cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2015.5.2.45 - Nicolas Coolman (02/05/2015)
~ Lancé par admin (04/05/2015 15:24:43)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Désactivée par l'utilisateur
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17728
MFIE: Mozilla Firefox 37.0.2 (Defaut)
GCIE: Google Chrome v42.0.2311.135
OPIE: Opera Stable v27.0.1689.66

---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : Absent (Not found)
Windows ID Activation : Inconnue (Unknown)
Windows Licence : Inconnue (Unknown)
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 7 Professional, 32-bit Service Pack 1 (Build 7601)

---\\ Logiciels de protection du système
Microsoft Security Client v4.7.0205.0
McAfee Security Scan Plus v3.8.150.1
Windows Defender W7 (Deactivate)

---\\ Logiciels d'optimisation du système
CCleaner v5.03

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 17 NPAPI
Adobe Acrobat Reader DC - Français

---\\ Informations sur le système
~ Processor: x86 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 1976 MB (16% free)
System Restore: Activé (Enable)
System drive C: has 8 GB (16%) free of 49 GB

---\\ Mode de connexion au système
~ Computer Name: ADMIN-PC
~ User Name: admin
~ All Users Names: HomeGroupUser$, Administrateur, admin,
~ Unselected Option: None
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\admin\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\admin\AppData\Roaming\
~ %Desktop% : C:\Users\admin\Desktop\
~ %Favorites% : C:\Users\admin\Favorites\
~ %LocalAppData% : C:\Users\admin\AppData\Local\
~ %StartMenu% : C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 8 Go of 49 Go)
D: Hard drive, Flash drive, Thumb drive (Free 205 Go of 249 Go)
E: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowMyGames: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: Modified =>Hijacker.Application
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: 46 Scanned in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.15BC38A7492BEFE831966ADB477CF76F] - (.Microsoft Corporation - Explorateur Windows.) (.03/02/2015 - 21:56:27.) -- C:\Windows\Explorer.exe [2613248]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.C46904F2E9E121A91DDDABB48D7648C3] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.13/03/2015 - 03:20:28.) -- C:\Windows\System32\wininet.dll [1888256]
[MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.17/07/2014 - 02:39:27.) -- C:\Windows\System32\Winlogon.exe [304128]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 22:29:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:36:07.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 22:29:07.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 22:29:08.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:18:22.) -- C:\Windows\system32\Drivers\ntfs.sys [1212352]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.B973FCFC50DC1434E1970A146F7E3885] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.20/11/2010 - 22:29:49.) -- C:\Windows\system32\Drivers\rdpdr.sys [133632]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:32:14.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Generic Processes: Scanned in 00mn 04s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes musiques (My Musics) : 1/2
~ Mes Favoris (My Favorites) : 1/26
~ Mes Documents (My Documents) : 1/97
~ Mon Bureau (My Desktop) : 25/397
~ Menu demarrer (Programs) : 1/4
~ Hidden Files: Scanned in 00mn 03s



---\\ Processus lancés
[MD5.6667B602F5FA5012859A44FD0D8D2B2E] - (...) -- C:\Users\admin\AppData\Everything\SFK.exe [92672] [PID.4016]
[MD5.13A317E9A45E2E5A864D120D8A2058E0] - (.http://goforfiles.com/ - GoforFiles Updater Application.) -- C:\Program Files\GoForFilesUpdater\GoForFilesUpdater.exe [278096] [PID.2340] =>P2P.GoforFiles
[MD5.38813ADD1A1C6B72D2D153DD27B2BEB1] - (.FlashBeat - Install.) -- C:\ProgramData\FlashBeat\FlashBeat.exe [634880] [PID.4028] =>PUP.FlashBeat
[MD5.C681F347514CC8671977FCBD2B7D001A] - (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe [185872] [PID.3680]
[MD5.2C1B1E9174D94E9F6EE3CF373ABAB7DD] - (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxtray.exe [137752] [PID.3956]
[MD5.87D78CF6365BDDACBE9D34B60FE0E23B] - (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe [171032] [PID.3916]
[MD5.89D3DE5E2C77DCD99C56F0E46310AEA0] - (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe [172568] [PID.3648]
[MD5.3FD2E665F30942DD873993070047A8C3] - (.Pas de propriétaire - SearchBase.) -- C:\Users\admin\AppData\Everything\SearchBase.exe [1049088] [PID.3404]
[MD5.9A9DDC8E9D12B1567097668249DFF8E9] - (.Pas de propriétaire - everything.) -- C:\Users\admin\AppData\Everything\Everything.exe [332288] [PID.2068]
[MD5.20CB286C4591EEA68778CA6626D70D47] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1791272] [PID.4196]
[MD5.16AFB34618E1286FF856DC600AC49C79] - (.Pas de propriétaire - DivX Update.) -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968] [PID.4312]
[MD5.10247055758850D4D0E9469322A93D42] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.4688]
[MD5.C5B54BF8A1306750F3D85FE21A873465] - (.Pas de propriétaire - Viber.) -- C:\Users\admin\AppData\Local\Viber\Viber.exe [936656] [PID.4932]
[MD5.3D558E2572EDF52FAD098AF2534B4E20] - (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe [279456] [PID.5024]
[MD5.2B24F194FC5B657397ECB2923A68350E] - (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe [5503768] [PID.5176]
[MD5.2759F22A2E98ACFE664019534E33508E] - (.Dropbox, Inc. - Dropbox.) -- C:\Users\admin\AppData\Roaming\Dropbox\bin\Dropbox.exe [43376600] [PID.5224]
[MD5.7E6B4AD487ED241D8224108E8E86A351] - (.Adobe Systems Incorporated - Adobe® Flash® Player Installer/Uninstaller.) -- C:\Windows\system32\Macromed\Flash\FlashUtil32_17_0_0_169_ActiveX.exe [927920] [PID.3112]
[MD5.B3581F426DC500A51091CDD5BACF0454] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [815288] [PID.3556]
[MD5.C06C9EC74A0971A31A40723432201C86] - (.Nicolas Coolman - ZHPDiag.) -- D:\ZHPDiag\ZHPDiag.exe [8206336] [PID.3260]
[MD5.73D19AFCCCDE13FCA91F3817C58FF1CC] - (.The MathWorks Inc. - MATLAB (R2014a).) -- D:\fichiers\bin\win32\MATLAB.exe [141824] [PID.6952]
[MD5.2DC8F1D1E2F387D9CEA87CEBD90E72BF] - (.Pas de propriétaire - 4291ca9383084a1bb30e07571604a9d6.) -- C:\ProgramData\4291ca9383084a1bb30e07571604a9d6\4291ca9383084a1bb30e07571604a9d6.exe [311296] [PID.7556]
~ Processes Running: Scanned in 00mn 28s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9l7vumfu.default\prefs.js (.not file.)
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\pgu6kut4.default-1429039266093\prefs.js
M2 - MFEP: RegExtension {e4f94d1e-2f53-401e-8885-681602c0ddd8} . (...) -- C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
M0 - MFSP: prefs.js [admin - pgu6kut4.default-1429039266093] www.google.fr
M2 - MFEP: Extension [admin - 9l7vumfu.default] idszasulqgikh_c@ieghilld_ewxvluh.edu
M2 - MFEP: Extension [admin - 9l7vumfu.default] veggy@veggyAddon.com
M2 - MFEP: Extension [admin - 9l7vumfu.default] {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Adblock Plus Extension Mozilla Firefox
M2 - MFEP: prefs.js [admin - pgu6kut4.default-1429039266093\idszasulqgikh_c@ieghilld_ewxvluh.edu] [] DiscountExt v8.19 (..)
M2 - MFEP: prefs.js [admin - pgu6kut4.default-1429039266093\veggy@veggyAddon.com] [] Mozilla Firefox Hotfixer v8.19 (..)
M2 - MFEP: prefs.js [admin - pgu6kut4.default-1429039266093\{ab2afb3f-ced5-e944-9a35-a0d802a604c7}] [] Zoom It v8.19 (..) =>PUP.ZoomIt
M2 - MFEP: Extension [admin - pgu6kut4.default-1429039266093] idszasulqgikh_c@ieghilld_ewxvluh.edu
M2 - MFEP: Extension [admin - pgu6kut4.default-1429039266093] veggy@veggyAddon.com
M2 - MFEP: Extension [admin - pgu6kut4.default-1429039266093] {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Adblock Plus Extension Mozilla Firefox
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFF12.DLL
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 15.7.20033.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN:Firefox Plugin Navigator . (.RealNetworks, Inc. - RealPlayer(tm) LiveConnect-Enabled Plug-In.) -- C:\Program Files\Mozilla Firefox\Plugins\nppl3260.dll
P2 - FPN:Firefox Plugin Navigator . (.RealNetworks, Inc. - RealJukebox Netscape Plugin.) -- C:\Program Files\Mozilla Firefox\Plugins\nprjplug.dll
P2 - FPN:Firefox Plugin Navigator . (.RealNetworks, Inc. - 6.0.12.69.) -- C:\Program Files\Mozilla Firefox\Plugins\nprpjplug.dll
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\delta-homes.xml =>Hijacker.DeltaHomes
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\StartWeb.xml =>Adware.IMBooster
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo-france.xml
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll
P2 - FPN: [HKLM] [@divx.com/DivX VOD Helper,version=1.0.0] - (.DivX, LLC. - DivX VOD Helper Plug-in.) -- C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
P2 - FPN: [HKLM] [@divx.com/DivX Web Player Plug-In,version=1.0.0] - (.DivX, LLC - DivX Web Player version 3.2.4.1250.) -- C:\Program Files\DivX\DivX Web Player\npdivx32.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
P2 - FPN: [HKLM] [@real.com/nppl3260;version=6.0.12.69] - (.RealNetworks, Inc. - RealPlayer(tm) LiveConnect-Enabled Plug-In.) -- C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
P2 - FPN: [HKLM] [@real.com/nprjplug;version=1.0.3.69] - (.RealNetworks, Inc. - RealJukebox Netscape Plugin.) -- C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
P2 - FPN: [HKLM] [@real.com/nprpjplug;version=6.0.12.69] - (.RealNetworks, Inc. - 6.0.12.69.) -- C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
P2 - FPN: [HKLM] [@staging.google.com/globalUpdate Update;version=10] - (...) -- C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (.not file.) =>PUP.GlobalUpdate
P2 - FPN: [HKLM] [@staging.google.com/globalUpdate Update;version=4] - (...) -- C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (.not file.) =>PUP.GlobalUpdate
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 15.7.20033.) -- C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
P2 - FPN: [HKCU] [@Skype Limited.com/Facebook Video Calling Plugin] - (.Skype Limited - Facebook Video Calling Plugin.) -- C:\Users\admin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
~ Firefox Browser: 55 Scanned in 00mn 04s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.safefinder.com =>Hijacker.SmartBar
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com =>Hijacker.DeltaHomes
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.safefinder.com =>Hijacker.SmartBar
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com =>PUP.SweetPage
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com =>Hijacker.DeltaHomes
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com =>PUP.SweetPage
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.safefinder.com =>Hijacker.SmartBar
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.safefinder.com =>Hijacker.SmartBar
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://feed.safefinder.com =>Hijacker.SmartBar
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (...) (No version) -- (.not file.)
R3 - URLSearchHook: (no name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} . (...) (No version) -- (.not file.)
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 0
~ IE Browser: 17 Scanned in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:52146;https=127.0.0.1:52146 =>Hijacker.Proxy
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (25)
~ Hosts File: Scanned in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: Automation Software Updater.lnk . (.Siemens AG - Pas de description.) -- C:\Program Files\Common Files\Siemens\ASU\Siemens.Automation.SoftwareUpdater.exe =>PUP.Eorezo
~ Global Startup: 1 Scanned in 00mn 40s



---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe =>.RealNetworks, Inc
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DivXMediaServer] . (.DivX, LLC - DivX Media Server Launcher.) -- C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] . (.Pas de propriétaire - DivX Update.) -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- C:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKLM\..\Run: [SiemensAutomationFileStorage_TIAP13] . (.Siemens AG - Siemens.Automation.ObjectFrame.FileStorage..) -- D:\logiciels\Siemens\Automation\Portal V13\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe
O4 - HKLM\..\Run: [gmsd_fr_414] Clé orpheline =>PUP.CrossRider
O4 - HKLM\..\Run: [mbot_fr_588] C:\Program Files\mbot_fr_588\mbot_fr_588.exe (.not file.) =>PUP.CrossRider
O4 - HKCU\..\Run: [Viber] . (.Pas de propriétaire - Viber.) -- C:\Users\admin\AppData\Local\Viber\Viber.exe
O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe
O4 - HKCU\..\Run: [pricefountainw.exe] C:\Users\admin\AppData\Local\PriceFountain\pricefountainw.exe (.not file.) =>PUP.PriceFountain
O4 - HKCU\..\Run: [BRS] C:\Program Files\WSE_Astromenda\BRS\brs.exe (.not file.) =>PUP.Astromenda
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
O4 - HKCU\..\Run: [UnicoBrowser] C:\Users\admin\AppData\Local\UnicoBrowser\Application\unicobrowser.exe (.not file.) =>PUP.UnicoBrowser
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-3876991765-701069293-2132216276-1000\..\Run: [Viber] . (.Pas de propriétaire - Viber.) -- C:\Users\admin\AppData\Local\Viber\Viber.exe
O4 - HKUS\S-1-5-21-3876991765-701069293-2132216276-1000\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe
O4 - HKUS\S-1-5-21-3876991765-701069293-2132216276-1000\..\Run: [pricefountainw.exe] C:\Users\admin\AppData\Local\PriceFountain\pricefountainw.exe (.not file.) =>PUP.PriceFountain
O4 - HKUS\S-1-5-21-3876991765-701069293-2132216276-1000\..\Run: [BRS] C:\Program Files\WSE_Astromenda\BRS\brs.exe (.not file.) =>PUP.Astromenda
O4 - HKUS\S-1-5-21-3876991765-701069293-2132216276-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
O4 - HKUS\S-1-5-21-3876991765-701069293-2132216276-1000\..\Run: [UnicoBrowser] C:\Users\admin\AppData\Local\UnicoBrowser\Application\unicobrowser.exe (.not file.) =>PUP.UnicoBrowser
~ Application: Scanned in 00mn 01s



---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ IE Control Panel: 1 Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
~ Winsock: 7 Scanned in 00mn 00s



---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} ((no name)) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
~ Objets ActiveX: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{E412C835-9AA0-4770-9F4A-8BDD59B90544}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 =>.Google DNS Redirections
O17 - HKLM\System\CCS\Services\Tcpip\..\{1716A0AE-8DD6-4B6F-AF02-C6D69DB17BAF}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CS1\Services\Tcpip\..\{E412C835-9AA0-4770-9F4A-8BDD59B90544}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 =>.Google DNS Redirections
O17 - HKLM\System\CS1\Services\Tcpip\..\{1716A0AE-8DD6-4B6F-AF02-C6D69DB17BAF}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CS2\Services\Tcpip\..\{E412C835-9AA0-4770-9F4A-8BDD59B90544}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 =>.Google DNS Redirections
O17 - HKLM\System\CS2\Services\Tcpip\..\{1716A0AE-8DD6-4B6F-AF02-C6D69DB17BAF}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - AppInit_DLLs: . (.FlashBeat - Install.) - C:\ProgramData\FlashBeat\FlashBeat32.dll =>PUP.FlashBeat
~ AppInit DLL: Scanned in 00mn 00s



---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ SSODL: 1 Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: goopad (0e6e6c53) . (...) - c:\Program Files\goopad\goopad.dll
O23 - Service: SeekerModule (5fd90e6b) . (...) - c:\Program Files\SeekerModule\SeekerModule.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) . (.LSI Corporation - LSI Soft Modem Call Progress Service.) - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Automation License Manager Service (almservice) . (.SIEMENS AG - Automation License Manager Service.) - C:\Program Files\Common Files\Siemens\sws\almsrv\almsrvx.exe
O23 - Service: Computer Backup (MyPC Backup) (BackupStack) . (...) - C:\Program Files\MyPC Backup\BackupStack.exe (.not file.) =>PUP.MyPCBackup
O23 - Service: ClaraUpdater (ClaraUpdater) . (...) - C:\Program Files\Common Files\ClaraUpdater\ClaraUpdater.exe (.not file.) =>Adware.SupTab
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) . (...) - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe (.not file.) =>PUP.GlobalUpdate
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc
O23 - Service: haw (haw) . (...) - c:\windows\haw.exe
O23 - Service: mhaw (mhaw) . (...) - c:\windows\mhaw.exe
O23 - Service: Reimage Real Time Protector (ReimageRealTimeProtector) . (...) - C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe (.not file.) =>Rogue.ReimageRepair
O23 - Service: SIMATIC S7DOS Help Service (s7oiehsx) . (.Siemens AG - Siemens SIMATIC S7DOS Help Service.) - C:\Program Files\Common Files\Siemens\S7IEPG\s7oiehsx.exe
O23 - Service: S7TraceServiceX (S7TraceServiceX) . (.Siemens AG - S7TraceServiceX Module.) - C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceServiceX.exe
O23 - Service: ServiceEverything (ServiceEverything) . (...) - C:\Users\admin\AppData\Everything\ServiceEverything.exe
O23 - Service: WinZiper service (winzipersvc) . (.Taiwan Shui Mu Chih Ching Technology Limite - dsk service.) - C:\Program Files\WinZipper\winzipersvc.exe =>Adware.D365
~ Services: 12 Scanned in 01mn 25s



---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Desktop Component: 4 Scanned in 00mn 00s



---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [a208d04d-b0d5-4747-bf28-bb1ba986e156-5] (...) -- C:\Program Files\HQCinema Pro 2.1V14.04\a208d04d-b0d5-4747-bf28-bb1ba986e156-5.exe (.not file.) [0] =>PUP.CrossRider
[MD5.00000000000000000000000000000000] [APT] [a208d04d-b0d5-4747-bf28-bb1ba986e156-5_user] (...) -- C:\Program Files\HQCinema Pro 2.1V14.04\a208d04d-b0d5-4747-bf28-bb1ba986e156-5.exe (.not file.) [0] =>PUP.CrossRider
[MD5.64495D9B3C4B640230E9265C23A33F55] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1018056]
[MD5.B04A4810C6CC205F9DC72DC22E4AB236] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [268464]
[MD5.00000000000000000000000000000000] [APT] [Binkiland] (...) -- C:\Users\admin\AppData\Roaming\BINKIL~1\UPDATE~1\UPDATE~1.exe (.not file.) [0] =>PUP.Binkiland
[MD5.2B24F194FC5B657397ECB2923A68350E] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [5503768]
[MD5.00000000000000000000000000000000] [APT] [CleanerPro_Popup] (...) -- C:\Program Files\Cleaner Pro\Splash.exe (.not file.) [0] =>PUP.CleanerPro
[MD5.00000000000000000000000000000000] [APT] [CleanerPro_Start] (...) -- C:\Program Files\Cleaner Pro\CleanerPro.exe (.not file.) [0] =>PUP.CleanerPro
[MD5.00000000000000000000000000000000] [APT] [Digital Sites] (...) -- C:\Users\admin\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.exe (.not file.) [0] =>Hijacker.DSite
[MD5.00000000000000000000000000000000] [APT] [Easy Driver Pro Schedule] (...) -- C:\Program Files\Probit Software\Easy Driver Pro\EDPTray.exe (.not file.) [0] =>PUP.ProbitSoftware
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000Core] (.Facebook Inc..) -- C:\Users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096]
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000UA] (.Facebook Inc..) -- C:\Users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [116648]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [116648]
[MD5.00000000000000000000000000000000] [APT] [Installer_sense] (...) -- C:\Users\admin\AppData\Local\Temp\nsyCB50.tmp\setup.exe (.not file.) [0]
[MD5.2DC8F1D1E2F387D9CEA87CEBD90E72BF] [APT] [IULCQ] (...) -- C:\ProgramData\4291ca9383084a1bb30e07571604a9d6\4291ca9383084a1bb30e07571604a9d6.exe [311296]
[MD5.00000000000000000000000000000000] [APT] [LaunchSignup] (...) -- C:\Program Files\MyPC Backup\Signup Wizard.exe (.not file.) [0] =>PUP.MyPCBackup
[MD5.9D9D0351A3B9CFD0A4336F61F2480A82] [APT] [Math Problem Solver CPU] (...) -- C:\Users\admin\AppData\Local\Math Problem Solver\cpu\Solve.exe [184443]
[MD5.72AE4B443A4D7138EA1F710946AC735E] [APT] [Math Problem Solver Optimize] (...) -- C:\Users\admin\AppData\Local\Math Problem Solver\Optimize.exe [67740]
[MD5.00000000000000000000000000000000] [APT] [Opera scheduled Autoupdate 1422719743] (...) -- C:\Program Files\Opera\launcher.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [PC SpeedUp Service Deactivator] (...) -- C:\Program Files\Accelerer PC\PCSUSD.exe (.not file.) [0] =>Rogue.PCSpeedUp
[MD5.00000000000000000000000000000000] [APT] [Price Fountain] (...) -- C:\Users\admin\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.exe (.not file.) [0] =>PUP.PriceFountain
[MD5.00000000000000000000000000000000] [APT] [ProPCCleaner_Popup] (...) -- C:\Program Files\Pro PC Cleaner\Splash.exe (.not file.) [0] =>PUP.DoctorPC
[MD5.00000000000000000000000000000000] [APT] [ProPCCleaner_Start] (...) -- C:\Program Files\Pro PC Cleaner\ProPCCleaner.exe (.not file.) [0] =>PUP.DoctorPC
[MD5.00000000000000000000000000000000] [APT] [ReimageUpdater] (...) -- C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe (.not file.) [0] =>Rogue.ReimageRepair
[MD5.00000000000000000000000000000000] [APT] [RocketTab] (...) -- C:\Program Files\Search Extensions\Client.exe (.not file.) [0] =>PUP.RocketTab
[MD5.00000000000000000000000000000000] [APT] [RocketTab Update Task] (...) -- C:\Program Files\Search Extensions\uninstall.exe (.not file.) [0] =>PUP.RocketTab
[MD5.00000000000000000000000000000000] [APT] [Run_Browser] (...) -- C:\Users\admin\AppData\Local\UnicoBrowser\Application\unicobrowser.exe (.not file.) [0] =>PUP.UnicoBrowser
[MD5.13A317E9A45E2E5A864D120D8A2058E0] [APT] [Update Service GoForFiles] (.http://goforfiles.com/.) -- C:\Program Files\GoForFilesUpdater\GoForFilesUpdater.exe [278096] =>P2P.GoforFiles
[MD5.00000000000000000000000000000000] [APT] [WSE_Astromenda] (...) -- C:\Users\admin\AppData\Roaming\WSE_AS~1\UPDATE~1\UPDATE~1.exe (.not file.) [0] =>PUP.Astromenda
[MD5.00000000000000000000000000000000] [APT] [Yahoo! Search] (...) -- C:\Users\admin\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrlte.exe (.not file.) [0] =>PUP.PaybyAds
[MD5.00000000000000000000000000000000] [APT] [Yahoo! Search Udpater] (...) -- C:\Users\admin\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrsetup.exe (.not file.) [0] =>PUP.PaybyAds
[MD5.38813ADD1A1C6B72D2D153DD27B2BEB1] [APT] [YRCPXQOXG1] (.FlashBeat.) -- C:\ProgramData\FlashBeat\FlashBeat.exe [634880] =>PUP.FlashBeat
[MD5.00000000000000000000000000000000] [APT] [{05ABE6DE-F7BE-49CC-BF92-C644214BA61D}] (...) -- C:\Program Files\ZHPDiag\ZHPFix\ZHPhep.exe (.not file.) [0]
[MD5.C26E8DB10C77C1138B4991882BDEE9C3] [APT] [{068A93B4-18A2-4EFD-A3C7-9006EE327D18}] (...) -- C:\Users\admin\Desktop\psim crack 32bit\PSIM 9.0.3.400_x32.exe [71213056]
[MD5.330E83B9C6557E0E7695AA442913AD0F] [APT] [{148C0D02-7290-4CA7-B166-FB6249EB1528}] (...) -- C:\Program Files\HDM Connection Manager\HDM Connection Manager.exe [536576]
[MD5.330E83B9C6557E0E7695AA442913AD0F] [APT] [{5F877CC5-020C-4EB4-9FDE-FAC78A9CD6EB}] (...) -- C:\Program Files\HDM Connection Manager\HDM Connection Manager.exe [536576]
[MD5.00000000000000000000000000000000] [APT] [{9191F52C-15D1-4098-8694-CC5864F7C737}] (...) -- J:\SetupSimple.exe (.not file.) [0]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{B3795B30-24E6-42AF-B6C5-C8DC429E8672}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.330E83B9C6557E0E7695AA442913AD0F] [APT] [{CF1DCD60-80F5-4E00-B587-BA88C977A4D0}] (...) -- C:\Program Files\HDM Connection Manager\HDM Connection Manager.exe [536576]
O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-1.job [1790] =>PUP.CrossRider
O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-11.job [4122] =>PUP.CrossRider
O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-2.job [1584] =>PUP.CrossRider
O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-4.job [2354] =>PUP.CrossRider
O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-5.job [1684] =>PUP.CrossRider
O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-5_user.job [1698] =>PUP.CrossRider
O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-6.job [1800] =>PUP.CrossRider
O39 - APT: - (..) -- C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-7.job [1730] =>PUP.CrossRider
O39 - APT: a208d04d-b0d5-4747-bf28-bb1ba986e156-5 - (...) -- C:\Windows\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5.job [2436] =>PUP.CrossRider
O39 - APT: a208d04d-b0d5-4747-bf28-bb1ba986e156-5 - (...) -- C:\Windows\System32\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5 [2436] =>PUP.CrossRider
O39 - APT: a208d04d-b0d5-4747-bf28-bb1ba986e156-5_user - (...) -- C:\Windows\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5_user.job [2436] =>PUP.CrossRider
O39 - APT: a208d04d-b0d5-4747-bf28-bb1ba986e156-5_user - (...) -- C:\Windows\System32\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5_user [2436] =>PUP.CrossRider
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: Binkiland - (...) -- C:\Windows\Tasks\Binkiland.job [292] =>PUP.Binkiland
O39 - APT: Binkiland - (...) -- C:\Windows\System32\Tasks\Binkiland [292] =>PUP.Binkiland
O39 - APT: Digital Sites - (...) -- C:\Windows\Tasks\Digital Sites.job [292] =>Hijacker.DSite
O39 - APT: Digital Sites - (...) -- C:\Windows\System32\Tasks\Digital Sites [292] =>Hijacker.DSite
O39 - APT: FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000Core - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000Core.job [906]
O39 - APT: FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000Core - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000Core [906]
O39 - APT: FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000UA - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000UA.job [928]
O39 - APT: FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000UA - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3876991765-701069293-2132216276-1000UA [928]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1054]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1054]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1058]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1058]
O39 - APT: Price Fountain - (...) -- C:\Windows\Tasks\Price Fountain.job [292] =>PUP.PriceFountain
O39 - APT: Price Fountain - (...) -- C:\Windows\System32\Tasks\Price Fountain [292] =>PUP.PriceFountain
O39 - APT: WSE_Astromenda - (...) -- C:\Windows\Tasks\WSE_Astromenda.job [292] =>PUP.Astromenda
O39 - APT: WSE_Astromenda - (...) -- C:\Windows\System32\Tasks\WSE_Astromenda [292] =>PUP.Astromenda
O39 - APT: YRCPXQOXG1 - (.FlashBeat.) -- C:\Windows\Tasks\YRCPXQOXG1.job [330] =>PUP.FlashBeat
O39 - APT: YRCPXQOXG1 - (.FlashBeat.) -- C:\Windows\System32\Tasks\YRCPXQOXG1 [330] =>PUP.FlashBeat
~ Scheduled Task: 68 Scanned in 00mn 55s



---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Disable SSL3 - {7D715857-A67C-4C2F-A929-038448584D63} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
O40 - ASIC: Google Chrome - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google Inc. - Google Chrome Installer.) -- C:\Program Files\Google\Chrome\Application\42.0.2311.135\Installer\chrmstp.exe
~ Active Setup: 11 Scanned in 00mn 01s



---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (BAPIDRV) . (. - .) - C:\Windows\System32\DRIVERS\BAPIDRV.sys (.not file.)
O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys
O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
O41 - Driver: C:\Windows\System32\cscsvc.dll (CSC) . (.Microsoft Corporation - Windows Client Side Caching Driver.) - C:\Windows\System32\drivers\csc.sys
O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
O41 - Driver: (dpmconv) . (.Siemens AG - DPM Kernel Mode Driver.) - C:\Windows\System32\DRIVERS\dpmconv32.sys
O41 - Driver: (ElbyCDIO) . (.Elaborate Bytes AG - ElbyCD Windows NT/2000/XP I/O driver.) - C:\Windows\System32\Drivers\ElbyCDIO.sys
O41 - Driver: (iSafeKrnlMon) . (. - .) - C:\Program Files\Elex-tech\YAC\iSafeKrnlMon.sys (.not file.) =>PUP.Elex
O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\System32\DRIVERS\mssmbios.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys
O41 - Driver: (VBoxDrv) . (.Oracle Corporation - VirtualBox Support Driver.) - C:\Windows\System32\DRIVERS\VBoxDrv.sys
O41 - Driver: (VBoxUSBMon) . (.Oracle Corporation - VirtualBox USB Monitor Driver.) - C:\Windows\System32\DRIVERS\VBoxUSBMon.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys
O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
O41 - Driver: ({55dce8ba-9dec-4013-937e-adbf9317d990}w) . (.StdLib - StdLib.) - C:\Windows\System32\drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}w.sys =>PUP.LinkiDoo
~ Drivers: 84 Scanned in 00mn 03s



---\\ Logiciels installés (O42)
O42 - Logiciel: Adobe Acrobat Reader DC - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AC0F074E4100}
O42 - Logiciel: Adobe Flash Player 17 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 17 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI
O42 - Logiciel: Affiche Facile - Studio-Scrap - (.CDIP.) [HKLM] -- {AF2F4120-B7B6-407E-A0BF-D6D710EE37EE}_is1
O42 - Logiciel: Astroburn Lite - (.Disc Soft Ltd.) [HKLM] -- Astroburn Lite
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: Configuration DivX - (.DivX, LLC.) [HKLM] -- DivX Setup
O42 - Logiciel: DC-Bass Source 1.3.0 - (...) [HKLM] -- DC-Bass Source
O42 - Logiciel: Deal Keeper - (.Deal Keeper.) [HKLM] -- Deal Keeper =>PUP.DealKeeper
O42 - Logiciel: DirectVobSub 2.40.4209 - (.MPC-HC Team.) [HKLM] -- vsfilter_is1
O42 - Logiciel: DiscountSmasher - (.DiscountSmasher.) [HKLM] -- {37476589-E48E-439E-A706-56189E2ED4C4}
O42 - Logiciel: Dropbox - (.Dropbox, Inc..) [HKCU] -- Dropbox
O42 - Logiciel: Extended Update - (.Extended Update.) [HKCU] -- Digital Sites =>PUP.Dealply
O42 - Logiciel: Facebook Video Calling 3.1.0.521 - (.Skype Limited.) [HKLM] -- {2091F234-EB58-4B80-8C96-8EB78C808CF7}
O42 - Logiciel: File Opener Packages - (...) [HKCU] -- File Opener Packages =>Adware.InstallCore
O42 - Logiciel: FileOpener - (.Tweaks.) [HKLM] -- Tweaks FileOpener =>Adware.InstallCore
O42 - Logiciel: FlashBeat - (...) [HKLM] -- FlashBeat =>PUP.FlashBeat
O42 - Logiciel: Free PDF to Word Converter 5.1.0.383 - (.Smart Soft.) [HKLM] -- Free PDF to Word Converter_is1 =>PUP.PDFtoWordConverter
O42 - Logiciel: GDR 5520 pour SQL Server 2008 (KB2977321) - (.Microsoft Corporation.) [HKLM] -- KB2977321
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: HDM Connection Manager - (.Huawei Technologies Co.,Ltd.) [HKLM] -- HDM Connection Manager
O42 - Logiciel: Haali Media Splitter - (...) [HKLM] -- HaaliMkx
O42 - Logiciel: Iminent - (.Iminent.) [HKLM] -- IMBoosterARP =>Adware.IMBooster
O42 - Logiciel: IminentToolbar - (.Iminent.) [HKLM] -- IminentToolbar =>Adware.IMBooster
O42 - Logiciel: Installer - (...) [HKLM] -- VOPackage =>Adware.Downware
O42 - Logiciel: LAME v3.99.3 (for Windows) - (...) [HKLM] -- LAME_is1
O42 - Logiciel: LPT System Updater Service - (.LPT.) [HKLM] -- {BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24} =>Adware.IncrediBar
O42 - Logiciel: LSI HDA Modem - (.LSI Corporation.) [HKLM] -- LSI Soft Modem
O42 - Logiciel: Lagarith Lossless Codec (1.3.27) - (...) [HKLM] -- {F59AC46C-10C3-4023-882C-4212A92283B3}_is1
O42 - Logiciel: LibreOffice 4.3.5.2 - (.The Document Foundation.) [HKLM] -- {1D4E90DA-C33C-40ED-BA00-75F6E6DF9CB0}
O42 - Logiciel: Linkey - (.Aztec Media Inc.) [HKCU] -- Linkey =>PUP.LinkeySearch
O42 - Logiciel: MATLAB Production Server R2014a - (.The MathWorks, Inc..) [HKLM] -- MATLAB Production Server R2014a
O42 - Logiciel: MATLAB R2011a - (.The MathWorks, Inc..) [HKLM] -- MatlabR2011a
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: Math Problem Solver - (...) [HKCU] -- Math Problem Solver
O42 - Logiciel: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM] -- McAfee Security Scan
O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
O42 - Logiciel: Microsoft Primary Interoperability Assemblies 2005 - (.Microsoft Corporation.) [HKLM] -- {D24DB8B9-BB6C-4334-9619-BA1C650E13D3}
O42 - Logiciel: Microsoft SOAP Toolkit 3.0 - (.Microsoft Corporation.) [HKLM] -- {BCB4C18A-ACA6-4383-8688-E19933A705DD}
O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {D6F9CBDC-58B6-430A-8DD4-8F61CBC1ADF4}
O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries - (.Microsoft Corporation.) [HKLM] -- {842FAF7C-50EF-4463-9B8F-6222E1384D7D}
O42 - Logiciel: Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Fra - (.Microsoft Corporation.) [HKLM] -- {484AB636-ADBC-3A85-AB82-41873BDD1083}
O42 - Logiciel: Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32 - (.Microsoft Corporation.) [HKLM] -- {044F9133-B8D7-4d11-BF39-803FA20F5C8B}
O42 - Logiciel: Mozilla Firefox 37.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 37.0.2 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: MyPC Backup - (.JDi Backup Ltd.) [HKLM] -- MyPC Backup =>PUP.MyPCBackup
O42 - Logiciel: Opera Stable 27.0.1689.66 - (.Opera Software ASA.) [HKLM] -- Opera 27.0.1689.66
O42 - Logiciel: Oracle VM VirtualBox 4.3.26 - (.Oracle Corporation.) [HKLM] -- {26B8608D-6C29-4171-9751-67621C834AA3}
O42 - Logiciel: PSIM 9.0.3 - (.Powersim.) [HKLM] -- {98D13EC5-0C60-48eb-A7FA-1B0008EC4C2D}
O42 - Logiciel: PSIM 9.1.1 Demo Version - (.Powersim.) [HKLM] -- {D46F2B61-FEE0-46AF-B57F-0EF74F0ECC98}
O42 - Logiciel: ParallelPragma - (.ParallelPragma.) [HKLM] -- {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{5fd90e6b} =>Adware.Graftor
O42 - Logiciel: PriceFountain (remove only) - (.Price Fountain.) [HKCU] -- PriceFountain =>PUP.PriceFountain
O42 - Logiciel: RealPlayer - (.RealNetworks.) [HKLM] -- RealPlayer 6.0
O42 - Logiciel: RocketTab - (.RocketTab.) [HKLM] -- RocketTab =>PUP.RocketTab
O42 - Logiciel: RonyaSoft Poster Designer (Poster Forge) 2.01 - (.RonyaSoft.) [HKLM] -- RonyaSoft Poster Designer (Poster Forge)
O42 - Logiciel: SIMATIC Prosave - (.Siemens AG.) [HKLM] -- {8E912B95-EDFE-457C-88C3-C8E4062A9C3A}
O42 - Logiciel: SIMATIC Prosave V13.0 - (.Siemens AG.) [HKLM] -- {8E912B95-EDFE-457C-88C3-C8E4062A9C3A}Prosave
O42 - Logiciel: SQL Server System CLR Types - (.Microsoft Corporation.) [HKLM] -- {342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}
O42 - Logiciel: SafeFinder Smartbar - (.Linkury Ltd..) [HKLM] -- {1898B668-CCF5-429F-A86F-9837E5439D77} =>Hijacker.SmartBar
O42 - Logiciel: Service Pack 3 pour SQL Server 2008 (KB2546951) - (.Microsoft Corporation.) [HKLM] -- KB2546951
O42 - Logiciel: Settings Manager - (.Aztec Media Inc.) [HKLM] -- Settings Manager =>PUP.SystemK
O42 - Logiciel: Shopper-Pro - (...) [HKLM] -- ShopperPro =>PUP.ShopperPro
O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - HM All Editions Single - (.Siemens AG.) [HKLM] -- {9ABABC1F-7789-4C55-9646-0D226AF77D17}
O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - HM NoBasic Single Setup - (.Siemens AG.) [HKLM] -- {F9E889FA-A86A-41EB-8C59-90134AA06632}
O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - Hardware Support Base P - (.Siemens AG.) [HKLM] -- {3B848F75-330D-4C4F-80B1-1A4540C08722}
O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - Hardware Support Base P - (.Siemens AG.) [HKLM] -- {92DEC257-1F2E-4D51-9607-DD95431488F9}
O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - Hardware Support Base P - (.Siemens AG.) [HKLM] -- {A9C45FA9-9BD4-4A26-9C80-62F4DCAF1A71}
O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - Hardware Support Base P - (.Siemens AG.) [HKLM] -- {FDFF76C9-501E-48DA-8632-11794A501F25}
O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - STEP 7 Single SetupPack - (.Siemens AG.) [HKLM] -- {36B49AF8-34D8-466C-8360-0E9A51AC7FF3}
O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - Simatic Single SetupPac - (.Siemens AG.) [HKLM] -- {CFC1C6B7-8863-4D82-B88E-029A48B29DE2}
O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - Support Base Package TO - (.Siemens AG.) [HKLM] -- {2D9E85E8-AF62-4779-8B5D-BFE115942412}
O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - Support Base Package TO - (.Siemens AG.) [HKLM] -- {5EABBDC2-FA29-473C-8BB1-5EF28A5CBDFF}
O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - TIA Tour Single SetupPa - (.Siemens AG.) [HKLM] -- {AA3B02C7-8179-4A4C-80D6-8EB90456D0EE}
O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - TIACOMPCHECK Single Set - (.Siemens AG.) [HKLM] -- {7365E985-FEAB-47F8-837B-D923F2408925}
O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - WinCC Single SetupPacka - (.Siemens AG.) [HKLM] -- {5B08D312-9383-4619-B1EF-C26D924B7404}
O42 - Logiciel: Siemens Automation License Manager - (.Siemens AG.) [HKLM] -- {9B4A5B53-8814-41C9-8A84-D4A952FADEA5}
O42 - Logiciel: Siemens Automation License Manager V5.3 + Upd1 - (.Siemens AG.) [HKLM] -- {9B4A5B53-8814-41C9-8A84-D4A952FADEA5}LicenseManager
O42 - Logiciel: Siemens Totally Integrated Automation Portal V13 - (.Siemens AG.) [HKLM] -- Siemens Installer Assistant - TIAP13
O42 - Logiciel: Sql Server Customer Experience Improvement Program - (.Microsoft Corporation.) [HKLM] -- {C965F01C-76EA-4BD7-973E-46236AE312D7}
O42 - Logiciel: Studio-Scrap : Complement-affiche-facile - (.CDIP.) [HKLM] -- {0B994F37-88CE-41D2-ACC0-AE4194832B72}}_is1
O42 - Logiciel: Studio-Scrap6 : Contenu graphique - (.CDIP.) [HKLM] -- {65143150-8B56-4F76-82AC-BE73B528925F}_is1
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey
O42 - Logiciel: Totally Integrated Automation Portal V13 - TIA Portal Single SetupPackage - (.Siemens AG.) [HKLM] -- {DC371F38-8208-498A-9A69-FD35DC3C074D}
O42 - Logiciel: Ultimate Codecs Setup Wizard Packages - (...) [HKCU] -- Ultimate Codecs Setup Wizard Packages =>Adware.InstallCore
O42 - Logiciel: UniDeallsa - (...) [HKLM] -- {11F6D5AB-263F-388E-74DE-E3DECD390E3F} =>PUP.UniDeals
O42 - Logiciel: Update Service GoForFiles - (.http://www.goforfiles.com.) [HKCU] -- Update Service GoForFiles =>P2P.GoforFiles
O42 - Logiciel: Update for PriceFountain - (.Update for PriceFountain.) [HKCU] -- Price Fountain =>PUP.PriceFountain
O42 - Logiciel: VC User 71 RTL X86 --- - (.redistributed from Microsoft Corporation merge modules.) [HKLM] -- {A4A4567C-5C29-4756-992D-F84D8250C435}
O42 - Logiciel: VC80CRTRedist - 8.0.50727.6195 - (.DivX, Inc.) [HKLM] -- {933B4015-4618-4716-A828-5289FC03165F}
O42 - Logiciel: VLC media player 1.1.2 - (.VideoLAN.) [HKLM] -- VLC media player =>.VideoLAN
O42 - Logiciel: Viber - (.Viber Media Inc.) [HKCU] -- Viber
O42 - Logiciel: WSE_Astromenda - (.WSE_Astromenda.) [HKLM] -- WSE_Astromenda =>PUP.Astromenda
O42 - Logiciel: WinRAR archiver - (...) [HKLM] -- WinRAR archiver
O42 - Logiciel: WinZipper - (.Taiwan Shui Mu Chih Ching Technology Limited..) [HKLM] -- WinZipper
O42 - Logiciel: Xvid Video Codec - (.Xvid Team.) [HKLM] -- Xvid Video Codec 1.3.2
O42 - Logiciel: Yahoo! Search - (.Pay-By-Ads.) [HKCU] -- Yahoo! Search =>PUP.PaybyAds
O42 - Logiciel: Yellow AdBlocker - (.Yellow AdBlocker.) [HKLM] -- {37476589-E48E-439E-A706-56189E2ED4C4}_is1 =>PUP.Adblocker
O42 - Logiciel: YouTube Accelerator - (.Goobzo Ltd..) [HKLM] -- YouTube Accelerator =>PUP.Goobzo
O42 - Logiciel: goopad - (.Software Publisher.) [HKLM] -- {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{e6e6c53} =>Adware.Graftor
O42 - Logiciel: iWebar - (.iWebar.) [HKLM] -- iWebar =>PUP.CrossRider
O42 - Logiciel: sweet-page uninstall - (.sweet-page.) [HKLM] -- sweet-page uninstall =>PUP.SweetPage
~ Logic: 71 Scanned in 00mn 02s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow\DealKeeper] =>PUP.DealKeeper
[HKCU\Software\AppDataLow\FDA]
[HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider
[HKCU\Software\AppDataLow\Software\DynConIE] =>PUP.DynConIE
[HKCU\Software\AppDataLow\Software\SpeedChecker] =>PUP.InternetSpeedChecker
[HKCU\Software\AppDataLow\Software\iWebar] =>PUP.CrossRider
[HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
[HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}] =>Adware.Graftor
[HKCU\Software\AppDataLow]
[HKCU\Software\ArenaHD] =>PUP.CrossRider
[HKCU\Software\Avira]
[HKCU\Software\BRS]
[HKCU\Software\Binkiland Browser] =>PUP.Binkiland
[HKCU\Software\Bitdefender]
[HKCU\Software\CDIP]
[HKCU\Software\Chromium]
[HKCU\Software\Classes]
[HKCU\Software\CleanerProConfig] =>PUP.CleanerPro
[HKCU\Software\CleanerProLanguage] =>PUP.CleanerPro
[HKCU\Software\Clients]
[HKCU\Software\ClkApp]
[HKCU\Software\Clubic]
[HKCU\Software\CoinisRevShare]
[HKCU\Software\CrossBrowser] =>PUP.CrossBrowser
[HKCU\Software\DSP-worx]
[HKCU\Software\DSiteproducts] =>Hijacker.DSite
[HKCU\Software\Deal Keeper] =>PUP.DealKeeper
[HKCU\Software\Disc Soft]
[HKCU\Software\DivX]
[HKCU\Software\Easy Speed Check]
[HKCU\Software\Elaborate Bytes]
[HKCU\Software\Facebook]
[HKCU\Software\GNU]
[HKCU\Software\Gabest]
[HKCU\Software\Gameo] =>PUP.Gameo
[HKCU\Software\GoforFiles] =>P2P.GoforFiles
[HKCU\Software\GoldenGate]
[HKCU\Software\Goobzo] =>PUP.Goobzo
[HKCU\Software\Google]
[HKCU\Software\Haali]
[HKCU\Software\HighDefAction] =>PUP.CrossRider
[HKCU\Software\Iminent] =>Adware.IMBooster
[HKCU\Software\InstallCore] =>Adware.InstallCore
[HKCU\Software\InstalledBrowserExtensions] =>PUP.BrowserExtensions
[HKCU\Software\Intel]
[HKCU\Software\LAV]
[HKCU\Software\Licenses]
[HKCU\Software\Local AppWizard-Generated Applications]
[HKCU\Software\MCAFEE]
[HKCU\Software\Macromedia]
[HKCU\Software\MainConcept]
[HKCU\Software\MathWorks]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Netscape]
[HKCU\Software\OB]
[HKCU\Software\ODBC]
[HKCU\Software\Opera Software]
[HKCU\Software\Optimizer Pro] =>PUP.OptimizerPro
[HKCU\Software\Oracle]
[HKCU\Software\POWERSIM]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\PrcFountain]
[HKCU\Software\ProPCCleanerConfig] =>PUP.DoctorPC
[HKCU\Software\ProPCCleanerLanguage] =>PUP.DoctorPC
[HKCU\Software\Probit Software] =>PUP.ProbitSoftware
[HKCU\Software\RealNetworks]
[HKCU\Software\Reg]
[HKCU\Software\Reimage] =>Rogue.ReimageRepair
[HKCU\Software\RocketTabInstalled] =>PUP.RocketTab
[HKCU\Software\RonyaSoft]
[HKCU\Software\SIEMENS]
[HKCU\Software\SafeGuardApp]
[HKCU\Software\Search Extensions] =>PUP.RocketTab
[HKCU\Software\ShopperPro] =>PUP.ShopperPro
[HKCU\Software\SkypeRS]
[HKCU\Software\Smart Soft]
[HKCU\Software\SmartbarBackup] =>Hijacker.SmartBar
[HKCU\Software\SmartbarLog] =>Hijacker.SmartBar
[HKCU\Software\Smartbar] =>Hijacker.SmartBar
[HKCU\Software\Softonic] =>Toolbar.Conduit
[HKCU\Software\Synaptics]
[HKCU\Software\SystemK] =>PUP.SystemK
[HKCU\Software\TeamViewer]
[HKCU\Software\TeleCharger]
[HKCU\Software\The Document Foundation]
[HKCU\Software\Trolltech]
[HKCU\Software\TutoTag] =>PUP.AgenceExclusive
[HKCU\Software\Tutorials] =>PUP.AgenceExclusive
[HKCU\Software\UnicoBrowser] =>PUP.UnicoBrowser
[HKCU\Software\UpdateStar]
[HKCU\Software\V9]
[HKCU\Software\Vosteran Browser] =>PUP.Vosteran
[HKCU\Software\WebApp]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\Wnkey]
[HKCU\Software\YorkNewCin] =>PUP.CrossRider
[HKCU\Software\ZebHelpProcess Helper]
[HKCU\Software\globalUpdate] =>PUP.GlobalUpdate
[HKCU\Software\rttasks]
[HKCU\Software\skype]
[HKCU\Software\summer games]
[HKCU\Software\summergames]
[HKCU\Software\wse_astromenda] =>PUP.Astromenda
[HKLM\Software\"alpha_installer"/n]
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719] =>PUP.CrossRider
[HKLM\Software\ATI Technologies]
[HKLM\Software\Adobe]
[HKLM\Software\Agere]
[HKLM\Software\AppDataLow]
[HKLM\Software\ArenaHD] =>PUP.CrossRider
[HKLM\Software\CBSTEST]
[HKLM\Software\Clara]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\DealKeeper] =>PUP.DealKeeper
[HKLM\Software\Debian]
[HKLM\Software\Disc Soft]
[HKLM\Software\DivX]
[HKLM\Software\EnigmaSoftwareGroup] =>PUP.EnigmaSoftware
[HKLM\Software\Flashbeat] =>PUP.FlashBeat
[HKLM\Software\GlobalUpdate] =>PUP.GlobalUpdate
[HKLM\Software\GoforFiles] =>P2P.GoforFiles
[HKLM\Software\Goobzo] =>PUP.Goobzo
[HKLM\Software\Google]
[HKLM\Software\HQCinema Pro 2.1V14.04] =>PUP.CrossRider
[HKLM\Software\HighDefAction] =>PUP.CrossRider
[HKLM\Software\Huawei technologies]
[HKLM\Software\IMGUpdater] =>PUP.IMGUpdater
[HKLM\Software\Iminent] =>Adware.IMBooster
[HKLM\Software\InstallCore] =>Adware.InstallCore
[HKLM\Software\InstallShield]
[HKLM\Software\InstalledBrowserExtensions] =>PUP.BrowserExtensions
[HKLM\Software\InstalledOptions]
[HKLM\Software\Intel]
[HKLM\Software\LSI]
[HKLM\Software\Lame For Audacity]
[HKLM\Software\LibreOffice]
[HKLM\Software\Licenses]
[HKLM\Software\Linkey] =>PUP.LinkeySearch
[HKLM\Software\MYBESTOFFERSTODAY] =>PUP.MyBestOffersToday
[HKLM\Software\Macromedia]
[HKLM\Software\MathWorks]
[HKLM\Software\MaxPower]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\ODBC]
[HKLM\Software\ORBTR] =>Toolbar.Conduit
[HKLM\Software\Opera Software]
[HKLM\Software\Oracle]
[HKLM\Software\POWERSIM]
[HKLM\Software\Piriform]
[HKLM\Software\PluginHp]
[HKLM\Software\Policies]
[HKLM\Software\RealNetworks]
[HKLM\Software\Reg]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Reimage] =>Rogue.ReimageRepair
[HKLM\Software\RichFX]
[HKLM\Software\RonyaSoft]
[HKLM\Software\SafeGuardApp]
[HKLM\Software\Siemens]
[HKLM\Software\SiteSee]
[HKLM\Software\Skype]
[HKLM\Software\Sonic]
[HKLM\Software\SupDp] =>PUP.SupTab
[HKLM\Software\Synaptics]
[HKLM\Software\SystemK] =>PUP.SystemK
[HKLM\Software\TeamViewer]
[HKLM\Software\The Document Foundation]
[HKLM\Software\Tutorials] =>PUP.AgenceExclusive
[HKLM\Software\Umbrella]
[HKLM\Software\Uniblue] =>PUP.UniblueSystem
[HKLM\Software\V9]
[HKLM\Software\VideoLAN]
[HKLM\Software\Volatile]
[HKLM\Software\WOW6432Node]
[HKLM\Software\WebProtector] =>PUP.WebProtect
[HKLM\Software\Xing Technology Corp.]
[HKLM\Software\Xvid Team]
[HKLM\Software\YorkNewCin] =>PUP.CrossRider
[HKLM\Software\delta-homesSoftware] =>Hijacker.DeltaHomes
[HKLM\Software\hdcode]
[HKLM\Software\mcafeeupdater]
[HKLM\Software\mozilla.org]
[HKLM\Software\supTab] =>PUP.SupTab
[HKLM\Software\supWPM] =>PUP.WpManager
[HKLM\Software\supWindowsMangerProtect] =>PUP.Fuyu
[HKLM\Software\sweet-pageSoftware] =>PUP.SweetPage
[HKLM\Software\winzipersvc] =>Adware.D365
~ Key Software: 382 Scanned in 00mn 02s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 31/10/2012 - 22:48:44 - [0] ----D C:\Program Files\2844371e45800dd4fe
O43 - CFD: 19/10/2014 - 21:05:56 - [0] ----D C:\Program Files\360
O43 - CFD: 22/04/2015 - 00:08:06 - [] ----D C:\Program Files\Adobe
O43 - CFD: 24/07/2014 - 02:31:28 - [] ----D C:\Program Files\Astroburn Lite
O43 - CFD: 15/12/2014 - 19:52:26 - [] ----D C:\Program Files\Avira
O43 - CFD: 07/10/2014 - 22:51:40 - [] ----D C:\Program Files\bin
O43 - CFD: 24/02/2015 - 15:52:02 - [] ----D C:\Program Files\CCleaner
O43 - CFD: 22/04/2015 - 00:08:06 - [] ----D C:\Program Files\Common Files
O43 - CFD: 07/10/2014 - 22:46:56 - [] ----D C:\Program Files\Dev-Cpp
O43 - CFD: 04/12/2014 - 18:36:48 - [] ----D C:\Program Files\DirectVobSub
O43 - CFD: 04/12/2014 - 18:41:05 - [] ----D C:\Program Files\DivX
O43 - CFD: 04/12/2014 - 18:36:45 - [] ----D C:\Program Files\DSP-worx
O43 - CFD: 12/04/2011 - 03:45:15 - [] ----D C:\Program Files\DVD Maker
O43 - CFD: 07/10/2014 - 22:55:09 - [] ----D C:\Program Files\etc
O43 - CFD: 07/10/2014 - 22:55:26 - [] ----D C:\Program Files\extern
O43 - CFD: 15/07/2014 - 04:36:26 - [] -SH-D C:\Program Files\Fichiers communs
O43 - CFD: 04/10/2014 - 11:18:47 - [] ----D C:\Program Files\GoforFiles =>P2P.GoforFiles
O43 - CFD: 28/09/2014 - 23:28:46 - [] ----D C:\Program Files\GoForFilesUpdater =>P2P.GoforFiles
O43 - CFD: 26/09/2014 - 19:29:11 - [] ----D C:\Program Files\Google
O43 - CFD: 18/03/2015 - 23:39:41 - [] ----D C:\Program Files\goopad
O43 - CFD: 04/12/2014 - 18:36:45 - [] ----D C:\Program Files\Haali
O43 - CFD: 22/07/2014 - 11:18:10 - [] ----D C:\Program Files\HDM Connection Manager
O43 - CFD: 07/10/2014 - 22:59:55 - [] ----D C:\Program Files\help
O43 - CFD: 30/09/2014 - 20:59:43 - [] ----D C:\Program Files\Intel
O43 - CFD: 15/04/2015 - 18:03:05 - [] ----D C:\Program Files\Internet Explorer
O43 - CFD: 04/12/2014 - 18:36:47 - [] ----D C:\Program Files\Lame For Audacity
O43 - CFD: 08/01/2015 - 16:59:07 - [] ----D C:\Program Files\LibreOffice 4
O43 - CFD: 30/09/2014 - 21:00:21 - [] ----D C:\Program Files\LSI SoftModem
O43 - CFD: 03/08/2014 - 20:43:27 - [] ----D C:\Program Files\MATLAB
O43 - CFD: 01/10/2014 - 13:27:47 - [] ----D C:\Program Files\McAfee Security Scan
O43 - CFD: 15/07/2014 - 21:02:13 - [] ----D C:\Program Files\Microsoft
O43 - CFD: 28/02/2015 - 11:14:39 - [] ----D C:\Program Files\Microsoft Office
O43 - CFD: 27/10/2014 - 20:33:24 - [] ----D C:\Program Files\Microsoft SDKs
O43 - CFD: 24/02/2015 - 17:00:17 - [] ----D C:\Program Files\Microsoft Security Client
O43 - CFD: 25/02/2015 - 00:23:18 - [] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 22/04/2015 - 23:37:49 - [] ----D C:\Program Files\Microsoft SQL Server
O43 - CFD: 15/07/2014 - 15:05:26 - [] ----D C:\Program Files\Microsoft Visual Studio
O43 - CFD: 15/07/2014 - 15:03:34 - [] ----D C:\Program Files\Microsoft Visual Studio 8
O43 - CFD: 27/10/2014 - 20:36:28 - [] ----D C:\Program Files\Microsoft Visual Studio 9.0
O43 - CFD: 25/02/2015 - 00:27:56 - [] ----D C:\Program Files\Microsoft Works
O43 - CFD: 27/10/2014 - 20:42:50 - [] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 23/04/2015 - 11:19:41 - [] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 23/04/2015 - 18:46:31 - [] ----D C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 15/07/2014 - 15:05:35 - [] ----D C:\Program Files\MSBuild
O43 - CFD: 31/07/2014 - 22:44:05 - [] ----D C:\Program Files\MSECache
O43 - CFD: 02/04/2015 - 19:29:13 - [] ----D C:\Program Files\MSSOAP
O43 - CFD: 05/04/2015 - 09:47:17 - [0] ----D C:\Program Files\MSXML 4.0
O43 - CFD: 25/03/2015 - 22:25:28 - [] ----D C:\Program Files\Oracle
O43 - CFD: 13/04/2015 - 21:46:23 - [0] ----D C:\Program Files\predm =>Adware.Downware
O43 - CFD: 07/10/2014 - 23:08:03 - [] R---D C:\Program Files\Program Files
O43 - CFD: 15/07/2014 - 15:31:52 - [] ----D C:\Program Files\Real
O43 - CFD: 14/07/2009 - 06:52:30 - [] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 24/02/2015 - 16:08:11 - [] ----D C:\Program Files\RemoveWAT
O43 - CFD: 07/10/2014 - 23:13:26 - [] ----D C:\Program Files\resources
O43 - CFD: 28/09/2014 - 15:17:31 - [] ----D C:\Program Files\RonyaSoft
O43 - CFD: 12/04/2015 - 16:34:53 - [] ----D C:\Program Files\SeekerModule
O43 - CFD: 28/09/2014 - 14:40:33 - [] ----D C:\Program Files\Studio-Scrap
O43 - CFD: 16/04/2015 - 22:32:02 - [0] ----D C:\Program Files\summer games
O43 - CFD: 30/09/2014 - 21:01:00 - [] ----D C:\Program Files\Synaptics
O43 - CFD: 07/10/2014 - 23:16:27 - [] ----D C:\Program Files\sys
O43 - CFD: 14/07/2009 - 06:53:23 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 15/07/2014 - 15:01:19 - [] ----D C:\Program Files\VideoLAN
O43 - CFD: 04/08/2014 - 20:15:32 - [0] ----D C:\Program Files\VirtualCloneDrive
O43 - CFD: 07/10/2014 - 22:48:27 - [] ----D C:\Program Files\Windows
O43 - CFD: 18/07/2014 - 02:28:06 - [] ----D C:\Program Files\Windows Defender
O43 - CFD: 18/07/2014 - 02:28:18 - [] ----D C:\Program Files\Windows Journal
O43 - CFD: 15/07/2014 - 21:02:07 - [] ----D C:\Program Files\Windows Live
O43 - CFD: 15/07/2014 - 21:01:56 - [] ----D C:\Program Files\Windows Live SkyDrive
O43 - CFD: 12/04/2011 - 03:35:39 - [] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 11/03/2015 - 08:36:35 - [] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 15/07/2014 - 04:36:26 - [] ----D C:\Program Files\Windows NT
O43 - CFD: 12/04/2011 - 03:35:39 - [] ----D C:\Program Files\Windows Photo Viewer
O43 - CFD: 20/11/2010 - 23:33:48 - [] ----D C:\Program Files\Windows Portable Devices
O43 - CFD: 12/04/2011 - 03:35:39 - [] ----D C:\Program Files\Windows Sidebar
O43 - CFD: 15/07/2014 - 14:59:32 - [] ----D C:\Program Files\WinRAR
O43 - CFD: 04/05/2015 - 14:36:59 - [] ----D C:\Program Files\WinZipper
O43 - CFD: 04/12/2014 - 18:37:12 - [] ----D C:\Program Files\Xvid
O43 - CFD: 28/09/2014 - 23:28:56 - [] ----D C:\Program Files\YouTube Accelerator
O43 - CFD: 22/04/2015 - 00:08:09 - [] ----D C:\Program Files\Common Files\Adobe
O43 - CFD: 20/04/2015 - 18:33:51 - [0] ----D C:\Program Files\Common Files\ClaraUpdater =>Adware.SupTab
O43 - CFD: 26/02/2015 - 02:05:50 - [] ----D C:\Program Files\Common Files\DESIGNER
O43 - CFD: 04/12/2014 - 18:40:46 - [] ----D C:\Program Files\Common Files\DivX Shared
O43 - CFD: 20/04/2015 - 18:33:51 - [0] ----D C:\Program Files\Common Files\IMGUpdater =>PUP.IMGUpdater
O43 - CFD: 31/10/2014 - 12:32:05 - [] ----D C:\Program Files\Common Files\InstallShield
O43 - CFD: 27/10/2014 - 20:35:32 - [] ----D C:\Program Files\Common Files\Merge Modules
O43 - CFD: 25/02/2015 - 00:28:06 - [] ----D C:\Program Files\Common Files\microsoft shared
O43 - CFD: 02/04/2015 - 19:29:10 - [] ----D C:\Program Files\Common Files\MSSoap
O43 - CFD: 15/07/2014 - 15:48:59 - [] ----D C:\Program Files\Common Files\Real
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\Services
O43 - CFD: 20/04/2015 - 18:33:51 - [0] ----D C:\Program Files\Common Files\ShopperPro =>PUP.ShopperPro
O43 - CFD: 02/04/2015 - 20:23:17 - [] ----D C:\Program Files\Common Files\Siemens
O43 - CFD: 14/07/2009 - 04:37:05 - [] ----D C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 26/02/2015 - 02:00:07 - [] ----D C:\Program Files\Common Files\System
O43 - CFD: 20/04/2015 - 18:33:51 - [0] ----D C:\Program Files\Common Files\Umbrella
O43 - CFD: 15/07/2014 - 21:00:18 - [] ----D C:\Program Files\Common Files\Windows Live
O43 - CFD: 20/04/2015 - 19:16:08 - [] ----D C:\Program Files\Common Files\Wise Installation Wizard
O43 - CFD: 15/07/2014 - 15:49:00 - [] ----D C:\Program Files\Common Files\xing shared
O43 - CFD: 20/04/2015 - 18:33:53 - [0] ----D C:\ProgramData\10151118858217902536
O43 - CFD: 03/01/2015 - 19:29:01 - [0] ----D C:\ProgramData\2308189059
O43 - CFD: 18/10/2014 - 19:42:27 - [] -SH-D C:\ProgramData\360Quarant
O43 - CFD: 03/05/2015 - 19:18:56 - [] ----D C:\ProgramData\4291ca9383084a1bb30e07571604a9d6
O43 - CFD: 22/04/2015 - 11:26:53 - [] ----D C:\ProgramData\Adobe
O43 - CFD: 24/02/2015 - 16:01:15 - [] ----D C:\ProgramData\ancfdjgoagdpnnklgagpodgclmnnpoke
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Application Data
O43 - CFD: 24/07/2014 - 02:31:27 - [] ----D C:\ProgramData\Astroburn Lite
O43 - CFD: 15/12/2014 - 19:52:31 - [] ----D C:\ProgramData\Avira
O43 - CFD: 20/04/2015 - 15:29:05 - [] ----D C:\ProgramData\boost_interprocess
O43 - CFD: 15/07/2014 - 04:36:26 - [] -SH-D C:\ProgramData\Bureau
O43 - CFD: 03/05/2015 - 19:18:48 - [] ----D C:\ProgramData\cfda197ad4914fd0ab4eae97a56d3e83
O43 - CFD: 25/07/2014 - 01:14:29 - [] ----D C:\ProgramData\DAEMON Tools Lite =>.DT Soft Ltd
O43 - CFD: 26/07/2014 - 03:24:00 - [] ----D C:\ProgramData\DAEMON Tools Ultra
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Desktop
O43 - CFD: 04/12/2014 - 18:41:07 - [] ----D C:\ProgramData\DivX
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Documents
O43 - CFD: 20/04/2015 - 18:33:53 - [0] ----D C:\ProgramData\DSearchLink =>Toolbar.DeltaSearch
O43 - CFD: 15/07/2014 - 04:36:26 - [] -SH-D C:\ProgramData\Favoris
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Favorites
O43 - CFD: 03/05/2015 - 19:18:56 - [] ----D C:\ProgramData\FlashBeat =>PUP.FlashBeat
O43 - CFD: 03/05/2015 - 19:18:23 - [] --H-D C:\ProgramData\haw
O43 - CFD: 24/02/2015 - 16:00:14 - [] ----D C:\ProgramData\hbenmebmconejhmdifgkgmlhohkcjidb
O43 - CFD: 20/04/2015 - 18:33:56 - [0] ----D C:\ProgramData\IePluginServices =>PUP.IePluginService
O43 - CFD: 24/02/2015 - 16:10:35 - [] ----D C:\ProgramData\jkcfpoknbcjdpailgciampmhljkepapp
O43 - CFD: 18/04/2015 - 16:23:18 - [] ----D C:\ProgramData\Just sing
O43 - CFD: 20/04/2015 - 18:33:53 - [0] ----D C:\ProgramData\LolliScan =>Adware.Graftor
O43 - CFD: 30/09/2014 - 13:23:10 - [] ----D C:\ProgramData\McAfee
O43 - CFD: 01/10/2014 - 13:27:58 - [] ----D C:\ProgramData\McAfee Security Scan
O43 - CFD: 15/07/2014 - 04:36:26 - [] -SH-D C:\ProgramData\Menu Démarrer
O43 - CFD: 22/04/2015 - 13:09:48 - [] -S--D C:\ProgramData\Microsoft
O43 - CFD: 22/04/2015 - 12:44:19 - [] ----D C:\ProgramData\Microsoft Help
O43 - CFD: 15/07/2014 - 04:36:26 - [] -SH-D C:\ProgramData\Modèles
O43 - CFD: 26/09/2014 - 16:01:20 - [] ----D C:\ProgramData\Mozilla
O43 - CFD: 16/04/2015 - 18:15:23 - [] ----D C:\ProgramData\NetEngine =>PUP.NetEngine
O43 - CFD: 15/12/2014 - 19:52:34 - [] ----D C:\ProgramData\Package Cache
O43 - CFD: 23/09/2014 - 22:57:47 - [] ----D C:\ProgramData\Real
O43 - CFD: 20/04/2015 - 18:33:56 - [0] ----D C:\ProgramData\Reimage Express =>Rogue.ReimageRepair
O43 - CFD: 20/04/2015 - 18:33:56 - [0] ----D C:\ProgramData\Reimage Protector =>Rogue.ReimageRepair
O43 - CFD: 20/04/2015 - 18:33:54 - [0] ----D C:\ProgramData\ShopperPro =>PUP.ShopperPro
O43 - CFD: 02/04/2015 - 19:01:42 - [] ----D C:\ProgramData\Siemens
O43 - CFD: 22/07/2014 - 11:40:34 - [] ----D C:\ProgramData\Smart Soft
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Start Menu
O43 - CFD: 29/09/2014 - 13:04:45 - [] ----D C:\ProgramData\Studio-Scrap6
O43 - CFD: 20/04/2015 - 18:33:55 - [0] ----D C:\ProgramData\systemk =>PUP.SystemK
O43 - CFD: 13/04/2015 - 13:46:26 - [0] ----D C:\ProgramData\T122078ED
O43 - CFD: 28/09/2014 - 11:05:19 - [0] ---AD C:\ProgramData\TEMP
O43 - CFD: 14/07/2009 - 06:53:55 - [] -SH-D C:\ProgramData\Templates
O43 - CFD: 20/04/2015 - 18:33:56 - [0] ----D C:\ProgramData\Uniblue =>PUP.UniblueSystem
O43 - CFD: 20/04/2015 - 18:33:56 - [0] ----D C:\ProgramData\WindowsMangerProtect =>PUP.Fuyu
O43 - CFD: 20/04/2015 - 18:33:56 - [0] ----D C:\ProgramData\Yellow AdBlocker =>PUP.Adblocker
O43 - CFD: 20/04/2015 - 18:33:56 - [0] ----D C:\ProgramData\YTAHelper =>PUP.Goobzo
O43 - CFD: 12/04/2015 - 16:29:57 - [] ----D C:\ProgramData\{373a3fdc-2f80-12c9-373a-a3fdc2f8ff70}
O43 - CFD: 12/04/2015 - 22:24:58 - [] ----D C:\ProgramData\{57499cb8-3f5e-5d4b-5749-99cb83f572e0}
O43 - CFD: 24/02/2015 - 15:59:03 - [] ----D C:\ProgramData\{8f0c8408-c058-2232-8f0c-c8408c051023}
O43 - CFD: 22/04/2015 - 13:16:30 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 22/07/2014 - 11:17:58 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 28/09/2014 - 14:36:24 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Affiche Facile - Studio-Scrap'
O43 - CFD: 24/07/2014 - 02:31:29 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Astroburn Lite
O43 - CFD: 24/02/2015 - 15:52:00 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
O43 - CFD: 04/12/2014 - 18:36:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DirectVobSub
O43 - CFD: 04/12/2014 - 18:40:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
O43 - CFD: 20/04/2015 - 18:33:59 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileOpener =>Adware.InstallCore
O43 - CFD: 12/04/2011 - 03:45:19 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 26/09/2014 - 19:29:23 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 04/12/2014 - 18:36:54 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
O43 - CFD: 18/04/2015 - 16:15:35 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Just sing
O43 - CFD: 08/01/2015 - 16:59:11 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.3
O43 - CFD: 14/07/2009 - 06:42:30 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 01/10/2014 - 13:28:01 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
O43 - CFD: 18/07/2014 - 00:01:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O43 - CFD: 25/02/2015 - 00:23:44 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
O43 - CFD: 02/04/2015 - 19:29:14 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SOAP Toolkit Version 3
O43 - CFD: 22/04/2015 - 23:39:18 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008
O43 - CFD: 25/02/2015 - 00:43:34 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual C++ 2008 Express Edition
O43 - CFD: 18/07/2014 - 00:01:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
O43 - CFD: 20/04/2015 - 18:33:59 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MYBESTOFFERSTODAY =>PUP.MyBestOffersToday
O43 - CFD: 25/03/2015 - 22:26:57 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
O43 - CFD: 20/04/2015 - 18:33:59 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip =>PUP.PepperZip
O43 - CFD: 31/10/2014 - 12:17:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSIM 9.0.3 (softkey time-limited)
O43 - CFD: 31/10/2014 - 23:01:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSIM 9.1.1 Demo Version
O43 - CFD: 18/07/2014 - 00:01:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
O43 - CFD: 20/04/2015 - 18:33:59 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Express =>Rogue.ReimageRepair
O43 - CFD: 28/09/2014 - 15:17:32 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RonyaSoft
O43 - CFD: 02/04/2015 - 20:23:05 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Siemens Automation
O43 - CFD: 14/04/2015 - 14:54:00 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 28/09/2014 - 23:29:58 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Studio-Scrap
O43 - CFD: 12/04/2011 - 03:44:56 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 18/07/2014 - 00:01:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
O43 - CFD: 18/07/2014 - 00:01:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
O43 - CFD: 18/07/2014 - 00:01:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 17/12/2014 - 13:50:40 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper
O43 - CFD: 04/12/2014 - 18:37:01 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
O43 - CFD: 28/09/2014 - 23:28:56 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
O43 - CFD: 04/05/2015 - 15:13:27 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP =>.Nicolas Coolman
O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\1H1Q1V1N1N1O1R =>Adware.InstallCore
O43 - CFD: 22/04/2015 - 17:22:44 - [] ----D C:\Users\admin\AppData\Roaming\Adobe
O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\Astromenda =>PUP.Astromenda
O43 - CFD: 16/07/2014 - 13:28:32 - [] ----D C:\Users\admin\AppData\Roaming\Avira
O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\Binkiland =>PUP.Binkiland
O43 - CFD: 07/09/2014 - 16:09:14 - [0] ----D C:\Users\admin\AppData\Roaming\BRT
O43 - CFD: 04/12/2014 - 18:36:47 - [] ----D C:\Users\admin\AppData\Roaming\CDXReader
O43 - CFD: 24/02/2015 - 17:37:37 - [] ----D C:\Users\admin\AppData\Roaming\DAEMON Tools Lite =>.DT Soft Ltd
O43 - CFD: 26/07/2014 - 03:21:27 - [] ----D C:\Users\admin\AppData\Roaming\DAEMON Tools Ultra
O43 - CFD: 13/10/2014 - 19:35:57 - [] ----D C:\Users\admin\AppData\Roaming\Dev-Cpp
O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\DigitalSites =>Hijacker.DSite
O43 - CFD: 04/12/2014 - 18:40:45 - [] ----D C:\Users\admin\AppData\Roaming\DivX
O43 - CFD: 04/05/2015 - 14:37:31 - [] ----D C:\Users\admin\AppData\Roaming\Dropbox
O43 - CFD: 12/02/2015 - 23:04:59 - [] ----D C:\Users\admin\AppData\Roaming\dvdcss
O43 - CFD: 26/02/2015 - 20:39:20 - [0] ----D C:\Users\admin\AppData\Roaming\eCyber =>PUP.Elex
O43 - CFD: 29/10/2014 - 01:13:57 - [0] ----D C:\Users\admin\AppData\Roaming\EurekaLog
O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\Free PDF to Word Converter =>PUP.PDFtoWordConverter
O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\Gameo =>PUP.Gameo
O43 - CFD: 18/07/2014 - 00:45:04 - [] ----D C:\Users\admin\AppData\Roaming\GoforFiles =>P2P.GoforFiles
O43 - CFD: 17/09/2014 - 13:21:55 - [] --H-D C:\Users\admin\AppData\Roaming\GoldenGate
O43 - CFD: 15/07/2014 - 04:36:48 - [] ----D C:\Users\admin\AppData\Roaming\Identities
O43 - CFD: 04/12/2014 - 18:36:48 - [] ----D C:\Users\admin\AppData\Roaming\LavFilters
O43 - CFD: 08/01/2015 - 17:03:20 - [] ----D C:\Users\admin\AppData\Roaming\LibreOffice
O43 - CFD: 19/10/2014 - 22:38:05 - [] ----D C:\Users\admin\AppData\Roaming\LockAP
O43 - CFD: 18/07/2014 - 00:13:46 - [] ----D C:\Users\admin\AppData\Roaming\Macromedia
O43 - CFD: 07/02/2015 - 18:23:06 - [] ----D C:\Users\admin\AppData\Roaming\MathWorks
O43 - CFD: 12/04/2011 - 03:44:56 - [0] ----D C:\Users\admin\AppData\Roaming\Media Center Programs
O43 - CFD: 19/04/2015 - 21:07:52 - [] -S--D C:\Users\admin\AppData\Roaming\Microsoft
O43 - CFD: 15/07/2014 - 14:55:32 - [] ----D C:\Users\admin\AppData\Roaming\Mozilla
O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\OpenCandy =>Adware.OpenCandy
O43 - CFD: 31/01/2015 - 17:56:25 - [] ----D C:\Users\admin\AppData\Roaming\Opera Software
O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\PriceFountain =>PUP.PriceFountain
O43 - CFD: 14/04/2015 - 14:53:17 - [0] ----D C:\Users\admin\AppData\Roaming\Probit Software =>PUP.ProbitSoftware
O43 - CFD: 27/01/2015 - 21:01:43 - [] ----D C:\Users\admin\AppData\Roaming\QuickScan
O43 - CFD: 12/04/2015 - 22:11:15 - [] ----D C:\Users\admin\AppData\Roaming\Rainmaker Software Group LLC.​
O43 - CFD: 23/09/2014 - 22:57:41 - [] ----D C:\Users\admin\AppData\Roaming\Real
O43 - CFD: 02/04/2015 - 21:15:45 - [] ----D C:\Users\admin\AppData\Roaming\Siemens
O43 - CFD: 28/10/2014 - 13:37:33 - [] ----D C:\Users\admin\AppData\Roaming\Studio-Scrap6
O43 - CFD: 08/02/2015 - 18:08:15 - [] ----D C:\Users\admin\AppData\Roaming\Subversion
O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\sweet-page =>PUP.SweetPage
O43 - CFD: 21/12/2014 - 13:11:10 - [0] ----D C:\Users\admin\AppData\Roaming\Systweak
O43 - CFD: 28/03/2015 - 21:04:54 - [] ----D C:\Users\admin\AppData\Roaming\TeamViewer
O43 - CFD: 03/10/2014 - 21:52:54 - [0] ----D C:\Users\admin\AppData\Roaming\uTorrent =>P2P.µTorrent
O43 - CFD: 04/05/2015 - 14:38:08 - [] ----D C:\Users\admin\AppData\Roaming\ViberPC
O43 - CFD: 25/04/2015 - 00:51:02 - [] ----D C:\Users\admin\AppData\Roaming\vlc
O43 - CFD: 20/04/2015 - 18:34:05 - [0] ----D C:\Users\admin\AppData\Roaming\VOPackage =>Adware.Downware
O43 - CFD: 12/04/2015 - 21:52:55 - [0] ----D C:\Users\admin\AppData\Roaming\WebExtend
O43 - CFD: 15/07/2014 - 14:59:47 - [0] ----D C:\Users\admin\AppData\Roaming\WinRAR
O43 - CFD: 15/01/2015 - 15:58:40 - [] ----D C:\Users\admin\AppData\Roaming\WinZipper
O43 - CFD: 20/04/2015 - 18:34:06 - [0] ----D C:\Users\admin\AppData\Roaming\WSE_Astromenda =>PUP.Astromenda
O43 - CFD: 04/05/2015 - 15:28:59 - [] ----D C:\Users\admin\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 22/04/2015 - 11:55:37 - [] ----D C:\Users\admin\AppData\Local\Adobe
O43 - CFD: 15/07/2014 - 04:36:36 - [] -SH-D C:\Users\admin\AppData\Local\Application Data
O43 - CFD: 15/07/2014 - 21:25:42 - [] ----D C:\Users\admin\AppData\Local\Apps
O43 - CFD: 20/04/2015 - 18:34:23 - [0] ----D C:\Users\admin\AppData\Local\Binkiland =>PUP.Binkiland
O43 - CFD: 20/04/2015 - 18:34:29 - [0] ----D C:\Users\admin\AppData\Local\CleanerPro
O43 - CFD: 20/04/2015 - 18:34:29 - [0] ----D C:\Users\admin\AppData\Local\CrashRpt
O43 - CFD: 15/07/2014 - 21:25:51 - [0] ----D C:\Users\admin\AppData\Local\Deployment
O43 - CFD: 20/04/2015 - 00:46:27 - [] ----D C:\Users\admin\AppData\Local\Diagnostics
O43 - CFD: 26/07/2014 - 03:26:44 - [] ----D C:\Users\admin\AppData\Local\Disc_Soft_Ltd
O43 - CFD: 03/03/2015 - 18:32:04 - [0] ----D C:\Users\admin\AppData\Local\ElevatedDiagnostics
O43 - CFD: 26/02/2015 - 19:41:08 - [] -SH-D C:\Users\admin\AppData\Local\EmieBrowserModeList
O43 - CFD: 28/09/2014 - 16:15:18 - [] -SH-D C:\Users\admin\AppData\Local\EmieSiteList
O43 - CFD: 28/09/2014 - 16:15:18 - [] -SH-D C:\Users\admin\AppData\Local\EmieUserList
O43 - CFD: 14/10/2014 - 22:11:21 - [] ----D C:\Users\admin\AppData\Local\Facebook
O43 - CFD: 20/04/2015 - 18:34:31 - [0] ----D C:\Users\admin\AppData\Local\Gameo =>PUP.Gameo
O43 - CFD: 17/09/2014 - 13:26:43 - [] ----D C:\Users\admin\AppData\Local\Genesis_09171126 =>PUP.Genesis
O43 - CFD: 20/04/2015 - 18:34:31 - [0] ----D C:\Users\admin\AppData\Local\globalUpdate =>PUP.GlobalUpdate
O43 - CFD: 15/07/2014 - 21:27:17 - [] ----D C:\Users\admin\AppData\Local\Google
O43 - CFD: 15/07/2014 - 04:36:36 - [] -SH-D C:\Users\admin\AppData\Local\Historique
O43 - CFD: 24/07/2014 - 02:27:29 - [] ----D C:\Users\admin\AppData\Local\Installer
O43 - CFD: 20/04/2015 - 18:34:31 - [0] ----D C:\Users\admin\AppData\Local\LPT =>Adware.Incredibar
O43 - CFD: 30/09/2014 - 20:21:00 - [] ----D C:\Users\admin\AppData\Local\Macromedia
O43 - CFD: 24/07/2014 - 02:29:01 - [] ----D C:\Users\admin\AppData\Local\Math Problem Solver
O43 - CFD: 08/02/2015 - 18:08:06 - [] ----D C:\Users\admin\AppData\Local\MathWorks
O43 - CFD: 20/04/2015 - 18:34:31 - [0] ----D C:\Users\admin\AppData\Local\mbot_fr_588 =>PUP.CrossRider
O43 - CFD: 01/04/2015 - 21:37:58 - [] ----D C:\Users\admin\AppData\Local\Microsoft
O43 - CFD: 27/10/2014 - 21:09:40 - [] ----D C:\Users\admin\AppData\Local\Microsoft Help
O43 - CFD: 26/09/2014 - 16:05:39 - [] ----D C:\Users\admin\AppData\Local\Mozilla
O43 - CFD: 31/01/2015 - 17:56:27 - [] ----D C:\Users\admin\AppData\Local\Opera Software
O43 - CFD: 20/04/2015 - 18:34:31 - [0] ----D C:\Users\admin\AppData\Local\Pay-By-Ads =>PUP.PaybyAds
O43 - CFD: 20/04/2015 - 18:34:23 - [] ----D C:\Users\admin\AppData\Local\PriceFountain =>PUP.PriceFountain
O43 - CFD: 17/09/2014 - 12:36:06 - [] ----D C:\Users\admin\AppData\Local\Programs
O43 - CFD: 20/04/2015 - 18:34:33 - [0] ----D C:\Users\admin\AppData\Local\Pro_PC_Cleaner =>PUP.DoctorPC
O43 - CFD: 20/04/2015 - 18:34:33 - [0] ----D C:\Users\admin\AppData\Local\Rainmaker_Software_Group_ =>PUP.DoctorPC
O43 - CFD: 20/04/2015 - 18:34:37 - [0] ----D C:\Users\admin\AppData\Local\Smartbar =>Hijacker.SmartBar
O43 - CFD: 04/05/2015 - 15:28:03 - [] ----D C:\Users\admin\AppData\Local\Temp
O43 - CFD: 15/07/2014 - 04:36:36 - [] -SH-D C:\Users\admin\AppData\Local\Temporary Internet Files
O43 - CFD: 15/01/2015 - 16:29:43 - [] ----D C:\Users\admin\AppData\Local\Temp{10CAD5C0-3726-4AD8-BA9D-1FBDB609C95D}
O43 - CFD: 04/05/2015 - 14:36:07 - [] ----D C:\Users\admin\AppData\Local\Viber
O43 - CFD: 01/02/2015 - 17:09:53 - [] ----D C:\Users\admin\AppData\Local\VirtualStore
O43 - CFD: 20/04/2015 - 18:35:19 - [0] ----D C:\Users\admin\AppData\Local\Vosteran =>PUP.Vosteran
O43 - CFD: 25/04/2015 - 00:37:53 - [] R---D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
~ Program Folder: 285 Scanned in 00mn 04s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.808F751F57ABA097D09FA81E691C07FD] - 01/05/2015 - 20:57:15 ---A- . (...) -- C:\Windows\PFRO.log [336]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 01/05/2015 - 20:57:40 ---A- . (...) -- C:\Windows\setuperr.log [0]
O44 - LFC:[MD5.4A7E2593C05793A0DE079ECB0102ECAD] - 03/05/2015 - 21:15:52 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1856310]
O44 - LFC:[MD5.2A0B900EC7C3F769416A0B2D4D8C1438] - 03/05/2015 - 21:15:52 ---A- . (...) -- C:\Windows\System32\perfc009.dat [147598]
O44 - LFC:[MD5.71D953FF60C78D80CAB04D5A51D72A03] - 03/05/2015 - 21:15:52 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [175648]
O44 - LFC:[MD5.85E20D3A999B7E5A019BA822300A7D17] - 03/05/2015 - 21:15:52 ---A- . (...) -- C:\Windows\System32\perfh009.dat [720636]
O44 - LFC:[MD5.B6BFBFA7121A930416B7D7CD25AF96DC] - 03/05/2015 - 21:15:52 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [814066]
O44 - LFC:[MD5.34F6FA2008419BCE99E963C4EADAF860] - 04/05/2015 - 13:33:40 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.4F3BB5CA906CDFED4CBEE14065A561F2] - 04/05/2015 - 13:33:48 ---A- . (...) -- C:\Windows\setupact.log [336]
O44 - LFC:[MD5.17F09721B6C8F806DA7C71481A8DB349] - 04/05/2015 - 13:47:05 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1894881]
O44 - LFC:[MD5.3258E716FD25380083AB92B098ADFDAA] - 20/04/2015 - 15:19:05 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512]
O44 - LFC:[MD5.5D9A1A3E5824CECE65871C60E5A08A1A] - 22/04/2015 - 10:42:07 ---A- . (.Microsoft Corporation - WSMAN Automation.) -- C:\Windows\System32\WsmAuto.dll [145920]
O44 - LFC:[MD5.B975C202F590BBC5AA63225FBD148791] - 22/04/2015 - 10:42:07 ---A- . (.Microsoft Corporation - WSMan HTTP Configuration File.) -- C:\Windows\System32\WSManHTTPConfig.exe [198656]
O44 - LFC:[MD5.1DE9BD23AFA36150586C732D876D9B74] - 22/04/2015 - 10:42:08 ---A- . (.Microsoft Corporation - Service WSMan.) -- C:\Windows\System32\WsmSvc.dll [1177088]
O44 - LFC:[MD5.B6AC69FFBAA159DD5CEED814245A286D] - 22/04/2015 - 10:42:08 ---A- . (.Microsoft Corporation - WSMAN WMI Provider.) -- C:\Windows\System32\WsmWmiPl.dll [214016]
O44 - LFC:[MD5.2C28FEC61C4AC68480A99CB7AA197FA9] - 22/04/2015 - 10:42:08 ---A- . (.Microsoft Corporation - WinRM Migration Plugin.) -- C:\Windows\System32\WSManMigrationPlugin.dll [248832]
O44 - LFC:[MD5.AFA53BD631FB0509A91A99391209BB70] - 22/04/2015 - 10:46:30 ---A- . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Inter.) -- C:\Windows\System32\msieftp.dll [301568]
O44 - LFC:[MD5.7CC38741B8F68F1E0D5D79DA6123666A] - 22/04/2015 - 10:47:19 ---A- . (.Microsoft Corporation - Service de configuration automatique WWAN.) -- C:\Windows\System32\wwansvc.dll [185344]
O44 - LFC:[MD5.DA8AAF7E56F698608A89542131F74818] - 22/04/2015 - 10:47:19 ---A- . (.Microsoft Corporation - WWAN Device Interface Module.) -- C:\Windows\System32\wwanprotdim.dll [40960]
O44 - LFC:[MD5.5D1BFF0FCE80F9E2E539F436710D4A79] - 22/04/2015 - 10:53:14 ---A- . (.Microsoft Corporation - Preview Handler Surrogate Host.) -- C:\Windows\System32\prevhost.exe [31232]
O44 - LFC:[MD5.1153DE2E4F5941E10C399CB5592F78A1] - 22/04/2015 - 10:53:18 ---A- . (.Microsoft Corporation - Pilote de bus Bluetooth.) -- C:\Windows\System32\Drivers\bthport.sys [393728]
O44 - LFC:[MD5.79896A78039C9A63C56197843CFBAD0B] - 22/04/2015 - 10:53:19 ---A- . (.Microsoft Corporation - Direct3D 10 Rasterizer.) -- C:\Windows\System32\d3d10warp.dll [1987584]
O44 - LFC:[MD5.A208DAC2932649CFF82A6A684D8BB1F6] - 22/04/2015 - 10:53:22 ---A- . (.Microsoft Corporation - Pas de description.) -- C:\Windows\System32\oleaut32.dll [571904]
O44 - LFC:[MD5.7E9917D5309A90E7576653BFE39F80D8] - 22/04/2015 - 10:53:31 ---A- . (.Microsoft Corporation - Panneau de configuration Date/Heure.) -- C:\Windows\System32\timedate.cpl [478720]
O44 - LFC:[MD5.EDF2A5E96BEC469DA3F64E9BDD386111] - 22/04/2015 - 10:53:33 ---A- . (.Microsoft Corporation - Microsoft XmlLite Library.) -- C:\Windows\System32\xmllite.dll [180224]
O44 - LFC:[MD5.E2ED66FAF894F545EB083AC5F5763854] - 22/04/2015 - 10:53:39 ---A- . (.Microsoft Corporation - Nettoyage de la mise à jour.) -- C:\Windows\System32\scavengeui.dll [434688]
O44 - LFC:[MD5.786B9C958A4F217322C24C736263C51F] - 22/04/2015 - 10:53:47 ---A- . (.Microsoft Corporation - OXPS to XPS Converter.) -- C:\Windows\System32\OxpsConverter.exe [245760]
O44 - LFC:[MD5.DDCE686D76C2B4DB435A3AF5BD0E691D] - 22/04/2015 - 10:53:49 ---A- . (.Microsoft Corporation - ATAPI Driver Extension.) -- C:\Windows\System32\Drivers\ataport.sys [133056]
O44 - LFC:[MD5.75E8EBD7040CE238684333F97014762A] - 22/04/2015 - 10:53:52 ---A- . (.Microsoft Corporation - Fichier DLL du service DAV pour le Web.) -- C:\Windows\System32\WebClnt.dll [205824]
O44 - LFC:[MD5.EAF4712B706936C0B10D3B5319B37E81] - 22/04/2015 - 10:53:52 ---A- . (.Microsoft Corporation - Web DAV Client DLL.) -- C:\Windows\System32\davclnt.dll [81920]
O44 - LFC:[MD5.E306A24D9694C724FA2491278BF50FDB] - 22/04/2015 - 10:53:54 ---A- . (.Microsoft Corporation - BitLocker Drive Encryption Driver.) -- C:\Windows\System32\Drivers\fvevol.sys [196328]
O44 - LFC:[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - 22/04/2015 - 10:53:57 ---A- . (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\Drivers\tdx.sys [74752]
O44 - LFC:[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - 22/04/2015 - 10:53:59 ---A- . (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\Drivers\ntfs.sys [1212352]
O44 - LFC:[MD5.DDE994E9159497D0D5AB2CDF66D1EAD6] - 22/04/2015 - 10:54:01 ---A- . (.Microsoft Corporation - Infrastructure de diagnostics Windows.) -- C:\Windows\System32\wdi.dll [76800]
O44 - LFC:[MD5.1115D5A98043254A0E787F888FC273C0] - 22/04/2015 - 10:54:01 ---A- . (.Microsoft Corporation - Microsoft Performance PerfTrack.) -- C:\Windows\System32\perftrack.dll [635904]
O44 - LFC:[MD5.A580CFFC56EE72550B803AED2EFD5442] - 22/04/2015 - 10:54:01 ---A- . (.Microsoft Corporation - Microsoft Performance PowerTracker.) -- C:\Windows\System32\powertracker.dll [27136]
O44 - LFC:[MD5.33DB506498E0419CD50B144DE7CCFC75] - 22/04/2015 - 10:54:03 ---A- . (.Microsoft Corporation - Bashkir Keyboard Layout.) -- C:\Windows\System32\KBDBASH.DLL [6144]
O44 - LFC:[MD5.1235259E135F87BF4AE5864A818E1513] - 22/04/2015 - 10:54:03 ---A- . (.Microsoft Corporation - Russia(Typewriter) Keyboard Layout.) -- C:\Windows\System32\KBDRU1.DLL [6144]
O44 - LFC:[MD5.EB3D06A9EDFDFD12228AD7A9F24D15D6] - 22/04/2015 - 10:54:03 ---A- . (.Microsoft Corporation - Russian Keyboard Layout.) -- C:\Windows\System32\KBDRU.DLL [5632]
O44 - LFC:[MD5.40FFC65117C4AC69D33DEC6D567392FD] - 22/04/2015 - 10:54:03 ---A- . (.Microsoft Corporation - Sakha - Russia Keyboard Layout.) -- C:\Windows\System32\KBDYAK.DLL [6144]
O44 - LFC:[MD5.F1886C30C3E4A7C5513525CBA665AA31] - 22/04/2015 - 10:54:03 ---A- . (.Microsoft Corporation - Tatar (Legacy) Keyboard Layout.) -- C:\Windows\System32\KBDTAT.DLL [6144]
O44 - LFC:[MD5.06FC8A93A4FA1F42A3D1D06694F2B339] - 22/04/2015 - 10:54:05 ---A- . (...) -- C:\Windows\System32\locale.nls [419992]
O44 - LFC:[MD5.896850F7D6E6E95DC5BE0F192E05CD0E] - 22/04/2015 - 10:54:16 ---A- . (.Microsoft Corporation - Mise à jour des données de compatibilité de.) -- C:\Windows\System32\aepdu.dll [202752]
O44 - LFC:[MD5.EF63EDC07D444AC4B6E88CA6E2841737] - 22/04/2015 - 10:54:21 ---A- . (.Microsoft Corporation - Application Experience Program Cache.) -- C:\Windows\System32\aepic.dll [159744]
O44 - LFC:[MD5.E51E2C5EED4CE667D2CF06E56AC6FF1C] - 22/04/2015 - 10:54:21 ---A- . (.Microsoft Corporation - Application Experience Program Inventory Co.) -- C:\Windows\System32\aeinv.dll [896000]
O44 - LFC:[MD5.5F823C55FB9761F1236AF48DFF630353] - 22/04/2015 - 10:54:21 ---A- . (.Microsoft Corporation - Compatibility Appraiser.) -- C:\Windows\System32\appraiser.dll [860160]
O44 - LFC:[MD5.98F09936B1C397987268D6F2F3D869DB] - 22/04/2015 - 10:54:21 ---A- . (.Microsoft Corporation - Compatibility Upgrade Migration Host.) -- C:\Windows\System32\acmigration.dll [26112]
O44 - LFC:[MD5.90D6FA9DB9502FC992D260DE4CB944C7] - 22/04/2015 - 10:54:21 ---A- . (.Microsoft Corporation - Device Inventory Library.) -- C:\Windows\System32\devinv.dll [331264]
O44 - LFC:[MD5.87D7FF1217B32CD069DAF079686F43AE] - 22/04/2015 - 10:54:21 ---A- . (.Microsoft Corporation - Inventory Agent.) -- C:\Windows\System32\invagent.dll [630784]
O44 - LFC:[MD5.F57E1D225AE5C2C8F475A99BFDF018F4] - 22/04/2015 - 10:54:22 ---A- . (.Microsoft Corporation - Application Impact Telemetry Static Analyze.) -- C:\Windows\System32\aitstatic.exe [1167520]
O44 - LFC:[MD5.76F800C6046B439799C3A4120A0B398A] - 22/04/2015 - 10:54:22 ---A- . (.Microsoft Corporation - General Telemetry.) -- C:\Windows\System32\generaltel.dll [576000]
O44 - LFC:[MD5.EF71BA5DF59034962B0C62314A71351A] - 22/04/2015 - 10:54:40 ---A- . (.Microsoft Corporation - Client DHCPv6.) -- C:\Windows\System32\dhcpcore6.dll [193536]
O44 - LFC:[MD5.81F6C1AE23B1C493D9E996C3103915D7] - 22/04/2015 - 10:54:40 ---A- . (.Microsoft Corporation - Client DHCPv6.) -- C:\Windows\System32\dhcpcsvc6.dll [44032]
O44 - LFC:[MD5.5BDF8B0B9A3EADE3A2A6F2ED8D44E36D] - 22/04/2015 - 10:55:19 ---A- . (.Microsoft Corporation - Connecteur Microsoft Search pour Outlook.) -- C:\Windows\System32\mssphtb.dll [197120]
O44 - LFC:[MD5.A6CD6B3F71E13E2E45B727FB8A47EA87] - 22/04/2015 - 10:55:19 ---A- . (.Microsoft Corporation - Microsoft Windows Search Filter Host.) -- C:\Windows\System32\SearchFilterHost.exe [86528]
O44 - LFC:[MD5.2DC6285EC4F902BE08E7C5FA6D3FD017] - 22/04/2015 - 10:55:19 ---A- . (.Microsoft Corporation - msscntrs.dll.) -- C:\Windows\System32\msscntrs.dll [59392]
O44 - LFC:[MD5.DB67C7C62038BDE813CB6486581A7611] - 22/04/2015 - 10:55:20 ---A- . (.Microsoft Corporation - Microsoft Search Protocol Handler.) -- C:\Windows\System32\mssph.dll [337408]
O44 - LFC:[MD5.E1AC89F6C5252057E6062843E36A6701] - 22/04/2015 - 10:55:20 ---A- . (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) -- C:\Windows\System32\SearchProtocolHost.exe [164352]
O44 - LFC:[MD5.987323F0247D023AD1AE52195540ECE0] - 22/04/2015 - 10:55:20 ---A- . (.Microsoft Corporation - Plateforme de recherche Microsoft Vista.) -- C:\Windows\System32\mssvp.dll [666624]
O44 - LFC:[MD5.236F286E103FD44BD85FDD93097FD5DD] - 22/04/2015 - 10:55:21 ---A- . (.Microsoft Corporation - Indexeur Microsoft Windows Search.) -- C:\Windows\System32\SearchIndexer.exe [427520]
O44 - LFC:[MD5.465DBF63A5049E4DB4BC5C12FFE781CB] - 22/04/2015 - 10:55:21 ---A- . (.Microsoft Corporation - tquery.dll.) -- C:\Windows\System32\tquery.dll [1549312]
O44 - LFC:[MD5.0241CB16136B9A4939CA0395768AE286] - 22/04/2015 - 10:55:22 ---A- . (.Microsoft Corporation - mssrch.dll.) -- C:\Windows\System32\mssrch.dll [1401344]
O44 - LFC:[MD5.5FB4F271032B6435F3B2252F577A4815] - 22/04/2015 - 10:56:08 ---A- . (.Microsoft Corporation - Crash Dump Disk Driver.) -- C:\Windows\System32\Drivers\Diskdump.sys [27072]
O44 - LFC:[MD5.8229618C90801E957BADC332CE32A6C5] - 22/04/2015 - 10:56:08 ---A- . (.Microsoft Corporation - DLL de journalisation des E/S.) -- C:\Windows\System32\iologmsg.dll [2048]
O44 - LFC:[MD5.F1A449D762657230629D8BFC107ABC14] - 22/04/2015 - 10:56:08 ---A- . (.Microsoft Corporation - Microsoft Storage Port Driver.) -- C:\Windows\System32\Drivers\storport.sys [149440]
O44 - LFC:[MD5.EB34CE31FABD4DC4343FD2AD16D2CAF9] - 22/04/2015 - 10:56:09 ---A- . (.Microsoft Corporation - Microsoft iSCSI Initiator Driver.) -- C:\Windows\System32\Drivers\msiscsi.sys [234432]
O44 - LFC:[MD5.A8DDB7ACB122FC36FF0D7C9B3099A380] - 22/04/2015 - 10:57:00 ---A- . (.Microsoft Corporation - Composant Connexion RemoteApp et Bureau à d.) -- C:\Windows\System32\TSWorkspace.dll [793600]
O44 - LFC:[MD5.8C9C922D71F1CD4DEF73F186416B7896] - 22/04/2015 - 10:57:15 ---A- . (.Microsoft Corporation - Pilote NDIS 6.20.) -- C:\Windows\System32\Drivers\ndis.sys [712048]
O44 - LFC:[MD5.ED80D303102A746D30C1684B387BCBF1] - 22/04/2015 - 10:57:15 ---A- . (.Microsoft Corporation - Remote NDIS Miniport.) -- C:\Windows\System32\Drivers\RNDISMP.sys [33280]
O44 - LFC:[MD5.9158DBE2F8483434FC72F320690C9DB8] - 22/04/2015 - 10:57:26 ---A- . (.Microsoft Corporation - Windows Rights Management Services Server S.) -- C:\Windows\System32\secproc_ssp_isv.dll [87040]
O44 - LFC:[MD5.7FA485555BF802FE3DB5598004DBDFAC] - 22/04/2015 - 10:57:27 ---A- . (.Microsoft Corporation - Client Gestion des droits Windows.) -- C:\Windows\System32\msdrm.dll [390144]
O44 - LFC:[MD5.12A9F24DC9F465DA79AC2272D829A81E] - 22/04/2015 - 10:57:27 ---A- . (.Microsoft Corporation - Windows Rights Management Desktop Security.) -- C:\Windows\System32\secproc.dll [428032]
O44 - LFC:[MD5.BBCE3E9E74C7CEA47FA4115B360AC2C6] - 22/04/2015 - 10:57:27 ---A- . (.Microsoft Corporation - Windows Rights Management Desktop Security.) -- C:\Windows\System32\secproc_isv.dll [423936]
O44 - LFC:[MD5.58712A48D31B40EBCB35B47205F87771] - 22/04/2015 - 10:57:27 ---A- . (.Microsoft Corporation - Windows Rights Management Services Server S.) -- C:\Windows\System32\secproc_ssp.dll [87040]
O44 - LFC:[MD5.6142C5540C8D2764D59CBC11AF4A5900] - 22/04/2015 - 10:57:28 ---A- . (.Microsoft Corporation - Windows Rights Management Services Activati.) -- C:\Windows\System32\RMActivate.exe [572416]
O44 - LFC:[MD5.E01D2AC63453534DB8AD1EA97DEE9C3A] - 22/04/2015 - 10:57:28 ---A- . (.Microsoft Corporation - Windows Rights Management Services Activati.) -- C:\Windows\System32\RMActivate_isv.exe [594944]
O44 - LFC:[MD5.08D323750350A8A29611D1004C0CF319] - 22/04/2015 - 10:57:28 ---A- . (.Microsoft Corporation - Windows Rights Management Services Activati.) -- C:\Windows\System32\RMActivate_ssp.exe [510976]
O44 - LFC:[MD5.0F5FEF37588AF457E02125674F171A4F] - 22/04/2015 - 10:57:28 ---A- . (.Microsoft Corporation - Windows Rights Management Services Activati.) -- C:\Windows\System32\RMActivate_ssp_isv.exe [508928]
O44 - LFC:[MD5.F991AB9CC6B908DB552166768176896A] - 22/04/2015 - 10:58:06 ---A- . (.Microsoft Corporation - USB Mass Storage Class Driver.) -- C:\Windows\System32\Drivers\USBSTOR.SYS [76288]
O44 - LFC:[MD5.D320BF87125326F996D4904FE24300FC] - 22/04/2015 - 10:58:07 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [80256]
O44 - LFC:[MD5.46387FB17B086D16DEA267D5BE23A2F2] - 22/04/2015 - 10:58:07 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [22400]
O44 - LFC:[MD5.B3E25EE28883877076E0E1FF877D02E0] - 22/04/2015 - 10:58:07 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117120]
O44 - LFC:[MD5.4380E59A170D88C4F1022EFF6719A8A4] - 22/04/2015 - 10:58:07 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [143744]
O44 - LFC:[MD5.5CD5F9A5444E6CDCB0AC89BD62D8B76E] - 22/04/2015 - 10:58:08 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332160]
O44 - LFC:[MD5.5C3F9DBA818CD93379D1A0F215270374] - 22/04/2015 - 10:58:08 ---A- . (.Microsoft Corporation - Moteur de stockage extensible pour Microsof.) -- C:\Windows\System32\esent.dll [1699328]
O44 - LFC:[MD5.B4834F08230A2EB7F498DE4E5B6AB814] - 22/04/2015 - 10:58:08 ---A- . (.Microsoft Corporation - fsutil.exe.) -- C:\Windows\System32\fsutil.exe [74240]
O44 - LFC:[MD5.4BCC63ED1C3D15B2635A8AE2B854B3EB] - 22/04/2015 - 10:58:24 ---A- . (.Microsoft Corporation - Fournisseur d’informations d’identification.) -- C:\Windows\System32\SmartcardCredentialProvider.dll [152576]
O44 - LFC:[MD5.E9BB0CD09DA17C71FD1B9954D75AEEF7] - 22/04/2015 - 10:58:24 ---A- . (.Microsoft Corporation - Interface utilisateur du gestionnaire d’inf.) -- C:\Windows\System32\credui.dll [168960]
O44 - LFC:[MD5.9EA3783672D21817B9DF1061B54C3B3C] - 22/04/2015 - 10:58:28 ---A- . (.Microsoft Corporation - Table des caractères.) -- C:\Windows\System32\charmap.exe [155136]
O44 - LFC:[MD5.45FBAFFA68CBC29AC2563985CEE72B9C] - 22/04/2015 - 10:58:42 ---A- . (.Microsoft Corporation - Dialogues communs de certificats Microsoft.) -- C:\Windows\System32\cryptdlg.dll [24576]
O44 - LFC:[MD5.03F3B770DFBED6131653CEDA8CA780F0] - 22/04/2015 - 10:58:46 ---A- . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll [442880]
O44 - LFC:[MD5.7752619457598CF057C4CC02A0867029] - 22/04/2015 - 10:59:40 ---A- . (.Microsoft - Système de classement CERO.) -- C:\Windows\System32\cero.rs [55296]
O44 - LFC:[MD5.DDD1C4AB9A9DAE6D4092C4C95E714650] - 22/04/2015 - 10:59:40 ---A- . (.Microsoft - Système de classement ESRB.) -- C:\Windows\System32\esrb.rs [51712]
O44 - LFC:[MD5.CBC69A055EF410CBD65593E4808B6DB4] - 22/04/2015 - 10:59:40 ---A- . (.Microsoft - Système de classement OFLC.) -- C:\Windows\System32\oflc.rs [23552]
O44 - LFC:[MD5.72035C97983745E742D71E9A8EF70BBB] - 22/04/2015 - 10:59:40 ---A- . (.Microsoft - Système de classement PEGI en Finlande.) -- C:\Windows\System32\pegi-fi.rs [20480]
O44 - LFC:[MD5.43C9CF6825CEA58F1815B7C3DBBB385C] - 22/04/2015 - 10:59:41 ---A- . (.Microsoft Corporation - Bibliothèque des paramètres WPC.) -- C:\Windows\System32\Wpc.dll [308736]
O44 - LFC:[MD5.64E211E0FDFCE4D186DF58BB7D0503BC] - 22/04/2015 - 10:59:41 ---A- . (.Microsoft Corporation - Explorateur des jeux.) -- C:\Windows\System32\gameux.dll [2576384]
O44 - LFC:[MD5.A067A19A91C2AA0198F9BD01A5CEF5C6] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classement GRB.) -- C:\Windows\System32\grb.rs [21504]
O44 - LFC:[MD5.4F5C56DBF076D5BBB1D22B37BF281396] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classement PEGI au Portugal.) -- C:\Windows\System32\pegi-pt.rs [20480]
O44 - LFC:[MD5.5109C45498BC709C8A7E016D5FFCCAC2] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classement PEGI.) -- C:\Windows\System32\pegi.rs [20480]
O44 - LFC:[MD5.9B7D7F4D1F79E8B7D727BE94B1630D59] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classement PEGI/BBFC.) -- C:\Windows\System32\pegibbfc.rs [44544]
O44 - LFC:[MD5.9EDCFA23CC081E38C86CA309D0F7E3DC] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classement USK.) -- C:\Windows\System32\usk.rs [30720]
O44 - LFC:[MD5.41CE7975CAD7BCF92538D2C452239523] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classification COB-AU.) -- C:\Windows\System32\cob-au.rs [40960]
O44 - LFC:[MD5.27828AAA24AA46F11036954ADE355C1C] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classification DJCTQ.) -- C:\Windows\System32\djctq.rs [15360]
O44 - LFC:[MD5.A704E750245D5D4EE4A23E99A00F27D5] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de classification FPB.) -- C:\Windows\System32\fpb.rs [46592]
O44 - LFC:[MD5.6EC618588447B82EA8D88719EE46F725] - 22/04/2015 - 10:59:42 ---A- . (.Microsoft - Système de notation CSRR.) -- C:\Windows\System32\csrr.rs [43520]
O44 - LFC:[MD5.ED59143843560B5EDB543C2A48CB9E4B] - 22/04/2015 - 10:59:43 ---A- . (.Microsoft - Système de classification OFLC-NZ.) -- C:\Windows\System32\oflc-nz.rs [45568]
O44 - LFC:[MD5.50C73E54062BA252350F3F29580E28DA] - 22/04/2015 - 11:00:13 ---A- . (.Microsoft Corporation - Fichier DLL de ressources des fuseaux horai.) -- C:\Windows\System32\tzres.dll [2048]
O44 - LFC:[MD5.23FC8068953C9BE2D63AE4EF1129112A] - 22/04/2015 - 11:00:31 ---A- . (.Microsoft Corporation - Manipulateur d’événements réseau.) -- C:\Windows\System32\netevent.dll [18944]
O44 - LFC:[MD5.3EEBD3BD93DA46A26E89893C7AB2FF3B] - 22/04/2015 - 11:00:32 ---A- . (.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) -- C:\Windows\System32\Drivers\tcpipreg.sys [35328]
O44 - LFC:[MD5.5078492B9CAC9CB721698DB51F039035] - 22/04/2015 - 11:00:33 ---A- . (.Microsoft Corporation - Classes d’assistance pour les diagnostics p.) -- C:\Windows\System32\netcorehc.dll [175104]
O44 - LFC:[MD5.58F67245D041FBE7AF88F4EAF79DF0FA] - 22/04/2015 - 11:00:33 ---A- . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [499712]
O44 - LFC:[MD5.CB55B9AAB060C803BE4AD229AA0FEC28] - 22/04/2015 - 11:00:47 ---A- . (.Microsoft Corporation - Windows Installer.) -- C:\Windows\System32\msi.dll [2363904]
O44 - LFC:[MD5.AEBCEA8A46A42FCFE4EA92186745EE69] - 22/04/2015 - 11:29:30 ---A- . (.Microsoft Corporation - SQL Server Cluster Resource DLL.) -- C:\Windows\System32\SQSRVRES.DLL [89960]
O44 - LFC:[MD5.45676E87AD75D5E4B63C4D975E1184A7] - 22/04/2015 - 11:29:31 ---A- . (.Microsoft Corporation - SQL Server Performance Acquisition DLL.) -- C:\Windows\System32\perf-MSSQL$SQLEXPRESS-sqlctr10.3.5500.0.dll [73064]
O44 - LFC:[MD5.933222B19FF3E7EA5F65517EA1F7D57E] - 22/04/2015 - 11:33:13 ---A- . (...) -- C:\Windows\System32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf [3]
O44 - LFC:[MD5.A36F7A256E65D858A7039DB00ADEEBDD] - 22/04/2015 - 11:33:14 ---A- . (.Microsoft Corporation - WDF:UMDF Framework Library.) -- C:\Windows\System32\WUDFx.dll [613888]
O44 - LFC:[MD5.980B6A5F92B8DB235C4A26728C2BE732] - 22/04/2015 - 11:33:15 ---A- . (.Microsoft Corporation - Windows Driver Foundation - Processus hôte.) -- C:\Windows\System32\WUDFHost.exe [196608]
O44 - LFC:[MD5.D689B2C2E69156D954C24810F4081C1E] - 22/04/2015 - 11:33:19 ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Platf.) -- C:\Windows\System32\WUDFCoinstaller.dll [38912]
O44 - LFC:[MD5.D5CF1536137026ACDED95BF6CBF849F6] - 22/04/2015 - 11:33:21 ---A- . (.Microsoft Corporation - Windows Driver Foundation - Bibliothèque de.) -- C:\Windows\System32\WUDFPlatform.dll [172032]
O44 - LFC:[MD5.FE47B7BC8EA320C2D9B5E5BF6E303765] - 22/04/2015 - 11:33:21 ---A- . (.Microsoft Corporation - Windows Driver Foundation - Service d’infra.) -- C:\Windows\System32\WUDFSvc.dll [73216]
O44 - LFC:[MD5.06E6F32C8D0A3F66D956F57B43A2E070] - 22/04/2015 - 11:33:23 ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\Drivers\WUDFPf.sys [66560]
O44 - LFC:[MD5.867C301E8B790040AE9CF6486E8041DF] - 22/04/2015 - 11:33:25 ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\Drivers\WUDFRd.sys [155136]
O44 - LFC:[MD5.2413D2216D08FAF7D7178D9E0B481AEB] - 22/04/2015 - 11:42:42 ---A- . (.Microsoft Corporation - Microsoft DTV-DVD Video Decoder.) -- C:\Windows\System32\msmpeg2vdec.dll [2285056]
O44 - LFC:[MD5.4676AAA9DDF52A50C829FEDB4EA81E54] - 22/04/2015 - 11:45:23 ---A- . (.Microsoft Corporation - Connexion Bureau à distance.) -- C:\Windows\System32\mstsc.exe [1068544]
O44 - LFC:[MD5.0FC6922517964E9D90DE84DC86F63E40] - 22/04/2015 - 11:45:24 ---A- . (.Microsoft Corporation - Runtime de connexion RemoteApp et Bureau à.) -- C:\Windows\System32\wksprt.exe [350208]
O44 - LFC:[MD5.5E676B296B762E211D83B87635F2C330] - 22/04/2015 - 11:45:25 ---A- . (.Microsoft Corporation - Remote Desktop Services Client for Microsof.) -- C:\Windows\System32\rdvidcrl.dll [855552]
O44 - LFC:[MD5.8DEEE20D8D30E9B0FBDCA31E58A027BD] - 22/04/2015 - 11:45:27 ---A- . (.Microsoft Corporation - Client de contrainte de quarantaine de la p.) -- C:\Windows\System32\tsgqec.dll [53248]
O44 - LFC:[MD5.2EFB1279E7BEA7D12D9F4D6508D27880] - 22/04/2015 - 11:45:27 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Acces.) -- C:\Windows\System32\MsRdpWebAccess.dll [50176]
O44 - LFC:[MD5.AB5EFB103DB01C1912C9D2F545EA5621] - 22/04/2015 - 11:45:30 ---A- . (.Microsoft Corporation - WorkspaceRuntime ProxyStub DLL.) -- C:\Windows\System32\wksprtPS.dll [17920]
O44 - LFC:[MD5.A90F47CDCC0898733596B5070039FC15] - 22/04/2015 - 11:45:31 ---A- . (.Microsoft Corporation - Extension de stratégie de groupe pour la re.) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll [14336]
O44 - LFC:[MD5.C6A5FBD4977305E1FA23E02C042DB463] - 22/04/2015 - 11:45:34 ---A- . (.Microsoft Corporation - Pilote de filtre pour concentrateur USB du.) -- C:\Windows\System32\Drivers\TsUsbFlt.sys [49152]
O44 - LFC:[MD5.D60E27D4BD5A91FCD17D2CB27F86738E] - 22/04/2015 - 11:45:36 ---A- . (.Microsoft Corporation - Remote Desktop USB Redirection GP Extension.) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe [12800]
O44 - LFC:[MD5.F37167FCDB661FD4B54CAD4755ABDD61] - 22/04/2015 - 11:45:39 ---A- . (.Microsoft Corporation - Co-installateur de pilote USB générique du.) -- C:\Windows\System32\TsUsbGDCoInstaller.dll [32256]
O44 - LFC:[MD5.8999F18D38D55E34D356796507FFD639] - 22/04/2015 - 11:49:10 ---A- . (.Microsoft Corporation - Point de terminaison audio RDP.) -- C:\Windows\System32\rdpendp_winip.dll [192000]
O44 - LFC:[MD5.65375DF758CA1872AB7EBBBA457FD5E6] - 22/04/2015 - 11:49:18 ---A- . (.Microsoft Corporation - Microsoft RDP Video Miniport driver.) -- C:\Windows\System32\Drivers\rdpvideominiport.sys [14848]
O44 - LFC:[MD5.63F066C8F1C666EC5B65DCF4B1B29C2F] - 22/04/2015 - 12:15:05 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [587896]
O44 - LFC:[MD5.3597DE1371DF9DDC15001778EBA54EAF] - 23/04/2015 - 10:19:40 ---A- . (.Microsoft Corporation - Client ActiveX des services Bureau à distan.) -- C:\Windows\System32\mstscax.dll [5702656]
O44 - LFC:[MD5.E284CFD490A1F2E03A8BE0B4C09A3DEE] - 24/04/2015 - 09:54:45 ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Proxy.) -- C:\Windows\System32\TSWbPrxy.exe [74240]
O44 - LFC:[MD5.6BF8843C99352B8A600794DE740C2566] - 24/04/2015 - 09:54:47 ---A- . (.Microsoft Corporation - DLL RDPCore TS.) -- C:\Windows\System32\rdpcorets.dll [2744320]
O44 - LFC:[MD5.06E6DEABDA3A27DDA054BE46207420E4] - 24/04/2015 - 09:54:47 ---A- . (.Microsoft Corporation - Remote Desktop Protocol Group Policy Extens.) -- C:\Windows\System32\RdpGroupPolicyExtension.dll [13824]
O44 - LFC:[MD5.1B430766C544BEF1D8BE2305FF7F8D9C] - 24/04/2015 - 09:54:47 ---A- . (.Microsoft Corporation - UMRDP Display Driver.) -- C:\Windows\System32\rdpudd.dll [221184]
~ Files: 142 Scanned in 01mn 00s



---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.B5AB6E0E90E561606FDEB9C09A15AF0F] - 14/04/2015 - 14:00:53 ---A- - C:\Windows\Prefetch\BACKUPSTACK.EXE-97682A25.pf =>PUP.MyPCBackup
O45 - LFCP:[MD5.0689AFF9A05CF76CD6B1652F710FF040] - 13/04/2015 - 20:23:59 ---A- - C:\Windows\Prefetch\MYPC BACKUP.EXE-2654E8AC.pf =>PUP.MyPCBackup
O45 - LFCP:[MD5.EA71600DB769E747E7152BFE5FBFB94F] - 14/04/2015 - 18:34:16 ---A- - C:\Windows\Prefetch\SUMMER_GAMES_UPDATING_SERVICE-E74068F4.pf =>PUP.CrossRider
O45 - LFCP:[MD5.0989F3F4F81DA9B74A85DCFC29B0BF3F] - 12/04/2015 - 20:49:29 ---A- - C:\Windows\Prefetch\UNICOBROWSER.EXE-51800076.pf =>PUP.UnicoBrowser
O45 - LFCP:[MD5.AA03FCFF17026D1E08A3B77F492A56DD] - 12/04/2015 - 20:52:38 ---A- - C:\Windows\Prefetch\WEBPROTECTPD.EXE-E1146886.pf =>PUP.WebProtect
~ Prefetcher: 5 Scanned in 00mn 01s



---\\ Déni du service (Local Security Authority) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll
~ LSA: 8 Scanned in 00mn 00s



---\\ Contrôle du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
~ CSB: 13 Scanned in 00mn 00s



---\\ Image File Execution Options (IFEO) (O50)
O50 - IFEO:Image File Execution Options - volaro - tasklist.exe =>Trojan.Vonteera
~ IFEO: Scanned in 00mn 00s



---\\ Clé de registre Shell MountPoints2 (MPSK) (O51)
O51 - MPSK:{30b561e4-13e1-11e4-b9eb-e02a827f9d3d}\AutoRun\command. (...) -- I:\setup.exe (.not file.)
O51 - MPSK:{354c80cf-1321-11e4-865c-e02a827f9d3d}\AutoRun\command. (...) -- H:\setup.exe (.not file.)
O51 - MPSK:{414d0c75-1180-11e4-9c63-64315080d8de}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.)
O51 - MPSK:{414d0c7c-1180-11e4-9c63-64315080d8de}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{8a8d608d-2647-11e4-a7f1-e02a827f9d3d}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{8a8d60e2-2647-11e4-a7f1-e02a827f9d3d}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{ae767fc1-1b3a-11e4-b0f0-e02a827f9d3d}\AutoRun\command. (...) -- J:\setup.exe (.not file.)
O51 - MPSK:{b23062ea-50a9-11e4-8acd-e02a827f9d3d}\AutoRun\command. (...) -- H:\setup.exe (.not file.)
O51 - MPSK:{e2cf9a3e-13da-11e4-800b-806e6f6e6963}\AutoRun\command. (...) -- F:\setup.exe (.not file.)
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="l3codecp.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Audio Layer-3 Codec for MSACM.) -- C:\Windows\System32\l3codecp.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll
O52 - TDSD: \Drivers32\"VIDC.LAGS"="lagarith.dll" . (.Pas de propriétaire - Lagarith.) -- C:\Windows\System32\lagarith.dll
O52 - TDSD: \Drivers32\"vidc.XVID"="xvidvfw.dll" . (...) -- C:\Windows\System32\xvidvfw.dll
O52 - TDSD: \drivers.desc\"lagarith.dll"="Lagarith lossless codec [LAGS]" . (.Pas de propriétaire - Lagarith.) -- C:\Windows\System32\lagarith.dll
O52 - TDSD: \drivers.desc\"xvidvfw.dll"="Xvid MPEG-4 Video Codec" . (...) -- C:\Windows\System32\xvidvfw.dll
O52 - TDSD: \drivers.desc\"l3codecp.acm"="Fraunhofer IIS MPEG Layer-3 Codec (professional)" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Audio Layer-3 Codec for MSACM.) -- C:\Windows\System32\l3codecp.acm
~ TDSD: 7 Scanned in 00mn 01s



---\\ Enumération des clés de registre SecurityProviders (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
~ MSCP: 2 Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Scanned in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976]
O58 - SDL:14/07/2009 - 02:26:17 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [297552]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\Drivers\adpu320.sys [146512]
O58 - SDL:26/01/2010 - 16:38:06 ---A- . (.LSI Corporation - SoftModem Device Driver.) -- C:\Windows\System32\Drivers\AGRSM.sys [1163328]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [14400]
O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [80256]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows fa.) -- C:\Windows\System32\Drivers\amdsbs.sys [159312]
O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [22400]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [76368]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [86608]
O58 - SDL:13/07/2009 - 23:02:49 ---A- . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gigabit Ethernet..) -- C:\Windows\System32\Drivers\b57nd60x.sys [229888]
O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [13568]
O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [5248]
O58 - SDL:14/07/2009 - 01:57:25 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [272128]
O58 - SDL:13/07/2009 - 23:53:32 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [62336]
O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [12160]
O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [11904]
O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbdx.sys [430080]
O58 - SDL:14/07/2009 - 02:26:21 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [15952]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\Drivers\djsvs.sys [70720]
O58 - SDL:10/04/2013 - 08:15:46 ---A- . (.Siemens AG - DPM Kernel Mode Driver.) -- C:\Windows\System32\Drivers\dpmconv32.sys [291328]
O58 - SDL:10/09/2014 - 11:53:14 ---A- . (.360.cn - dsark.sys.) -- C:\Windows\System32\Drivers\DsArk.sys [84040]
O58 - SDL:04/03/2013 - 10:25:00 ---A- . (.Elaborate Bytes AG - ElbyCD Windows NT/2000/XP I/O driver.) -- C:\Windows\System32\Drivers\ElbyCDIO.sys [30616]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712]
O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbdx.sys [3100160]
O58 - SDL:09/08/2007 - 04:06:40 ---A- . (.Huawei Tech. Co., Ltd. - HUAWEI USB Smart Card Driver.) -- C:\Windows\System32\Drivers\ewdcsc.sys [23424]
O58 - SDL:12/10/2009 - 15:22:56 ---A- . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\Windows\System32\Drivers\ewusbdev.sys [101120]
O58 - SDL:07/12/2009 - 19:53:18 ---A- . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\Windows\System32\Drivers\ewusbmdm.sys [103168]
O58 - SDL:07/12/2009 - 19:36:48 ---A- . (.Huawei Technologies Co., Ltd. - USB NDIS Miniport Driver.) -- C:\Windows\System32\Drivers\ewusbnet.sys [201168]
O58 - SDL:13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [67152]
O58 - SDL:11/03/2011 - 06:38:51 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332160]
O58 - SDL:11/02/2011 - 18:12:16 ---A- . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\Drivers\igdkmd32.sys [9036800]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [41040]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [95824]
O58 - SDL:14/07/2009 - 02:20:37 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [89168]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [54864]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [96848]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7 for x86.) -- C:\Windows\System32\Drivers\megasas.sys [30800]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [235584]
O58 - SDL:06/12/2012 - 08:42:10 ---A- . (.Ralink Technology, Corp. - Ralink 802.11 Wireless Adapter Driver.) -- C:\Windows\System32\Drivers\netr28.sys [2046560]
O58 - SDL:14/07/2009 - 02:20:44 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [44624]
O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117120]
O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [143744]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1383488]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [106064]
O58 - SDL:10/06/2011 - 05:34:52 ---A- . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.20 32-bit Driver.) -- C:\Windows\System32\Drivers\Rt86win7.sys [394856]
O58 - SDL:24/07/2012 - 11:25:34 ---A- . (.SIEMENS AG - Knotentaufe Kernel Mode Driver.) -- C:\Windows\System32\Drivers\S7odpx2x32.sys [87552]
O58 - SDL:03/12/2013 - 11:46:58 ---A- . (.Siemens AG - MPI-Transport Kernel Mode Driver.) -- C:\Windows\System32\Drivers\S7otranx32.sys [521216]
O58 - SDL:24/07/2012 - 11:25:58 ---A- . (.SIEMENS AG - TS Adapter RS232-32 Device Driver.) -- C:\Windows\System32\Drivers\s7otsadx32.sys [194560]
O58 - SDL:17/12/2013 - 09:00:00 ---A- . (.Siemens AG - S7DOS USB Kernel Mode WDM Driver.) -- C:\Windows\System32\Drivers\s7ousbu32x.sys [123904]
O58 - SDL:09/05/2012 - 09:22:26 ---A- . (.SIEMENS AG - SIEMENS RT-Protocol V2.0 (ether-type 0x8892).) -- C:\Windows\System32\Drivers\s7sn2srtx.sys [69848]
O58 - SDL:13/07/2009 - 21:50:20 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [20480]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [40016]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [77888]
O58 - SDL:28/10/2013 - 14:38:14 ---A- . (.Siemens AG - SOFTNET IE ISO Protocol Driver (x86).) -- C:\Windows\System32\Drivers\SNTIE.SYS [276192]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072]
O58 - SDL:04/06/2010 - 01:18:58 ---A- . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\Windows\System32\Drivers\SynTP.sys [1303728]
O58 - SDL:16/03/2015 - 18:44:30 ---A- . (.Oracle Corporation - VirtualBox Support Driver.) -- C:\Windows\System32\Drivers\VBoxDrv.sys [749664]
O58 - SDL:16/03/2015 - 18:42:58 ---A- . (.Oracle Corporation - VirtualBox Host-Only Network Adapter Driver.) -- C:\Windows\System32\Drivers\VBoxNetAdp.sys [115672]
O58 - SDL:16/03/2015 - 18:42:58 ---A- . (.Oracle Corporation - VirtualBox Bridged Networking Driver.) -- C:\Windows\System32\Drivers\VBoxNetFlt.sys [127008]
O58 - SDL:16/03/2015 - 18:42:58 ---A- . (.Oracle Corporation - VirtualBox USB Monitor Driver.) -- C:\Windows\System32\Drivers\VBoxUSBMon.sys [104384]
O58 - SDL:24/07/2013 - 16:03:04 ---A- . (.Elaborate Bytes AG - Virtual CloneDrive storage miniport.) -- C:\Windows\System32\Drivers\VClone.sys [29696]
O58 - SDL:14/07/2009 - 02:19:10 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [16976]
O58 - SDL:14/07/2009 - 02:19:11 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [141904]
O58 - SDL:07/08/2013 - 10:26:12 ---A- . (.SIEMENS AG - FDLAda Kernel Mode Driver (x86).) -- C:\Windows\System32\Drivers\vsnl2ada32.sys [109056]
O58 - SDL:06/08/2014 - 16:29:08 ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}w.sys [52880] =>PUP.LinkiDoo
O58 - SDL:13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672]
~ Drivers: 82 Scanned in 00mn 31s



---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 03/05/2015 - 15:31:27 ---A- . (...) -- C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\UserCache.bin [111540]
O61 - LFC: 03/05/2015 - 15:33:01 ---A- . (...) -- C:\Users\admin\AppData\Local\Temp\OnlineBackup.exe [1120135]
O61 - LFC: 04/05/2015 - 15:32:53 ---A- . (...) -- C:\Users\admin\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpaxjydt.dll [43008]
O61 - LFC: 04/05/2015 - 15:32:54 ----- . (.Java(TM) Native Access (JNA).) -- C:\Users\admin\AppData\Local\Temp\jna\jna8727212715470846939.dll [441220]
O61 - LFC: 04/05/2015 - 15:36:23 ---A- . (.Adobe.) -- C:\Users\admin\Downloads\flash_setup.exe [1055936]
O61 - LFC: 27/04/2015 - 15:31:10 ---A- . (.Everything.) -- C:\Users\admin\AppData\Everything\uninst.exe [121437]
O61 - LFC: 27/04/2015 - 15:31:25 ---A- . (.Everything.) -- C:\Users\admin\AppData\Everything\update.exe [1967668]
~ 1212 Fichiers temporaires (Temporary files)
~ 310 Fichiers cookies (Cookies files)
~ Files: 7 Scanned in 06mn 56s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - 10/09/2014 - C:\Windows\System32\Drivers\DsArk.sys (DsArk) .(.360.cn - dsark.sys.) - LEGACY_DSARK
O64 - Services: CurCS - 04/03/2013 - C:\Windows\System32\Drivers\ElbyCDIO.sys (ElbyCDIO) .(.Elaborate Bytes AG - ElbyCD Windows NT/2000/XP I/O driver.) - LEGACY_ELBYCDIO
O64 - Services: CurCS - 09/05/2012 - C:\Windows\System32\DRIVERS\s7sn2srtx.sys (s7sn2srtx) .(.SIEMENS AG - SIEMENS RT-Protocol V2.0 (ether-type 0x8892.) - LEGACY_S7SN2SRTX
O64 - Services: CurCS - 13/07/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV
O64 - Services: CurCS - 28/10/2013 - C:\Windows\System32\DRIVERS\sntie.sys (SNTIE) .(.Siemens AG - SOFTNET IE ISO Protocol Driver (x86).) - LEGACY_SNTIE
O64 - Services: CurCS - 16/03/2015 - C:\Windows\System32\DRIVERS\VBoxDrv.sys (VBoxDrv) .(.Oracle Corporation - VirtualBox Support Driver.) - LEGACY_VBOXDRV
O64 - Services: CurCS - 16/03/2015 - C:\Windows\System32\DRIVERS\VBoxUSBMon.sys (VBoxUSBMon) .(.Oracle Corporation - VirtualBox USB Monitor Driver.) - LEGACY_VBOXUSBMON
O64 - Services: CurCS - 06/08/2014 - C:\Windows\System32\drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}w.sys ({55dce8ba-9dec-4013-937e-adbf9317d990}w) .(.StdLib - StdLib.) - LEGACY_{55DCE8BA-9DEC-4013-937E-ADBF9317D990}W =>PUP.LinkiDoo
~ Legacy: 109 Scanned in 00mn 03s



---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (...) -- C:\Program Files\Opera\Launcher.exe
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
~ FASS Keys: 11 Scanned in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Opera\Launcher.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Users\admin\AppData\Local\UnicoBrowser\Application\unicobrowser.exe (.not file.) =>PUP.UnicoBrowser
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} - (Trovi) - http://www.trovi.com =>Hijacker.TroviCom
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} - (delta-homes) - http://search.delta-homes.com =>Hijacker.DeltaHomes
O69 - SBI: SearchScopes [HKCU] {425ED333-6083-428a-92C9-0CFC28B9D1BF} - (V9) - http://www.v9.com =>PUP.V9Software
O69 - SBI: SearchScopes [HKCU] {460C3D19-B3D4-4964-A550-77D263B0CCCB} - (SafeFinder Search) - http://feed.safefinder.com =>Hijacker.SmartBar
O69 - SBI: SearchScopes [HKCU] {9BB47C17-9C68-4BB3-B188-DD9AF0FD2514} - (default-search.net) - http://www.default-search.net =>Hijacker.Browsers
O69 - SBI: SearchScopes [HKCU] {A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9} - (Astromenda) - http://astromenda.com =>PUP.Astromenda
O69 - SBI: SearchScopes [HKCU] {D5E56FB0-048E-4681-9A1C-A85911AF58E0} - (Search The Web (buenosearch)) - http://www.buenosearch.com =>PUP.BuenoSearch
O69 - SBI: SearchScopes [HKCU] {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} - (StartWeb) - http://start.iminent.com =>Adware.IMBooster
O69 - SBI: SearchScopes [HKCU] {F7C78C08-3CC7-416F-B827-7C1785ABBDA8} - (Vosteran) - http://Vosteran.com =>PUP.Vosteran
~ Keys: Scanned in 00mn 00s



---\\ Enumère les service demarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [475136]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [523776]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2020864]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [47104]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [49664]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164864]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [71168]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [113664]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [102912]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800]
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [149504]
~ Services: 33 Scanned in 00mn 02s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.9CF5FF46D2B1483A28811C29EA757697] [SPRF][20/04/2015] (...) -- C:\Users\admin\AppData\Roaming\appdataFr3.bin [20]
[MD5.91CD76399FE828FD055CBB48B0AA1DCE] [SPRF][10/07/2014] (.Smart Soft - Free PDF to Word Converter Setup.) -- C:\Users\admin\Desktop\pdf-to-word-converter [1].exe [4512336] =>PUP.PDFtoWordConverter
[MD5.07114BF359E26D6AAE44A7D555C220AA] [SPRF][27/10/2014] (.Systweak Inc - RegClean Pro.) -- C:\Users\admin\Desktop\rcpsetup_sdl_fr_sdl_fr.exe [3850512] =>Rogue.RegistryPowerCleaner
[MD5.7492BF962C2948FDAD6BABCDE4B0CE71] [SPRF][27/10/2014] (.Microsoft Corporation - Microsoft Visual C++ 2008 Express Edition - FRA Setup.) -- C:\Users\admin\Desktop\vcsetup.exe [2743800]
~ Files: 4 Scanned in 00mn 00s



---\\ Recherche d'infection Rogue (SRI) (O86)
O43 - CFD: 03/05/2015 - 19:18:56 - [] ----D C:\ProgramData\4291ca9383084a1bb30e07571604a9d6
[MD5.2DC8F1D1E2F387D9CEA87CEBD90E72BF] [SRI] (.Pas de propriétaire - 4291ca9383084a1bb30e07571604a9d6.) -- C:\ProgramData\4291ca9383084a1bb30e07571604a9d6\4291ca9383084a1bb30e07571604a9d6.exe [311296]
O43 - CFD: 03/05/2015 - 19:18:48 - [] ----D C:\ProgramData\cfda197ad4914fd0ab4eae97a56d3e83
~ Files: Scanned in 00mn 00s



---\\ Liste des exceptions du parefeu (FirewallRules) (O87)
O87 - FAEL: "{D26A5F88-FA4D-4B24-BC9E-1D42135853C5}" | In - Public - P6 - TRUE | .(.http://goforfiles.com/ - GoforFiles Downloader Application.) -- C:\Program Files\GoforFiles\goforfilesdl.exe =>P2P.GoforFiles
O87 - FAEL: "{091D4E10-FE01-4C41-830F-DEF185BF5B1C}" | In - Public - P17 - TRUE | .(.http://goforfiles.com/ - GoforFiles Downloader Application.) -- C:\Program Files\GoforFiles\goforfilesdl.exe =>P2P.GoforFiles
O87 - FAEL: "TCP Query User{13D1F1A2-C586-464E-8453-2EBE22E187E1}C:\users\admin\desktop\goforfiles\goforfilesdl.exe" | In - Public - P6 - TRUE | .(.http://goforfiles.com/ - goforfilesdl Application.) -- C:\users\admin\desktop\goforfiles\goforfilesdl.exe =>P2P.GoforFiles
O87 - FAEL: "UDP Query User{5BD8B83E-1077-4E51-8D06-4E76D4E34416}C:\users\admin\desktop\goforfiles\goforfilesdl.exe" | In - Public - P17 - TRUE | .(.http://goforfiles.com/ - goforfilesdl Application.) -- C:\users\admin\desktop\goforfiles\goforfilesdl.exe =>P2P.GoforFiles
~ Firewall: 4 Scanned in 00mn 11s



---\\ Export de clés de registre aléatoires (O91)
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:060df2cd="c/Au/XV/H/Ap/X2/GP/j/Xt/axAv/X6////%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:0c230bcb="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:0dc3ee96="/P////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:0e93c3f3="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:1520c6f1="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:1c311243="GlAk/X6/G/Ap/YV/UxAk/YZ/Gl////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:27ddcf6f="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:2d71d5ab="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:2e22d94e="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:340d3099="/P////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:37b7a6d8="UlAr/XJ/c//k////"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:38583bc3="Ml/2/CF/M//g/CZ////%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:3c09c42b="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:414bc593="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:48bd1aff="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:51d2f2ea="J/Ay/YZ/FPAm/Xl/GPAm/W//bxAy/Xb/aPAy////"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:587b5709="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:6185d035="Vx/2/Cx/V//l////"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:65114b36="Vl/l////"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:72758a5d="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:7367429f="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:7f69fa1f="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:8b9e4cbc="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:a0743acc="N/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:a1dcff5b="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:a2e3b941="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:bbf88800="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:c24899a6="VP/g/CV/Vl/2/Cx////%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:c5705860="Vx////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:c6c5dd44="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:c99a5f5c="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:d1abcdb6="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:d94388d2="GlAk/X6/G/Ap/YV/UxAk/YZ/Gl////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:e46c271e="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:e8f9dcc7="UlAr/XJ/c//k////"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:f0bf0bde="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:f1f24e29="Vl/l/C/////%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:f2c53c49="UlAr/XJ/c//k////"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:f6ad6fa6="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\28584168269915265\eae10f9d]:fe94ce1e="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:060df2cd="c/Au/XV/H/Ap/X2/GP/j/Xt/axAv/X6////%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:0c230bcb="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:0dc3ee96="/P////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:0e93c3f3="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:1520c6f1="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:1c311243="GlAk/X6/G/Ap/YV/UxAk/YZ/Gl////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:27ddcf6f="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:2d71d5ab="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:2e22d94e="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:340d3099="/P////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:37b7a6d8="UlAr/XJ/c//k////"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:38583bc3="Ml/2/CF/M//g/CZ////%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:3c09c42b="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:414bc593="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:48bd1aff="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:51d2f2ea="GlAk/X6/b/Ay/XP////%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:587b5709="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:6185d035="Vx/2/Cx/V//l////"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:65114b36="VP/l////"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:72758a5d="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:7367429f="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:7f69fa1f="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:8b9e4cbc="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:a0743acc="N/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:a1dcff5b="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:a2e3b941="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:bbf88800="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:c24899a6="VP/g/CV/Vl/2/Cx////%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:c5705860="Vx////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:c6c5dd44="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:c99a5f5c="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:d1abcdb6="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:d94388d2="GlAk/X6/G/Ap/YV/UxAk/YZ/Gl////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:e46c271e="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:e8f9dcc7="UlAr/XJ/c//k////"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:f0bf0bde="///%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:f1f24e29="Vl/l/C/////%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:f2c53c49="UlAr/XJ/c//k////"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:f6ad6fa6="V/////%%"
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719\4303776759456825\eae10f9d]:fe94ce1e="V/////%%"
~ Export Key Software: Scanned in 00mn 00s



---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.F7521B56E8B1AD8BB30E71126FC62A13] [WIS][17/09/2014] (.Linkury Ltd. - SafeFinder Smartbar.) -- C:\Windows\Installer\f56fa.msi [10903552] =>Hijacker.SmartBar
[MD5.E891DE918A54A615DF677DDA5AC93AD5] [WIS][27/08/2014] (.LPT - LPT System Updater Service.) -- C:\Windows\Installer\f5700.msi [2138112] =>Adware.IncrediBar
~ WIS: 2 Scanned in 00mn 10s



---\\ Recherche de clés de registre Tracing (O100)
HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32 =>PUP.MyPCBackup
HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS =>PUP.MyPCBackup
HKLM\SOFTWARE\Microsoft\Tracing\DealKeeperSetup_RASAPI32 =>PUP.DealKeeper
HKLM\SOFTWARE\Microsoft\Tracing\DealKeeperSetup_RASMANCS =>PUP.DealKeeper
HKLM\SOFTWARE\Microsoft\Tracing\DealKeeper_RASAPI32 =>PUP.DealKeeper
HKLM\SOFTWARE\Microsoft\Tracing\DealKeeper_RASMANCS =>PUP.DealKeeper
HKLM\SOFTWARE\Microsoft\Tracing\DealKeeper_Setup_RASAPI32 =>PUP.DealKeeper
HKLM\SOFTWARE\Microsoft\Tracing\DealKeeper_Setup_RASMANCS =>PUP.DealKeeper
HKLM\SOFTWARE\Microsoft\Tracing\GoforFiles_RASAPI32 =>P2P.GoforFiles
HKLM\SOFTWARE\Microsoft\Tracing\GoforFiles_RASMANCS =>P2P.GoforFiles
HKLM\SOFTWARE\Microsoft\Tracing\MixVideoPlayer_RASAPI32 =>PUP.MixVideoPlayer
HKLM\SOFTWARE\Microsoft\Tracing\MixVideoPlayer_RASMANCS =>PUP.MixVideoPlayer
HKLM\SOFTWARE\Microsoft\Tracing\netengine_RASAPI32 =>PUP.NetEngine
HKLM\SOFTWARE\Microsoft\Tracing\netengine_RASMANCS =>PUP.NetEngine
HKLM\SOFTWARE\Microsoft\Tracing\SafeFinder_RASAPI32 =>Hijacker.SmartBar
HKLM\SOFTWARE\Microsoft\Tracing\SafeFinder_RASMANCS =>Hijacker.SmartBar
HKLM\SOFTWARE\Microsoft\Tracing\SupTab_v5_RASAPI32 =>PUP.SupTab
HKLM\SOFTWARE\Microsoft\Tracing\SupTab_v5_RASMANCS =>PUP.SupTab
HKLM\SOFTWARE\Microsoft\Tracing\updateDealKeeper_RASAPI32 =>PUP.DealKeeper
HKLM\SOFTWARE\Microsoft\Tracing\updateDealKeeper_RASMANCS =>PUP.DealKeeper
HKLM\SOFTWARE\Microsoft\Tracing\utilDealKeeper_RASAPI32 =>PUP.DealKeeper
HKLM\SOFTWARE\Microsoft\Tracing\utilDealKeeper_RASMANCS =>PUP.DealKeeper
HKLM\SOFTWARE\Microsoft\Tracing\wpm_v20_RASAPI32 =>PUP.WpManager
HKLM\SOFTWARE\Microsoft\Tracing\wpm_v20_RASMANCS =>PUP.WpManager
~ BTK: 146 Scanned in 00mn 00s



---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{11111111-1111-1111-1111-110611191113}] (iWebar) =>PUP.CrossRider
[HKCR\CLSID\{22222222-2222-2222-2222-220622192213}] (CrossriderApp0061913.Sandbox) =>PUP.CrossRider
[HKCR\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] (SafeFinder SmartbarEngine) =>Hijacker.SmartBar
[HKCR\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}] (SystemK Module) =>PUP.SystemK
[HKCR\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}] (globalUpdate Update Plugin) =>PUP.GlobalUpdate
[HKCR\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}] (globalUpdate.OneClickProcessLauncher) =>PUP.GlobalUpdate
[HKCR\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] (IMinent WebBooster (BHO)) =>Adware.IMBooster
[HKCR\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}] (SafeFinder Smartbar) =>Hijacker.SmartBar
[HKCR\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}] (globalUpdate Update Plugin) =>PUP.GlobalUpdate
[HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}] (YTAHelper) =>PUP.Goobzo
~ BCK: 5889 Scanned in 00mn 39s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 17/04/2015 268464 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Auto 22/07/1658 0 | (BackupStack) . (...) - C:\Program Files\MyPC Backup\BackupStack.exe =>PUP.MyPCBackup
SS - | Auto 22/07/1658 0 | (ClaraUpdater) . (...) - C:\Program Files\Common Files\ClaraUpdater\ClaraUpdater.exe =>Adware.SupTab
SS - | Auto 22/07/1658 0 | (globalUpdate) . (...) - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe =>PUP.GlobalUpdate
SS - | Demand 22/07/1658 0 | (globalUpdatem) . (...) - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe =>PUP.GlobalUpdate
SS - | Disabled 22/07/1658 0 | (GlobalUpdater) . (...) - C:\Program Files\Common Files\IMGUpdater\IMGUpdater.exe =>PUP.IMGUpdater
SS - | Auto 26/09/2014 116648 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 26/09/2014 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 09/04/2014 235696 | (McComponentHostService) . (.McAfee, Inc..) - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
SS - | Demand 16/04/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Auto 22/07/1658 0 | (ReimageRealTimeProtector) . (...) - C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe =>Rogue.ReimageRepair
SS - | Disabled 22/07/1658 0 | (SProtection) . (...) - C:\Program Files\Common Files\Umbrella\Umbrella226.exe
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 18/03/2015 1962496 | (0e6e6c53) . (...) - c:\Program Files\goopad\goopad.dll
SR - | Auto 12/04/2015 1695232 | (5fd90e6b) . (...) - c:\Program Files\SeekerModule\SeekerModule.dll
SR - | Auto 06/03/2015 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 03/12/2009 26112 | (AgereModemAudio) . (.LSI Corporation.) - C:\Program Files\LSI SoftModem\agrsmsvc.exe
SR - | Auto 13/01/2014 1295168 | (almservice) . (.SIEMENS AG.) - C:\Program Files\Common Files\Siemens\sws\almsrv\almsrvx.exe
SR - | Auto 12/04/2015 531456 | (haw) . (...) - c:\windows\haw.exe
SR - | Auto 12/04/2015 523264 | (mhaw) . (...) - c:\windows\mhaw.exe
SR - | Auto 30/01/2015 22184 | (MsMpSvc) . (.Microsoft Corporation.) - C:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 16/01/2014 425696 | (s7oiehsx) . (.Siemens AG.) - C:\Program Files\Common Files\Siemens\S7IEPG\s7oiehsx.exe
SR - | Auto 16/01/2014 560864 | (S7TraceServiceX) . (.Siemens AG.) - C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceServiceX.exe
SR - | Auto 23/04/2015 237056 | (ServiceEverything) . (...) - C:\Users\admin\AppData\Everything\ServiceEverything.exe
SR - | Auto 12/01/2015 424624 | (winzipersvc) . (.Taiwan Shui Mu Chih Ching Technology Limite.) - C:\Program Files\WinZipper\winzipersvc.exe =>Adware.D365
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 48s



---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by admin at 04/05/2015 15:46:22
********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s



---\\ Scan Additionnel (O88)
Database Version : 13008 - (02/05/2015)
Clés trouvées (Keys found) : 98
Valeurs trouvées (Values found) : 4
Dossiers trouvés (Folders found) : 54
Fichiers trouvés (Files found) : 95

[HKLM\SYSTEM\CurrentControlSet\Services\MyPC Backup) (BackupStack] =>PUP.MyPCBackup^
[HKLM\SYSTEM\CurrentControlSet\Services\ClaraUpdater] =>Adware.SupTab^
[HKLM\SYSTEM\CurrentControlSet\Services\globalUpdate) (globalUpdate] =>PUP.GlobalUpdate^
[HKLM\SYSTEM\CurrentControlSet\Services\ReimageRealTimeProtector] =>Rogue.ReimageRepair^
[HKLM\SYSTEM\CurrentControlSet\Services\winzipersvc] =>Adware.D365^
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Binkiland] =>PUP.Binkiland^
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC SpeedUp Service Deactivator] =>Rogue.PCSpeedUp^
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Price Fountain] =>PUP.PriceFountain^
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ReimageUpdater] =>Rogue.ReimageRepair^
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RocketTab] =>PUP.RocketTab^
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RocketTab Update Task] =>PUP.RocketTab^
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update Service GoForFiles] =>P2P.GoforFiles^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Deal Keeper] =>PUP.DealKeeper^
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Digital Sites] =>PUP.Dealply^
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\File Opener Packages] =>Adware.InstallCore^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Tweaks FileOpener] =>Adware.InstallCore^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\FlashBeat] =>PUP.FlashBeat^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Free PDF to Word Converter_is1] =>PUP.PDFtoWordConverter^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP] =>Adware.IMBooster^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar] =>Adware.IMBooster^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage] =>Adware.Downware^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}] =>Adware.IncrediBar^
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Linkey] =>PUP.LinkeySearch^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup] =>PUP.MyPCBackup^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{5fd90e6b}] =>Adware.Graftor^
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PriceFountain] =>PUP.PriceFountain^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\RocketTab] =>PUP.RocketTab^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1898B668-CCF5-429F-A86F-9837E5439D77}] =>Hijacker.SmartBar^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Settings Manager] =>PUP.SystemK^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro] =>PUP.ShopperPro^
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Ultimate Codecs Setup Wizard Packages] =>Adware.InstallCore^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{11F6D5AB-263F-388E-74DE-E3DECD390E3F}] =>PUP.UniDeals^
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Update Service GoForFiles] =>P2P.GoforFiles^
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Price Fountain] =>PUP.PriceFountain^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WSE_Astromenda] =>PUP.Astromenda^
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Search] =>PUP.PaybyAds^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{37476589-E48E-439E-A706-56189E2ED4C4}_is1] =>PUP.Adblocker^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator] =>PUP.Goobzo^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{e6e6c53}] =>Adware.Graftor^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\iWebar] =>PUP.CrossRider^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\sweet-page uninstall] =>PUP.SweetPage^
[HKLM\Software\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}] =>Adware.IMBooster
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent
[HKLM\Software\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software
[HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software
[HKLM\Software\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}] =>Adware.IMBooster
[HKLM\Software\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}] =>Hijacker.SmartBar
[HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}] =>Adware.IMBooster
[HKLM\Software\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}] =>Hijacker.SmartBar
[HKLM\Software\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}] =>Hijacker.SmartBar
[HKLM\Software\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}] =>Hijacker.SmartBar
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] =>Adware.IMBooster
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] =>Adware.IMBooster
[HKLM\Software\Classes\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] =>Adware.IMBooster
[HKLM\Software\Classes\TypeLib\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC}] =>Adware.IMBooster
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ae07101b-46d4-4a98-af68-0333ea26e113}] =>Adware.Agent
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ae07101b-46d4-4a98-af68-0333ea26e113}] =>Adware.Agent
[HKLM\Software\Classes\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}] =>Adware.Agent
[HKLM\Software\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}] =>Hijacker.SmartBar
[HKLM\Software\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}] =>Adware.IMBooster
[HKLM\Software\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}] =>Adware.IMBooster
[HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}] =>Adware.IMBooster
[HKCU\Software\Iminent] =>Adware.IMBooster
[HKLM\Software\Iminent] =>Adware.IMBooster
[HKCU\Software\SmartbarBackup] =>Hijacker.SmartBar
[HKCU\Software\SmartbarLog] =>Hijacker.SmartBar
[HKCU\Software\Softonic] =>PUP.Conduit
[HKCU\Software\Tutorials] =>Spyware.AgenceExclusive
[HKLM\Software\Tutorials] =>Spyware.AgenceExclusive
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{37476589-E48E-439E-A706-56189E2ED4C4}] =>Adware.Agent
[HKCU\Software\InstallCore] =>Adware.InstallCore
[HKLM\Software\InstallCore] =>Adware.InstallCore
[HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider
[HKCU\Software\InstalledBrowserExtensions\] =>PUP.CrossRider
[HKCU\Software\Reimage] =>Rogue.ReimageRepair
[HKLM\Software\Reimage] =>Rogue.ReimageRepair
[HKLM\Software\delta-homesSoftware] =>Toolbar.DeltaSearch
[HKCU\Software\InstalledBrowserExtensions] =>PUP.CrossRider
[HKLM\Software\InstalledBrowserExtensions] =>PUP.CrossRider
[HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro
[HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro
[HKLM\Software\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}] =>Adware.BrowseFox
[HKLM\Software\Classes\CrossriderApp0061913.BHO] =>PUP.CrossRider
[HKLM\Software\Classes\CrossriderApp0061913.BHO.1] =>PUP.CrossRider
[HKLM\Software\Classes\CrossriderApp0061913.Sandbox] =>PUP.CrossRider
[HKLM\Software\Classes\CrossriderApp0061913.Sandbox.1] =>PUP.CrossRider
[HKLM\Software\Classes\Iminent] =>Adware.IMBooster
[HKLM\Software\Classes\IminentWebBooster.BrowserHelperObject] =>Adware.IMBooster
[HKLM\Software\Classes\IminentWebBooster.BrowserHelperObject.1] =>Adware.IMBooster
[HKLM\Software\Classes\IminentWebBooster.ScriptExtender] =>Adware.IMBooster
[HKLM\Software\Classes\IminentWebBooster.ScriptExtender.1] =>Adware.IMBooster
[HKCU\Software\Classes\keepmysearch] =>Adware.MyWebSearch
[HKLM\Software\Classes\CLSID\{11111111-1111-1111-1111-110611191113}] =>PUP.CrossRider
[HKLM\Software\Classes\CLSID\{22222222-2222-2222-2222-220622192213}] =>PUP.CrossRider
[HKLM\Software\Classes\AppID\Iminent.WebBooster.InternetExplorer.DLL] =>Adware.IMBooster
[HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2514}] =>Adware.Bandoo^
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:gmsd_fr_414 =>PUP.CrossRider^
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:pricefountainw.exe =>PUP.PriceFountain^
[HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks]:{84FF7BD6-B47F-46F8-9130-01B2696B36CB} =>Adware.IMBooster
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\pgu6kut4.default-1429039266093\extensions\{ab2afb3f-ced5-e944-9a35-a0d802a604c7} =>PUP.ZoomIt^
C:\Program Files\GoforFiles =>P2P.GoforFiles^
C:\Program Files\GoForFilesUpdater =>P2P.GoforFiles^
C:\Program Files\predm =>Adware.Downware^
C:\Program Files\Common Files\ClaraUpdater =>Adware.SupTab^
C:\Program Files\Common Files\IMGUpdater =>PUP.IMGUpdater^
C:\Program Files\Common Files\ShopperPro =>PUP.ShopperPro^
C:\ProgramData\DSearchLink =>Toolbar.DeltaSearch^
C:\ProgramData\FlashBeat =>PUP.FlashBeat^
C:\ProgramData\IePluginServices =>PUP.IePluginService^
C:\ProgramData\LolliScan =>Adware.Graftor^
C:\ProgramData\NetEngine =>PUP.NetEngine^
C:\ProgramData\Reimage Express =>Rogue.ReimageRepair^
C:\ProgramData\Reimage Protector =>Rogue.ReimageRepair^
C:\ProgramData\ShopperPro =>PUP.ShopperPro^
C:\ProgramData\systemk =>PUP.SystemK^
C:\ProgramData\Uniblue =>PUP.UniblueSystem^
C:\ProgramData\WindowsMangerProtect =>PUP.Fuyu^
C:\ProgramData\Yellow AdBlocker =>PUP.Adblocker^
C:\ProgramData\YTAHelper =>PUP.Goobzo^
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileOpener =>Adware.InstallCore^
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MYBESTOFFERSTODAY =>PUP.MyBestOffersToday^
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip =>PUP.PepperZip^
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Express =>Rogue.ReimageRepair^
C:\Users\admin\AppData\Roaming\1H1Q1V1N1N1O1R =>Adware.InstallCore^
C:\Users\admin\AppData\Roaming\Astromenda =>PUP.Astromenda^
C:\Users\admin\AppData\Roaming\Binkiland =>PUP.Binkiland^
C:\Users\admin\AppData\Roaming\DigitalSites =>Hijacker.DSite^
C:\Users\admin\AppData\Roaming\eCyber =>PUP.Elex^
C:\Users\admin\AppData\Roaming\Free PDF to Word Converter =>PUP.PDFtoWordConverter^
C:\Users\admin\AppData\Roaming\Gameo =>PUP.Gameo^
C:\Users\admin\AppData\Roaming\GoforFiles =>P2P.GoforFiles^
C:\Users\admin\AppData\Roaming\OpenCandy =>Adware.OpenCandy^
C:\Users\admin\AppData\Roaming\PriceFountain =>PUP.PriceFountain^
C:\Users\admin\AppData\Roaming\Probit Software =>PUP.ProbitSoftware^
C:\Users\admin\AppData\Roaming\sweet-page =>PUP.SweetPage^
C:\Users\admin\AppData\Roaming\uTorrent =>P2P.µTorrent^
C:\Users\admin\AppData\Roaming\VOPackage =>Adware.Downware^
C:\Users\admin\AppData\Roaming\WSE_Astromenda =>PUP.Astromenda^
C:\Users\admin\AppData\Local\Binkiland =>PUP.Binkiland^
C:\Users\admin\AppData\Local\Gameo =>PUP.Gameo^
C:\Users\admin\AppData\Local\Genesis_09171126 =>PUP.Genesis^
C:\Users\admin\AppData\Local\globalUpdate =>PUP.GlobalUpdate^
C:\Users\admin\AppData\Local\LPT =>Adware.Incredibar^
C:\Users\admin\AppData\Local\mbot_fr_588 =>PUP.CrossRider^
C:\Users\admin\AppData\Local\Pay-By-Ads =>PUP.PaybyAds^
C:\Users\admin\AppData\Local\PriceFountain =>PUP.PriceFountain^
C:\Users\admin\AppData\Local\Pro_PC_Cleaner =>PUP.DoctorPC^
C:\Users\admin\AppData\Local\Rainmaker_Software_Group_ =>PUP.DoctorPC^
C:\Users\admin\AppData\Local\Smartbar =>Hijacker.SmartBar^
C:\Users\admin\AppData\Local\Vosteran =>PUP.Vosteran^
C:\Program Files\Common Files\Umbrella =>Adware.IMBooster
C:\Users\admin\AppData\Local\Installer =>Adware.InstallPedia
C:\Users\admin\AppData\LocalLow\Smartbar =>Hijacker.SmartBar
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: Modified =>Hijacker.Application^
C:\Program Files\GoForFilesUpdater\GoForFilesUpdater.exe =>P2P.GoforFiles^
C:\ProgramData\FlashBeat\FlashBeat.exe =>PUP.FlashBeat^
C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-1.job =>PUP.CrossRider^
C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-11.job =>PUP.CrossRider^
C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-2.job =>PUP.CrossRider^
C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-4.job =>PUP.CrossRider^
C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-5.job =>PUP.CrossRider^
C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-5_user.job =>PUP.CrossRider^
C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-6.job =>PUP.CrossRider^
C:\Windows\Tasks\29beb69c-69e5-4176-897e-d2a29a91d413-7.job =>PUP.CrossRider^
C:\Windows\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5.job =>PUP.CrossRider^
C:\Windows\System32\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5 =>PUP.CrossRider^
C:\Windows\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5_user.job =>PUP.CrossRider^
C:\Windows\System32\Tasks\a208d04d-b0d5-4747-bf28-bb1ba986e156-5_user =>PUP.CrossRider^
C:\Windows\Tasks\Binkiland.job =>PUP.Binkiland^
C:\Windows\System32\Tasks\Binkiland =>PUP.Binkiland^
C:\Windows\Tasks\Digital Sites.job =>Hijacker.DSite^
C:\Windows\System32\Tasks\Digital Sites =>Hijacker.DSite^
C:\Windows\Tasks\Price Fountain.job =>PUP.PriceFountain^
C:\Windows\System32\Tasks\Price Fountain =>PUP.PriceFountain^
C:\Windows\Tasks\WSE_Astromenda.job =>PUP.Astromenda^
C:\Windows\System32\Tasks\WSE_Astromenda =>PUP.Astromenda^
C:\Windows\Tasks\YRCPXQOXG1.job =>PUP.FlashBeat^
C:\Windows\System32\Tasks\YRCPXQOXG1 =>PUP.FlashBeat^
[HKCU\Software\AppDataLow\DealKeeper] =>PUP.DealKeeper^
[HKCU\Software\AppDataLow\Software\DynConIE] =>PUP.DynConIE^
[HKCU\Software\AppDataLow\Software\SpeedChecker] =>PUP.InternetSpeedChecker^
[HKCU\Software\AppDataLow\Software\iWebar] =>PUP.CrossRider^
[HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}] =>Adware.Graftor^
[HKCU\Software\ArenaHD] =>PUP.CrossRider^
[HKCU\Software\Binkiland Browser] =>PUP.Binkiland^
[HKCU\Software\CleanerProConfig] =>PUP.CleanerPro^
[HKCU\Software\CleanerProLanguage] =>PUP.CleanerPro^
[HKCU\Software\CrossBrowser] =>PUP.CrossBrowser^
[HKCU\Software\DSiteproducts] =>Hijacker.DSite^
[HKCU\Software\Deal Keeper] =>PUP.DealKeeper^
[HKCU\Software\Gameo] =>PUP.Gameo^
[HKCU\Software\GoforFiles] =>P2P.GoforFiles^
[HKCU\Software\Goobzo] =>PUP.Goobzo^
[HKCU\Software\HighDefAction] =>PUP.CrossRider^
[HKCU\Software\Optimizer Pro] =>PUP.OptimizerPro^
[HKCU\Software\ProPCCleanerConfig] =>PUP.DoctorPC^
[HKCU\Software\ProPCCleanerLanguage] =>PUP.DoctorPC^
[HKCU\Software\Probit Software] =>PUP.ProbitSoftware^
[HKCU\Software\RocketTabInstalled] =>PUP.RocketTab^
[HKCU\Software\Search Extensions] =>PUP.RocketTab^
[HKCU\Software\ShopperPro] =>PUP.ShopperPro^
[HKCU\Software\Smartbar] =>Hijacker.SmartBar^
[HKCU\Software\SystemK] =>PUP.SystemK^
[HKCU\Software\TutoTag] =>PUP.AgenceExclusive^
[HKCU\Software\UnicoBrowser] =>PUP.UnicoBrowser^
[HKCU\Software\Vosteran Browser] =>PUP.Vosteran^
[HKCU\Software\YorkNewCin] =>PUP.CrossRider^
[HKCU\Software\globalUpdate] =>PUP.GlobalUpdate^
[HKCU\Software\wse_astromenda] =>PUP.Astromenda^
[HKLM\Software\4d2f4bf9-1897-1585-ab41-201e1b4f3719] =>PUP.CrossRider^
[HKLM\Software\ArenaHD] =>PUP.CrossRider^
[HKLM\Software\DealKeeper] =>PUP.DealKeeper^
[HKLM\Software\EnigmaSoftwareGroup] =>PUP.EnigmaSoftware^
[HKLM\Software\Flashbeat] =>PUP.FlashBeat^
[HKLM\Software\GlobalUpdate] =>PUP.GlobalUpdate^
[HKLM\Software\GoforFiles] =>P2P.GoforFiles^
[HKLM\Software\Goobzo] =>PUP.Goobzo^
[HKLM\Software\HQCinema Pro 2.1V14.04] =>PUP.CrossRider^
[HKLM\Software\HighDefAction] =>PUP.CrossRider^
[HKLM\Software\IMGUpdater] =>PUP.IMGUpdater^
[HKLM\Software\Linkey] =>PUP.LinkeySearch^
[HKLM\Software\MYBESTOFFERSTODAY] =>PUP.MyBestOffersToday^
[HKLM\Software\ORBTR] =>Toolbar.Conduit^
[HKLM\Software\SupDp] =>PUP.SupTab^
[HKLM\Software\SystemK] =>PUP.SystemK^
[HKLM\Software\Uniblue] =>PUP.UniblueSystem^
[HKLM\Software\WebProtector] =>PUP.WebProtect^
[HKLM\Software\YorkNewCin] =>PUP.CrossRider^
[HKLM\Software\supTab] =>PUP.SupTab^
[HKLM\Software\supWPM] =>PUP.WpManager^
[HKLM\Software\supWindowsMangerProtect] =>PUP.Fuyu^
[HKLM\Software\sweet-pageSoftware] =>PUP.SweetPage^
[HKLM\Software\winzipersvc] =>Adware.D365^
C:\Users\admin\Desktop\pdf-to-word-converter =>PUP.PDFtoWordConverter^
C:\Users\admin\Desktop\rcpsetup_sdl_fr_sdl_fr.exe =>Rogue.RegistryPowerCleaner^
C:\Windows\Installer\f56fa.msi =>Hijacker.SmartBar^
C:\Windows\Installer\f5700.msi =>Adware.IncrediBar^
[HKCR\CLSID\{11111111-1111-1111-1111-110611191113}] (iWebar) =>PUP.CrossRider^
[HKCR\CLSID\{22222222-2222-2222-2222-220622192213}] (CrossriderApp0061913.Sandbox) =>PUP.CrossRider^
[HKCR\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] (SafeFinder SmartbarEngine) =>Hijacker.SmartBar^
[HKCR\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}] (SystemK Module) =>PUP.SystemK^
[HKCR\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}] (globalUpdate Update Plugin) =>PUP.GlobalUpdate^
[HKCR\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}] (globalUpdate.OneClickProcessLauncher) =>PUP.GlobalUpdate^
[HKCR\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] (IMinent WebBooster (BHO)) =>Adware.IMBooster^
[HKCR\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}] (SafeFinder Smartbar) =>Hijacker.SmartBar^
[HKCR\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}] (globalUpdate Update Plugin) =>PUP.GlobalUpdate^
[HKCR\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}] (YTAHelper) =>PUP.Goobzo^
C:\Windows\Reimage.ini =>Rogue.ReimageRepair
~ Additionnel Scan: 516214 Items scanned in 02mn 45s



---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ http://nicolascoolman.fr/o50-image-file-execution-options-zhpdiag/ =>.Image File Execution Options (IFEO) (O50)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
~ AMI: 4 Scanned in 00mn 00s



---\\ Récapitulatif des détections trouvées sur votre station
http://www.nicolascoolman.fr/blog/ =>Hijacker.Application
http://www.nicolascoolman.fr/blog/ =>PUP.FlashBeat
http://www.nicolascoolman.fr/blog/ =>PUP.ZoomIt
http://www.nicolascoolman.fr/blog/ =>Hijacker.DeltaHomes
http://nicolascoolman.fr/adware-imbooster =>Adware.IMBooster
http://nicolascoolman.fr/pup-globalupdate =>PUP.GlobalUpdate
http://nicolascoolman.fr/hijacker-smartbar =>Hijacker.SmartBar
http://nicolascoolman.fr/pup-sweetpage =>PUP.SweetPage
http://nicolascoolman.fr/hijacker-proxy =>Hijacker.Proxy
http://nicolascoolman.fr/pup-eorezo =>PUP.Eorezo
http://nicolascoolman.fr/pup-crossrider =>PUP.CrossRider
http://www.nicolascoolman.fr/blog/ =>PUP.PriceFountain
http://nicolascoolman.fr/pup-astromenda =>PUP.Astromenda
http://www.nicolascoolman.fr/blog/ =>PUP.UnicoBrowser
http://nicolascoolman.fr/pup-mypcbackup =>PUP.MyPCBackup
http://www.nicolascoolman.fr/blog/ =>Adware.SupTab
http://nicolascoolman.fr/rogue-reimagerepair =>Rogue.ReimageRepair
http://www.nicolascoolman.fr/blog/ =>Adware.D365
http://www.nicolascoolman.fr/blog/ =>PUP.Binkiland
http://www.nicolascoolman.fr/blog/ =>PUP.CleanerPro
http://nicolascoolman.fr/hijacker-dsite =>Hijacker.DSite
http://nicolascoolman.fr/pup-probitsoftware =>PUP.ProbitSoftware
http://nicolascoolman.fr/rogue-pcspeedup =>Rogue.PCSpeedUp
http://www.nicolascoolman.fr/blog/ =>PUP.DoctorPC
http://www.nicolascoolman.fr/blog/ =>PUP.RocketTab
http://nicolascoolman.fr/pup-paybyads =>PUP.PaybyAds
http://nicolascoolman.fr/pup-elex =>PUP.Elex
http://nicolascoolman.fr/pup-linkidoo =>PUP.LinkiDoo
http://nicolascoolman.fr/pup-dealkeeper =>PUP.DealKeeper
http://nicolascoolman.fr/pup-dealply =>PUP.Dealply
http://nicolascoolman.fr/adware-installcore =>Adware.InstallCore
http://www.nicolascoolman.fr/blog/ =>PUP.PDFtoWordConverter
http://nicolascoolman.fr/adware-downware =>Adware.Downware
http://nicolascoolman.fr/adware-incredibar =>Adware.IncrediBar
http://nicolascoolman.fr/pup-linkeysearch =>PUP.LinkeySearch
http://www.nicolascoolman.fr/blog/ =>Adware.Graftor
http://nicolascoolman.fr/pup-systemk =>PUP.SystemK
http://nicolascoolman.fr/pup-shopperpro =>PUP.ShopperPro
http://www.nicolascoolman.fr/blog/ =>PUP.UniDeals
http://www.nicolascoolman.fr/blog/ =>PUP.Adblocker
http://www.nicolascoolman.fr/blog/ =>PUP.Goobzo
http://www.nicolascoolman.fr/blog/ =>PUP.DynConIE
http://nicolascoolman.fr/pup-internetspeedchecker =>PUP.InternetSpeedChecker
http://www.nicolascoolman.fr/blog/ =>PUP.CrossBrowser
http://www.nicolascoolman.fr/blog/ =>PUP.Gameo
http://www.nicolascoolman.fr/blog/ =>PUP.BrowserExtensions
http://nicolascoolman.fr/pup-optimizerpro =>PUP.OptimizerPro
http://nicolascoolman.fr/toolbar-conduit =>Toolbar.Conduit
http://nicolascoolman.fr/spyware-agenceexclusive =>PUP.AgenceExclusive
http://www.nicolascoolman.fr/blog/ =>PUP.Vosteran
http://www.nicolascoolman.fr/blog/ =>PUP.EnigmaSoftware
http://nicolascoolman.fr/pup-imgupdater =>PUP.IMGUpdater
http://www.nicolascoolman.fr/blog/ =>PUP.MyBestOffersToday
http://nicolascoolman.fr/pup-suptab =>PUP.SupTab
http://www.nicolascoolman.fr/blog/ =>PUP.UniblueSystem
http://www.nicolascoolman.fr/blog/ =>PUP.WebProtect
http://nicolascoolman.fr/pup-wpmanager =>PUP.WpManager
http://www.nicolascoolman.fr/blog/ =>PUP.Fuyu
http://nicolascoolman.fr/toolbar-deltasearch =>Toolbar.DeltaSearch
http://www.nicolascoolman.fr/blog/ =>PUP.IePluginService
http://www.nicolascoolman.fr/blog/ =>PUP.NetEngine
http://www.nicolascoolman.fr/blog/ =>PUP.PepperZip
http://nicolascoolman.fr/adware-opencandy =>Adware.OpenCandy
http://nicolascoolman.fr/pup-genesis =>PUP.Genesis
http://nicolascoolman.fr/trojan-vonteera =>Trojan.Vonteera
http://nicolascoolman.fr/hijacker-trovicom =>Hijacker.TroviCom
http://nicolascoolman.fr/pup-v9software =>PUP.V9Software
http://nicolascoolman.fr/hijacker-browsers =>Hijacker.Browsers
http://nicolascoolman.fr/pup-buenosearch =>PUP.BuenoSearch
http://nicolascoolman.fr/rogue-registrypowercleaner =>Rogue.RegistryPowerCleaner
http://www.nicolascoolman.fr/blog/ =>PUP.MixVideoPlayer
http://www.nicolascoolman.fr/blog/ =>Toolbar.Agent
http://www.nicolascoolman.fr/blog/ =>Adware.Agent
http://www.nicolascoolman.fr/blog/ =>PUP.Conduit
http://www.nicolascoolman.fr/blog/ =>Spyware.AgenceExclusive
http://nicolascoolman.fr/adware-browsefox =>Adware.BrowseFox
http://nicolascoolman.fr/adware-mywebsearch =>Adware.MyWebSearch
http://nicolascoolman.fr/adware-bandoo =>Adware.Bandoo
http://nicolascoolman.fr/adware-installpedia =>Adware.InstallPedia
~ MSI: 79 link(s) detected in 00mn 00s



End of the scan (2113 lines in 24mn 38s)(0.8)

Publicité


Signaler le contenu de ce document

Publicité