cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.9.10.139 Par Nicolas Coolman (2015/09/10)
~ Démarré par Utilisateur (Administrator) (2015/09/10 20:10:16)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Documents and Settings\Utilisateur\Bureau\ZHPDiag.txt
~ Rapport: C:\Documents and Settings\Utilisateur\Application Data\ZHP\ZHPDiag.txt
~ UAC: Deactivate
~ Démarrage du système: Normal (Normal boot)
Windows XP, 32-bit Service Pack 3 (Build 2600)

---\\ Navigateurs Internet (4) - 0s
GCIE: Google Chrome v39.0.2171.99
MFIE: Mozilla Firefox 37.0.1 (x86 en-US) v37.0.1
OPIE: Opera 30.0.1835.125 v30.0.1835.125
MSIE: Internet Explorer v7.0.5730.13

---\\ Informations sur les produits Windows (3) - 0s
Windows Automatic Updates : OK
Windows Activation Technologies : KO
Windows Genuine Advantage : KO

---\\ Logiciels de protection (1) - 0s
Malwarebytes Anti-Malware version 2.1.8.1057

---\\ Logiciels d'optimisation (1) - 0s
CCleaner v5.01

---\\ Surveillance de Logiciels (2) - 0s
Adobe Flash Player 18 PPAPI
Adobe Reader 8.1.1 - Français

---\\ Informations sur le système (6) - 0s
~ Operating System: x86 Family 6 Model 22 Stepping 1, GenuineIntel
~ Operating System: 32-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 2086.912 MB (66% free)
~ System Restore: Activé (Enable)
~ System drive C: has 37 GB free of 49 GB

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: BLEUXP-0798CF43
~ User Name: Utilisateur
~ Logged in as Administrator

---\\ Enumération des unités disques (3) - 0s
~ Drive C: has 37 GB free of 49 GB (System)
~ Drive D: has 46 GB free of 49 GB
~ Drive E: has 48 GB free of 52 GB

---\\ Etat du Centre de Sécurité Windows (8) - 0s
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] WarnOnHTTPSToHTTPRedirect: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Intl: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] XMLLookup: Modified
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Recherche particulière de fichiers génériques (23) - 0s
[MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\WINDOWS\Explorer.exe [1037824] ©
[MD5.93AD0B78C7357A05F50E594EC7C22300] - (.Microsoft Corporation - Exécuter une DLL en tant qu'application.) () -- C:\WINDOWS\System32\rundll32.exe [33792] ©
[MD5.E30CACD98479B36A3DBFA3267BF62DD0] - (.Microsoft Corporation - Internet Extensions for Win32.) () -- C:\WINDOWS\System32\wininet.dll [826368] ©
[MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows.) () -- C:\WINDOWS\System32\Winlogon.exe [512000] ©
[MD5.38A68A246F50F01F0A3A0DAD39A3FA6B] - (.Microsoft Corporation - DNS Client API DLL.) () -- C:\WINDOWS\System32\dnsapi.dll [147968] ©
[MD5.4D43E74F2A1239D53929B82600F1971C] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\WINDOWS\System32\drivers\AFD.sys [138496] ©
[MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) () -- C:\WINDOWS\System32\drivers\atapi.sys [96512] ©
[MD5.C885B02847F5D2FD45A24E219ED93B32] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\WINDOWS\System32\drivers\Cdfs.sys [63744] ©
[MD5.1F4260CC5B42272D71F79E570A27A4FE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\WINDOWS\System32\drivers\Cdrom.sys [62976] ©
[MD5.31F923EB2170FC172C81ABDA0045D18C] - (.Microsoft Corporation - Pilote de cryptographie FIPS.) () -- C:\WINDOWS\System32\drivers\Fips.sys [44672] ©
[MD5.573C7D0A32852B48F3058CFD8026F511] - (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) () -- C:\WINDOWS\System32\drivers\HDAudBus.sys [144384]
[MD5.A09BDC4ED10E3B2E0EC27BB94AF32516] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\WINDOWS\System32\drivers\i8042prt.sys [54144] ©
[MD5.083A052659F5310DD8B6A6CB05EDCF8E] - (.Microsoft Corporation - IMAPI Kernel Driver.) () -- C:\WINDOWS\System32\drivers\Imapi.sys [42112] ©
[MD5.CC748EA12C6EFFDE940EE98098BF96BB] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\WINDOWS\System32\drivers\IpNat.sys [152832] ©
[MD5.23C74D75E36E7158768DD63D92789A91] - (.Microsoft Corporation - IPSec Driver.) () -- C:\WINDOWS\System32\drivers\IPSec.sys [75264] ©
[MD5.68755F0FF16070178B54674FE5B847B0] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\WINDOWS\System32\drivers\MRxSmb.sys [456576] ©
[MD5.74B2B2F5BEA5E9A3DC021D685551BD3D] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\WINDOWS\System32\drivers\netBT.sys [162816] ©
[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) () -- C:\WINDOWS\System32\drivers\ntfs.sys [574976] ©
[MD5.8FD0BDBEA875D06CCF6C945CA9ABAF75] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\WINDOWS\System32\drivers\Parport.sys [80384] ©
[MD5.11B4A627BC9614B885C4969BFA5FF8A6] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [51328] ©
[MD5.15CABD0F7C00C47C70124907916AF3F1] - (.Microsoft Corporation - Microsoft RDP Device redirector.) () -- C:\WINDOWS\System32\drivers\rdpdr.sys [196224] ©
[MD5.D8EB2A7904DB6C916EB5361878DDCBAE] - (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) () -- C:\WINDOWS\System32\drivers\redbook.sys [58752] ©
[MD5.46DE1126684369BACE4849E4FC8C43CA] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\WINDOWS\System32\drivers\volsnap.sys [53376] ©

---\\ Processus lancés (10) - 1s
[MD5.C1A88CC926FFC4FE2ECA6383F0A3A029] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe [3886672] [PID.1816] ©
[MD5.20C2F1613EBCF66D0395C59076EE472E] - (...) -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056] [PID.436]
[MD5.A87F0161A6AD63950AEE581828677D54] - (.IAC Search and Media - IAC Updater.) -- C:\Program Files\IAC Updater\iacupdater.exe [180128] [PID.636]
[MD5.BD95E822E7A958BBCA842D078426A151] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe [269848] [PID.1924] ©
[MD5.2CA0461A5730F6FC3F90FA3833C645C9] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [856904] [PID.2652] ©
[MD5.2CA0461A5730F6FC3F90FA3833C645C9] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [856904] [PID.3180] ©
[MD5.2CA0461A5730F6FC3F90FA3833C645C9] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [856904] [PID.1472] ©
[MD5.2CA0461A5730F6FC3F90FA3833C645C9] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [856904] [PID.3780] ©
[MD5.2CA0461A5730F6FC3F90FA3833C645C9] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [856904] [PID.3364] ©
[MD5.886A7A8D794D4C8DB2D8ADC9990CCD7D] - (.Nicolas Coolman - ZHPDiag.) -- C:\Documents and Settings\Utilisateur\Application Data\ZHP\ZHPDiag3.exe [1925632] [PID.3328] ©

---\\ Google Chrome, Démarrage,Recherche,Extensions (4) - 0s
G2 - GCE: Preference [User Data\Default] [aaaaaigjndjblmpeckabiffcpogflfgl] Movies App =>PUP.Optional.CrossRider
G2 - GCE: Preference [User Data\Default] [akaelkiagnbfcccfnmbimdbplecgbikh] SavePass 1.1 =>PUP.Optional.CrossRider
G2 - GCE: Preference [User Data\Default] [fcfenmboojpjinhpgggodefccipikbpd] Bing
G2 - GCE: Preference [User Data\Default] [jeaohhlajejodfjadcponpnjgkiikocn] IDM Integration Module

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (26) - 2s
M0 - MFSP: prefs.js [Utilisateur - 238zet1k.default] http://www.oursurfing.com/?type=hp&ts=1441831183&z=127fc81e775df9bc95611dfg7zez5gab3c2e7q1mdt&from=2sq3&uid=HitachiXHTS542516K9SA00_071126BB0300WCHDLXJCX =>PUP.Optional.OurSurfing
P2 - EXT FILE: (...) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\extensions\firefox@zenmate.com.xpi
P2 - EXT FILE: (...) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\extensions\info@youtube-mp3.org.xpi
P2 - EXT FILE: (...) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\extensions\jid1-5TIPw62vHHvQTQ@jetpack.xpi
P2 - EXT FILE: (...) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\extensions\jid1-cwbvBTE216jjpg@jetpack.xpi
P2 - EXT FILE: (...) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\extensions\SkipScreen@SkipScreen.xpi
P2 - EXT FILE: (...) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\extensions\{726412ac-2531-4d86-8f5c-32e7574763e8}.xpi
P2 - EXT FILE: (...) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
P2 - EXT FILE: (...) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\searchplugins\findit.xml =>PUP.Optional.SmartBar
P2 - EXT FILE: (...) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\searchplugins\jaleco.xml
P2 - EXT FILE: (...) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\searchplugins\oursurfing.xml =>PUP.Optional.OurSurfing
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazondotcom.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\findit.xml =>PUP.Optional.SmartBar
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\twitter.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo.xml =>PUP.Optional.BDYahoo
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ©
P2 - EXT: (.roc - Default SearchProtected .) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\extensions\defsearchp@gmail.com
P2 - EXT: (.lightningnewtab.com - deskCut.) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\extensions\deskCutv2@gmail.com =>PUP.Optional.LightningNewTab
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll ©
P2 - FPN: [HKLM] [@real.com/nprpplugin;version=16.0.4.19] - (.RealPlayer.) -- C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll
P2 - FPN: [HKLM] [@realnetworks.com/npdlplugin;version=1] - (.RealDownloader.) -- C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll

---\\ Opera, Démarrage,Recherche,Plugins (2) - 0s
B2 - EXT: [SavePass 1.1] C:\Documents and Settings\Utilisateur\Application Data\Opera Software\Opera Stable\Extensions\akaelkiagnbfcccfnmbimdbplecgbikh
B2 - EXT: [Cinem Plus 2.4cV07.09] C:\Documents and Settings\Utilisateur\Application Data\Opera Software\Opera Stable\Extensions\gegdfeiahlfolhcfioipjlkombmgbakh

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (16) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://safesearch.avira.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://safesearch.avira.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://safesearch.avira.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer
R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2

---\\ Internet Explorer,Proxy Management (4) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe (.Microsoft Corporation.)
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.)
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"

---\\ Etude du fichier hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (1)

---\\ Browser Helper Object de navigateur (BHO) (2) - 0s
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AnySend - {61628E2A-4FF9-4454-992D-D92A8CD27399} (Orphean) =>PUP.Optional.ASPackage

---\\ Internet Explorer, Barre d'outil (1) - 0s
O3 - Toolbar: (no name) - [HKLM]{61628E2A-4FF9-4454-992D-D92A8CD27399} (Orphean) (.not file.)

---\\ Applications lancées au démarrage du système (6) - 0s
O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe ©
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe ©
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe ©
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32
O4 - HKUS\S-1-5-21-2000478354-299502267-1417001333-1003\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe ©

---\\ Modification Domaine/Adresses DNS (3) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

---\\ Protocole additionnel (27) - 0s
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll ©
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\WINDOWS\system32\msvidctl.dll ©
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll ©
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll ©
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll ©
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API.) -- C:\WINDOWS\system32\inetcomm.dll ©
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll ©
O18 - Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Information Retrieval\MSITSS.DLL ©
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll ©
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\WINDOWS\system32\msvidctl.dll ©
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll ©
O18 - Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} . (.Microsoft Corporation - WIA Scripting Layer.) -- C:\WINDOWS\system32\wiascr.dll ©
O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll ©
O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll ©
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll ©
O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll ©
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL ©

---\\ Liste des services NT non Microsoft et non désactivés (3) - 0s
O23 - Service: IAC Update Service (IAC Update Service) . (.IAC Search and Media - IAC Updater.) - C:\Program Files\IAC Updater\iacupdater.exe
O23 - Service: RealNetworks Downloader Resolver Service (RealNetworks Downloader Resolver Service) . (...) - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe ©

---\\ Logiciels installés (33) - 9s
O42 - Logiciel: Adobe Flash Player 16 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI ©
O42 - Logiciel: Adobe Flash Player 18 PPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player PPAPI ©
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner ©
O42 - Logiciel: DocX Reader 2.0 - (...) [HKLM] -- DocX Reader 2.0
O42 - Logiciel: Free Player - (.Free Player.) [HKLM] -- Free Player
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome ©
O42 - Logiciel: Trojan Killer - (.GridinSoft LLC.) [HKLM] -- GridinSoft Trojan Killer
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (...) [HKLM] -- HDMI
O42 - Logiciel: Ooredoo N'ternet - (.اسم شركتك.) [HKLM] -- InstallShield_{E9AD7C62-C507-49BA-91AC-1A2D0F86A913}
O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM] -- Internet Download Manager ©
O42 - Logiciel: Hotfix for Windows XP (KB915865) - (.Microsoft Corporation.) [HKLM] -- KB915865 ©
O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5 ©
O42 - Logiciel: K-Lite Mega Codec Pack 10.5.5 - (...) [HKLM] -- KLiteCodecPack_is1
O42 - Logiciel: Malwarebytes Anti-Malware version 2.1.8.1057 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1 ©
O42 - Logiciel: Mozilla Firefox 37.0.1 (x86 en-US) - (.Mozilla.) [HKLM] -- Mozilla Firefox 37.0.1 (x86 en-US) ©
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService ©
O42 - Logiciel: Opera Stable 30.0.1835.125 - (.Opera Software.) [HKLM] -- Opera 30.0.1835.125 ©
O42 - Logiciel: oursurfing uninstall - (.oursurfing.) [HKLM] -- oursurfing uninstall =>PUP.Optional.OurSurfing
O42 - Logiciel: Paltalk Messenger 11.5 - (.AVM Software Inc..) [HKLM] -- Paltalk Messenger
O42 - Logiciel: RealPlayer - (.RealNetworks.) [HKLM] -- RealPlayer 16.0 ©
O42 - Logiciel: Simple Shutdown Timer - (.PcWinTech.com.) [HKLM] -- Simple Shutdown Timer1.1.2
O42 - Logiciel: SuperCopier2 - (...) [HKLM] -- SuperCopier2
O42 - Logiciel: USB Disk Security - (.Zbshareware Lab.) [HKLM] -- USB Disk Security_is1
O42 - Logiciel: VLC media player 2.1.3 - (.VideoLAN.) [HKLM] -- VLC media player ©
O42 - Logiciel: WinRAR 5.21 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver ©
O42 - Logiciel: Skype™ 7.1 - (.Skype Technologies S.A..) [HKLM] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7} ©
O42 - Logiciel: RealUpgrade 1.1 - (.RealNetworks, Inc..) [HKLM] -- {28C2DED6-325B-4CC7-983A-1777C8F7FBAB} ©
O42 - Logiciel: Java(TM) 6 Update 3 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160030} ©
O42 - Logiciel: RealDownloader - (.RealNetworks, Inc..) [HKLM] -- {6935C750-2D8C-4705-B4F9-052F550D225D} ©
O42 - Logiciel: AnySend 1.0.18.0 (x86) - (.ClickMeIn Limited.) [HKLM] -- {7478BEEF-6424-4D10-A8B2-A3126A97C2D5} =>PUP.Optional.ASPackage
O42 - Logiciel: Adobe Reader 8.1.1 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A81000000003} ©
O42 - Logiciel: Ooredoo N'ternet - (.اسم شركتك.) [HKLM] -- {E9AD7C62-C507-49BA-91AC-1A2D0F86A913}
O42 - Logiciel: Realtek High Definition Audio Driver - (...) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}

---\\ HKCU & HKLM Software Keys (106) - 9s
HKLM\SOFTWARE\acer
HKLM\SOFTWARE\Acrobat Reader
HKLM\SOFTWARE\Adobe
HKLM\SOFTWARE\APNDTX
HKLM\SOFTWARE\BitDefender Parental Control
HKLM\SOFTWARE\C07ft5Y
HKLM\SOFTWARE\CDDB
HKLM\SOFTWARE\CyberGhost
HKLM\SOFTWARE\downchecker =>PUP.Optional.DownChecker
HKLM\SOFTWARE\FreeDownloadManager.ORG
HKLM\SOFTWARE\Gemplus
HKLM\SOFTWARE\GNU
HKLM\SOFTWARE\Google
HKLM\SOFTWARE\GreatFind =>PUP.Optional.GreatFind
HKLM\SOFTWARE\GridinSoft
HKLM\SOFTWARE\HaaliMkx
HKLM\SOFTWARE\HSPA
HKLM\SOFTWARE\Icaros
HKLM\SOFTWARE\IM Providers
HKLM\SOFTWARE\INTEL
HKLM\SOFTWARE\Internet Download Manager
HKLM\SOFTWARE\JavaSoft
HKLM\SOFTWARE\KasperskyLab
HKLM\SOFTWARE\KLCodecPack
HKLM\SOFTWARE\LAV
HKLM\SOFTWARE\Licenses
HKLM\SOFTWARE\Macromedia
HKLM\SOFTWARE\Malwarebytes' Anti-Malware
HKLM\SOFTWARE\Mozilla
HKLM\SOFTWARE\mozilla.org
HKLM\SOFTWARE\MozillaPlugins
HKLM\SOFTWARE\mtExtTag
HKLM\SOFTWARE\mtSaophase
HKLM\SOFTWARE\ODBC
HKLM\SOFTWARE\OIX
HKLM\SOFTWARE\Opera Software
HKLM\SOFTWARE\oursurfingSoftware =>PUP.Optional.OurSurfing
HKLM\SOFTWARE\Piriform
HKLM\SOFTWARE\Program Groups
HKLM\SOFTWARE\RALINK
HKLM\SOFTWARE\RealNetworks
HKLM\SOFTWARE\Realtek
HKLM\SOFTWARE\RegisteredApplications
HKLM\SOFTWARE\Schlumberger
HKLM\SOFTWARE\Secure
HKLM\SOFTWARE\SiteSee
HKLM\SOFTWARE\Skype
HKLM\SOFTWARE\Swearware
HKLM\SOFTWARE\TP-LINK
HKLM\SOFTWARE\tueagles
HKLM\SOFTWARE\VideoLAN
HKLM\SOFTWARE\WdsManPro =>PUP.Optional.WdsManPro
HKLM\SOFTWARE\Windows 3.1 Migration Status
HKLM\SOFTWARE\WinRAR
HKLM\SOFTWARE\Wise Solutions
HKLM\SOFTWARE\Wow6432Node
HKLM\SOFTWARE\Xing Technology Corp.
HKLM\SOFTWARE\zbshareware
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\Ahead
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\Chromium
HKCU\SOFTWARE\DownloadManager
HKCU\SOFTWARE\FreeDownloadManager.ORG
HKCU\SOFTWARE\Gabest
HKCU\SOFTWARE\GNU
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\GridinSoft
HKCU\SOFTWARE\Haali
HKCU\SOFTWARE\IACCOMMON
HKCU\SOFTWARE\Icaros
HKCU\SOFTWARE\ilividmoviestoolbar280 =>PUP.Optional.Bandoo
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\Intel
HKCU\SOFTWARE\KasperskyLabSetup
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\madshi
HKCU\SOFTWARE\MediaInfo
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\MPC-HC
HKCU\SOFTWARE\mtExtTag
HKCU\SOFTWARE\mtSaophase
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\ODBC
HKCU\SOFTWARE\Opera Software
HKCU\SOFTWARE\Paltalk
HKCU\SOFTWARE\Piriform
HKCU\SOFTWARE\pth264
HKCU\SOFTWARE\RealNetworks
HKCU\SOFTWARE\Realtek
HKCU\SOFTWARE\SampleShellExtnesion
HKCU\SOFTWARE\SecurityXploded
HKCU\SOFTWARE\SFX TEAM
HKCU\SOFTWARE\Skype
HKCU\SOFTWARE\Sysinternals
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\TuneUp
HKCU\SOFTWARE\undefined
HKCU\SOFTWARE\USB Disk Security
HKCU\SOFTWARE\VB and VBA Program Settings
HKCU\SOFTWARE\Wget
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\WPI
HKCU\SOFTWARE\ZebHelpProcess Helper

---\\ Contenu des dossiers Programmes (158) - 7s
O43 - CFD: 2015/09/09 19:01:56 - [] D -- C:\Program Files\694171D0-1441654915-3D38-8455-001B387651C1 =>PUP.Optional.CrossRider
O43 - CFD: 2015/09/09 19:02:15 - [] D -- C:\Program Files\Adobe
O43 - CFD: 2015/09/03 22:15:01 - [] D -- C:\Program Files\baidu
O43 - CFD: 2015/03/23 21:07:16 - [] D -- C:\Program Files\Bitdefender
O43 - CFD: 2015/01/08 21:22:46 - [] D -- C:\Program Files\CCleaner
O43 - CFD: 2015/03/22 19:25:30 - [] D -- C:\Program Files\Common Files
O43 - CFD: 2001/01/01 01:06:13 - [0] D -- C:\Program Files\ComPlus Applications
O43 - CFD: 2015/09/09 20:57:15 - [] D -- C:\Program Files\Fichiers communs
O43 - CFD: 2015/01/15 16:58:01 - [] D -- C:\Program Files\Flash Save
O43 - CFD: 2015/09/08 21:08:39 - [] D -- C:\Program Files\FoxPDF Software Inc
O43 - CFD: 2014/12/24 21:21:54 - [] D -- C:\Program Files\Free Download Manager
O43 - CFD: 2015/06/02 22:07:25 - [] D -- C:\Program Files\FreePlayer
O43 - CFD: 2015/01/15 17:04:32 - [] D -- C:\Program Files\Google
O43 - CFD: 2015/09/09 17:37:35 - [] D -- C:\Program Files\GridinSoft Trojan Killer
O43 - CFD: 2015/03/23 14:47:57 - [] D -- C:\Program Files\Grooveshark Enhancement Suite
O43 - CFD: 2014/12/24 15:53:54 - [] D -- C:\Program Files\GUM2C.tmp
O43 - CFD: 2015/04/05 20:25:14 - [] D -- C:\Program Files\HSPA USB Modem
O43 - CFD: 2015/09/05 13:38:46 - [] D -- C:\Program Files\IAC Updater
O43 - CFD: 2015/04/05 20:55:01 - [] D -- C:\Program Files\InstallShield Installation Information
O43 - CFD: 2015/01/12 13:55:37 - [] D -- C:\Program Files\Internet Download Manager
O43 - CFD: 2015/01/05 20:59:23 - [] D -- C:\Program Files\Internet Explorer
O43 - CFD: 2001/01/01 01:30:53 - [] D -- C:\Program Files\Java
O43 - CFD: 2014/12/24 15:58:13 - [] D -- C:\Program Files\K-Lite Codec Pack
O43 - CFD: 2015/09/03 21:32:56 - [] D -- C:\Program Files\Malwarebytes Anti-Malware
O43 - CFD: 2001/01/01 01:20:47 - [] D -- C:\Program Files\microsoft frontpage
O43 - CFD: 2001/01/01 01:33:08 - [] D -- C:\Program Files\Microsoft Office
O43 - CFD: 2015/01/05 21:01:11 - [] D -- C:\Program Files\Microsoft.NET
O43 - CFD: 2001/01/01 01:07:26 - [] D -- C:\Program Files\Movie Maker
O43 - CFD: 2015/04/12 13:43:39 - [] D -- C:\Program Files\Mozilla Firefox
O43 - CFD: 2015/04/12 20:32:46 - [] D -- C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 2015/01/23 18:58:38 - [] D -- C:\Program Files\MSBuild
O43 - CFD: 2015/09/08 21:06:59 - [] D -- C:\Program Files\MSECache
O43 - CFD: 2001/01/01 01:05:45 - [] D -- C:\Program Files\MSN Gaming Zone
O43 - CFD: 2001/01/01 01:07:36 - [] D -- C:\Program Files\NetMeeting
O43 - CFD: 2015/06/02 22:07:23 - [] D -- C:\Program Files\Office-Converter.com
O43 - CFD: 2015/07/26 16:00:47 - [] D -- C:\Program Files\Opera
O43 - CFD: 2001/01/01 01:07:33 - [] D -- C:\Program Files\Outlook Express
O43 - CFD: 2015/02/22 20:44:41 - [] D -- C:\Program Files\Paltalk Messenger
O43 - CFD: 2015/03/23 14:44:57 - [] D -- C:\Program Files\Photo download for Facebook
O43 - CFD: 2014/12/24 15:45:27 - [] D -- C:\Program Files\Real
O43 - CFD: 2014/12/24 15:45:34 - [] D -- C:\Program Files\RealNetworks
O43 - CFD: 2015/01/23 18:58:29 - [] D -- C:\Program Files\Reference Assemblies
O43 - CFD: 2015/03/10 21:36:40 - [] D -- C:\Program Files\SecurityXploded
O43 - CFD: 2001/01/01 01:08:02 - [] D -- C:\Program Files\Services en ligne
O43 - CFD: 2015/09/10 14:44:10 - [] D -- C:\Program Files\SFK =>PUP.Optional.MyWebSearch
O43 - CFD: 2015/04/17 22:11:01 - [] D -- C:\Program Files\Simple Shutdown Timer
O43 - CFD: 2015/02/02 16:09:50 - [] RD -- C:\Program Files\Skype
O43 - CFD: 2015/01/15 16:58:01 - [] D -- C:\Program Files\Smart Saver
O43 - CFD: 2001/01/01 01:31:01 - [] D -- C:\Program Files\SuperCopier2
O43 - CFD: 2015/03/10 21:01:26 - [] D -- C:\Program Files\tuEagles
O43 - CFD: 2001/01/01 01:34:48 - [0] HD -- C:\Program Files\Uninstall Information
O43 - CFD: 2015/09/07 20:18:25 - [] D -- C:\Program Files\USB Disk Security
O43 - CFD: 2015/07/26 15:39:00 - [] D -- C:\Program Files\VideoLAN
O43 - CFD: 2001/01/01 01:05:51 - [] D -- C:\Program Files\Windows Media Connect 2
O43 - CFD: 2001/01/01 01:09:11 - [] D -- C:\Program Files\Windows Media Player
O43 - CFD: 2001/01/01 01:05:38 - [] D -- C:\Program Files\Windows NT
O43 - CFD: 2001/01/01 01:08:05 - [0] HD -- C:\Program Files\WindowsUpdate
O43 - CFD: 2015/09/09 16:43:19 - [] D -- C:\Program Files\WinRAR
O43 - CFD: 2001/01/01 01:20:47 - [] D -- C:\Program Files\xerox
O43 - CFD: 2001/01/01 01:08:55 - [] RD -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Accessoires
O43 - CFD: 2014/12/24 15:58:16 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\CCleaner
O43 - CFD: 2015/04/05 10:00:57 - [] RD -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
O43 - CFD: 2015/01/15 17:05:59 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Google Chrome
O43 - CFD: 2015/09/09 17:37:48 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\GridinSoft Trojan Killer
O43 - CFD: 2014/12/23 19:33:28 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Internet Download Manager
O43 - CFD: 2001/01/01 01:06:23 - [] RD -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Jeux
O43 - CFD: 2014/12/24 15:58:18 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\K-Lite Codec Pack
O43 - CFD: 2015/09/03 21:32:57 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Malwarebytes Anti-Malware
O43 - CFD: 2001/01/01 01:33:27 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Microsoft Office
O43 - CFD: 2015/04/05 20:27:15 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Ooredoo N'ternet
O43 - CFD: 2001/01/01 01:09:20 - [] RD -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Outils d'administration
O43 - CFD: 2014/12/24 15:45:36 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\RealNetworks
O43 - CFD: 2015/09/09 21:49:27 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Skype
O43 - CFD: 2015/09/07 20:18:26 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\USB Disk Security
O43 - CFD: 2015/07/26 15:39:24 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\VideoLAN
O43 - CFD: 2001/01/01 01:31:02 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinRAR
O43 - CFD: 2001/01/01 01:30:21 - [] D -- C:\Documents and Settings\All Users\Application Data\Adobe
O43 - CFD: 2015/09/09 16:57:35 - [] D -- C:\Documents and Settings\All Users\Application Data\AnySend =>PUP.Optional.ASPackage
O43 - CFD: 2015/01/23 17:37:32 - [] D -- C:\Documents and Settings\All Users\Application Data\AVAST Software
O43 - CFD: 2015/09/09 20:53:40 - [] D -- C:\Documents and Settings\All Users\Application Data\Avira
O43 - CFD: 2015/01/25 22:35:06 - [] D -- C:\Documents and Settings\All Users\Application Data\BDLogging
O43 - CFD: 2015/01/15 16:58:01 - [] D -- C:\Documents and Settings\All Users\Application Data\ccopunik
O43 - CFD: 2015/09/09 14:29:51 - [] D -- C:\Documents and Settings\All Users\Application Data\d64c6aa4-9b30-4b06-8859-0cfa31bd50dc
O43 - CFD: 2015/01/10 14:53:08 - [] D -- C:\Documents and Settings\All Users\Application Data\e292940e1b35fc7c
O43 - CFD: 2015/09/09 20:56:07 - [] D -- C:\Documents and Settings\All Users\Application Data\ExtTag =>PUP.Optional.ExtTag
O43 - CFD: 2015/09/08 19:12:25 - [] D -- C:\Documents and Settings\All Users\Application Data\ExtTags =>PUP.Optional.ExtTag
O43 - CFD: 2015/01/15 17:12:03 - [] D -- C:\Documents and Settings\All Users\Application Data\FaceOffMax
O43 - CFD: 2015/01/11 12:50:55 - [] D -- C:\Documents and Settings\All Users\Application Data\GridinSoft
O43 - CFD: 2001/01/04 00:47:38 - [0] D -- C:\Documents and Settings\All Users\Application Data\IDM
O43 - CFD: 2015/09/09 21:40:41 - [] D -- C:\Documents and Settings\All Users\Application Data\iWdsManProi =>PUP.Optional.WdsManPro
O43 - CFD: 2015/09/10 15:07:14 - [] D -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
O43 - CFD: 2015/01/15 16:06:53 - [] D -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
O43 - CFD: 2001/01/01 01:09:08 - [] SD -- C:\Documents and Settings\All Users\Application Data\Microsoft
O43 - CFD: 2014/12/21 21:00:30 - [] D -- C:\Documents and Settings\All Users\Application Data\Mozilla
O43 - CFD: 2014/12/24 15:45:24 - [] D -- C:\Documents and Settings\All Users\Application Data\Real
O43 - CFD: 2014/12/24 15:45:32 - [] D -- C:\Documents and Settings\All Users\Application Data\RealNetworks
O43 - CFD: 2015/09/09 20:56:07 - [] D -- C:\Documents and Settings\All Users\Application Data\Saophase
O43 - CFD: 2015/09/07 22:01:50 - [] D -- C:\Documents and Settings\All Users\Application Data\Saophases
O43 - CFD: 2015/09/09 21:49:32 - [] D -- C:\Documents and Settings\All Users\Application Data\Skype
O43 - CFD: 2014/12/23 20:08:11 - [] D -- C:\Documents and Settings\All Users\Application Data\Video Accelerator
O43 - CFD: 2015/09/07 20:42:35 - [] D -- C:\Documents and Settings\All Users\Application Data\vWdsManProv =>PUP.Optional.WdsManPro
O43 - CFD: 2015/03/23 20:10:42 - [] D -- C:\Documents and Settings\All Users\Application Data\{5e335bb5-da8e-3495-5e33-35bb5da86ed7}
O43 - CFD: 2015/01/31 20:04:04 - [] D -- C:\Documents and Settings\All Users\Application Data\{8e8dd5c3-431e-7cff-8e8d-dd5c3431570d}
O43 - CFD: 2015/01/31 20:04:20 - [] D -- C:\Documents and Settings\All Users\Application Data\{ce35b383-e1f3-4d55-ce35-5b383e1fce0f}
O43 - CFD: 2001/01/01 01:30:24 - [] D -- C:\Program Files\Fichiers communs\Adobe
O43 - CFD: 2015/03/23 21:06:18 - [] D -- C:\Program Files\Fichiers communs\Bitdefender
O43 - CFD: 2001/01/01 01:33:06 - [] D -- C:\Program Files\Fichiers communs\DESIGNER
O43 - CFD: 2001/01/01 01:30:38 - [] D -- C:\Program Files\Fichiers communs\Java
O43 - CFD: 2015/01/11 12:40:40 - [] D -- C:\Program Files\Fichiers communs\Microsoft Shared
O43 - CFD: 2001/01/01 01:07:32 - [] D -- C:\Program Files\Fichiers communs\MSSoap
O43 - CFD: 2001/01/01 01:58:20 - [] D -- C:\Program Files\Fichiers communs\ODBC
O43 - CFD: 2001/01/01 01:07:36 - [] D -- C:\Program Files\Fichiers communs\Services
O43 - CFD: 2015/02/02 16:09:49 - [] D -- C:\Program Files\Fichiers communs\Skype
O43 - CFD: 2001/01/01 01:58:18 - [] D -- C:\Program Files\Fichiers communs\SpeechEngines
O43 - CFD: 2001/01/01 01:07:03 - [] D -- C:\Program Files\Fichiers communs\System
O43 - CFD: 2015/09/07 21:58:59 - [] D -- C:\Program Files\Fichiers communs\v5egcusj
O43 - CFD: 2014/12/24 15:45:25 - [] D -- C:\Program Files\Fichiers communs\xing shared
O43 - CFD: 2015/09/08 21:08:56 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\.oit
O43 - CFD: 2014/12/24 21:16:32 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\Adobe
O43 - CFD: 2015/09/10 15:40:05 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\DMCache
O43 - CFD: 2015/01/11 21:09:59 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\FaceOffMax
O43 - CFD: 2001/01/01 01:34:52 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\Identities
O43 - CFD: 2015/09/09 20:39:01 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\IDM
O43 - CFD: 2015/09/05 13:38:47 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\ilividmoviestoolbar280 =>PUP.Optional.Bandoo
O43 - CFD: 2014/12/24 21:16:32 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\Macromedia
O43 - CFD: 2015/04/20 14:30:14 - [] SD -- C:\Documents and Settings\Utilisateur\Application Data\Microsoft
O43 - CFD: 2014/12/21 21:00:45 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla
O43 - CFD: 2014/12/24 15:59:43 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\MPC-HC
O43 - CFD: 2015/02/22 20:47:52 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\Opera Software
O43 - CFD: 2015/09/09 21:40:37 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\oursurfing =>PUP.Optional.OurSurfing
O43 - CFD: 2015/02/22 20:44:40 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\Paltalk
O43 - CFD: 2015/01/25 20:18:48 - [0] D -- C:\Documents and Settings\Utilisateur\Application Data\QuickScan
O43 - CFD: 2014/12/24 15:46:10 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\Real
O43 - CFD: 2014/12/24 15:45:51 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\RealNetworks
O43 - CFD: 2015/04/13 22:03:34 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\Skype
O43 - CFD: 2001/01/01 01:30:30 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\Sun
O43 - CFD: 2015/07/26 15:41:10 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\vlc
O43 - CFD: 2015/01/11 13:51:18 - [0] D -- C:\Documents and Settings\Utilisateur\Application Data\WebTest
O43 - CFD: 2015/09/09 16:10:21 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\WinRAR
O43 - CFD: 2015/09/07 20:18:28 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\Zbshareware Lab
O43 - CFD: 2015/09/10 20:10:19 - [] D -- C:\Documents and Settings\Utilisateur\Application Data\ZHP
O43 - CFD: 2015/07/19 11:21:52 - [] D -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Adobe
O43 - CFD: 2015/01/15 17:08:00 - [] D -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Google
O43 - CFD: 2015/04/19 15:28:36 - [] D -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Identities
O43 - CFD: 2015/04/24 15:50:54 - [] SD -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Microsoft
O43 - CFD: 2014/12/21 21:00:45 - [] D -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla
O43 - CFD: 2015/02/22 20:47:57 - [] D -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Opera Software
O43 - CFD: 2015/02/02 16:10:04 - [] D -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Skype
O43 - CFD: 2015/01/15 17:22:05 - [] D -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Temp
O43 - CFD: 2001/01/01 01:35:07 - [] RD -- C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\Accessoires
O43 - CFD: 2015/09/07 21:31:02 - [] D -- C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\AnySend =>PUP.Optional.ASPackage
O43 - CFD: 2015/03/23 13:38:53 - [] RD -- C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\Démarrage
O43 - CFD: 2014/12/23 19:33:28 - [] D -- C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\Internet Download Manager
O43 - CFD: 2015/03/05 15:06:52 - [] RD -- C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\Outils d'administration
O43 - CFD: 2015/02/22 20:44:41 - [] D -- C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\Paltalk Messenger
O43 - CFD: 2015/07/02 21:04:42 - [] D -- C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\Simple Shutdown Timer
O43 - CFD: 2001/01/01 01:31:01 - [] D -- C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\SuperCopier2
O43 - CFD: 2001/01/01 01:31:02 - [] D -- C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\WinRAR

---\\ Enumération des clés StartupReg (16) - 1s
O53 - SMSR:HKLM\...\startupreg\C-cleaner [Key] . (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\system32\wscript.exe ©
O53 - SMSR:HKLM\...\startupreg\CCleaner Monitoring [Key] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe ©
O53 - SMSR:HKLM\...\startupreg\Free Player [Key] . (...) -- C:\Program Files\FreePlayer\FreePlayer.exe
O53 - SMSR:HKLM\...\startupreg\HotKeysCmds [Key] . (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\system32\hkcmd.exe ©
O53 - SMSR:HKLM\...\startupreg\HSPALauncher [Key] . (.Copyright (C) 2010 - HSDPALauncher MFC Application.) -- C:\Program Files\HSPA USB Modem\HSPALauncher.exe
O53 - SMSR:HKLM\...\startupreg\IDMan [Key] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe ©
O53 - SMSR:HKLM\...\startupreg\IgfxTray [Key] . (.Intel Corporation - igfxTray Module.) -- C:\WINDOWS\system32\igfxtray.exe ©
O53 - SMSR:HKLM\...\startupreg\KernelFaultCheck [Key] . (...) -- C:\WINDOWS\system32\dumprep 0 -k (.not file.)
O53 - SMSR:HKLM\...\startupreg\Persistence [Key] . (.Intel Corporation - persistence Module.) -- C:\WINDOWS\system32\igfxpers.exe ©
O53 - SMSR:HKLM\...\startupreg\RTHDCPL [Key] . (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- RTHDCPL.EXE (.not file.) ©
O53 - SMSR:HKLM\...\startupreg\Skype [Key] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe ©
O53 - SMSR:HKLM\...\startupreg\SuperCopier2.exe [Key] . (.SFX TEAM - SuperCopier 2 (explorer file copy replaceme.) -- C:\Program Files\SuperCopier2\SuperCopier2.exe ©
O53 - SMSR:HKLM\...\startupreg\TkBellExe [Key] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe ©
O53 - SMSR:HKLM\...\startupreg\Trojan Killer (32-bit) [Key] . (.GridinSoft LLC - Trojan Killer.) -- C:\Program Files\GridinSoft Trojan Killer\trojankiller.exe
O53 - SMSR:HKLM\...\startupreg\USB Security [Key] . (.Zbshareware Lab - USB Disk Security.) -- C:\Program Files\USB Disk Security\USBGuard.exe
O53 - SMSR:HKLM\...\startupreg\VideoLAN [Key] . (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\system32\wscript.exe ©

---\\ Liste des pilotes du système (40) - 1s
O58 - SDL:2007/12/13 11:21:56 A . (.Atheros Communications, Inc. - Driver for Atheros AR5001 Wireless Network.) -- C:\WINDOWS\System32\drivers\ar5211.sys [547904] ©
O58 - SDL:2007/10/22 09:24:14 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS5.1.) -- C:\WINDOWS\System32\drivers\b57xp32.sys [161792] ©
O58 - SDL:2008/11/05 23:15:54 A . (.RAVISENT Technologies Inc. - Pilote principal CineMaster C 1.2 WDM.) -- C:\WINDOWS\System32\drivers\cinemst2.sys [262528] ©
O58 - SDL:2013/06/29 17:10:58 A . (.Mobile Connector - USB Modem/Serial Device Driver.) -- C:\WINDOWS\System32\drivers\cmusbser.sys [103552] ©
O58 - SDL:2008/11/05 23:15:54 A . (.Compaq Computer Corporation - Compaq PA-1 Player Driver.) -- C:\WINDOWS\System32\drivers\cpqdap01.sys [11776] ©
O58 - SDL:2008/04/13 20:05:08 A . (.Microsoft Corp., Veritas Software - Pilote de démarrage du gestionnaire de disq.) -- C:\WINDOWS\System32\drivers\dmboot.sys [800256] ©
O58 - SDL:2008/04/13 20:05:14 A . (.Microsoft Corp., Veritas Software - Pilote E/S du Gestionnaire de disques NT.) -- C:\WINDOWS\System32\drivers\dmio.sys [154496] ©
O58 - SDL:2002/09/07 03:00:00 A . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\System32\drivers\dmload.sys [5888] ©
O58 - SDL:2015/07/31 16:53:42 A . (.Windows (R) Win 7 DDK provider - GridinSoft Trojan Killer Mini-Filter Driver.) -- C:\WINDOWS\System32\drivers\gtkdrv.sys [16128] ©
O58 - SDL:2008/04/13 09:36:06 A . (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) -- C:\WINDOWS\System32\drivers\hdaudbus.sys [144384]
O58 - SDL:2014/11/29 01:37:06 A . (.Tonec Inc. - Internet Download Manager TDI Driver.) -- C:\WINDOWS\System32\drivers\idmtdi.sys [123360] ©
O58 - SDL:2007/12/19 10:32:12 A . (.Intel Corporation - Intel Graphics Miniport Driver.) -- C:\WINDOWS\System32\drivers\igxpmp32.sys [5854688] ©
O58 - SDL:2015/06/18 08:41:36 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\mbam.sys [23256] ©
O58 - SDL:2015/06/18 08:41:46 A . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys [121560] ©
O58 - SDL:2015/09/09 20:11:10 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [98520] ©
O58 - SDL:2008/11/05 23:15:54 A . (.S3/Diamond Multimedia Systems - NikeDrv Usb Driver.) -- C:\WINDOWS\System32\drivers\nikedrv.sys [12032] ©
O58 - SDL:2002/09/07 02:00:00 A . (.Parallel Technologies, Inc. - Parallel Technologies DirectParallel IO Lib.) -- C:\WINDOWS\System32\drivers\ptilink.sys [17792] ©
O58 - SDL:2008/11/05 23:15:54 A . (.S3/Diamond Multimedia Systems - Rio8Drv.sys Usb Driver.) -- C:\WINDOWS\System32\drivers\rio8drv.sys [12032] ©
O58 - SDL:2008/11/05 23:15:54 A . (.S3/Diamond Multimedia Systems - RioDrv Usb Driver.) -- C:\WINDOWS\System32\drivers\riodrv.sys [12032] ©
O58 - SDL:2011/02/16 00:16:16 RA . (.Ralink Technology, Corp. - Ralink 802.11 USB Wireless Adapter Driver.) -- C:\WINDOWS\System32\drivers\rt2870.sys [829792] ©
O58 - SDL:2008/01/30 11:28:36 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys [4725760] ©
O58 - SDL:2008/04/13 09:39:16 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\WINDOWS\System32\drivers\secdrv.sys [20480] ©
O58 - SDL:2013/08/22 13:40:22 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver.) -- C:\WINDOWS\System32\drivers\tap0901.sys [35288] ©
O58 - SDL:2008/11/05 23:15:54 A . (.Toshiba Corporation - WDM Toshiba Tecra Video Capture Driver.) -- C:\WINDOWS\System32\drivers\tsbvcap.sys [21376] ©
O58 - SDL:2008/11/05 23:15:54 A . (.RAVISENT Technologies Inc. - CineMaster C WDM DVD Minidriver.) -- C:\WINDOWS\System32\drivers\vdmindvd.sys [58112] ©
O58 - SDL:2002/09/07 03:00:00 A . (...) -- C:\WINDOWS\System32\ansi.sys [9037]
O58 - SDL:2002/09/07 03:00:00 A . (...) -- C:\WINDOWS\System32\country.sys [27097]
O58 - SDL:2002/09/07 03:00:00 A . (...) -- C:\WINDOWS\System32\himem.sys [4912]
O58 - SDL:2002/09/07 03:00:00 A . (...) -- C:\WINDOWS\System32\key01.sys [42809]
O58 - SDL:2008/04/13 10:50:56 A . (...) -- C:\WINDOWS\System32\keyboard.sys [42537]
O58 - SDL:2002/09/07 02:00:00 A . (...) -- C:\WINDOWS\System32\ntdos.sys [27916]
O58 - SDL:2002/09/07 02:00:00 A . (...) -- C:\WINDOWS\System32\ntdos404.sys [29146]
O58 - SDL:2002/09/07 02:00:00 A . (...) -- C:\WINDOWS\System32\ntdos411.sys [29370]
O58 - SDL:2002/09/07 02:00:00 A . (...) -- C:\WINDOWS\System32\ntdos412.sys [29274]
O58 - SDL:2002/09/07 02:00:00 A . (...) -- C:\WINDOWS\System32\ntdos804.sys [29146]
O58 - SDL:2008/04/13 09:49:52 A . (...) -- C:\WINDOWS\System32\ntio.sys [34000]
O58 - SDL:2008/04/13 09:49:44 A . (...) -- C:\WINDOWS\System32\ntio404.sys [34560]
O58 - SDL:2008/04/13 09:49:40 A . (...) -- C:\WINDOWS\System32\ntio411.sys [35648]
O58 - SDL:2008/04/13 09:49:44 A . (...) -- C:\WINDOWS\System32\ntio412.sys [35424]
O58 - SDL:2008/04/13 09:49:42 A . (...) -- C:\WINDOWS\System32\ntio804.sys [34560]

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (10) - 2s
O61 - LFC: 2015/09/07 20:18:31 A . (.Zbshareware Lab.) -- C:\Documents and Settings\Utilisateur\Mes documents\USBGuard6.5.0.0.exe [4027752]
O61 - LFC: 2015/09/09 15:13:00 A . (..) -- C:\Documents and Settings\Utilisateur\Mes documents\Downloads\Programs\avira_internet_security_fr.exe [217842000]
O61 - LFC: 2015/09/08 21:08:30 A . (.FoxPDF Software Inc.) -- C:\Documents and Settings\Utilisateur\Mes documents\Downloads\Programs\docxreader.exe [12284687]
O61 - LFC: 2015/09/09 21:28:39 A . (.Лаборатория Касперского.) -- C:\Documents and Settings\Utilisateur\Mes documents\Downloads\Programs\kis15.0.2.361ru_7781.exe [198476608]
O61 - LFC: 2015/09/09 14:24:09 A . (..) -- C:\Documents and Settings\Utilisateur\Mes documents\Downloads\Programs\Torrent_Torrentex.exe [4085536]
O61 - LFC: 2015/09/07 20:18:15 A . (.Zbshareware Lab.) -- C:\Documents and Settings\Utilisateur\Mes documents\Downloads\Programs\USBGuard6.5.0.0.exe [4027752]
O61 - LFC: 2015/09/07 20:36:44 A . (.UMYFH.) -- C:\Documents and Settings\Utilisateur\Mes documents\Downloads\Programs\Xp Arabic Font.exe [600608]
O61 - LFC: 2015/09/09 21:38:02 A . (..) -- C:\Documents and Settings\Utilisateur\Bureau\smartcop.rar__15022_i1637667859_il1794096.exe [766128]
O61 - LFC: 2015/09/08 05:55:32 A . (.TODO: .) -- C:\Documents and Settings\Utilisateur\Application Data\oursurfing\UninstallManager.exe [375296] =>PUP.Optional.OurSurfing
O61 - LFC: 2015/09/03 22:37:41 A . (..) -- C:\Documents and Settings\Utilisateur\Application Data\IDM\DwnlData\Utilisateur\general-20removal-20free-20dow_650\general-20removal-20free-20dow.exe [337016]

---\\ Associations Shell Spawning (10) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll ©
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe ©
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\system32\wscript.exe ©
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe ©
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe ©

---\\ Menu de démarrage Internet (15) - 0s
O68 - StartMenuInternet: <>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe http://www.oursurfing.com/ ©
O68 - StartMenuInternet: <>[HKLM\..\Shell\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe http://www.oursurfing.com/ ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\Launcher.exe http://www.oursurfing.com/ ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\WINDOWS\system32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\WINDOWS\system32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\WINDOWS\system32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe ©

---\\ Recherche d'infection sur les navigateurs (13) - 1s
O69 - SBI: prefs.js [Utilisateur - 238zet1k.default] user_pref("browser.newtab.url", "http://www.oursurfing.com/newtab/?type=nt&ts=1441831183&z=127fc81e775df9bc95611dfg7zez5gab3c2e7q1[...] =>PUP.Optional.OurSurfing
O69 - SBI: prefs.js [Utilisateur - 238zet1k.default] user_pref("browser.search.searchengine.alias", "oursurfing"); =>PUP.Optional.OurSurfing
O69 - SBI: prefs.js [Utilisateur - 238zet1k.default] user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [Utilisateur - 238zet1k.default] user_pref("browser.search.searchengine.iconURL", "http://www.oursurfing.com/favicon.ico"); =>PUP.Optional.OurSurfing
O69 - SBI: prefs.js [Utilisateur - 238zet1k.default] user_pref("browser.search.searchengine.name", "oursurfing"); =>PUP.Optional.OurSurfing
O69 - SBI: prefs.js [Utilisateur - 238zet1k.default] user_pref("browser.search.searchengine.ptid", "2sq3"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [Utilisateur - 238zet1k.default] user_pref("browser.search.searchengine.uid", "HitachiXHTS542516K9SA00_071126BB0300WCHDLXJCX"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [Utilisateur - 238zet1k.default] user_pref("browser.search.searchengine.url", "http://www.oursurfing.com/web/?type=ds&ts=1441831183&z=127fc81e775df9bc95611dfg7zez5[...] =>PUP.Optional.OurSurfing
O69 - SBI: prefs.js [Utilisateur - 238zet1k.default] user_pref("browser.startup.homepage", "http://www.oursurfing.com/?type=hp&ts=1441831183&z=127fc81e775df9bc95611dfg7zez5gab3c2e7q1m[...] =>PUP.Optional.OurSurfing
O69 - SBI: prefs.js [Utilisateur - 238zet1k.default] user_pref("extensions.enabledAddons", "deskCutv2%40gmail.com:0.0.10"); =>PUP.Optional.DeskCut
O69 - SBI: SearchScopes [HKCU] {ielnksrch} - (Search the web) - http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_ByuMcS4zqTgWbU5vS0OBHBt-YBNbDOqA2MLdMjX2AK4neJKFS2mjibIrtngtDaJSinxdFFm54WzyIvggwiPf4CcQlebL7ehV9fE-br8qWaP-VRhyxp_ClOuCR-E4kU4pm9L6IY_FYSZluovw-MvTI5zfe27vF&q={searchTerms}
O69 - SBI: SearchScopes [HKUS\S-1-5-19] {ielnksrch} [DefaultScope] - (Search the web) - http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_ByuMcS4zqTgWbU5vS0OBHBt-YBNbDOqA2MLdMjX2AK4neJKFS2mjibIrtngtDaJSinxdFFm54WzyIvggwiPf4CcQlebL7ehV9fE-br8qWaP-VRhyxp_ClOuCR-E4kU4pm9L6IY_FYSZluovw-MvTI5zfe27vF&q={searchTerms}
O69 - SBI: SearchScopes [HKUS\S-1-5-20] {ielnksrch} [DefaultScope] - (Search the web) - http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_ByuMcS4zqTgWbU5vS0OBHBt-YBNbDOqA2MLdMjX2AK4neJKFS2mjibIrtngtDaJSinxdFFm54WzyIvggwiPf4CcQlebL7ehV9fE-br8qWaP-VRhyxp_ClOuCR-E4kU4pm9L6IY_FYSZluovw-MvTI5zfe27vF&q={searchTerms}

---\\ Enumère les fichiers Crack & Keygen (1) - 2s
O82 - LFC: 2010/03/31 08:50:12 A . (...) -- C:\Documents and Settings\Utilisateur\Bureau\Lz0\keygen.exe [155648] =>.Crack,Keygen

---\\ Enumère les services démarrés par Svchost (40) - 0s
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\WINDOWS\system32\appmgmts.dll [176640] ©
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\WINDOWS\system32\audiosrv.dll [42496] ©
O83 - Search Svchost Services: Browser (Browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINDOWS\system32\browser.dll [77824] ©
O83 - Search Svchost Services: CryptSvc (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) -- C:\WINDOWS\system32\cryptsvc.dll [62464] ©
O83 - Search Svchost Services: DMServer (DMServer) . (.Microsoft Corp. - DLL Service gestionnaire de disque logique.) -- C:\WINDOWS\system32\dmserver.dll [24576] ©
O83 - Search Svchost Services: DHCP (DHCP) . (.Microsoft Corporation - Service client DHCP.) -- C:\WINDOWS\system32\dhcpcsvc.dll [127488] ©
O83 - Search Svchost Services: ERSvc (ERSvc) . (.Microsoft Corporation - Windows Error Reporting Service.) -- C:\WINDOWS\system32\ersvc.dll [23040] ©
O83 - Search Svchost Services: EventSystem (EventSystem) . (.Microsoft Corporation - .) -- C:\WINDOWS\system32\es.dll [253952] ©
O83 - Search Svchost Services: FastUserSwitchingCompatibility (FastUserSwitchingCompatibility) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680] ©
O83 - Search Svchost Services: HidServ (HidServ) . (...) -- C:\WINDOWS\System32\hidserv.dll [0]
O83 - Search Svchost Services: LanmanServer (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\system32\srvsvc.dll [96768] ©
O83 - Search Svchost Services: LanmanWorkstation (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) -- C:\WINDOWS\system32\wkssvc.dll [132096] ©
O83 - Search Svchost Services: Messenger (Messenger) . (.Microsoft Corporation - NT Messenger Service.) -- C:\WINDOWS\system32\msgsvc.dll [33792] ©
O83 - Search Svchost Services: Netman (Netman) . (.Microsoft Corporation - Gestionnaire de connexions réseau.) -- C:\WINDOWS\system32\netman.dll [198144] ©
O83 - Search Svchost Services: Nla (Nla) . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Micro.) -- C:\WINDOWS\system32\mswsock.dll [247808] ©
O83 - Search Svchost Services: Ntmssvc (Ntmssvc) . (.Microsoft Corporation - Gestionnaire de stockage amovible.) -- C:\WINDOWS\system32\ntmssvc.dll [438272] ©
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\system32\rasauto.dll [88576] ©
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\system32\rasmans.dll [186368] ©
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\WINDOWS\system32\mprdim.dll [53248] ©
O83 - Search Svchost Services: Schedule (Schedule) . (.Microsoft Corporation - Moteur du Planificateur de tâches.) -- C:\WINDOWS\system32\schedsvc.dll [194560] ©
O83 - Search Svchost Services: Seclogon (Seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secon.) -- C:\WINDOWS\system32\seclogon.dll [18944] ©
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\system32\sens.dll [39424] ©
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à.) -- C:\WINDOWS\system32\ipnathlp.dll [332288] ©
O83 - Search Svchost Services: SRService (SRService) . (.Microsoft Corporation - Service de restauration du système.) -- C:\WINDOWS\system32\srsvc.dll [171520] ©
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\WINDOWS\system32\tapisrv.dll [249856] ©
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680] ©
O83 - Search Svchost Services: TrkWks (TrkWks) . (.Microsoft Corporation - Distributed Link Tracking Client.) -- C:\WINDOWS\system32\trkwks.dll [90112] ©
O83 - Search Svchost Services: W32Time (W32Time) . (.Microsoft Corporation - Service de temps Windows.) -- C:\WINDOWS\system32\w32time.dll [178176] ©
O83 - Search Svchost Services: WZCSVC (WZCSVC) . (.Microsoft Corporation - Service configuration automatique sans fil.) -- C:\WINDOWS\system32\wzcsvc.dll [483840] ©
O83 - Search Svchost Services: Wmi (Wmi) . (.Microsoft Corporation - API avancées Windows 32.) -- C:\WINDOWS\system32\advapi32.dll [685568] ©
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\wmisvc.dll [145408] ©
O83 - Search Svchost Services: wscsvc (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) -- C:\WINDOWS\system32\wscsvc.dll [80896] ©
O83 - Search Svchost Services: xmlprov (xmlprov) . (.Microsoft Corporation - Network Provisioning Service.) -- C:\WINDOWS\system32\xmlprov.dll [129024] ©
O83 - Search Svchost Services: napagent (napagent) . (.Microsoft Corporation - Exécution du service Agent de quarantaine.) -- C:\WINDOWS\system32\qagentrt.dll [293376] ©
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\WINDOWS\system32\kmsvc.dll [61440] ©
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\WINDOWS\system32\qmgr.dll [409088] ©
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update AutoUpdate Service.) -- C:\WINDOWS\system32\wuauserv.dll [6656] ©
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680] ©
O83 - Search Svchost Services: helpsvc (helpsvc) . (.Microsoft Corporation - Microsoft PCHealth Service Holder.) -- C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll [38400] ©
O83 - Search Svchost Services: WmdmPmSN (WmdmPmSN) . (.Microsoft Corporation - Microsoft Media Device Service Provider.) -- C:\WINDOWS\system32\mspmsnsv.dll [27136] ©

---\\ Enumère les codes produits des logiciels (1) - 0s
O90 - PUC: "FEEB8747424601D48A2B3A21A6792C5D" . (.AnySend 1.0.18.0 (x86).) =>PUP.Optional.ASPackage

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (8) - 16s

SS - Demand [2015/07/19 11:27:03] [ 268976] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe ©
SS - Demand [2014/12/24 15:53:51] [ 116648] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe ©
SS - Demand [2014/12/24 15:53:51] [ 116648] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe ©
SR - Auto [2015/06/10 19:55:12] [ 180128] IAC Update Service (IAC Update Service) . (.IAC Search and Media.) - C:\Program Files\IAC Updater\iacupdater.exe
SS - Demand [2015/04/12 13:43:37] [ 148080] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe ©
SR - Auto [2014/08/12 11:34:48] [ 39056] RealNetworks Downloader Resolver Service (RealNetworks Downloader Resolver Service) . (...) - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
SS - Auto [2015/01/02 19:45:12] [ 315488] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe ©

---\\ Scan Additionnel (28) - 0s
C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aaaaaigjndjblmpeckabiffcpogflfgl
C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\akaelkiagnbfcccfnmbimdbplecgbikh
C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\searchplugins\findit.xml =>PUP.Optional.SmartBar
C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\searchplugins\oursurfing.xml =>PUP.Optional.OurSurfing
C:\Program Files\Mozilla Firefox\browser\searchplugins\findit.xml =>PUP.Optional.SmartBar
C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo.xml =>PUP.Optional.BDYahoo
C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\238zet1k.default\extensions\deskCutv2@gmail.com =>PUP.Optional.LightningNewTab
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{61628E2A-4FF9-4454-992D-D92A8CD27399} =>PUP.Optional.ASPackage
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\oursurfing uninstall =>PUP.Optional.OurSurfing
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7478BEEF-6424-4D10-A8B2-A3126A97C2D5} =>PUP.Optional.ASPackage
HKLM\SOFTWARE\downchecker =>PUP.Optional.DownChecker
HKLM\SOFTWARE\GreatFind =>PUP.Optional.GreatFind
HKLM\SOFTWARE\oursurfingSoftware =>PUP.Optional.OurSurfing
HKLM\SOFTWARE\WdsManPro =>PUP.Optional.WdsManPro
HKCU\SOFTWARE\ilividmoviestoolbar280 =>PUP.Optional.Bandoo
C:\Program Files\694171D0-1441654915-3D38-8455-001B387651C1 =>PUP.Optional.CrossRider
C:\Program Files\SFK =>PUP.Optional.MyWebSearch
C:\Documents and Settings\All Users\Application Data\AnySend =>PUP.Optional.ASPackage
C:\Documents and Settings\All Users\Application Data\ExtTag =>PUP.Optional.ExtTag
C:\Documents and Settings\All Users\Application Data\ExtTags =>PUP.Optional.ExtTag
C:\Documents and Settings\All Users\Application Data\iWdsManProi =>PUP.Optional.WdsManPro
C:\Documents and Settings\All Users\Application Data\vWdsManProv =>PUP.Optional.WdsManPro
C:\Documents and Settings\Utilisateur\Application Data\ilividmoviestoolbar280 =>PUP.Optional.Bandoo
C:\Documents and Settings\Utilisateur\Application Data\oursurfing =>PUP.Optional.OurSurfing
C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\AnySend =>PUP.Optional.ASPackage
C:\Documents and Settings\Utilisateur\Application Data\oursurfing\UninstallManager.exe =>PUP.Optional.OurSurfing
HKLM\Software\Classes\Installer\Products\FEEB8747424601D48A2B3A21A6792C5D =>PUP.Optional.ASPackage
HKLM\Software\Classes\Installer\Features\FEEB8747424601D48A2B3A21A6792C5D =>PUP.Optional.ASPackage

---\\ Récapitulatif des éléments trouvées sur votre station (14) - 0s
http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider
http://www.nicolascoolman.fr/blog =>PUP.Optional.OurSurfing
http://www.nicolascoolman.fr/hijacker-smartbar/ =>PUP.Optional.SmartBar
http://www.nicolascoolman.fr/blog =>PUP.Optional.BDYahoo
http://www.nicolascoolman.fr/blog =>PUP.Optional.LightningNewTab
http://www.nicolascoolman.fr/blog =>PUP.Optional.ASPackage
http://www.nicolascoolman.fr/blog =>PUP.Optional.DownChecker
http://www.nicolascoolman.fr/blog =>PUP.Optional.GreatFind
http://www.nicolascoolman.fr/blog =>PUP.Optional.WdsManPro
http://www.nicolascoolman.fr/adware-bandoo/ =>PUP.Optional.Bandoo
http://www.nicolascoolman.fr/adware-mywebsearch/ =>PUP.Optional.MyWebSearch
http://www.nicolascoolman.fr/pup-optional-exttag =>PUP.Optional.ExtTag
http://www.nicolascoolman.fr/blog =>PUP.Optional.SearchEngine
http://www.nicolascoolman.fr/blog =>PUP.Optional.DeskCut

~ End of the scan, 15020 items in 50 seconds (694)(1)()

Publicité


Signaler le contenu de ce document

Publicité