cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.9.22.144 Par Nicolas Coolman (2015/09/22)
~ Démarré par rose (Administrator) (2015/09/22 10:48:10)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\rose\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\rose\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
Windows VISTA, 32-bit Service Pack 2 (Build 6002)

---\\ Navigateurs Internet (3) - 0s
GCIE: Google Chrome v45.0.2454.93
MFIE: Mozilla Firefox 36.0.1 (x86 fr) v36.0.1
MSIE: Internet Explorer v9.0.8112.16421

---\\ Informations sur les produits Windows (4) - 3s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK
Windows Activation Technologies : KO

---\\ Logiciels de protection (4) - 6s
Malwarebytes Anti-Malware version 2.1.8.1057
Microsoft Security Client v4.8.0204.0
Microsoft Security Essentials v4.8.204.0
Windows Defender VISTA (Deactivate)

---\\ Logiciels de protection et autres (Superflus) (1) - 7s
Spybot - Search & Destroy v2.4.40

---\\ Logiciels d'optimisation (1) - 7s
CCleaner v4.14

---\\ Surveillance de Logiciels (2) - 7s
Adobe Flash Player 19 NPAPI
Adobe Reader XI

---\\ Informations sur le système (6) - 0s
~ Operating System: x86 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 32-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 3108.74 MB (63% free)
~ System Restore: Activé (Enable)
~ System drive C: has 145 GB free of 231 GB

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: PC-DE-ROSE
~ User Name: rose
~ Logged in as Administrator

---\\ Enumération des unités disques (2) - 0s
~ Drive C: has 145 GB free of 231 GB (System)
~ Drive D: has 211 GB free of 231 GB

---\\ Etat du Centre de Sécurité Windows (11) - 0s
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Recherche particulière de fichiers génériques (24) - 3s
[MD5.D07D4C3038F3578FFCE1C0237F2A1253] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\Windows\Explorer.exe [2926592] ©
[MD5.4B555106290BD117334E9A08761C035A] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\Windows\System32\rundll32.exe [44544] ©
[MD5.101BA3EA053480BB5D957EF37C06B5ED] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\Windows\System32\Wininit.exe [96768] ©
[MD5.605FFF8DF63D05DB523E635A14DDB43C] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\Windows\System32\wininet.dll [1129472] ©
[MD5.898E7C06A350D4A1A64A9EA264D55452] - (.Microsoft Corporation - Application d'ouverture de session Windows.) () -- C:\Windows\System32\Winlogon.exe [314368] ©
[MD5.85E861D0B88DB2B54ACB0839654C09F7] - (.Microsoft Corporation - DNS DLL de l'API Client.) () -- C:\Windows\System32\dnsapi.dll [168448] ©
[MD5.95F5FF73B076576C41740F1A842B9B57] - (.Microsoft Corporation - DLL client de l'API uilisateur de Windows m.) () -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] ©
[MD5.F5272A105F59A7B3B345D9D6D87DA7AD] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\Windows\System32\drivers\AFD.sys [273408] ©
[MD5.1F05B78AB91C9075565A9D8A4B880BC4] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\Windows\System32\drivers\atapi.sys [19944] ©
[MD5.7ADD03E75BEB9E6DD102C3081D29840A] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\Windows\System32\drivers\Cdfs.sys [70144] ©
[MD5.6B4BFFB9BECD728097024276430DB314] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\Windows\System32\drivers\Cdrom.sys [67072] ©
[MD5.622C41A07CA7E6DD91770F50D532CB6C] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\Windows\System32\drivers\DfsC.sys [75264] ©
[MD5.062452B7FFD68C8C042A6261FE8DFF4A] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\Windows\System32\drivers\HDAudBus.sys [561152] ©
[MD5.22D56C8184586B7A1F6FA60BE5F5A2BD] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\Windows\System32\drivers\i8042prt.sys [54784] ©
[MD5.8793643A67B42CEC66490B2A0CF92D68] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\Windows\System32\drivers\IpNat.sys [100864] ©
[MD5.1B864548B2ACEC1C0BB29B615CC42978] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\Windows\System32\drivers\MRxSmb.sys [107008] ©
[MD5.ECD64230A59CBD93C85F1CD1CAB9F3F6] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\Windows\System32\drivers\netBT.sys [185856] ©
[MD5.2C1121F2B87E9A6B12485DF53CD848C7] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\Windows\System32\drivers\ntfs.sys [1082232] ©
[MD5.0FA9B5055484649D63C303FE404E5F4D] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\Windows\System32\drivers\Parport.sys [79360] ©
[MD5.A214ADBAF4CB47DD2728859EF31F26B0] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\Windows\System32\drivers\Rasl2tp.sys [76288] ©
[MD5.FBC0BACD9C3D7F6956853F64A66E252D] - (.Microsoft Corporation - Microsoft RDP Device redirector.) () -- C:\Windows\System32\drivers\rdpdr.sys [248832] ©
[MD5.7B75299A4D201D6A6533603D6914AB04] - (.Microsoft Corporation - SMB Transport driver.) () -- C:\Windows\System32\drivers\smb.sys [66560] ©
[MD5.76B06EB8A01FC8624D699E7045303E54] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\Windows\System32\drivers\tdx.sys [72192] ©
[MD5.786DB5771F05EF300390399F626BF30A] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\Windows\System32\drivers\volsnap.sys [224640] ©

---\\ Processus lancés (17) - 1s
[MD5.DB338C400CC9F5CEB568899D664FF335] - (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) -- C:\Windows\System32\Ati2evxx.exe [733184] [PID.1148] ©
[MD5.DB338C400CC9F5CEB568899D664FF335] - (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) -- C:\Windows\System32\Ati2evxx.exe [733184] [PID.1708] ©
[MD5.30C65FB4BB8082B077ED71E228C54A36] - (.Samsung Electronics Co., Ltd. - EasySpeedUpManager.) -- C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe [742400] [PID.1508] ©
[MD5.787311D77B29EE718A1A22859C3E4F6F] - (.Samsung Electronics Co., Ltd. - Samsung Magic Doctor Launcher.) -- C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe [45056] [PID.1756] ©
[MD5.019D6C51FD7A7E0760B7C7C95EA77528] - (.SAMSUNG Electronics co., LTD. - Easy Battery Manager 3.) -- C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe [352256] [PID.2156] ©
[MD5.0BC0C47AB03B84F4ECC511DEEE887445] - (.Samsung Electronics Co., Ltd. - Easy Display Manager.) -- C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [692224] [PID.2168] ©
[MD5.013697369EAFFA675D0671607F036020] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [82128] [PID.2456] ©
[MD5.EFBC44FBD75E4F80BD927AEBF6E7EADE] - (.Agere Systems - Agere Soft Modem Call Progress Service.) -- C:\Windows\System32\agrsmsvc.exe [13312] [PID.2472] ©
[MD5.F85AE59A52885F4B09AADAFB23001A3B] - (.Copyright (C) 2009 - .) -- C:\Windows\System32\Rezip.exe [311296] [PID.2744]
[MD5.D777F1417D9BB9F66CD9D9C3B61F730F] - (.Safer-Networking Ltd. - Spybot-S&D 2 Scanner Service.) -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168] [PID.2808] ©
[MD5.68D6C7F99BC73B88954D844FCCBEB2A0] - (.Safer-Networking Ltd. - Spybot-S&D 2 Background update service.) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408] [PID.3272] ©
[MD5.9B9B368A8FF5CAF91D7A333CF62CD2CC] - (.Safer-Networking Ltd. - Windows Security Center integration..) -- C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928] [PID.3604] ©
[MD5.83946783D86BEB7A898BC6B562F1F189] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [815944] [PID.544] ©
[MD5.83946783D86BEB7A898BC6B562F1F189] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [815944] [PID.2360] ©
[MD5.83946783D86BEB7A898BC6B562F1F189] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [815944] [PID.3716] ©
[MD5.83946783D86BEB7A898BC6B562F1F189] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [815944] [PID.4052] ©
[MD5.3274AC8202980DD1B63F3062B7A5D37A] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\rose\ZHPDiag3.exe [1936896] [PID.5280] ©

---\\ Google Chrome, Démarrage,Recherche,Extensions (5) - 0s
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.google.com/
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [hdpnmimnmfiglnagjpadkhgggagodcck] Background for G+
G2 - GCE: Preference [User Data\Default] [lccekmodgklaepjeofjdjpbminllajkg] Chrome Hotword Shared Module
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (11) - 1s
M0 - MFSP: prefs.js [rose - j41o90gl.default] http://www.google.com/
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-france.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay-france.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo-france.xml
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ©
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\NPSWF32_19_0_0_185.dll ©

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (11) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer

---\\ Internet Explorer,Proxy Management (4) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.)
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.)
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"

---\\ Etude du fichier hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (15517)

---\\ Browser Helper Object de navigateur (BHO) (4) - 1s
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} (Orphean)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} (Orphean)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll ©
O2 - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} (Orphean)

---\\ Internet Explorer, Barre d'outil (2) - 0s
O3 - Toolbar: 0xB1C218236549D4119B18009027A5CD4F - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} . (...) -- (.not file.)
O3 - Toolbar: IEToolbar - [HKLM]{381FFDE8-2394-4f90-B10D-FC6124A40F8C} . (...) -- (.not file.)

---\\ Applications lancées au démarrage du système (8) - 0s
O4 - HKCU\..\Run: [WMPNSCFG] . (.Microsoft Corporation - Application de configuration du service Par.) -- C:\Program Files\Windows Media Player\wmpnscfg.exe ©
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_4878BA9AB6674643E1160A3519305162] . (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe ©
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe ©
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe ©
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe ©
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe ©
O4 - HKUS\S-1-5-21-1228387082-1587413325-2831801477-1003\..\Run: [WMPNSCFG] . (.Microsoft Corporation - Application de configuration du service Par.) -- C:\Program Files\Windows Media Player\wmpnscfg.exe ©
O4 - HKUS\S-1-5-21-1228387082-1587413325-2831801477-1003\..\Run: [GoogleChromeAutoLaunch_4878BA9AB6674643E1160A3519305162] . (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe ©

---\\ Modification Domaine/Adresses DNS (6) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240

---\\ Protocole additionnel (25) - 1s
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll ©
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll ©
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll ©
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll ©
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll ©
O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll ©
O18 - Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll ©
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll ©
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files\Windows Live\Mail\mailcomm.dll ©
O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©
O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL ©

---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (1) - 0s
O20 - AppInit_DLLs: . (...) - C:\ProgramData\FlashBeat\FlashBeat32.dll C:\ProgramData\LolliScan\LolliScan32.dll (.not file.) =>PUP.Optional.Graftor

---\\ Liste des services NT non Microsoft et non désactivés (9) - 1s
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe ©
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) . (.Agere Systems - Agere Soft Modem Call Progress Service.) - C:\Windows\System32\agrsmsvc.exe ©
O23 - Service: (Ati External Event Utility) . (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) - C:\Windows\System32\Ati2evxx.exe ©
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe ©
O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe ©
O23 - Service: Rezip (Rezip) . (.Copyright (C) 2009 - .) - C:\Windows\System32\Rezip.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) . (.Safer-Networking Ltd. - Spybot-S&D 2 Scanner Service.) - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe ©
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) . (.Safer-Networking Ltd. - Spybot-S&D 2 Background update service.) - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe ©
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) . (.Safer-Networking Ltd. - Windows Security Center integration..) - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe ©

---\\ Enumère les données de BootExecute (1) - 0s
O34 - HKLM BootExecute: (sdnclean.exe) (.Safer Networking Limited - .) -- sdnclean.exe

---\\ Tâches planifiées en automatique (39) - 4s
[MD5.E3FB05F33E1404AD606B1E1FE7C323C3] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [998104] ©
[MD5.C6D147C12C424373B016C0AB0A6C61EB] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [269000] ©
[MD5.0395F4275F825078271AB287EFC4BF75] [APT] [BatteryLifeExtender] (.Samsung Electronics. Co. Ltd..) -- C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [550912]
[MD5.13ECAC1C51CC00147BD06B5ABF142956] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [4529944] ©
[MD5.9CCE733E5262FB92C2331E8578512B49] [APT] [Check for updates (Spybot - Search & Destroy)] (.Safer-Networking Ltd..) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe [4747720] ©
[MD5.00000000000000000000000000000000] [APT] [DBJXMQ1] (...) -- C:\ProgramData\FlashBeat\FlashBeat.exe (.not file.) [0] =>PUP.Optional.FlashBeat
[MD5.019D6C51FD7A7E0760B7C7C95EA77528] [APT] [EasyBatteryManager] (.SAMSUNG Electronics co., LTD..) -- C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe [352256] ©
[MD5.0BC0C47AB03B84F4ECC511DEEE887445] [APT] [EasyDisplayMgr] (.Samsung Electronics Co., Ltd..) -- C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [692224] ©
[MD5.30C65FB4BB8082B077ED71E228C54A36] [APT] [EasySpeedUpManager] (.Samsung Electronics Co., Ltd..) -- C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe [742400] ©
[MD5.E1B44A75947137F4143308D566889837] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107848] ©
[MD5.E1B44A75947137F4143308D566889837] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107848] ©
[MD5.48FAE038F51676A795CEFAD780448D94] [APT] [Refresh immunization (Spybot - Search & Destroy)] (.Safer-Networking Ltd..) -- C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe [4460472] ©
[MD5.787311D77B29EE718A1A22859C3E4F6F] [APT] [SamsungMagicDoctor] (.Samsung Electronics Co., Ltd..) -- C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe [45056] ©
[MD5.280C014187E24860A7C860329513208F] [APT] [Scan the system (Spybot - Search & Destroy)] (.Safer-Networking Ltd..) -- C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe [4818848] ©
[MD5.06F7D67EC4D15F11A2923268BAA937D3] [APT] [SUPBackground] (...) -- C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe [300912]
[MD5.00000000000000000000000000000000] [APT] [Wluklinu] (...) -- C:\ProgramData\Wluklinu\1.0.1.0\eulvravu.exe (.not file.) [0] =>Heuristic.PullUpdate
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002] ©
O39 - APT: Check for updates (Spybot - Search & Destroy) - (.Safer-Networking Ltd..) -- C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job [644] ©
O39 - APT: DBJXMQ1 - (...) -- C:\Windows\Tasks\DBJXMQ1.job [328] =>PUP.Optional.FlashBeat
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1052] ©
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1056] ©
O39 - APT: Refresh immunization (Spybot - Search & Destroy) - (.Safer-Networking Ltd..) -- C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job [616] ©
O39 - APT: Scan the system (Spybot - Search & Destroy) - (.Safer-Networking Ltd..) -- C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job [446] ©
O39 - APT: Adobe Acrobat Update Task - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Acrobat Update Task [3874] ©
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [3854] ©
O39 - APT: BatteryLifeExtender - (.Samsung Electronics. Co. Ltd..) -- C:\Windows\System32\Tasks\BatteryLifeExtender [3088]
O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [2770] ©
O39 - APT: Check for updates (Spybot - Search & Destroy) - (.Safer-Networking Ltd..) -- C:\Windows\System32\Tasks\Check for updates (Spybot - Search & Destroy) [3010] ©
O39 - APT: DBJXMQ1 - (...) -- C:\Windows\System32\Tasks\DBJXMQ1 [2850] =>PUP.Optional.FlashBeat
O39 - APT: EasyBatteryManager - (.SAMSUNG Electronics co., LTD..) -- C:\Windows\System32\Tasks\EasyBatteryManager [3130] ©
O39 - APT: EasyDisplayMgr - (.Samsung Electronics Co., Ltd..) -- C:\Windows\System32\Tasks\EasyDisplayMgr [3156] ©
O39 - APT: EasySpeedUpManager - (.Samsung Electronics Co., Ltd..) -- C:\Windows\System32\Tasks\EasySpeedUpManager [3272] ©
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [3800] ©
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [4052] ©
O39 - APT: Refresh immunization (Spybot - Search & Destroy) - (.Safer-Networking Ltd..) -- C:\Windows\System32\Tasks\Refresh immunization (Spybot - Search & Destroy) [3430] ©
O39 - APT: SamsungMagicDoctor - (.Samsung Electronics Co., Ltd..) -- C:\Windows\System32\Tasks\SamsungMagicDoctor [3264] ©
O39 - APT: Scan the system (Spybot - Search & Destroy) - (.Safer-Networking Ltd..) -- C:\Windows\System32\Tasks\Scan the system (Spybot - Search & Destroy) [3784] ©
O39 - APT: SUPBackground - (...) -- C:\Windows\System32\Tasks\SUPBackground [3158]
O39 - APT: Wluklinu - (...) -- C:\Windows\System32\Tasks\Wluklinu [3458] =>Heuristic.PullUpdate

---\\ Logiciels installés (59) - 8s
O42 - Logiciel: Adobe Flash Player ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX ©
O42 - Logiciel: Adobe Flash Player 19 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI ©
O42 - Logiciel: Agere Systems HDA Modem - (.Agere Systems.) [HKLM] -- Agere Systems Soft Modem ©
O42 - Logiciel: Gestionnaire de contacts professionnels pour Outlook 2007 SP2 - (.Microsoft Corporation.) [HKLM] -- Business Contact Manager ©
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner ©
O42 - Logiciel: CX4300_5500_DX4400 Manuel - (...) [HKLM] -- CX4300_5500_DX4400 Manuel
O42 - Logiciel: East-Tec Eraser 2010 Version 9.9 - (.EAST Technologies.) [HKLM] -- East-Tec Eraser 2010_is1 ©
O42 - Logiciel: EPSON Logiciel imprimante - (.SEIKO EPSON Corporation.) [HKLM] -- EPSON Printer and Utilities ©
O42 - Logiciel: EPSON Scan - (...) [HKLM] -- EPSON Scanner
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome ©
O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM] -- InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D} ©
O42 - Logiciel: EPSON Attach To Email - (.SEIKO EPSON.) [HKLM] -- InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5} ©
O42 - Logiciel: Samsung Update Plus - (.Samsung Electronics Co., LTD.) [HKLM] -- InstallShield_{A5F483F0-2D79-4FCA-AE09-D0D96E23EBF7} ©
O42 - Logiciel: Malwarebytes Anti-Malware version 2.1.8.1057 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1 ©
O42 - Logiciel: Marvell Miniport Driver - (.Marvell.) [HKLM] -- Marvell Miniport Driver ©
O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client ©
O42 - Logiciel: Mozilla Firefox 36.0.1 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 36.0.1 (x86 fr) ©
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService ©
O42 - Logiciel: Intel PROSet Wireless - (...) [HKLM] -- ProInst
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics.) [HKLM] -- SynTPDeinstKey ©
O42 - Logiciel: WinRAR 4.01 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver ©
O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM] -- {01FB4998-33C4-4431-85ED-079E3EEFE75D} ©
O42 - Logiciel: Atheros WLAN Client - (...) [HKLM] -- {04983D37-2202-4295-94A2-8B547C66133F}
O42 - Logiciel: Samsung Recovery Solution III - (.Samsung.) [HKLM] -- {145DE957-0679-4A2A-BB5C-1D3E9808FAB2} ©
O42 - Logiciel: Easy Display Manager - (.Samsung Electronics Co., Ltd..) [HKLM] -- {17283B95-21A8-4996-97DA-547A48DB266F} ©
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94} ©
O42 - Logiciel: EPSON Scan Assistant - (...) [HKLM] -- {2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}
O42 - Logiciel: EPSON File Manager - (...) [HKLM] -- {2EB81825-E9EE-44F4-8F51-1240C3898DC6}
O42 - Logiciel: Samsung Magic Doctor - (.Samsung Electronics Co., LTD.) [HKLM] -- {32D6A58F-9659-446C-BBFC-E6F2B41F24DC} ©
O42 - Logiciel: Fichiers de prise en charge de l'installation de Microsoft SQL Server (Fran - (.Microsoft Corporation.) [HKLM] -- {3380F354-C5F7-4E71-8F51-EEE6C3F06C62} ©
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} ©
O42 - Logiciel: EPSON Copy Utility 3 - (...) [HKLM] -- {67EDD823-135A-4D59-87BD-950616D6E857}
O42 - Logiciel: PCTroubleshooting - (.Samsung Electronics Co.,LTD..) [HKLM] -- {68CAE442-579C-4D84-AA5F-253852522ED5} ©
O42 - Logiciel: Gestionnaire de contacts professionnels pour Outlook 2007 SP2 - (.Microsoft Corporation.) [HKLM] -- {69ca8988-1c6c-4285-b8af-db780a6e42af} ©
O42 - Logiciel: REALTEK Wireless LAN Software - (.REALTEK Semiconductor Corp..) [HKLM] -- {6A1F72DD-2465-43A2-A137-8A849399B7A8} ©
O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {6E3939AE-9996-4D07-9A30-14C78AE93576} ©
O42 - Logiciel: Easy Battery Manager - (.Samsung.) [HKLM] -- {6F730513-8688-4C3C-90A3-6B9792CE2EF3} ©
O42 - Logiciel: Namuga 1.3M Webcam - (.Vimicro Corporation.) [HKLM] -- {71A51B59-E7D3-11DB-A386-005056C00008} ©
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} ©
O42 - Logiciel: Microsoft Sync Framework Runtime Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {8A74E887-8F0F-4017-AF53-CBA42211AAA5} ©
O42 - Logiciel: Camera RAW Plug-In for EPSON Creativity Suite - (...) [HKLM] -- {8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}
O42 - Logiciel: imagine digital freedom - Samsung - (.Samsung Electronics Co. Ltd.,.) [HKLM] -- {8E106A57-A17E-431D-B48F-175E42EB9F74}
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {8E5233E1-7495-44FB-8DEB-4BE906D59619} ©
O42 - Logiciel: Intel® Matrix Storage Manager - (.Intel Corporation.) [HKLM] -- {9068B2BE-D93A-4C0A-861C-5E35E2C0E09E} ©
O42 - Logiciel: Samsung Update Plus - (.Samsung Electronics Co., LTD.) [HKLM] -- {A5F483F0-2D79-4FCA-AE09-D0D96E23EBF7} ©
O42 - Logiciel: Easy Network Manager - (.Samsung.) [HKLM] -- {A7581D39-EA20-4883-A480-80C21047052B} ©
O42 - Logiciel: Software Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} ©
O42 - Logiciel: BatteryLifeExtender - (.Samsung.) [HKLM] -- {AA16A9E5-40E9-44F5-801E-6B3D3CFE79E5} ©
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-0804-1033-1959-001824147215} ©
O42 - Logiciel: Adobe Reader XI (11.0.10) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AB0000000001} ©
O42 - Logiciel: Spybot - Search & Destroy - (.Safer-Networking Ltd..) [HKLM] -- {B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1 ©
O42 - Logiciel: EPSON Easy Photo Print - (...) [HKLM] -- {B66E665A-DF96-4C38-9422-C7F74BC1B4E5}
O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM] -- {B6D8DC8C-F077-4631-A221-4D5E1D8E87E7} ©
O42 - Logiciel: User Guide - (...) [HKLM] -- {BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}
O42 - Logiciel: Microsoft Sync Framework Services Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {BD64AF4A-8C80-4152-AD77-FCDDF05208AB} ©
O42 - Logiciel: Easy SpeedUp Manager - (...) [HKLM] -- {EF367AA4-070B-493C-9575-85BE59D789C9}
O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570} ©
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} ©
O42 - Logiciel: PhotoFiltre Studio X - (...) [HKCU] -- PhotoFiltre Studio X

---\\ HKCU & HKLM Software Keys (83) - 8s
HKLM\SOFTWARE\Adobe
HKLM\SOFTWARE\AdwCleaner
HKLM\SOFTWARE\Agere
HKLM\SOFTWARE\AMD
HKLM\SOFTWARE\America Online
HKLM\SOFTWARE\AppDataLow
HKLM\SOFTWARE\ASKInstaller =>Toolbar.Ask
HKLM\SOFTWARE\ATI
HKLM\SOFTWARE\ATI Technologies
HKLM\SOFTWARE\Caphyon
HKLM\SOFTWARE\CyberLink
HKLM\SOFTWARE\EAST Technologies
HKLM\SOFTWARE\EAST_Technologies
HKLM\SOFTWARE\EPSON
HKLM\SOFTWARE\Google
HKLM\SOFTWARE\InstalledOptions
HKLM\SOFTWARE\InstallShield
HKLM\SOFTWARE\Intel
HKLM\SOFTWARE\Licenses
HKLM\SOFTWARE\Macromedia
HKLM\SOFTWARE\Malwarebytes' Anti-Malware
HKLM\SOFTWARE\Marvell
HKLM\SOFTWARE\Mozilla
HKLM\SOFTWARE\mozilla.org
HKLM\SOFTWARE\MozillaPlugins
HKLM\SOFTWARE\Myriad Software
HKLM\SOFTWARE\ODBC
HKLM\SOFTWARE\Piriform
HKLM\SOFTWARE\Realtek
HKLM\SOFTWARE\Realtek Semiconductor Corp.
HKLM\SOFTWARE\RegisteredApplications
HKLM\SOFTWARE\RtWLan
HKLM\SOFTWARE\Safer Networking Limited
HKLM\SOFTWARE\SAMSUNG
HKLM\SOFTWARE\Samsung Electronics Co., Ltd.
HKLM\SOFTWARE\Software
HKLM\SOFTWARE\Softwin
HKLM\SOFTWARE\Sonic
HKLM\SOFTWARE\SRS Labs
HKLM\SOFTWARE\Synaptics
HKLM\SOFTWARE\Vimicro Corporation
HKLM\SOFTWARE\Volatile
HKLM\SOFTWARE\Waves Audio
HKLM\SOFTWARE\WinRAR
HKLM\SOFTWARE\WOW6432Node
HKCU\SOFTWARE\7UPO42vccKQNXWB
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\AOL
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\ATI
HKCU\SOFTWARE\ATI Technologies Inc.
HKCU\SOFTWARE\Chromium
HKCU\SOFTWARE\ComNotificationsV06.03
HKCU\SOFTWARE\CyberLink
HKCU\SOFTWARE\DdZl24IYPbTK
HKCU\SOFTWARE\EAST Technologies
HKCU\SOFTWARE\EPSON
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\JVUEG
HKCU\SOFTWARE\Kromtech
HKCU\SOFTWARE\Local AppWizard-Generated Applications
HKCU\SOFTWARE\LowRegistry
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\ODBC
HKCU\SOFTWARE\PhotoFiltre Studio X
HKCU\SOFTWARE\Piriform
HKCU\SOFTWARE\Realtek
HKCU\SOFTWARE\Safer Networking Limited
HKCU\SOFTWARE\Samsung
HKCU\SOFTWARE\SEIKO EPSON
HKCU\SOFTWARE\Software
HKCU\SOFTWARE\Synaptics
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\yvW4UYKGBoaFKv
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\MB_temp
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\Google

---\\ Contenu des dossiers Programmes (155) - 7s
O43 - CFD: 2015/06/10 10:52:08 - [0] D -- C:\Program Files\9fdf270e-3374-4ae3-b6f3-c6c9951158e7 =>PUP.Optional.CrossRider
O43 - CFD: 2015/03/17 16:43:22 - [] D -- C:\Program Files\Adobe
O43 - CFD: 2009/06/10 13:20:48 - [] D -- C:\Program Files\Atheros WLAN Client
O43 - CFD: 2009/06/10 13:14:50 - [] D -- C:\Program Files\ATI
O43 - CFD: 2009/06/10 13:17:00 - [] D -- C:\Program Files\ATI Technologies
O43 - CFD: 2015/03/17 05:05:19 - [] D -- C:\Program Files\CCleaner
O43 - CFD: 2015/03/19 05:34:04 - [] D -- C:\Program Files\Common Files
O43 - CFD: 2015/06/08 17:57:18 - [] D -- C:\Program Files\ControlThis Parental Control
O43 - CFD: 2010/05/22 11:03:17 - [] D -- C:\Program Files\CyberLink
O43 - CFD: 2015/03/17 17:50:58 - [] D -- C:\Program Files\East-Tec Eraser 2010
O43 - CFD: 2015/03/17 19:58:05 - [] D -- C:\Program Files\epson
O43 - CFD: 2010/05/22 10:58:25 - [0] SHD -- C:\Program Files\Fichiers communs
O43 - CFD: 2015/09/22 10:20:48 - [] D -- C:\Program Files\Google
O43 - CFD: 2015/03/17 20:08:30 - [] HD -- C:\Program Files\InstallShield Installation Information
O43 - CFD: 2009/06/10 13:21:13 - [] D -- C:\Program Files\Intel
O43 - CFD: 2015/09/10 08:22:53 - [] D -- C:\Program Files\Internet Explorer
O43 - CFD: 2015/09/22 09:48:08 - [] D -- C:\Program Files\Malwarebytes Anti-Malware
O43 - CFD: 2009/06/10 13:20:03 - [] D -- C:\Program Files\Marvell
O43 - CFD: 2015/06/08 17:55:20 - [] D -- C:\Program Files\Microsoft
O43 - CFD: 2006/11/02 14:37:34 - [] D -- C:\Program Files\Microsoft Games
O43 - CFD: 2015/06/10 13:16:42 - [] D -- C:\Program Files\Microsoft Office
O43 - CFD: 2015/03/17 16:35:09 - [] D -- C:\Program Files\Microsoft Office Outlook Connector
O43 - CFD: 2015/05/14 19:34:25 - [] D -- C:\Program Files\Microsoft Security Client
O43 - CFD: 2015/08/13 09:33:21 - [] D -- C:\Program Files\Microsoft Silverlight
O43 - CFD: 2015/03/17 08:09:49 - [] D -- C:\Program Files\Microsoft Small Business
O43 - CFD: 2015/03/17 16:19:29 - [] D -- C:\Program Files\Microsoft SQL Server
O43 - CFD: 2015/03/17 16:33:36 - [] D -- C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 2015/03/17 16:34:35 - [] D -- C:\Program Files\Microsoft Sync Framework
O43 - CFD: 2009/06/10 14:42:19 - [] D -- C:\Program Files\Microsoft Visual Studio
O43 - CFD: 2015/03/17 08:27:00 - [] D -- C:\Program Files\Microsoft Visual Studio 8
O43 - CFD: 2015/03/17 16:07:23 - [] D -- C:\Program Files\Microsoft Works
O43 - CFD: 2015/03/17 14:55:46 - [] D -- C:\Program Files\Microsoft.NET
O43 - CFD: 2015/03/17 17:32:30 - [] D -- C:\Program Files\Movie Maker
O43 - CFD: 2015/09/13 09:03:17 - [] D -- C:\Program Files\Mozilla Firefox
O43 - CFD: 2015/08/11 12:40:57 - [] D -- C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 2015/03/17 08:30:33 - [] D -- C:\Program Files\MSBuild
O43 - CFD: 2015/03/17 08:26:28 - [] D -- C:\Program Files\PhotoFiltre Studio X
O43 - CFD: 2009/06/10 13:17:15 - [] D -- C:\Program Files\Realtek
O43 - CFD: 2009/06/10 13:22:12 - [] D -- C:\Program Files\REALTEK Wireless LAN Software
O43 - CFD: 2006/11/02 14:37:34 - [] D -- C:\Program Files\Reference Assemblies
O43 - CFD: 2009/06/10 14:49:38 - [] D -- C:\Program Files\Samsung
O43 - CFD: 2015/06/09 10:27:42 - [] D -- C:\Program Files\Software =>PUP.Optional.Boxore
O43 - CFD: 2015/06/09 12:24:47 - [] D -- C:\Program Files\Spybot - Search & Destroy 2
O43 - CFD: 2009/06/10 13:22:41 - [] D -- C:\Program Files\Synaptics
O43 - CFD: 2009/06/10 13:17:50 - [0] HD -- C:\Program Files\Temp
O43 - CFD: 2006/11/02 15:01:55 - [0] HD -- C:\Program Files\Uninstall Information
O43 - CFD: 2009/06/10 13:23:01 - [] D -- C:\Program Files\Vimicro Corporation
O43 - CFD: 2015/03/17 17:32:30 - [] D -- C:\Program Files\Windows Calendar
O43 - CFD: 2015/03/17 17:32:30 - [] D -- C:\Program Files\Windows Collaboration
O43 - CFD: 2015/03/17 17:32:29 - [] D -- C:\Program Files\Windows Defender
O43 - CFD: 2015/09/10 08:22:53 - [] D -- C:\Program Files\Windows Journal
O43 - CFD: 2015/03/19 07:30:56 - [] D -- C:\Program Files\Windows Live
O43 - CFD: 2015/03/17 16:32:12 - [] D -- C:\Program Files\Windows Live SkyDrive
O43 - CFD: 2015/03/19 07:19:51 - [] D -- C:\Program Files\Windows Mail
O43 - CFD: 2015/06/10 13:17:54 - [] D -- C:\Program Files\Windows Media Player
O43 - CFD: 2010/05/22 10:58:25 - [] D -- C:\Program Files\Windows NT
O43 - CFD: 2015/03/17 17:32:30 - [] D -- C:\Program Files\Windows Photo Gallery
O43 - CFD: 2015/03/19 07:20:03 - [] D -- C:\Program Files\Windows Portable Devices
O43 - CFD: 2015/03/17 17:32:30 - [] D -- C:\Program Files\Windows Sidebar
O43 - CFD: 2015/03/17 05:04:20 - [] D -- C:\Program Files\WinRAR
O43 - CFD: 2015/03/19 07:19:47 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2015/03/17 09:50:20 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2009/06/10 13:17:03 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
O43 - CFD: 2015/03/17 05:05:19 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
O43 - CFD: 2015/03/17 17:50:50 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\East-Tec Eraser 2010
O43 - CFD: 2015/03/17 19:54:16 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
O43 - CFD: 2015/03/17 20:06:53 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Creativity Suite
O43 - CFD: 2015/03/17 19:49:57 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Scan
O43 - CFD: 2008/01/21 04:42:47 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Extras and Upgrades
O43 - CFD: 2008/01/21 04:42:49 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 2015/06/09 10:32:50 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 2006/11/02 14:56:46 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/09/22 09:48:08 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
O43 - CFD: 2015/03/17 08:31:33 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O43 - CFD: 2015/03/17 16:35:19 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
O43 - CFD: 2015/08/13 09:15:11 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
O43 - CFD: 2009/06/10 14:47:00 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2005
O43 - CFD: 2015/03/17 08:26:29 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre Studio X
O43 - CFD: 2009/06/10 14:49:53 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
O43 - CFD: 2015/06/09 12:20:16 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
O43 - CFD: 2006/11/02 14:50:50 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2006/11/02 14:37:34 - [] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 2015/03/17 16:34:58 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
O43 - CFD: 2015/03/17 05:04:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 2015/06/09 10:39:23 - [] D -- C:\ProgramData\28341ff220e0446c9fff27c4493d622e
O43 - CFD: 2015/06/08 17:56:04 - [] D -- C:\ProgramData\7c0535b143fc4671b6ebd202fbffe066
O43 - CFD: 2015/03/17 17:39:17 - [] D -- C:\ProgramData\Adobe
O43 - CFD: 2006/11/02 15:02:03 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 2009/06/10 14:50:35 - [] D -- C:\ProgramData\ATI
O43 - CFD: 2010/05/22 10:58:25 - [0] SHD -- C:\ProgramData\Bureau
O43 - CFD: 2006/11/02 15:02:03 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 2006/11/02 15:02:03 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 2015/03/23 10:58:09 - [] D -- C:\ProgramData\EPSON
O43 - CFD: 2010/05/22 10:58:25 - [0] SHD -- C:\ProgramData\Favoris
O43 - CFD: 2006/11/02 15:02:03 - [0] SHD -- C:\ProgramData\Favorites
O43 - CFD: 2015/09/22 10:20:48 - [] D -- C:\ProgramData\Google
O43 - CFD: 2015/06/10 10:27:35 - [] D -- C:\ProgramData\Malwarebytes
O43 - CFD: 2010/05/22 10:58:25 - [0] SHD -- C:\ProgramData\Menu Démarrer
O43 - CFD: 2015/06/09 12:20:15 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 2015/09/10 08:06:37 - [] D -- C:\ProgramData\Microsoft Help
O43 - CFD: 2010/05/22 10:58:25 - [0] SHD -- C:\ProgramData\Modèles
O43 - CFD: 2015/03/17 09:26:46 - [] D -- C:\ProgramData\Mozilla
O43 - CFD: 2009/06/10 14:37:54 - [] D -- C:\ProgramData\SAMSUNG
O43 - CFD: 2015/06/09 12:26:55 - [] D -- C:\ProgramData\Spybot - Search & Destroy
O43 - CFD: 2006/11/02 15:02:03 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 2015/09/18 17:37:03 - [] AD -- C:\ProgramData\Temp
O43 - CFD: 2006/11/02 15:02:04 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 2015/03/17 19:59:59 - [] D -- C:\ProgramData\UDL
O43 - CFD: 2015/06/09 10:38:37 - [] HD -- C:\ProgramData\upv
O43 - CFD: 2015/03/17 14:57:55 - [] D -- C:\ProgramData\WinClon
O43 - CFD: 2015/03/17 08:41:53 - [] D -- C:\ProgramData\WindowsSearch
O43 - CFD: 2015/03/17 16:43:44 - [] D -- C:\Program Files\Common Files\Adobe
O43 - CFD: 2015/03/17 14:53:53 - [] D -- C:\Program Files\Common Files\BitDefender
O43 - CFD: 2015/03/19 05:34:04 - [] D -- C:\Program Files\Common Files\DESIGNER
O43 - CFD: 2015/03/17 20:02:58 - [] D -- C:\Program Files\Common Files\InstallShield
O43 - CFD: 2015/03/17 16:32:16 - [] D -- C:\Program Files\Common Files\microsoft shared
O43 - CFD: 2006/11/02 13:18:33 - [] D -- C:\Program Files\Common Files\Services
O43 - CFD: 2006/11/02 13:18:33 - [] D -- C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 2015/03/19 07:19:49 - [] D -- C:\Program Files\Common Files\System
O43 - CFD: 2015/03/17 16:23:11 - [] D -- C:\Program Files\Common Files\Windows Live
O43 - CFD: 2015/04/16 10:25:07 - [] D -- C:\Users\rose\AppData\Roaming\ACAMPREF
O43 - CFD: 2015/03/17 18:12:01 - [] D -- C:\Users\rose\AppData\Roaming\Adobe
O43 - CFD: 2010/05/22 11:05:34 - [] D -- C:\Users\rose\AppData\Roaming\ATI
O43 - CFD: 2015/03/17 17:54:07 - [] D -- C:\Users\rose\AppData\Roaming\EAST Technologies
O43 - CFD: 2015/09/04 14:55:52 - [] D -- C:\Users\rose\AppData\Roaming\EPSON
O43 - CFD: 2015/03/17 09:00:22 - [] D -- C:\Users\rose\AppData\Roaming\Google
O43 - CFD: 2015/03/17 08:26:32 - [] D -- C:\Users\rose\AppData\Roaming\Identities
O43 - CFD: 2015/03/17 19:54:24 - [] D -- C:\Users\rose\AppData\Roaming\InstallShield
O43 - CFD: 2015/03/17 08:08:25 - [] D -- C:\Users\rose\AppData\Roaming\Macromedia
O43 - CFD: 2006/11/02 14:37:34 - [0] D -- C:\Users\rose\AppData\Roaming\Media Center Programs
O43 - CFD: 2015/06/10 09:35:59 - [] SD -- C:\Users\rose\AppData\Roaming\Microsoft
O43 - CFD: 2015/03/17 09:27:09 - [] D -- C:\Users\rose\AppData\Roaming\Mozilla
O43 - CFD: 2015/03/17 08:27:53 - [] D -- C:\Users\rose\AppData\Roaming\PhotoFiltre Studio X
O43 - CFD: 2015/09/22 10:48:33 - [] D -- C:\Users\rose\AppData\Roaming\ZHP
O43 - CFD: 2015/03/17 17:48:48 - [] D -- C:\Users\rose\AppData\Local\Adobe
O43 - CFD: 2010/05/22 11:02:15 - [0] SHD -- C:\Users\rose\AppData\Local\Application Data
O43 - CFD: 2010/05/22 11:05:34 - [] D -- C:\Users\rose\AppData\Local\ATI
O43 - CFD: 2015/09/22 10:20:48 - [] D -- C:\Users\rose\AppData\Local\Google
O43 - CFD: 2010/05/22 11:02:15 - [0] SHD -- C:\Users\rose\AppData\Local\Historique
O43 - CFD: 2015/08/11 09:56:07 - [] D -- C:\Users\rose\AppData\Local\Macromedia
O43 - CFD: 2015/09/18 17:56:43 - [] D -- C:\Users\rose\AppData\Local\Microsoft
O43 - CFD: 2015/09/06 11:18:18 - [] D -- C:\Users\rose\AppData\Local\Microsoft Games
O43 - CFD: 2015/03/17 08:27:03 - [0] D -- C:\Users\rose\AppData\Local\Microsoft Help
O43 - CFD: 2015/03/17 09:26:58 - [] D -- C:\Users\rose\AppData\Local\Mozilla
O43 - CFD: 2015/09/22 10:48:40 - [] D -- C:\Users\rose\AppData\Local\Temp
O43 - CFD: 2010/05/22 11:02:15 - [0] SHD -- C:\Users\rose\AppData\Local\Temporary Internet Files
O43 - CFD: 2015/08/26 10:43:33 - [] D -- C:\Users\rose\AppData\Local\VirtualStore
O43 - CFD: 2015/06/10 11:58:57 - [] D -- C:\Users\rose\AppData\Local\Windows Live
O43 - CFD: 2008/01/21 04:42:46 - [] RD -- C:\Users\rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2010/05/22 11:04:20 - [] RD -- C:\Users\rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2010/05/22 11:03:19 - [] D -- C:\Users\rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam
O43 - CFD: 2008/01/21 04:42:46 - [] RD -- C:\Users\rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/03/17 08:26:28 - [0] D -- C:\Users\rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoFiltre Studio X
O43 - CFD: 2015/06/10 11:50:21 - [] RD -- C:\Users\rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2015/03/17 05:04:21 - [] D -- C:\Users\rose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR

---\\ ShellIconOverlayIdentifiers (SOI) (1) - 0s
O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Extension d'environnement du périphérique d.) -- C:\Windows\System32\EhStorShell.dll ©

---\\ Enumération des clés StartupReg (12) - 2s
O53 - SMSR:HKLM\...\startupreg\EPSON Stylus DX4400 Series [Key] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\w32x86\3\E_FATICAE.EXE ©
O53 - SMSR:HKLM\...\startupreg\MSC [Key] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- C:\Program Files\Microsoft Security Client\msseces.exe ©
O53 - SMSR:HKLM\...\startupreg\RtHDVCpl [Key] . (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe ©
O53 - SMSR:HKLM\...\startupreg\SDTray [Key] . (.Safer-Networking Ltd. - Spybot - Search & Destroy tray access.) -- C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe ©
O53 - SMSR:HKLM\...\startupreg\Skytel [Key] . (.Realtek Semiconductor Corp. - Realtek Voice Manager.) -- C:\Program Files\Realtek\Audio\HDA\SkyTel.exe ©
O53 - SMSR:HKLM\...\startupreg\Spybot-S&D Cleaning [Key] . (.Safer-Networking Ltd. - Search results cleaner.) -- C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe ©
O53 - SMSR:HKLM\...\startupreg\StartCCC [Key] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ©
O53 - SMSR:HKLM\...\startupreg\swg [Key] . (...) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\SynTPEnh [Key] . (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ©
O53 - SMSR:HKLM\...\startupreg\UCam_Menu [Key] . (.CyberLink Corp. - MUI StartMenu Application.) -- C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe ©
O53 - SMSR:HKLM\...\startupreg\Windows Defender [Key] . (.Microsoft Corporation - Windows Defender User Interface.) -- C:\Program Files\Windows Defender\MSASCui.exe ©
O53 - SMSR:HKLM\...\startupreg\WMPNSCFG [Key] . (.Microsoft Corporation - Application de configuration du service Par.) -- C:\Program Files\Windows Media Player\wmpnscfg.exe ©

---\\ Liste des pilotes du système (77) - 8s
O58 - SDL:2008/01/21 04:23:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [422968] ©
O58 - SDL:2008/01/21 04:23:25 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [300600] ©
O58 - SDL:2008/01/21 04:23:26 A . (.Adaptec, Inc. - Adaptec LH Ultra160 Driver (x86).) -- C:\Windows\System32\drivers\adpu160m.sys [101432] ©
O58 - SDL:2008/01/21 04:23:27 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\drivers\adpu320.sys [149560] ©
O58 - SDL:2008/03/21 05:13:00 A . (.Agere Systems - SoftModem Device Driver.) -- C:\Windows\System32\drivers\AGRSM.sys [1203776] ©
O58 - SDL:2008/01/21 04:23:00 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [17464] ©
O58 - SDL:2008/01/21 04:23:23 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [79416] ©
O58 - SDL:2008/01/21 04:23:24 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [79928] ©
O58 - SDL:2009/12/17 17:02:20 A . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driv.) -- C:\Windows\System32\drivers\athr.sys [1203712] ©
O58 - SDL:2009/03/12 18:25:28 A . (.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\drivers\atikmdag.sys [4386304] ©
O58 - SDL:2006/11/02 09:30:53 A . (.Broadcom Corporation - Pilote Ethernet 5.1 NDIS Broadcom Corporati.) -- C:\Windows\System32\drivers\bcm4sbxp.sys [45056] ©
O58 - SDL:2006/11/02 10:24:45 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [13568] ©
O58 - SDL:2006/11/02 10:24:46 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [5248] ©
O58 - SDL:2006/11/02 10:25:24 A . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [71808] ©
O58 - SDL:2006/11/02 10:24:44 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [62336] ©
O58 - SDL:2006/11/02 10:24:44 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [12160] ©
O58 - SDL:2006/11/02 10:24:47 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [11904] ©
O58 - SDL:2008/01/21 04:23:00 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [19000] ©
O58 - SDL:2006/11/02 11:50:11 A . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\drivers\djsvs.sys [71272] ©
O58 - SDL:2008/01/21 04:23:24 A . (.Intel Corporation - Pilote désérialisé NDIS 6 de la carte Intel.) -- C:\Windows\System32\drivers\E1G60I32.sys [118784] ©
O58 - SDL:2008/01/21 04:23:22 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [342584] ©
O58 - SDL:2008/01/21 04:23:26 A . (.Hewlett-Packard Company - Smart Array Storport Driver.) -- C:\Windows\System32\drivers\HpCISSs.sys [40504] ©
O58 - SDL:2009/02/11 10:11:50 A . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\drivers\iaStor.sys [329752] ©
O58 - SDL:2008/01/21 04:23:23 A . (.Intel Corporation - Intel Matrix Storage Manager driver (base).) -- C:\Windows\System32\drivers\iaStorV.sys [235064] ©
O58 - SDL:2006/10/19 04:10:57 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd32.sys [1380864] ©
O58 - SDL:2006/11/02 11:50:17 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [41576] ©
O58 - SDL:2006/11/02 11:50:07 A . (.Integrated Technology Express, Inc. - ITE IT8211 ATA/ATAPI SCSI miniport.) -- C:\Windows\System32\drivers\iteatapi.sys [35944] ©
O58 - SDL:2006/11/02 11:50:09 A . (.Integrated Technology Express, Inc. - ITE IT8212 ATA RAID SCSI miniport.) -- C:\Windows\System32\drivers\iteraid.sys [35944] ©
O58 - SDL:2008/08/12 04:03:20 A . (.SAMSUNG ELECTRONICS CO., LTD. - Non PnP Driver.) -- C:\Windows\System32\drivers\KMDFMEMIO.sys [13312] ©
O58 - SDL:2008/10/09 16:42:42 A . (.Windows (R) Codename Longhorn DDK provider - KMWDFilter Driver from UASSOFT.COM.) -- C:\Windows\System32\drivers\KMWDFILTER.sys [17408] ©
O58 - SDL:2008/01/21 04:23:23 A . (.LSI Logic - LSI Logic Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [96312] ©
O58 - SDL:2008/01/21 04:23:25 A . (.LSI Logic - LSI Logic Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [89656] ©
O58 - SDL:2008/01/21 04:23:23 A . (.LSI Logic - LSI Logic Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [96312] ©
O58 - SDL:2015/06/18 08:41:36 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\mbam.sys [23256] ©
O58 - SDL:2015/06/18 08:41:42 A . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\drivers\mbamchameleon.sys [94936] ©
O58 - SDL:2015/09/22 09:55:37 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys [98520] ©
O58 - SDL:2008/01/21 04:23:27 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [31288] ©
O58 - SDL:2008/01/21 04:23:27 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [386616] ©
O58 - SDL:2006/11/02 11:49:59 A . (.LSI Logic Corporation - MegaRAID RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\Mraid35x.sys [33384] ©
O58 - SDL:2015/06/18 08:41:50 A . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\drivers\mwac.sys [51928] ©
O58 - SDL:2008/01/21 04:23:20 A . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\Windows\System32\drivers\NETw3v32.sys [2225664] ©
O58 - SDL:2006/11/02 11:50:19 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [45160] ©
O58 - SDL:2006/11/02 09:36:50 A . (.N-trig Innovative Technologies - Pilote intégré de digitalisateur de tablett.) -- C:\Windows\System32\drivers\ntrigdigi.sys [20608] ©
O58 - SDL:2008/01/21 04:23:21 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [102968] ©
O58 - SDL:2008/01/21 04:23:21 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [45112] ©
O58 - SDL:2008/01/21 04:23:24 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1122360] ©
O58 - SDL:2006/11/02 11:50:35 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [106088] ©
O58 - SDL:2009/02/13 09:49:56 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHDA.sys [2325728] ©
O58 - SDL:2009/05/23 04:33:32 A . (.Realtek Semiconductor Corporation - Realtek RTL819xP NDIS Driverr.) -- C:\Windows\System32\drivers\rtl819xp.sys [505344] ©
O58 - SDL:2006/11/02 08:37:21 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [20480] ©
O58 - SDL:2008/01/21 04:23:26 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [74808] ©
O58 - SDL:2006/11/02 11:50:05 A . (.LSI Logic - LSI Logic 8XX SCSI Miniport Driver.) -- C:\Windows\System32\drivers\symc8xx.sys [35944] ©
O58 - SDL:2006/11/02 11:49:56 A . (.LSI Logic - LSI Logic Hi-Perf SCSI Miniport Driver.) -- C:\Windows\System32\drivers\sym_hi.sys [31848] ©
O58 - SDL:2006/11/02 11:50:03 A . (.LSI Logic - LSI Logic Ultra160 SCSI Miniport Driver.) -- C:\Windows\System32\drivers\sym_u3.sys [34920] ©
O58 - SDL:2008/08/28 04:52:52 A . (.Synaptics, Inc. - Synaptics Touchpad Driver.) -- C:\Windows\System32\drivers\SynTP.sys [199344] ©
O58 - SDL:2008/01/21 04:23:20 A . (.ULi Electronics Inc. - ULi SATA Controller Driver.) -- C:\Windows\System32\drivers\uliahci.sys [238648] ©
O58 - SDL:2006/11/02 11:50:35 A . (.Promise Technology, Inc. - Promise Ultra/Sata Series Driver for Win200.) -- C:\Windows\System32\drivers\ulsata.sys [98408] ©
O58 - SDL:2008/01/21 04:23:23 A . (.Promise Technology, Inc. - Promise SATAII150 Series Windows Drivers.) -- C:\Windows\System32\drivers\ulsata2.sys [115816] ©
O58 - SDL:2008/01/21 04:23:00 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [20024] ©
O58 - SDL:2008/11/21 03:22:24 A . (.Vimicro Corporation - Vimicro USB Video Class Camera.) -- C:\Windows\System32\drivers\VMC326.sys [238464] ©
O58 - SDL:2008/01/21 04:23:23 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [130616] ©
O58 - SDL:2009/01/30 11:07:00 A . (.Marvell - Miniport Driver for Marvell Yukon Ethernet.) -- C:\Windows\System32\drivers\yk60x86.sys [311296] ©
O58 - SDL:2006/11/02 09:09:42 A . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:2006/11/02 09:09:45 A . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:2006/11/02 09:09:41 A . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:2006/11/02 09:09:44 A . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:2006/11/02 09:09:44 A . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:2006/11/02 09:09:29 A . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:2006/11/02 09:09:35 A . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:2006/11/02 09:09:38 A . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:2006/11/02 09:09:40 A . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:2006/11/02 09:09:31 A . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:2006/11/02 09:09:20 A . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:2006/11/02 09:09:23 A . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:2006/11/02 09:09:24 A . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:2006/11/02 09:09:26 A . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:2006/11/02 09:09:22 A . (...) -- C:\Windows\System32\NTIO804.SYS [34672]

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (2) - 2s
O61 - LFC: 2015/09/22 10:13:28 A . (..) -- C:\Users\rose\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [674082]
O61 - LFC: 2015/09/22 10:44:41 A . (..) -- C:\Users\rose\AppData\Local\Google\Chrome\User Data\nacl_validation_cache.bin [164]

---\\ Associations Shell Spawning (10) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe ©
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe ©
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ©
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\Windows\System32\wscript.exe ©
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe ©
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S

---\\ Menu de démarrage Internet (12) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- iexplore.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©

---\\ Recherche d'infection sur les navigateurs (4) - 4s
O69 - SBI: prefs.js [rose - j41o90gl.default] user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [rose - j41o90gl.default] user_pref("browser.search.searchengine.ptid", "cmi"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [rose - j41o90gl.default] user_pref("browser.search.searchengine.uid", "ST9500325AS_5VE40WF2XXXX5VE40WF2"); =>PUP.Optional.SearchEngine
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/

---\\ Enumère les services démarrés par Svchost (31) - 0s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [24576] ©
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [62976] ©
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [247808] ©
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [40448] ©
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [40448] ©
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [125952] ©
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [576512] ©
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [444928] ©
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\audiosrv.dll [316928] ©
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [90624] ©
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [262144] ©
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [68608] ©
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [47104] ©
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à.) -- C:\Windows\System32\ipnathlp.dll [288256] ©
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [242688] ©
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes Termi.) -- C:\Windows\System32\termsrv.dll [449536] ©
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [1933848] ©
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [758784] ©
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [247808] ©
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [200704] ©
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [19968] ©
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [33280] ©
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [111616] ©
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\System32\mmcss.dll [45056] ©
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [153600] ©
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [57344] ©
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [162304] ©
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [602112] ©
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service de configuration des services Termi.) -- C:\Windows\System32\SessEnv.dll [84992] ©
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [81920] ©
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\KMSVC.DLL [68096] ©

---\\ Liste des exceptions du parefeu Windows (1) - 1s
O87 - FAEL: "{1FCBF794-4233-4301-A509-95479C6DC578}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe (.not file.)

---\\ Enumère les codes produits des logiciels (2) - 2s
O90 - PUC: "E41FC473BA71A3644ADA1331D8D48F7E" . (.PC Privacy Dock.) -- C:\Windows\Installer\{374CF14E-17AB-463A-A4AD-31138D4DF8E7}\icon.exe =>PUP.Optional.PCPrivacyDock
O90 - PUC: "E8E877ED6825FF148AE54DA13648DD38" . (.Boxore Client.) -- C:\Windows\Installer\{DE778E8E-5286-41FF-A85E-D41A6384DD83}\Boxore.ico =>PUP.Optional.Boxore

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (13) - 21s

SR - Auto [2015/07/07 20:12:28] [ 82128] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe ©
SS - Demand [2015/09/22 07:55:30] [ 269000] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe ©
SR - Auto [2008/03/18 05:27:12] [ 13312] Agere Modem Call Progress Audio (AgereModemAudio) . (.Agere Systems.) - C:\Windows\System32\agrsmsvc.exe ©
SR - Auto [2009/03/12 16:23:14] [ 733184] (Ati External Event Utility) . (.ATI Technologies Inc..) - C:\Windows\System32\Ati2evxx.exe ©
SS - Auto [2015/03/17 08:16:20] [ 107848] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe ©
SS - Demand [2015/03/17 08:16:20] [ 107848] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe ©
SS - Auto [2015/06/18 08:39:50] [ 1133880] (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe ©
SS - Demand [2015/03/05 15:06:22] [ 148080] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe ©
SR - Auto [2009/03/05 11:54:50] [ 311296] Rezip (Rezip) . (.Copyright (C) 2009.) - C:\Windows\System32\Rezip.exe
SR - Auto [2014/06/24 10:41:42] [ 1738168] Spybot-S&D 2 Scanner Service (SDScannerService) . (.Safer-Networking Ltd..) - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe ©
SR - Auto [2014/06/27 11:52:26] [ 2088408] Spybot-S&D 2 Updating Service (SDUpdateService) . (.Safer-Networking Ltd..) - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe ©
SR - Auto [2014/04/25 14:12:20] [ 171928] Spybot-S&D 2 Security Center Service (SDWSCService) . (.Safer-Networking Ltd..) - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe ©

---\\ Scan Additionnel (12) - 0s
C:\Windows\Tasks\DBJXMQ1.job =>PUP.Optional.FlashBeat
C:\Windows\System32\Tasks\DBJXMQ1 =>PUP.Optional.FlashBeat
C:\Windows\System32\Tasks\Wluklinu =>Heuristic.PullUpdate
HKLM\SOFTWARE\ASKInstaller =>Toolbar.Ask
C:\Program Files\9fdf270e-3374-4ae3-b6f3-c6c9951158e7 =>PUP.Optional.CrossRider
C:\Program Files\Software =>PUP.Optional.Boxore
C:\Windows\Installer\{374CF14E-17AB-463A-A4AD-31138D4DF8E7}\icon.exe =>PUP.Optional.PCPrivacyDock
HKLM\Software\Classes\Installer\Products\E41FC473BA71A3644ADA1331D8D48F7E =>PUP.Optional.PCPrivacyDock
HKLM\Software\Classes\Installer\Features\E41FC473BA71A3644ADA1331D8D48F7E =>PUP.Optional.PCPrivacyDock
C:\Windows\Installer\{DE778E8E-5286-41FF-A85E-D41A6384DD83}\Boxore.ico =>PUP.Optional.Boxore
HKLM\Software\Classes\Installer\Products\E8E877ED6825FF148AE54DA13648DD38 =>PUP.Optional.Boxore
HKLM\Software\Classes\Installer\Features\E8E877ED6825FF148AE54DA13648DD38 =>PUP.Optional.Boxore

---\\ Récapitulatif des éléments trouvées sur votre station (8) - 0s
http://www.nicolascoolman.fr/blog =>PUP.Optional.Graftor
http://www.nicolascoolman.fr/blog =>PUP.Optional.FlashBeat
http://www.nicolascoolman.fr/blog =>Heuristic.PullUpdate
http://www.nicolascoolman.fr/toolbar-ask/ =>Toolbar.Ask
http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider
http://www.nicolascoolman.fr/adware-boxore/ =>PUP.Optional.Boxore
http://www.nicolascoolman.fr/blog =>PUP.Optional.SearchEngine
http://www.nicolascoolman.fr/blog =>PUP.Optional.PCPrivacyDock

~ End of the scan, 43705 items in 109 seconds (733)(0)()

Publicité


Signaler le contenu de ce document

Publicité