cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.8.15.119 Par Nicolas Coolman (2015/08/15)
~ Démarré par Propriétaire (Administrator) (2015/08/16 17:02:16)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Documents and Settings\Propriétaire.POT-26C99C14026\Bureau\ZHPDiag.txt
~ Rapport: C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\ZHP\ZHPDiag.txt
~ UAC: Deactivate
~ Démarrage du système: Normal (Normal boot)
Windows XP, 32-bit Service Pack 3 (Build 2600)

---\\ Navigateurs Internet (1) - 0s
MSIE: Internet Explorer v6.0.2900.5512

---\\ Logiciels de protection (3) - 1s
Avast Free Antivirus v10.3.2225
Microsoft Security Client v4.4.0304.0
Microsoft Security Essentials v4.4.304.0

---\\ Surveillance de Logiciels (2) - 2s
Adobe Flash Player 18 NPAPI
Adobe Reader XI

---\\ Informations sur le système (6) - 0s
~ Operating System: x86 Family 6 Model 58 Stepping 9, GenuineIntel
~ Operating System: 32-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 3565.524 MB (71% free)
~ System Restore: Activé (Enable)
~ System drive C: has 432 GB free of 476 GB

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: POT-26C99C14026
~ User Name: Propriétaire
~ Logged in as Administrator

---\\ Enumération des unités disques (1) - 0s
~ Drive C: has 432 GB free of 476 GB (System)

---\\ Etat du Centre de Sécurité Windows (9) - 0s
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Intl: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] XMLLookup: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Recherche particulière de fichiers génériques (22) - 1s
[MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\WINDOWS\Explorer.exe [1037824]
[MD5.93AD0B78C7357A05F50E594EC7C22300] - (.Microsoft Corporation - Exécuter une DLL en tant qu'application.) () -- C:\WINDOWS\System32\rundll32.exe [33792]
[MD5.C95CAC9E1322713AAC888DED4A748EEC] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\WINDOWS\System32\wininet.dll [672768]
[MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows.) () -- C:\WINDOWS\System32\Winlogon.exe [512000]
[MD5.1E44BC1E83D8FD2305F8D452DB109CF9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\WINDOWS\System32\drivers\AFD.sys [138496]
[MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) () -- C:\WINDOWS\System32\drivers\atapi.sys [96512]
[MD5.C885B02847F5D2FD45A24E219ED93B32] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\WINDOWS\System32\drivers\Cdfs.sys [63744]
[MD5.1F4260CC5B42272D71F79E570A27A4FE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\WINDOWS\System32\drivers\Cdrom.sys [62976]
[MD5.31F923EB2170FC172C81ABDA0045D18C] - (.Microsoft Corporation - Pilote de cryptographie FIPS.) () -- C:\WINDOWS\System32\drivers\Fips.sys [44672]
[MD5.573C7D0A32852B48F3058CFD8026F511] - (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) () -- C:\WINDOWS\System32\drivers\HDAudBus.sys [144384]
[MD5.A09BDC4ED10E3B2E0EC27BB94AF32516] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\WINDOWS\System32\drivers\i8042prt.sys [54144]
[MD5.083A052659F5310DD8B6A6CB05EDCF8E] - (.Microsoft Corporation - IMAPI Kernel Driver.) () -- C:\WINDOWS\System32\drivers\Imapi.sys [42112]
[MD5.CC748EA12C6EFFDE940EE98098BF96BB] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\WINDOWS\System32\drivers\IpNat.sys [152832]
[MD5.23C74D75E36E7158768DD63D92789A91] - (.Microsoft Corporation - IPSec Driver.) () -- C:\WINDOWS\System32\drivers\IPSec.sys [75264]
[MD5.7D304A5EB4344EBEEAB53A2FE3FFB9F0] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\WINDOWS\System32\drivers\MRxSmb.sys [456320]
[MD5.74B2B2F5BEA5E9A3DC021D685551BD3D] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\WINDOWS\System32\drivers\netBT.sys [162816]
[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) () -- C:\WINDOWS\System32\drivers\ntfs.sys [574976]
[MD5.8FD0BDBEA875D06CCF6C945CA9ABAF75] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\WINDOWS\System32\drivers\Parport.sys [80384]
[MD5.11B4A627BC9614B885C4969BFA5FF8A6] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [51328]
[MD5.15CABD0F7C00C47C70124907916AF3F1] - (.Microsoft Corporation - Microsoft RDP Device redirector.) () -- C:\WINDOWS\System32\drivers\rdpdr.sys [196224]
[MD5.D8EB2A7904DB6C916EB5361878DDCBAE] - (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) () -- C:\WINDOWS\System32\drivers\redbook.sys [58752]
[MD5.46DE1126684369BACE4849E4FC8C43CA] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\WINDOWS\System32\drivers\volsnap.sys [53376]

---\\ Processus lancés (15) - 2s
[MD5.4956380A54B1C9E6BFDF3D80DACB9698] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600] [PID.1780]
[MD5.AFFF9B106DB80D85FAEE14D47ECFC3CD] - (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe [462088] [PID.468]
[MD5.4F0F3FDE7F571531B356B8BAB55DDF05] - (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) -- C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720] [PID.488]
[MD5.32BB92C41C73D0213B417AAEF83E3D30] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [277824] [PID.560]
[MD5.B89514A95A9D435EB974EA22153BB9FF] - (.Intel Corporation - User Notification Service.) -- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [365376] [PID.716]
[MD5.0D8F0BB0AC8C2EA14B4E60C75FAF052C] - (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\system32\hkcmd.exe [181528] [PID.1140]
[MD5.A333781DD2DFFFB2447413491158B02E] - (.Intel Corporation - persistence Module.) -- C:\WINDOWS\system32\igfxpers.exe [169752] [PID.1148]
[MD5.8C31C7B29061F27A850654F292BCB9DD] - (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.EXE [20065936] [PID.1312]
[MD5.7E6EFC5383FEF3EF852F2C7D41DEE83F] - (.Brother Industries, Ltd. - Brother Status Monitor MFC Application.) -- C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [663552] [PID.1460]
[MD5.D6FE9E0F705794A86F87A01B222290EF] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [6109776] [PID.1476]
[MD5.B7FB48205F2E7FC9810B001CC0B46B55] - (.Copyright (C) 2007 - NetgearCUv3 MFC Application.) -- C:\Program Files\NETGEAR\WNA1000M\WNA1000M.exe [2079200] [PID.984]
[MD5.09622B465C5F98600CBA53B758A266F4] - (.Brother Industries, Ltd. - Status Monitor (Local).) -- C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe [98304] [PID.2904]
[MD5.362915F307064C669B47A7B5389862DA] - (.Intel Corporation - Intel(R) Management and Security Status.) -- C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe [1844544] [PID.2140]
[MD5.749C9E51E6D5A5AC23D2B4B8B63CAFE9] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [377000] [PID.1568]
[MD5.69924CB1D8D8ED7D67FF2AC269119084] - (.Nicolas Coolman - ZHPDiag.) -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Mes documents\Téléchargements\ZHPDiag3.exe [1902592] [PID.568]

---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) (11) - 1s
M1 - SPR:Search Page Redirection - C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
M1 - SPR:Search Page Redirection - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
M1 - SPR:Search Page Redirection - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
M1 - SPR:Search Page Redirection - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.FRA
P2 - EXT FILE: (...) -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\Mozilla\Firefox\Profiles\n75b5yho.default-1432466562656\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\delta-homes.xml =>PUP.Optional.DeltaHomes
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\sweet-page.xml =>PUP.Optional.SweetPage
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll
P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.1.3] - (.VideoLAN.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll

---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) (8) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = about:newtab
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer
R3 - URLSearchHook: (no name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} Orphean

---\\ Internet Explorer, Proxy Management (R5) (3) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe (.Microsoft Corporation.)
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.)
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"

---\\ Hosts file redirection (O1) (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (20)

---\\ Browser Helper Object de navigateur (BHO) (O2) (1) - 0s
O2 - BHO: (no name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} (Orphean)

---\\ Internet Explorer Toolbars (O3) (1) - 0s
O3 - Toolbar: 0x7F7C02D44A156640A1AD4243D8127440 - [HKCU]{D4027C7F-154A-4066-A1AD-4243D8127440} . (...) -- (.not file.)

---\\ Applications lancées au démarrage du sytème (O4) (19) - 1s
O4 - HKLM\..\Run: [IMSS] . (.Intel Corporation - PIcon startup utility.) -- C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] . (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.EXE
O4 - HKLM\..\Run: [SSBkgdUpdate] . (.Nuance Communications, Inc. - SSBkgdUpdate.) -- C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe
O4 - HKLM\..\Run: [BrMfcWnd] . (.Brother Industries, Ltd. - Brother Status Monitor MFC Application.) -- C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files\Mobogenie\DaemonProcess.exe (.not file.) =>PUP.Optional.Mobogenie
O4 - HKLM\..\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] . (.Microsoft Corporation - Watson Subscriber for SENS Network Notifica.) -- c:\Program Files\Fichiers communs\Microsoft Shared\DW\DWTRIG20.EXE
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] . (.Microsoft Corporation - Watson Subscriber for SENS Network Notifica.) -- c:\Program Files\Fichiers communs\Microsoft Shared\DW\DWTRIG20.EXE
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1606980848-179605362-725345543-1003\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe

---\\ Modification Domaine/Adresses DNS (O17) (9) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = lan
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpDomain = lan
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: DhcpDomain = lan

---\\ Liste des services NT non Microsoft et non désactivés (O23) (6) - 1s
O23 - Service: Avast Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) - C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

---\\ Enumère les données de BootExecute (BEX) (O34) (1) - 0s
O34 - HKLM BootExecute: (sprestrt) (.Microsoft Corporation - Restaure le registre pour redémarrer la par.) -- C:\WINDOWS\System32\sprestrt.exe

---\\ Tâches planifiées en automatique (O39) (5) - 0s
O39 - APT: Orphean - (...) -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT: Orphean - (...) -- C:\WINDOWS\Tasks\avast! Emergency Update.job [364]
O39 - APT: Orphean - (...) -- C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job [400]
O39 - APT: Orphean - (...) -- C:\WINDOWS\Tasks\Notification de fin de service de Microsoft Windows XP - à la connexion.job [236]
O39 - APT: Orphean - (...) -- C:\WINDOWS\Tasks\Notification de fin de service de Microsoft Windows XP -mensuellement.job [230]

---\\ Logiciels installés (O42) (40) - 3s
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- Adobe AIR
O42 - Logiciel: Adobe Flash Player 18 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI
O42 - Logiciel: Avast Free Antivirus - (.AVAST Software.) [HKLM] -- Avast
O42 - Logiciel: NETGEAR WNA1000M Wireless USB 2.0 Adapter - (.Nom de votre société.) [HKLM] -- InstallShield_{62F7B391-E2B2-4714-BBAA-A14E4FAAB95C}
O42 - Logiciel: Windows Genuine Advantage Validation Tool (KB892130) - (.Microsoft Corporation.) [HKLM] -- KB892130
O42 - Logiciel: Package de base Microsoft de service de chiffrement pour cartes à puce - (.Microsoft Corporation.) [HKLM] -- KB909520
O42 - Logiciel: Hotfix for Windows XP (KB915800-v4) - (.Microsoft Corporation.) [HKLM] -- KB915800-v4
O42 - Logiciel: Hotfix for Windows Media Format 11 SDK (KB929399) - (.Microsoft Corporation.) [HKLM] -- KB929399
O42 - Logiciel: Windows Search 4.0 - (.Microsoft Corporation.) [HKLM] -- KB940157
O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5
O42 - Logiciel: Security Update for Windows Search 4 - KB963093 - (.Microsoft Corporation.) [HKLM] -- KB963093
O42 - Logiciel: Windows Management Framework Core - (.Microsoft Corporation.) [HKLM] -- KB968930
O42 - Logiciel: Hotfix for Windows XP (KB976002-v5) - (.Microsoft Corporation.) [HKLM] -- KB976002-v5
O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client
O42 - Logiciel: Mozilla Firefox 40.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 40.0.2 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: Microsoft Compression Client Pack 1.0 for Windows XP - (.Microsoft Corporation.) [HKLM] -- MSCompPackV1
O42 - Logiciel: Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 - (.Microsoft Corporation.) [HKLM] -- Wdf01009
O42 - Logiciel: Windows Media Format 11 runtime - (...) [HKLM] -- Windows Media Format Runtime
O42 - Logiciel: Lecteur Windows Media 11 - (...) [HKLM] -- Windows Media Player
O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM] -- WMFDist11
O42 - Logiciel: Windows Media Player 11 - (.Microsoft Corporation.) [HKLM] -- wmp11
O42 - Logiciel: Microsoft User-Mode Driver Framework Feature Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- Wudf01000
O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {0CD47142-BA4F-46B0-AA92-2675864928B8}
O42 - Logiciel: CutterProcessor - (.Software Publisher.) [HKLM] -- {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{f080fb60} =>PUP.Optional.Graftor
O42 - Logiciel: Skype™ 7.4 - (.Skype Technologies S.A..) [HKLM] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- {31B9D218-FED2-4C6C-B19F-7294FFC130B0}
O42 - Logiciel: ON_OFF Charge B11.1102.1 - (.GIGABYTE.) [HKLM] -- {3DECD372-76A1-4483-BF10-B547790A3261}
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: OpenOffice 4.0.1 - (.Apache Software Foundation.) [HKLM] -- {8D5D54B8-3D29-4AB4-8DA8-1868DAF941D8}
O42 - Logiciel: Conseiller de mise à niveau vers Windows 7 - (.Microsoft Corporation.) [HKLM] -- {9D10CB57-B085-44c3-B435-2D193BA153F0}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Adobe Reader XI (11.0.08) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AB0000000001}
O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM] -- {BCED7487-44BC-487C-94CF-824AB27909E0}
O42 - Logiciel: REALTEK GbE & FE Ethernet PCI-E NIC Driver - (.Realtek.) [HKLM] -- {C9BED750-1211-4480-B1A5-718A3BE15525}
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}

---\\ HKCU & HKLM Software Keys (74) - 3s
HKLM\SOFTWARE\Adobe
HKLM\SOFTWARE\AdwCleaner
HKLM\SOFTWARE\AVAST Software
HKLM\SOFTWARE\Brother
HKLM\SOFTWARE\C07ft5Y
HKLM\SOFTWARE\cameo
HKLM\SOFTWARE\cbb813a7-c4ea-0f50-3575-8767a9c375bc =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Creative Tech
HKLM\SOFTWARE\delta-homesSoftware =>PUP.Optional.DeltaHomes
HKLM\SOFTWARE\Dropbox
HKLM\SOFTWARE\Gemplus
HKLM\SOFTWARE\GIGABYTE
HKLM\SOFTWARE\Google
HKLM\SOFTWARE\IHProtect =>PUP.Optional.AgentODR
HKLM\SOFTWARE\IM Providers
HKLM\SOFTWARE\Iminent =>PUP.Optional.IMBooster
HKLM\SOFTWARE\InstallShield
HKLM\SOFTWARE\Intel
HKLM\SOFTWARE\Macromedia
HKLM\SOFTWARE\McAfee.com
HKLM\SOFTWARE\MDC
HKLM\SOFTWARE\Mozilla
HKLM\SOFTWARE\mozilla.org
HKLM\SOFTWARE\MozillaPlugins
HKLM\SOFTWARE\Nero
HKLM\SOFTWARE\NETGEAR
HKLM\SOFTWARE\ODBC
HKLM\SOFTWARE\OpenOffice
HKLM\SOFTWARE\Program Groups
HKLM\SOFTWARE\Realtek
HKLM\SOFTWARE\Realtek Semiconductor Corp.
HKLM\SOFTWARE\RegisteredApplications
HKLM\SOFTWARE\RTLSetup
HKLM\SOFTWARE\RtWlan
HKLM\SOFTWARE\ScanSoft
HKLM\SOFTWARE\Schlumberger
HKLM\SOFTWARE\Secure
HKLM\SOFTWARE\Skype
HKLM\SOFTWARE\SupDp =>PUP.Optional.SupTab
HKLM\SOFTWARE\supWindowsMangerProtect =>PUP.Optional.Fuyu
HKLM\SOFTWARE\sweet-pageSoftware =>PUP.Optional.SweetPage
HKLM\SOFTWARE\Trymedia Systems =>PUP.Optional.Trymedia
HKLM\SOFTWARE\Windows 3.1 Migration Status
HKLM\SOFTWARE\Zeon
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\AVAST Software
HKCU\SOFTWARE\Brother
HKCU\SOFTWARE\DownloadCenter
HKCU\SOFTWARE\EasySystems
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\InstallCore =>PUP.Optional.InstallCore
HKCU\SOFTWARE\Intel
HKCU\SOFTWARE\kde.org
HKCU\SOFTWARE\Local AppWizard-Generated Applications
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\Macrovision
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\Nero
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\Nuance
HKCU\SOFTWARE\NVIDIA Corporation
HKCU\SOFTWARE\OpenOffice
HKCU\SOFTWARE\Realtek
HKCU\SOFTWARE\RtWlan
HKCU\SOFTWARE\SCS Software
HKCU\SOFTWARE\Skype
HKCU\SOFTWARE\Softonic =>PUP.Optional.Softonic
HKCU\SOFTWARE\Super Optimizer =>PUP.Optional.SuperOptimizer
HKCU\SOFTWARE\TeleCharger
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\ZebHelpProcess Helper

---\\ Contenu des dossiers Programmes (O43) (211) - 3s
O43 - CFD: 2012/02/27 14:23:33 - [] D -- C:\Program Files\3GPConverter2011
O43 - CFD: 2015/08/15 21:04:03 - [] D -- C:\Program Files\Adobe
O43 - CFD: 2012/04/18 14:13:40 - [] D -- C:\Program Files\Adobe Download Assistant
O43 - CFD: 2008/09/16 19:15:11 - [] D -- C:\Program Files\adslTV
O43 - CFD: 2006/01/18 18:56:15 - [] D -- C:\Program Files\Ahead
O43 - CFD: 2010/10/22 12:24:43 - [] D -- C:\Program Files\Alwil Software
O43 - CFD: 2007/12/02 11:12:16 - [] D -- C:\Program Files\ArcSoft
O43 - CFD: 2006/03/15 15:19:14 - [] D -- C:\Program Files\Aubade
O43 - CFD: 2014/04/08 12:22:06 - [] D -- C:\Program Files\AVAST Software
O43 - CFD: 2012/01/21 19:31:17 - [] D -- C:\Program Files\AVS4YOU
O43 - CFD: 2006/06/15 16:11:16 - [0] D -- C:\Program Files\AWS
O43 - CFD: 2010/08/27 10:09:21 - [] D -- C:\Program Files\BingoLiner
O43 - CFD: 2013/03/17 15:28:38 - [] D -- C:\Program Files\BitTorrent_DNA
O43 - CFD: 2007/01/25 18:25:53 - [] D -- C:\Program Files\BlazeDVD 4 Professional
O43 - CFD: 2010/02/01 18:56:16 - [] D -- C:\Program Files\BlueSquad
O43 - CFD: 2006/05/06 19:53:58 - [] D -- C:\Program Files\BoontyGames
O43 - CFD: 2008/10/24 18:54:17 - [] D -- C:\Program Files\Brother
O43 - CFD: 2015/02/26 11:11:13 - [] D -- C:\Program Files\bUUyfaast
O43 - CFD: 2015/02/26 11:11:13 - [] D -- C:\Program Files\buyafast
O43 - CFD: 2006/03/05 02:07:31 - [] D -- C:\Program Files\Common Files
O43 - CFD: 2005/12/19 19:05:13 - [0] D -- C:\Program Files\ComPlus Applications
O43 - CFD: 2015/02/26 12:58:39 - [0] D -- C:\Program Files\CutterProcessor
O43 - CFD: 2012/02/27 14:21:22 - [] D -- C:\Program Files\DealBulldog Toolbar Toolbar =>PUP.Optional.SocialSkinz
O43 - CFD: 2010/04/30 18:53:42 - [] D -- C:\Program Files\DIFX
O43 - CFD: 2008/10/03 08:03:24 - [] D -- C:\Program Files\DivX
O43 - CFD: 2005/12/20 21:32:40 - [] D -- C:\Program Files\DVD Shrink
O43 - CFD: 2007/08/07 19:31:54 - [] D -- C:\Program Files\eChanblard
O43 - CFD: 2009/10/17 21:42:11 - [] D -- C:\Program Files\eMule
O43 - CFD: 2015/08/15 21:01:31 - [] D -- C:\Program Files\Fichiers communs
O43 - CFD: 2012/03/03 15:45:10 - [] D -- C:\Program Files\FreeTime
O43 - CFD: 2013/04/14 07:06:12 - [] D -- C:\Program Files\GIGABYTE
O43 - CFD: 2015/08/15 20:43:50 - [] D -- C:\Program Files\Google
O43 - CFD: 2006/09/06 21:14:28 - [] D -- C:\Program Files\Hercules
O43 - CFD: 2007/08/07 10:36:01 - [] D -- C:\Program Files\Ihsv
O43 - CFD: 2013/04/14 07:06:12 - [] HD -- C:\Program Files\InstallShield Installation Information
O43 - CFD: 2013/04/14 07:03:00 - [] D -- C:\Program Files\Intel
O43 - CFD: 2014/04/08 13:19:19 - [] D -- C:\Program Files\Internet Explorer
O43 - CFD: 2013/02/23 15:37:54 - [] D -- C:\Program Files\Java
O43 - CFD: 2006/06/21 16:06:26 - [] D -- C:\Program Files\LeapFrogMessenger
O43 - CFD: 2015/02/23 14:29:46 - [] D -- C:\Program Files\Listen and Download Quran
O43 - CFD: 2006/03/11 21:09:55 - [] D -- C:\Program Files\Logitech
O43 - CFD: 2007/08/07 21:12:44 - [] D -- C:\Program Files\Macrogaming
O43 - CFD: 2008/10/14 19:20:15 - [0] D -- C:\Program Files\Masta
O43 - CFD: 2014/11/14 20:34:52 - [] D -- C:\Program Files\Messenger
O43 - CFD: 2013/03/17 15:51:18 - [] D -- C:\Program Files\Microsoft
O43 - CFD: 2008/11/20 23:26:16 - [] D -- C:\Program Files\Microsoft AntiSpyware
O43 - CFD: 2007/05/09 13:42:45 - [] D -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
O43 - CFD: 2005/12/19 19:08:44 - [] D -- C:\Program Files\microsoft frontpage
O43 - CFD: 2014/08/26 16:45:06 - [] D -- C:\Program Files\Microsoft Office
O43 - CFD: 2010/02/06 11:16:58 - [] D -- C:\Program Files\Microsoft Picture It! PhotoPub
O43 - CFD: 2015/05/15 19:02:25 - [] D -- C:\Program Files\Microsoft Security Client
O43 - CFD: 2014/07/25 15:55:08 - [] D -- C:\Program Files\Microsoft Silverlight
O43 - CFD: 2007/12/30 13:33:16 - [] D -- C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 2009/01/29 10:50:27 - [] D -- C:\Program Files\Microsoft Sync Framework
O43 - CFD: 2014/08/26 16:46:15 - [] D -- C:\Program Files\Microsoft Windows 7 Upgrade Advisor
O43 - CFD: 2013/04/14 06:56:41 - [] D -- C:\Program Files\Microsoft.NET
O43 - CFD: 2012/02/27 14:18:08 - [] D -- C:\Program Files\MIKSOFT
O43 - CFD: 2013/04/11 14:08:59 - [] D -- C:\Program Files\Movie Maker
O43 - CFD: 2015/08/15 10:10:22 - [] D -- C:\Program Files\Mozilla Firefox
O43 - CFD: 2015/08/15 20:40:17 - [] D -- C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 2009/03/31 18:29:41 - [] D -- C:\Program Files\MSBuild
O43 - CFD: 2014/08/26 16:45:00 - [] D -- C:\Program Files\MSECache
O43 - CFD: 2011/06/21 14:09:54 - [] D -- C:\Program Files\MSN
O43 - CFD: 2005/12/19 19:04:24 - [] D -- C:\Program Files\MSN Gaming Zone
O43 - CFD: 2007/12/30 13:30:36 - [] D -- C:\Program Files\MSN Messenger
O43 - CFD: 2006/10/19 17:27:00 - [0] D -- C:\Program Files\MSXML 4.0
O43 - CFD: 2011/10/05 19:00:39 - [] D -- C:\Program Files\NETGEAR
O43 - CFD: 2013/04/13 15:17:42 - [] D -- C:\Program Files\NetMeeting
O43 - CFD: 2008/10/21 18:57:44 - [] D -- C:\Program Files\Neuf
O43 - CFD: 2015/02/23 14:28:56 - [] D -- C:\Program Files\nItrodueal
O43 - CFD: 2010/04/30 18:51:01 - [] D -- C:\Program Files\Nokia
O43 - CFD: 2009/08/08 20:59:38 - [0] D -- C:\Program Files\NOS
O43 - CFD: 2008/10/24 18:52:01 - [] D -- C:\Program Files\Nuance
O43 - CFD: 2011/12/05 12:06:22 - [] D -- C:\Program Files\NVIDIA Corporation
O43 - CFD: 2005/12/19 19:04:35 - [] D -- C:\Program Files\Online Services
O43 - CFD: 2013/12/27 18:37:46 - [] D -- C:\Program Files\OpenOffice 4
O43 - CFD: 2013/03/17 16:16:09 - [] D -- C:\Program Files\OpenOffice.org 3
O43 - CFD: 2013/04/11 14:10:05 - [] D -- C:\Program Files\Outlook Express
O43 - CFD: 2014/04/08 12:37:02 - [] D -- C:\Program Files\PC Connectivity Solution
O43 - CFD: 2013/03/17 16:20:48 - [] D -- C:\Program Files\PowerISO
O43 - CFD: 2010/01/27 14:26:48 - [0] D -- C:\Program Files\PurFlirt
O43 - CFD: 2008/07/16 10:12:54 - [] D -- C:\Program Files\QuickTime
O43 - CFD: 2012/06/05 22:41:03 - [] D -- C:\Program Files\QuickTime Alternative
O43 - CFD: 2007/08/06 17:49:58 - [] D -- C:\Program Files\Real
O43 - CFD: 2013/04/14 07:05:36 - [] D -- C:\Program Files\Realtek
O43 - CFD: 2009/03/31 18:29:23 - [] D -- C:\Program Files\Reference Assemblies
O43 - CFD: 2015/02/23 14:29:31 - [] D -- C:\Program Files\rocckeTsaLe
O43 - CFD: 2005/12/20 18:38:52 - [] D -- C:\Program Files\S3Inc
O43 - CFD: 2015/02/23 14:28:59 - [] D -- C:\Program Files\salePrizes
O43 - CFD: 2012/11/11 19:44:02 - [] D -- C:\Program Files\Samsung
O43 - CFD: 2008/10/24 18:50:07 - [] D -- C:\Program Files\ScanSoft
O43 - CFD: 2005/12/20 10:05:38 - [] D -- C:\Program Files\Services en ligne
O43 - CFD: 2015/05/20 20:35:27 - [] RD -- C:\Program Files\Skype
O43 - CFD: 2010/10/16 15:30:39 - [] D -- C:\Program Files\Spybot - Search & Destroy
O43 - CFD: 2007/02/24 11:33:17 - [] D -- C:\Program Files\Trend Micro
O43 - CFD: 2005/12/19 22:22:14 - [0] HD -- C:\Program Files\Uninstall Information
O43 - CFD: 2011/01/13 12:06:28 - [] D -- C:\Program Files\Unlocker
O43 - CFD: 2011/02/03 15:10:18 - [0] D -- C:\Program Files\uTorrent
O43 - CFD: 2005/12/19 22:27:21 - [] D -- C:\Program Files\VIA
O43 - CFD: 2005/12/20 18:41:49 - [] D -- C:\Program Files\VIAudioi
O43 - CFD: 2015/05/31 14:44:55 - [0] D -- C:\Program Files\VideoLAN
O43 - CFD: 2008/11/28 23:56:08 - [] D -- C:\Program Files\Wakfu
O43 - CFD: 2007/10/28 19:19:49 - [] D -- C:\Program Files\Weflirt
O43 - CFD: 2006/03/03 14:23:13 - [0] D -- C:\Program Files\Winamp
O43 - CFD: 2014/11/14 20:34:51 - [] D -- C:\Program Files\Windows Desktop Search
O43 - CFD: 2009/11/27 18:44:10 - [] D -- C:\Program Files\Windows Journal Viewer
O43 - CFD: 2012/12/08 20:22:21 - [] D -- C:\Program Files\Windows Live
O43 - CFD: 2008/04/03 23:35:11 - [] D -- C:\Program Files\Windows Live Safety Center
O43 - CFD: 2009/01/29 10:51:03 - [] D -- C:\Program Files\Windows Live Toolbar
O43 - CFD: 2006/12/14 20:19:55 - [] D -- C:\Program Files\Windows Media Connect 2
O43 - CFD: 2013/04/20 16:26:24 - [] D -- C:\Program Files\Windows Media Player
O43 - CFD: 2013/04/13 15:16:48 - [] D -- C:\Program Files\Windows NT
O43 - CFD: 2005/12/19 19:07:10 - [0] HD -- C:\Program Files\WindowsUpdate
O43 - CFD: 2013/03/17 16:01:45 - [] D -- C:\Program Files\WinRAR
O43 - CFD: 2008/11/26 16:36:45 - [0] D -- C:\Program Files\WinZip
O43 - CFD: 2010/09/07 10:22:03 - [] D -- C:\Program Files\WordPerfect Office 11
O43 - CFD: 2010/09/13 20:27:48 - [0] D -- C:\Program Files\Xenocode
O43 - CFD: 2005/12/19 19:08:44 - [] D -- C:\Program Files\xerox
O43 - CFD: 2015/08/12 18:57:40 - [] D -- C:\Program Files\XTab =>PUP.Optional.XTab
O43 - CFD: 2011/02/15 20:41:16 - [] D -- C:\Program Files\Yahoo!
O43 - CFD: 2008/11/28 19:40:43 - [] D -- C:\Program Files\YesMessenger
O43 - CFD: 2014/04/08 11:30:18 - [] RD -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Accessoires
O43 - CFD: 2014/05/28 17:58:49 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Assistant Smart Wizard NETGEAR pour WNA1000M
O43 - CFD: 2015/04/08 19:24:42 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\AVAST Software
O43 - CFD: 2014/05/28 17:59:58 - [] RD -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage
O43 - CFD: 2013/04/14 07:01:50 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Intel
O43 - CFD: 2013/03/17 23:13:28 - [] RD -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Jeux
O43 - CFD: 2014/07/24 17:08:32 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Microsoft Silverlight
O43 - CFD: 2013/12/27 18:39:12 - [] SD -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\OpenOffice 4.0.1
O43 - CFD: 2014/04/08 11:28:19 - [] RD -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Outils d'administration
O43 - CFD: 2015/05/20 20:35:27 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Skype
O43 - CFD: 2015/02/23 14:29:31 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\16245437832846811298
O43 - CFD: 2015/02/22 09:27:14 - [0] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\a43f7f460000293d
O43 - CFD: 2015/08/15 21:04:06 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe
O43 - CFD: 2014/04/08 12:21:51 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\AVAST Software
O43 - CFD: 2013/07/19 15:04:49 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Brother
O43 - CFD: 2015/02/22 09:47:25 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\earnsale
O43 - CFD: 2015/02/23 14:29:11 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\fkhppkoklheifkeodkdfjlgalihnppna
O43 - CFD: 2013/04/10 23:44:56 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Geek Squad
O43 - CFD: 2015/05/20 12:53:38 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\IHProtectUpDate =>PUP.Optional.AgentODR
O43 - CFD: 2013/07/19 15:05:42 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\InstallShield
O43 - CFD: 2013/04/14 07:04:57 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Intel
O43 - CFD: 2013/11/30 11:25:03 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee
O43 - CFD: 2015/06/01 20:28:34 - [] SD -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
O43 - CFD: 2013/03/18 12:02:56 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Mozilla
O43 - CFD: 2015/02/01 11:28:01 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Nero
O43 - CFD: 2015/08/15 20:50:07 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\ScanSoft
O43 - CFD: 2015/05/20 20:35:32 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype
O43 - CFD: 2013/04/11 13:55:47 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Windows Genuine Advantage
O43 - CFD: 2015/05/24 10:41:35 - [] D -- C:\Documents and Settings\All Users.WINDOWS\Application Data\WindowsMangerProtect =>PUP.Optional.Fuyu
O43 - CFD: 2015/08/15 21:04:19 - [] D -- C:\Program Files\Fichiers communs\Adobe
O43 - CFD: 2015/08/15 21:01:31 - [] D -- C:\Program Files\Fichiers communs\Adobe AIR
O43 - CFD: 2006/01/18 18:45:24 - [] D -- C:\Program Files\Fichiers communs\Ahead
O43 - CFD: 2006/09/06 21:16:57 - [] D -- C:\Program Files\Fichiers communs\ArcSoft
O43 - CFD: 2012/01/21 19:31:14 - [] D -- C:\Program Files\Fichiers communs\AVSMedia
O43 - CFD: 2005/12/20 21:05:41 - [] D -- C:\Program Files\Fichiers communs\Borland Shared
O43 - CFD: 2005/12/20 21:05:14 - [] D -- C:\Program Files\Fichiers communs\Corel
O43 - CFD: 2006/05/07 19:41:14 - [] D -- C:\Program Files\Fichiers communs\Digi338
O43 - CFD: 2006/03/11 21:07:50 - [] D -- C:\Program Files\Fichiers communs\InstallShield
O43 - CFD: 2013/02/23 15:39:44 - [] D -- C:\Program Files\Fichiers communs\Java
O43 - CFD: 2007/10/10 07:05:14 - [0] D -- C:\Program Files\Fichiers communs\Logitech
O43 - CFD: 2014/08/26 16:45:09 - [] D -- C:\Program Files\Fichiers communs\Microsoft Shared
O43 - CFD: 2005/12/19 19:06:07 - [] D -- C:\Program Files\Fichiers communs\MSSoap
O43 - CFD: 2010/04/30 18:48:32 - [] D -- C:\Program Files\Fichiers communs\Nokia
O43 - CFD: 2005/12/19 18:16:19 - [] D -- C:\Program Files\Fichiers communs\ODBC
O43 - CFD: 2007/04/08 00:07:14 - [] D -- C:\Program Files\Fichiers communs\PCSuite
O43 - CFD: 2009/05/01 17:12:43 - [] D -- C:\Program Files\Fichiers communs\Real
O43 - CFD: 2015/08/15 20:49:56 - [] D -- C:\Program Files\Fichiers communs\ScanSoft Shared
O43 - CFD: 2005/12/19 19:06:12 - [] D -- C:\Program Files\Fichiers communs\Services
O43 - CFD: 2015/05/20 20:35:27 - [] D -- C:\Program Files\Fichiers communs\Skype
O43 - CFD: 2005/12/19 18:16:15 - [] D -- C:\Program Files\Fichiers communs\SpeechEngines
O43 - CFD: 2013/04/13 15:17:39 - [] D -- C:\Program Files\Fichiers communs\System
O43 - CFD: 2008/12/18 22:05:55 - [] D -- C:\Program Files\Fichiers communs\Windows Live
O43 - CFD: 2007/12/30 13:28:15 - [] SHDC -- C:\Program Files\Fichiers communs\WindowsLiveInstaller
O43 - CFD: 2007/04/28 11:50:14 - [0] D -- C:\Program Files\Fichiers communs\{3460D938-0707-1036-0915-051213040021}
O43 - CFD: 2013/07/19 16:10:56 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\Adobe
O43 - CFD: 2014/04/08 12:24:32 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\AVAST Software
O43 - CFD: 2013/08/29 14:04:45 - [] RD -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\Brother
O43 - CFD: 2013/03/17 23:36:52 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\Identities
O43 - CFD: 2013/04/14 07:01:27 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\InstallShield
O43 - CFD: 2013/09/10 12:52:33 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\Macromedia
O43 - CFD: 2015/05/14 10:26:04 - [] SD -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\Microsoft
O43 - CFD: 2013/03/18 00:09:04 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\Mozilla
O43 - CFD: 2014/03/13 19:20:48 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\Nero
O43 - CFD: 2013/12/27 18:39:59 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\OpenOffice
O43 - CFD: 2015/05/20 20:35:36 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\Skype
O43 - CFD: 2015/02/01 12:10:49 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\sweet-page =>PUP.Optional.SweetPage
O43 - CFD: 2014/11/01 10:21:41 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\vlc
O43 - CFD: 2014/04/08 11:29:34 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\Windows Desktop Search
O43 - CFD: 2014/04/08 11:38:10 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\Windows Search
O43 - CFD: 2015/08/16 17:02:22 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\ZHP
O43 - CFD: 2015/08/15 21:05:40 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\Adobe
O43 - CFD: 2014/04/09 12:51:35 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\ApplicationHistory
O43 - CFD: 2014/01/25 20:01:56 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\cache
O43 - CFD: 2014/04/08 13:04:11 - [0] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\genienext =>PUP.Optional.NextLive
O43 - CFD: 2015/08/15 20:43:38 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\Google
O43 - CFD: 2013/10/17 11:18:42 - [0] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\Help
O43 - CFD: 2013/06/24 15:50:01 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\Identities
O43 - CFD: 2014/06/04 15:45:32 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\Microsoft
O43 - CFD: 2014/08/26 16:46:30 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\Microsoft Corporation
O43 - CFD: 2014/01/25 21:06:52 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\Mobogenie =>PUP.Optional.Mobogenie
O43 - CFD: 2013/03/18 00:08:49 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\Mozilla
O43 - CFD: 2013/11/13 18:52:17 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\Neuf
O43 - CFD: 2015/05/14 10:26:48 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\PCHealth
O43 - CFD: 2013/07/19 15:10:37 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\Scansoft
O43 - CFD: 2014/05/27 06:38:47 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\Skype
O43 - CFD: 2014/04/08 13:31:55 - [] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\Temp
O43 - CFD: 2014/02/04 21:05:39 - [0] D -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\WMTools Downloaded Files
O43 - CFD: 2013/04/11 15:13:19 - [] RD -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Menu Démarrer\Programmes\Accessoires
O43 - CFD: 2013/03/17 23:55:50 - [] RD -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Menu Démarrer\Programmes\Démarrage
O43 - CFD: 2013/03/17 23:57:27 - [] RD -- C:\Documents and Settings\Propriétaire.POT-26C99C14026\Menu Démarrer\Programmes\Outils d'administration

---\\ Liste des pilotes du système (SDL) (O58) (53) - 7s
O58 - SDL:2014/05/28 18:00:57 A . (.Cisco Systems, Inc. - IEEE 802.1X Protocol Driver.) -- C:\WINDOWS\System32\drivers\AegisP.sys [21361]
O58 - SDL:2009/11/18 01:16:00 A . (.Creative - Creative WDM 3D Audio Driver.) -- C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480]
O58 - SDL:2008/04/13 11:36:40 A . (.Advanced Micro Devices, Inc. - AMD Win2000 AGP Filter.) -- C:\WINDOWS\System32\drivers\amdagp.sys [43008]
O58 - SDL:2011/11/02 10:48:36 A . (...) -- C:\WINDOWS\System32\drivers\AppleCharger.sys [19056]
O58 - SDL:2015/08/09 19:38:13 A . (.AVAST Software - avast! HWID.) -- C:\WINDOWS\System32\drivers\aswHwid.sys [24016]
O58 - SDL:2015/08/09 19:38:13 A . (.AVAST Software - avast! File System Minifilter for Windows 2.) -- C:\WINDOWS\System32\drivers\aswMonFlt.sys [76000]
O58 - SDL:2015/08/09 19:38:13 A . (.AVAST Software - avast! TDI Redirect Driver.) -- C:\WINDOWS\System32\drivers\aswRdr.sys [55200]
O58 - SDL:2015/08/09 19:38:13 A . (.AVAST Software - avast! Revert.) -- C:\WINDOWS\System32\drivers\aswRvrt.sys [49776]
O58 - SDL:2015/08/09 19:38:04 A . (.AVAST Software - avast! Virtualization Driver.) -- C:\WINDOWS\System32\drivers\aswSnx.sys [788784]
O58 - SDL:2015/08/09 19:38:13 A . (.AVAST Software - avast! self protection module.) -- C:\WINDOWS\System32\drivers\aswSP.sys [433264]
O58 - SDL:2015/08/09 19:38:14 A . (.AVAST Software - avast! Stream Filter.) -- C:\WINDOWS\System32\drivers\aswStmXP.sys [161472]
O58 - SDL:2015/08/09 19:38:14 A . (.AVAST Software - avast! TDI Filter Driver.) -- C:\WINDOWS\System32\drivers\aswTdi.sys [57888]
O58 - SDL:2015/08/09 19:38:14 A . (.AVAST Software - avast! VM Monitor.) -- C:\WINDOWS\System32\drivers\aswVmm.sys [208664]
O58 - SDL:2004/10/15 12:50:20 A . (.Brother Industries Ltd. - Brother USB Scanner Driver.) -- C:\WINDOWS\System32\drivers\BrScnUsb.sys [15295]
O58 - SDL:2008/04/14 14:00:00 A . (.RAVISENT Technologies Inc. - Pilote principal CineMaster C 1.2 WDM.) -- C:\WINDOWS\System32\drivers\cinemst2.sys [262528]
O58 - SDL:2008/04/14 14:00:00 A . (.Compaq Computer Corporation - Compaq PA-1 Player Driver.) -- C:\WINDOWS\System32\drivers\cpqdap01.sys [11776]
O58 - SDL:2008/04/14 14:00:00 A . (.Microsoft Corp., Veritas Software - Pilote de démarrage du gestionnaire de disq.) -- C:\WINDOWS\System32\drivers\dmboot.sys [800256]
O58 - SDL:2008/04/14 14:00:00 A . (.Microsoft Corp., Veritas Software - Pilote E/S du Gestionnaire de disques NT.) -- C:\WINDOWS\System32\drivers\dmio.sys [154496]
O58 - SDL:2008/04/14 14:00:00 A . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\System32\drivers\dmload.sys [5888]
O58 - SDL:2008/04/14 14:00:00 A . (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) -- C:\WINDOWS\System32\drivers\hdaudbus.sys [144384]
O58 - SDL:2012/07/02 15:16:00 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\HECI.sys [55104]
O58 - SDL:2012/04/02 20:50:50 RA . (.Intel Corporation - Intel Graphics Miniport Driver.) -- C:\WINDOWS\System32\drivers\igxpmp32.sys [2522784]
O58 - SDL:2009/11/18 01:17:00 A . (.Creative Technology Ltd. - Creative WDM Audio Driver (32-bit).) -- C:\WINDOWS\System32\drivers\Monfilt.sys [1395800]
O58 - SDL:2008/04/14 14:00:00 A . (.S3/Diamond Multimedia Systems - NikeDrv Usb Driver.) -- C:\WINDOWS\System32\drivers\nikedrv.sys [12032]
O58 - SDL:2007/12/05 09:11:00 N . (.NVIDIA Corporation - NVIDIA Compatible Windows 2000 Miniport Dri.) -- C:\WINDOWS\System32\drivers\nv4_mini.sys [7435392]
O58 - SDL:2005/11/19 03:13:18 A . (.Printing Communications Assoc., Inc. (PCAUSA) - PCAUSA NDIS 5.0 SPR Protocol Driver.) -- C:\WINDOWS\System32\drivers\PCASp50.sys [20096]
O58 - SDL:2008/04/14 14:00:00 A . (.Parallel Technologies, Inc. - Parallel Technologies DirectParallel IO Lib.) -- C:\WINDOWS\System32\drivers\ptilink.sys [17792]
O58 - SDL:2008/04/14 14:00:00 A . (.S3/Diamond Multimedia Systems - Rio8Drv.sys Usb Driver.) -- C:\WINDOWS\System32\drivers\rio8drv.sys [12032]
O58 - SDL:2008/04/14 14:00:00 A . (.S3/Diamond Multimedia Systems - RioDrv Usb Driver.) -- C:\WINDOWS\System32\drivers\riodrv.sys [12032]
O58 - SDL:2011/12/08 08:09:16 A . (.Realtek Semiconductor Corporation - Realtek 10/100/1000 NDIS 5.1 Driver.) -- C:\WINDOWS\System32\drivers\Rtenicxp.sys [327400]
O58 - SDL:2012/06/19 10:54:20 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys [6141584]
O58 - SDL:2008/04/14 14:00:00 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\WINDOWS\System32\drivers\secdrv.sys [20480]
O58 - SDL:2008/04/13 11:36:40 A . (.Silicon Integrated Systems Corporation - SiS NT AGP Filter.) -- C:\WINDOWS\System32\drivers\sisagp.sys [40960]
O58 - SDL:2008/04/14 14:00:00 A . (.Toshiba Corporation - WDM Toshiba Tecra Video Capture Driver.) -- C:\WINDOWS\System32\drivers\tsbvcap.sys [21376]
O58 - SDL:2008/04/14 14:00:00 A . (.RAVISENT Technologies Inc. - CineMaster C WDM DVD Minidriver.) -- C:\WINDOWS\System32\drivers\vdmindvd.sys [58112]
O58 - SDL:2008/02/27 10:54:00 A . (.Copyright (C) - WLAN NDIS 5.0 User Mode Control Driver.) -- C:\WINDOWS\System32\drivers\WLNdis50.sys [20480]
O58 - SDL:2011/01/31 17:03:44 A . (.Realtek Semiconductor Corporation - Realtek RTL8192C USB NDIS Driver.) -- C:\WINDOWS\System32\drivers\WNA1000M.sys [994664]
O58 - SDL:2015/01/31 20:25:06 A . (.StdLib - StdLib.) -- C:\WINDOWS\System32\drivers\{df8eec40-f909-439c-9ffe-3fee212f71b9}Gt.sys [55824] =>PUP.Optional.LinkiDoo
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\ansi.sys [9037]
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\country.sys [27097]
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\himem.sys [4912]
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\key01.sys [42809]
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\keyboard.sys [42537]
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\ntdos.sys [27916]
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\ntdos404.sys [29146]
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\ntdos411.sys [29370]
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\ntdos412.sys [29274]
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\ntdos804.sys [29146]
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\ntio.sys [34000]
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\ntio404.sys [34560]
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\ntio411.sys [35648]
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\ntio412.sys [35424]
O58 - SDL:2008/04/14 14:00:00 A . (...) -- C:\WINDOWS\System32\ntio804.sys [34560]

---\\ Associations Shell Spawning (O67) (10) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\system32\wscript.exe
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe

---\\ Menu de démarrage Internet (SMI) (O68) (8) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Windows NT User Data Migration Tool.) -- C:\WINDOWS\system32\shmgrate.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Windows NT User Data Migration Tool.) -- C:\WINDOWS\system32\shmgrate.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Windows NT User Data Migration Tool.) -- C:\WINDOWS\system32\shmgrate.exe

---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) (3) - 2s
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - () - http://search.live.com/
O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} - (sweet-page) - http://www.sweet-page.com/ =>PUP.Optional.SweetPage
O69 - SBI: SearchScopes [HKCU] {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} [DefaultScope] - (Google) - http://www.google.com/

---\\ Enumère les services démarrés par Svchost (SSS) (O83) (38) - 1s
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (...) -- C:\WINDOWS\System32\appmgmts.dll [0]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\WINDOWS\system32\audiosrv.dll [42496]
O83 - Search Svchost Services: Browser (Browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINDOWS\system32\browser.dll [78336]
O83 - Search Svchost Services: CryptSvc (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) -- C:\WINDOWS\system32\cryptsvc.dll [62464]
O83 - Search Svchost Services: DMServer (DMServer) . (.Microsoft Corp. - DLL Service gestionnaire de disque logique.) -- C:\WINDOWS\system32\dmserver.dll [24576]
O83 - Search Svchost Services: DHCP (DHCP) . (.Microsoft Corporation - Service client DHCP.) -- C:\WINDOWS\system32\dhcpcsvc.dll [127488]
O83 - Search Svchost Services: ERSvc (ERSvc) . (.Microsoft Corporation - Windows Error Reporting Service.) -- C:\WINDOWS\system32\ersvc.dll [23040]
O83 - Search Svchost Services: EventSystem (EventSystem) . (.Microsoft Corporation - .) -- C:\WINDOWS\system32\es.dll [253952]
O83 - Search Svchost Services: FastUserSwitchingCompatibility (FastUserSwitchingCompatibility) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680]
O83 - Search Svchost Services: HidServ (HidServ) . (...) -- C:\WINDOWS\System32\hidserv.dll [0]
O83 - Search Svchost Services: LanmanServer (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\system32\srvsvc.dll [99840]
O83 - Search Svchost Services: LanmanWorkstation (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) -- C:\WINDOWS\system32\wkssvc.dll [132096]
O83 - Search Svchost Services: Messenger (Messenger) . (.Microsoft Corporation - NT Messenger Service.) -- C:\WINDOWS\system32\msgsvc.dll [33792]
O83 - Search Svchost Services: Netman (Netman) . (.Microsoft Corporation - Gestionnaire de connexions réseau.) -- C:\WINDOWS\system32\netman.dll [198144]
O83 - Search Svchost Services: Nla (Nla) . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Micro.) -- C:\WINDOWS\system32\mswsock.dll [247808]
O83 - Search Svchost Services: Ntmssvc (Ntmssvc) . (.Microsoft Corporation - Gestionnaire de stockage amovible.) -- C:\WINDOWS\system32\ntmssvc.dll [438272]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\system32\rasauto.dll [88576]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\system32\rasmans.dll [186368]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\WINDOWS\system32\mprdim.dll [53248]
O83 - Search Svchost Services: Schedule (Schedule) . (.Microsoft Corporation - Moteur du Planificateur de tâches.) -- C:\WINDOWS\system32\schedsvc.dll [194560]
O83 - Search Svchost Services: Seclogon (Seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secon.) -- C:\WINDOWS\system32\seclogon.dll [18944]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\system32\sens.dll [39424]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à.) -- C:\WINDOWS\system32\ipnathlp.dll [332800]
O83 - Search Svchost Services: SRService (SRService) . (.Microsoft Corporation - Service de restauration du système.) -- C:\WINDOWS\system32\srsvc.dll [171520]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\WINDOWS\system32\tapisrv.dll [249856]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680]
O83 - Search Svchost Services: TrkWks (TrkWks) . (.Microsoft Corporation - Distributed Link Tracking Client.) -- C:\WINDOWS\system32\trkwks.dll [90112]
O83 - Search Svchost Services: W32Time (W32Time) . (.Microsoft Corporation - Service de temps Windows.) -- C:\WINDOWS\system32\w32time.dll [178176]
O83 - Search Svchost Services: WZCSVC (WZCSVC) . (.Microsoft Corporation - Service configuration automatique sans fil.) -- C:\WINDOWS\system32\wzcsvc.dll [483840]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\wmisvc.dll [145408]
O83 - Search Svchost Services: wscsvc (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) -- C:\WINDOWS\system32\wscsvc.dll [80896]
O83 - Search Svchost Services: xmlprov (xmlprov) . (.Microsoft Corporation - Network Provisioning Service.) -- C:\WINDOWS\system32\xmlprov.dll [129024]
O83 - Search Svchost Services: napagent (napagent) . (.Microsoft Corporation - Exécution du service Agent de quarantaine.) -- C:\WINDOWS\system32\qagentrt.dll [293376]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\WINDOWS\system32\kmsvc.dll [61440]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\WINDOWS\system32\qmgr.dll [409088]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update AutoUpdate Service.) -- C:\WINDOWS\system32\wuauserv.dll [6656]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680]
O83 - Search Svchost Services: helpsvc (helpsvc) . (.Microsoft Corporation - Microsoft PCHealth Service Holder.) -- C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll [38400]

---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) (9) - 11s
SS - Demand [2015/08/15 20:59:57] [ 269000] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - Demand [2010/04/06 16:30:38] [ 31272] AppleChargerSrv (AppleChargerSrv) . (...) - C:\WINDOWS\system32\AppleChargerSrv.exe
SR - Auto [2015/08/09 19:38:09] [ 146600] Avast Antivirus (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
SR - Auto [2012/06/19 19:03:28] [ 462088] Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe
SR - Auto [2012/07/05 13:23:34] [ 166720] Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
SR - Auto [2012/07/19 09:53:10] [ 277824] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SS - Demand [2015/08/15 09:17:38] [ 149160] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - Auto [2015/02/18 20:11:32] [ 315488] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SR - Auto [2012/07/19 09:53:16] [ 365376] Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

---\\ Scan Additionnel (O88) (22) - 0s
C:\Program Files\Mozilla Firefox\browser\searchplugins\delta-homes.xml =>PUP.Optional.DeltaHomes
C:\Program Files\Mozilla Firefox\browser\searchplugins\sweet-page.xml =>PUP.Optional.SweetPage
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{f080fb60} =>PUP.Optional.Graftor
HKLM\SOFTWARE\cbb813a7-c4ea-0f50-3575-8767a9c375bc =>PUP.Optional.CrossRider
HKLM\SOFTWARE\delta-homesSoftware =>PUP.Optional.DeltaHomes
HKLM\SOFTWARE\IHProtect =>PUP.Optional.AgentODR
HKLM\SOFTWARE\Iminent =>PUP.Optional.IMBooster
HKLM\SOFTWARE\SupDp =>PUP.Optional.SupTab
HKLM\SOFTWARE\supWindowsMangerProtect =>PUP.Optional.Fuyu
HKLM\SOFTWARE\sweet-pageSoftware =>PUP.Optional.SweetPage
HKLM\SOFTWARE\Trymedia Systems =>PUP.Optional.Trymedia
HKCU\SOFTWARE\InstallCore =>PUP.Optional.InstallCore
HKCU\SOFTWARE\Softonic =>PUP.Optional.Softonic
HKCU\SOFTWARE\Super Optimizer =>PUP.Optional.SuperOptimizer
C:\Program Files\DealBulldog Toolbar Toolbar =>PUP.Optional.SocialSkinz
C:\Program Files\XTab =>PUP.Optional.XTab
C:\Documents and Settings\All Users.WINDOWS\Application Data\IHProtectUpDate =>PUP.Optional.AgentODR
C:\Documents and Settings\All Users.WINDOWS\Application Data\WindowsMangerProtect =>PUP.Optional.Fuyu
C:\Documents and Settings\Propriétaire.POT-26C99C14026\Application Data\sweet-page =>PUP.Optional.SweetPage
C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\genienext =>PUP.Optional.NextLive
C:\Documents and Settings\Propriétaire.POT-26C99C14026\Local Settings\Application Data\Mobogenie =>PUP.Optional.Mobogenie
C:\WINDOWS\System32\drivers\{df8eec40-f909-439c-9ffe-3fee212f71b9}Gt.sys =>PUP.Optional.LinkiDoo

---\\ Récapitulatif des éléments trouvées sur votre station (17) - 0s
http://www.nicolascoolman.fr/blog =>PUP.Optional.DeltaHomes
http://www.nicolascoolman.fr/pup-sweetpage/ =>PUP.Optional.SweetPage
http://www.nicolascoolman.fr/pup-mobogenie/ =>PUP.Optional.Mobogenie
http://www.nicolascoolman.fr/blog =>PUP.Optional.Graftor
http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider
http://www.nicolascoolman.fr/blog =>PUP.Optional.AgentODR
http://www.nicolascoolman.fr/adware-imbooster/ =>PUP.Optional.IMBooster
http://www.nicolascoolman.fr/pup-suptab/ =>PUP.Optional.SupTab
http://www.nicolascoolman.fr/trojan-fuyu/ =>PUP.Optional.Fuyu
http://www.nicolascoolman.fr/adware-trymedia/ =>PUP.Optional.Trymedia
http://www.nicolascoolman.fr/adware-installcore/ =>PUP.Optional.InstallCore
http://www.nicolascoolman.fr/blog =>PUP.Optional.Softonic
http://www.nicolascoolman.fr/blog =>PUP.Optional.SuperOptimizer
http://www.nicolascoolman.fr/adware-socialskinz/ =>PUP.Optional.SocialSkinz
http://www.nicolascoolman.fr/blog =>PUP.Optional.XTab
http://www.nicolascoolman.fr/pup-nextlive/ =>PUP.Optional.NextLive
http://www.nicolascoolman.fr/pup-linkidoo/ =>PUP.Optional.LinkiDoo

~ End of the scan, 49995 items in 79 seconds (647)(0)()

Publicité


Signaler le contenu de ce document

Publicité