~ Rapport de ZHPDiag v2015.5.2.45 - Nicolas Coolman (02/05/2015) ~ Lancé par admin (04/05/2015 15:24:43) ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ Adresse du Forum http://forum.nicolascoolman.fr ~ Traduit par Nicolas Coolman ~ Etat de la version : Version à jour. ~ Liste blanche : Désactivée par l'utilisateur ~ Elévation des Privilèges : OK ~ User Account Control (UAC): Activate by user ---\\ Navigateurs Internet MSIE: Internet Explorer v11.0.9600.17728 MFIE: Mozilla Firefox 37.0.2 (Defaut) GCIE: Google Chrome v42.0.2311.135 OPIE: Opera Stable v27.0.1689.66 ---\\ Informations sur les produits Windows ~ Langage: Français Windows Server License Manager Script : Absent (Not found) Windows ID Activation : Inconnue (Unknown) Windows Licence : Inconnue (Unknown) Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK Windows 7 Professional, 32-bit Service Pack 1 (Build 7601) ---\\ Logiciels de protection du système Microsoft Security Client v4.7.0205.0 McAfee Security Scan Plus v3.8.150.1 Windows Defender W7 (Deactivate) ---\\ Logiciels d'optimisation du système CCleaner v5.03 ---\\ Logiciels de partage PeerToPeer ---\\ Surveillance de Logiciels Adobe Flash Player 17 NPAPI Adobe Acrobat Reader DC - Français ---\\ Informations sur le système ~ Processor: x86 Family 6 Model 23 Stepping 10, GenuineIntel ~ Operating System: 32 Bits Boot mode: Normal (Normal boot) Total RAM: 1976 MB (16% free) System Restore: Activé (Enable) System drive C: has 8 GB (16%) free of 49 GB ---\\ Mode de connexion au système ~ Computer Name: ADMIN-PC ~ User Name: admin ~ All Users Names: HomeGroupUser$, Administrateur, admin, ~ Unselected Option: None Logged in as Administrator ---\\ Variables d'environnement ~ System Unit : C:\ ~ %AppZHP% : C:\Users\admin\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\admin\AppData\Roaming\ ~ %Desktop% : C:\Users\admin\Desktop\ ~ %Favorites% : C:\Users\admin\Favorites\ ~ %LocalAppData% : C:\Users\admin\AppData\Local\ ~ %StartMenu% : C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumération des unités disques C: Hard drive, Flash drive, Thumb drive (Free 8 Go of 49 Go) D: Hard drive, Flash drive, Thumb drive (Free 205 Go of 249 Go) E: CD-ROM drive (Not Inserted) ---\\ Etat du Centre de Sécurité Windows [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowMyGames: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: Modified =>Hijacker.Application [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ~ Security Center: 46 Scanned in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.15BC38A7492BEFE831966ADB477CF76F] - (.Microsoft Corporation - Explorateur Windows.) (.03/02/2015 - 21:56:27.) -- C:\Windows\Explorer.exe [2613248] [MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256] [MD5.C46904F2E9E121A91DDDABB48D7648C3] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.13/03/2015 - 03:20:28.) -- C:\Windows\System32\wininet.dll [1888256] [MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.17/07/2014 - 02:39:27.) -- C:\Windows\System32\Winlogon.exe [304128] [MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 22:29:24.) -- C:\Windows\System32\sppcomapi.dll [193536] [MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:36:07.) -- C:\Windows\system32\Drivers\AFD.sys [338944] [MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584] [MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656] [MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544] [MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 22:29:07.) -- C:\Windows\system32\Drivers\DfsC.sys [78336] [MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544] [MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896] [MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888] [MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904] [MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 22:29:08.) -- C:\Windows\system32\Drivers\netBT.sys [187904] [MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:18:22.) -- C:\Windows\system32\Drivers\ntfs.sys [1212352] [MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360] [MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848] [MD5.B973FCFC50DC1434E1970A146F7E3885] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.20/11/2010 - 22:29:49.) -- C:\Windows\system32\Drivers\rdpdr.sys [133632] [MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168] [MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:32:14.) -- C:\Windows\system32\Drivers\tdx.sys [74752] [MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\volsnap.sys [245632] ~ Generic Processes: Scanned in 00mn 04s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes musiques (My Musics) : 1/2 ~ Mes Favoris (My Favorites) : 1/26 ~ Mes Documents (My Documents) : 1/97 ~ Mon Bureau (My Desktop) : 25/397 ~ Menu demarrer (Programs) : 1/4 ~ Hidden Files: Scanned in 00mn 03s ---\\ Processus lancés [MD5.6667B602F5FA5012859A44FD0D8D2B2E] - (...) -- C:\Users\admin\AppData\Everything\SFK.exe [92672] [PID.4016] [MD5.13A317E9A45E2E5A864D120D8A2058E0] - (.http://goforfiles.com/ - GoforFiles Updater Application.) -- C:\Program Files\GoForFilesUpdater\GoForFilesUpdater.exe [278096] [PID.2340] =>P2P.GoforFiles [MD5.38813ADD1A1C6B72D2D153DD27B2BEB1] - (.FlashBeat - Install.) -- C:\ProgramData\FlashBeat\FlashBeat.exe [634880] [PID.4028] =>PUP.FlashBeat [MD5.C681F347514CC8671977FCBD2B7D001A] - (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe [185872] [PID.3680] [MD5.2C1B1E9174D94E9F6EE3CF373ABAB7DD] - (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxtray.exe [137752] [PID.3956] [MD5.87D78CF6365BDDACBE9D34B60FE0E23B] - (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe [171032] [PID.3916] [MD5.89D3DE5E2C77DCD99C56F0E46310AEA0] - (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe [172568] [PID.3648] [MD5.3FD2E665F30942DD873993070047A8C3] - (.Pas de propriétaire - SearchBase.) -- C:\Users\admin\AppData\Everything\SearchBase.exe [1049088] [PID.3404] [MD5.9A9DDC8E9D12B1567097668249DFF8E9] - (.Pas de propriétaire - everything.) -- C:\Users\admin\AppData\Everything\Everything.exe [332288] [PID.2068] [MD5.20CB286C4591EEA68778CA6626D70D47] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1791272] [PID.4196] [MD5.16AFB34618E1286FF856DC600AC49C79] - (.Pas de propriétaire - DivX Update.) -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968] [PID.4312] [MD5.10247055758850D4D0E9469322A93D42] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.4688] [MD5.C5B54BF8A1306750F3D85FE21A873465] - (.Pas de propriétaire - Viber.) -- C:\Users\admin\AppData\Local\Viber\Viber.exe [936656] [PID.4932] [MD5.3D558E2572EDF52FAD098AF2534B4E20] - (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe [279456] [PID.5024] [MD5.2B24F194FC5B657397ECB2923A68350E] - (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe [5503768] [PID.5176] [MD5.2759F22A2E98ACFE664019534E33508E] - (.Dropbox, Inc. - Dropbox.) -- C:\Users\admin\AppData\Roaming\Dropbox\bin\Dropbox.exe [43376600] [PID.5224] [MD5.7E6B4AD487ED241D8224108E8E86A351] - (.Adobe Systems Incorporated - Adobe® Flash® Player Installer/Uninstaller.) -- C:\Windows\system32\Macromed\Flash\FlashUtil32_17_0_0_169_ActiveX.exe [927920] [PID.3112] [MD5.B3581F426DC500A51091CDD5BACF0454] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [815288] [PID.3556] [MD5.C06C9EC74A0971A31A40723432201C86] - (.Nicolas Coolman - ZHPDiag.) -- D:\ZHPDiag\ZHPDiag.exe [8206336] [PID.3260] [MD5.73D19AFCCCDE13FCA91F3817C58FF1CC] - (.The MathWorks Inc. - MATLAB (R2014a).) -- D:\fichiers\bin\win32\MATLAB.exe [141824] [PID.6952] [MD5.2DC8F1D1E2F387D9CEA87CEBD90E72BF] - (.Pas de propriétaire - 4291ca9383084a1bb30e07571604a9d6.) -- C:\ProgramData\4291ca9383084a1bb30e07571604a9d6\4291ca9383084a1bb30e07571604a9d6.exe [311296] [PID.7556] ~ Processes Running: Scanned in 00mn 28s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9l7vumfu.default\prefs.js (.not file.) C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\pgu6kut4.default-1429039266093\prefs.js M2 - MFEP: RegExtension {e4f94d1e-2f53-401e-8885-681602c0ddd8} . (...) -- C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi M0 - MFSP: prefs.js [admin - pgu6kut4.default-1429039266093] www.google.fr M2 - MFEP: Extension [admin - 9l7vumfu.default] idszasulqgikh_c@ieghilld_ewxvluh.edu M2 - MFEP: Extension [admin - 9l7vumfu.default] veggy@veggyAddon.com M2 - MFEP: Extension [admin - 9l7vumfu.default] {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Adblock Plus Extension Mozilla Firefox M2 - MFEP: prefs.js [admin - pgu6kut4.default-1429039266093\idszasulqgikh_c@ieghilld_ewxvluh.edu] [] DiscountExt v8.19 (..) M2 - MFEP: prefs.js [admin - pgu6kut4.default-1429039266093\veggy@veggyAddon.com] [] Mozilla Firefox Hotfixer v8.19 (..) M2 - MFEP: prefs.js [admin - pgu6kut4.default-1429039266093\{ab2afb3f-ced5-e944-9a35-a0d802a604c7}] [] Zoom It v8.19 (..) =>PUP.ZoomIt M2 - MFEP: Extension [admin - pgu6kut4.default-1429039266093] idszasulqgikh_c@ieghilld_ewxvluh.edu M2 - MFEP: Extension [admin - pgu6kut4.default-1429039266093] veggy@veggyAddon.com M2 - MFEP: Extension [admin - pgu6kut4.default-1429039266093] {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Adblock Plus Extension Mozilla Firefox P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFF12.DLL P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 15.7.20033.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll P2 - FPN:Firefox Plugin Navigator . (.RealNetworks, Inc. - RealPlayer(tm) LiveConnect-Enabled Plug-In.) -- C:\Program Files\Mozilla Firefox\Plugins\nppl3260.dll P2 - FPN:Firefox Plugin Navigator . (.RealNetworks, Inc. - RealJukebox Netscape Plugin.) -- C:\Program Files\Mozilla Firefox\Plugins\nprjplug.dll P2 - FPN:Firefox Plugin Navigator . (.RealNetworks, Inc. - 6.0.12.69.) -- C:\Program Files\Mozilla Firefox\Plugins\nprpjplug.dll P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-france.xml P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\delta-homes.xml =>Hijacker.DeltaHomes P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay-france.xml P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\StartWeb.xml =>Adware.IMBooster P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo-france.xml P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll P2 - FPN: [HKLM] [@divx.com/DivX VOD Helper,version=1.0.0] - (.DivX, LLC. - DivX VOD Helper Plug-in.) -- C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll P2 - FPN: [HKLM] [@divx.com/DivX Web Player Plug-In,version=1.0.0] - (.DivX, LLC - DivX Web Player version 3.2.4.1250.) -- C:\Program Files\DivX\DivX Web Player\npdivx32.dll P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll P2 - FPN: [HKLM] [@real.com/nppl3260;version=6.0.12.69] - (.RealNetworks, Inc. - RealPlayer(tm) LiveConnect-Enabled Plug-In.) -- C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll P2 - FPN: [HKLM] [@real.com/nprjplug;version=1.0.3.69] - (.RealNetworks, Inc. - RealJukebox Netscape Plugin.) -- C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll P2 - FPN: [HKLM] [@real.com/nprpjplug;version=6.0.12.69] - (.RealNetworks, Inc. - 6.0.12.69.) -- C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll P2 - FPN: [HKLM] [@staging.google.com/globalUpdate Update;version=10] - (...) -- C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (.not file.) =>PUP.GlobalUpdate P2 - FPN: [HKLM] [@staging.google.com/globalUpdate Update;version=4] - (...) -- C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (.not file.) =>PUP.GlobalUpdate P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 15.7.20033.) -- C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll P2 - FPN: [HKCU] [@Skype Limited.com/Facebook Video Calling Plugin] - (.Skype Limited - Facebook Video Calling Plugin.) -- C:\Users\admin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll ~ Firefox Browser: 55 Scanned in 00mn 04s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.safefinder.com =>Hijacker.SmartBar R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com =>Hijacker.DeltaHomes R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.safefinder.com =>Hijacker.SmartBar R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com =>PUP.SweetPage R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com =>Hijacker.DeltaHomes R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com =>PUP.SweetPage R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.safefinder.com =>Hijacker.SmartBar R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.safefinder.com =>Hijacker.SmartBar R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://feed.safefinder.com =>Hijacker.SmartBar R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (...) (No version) -- (.not file.) R3 - URLSearchHook: (no name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} . (...) (No version) -- (.not file.) R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 0 ~ IE Browser: 17 Scanned in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:52146;https=127.0.0.1:52146 =>Hijacker.Proxy R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Hosts file redirection (O1) ~ Le fichier hôte est sain (The hosts file is clean) (25) ~ Hosts File: Scanned in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\Desktop [Public]: Automation Software Updater.lnk . (.Siemens AG - Pas de description.) -- C:\Program Files\Common Files\Siemens\ASU\Siemens.Automation.SoftwareUpdater.exe =>PUP.Eorezo ~ Global Startup: 1 Scanned in 00mn 40s ---\\ Applications lancées au démarrage du système (O4) O4 - HKLM\..\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe =>.RealNetworks, Inc O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [DivXMediaServer] . (.DivX, LLC - DivX Media Server Launcher.) -- C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe O4 - HKLM\..\Run: [DivXUpdate] . (.Pas de propriétaire - DivX Update.) -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- C:\Program Files\Microsoft Security Client\msseces.exe O4 - HKLM\..\Run: [SiemensAutomationFileStorage_TIAP13] . (.Siemens AG - Siemens.Automation.ObjectFrame.FileStorage..) -- D:\logiciels\Siemens\Automation\Portal V13\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe O4 - HKLM\..\Run: [gmsd_fr_414] Clé orpheline =>PUP.CrossRider O4 - HKLM\..\Run: [mbot_fr_588] C:\Program Files\mbot_fr_588\mbot_fr_588.exe (.not file.) =>PUP.CrossRider O4 - HKCU\..\Run: [Viber] . (.Pas de propriétaire - Viber.) -- C:\Users\admin\AppData\Local\Viber\Viber.exe O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe O4 - HKCU\..\Run: [pricefountainw.exe] C:\Users\admin\AppData\Local\PriceFountain\pricefountainw.exe (.not file.) =>PUP.PriceFountain O4 - HKCU\..\Run: [BRS] C:\Program Files\WSE_Astromenda\BRS\brs.exe (.not file.) =>PUP.Astromenda O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd O4 - HKCU\..\Run: [UnicoBrowser] C:\Users\admin\AppData\Local\UnicoBrowser\Application\unicobrowser.exe (.not file.) =>PUP.UnicoBrowser O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-3876991765-701069293-2132216276-1000\..\Run: [Viber] . (.Pas de propriétaire - Viber.) -- C:\Users\admin\AppData\Local\Viber\Viber.exe O4 - HKUS\S-1-5-21-3876991765-701069293-2132216276-1000\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe O4 - HKUS\S-1-5-21-3876991765-701069293-2132216276-1000\..\Run: [pricefountainw.exe] C:\Users\admin\AppData\Local\PriceFountain\pricefountainw.exe (.not file.) =>PUP.PriceFountain O4 - HKUS\S-1-5-21-3876991765-701069293-2132216276-1000\..\Run: [BRS] C:\Program Files\WSE_Astromenda\BRS\brs.exe (.not file.) =>PUP.Astromenda O4 - HKUS\S-1-5-21-3876991765-701069293-2132216276-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd O4 - HKUS\S-1-5-21-3876991765-701069293-2132216276-1000\..\Run: [UnicoBrowser] C:\Users\admin\AppData\Local\UnicoBrowser\Application\unicobrowser.exe (.not file.) =>PUP.UnicoBrowser ~ Application: Scanned in 00mn 01s ---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5) O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no ~ IE Control Panel: 1 Scanned in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO ~ IE Extra Buttons: Scanned in 00mn 00s ---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll ~ Winsock: 7 Scanned in 00mn 00s ---\\ Objets ActiveX (Downloaded Program Files)(O16) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} ((no name)) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab ~ Objets ActiveX: Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{E412C835-9AA0-4770-9F4A-8BDD59B90544}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 =>.Google DNS Redirections O17 - HKLM\System\CCS\Services\Tcpip\..\{1716A0AE-8DD6-4B6F-AF02-C6D69DB17BAF}: DhcpNameServer = 212.27.40.241 212.27.40.240 O17 - HKLM\System\CS1\Services\Tcpip\..\{E412C835-9AA0-4770-9F4A-8BDD59B90544}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 =>.Google DNS Redirections O17 - HKLM\System\CS1\Services\Tcpip\..\{1716A0AE-8DD6-4B6F-AF02-C6D69DB17BAF}: DhcpNameServer = 212.27.40.241 212.27.40.240 O17 - HKLM\System\CS2\Services\Tcpip\..\{E412C835-9AA0-4770-9F4A-8BDD59B90544}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 =>.Google DNS Redirections O17 - HKLM\System\CS2\Services\Tcpip\..\{1716A0AE-8DD6-4B6F-AF02-C6D69DB17BAF}: DhcpNameServer = 212.27.40.241 212.27.40.240 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll ~ Winlogon: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - AppInit_DLLs: . (.FlashBeat - Install.) - C:\ProgramData\FlashBeat\FlashBeat32.dll =>PUP.FlashBeat ~ AppInit DLL: Scanned in 00mn 00s ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. ~ SSODL: 1 Scanned in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: goopad (0e6e6c53) . (...) - c:\Program Files\goopad\goopad.dll O23 - Service: SeekerModule (5fd90e6b) . (...) - c:\Program Files\SeekerModule\SeekerModule.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) . (.LSI Corporation - LSI Soft Modem Call Progress Service.) - C:\Program Files\LSI SoftModem\agrsmsvc.exe O23 - Service: Automation License Manager Service (almservice) . (.SIEMENS AG - Automation License Manager Service.) - C:\Program Files\Common Files\Siemens\sws\almsrv\almsrvx.exe O23 - Service: Computer Backup (MyPC Backup) (BackupStack) . (...) - C:\Program Files\MyPC Backup\BackupStack.exe (.not file.) =>PUP.MyPCBackup O23 - Service: ClaraUpdater (ClaraUpdater) . (...) - C:\Program Files\Common Files\ClaraUpdater\ClaraUpdater.exe (.not file.) =>Adware.SupTab O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) . (...) - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe (.not file.) =>PUP.GlobalUpdate O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc O23 - Service: haw (haw) . (...) - c:\windows\haw.exe O23 - Service: mhaw (mhaw) . (...) - c:\windows\mhaw.exe O23 - Service: Reimage Real Time Protector (ReimageRealTimeProtector) . (...) - C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe (.not file.) =>Rogue.ReimageRepair O23 - Service: SIMATIC S7DOS Help Service (s7oiehsx) . (.Siemens AG - Siemens SIMATIC S7DOS Help Service.) - C:\Program Files\Common Files\Siemens\S7IEPG\s7oiehsx.exe O23 - Service: S7TraceServiceX (S7TraceServiceX) . (.Siemens AG - S7TraceServiceX Module.) - C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceServiceX.exe O23 - Service: ServiceEverything (ServiceEverything) . (...) - C:\Users\admin\AppData\Everything\ServiceEverything.exe O23 - Service: WinZiper service (winzipersvc) . (.Taiwan Shui Mu Chih Ching Technology Limite - dsk service.) - C:\Program Files\WinZipper\winzipersvc.exe =>Adware.D365 ~ Services: 12 Scanned in 01mn 25s ---\\ Enumération Active Desktop & MHTML Editor (O24) O24 - Default MHTML Editor: Last - .(...) - (.not file.) ~ Desktop Component: 4 Scanned in 00mn 00s ---\\ Enumère les données de BootExecute (BEX) (O34) O34 - HKLM BootExecute: (autocheck autochk *) - File not found ~ BEX: 1 Scanned in 00mn 00s ---\\ Tâches planifiées en automatique (O39) [MD5.00000000000000000000000000000000] [APT] [a208d04d-b0d5-4747-bf28-bb1ba986e156-5] (...) -- C:\Program Files\HQCinema Pro 2.1V14.04\a208d04d-b0d5-4747-bf28-bb1ba986e156-5.exe (.not file.) [0] =>PUP.CrossRider [MD5.00000000000000000000000000000000] [APT] [a208d04d-b0d5-4747-bf28-bb1ba986e156-5_user] (...) -- C:\Program Files\HQCinema Pro 2.1V14.04\a208d04d-b0d5-4747-bf28-bb1ba986e156-5.exe (.not file.) [0] =>PUP.CrossRider [MD5.64495D9B3C4B640230E9265C23A33F55] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1018056] [MD5.B04A4810C6CC205F9DC72DC22E4AB236] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [268464] [MD5.00000000000000000000000000000000] [APT] [Binkiland] (...) -- C:\Users\admin\AppData\Roaming\BINKIL~1\UPDATE~1\UPDATE~1.exe (.not file.) [0] =>PUP.Binkiland [MD5.2B24F194FC5B657397ECB2923A68350E] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [5503768] [MD5.00000000000000000000000000000000] [APT] [CleanerPro_Popup] (...) -- C:\Program Files\Cleaner Pro\Splash.exe (.not file.) [0] =>PUP.CleanerPro [MD5.00000000000000000000000000000000] [APT] [CleanerPro_Start] (...) -- C:\Program Files\Cleaner Pro\CleanerPro.exe (.not file.) [0] =>PUP.CleanerPro [MD5.00000000000000000000000000000000] [APT] [Digital Sites] (...) -- C:\Users\admin\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.exe (.not file.) [0] =>Hijacker.DSite [MD5.00000000000000000000000000000000] [APT] [Easy Driver Pro Schedule] (...) -- C:\Program Files\Probit Software\Easy Driver Pro\EDPTray.exe (.not file.) [0] =>PUP.ProbitSoftware [MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000Core] (.Facebook Inc..) -- C:\Users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000UA] (.Facebook Inc..) -- C:\Users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [116648] [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [116648] [MD5.00000000000000000000000000000000] [APT] [Installer_sense] (...) -- C:\Users\admin\AppData\Local\Temp\nsyCB50.tmp\setup.exe (.not file.) [0] [MD5.2DC8F1D1E2F387D9CEA87CEBD90E72BF] [APT] [IULCQ] (...) -- C:\ProgramData\4291ca9383084a1bb30e07571604a9d6\4291ca9383084a1bb30e07571604a9d6.exe [311296] [MD5.00000000000000000000000000000000] [APT] [LaunchSignup] (...) -- C:\Program Files\MyPC Backup\Signup Wizard.exe (.not file.) [0] =>PUP.MyPCBackup [MD5.9D9D0351A3B9CFD0A4336F61F2480A82] [APT] [Math Problem Solver CPU] (...) -- C:\Users\admin\AppData\Local\Math Problem Solver\cpu\Solve.exe [184443] [MD5.72AE4B443A4D7138EA1F710946AC735E] [APT] [Math Problem Solver Optimize] (...) -- C:\Users\admin\AppData\Local\Math Problem Solver\Optimize.exe [67740] [MD5.00000000000000000000000000000000] [APT] [Opera scheduled Autoupdate 1422719743] (...) -- C:\Program Files\Opera\launcher.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [PC SpeedUp Service Deactivator] (...) -- C:\Program Files\Accelerer PC\PCSUSD.exe (.not file.) [0] =>Rogue.PCSpeedUp [MD5.00000000000000000000000000000000] [APT] [Price Fountain] (...) -- C:\Users\admin\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.exe (.not file.) [0] =>PUP.PriceFountain [MD5.00000000000000000000000000000000] [APT] [ProPCCleaner_Popup] (...) -- C:\Program Files\Pro PC Cleaner\Splash.exe (.not file.) [0] =>PUP.DoctorPC [MD5.00000000000000000000000000000000] [APT] [ProPCCleaner_Start] (...) -- C:\Program Files\Pro PC Cleaner\ProPCCleaner.exe (.not file.) [0] =>PUP.DoctorPC [MD5.00000000000000000000000000000000] [APT] [ReimageUpdater] (...) -- C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe (.not file.) [0] =>Rogue.ReimageRepair [MD5.00000000000000000000000000000000] [APT] [RocketTab] (...) -- C:\Program Files\Search Extensions\Client.exe (.not file.) [0] =>PUP.RocketTab [MD5.00000000000000000000000000000000] [APT] [RocketTab Update Task] (...) -- C:\Program Files\Search Extensions\uninstall.exe (.not file.) [0] =>PUP.RocketTab [MD5.00000000000000000000000000000000] [APT] [Run_Browser] (...) -- C:\Users\admin\AppData\Local\UnicoBrowser\Application\unicobrowser.exe (.not file.) [0] =>PUP.UnicoBrowser [MD5.13A317E9A45E2E5A864D120D8A2058E0] [APT] [Update Service GoForFiles] (.http://goforfiles.com/.) -- C:\Program Files\GoForFilesUpdater\GoForFilesUpdater.exe [278096] =>P2P.GoforFiles [MD5.00000000000000000000000000000000] [APT] [WSE_Astromenda] (...) -- C:\Users\admin\AppData\Roaming\WSE_AS~1\UPDATE~1\UPDATE~1.exe (.not file.) [0] =>PUP.Astromenda [MD5.00000000000000000000000000000000] [APT] [Yahoo! Search] (...) -- C:\Users\admin\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrlte.exe (.not file.) [0] =>PUP.PaybyAds [MD5.00000000000000000000000000000000] [APT] [Yahoo! Search Udpater] (...) -- C:\Users\admin\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrsetup.exe (.not file.) [0] =>PUP.PaybyAds [MD5.38813ADD1A1C6B72D2D153DD27B2BEB1] [APT] [YRCPXQOXG1] (.FlashBeat.) -- C:\ProgramData\FlashBeat\FlashBeat.exe [634880] =>PUP.FlashBeat [MD5.00000000000000000000000000000000] [APT] [{05ABE6DE-F7BE-49CC-BF92-C644214BA61D}] (...) -- C:\Program Files\ZHPDiag\ZHPFix\ZHPhep.exe (.not file.) [0] [MD5.C26E8DB10C77C1138B4991882BDEE9C3] [APT] [{068A93B4-18A2-4EFD-A3C7-9006EE327D18}] (...) -- C:\Users\admin\Desktop\psim crack 32bit\PSIM 9.0.3.400_x32.exe [71213056] [MD5.330E83B9C6557E0E7695AA442913AD0F] [APT] [{148C0D02-7290-4CA7-B166-FB6249EB1528}] (...) -- C:\Program Files\HDM Connection Manager\HDM Connection Manager.exe [536576] [MD5.330E83B9C6557E0E7695AA442913AD0F] [APT] [{5F877CC5-020C-4EB4-9FDE-FAC78A9CD6EB}] (...) -- C:\Program Files\HDM Connection Manager\HDM Connection Manager.exe [536576] [MD5.00000000000000000000000000000000] [APT] [{9191F52C-15D1-4098-8694-CC5864F7C737}] (...) -- J:\SetupSimple.exe (.not file.) [0] [MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{B3795B30-24E6-42AF-B6C5-C8DC429E8672}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944] [MD5.330E83B9C6557E0E7695AA442913AD0F] [APT] [{CF1DCD60-80F5-4E00-B587-BA88C977A4D0}] (...) -- C:\Program Files\HDM Connection Manager\HDM Connection Manager.exe [536576] O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-1.job [1790] =>PUP.CrossRider O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-11.job [4122] =>PUP.CrossRider O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-2.job [1584] =>PUP.CrossRider O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-4.job [2354] =>PUP.CrossRider O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-5.job [1684] =>PUP.CrossRider O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-5_user.job [1698] =>PUP.CrossRider O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-6.job [1800] =>PUP.CrossRider O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-7.job [1730] =>PUP.CrossRider O39 - APT: a208d04d-b0d5-4747-bf28-bb1ba986e156-5 - (...) -- C:\Windows\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5.job [2436] =>PUP.CrossRider O39 - APT: a208d04d-b0d5-4747-bf28-bb1ba986e156-5 - (...) -- C:\Windows\System32\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5 [2436] =>PUP.CrossRider O39 - APT: a208d04d-b0d5-4747-bf28-bb1ba986e156-5_user - (...) -- C:\Windows\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5_user.job [2436] =>PUP.CrossRider O39 - APT: a208d04d-b0d5-4747-bf28-bb1ba986e156-5_user - (...) -- C:\Windows\System32\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5_user [2436] =>PUP.CrossRider O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002] O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002] O39 - APT: Binkiland - (...) -- C:\Windows\Tasks\Binkiland.job [292] =>PUP.Binkiland O39 - APT: Binkiland - (...) -- C:\Windows\System32\Tasks\Binkiland [292] =>PUP.Binkiland O39 - APT: Digital Sites - (...) -- C:\Windows\Tasks\Digital Sites.job [292] =>Hijacker.DSite O39 - APT: Digital Sites - (...) -- C:\Windows\System32\Tasks\Digital Sites [292] =>Hijacker.DSite O39 - APT: FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000Core - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000Core.job [906] O39 - APT: FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000Core - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000Core [906] O39 - APT: FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000UA - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000UA.job [928] O39 - APT: FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000UA - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000UA [928] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1054] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1054] O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1058] O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1058] O39 - APT: Price Fountain - (...) -- C:\Windows\Tasks\Price Fountain.job [292] =>PUP.PriceFountain O39 - APT: Price Fountain - (...) -- C:\Windows\System32\Tasks\Price Fountain [292] =>PUP.PriceFountain O39 - APT: WSE_Astromenda - (...) -- C:\Windows\Tasks\WSE_Astromenda.job [292] =>PUP.Astromenda O39 - APT: WSE_Astromenda - (...) -- C:\Windows\System32\Tasks\WSE_Astromenda [292] =>PUP.Astromenda O39 - APT: YRCPXQOXG1 - (.FlashBeat.) -- C:\Windows\Tasks\YRCPXQOXG1.job [330] =>PUP.FlashBeat O39 - APT: YRCPXQOXG1 - (.FlashBeat.) -- C:\Windows\System32\Tasks\YRCPXQOXG1 [330] =>PUP.FlashBeat ~ Scheduled Task: 68 Scanned in 00mn 55s ---\\ Composants installés (ActiveSetup Installed Components) (O40) O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation O40 - ASIC: Disable SSL3 - {7D715857-A67C-4C2F-A929-038448584D63} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll O40 - ASIC: Google Chrome - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google Inc. - Google Chrome Installer.) -- C:\Program Files\Google\Chrome\Application\42.0.2311.135\Installer\chrmstp.exe ~ Active Setup: 11 Scanned in 00mn 01s ---\\ Pilotes lancés au démarrage du système (O41) O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys O41 - Driver: (BAPIDRV) . (. - .) - C:\Windows\System32\DRIVERS\BAPIDRV.sys (.not file.) O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys O41 - Driver: C:\Windows\System32\cscsvc.dll (CSC) . (.Microsoft Corporation - Windows Client Side Caching Driver.) - C:\Windows\System32\drivers\csc.sys O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys O41 - Driver: (dpmconv) . (.Siemens AG - DPM Kernel Mode Driver.) - C:\Windows\System32\DRIVERS\dpmconv32.sys O41 - Driver: (ElbyCDIO) . (.Elaborate Bytes AG - ElbyCD Windows NT/2000/XP I/O driver.) - C:\Windows\System32\Drivers\ElbyCDIO.sys O41 - Driver: (iSafeKrnlMon) . (. - .) - C:\Program Files\Elex-tech\YAC\iSafeKrnlMon.sys (.not file.) =>PUP.Elex O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\System32\DRIVERS\mssmbios.sys O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys O41 - Driver: (VBoxDrv) . (.Oracle Corporation - VirtualBox Support Driver.) - C:\Windows\System32\DRIVERS\VBoxDrv.sys O41 - Driver: (VBoxUSBMon) . (.Oracle Corporation - VirtualBox USB Monitor Driver.) - C:\Windows\System32\DRIVERS\VBoxUSBMon.sys O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys O41 - Driver: ({55dce8ba-9dec-4013-937e-adbf9317d990}w) . (.StdLib - StdLib.) - C:\Windows\System32\drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}w.sys =>PUP.LinkiDoo ~ Drivers: 84 Scanned in 00mn 03s ---\\ Logiciels installés (O42) O42 - Logiciel: Adobe Acrobat Reader DC - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AC0F074E4100} O42 - Logiciel: Adobe Flash Player 17 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Flash Player 17 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI O42 - Logiciel: Affiche Facile - Studio-Scrap - (.CDIP.) [HKLM] -- {AF2F4120-B7B6-407E-A0BF-D6D710EE37EE}_is1 O42 - Logiciel: Astroburn Lite - (.Disc Soft Ltd.) [HKLM] -- Astroburn Lite O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner O42 - Logiciel: Configuration DivX - (.DivX, LLC.) [HKLM] -- DivX Setup O42 - Logiciel: DC-Bass Source 1.3.0 - (...) [HKLM] -- DC-Bass Source O42 - Logiciel: Deal Keeper - (.Deal Keeper.) [HKLM] -- Deal Keeper =>PUP.DealKeeper O42 - Logiciel: DirectVobSub 2.40.4209 - (.MPC-HC Team.) [HKLM] -- vsfilter_is1 O42 - Logiciel: DiscountSmasher - (.DiscountSmasher.) [HKLM] -- {37476589-E48E-439E-A706-56189E2ED4C4} O42 - Logiciel: Dropbox - (.Dropbox, Inc..) [HKCU] -- Dropbox O42 - Logiciel: Extended Update - (.Extended Update.) [HKCU] -- Digital Sites =>PUP.Dealply O42 - Logiciel: Facebook Video Calling 3.1.0.521 - (.Skype Limited.) [HKLM] -- {2091F234-EB58-4B80-8C96-8EB78C808CF7} O42 - Logiciel: File Opener Packages - (...) [HKCU] -- File Opener Packages =>Adware.InstallCore O42 - Logiciel: FileOpener - (.Tweaks.) [HKLM] -- Tweaks FileOpener =>Adware.InstallCore O42 - Logiciel: FlashBeat - (...) [HKLM] -- FlashBeat =>PUP.FlashBeat O42 - Logiciel: Free PDF to Word Converter 5.1.0.383 - (.Smart Soft.) [HKLM] -- Free PDF to Word Converter_is1 =>PUP.PDFtoWordConverter O42 - Logiciel: GDR 5520 pour SQL Server 2008 (KB2977321) - (.Microsoft Corporation.) [HKLM] -- KB2977321 O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} O42 - Logiciel: HDM Connection Manager - (.Huawei Technologies Co.,Ltd.) [HKLM] -- HDM Connection Manager O42 - Logiciel: Haali Media Splitter - (...) [HKLM] -- HaaliMkx O42 - Logiciel: Iminent - (.Iminent.) [HKLM] -- IMBoosterARP =>Adware.IMBooster O42 - Logiciel: IminentToolbar - (.Iminent.) [HKLM] -- IminentToolbar =>Adware.IMBooster O42 - Logiciel: Installer - (...) [HKLM] -- VOPackage =>Adware.Downware O42 - Logiciel: LAME v3.99.3 (for Windows) - (...) [HKLM] -- LAME_is1 O42 - Logiciel: LPT System Updater Service - (.LPT.) [HKLM] -- {BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24} =>Adware.IncrediBar O42 - Logiciel: LSI HDA Modem - (.LSI Corporation.) [HKLM] -- LSI Soft Modem O42 - Logiciel: Lagarith Lossless Codec (1.3.27) - (...) [HKLM] -- {F59AC46C-10C3-4023-882C-4212A92283B3}_is1 O42 - Logiciel: LibreOffice 4.3.5.2 - (.The Document Foundation.) [HKLM] -- {1D4E90DA-C33C-40ED-BA00-75F6E6DF9CB0} O42 - Logiciel: Linkey - (.Aztec Media Inc.) [HKCU] -- Linkey =>PUP.LinkeySearch O42 - Logiciel: MATLAB Production Server R2014a - (.The MathWorks, Inc..) [HKLM] -- MATLAB Production Server R2014a O42 - Logiciel: MATLAB R2011a - (.The MathWorks, Inc..) [HKLM] -- MatlabR2011a O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94} O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71} O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC} O42 - Logiciel: Math Problem Solver - (...) [HKCU] -- Math Problem Solver O42 - Logiciel: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM] -- McAfee Security Scan O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570} O42 - Logiciel: Microsoft Primary Interoperability Assemblies 2005 - (.Microsoft Corporation.) [HKLM] -- {D24DB8B9-BB6C-4334-9619-BA1C650E13D3} O42 - Logiciel: Microsoft SOAP Toolkit 3.0 - (.Microsoft Corporation.) [HKLM] -- {BCB4C18A-ACA6-4383-8688-E19933A705DD} O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {D6F9CBDC-58B6-430A-8DD4-8F61CBC1ADF4} O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} O42 - Logiciel: Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries - (.Microsoft Corporation.) [HKLM] -- {842FAF7C-50EF-4463-9B8F-6222E1384D7D} O42 - Logiciel: Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Fra - (.Microsoft Corporation.) [HKLM] -- {484AB636-ADBC-3A85-AB82-41873BDD1083} O42 - Logiciel: Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32 - (.Microsoft Corporation.) [HKLM] -- {044F9133-B8D7-4d11-BF39-803FA20F5C8B} O42 - Logiciel: Mozilla Firefox 37.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 37.0.2 (x86 fr) O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService O42 - Logiciel: MyPC Backup - (.JDi Backup Ltd.) [HKLM] -- MyPC Backup =>PUP.MyPCBackup O42 - Logiciel: Opera Stable 27.0.1689.66 - (.Opera Software ASA.) [HKLM] -- Opera 27.0.1689.66 O42 - Logiciel: Oracle VM VirtualBox 4.3.26 - (.Oracle Corporation.) [HKLM] -- {26B8608D-6C29-4171-9751-67621C834AA3} O42 - Logiciel: PSIM 9.0.3 - (.Powersim.) [HKLM] -- {98D13EC5-0C60-48eb-A7FA-1B0008EC4C2D} O42 - Logiciel: PSIM 9.1.1 Demo Version - (.Powersim.) [HKLM] -- {D46F2B61-FEE0-46AF-B57F-0EF74F0ECC98} O42 - Logiciel: ParallelPragma - (.ParallelPragma.) [HKLM] -- {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{5fd90e6b} =>Adware.Graftor O42 - Logiciel: PriceFountain (remove only) - (.Price Fountain.) [HKCU] -- PriceFountain =>PUP.PriceFountain O42 - Logiciel: RealPlayer - (.RealNetworks.) [HKLM] -- RealPlayer 6.0 O42 - Logiciel: RocketTab - (.RocketTab.) [HKLM] -- RocketTab =>PUP.RocketTab O42 - Logiciel: RonyaSoft Poster Designer (Poster Forge) 2.01 - (.RonyaSoft.) [HKLM] -- RonyaSoft Poster Designer (Poster Forge) O42 - Logiciel: SIMATIC Prosave - (.Siemens AG.) [HKLM] -- {8E912B95-EDFE-457C-88C3-C8E4062A9C3A} O42 - Logiciel: SIMATIC Prosave V13.0 - (.Siemens AG.) [HKLM] -- {8E912B95-EDFE-457C-88C3-C8E4062A9C3A}Prosave O42 - Logiciel: SQL Server System CLR Types - (.Microsoft Corporation.) [HKLM] -- {342D4AD7-EC4C-4EC8-AEA6-E70F5905A490} O42 - Logiciel: SafeFinder Smartbar - (.Linkury Ltd..) [HKLM] -- {1898B668-CCF5-429F-A86F-9837E5439D77} =>Hijacker.SmartBar O42 - Logiciel: Service Pack 3 pour SQL Server 2008 (KB2546951) - (.Microsoft Corporation.) [HKLM] -- KB2546951 O42 - Logiciel: Settings Manager - (.Aztec Media Inc.) [HKLM] -- Settings Manager =>PUP.SystemK O42 - Logiciel: Shopper-Pro - (...) [HKLM] -- ShopperPro =>PUP.ShopperPro O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - HM All Editions Single - (.Siemens AG.) [HKLM] -- {9ABABC1F-7789-4C55-9646-0D226AF77D17} O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - HM NoBasic Single Setup - (.Siemens AG.) [HKLM] -- {F9E889FA-A86A-41EB-8C59-90134AA06632} O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - Hardware Support Base P - (.Siemens AG.) [HKLM] -- {3B848F75-330D-4C4F-80B1-1A4540C08722} O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - Hardware Support Base P - (.Siemens AG.) [HKLM] -- {92DEC257-1F2E-4D51-9607-DD95431488F9} O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - Hardware Support Base P - (.Siemens AG.) [HKLM] -- {A9C45FA9-9BD4-4A26-9C80-62F4DCAF1A71} O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - Hardware Support Base P - (.Siemens AG.) [HKLM] -- {FDFF76C9-501E-48DA-8632-11794A501F25} O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - STEP 7 Single SetupPack - (.Siemens AG.) [HKLM] -- {36B49AF8-34D8-466C-8360-0E9A51AC7FF3} O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - Simatic Single SetupPac - (.Siemens AG.) [HKLM] -- {CFC1C6B7-8863-4D82-B88E-029A48B29DE2} O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - Support Base Package TO - (.Siemens AG.) [HKLM] -- {2D9E85E8-AF62-4779-8B5D-BFE115942412} O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - Support Base Package TO - (.Siemens AG.) [HKLM] -- {5EABBDC2-FA29-473C-8BB1-5EF28A5CBDFF} O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - TIA Tour Single SetupPa - (.Siemens AG.) [HKLM] -- {AA3B02C7-8179-4A4C-80D6-8EB90456D0EE} O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - TIACOMPCHECK Single Set - (.Siemens AG.) [HKLM] -- {7365E985-FEAB-47F8-837B-D923F2408925} O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - WinCC Single SetupPacka - (.Siemens AG.) [HKLM] -- {5B08D312-9383-4619-B1EF-C26D924B7404} O42 - Logiciel: Siemens Automation License Manager - (.Siemens AG.) [HKLM] -- {9B4A5B53-8814-41C9-8A84-D4A952FADEA5} O42 - Logiciel: Siemens Automation License Manager V5.3 + Upd1 - (.Siemens AG.) [HKLM] -- {9B4A5B53-8814-41C9-8A84-D4A952FADEA5}LicenseManager O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - (.Siemens AG.) [HKLM] -- Siemens Installer Assistant - TIAP13 O42 - Logiciel: Sql Server Customer Experience Improvement Program - (.Microsoft Corporation.) [HKLM] -- {C965F01C-76EA-4BD7-973E-46236AE312D7} O42 - Logiciel: Studio-Scrap : Complement-affiche-facile - (.CDIP.) [HKLM] -- {0B994F37-88CE-41D2-ACC0-AE4194832B72}}_is1 O42 - Logiciel: Studio-Scrap6 : Contenu graphique - (.CDIP.) [HKLM] -- {65143150-8B56-4F76-82AC-BE73B528925F}_is1 O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey O42 - Logiciel: Totally Integrated Automation Portal V13 - TIA Portal Single SetupPackage - (.Siemens AG.) [HKLM] -- {DC371F38-8208-498A-9A69-FD35DC3C074D} O42 - Logiciel: Ultimate Codecs Setup Wizard Packages - (...) [HKCU] -- Ultimate Codecs Setup Wizard Packages =>Adware.InstallCore O42 - Logiciel: UniDeallsa - (...) [HKLM] -- {11F6D5AB-263F-388E-74DE-E3DECD390E3F} =>PUP.UniDeals O42 - Logiciel: Update Service GoForFiles - (.http://www.goforfiles.com.) [HKCU] -- Update Service GoForFiles =>P2P.GoforFiles O42 - Logiciel: Update for PriceFountain - (.Update for PriceFountain.) [HKCU] -- Price Fountain =>PUP.PriceFountain O42 - Logiciel: VC User 71 RTL X86 --- - (.redistributed from Microsoft Corporation merge modules.) [HKLM] -- {A4A4567C-5C29-4756-992D-F84D8250C435} O42 - Logiciel: VC80CRTRedist - 8.0.50727.6195 - (.DivX, Inc.) [HKLM] -- {933B4015-4618-4716-A828-5289FC03165F} O42 - Logiciel: VLC media player 1.1.2 - (.VideoLAN.) [HKLM] -- VLC media player =>.VideoLAN O42 - Logiciel: Viber - (.Viber Media Inc.) [HKCU] -- Viber O42 - Logiciel: WSE_Astromenda - (.WSE_Astromenda.) [HKLM] -- WSE_Astromenda =>PUP.Astromenda O42 - Logiciel: WinRAR archiver - (...) [HKLM] -- WinRAR archiver O42 - Logiciel: WinZipper - (.Taiwan Shui Mu Chih Ching Technology Limited..) [HKLM] -- WinZipper O42 - Logiciel: Xvid Video Codec - (.Xvid Team.) [HKLM] -- Xvid Video Codec 1.3.2 O42 - Logiciel: Yahoo! Search - (.Pay-By-Ads.) [HKCU] -- Yahoo! Search =>PUP.PaybyAds O42 - Logiciel: Yellow AdBlocker - (.Yellow AdBlocker.) [HKLM] -- {37476589-E48E-439E-A706-56189E2ED4C4}_is1 =>PUP.Adblocker O42 - Logiciel: YouTube Accelerator - (.Goobzo Ltd..) [HKLM] -- YouTube Accelerator =>PUP.Goobzo O42 - Logiciel: goopad - (.Software Publisher.) [HKLM] -- {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{e6e6c53} =>Adware.Graftor O42 - Logiciel: iWebar - (.iWebar.) [HKLM] -- iWebar =>PUP.CrossRider O42 - Logiciel: sweet-page uninstall - (.sweet-page.) [HKLM] -- sweet-page uninstall =>PUP.SweetPage ~ Logic: 71 Scanned in 00mn 02s ---\\ HKCU & HKLM Software Keys [HKCU\Software\Adobe] [HKCU\Software\AppDataLow\DealKeeper] =>PUP.DealKeeper [HKCU\Software\AppDataLow\FDA] [HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider [HKCU\Software\AppDataLow\Software\DynConIE] =>PUP.DynConIE [HKCU\Software\AppDataLow\Software\SpeedChecker] =>PUP.InternetSpeedChecker [HKCU\Software\AppDataLow\Software\iWebar] =>PUP.CrossRider [HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}] [HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}] =>Adware.Graftor [HKCU\Software\AppDataLow] [HKCU\Software\ArenaHD] =>PUP.CrossRider [HKCU\Software\Avira] [HKCU\Software\BRS] [HKCU\Software\Binkiland Browser] =>PUP.Binkiland [HKCU\Software\Bitdefender] [HKCU\Software\CDIP] [HKCU\Software\Chromium] [HKCU\Software\Classes] [HKCU\Software\CleanerProConfig] =>PUP.CleanerPro [HKCU\Software\CleanerProLanguage] =>PUP.CleanerPro [HKCU\Software\Clients] [HKCU\Software\ClkApp] [HKCU\Software\Clubic] [HKCU\Software\CoinisRevShare] [HKCU\Software\CrossBrowser] =>PUP.CrossBrowser [HKCU\Software\DSP-worx] [HKCU\Software\DSiteproducts] =>Hijacker.DSite [HKCU\Software\Deal Keeper] =>PUP.DealKeeper [HKCU\Software\Disc Soft] [HKCU\Software\DivX] [HKCU\Software\Easy Speed Check] [HKCU\Software\Elaborate Bytes] [HKCU\Software\Facebook] [HKCU\Software\GNU] [HKCU\Software\Gabest] [HKCU\Software\Gameo] =>PUP.Gameo [HKCU\Software\GoforFiles] =>P2P.GoforFiles [HKCU\Software\GoldenGate] [HKCU\Software\Goobzo] =>PUP.Goobzo [HKCU\Software\Google] [HKCU\Software\Haali] [HKCU\Software\HighDefAction] =>PUP.CrossRider [HKCU\Software\Iminent] =>Adware.IMBooster [HKCU\Software\InstallCore] =>Adware.InstallCore [HKCU\Software\InstalledBrowserExtensions] =>PUP.BrowserExtensions [HKCU\Software\Intel] [HKCU\Software\LAV] [HKCU\Software\Licenses] [HKCU\Software\Local AppWizard-Generated Applications] [HKCU\Software\MCAFEE] [HKCU\Software\Macromedia] [HKCU\Software\MainConcept] [HKCU\Software\MathWorks] [HKCU\Software\MozillaPlugins] [HKCU\Software\Mozilla] [HKCU\Software\Netscape] [HKCU\Software\OB] [HKCU\Software\ODBC] [HKCU\Software\Opera Software] [HKCU\Software\Optimizer Pro] =>PUP.OptimizerPro [HKCU\Software\Oracle] [HKCU\Software\POWERSIM] [HKCU\Software\Piriform] [HKCU\Software\Policies] [HKCU\Software\PrcFountain] [HKCU\Software\ProPCCleanerConfig] =>PUP.DoctorPC [HKCU\Software\ProPCCleanerLanguage] =>PUP.DoctorPC [HKCU\Software\Probit Software] =>PUP.ProbitSoftware [HKCU\Software\RealNetworks] [HKCU\Software\Reg] [HKCU\Software\Reimage] =>Rogue.ReimageRepair [HKCU\Software\RocketTabInstalled] =>PUP.RocketTab [HKCU\Software\RonyaSoft] [HKCU\Software\SIEMENS] [HKCU\Software\SafeGuardApp] [HKCU\Software\Search Extensions] =>PUP.RocketTab [HKCU\Software\ShopperPro] =>PUP.ShopperPro [HKCU\Software\SkypeRS] [HKCU\Software\Smart Soft] [HKCU\Software\SmartbarBackup] =>Hijacker.SmartBar [HKCU\Software\SmartbarLog] =>Hijacker.SmartBar [HKCU\Software\Smartbar] =>Hijacker.SmartBar [HKCU\Software\Softonic] =>Toolbar.Conduit [HKCU\Software\Synaptics] [HKCU\Software\SystemK] =>PUP.SystemK [HKCU\Software\TeamViewer] [HKCU\Software\TeleCharger] [HKCU\Software\The Document Foundation] [HKCU\Software\Trolltech] [HKCU\Software\TutoTag] =>PUP.AgenceExclusive [HKCU\Software\Tutorials] =>PUP.AgenceExclusive [HKCU\Software\UnicoBrowser] =>PUP.UnicoBrowser [HKCU\Software\UpdateStar] [HKCU\Software\V9] [HKCU\Software\Vosteran Browser] =>PUP.Vosteran [HKCU\Software\WebApp] [HKCU\Software\WinRAR SFX] [HKCU\Software\WinRAR] [HKCU\Software\Wnkey] [HKCU\Software\YorkNewCin] =>PUP.CrossRider [HKCU\Software\ZebHelpProcess Helper] [HKCU\Software\globalUpdate] =>PUP.GlobalUpdate [HKCU\Software\rttasks] [HKCU\Software\skype] [HKCU\Software\summer games] [HKCU\Software\summergames] [HKCU\Software\wse_astromenda] =>PUP.Astromenda [HKLM\Software\"alpha_installer"/n] [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719] =>PUP.CrossRider [HKLM\Software\ATI Technologies] [HKLM\Software\Adobe] [HKLM\Software\Agere] [HKLM\Software\AppDataLow] [HKLM\Software\ArenaHD] =>PUP.CrossRider [HKLM\Software\CBSTEST] [HKLM\Software\Clara] [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\DealKeeper] =>PUP.DealKeeper [HKLM\Software\Debian] [HKLM\Software\Disc Soft] [HKLM\Software\DivX] [HKLM\Software\EnigmaSoftwareGroup] =>PUP.EnigmaSoftware [HKLM\Software\Flashbeat] =>PUP.FlashBeat [HKLM\Software\GlobalUpdate] =>PUP.GlobalUpdate [HKLM\Software\GoforFiles] =>P2P.GoforFiles [HKLM\Software\Goobzo] =>PUP.Goobzo [HKLM\Software\Google] [HKLM\Software\HQCinema Pro 2.1V14.04] =>PUP.CrossRider [HKLM\Software\HighDefAction] =>PUP.CrossRider [HKLM\Software\Huawei technologies] [HKLM\Software\IMGUpdater] =>PUP.IMGUpdater [HKLM\Software\Iminent] =>Adware.IMBooster [HKLM\Software\InstallCore] =>Adware.InstallCore [HKLM\Software\InstallShield] [HKLM\Software\InstalledBrowserExtensions] =>PUP.BrowserExtensions [HKLM\Software\InstalledOptions] [HKLM\Software\Intel] [HKLM\Software\LSI] [HKLM\Software\Lame For Audacity] [HKLM\Software\LibreOffice] [HKLM\Software\Licenses] [HKLM\Software\Linkey] =>PUP.LinkeySearch [HKLM\Software\MYBESTOFFERSTODAY] =>PUP.MyBestOffersToday [HKLM\Software\Macromedia] [HKLM\Software\MathWorks] [HKLM\Software\MaxPower] [HKLM\Software\MozillaPlugins] [HKLM\Software\Mozilla] [HKLM\Software\ODBC] [HKLM\Software\ORBTR] =>Toolbar.Conduit [HKLM\Software\Opera Software] [HKLM\Software\Oracle] [HKLM\Software\POWERSIM] [HKLM\Software\Piriform] [HKLM\Software\PluginHp] [HKLM\Software\Policies] [HKLM\Software\RealNetworks] [HKLM\Software\Reg] [HKLM\Software\RegisteredApplications] [HKLM\Software\Reimage] =>Rogue.ReimageRepair [HKLM\Software\RichFX] [HKLM\Software\RonyaSoft] [HKLM\Software\SafeGuardApp] [HKLM\Software\Siemens] [HKLM\Software\SiteSee] [HKLM\Software\Skype] [HKLM\Software\Sonic] [HKLM\Software\SupDp] =>PUP.SupTab [HKLM\Software\Synaptics] [HKLM\Software\SystemK] =>PUP.SystemK [HKLM\Software\TeamViewer] [HKLM\Software\The Document Foundation] [HKLM\Software\Tutorials] =>PUP.AgenceExclusive [HKLM\Software\Umbrella] [HKLM\Software\Uniblue] =>PUP.UniblueSystem [HKLM\Software\V9] [HKLM\Software\VideoLAN] [HKLM\Software\Volatile] [HKLM\Software\WOW6432Node] [HKLM\Software\WebProtector] =>PUP.WebProtect [HKLM\Software\Xing Technology Corp.] [HKLM\Software\Xvid Team] [HKLM\Software\YorkNewCin] =>PUP.CrossRider [HKLM\Software\delta-homesSoftware] =>Hijacker.DeltaHomes [HKLM\Software\hdcode] [HKLM\Software\mcafeeupdater] [HKLM\Software\mozilla.org] [HKLM\Software\supTab] =>PUP.SupTab [HKLM\Software\supWPM] =>PUP.WpManager [HKLM\Software\supWindowsMangerProtect] =>PUP.Fuyu [HKLM\Software\sweet-pageSoftware] =>PUP.SweetPage [HKLM\Software\winzipersvc] =>Adware.D365 ~ Key Software: 382 Scanned in 00mn 02s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 31/10/2012 - 22:48:44 - [0] ----D C:\Program Files\2844371e45800dd4fe O43 - CFD: 19/10/2014 - 21:05:56 - [0] ----D C:\Program Files\360 O43 - CFD: 22/04/2015 - 00:08:06 - [] ----D C:\Program Files\Adobe O43 - CFD: 24/07/2014 - 02:31:28 - [] ----D C:\Program Files\Astroburn Lite O43 - CFD: 15/12/2014 - 19:52:26 - [] ----D C:\Program Files\Avira O43 - CFD: 07/10/2014 - 22:51:40 - [] ----D C:\Program Files\bin O43 - CFD: 24/02/2015 - 15:52:02 - [] ----D C:\Program Files\CCleaner O43 - CFD: 22/04/2015 - 00:08:06 - [] ----D C:\Program Files\Common Files O43 - CFD: 07/10/2014 - 22:46:56 - [] ----D C:\Program Files\Dev-Cpp O43 - CFD: 04/12/2014 - 18:36:48 - [] ----D C:\Program Files\DirectVobSub O43 - CFD: 04/12/2014 - 18:41:05 - [] ----D C:\Program Files\DivX O43 - CFD: 04/12/2014 - 18:36:45 - [] ----D C:\Program Files\DSP-worx O43 - CFD: 12/04/2011 - 03:45:15 - [] ----D C:\Program Files\DVD Maker O43 - CFD: 07/10/2014 - 22:55:09 - [] ----D C:\Program Files\etc O43 - CFD: 07/10/2014 - 22:55:26 - [] ----D C:\Program Files\extern O43 - CFD: 15/07/2014 - 04:36:26 - [] -SH-D C:\Program Files\Fichiers communs O43 - CFD: 04/10/2014 - 11:18:47 - [] ----D C:\Program Files\GoforFiles =>P2P.GoforFiles O43 - CFD: 28/09/2014 - 23:28:46 - [] ----D C:\Program Files\GoForFilesUpdater =>P2P.GoforFiles O43 - CFD: 26/09/2014 - 19:29:11 - [] ----D C:\Program Files\Google O43 - CFD: 18/03/2015 - 23:39:41 - [] ----D C:\Program Files\goopad O43 - CFD: 04/12/2014 - 18:36:45 - [] ----D C:\Program Files\Haali O43 - CFD: 22/07/2014 - 11:18:10 - [] ----D C:\Program Files\HDM Connection Manager O43 - CFD: 07/10/2014 - 22:59:55 - [] ----D C:\Program Files\help O43 - CFD: 30/09/2014 - 20:59:43 - [] ----D C:\Program Files\Intel O43 - CFD: 15/04/2015 - 18:03:05 - [] ----D C:\Program Files\Internet Explorer O43 - CFD: 04/12/2014 - 18:36:47 - [] ----D C:\Program Files\Lame For Audacity O43 - CFD: 08/01/2015 - 16:59:07 - [] ----D C:\Program Files\LibreOffice 4 O43 - CFD: 30/09/2014 - 21:00:21 - [] ----D C:\Program Files\LSI SoftModem O43 - CFD: 03/08/2014 - 20:43:27 - [] ----D C:\Program Files\MATLAB O43 - CFD: 01/10/2014 - 13:27:47 - [] ----D C:\Program Files\McAfee Security Scan O43 - CFD: 15/07/2014 - 21:02:13 - [] ----D C:\Program Files\Microsoft O43 - CFD: 28/02/2015 - 11:14:39 - [] ----D C:\Program Files\Microsoft Office O43 - CFD: 27/10/2014 - 20:33:24 - [] ----D C:\Program Files\Microsoft SDKs O43 - CFD: 24/02/2015 - 17:00:17 - [] ----D C:\Program Files\Microsoft Security Client O43 - CFD: 25/02/2015 - 00:23:18 - [] ----D C:\Program Files\Microsoft Silverlight O43 - CFD: 22/04/2015 - 23:37:49 - [] ----D C:\Program Files\Microsoft SQL Server O43 - CFD: 15/07/2014 - 15:05:26 - [] ----D C:\Program Files\Microsoft Visual Studio O43 - CFD: 15/07/2014 - 15:03:34 - [] ----D C:\Program Files\Microsoft Visual Studio 8 O43 - CFD: 27/10/2014 - 20:36:28 - [] ----D C:\Program Files\Microsoft Visual Studio 9.0 O43 - CFD: 25/02/2015 - 00:27:56 - [] ----D C:\Program Files\Microsoft Works O43 - CFD: 27/10/2014 - 20:42:50 - [] ----D C:\Program Files\Microsoft.NET O43 - CFD: 23/04/2015 - 11:19:41 - [] ----D C:\Program Files\Mozilla Firefox O43 - CFD: 23/04/2015 - 18:46:31 - [] ----D C:\Program Files\Mozilla Maintenance Service O43 - CFD: 15/07/2014 - 15:05:35 - [] ----D C:\Program Files\MSBuild O43 - CFD: 31/07/2014 - 22:44:05 - [] ----D C:\Program Files\MSECache O43 - CFD: 02/04/2015 - 19:29:13 - [] ----D C:\Program Files\MSSOAP O43 - CFD: 05/04/2015 - 09:47:17 - [0] ----D C:\Program Files\MSXML 4.0 O43 - CFD: 25/03/2015 - 22:25:28 - [] ----D C:\Program Files\Oracle O43 - CFD: 13/04/2015 - 21:46:23 - [0] ----D C:\Program Files\predm =>Adware.Downware O43 - CFD: 07/10/2014 - 23:08:03 - [] R---D C:\Program Files\Program Files O43 - CFD: 15/07/2014 - 15:31:52 - [] ----D C:\Program Files\Real O43 - CFD: 14/07/2009 - 06:52:30 - [] ----D C:\Program Files\Reference Assemblies O43 - CFD: 24/02/2015 - 16:08:11 - [] ----D C:\Program Files\RemoveWAT O43 - CFD: 07/10/2014 - 23:13:26 - [] ----D C:\Program Files\resources O43 - CFD: 28/09/2014 - 15:17:31 - [] ----D C:\Program Files\RonyaSoft O43 - CFD: 12/04/2015 - 16:34:53 - [] ----D C:\Program Files\SeekerModule O43 - CFD: 28/09/2014 - 14:40:33 - [] ----D C:\Program Files\Studio-Scrap O43 - CFD: 16/04/2015 - 22:32:02 - [0] ----D C:\Program Files\summer games O43 - CFD: 30/09/2014 - 21:01:00 - [] ----D C:\Program Files\Synaptics O43 - CFD: 07/10/2014 - 23:16:27 - [] ----D C:\Program Files\sys O43 - CFD: 14/07/2009 - 06:53:23 - [0] --H-D C:\Program Files\Uninstall Information O43 - CFD: 15/07/2014 - 15:01:19 - [] ----D C:\Program Files\VideoLAN O43 - CFD: 04/08/2014 - 20:15:32 - [0] ----D C:\Program Files\VirtualCloneDrive O43 - CFD: 07/10/2014 - 22:48:27 - [] ----D C:\Program Files\Windows O43 - CFD: 18/07/2014 - 02:28:06 - [] ----D C:\Program Files\Windows Defender O43 - CFD: 18/07/2014 - 02:28:18 - [] ----D C:\Program Files\Windows Journal O43 - CFD: 15/07/2014 - 21:02:07 - [] ----D C:\Program Files\Windows Live O43 - CFD: 15/07/2014 - 21:01:56 - [] ----D C:\Program Files\Windows Live SkyDrive O43 - CFD: 12/04/2011 - 03:35:39 - [] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation O43 - CFD: 11/03/2015 - 08:36:35 - [] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation O43 - CFD: 15/07/2014 - 04:36:26 - [] ----D C:\Program Files\Windows NT O43 - CFD: 12/04/2011 - 03:35:39 - [] ----D C:\Program Files\Windows Photo Viewer O43 - CFD: 20/11/2010 - 23:33:48 - [] ----D C:\Program Files\Windows Portable Devices O43 - CFD: 12/04/2011 - 03:35:39 - [] ----D C:\Program Files\Windows Sidebar O43 - CFD: 15/07/2014 - 14:59:32 - [] ----D C:\Program Files\WinRAR O43 - CFD: 04/05/2015 - 14:36:59 - [] ----D C:\Program Files\WinZipper O43 - CFD: 04/12/2014 - 18:37:12 - [] ----D C:\Program Files\Xvid O43 - CFD: 28/09/2014 - 23:28:56 - [] ----D C:\Program Files\YouTube Accelerator O43 - CFD: 22/04/2015 - 00:08:09 - [] ----D C:\Program Files\Common Files\Adobe O43 - CFD: 20/04/2015 - 18:33:51 - [0] ----D C:\Program Files\Common Files\ClaraUpdater =>Adware.SupTab O43 - CFD: 26/02/2015 - 02:05:50 - [] ----D C:\Program Files\Common Files\DESIGNER O43 - CFD: 04/12/2014 - 18:40:46 - [] ----D C:\Program Files\Common Files\DivX Shared O43 - CFD: 20/04/2015 - 18:33:51 - [0] ----D C:\Program Files\Common Files\IMGUpdater =>PUP.IMGUpdater O43 - CFD: 31/10/2014 - 12:32:05 - [] ----D C:\Program Files\Common Files\InstallShield O43 - CFD: 27/10/2014 - 20:35:32 - [] ----D C:\Program Files\Common Files\Merge Modules O43 - CFD: 25/02/2015 - 00:28:06 - [] ----D C:\Program Files\Common Files\microsoft shared O43 - CFD: 02/04/2015 - 19:29:10 - [] ----D C:\Program Files\Common Files\MSSoap O43 - CFD: 15/07/2014 - 15:48:59 - [] ----D C:\Program Files\Common Files\Real O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\Services O43 - CFD: 20/04/2015 - 18:33:51 - [0] ----D C:\Program Files\Common Files\ShopperPro =>PUP.ShopperPro O43 - CFD: 02/04/2015 - 20:23:17 - [] ----D C:\Program Files\Common Files\Siemens O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\SpeechEngines O43 - CFD: 26/02/2015 - 02:00:07 - [] ----D C:\Program Files\Common Files\System O43 - CFD: 20/04/2015 - 18:33:51 - [0] ----D C:\Program Files\Common Files\Umbrella O43 - CFD: 15/07/2014 - 21:00:18 - [] ----D C:\Program Files\Common Files\Windows Live O43 - CFD: 20/04/2015 - 19:16:08 - [] ----D C:\Program Files\Common Files\Wise Installation Wizard O43 - CFD: 15/07/2014 - 15:49:00 - [] ----D C:\Program Files\Common Files\xing shared O43 - CFD: 20/04/2015 - 18:33:53 - [0] ----D C:\ProgramData\10151118858217902536 O43 - CFD: 03/01/2015 - 19:29:01 - [0] ----D C:\ProgramData\2308189059 O43 - CFD: 18/10/2014 - 19:42:27 - [] -SH-D C:\ProgramData\360Quarant O43 - CFD: 03/05/2015 - 19:18:56 - [] ----D C:\ProgramData\4291ca9383084a1bb30e07571604a9d6 O43 - CFD: 22/04/2015 - 11:26:53 - [] ----D C:\ProgramData\Adobe O43 - CFD: 24/02/2015 - 16:01:15 - [] ----D C:\ProgramData\ancfdjgoagdpnnklgagpodgclmnnpoke O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Application Data O43 - CFD: 24/07/2014 - 02:31:27 - [] ----D C:\ProgramData\Astroburn Lite O43 - CFD: 15/12/2014 - 19:52:31 - [] ----D C:\ProgramData\Avira O43 - CFD: 20/04/2015 - 15:29:05 - [] ----D C:\ProgramData\boost_interprocess O43 - CFD: 15/07/2014 - 04:36:26 - [] -SH-D C:\ProgramData\Bureau O43 - CFD: 03/05/2015 - 19:18:48 - [] ----D C:\ProgramData\cfda197ad4914fd0ab4eae97a56d3e83 O43 - CFD: 25/07/2014 - 01:14:29 - [] ----D C:\ProgramData\DAEMON Tools Lite =>.DT Soft Ltd O43 - CFD: 26/07/2014 - 03:24:00 - [] ----D C:\ProgramData\DAEMON Tools Ultra O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Desktop O43 - CFD: 04/12/2014 - 18:41:07 - [] ----D C:\ProgramData\DivX O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Documents O43 - CFD: 20/04/2015 - 18:33:53 - [0] ----D C:\ProgramData\DSearchLink =>Toolbar.DeltaSearch O43 - CFD: 15/07/2014 - 04:36:26 - [] -SH-D C:\ProgramData\Favoris O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Favorites O43 - CFD: 03/05/2015 - 19:18:56 - [] ----D C:\ProgramData\FlashBeat =>PUP.FlashBeat O43 - CFD: 03/05/2015 - 19:18:23 - [] --H-D C:\ProgramData\haw O43 - CFD: 24/02/2015 - 16:00:14 - [] ----D C:\ProgramData\hbenmebmconejhmdifgkgmlhohkcjidb O43 - CFD: 20/04/2015 - 18:33:56 - [0] ----D C:\ProgramData\IePluginServices =>PUP.IePluginService O43 - CFD: 24/02/2015 - 16:10:35 - [] ----D C:\ProgramData\jkcfpoknbcjdpailgciampmhljkepapp O43 - CFD: 18/04/2015 - 16:23:18 - [] ----D C:\ProgramData\Just sing O43 - CFD: 20/04/2015 - 18:33:53 - [0] ----D C:\ProgramData\LolliScan =>Adware.Graftor O43 - CFD: 30/09/2014 - 13:23:10 - [] ----D C:\ProgramData\McAfee O43 - CFD: 01/10/2014 - 13:27:58 - [] ----D C:\ProgramData\McAfee Security Scan O43 - CFD: 15/07/2014 - 04:36:26 - [] -SH-D C:\ProgramData\Menu Démarrer O43 - CFD: 22/04/2015 - 13:09:48 - [] -S--D C:\ProgramData\Microsoft O43 - CFD: 22/04/2015 - 12:44:19 - [] ----D C:\ProgramData\Microsoft Help O43 - CFD: 15/07/2014 - 04:36:26 - [] -SH-D C:\ProgramData\Modèles O43 - CFD: 26/09/2014 - 16:01:20 - [] ----D C:\ProgramData\Mozilla O43 - CFD: 16/04/2015 - 18:15:23 - [] ----D C:\ProgramData\NetEngine =>PUP.NetEngine O43 - CFD: 15/12/2014 - 19:52:34 - [] ----D C:\ProgramData\Package Cache O43 - CFD: 23/09/2014 - 22:57:47 - [] ----D C:\ProgramData\Real O43 - CFD: 20/04/2015 - 18:33:56 - [0] ----D C:\ProgramData\Reimage Express =>Rogue.ReimageRepair O43 - CFD: 20/04/2015 - 18:33:56 - [0] ----D C:\ProgramData\Reimage Protector =>Rogue.ReimageRepair O43 - CFD: 20/04/2015 - 18:33:54 - [0] ----D C:\ProgramData\ShopperPro =>PUP.ShopperPro O43 - CFD: 02/04/2015 - 19:01:42 - [] ----D C:\ProgramData\Siemens O43 - CFD: 22/07/2014 - 11:40:34 - [] ----D C:\ProgramData\Smart Soft O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Start Menu O43 - CFD: 29/09/2014 - 13:04:45 - [] ----D C:\ProgramData\Studio-Scrap6 O43 - CFD: 20/04/2015 - 18:33:55 - [0] ----D C:\ProgramData\systemk =>PUP.SystemK O43 - CFD: 13/04/2015 - 13:46:26 - [0] ----D C:\ProgramData\T122078ED O43 - CFD: 28/09/2014 - 11:05:19 - [0] ---AD C:\ProgramData\TEMP O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Templates O43 - CFD: 20/04/2015 - 18:33:56 - [0] ----D C:\ProgramData\Uniblue =>PUP.UniblueSystem O43 - CFD: 20/04/2015 - 18:33:56 - [0] ----D C:\ProgramData\WindowsMangerProtect =>PUP.Fuyu O43 - CFD: 20/04/2015 - 18:33:56 - [0] ----D C:\ProgramData\Yellow AdBlocker =>PUP.Adblocker O43 - CFD: 20/04/2015 - 18:33:56 - [0] ----D C:\ProgramData\YTAHelper =>PUP.Goobzo O43 - CFD: 12/04/2015 - 16:29:57 - [] ----D C:\ProgramData\{373a3fdc-2f80-12c9-373a-a3fdc2f8ff70} O43 - CFD: 12/04/2015 - 22:24:58 - [] ----D C:\ProgramData\{57499cb8-3f5e-5d4b-5749-99cb83f572e0} O43 - CFD: 24/02/2015 - 15:59:03 - [] ----D C:\ProgramData\{8f0c8408-c058-2232-8f0c-c8408c051023} O43 - CFD: 22/04/2015 - 13:16:30 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 22/07/2014 - 11:17:58 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 28/09/2014 - 14:36:24 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Affiche Facile - Studio-Scrap' O43 - CFD: 24/07/2014 - 02:31:29 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Astroburn Lite O43 - CFD: 24/02/2015 - 15:52:00 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner O43 - CFD: 04/12/2014 - 18:36:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DirectVobSub O43 - CFD: 04/12/2014 - 18:40:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX O43 - CFD: 20/04/2015 - 18:33:59 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileOpener =>Adware.InstallCore O43 - CFD: 12/04/2011 - 03:45:19 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 26/09/2014 - 19:29:23 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 04/12/2014 - 18:36:54 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter O43 - CFD: 18/04/2015 - 16:15:35 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Just sing O43 - CFD: 08/01/2015 - 16:59:11 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.3 O43 - CFD: 14/07/2009 - 06:42:30 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 01/10/2014 - 13:28:01 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus O43 - CFD: 18/07/2014 - 00:01:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office O43 - CFD: 25/02/2015 - 00:23:44 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight O43 - CFD: 02/04/2015 - 19:29:14 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SOAP Toolkit Version 3 O43 - CFD: 22/04/2015 - 23:39:18 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008 O43 - CFD: 25/02/2015 - 00:43:34 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual C++ 2008 Express Edition O43 - CFD: 18/07/2014 - 00:01:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox O43 - CFD: 20/04/2015 - 18:33:59 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MYBESTOFFERSTODAY =>PUP.MyBestOffersToday O43 - CFD: 25/03/2015 - 22:26:57 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox O43 - CFD: 20/04/2015 - 18:33:59 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip =>PUP.PepperZip O43 - CFD: 31/10/2014 - 12:17:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSIM 9.0.3 (softkey time-limited) O43 - CFD: 31/10/2014 - 23:01:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSIM 9.1.1 Demo Version O43 - CFD: 18/07/2014 - 00:01:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real O43 - CFD: 20/04/2015 - 18:33:59 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Express =>Rogue.ReimageRepair O43 - CFD: 28/09/2014 - 15:17:32 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RonyaSoft O43 - CFD: 02/04/2015 - 20:23:05 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Siemens Automation O43 - CFD: 14/04/2015 - 14:54:00 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 28/09/2014 - 23:29:58 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Studio-Scrap O43 - CFD: 12/04/2011 - 03:44:56 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 18/07/2014 - 00:01:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN O43 - CFD: 18/07/2014 - 00:01:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live O43 - CFD: 18/07/2014 - 00:01:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 17/12/2014 - 13:50:40 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper O43 - CFD: 04/12/2014 - 18:37:01 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid O43 - CFD: 28/09/2014 - 23:28:56 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator O43 - CFD: 04/05/2015 - 15:13:27 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP =>.Nicolas Coolman O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\1H1Q1V1N1N1O1R =>Adware.InstallCore O43 - CFD: 22/04/2015 - 17:22:44 - [] ----D C:\Users\admin\AppData\Roaming\Adobe O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\Astromenda =>PUP.Astromenda O43 - CFD: 16/07/2014 - 13:28:32 - [] ----D C:\Users\admin\AppData\Roaming\Avira O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\Binkiland =>PUP.Binkiland O43 - CFD: 07/09/2014 - 16:09:14 - [0] ----D C:\Users\admin\AppData\Roaming\BRT O43 - CFD: 04/12/2014 - 18:36:47 - [] ----D C:\Users\admin\AppData\Roaming\CDXReader O43 - CFD: 24/02/2015 - 17:37:37 - [] ----D C:\Users\admin\AppData\Roaming\DAEMON Tools Lite =>.DT Soft Ltd O43 - CFD: 26/07/2014 - 03:21:27 - [] ----D C:\Users\admin\AppData\Roaming\DAEMON Tools Ultra O43 - CFD: 13/10/2014 - 19:35:57 - [] ----D C:\Users\admin\AppData\Roaming\Dev-Cpp O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\DigitalSites =>Hijacker.DSite O43 - CFD: 04/12/2014 - 18:40:45 - [] ----D C:\Users\admin\AppData\Roaming\DivX O43 - CFD: 04/05/2015 - 14:37:31 - [] ----D C:\Users\admin\AppData\Roaming\Dropbox O43 - CFD: 12/02/2015 - 23:04:59 - [] ----D C:\Users\admin\AppData\Roaming\dvdcss O43 - CFD: 26/02/2015 - 20:39:20 - [0] ----D C:\Users\admin\AppData\Roaming\eCyber =>PUP.Elex O43 - CFD: 29/10/2014 - 01:13:57 - [0] ----D C:\Users\admin\AppData\Roaming\EurekaLog O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\Free PDF to Word Converter =>PUP.PDFtoWordConverter O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\Gameo =>PUP.Gameo O43 - CFD: 18/07/2014 - 00:45:04 - [] ----D C:\Users\admin\AppData\Roaming\GoforFiles =>P2P.GoforFiles O43 - CFD: 17/09/2014 - 13:21:55 - [] --H-D C:\Users\admin\AppData\Roaming\GoldenGate O43 - CFD: 15/07/2014 - 04:36:48 - [] ----D C:\Users\admin\AppData\Roaming\Identities O43 - CFD: 04/12/2014 - 18:36:48 - [] ----D C:\Users\admin\AppData\Roaming\LavFilters O43 - CFD: 08/01/2015 - 17:03:20 - [] ----D C:\Users\admin\AppData\Roaming\LibreOffice O43 - CFD: 19/10/2014 - 22:38:05 - [] ----D C:\Users\admin\AppData\Roaming\LockAP O43 - CFD: 18/07/2014 - 00:13:46 - [] ----D C:\Users\admin\AppData\Roaming\Macromedia O43 - CFD: 07/02/2015 - 18:23:06 - [] ----D C:\Users\admin\AppData\Roaming\MathWorks O43 - CFD: 12/04/2011 - 03:44:56 - [0] ----D C:\Users\admin\AppData\Roaming\Media Center Programs O43 - CFD: 19/04/2015 - 21:07:52 - [] -S--D C:\Users\admin\AppData\Roaming\Microsoft O43 - CFD: 15/07/2014 - 14:55:32 - [] ----D C:\Users\admin\AppData\Roaming\Mozilla O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\OpenCandy =>Adware.OpenCandy O43 - CFD: 31/01/2015 - 17:56:25 - [] ----D C:\Users\admin\AppData\Roaming\Opera Software O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\PriceFountain =>PUP.PriceFountain O43 - CFD: 14/04/2015 - 14:53:17 - [0] ----D C:\Users\admin\AppData\Roaming\Probit Software =>PUP.ProbitSoftware O43 - CFD: 27/01/2015 - 21:01:43 - [] ----D C:\Users\admin\AppData\Roaming\QuickScan O43 - CFD: 12/04/2015 - 22:11:15 - [] ----D C:\Users\admin\AppData\Roaming\Rainmaker Software Group LLC.​ O43 - CFD: 23/09/2014 - 22:57:41 - [] ----D C:\Users\admin\AppData\Roaming\Real O43 - CFD: 02/04/2015 - 21:15:45 - [] ----D C:\Users\admin\AppData\Roaming\Siemens O43 - CFD: 28/10/2014 - 13:37:33 - [] ----D C:\Users\admin\AppData\Roaming\Studio-Scrap6 O43 - CFD: 08/02/2015 - 18:08:15 - [] ----D C:\Users\admin\AppData\Roaming\Subversion O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\sweet-page =>PUP.SweetPage O43 - CFD: 21/12/2014 - 13:11:10 - [0] ----D C:\Users\admin\AppData\Roaming\Systweak O43 - CFD: 28/03/2015 - 21:04:54 - [] ----D C:\Users\admin\AppData\Roaming\TeamViewer O43 - CFD: 03/10/2014 - 21:52:54 - [0] ----D C:\Users\admin\AppData\Roaming\uTorrent =>P2P.µTorrent O43 - CFD: 04/05/2015 - 14:38:08 - [] ----D C:\Users\admin\AppData\Roaming\ViberPC O43 - CFD: 25/04/2015 - 00:51:02 - [] ----D C:\Users\admin\AppData\Roaming\vlc O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\VOPackage =>Adware.Downware O43 - CFD: 12/04/2015 - 21:52:55 - [0] ----D C:\Users\admin\AppData\Roaming\WebExtend O43 - CFD: 15/07/2014 - 14:59:47 - [0] ----D C:\Users\admin\AppData\Roaming\WinRAR O43 - CFD: 15/01/2015 - 15:58:40 - [] ----D C:\Users\admin\AppData\Roaming\WinZipper O43 - CFD: 20/04/2015 - 18:34:06 - [0] ----D C:\Users\admin\AppData\Roaming\WSE_Astromenda =>PUP.Astromenda O43 - CFD: 04/05/2015 - 15:28:59 - [] ----D C:\Users\admin\AppData\Roaming\ZHP =>.Nicolas Coolman O43 - CFD: 22/04/2015 - 11:55:37 - [] ----D C:\Users\admin\AppData\Local\Adobe O43 - CFD: 15/07/2014 - 04:36:36 - [] -SH-D C:\Users\admin\AppData\Local\Application Data O43 - CFD: 15/07/2014 - 21:25:42 - [] ----D C:\Users\admin\AppData\Local\Apps O43 - CFD: 20/04/2015 - 18:34:23 - [0] ----D C:\Users\admin\AppData\Local\Binkiland =>PUP.Binkiland O43 - CFD: 20/04/2015 - 18:34:29 - [0] ----D C:\Users\admin\AppData\Local\CleanerPro O43 - CFD: 20/04/2015 - 18:34:29 - [0] ----D C:\Users\admin\AppData\Local\CrashRpt O43 - CFD: 15/07/2014 - 21:25:51 - [0] ----D C:\Users\admin\AppData\Local\Deployment O43 - CFD: 20/04/2015 - 00:46:27 - [] ----D C:\Users\admin\AppData\Local\Diagnostics O43 - CFD: 26/07/2014 - 03:26:44 - [] ----D C:\Users\admin\AppData\Local\Disc_Soft_Ltd O43 - CFD: 03/03/2015 - 18:32:04 - [0] ----D C:\Users\admin\AppData\Local\ElevatedDiagnostics O43 - CFD: 26/02/2015 - 19:41:08 - [] -SH-D C:\Users\admin\AppData\Local\EmieBrowserModeList O43 - CFD: 28/09/2014 - 16:15:18 - [] -SH-D C:\Users\admin\AppData\Local\EmieSiteList O43 - CFD: 28/09/2014 - 16:15:18 - [] -SH-D C:\Users\admin\AppData\Local\EmieUserList O43 - CFD: 14/10/2014 - 22:11:21 - [] ----D C:\Users\admin\AppData\Local\Facebook O43 - CFD: 20/04/2015 - 18:34:31 - [0] ----D C:\Users\admin\AppData\Local\Gameo =>PUP.Gameo O43 - CFD: 17/09/2014 - 13:26:43 - [] ----D C:\Users\admin\AppData\Local\Genesis_09171126 =>PUP.Genesis O43 - CFD: 20/04/2015 - 18:34:31 - [0] ----D C:\Users\admin\AppData\Local\globalUpdate =>PUP.GlobalUpdate O43 - CFD: 15/07/2014 - 21:27:17 - [] ----D C:\Users\admin\AppData\Local\Google O43 - CFD: 15/07/2014 - 04:36:36 - [] -SH-D C:\Users\admin\AppData\Local\Historique O43 - CFD: 24/07/2014 - 02:27:29 - [] ----D C:\Users\admin\AppData\Local\Installer O43 - CFD: 20/04/2015 - 18:34:31 - [0] ----D C:\Users\admin\AppData\Local\LPT =>Adware.Incredibar O43 - CFD: 30/09/2014 - 20:21:00 - [] ----D C:\Users\admin\AppData\Local\Macromedia O43 - CFD: 24/07/2014 - 02:29:01 - [] ----D C:\Users\admin\AppData\Local\Math Problem Solver O43 - CFD: 08/02/2015 - 18:08:06 - [] ----D C:\Users\admin\AppData\Local\MathWorks O43 - CFD: 20/04/2015 - 18:34:31 - [0] ----D C:\Users\admin\AppData\Local\mbot_fr_588 =>PUP.CrossRider O43 - CFD: 01/04/2015 - 21:37:58 - [] ----D C:\Users\admin\AppData\Local\Microsoft O43 - CFD: 27/10/2014 - 21:09:40 - [] ----D C:\Users\admin\AppData\Local\Microsoft Help O43 - CFD: 26/09/2014 - 16:05:39 - [] ----D C:\Users\admin\AppData\Local\Mozilla O43 - CFD: 31/01/2015 - 17:56:27 - [] ----D C:\Users\admin\AppData\Local\Opera Software O43 - CFD: 20/04/2015 - 18:34:31 - [0] ----D C:\Users\admin\AppData\Local\Pay-By-Ads =>PUP.PaybyAds O43 - CFD: 20/04/2015 - 18:34:23 - [] ----D C:\Users\admin\AppData\Local\PriceFountain =>PUP.PriceFountain O43 - CFD: 17/09/2014 - 12:36:06 - [] ----D C:\Users\admin\AppData\Local\Programs O43 - CFD: 20/04/2015 - 18:34:33 - [0] ----D C:\Users\admin\AppData\Local\Pro_PC_Cleaner =>PUP.DoctorPC O43 - CFD: 20/04/2015 - 18:34:33 - [0] ----D C:\Users\admin\AppData\Local\Rainmaker_Software_Group_ =>PUP.DoctorPC O43 - CFD: 20/04/2015 - 18:34:37 - [0] ----D C:\Users\admin\AppData\Local\Smartbar =>Hijacker.SmartBar O43 - CFD: 04/05/2015 - 15:28:03 - [] ----D C:\Users\admin\AppData\Local\Temp O43 - CFD: 15/07/2014 - 04:36:36 - [] -SH-D C:\Users\admin\AppData\Local\Temporary Internet Files O43 - CFD: 15/01/2015 - 16:29:43 - [] ----D C:\Users\admin\AppData\Local\Temp{10CAD5C0-3726-4AD8-BA9D-1FBDB609C95D} O43 - CFD: 04/05/2015 - 14:36:07 - [] ----D C:\Users\admin\AppData\Local\Viber O43 - CFD: 01/02/2015 - 17:09:53 - [] ----D C:\Users\admin\AppData\Local\VirtualStore O43 - CFD: 20/04/2015 - 18:35:19 - [0] ----D C:\Users\admin\AppData\Local\Vosteran =>PUP.Vosteran O43 - CFD: 25/04/2015 - 00:37:53 - [] R---D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup ~ Program Folder: 285 Scanned in 00mn 04s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.808F751F57ABA097D09FA81E691C07FD] - 01/05/2015 - 20:57:15 ---A- . (...) -- C:\Windows\PFRO.log [336] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 01/05/2015 - 20:57:40 ---A- . (...) -- C:\Windows\setuperr.log [0] O44 - LFC:[MD5.4A7E2593C05793A0DE079ECB0102ECAD] - 03/05/2015 - 21:15:52 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1856310] O44 - LFC:[MD5.2A0B900EC7C3F769416A0B2D4D8C1438] - 03/05/2015 - 21:15:52 ---A- . (...) -- C:\Windows\System32\perfc009.dat [147598] O44 - LFC:[MD5.71D953FF60C78D80CAB04D5A51D72A03] - 03/05/2015 - 21:15:52 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [175648] O44 - LFC:[MD5.85E20D3A999B7E5A019BA822300A7D17] - 03/05/2015 - 21:15:52 ---A- . (...) -- C:\Windows\System32\perfh009.dat [720636] O44 - LFC:[MD5.B6BFBFA7121A930416B7D7CD25AF96DC] - 03/05/2015 - 21:15:52 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [814066] O44 - LFC:[MD5.34F6FA2008419BCE99E963C4EADAF860] - 04/05/2015 - 13:33:40 -S-A- . (...) -- C:\Windows\bootstat.dat [67584] O44 - LFC:[MD5.4F3BB5CA906CDFED4CBEE14065A561F2] - 04/05/2015 - 13:33:48 ---A- . (...) -- C:\Windows\setupact.log [336] O44 - LFC:[MD5.17F09721B6C8F806DA7C71481A8DB349] - 04/05/2015 - 13:47:05 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1894881] O44 - LFC:[MD5.3258E716FD25380083AB92B098ADFDAA] - 20/04/2015 - 15:19:05 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512] O44 - LFC:[MD5.5D9A1A3E5824CECE65871C60E5A08A1A] - 22/04/2015 - 10:42:07 ---A- . (.Microsoft Corporation - WSMAN Automation.) -- C:\Windows\System32\WsmAuto.dll [145920] O44 - LFC:[MD5.B975C202F590BBC5AA63225FBD148791] - 22/04/2015 - 10:42:07 ---A- . (.Microsoft Corporation - WSMan HTTP Configuration File.) -- C:\Windows\System32\WSManHTTPConfig.exe [198656] O44 - LFC:[MD5.1DE9BD23AFA36150586C732D876D9B74] - 22/04/2015 - 10:42:08 ---A- . (.Microsoft Corporation - Service WSMan.) -- C:\Windows\System32\WsmSvc.dll [1177088] O44 - LFC:[MD5.B6AC69FFBAA159DD5CEED814245A286D] - 22/04/2015 - 10:42:08 ---A- . (.Microsoft Corporation - WSMAN WMI Provider.) -- C:\Windows\System32\WsmWmiPl.dll [214016] O44 - LFC:[MD5.2C28FEC61C4AC68480A99CB7AA197FA9] - 22/04/2015 - 10:42:08 ---A- . (.Microsoft Corporation - WinRM Migration Plugin.) -- C:\Windows\System32\WSManMigrationPlugin.dll [248832] O44 - LFC:[MD5.AFA53BD631FB0509A91A99391209BB70] - 22/04/2015 - 10:46:30 ---A- . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Inter.) -- C:\Windows\System32\msieftp.dll [301568] O44 - LFC:[MD5.7CC38741B8F68F1E0D5D79DA6123666A] - 22/04/2015 - 10:47:19 ---A- . (.Microsoft Corporation - Service de configuration automatique WWAN.) -- C:\Windows\System32\wwansvc.dll [185344] O44 - LFC:[MD5.DA8AAF7E56F698608A89542131F74818] - 22/04/2015 - 10:47:19 ---A- . (.Microsoft Corporation - WWAN Device Interface Module.) -- C:\Windows\System32\wwanprotdim.dll [40960] O44 - LFC:[MD5.5D1BFF0FCE80F9E2E539F436710D4A79] - 22/04/2015 - 10:53:14 ---A- . (.Microsoft Corporation - Preview Handler Surrogate Host.) -- C:\Windows\System32\prevhost.exe [31232] O44 - LFC:[MD5.1153DE2E4F5941E10C399CB5592F78A1] - 22/04/2015 - 10:53:18 ---A- . (.Microsoft Corporation - Pilote de bus Bluetooth.) -- C:\Windows\System32\Drivers\bthport.sys [393728] O44 - LFC:[MD5.79896A78039C9A63C56197843CFBAD0B] - 22/04/2015 - 10:53:19 ---A- . (.Microsoft Corporation - Direct3D 10 Rasterizer.) -- C:\Windows\System32\d3d10warp.dll [1987584] O44 - LFC:[MD5.A208DAC2932649CFF82A6A684D8BB1F6] - 22/04/2015 - 10:53:22 ---A- . (.Microsoft Corporation - Pas de description.) -- C:\Windows\System32\oleaut32.dll [571904] O44 - LFC:[MD5.7E9917D5309A90E7576653BFE39F80D8] - 22/04/2015 - 10:53:31 ---A- . (.Microsoft Corporation - Panneau de configuration Date/Heure.) -- C:\Windows\System32\timedate.cpl [478720] O44 - LFC:[MD5.EDF2A5E96BEC469DA3F64E9BDD386111] - 22/04/2015 - 10:53:33 ---A- . (.Microsoft Corporation - Microsoft XmlLite Library.) -- C:\Windows\System32\xmllite.dll [180224] O44 - LFC:[MD5.E2ED66FAF894F545EB083AC5F5763854] - 22/04/2015 - 10:53:39 ---A- . (.Microsoft Corporation - Nettoyage de la mise à jour.) -- C:\Windows\System32\scavengeui.dll [434688] O44 - LFC:[MD5.786B9C958A4F217322C24C736263C51F] - 22/04/2015 - 10:53:47 ---A- . (.Microsoft Corporation - OXPS to XPS Converter.) -- C:\Windows\System32\OxpsConverter.exe [245760] O44 - LFC:[MD5.DDCE686D76C2B4DB435A3AF5BD0E691D] - 22/04/2015 - 10:53:49 ---A- . (.Microsoft Corporation - ATAPI Driver Extension.) -- C:\Windows\System32\Drivers\ataport.sys [133056] O44 - LFC:[MD5.75E8EBD7040CE238684333F97014762A] - 22/04/2015 - 10:53:52 ---A- . (.Microsoft Corporation - Fichier DLL du service DAV pour le Web.) -- C:\Windows\System32\WebClnt.dll [205824] O44 - LFC:[MD5.EAF4712B706936C0B10D3B5319B37E81] - 22/04/2015 - 10:53:52 ---A- . (.Microsoft Corporation - Web DAV Client DLL.) -- C:\Windows\System32\davclnt.dll [81920] O44 - LFC:[MD5.E306A24D9694C724FA2491278BF50FDB] - 22/04/2015 - 10:53:54 ---A- . (.Microsoft Corporation - BitLocker Drive Encryption Driver.) -- C:\Windows\System32\Drivers\fvevol.sys [196328] O44 - LFC:[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - 22/04/2015 - 10:53:57 ---A- . (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\Drivers\tdx.sys [74752] O44 - LFC:[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - 22/04/2015 - 10:53:59 ---A- . (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\Drivers\ntfs.sys [1212352] O44 - LFC:[MD5.DDE994E9159497D0D5AB2CDF66D1EAD6] - 22/04/2015 - 10:54:01 ---A- . (.Microsoft Corporation - Infrastructure de diagnostics Windows.) -- C:\Windows\System32\wdi.dll [76800] O44 - LFC:[MD5.1115D5A98043254A0E787F888FC273C0] - 22/04/2015 - 10:54:01 ---A- . (.Microsoft Corporation - Microsoft Performance PerfTrack.) -- C:\Windows\System32\perftrack.dll [635904] O44 - LFC:[MD5.A580CFFC56EE72550B803AED2EFD5442] - 22/04/2015 - 10:54:01 ---A- . (.Microsoft Corporation - Microsoft Performance PowerTracker.) -- C:\Windows\System32\powertracker.dll [27136] O44 - LFC:[MD5.33DB506498E0419CD50B144DE7CCFC75] - 22/04/2015 - 10:54:03 ---A- . (.Microsoft Corporation - Bashkir Keyboard Layout.) -- C:\Windows\System32\KBDBASH.DLL [6144] O44 - LFC:[MD5.1235259E135F87BF4AE5864A818E1513] - 22/04/2015 - 10:54:03 ---A- . (.Microsoft Corporation - Russia(Typewriter) Keyboard Layout.) -- C:\Windows\System32\KBDRU1.DLL [6144] O44 - LFC:[MD5.EB3D06A9EDFDFD12228AD7A9F24D15D6] - 22/04/2015 - 10:54:03 ---A- . (.Microsoft Corporation - Russian Keyboard Layout.) -- C:\Windows\System32\KBDRU.DLL [5632] O44 - LFC:[MD5.40FFC65117C4AC69D33DEC6D567392FD] - 22/04/2015 - 10:54:03 ---A- . (.Microsoft Corporation - Sakha - Russia Keyboard Layout.) -- C:\Windows\System32\KBDYAK.DLL [6144] O44 - LFC:[MD5.F1886C30C3E4A7C5513525CBA665AA31] - 22/04/2015 - 10:54:03 ---A- . (.Microsoft Corporation - Tatar (Legacy) Keyboard Layout.) -- C:\Windows\System32\KBDTAT.DLL [6144] O44 - LFC:[MD5.06FC8A93A4FA1F42A3D1D06694F2B339] - 22/04/2015 - 10:54:05 ---A- . (...) -- C:\Windows\System32\locale.nls [419992] O44 - LFC:[MD5.896850F7D6E6E95DC5BE0F192E05CD0E] - 22/04/2015 - 10:54:16 ---A- . (.Microsoft Corporation - Mise à jour des données de compatibilité de.) -- C:\Windows\System32\aepdu.dll [202752] O44 - LFC:[MD5.EF63EDC07D444AC4B6E88CA6E2841737] - 22/04/2015 - 10:54:21 ---A- . (.Microsoft Corporation - Application Experience Program Cache.) -- C:\Windows\System32\aepic.dll [159744] O44 - LFC:[MD5.E51E2C5EED4CE667D2CF06E56AC6FF1C] - 22/04/2015 - 10:54:21 ---A- . (.Microsoft Corporation - Application Experience Program Inventory Co.) -- C:\Windows\System32\aeinv.dll [896000] O44 - LFC:[MD5.5F823C55FB9761F1236AF48DFF630353] - 22/04/2015 - 10:54:21 ---A- . (.Microsoft Corporation - Compatibility Appraiser.) -- C:\Windows\System32\appraiser.dll [860160] O44 - LFC:[MD5.98F09936B1C397987268D6F2F3D869DB] - 22/04/2015 - 10:54:21 ---A- . (.Microsoft Corporation - Compatibility Upgrade Migration Host.) -- C:\Windows\System32\acmigration.dll [26112] O44 - LFC:[MD5.90D6FA9DB9502FC992D260DE4CB944C7] - 22/04/2015 - 10:54:21 ---A- . (.Microsoft Corporation - Device Inventory Library.) -- C:\Windows\System32\devinv.dll [331264] O44 - LFC:[MD5.87D7FF1217B32CD069DAF079686F43AE] - 22/04/2015 - 10:54:21 ---A- . (.Microsoft Corporation - Inventory Agent.) -- C:\Windows\System32\invagent.dll [630784] O44 - LFC:[MD5.F57E1D225AE5C2C8F475A99BFDF018F4] - 22/04/2015 - 10:54:22 ---A- . (.Microsoft Corporation - Application Impact Telemetry Static Analyze.) -- C:\Windows\System32\aitstatic.exe [1167520] O44 - LFC:[MD5.76F800C6046B439799C3A4120A0B398A] - 22/04/2015 - 10:54:22 ---A- . (.Microsoft Corporation - General Telemetry.) -- C:\Windows\System32\generaltel.dll [576000] O44 - LFC:[MD5.EF71BA5DF59034962B0C62314A71351A] - 22/04/2015 - 10:54:40 ---A- . (.Microsoft Corporation - Client DHCPv6.) -- C:\Windows\System32\dhcpcore6.dll [193536] O44 - LFC:[MD5.81F6C1AE23B1C493D9E996C3103915D7] - 22/04/2015 - 10:54:40 ---A- . (.Microsoft Corporation - Client DHCPv6.) -- C:\Windows\System32\dhcpcsvc6.dll [44032] O44 - LFC:[MD5.5BDF8B0B9A3EADE3A2A6F2ED8D44E36D] - 22/04/2015 - 10:55:19 ---A- . (.Microsoft Corporation - Connecteur Microsoft Search pour Outlook.) -- C:\Windows\System32\mssphtb.dll [197120] O44 - LFC:[MD5.A6CD6B3F71E13E2E45B727FB8A47EA87] - 22/04/2015 - 10:55:19 ---A- . (.Microsoft Corporation - Microsoft Windows Search Filter Host.) -- C:\Windows\System32\SearchFilterHost.exe [86528] O44 - LFC:[MD5.2DC6285EC4F902BE08E7C5FA6D3FD017] - 22/04/2015 - 10:55:19 ---A- . (.Microsoft Corporation - msscntrs.dll.) -- C:\Windows\System32\msscntrs.dll [59392] O44 - LFC:[MD5.DB67C7C62038BDE813CB6486581A7611] - 22/04/2015 - 10:55:20 ---A- . (.Microsoft Corporation - Microsoft Search Protocol Handler.) -- C:\Windows\System32\mssph.dll [337408] O44 - LFC:[MD5.E1AC89F6C5252057E6062843E36A6701] - 22/04/2015 - 10:55:20 ---A- . (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) -- C:\Windows\System32\SearchProtocolHost.exe [164352] O44 - LFC:[MD5.987323F0247D023AD1AE52195540ECE0] - 22/04/2015 - 10:55:20 ---A- . (.Microsoft Corporation - Plateforme de recherche Microsoft Vista.) -- C:\Windows\System32\mssvp.dll [666624] O44 - LFC:[MD5.236F286E103FD44BD85FDD93097FD5DD] - 22/04/2015 - 10:55:21 ---A- . (.Microsoft Corporation - Indexeur Microsoft Windows Search.) -- C:\Windows\System32\SearchIndexer.exe [427520] O44 - LFC:[MD5.465DBF63A5049E4DB4BC5C12FFE781CB] - 22/04/2015 - 10:55:21 ---A- . (.Microsoft Corporation - tquery.dll.) -- C:\Windows\System32\tquery.dll [1549312] O44 - LFC:[MD5.0241CB16136B9A4939CA0395768AE286] - 22/04/2015 - 10:55:22 ---A- . (.Microsoft Corporation - mssrch.dll.) -- C:\Windows\System32\mssrch.dll [1401344] O44 - LFC:[MD5.5FB4F271032B6435F3B2252F577A4815] - 22/04/2015 - 10:56:08 ---A- . (.Microsoft Corporation - Crash Dump Disk Driver.) -- C:\Windows\System32\Drivers\Diskdump.sys [27072] O44 - LFC:[MD5.8229618C90801E957BADC332CE32A6C5] - 22/04/2015 - 10:56:08 ---A- . (.Microsoft Corporation - DLL de journalisation des E/S.) -- C:\Windows\System32\iologmsg.dll [2048] O44 - LFC:[MD5.F1A449D762657230629D8BFC107ABC14] - 22/04/2015 - 10:56:08 ---A- . (.Microsoft Corporation - Microsoft Storage Port Driver.) -- C:\Windows\System32\Drivers\storport.sys [149440] O44 - LFC:[MD5.EB34CE31FABD4DC4343FD2AD16D2CAF9] - 22/04/2015 - 10:56:09 ---A- . (.Microsoft Corporation - Microsoft iSCSI Initiator Driver.) -- C:\Windows\System32\Drivers\msiscsi.sys [234432] O44 - LFC:[MD5.A8DDB7ACB122FC36FF0D7C9B3099A380] - 22/04/2015 - 10:57:00 ---A- . (.Microsoft Corporation - Composant Connexion RemoteApp et Bureau à d.) -- C:\Windows\System32\TSWorkspace.dll [793600] O44 - LFC:[MD5.8C9C922D71F1CD4DEF73F186416B7896] - 22/04/2015 - 10:57:15 ---A- . (.Microsoft Corporation - Pilote NDIS 6.20.) -- C:\Windows\System32\Drivers\ndis.sys [712048] O44 - LFC:[MD5.ED80D303102A746D30C1684B387BCBF1] - 22/04/2015 - 10:57:15 ---A- . (.Microsoft Corporation - Remote NDIS Miniport.) -- C:\Windows\System32\Drivers\RNDISMP.sys [33280] O44 - LFC:[MD5.9158DBE2F8483434FC72F320690C9DB8] - 22/04/2015 - 10:57:26 ---A- . (.Microsoft Corporation - Windows Rights Management Services Server S.) -- C:\Windows\System32\secproc_ssp_isv.dll [87040] O44 - LFC:[MD5.7FA485555BF802FE3DB5598004DBDFAC] - 22/04/2015 - 10:57:27 ---A- . (.Microsoft Corporation - Client Gestion des droits Windows.) -- C:\Windows\System32\msdrm.dll [390144] O44 - LFC:[MD5.12A9F24DC9F465DA79AC2272D829A81E] - 22/04/2015 - 10:57:27 ---A- . (.Microsoft Corporation - Windows Rights Management Desktop Security.) -- C:\Windows\System32\secproc.dll [428032] O44 - LFC:[MD5.BBCE3E9E74C7CEA47FA4115B360AC2C6] - 22/04/2015 - 10:57:27 ---A- . (.Microsoft Corporation - Windows Rights Management Desktop Security.) -- C:\Windows\System32\secproc_isv.dll [423936] O44 - LFC:[MD5.58712A48D31B40EBCB35B47205F87771] - 22/04/2015 - 10:57:27 ---A- . (.Microsoft Corporation - Windows Rights Management Services Server S.) -- C:\Windows\System32\secproc_ssp.dll [87040] O44 - LFC:[MD5.6142C5540C8D2764D59CBC11AF4A5900] - 22/04/2015 - 10:57:28 ---A- . (.Microsoft Corporation - Windows Rights Management Services Activati.) -- C:\Windows\System32\RMActivate.exe [572416] O44 - LFC:[MD5.E01D2AC63453534DB8AD1EA97DEE9C3A] - 22/04/2015 - 10:57:28 ---A- . (.Microsoft Corporation - Windows Rights Management Services Activati.) -- C:\Windows\System32\RMActivate_isv.exe [594944] O44 - LFC:[MD5.08D323750350A8A29611D1004C0CF319] - 22/04/2015 - 10:57:28 ---A- . (.Microsoft Corporation - Windows Rights Management Services Activati.) -- C:\Windows\System32\RMActivate_ssp.exe [510976] O44 - LFC:[MD5.0F5FEF37588AF457E02125674F171A4F] - 22/04/2015 - 10:57:28 ---A- . (.Microsoft Corporation - Windows Rights Management Services Activati.) -- C:\Windows\System32\RMActivate_ssp_isv.exe [508928] O44 - LFC:[MD5.F991AB9CC6B908DB552166768176896A] - 22/04/2015 - 10:58:06 ---A- . (.Microsoft Corporation - USB Mass Storage Class Driver.) -- C:\Windows\System32\Drivers\USBSTOR.SYS [76288] O44 - LFC:[MD5.D320BF87125326F996D4904FE24300FC] - 22/04/2015 - 10:58:07 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [80256] O44 - LFC:[MD5.46387FB17B086D16DEA267D5BE23A2F2] - 22/04/2015 - 10:58:07 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [22400] O44 - LFC:[MD5.B3E25EE28883877076E0E1FF877D02E0] - 22/04/2015 - 10:58:07 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117120] O44 - LFC:[MD5.4380E59A170D88C4F1022EFF6719A8A4] - 22/04/2015 - 10:58:07 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [143744] O44 - LFC:[MD5.5CD5F9A5444E6CDCB0AC89BD62D8B76E] - 22/04/2015 - 10:58:08 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332160] O44 - LFC:[MD5.5C3F9DBA818CD93379D1A0F215270374] - 22/04/2015 - 10:58:08 ---A- . (.Microsoft Corporation - Moteur de stockage extensible pour Microsof.) -- C:\Windows\System32\esent.dll [1699328] O44 - LFC:[MD5.B4834F08230A2EB7F498DE4E5B6AB814] - 22/04/2015 - 10:58:08 ---A- . (.Microsoft Corporation - fsutil.exe.) -- C:\Windows\System32\fsutil.exe [74240] O44 - LFC:[MD5.4BCC63ED1C3D15B2635A8AE2B854B3EB] - 22/04/2015 - 10:58:24 ---A- . (.Microsoft Corporation - Fournisseur d’informations d’identification.) -- C:\Windows\System32\SmartcardCredentialProvider.dll [152576] O44 - LFC:[MD5.E9BB0CD09DA17C71FD1B9954D75AEEF7] - 22/04/2015 - 10:58:24 ---A- . (.Microsoft Corporation - Interface utilisateur du gestionnaire d’inf.) -- C:\Windows\System32\credui.dll [168960] O44 - LFC:[MD5.9EA3783672D21817B9DF1061B54C3B3C] - 22/04/2015 - 10:58:28 ---A- . (.Microsoft Corporation - Table des caractères.) -- C:\Windows\System32\charmap.exe [155136] O44 - LFC:[MD5.45FBAFFA68CBC29AC2563985CEE72B9C] - 22/04/2015 - 10:58:42 ---A- . (.Microsoft Corporation - Dialogues communs de certificats Microsoft.) -- C:\Windows\System32\cryptdlg.dll [24576] O44 - LFC:[MD5.03F3B770DFBED6131653CEDA8CA780F0] - 22/04/2015 - 10:58:46 ---A- . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll [442880] O44 - LFC:[MD5.7752619457598CF057C4CC02A0867029] - 22/04/2015 - 10:59:40 ---A- . (.Microsoft - Système de classement CERO.) -- C:\Windows\System32\cero.rs [55296] O44 - LFC:[MD5.DDD1C4AB9A9DAE6D4092C4C95E714650] - 22/04/2015 - 10:59:40 ---A- . (.Microsoft - Système de classement ESRB.) -- C:\Windows\System32\esrb.rs [51712] O44 - LFC:[MD5.CBC69A055EF410CBD65593E4808B6DB4] - 22/04/2015 - 10:59:40 ---A- . (.Microsoft - Système de classement OFLC.) -- C:\Windows\System32\oflc.rs [23552] O44 - LFC:[MD5.72035C97983745E742D71E9A8EF70BBB] - 22/04/2015 - 10:59:40 ---A- . (.Microsoft - Système de classement PEGI en Finlande.) -- C:\Windows\System32\pegi-fi.rs [20480] O44 - LFC:[MD5.43C9CF6825CEA58F1815B7C3DBBB385C] - 22/04/2015 - 10:59:41 ---A- . (.Microsoft Corporation - Bibliothèque des paramètres WPC.) -- C:\Windows\System32\Wpc.dll [308736] O44 - LFC:[MD5.64E211E0FDFCE4D186DF58BB7D0503BC] - 22/04/2015 - 10:59:41 ---A- . (.Microsoft Corporation - Explorateur des jeux.) -- C:\Windows\System32\gameux.dll [2576384] O44 - LFC:[MD5.A067A19A91C2AA0198F9BD01A5CEF5C6] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classement GRB.) -- C:\Windows\System32\grb.rs [21504] O44 - LFC:[MD5.4F5C56DBF076D5BBB1D22B37BF281396] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classement PEGI au Portugal.) -- C:\Windows\System32\pegi-pt.rs [20480] O44 - LFC:[MD5.5109C45498BC709C8A7E016D5FFCCAC2] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classement PEGI.) -- C:\Windows\System32\pegi.rs [20480] O44 - LFC:[MD5.9B7D7F4D1F79E8B7D727BE94B1630D59] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classement PEGI/BBFC.) -- C:\Windows\System32\pegibbfc.rs [44544] O44 - LFC:[MD5.9EDCFA23CC081E38C86CA309D0F7E3DC] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classement USK.) -- C:\Windows\System32\usk.rs [30720] O44 - LFC:[MD5.41CE7975CAD7BCF92538D2C452239523] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classification COB-AU.) -- C:\Windows\System32\cob-au.rs [40960] O44 - LFC:[MD5.27828AAA24AA46F11036954ADE355C1C] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classification DJCTQ.) -- C:\Windows\System32\djctq.rs [15360] O44 - LFC:[MD5.A704E750245D5D4EE4A23E99A00F27D5] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classification FPB.) -- C:\Windows\System32\fpb.rs [46592] O44 - LFC:[MD5.6EC618588447B82EA8D88719EE46F725] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de notation CSRR.) -- C:\Windows\System32\csrr.rs [43520] O44 - LFC:[MD5.ED59143843560B5EDB543C2A48CB9E4B] - 22/04/2015 - 10:59:43 ---A- . (.Microsoft - Système de classification OFLC-NZ.) -- C:\Windows\System32\oflc-nz.rs [45568] O44 - LFC:[MD5.50C73E54062BA252350F3F29580E28DA] - 22/04/2015 - 11:00:13 ---A- . (.Microsoft Corporation - Fichier DLL de ressources des fuseaux horai.) -- C:\Windows\System32\tzres.dll [2048] O44 - LFC:[MD5.23FC8068953C9BE2D63AE4EF1129112A] - 22/04/2015 - 11:00:31 ---A- . (.Microsoft Corporation - Manipulateur d’événements réseau.) -- C:\Windows\System32\netevent.dll [18944] O44 - LFC:[MD5.3EEBD3BD93DA46A26E89893C7AB2FF3B] - 22/04/2015 - 11:00:32 ---A- . (.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) -- C:\Windows\System32\Drivers\tcpipreg.sys [35328] O44 - LFC:[MD5.5078492B9CAC9CB721698DB51F039035] - 22/04/2015 - 11:00:33 ---A- . (.Microsoft Corporation - Classes d’assistance pour les diagnostics p.) -- C:\Windows\System32\netcorehc.dll [175104] O44 - LFC:[MD5.58F67245D041FBE7AF88F4EAF79DF0FA] - 22/04/2015 - 11:00:33 ---A- . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [499712] O44 - LFC:[MD5.CB55B9AAB060C803BE4AD229AA0FEC28] - 22/04/2015 - 11:00:47 ---A- . (.Microsoft Corporation - Windows Installer.) -- C:\Windows\System32\msi.dll [2363904] O44 - LFC:[MD5.AEBCEA8A46A42FCFE4EA92186745EE69] - 22/04/2015 - 11:29:30 ---A- . (.Microsoft Corporation - SQL Server Cluster Resource DLL.) -- C:\Windows\System32\SQSRVRES.DLL [89960] O44 - LFC:[MD5.45676E87AD75D5E4B63C4D975E1184A7] - 22/04/2015 - 11:29:31 ---A- . (.Microsoft Corporation - SQL Server Performance Acquisition DLL.) -- C:\Windows\System32\perf-MSSQL$SQLEXPRESS-sqlctr10.3.5500.0.dll [73064] O44 - LFC:[MD5.933222B19FF3E7EA5F65517EA1F7D57E] - 22/04/2015 - 11:33:13 ---A- . (...) -- C:\Windows\System32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf [3] O44 - LFC:[MD5.A36F7A256E65D858A7039DB00ADEEBDD] - 22/04/2015 - 11:33:14 ---A- . (.Microsoft Corporation - WDF:UMDF Framework Library.) -- C:\Windows\System32\WUDFx.dll [613888] O44 - LFC:[MD5.980B6A5F92B8DB235C4A26728C2BE732] - 22/04/2015 - 11:33:15 ---A- . (.Microsoft Corporation - Windows Driver Foundation - Processus hôte.) -- C:\Windows\System32\WUDFHost.exe [196608] O44 - LFC:[MD5.D689B2C2E69156D954C24810F4081C1E] - 22/04/2015 - 11:33:19 ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Platf.) -- C:\Windows\System32\WUDFCoinstaller.dll [38912] O44 - LFC:[MD5.D5CF1536137026ACDED95BF6CBF849F6] - 22/04/2015 - 11:33:21 ---A- . (.Microsoft Corporation - Windows Driver Foundation - Bibliothèque de.) -- C:\Windows\System32\WUDFPlatform.dll [172032] O44 - LFC:[MD5.FE47B7BC8EA320C2D9B5E5BF6E303765] - 22/04/2015 - 11:33:21 ---A- . (.Microsoft Corporation - Windows Driver Foundation - Service d’infra.) -- C:\Windows\System32\WUDFSvc.dll [73216] O44 - LFC:[MD5.06E6F32C8D0A3F66D956F57B43A2E070] - 22/04/2015 - 11:33:23 ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\Drivers\WUDFPf.sys [66560] O44 - LFC:[MD5.867C301E8B790040AE9CF6486E8041DF] - 22/04/2015 - 11:33:25 ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\Drivers\WUDFRd.sys [155136] O44 - LFC:[MD5.2413D2216D08FAF7D7178D9E0B481AEB] - 22/04/2015 - 11:42:42 ---A- . (.Microsoft Corporation - Microsoft DTV-DVD Video Decoder.) -- C:\Windows\System32\msmpeg2vdec.dll [2285056] O44 - LFC:[MD5.4676AAA9DDF52A50C829FEDB4EA81E54] - 22/04/2015 - 11:45:23 ---A- . (.Microsoft Corporation - Connexion Bureau à distance.) -- C:\Windows\System32\mstsc.exe [1068544] O44 - LFC:[MD5.0FC6922517964E9D90DE84DC86F63E40] - 22/04/2015 - 11:45:24 ---A- . (.Microsoft Corporation - Runtime de connexion RemoteApp et Bureau à.) -- C:\Windows\System32\wksprt.exe [350208] O44 - LFC:[MD5.5E676B296B762E211D83B87635F2C330] - 22/04/2015 - 11:45:25 ---A- . (.Microsoft Corporation - Remote Desktop Services Client for Microsof.) -- C:\Windows\System32\rdvidcrl.dll [855552] O44 - LFC:[MD5.8DEEE20D8D30E9B0FBDCA31E58A027BD] - 22/04/2015 - 11:45:27 ---A- . (.Microsoft Corporation - Client de contrainte de quarantaine de la p.) -- C:\Windows\System32\tsgqec.dll [53248] O44 - LFC:[MD5.2EFB1279E7BEA7D12D9F4D6508D27880] - 22/04/2015 - 11:45:27 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Acces.) -- C:\Windows\System32\MsRdpWebAccess.dll [50176] O44 - LFC:[MD5.AB5EFB103DB01C1912C9D2F545EA5621] - 22/04/2015 - 11:45:30 ---A- . (.Microsoft Corporation - WorkspaceRuntime ProxyStub DLL.) -- C:\Windows\System32\wksprtPS.dll [17920] O44 - LFC:[MD5.A90F47CDCC0898733596B5070039FC15] - 22/04/2015 - 11:45:31 ---A- . (.Microsoft Corporation - Extension de stratégie de groupe pour la re.) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll [14336] O44 - LFC:[MD5.C6A5FBD4977305E1FA23E02C042DB463] - 22/04/2015 - 11:45:34 ---A- . (.Microsoft Corporation - Pilote de filtre pour concentrateur USB du.) -- C:\Windows\System32\Drivers\TsUsbFlt.sys [49152] O44 - LFC:[MD5.D60E27D4BD5A91FCD17D2CB27F86738E] - 22/04/2015 - 11:45:36 ---A- . (.Microsoft Corporation - Remote Desktop USB Redirection GP Extension.) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe [12800] O44 - LFC:[MD5.F37167FCDB661FD4B54CAD4755ABDD61] - 22/04/2015 - 11:45:39 ---A- . (.Microsoft Corporation - Co-installateur de pilote USB générique du.) -- C:\Windows\System32\TsUsbGDCoInstaller.dll [32256] O44 - LFC:[MD5.8999F18D38D55E34D356796507FFD639] - 22/04/2015 - 11:49:10 ---A- . (.Microsoft Corporation - Point de terminaison audio RDP.) -- C:\Windows\System32\rdpendp_winip.dll [192000] O44 - LFC:[MD5.65375DF758CA1872AB7EBBBA457FD5E6] - 22/04/2015 - 11:49:18 ---A- . (.Microsoft Corporation - Microsoft RDP Video Miniport driver.) -- C:\Windows\System32\Drivers\rdpvideominiport.sys [14848] O44 - LFC:[MD5.63F066C8F1C666EC5B65DCF4B1B29C2F] - 22/04/2015 - 12:15:05 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [587896] O44 - LFC:[MD5.3597DE1371DF9DDC15001778EBA54EAF] - 23/04/2015 - 10:19:40 ---A- . (.Microsoft Corporation - Client ActiveX des services Bureau à distan.) -- C:\Windows\System32\mstscax.dll [5702656] O44 - LFC:[MD5.E284CFD490A1F2E03A8BE0B4C09A3DEE] - 24/04/2015 - 09:54:45 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Proxy.) -- C:\Windows\System32\TSWbPrxy.exe [74240] O44 - LFC:[MD5.6BF8843C99352B8A600794DE740C2566] - 24/04/2015 - 09:54:47 ---A- . (.Microsoft Corporation - DLL RDPCore TS.) -- C:\Windows\System32\rdpcorets.dll [2744320] O44 - LFC:[MD5.06E6DEABDA3A27DDA054BE46207420E4] - 24/04/2015 - 09:54:47 ---A- . (.Microsoft Corporation - Remote Desktop Protocol Group Policy Extens.) -- C:\Windows\System32\RdpGroupPolicyExtension.dll [13824] O44 - LFC:[MD5.1B430766C544BEF1D8BE2305FF7F8D9C] - 24/04/2015 - 09:54:47 ---A- . (.Microsoft Corporation - UMRDP Display Driver.) -- C:\Windows\System32\rdpudd.dll [221184] ~ Files: 142 Scanned in 01mn 00s ---\\ Derniers fichiers créés dans Windows Prefetcher (O45) O45 - LFCP:[MD5.B5AB6E0E90E561606FDEB9C09A15AF0F] - 14/04/2015 - 14:00:53 ---A- - C:\Windows\Prefetch\BACKUPSTACK.EXE-97682A25.pf =>PUP.MyPCBackup O45 - LFCP:[MD5.0689AFF9A05CF76CD6B1652F710FF040] - 13/04/2015 - 20:23:59 ---A- - C:\Windows\Prefetch\MYPC BACKUP.EXE-2654E8AC.pf =>PUP.MyPCBackup O45 - LFCP:[MD5.EA71600DB769E747E7152BFE5FBFB94F] - 14/04/2015 - 18:34:16 ---A- - C:\Windows\Prefetch\SUMMER_GAMES_UPDATING_SERVICE-E74068F4.pf =>PUP.CrossRider O45 - LFCP:[MD5.0989F3F4F81DA9B74A85DCFC29B0BF3F] - 12/04/2015 - 20:49:29 ---A- - C:\Windows\Prefetch\UNICOBROWSER.EXE-51800076.pf =>PUP.UnicoBrowser O45 - LFCP:[MD5.AA03FCFF17026D1E08A3B77F492A56DD] - 12/04/2015 - 20:52:38 ---A- - C:\Windows\Prefetch\WEBPROTECTPD.EXE-E1146886.pf =>PUP.WebProtect ~ Prefetcher: 5 Scanned in 00mn 01s ---\\ Déni du service (Local Security Authority) (O48) O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll ~ LSA: 8 Scanned in 00mn 00s ---\\ Contrôle du Safe Boot (CSB) (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys ~ CSB: 13 Scanned in 00mn 00s ---\\ Image File Execution Options (IFEO) (O50) O50 - IFEO:Image File Execution Options - volaro - tasklist.exe =>Trojan.Vonteera ~ IFEO: Scanned in 00mn 00s ---\\ Clé de registre Shell MountPoints2 (MPSK) (O51) O51 - MPSK:{30b561e4-13e1-11e4-b9eb-e02a827f9d3d}\AutoRun\command. (...) -- I:\setup.exe (.not file.) O51 - MPSK:{354c80cf-1321-11e4-865c-e02a827f9d3d}\AutoRun\command. (...) -- H:\setup.exe (.not file.) O51 - MPSK:{414d0c75-1180-11e4-9c63-64315080d8de}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{414d0c7c-1180-11e4-9c63-64315080d8de}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.) O51 - MPSK:{8a8d608d-2647-11e4-a7f1-e02a827f9d3d}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.) O51 - MPSK:{8a8d60e2-2647-11e4-a7f1-e02a827f9d3d}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.) O51 - MPSK:{ae767fc1-1b3a-11e4-b0f0-e02a827f9d3d}\AutoRun\command. (...) -- J:\setup.exe (.not file.) O51 - MPSK:{b23062ea-50a9-11e4-8acd-e02a827f9d3d}\AutoRun\command. (...) -- H:\setup.exe (.not file.) O51 - MPSK:{e2cf9a3e-13da-11e4-800b-806e6f6e6963}\AutoRun\command. (...) -- F:\setup.exe (.not file.) ~ Keys: Scanned in 00mn 00s ---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52) O52 - TDSD: \Drivers32\"msacm.l3acm"="l3codecp.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Audio Layer-3 Codec for MSACM.) -- C:\Windows\System32\l3codecp.acm O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll O52 - TDSD: \Drivers32\"VIDC.LAGS"="lagarith.dll" . (.Pas de propriétaire - Lagarith.) -- C:\Windows\System32\lagarith.dll O52 - TDSD: \Drivers32\"vidc.XVID"="xvidvfw.dll" . (...) -- C:\Windows\System32\xvidvfw.dll O52 - TDSD: \drivers.desc\"lagarith.dll"="Lagarith lossless codec [LAGS]" . (.Pas de propriétaire - Lagarith.) -- C:\Windows\System32\lagarith.dll O52 - TDSD: \drivers.desc\"xvidvfw.dll"="Xvid MPEG-4 Video Codec" . (...) -- C:\Windows\System32\xvidvfw.dll O52 - TDSD: \drivers.desc\"l3codecp.acm"="Fraunhofer IIS MPEG Layer-3 Codec (professional)" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Audio Layer-3 Codec for MSACM.) -- C:\Windows\System32\l3codecp.acm ~ TDSD: 7 Scanned in 00mn 01s ---\\ Enumération des clés de registre SecurityProviders (MCSP) (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll ~ MSCP: 2 Scanned in 00mn 00s ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0 O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 16 Scanned in 00mn 00s ---\\ Liste des pilotes du système (SDL) (O58) O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976] O58 - SDL:14/07/2009 - 02:26:17 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [297552] O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\Drivers\adpu320.sys [146512] O58 - SDL:26/01/2010 - 16:38:06 ---A- . (.LSI Corporation - SoftModem Device Driver.) -- C:\Windows\System32\Drivers\AGRSM.sys [1163328] O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [14400] O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [80256] O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows fa.) -- C:\Windows\System32\Drivers\amdsbs.sys [159312] O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [22400] O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [76368] O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [86608] O58 - SDL:13/07/2009 - 23:02:49 ---A- . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gigabit Ethernet..) -- C:\Windows\System32\Drivers\b57nd60x.sys [229888] O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [13568] O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [5248] O58 - SDL:14/07/2009 - 01:57:25 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [272128] O58 - SDL:13/07/2009 - 23:53:32 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [62336] O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [12160] O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [11904] O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbdx.sys [430080] O58 - SDL:14/07/2009 - 02:26:21 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [15952] O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\Drivers\djsvs.sys [70720] O58 - SDL:10/04/2013 - 08:15:46 ---A- . (.Siemens AG - DPM Kernel Mode Driver.) -- C:\Windows\System32\Drivers\dpmconv32.sys [291328] O58 - SDL:10/09/2014 - 11:53:14 ---A- . (.360.cn - dsark.sys.) -- C:\Windows\System32\Drivers\DsArk.sys [84040] O58 - SDL:04/03/2013 - 10:25:00 ---A- . (.Elaborate Bytes AG - ElbyCD Windows NT/2000/XP I/O driver.) -- C:\Windows\System32\Drivers\ElbyCDIO.sys [30616] O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712] O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbdx.sys [3100160] O58 - SDL:09/08/2007 - 04:06:40 ---A- . (.Huawei Tech. Co., Ltd. - HUAWEI USB Smart Card Driver.) -- C:\Windows\System32\Drivers\ewdcsc.sys [23424] O58 - SDL:12/10/2009 - 15:22:56 ---A- . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\Windows\System32\Drivers\ewusbdev.sys [101120] O58 - SDL:07/12/2009 - 19:53:18 ---A- . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\Windows\System32\Drivers\ewusbmdm.sys [103168] O58 - SDL:07/12/2009 - 19:36:48 ---A- . (.Huawei Technologies Co., Ltd. - USB NDIS Miniport Driver.) -- C:\Windows\System32\Drivers\ewusbnet.sys [201168] O58 - SDL:13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624] O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [67152] O58 - SDL:11/03/2011 - 06:38:51 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332160] O58 - SDL:11/02/2011 - 18:12:16 ---A- . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\Drivers\igdkmd32.sys [9036800] O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [41040] O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [95824] O58 - SDL:14/07/2009 - 02:20:37 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [89168] O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [54864] O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [96848] O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7 for x86.) -- C:\Windows\System32\Drivers\megasas.sys [30800] O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [235584] O58 - SDL:06/12/2012 - 08:42:10 ---A- . (.Ralink Technology, Corp. - Ralink 802.11 Wireless Adapter Driver.) -- C:\Windows\System32\Drivers\netr28.sys [2046560] O58 - SDL:14/07/2009 - 02:20:44 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [44624] O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117120] O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [143744] O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1383488] O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [106064] O58 - SDL:10/06/2011 - 05:34:52 ---A- . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.20 32-bit Driver.) -- C:\Windows\System32\Drivers\Rt86win7.sys [394856] O58 - SDL:24/07/2012 - 11:25:34 ---A- . (.SIEMENS AG - Knotentaufe Kernel Mode Driver.) -- C:\Windows\System32\Drivers\S7odpx2x32.sys [87552] O58 - SDL:03/12/2013 - 11:46:58 ---A- . (.Siemens AG - MPI-Transport Kernel Mode Driver.) -- C:\Windows\System32\Drivers\S7otranx32.sys [521216] O58 - SDL:24/07/2012 - 11:25:58 ---A- . (.SIEMENS AG - TS Adapter RS232-32 Device Driver.) -- C:\Windows\System32\Drivers\s7otsadx32.sys [194560] O58 - SDL:17/12/2013 - 09:00:00 ---A- . (.Siemens AG - S7DOS USB Kernel Mode WDM Driver.) -- C:\Windows\System32\Drivers\s7ousbu32x.sys [123904] O58 - SDL:09/05/2012 - 09:22:26 ---A- . (.SIEMENS AG - SIEMENS RT-Protocol V2.0 (ether-type 0x8892).) -- C:\Windows\System32\Drivers\s7sn2srtx.sys [69848] O58 - SDL:13/07/2009 - 21:50:20 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [20480] O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [40016] O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [77888] O58 - SDL:28/10/2013 - 14:38:14 ---A- . (.Siemens AG - SOFTNET IE ISO Protocol Driver (x86).) -- C:\Windows\System32\Drivers\SNTIE.SYS [276192] O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072] O58 - SDL:04/06/2010 - 01:18:58 ---A- . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\Windows\System32\Drivers\SynTP.sys [1303728] O58 - SDL:16/03/2015 - 18:44:30 ---A- . (.Oracle Corporation - VirtualBox Support Driver.) -- C:\Windows\System32\Drivers\VBoxDrv.sys [749664] O58 - SDL:16/03/2015 - 18:42:58 ---A- . (.Oracle Corporation - VirtualBox Host-Only Network Adapter Driver.) -- C:\Windows\System32\Drivers\VBoxNetAdp.sys [115672] O58 - SDL:16/03/2015 - 18:42:58 ---A- . (.Oracle Corporation - VirtualBox Bridged Networking Driver.) -- C:\Windows\System32\Drivers\VBoxNetFlt.sys [127008] O58 - SDL:16/03/2015 - 18:42:58 ---A- . (.Oracle Corporation - VirtualBox USB Monitor Driver.) -- C:\Windows\System32\Drivers\VBoxUSBMon.sys [104384] O58 - SDL:24/07/2013 - 16:03:04 ---A- . (.Elaborate Bytes AG - Virtual CloneDrive storage miniport.) -- C:\Windows\System32\Drivers\VClone.sys [29696] O58 - SDL:14/07/2009 - 02:19:10 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [16976] O58 - SDL:14/07/2009 - 02:19:11 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [141904] O58 - SDL:07/08/2013 - 10:26:12 ---A- . (.SIEMENS AG - FDLAda Kernel Mode Driver (x86).) -- C:\Windows\System32\Drivers\vsnl2ada32.sys [109056] O58 - SDL:06/08/2014 - 16:29:08 ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}w.sys [52880] =>PUP.LinkiDoo O58 - SDL:13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029] O58 - SDL:13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097] O58 - SDL:13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768] O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809] O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537] O58 - SDL:13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866] O58 - SDL:13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146] O58 - SDL:13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370] O58 - SDL:13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274] O58 - SDL:13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146] O58 - SDL:13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952] O58 - SDL:13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672] O58 - SDL:13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776] O58 - SDL:13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536] O58 - SDL:13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672] ~ Drivers: 82 Scanned in 00mn 31s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC: 03/05/2015 - 15:31:27 ---A- . (...) -- C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\UserCache.bin [111540] O61 - LFC: 03/05/2015 - 15:33:01 ---A- . (...) -- C:\Users\admin\AppData\Local\Temp\OnlineBackup.exe [1120135] O61 - LFC: 04/05/2015 - 15:32:53 ---A- . (...) -- C:\Users\admin\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpaxjydt.dll [43008] O61 - LFC: 04/05/2015 - 15:32:54 ----- . (.Java(TM) Native Access (JNA).) -- C:\Users\admin\AppData\Local\Temp\jna\jna8727212715470846939.dll [441220] O61 - LFC: 04/05/2015 - 15:36:23 ---A- . (.Adobe.) -- C:\Users\admin\Downloads\flash_setup.exe [1055936] O61 - LFC: 27/04/2015 - 15:31:10 ---A- . (.Everything.) -- C:\Users\admin\AppData\Everything\uninst.exe [121437] O61 - LFC: 27/04/2015 - 15:31:25 ---A- . (.Everything.) -- C:\Users\admin\AppData\Everything\update.exe [1967668] ~ 1212 Fichiers temporaires (Temporary files) ~ 310 Fichiers cookies (Cookies files) ~ Files: 7 Scanned in 06mn 56s ---\\ Liste des outils de désinfection (LATC) (O63) O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn 00s ---\\ Liste les services legacy du registre (LALS) (O64) O64 - Services: CurCS - 10/09/2014 - C:\Windows\System32\Drivers\DsArk.sys (DsArk) .(.360.cn - dsark.sys.) - LEGACY_DSARK O64 - Services: CurCS - 04/03/2013 - C:\Windows\System32\Drivers\ElbyCDIO.sys (ElbyCDIO) .(.Elaborate Bytes AG - ElbyCD Windows NT/2000/XP I/O driver.) - LEGACY_ELBYCDIO O64 - Services: CurCS - 09/05/2012 - C:\Windows\System32\DRIVERS\s7sn2srtx.sys (s7sn2srtx) .(.SIEMENS AG - SIEMENS RT-Protocol V2.0 (ether-type 0x8892.) - LEGACY_S7SN2SRTX O64 - Services: CurCS - 13/07/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV O64 - Services: CurCS - 28/10/2013 - C:\Windows\System32\DRIVERS\sntie.sys (SNTIE) .(.Siemens AG - SOFTNET IE ISO Protocol Driver (x86).) - LEGACY_SNTIE O64 - Services: CurCS - 16/03/2015 - C:\Windows\System32\DRIVERS\VBoxDrv.sys (VBoxDrv) .(.Oracle Corporation - VirtualBox Support Driver.) - LEGACY_VBOXDRV O64 - Services: CurCS - 16/03/2015 - C:\Windows\System32\DRIVERS\VBoxUSBMon.sys (VBoxUSBMon) .(.Oracle Corporation - VirtualBox USB Monitor Driver.) - LEGACY_VBOXUSBMON O64 - Services: CurCS - 06/08/2014 - C:\Windows\System32\drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}w.sys ({55dce8ba-9dec-4013-937e-adbf9317d990}w) .(.StdLib - StdLib.) - LEGACY_{55DCE8BA-9DEC-4013-937E-ADBF9317D990}W =>PUP.LinkiDoo ~ Legacy: 109 Scanned in 00mn 03s ---\\ Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (...) -- C:\Program Files\Opera\Launcher.exe O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe ~ FASS Keys: 11 Scanned in 00mn 00s ---\\ Menu de démarrage Internet (SMI) (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Internet Explorer\iexplore.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Opera\Launcher.exe (.not file.) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Users\admin\AppData\Local\UnicoBrowser\Application\unicobrowser.exe (.not file.) =>PUP.UnicoBrowser ~ Keys: Scanned in 00mn 00s ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) O69 - SBI: SearchScopes [HKCU] {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} - (Trovi) - http://www.trovi.com =>Hijacker.TroviCom O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} - (delta-homes) - http://search.delta-homes.com =>Hijacker.DeltaHomes O69 - SBI: SearchScopes [HKCU] {425ED333-6083-428a-92C9-0CFC28B9D1BF} - (V9) - http://www.v9.com =>PUP.V9Software O69 - SBI: SearchScopes [HKCU] {460C3D19-B3D4-4964-A550-77D263B0CCCB} - (SafeFinder Search) - http://feed.safefinder.com =>Hijacker.SmartBar O69 - SBI: SearchScopes [HKCU] {9BB47C17-9C68-4BB3-B188-DD9AF0FD2514} - (default-search.net) - http://www.default-search.net =>Hijacker.Browsers O69 - SBI: SearchScopes [HKCU] {A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9} - (Astromenda) - http://astromenda.com =>PUP.Astromenda O69 - SBI: SearchScopes [HKCU] {D5E56FB0-048E-4681-9A1C-A85911AF58E0} - (Search The Web (buenosearch)) - http://www.buenosearch.com =>PUP.BuenoSearch O69 - SBI: SearchScopes [HKCU] {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} - (StartWeb) - http://start.iminent.com =>Adware.IMBooster O69 - SBI: SearchScopes [HKCU] {F7C78C08-3CC7-416F-B827-7C1785ABBDA8} - (Vosteran) - http://Vosteran.com =>PUP.Vosteran ~ Keys: Scanned in 00mn 00s ---\\ Enumère les service demarrés par Svchost (SSS) (O83) O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [62464] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [475136] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [90624] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [286208] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [49664] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [523776] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2020864] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [47104] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [49664] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164864] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [71168] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [113664] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [102912] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800] O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [149504] ~ Services: 33 Scanned in 00mn 02s ---\\ Recherche particulière à la racine du système (SPRF) (O84) [MD5.9CF5FF46D2B1483A28811C29EA757697] [SPRF][20/04/2015] (...) -- C:\Users\admin\AppData\Roaming\appdataFr3.bin [20] [MD5.91CD76399FE828FD055CBB48B0AA1DCE] [SPRF][10/07/2014] (.Smart Soft - Free PDF to Word Converter Setup.) -- C:\Users\admin\Desktop\pdf-to-word-converter [1].exe [4512336] =>PUP.PDFtoWordConverter [MD5.07114BF359E26D6AAE44A7D555C220AA] [SPRF][27/10/2014] (.Systweak Inc - RegClean Pro.) -- C:\Users\admin\Desktop\rcpsetup_sdl_fr_sdl_fr.exe [3850512] =>Rogue.RegistryPowerCleaner [MD5.7492BF962C2948FDAD6BABCDE4B0CE71] [SPRF][27/10/2014] (.Microsoft Corporation - Microsoft Visual C++ 2008 Express Edition - FRA Setup.) -- C:\Users\admin\Desktop\vcsetup.exe [2743800] ~ Files: 4 Scanned in 00mn 00s ---\\ Recherche d'infection Rogue (SRI) (O86) O43 - CFD: 03/05/2015 - 19:18:56 - [] ----D C:\ProgramData\4291ca9383084a1bb30e07571604a9d6 [MD5.2DC8F1D1E2F387D9CEA87CEBD90E72BF] [SRI] (.Pas de propriétaire - 4291ca9383084a1bb30e07571604a9d6.) -- C:\ProgramData\4291ca9383084a1bb30e07571604a9d6\4291ca9383084a1bb30e07571604a9d6.exe [311296] O43 - CFD: 03/05/2015 - 19:18:48 - [] ----D C:\ProgramData\cfda197ad4914fd0ab4eae97a56d3e83 ~ Files: Scanned in 00mn 00s ---\\ Liste des exceptions du parefeu (FirewallRules) (O87) O87 - FAEL: "{D26A5F88-FA4D-4B24-BC9E-1D42135853C5}" | In - Public - P6 - TRUE | .(.http://goforfiles.com/ - GoforFiles Downloader Application.) -- C:\Program Files\GoforFiles\goforfilesdl.exe =>P2P.GoforFiles O87 - FAEL: "{091D4E10-FE01-4C41-830F-DEF185BF5B1C}" | In - Public - P17 - TRUE | .(.http://goforfiles.com/ - GoforFiles Downloader Application.) -- C:\Program Files\GoforFiles\goforfilesdl.exe =>P2P.GoforFiles O87 - FAEL: "TCP Query User{13D1F1A2-C586-464E-8453-2EBE22E187E1}C:\users\admin\desktop\goforfiles\goforfilesdl.exe" | In - Public - P6 - TRUE | .(.http://goforfiles.com/ - goforfilesdl Application.) -- C:\users\admin\desktop\goforfiles\goforfilesdl.exe =>P2P.GoforFiles O87 - FAEL: "UDP Query User{5BD8B83E-1077-4E51-8D06-4E76D4E34416}C:\users\admin\desktop\goforfiles\goforfilesdl.exe" | In - Public - P17 - TRUE | .(.http://goforfiles.com/ - goforfilesdl Application.) -- C:\users\admin\desktop\goforfiles\goforfilesdl.exe =>P2P.GoforFiles ~ Firewall: 4 Scanned in 00mn 11s ---\\ Export de clés de registre aléatoires (O91) [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:060df2cd="c/Au/XV/H/Ap/X2/GP/j/Xt/axAv/X6////%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:0c230bcb="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:0dc3ee96="/P////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:0e93c3f3="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:1520c6f1="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:1c311243="GlAk/X6/G/Ap/YV/UxAk/YZ/Gl////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:27ddcf6f="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:2d71d5ab="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:2e22d94e="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:340d3099="/P////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:37b7a6d8="UlAr/XJ/c//k////" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:38583bc3="Ml/2/CF/M//g/CZ////%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:3c09c42b="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:414bc593="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:48bd1aff="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:51d2f2ea="J/Ay/YZ/FPAm/Xl/GPAm/W//bxAy/Xb/aPAy////" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:587b5709="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:6185d035="Vx/2/Cx/V//l////" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:65114b36="Vl/l////" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:72758a5d="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:7367429f="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:7f69fa1f="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:8b9e4cbc="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:a0743acc="N/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:a1dcff5b="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:a2e3b941="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:bbf88800="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:c24899a6="VP/g/CV/Vl/2/Cx////%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:c5705860="Vx////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:c6c5dd44="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:c99a5f5c="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:d1abcdb6="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:d94388d2="GlAk/X6/G/Ap/YV/UxAk/YZ/Gl////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:e46c271e="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:e8f9dcc7="UlAr/XJ/c//k////" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:f0bf0bde="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:f1f24e29="Vl/l/C/////%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:f2c53c49="UlAr/XJ/c//k////" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:f6ad6fa6="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:fe94ce1e="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:060df2cd="c/Au/XV/H/Ap/X2/GP/j/Xt/axAv/X6////%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:0c230bcb="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:0dc3ee96="/P////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:0e93c3f3="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:1520c6f1="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:1c311243="GlAk/X6/G/Ap/YV/UxAk/YZ/Gl////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:27ddcf6f="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:2d71d5ab="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:2e22d94e="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:340d3099="/P////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:37b7a6d8="UlAr/XJ/c//k////" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:38583bc3="Ml/2/CF/M//g/CZ////%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:3c09c42b="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:414bc593="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:48bd1aff="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:51d2f2ea="GlAk/X6/b/Ay/XP////%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:587b5709="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:6185d035="Vx/2/Cx/V//l////" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:65114b36="VP/l////" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:72758a5d="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:7367429f="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:7f69fa1f="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:8b9e4cbc="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:a0743acc="N/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:a1dcff5b="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:a2e3b941="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:bbf88800="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:c24899a6="VP/g/CV/Vl/2/Cx////%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:c5705860="Vx////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:c6c5dd44="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:c99a5f5c="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:d1abcdb6="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:d94388d2="GlAk/X6/G/Ap/YV/UxAk/YZ/Gl////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:e46c271e="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:e8f9dcc7="UlAr/XJ/c//k////" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:f0bf0bde="///%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:f1f24e29="Vl/l/C/////%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:f2c53c49="UlAr/XJ/c//k////" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:f6ad6fa6="V/////%%" [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:fe94ce1e="V/////%%" ~ Export Key Software: Scanned in 00mn 00s ---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS) [MD5.F7521B56E8B1AD8BB30E71126FC62A13] [WIS][17/09/2014] (.Linkury Ltd. - SafeFinder Smartbar.) -- C:\Windows\Installer\f56fa.msi [10903552] =>Hijacker.SmartBar [MD5.E891DE918A54A615DF677DDA5AC93AD5] [WIS][27/08/2014] (.LPT - LPT System Updater Service.) -- C:\Windows\Installer\f5700.msi [2138112] =>Adware.IncrediBar ~ WIS: 2 Scanned in 00mn 10s ---\\ Recherche de clés de registre Tracing (O100) HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32 =>PUP.MyPCBackup HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS =>PUP.MyPCBackup HKLM\SOFTWARE\Microsoft\Tracing\DealKeeperSetup_RASAPI32 =>PUP.DealKeeper HKLM\SOFTWARE\Microsoft\Tracing\DealKeeperSetup_RASMANCS =>PUP.DealKeeper HKLM\SOFTWARE\Microsoft\Tracing\DealKeeper_RASAPI32 =>PUP.DealKeeper HKLM\SOFTWARE\Microsoft\Tracing\DealKeeper_RASMANCS =>PUP.DealKeeper HKLM\SOFTWARE\Microsoft\Tracing\DealKeeper_Setup_RASAPI32 =>PUP.DealKeeper HKLM\SOFTWARE\Microsoft\Tracing\DealKeeper_Setup_RASMANCS =>PUP.DealKeeper HKLM\SOFTWARE\Microsoft\Tracing\GoforFiles_RASAPI32 =>P2P.GoforFiles HKLM\SOFTWARE\Microsoft\Tracing\GoforFiles_RASMANCS =>P2P.GoforFiles HKLM\SOFTWARE\Microsoft\Tracing\MixVideoPlayer_RASAPI32 =>PUP.MixVideoPlayer HKLM\SOFTWARE\Microsoft\Tracing\MixVideoPlayer_RASMANCS =>PUP.MixVideoPlayer HKLM\SOFTWARE\Microsoft\Tracing\netengine_RASAPI32 =>PUP.NetEngine HKLM\SOFTWARE\Microsoft\Tracing\netengine_RASMANCS =>PUP.NetEngine HKLM\SOFTWARE\Microsoft\Tracing\SafeFinder_RASAPI32 =>Hijacker.SmartBar HKLM\SOFTWARE\Microsoft\Tracing\SafeFinder_RASMANCS =>Hijacker.SmartBar HKLM\SOFTWARE\Microsoft\Tracing\SupTab_v5_RASAPI32 =>PUP.SupTab HKLM\SOFTWARE\Microsoft\Tracing\SupTab_v5_RASMANCS =>PUP.SupTab HKLM\SOFTWARE\Microsoft\Tracing\updateDealKeeper_RASAPI32 =>PUP.DealKeeper HKLM\SOFTWARE\Microsoft\Tracing\updateDealKeeper_RASMANCS =>PUP.DealKeeper HKLM\SOFTWARE\Microsoft\Tracing\utilDealKeeper_RASAPI32 =>PUP.DealKeeper HKLM\SOFTWARE\Microsoft\Tracing\utilDealKeeper_RASMANCS =>PUP.DealKeeper HKLM\SOFTWARE\Microsoft\Tracing\wpm_v20_RASAPI32 =>PUP.WpManager HKLM\SOFTWARE\Microsoft\Tracing\wpm_v20_RASMANCS =>PUP.WpManager ~ BTK: 146 Scanned in 00mn 00s ---\\ Recherche de clés de registre CLSID (O101) [HKCR\CLSID\{11111111-1111-1111-1111-110611191113}] (iWebar) =>PUP.CrossRider [HKCR\CLSID\{22222222-2222-2222-2222-220622192213}] (CrossriderApp0061913.Sandbox) =>PUP.CrossRider [HKCR\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] (SafeFinder SmartbarEngine) =>Hijacker.SmartBar [HKCR\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}] (SystemK Module) =>PUP.SystemK [HKCR\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}] (globalUpdate Update Plugin) =>PUP.GlobalUpdate [HKCR\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}] (globalUpdate.OneClickProcessLauncher) =>PUP.GlobalUpdate [HKCR\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] (IMinent WebBooster (BHO)) =>Adware.IMBooster [HKCR\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}] (SafeFinder Smartbar) =>Hijacker.SmartBar [HKCR\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}] (globalUpdate Update Plugin) =>PUP.GlobalUpdate [HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}] (YTAHelper) =>PUP.Goobzo ~ BCK: 5889 Scanned in 00mn 39s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 17/04/2015 268464 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe SS - | Auto 22/07/1658 0 | (BackupStack) . (...) - C:\Program Files\MyPC Backup\BackupStack.exe =>PUP.MyPCBackup SS - | Auto 22/07/1658 0 | (ClaraUpdater) . (...) - C:\Program Files\Common Files\ClaraUpdater\ClaraUpdater.exe =>Adware.SupTab SS - | Auto 22/07/1658 0 | (globalUpdate) . (...) - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe =>PUP.GlobalUpdate SS - | Demand 22/07/1658 0 | (globalUpdatem) . (...) - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe =>PUP.GlobalUpdate SS - | Disabled 22/07/1658 0 | (GlobalUpdater) . (...) - C:\Program Files\Common Files\IMGUpdater\IMGUpdater.exe =>PUP.IMGUpdater SS - | Auto 26/09/2014 116648 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Demand 26/09/2014 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Demand 09/04/2014 235696 | (McComponentHostService) . (.McAfee, Inc..) - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe SS - | Demand 16/04/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe SS - | Auto 22/07/1658 0 | (ReimageRealTimeProtector) . (...) - C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe =>Rogue.ReimageRepair SS - | Disabled 22/07/1658 0 | (SProtection) . (...) - C:\Program Files\Common Files\Umbrella\Umbrella226.exe SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 18/03/2015 1962496 | (0e6e6c53) . (...) - c:\Program Files\goopad\goopad.dll SR - | Auto 12/04/2015 1695232 | (5fd90e6b) . (...) - c:\Program Files\SeekerModule\SeekerModule.dll SR - | Auto 06/03/2015 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe SR - | Auto 03/12/2009 26112 | (AgereModemAudio) . (.LSI Corporation.) - C:\Program Files\LSI SoftModem\agrsmsvc.exe SR - | Auto 13/01/2014 1295168 | (almservice) . (.SIEMENS AG.) - C:\Program Files\Common Files\Siemens\sws\almsrv\almsrvx.exe SR - | Auto 12/04/2015 531456 | (haw) . (...) - c:\windows\haw.exe SR - | Auto 12/04/2015 523264 | (mhaw) . (...) - c:\windows\mhaw.exe SR - | Auto 30/01/2015 22184 | (MsMpSvc) . (.Microsoft Corporation.) - C:\Program Files\Microsoft Security Client\MsMpEng.exe SR - | Auto 16/01/2014 425696 | (s7oiehsx) . (.Siemens AG.) - C:\Program Files\Common Files\Siemens\S7IEPG\s7oiehsx.exe SR - | Auto 16/01/2014 560864 | (S7TraceServiceX) . (.Siemens AG.) - C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceServiceX.exe SR - | Auto 23/04/2015 237056 | (ServiceEverything) . (...) - C:\Users\admin\AppData\Everything\ServiceEverything.exe SR - | Auto 12/01/2015 424624 | (winzipersvc) . (.Taiwan Shui Mu Chih Ching Technology Limite.) - C:\Program Files\WinZipper\winzipersvc.exe =>Adware.D365 SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Services: Scanned in 00mn 48s ---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by admin at 04/05/2015 15:46:22 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 04s ---\\ Scan Additionnel (O88) Database Version : 13008 - (02/05/2015) Clés trouvées (Keys found) : 98 Valeurs trouvées (Values found) : 4 Dossiers trouvés (Folders found) : 54 Fichiers trouvés (Files found) : 95 [HKLM\SYSTEM\CurrentControlSet\Services\MyPC Backup) (BackupStack] =>PUP.MyPCBackup^ [HKLM\SYSTEM\CurrentControlSet\Services\ClaraUpdater] =>Adware.SupTab^ [HKLM\SYSTEM\CurrentControlSet\Services\globalUpdate) (globalUpdate] =>PUP.GlobalUpdate^ [HKLM\SYSTEM\CurrentControlSet\Services\ReimageRealTimeProtector] =>Rogue.ReimageRepair^ [HKLM\SYSTEM\CurrentControlSet\Services\winzipersvc] =>Adware.D365^ [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Binkiland] =>PUP.Binkiland^ [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC SpeedUp Service Deactivator] =>Rogue.PCSpeedUp^ [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Price Fountain] =>PUP.PriceFountain^ [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ReimageUpdater] =>Rogue.ReimageRepair^ [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RocketTab] =>PUP.RocketTab^ [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RocketTab Update Task] =>PUP.RocketTab^ [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update Service GoForFiles] =>P2P.GoforFiles^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Deal Keeper] =>PUP.DealKeeper^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Digital Sites] =>PUP.Dealply^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\File Opener Packages] =>Adware.InstallCore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Tweaks FileOpener] =>Adware.InstallCore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\FlashBeat] =>PUP.FlashBeat^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Free PDF to Word Converter_is1] =>PUP.PDFtoWordConverter^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP] =>Adware.IMBooster^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar] =>Adware.IMBooster^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage] =>Adware.Downware^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}] =>Adware.IncrediBar^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Linkey] =>PUP.LinkeySearch^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup] =>PUP.MyPCBackup^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{5fd90e6b}] =>Adware.Graftor^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PriceFountain] =>PUP.PriceFountain^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\RocketTab] =>PUP.RocketTab^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1898B668-CCF5-429F-A86F-9837E5439D77}] =>Hijacker.SmartBar^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Settings Manager] =>PUP.SystemK^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro] =>PUP.ShopperPro^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Ultimate Codecs Setup Wizard Packages] =>Adware.InstallCore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{11F6D5AB-263F-388E-74DE-E3DECD390E3F}] =>PUP.UniDeals^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Update Service GoForFiles] =>P2P.GoforFiles^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Price Fountain] =>PUP.PriceFountain^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WSE_Astromenda] =>PUP.Astromenda^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Search] =>PUP.PaybyAds^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{37476589-E48E-439E-A706-56189E2ED4C4}_is1] =>PUP.Adblocker^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator] =>PUP.Goobzo^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{e6e6c53}] =>Adware.Graftor^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iWebar] =>PUP.CrossRider^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\sweet-page uninstall] =>PUP.SweetPage^ [HKLM\Software\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}] =>Adware.IMBooster [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent [HKLM\Software\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software [HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software [HKLM\Software\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}] =>Adware.IMBooster [HKLM\Software\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}] =>Hijacker.SmartBar [HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}] =>Adware.IMBooster [HKLM\Software\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}] =>Hijacker.SmartBar [HKLM\Software\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}] =>Hijacker.SmartBar [HKLM\Software\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}] =>Hijacker.SmartBar [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] =>Adware.IMBooster [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] =>Adware.IMBooster [HKLM\Software\Classes\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] =>Adware.IMBooster [HKLM\Software\Classes\TypeLib\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC}] =>Adware.IMBooster [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ae07101b-46d4-4a98-af68-0333ea26e113}] =>Adware.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ae07101b-46d4-4a98-af68-0333ea26e113}] =>Adware.Agent [HKLM\Software\Classes\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}] =>Adware.Agent [HKLM\Software\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}] =>Hijacker.SmartBar [HKLM\Software\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}] =>Adware.IMBooster [HKLM\Software\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}] =>Adware.IMBooster [HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}] =>Adware.IMBooster [HKCU\Software\Iminent] =>Adware.IMBooster [HKLM\Software\Iminent] =>Adware.IMBooster [HKCU\Software\SmartbarBackup] =>Hijacker.SmartBar [HKCU\Software\SmartbarLog] =>Hijacker.SmartBar [HKCU\Software\Softonic] =>PUP.Conduit [HKCU\Software\Tutorials] =>Spyware.AgenceExclusive [HKLM\Software\Tutorials] =>Spyware.AgenceExclusive [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{37476589-E48E-439E-A706-56189E2ED4C4}] =>Adware.Agent [HKCU\Software\InstallCore] =>Adware.InstallCore [HKLM\Software\InstallCore] =>Adware.InstallCore [HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider [HKCU\Software\InstalledBrowserExtensions\] =>PUP.CrossRider [HKCU\Software\Reimage] =>Rogue.ReimageRepair [HKLM\Software\Reimage] =>Rogue.ReimageRepair [HKLM\Software\delta-homesSoftware] =>Toolbar.DeltaSearch [HKCU\Software\InstalledBrowserExtensions] =>PUP.CrossRider [HKLM\Software\InstalledBrowserExtensions] =>PUP.CrossRider [HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro [HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro [HKLM\Software\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}] =>Adware.BrowseFox [HKLM\Software\Classes\CrossriderApp0061913.BHO] =>PUP.CrossRider [HKLM\Software\Classes\CrossriderApp0061913.BHO.1] =>PUP.CrossRider [HKLM\Software\Classes\CrossriderApp0061913.Sandbox] =>PUP.CrossRider [HKLM\Software\Classes\CrossriderApp0061913.Sandbox.1] =>PUP.CrossRider [HKLM\Software\Classes\Iminent] =>Adware.IMBooster [HKLM\Software\Classes\IminentWebBooster.BrowserHelperObject] =>Adware.IMBooster [HKLM\Software\Classes\IminentWebBooster.BrowserHelperObject.1] =>Adware.IMBooster [HKLM\Software\Classes\IminentWebBooster.ScriptExtender] =>Adware.IMBooster [HKLM\Software\Classes\IminentWebBooster.ScriptExtender.1] =>Adware.IMBooster [HKCU\Software\Classes\keepmysearch] =>Adware.MyWebSearch [HKLM\Software\Classes\CLSID\{11111111-1111-1111-1111-110611191113}] =>PUP.CrossRider [HKLM\Software\Classes\CLSID\{22222222-2222-2222-2222-220622192213}] =>PUP.CrossRider [HKLM\Software\Classes\AppID\Iminent.WebBooster.InternetExplorer.DLL] =>Adware.IMBooster [HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2514}] =>Adware.Bandoo^ [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:gmsd_fr_414 =>PUP.CrossRider^ [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:pricefountainw.exe =>PUP.PriceFountain^ [HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks]:{84FF7BD6-B47F-46F8-9130-01B2696B36CB} =>Adware.IMBooster C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\pgu6kut4.default-1429039266093\extensions\{ab2afb3f-ced5-e944-9a35-a0d802a604c7} =>PUP.ZoomIt^ C:\Program Files\GoforFiles =>P2P.GoforFiles^ C:\Program Files\GoForFilesUpdater =>P2P.GoforFiles^ C:\Program Files\predm =>Adware.Downware^ C:\Program Files\Common Files\ClaraUpdater =>Adware.SupTab^ C:\Program Files\Common Files\IMGUpdater =>PUP.IMGUpdater^ C:\Program Files\Common Files\ShopperPro =>PUP.ShopperPro^ C:\ProgramData\DSearchLink =>Toolbar.DeltaSearch^ C:\ProgramData\FlashBeat =>PUP.FlashBeat^ C:\ProgramData\IePluginServices =>PUP.IePluginService^ C:\ProgramData\LolliScan =>Adware.Graftor^ C:\ProgramData\NetEngine =>PUP.NetEngine^ C:\ProgramData\Reimage Express =>Rogue.ReimageRepair^ C:\ProgramData\Reimage Protector =>Rogue.ReimageRepair^ C:\ProgramData\ShopperPro =>PUP.ShopperPro^ C:\ProgramData\systemk =>PUP.SystemK^ C:\ProgramData\Uniblue =>PUP.UniblueSystem^ C:\ProgramData\WindowsMangerProtect =>PUP.Fuyu^ C:\ProgramData\Yellow AdBlocker =>PUP.Adblocker^ C:\ProgramData\YTAHelper =>PUP.Goobzo^ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileOpener =>Adware.InstallCore^ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MYBESTOFFERSTODAY =>PUP.MyBestOffersToday^ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip =>PUP.PepperZip^ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Express =>Rogue.ReimageRepair^ C:\Users\admin\AppData\Roaming\1H1Q1V1N1N1O1R =>Adware.InstallCore^ C:\Users\admin\AppData\Roaming\Astromenda =>PUP.Astromenda^ C:\Users\admin\AppData\Roaming\Binkiland =>PUP.Binkiland^ C:\Users\admin\AppData\Roaming\DigitalSites =>Hijacker.DSite^ C:\Users\admin\AppData\Roaming\eCyber =>PUP.Elex^ C:\Users\admin\AppData\Roaming\Free PDF to Word Converter =>PUP.PDFtoWordConverter^ C:\Users\admin\AppData\Roaming\Gameo =>PUP.Gameo^ C:\Users\admin\AppData\Roaming\GoforFiles =>P2P.GoforFiles^ C:\Users\admin\AppData\Roaming\OpenCandy =>Adware.OpenCandy^ C:\Users\admin\AppData\Roaming\PriceFountain =>PUP.PriceFountain^ C:\Users\admin\AppData\Roaming\Probit Software =>PUP.ProbitSoftware^ C:\Users\admin\AppData\Roaming\sweet-page =>PUP.SweetPage^ C:\Users\admin\AppData\Roaming\uTorrent =>P2P.µTorrent^ C:\Users\admin\AppData\Roaming\VOPackage =>Adware.Downware^ C:\Users\admin\AppData\Roaming\WSE_Astromenda =>PUP.Astromenda^ C:\Users\admin\AppData\Local\Binkiland =>PUP.Binkiland^ C:\Users\admin\AppData\Local\Gameo =>PUP.Gameo^ C:\Users\admin\AppData\Local\Genesis_09171126 =>PUP.Genesis^ C:\Users\admin\AppData\Local\globalUpdate =>PUP.GlobalUpdate^ C:\Users\admin\AppData\Local\LPT =>Adware.Incredibar^ C:\Users\admin\AppData\Local\mbot_fr_588 =>PUP.CrossRider^ C:\Users\admin\AppData\Local\Pay-By-Ads =>PUP.PaybyAds^ C:\Users\admin\AppData\Local\PriceFountain =>PUP.PriceFountain^ C:\Users\admin\AppData\Local\Pro_PC_Cleaner =>PUP.DoctorPC^ C:\Users\admin\AppData\Local\Rainmaker_Software_Group_ =>PUP.DoctorPC^ C:\Users\admin\AppData\Local\Smartbar =>Hijacker.SmartBar^ C:\Users\admin\AppData\Local\Vosteran =>PUP.Vosteran^ C:\Program Files\Common Files\Umbrella =>Adware.IMBooster C:\Users\admin\AppData\Local\Installer =>Adware.InstallPedia C:\Users\admin\AppData\LocalLow\Smartbar =>Hijacker.SmartBar [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: Modified =>Hijacker.Application^ C:\Program Files\GoForFilesUpdater\GoForFilesUpdater.exe =>P2P.GoforFiles^ C:\ProgramData\FlashBeat\FlashBeat.exe =>PUP.FlashBeat^ C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-1.job =>PUP.CrossRider^ C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-11.job =>PUP.CrossRider^ C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-2.job =>PUP.CrossRider^ C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-4.job =>PUP.CrossRider^ C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-5.job =>PUP.CrossRider^ C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-5_user.job =>PUP.CrossRider^ C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-6.job =>PUP.CrossRider^ C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-7.job =>PUP.CrossRider^ C:\Windows\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5.job =>PUP.CrossRider^ C:\Windows\System32\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5 =>PUP.CrossRider^ C:\Windows\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5_user.job =>PUP.CrossRider^ C:\Windows\System32\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5_user =>PUP.CrossRider^ C:\Windows\Tasks\Binkiland.job =>PUP.Binkiland^ C:\Windows\System32\Tasks\Binkiland =>PUP.Binkiland^ C:\Windows\Tasks\Digital Sites.job =>Hijacker.DSite^ C:\Windows\System32\Tasks\Digital Sites =>Hijacker.DSite^ C:\Windows\Tasks\Price Fountain.job =>PUP.PriceFountain^ C:\Windows\System32\Tasks\Price Fountain =>PUP.PriceFountain^ C:\Windows\Tasks\WSE_Astromenda.job =>PUP.Astromenda^ C:\Windows\System32\Tasks\WSE_Astromenda =>PUP.Astromenda^ C:\Windows\Tasks\YRCPXQOXG1.job =>PUP.FlashBeat^ C:\Windows\System32\Tasks\YRCPXQOXG1 =>PUP.FlashBeat^ [HKCU\Software\AppDataLow\DealKeeper] =>PUP.DealKeeper^ [HKCU\Software\AppDataLow\Software\DynConIE] =>PUP.DynConIE^ [HKCU\Software\AppDataLow\Software\SpeedChecker] =>PUP.InternetSpeedChecker^ [HKCU\Software\AppDataLow\Software\iWebar] =>PUP.CrossRider^ [HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}] =>Adware.Graftor^ [HKCU\Software\ArenaHD] =>PUP.CrossRider^ [HKCU\Software\Binkiland Browser] =>PUP.Binkiland^ [HKCU\Software\CleanerProConfig] =>PUP.CleanerPro^ [HKCU\Software\CleanerProLanguage] =>PUP.CleanerPro^ [HKCU\Software\CrossBrowser] =>PUP.CrossBrowser^ [HKCU\Software\DSiteproducts] =>Hijacker.DSite^ [HKCU\Software\Deal Keeper] =>PUP.DealKeeper^ [HKCU\Software\Gameo] =>PUP.Gameo^ [HKCU\Software\GoforFiles] =>P2P.GoforFiles^ [HKCU\Software\Goobzo] =>PUP.Goobzo^ [HKCU\Software\HighDefAction] =>PUP.CrossRider^ [HKCU\Software\Optimizer Pro] =>PUP.OptimizerPro^ [HKCU\Software\ProPCCleanerConfig] =>PUP.DoctorPC^ [HKCU\Software\ProPCCleanerLanguage] =>PUP.DoctorPC^ [HKCU\Software\Probit Software] =>PUP.ProbitSoftware^ [HKCU\Software\RocketTabInstalled] =>PUP.RocketTab^ [HKCU\Software\Search Extensions] =>PUP.RocketTab^ [HKCU\Software\ShopperPro] =>PUP.ShopperPro^ [HKCU\Software\Smartbar] =>Hijacker.SmartBar^ [HKCU\Software\SystemK] =>PUP.SystemK^ [HKCU\Software\TutoTag] =>PUP.AgenceExclusive^ [HKCU\Software\UnicoBrowser] =>PUP.UnicoBrowser^ [HKCU\Software\Vosteran Browser] =>PUP.Vosteran^ [HKCU\Software\YorkNewCin] =>PUP.CrossRider^ [HKCU\Software\globalUpdate] =>PUP.GlobalUpdate^ [HKCU\Software\wse_astromenda] =>PUP.Astromenda^ [HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719] =>PUP.CrossRider^ [HKLM\Software\ArenaHD] =>PUP.CrossRider^ [HKLM\Software\DealKeeper] =>PUP.DealKeeper^ [HKLM\Software\EnigmaSoftwareGroup] =>PUP.EnigmaSoftware^ [HKLM\Software\Flashbeat] =>PUP.FlashBeat^ [HKLM\Software\GlobalUpdate] =>PUP.GlobalUpdate^ [HKLM\Software\GoforFiles] =>P2P.GoforFiles^ [HKLM\Software\Goobzo] =>PUP.Goobzo^ [HKLM\Software\HQCinema Pro 2.1V14.04] =>PUP.CrossRider^ [HKLM\Software\HighDefAction] =>PUP.CrossRider^ [HKLM\Software\IMGUpdater] =>PUP.IMGUpdater^ [HKLM\Software\Linkey] =>PUP.LinkeySearch^ [HKLM\Software\MYBESTOFFERSTODAY] =>PUP.MyBestOffersToday^ [HKLM\Software\ORBTR] =>Toolbar.Conduit^ [HKLM\Software\SupDp] =>PUP.SupTab^ [HKLM\Software\SystemK] =>PUP.SystemK^ [HKLM\Software\Uniblue] =>PUP.UniblueSystem^ [HKLM\Software\WebProtector] =>PUP.WebProtect^ [HKLM\Software\YorkNewCin] =>PUP.CrossRider^ [HKLM\Software\supTab] =>PUP.SupTab^ [HKLM\Software\supWPM] =>PUP.WpManager^ [HKLM\Software\supWindowsMangerProtect] =>PUP.Fuyu^ [HKLM\Software\sweet-pageSoftware] =>PUP.SweetPage^ [HKLM\Software\winzipersvc] =>Adware.D365^ C:\Users\admin\Desktop\pdf-to-word-converter =>PUP.PDFtoWordConverter^ C:\Users\admin\Desktop\rcpsetup_sdl_fr_sdl_fr.exe =>Rogue.RegistryPowerCleaner^ C:\Windows\Installer\f56fa.msi =>Hijacker.SmartBar^ C:\Windows\Installer\f5700.msi =>Adware.IncrediBar^ [HKCR\CLSID\{11111111-1111-1111-1111-110611191113}] (iWebar) =>PUP.CrossRider^ [HKCR\CLSID\{22222222-2222-2222-2222-220622192213}] (CrossriderApp0061913.Sandbox) =>PUP.CrossRider^ [HKCR\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] (SafeFinder SmartbarEngine) =>Hijacker.SmartBar^ [HKCR\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}] (SystemK Module) =>PUP.SystemK^ [HKCR\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}] (globalUpdate Update Plugin) =>PUP.GlobalUpdate^ [HKCR\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}] (globalUpdate.OneClickProcessLauncher) =>PUP.GlobalUpdate^ [HKCR\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] (IMinent WebBooster (BHO)) =>Adware.IMBooster^ [HKCR\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}] (SafeFinder Smartbar) =>Hijacker.SmartBar^ [HKCR\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}] (globalUpdate Update Plugin) =>PUP.GlobalUpdate^ [HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}] (YTAHelper) =>PUP.Goobzo^ C:\Windows\Reimage.ini =>Rogue.ReimageRepair ~ Additionnel Scan: 516214 Items scanned in 02mn 45s ---\\ Informations complémentaires sur les modules ~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5) ~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4) ~ http://nicolascoolman.fr/o50-image-file-execution-options-zhpdiag/ =>.Image File Execution Options (IFEO) (O50) ~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51) ~ AMI: 4 Scanned in 00mn 00s ---\\ Récapitulatif des détections trouvées sur votre station http://www.nicolascoolman.fr/blog/ =>Hijacker.Application http://www.nicolascoolman.fr/blog/ =>PUP.FlashBeat http://www.nicolascoolman.fr/blog/ =>PUP.ZoomIt http://www.nicolascoolman.fr/blog/ =>Hijacker.DeltaHomes http://nicolascoolman.fr/adware-imbooster =>Adware.IMBooster http://nicolascoolman.fr/pup-globalupdate =>PUP.GlobalUpdate http://nicolascoolman.fr/hijacker-smartbar =>Hijacker.SmartBar http://nicolascoolman.fr/pup-sweetpage =>PUP.SweetPage http://nicolascoolman.fr/hijacker-proxy =>Hijacker.Proxy http://nicolascoolman.fr/pup-eorezo =>PUP.Eorezo http://nicolascoolman.fr/pup-crossrider =>PUP.CrossRider http://www.nicolascoolman.fr/blog/ =>PUP.PriceFountain http://nicolascoolman.fr/pup-astromenda =>PUP.Astromenda http://www.nicolascoolman.fr/blog/ =>PUP.UnicoBrowser http://nicolascoolman.fr/pup-mypcbackup =>PUP.MyPCBackup http://www.nicolascoolman.fr/blog/ =>Adware.SupTab http://nicolascoolman.fr/rogue-reimagerepair =>Rogue.ReimageRepair http://www.nicolascoolman.fr/blog/ =>Adware.D365 http://www.nicolascoolman.fr/blog/ =>PUP.Binkiland http://www.nicolascoolman.fr/blog/ =>PUP.CleanerPro http://nicolascoolman.fr/hijacker-dsite =>Hijacker.DSite http://nicolascoolman.fr/pup-probitsoftware =>PUP.ProbitSoftware http://nicolascoolman.fr/rogue-pcspeedup =>Rogue.PCSpeedUp http://www.nicolascoolman.fr/blog/ =>PUP.DoctorPC http://www.nicolascoolman.fr/blog/ =>PUP.RocketTab http://nicolascoolman.fr/pup-paybyads =>PUP.PaybyAds http://nicolascoolman.fr/pup-elex =>PUP.Elex http://nicolascoolman.fr/pup-linkidoo =>PUP.LinkiDoo http://nicolascoolman.fr/pup-dealkeeper =>PUP.DealKeeper http://nicolascoolman.fr/pup-dealply =>PUP.Dealply http://nicolascoolman.fr/adware-installcore =>Adware.InstallCore http://www.nicolascoolman.fr/blog/ =>PUP.PDFtoWordConverter http://nicolascoolman.fr/adware-downware =>Adware.Downware http://nicolascoolman.fr/adware-incredibar =>Adware.IncrediBar http://nicolascoolman.fr/pup-linkeysearch =>PUP.LinkeySearch http://www.nicolascoolman.fr/blog/ =>Adware.Graftor http://nicolascoolman.fr/pup-systemk =>PUP.SystemK http://nicolascoolman.fr/pup-shopperpro =>PUP.ShopperPro http://www.nicolascoolman.fr/blog/ =>PUP.UniDeals http://www.nicolascoolman.fr/blog/ =>PUP.Adblocker http://www.nicolascoolman.fr/blog/ =>PUP.Goobzo http://www.nicolascoolman.fr/blog/ =>PUP.DynConIE http://nicolascoolman.fr/pup-internetspeedchecker =>PUP.InternetSpeedChecker http://www.nicolascoolman.fr/blog/ =>PUP.CrossBrowser http://www.nicolascoolman.fr/blog/ =>PUP.Gameo http://www.nicolascoolman.fr/blog/ =>PUP.BrowserExtensions http://nicolascoolman.fr/pup-optimizerpro =>PUP.OptimizerPro http://nicolascoolman.fr/toolbar-conduit =>Toolbar.Conduit http://nicolascoolman.fr/spyware-agenceexclusive =>PUP.AgenceExclusive http://www.nicolascoolman.fr/blog/ =>PUP.Vosteran http://www.nicolascoolman.fr/blog/ =>PUP.EnigmaSoftware http://nicolascoolman.fr/pup-imgupdater =>PUP.IMGUpdater http://www.nicolascoolman.fr/blog/ =>PUP.MyBestOffersToday http://nicolascoolman.fr/pup-suptab =>PUP.SupTab http://www.nicolascoolman.fr/blog/ =>PUP.UniblueSystem http://www.nicolascoolman.fr/blog/ =>PUP.WebProtect http://nicolascoolman.fr/pup-wpmanager =>PUP.WpManager http://www.nicolascoolman.fr/blog/ =>PUP.Fuyu http://nicolascoolman.fr/toolbar-deltasearch =>Toolbar.DeltaSearch http://www.nicolascoolman.fr/blog/ =>PUP.IePluginService http://www.nicolascoolman.fr/blog/ =>PUP.NetEngine http://www.nicolascoolman.fr/blog/ =>PUP.PepperZip http://nicolascoolman.fr/adware-opencandy =>Adware.OpenCandy http://nicolascoolman.fr/pup-genesis =>PUP.Genesis http://nicolascoolman.fr/trojan-vonteera =>Trojan.Vonteera http://nicolascoolman.fr/hijacker-trovicom =>Hijacker.TroviCom http://nicolascoolman.fr/pup-v9software =>PUP.V9Software http://nicolascoolman.fr/hijacker-browsers =>Hijacker.Browsers http://nicolascoolman.fr/pup-buenosearch =>PUP.BuenoSearch http://nicolascoolman.fr/rogue-registrypowercleaner =>Rogue.RegistryPowerCleaner http://www.nicolascoolman.fr/blog/ =>PUP.MixVideoPlayer http://www.nicolascoolman.fr/blog/ =>Toolbar.Agent http://www.nicolascoolman.fr/blog/ =>Adware.Agent http://www.nicolascoolman.fr/blog/ =>PUP.Conduit http://www.nicolascoolman.fr/blog/ =>Spyware.AgenceExclusive http://nicolascoolman.fr/adware-browsefox =>Adware.BrowseFox http://nicolascoolman.fr/adware-mywebsearch =>Adware.MyWebSearch http://nicolascoolman.fr/adware-bandoo =>Adware.Bandoo http://nicolascoolman.fr/adware-installpedia =>Adware.InstallPedia ~ MSI: 79 link(s) detected in 00mn 00s End of the scan (2113 lines in 24mn 38s)(0.8)