cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.7.17.92 Par Nicolas Coolman (2015/07/17)
~ Démarré par gabriel (Administrator) (2015/07/17 16:23:32)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: D:\gabriel\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\gabriel\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Deactivate
~ Démarrage du système: Normal (Normal boot)
~ Windows 7, 64-bit Service Pack 1 (Build 7601)

---\\ Navigateurs Internet (3) - 0s
GCIE: Google Chrome v43.0.2357.134
MFIE: Mozilla Firefox 9.0 (x86 fr) v9.0
MSIE: Internet Explorer v9.0.8112.16421

---\\ Informations sur les produits Windows (3) - 13s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Activation Technologies : OK

---\\ Logiciels de protection (2) - 2s
Microsoft Forefront Endpoint Protection 2010 Server Management v2.2.0903.0
Microsoft Security Client FR-FR Language Pack v2.2.0903.0

---\\ Logiciels d'optimisation (1) - 2s
CCleaner v4.16

---\\ Surveillance de Logiciels (2) - 3s
Adobe Flash Player 18 NPAPI
Adobe Reader XI

---\\ Informations sur le système (6) - 0s
~ Operating System: Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
~ Total physical RAM (KB): 4060788
~ System Restore: Activé (Enable)
~ System drive C: has 61 GB free of 99 GB

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: FPSE-304690-001
~ User Name: gabriel
~ Logged in as Administrator

---\\ Enumération des unités disques (3) - 0s
~ Drive C: has 61 GB free of 99 GB (System)
~ Drive D: has 80 GB free of 205 GB
~ Drive F: has 2 GB free of 3 GB

---\\ Recherche particulière de fichiers génériques (24) - 2s
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\windows\Explorer.exe [2871808]
[MD5.DD81D91FF3B0763C392422865C9AC12E] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\windows\System32\rundll32.exe [45568]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\windows\System32\Wininit.exe [129024]
[MD5.75F110F4005DAE430AECA787FDEA9CBB] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\windows\System32\wininet.dll [1392128]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) () -- C:\windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) () -- C:\windows\System32\sppcomapi.dll [232448]
[MD5.0D57D091E06BB1E58E72E5D08479FDDF] - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) () -- C:\windows\System32\fr-FR\user32.dll.mui [20480]
[MD5.1C7857B62DE5994A75B054A9FD4C3825] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\windows\System32\drivers\AFD.sys [498688]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\windows\System32\drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\windows\System32\drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\windows\System32\drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\windows\System32\drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\windows\System32\drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\windows\System32\drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\windows\System32\drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\windows\System32\drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\windows\System32\drivers\netBT.sys [261632]
[MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\windows\System32\drivers\ntfs.sys [1656680]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\windows\System32\drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\windows\System32\drivers\Rasl2tp.sys [129536]
[MD5.1B6163C503398B23FF8B939C67747683] - (.Microsoft Corporation - Microsoft RDP Device redirector.) () -- C:\windows\System32\drivers\rdpdr.sys [165888]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) () -- C:\windows\System32\drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\windows\System32\drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\windows\System32\drivers\volsnap.sys [295808]

---\\ Processus lancés (29) - 3s
[MD5.F3F2E0D9DB9B20F1B160B75E3CD16B32] - (.Novell, Inc - micasad.exe.) -- C:\Program Files (x86)\Novell\CASA\bin\micasad.exe [249856] [PID.752]
[MD5.4D4FD703DBE396747F22874B6DDA3D4E] - (.AMD - AMD External Events Service Module.) -- C:\windows\system32\atiesrxx.exe [204288] [PID.972]
[MD5.CEBC197727D87B89645F7181FD877B48] - (.AMD - AMD External Events Client Module.) -- C:\windows\system32\atieclxx.exe [516608] [PID.1332]
[MD5.AD5DF6F4FBBC798636EDC66BFEC7D0DE] - (.Copyright CANON INC. 2006-2010 All Rights Reserved - Inkjet Printer/Scanner/Fax Extended Survey.) -- C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe [116104] [PID.1908]
[MD5.CDEA4AEFF5975061813036F157F106DF] - (.Copyright (C) 2014 - .) -- C:\Program Files (x86)\ver5NewPlayer\V7NewPlayerwL178.exe [291328] [PID.328] =>PUP.Optional.NewPlayer
[MD5.93E333483AE6BA2DA645FF096FF20282] - (.Copyright © 2014 - NewVideoPlayerUpdaterService.) -- C:\Program Files (x86)\NewPlayer\NewVideoPlayerUpdaterService.exe [11776] [PID.1444] =>PUP.Optional.NewPlayer
[MD5.1ABE08B289452D24884530C03839183A] - (...) -- C:\monitor.exe [487483] [PID.2264]
[MD5.49CE79CE698B91EE8A97834244F2C348] - (...) -- C:\Windows\score.exe [4823040] [PID.2352]
[MD5.6C624641A4563E036C305CE7C3D41E95] - (.app - Browsers Apps- exe.) -- C:\Program Files (x86)\Browsers Apps-\7fc7d17b-ba69-4bc7-ba33-2c036a5f94b3.exe [356224] [PID.2952] =>PUP.Optional.CrossRider
[MD5.D858BA2EE718B1DB1CED20646E641D08] - (.globalUpdate - globalUpdate Update.) -- C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608] [PID.3024] =>PUP.Optional.GlobalUpdate
[MD5.7016A5D74459577060366F7D1E44F495] - (.FileProperties_CompanyName - FileProperties_FileDescription.) -- C:\Program Files (x86)\coupons and fun\coupons_and_fun_notification_service.exe [1417216] [PID.1616] =>PUP.Optional.CrossRider
[MD5.E7704CBF568815C1CAA6E513387BD3F2] - (.Advanced Micro Devices Inc. - Catalyst Control Center: Monitoring program.) -- c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe [65536] [PID.3408]
[MD5.3B78ACCCAA5132638E7CF419F4A965C7] - (.CANON INC. - Canon Solution Menu EX.) -- C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112] [PID.3744]
[MD5.74EF310FAC89341CE2897B7F2C4A7B0F] - (.ATI Technologies Inc. - Catalyst Control Centre: Host application.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [65536] [PID.4400]
[MD5.227846995AFEEFA70D328BF5334A86A5] - (.Macrovision Europe Ltd. - Activation Licensing Service.) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848] [PID.2280]
[MD5.411F9EEF72CACD4E76431B282099A3A6] - (.MyOSCompany - .) -- C:\Program Files (x86)\PCTRunner\MyOSProtect.exe [1317096] [PID.2876] =>PUP.Optional.WebProtect
[MD5.8A76DBBF66FAB5CC7DDA707F73CAB68F] - (...) -- C:\Windows\Temp\NewVideoPlayerSetup.exe [693096] [PID.6360]
[MD5.4769DE7294FAD1CB42213D1F49C7A3F8] - (.Copyright © 2014 - Torpedo.) -- C:\Program Files (x86)\Browsers Apps-\6dd9516d-ead4-47a9-b3d2-d447fe9cc131.exe [32128] [PID.33380] =>PUP.Optional.CrossRider
[MD5.6C52FDB55655AB9272EDD62A16A55352] - (...) -- C:\Program Files (x86)\Framed Display\updateFramedDisplay.exe [459000] [PID.39432] =>PUP.FramedDisplay
[MD5.7057BD7392002F0522AEC901D92BCB3D] - (...) -- C:\Program Files (x86)\Summer Sports\summer_sports_helper_service.exe [191719] [PID.40368]
[MD5.2B93A9A249D744950C52519D78D00216] - (.Pay By Ads LTD - .) -- C:\Program Files (x86)\Pay-By-Ads\Yahoo! Search\1.3.26.12\dsrlte.exe [660736] [PID.42924] =>PUP.Optional.PaybyAds
[MD5.D3FEE9C54D8BB3E0E16F2BD620F73121] - (...) -- C:\ProgramData\ecbaef90-5696-41e1-a1c3-3e8112ce2840\maintainer.exe [128248] [PID.39428]
[MD5.2C0D1C006F357049423049432C128EB2] - (...) -- C:\ProgramData\80810f5c-7b66-4b02-af93-03f2b7680a45\maintainer.exe [128288] [PID.2968]
[MD5.4382F587DF36BC0E358D8A0504C950F0] - (...) -- C:\Program Files (x86)\glindorus\bin\utilglindorus.exe [456992] [PID.50688] =>PUP.Glindorus
[MD5.C8740A8C5F2DD61B8780D6F17ADFD3E8] - (...) -- C:\Program Files (x86)\glindorus\bin\glindorus.PurBrowse64.exe [353568] [PID.50320] =>PUP.Glindorus
[MD5.10ADC89CDE5216204D6AE6FB52457F36] - (...) -- C:\Program Files (x86)\glindorus\bin\glindorus.BrowserAdapter.exe [108832] [PID.1432] =>PUP.Glindorus
[MD5.EA981967DEAEF5749D924C34BCFA8D7A] - (...) -- C:\Program Files (x86)\glindorus\bin\glindorus.BrowserAdapter64.exe [126752] [PID.49792] =>PUP.Glindorus
[MD5.58D46E1C3B2C78C4BBC463B1A1C84B49] - (...) -- C:\Program Files (x86)\glindorus\bin\glindorus.expext.exe [114976] [PID.50520] =>PUP.Glindorus
[MD5.4382F587DF36BC0E358D8A0504C950F0] - (...) -- C:\Program Files (x86)\glindorus\updateglindorus.exe [456992] [PID.54088] =>PUP.Glindorus

---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2) (12) - 1s
G2 - GCE: Preference [User Data\Default] [fcfenmboojpjinhpgggodefccipikbpd] Bing
G2 - GCE: Preference [User Data\Default] [ffhfoagmjcnkolneahbpagjcjjaeofbg] Browsers Apps- =>PUP.Optional.CrossRider
G2 - GCE: Preference [User Data\Default] [floipahigmmkfhkoapmnijnlnboniglg] floipahigmmkfhkoapmnijnlnboniglg
G2 - GCE: Preference [User Data\Default] [gagcbogmgkaogoadfcoicjdojbmkegao] Framed Display =>PUP.Optional.Sambreel
G2 - GCE: Preference [User Data\Default] [gmlllbghnfkpflemihljekbapjopfjik] Bookmark Manager
G2 - GCE: Preference [User Data\Default] [hnhiokdidpkighjkankkbahmeheadohg] coupons and fun
G2 - GCE: Preference [User Data\Default] [lccekmodgklaepjeofjdjpbminllajkg] Chrome Hotword Shared Module
G2 - GCE: Preference [User Data\Default] [lifbcibllhkdhoafpjfnlhfpfgnpldfl] Skype Click to Call
G2 - GCE: Preference [User Data\Default] [llmcibonccojooiboenghfafpieoabpl] glindorus =>PUP.Optional.Sambreel
G2 - GCE: Preference [User Data\Default] [monhkdcehmbdgkhgpccaccbbcgcfpjkd] monhkdcehmbdgkhgpccaccbbcgcfpjkd
G2 - GCE: Preference [User Data\Default] [monpennifgclhopkmgdbcnaagkgdemch] Summer Sports
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.

---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) (12) - 2s
M0 - MFSP: prefs.js [gabriel - 4qqvklyb.default] http://fr.search.yahoo.com/?fr=hp-ddc-bd&type=pr-bfr-is__alt__ddc_dsssyc_bd_com
M1 - SPR:Search Page Redirection - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
M1 - SPR:Search Page Redirection - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\nppdf32.DEU
P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\nppdf32.FRA
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=11.31.2] - (.Oracle Corporation.) -- C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=11.31.2] - (.Oracle Corporation.) -- C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft.) -- C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@staging.google.com/globalUpdate Update;version=10] - (.globalUpdate.) -- C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll =>PUP.Optional.GlobalUpdate
P2 - FPN: [HKLM] [@staging.google.com/globalUpdate Update;version=4] - (.globalUpdate.) -- C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll =>PUP.Optional.GlobalUpdate
P2 - FPN: [HKLM] [@www.dlmanager.net/omaha/tools//Software Update;version=8] - (.Boxore OU..) -- C:\Program Files (x86)\Software\Update\1.2.201.0\npSoftwareOneClick8.dll =>PUP.Optional.Boxore

---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) (22) - 1s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ch.search.yahoo.com/
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/ =>PUP.Optional.HelperBar
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/ =>PUP.Optional.HelperBar
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/ =>PUP.Optional.AwesomeHP
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/ =>PUP.Optional.AwesomeHP
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/ =>PUP.Optional.HelperBar
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/ =>PUP.Optional.HelperBar
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://feed.helperbar.com/ =>PUP.Optional.HelperBar
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/ =>PUP.Optional.AwesomeHP
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/ =>PUP.Optional.AwesomeHP
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer

---\\ Internet Explorer, Proxy Management (R5) (5) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:14199;https=127.0.0.1:14199 =>Hijacker.Proxy
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.)
F2 - REG:system.ini: Shell=C:\windows\explorer.exe (.Microsoft Corporation.)
F2 - REG:system.ini: VMApplet=C:\windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.)

---\\ Hosts file redirection (O1) (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ Browser Helper Object de navigateur (BHO) (O2) (8) - 1s
O2 - BHO: Framed Display 1.0.0.7 [64Bits] - {05b5ef3f-4c6a-426e-b77e-48ebb3e721f1} (Orphean) =>PUP.Optional.FramedDisplay
O2 - BHO: CrossriderApp0061787 [64Bits] - {11111111-1111-1111-1111-110611171187} . (.app - Browsers Apps- BHO.) -- C:\Program Files (x86)\Browsers Apps-\Browsers Apps--bho64.dll =>PUP.Optional.CrossRider
O2 - BHO: MuvicEngine [64Bits] - {31ad400d-1b06-4e33-a59a-90c2c140cba0} . (...) -- mscoree.dll (.not file.) =>PUP.Optional.SmartBar
O2 - BHO: (no name) [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (Orphean)
O2 - BHO: glindorus 1.0.0.7 [64Bits] - {9598e82a-7e09-4438-b425-b9e9718c3c73} (Orphean) =>PUP.Glindorus
O2 - BHO: (no name) [64Bits] - {AE7CD045-E861-484f-8273-0445EE161910} (Orphean)
O2 - BHO: (no name) [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} (Orphean)
O2 - BHO: mysearchdial Helper Object [64Bits] - {EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} (Orphean) =>PUP.Optional.Hotbar

---\\ Internet Explorer Toolbars (O3) (2) - 0s
O3 - Toolbar: 0xB1C218236549D4119B18009027A5CD4F - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} . (...) -- (.not file.)
O3 - Toolbar: mysearchdial Toolbar - [HKLM]{3004627E-F8E9-4E8B-909D-316753CBA923} . (.Ironsource Israel (2011) LTD - .) -- C:\Program Files (x86)\Mysearchdial\1.8.21.0\mysearchdialTlbr.dll =>PUP.Optional.Hotbar

---\\ Applications lancées au démarrage du sytème (O4) (15) - 1s
O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor Corp. - HD Audio Control Panel.) -- C:\Program Files\Realtek\Audio\HDA\RtDCpl64.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKLM\..\Run: [BCSSync] . (.Microsoft Corporation - Microsoft Office 2010 component.) -- C:\Program Files\Microsoft Office\Office14\BCSSync.exe
O4 - HKCU\..\Run: [Yahoo! Search] . (.Pay By Ads LTD - .) -- C:\Program Files (x86)\Pay-By-Ads\Yahoo! Search\1.3.26.12\dsrlte.exe =>PUP.Optional.PaybyAds
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_17_0_0_190_Plugin.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [IAStorIcon] . (.Intel Corporation - IAStorIcon.) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-21-663432453-3043917424-1043612045-1006\..\Run: [Yahoo! Search] . (.Pay By Ads LTD - .) -- C:\Program Files (x86)\Pay-By-Ads\Yahoo! Search\1.3.26.12\dsrlte.exe =>PUP.Optional.PaybyAds
O4 - HKUS\S-1-5-21-663432453-3043917424-1043612045-1006\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
O4 - HKUS\S-1-5-21-663432453-3043917424-1043612045-1006\..\RunOnce: [FlashPlayerUpdate] C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_17_0_0_190_Plugin.exe (.not file.)

---\\ Raccourcis Global Startup (O4G) (16) - 4s
O4 - GS\Desktop [Administrateur]: FLV Player.lnk . (...) C:\Program Files (x86)\FLV Player\FLVPlayer.exe =>PUP.Optional.FLVPlayer
O4 - GS\Desktop [Administrateur]: Yahoo! Search.lnk . (.Pay By Ads LTD - .) C:\Users\gabriel\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.8.2\dsrlte.exe =>PUP.Optional.PaybyAds
O4 - GS\Quicklaunch [Administrateur]: FLV Player.lnk . (...) C:\Program Files (x86)\FLV Player\FLVPlayer.exe =>PUP.Optional.FLVPlayer
O4 - GS\Quicklaunch [Administrateur]: SpeedUpMyPC.lnk . (...) C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe =>PUP.Optional.SpeedUpMyPC
O4 - GS\Desktop [essai2]: FLV Player.lnk . (...) C:\Program Files (x86)\FLV Player\FLVPlayer.exe =>PUP.Optional.FLVPlayer
O4 - GS\Desktop [essai2]: Yahoo! Search.lnk . (.Pay By Ads LTD - .) C:\Users\gabriel\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.8.2\dsrlte.exe =>PUP.Optional.PaybyAds
O4 - GS\Quicklaunch [essai2]: FLV Player.lnk . (...) C:\Program Files (x86)\FLV Player\FLVPlayer.exe =>PUP.Optional.FLVPlayer
O4 - GS\Quicklaunch [essai2]: SpeedUpMyPC.lnk . (...) C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe =>PUP.Optional.SpeedUpMyPC
O4 - GS\Desktop [gabriel]: FLV Player.lnk . (...) C:\Program Files (x86)\FLV Player\FLVPlayer.exe =>PUP.Optional.FLVPlayer
O4 - GS\Desktop [gabriel]: Yahoo! Search.lnk . (.Pay By Ads LTD - .) C:\Users\gabriel\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.8.2\dsrlte.exe =>PUP.Optional.PaybyAds
O4 - GS\Quicklaunch [gabriel]: FLV Player.lnk . (...) C:\Program Files (x86)\FLV Player\FLVPlayer.exe =>PUP.Optional.FLVPlayer
O4 - GS\Quicklaunch [gabriel]: SpeedUpMyPC.lnk . (...) C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe =>PUP.Optional.SpeedUpMyPC
O4 - GS\Desktop [Invité]: FLV Player.lnk . (...) C:\Program Files (x86)\FLV Player\FLVPlayer.exe =>PUP.Optional.FLVPlayer
O4 - GS\Desktop [Invité]: Yahoo! Search.lnk . (.Pay By Ads LTD - .) C:\Users\gabriel\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.8.2\dsrlte.exe =>PUP.Optional.PaybyAds
O4 - GS\Quicklaunch [Invité]: FLV Player.lnk . (...) C:\Program Files (x86)\FLV Player\FLVPlayer.exe =>PUP.Optional.FLVPlayer
O4 - GS\Quicklaunch [Invité]: SpeedUpMyPC.lnk . (...) C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe =>PUP.Optional.SpeedUpMyPC

---\\ Winsock hijacker (Layered Service Provider) (O10) (10) - 0s
O10 - WLSP:\Catalog_Entries\000000000001\Winsock LSP File . (...) -- C:\Windows\System32\MyOSProtect.dll (Not File) (Hijacker.Winsock)
O10 - WLSP:\Catalog_Entries\000000000002\Winsock LSP File . (...) -- C:\Windows\System32\MyOSProtect.dll (Not File) (Hijacker.Winsock)
O10 - WLSP:\Catalog_Entries\000000000003\Winsock LSP File . (...) -- C:\Windows\System32\MyOSProtect.dll (Not File) (Hijacker.Winsock)
O10 - WLSP:\Catalog_Entries\000000000004\Winsock LSP File . (...) -- C:\Windows\System32\MyOSProtect.dll (Not File) (Hijacker.Winsock)
O10 - WLSP:\Catalog_Entries\000000000015\Winsock LSP File . (...) -- C:\Windows\System32\MyOSProtect.dll (Not File) (Hijacker.Winsock)
O10 - WLSP:\Catalog_Entries64\000000000001\Winsock LSP File . (.MyOSCompany.) -- C:\windows\system32\MyOSProtect64.dll (Hijacker.Winsock)
O10 - WLSP:\Catalog_Entries64\000000000002\Winsock LSP File . (.MyOSCompany.) -- C:\windows\system32\MyOSProtect64.dll (Hijacker.Winsock)
O10 - WLSP:\Catalog_Entries64\000000000003\Winsock LSP File . (.MyOSCompany.) -- C:\windows\system32\MyOSProtect64.dll (Hijacker.Winsock)
O10 - WLSP:\Catalog_Entries64\000000000004\Winsock LSP File . (.MyOSCompany.) -- C:\windows\system32\MyOSProtect64.dll (Hijacker.Winsock)
O10 - WLSP:\Catalog_Entries64\000000000015\Winsock LSP File . (.MyOSCompany.) -- C:\windows\system32\MyOSProtect64.dll (Hijacker.Winsock)

---\\ Modification Domaine/Adresses DNS (O17) (9) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 129.194.4.32 129.194.8.7 129.194.4.6
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = unige.ch
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 129.194.4.32 129.194.8.7 129.194.4.6
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpDomain = unige.ch
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 129.194.4.32 129.194.8.7 129.194.4.6
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpDomain = unige.ch

---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) (1) - 0s
O20 - AppInit_DLLs: . (...) - C:\Users\gabriel\AppData\Local\Smartbar\Application\Resources\crdlil64.dll =>PUP.Optional.SmartBar

---\\ Liste des services NT non Microsoft et non désactivés (O23) (23) - 1s
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\windows\system32\atiesrxx.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) . (.globalUpdate - globalUpdate Update.) - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe =>PUP.Optional.GlobalUpdate
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation - IAStorDataSvc.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) . (.Copyright CANON INC. 2006-2010 All Rights Reserved - Inkjet Printer/Scanner/Fax Extended Survey.) - C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
O23 - Service: Intel(R) PROSet Monitoring Service (Intel(R) PROSet Monitoring Service) . (.Intel Corporation - Intel® PROSet Monitoring Service.) - C:\Windows\system32\IProsetMonitor.exe
O23 - Service: Intel(R) Identity Protection Technology Host Interface Serv (jhi_service) . (.Intel Corporation - Intel IPT Host Interface Service.) - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MaintainerSvc1.92.5302915 (MaintainerSvc1.92.5302915) . (...) - C:\ProgramData\ecbaef90-5696-41e1-a1c3-3e8112ce2840\maintainer.exe =>PUP.Optional.MaintainerSvc
O23 - Service: MaintainerSvc2.13.426751 (MaintainerSvc2.13.426751) . (...) - C:\ProgramData\80810f5c-7b66-4b02-af93-03f2b7680a45\maintainer.exe =>PUP.Optional.MaintainerSvc
O23 - Service: NewPlayer (NewPlayer) . (.Copyright (C) 2014 - .) - C:\Program Files (x86)\ver5NewPlayer\V7NewPlayerwL178.exe =>PUP.Optional.NewPlayer
O23 - Service: NewVideoPlayer Updater Service (NewVideoPlayerUpdaterService) . (.Copyright © 2014 - NewVideoPlayerUpdaterService.) - C:\Program Files (x86)\NewPlayer\NewVideoPlayerUpdaterService.exe =>PUP.Optional.NewPlayer
O23 - Service: Novell Identity Store (Novell Identity Store) . (.Novell, Inc - micasad.exe.) - C:\Program Files (x86)\Novell\CASA\bin\micasad.exe
O23 - Service: Protect Monitor (ProtectMonitor) . (...) - C:\monitorsvc.exe =>Trojan.BitCoinMiner
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) . (.Sonic Solutions - RoxWatch12 Module.) - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: scores (scores) . (...) - C:\Windows\score.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Update Framed Display (Update Framed Display) . (...) - C:\Program Files (x86)\Framed Display\updateFramedDisplay.exe =>PUP.Optional.FramedDisplay
O23 - Service: Update glindorus (Update glindorus) . (...) - C:\Program Files (x86)\glindorus\updateglindorus.exe =>PUP.Optional.glindorus
O23 - Service: Util Framed Display (Util Framed Display) . (...) - C:\Program Files (x86)\Framed Display\bin\utilFramedDisplay.exe =>PUP.Optional.FramedDisplay
O23 - Service: Util glindorus (Util glindorus) . (...) - C:\Program Files (x86)\glindorus\bin\utilglindorus.exe =>PUP.Optional.glindorus

---\\ Tâches planifiées en automatique (O39) (73) - 5s
[MD5.E768C1786C9C44D945A225D62DD534A3] [APT] [4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-1] (.app.) -- C:\Program Files (x86)\Browsers Apps-\Browsers Apps--codedownloader.exe [1095040] =>PUP.Optional.CrossRider
[MD5.B6CE609CCA78C22799B133FA11637521] [APT] [4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-11] (.app.) -- C:\Program Files (x86)\Browsers Apps-\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-11.exe [1950592] =>PUP.Optional.CrossRider
[MD5.B6CE609CCA78C22799B133FA11637521] [APT] [4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-3] (.app.) -- C:\Program Files (x86)\Browsers Apps-\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-3.exe [1950592] =>PUP.Optional.CrossRider
[MD5.7576606493C9444C339D42A9929DCE8D] [APT] [4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-4] (.app.) -- C:\Program Files (x86)\Browsers Apps-\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-4.exe [1494912] =>PUP.Optional.CrossRider
[MD5.86F0E7B631A0A8A7674757926C204DD6] [APT] [4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5] (.app.) -- C:\Program Files (x86)\Browsers Apps-\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5.exe [996224] =>PUP.Optional.CrossRider
[MD5.86F0E7B631A0A8A7674757926C204DD6] [APT] [4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5_user] (.app.) -- C:\Program Files (x86)\Browsers Apps-\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5.exe [996224] =>PUP.Optional.CrossRider
[MD5.02DCFD4CCFDEB29C29816670D2175E01] [APT] [4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-6] (.app.) -- C:\Program Files (x86)\Browsers Apps-\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-6.exe [1251712] =>PUP.Optional.CrossRider
[MD5.E768C1786C9C44D945A225D62DD534A3] [APT] [4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-7] (.app.) -- C:\Program Files (x86)\Browsers Apps-\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-7.exe [1095040] =>PUP.Optional.CrossRider
[MD5.4769DE7294FAD1CB42213D1F49C7A3F8] [APT] [6dd9516d-ead4-47a9-b3d2-d447fe9cc131] (.Copyright © 2014.) -- C:\Program Files (x86)\Browsers Apps-\6dd9516d-ead4-47a9-b3d2-d447fe9cc131.exe [32128] =>PUP.Optional.CrossRider
[MD5.6C624641A4563E036C305CE7C3D41E95] [APT] [7fc7d17b-ba69-4bc7-ba33-2c036a5f94b3] (.app.) -- C:\Program Files (x86)\Browsers Apps-\7fc7d17b-ba69-4bc7-ba33-2c036a5f94b3.exe [356224] =>PUP.Optional.CrossRider
[MD5.E3FB05F33E1404AD606B1E1FE7C323C3] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [998104]
[MD5.9B3355B29942AF67F014EA90CE1EA960] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [268976]
[MD5.87D3B83809ED4FCD0CF7B29569096D42] [APT] [AffiliatedUpdate] (...) -- C:\Users\gabriel\AppData\Roaming\AffiliatedUpdate\UpdateProc\UpdateTask.exe [104448]
[MD5.87D3B83809ED4FCD0CF7B29569096D42] [APT] [bench-sys] (...) -- C:\Users\gabriel\AppData\Roaming\AffiliatedUpdate\UpdateProc\UpdateTask.exe [104448]
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-1 - (.app.) -- C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-1.job [2762] =>PUP.Optional.CrossRider
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-11 - (.app.) -- C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-11.job [4486] =>PUP.Optional.CrossRider
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-3 - (.app.) -- C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-3.job [3804] =>PUP.Optional.CrossRider
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-4 - (.app.) -- C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-4.job [3804] =>PUP.Optional.CrossRider
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5 - (.app.) -- C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5.job [2436] =>PUP.Optional.CrossRider
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5_user - (.app.) -- C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5_user.job [2436] =>PUP.Optional.CrossRider
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-6 - (.app.) -- C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-6.job [3460] =>PUP.Optional.CrossRider
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-7 - (.app.) -- C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-7.job [3460] =>PUP.Optional.CrossRider
O39 - APT: 6dd9516d-ead4-47a9-b3d2-d447fe9cc131 - (.Copyright © 2014.) -- C:\windows\Tasks\6dd9516d-ead4-47a9-b3d2-d447fe9cc131.job [624]
O39 - APT: 7fc7d17b-ba69-4bc7-ba33-2c036a5f94b3 - (.app.) -- C:\windows\Tasks\7fc7d17b-ba69-4bc7-ba33-2c036a5f94b3.job [1464] =>PUP.Optional.CrossRider
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\windows\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT: AffiliatedUpdate - (..) -- C:\windows\Tasks\AffiliatedUpdate.job [300]
O39 - APT: bench-sys - (..) -- C:\windows\Tasks\bench-sys.job [348]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\Tasks\bench-Updater removing.job [288] =>PUP.Optional.CrossRider
O39 - APT: Automatic Planified Task - (...) -- C:\windows\Tasks\coupons_and_fun_notification_service.job [1348]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\Tasks\coupons_and_fun_updating_service.job [710]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\Tasks\globalUpdateUpdateTaskMachineCore.job [890] =>PUP.Optional.GlobalUpdate
O39 - APT: Automatic Planified Task - (...) -- C:\windows\Tasks\GoogleUpdateTaskMachineCore.job [1066]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\Tasks\GoogleUpdateTaskMachineUA.job [1070]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\Tasks\NewPlayer Update.job [410] =>PUP.Optional.NewPlayer
O39 - APT: Automatic Planified Task - (...) -- C:\windows\Tasks\NewPlayer_wd.job [390] =>PUP.Optional.NewPlayer
O39 - APT: Automatic Planified Task - (...) -- C:\windows\Tasks\SpeedUpMyPC Maintenance.job [282] =>PUP.Optional.SpeedUpMyPC
O39 - APT: Automatic Planified Task - (...) -- C:\windows\Tasks\SpeedUpMyPC Startup.job [276] =>PUP.Optional.SpeedUpMyPC
O39 - APT: Automatic Planified Task - (...) -- C:\windows\Tasks\summer_sports_helper_service.job [524]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\Tasks\xGOmrq0MzH2KqgvpQ.job [1014]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\Tasks\xGOmrq0MzH2KqgvpQfWk.job [1020]
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-1 - (.app.) -- C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-1 [5792] =>PUP.Optional.CrossRider
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-11 - (.app.) -- C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-11 [7516] =>PUP.Optional.CrossRider
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-3 - (.app.) -- C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-3 [6834] =>PUP.Optional.CrossRider
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-4 - (.app.) -- C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-4 [6834] =>PUP.Optional.CrossRider
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5 - (.app.) -- C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5 [5466] =>PUP.Optional.CrossRider
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5_user - (.app.) -- C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5_user [5480] =>PUP.Optional.CrossRider
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-6 - (.app.) -- C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-6 [6488] =>PUP.Optional.CrossRider
O39 - APT: 4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-7 - (.app.) -- C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-7 [6490] =>PUP.Optional.CrossRider
O39 - APT: 6dd9516d-ead4-47a9-b3d2-d447fe9cc131 - (.Copyright © 2014.) -- C:\windows\System32\Tasks\6dd9516d-ead4-47a9-b3d2-d447fe9cc131 [3668]
O39 - APT: 7fc7d17b-ba69-4bc7-ba33-2c036a5f94b3 - (.app.) -- C:\windows\System32\Tasks\7fc7d17b-ba69-4bc7-ba33-2c036a5f94b3 [4494] =>PUP.Optional.CrossRider
O39 - APT: Adobe Acrobat Update Task - (.Adobe Systems Incorporated.) -- C:\windows\System32\Tasks\Adobe Acrobat Update Task [3886]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\windows\System32\Tasks\Adobe Flash Player Updater [3940]
O39 - APT: AffiliatedUpdate - (..) -- C:\windows\System32\Tasks\AffiliatedUpdate [3258]
O39 - APT: bench-sys - (..) -- C:\windows\System32\Tasks\bench-sys [3244]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\bench-Updater removing [3228] =>PUP.Optional.CrossRider
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\CCleanerSkipUAC [2776]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\coupons_and_fun_notification_service [4388]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\coupons_and_fun_updating_service [3752]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\globalUpdateUpdateTaskMachineCore [3638] =>PUP.Optional.GlobalUpdate
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore [3814]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA [4066]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\LaunchSignup [4042]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\NewPlayer Update [3062] =>PUP.Optional.NewPlayer
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\NewPlayer_wd [2982] =>PUP.Optional.NewPlayer
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\SpeedUpMyPC Maintenance [3238] =>PUP.Optional.SpeedUpMyPC
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\SpeedUpMyPC Startup [2526] =>PUP.Optional.SpeedUpMyPC
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\summer_sports_helper_service [3498]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\xGOmrq0MzH2KqgvpQ [4058]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\xGOmrq0MzH2KqgvpQfWk [4064]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\Yahoo! Search Updater [3594]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\{1C94EF23-C1D8-4267-A454-6A7F08E9CBA3} [3010]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\{4671B181-4DD2-4A72-8635-0CD1C6323CF9} [3078]
O39 - APT: Automatic Planified Task - (...) -- C:\windows\System32\Tasks\{D678EDAC-FDDB-4DC7-82D5-25612F09390F} [3232]

---\\ Logiciels installés (O42) (74) - 10s
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner
O42 - Logiciel: Framed Display - (.Framed Display.) [HKLM][64Bits] -- Framed Display =>PUP.Optional.Sambreel
O42 - Logiciel: glindorus 1.0.0 - (.glindorus.) [HKLM][64Bits] -- glindorus =>PUP.Optional.Sambreel
O42 - Logiciel: System Center 2012 Endpoint Protection - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Security Client
O42 - Logiciel: Intel(R) Network Connections 15.7.176.1 - (.Dell.) [HKLM][64Bits] -- PROSetDX
O42 - Logiciel: Microsoft Antimalware Service FR-FR Language Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {0450B7B0-AC71-44A4-AB40-4DD678DF3A8C}
O42 - Logiciel: Microsoft Antimalware - (.Microsoft Corporation.) [HKLM][64Bits] -- {0C243024-B7AF-478B-B6F1-574A4AB0E07C}
O42 - Logiciel: Microsoft Forefront Endpoint Protection 2010 Server Management - (.Microsoft Corporation.) [HKLM][64Bits] -- {0E0818E4-C87B-4211-9791-E958BD34B96C}
O42 - Logiciel: CanoScan LiDE 110 Scanner Driver - (...) [HKLM][64Bits] -- {1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_cnq2414
O42 - Logiciel: IBM SPSS Statistics 20 - (.IBM Corp.) [HKLM][64Bits] -- {2AF8017B-E503-408F-AACE-8A335452CAD2}
O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM][64Bits] -- {4C7F9B08-C9B2-42EA-93F7-5A3093430450}
O42 - Logiciel: Upek Touchchip Fingerprint Reader - (.Dell Inc..) [HKLM][64Bits] -- {4E60E212-3177-4B16-BCB3-616CCC52357D}
O42 - Logiciel: NICI (64 bit) - (.Novell, Inc..) [HKLM][64Bits] -- {559D2B32-5066-4762-A2F2-52831AC6F67B}
O42 - Logiciel: Cisco Systems VPN Client - (.Cisco Systems, Inc..) [HKLM][64Bits] -- {5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}
O42 - Logiciel: Roxio File Backup - (.Roxio.) [HKLM][64Bits] -- {60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Intel(R) Network Connections 15.7.176.1 - (.Dell.) [HKLM][64Bits] -- {8C9B6B1F-0A8E-402A-A60C-110BBB38D67E}
O42 - Logiciel: Dell Edoc Viewer - (.Dell Inc.) [HKLM][64Bits] -- {8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}
O42 - Logiciel: RBVirtualFolder64Inst - (.Roxio, Inc..) [HKLM][64Bits] -- {9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}
O42 - Logiciel: BioAPI Framework - (.Dell Inc..) [HKLM][64Bits] -- {9DAED4FC-2B0E-4F3F-8141-F2ABF02CCFCB}
O42 - Logiciel: Buzzdock - (.Alactro LLC.) [HKLM][64Bits] -- {ac225167-00fc-452d-94c5-bb93600e7d9a} =>PUP.Optional.BuzzDock
O42 - Logiciel: CASA - (.Novell.) [HKLM][64Bits] -- {CE255082-97B3-4D35-A92E-C24075D7D363}
O42 - Logiciel: Microsoft Security Client FR-FR Language Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {DC911ADF-7B60-40F2-A112-FB1EB6402D07}
O42 - Logiciel: NewPlayer - (.NewPlayer-software.) [HKLM][64Bits] -- 36C865CC-38FF-12E8-F95D-49EFB0316B5E
O42 - Logiciel: Adobe Acrobat 8 Professional - English, Français, Deutsch - (.Adobe Systems.) [HKLM][64Bits] -- Adobe Acrobat 8 Professional - English, Français, Deutsch
O42 - Logiciel: Adobe Flash Player 18 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 18 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI
O42 - Logiciel: Browsers Apps- - (.app.) [HKLM][64Bits] -- Browsers Apps- =>PUP.Optional.CrossRider
O42 - Logiciel: Canon Inkjet Printer/Scanner/Fax Extended Survey Program - (...) [HKLM][64Bits] -- CANONIJPLM100
O42 - Logiciel: Canon Solution Menu EX - (...) [HKLM][64Bits] -- CanonSolutionMenuEX
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: Mozilla Firefox 9.0 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 9.0 (x86 fr)
O42 - Logiciel: Canon MP Navigator EX 4.0 - (...) [HKLM][64Bits] -- MP Navigator EX 4.0
O42 - Logiciel: NewPlayer - (.SoftForce LLC.) [HKLM][64Bits] -- NewPlayer
O42 - Logiciel: Remote Desktop Access (VuuPC) - (.CMI Limited.) [HKLM][64Bits] -- VOPackage =>PUP.Optional.Downware
O42 - Logiciel: Web Protect for Windows - (.PC Publishing.) [HKLM][64Bits] -- wp-dcollect-tgu =>PUP.Optional.WebProtect
O42 - Logiciel: Software Update Helper - (.Boxore OU..) [HKLM][64Bits] -- {006E6A46-8D55-4F10-BBA8-2C9653B4278B} =>PUP.Optional.Boxore
O42 - Logiciel: ATI Catalyst Control Center - (...) [HKLM][64Bits] -- {055EE59D-217B-43A7-ABFF-507B966405D8}
O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM][64Bits] -- {2136B58D-D966-49C7-AD88-011FB089CCBD}
O42 - Logiciel: Skype™ 7.5 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
O42 - Logiciel: Java 8 Update 31 - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83218031F0}
O42 - Logiciel: Intel(R) Identity Protection Technology 1.0.71.0 - (.Intel Corporation.) [HKLM][64Bits] -- {2C43790E-8470-1027-82D3-DF319F3C410F}
O42 - Logiciel: PhotoShowExpress - (.Sonic Solutions.) [HKLM][64Bits] -- {3250260C-7A95-4632-893B-89657EB5545B}
O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {3E29EE6C-963A-4aae-86C1-DC237C4A49FC}
O42 - Logiciel: Roxio BackOnTrack - (.Roxio.) [HKLM][64Bits] -- {5A06423A-210C-49FB-950E-CB0EB8C5CEC7}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
O42 - Logiciel: Roxio Express Labeler 3 - (.Roxio.) [HKLM][64Bits] -- {6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM][64Bits] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM][64Bits] -- {6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}
O42 - Logiciel: Roxio Burn - (.Roxio.) [HKLM][64Bits] -- {7746BFAA-2B5D-4FFD-A0E8-4558F4668105}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM][64Bits] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: Sonic CinePlayer Decoder Pack - (.Sonic Solutions.) [HKLM][64Bits] -- {9A00EC4E-27E1-42C4-98DD-662F32AC8870}
O42 - Logiciel: Roxio Activation Module - (.Roxio.) [HKLM][64Bits] -- {A121EEDE-C68F-461D-91AA-D48BA226AF1C}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM][64Bits] -- {A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001824147215}
O42 - Logiciel: Adobe Reader XI (11.0.12) - Français - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1036-7B44-AB0000000001}
O42 - Logiciel: DirectX 9 Runtime - (.Sonic Solutions.) [HKLM][64Bits] -- {AF9E97C1-7431-426D-A8D5-ABE40995C0B1}
O42 - Logiciel: LPT System Updater Service - (.LPT.) [HKLM][64Bits] -- {BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24} =>PUP.Optional.Linkury
O42 - Logiciel: Muvic Smartbar - (.PinWid Ltd..) [HKLM][64Bits] -- {C8428739-5207-4817-9F19-69FA77018633} =>PUP.Optional.SmartBar
O42 - Logiciel: Boxore Client - (.Boxore OU.) [HKLM][64Bits] -- {D8D8A342-0E9F-47EA-A35E-CF431B50B286} =>PUP.Optional.Boxore
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM][64Bits] -- {EF56258E-0326-48C5-A86C-3BAC26FC15DF}
O42 - Logiciel: NICI (Shared) U.S./Worldwide (128 bit) (2.7.6-1) - (...) [HKLM][64Bits] -- {F02DBC5D-33E3-45E9-B0F8-B7745229ED1C}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM][64Bits] -- {F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM][64Bits] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: Intel(R) Control Center - (.Intel Corporation.) [HKLM][64Bits] -- {F8A9085D-4C7A-41a9-8A77-C8998A96C421}
O42 - Logiciel: Extended Update - (...) [HKCU][64Bits] -- AffiliatedUpdate =>PUP.Optional.Dealply
O42 - Logiciel: CCleaner Packages - (...) [HKCU][64Bits] -- CCleaner Packages =>PUP.Optional.InstallCore
O42 - Logiciel: FLV Player - (...) [HKCU][64Bits] -- FLV Player
O42 - Logiciel: Yahoo! Search - (.Pay-By-Ads.) [HKCU][64Bits] -- Yahoo! Search
O42 - Logiciel: Muvic Smartbar Engine - (.PinWid Ltd..) [HKCU][64Bits] -- {085992c3-6315-4628-acd6-da11e3f8c7d8} =>PUP.Optional.SmartBar

---\\ HKCU & HKLM Software Keys (131) - 10s
HKLM\SOFTWARE\Wow6432Node\590381a3-13d3-4ff7-a240-69fe15075892 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Adobe
HKLM\SOFTWARE\Wow6432Node\Analog Devices
HKLM\SOFTWARE\Wow6432Node\ATI
HKLM\SOFTWARE\Wow6432Node\ATI Technologies
HKLM\SOFTWARE\Wow6432Node\awesomehpSoftware =>PUP.Optional.AwesomeHP
HKLM\SOFTWARE\Wow6432Node\Babylon =>PUP.Optional.Babylon
HKLM\SOFTWARE\Wow6432Node\Bench
HKLM\SOFTWARE\Wow6432Node\Boxore =>PUP.Optional.Boxore
HKLM\SOFTWARE\Wow6432Node\Browsers Apps- =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Browsers Apps--nv =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Canon
HKLM\SOFTWARE\Wow6432Node\Cisco Systems
HKLM\SOFTWARE\Wow6432Node\CLSYSTEM
HKLM\SOFTWARE\Wow6432Node\CyberLink
HKLM\SOFTWARE\Wow6432Node\Debug
HKLM\SOFTWARE\Wow6432Node\DeterministicNetworks
HKLM\SOFTWARE\Wow6432Node\Duuqu =>PUP.Optional.FrameFox
HKLM\SOFTWARE\Wow6432Node\Framed Display =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Freesofttoday =>PUP.Optional.Multiplug
HKLM\SOFTWARE\Wow6432Node\glindorus =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\GlobalUpdate =>PUP.Optional.GlobalUpdate
HKLM\SOFTWARE\Wow6432Node\Google
HKLM\SOFTWARE\Wow6432Node\illiminable
HKLM\SOFTWARE\Wow6432Node\IM Providers
HKLM\SOFTWARE\Wow6432Node\InstallCore =>PUP.Optional.InstallCore
HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions
HKLM\SOFTWARE\Wow6432Node\Intel
HKLM\SOFTWARE\Wow6432Node\JavaSoft
HKLM\SOFTWARE\Wow6432Node\JreMetrics
HKLM\SOFTWARE\Wow6432Node\Lake
HKLM\SOFTWARE\Wow6432Node\Licenses
HKLM\SOFTWARE\Wow6432Node\Macromedia
HKLM\SOFTWARE\Wow6432Node\Macrovision
HKLM\SOFTWARE\Wow6432Node\MaxPower
HKLM\SOFTWARE\Wow6432Node\MAXSOFT-OCRON
HKLM\SOFTWARE\Wow6432Node\MicroVision
HKLM\SOFTWARE\Wow6432Node\Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\mysearchdial =>PUP.Optional.MySearchDial
HKLM\SOFTWARE\Wow6432Node\NetWare
HKLM\SOFTWARE\Wow6432Node\Network Associates
HKLM\SOFTWARE\Wow6432Node\NewPlayer
HKLM\SOFTWARE\Wow6432Node\Novell
HKLM\SOFTWARE\Wow6432Node\Ntpad
HKLM\SOFTWARE\Wow6432Node\NTRU Cryptosystems
HKLM\SOFTWARE\Wow6432Node\ODBC
HKLM\SOFTWARE\Wow6432Node\PCTRunner =>PUP.Optional.WebProtect
HKLM\SOFTWARE\Wow6432Node\Rainbow Technologies
HKLM\SOFTWARE\Wow6432Node\Roxio
HKLM\SOFTWARE\Wow6432Node\Skype
HKLM\SOFTWARE\Wow6432Node\Software
HKLM\SOFTWARE\Wow6432Node\Sonic
HKLM\SOFTWARE\Wow6432Node\supTab =>PUP.Optional.SupTab
HKLM\SOFTWARE\Wow6432Node\supWPM =>PUP.Optional.WpManager
HKLM\SOFTWARE\Wow6432Node\Systweak =>PUP.Optional.Systweak
HKLM\SOFTWARE\Wow6432Node\Tutorials =>PUP.Optional.AgenceExclusive
HKLM\SOFTWARE\Wow6432Node\Uniblue =>PUP.Optional.Uniblue
HKLM\SOFTWARE\Wow6432Node\Volatile
HKLM\SOFTWARE\Wow6432Node\Windows
HKLM\SOFTWARE\Wow6432Node\Wpm
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications
HKCU\SOFTWARE\1ClickDownload =>PUP.Optional.1ClickDownloader
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\AffiliatedUpdate
HKCU\SOFTWARE\Analog Devices
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\ATI
HKCU\SOFTWARE\Boxore =>PUP.Optional.Boxore
HKCU\SOFTWARE\Canon
HKCU\SOFTWARE\Chromium
HKCU\SOFTWARE\coupons and fun
HKCU\SOFTWARE\couponsandfun
HKCU\SOFTWARE\CyberLink
HKCU\SOFTWARE\DeterministicNetworks
HKCU\SOFTWARE\Duuqu =>PUP.Optional.FrameFox
HKCU\SOFTWARE\Framed Display =>PUP.Optional.Sambreel
HKCU\SOFTWARE\freesofttoday =>PUP.Optional.Multiplug
HKCU\SOFTWARE\Gameo =>PUP.Optional.Gameo
HKCU\SOFTWARE\Genesis =>PUP.Optional.Genesis
HKCU\SOFTWARE\glindorus =>PUP.Optional.Sambreel
HKCU\SOFTWARE\globalUpdate =>PUP.Optional.GlobalUpdate
HKCU\SOFTWARE\GoldenGate
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\Hewlett-Packard
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\Iminent =>PUP.Optional.IMBooster
HKCU\SOFTWARE\InstallCore =>PUP.Optional.InstallCore
HKCU\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions
HKCU\SOFTWARE\Intel
HKCU\SOFTWARE\JavaSoft
HKCU\SOFTWARE\Licenses
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\Macrovision
HKCU\SOFTWARE\mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\mysearchdial =>PUP.Optional.MySearchDial
HKCU\SOFTWARE\mysearchdial.com =>PUP.Optional.MySearchDial
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\Netware
HKCU\SOFTWARE\Novell
HKCU\SOFTWARE\Novell-iPrint
HKCU\SOFTWARE\ODBC
HKCU\SOFTWARE\Optimizer Pro =>PUP.Optional.OptimizerPro
HKCU\SOFTWARE\PCTRunner =>PUP.Optional.WebProtect
HKCU\SOFTWARE\PerformerSoft LLC =>PUP.Optional.PerformerSoft
HKCU\SOFTWARE\Piriform
HKCU\SOFTWARE\Realtek
HKCU\SOFTWARE\Roxio
HKCU\SOFTWARE\Skype
HKCU\SOFTWARE\Smartbar =>PUP.Optional.SmartBar
HKCU\SOFTWARE\SmartbarBackup =>PUP.Optional.SmartBar
HKCU\SOFTWARE\SmartbarLog =>PUP.Optional.SmartBar
HKCU\SOFTWARE\Sonic
HKCU\SOFTWARE\StormWatch =>PUP.Optional.StormWatch
HKCU\SOFTWARE\Systweak =>PUP.Optional.Systweak
HKCU\SOFTWARE\TeleCharger
HKCU\SOFTWARE\test
HKCU\SOFTWARE\Tutorials =>PUP.Optional.AgenceExclusive
HKCU\SOFTWARE\TutoTag =>PUP.Optional.AgenceExclusive
HKCU\SOFTWARE\xGOmrq0MzH2KqgvpQ
HKCU\SOFTWARE\xGOmrq0MzH2KqgvpQfWk
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\FDA
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\Browsers Apps- =>PUP.Optional.CrossRider
HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider
HKCU\SOFTWARE\AppDataLow\Software\GenericAddon
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft
HKCU\SOFTWARE\AppDataLow\Software\SelectionTool

---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) (212) - 9s
O43 - CFD: 2013/10/07 11:05:37 - [] D -- C:\Program Files (x86)\Adobe
O43 - CFD: 2013/10/04 16:17:20 - [] D -- C:\Program Files (x86)\Analog Devices
O43 - CFD: 2011/05/25 13:17:30 - [] D -- C:\Program Files (x86)\ATI Technologies
O43 - CFD: 2014/05/04 11:13:03 - [] D -- C:\Program Files (x86)\Bench
O43 - CFD: 2011/06/06 10:17:49 - [] D -- C:\Program Files (x86)\Bing Bar Installer
O43 - CFD: 2014/09/30 17:04:48 - [] D -- C:\Program Files (x86)\Boxore =>PUP.Optional.Boxore
O43 - CFD: 2015/01/06 17:45:13 - [] D -- C:\Program Files (x86)\Browsers Apps- =>PUP.Optional.CrossRider
O43 - CFD: 2013/10/27 14:30:40 - [] D -- C:\Program Files (x86)\Canon
O43 - CFD: 2013/10/07 09:58:00 - [] D -- C:\Program Files (x86)\Cisco Systems
O43 - CFD: 2015/02/10 17:43:29 - [] D -- C:\Program Files (x86)\Common Files
O43 - CFD: 2015/04/02 12:08:12 - [] D -- C:\Program Files (x86)\coupons and fun
O43 - CFD: 2011/05/25 13:24:17 - [] D -- C:\Program Files (x86)\CyberLink
O43 - CFD: 2011/05/25 13:17:49 - [] D -- C:\Program Files (x86)\Dell
O43 - CFD: 2014/04/30 12:33:03 - [] D -- C:\Program Files (x86)\Duuqu =>PUP.Optional.Duuqu
O43 - CFD: 2013/11/18 12:20:12 - [] D -- C:\Program Files (x86)\FLV Player
O43 - CFD: 2015/07/17 16:04:38 - [] D -- C:\Program Files (x86)\Framed Display =>PUP.FramedDisplay
O43 - CFD: 2015/07/17 16:05:24 - [] D -- C:\Program Files (x86)\glindorus =>PUP.Glindorus
O43 - CFD: 2014/09/05 10:42:44 - [] D -- C:\Program Files (x86)\globalUpdate =>PUP.Optional.GlobalUpdate
O43 - CFD: 2014/05/04 11:13:03 - [] D -- C:\Program Files (x86)\Google
O43 - CFD: 2014/02/25 18:29:00 - [] D -- C:\Program Files (x86)\HiDefMedia =>PUP.Optional.HiDefMedia
O43 - CFD: 2013/05/29 17:00:08 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 2011/05/25 13:20:48 - [] D -- C:\Program Files (x86)\Intel
O43 - CFD: 2013/10/07 09:43:07 - [] D -- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 2015/02/10 17:43:02 - [] D -- C:\Program Files (x86)\Java
O43 - CFD: 2014/09/05 10:44:34 - [] D -- C:\Program Files (x86)\LPT
O43 - CFD: 2012/05/07 09:50:47 - [] D -- C:\Program Files (x86)\McAfee
O43 - CFD: 2011/06/06 10:17:30 - [0] D -- C:\Program Files (x86)\Microsoft
O43 - CFD: 2012/08/02 17:13:21 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services
O43 - CFD: 2012/08/02 17:13:16 - [] D -- C:\Program Files (x86)\Microsoft Office
O43 - CFD: 2012/05/07 09:56:41 - [] D -- C:\Program Files (x86)\Microsoft Security Client
O43 - CFD: 2014/08/18 09:20:10 - [] D -- C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD: 2012/08/02 17:13:54 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio 8
O43 - CFD: 2012/08/02 17:14:41 - [] D -- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 2015/04/02 12:08:19 - [] D -- C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 2012/08/02 17:14:50 - [] D -- C:\Program Files (x86)\MSBuild
O43 - CFD: 2011/07/26 13:00:19 - [0] D -- C:\Program Files (x86)\MSXML 4.0
O43 - CFD: 2013/11/18 12:20:15 - [] D -- C:\Program Files (x86)\Mysearchdial =>PUP.Optional.MySearchDial
O43 - CFD: 2015/02/21 14:05:30 - [] D -- C:\Program Files (x86)\NewPlayer =>PUP.Optional.NewPlayer
O43 - CFD: 2013/10/04 16:30:36 - [] D -- C:\Program Files (x86)\Novell
O43 - CFD: 2015/03/29 14:56:13 - [] D -- C:\Program Files (x86)\Pay-By-Ads =>PUP.Optional.PaybyAds
O43 - CFD: 2014/09/30 17:06:31 - [] D -- C:\Program Files (x86)\PCTRunner =>PUP.Optional.WebProtect
O43 - CFD: 2014/04/30 12:03:02 - [0] D -- C:\Program Files (x86)\predm =>PUP.Optional.Downware
O43 - CFD: 2014/04/30 12:05:57 - [0] D -- C:\Program Files (x86)\QueeeNCOupon =>PUP.Optional.Multiplug
O43 - CFD: 2009/07/14 07:32:38 - [] D -- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 2011/05/25 13:33:03 - [] D -- C:\Program Files (x86)\Roxio
O43 - CFD: 2014/03/07 14:09:47 - [] D -- C:\Program Files (x86)\SearchProtect923167 =>PUP.SearchProtect
O43 - CFD: 2015/05/28 10:07:57 - [] RD -- C:\Program Files (x86)\Skype
O43 - CFD: 2014/04/30 12:06:41 - [0] D -- C:\Program Files (x86)\SmuartComparre =>PUP.Optional.Multiplug
O43 - CFD: 2014/09/30 17:02:40 - [] D -- C:\Program Files (x86)\Software
O43 - CFD: 2015/05/28 10:09:42 - [] D -- C:\Program Files (x86)\Summer Sports
O43 - CFD: 2014/04/30 12:02:38 - [] D -- C:\Program Files (x86)\SupTab =>PUP.Optional.SupTab
O43 - CFD: 2009/07/14 06:57:06 - [0] HD -- C:\Program Files (x86)\Uninstall Information
O43 - CFD: 2014/09/05 10:41:31 - [] D -- C:\Program Files (x86)\ver5NewPlayer =>PUP.Optional.NewPlayer
O43 - CFD: 2013/07/22 13:25:29 - [] D -- C:\Program Files (x86)\Windows Defender
O43 - CFD: 2010/11/21 08:19:00 - [] D -- C:\Program Files (x86)\Windows Mail
O43 - CFD: 2010/11/21 08:19:00 - [] D -- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 2009/07/14 07:32:38 - [] D -- C:\Program Files (x86)\Windows NT
O43 - CFD: 2010/11/21 08:19:00 - [] D -- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 2010/11/21 05:31:38 - [] D -- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 2010/11/21 08:19:00 - [] D -- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 2011/02/12 13:11:56 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2011/02/12 13:12:00 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2013/10/27 14:27:20 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon CanoScan LiDE 110 Manual
O43 - CFD: 2013/10/27 14:27:58 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
O43 - CFD: 2013/10/07 21:15:24 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CanoScan LiDE 110
O43 - CFD: 2011/05/25 13:17:30 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
O43 - CFD: 2014/10/02 10:30:42 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
O43 - CFD: 2013/10/07 09:58:01 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco Systems VPN Client
O43 - CFD: 2011/05/25 13:43:03 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 9.5
O43 - CFD: 2010/11/21 08:30:09 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 2014/02/05 22:11:59 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 2013/10/07 10:05:58 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IBM SPSS Statistics
O43 - CFD: 2011/05/25 13:16:54 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
O43 - CFD: 2015/02/10 17:43:14 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 2009/07/14 06:57:09 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2012/08/02 17:15:36 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O43 - CFD: 2014/08/18 09:20:18 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
O43 - CFD: 2012/08/02 17:13:57 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005
O43 - CFD: 2014/10/01 19:58:12 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewPlayer =>PUP.Optional.NewPlayer
O43 - CFD: 2013/06/07 10:03:18 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Novell CASA
O43 - CFD: 2014/09/05 10:42:00 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip =>PUP.Optional.PepperZip
O43 - CFD: 2011/05/25 13:33:18 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio Creator Starter
O43 - CFD: 2012/08/02 17:15:36 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
O43 - CFD: 2014/10/11 09:04:08 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 2014/10/02 10:27:58 - [0] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2010/11/21 08:29:40 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 2014/01/16 10:06:02 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue =>PUP.Optional.Uniblue
O43 - CFD: 2014/04/30 12:06:41 - [] D -- C:\ProgramData\280e3b80f224d226
O43 - CFD: 2014/10/02 11:28:18 - [0] D -- C:\ProgramData\374311380
O43 - CFD: 2015/07/17 16:00:47 - [] D -- C:\ProgramData\80810f5c-7b66-4b02-af93-03f2b7680a45
O43 - CFD: 2013/10/07 11:08:05 - [] D -- C:\ProgramData\Adobe
O43 - CFD: 2013/10/27 09:02:45 - [] D -- C:\ProgramData\APN
O43 - CFD: 2009/07/14 07:08:56 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 2011/05/25 13:43:01 - [] D -- C:\ProgramData\ATI
O43 - CFD: 2013/05/29 17:11:11 - [0] D -- C:\ProgramData\Babylon =>PUP.Optional.Babylon
O43 - CFD: 2011/06/06 09:43:36 - [0] SHD -- C:\ProgramData\Bureau
O43 - CFD: 2013/10/27 15:23:24 - [] D -- C:\ProgramData\CanonIJ
O43 - CFD: 2015/07/06 23:25:54 - [] D -- C:\ProgramData\CanonIJPLM
O43 - CFD: 2013/10/27 13:29:35 - [] HD -- C:\ProgramData\CanonIJScan
O43 - CFD: 2013/10/27 14:29:41 - [] HD -- C:\ProgramData\CanonIJSolutionMenuEX
O43 - CFD: 2013/10/27 14:27:57 - [] D -- C:\ProgramData\CanonIJWSpt
O43 - CFD: 2009/07/14 07:08:56 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 2009/07/14 07:08:56 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 2015/07/17 16:00:45 - [] D -- C:\ProgramData\ecbaef90-5696-41e1-a1c3-3e8112ce2840
O43 - CFD: 2011/06/06 09:43:36 - [0] SHD -- C:\ProgramData\Favoris
O43 - CFD: 2009/07/14 07:08:56 - [0] SHD -- C:\ProgramData\Favorites
O43 - CFD: 2014/08/31 07:21:09 - [] D -- C:\ProgramData\FLEXnet
O43 - CFD: 2013/10/08 08:12:29 - [] D -- C:\ProgramData\Hewlett-Packard
O43 - CFD: 2014/04/30 12:04:17 - [] D -- C:\ProgramData\IePluginService =>PUP.Optional.IePluginService
O43 - CFD: 2011/05/25 13:31:33 - [] D -- C:\ProgramData\Macrovision
O43 - CFD: 2012/05/07 09:51:04 - [] D -- C:\ProgramData\McAfee
O43 - CFD: 2011/06/06 09:43:36 - [0] SHD -- C:\ProgramData\Menu Démarrer
O43 - CFD: 2012/08/02 17:14:41 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 2014/05/13 16:39:01 - [] D -- C:\ProgramData\Microsoft Help
O43 - CFD: 2011/06/06 09:43:36 - [0] SHD -- C:\ProgramData\Modèles
O43 - CFD: 2013/10/04 16:28:01 - [] D -- C:\ProgramData\Novell
O43 - CFD: 2015/02/10 17:43:52 - [] D -- C:\ProgramData\Oracle
O43 - CFD: 2011/05/25 13:32:53 - [] D -- C:\ProgramData\PhotoShow Shared Assets
O43 - CFD: 2014/05/04 11:13:03 - [0] D -- C:\ProgramData\QueeeNCOupon =>PUP.Optional.Multiplug
O43 - CFD: 2011/05/25 13:43:08 - [] D -- C:\ProgramData\Roxio
O43 - CFD: 2013/10/07 10:06:03 - [] D -- C:\ProgramData\SafeNet Sentinel
O43 - CFD: 2015/06/19 15:01:52 - [] D -- C:\ProgramData\Skype
O43 - CFD: 2014/05/04 11:13:03 - [0] D -- C:\ProgramData\SmuartComparre =>PUP.Optional.Multiplug
O43 - CFD: 2013/10/04 16:35:45 - [] D -- C:\ProgramData\Sonic
O43 - CFD: 2013/10/04 16:17:21 - [] D -- C:\ProgramData\SonicFocus
O43 - CFD: 2013/10/07 10:06:00 - [] D -- C:\ProgramData\SPSS
O43 - CFD: 2009/07/14 07:08:56 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 2011/05/25 13:13:44 - [] D -- C:\ProgramData\Sun
O43 - CFD: 2014/04/30 10:15:54 - [] AD -- C:\ProgramData\Temp
O43 - CFD: 2009/07/14 07:08:56 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 2011/05/25 13:33:27 - [] D -- C:\ProgramData\Uninstall
O43 - CFD: 2012/03/07 17:49:19 - [] D -- C:\ProgramData\Wave Systems Corp
O43 - CFD: 2014/02/04 20:30:05 - [] D -- C:\ProgramData\WPM =>PUP.Optional.WpManager
O43 - CFD: 2013/10/07 11:08:12 - [] D -- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 2011/06/06 11:20:32 - [] D -- C:\Program Files (x86)\Common Files\Cisco Systems
O43 - CFD: 2011/05/25 13:24:18 - [] D -- C:\Program Files (x86)\Common Files\CyberLink
O43 - CFD: 2013/05/29 17:00:07 - [] D -- C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 2015/02/10 17:43:29 - [] D -- C:\Program Files (x86)\Common Files\Java
O43 - CFD: 2013/10/07 11:08:06 - [] D -- C:\Program Files (x86)\Common Files\Macrovision Shared
O43 - CFD: 2012/08/02 17:24:07 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared
O43 - CFD: 2011/05/25 13:16:50 - [] D -- C:\Program Files (x86)\Common Files\postureAgent
O43 - CFD: 2011/05/25 13:33:13 - [] D -- C:\Program Files (x86)\Common Files\PX Storage Engine
O43 - CFD: 2011/05/25 13:33:27 - [] D -- C:\Program Files (x86)\Common Files\Roxio Shared
O43 - CFD: 2009/07/14 05:20:08 - [] D -- C:\Program Files (x86)\Common Files\Services
O43 - CFD: 2014/10/11 09:04:07 - [] D -- C:\Program Files (x86)\Common Files\Skype
O43 - CFD: 2011/05/25 13:33:00 - [] D -- C:\Program Files (x86)\Common Files\Sonic Shared
O43 - CFD: 2009/07/14 05:20:08 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD: 2011/05/25 13:32:59 - [] D -- C:\Program Files (x86)\Common Files\SureThing Shared
O43 - CFD: 2011/11/14 18:16:38 - [] D -- C:\Program Files (x86)\Common Files\System
O43 - CFD: 2011/05/25 13:24:35 - [] D -- C:\Program Files (x86)\Common Files\Windows Live
O43 - CFD: 2014/10/02 10:28:58 - [] D -- C:\Users\gabriel\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z =>PUP.Optional.InstallCore
O43 - CFD: 2013/10/07 11:08:12 - [] D -- C:\Users\gabriel\AppData\Roaming\Adobe
O43 - CFD: 2013/11/18 12:20:17 - [] D -- C:\Users\gabriel\AppData\Roaming\AffiliatedUpdate
O43 - CFD: 2013/05/29 17:26:14 - [] D -- C:\Users\gabriel\AppData\Roaming\ATI
O43 - CFD: 2014/04/30 12:02:18 - [] D -- C:\Users\gabriel\AppData\Roaming\awesomehp =>PUP.Optional.AwesomeHP
O43 - CFD: 2013/05/30 14:56:06 - [] D -- C:\Users\gabriel\AppData\Roaming\Babylon =>PUP.Optional.Babylon
O43 - CFD: 2014/10/02 10:31:37 - [0] D -- C:\Users\gabriel\AppData\Roaming\BRT
O43 - CFD: 2013/10/27 13:29:35 - [] D -- C:\Users\gabriel\AppData\Roaming\Canon
O43 - CFD: 2013/05/29 17:26:14 - [0] D -- C:\Users\gabriel\AppData\Roaming\FreeFixer
O43 - CFD: 2014/10/02 10:30:15 - [] HD -- C:\Users\gabriel\AppData\Roaming\GoldenGate
O43 - CFD: 2014/03/01 20:35:10 - [] D -- C:\Users\gabriel\AppData\Roaming\Google
O43 - CFD: 2013/10/04 16:33:41 - [] D -- C:\Users\gabriel\AppData\Roaming\Identities
O43 - CFD: 2013/05/29 17:26:14 - [] D -- C:\Users\gabriel\AppData\Roaming\Intel Corporation
O43 - CFD: 2013/05/29 17:26:14 - [] D -- C:\Users\gabriel\AppData\Roaming\Macromedia
O43 - CFD: 2013/05/29 17:26:14 - [] D -- C:\Users\gabriel\AppData\Roaming\Macrovision
O43 - CFD: 2010/11/21 08:29:40 - [0] D -- C:\Users\gabriel\AppData\Roaming\Media Center Programs
O43 - CFD: 2015/02/12 12:56:11 - [] SD -- C:\Users\gabriel\AppData\Roaming\Microsoft
O43 - CFD: 2014/09/30 17:04:15 - [] D -- C:\Users\gabriel\AppData\Roaming\Mozilla
O43 - CFD: 2013/11/18 12:20:24 - [] D -- C:\Users\gabriel\AppData\Roaming\mysearchdial =>PUP.Optional.MySearchDial
O43 - CFD: 2014/04/30 11:50:46 - [0] D -- C:\Users\gabriel\AppData\Roaming\PerformerSoft =>PUP.Optional.PerformerSoft
O43 - CFD: 2013/05/29 17:26:15 - [] D -- C:\Users\gabriel\AppData\Roaming\Roxio
O43 - CFD: 2015/07/17 16:22:34 - [] D -- C:\Users\gabriel\AppData\Roaming\Skype
O43 - CFD: 2014/04/30 12:47:51 - [0] D -- C:\Users\gabriel\AppData\Roaming\Systweak =>PUP.Optional.Systweak
O43 - CFD: 2013/05/30 14:56:07 - [] D -- C:\Users\gabriel\AppData\Roaming\Thunderbird
O43 - CFD: 2014/01/16 10:05:58 - [] D -- C:\Users\gabriel\AppData\Roaming\Uniblue =>PUP.Optional.Uniblue
O43 - CFD: 2014/09/05 10:43:29 - [] D -- C:\Users\gabriel\AppData\Roaming\VOPackage =>PUP.Optional.Downware
O43 - CFD: 2013/05/30 14:56:07 - [] D -- C:\Users\gabriel\AppData\Roaming\Wave Systems Corp
O43 - CFD: 2015/07/17 16:24:04 - [] D -- C:\Users\gabriel\AppData\Roaming\ZHP
O43 - CFD: 2013/10/07 11:08:50 - [] D -- C:\Users\gabriel\AppData\Local\Adobe
O43 - CFD: 2013/10/04 16:33:25 - [0] SHD -- C:\Users\gabriel\AppData\Local\Application Data
O43 - CFD: 2013/10/04 16:33:59 - [] D -- C:\Users\gabriel\AppData\Local\ATI
O43 - CFD: 2014/09/05 10:43:55 - [] D -- C:\Users\gabriel\AppData\Local\com
O43 - CFD: 2014/01/09 22:28:31 - [] D -- C:\Users\gabriel\AppData\Local\Duuqu =>PUP.Optional.Duuqu
O43 - CFD: 2014/08/28 09:02:47 - [] D -- C:\Users\gabriel\AppData\Local\ElevatedDiagnostics
O43 - CFD: 2014/10/02 11:26:26 - [] D -- C:\Users\gabriel\AppData\Local\Gameo =>PUP.Optional.Gameo
O43 - CFD: 2013/10/15 17:43:53 - [0] D -- C:\Users\gabriel\AppData\Local\GHISLER
O43 - CFD: 2014/09/05 10:42:44 - [] D -- C:\Users\gabriel\AppData\Local\globalUpdate =>PUP.Optional.GlobalUpdate
O43 - CFD: 2014/04/30 11:56:19 - [] D -- C:\Users\gabriel\AppData\Local\Google
O43 - CFD: 2013/10/04 16:33:25 - [0] SHD -- C:\Users\gabriel\AppData\Local\Historique
O43 - CFD: 2013/10/07 10:12:53 - [] D -- C:\Users\gabriel\AppData\Local\IBM
O43 - CFD: 2013/10/07 10:12:49 - [] D -- C:\Users\gabriel\AppData\Local\javasharedresources
O43 - CFD: 2014/09/05 10:42:58 - [] D -- C:\Users\gabriel\AppData\Local\LPT
O43 - CFD: 2014/03/01 19:25:42 - [] D -- C:\Users\gabriel\AppData\Local\Macromedia
O43 - CFD: 2015/02/12 20:04:30 - [] D -- C:\Users\gabriel\AppData\Local\Microsoft
O43 - CFD: 2011/07/26 13:09:34 - [0] D -- C:\Users\gabriel\AppData\Local\Microsoft Help
O43 - CFD: 2013/10/04 16:34:35 - [] D -- C:\Users\gabriel\AppData\Local\Mozilla
O43 - CFD: 2014/09/05 10:43:12 - [] D -- C:\Users\gabriel\AppData\Local\newplayer =>PUP.Optional.NewPlayer
O43 - CFD: 2014/03/17 20:03:48 - [] D -- C:\Users\gabriel\AppData\Local\Packages
O43 - CFD: 2014/06/14 08:51:29 - [] D -- C:\Users\gabriel\AppData\Local\Pay-By-Ads =>PUP.Optional.PaybyAds
O43 - CFD: 2013/10/27 15:37:16 - [] D -- C:\Users\gabriel\AppData\Local\Programs
O43 - CFD: 2014/05/13 15:31:10 - [] D -- C:\Users\gabriel\AppData\Local\Skype
O43 - CFD: 2014/09/05 10:42:44 - [] D -- C:\Users\gabriel\AppData\Local\Smartbar =>PUP.Optional.SmartBar
O43 - CFD: 2014/09/30 17:02:39 - [] D -- C:\Users\gabriel\AppData\Local\Software
O43 - CFD: 2015/07/17 16:22:48 - [] D -- C:\Users\gabriel\AppData\Local\Temp
O43 - CFD: 2013/10/04 16:33:25 - [0] SHD -- C:\Users\gabriel\AppData\Local\Temporary Internet Files
O43 - CFD: 2013/05/30 14:56:07 - [] RD -- C:\Users\gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2013/10/07 09:53:43 - [] RD -- C:\Users\gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2013/11/18 12:20:12 - [] D -- C:\Users\gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player
O43 - CFD: 2013/05/30 14:56:07 - [0] RD -- C:\Users\gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2014/10/02 11:38:23 - [] RD -- C:\Users\gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2013/05/30 14:56:07 - [0] D -- C:\Users\gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Thunderbird
O43 - CFD: 2014/09/05 10:43:29 - [] D -- C:\Users\gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage =>PUP.Optional.Downware

---\\ Enumération des clés de registre StartupReg (SMSR) (O53) (8) - 1s
O53 - SMSR:HKLM\...\startupreg\Adobe ARM [Key] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O53 - SMSR:HKLM\...\startupreg\Adobe Reader Speed Launcher [Key] . (...) -- C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\BCSSync [Key] . (.Microsoft Corporation - Microsoft Office 2010 component.) -- C:\Program Files\Microsoft Office\Office14\BCSSync.exe
O53 - SMSR:HKLM\...\startupreg\Desktop Disc Tool [Key] . (.Copyright 2008 - Roxio Burn Launcher.) -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
O53 - SMSR:HKLM\...\startupreg\IMSS [Key] . (.Intel Corporation - PIcon startup utility.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe
O53 - SMSR:HKLM\...\startupreg\PDVD9LanguageShortcut [Key] . (.CyberLink Corp. - PowerDVD Language Application.) -- C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe
O53 - SMSR:HKLM\...\startupreg\RemoteControl9 [Key] . (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
O53 - SMSR:HKLM\...\startupreg\RoxWatchTray [Key] . (.Sonic Solutions - RoxMMTrayApp Module.) -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe

---\\ Liste des pilotes du système (SDL) (O58) (116) - 6s
O58 - SDL:2011/08/29 12:06:14 A . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\windows\System32\drivers\Accelern.sys [27760]
O58 - SDL:2011/09/01 14:39:30 A . (.Analog Devices, Inc. - High Definition Audio Function Driver.) -- C:\windows\System32\drivers\ADIHdAud.sys [497152]
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\windows\System32\drivers\adp94xx.sys [491088]
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\windows\System32\drivers\adpahci.sys [339536]
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\windows\System32\drivers\adpu320.sys [182864]
O58 - SDL:2009/07/14 03:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\windows\System32\drivers\aliide.sys [15440]
O58 - SDL:2011/03/11 08:41:12 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\windows\System32\drivers\amdsata.sys [107904]
O58 - SDL:2009/07/14 03:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\windows\System32\drivers\amdsbs.sys [194128]
O58 - SDL:2011/03/11 08:41:12 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\windows\System32\drivers\amdxata.sys [27008]
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\windows\System32\drivers\arc.sys [87632]
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\windows\System32\drivers\arcsas.sys [97856]
O58 - SDL:2012/04/12 18:29:38 A . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\windows\System32\drivers\AtihdW76.sys [95248]
O58 - SDL:2012/04/12 18:29:30 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\windows\System32\drivers\atikmdag.sys [10570752]
O58 - SDL:2012/04/12 18:29:30 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\windows\System32\drivers\atikmpag.sys [325632]
O58 - SDL:2009/06/10 22:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\windows\System32\drivers\b57nd60a.sys [270848]
O58 - SDL:2009/06/10 22:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\windows\System32\drivers\BrFiltLo.sys [18432]
O58 - SDL:2009/06/10 22:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\windows\System32\drivers\BrFiltUp.sys [8704]
O58 - SDL:2009/07/14 03:19:07 A . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\windows\System32\drivers\BrSerId.sys [286720]
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\windows\System32\drivers\BrSerWdm.sys [47104]
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\windows\System32\drivers\BrUsbMdm.sys [14976]
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\windows\System32\drivers\BrUsbSer.sys [14720]
O58 - SDL:2009/06/10 22:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\windows\System32\drivers\bxvbda.sys [468480]
O58 - SDL:2009/10/20 04:00:00 A . (.Sonic Solutions - CDR4 64-bit CD and DVD Place Holder Driver.) -- C:\windows\System32\drivers\cdr4_xp.sys [10224]
O58 - SDL:2009/10/20 04:00:00 A . (.Sonic Solutions - CDRAL 64-bit Place Holder Driver (see PxHel.) -- C:\windows\System32\drivers\cdralw2k.sys [10224]
O58 - SDL:2009/07/14 03:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\windows\System32\drivers\cmdide.sys [17488]
O58 - SDL:2010/02/08 08:32:00 A . (.Cisco Systems, Inc. - Cisco Systems VPN Adapter.) -- C:\windows\System32\drivers\CVirtA64.sys [14992]
O58 - SDL:2011/03/04 12:51:50 A . (...) -- C:\windows\System32\drivers\CVPNDRVA.sys [306536]
O58 - SDL:2011/08/29 12:06:28 A . (.Ericsson AB - F3607gw Mobile Broadband GPS Port.) -- C:\windows\System32\drivers\d554gps64.sys [101416]
O58 - SDL:2008/11/16 18:39:44 A . (.Deterministic Networks, Inc. - Deterministic Network Enhancer for NDIS 5.1.) -- C:\windows\System32\drivers\dne64x.sys [157968]
O58 - SDL:2012/04/12 18:29:06 A . (.Intel Corporation - Intel(R) Gigabit Adapter NDIS 6.x driver.) -- C:\windows\System32\drivers\e1c62x64.sys [358576]
O58 - SDL:2011/08/29 12:06:38 A . (.Intel Corporation - Intel(R) Gigabit Adapter NDIS 6.x driver.) -- C:\windows\System32\drivers\e1k62x64.sys [301232]
O58 - SDL:2009/07/14 03:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\windows\System32\drivers\elxstor.sys [530496]
O58 - SDL:2009/06/10 22:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\windows\System32\drivers\evbda.sys [3286016]
O58 - SDL:2009/08/31 02:55:58 A . (.Gemalto - Keyboard Smart Card Reader Driver.) -- C:\windows\System32\drivers\GKUPRO2D.sys [120064]
O58 - SDL:2009/06/10 22:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\windows\System32\drivers\hcw85cir.sys [31232]
O58 - SDL:2011/09/01 14:39:32 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\windows\System32\drivers\HECIx64.sys [56344]
O58 - SDL:2010/11/21 05:23:47 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\windows\System32\drivers\HpSAMD.sys [78720]
O58 - SDL:2010/09/20 15:32:46 A . (.Intel Corporation - NDIS 6.1 Advanced Networking Services..) -- C:\windows\System32\drivers\iANSW60e.sys [157544]
O58 - SDL:2012/04/12 18:29:06 A . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\windows\System32\drivers\iaStor.sys [568600]
O58 - SDL:2011/03/11 08:41:26 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\windows\System32\drivers\iaStorV.sys [410496]
O58 - SDL:2009/07/14 03:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\windows\System32\drivers\iirsp.sys [44112]
O58 - SDL:2011/08/29 12:07:03 A . (.Intel Corporation - Intel(R) Turbo Boost Technology Driver.) -- C:\windows\System32\drivers\Impcd.sys [158976]
O58 - SDL:2010/09/17 04:02:24 A . (.Intel Corporation - Intel(R) Network Adapter Diagnostic Driver.) -- C:\windows\System32\drivers\iqvw64e.sys [32936]
O58 - SDL:2012/02/22 23:35:00 A . (.Intel Corporation - Intel(R) Rapid Start Technology Driver.) -- C:\windows\System32\drivers\irstrtdv.sys [26504]
O58 - SDL:2012/04/12 18:29:04 A . (.Intel Corporation - Intel(R) USB 3.0 Host Controller Switch Dri.) -- C:\windows\System32\drivers\iusb3hcs.sys [16152]
O58 - SDL:2012/04/12 18:29:04 A . (.Intel Corporation - Intel(R) USB 3.0 Hub Driver.) -- C:\windows\System32\drivers\iusb3hub.sys [356120]
O58 - SDL:2012/04/12 18:29:04 A . (.Intel Corporation - Intel(R) USB 3.0 eXtensible Host Controller.) -- C:\windows\System32\drivers\iusb3xhc.sys [788760]
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\windows\System32\drivers\lsi_fc.sys [114752]
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\windows\System32\drivers\lsi_sas.sys [106560]
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\windows\System32\drivers\lsi_sas2.sys [65600]
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\windows\System32\drivers\lsi_scsi.sys [115776]
O58 - SDL:2011/10/05 20:01:04 A . (.MCCI Corporation - F3607gw Mobile Broadband Device Driver.) -- C:\windows\System32\drivers\Mbm3CBus.sys [419400]
O58 - SDL:2011/10/05 20:01:06 A . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\windows\System32\drivers\Mbm3cm.sys [15432]
O58 - SDL:2011/10/05 20:01:06 A . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\windows\System32\drivers\Mbm3cmnt.sys [15432]
O58 - SDL:2011/10/05 20:01:10 A . (.MCCI Corporation - F3607gw Mobile Broadband Device Management.) -- C:\windows\System32\drivers\Mbm3DevMt.sys [430664]
O58 - SDL:2011/10/05 20:01:18 A . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\windows\System32\drivers\Mbm3wh.sys [15944]
O58 - SDL:2011/10/05 20:01:18 A . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\windows\System32\drivers\Mbm3whnt.sys [15944]
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\windows\System32\drivers\megasas.sys [35392]
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\windows\System32\drivers\MegaSR.sys [284736]
O58 - SDL:2009/07/14 03:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\windows\System32\drivers\nfrd960.sys [51264]
O58 - SDL:2011/10/26 04:57:38 A . (.Renesas Electronics Corporation - USB 3.0 Hub Driver.) -- C:\windows\System32\drivers\nusb3hub.sys [96768]
O58 - SDL:2011/10/26 04:57:38 A . (.Renesas Electronics Corporation - USB 3.0 Host Controller Driver.) -- C:\windows\System32\drivers\nusb3xhc.sys [213504]
O58 - SDL:2011/03/11 08:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\windows\System32\drivers\nvraid.sys [148352]
O58 - SDL:2011/03/11 08:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\windows\System32\drivers\nvstor.sys [166272]
O58 - SDL:2012/08/13 20:20:00 A . (.NVIDIA Corporation - Stereoscopic 3D USB controller driver.) -- C:\windows\System32\drivers\nvstusb.sys [398656]
O58 - SDL:2011/08/29 12:06:27 A . (.Novatel Wireless Inc - Filter Driver for the Novatel Wireless USB.) -- C:\windows\System32\drivers\nwdelgobi3kfilter.sys [34304]
O58 - SDL:2011/08/29 12:06:32 A . (.Novatel Wireless Inc. - Novatel Wireless USB Modem/Serial Device Dr.) -- C:\windows\System32\drivers\nwdelser.sys [217856]
O58 - SDL:2011/08/29 12:06:32 A . (.Novatel Wireless Inc. - Novatel Wireless USB Modem/Serial Device Dr.) -- C:\windows\System32\drivers\nwdelser2.sys [217856]
O58 - SDL:2011/08/29 12:06:27 A . (.Novatel Wireless Inc. - Novatel Wireless USB Modem/Serial Device Dr.) -- C:\windows\System32\drivers\nwdelserial.sys [234112]
O58 - SDL:2011/08/29 12:06:26 A . (.O2Micro - O2Micro Media Reader Driver (AMD64).) -- C:\windows\System32\drivers\o2mdfw7x64.sys [72808]
O58 - SDL:2011/08/29 12:06:26 A . (.O2Micro - O2Micro Media Reader Driver (AMD64).) -- C:\windows\System32\drivers\O2MDRw7x64.sys [74984]
O58 - SDL:2011/08/29 12:06:26 A . (.O2Micro - O2Micro SD Reader Driver (AMD64).) -- C:\windows\System32\drivers\o2sdjw7x64.sys [75240]
O58 - SDL:2010/03/19 04:00:00 A . (.Sonic Solutions - Px Engine Device Driver for 64-bit Windows.) -- C:\windows\System32\drivers\PxHlpa64.sys [55856]
O58 - SDL:2011/08/29 12:06:26 A . (.QUALCOMM Incorporated - Filter Driver for the Qualcomm USB Driver S.) -- C:\windows\System32\drivers\qcfilterdl2k.sys [6400]
O58 - SDL:2011/08/29 12:06:26 A . (.QUALCOMM Incorporated - USB Modem/Serial Device Driver.) -- C:\windows\System32\drivers\qcusbserdl2k.sys [230784]
O58 - SDL:2009/07/14 03:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\windows\System32\drivers\ql2300.sys [1524816]
O58 - SDL:2009/07/14 03:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\windows\System32\drivers\ql40xx.sys [128592]
O58 - SDL:2011/08/29 12:06:23 A . (.REDC - RICOH MMC Driver.) -- C:\windows\System32\drivers\rimmpx64.sys [67584]
O58 - SDL:2011/08/29 12:06:21 A . (.REDC - RICOH MS Driver.) -- C:\windows\System32\drivers\rimspe64.sys [61952]
O58 - SDL:2011/08/29 12:06:23 A . (.REDC - RICOH MS Driver.) -- C:\windows\System32\drivers\rimspx64.sys [55296]
O58 - SDL:2008/04/16 15:49:34 A . (.Research In Motion Limited - BlackBerry Device Driver.) -- C:\windows\System32\drivers\RimUsb_AMD64.sys [28416]
O58 - SDL:2011/08/29 12:06:22 A . (.REDC - RICOH SD/MMC Driver.) -- C:\windows\System32\drivers\risdpe64.sys [81920]
O58 - SDL:2011/05/26 12:23:00 A . (.REDC - RICOH PCIe SDXC/MMC Controller Driver.) -- C:\windows\System32\drivers\risdxc64.sys [101888]
O58 - SDL:2011/08/29 12:06:22 A . (.REDC - RICOH PCIe XD Driver.) -- C:\windows\System32\drivers\rixdpe64.sys [55808]
O58 - SDL:2011/08/29 12:06:23 A . (.REDC - RICOH xD SM Driver.) -- C:\windows\System32\drivers\rixdpx64.sys [57856]
O58 - SDL:2012/04/12 18:29:02 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\windows\System32\drivers\RTDVHD64.sys [3708776]
O58 - SDL:2009/06/10 22:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\windows\System32\drivers\secdrv.sys [23040]
O58 - SDL:2009/07/14 03:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\windows\System32\drivers\sisraid2.sys [43584]
O58 - SDL:2009/07/14 03:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\windows\System32\drivers\sisraid4.sys [80464]
O58 - SDL:2011/09/01 14:39:37 A . (.SUNIX Co., Ltd. - SUNIX Parallel Driver (x64).) -- C:\windows\System32\drivers\snxppamd.sys [100728]
O58 - SDL:2011/09/01 14:39:37 A . (.SUNIX Co., Ltd. - SUNIX Serial Driver (x64).) -- C:\windows\System32\drivers\snxpsamd.sys [97144]
O58 - SDL:2009/07/14 03:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\windows\System32\drivers\stexstor.sys [24656]
O58 - SDL:2011/10/05 19:52:32 A . (.Ericsson AB - F3607gw Mobile Broadband GPS Port.) -- C:\windows\System32\drivers\t36wgps64.sys [102440]
O58 - SDL:2011/08/29 12:06:43 A . (...) -- C:\windows\System32\drivers\tcm.sys [17048]
O58 - SDL:2011/07/13 15:08:02 A . (.TOSHIBA Corporation - TOSHIBA Bluetooth EC Driver.) -- C:\windows\System32\drivers\tosrfec.sys [19904]
O58 - SDL:2009/07/15 07:25:14 A . (.TOSHIBA Corporation - TOSHIBA ACPI-Based Value Added Logical and.) -- C:\windows\System32\drivers\TVALZ.SYS [26840]
O58 - SDL:2009/07/14 03:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\windows\System32\drivers\viaide.sys [17488]
O58 - SDL:2009/07/14 03:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\windows\System32\drivers\vsmraid.sys [161872]
O58 - SDL:2011/08/29 12:06:29 A . (.Ericsson AB - Ericsson WWAN Selective suspend Device Driv.) -- C:\windows\System32\drivers\wwuss64.sys [26664]
O58 - SDL:2011/08/29 12:06:29 A . (.Ericsson AB - Ericsson WWAN Selective suspend Filter Driv.) -- C:\windows\System32\drivers\wwussf64.sys [30248]
O58 - SDL:2014/06/09 11:57:12 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{26d264d2-014c-4f07-bf2c-ebf9aed40cef}w64.sys [61112] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/11/04 04:34:36 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{2859046f-5dca-482a-8c2d-37943d33a392}w64.sys [48792] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/10/26 04:41:00 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{29302da5-1178-40ac-a178-4cb57ebcc501}w64.sys [48792] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/11/28 11:32:34 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{43cf8855-c9cb-4281-aca0-c67a8c4b59de}w64.sys [48824] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/11/30 02:30:40 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{44a99463-0ff3-4b62-9d3c-802722bf3043}w64.sys [48824] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/11/28 12:38:10 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{5f0f49f4-526a-4e0c-b198-a0742c879601}w64.sys [48784] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/11/03 07:39:42 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{6db7eb66-a30b-41a3-809c-addb2341dafb}w64.sys [48792] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/10/11 03:15:40 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{7012eec1-4f37-42d4-a2cd-26727494d248}w64.sys [48792] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/11/27 09:33:10 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{77288bc4-30b5-49f8-88e2-b9b5110ed762}w64.sys [48824] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/11/06 21:33:24 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{8c39d0b0-9b68-43ef-bc3c-2ef385fe5169}w64.sys [48792] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/11/10 03:30:18 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{9de7e012-74d3-4f9d-b4b0-2d3150073168}w64.sys [48792] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/10/23 05:37:12 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{a6762132-8e80-4305-b1ba-2bec91757ac2}w64.sys [48792] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/11/27 03:32:22 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{b30c55f2-a940-4907-8051-f13c9acdacdd}w64.sys [48784] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/11/30 03:33:42 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{cd63c300-b231-4a93-a479-5a1e96976d74}w64.sys [48784] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/10/29 10:39:04 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{dda91daf-e6f8-4453-88d1-df18d861c904}w64.sys [48792] =>PUP.Optional.LinkiDoo
O58 - SDL:2014/10/01 21:07:58 A . (.StdLib - StdLib.) -- C:\windows\System32\drivers\{e9bebce7-deb3-4ab9-896c-549739f208c5}w64.sys [48792] =>PUP.Optional.LinkiDoo

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) (1) - 12s
O61 - LFC: 2015/07/16 15:59:16 A . (..) -- C:\Users\gabriel\AppData\Local\ATI\ACE\Manifest.Bin [32089]

---\\ Associations Shell Spawning (O67) (9) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S

---\\ Menu de démarrage Internet (SMI) (O68) (12) - 1s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- iexplore.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe

---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) (83) - 10s
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.Framed Display.aul", "1419339894686"); =>PUP.FramedDisplay
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.Framed Display.irl", true); =>PUP.FramedDisplay
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.Framed Display.is", "isgizzFR"); =>PUP.FramedDisplay
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.Framed Display.ug", "5D27472B-BFC6-4332-A58C-EC4C9C0ECADB"); =>PUP.FramedDisplay
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_firstRun.expiration", "Fri Feb 07 2[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_firstRun.value", "false"); =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_is_install_reported_.expiration", "[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_is_install_reported_.value", "true"[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_lastUpdate.expiration", "Tue Jul 08[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_lastUpdate.value", "1436624666098")[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_last_report_errors.expiration", "Tu[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_last_report_errors.value", "%7B%7D"[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_loader_session_page_impression.expi[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_loader_session_page_impression.valu[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_monetization_impression_buckets.exp[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_monetization_impression_buckets.val[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_monetization_page_view.expiration",[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_monetization_page_view.value", "72"[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_monetization_plugins_delay.expirati[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_monetization_plugins_delay.value", [...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_monetization_plugins_ids.expiration[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_monetization_plugins_ids.value", "%[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_override_verticals.expiration", "Tu[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_override_verticals.value", "%7B%7D"[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_plugins_version_.expiration", "Tue [...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_plugins_version_.value", "117"); =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_stats_.expiration", "Fri Feb 07 202[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.asyncinternaldb.monetization_plugin_stats_.value", "%7B%22bic%22%3A%221[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.internaldb.monetization_plugin_bundledUrls.expiration", "Fri Feb 01 203[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.internaldb.monetization_plugin_bundledWithHash.expiration", "Fri Feb 01[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.internaldb.monetization_plugin_bundledWithHash.value", "null"); =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.internaldb.monetization_plugin_notBundledArr_.expiration", "Fri Feb 01 [...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.internaldb.monetization_plugin_notBundledArr_.value", "%5B%5D"); =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.internaldb.monetization_plugin_regBundledWithSoftware.expiration", "Fri[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.internaldb.monetization_plugin_regBundledWithSoftware.value", "%7B%7D")[...] =>PUP.Optional.Monetization
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.name", "Browsers App"); =>PUP.Optional.CrossRider
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.ahermanthorne45outlookcom61787.61787.publisher", "Freeven"); =>PUP.Optional.CrossRider
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.AL", 4); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.aflt", "ast_ggbc_14_40_ch"); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.appId", "{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}"); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.cd", "2XzuyEtN2Y1L1QzutDtDtBtA0A0E0AyE0FtAtAyDtAtCyB0EtN0D0Tzu0StCtDtDyDtN1L2XzutAtFtBtFtCtFyDtN1[...] =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.cr", "1279478973"); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.dfltLng", ""); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.dfltSrch", true); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.dnsErr", true); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.excTlbr", false); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.hmpg", true); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.hmpgUrl", "http://astromenda.com/?f=1&a=ast_ggbc_14_40_ch&cd=2XzuyEtN2Y1L1QzutDtDtBtA0A0E0AyE0FtA[...] =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.id", "0023AEA4F335317E"); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.instlDay", "16345"); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.instlRef", "142905_f"); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.newTabUrl", "http://astromenda.com/?f=2&a=ast_ggbc_14_40_ch&cd=2XzuyEtN2Y1L1QzutDtDtBtA0A0E0AyE0F[...] =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.prdct", "astrmndasr"); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.prtnrId", "WSE_Astromenda"); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.srchPrvdr", "Astromenda"); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.tlbrId", ""); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.tlbrSrchUrl", "http://astromenda.com/?f=3&a=ast_ggbc_14_40_ch&cd=2XzuyEtN2Y1L1QzutDtDtBtA0A0E0AyE[...] =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.vrsn", ""); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr.vrsni", ""); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr_i.newTab", true); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr_i.smplGrp", "none"); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.astrmndasr_i.vrsnTs", "10:27:50"); =>PUP.Optional.Astromenda
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.crossrider.bic", "14b73647958818f5376b95416f93264b"); =>PUP.Optional.CrossRider
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.enabledAddons", "ffxtlbr@mysearchdial.com:1.6.0,{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}:9.5.3,{a86d6d1e-4fac-[...] =>PUP.Optional.MySearchDial
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.glindorus.asul", "1436198234536"); =>PUP.Optional.Sambreel
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.glindorus.aul", "1436624667458"); =>PUP.Optional.Sambreel
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.glindorus.irl", true); =>PUP.Optional.Sambreel
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.glindorus.is", "grbgofr"); =>PUP.Optional.Sambreel
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.glindorus.ug", "BB27C5AA-5623-48AD-B5BD-7BFA9063432B"); =>PUP.Optional.Sambreel
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.mysearchdial.cntry", "FR"); =>PUP.Optional.MySearchDial
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497[...] =>PUP.Optional.MySearchDial
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.mysearchdial.hdrMd5", ""); =>PUP.Optional.MySearchDial
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.mysearchdial.lastB", "chrome://branding/locale/browserconfig.properties"); =>PUP.Optional.MySearchDial
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.mysearchdial.lastVrsnTs", ""); =>PUP.Optional.MySearchDial
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"96\",\"lastVrsn\":\"96\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"s[...] =>PUP.Optional.MySearchDial
O69 - SBI: prefs.js [gabriel - 4qqvklyb.default] user_pref("extensions.mysearchdial.sg", "{smplGrp}"); =>PUP.Optional.MySearchDial
O69 - SBI: SearchScopes [HKCU] OldSearch - (Yahoo! Search) - http://fr.search.yahoo.com/
O69 - SBI: SearchScopes [HKCU] {006ee092-9658-4fd6-bd8e-a21a348e59f5} [DefaultScope] - (Yahoo! Search) - http://fr.search.yahoo.com/
O69 - SBI: SearchScopes [HKCU] {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} - (Web Search) - http://feed.helperbar.com/ =>PUP.Optional.HelperBar
O69 - SBI: SearchScopes [HKCU] {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} - (Search The Web) - http://www.mystart.com/
O69 - SBI: SearchScopes [HKCU] {5036F6E4-757B-4BC2-B7F3-C298FFC957F2} - (Astromenda) - http://astromenda.com/ =>PUP.Optional.Astromenda
O69 - SBI: SearchScopes [HKCU] {D545FEB5-0B2B-43F0-A771-45A4F45D9363} - (Yahoo! Search) - http://rts.dsrlte.com/ =>PUP.Optional.PaybyAds

---\\ Enumère les services démarrés par Svchost (SSS) (O83) (33) - 2s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\windows\System32\aelupsvc.dll [72192]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\windows\System32\certprop.dll [80384]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\windows\System32\certprop.dll [80384]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\windows\system32\srvsvc.dll [236032]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\windows\System32\gpsvc.dll [777728]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\windows\System32\ikeext.dll [853504]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\windows\System32\Audiosrv.dll [679424]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\windows\System32\rasauto.dll [99328]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\windows\System32\rasmans.dll [344064]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [64512]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\windows\System32\ipnathlp.dll [359424]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [316928]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du se.) -- C:\windows\System32\termsrv.dll [680960]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\windows\system32\wuaueng.dll [2428952]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\windows\System32\qmgr.dll [849920]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [370688]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\windows\System32\iphlpsvc.dll [569344]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\windows\system32\seclogon.dll [30720]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\windows\System32\appinfo.dll [70144]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\windows\system32\iscsiexe.dll [156672]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\windows\system32\mmcss.dll [67584]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\windows\system32\wbem\WMIsvc.dll [242688]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [121856]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\windows\System32\browser.dll [136704]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\windows\System32\eapsvc.dll [111104]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\windows\system32\schedsvc.dll [1110016]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\windows\system32\kmsvc.dll [90624]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\windows\System32\wercplsupport.dll [84480]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\windows\system32\profsvc.dll [209920]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\windows\system32\themeservice.dll [44544]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\windows\System32\bdesvc.dll [100864]
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [193536]

---\\ Liste des exceptions du parefeu (FirewallRules) (O87) (14) - 6s
O87 - FAEL: "{7179EDF7-430B-4B3E-8767-DE0A539344F1}" [In-None-P6-TRUE] .(.CyberLink Corp. - CyberLink PowerDVD Cinema Main Program.) -- C:\Program Files (x86)\CyberLink\PowerDVD9\PowerDVD Cinema\PowerDVDCinema.exe
O87 - FAEL: "{A54DEEB2-16E6-46EE-8215-702B7A832D8B}" [In-None-P6-TRUE] .(.CyberLink Corp. - PowerDVD 9.5.) -- C:\Program Files (x86)\CyberLink\PowerDVD9\PowerDVD9.EXE
O87 - FAEL: "{1B520761-4328-4935-A7A5-8CD58BFE0727}" [In-None-P6-FALSE] .(.IBM Corp. - IBM SPSS Statistics 20.) -- C:\Program Files\IBM\SPSS\Statistics\20\stats.exe
O87 - FAEL: "{067BBC29-B007-4F2A-8CA5-44E9CA5013B2}" [In-None-P6-FALSE] .(.IBM Corp. - IBM SPSS Statistics 20 Command.) -- C:\Program Files\IBM\SPSS\Statistics\20\stats.com
O87 - FAEL: "{E78BD97B-FCF8-4A4C-9B59-F5CAD8100B4E}" [In-None-P6-FALSE] .(.IBM Corp. - IBM SPSS WinWrap Basic IDE 20.) -- C:\Program Files\IBM\SPSS\Statistics\20\WinWrapIDE.exe
O87 - FAEL: "{2462FBA7-0396-40BB-A3B8-3ABB9518CAD8}" [In-None-P17-FALSE] .(.IBM Corp. - IBM SPSS Statistics 20 Command.) -- C:\Program Files\IBM\SPSS\Statistics\20\stats.com
O87 - FAEL: "{C1CA8161-EAEC-4572-8063-2A681EDB3B79}" [In-None-P17-FALSE] .(.IBM Corp. - IBM SPSS Statistics 20.) -- C:\Program Files\IBM\SPSS\Statistics\20\stats.exe
O87 - FAEL: "{C0A679C3-9A55-4859-A5A4-66F6A9DBF9CB}" [In-None-P17-FALSE] .(.IBM Corp. - IBM SPSS WinWrap Basic IDE 20.) -- C:\Program Files\IBM\SPSS\Statistics\20\WinWrapIDE.exe
O87 - FAEL: "TCP Query User{66083C79-8C1D-4464-B94A-FC6C971EBECD}C:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe" [In-None-P6-TRUE] .(.IBM - Java(TM) Platform SE binary.) -- C:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe
O87 - FAEL: "UDP Query User{09ECB74D-949B-49BE-8785-F43D2B7D391A}C:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe" [In-None-P17-TRUE] .(.IBM - Java(TM) Platform SE binary.) -- C:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe
O87 - FAEL: "TCP Query User{A82D00BC-383C-4BAD-A8F1-95C71F57BA6A}C:\program files\ibm\spss\statistics\20\stats.exe" [In-None-P6-TRUE] .(.IBM Corp. - IBM SPSS Statistics 20.) -- C:\program files\ibm\spss\statistics\20\stats.exe
O87 - FAEL: "UDP Query User{A1A91D69-9F54-49FB-BEEE-590A234CB0A2}C:\program files\ibm\spss\statistics\20\stats.exe" [In-None-P17-TRUE] .(.IBM Corp. - IBM SPSS Statistics 20.) -- C:\program files\ibm\spss\statistics\20\stats.exe
O87 - FAEL: "TCP Query User{C6DFFEC4-74D0-420D-82D3-FCACF0E7A892}C:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe" [In-None-P6-TRUE] .(.IBM - Java(TM) Platform SE binary.) -- C:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe
O87 - FAEL: "UDP Query User{3E42B452-DCCD-4695-BDAE-A783728A5330}C:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe" [In-None-P17-TRUE] .(.IBM - Java(TM) Platform SE binary.) -- C:\program files\ibm\spss\statistics\20\jre\bin\javaw.exe

---\\ Enumère les codes produits des logiciels (PUC) (O90) (1) - 1s
O90 - PUC: "243A8D8DF9E0AE743AE5FC34B1052B68" . (.Boxore Client.) -- C:\windows\Installer\{D8D8A342-0E9F-47EA-A35E-CF431B50B286}\boxore.ico =>PUP.Optional.Boxore =>PUP.Optional.Boxore

---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS) (2) - 6s
[MD5.] [WIS][2014/09/30 17:10:15] (.Boxore OU. - Windows Installer XML (3.5.2519.0).) -- C:\windows\Installer\2fac9.msi [45056] =>PUP.Optional.Boxore
[MD5.] [WIS][2014/08/27 18:48:02] (.LPT - Windows Installer XML (3.5.2519.0).) -- C:\windows\Installer\b8fd8f.msi [2154496] =>PUP.Optional.Linkury

---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) (32) - 18s
SR - Auto [2015/07/07 20:12:28] [ 82128] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SS - Demand [2015/07/17 16:00:22] [ 268976] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SR - Auto [2012/04/12 18:29:30] [ 204288] (AMD External Events Utility) . (.AMD.) - C:\windows\system32\atiesrxx.exe
SS - Disabled [2011/03/04 12:45:08] [ 1529856] Cisco Systems, Inc. VPN Service (CVPND) . (.Cisco Systems, Inc..) - C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
SR - Demand [2013/10/07 11:08:06] [ 654848] FLEXnet Licensing Service (FLEXnet Licensing Service) . (.Macrovision Europe Ltd..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - Auto [2014/09/05 10:42:42] [ 68608] globalUpdate Update Service (globalUpdate) (globalUpdate) . (.globalUpdate.) - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
SS - Demand [2014/09/05 10:42:42] [ 68608] globalUpdate Update Service (globalUpdatem) (globalUpdatem) . (.globalUpdate.) - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
SS - Auto [2014/02/05 22:08:50] [ 116648] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - Demand [2014/02/05 22:08:50] [ 116648] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SR - Auto [2010/11/06 00:54:22] [ 13336] Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
SR - Auto [2010/04/05 21:55:01] [ 116104] Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) . (.Copyright CANON INC. 2006-2010 All Rights Reserved.) - C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
SR - Auto [2010/09/22 01:05:24] [ 165032] Intel(R) PROSet Monitoring Service (Intel(R) PROSet Monitoring Service) . (.Intel Corporation.) - C:\Windows\system32\IProsetMonitor.exe
SR - Auto [2010/11/29 13:10:32] [ 210896] Intel(R) Identity Protection Technology Host Interface Serv (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
SR - Auto [2010/12/04 01:20:16] [ 325656] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SS - Disabled [2014/08/27 18:44:04] [ 34328] LPT System Updater Service (LPTSystemUpdater) . (...) - C:\Program Files (x86)\LPT\srpts.exe
SR - Auto [2015/07/17 16:00:45] [ 128248] MaintainerSvc1.92.5302915 (MaintainerSvc1.92.5302915) . (...) - C:\ProgramData\ecbaef90-5696-41e1-a1c3-3e8112ce2840\maintainer.exe
SR - Auto [2015/07/17 16:00:47] [ 128288] MaintainerSvc2.13.426751 (MaintainerSvc2.13.426751) . (...) - C:\ProgramData\80810f5c-7b66-4b02-af93-03f2b7680a45\maintainer.exe
SR - Demand [2014/09/01 20:26:50] [ 1317096] MyOSProtect (MyOSProtect) . (.MyOSCompany.) - C:\Program Files (x86)\PCTRunner\MyOSProtect.exe
SR - Auto [2014/09/05 10:41:25] [ 291328] NewPlayer (NewPlayer) . (.Copyright (C) 2014.) - C:\Program Files (x86)\ver5NewPlayer\V7NewPlayerwL178.exe
SR - Auto [2015/03/16 14:13:10] [ 11776] NewVideoPlayer Updater Service (NewVideoPlayerUpdaterService) . (.Copyright © 2014.) - C:\Program Files (x86)\NewPlayer\NewVideoPlayerUpdaterService.exe
SR - Auto [2012/05/30 11:53:06] [ 249856] Novell Identity Store (Novell Identity Store) . (.Novell, Inc.) - C:\Program Files (x86)\Novell\CASA\bin\micasad.exe
SS - Auto [2014/09/02 21:55:26] [ 34244] Protect Monitor (ProtectMonitor) . (...) - C:\monitorsvc.exe
SS - Demand [2010/11/25 06:33:18] [ 1116656] RoxMediaDB12OEM (RoxMediaDB12OEM) . (.Sonic Solutions.) - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
SS - Auto [2010/11/25 06:34:18] [ 219632] Roxio Hard Drive Watcher 12 (RoxWatch12) . (.Sonic Solutions.) - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
SR - Auto [2014/09/02 14:11:58] [ 4823040] scores (scores) . (...) - C:\Windows\score.exe
SS - Auto [2015/02/18 19:11:32] [ 315488] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SS - Demand [2010/11/08 18:58:48] [ 74392] stllssvr (stllssvr) . (.MicroVision Development, Inc..) - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
SR - Auto [2010/12/04 01:20:18] [ 2656280] Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - Auto [2015/07/16 17:07:09] [ 459000] Update Framed Display (Update Framed Display) . (...) - C:\Program Files (x86)\Framed Display\updateFramedDisplay.exe
SR - Auto [2015/07/17 16:09:15] [ 456992] Update glindorus (Update glindorus) . (...) - C:\Program Files (x86)\glindorus\updateglindorus.exe
SS - Auto [2015/07/17 16:04:52] [ 469752] Util Framed Display (Util Framed Display) . (...) - C:\Program Files (x86)\Framed Display\bin\utilFramedDisplay.exe
SR - Auto [2015/07/17 16:04:54] [ 456992] Util glindorus (Util glindorus) . (...) - C:\Program Files (x86)\glindorus\bin\utilglindorus.exe

---\\ Recherche de clés de registre Tracing (O100) (36) - 4s
HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32 =>PUP.Optional.MyPCBackup
HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS =>PUP.Optional.MyPCBackup
HKLM\SOFTWARE\Microsoft\Tracing\FramedDisplay_RASAPI32 =>PUP.FramedDisplay
HKLM\SOFTWARE\Microsoft\Tracing\FramedDisplay_RASMANCS =>PUP.FramedDisplay
HKLM\SOFTWARE\Microsoft\Tracing\glindorus_RASAPI32 =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Microsoft\Tracing\glindorus_RASMANCS =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32 =>PUP.Optional.AdvancedSystemProtector
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS =>PUP.Optional.AdvancedSystemProtector
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BabMaint_RASAPI32 =>PUP.Optional.BabSolution
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BabMaint_RASMANCS =>PUP.Optional.BabSolution
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\boxore_RASAPI32 =>PUP.Optional.Boxore
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\boxore_RASMANCS =>PUP.Optional.Boxore
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\browsers apps--bg_RASAPI32 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\browsers apps--bg_RASMANCS =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Browsers Apps--codedownloader_RASAPI32 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Browsers Apps--codedownloader_RASMANCS =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FastPlayer_RASAPI32 =>PUP.Optional.FastPlayer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FastPlayer_RASMANCS =>PUP.Optional.FastPlayer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FLVPlayerSetup_RASAPI32 =>PUP.Optional.FLVPlayer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FLVPlayerSetup_RASMANCS =>PUP.Optional.FLVPlayer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FramedDisplay_RASAPI32 =>PUP.FramedDisplay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FramedDisplay_RASMANCS =>PUP.FramedDisplay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FramedDisplay_Setup_RASAPI32 =>PUP.FramedDisplay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FramedDisplay_Setup_RASMANCS =>PUP.FramedDisplay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\gameo_RASAPI32 =>PUP.Optional.Gameo
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\gameo_RASMANCS =>PUP.Optional.Gameo
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\glindorus_2709-e3c075a1_RASAPI32 =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\glindorus_2709-e3c075a1_RASMANCS =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\glindorus_RASAPI32 =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\glindorus_RASMANCS =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\glindorus_Setup_RASAPI32 =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\glindorus_Setup_RASMANCS =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\IminentSetup_2509-9f33b5cf_RASAPI32 =>PUP.Optional.IMBooster
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\IminentSetup_2509-9f33b5cf_RASMANCS =>PUP.Optional.IMBooster
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Iminent_RASAPI32 =>PUP.Optional.IMBooster
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Iminent_RASMANCS =>PUP.Optional.IMBooster

---\\ Scan Additionnel (O88) (248) - 0s
C:\Program Files (x86)\ver5NewPlayer\V7NewPlayerwL178.exe =>PUP.Optional.NewPlayer
C:\Program Files (x86)\NewPlayer\NewVideoPlayerUpdaterService.exe =>PUP.Optional.NewPlayer
C:\Program Files (x86)\Browsers Apps-\7fc7d17b-ba69-4bc7-ba33-2c036a5f94b3.exe =>PUP.Optional.CrossRider
C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe =>PUP.Optional.GlobalUpdate
C:\Program Files (x86)\coupons and fun\coupons_and_fun_notification_service.exe =>PUP.Optional.CrossRider
C:\Program Files (x86)\PCTRunner\MyOSProtect.exe =>PUP.Optional.WebProtect
C:\Program Files (x86)\Browsers Apps-\6dd9516d-ead4-47a9-b3d2-d447fe9cc131.exe =>PUP.Optional.CrossRider
C:\Program Files (x86)\Framed Display\updateFramedDisplay.exe =>PUP.FramedDisplay
C:\Program Files (x86)\Pay-By-Ads\Yahoo! Search\1.3.26.12\dsrlte.exe =>PUP.Optional.PaybyAds
C:\Program Files (x86)\glindorus\bin\utilglindorus.exe =>PUP.Glindorus
C:\Program Files (x86)\glindorus\bin\glindorus.PurBrowse64.exe =>PUP.Glindorus
C:\Program Files (x86)\glindorus\bin\glindorus.BrowserAdapter.exe =>PUP.Glindorus
C:\Program Files (x86)\glindorus\bin\glindorus.BrowserAdapter64.exe =>PUP.Glindorus
C:\Program Files (x86)\glindorus\bin\glindorus.expext.exe =>PUP.Glindorus
C:\Program Files (x86)\glindorus\updateglindorus.exe =>PUP.Glindorus
C:\Users\gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffhfoagmjcnkolneahbpagjcjjaeofbg
C:\Users\gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gagcbogmgkaogoadfcoicjdojbmkegao
C:\Users\gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\llmcibonccojooiboenghfafpieoabpl
C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll =>PUP.Optional.GlobalUpdate
C:\Program Files (x86)\Software\Update\1.2.201.0\npSoftwareOneClick8.dll =>PUP.Optional.Boxore
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{05b5ef3f-4c6a-426e-b77e-48ebb3e721f1} =>PUP.Optional.FramedDisplay
C:\Program Files (x86)\Browsers Apps-\Browsers Apps--bho64.dll =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171187} =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0} =>PUP.Optional.SmartBar
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9598e82a-7e09-4438-b425-b9e9718c3c73} =>PUP.Glindorus
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} =>PUP.Optional.Hotbar
C:\Program Files (x86)\Mysearchdial\1.8.21.0\mysearchdialTlbr.dll =>PUP.Optional.Hotbar
C:\windows\system32\MyOSProtect64.dll =>Hijacker.Winsock
C:\Users\gabriel\AppData\Local\Smartbar\Application\Resources\crdlil64.dll =>PUP.Optional.SmartBar
HKLM\SYSTEM\CurrentControlSet\Services\globalUpdate =>PUP.Optional.GlobalUpdate
HKLM\SYSTEM\CurrentControlSet\Services\MaintainerSvc1.92.5302915 =>PUP.Optional.MaintainerSvc
C:\ProgramData\ecbaef90-5696-41e1-a1c3-3e8112ce2840\maintainer.exe =>PUP.Optional.MaintainerSvc
HKLM\SYSTEM\CurrentControlSet\Services\MaintainerSvc2.13.426751 =>PUP.Optional.MaintainerSvc
C:\ProgramData\80810f5c-7b66-4b02-af93-03f2b7680a45\maintainer.exe =>PUP.Optional.MaintainerSvc
HKLM\SYSTEM\CurrentControlSet\Services\NewPlayer =>PUP.Optional.NewPlayer
HKLM\SYSTEM\CurrentControlSet\Services\NewVideoPlayerUpdaterService =>PUP.Optional.NewPlayer
HKLM\SYSTEM\CurrentControlSet\Services\ProtectMonitor =>Trojan.BitCoinMiner
C:\monitorsvc.exe =>Trojan.BitCoinMiner
HKLM\SYSTEM\CurrentControlSet\Services\Update Framed Display =>PUP.Optional.FramedDisplay
C:\Program Files (x86)\Framed Display\updateFramedDisplay.exe =>PUP.Optional.FramedDisplay
HKLM\SYSTEM\CurrentControlSet\Services\Update glindorus =>PUP.Optional.glindorus
C:\Program Files (x86)\glindorus\updateglindorus.exe =>PUP.Optional.glindorus
HKLM\SYSTEM\CurrentControlSet\Services\Util Framed Display =>PUP.Optional.FramedDisplay
C:\Program Files (x86)\Framed Display\bin\utilFramedDisplay.exe =>PUP.Optional.FramedDisplay
HKLM\SYSTEM\CurrentControlSet\Services\Util glindorus =>PUP.Optional.glindorus
C:\Program Files (x86)\glindorus\bin\utilglindorus.exe =>PUP.Optional.glindorus
C:\Program Files (x86)\Browsers Apps-\Browsers Apps--codedownloader.exe =>PUP.Optional.CrossRider
C:\Program Files (x86)\Browsers Apps-\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-11.exe =>PUP.Optional.CrossRider
C:\Program Files (x86)\Browsers Apps-\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-3.exe =>PUP.Optional.CrossRider
C:\Program Files (x86)\Browsers Apps-\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-4.exe =>PUP.Optional.CrossRider
C:\Program Files (x86)\Browsers Apps-\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5.exe =>PUP.Optional.CrossRider
C:\Program Files (x86)\Browsers Apps-\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-6.exe =>PUP.Optional.CrossRider
C:\Program Files (x86)\Browsers Apps-\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-7.exe =>PUP.Optional.CrossRider
C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-1.job =>PUP.Optional.CrossRider
C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-11.job =>PUP.Optional.CrossRider
C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-3.job =>PUP.Optional.CrossRider
C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-4.job =>PUP.Optional.CrossRider
C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5.job =>PUP.Optional.CrossRider
C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5_user.job =>PUP.Optional.CrossRider
C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-6.job =>PUP.Optional.CrossRider
C:\windows\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-7.job =>PUP.Optional.CrossRider
C:\windows\Tasks\7fc7d17b-ba69-4bc7-ba33-2c036a5f94b3.job =>PUP.Optional.CrossRider
C:\windows\Tasks\bench-Updater removing.job =>PUP.Optional.CrossRider
C:\windows\Tasks\globalUpdateUpdateTaskMachineCore.job =>PUP.Optional.GlobalUpdate
C:\windows\Tasks\NewPlayer Update.job =>PUP.Optional.NewPlayer
C:\windows\Tasks\NewPlayer_wd.job =>PUP.Optional.NewPlayer
C:\windows\Tasks\SpeedUpMyPC Maintenance.job =>PUP.Optional.SpeedUpMyPC
C:\windows\Tasks\SpeedUpMyPC Startup.job =>PUP.Optional.SpeedUpMyPC
C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-1 =>PUP.Optional.CrossRider
C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-11 =>PUP.Optional.CrossRider
C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-3 =>PUP.Optional.CrossRider
C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-4 =>PUP.Optional.CrossRider
C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5 =>PUP.Optional.CrossRider
C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-5_user =>PUP.Optional.CrossRider
C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-6 =>PUP.Optional.CrossRider
C:\windows\System32\Tasks\4afdfb77-35e5-4a8c-945e-305f0cfe2aa4-7 =>PUP.Optional.CrossRider
C:\windows\System32\Tasks\7fc7d17b-ba69-4bc7-ba33-2c036a5f94b3 =>PUP.Optional.CrossRider
C:\windows\System32\Tasks\bench-Updater removing =>PUP.Optional.CrossRider
C:\windows\System32\Tasks\globalUpdateUpdateTaskMachineCore =>PUP.Optional.GlobalUpdate
C:\windows\System32\Tasks\NewPlayer Update =>PUP.Optional.NewPlayer
C:\windows\System32\Tasks\NewPlayer_wd =>PUP.Optional.NewPlayer
C:\windows\System32\Tasks\SpeedUpMyPC Maintenance =>PUP.Optional.SpeedUpMyPC
C:\windows\System32\Tasks\SpeedUpMyPC Startup =>PUP.Optional.SpeedUpMyPC
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Framed Display =>PUP.Optional.Sambreel
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\glindorus =>PUP.Optional.Sambreel
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ac225167-00fc-452d-94c5-bb93600e7d9a} =>PUP.Optional.BuzzDock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Browsers Apps- =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage =>PUP.Optional.Downware
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\wp-dcollect-tgu =>PUP.Optional.WebProtect
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{006E6A46-8D55-4F10-BBA8-2C9653B4278B} =>PUP.Optional.Boxore
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24} =>PUP.Optional.Linkury
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C8428739-5207-4817-9F19-69FA77018633} =>PUP.Optional.SmartBar
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D8D8A342-0E9F-47EA-A35E-CF431B50B286} =>PUP.Optional.Boxore
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AffiliatedUpdate =>PUP.Optional.Dealply
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CCleaner Packages =>PUP.Optional.InstallCore
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{085992c3-6315-4628-acd6-da11e3f8c7d8} =>PUP.Optional.SmartBar
HKLM\SOFTWARE\Wow6432Node\awesomehpSoftware =>PUP.Optional.AwesomeHP
HKLM\SOFTWARE\Wow6432Node\Babylon =>PUP.Optional.Babylon
HKLM\SOFTWARE\Wow6432Node\Boxore =>PUP.Optional.Boxore
HKLM\SOFTWARE\Wow6432Node\Browsers Apps- =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Browsers Apps--nv =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Duuqu =>PUP.Optional.FrameFox
HKLM\SOFTWARE\Wow6432Node\Framed Display =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Freesofttoday =>PUP.Optional.Multiplug
HKLM\SOFTWARE\Wow6432Node\glindorus =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\GlobalUpdate =>PUP.Optional.GlobalUpdate
HKLM\SOFTWARE\Wow6432Node\InstallCore =>PUP.Optional.InstallCore
HKLM\SOFTWARE\Wow6432Node\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions
HKLM\SOFTWARE\Wow6432Node\mysearchdial =>PUP.Optional.MySearchDial
HKLM\SOFTWARE\Wow6432Node\PCTRunner =>PUP.Optional.WebProtect
HKLM\SOFTWARE\Wow6432Node\supTab =>PUP.Optional.SupTab
HKLM\SOFTWARE\Wow6432Node\supWPM =>PUP.Optional.WpManager
HKLM\SOFTWARE\Wow6432Node\Systweak =>PUP.Optional.Systweak
HKLM\SOFTWARE\Wow6432Node\Tutorials =>PUP.Optional.AgenceExclusive
HKLM\SOFTWARE\Wow6432Node\Uniblue =>PUP.Optional.Uniblue
HKCU\SOFTWARE\1ClickDownload =>PUP.Optional.1ClickDownloader
HKCU\SOFTWARE\Boxore =>PUP.Optional.Boxore
HKCU\SOFTWARE\Duuqu =>PUP.Optional.FrameFox
HKCU\SOFTWARE\Framed Display =>PUP.Optional.Sambreel
HKCU\SOFTWARE\freesofttoday =>PUP.Optional.Multiplug
HKCU\SOFTWARE\Gameo =>PUP.Optional.Gameo
HKCU\SOFTWARE\Genesis =>PUP.Optional.Genesis
HKCU\SOFTWARE\glindorus =>PUP.Optional.Sambreel
HKCU\SOFTWARE\globalUpdate =>PUP.Optional.GlobalUpdate
HKCU\SOFTWARE\Iminent =>PUP.Optional.IMBooster
HKCU\SOFTWARE\InstallCore =>PUP.Optional.InstallCore
HKCU\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions
HKCU\SOFTWARE\mysearchdial =>PUP.Optional.MySearchDial
HKCU\SOFTWARE\mysearchdial.com =>PUP.Optional.MySearchDial
HKCU\SOFTWARE\Optimizer Pro =>PUP.Optional.OptimizerPro
HKCU\SOFTWARE\PCTRunner =>PUP.Optional.WebProtect
HKCU\SOFTWARE\PerformerSoft LLC =>PUP.Optional.PerformerSoft
HKCU\SOFTWARE\Smartbar =>PUP.Optional.SmartBar
HKCU\SOFTWARE\SmartbarBackup =>PUP.Optional.SmartBar
HKCU\SOFTWARE\SmartbarLog =>PUP.Optional.SmartBar
HKCU\SOFTWARE\StormWatch =>PUP.Optional.StormWatch
HKCU\SOFTWARE\Systweak =>PUP.Optional.Systweak
HKCU\SOFTWARE\Tutorials =>PUP.Optional.AgenceExclusive
HKCU\SOFTWARE\TutoTag =>PUP.Optional.AgenceExclusive
HKCU\SOFTWARE\AppDataLow\Software\Browsers Apps- =>PUP.Optional.CrossRider =>PUP.Optional.CrossRider
HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider =>PUP.Optional.CrossRider
C:\Program Files (x86)\Boxore =>PUP.Optional.Boxore
C:\Program Files (x86)\Browsers Apps- =>PUP.Optional.CrossRider
C:\Program Files (x86)\Duuqu =>PUP.Optional.Duuqu
C:\Program Files (x86)\Framed Display =>PUP.FramedDisplay
C:\Program Files (x86)\glindorus =>PUP.Glindorus
C:\Program Files (x86)\globalUpdate =>PUP.Optional.GlobalUpdate
C:\Program Files (x86)\HiDefMedia =>PUP.Optional.HiDefMedia
C:\Program Files (x86)\Mysearchdial =>PUP.Optional.MySearchDial
C:\Program Files (x86)\NewPlayer =>PUP.Optional.NewPlayer
C:\Program Files (x86)\Pay-By-Ads =>PUP.Optional.PaybyAds
C:\Program Files (x86)\PCTRunner =>PUP.Optional.WebProtect
C:\Program Files (x86)\predm =>PUP.Optional.Downware
C:\Program Files (x86)\QueeeNCOupon =>PUP.Optional.Multiplug
C:\Program Files (x86)\SearchProtect923167 =>PUP.SearchProtect
C:\Program Files (x86)\SmuartComparre =>PUP.Optional.Multiplug
C:\Program Files (x86)\SupTab =>PUP.Optional.SupTab
C:\Program Files (x86)\ver5NewPlayer =>PUP.Optional.NewPlayer
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewPlayer =>PUP.Optional.NewPlayer
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip =>PUP.Optional.PepperZip
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue =>PUP.Optional.Uniblue
C:\ProgramData\Babylon =>PUP.Optional.Babylon
C:\ProgramData\IePluginService =>PUP.Optional.IePluginService
C:\ProgramData\QueeeNCOupon =>PUP.Optional.Multiplug
C:\ProgramData\SmuartComparre =>PUP.Optional.Multiplug
C:\ProgramData\WPM =>PUP.Optional.WpManager
C:\Users\gabriel\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z =>PUP.Optional.InstallCore
C:\Users\gabriel\AppData\Roaming\awesomehp =>PUP.Optional.AwesomeHP
C:\Users\gabriel\AppData\Roaming\Babylon =>PUP.Optional.Babylon
C:\Users\gabriel\AppData\Roaming\mysearchdial =>PUP.Optional.MySearchDial
C:\Users\gabriel\AppData\Roaming\PerformerSoft =>PUP.Optional.PerformerSoft
C:\Users\gabriel\AppData\Roaming\Systweak =>PUP.Optional.Systweak
C:\Users\gabriel\AppData\Roaming\Uniblue =>PUP.Optional.Uniblue
C:\Users\gabriel\AppData\Roaming\VOPackage =>PUP.Optional.Downware
C:\Users\gabriel\AppData\Local\Duuqu =>PUP.Optional.Duuqu
C:\Users\gabriel\AppData\Local\Gameo =>PUP.Optional.Gameo
C:\Users\gabriel\AppData\Local\globalUpdate =>PUP.Optional.GlobalUpdate
C:\Users\gabriel\AppData\Local\newplayer =>PUP.Optional.NewPlayer
C:\Users\gabriel\AppData\Local\Pay-By-Ads =>PUP.Optional.PaybyAds
C:\Users\gabriel\AppData\Local\Smartbar =>PUP.Optional.SmartBar
C:\Users\gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage =>PUP.Optional.Downware
C:\windows\System32\drivers\{26d264d2-014c-4f07-bf2c-ebf9aed40cef}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{2859046f-5dca-482a-8c2d-37943d33a392}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{29302da5-1178-40ac-a178-4cb57ebcc501}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{43cf8855-c9cb-4281-aca0-c67a8c4b59de}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{44a99463-0ff3-4b62-9d3c-802722bf3043}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{5f0f49f4-526a-4e0c-b198-a0742c879601}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{6db7eb66-a30b-41a3-809c-addb2341dafb}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{7012eec1-4f37-42d4-a2cd-26727494d248}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{77288bc4-30b5-49f8-88e2-b9b5110ed762}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{8c39d0b0-9b68-43ef-bc3c-2ef385fe5169}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{9de7e012-74d3-4f9d-b4b0-2d3150073168}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{a6762132-8e80-4305-b1ba-2bec91757ac2}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{b30c55f2-a940-4907-8051-f13c9acdacdd}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{cd63c300-b231-4a93-a479-5a1e96976d74}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{dda91daf-e6f8-4453-88d1-df18d861c904}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\System32\drivers\{e9bebce7-deb3-4ab9-896c-549739f208c5}w64.sys =>PUP.Optional.LinkiDoo
C:\windows\Installer\{D8D8A342-0E9F-47EA-A35E-CF431B50B286}\boxore.ico =>PUP.Optional.Boxore
HKLM\Software\Classes\Installer\Products\243A8D8DF9E0AE743AE5FC34B1052B68 =>PUP.Optional.Boxore
HKLM\Software\Classes\Installer\Features\243A8D8DF9E0AE743AE5FC34B1052B68 =>PUP.Optional.Boxore
C:\windows\Installer\2fac9.msi =>PUP.Optional.Boxore
C:\windows\Installer\b8fd8f.msi =>PUP.Optional.Linkury
HKLM\SYSTEM\CurrentControlSet\Services\globalUpdatem =>PUP.Optional.GlobalUpdate
HKLM\SYSTEM\CurrentControlSet\Services\LPTSystemUpdater =>PUP.Optional.Linkury
C:\Program Files (x86)\LPT\srpts.exe =>PUP.Optional.Linkury
HKLM\SYSTEM\CurrentControlSet\Services\MyOSProtect =>PUP.Optional.MyOSProtect
C:\Program Files (x86)\PCTRunner\MyOSProtect.exe =>PUP.Optional.MyOSProtect
HKLM\SYSTEM\CurrentControlSet\Services\Update Framed Display =>PUP.FramedDisplay
HKLM\SYSTEM\CurrentControlSet\Services\Update glindorus =>PUP.Glindorus
HKLM\SYSTEM\CurrentControlSet\Services\Util Framed Display =>PUP.FramedDisplay
C:\Program Files (x86)\Framed Display\bin\utilFramedDisplay.exe =>PUP.FramedDisplay
HKLM\SYSTEM\CurrentControlSet\Services\Util glindorus =>PUP.Glindorus
HKLM64\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32 =>PUP.Optional.MyPCBackup
HKLM64\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS =>PUP.Optional.MyPCBackup
HKLM64\SOFTWARE\Microsoft\Tracing\FramedDisplay_RASAPI32 =>PUP.FramedDisplay
HKLM64\SOFTWARE\Microsoft\Tracing\FramedDisplay_RASMANCS =>PUP.FramedDisplay
HKLM64\SOFTWARE\Microsoft\Tracing\glindorus_RASAPI32 =>PUP.Optional.Sambreel
HKLM64\SOFTWARE\Microsoft\Tracing\glindorus_RASMANCS =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32 =>PUP.Optional.AdvancedSystemProtector
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS =>PUP.Optional.AdvancedSystemProtector
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BabMaint_RASAPI32 =>PUP.Optional.BabSolution
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BabMaint_RASMANCS =>PUP.Optional.BabSolution
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\boxore_RASAPI32 =>PUP.Optional.Boxore
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\boxore_RASMANCS =>PUP.Optional.Boxore
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\browsers apps--bg_RASAPI32 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\browsers apps--bg_RASMANCS =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Browsers Apps--codedownloader_RASAPI32 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Browsers Apps--codedownloader_RASMANCS =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FastPlayer_RASAPI32 =>PUP.Optional.FastPlayer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FastPlayer_RASMANCS =>PUP.Optional.FastPlayer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FLVPlayerSetup_RASAPI32 =>PUP.Optional.FLVPlayer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FLVPlayerSetup_RASMANCS =>PUP.Optional.FLVPlayer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FramedDisplay_RASAPI32 =>PUP.FramedDisplay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FramedDisplay_RASMANCS =>PUP.FramedDisplay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FramedDisplay_Setup_RASAPI32 =>PUP.FramedDisplay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FramedDisplay_Setup_RASMANCS =>PUP.FramedDisplay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\gameo_RASAPI32 =>PUP.Optional.Gameo
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\gameo_RASMANCS =>PUP.Optional.Gameo
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\glindorus_2709-e3c075a1_RASAPI32 =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\glindorus_2709-e3c075a1_RASMANCS =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\glindorus_RASAPI32 =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\glindorus_RASMANCS =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\glindorus_Setup_RASAPI32 =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\glindorus_Setup_RASMANCS =>PUP.Optional.Sambreel
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\IminentSetup_2509-9f33b5cf_RASAPI32 =>PUP.Optional.IMBooster
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\IminentSetup_2509-9f33b5cf_RASMANCS =>PUP.Optional.IMBooster
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Iminent_RASAPI32 =>PUP.Optional.IMBooster
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Iminent_RASMANCS =>PUP.Optional.IMBooster

---\\ Récapitulatif des éléments trouvées sur votre station (54) - 0s
http://www.nicolascoolman.fr/blog =>PUP.Optional.NewPlayer
http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider
http://www.nicolascoolman.fr/pup-globalupdate/ =>PUP.Optional.GlobalUpdate
http://www.nicolascoolman.fr/blog =>PUP.Optional.WebProtect
http://www.nicolascoolman.fr/blog =>PUP.FramedDisplay
http://www.nicolascoolman.fr/pup-paybyads/ =>PUP.Optional.PaybyAds
http://www.nicolascoolman.fr/blog =>PUP.Glindorus
http://www.nicolascoolman.fr/blog =>PUP.Optional.Sambreel
http://www.nicolascoolman.fr/adware-boxore/ =>PUP.Optional.Boxore
http://www.nicolascoolman.fr/pup-helperbar/ =>PUP.Optional.HelperBar
http://www.nicolascoolman.fr/pup-awesomehp/ =>PUP.Optional.AwesomeHP
http://www.nicolascoolman.fr/blog =>PUP.Optional.FramedDisplay
http://www.nicolascoolman.fr/hijacker-smartbar/ =>PUP.Optional.SmartBar
http://www.nicolascoolman.fr/adware-hotbar/ =>PUP.Optional.Hotbar
http://www.nicolascoolman.fr/blog =>PUP.Optional.FLVPlayer
http://www.nicolascoolman.fr/blog =>PUP.Optional.SpeedUpMyPC
http://www.nicolascoolman.fr/blog =>PUP.Optional.MaintainerSvc
http://www.nicolascoolman.fr/trojan-bitcoinminer/ =>Trojan.BitCoinMiner
http://www.nicolascoolman.fr/pup-glindorus/ =>PUP.Optional.glindorus
http://www.nicolascoolman.fr/blog =>PUP.Optional.BuzzDock
http://www.nicolascoolman.fr/adware-downware/ =>PUP.Optional.Downware
http://www.nicolascoolman.fr/blog =>PUP.Optional.Linkury
http://www.nicolascoolman.fr/pup-dealply/ =>PUP.Optional.Dealply
http://www.nicolascoolman.fr/adware-installcore/ =>PUP.Optional.InstallCore
http://www.nicolascoolman.fr/pup-babylon/ =>PUP.Optional.Babylon
http://www.nicolascoolman.fr/pup-framefox / =>PUP.Optional.FrameFox
http://www.nicolascoolman.fr/pup-mutiplug/ =>PUP.Optional.Multiplug
http://www.nicolascoolman.fr/blog =>PUP.Optional.BrowserExtensions
http://www.nicolascoolman.fr/blog =>PUP.Optional.MySearchDial
http://www.nicolascoolman.fr/pup-suptab/ =>PUP.Optional.SupTab
http://www.nicolascoolman.fr/pup-wpmanager/ =>PUP.Optional.WpManager
http://www.nicolascoolman.fr/pup-systweak/ =>PUP.Optional.Systweak
http://www.nicolascoolman.fr/spyware-agenceexclusive/ =>PUP.Optional.AgenceExclusive
http://www.nicolascoolman.fr/blog =>PUP.Optional.Uniblue
http://www.nicolascoolman.fr/pup-1clickdownloader/ =>PUP.Optional.1ClickDownloader
http://www.nicolascoolman.fr/blog =>PUP.Optional.Gameo
http://www.nicolascoolman.fr/pup-genesis/ =>PUP.Optional.Genesis
http://www.nicolascoolman.fr/adware-imbooster/ =>PUP.Optional.IMBooster
http://www.nicolascoolman.fr/pup-optimizerpro/ =>PUP.Optional.OptimizerPro
http://www.nicolascoolman.fr/blog =>PUP.Optional.PerformerSoft
http://www.nicolascoolman.fr/blog =>PUP.Optional.StormWatch
http://www.nicolascoolman.fr/pup-duuqu/ =>PUP.Optional.Duuqu
http://www.nicolascoolman.fr/blog =>PUP.Optional.HiDefMedia
http://www.nicolascoolman.fr/blog =>PUP.SearchProtect
http://www.nicolascoolman.fr/blog =>PUP.Optional.PepperZip
http://www.nicolascoolman.fr/blog =>PUP.Optional.IePluginService
http://www.nicolascoolman.fr/pup-linkidoo/ =>PUP.Optional.LinkiDoo
http://www.nicolascoolman.fr/blog =>PUP.Optional.Monetization
http://www.nicolascoolman.fr/pup-astromenda/ =>PUP.Optional.Astromenda
http://www.nicolascoolman.fr/blog =>PUP.Optional.MyOSProtect
http://www.nicolascoolman.fr/pup-mypcbackup/ =>PUP.Optional.MyPCBackup
http://www.nicolascoolman.fr/pup-advancedsystemprotector/ =>PUP.Optional.AdvancedSystemProtector
http://www.nicolascoolman.fr/hijacker-babsolution/ =>PUP.Optional.BabSolution
http://www.nicolascoolman.fr/blog =>PUP.Optional.FastPlayer

~ End of the scan, 54716 items in 128 seconds (1396)(0)()

Publicité


Signaler le contenu de ce document

Publicité