaming\BaiduYunGuanjia O43 - CFD: 28/02/2014 - 20:19:14 - [] ----D C:\Users\Xavier\AppData\Roaming\Canneverbe Limited O43 - CFD: 19/01/2014 - 11:28:21 - [] ----D C:\Users\Xavier\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 O43 - CFD: 07/04/2015 - 18:26:04 - [] ----D C:\Users\Xavier\AppData\Roaming\DigitalSites =>Hijacker.DSite O43 - CFD: 28/01/2014 - 23:16:27 - [] ----D C:\Users\Xavier\AppData\Roaming\dvdcss O43 - CFD: 07/02/2015 - 20:19:55 - [] ----D C:\Users\Xavier\AppData\Roaming\Engelmann Media O43 - CFD: 02/08/2013 - 19:32:59 - [] ----D C:\Users\Xavier\AppData\Roaming\ESET O43 - CFD: 11/08/2013 - 21:25:16 - [] ----D C:\Users\Xavier\AppData\Roaming\FastStone O43 - CFD: 04/03/2015 - 22:03:35 - [] ----D C:\Users\Xavier\AppData\Roaming\FileZilla O43 - CFD: 03/08/2013 - 09:44:22 - [] ----D C:\Users\Xavier\AppData\Roaming\FLEXnet O43 - CFD: 13/02/2014 - 22:53:34 - [] ----D C:\Users\Xavier\AppData\Roaming\Gadwin O43 - CFD: 22/09/2014 - 22:15:01 - [] ----D C:\Users\Xavier\AppData\Roaming\Garmin O43 - CFD: 31/03/2015 - 20:09:43 - [] ----D C:\Users\Xavier\AppData\Roaming\HpUpdate O43 - CFD: 29/07/2013 - 22:25:17 - [] ----D C:\Users\Xavier\AppData\Roaming\Identities O43 - CFD: 28/01/2014 - 23:21:41 - [] ----D C:\Users\Xavier\AppData\Roaming\inkscape O43 - CFD: 04/08/2013 - 17:55:09 - [] ----D C:\Users\Xavier\AppData\Roaming\InstallShield O43 - CFD: 04/08/2013 - 18:17:35 - [] ----D C:\Users\Xavier\AppData\Roaming\Leadertech O43 - CFD: 14/03/2015 - 23:00:58 - [] ----D C:\Users\Xavier\AppData\Roaming\library_dir O43 - CFD: 27/08/2013 - 22:23:17 - [] ----D C:\Users\Xavier\AppData\Roaming\LibreOffice O43 - CFD: 04/08/2013 - 18:10:03 - [] ----D C:\Users\Xavier\AppData\Roaming\Logishrd O43 - CFD: 04/08/2013 - 18:09:58 - [] ----D C:\Users\Xavier\AppData\Roaming\Logitech O43 - CFD: 03/08/2013 - 10:13:49 - [] ----D C:\Users\Xavier\AppData\Roaming\Macromedia O43 - CFD: 14/07/2009 - 17:35:18 - [0] ----D C:\Users\Xavier\AppData\Roaming\Media Center Programs O43 - CFD: 13/10/2014 - 20:55:08 - [] -S--D C:\Users\Xavier\AppData\Roaming\Microsoft O43 - CFD: 29/03/2014 - 14:45:16 - [] ----D C:\Users\Xavier\AppData\Roaming\Mozilla O43 - CFD: 03/08/2013 - 21:57:47 - [] ----D C:\Users\Xavier\AppData\Roaming\No Company Name O43 - CFD: 02/08/2013 - 22:06:29 - [] ----D C:\Users\Xavier\AppData\Roaming\Nuance O43 - CFD: 31/03/2015 - 23:11:58 - [] ----D C:\Users\Xavier\AppData\Roaming\OnlineArmor O43 - CFD: 15/09/2014 - 19:29:59 - [] ----D C:\Users\Xavier\AppData\Roaming\Oxemis O43 - CFD: 01/04/2015 - 22:43:48 - [] ----D C:\Users\Xavier\AppData\Roaming\Raptr O43 - CFD: 22/03/2014 - 15:51:33 - [] ----D C:\Users\Xavier\AppData\Roaming\Research In Motion O43 - CFD: 18/12/2013 - 21:00:39 - [] ----D C:\Users\Xavier\AppData\Roaming\Sage O43 - CFD: 27/08/2013 - 21:47:21 - [] ----D C:\Users\Xavier\AppData\Roaming\Scribus O43 - CFD: 26/01/2014 - 11:45:20 - [] R-H-D C:\Users\Xavier\AppData\Roaming\SecuROM O43 - CFD: 07/02/2015 - 20:05:33 - [] ----D C:\Users\Xavier\AppData\Roaming\Serif O43 - CFD: 03/08/2013 - 19:33:04 - [] ----D C:\Users\Xavier\AppData\Roaming\Soluto O43 - CFD: 19/01/2014 - 11:05:37 - [] ----D C:\Users\Xavier\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1 O43 - CFD: 07/04/2015 - 18:32:59 - [] ----D C:\Users\Xavier\AppData\Roaming\Super Optimizer =>PUP.SuperOptimizer O43 - CFD: 25/01/2014 - 12:13:58 - [] ----D C:\Users\Xavier\AppData\Roaming\TeamViewer O43 - CFD: 09/02/2014 - 17:08:42 - [] ----D C:\Users\Xavier\AppData\Roaming\Tencent =>Adware.TencentAddressBar O43 - CFD: 17/10/2013 - 18:47:57 - [] ----D C:\Users\Xavier\AppData\Roaming\Thunderbird =>.Mozilla Corporation O43 - CFD: 10/11/2014 - 23:05:57 - [] ----D C:\Users\Xavier\AppData\Roaming\vlc O43 - CFD: 22/03/2014 - 15:44:14 - [0] ----D C:\Users\Xavier\AppData\Roaming\XCPCSync.OEM O43 - CFD: 03/08/2013 - 10:15:18 - [] ----D C:\Users\Xavier\AppData\Roaming\Zeon O43 - CFD: 07/04/2015 - 18:40:13 - [] ----D C:\Users\Xavier\AppData\Roaming\ZHP =>.Nicolas Coolman O43 - CFD: 07/04/2015 - 18:29:31 - [] ----D C:\Users\Xavier\AppData\Local\Adobe O43 - CFD: 18/03/2015 - 23:06:33 - [0] ----D C:\Users\Xavier\AppData\Local\AntiLogger Free O43 - CFD: 29/07/2013 - 22:25:09 - [] -SH-D C:\Users\Xavier\AppData\Local\Application Data O43 - CFD: 14/03/2015 - 23:04:11 - [] ----D C:\Users\Xavier\AppData\Local\ATI O43 - CFD: 16/10/2014 - 18:25:07 - [0] ----D C:\Users\Xavier\AppData\Local\Diagnostics O43 - CFD: 15/09/2014 - 19:29:01 - [] ----D C:\Users\Xavier\AppData\Local\Downloaded Installations O43 - CFD: 29/03/2014 - 14:45:17 - [] ----D C:\Users\Xavier\AppData\Local\eclipse O43 - CFD: 07/02/2015 - 20:20:15 - [] -SH-D C:\Users\Xavier\AppData\Local\EmieBrowserModeList O43 - CFD: 04/06/2014 - 20:13:03 - [] -SH-D C:\Users\Xavier\AppData\Local\EmieSiteList O43 - CFD: 04/06/2014 - 20:13:03 - [] -SH-D C:\Users\Xavier\AppData\Local\EmieUserList O43 - CFD: 02/08/2013 - 19:32:59 - [] ----D C:\Users\Xavier\AppData\Local\ESET O43 - CFD: 24/02/2014 - 23:43:35 - [] ----D C:\Users\Xavier\AppData\Local\fontconfig O43 - CFD: 13/02/2014 - 22:53:34 - [] ----D C:\Users\Xavier\AppData\Local\Gadwin O43 - CFD: 24/02/2014 - 23:43:32 - [] ----D C:\Users\Xavier\AppData\Local\gegl-0.2 O43 - CFD: 03/08/2013 - 09:47:10 - [] ----D C:\Users\Xavier\AppData\Local\gladinet O43 - CFD: 17/07/2014 - 21:37:32 - [] ----D C:\Users\Xavier\AppData\Local\Google O43 - CFD: 13/02/2015 - 23:12:12 - [] ----D C:\Users\Xavier\AppData\Local\gtk-2.0 O43 - CFD: 29/07/2013 - 22:25:09 - [] -SH-D C:\Users\Xavier\AppData\Local\Historique O43 - CFD: 02/08/2013 - 21:12:20 - [] ----D C:\Users\Xavier\AppData\Local\HP O43 - CFD: 16/02/2015 - 23:19:40 - [] ----D C:\Users\Xavier\AppData\Local\ImpressionFacile O43 - CFD: 16/10/2014 - 17:53:12 - [] ----D C:\Users\Xavier\AppData\Local\IsolatedStorage O43 - CFD: 04/08/2013 - 18:17:25 - [] ----D C:\Users\Xavier\AppData\Local\Logishrd O43 - CFD: 03/08/2013 - 22:22:23 - [] ----D C:\Users\Xavier\AppData\Local\Macromedia O43 - CFD: 03/08/2013 - 15:01:55 - [] ----D C:\Users\Xavier\AppData\Local\Memory-Map-License O43 - CFD: 13/10/2014 - 20:46:50 - [] ----D C:\Users\Xavier\AppData\Local\Micro Application O43 - CFD: 14/01/2015 - 20:22:55 - [] ----D C:\Users\Xavier\AppData\Local\Microsoft O43 - CFD: 17/02/2014 - 20:22:18 - [] ----D C:\Users\Xavier\AppData\Local\Microsoft Help O43 - CFD: 13/02/2015 - 22:59:12 - [] ----D C:\Users\Xavier\AppData\Local\MicroVision Applications O43 - CFD: 13/10/2014 - 20:46:48 - [] ----D C:\Users\Xavier\AppData\Local\Micro_Application O43 - CFD: 08/10/2013 - 21:09:34 - [] ----D C:\Users\Xavier\AppData\Local\Mozilla O43 - CFD: 27/08/2013 - 21:44:01 - [] ----D C:\Users\Xavier\AppData\Local\Nuance O43 - CFD: 24/02/2014 - 23:25:31 - [] ----D C:\Users\Xavier\AppData\Local\Programs O43 - CFD: 29/03/2014 - 14:45:00 - [] ----D C:\Users\Xavier\AppData\Local\Research In Motion O43 - CFD: 07/04/2015 - 18:39:30 - [] ----D C:\Users\Xavier\AppData\Local\Temp O43 - CFD: 29/07/2013 - 22:25:09 - [] -SH-D C:\Users\Xavier\AppData\Local\Temporary Internet Files O43 - CFD: 08/10/2014 - 20:58:13 - [] ----D C:\Users\Xavier\AppData\Local\Thunderbird =>.Mozilla Corporation O43 - CFD: 15/09/2014 - 19:40:18 - [] ----D C:\Users\Xavier\AppData\Local\VirtualStore O43 - CFD: 18/03/2015 - 23:09:46 - [] ----D C:\Users\Xavier\AppData\Local\Zemana O43 - CFD: 14/07/2009 - 06:54:32 - [] R---D C:\Users\Xavier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 14/03/2015 - 22:45:38 - [] R---D C:\Users\Xavier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 16/03/2015 - 22:23:19 - [0] ----D C:\Users\Xavier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Advanced Port Scanner O43 - CFD: 29/03/2014 - 14:35:40 - [] ----D C:\Users\Xavier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BlackBerry O43 - CFD: 06/04/2015 - 14:48:25 - [0] ----D C:\Users\Xavier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CartoExploreur O43 - CFD: 14/07/2009 - 06:49:38 - [] R---D C:\Users\Xavier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 01/04/2015 - 18:10:14 - [] R---D C:\Users\Xavier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup ~ Program Folder: 306 Scanned in 00mn 00s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.68F242EA45FF2AAC1012A9765A97DC7D] - 01/04/2015 - 21:38:10 ---A- . (.Resplendence Software Projects Sp. - Resplendence SanityCheck.) -- C:\Windows\System32\Drivers\rspSanity64.sys [31328] O44 - LFC:[MD5.222C0F02D768E7A74C6CB54815CE734F] - 07/04/2015 - 17:19:13 -S-A- . (...) -- C:\Windows\bootstat.dat [67584] O44 - LFC:[MD5.B258E0750CEC2E017645146EC2382DA1] - 07/04/2015 - 17:19:15 ---A- . (...) -- C:\Windows\setupact.log [76742] O44 - LFC:[MD5.C1DCD5C194374CB51495A046F5F77412] - 07/04/2015 - 17:25:42 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1525597] O44 - LFC:[MD5.C9556E42DF3CD57DD83DD309BC117877] - 07/04/2015 - 17:26:05 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1812380] O44 - LFC:[MD5.7B63AE8B3414F33FC61896BF5CC52714] - 07/04/2015 - 17:26:05 ---A- . (...) -- C:\Windows\System32\perfc009.dat [122126] O44 - LFC:[MD5.F2816D69C13410A174CA0292F933B236] - 07/04/2015 - 17:26:05 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [210564] O44 - LFC:[MD5.8103193514059F4ADD6796A888A3C7C4] - 07/04/2015 - 17:26:05 ---A- . (...) -- C:\Windows\System32\perfh009.dat [654254] O44 - LFC:[MD5.EB9C067407A814CE7B976CF5B6982398] - 07/04/2015 - 17:26:05 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [828080] O44 - LFC:[MD5.AAE6A650F791FE660068457A5BB6FF02] - 07/04/2015 - 17:39:09 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512] O44 - LFC:[MD5.82DA0901A5F9F9E0998002BDD8033785] - 31/03/2015 - 19:09:13 ---A- . (.Emsisoft - OA Helper Driver.) -- C:\Windows\System32\Drivers\OAnet.sys [35368] ~ Files: 11 Scanned in 00mn 26s ---\\ Déni du service (Local Security Authority) (O48) O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll ~ LSA: 8 Scanned in 00mn 00s ---\\ Contrôle du Safe Boot (CSB) (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys ~ CSB: 13 Scanned in 00mn 00s ---\\ Clé de registre Shell MountPoints2 (MPSK) (O51) O51 - MPSK:{193ec372-91d5-11e3-93bd-806e6f6e6963}\AutoRun\command. (...) -- G:\setup.exe (.not file.) O51 - MPSK:{3813e06c-9195-11e3-bc41-00e04c6913e9}\AutoRun\command. (...) -- G:\setup.exe (.not file.) O51 - MPSK:{3813e08a-9195-11e3-bc41-00e04c6913e9}\AutoRun\command. (...) -- G:\setup.exe (.not file.) ~ Keys: Scanned in 00mn 00s ---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52) O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm ~ TDSD: 2 Scanned in 00mn 00s ---\\ Enumération des clés de registre SecurityProviders (MCSP) (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll ~ MSCP: 2 Scanned in 00mn 00s ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0 O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 16 Scanned in 00mn 00s ---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56) O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0 ~ MWPE Keys: 3 Scanned in 00mn 00s ---\\ Liste des pilotes du système (SDL) (O58) O58 - SDL:14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088] O58 - SDL:14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [339536] O58 - SDL:14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\Drivers\adpu320.sys [182864] O58 - SDL:14/07/2009 - 02:52:21 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [15440] O58 - SDL:18/04/2014 - 03:39:06 ---A- . (.Advanced Micro Devices - AMD ACP Kernel Service Driver.) -- C:\Windows\System32\Drivers\amdacpksd.sys [274656] O58 - SDL:11/03/2011 - 07:41:12 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [107904] O58 - SDL:14/07/2009 - 02:52:20 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows -.) -- C:\Windows\System32\Drivers\amdsbs.sys [194128] O58 - SDL:11/03/2011 - 07:41:12 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [27008] O58 - SDL:14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [87632] O58 - SDL:14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [97856] O58 - SDL:21/06/2014 - 18:01:22 ---A- . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\Windows\System32\Drivers\AtihdW76.sys [94720] O58 - SDL:18/04/2014 - 03:36:46 ---A- . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\Drivers\atikmdag.sys [15376384] O58 - SDL:18/04/2014 - 02:07:06 ---A- . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\System32\Drivers\atikmpag.sys [638976] O58 - SDL:10/06/2009 - 21:34:23 ---A- . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver..) -- C:\Windows\System32\Drivers\b57nd60a.sys [270848] O58 - SDL:10/06/2009 - 21:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [18432] O58 - SDL:10/06/2009 - 21:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [8704] O58 - SDL:14/07/2009 - 02:19:07 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [286720] O58 - SDL:10/06/2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [47104] O58 - SDL:10/06/2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [14976] O58 - SDL:10/06/2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [14720] O58 - SDL:10/06/2009 - 21:34:28 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbda.sys [468480] O58 - SDL:20/10/2009 - 02:00:00 ----- . (.Sonic Solutions - CDR4 64-bit CD and DVD Place Holder Driver (see PxHelp).) -- C:\Windows\System32\Drivers\cdr4_xp.sys [10224] O58 - SDL:20/10/2009 - 02:00:00 ----- . (.Sonic Solutions - CDRAL 64-bit Place Holder Driver (see PxHelp).) -- C:\Windows\System32\Drivers\cdralw2k.sys [10224] O58 - SDL:26/06/2014 - 06:33:42 ---A- . (.Windows ® Win 7 DDK provider - Safe Deletion Driver.) -- C:\Windows\System32\Drivers\CFRMD.sys [37976] O58 - SDL:14/07/2009 - 02:52:31 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [17488] O58 - SDL:22/09/2014 - 08:20:06 ---A- . (.ESET - Amon monitor.) -- C:\Windows\System32\Drivers\eamonm.sys [243440] O58 - SDL:22/09/2014 - 08:20:06 ---A- . (.ESET - Devmon monitor.) -- C:\Windows\System32\Drivers\edevmon.sys [241368] O58 - SDL:22/09/2014 - 08:20:06 ---A- . (.ESET - ESET Helper driver.) -- C:\Windows\System32\Drivers\ehdrv.sys [169280] O58 - SDL:14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496] O58 - SDL:22/09/2014 - 08:20:06 ---A- . (.ESET - ESET Personal Firewall driver.) -- C:\Windows\System32\Drivers\epfw.sys [222280] O58 - SDL:22/09/2014 - 08:20:06 ---A- . (.ESET - Epfw NDIS LightWeight Filter.) -- C:\Windows\System32\Drivers\EpfwLWF.sys [44632] O58 - SDL:22/09/2014 - 08:20:06 ---A- . (.ESET - ESET Personal Firewall driver.) -- C:\Windows\System32\Drivers\epfwwfp.sys [63160] O58 - SDL:10/06/2009 - 21:34:33 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbda.sys [3286016] O58 - SDL:10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232] O58 - SDL:20/11/2010 - 14:33:35 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [78720] O58 - SDL:11/03/2011 - 07:41:26 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\Drivers\iaStorV.sys [410496] O58 - SDL:23/09/2009 - 19:23:02 ---A- . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\Drivers\igdkmd64.sys [6180832] O58 - SDL:14/07/2009 - 02:48:04 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [44112] O58 - SDL:30/12/2014 - 13:18:16 ---A- . (.Zemana Ltd. - Zemana AntiLogger Free.) -- C:\Windows\System32\Drivers\KeyCrypt64.sys [76520] O58 - SDL:03/01/2013 - 09:17:38 ---A- . (.Logitech, Inc. - Logitech HID Filter Driver..) -- C:\Windows\System32\Drivers\LHidFilt.Sys [77192] O58 - SDL:03/01/2013 - 09:17:38 ---A- . (.Logitech, Inc. - Logitech Mouse Filter Driver..) -- C:\Windows\System32\Drivers\LMouFilt.Sys [61832] O58 - SDL:22/10/2013 - 17:26:57 ---A- . (.Logitech, Inc. - Logitech Non-Plug and Play Driver..) -- C:\Windows\System32\Drivers\LNonPnP.sys [18960] O58 - SDL:14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [114752] O58 - SDL:14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [106560] O58 - SDL:14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [65600] O58 - SDL:14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [115776] O58 - SDL:14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for.) -- C:\Windows\System32\Drivers\megasas.sys [35392] O58 - SDL:14/07/2009 - 02:48:04 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [284736] O58 - SDL:14/07/2009 - 02:48:26 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [51264] O58 - SDL:11/03/2011 - 07:41:34 ---A- . (.NVIDIA Corporation - NVIDIA® nForce RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [148352] O58 - SDL:11/03/2011 - 07:41:34 ---A- . (.NVIDIA Corporation - NVIDIA® nForce Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [166272] O58 - SDL:11/10/2013 - 02:40:50 ---A- . (.Emsisoft - OA Helper Driver.) -- C:\Windows\System32\Drivers\OAnet.sys [35368] O58 - SDL:19/03/2010 - 02:00:00 ----- . (.Sonic Solutions - Px Engine Device Driver for 64-bit Windows.) -- C:\Windows\System32\Drivers\PxHlpa64.sys [55856] O58 - SDL:31/08/2012 - 18:54:22 ---A- . (.Qualcomm Inc. - USB NDIS Miniport Driver.) -- C:\Windows\System32\Drivers\qcusbnet.sys [161792] O58 - SDL:31/08/2012 - 18:53:46 ---A- . (.Qualcomm Inc. - USB/Serial Device Driver.) -- C:\Windows\System32\Drivers\qcusbser.sys [125952] O58 - SDL:14/07/2009 - 02:45:46 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1524816] O58 - SDL:14/07/2009 - 02:45:45 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [128592] O58 - SDL:10/12/2012 - 15:48:02 ---A- . (.Research in Motion Ltd - RIM Virtual Serial Driver.) -- C:\Windows\System32\Drivers\RimSerial_AMD64.sys [44544] O58 - SDL:02/12/2013 - 11:34:56 ---A- . (.BlackBerry Limited - BlackBerry Device Driver.) -- C:\Windows\System32\Drivers\RimUsb_AMD64.sys [79872] O58 - SDL:07/05/2014 - 11:41:04 ---A- . (.Research in Motion Limited - RIM Tunnel Driver.) -- C:\Windows\System32\Drivers\rimvndis6_AMD64.sys [17920] O58 - SDL:29/10/2012 - 07:20:32 ---A- . (.Resplendence Software Projects Sp. - Resplendence SanityCheck.) -- C:\Windows\System32\Drivers\rspSanity64.sys [31328] O58 - SDL:10/06/2011 - 05:34:52 ---A- . (.Realtek - Realtek 8136/8168/8169 NDIS 6.20 64-bit Driver.) -- C:\Windows\System32\Drivers\Rt64win7.sys [539240] O58 - SDL:10/06/2009 - 21:37:19 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [23040] O58 - SDL:14/07/2009 - 02:45:45 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [43584] O58 - SDL:14/07/2009 - 02:45:46 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [80464] O58 - SDL:21/06/2007 - 05:42:22 ---A- . (.PixArt Imaging Inc. - SPC610NC.) -- C:\Windows\System32\Drivers\SPC500NC.SYS [481280] O58 - SDL:14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656] O58 - SDL:14/07/2009 - 02:45:55 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [17488] O58 - SDL:14/07/2009 - 02:45:55 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [161872] O58 - SDL:18/03/2015 - 22:10:01 ---A- . (.Zemana Ltd. - Zemana AntiMalware.) -- C:\Windows\System32\Drivers\zam64.sys [101680] O58 - SDL:11/10/2013 - 02:40:46 ---A- . (...) -- C:\Windows\SysWOW64\drivers\OADriver.sys [64720] O58 - SDL:11/10/2013 - 02:41:06 ---A- . (...) -- C:\Windows\SysWOW64\drivers\oahlp64.sys [62008] O58 - SDL:11/10/2013 - 02:40:48 ---A- . (.Emsisoft - TDI Helper Driver.) -- C:\Windows\SysWOW64\drivers\OAmon.sys [52360] ~ Drivers: 73 Scanned in 00mn 03s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC: 01/04/2015 - 18:40:51 ---A- . (...) -- C:\Users\Xavier\AppData\Local\Adobe\Acrobat\11.0\UserCache.bin [155854] O61 - LFC: 01/04/2015 - 18:40:55 ---A- . (.Resplendence Software Projects Sp..) -- C:\Users\Xavier\Downloads\sanitySetup.exe [1331232] O61 - LFC: 07/04/2015 - 18:40:53 ---A- . (.Super PC Tools ltd.) -- C:\Users\Xavier\AppData\Local\Temp\supoptsetup.exe [5936560] =>PUP.SuperPCTools O61 - LFC: 07/04/2015 - 18:40:56 ---A- . (.Nicolas Coolman.) -- C:\Users\Xavier\Downloads\ZHPDiag2.exe [6877287] =>.Nicolas Coolman O61 - LFC: 31/03/2015 - 18:40:53 ---A- . (...) -- C:\Users\Xavier\AppData\Local\Temp\ProxyX64Process_18467.exe [41472] O61 - LFC: 31/03/2015 - 18:40:54 ---A- . (.Emsisoft GmbH.) -- C:\Users\Xavier\Desktop\OnlineArmorSetup(1).exe [10696960] O61 - LFC: 31/03/2015 - 18:40:55 ---A- . (...) -- C:\Users\Xavier\Downloads\EmsisoftEmergencyKit.exe [161500904] ~ 1239 Fichiers temporaires (Temporary files) ~ 170 Fichiers cookies (Cookies files) ~ Files: 7 Scanned in 00mn 06s ---\\ Liste des outils de désinfection (LATC) (O63) O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn 00s ---\\ Liste les services legacy du registre (LALS) (O64) O64 - Services: CurCS - 18/04/2014 - C:\Windows\System32\DRIVERS\atikmdag.sys (amdkmdag) .(.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) - LEGACY_AMDKMDAG O64 - Services: CurCS - 26/06/2014 - C:\Windows\System32\Drivers\CFRMD.sys (CFRMD) .(.Windows ® Win 7 DDK provider - Safe Deletion Driver.) - LEGACY_CFRMD O64 - Services: CurCS - 22/09/2014 - C:\Windows\System32\DRIVERS\eamonm.sys (eamonm) .(.ESET - Amon monitor.) - LEGACY_EAMONM O64 - Services: CurCS - 22/09/2014 - C:\Windows\System32\DRIVERS\ehdrv.sys (ehdrv) .(.ESET - ESET Helper driver.) - LEGACY_EHDRV O64 - Services: CurCS - 22/09/2014 - C:\Windows\System32\DRIVERS\epfw.sys (epfw) .(.ESET - ESET Personal Firewall driver.) - LEGACY_EPFW O64 - Services: CurCS - 22/09/2014 - C:\Windows\System32\DRIVERS\EpfwLWF.sys (EpfwLWF) .(.ESET - Epfw NDIS LightWeight Filter.) - LEGACY_EPFWLWF O64 - Services: CurCS - 22/09/2014 - C:\Windows\System32\DRIVERS\epfwwfp.sys (epfwwfp) .(.ESET - ESET Personal Firewall driver.) - LEGACY_EPFWWFP O64 - Services: CurCS - 11/10/2013 - C:\Windows\sysWow64\Drivers\OADriver.sys (OADevice) .(...) - LEGACY_OADEVICE O64 - Services: CurCS - 11/10/2013 - C:\Windows\sysWOW64\Drivers\OAmon.sys (OAmon) .(.Emsisoft - TDI Helper Driver.) - LEGACY_OAMON O64 - Services: CurCS - 10/06/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV O64 - Services: CurCS - 18/03/2015 - C:\Windows\system32\drivers\zam64.sys (ZAM) .(.Zemana Ltd. - Zemana AntiMalware.) - LEGACY_ZAM ~ Legacy: 124 Scanned in 00mn 00s ---\\ Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O67 - Shell Spawning: <.js> <jsfile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe ~ FASS Keys: 11 Scanned in 00mn 00s ---\\ Menu de démarrage Internet (SMI) (O68) O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Search Provided by Yahoo) - http://fr.yhs4.search.yahoo.comEtCzzzy0F0ByDyEtDyByC2QtN0A0LzutB%26cr%3D1291938040%26a%3Dwny_ggfc_15_15%26os%3DWindows 7 Professional&p={searchTerms} O69 - SBI: SearchScopes [HKCU] {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} - (Yahoo! Search) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKUS\.DEFAULT] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKUS\S-1-5-18] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com ~ Keys: Scanned in 00mn 00s ---\\ Enumère les service demarrés par Svchost (SSS) (O83) O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [236032] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [777728] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [859648] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [680960] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [99328] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [344064] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [64512] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [359424] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows.) -- C:\Windows\System32\tapisrv.dll [316928] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [683520] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2477536] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [849920] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [370688] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [569344] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [30720] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70144] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [156672] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [67584] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [242688] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [121856] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136704] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1110016] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [90624] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84480] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [210432] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [44544] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864] O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [193536] ~ Services: 33 Scanned in 00mn 00s ---\\ Recherche particulière à la racine du système (SPRF) (O84) [MD5.C1CA99F7AD8AB8ED61356DB1FC98378C] [sPRF][31/03/2015] (.Emsisoft GmbH - Online Armor Setup.) -- C:\Users\Xavier\Desktop\OnlineArmorSetup(1).exe [10696960] [MD5.15EDC16DBD5F9B6B59EAB98E2FDEC560] [sPRF][08/04/2014] (.TeamViewer GmbH - Pas de description.) -- C:\Users\Xavier\Desktop\TeamViewer_Setup_fr.exe [6122752] ~ Files: 2 Scanned in 00mn 00s ---\\ Liste des exceptions du parefeu (FirewallRules) (O87) O87 - FAEL: "{C508843B-FD61-4AD6-847F-0797B09F4F7F}" | In - None - P17 - TRUE | .(.Tencent - 腾讯高速下载引擎.) -- C:\program files (x86)\common files\tencent\qqdownload\123\tencentdl.exe =>Adware.TencentAddressBar ~ Firewall: 1 Scanned in 00mn 01s ---\\ Export de clés de registre aléatoires (O91) [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:060df2cd="blA+/Y//GPAf/X6/b/Ah/Xt/aPAp/Yq/GPAp/YP/UxAs/X6/aP////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:0c230bcb="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:0dc3ee96="/P////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:0e93c3f3="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:1520c6f1="V/////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:1c311243="blA+/Y//GPAf/X6/b/Ah/Xt/aPAp/Yq/GPAf/YV/cPAf/XF/UxAs/X6/aP////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:27ddcf6f="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:2d71d5ab="V/////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:2e22d94e="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:340d3099="/P////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:37b7a6d8="UlAr/XJ/c//k////" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:38583bc3="Ml/2/CF/M//g/CZ////%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:3c09c42b="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:414bc593="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:48bd1aff="V/////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:51d2f2ea="JlA+/Y//GPAf/D6/b/Ah/Xt/aPAp/Yq/GPAf/B//JlAh/XD/c/Ag/B//VP/j/Cx/V//j/CZ/V//h/C [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:587b5709="V/////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:6185d035="VP/h/CP/V//l////" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:65114b36="VP/+////" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:72758a5d="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:7367429f="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:7f69fa1f="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:8b9e4cbc="V/////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:a0743acc="N/////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:a1dcff5b="V/////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:a2e3b941="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:bbf88800="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:c24899a6="VP/g/CV/Vl/1/CF////%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:c5705860="Vx////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:c6c5dd44="V/////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:c99a5f5c="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:d1abcdb6="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:d94388d2="blA+/Y//GPAf/X6/b/Ah/Xt/aPAp/Yq/GPAf/YV/cPAf/XF/UxAs/X6/aP////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:e46c271e="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:e8f9dcc7="UlAr/XJ/c//k////" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:f0bf0bde="///%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:f1f24e29="Vl/l/C/////%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:f2c53c49="UlAr/XJ/c//k////" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:f6ad6fa6="V/////%%" [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6\60513467414968785\eae10f9d]:fe94ce1e="V/////%%" ~ Export Key Software: Scanned in 00mn 00s ---\\ Recherche de clés de registre Tracing (O100) HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\tencentdl_RASAPI32 =>Adware.TencentAddressBar ~ BTK: 88 Scanned in 00mn 00s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 06/04/2015 268464 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe SS - | Demand 21/01/2014 585728 | (BlackBerry Device Manager) . (.BlackBerry Limited.) - C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe SS - | Demand 13/03/2015 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe SS - | Demand 08/02/2013 359664 | (LBTServ) . (.Logitech, Inc..) - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe SS - | Demand 05/09/2012 234776 | (McComponentHostService) . (.McAfee, Inc..) - C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe SS - | Demand 26/03/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe SS - | Auto 07/05/2014 1324544 | (RIM Tunnel Service) . (.Research In Motion Limited.) - C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe SS - | Auto 11/10/2013 4457688 | (SvcOnlineArmor) . (.Emsisoft GmbH.) - C:\Program Files (x86)\Online Armor\oasrv.exe SR - | Auto 01/09/2011 169624 | (AdobeActiveFileMonitor10.0) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe SR - | Auto 07/04/2015 2320432 | (cae99edb) . (...) - c:\Program Files (x86)\Super Optimizer\SupOptStats.dll =>PUP.SuperOptimizer SR - | Auto 01/10/2014 1349576 | (ekrn) . (.ESET.) - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe SR - | Auto 16/01/2013 73728 | (LightScribeService) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe SR - | Auto 11/10/2013 584864 | (OAcat) . (.Emsisoft GmbH.) - C:\Program Files (x86)\Online Armor\OAcat.exe SR - | Auto 23/10/2012 135056 | (PDFProFiltSrv) . (.Nuance Communications, Inc..) - C:\Program Files (x86)\Nuance\PDF Professional 8\PDFProFiltSrv.exe SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 22/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 24/02/2015 10340720 | (ZAMSvc) . (.Zemana Ltd..) - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe ~ Services: Scanned in 00mn 09s ---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80) Run by Xavier at 07/04/2015 18:42:02 ~ OS 64 not supported by MBR tool ~ MBR: 0 Scanned in 00mn 00s ---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by Xavier at 07/04/2015 18:42:04 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 02s ---\\ Scan Additionnel (O88) Database Version : 13008 - (29/03/2015) Clés trouvées (Keys found) : 7 Valeurs trouvées (Values found) : 4 Dossiers trouvés (Folders found) : 9 Fichiers trouvés (Files found) : 4 [HKLM\SYSTEM\CurrentControlSet\Services\cae99edb] =>PUP.SuperOptimizer^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Digital Sites] =>PUP.Dealply^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\File Opener Packages] =>Adware.InstallCore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Tweaks FileOpener] =>Adware.InstallCore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Super Optimizer_is1] =>PUP.SuperPCTools^ [HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro [HKLM\Software\Wow6432Node\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:Super Optimizer =>PUP.SuperOptimizer^ [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]:DigitalSites =>Hijacker.DSite^ C:\Program Files (x86)\Super Optimizer =>PUP.SuperOptimizer^ C:\Program Files (x86)\Common Files\Tencent =>Adware.TencentAddressBar^ C:\ProgramData\Tencent =>Adware.TencentAddressBar^ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileOpener =>Adware.InstallCore^ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Super Optimizer =>PUP.SuperOptimizer^ C:\Users\Xavier\AppData\Roaming\1H1Q1V1N1N1O1R =>Adware.InstallCore^ C:\Users\Xavier\AppData\Roaming\DigitalSites =>Hijacker.DSite^ C:\Users\Xavier\AppData\Roaming\Super Optimizer =>PUP.SuperOptimizer^ C:\Users\Xavier\AppData\Roaming\Tencent =>Adware.TencentAddressBar^ C:\Program Files (x86)\Super Optimizer\SupOptLauncher.exe =>PUP.SuperOptimizer^ [HKCU\Software\Super Optimizer] =>PUP.SuperOptimizer^ [HKLM\Software\Conduit] =>Toolbar.Conduit^ [HKLM\Software\Wow6432Node\3266ea39-4197-fc12-6b8c-b60ebb2914a6] =>PUP.CrossRider^ ~ Additionnel Scan: 382564 Items scanned in 00mn 34s ---\\ Informations complémentaires sur les modules ~ ~ ~ ~ ~ AMI: 4 Scanned in 00mn 00s ---\\ Récapitulatif des détections trouvées sur votre station ~ MSI: 10 link(s) detected in 00mn 00s End of the scan (1496 lines in 02mn 55s)(0.10)
  11. Bonjour, Je suis sous la surveillance d'un keylogger, tout ce que je tape sur mon clavier est commenté ainsi par deux secrétaires. Je suis accusé de calomnie chaque fois que j'en parle. Comme c'est très pénible et que j'ai du mal à faire mon travail, il m'est arrivé plusieurs fois d'amener des bases de données sous Access à finir de développer chez moi, or depuis le début de l'année, je me suis envoyé des messages d'une boite mail personnelle à une autre personnelle volontairement provoquant vis-à-vis de ces personnes. J'en ai entendu parler à mon travail. J'ai changé les mots de passe à plusieurs reprises, cela ne change rien. IObit malware, Zemana ne trouvent rien sur mon ordinateur. Est-ce réellement possible que mon ordinateur ait été contaminé par les fichiers que j'ai amené pour finir mon travail chez moi ? Est-ce réellement possible qu'un antilogger envoie des rapports que je me connecte sous Linux ou sous Windows, ou ne le fait-il que lorsque je prends Windows ?
×
×
  • Créer...