cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.8.23.124 Par Nicolas Coolman (2015/08/23)
~ Démarré par Antoine (Administrator) (2015/10/08 20:30:01)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Etat de la version: Pas de fichier réseau
~ Mode: Scanner
~ Rapport: C:\Users\chris_000\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\chris_000\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
Windows 10 Home, 64-bit (Build 10240)

---\\ Navigateurs Internet (2) - 0s
GCIE: Google Chrome v45.0.2454.101
MSIE: Internet Explorer v11.0.10240.16384

---\\ Informations sur les produits Windows (9) - 5s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
~ Windows(R) Operating System, RETAIL channel
Windows ID Activation : OK
~ Windows Partial Key : 8HVX7
Windows License : OK
~ Windows Remaining Initializations Number : 1001
Windows Automatic Updates : OK (Auto)
Windows Activation Technologies : OK

---\\ Logiciels de protection (2) - 0s
Avast Premier v10.4.2233
Windows Defender W10 (Activate)

---\\ Informations sur le système (6) - 0s
~ Operating System: Intel64 Family 6 Model 60 Stepping 3, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 8274.92 MB (43% free)
~ System Restore: Activé (Enable)
~ System drive C: has 53 GB free of 106 GB

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: ANTOINE
~ User Name: Antoine
~ Logged in as Administrator

---\\ Enumération des unités disques (4) - 1s
~ Drive C: has 53 GB free of 106 GB (System)
~ Drive D: has 411 GB free of 476 GB
~ Drive E: has 476 GB free of 476 GB
~ Drive G: has 14 GB free of 14 GB

---\\ Etat du Centre de Sécurité Windows (7) - 0s
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Recherche particulière de fichiers génériques (23) - 0s
[MD5.A7FFEC1BD46B20FE7E293F2D9DD1C8F5] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\WINDOWS\Explorer.exe [4528168]
[MD5.5DED2A3F11AE916C8F2724947E736261] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\WINDOWS\System32\rundll32.exe [59392]
[MD5.CAAA293DD133160DF13D95CC48FC42B9] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\WINDOWS\System32\Wininit.exe [290304]
[MD5.32A862495B7C356B9895FDD0B9023C5F] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\WINDOWS\System32\wininet.dll [2741248]
[MD5.536B686D86402D254C59B5DE3A575F45] - (.Microsoft Corporation - Application d’ouverture de session Windows.) () -- C:\WINDOWS\System32\Winlogon.exe [578048]
[MD5.8DE3F0DF5BCD3AC6360AB753BD1A63DE] - (.Microsoft Corporation - Bibliothèque de licences.) () -- C:\WINDOWS\System32\sppcomapi.dll [429056]
[MD5.8C795953726C7D2DE72CE4748208C5ED] - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) () -- C:\WINDOWS\System32\fr-FR\user32.dll.mui [20480]
[MD5.6C12C7E01A4F64E0AA9C88AF66955CC9] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) () -- C:\WINDOWS\System32\drivers\AFD.sys [577888]
[MD5.8921DF6060DB5C7700AA48CB12E9EA08] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\WINDOWS\System32\drivers\atapi.sys [28512]
[MD5.F2829DC6D292DCAC5029893BB2E9FEE3] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\WINDOWS\System32\drivers\Cdfs.sys [92672]
[MD5.CA160E02F35A61C6F5C681FB4669C519] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\WINDOWS\System32\drivers\Cdrom.sys [174080]
[MD5.25435407D97419627F4B10653433BF2B] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\WINDOWS\System32\drivers\DfsC.sys [138240]
[MD5.C277A49F8A8295840DEBC9240B75A282] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\WINDOWS\System32\drivers\HDAudBus.sys [80896]
[MD5.D4CDEE4A62BDFFF6E8558A9552148EA7] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\WINDOWS\System32\drivers\i8042prt.sys [114688]
[MD5.5D3744E6FDEC1A6FB3FA9B1DD4AF0694] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\WINDOWS\System32\drivers\IpNat.sys [143360]
[MD5.1DF2C5FD2710A13B07E663A12F0E0EEA] - (.Microsoft Corporation - Minirdr SMB Windows NT.) () -- C:\WINDOWS\System32\drivers\MRxSmb.sys [415232]
[MD5.F0D791348AD254360CC3C3E501CCB745] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\WINDOWS\System32\drivers\netBT.sys [273408]
[MD5.5B3D91EB07785D0EDB19449D5C35E30A] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\WINDOWS\System32\drivers\ntfs.sys [2117472]
[MD5.38F1AE32339731F6E5A7281AE8042545] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\WINDOWS\System32\drivers\Parport.sys [96768]
[MD5.CA60F6C03611AF1710BC903ED9F566FB] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [104960]
[MD5.A32AED8C644734B283A7C9D08D76064D] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) () -- C:\WINDOWS\System32\drivers\rdpdr.sys [176128]
[MD5.28E1E63A1AC65E17B3194238FA2CF3BF] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\WINDOWS\System32\drivers\tdx.sys [116576]
[MD5.823A237D871CD652C6BFD47BECB6810A] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\WINDOWS\System32\drivers\volsnap.sys [378720]

---\\ Processus lancés (34) - 1s
[MD5.1B44B5244EAF26BEC315AE84B0AFFC66] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 353.5.) -- C:\WINDOWS\system32\nvvsvc.exe [937616] [PID.864]
[MD5.AC4F72ABB5ED596A0F3D9D1EDDC4B27C] - (.Intel Corporation - igfxCUIService Module.) -- C:\WINDOWS\system32\igfxCUIService.exe [351120] [PID.1256]
[MD5.07F3534C07C5110E9A424C04634C4A8D] - (.Conexant Systems Inc. - Conexant Audio Message Service.) -- C:\WINDOWS\system32\CxAudMsg64.exe [207576] [PID.1880]
[MD5.D89DD60F108E6E5944029EF68E0438ED] - (.Adobe Systems, Incorporated - AGS Service.) -- C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2015936] [PID.1924]
[MD5.0D19026AB5812D3A7B9DBB386F8334D8] - (.Adobe Systems Incorporated - Adobe Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [669872] [PID.1932]
[MD5.07D58D5F7839ABA76118BC037C2C63BD] - (.Conexant Systems, Inc. - SmartAudio Service Application.) -- C:\Windows\syswow64\SASrv.exe [447104] [PID.1852]
[MD5.11DB4520BD8467D85F1FE6F3337D5D10] - (.Adobe Systems, Incorporated - Adobe Photoshop CC 2015.) -- C:\Program Files\Adobe\Adobe Photoshop CC 2015\Photoshop.exe [121820360] [PID.6336]
[MD5.21F982FD101BF613504921554C842164] - (...) -- C:\Program Files (x86)\MediaPlayerVideos 1.2\mediaplayervideos_1.2_helper_service.exe [195213] [PID.6112] =>PUP.Optional.CrossRider
[MD5.FF55FD70EA248ADFF73C148794F5FE9F] - (.Abengine - .) -- C:\Program Files (x86)\Fast-Search\acengine.exe [2327712] [PID.9140] =>PUP.Optional.Abengine
[MD5.9B79741F1B6FE2CD92E65B78467F1B26] - (.Copyright 2015. All rights reserved. - Service.) -- C:\Program Files (x86)\RayDld\ihpmServer.exe [268520] [PID.4336]
[MD5.8D935EA86C0927CDFAB324F3B3D38FB3] - (.Copyright (C) 2014 - .) -- C:\Program Files\WaInterEn\wajam_64.exe [2244096] [PID.8148] =>PUP.Optional.Wajam
[MD5.5F252E6E9229515DBF401C753BCAFB27] - (.Irrational Number Applications - WebShield Service.) -- C:\ProgramData\stVjnfds\uauEEWZ.exe [3000824] [PID.3200] =>PUP.Optional.WebShield
[MD5.F78C9DD12267CCE7188B8E614C692F5B] - (.Copyright © 2015 - iirubsao.) -- C:\ProgramData\Nneledoh\1.0.6.1\iirubsao.exe [158208] [PID.4812]
[MD5.F423D12EE3D40C26BF415B0DCDF60F40] - (.AVAST Software - avast! firewall service.) -- C:\Program Files\AVAST Software\Avast\afwServ.exe [109008] [PID.9572]
[MD5.123CE08362EE48BBA7F9F1D7EB50F24F] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544] [PID.8648]
[MD5.240AF8882E2C0D1280572DFAB3C31D93] - (.Adobe Systems Incorporated - Adobe IPC Broker.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe [1011872] [PID.9212]
[MD5.F78C9DD12267CCE7188B8E614C692F5B] - (.Copyright © 2015 - iirubsao.) -- C:\ProgramData\Nneledoh\1.0.6.1\iirubsao.exe [158208] [PID.7436]
[MD5.1B44B5244EAF26BEC315AE84B0AFFC66] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 353.5.) -- C:\WINDOWS\system32\nvvsvc.exe [937616] [PID.3732]
[MD5.DB1EC96C28212D0EAE597317EEFF6D67] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [1253008] [PID.10148]
[MD5.6B87CC5B94F13C5CA7A4D2743DEB027A] - (.Copyright © 2014 - Money.) -- C:\Program Files\WindowsApps\Microsoft.BingFinance_4.5.168.0_x86__8wekyb3d8bbwe\Microsoft.Msn.Money.exe [7680] [PID.1308]
[MD5.831EE34C9AE23FE421E642DBA8E46C2A] - (.Spotify Ltd - Spotify.) -- C:\Users\chris_000\AppData\Roaming\Spotify\Spotify.exe [7660648] [PID.7808]
[MD5.1E9386E3CF138ABE1158B51FFF768BED] - (.Spotify Ltd - SpotifyCrashService.) -- C:\Users\chris_000\AppData\Roaming\Spotify\SpotifyCrashService.exe [1067112] [PID.10020]
[MD5.831EE34C9AE23FE421E642DBA8E46C2A] - (.Spotify Ltd - Spotify.) -- C:\Users\chris_000\AppData\Roaming\Spotify\Spotify.exe [7660648] [PID.5160]
[MD5.781DCED079ABD884DF8CA22B6FA30F05] - (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\chris_000\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2541160] [PID.7424]
[MD5.831EE34C9AE23FE421E642DBA8E46C2A] - (.Spotify Ltd - Spotify.) -- C:\Users\chris_000\AppData\Roaming\Spotify\Spotify.exe [7660648] [PID.3824]
[MD5.21739F352B89F6B948E5EBC2C1C1AA24] - (...) -- C:\Program Files (x86)\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe [225792] [PID.8436]
[MD5.C6352C29C56077749CEEDD08680D347D] - (.Copyright (C) 2009 Wacom Europe GmbH - BambooDock back-end application.) -- C:\Program Files (x86)\Bamboo Dock\BambooCore.exe [646744] [PID.5260]
[MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.8032]
[MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.704]
[MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.2248]
[MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.5224]
[MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.11000]
[MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.1572]
[MD5.84867350CFF4C8551E5F5A3D355D8CB3] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\chris_000\Downloads\ZHPDiag3.exe [1901056] [PID.6300]

---\\ Google Chrome, Démarrage,Recherche,Extensions (11) - 0s
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.google.fr/
G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [gomekmidlodglbbmalcneegieacbdmki] Avast Online Security
G2 - GCE: Preference [User Data\Default] [lccekmodgklaepjeofjdjpbminllajkg] Chrome Hotword Shared Module
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc.

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (2) - 1s
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc..) -- C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc..) -- C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (16) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer

---\\ Internet Explorer,Proxy Management (2) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.)
F2 - REG:system.ini: VMApplet=

---\\ Etude du fichier hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ Browser Helper Object de navigateur (BHO) (1) - 0s
O2 - BHO: avast! Online Security [64Bits] - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll

---\\ Applications lancées au démarrage du système (14) - 0s
O4 - HKLM\..\Run: [cAudioFilterAgent] . (.Conexant Systems, Inc. - Conexant High Definition Audio Filter Agent.) -- C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
O4 - HKLM\..\Run: [SmartAudio] . (.Conexant Systems, Inc. - SmartAudio CPL (32bit).) -- C:\Program Files\CONEXANT\SAII\SACpl.exe
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\chris_000\AppData\Local\Microsoft\OneDrive\OneDrive.exe
O4 - HKCU\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\chris_000\AppData\Roaming\Spotify\SpotifyWebHelper.exe
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\chris_000\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe Creative Cloud] . (.Adobe Systems Incorporated - Adobe Creative Cloud.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
O4 - HKLM\..\Wow6432Node\Run: [BambooCore] . (.Copyright (C) 2009 Wacom Europe GmbH - BambooDock back-end application.) -- C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\syswow64\OneDriveSetup.exe
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\syswow64\OneDriveSetup.exe
O4 - HKUS\S-1-5-21-2145442706-2107086627-2595070405-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\chris_000\AppData\Local\Microsoft\OneDrive\OneDrive.exe
O4 - HKUS\S-1-5-21-2145442706-2107086627-2595070405-1001\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\chris_000\AppData\Roaming\Spotify\SpotifyWebHelper.exe
O4 - HKUS\S-1-5-21-2145442706-2107086627-2595070405-1001\..\RunOnce: [Uninstall C:\Users\chris_000\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe

---\\ Winsock hijacker (Layered Service Provider) (10) - 0s
O10 - WLSP:\Catalog_Entries\000000000001\Winsock LSP File . (...) -- C:\Windows\System32\acengine.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries\000000000002\Winsock LSP File . (...) -- C:\Windows\System32\acengine.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries\000000000003\Winsock LSP File . (...) -- C:\Windows\System32\acengine.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries\000000000004\Winsock LSP File . (...) -- C:\Windows\System32\acengine.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries\000000000017\Winsock LSP File . (...) -- C:\Windows\System32\acengine.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000001\Winsock LSP File . (.Abengine.) -- C:\WINDOWS\system32\acengine64.dll =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000002\Winsock LSP File . (.Abengine.) -- C:\WINDOWS\system32\acengine64.dll =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000003\Winsock LSP File . (.Abengine.) -- C:\WINDOWS\system32\acengine64.dll =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000004\Winsock LSP File . (.Abengine.) -- C:\WINDOWS\system32\acengine64.dll =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000017\Winsock LSP File . (.Abengine.) -- C:\WINDOWS\system32\acengine64.dll =>Hijacker.Winsock

---\\ Modification Domaine/Adresses DNS (2) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.55.55
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.55.55

---\\ Protocole additionnel (21) - 0s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll

---\\ Liste des services NT non Microsoft et non désactivés (13) - 0s
O23 - Service: acengine (acengine) . (.Abengine - .) - C:\Program Files (x86)\Fast-Search\acengine.exe =>PUP.Optional.Abengine
O23 - Service: (AdobeUpdateService) . (.Adobe Systems Incorporated - Adobe Update Service.) - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) . (.Adobe Systems, Incorporated - AGS Service.) - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Firewall (avast! Firewall) . (.AVAST Software - avast! firewall service.) - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: @C:\WINDOWS\system32\CxAudMsg64.exe,-100 (CxAudMsg) . (.Conexant Systems Inc. - Conexant Audio Message Service.) - C:\WINDOWS\system32\CxAudMsg64.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\WINDOWS\system32\igfxCUIService.exe
O23 - Service: ihpmServer (ihpmServer) . (.Copyright 2015. All rights reserved. - Service.) - C:\Program Files (x86)\RayDld\ihpmServer.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 353.5.) - C:\WINDOWS\system32\nvvsvc.exe
O23 - Service: Conexant SmartAudio service (SAService) . (...) - C:\Windows\System32\SASrv.exe (.not file.)
O23 - Service: uauEEWZ (uauEEWZ) . (.Irrational Number Applications - WebShield Service.) - C:\ProgramData\stVjnfds\uauEEWZ.exe =>PUP.Optional.WebShield
O23 - Service: WaInterEn Monitor (WaInterEn Monitor) . (.Copyright (C) 2014 - .) - C:\Program Files\WaInterEn\wajam_64.exe =>PUP.Optional.Wajam

---\\ Tâches planifiées en automatique (22) - 4s
[MD5.7FA88AB757C25E0635AF71DDBAFAB25E] [APT] [ASUS Smart Gesture Launcher] (.AsusTek.) -- C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [18416]
[MD5.D9E35285D8CCE58241038E5B23507DAB] [APT] [avast! Emergency Update] (.AVAST Software.) -- C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [1382112]
[MD5.053EEEE1ABAE53F044F1E386E22AE525] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200]
[MD5.053EEEE1ABAE53F044F1E386E22AE525] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200]
[MD5.21F982FD101BF613504921554C842164] [APT] [mediaplayervideos_1.2_helper_service] (...) -- C:\Program Files (x86)\MediaPlayerVideos 1.2\mediaplayervideos_1.2_helper_service.exe [195213] =>PUP.Optional.CrossRider
[MD5.0615E91D08F456044AA7893FCACFED73] [APT] [mediaplayervideos_1.2_updating_service] (...) -- C:\Program Files (x86)\MediaPlayerVideos 1.2\mediaplayervideos_1.2_updating_service.exe [101376] =>PUP.Optional.CrossRider
[MD5.F78C9DD12267CCE7188B8E614C692F5B] [APT] [Nneledoh] (.Copyright © 2015.) -- C:\ProgramData\Nneledoh\1.0.6.1\iirubsao.exe [158208] =>Heuristic.PullUpdate
[MD5.E5728FFF1D7425CC12A24934E7B81138] [APT] [updateTask] (...) -- c:/task.vbs [296]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [1088] =>.Google Inc.
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [1092] =>.Google Inc.
O39 - APT: mediaplayervideos_1.2_helper_service - (...) -- C:\WINDOWS\Tasks\mediaplayervideos_1.2_helper_service.job [588] =>PUP.Optional.CrossRider
O39 - APT: mediaplayervideos_1.2_updating_service - (...) -- C:\WINDOWS\Tasks\mediaplayervideos_1.2_updating_service.job [826] =>PUP.Optional.CrossRider
O39 - APT: Orphean - (...) -- C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-antoine97@hotmail.de [3654]
O39 - APT: ASUS Smart Gesture Launcher - (.AsusTek.) -- C:\WINDOWS\System32\Tasks\ASUS Smart Gesture Launcher [3628] =>.AsusTek
O39 - APT: avast! Emergency Update - (.AVAST Software.) -- C:\WINDOWS\System32\Tasks\avast! Emergency Update [4006] =>.AVAST Software
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore [3918] =>.Google Inc.
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA [4150] =>.Google Inc.
O39 - APT: mediaplayervideos_1.2_helper_service - (...) -- C:\WINDOWS\System32\Tasks\mediaplayervideos_1.2_helper_service [3690] =>PUP.Optional.CrossRider
O39 - APT: mediaplayervideos_1.2_updating_service - (...) -- C:\WINDOWS\System32\Tasks\mediaplayervideos_1.2_updating_service [4000] =>PUP.Optional.CrossRider
O39 - APT: Nneledoh - (.Copyright © 2015.) -- C:\WINDOWS\System32\Tasks\Nneledoh [3510] =>Heuristic.PullUpdate
O39 - APT: Orphean - (...) -- C:\WINDOWS\System32\Tasks\runTask [3312]
O39 - APT: updateTask - (...) -- C:\WINDOWS\System32\Tasks\updateTask [3222]

---\\ Logiciels installés (21) - 1s
O42 - Logiciel: Package de pilotes Windows - ASUS (ATP) Mouse (08/01/2015 10.0.0.5) - (.ASUS.) [HKLM][64Bits] -- B267A462F49A1ACD7A2EC5C262BA0DC7D7B23891
O42 - Logiciel: Conexant HD Audio - (.Conexant.) [HKLM][64Bits] -- CNXT_AUDIO_HDA
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR
O42 - Logiciel: Adobe Creative Cloud - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Creative Cloud
O42 - Logiciel: Avast Premier - (.AVAST Software.) [HKLM][64Bits] -- Avast
O42 - Logiciel: Bamboo Dock - (.Wacom Co., Ltd..) [HKLM][64Bits] -- Bamboo Dock
O42 - Logiciel: Battle.net - (.Blizzard Entertainment.) [HKLM][64Bits] -- Battle.net
O42 - Logiciel: Fast-Search - (.Aleksandr Davidu.) [HKLM][64Bits] -- Fast-Search
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome
O42 - Logiciel: MediaPlayerVideos 1.2 - (...) [HKLM][64Bits] -- MediaPlayerVideos 1.2 =>PUP.Optional.CrossRider
O42 - Logiciel: mystartsearch - (...) [HKLM][64Bits] -- mystartsearch =>PUP.Optional.StartSearch
O42 - Logiciel: Bamboo Dock - (.Wacom Europe GmbH.) [HKLM][64Bits] -- wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
O42 - Logiciel: Wajam - (.Wajam.) [HKLM][64Bits] -- WaInterEn =>PUP.Optional.Wajam
O42 - Logiciel: Web Shield - (.Irrational Number Applications.) [HKLM][64Bits] -- WebShield =>PUP.Optional.WebShield
O42 - Logiciel: ASUS Smart Gesture - (.ASUS.) [HKLM][64Bits] -- {4D3286A6-F6AB-498A-82A4-E4F040529F3D}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
O42 - Logiciel: Adobe Photoshop CC 2015 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {793C2BF7-A4FE-4608-91C9-9282C5801C21}
O42 - Logiciel: Bamboo Dock - (.Wacom Europe GmbH.) [HKLM][64Bits] -- {90DFD61B-8224-00C6-3D69-A983B60A394E}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AFF7E080-1974-45BF-9310-10DE1A1F5ED0}
O42 - Logiciel: Spotify - (.Spotify AB.) [HKCU][64Bits] -- Spotify

---\\ HKCU & HKLM Software Keys (45) - 1s
HKLM\SOFTWARE\Wow6432Node\Adobe
HKLM\SOFTWARE\Wow6432Node\ASUS
HKLM\SOFTWARE\Wow6432Node\AVAST Software
HKLM\SOFTWARE\Wow6432Node\Blizzard Entertainment
HKLM\SOFTWARE\Wow6432Node\Conexant
HKLM\SOFTWARE\Wow6432Node\Fast-Search
HKLM\SOFTWARE\Wow6432Node\Google
HKLM\SOFTWARE\Wow6432Node\ihpmserver
HKLM\SOFTWARE\Wow6432Node\Intel
HKLM\SOFTWARE\Wow6432Node\Khronos
HKLM\SOFTWARE\Wow6432Node\Macromedia
HKLM\SOFTWARE\Wow6432Node\MaxPower
HKLM\SOFTWARE\Wow6432Node\Mozilla
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\mystartsearchSoftware =>PUP.Optional.StartSearch
HKLM\SOFTWARE\Wow6432Node\ODBC
HKLM\SOFTWARE\Wow6432Node\RayDld
HKLM\SOFTWARE\Wow6432Node\Valve
HKLM\SOFTWARE\Wow6432Node\WaInterEn
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\ASUS
HKCU\SOFTWARE\AVAST Software
HKCU\SOFTWARE\Blizzard Entertainment
HKCU\SOFTWARE\Chromium
HKCU\SOFTWARE\Conexant
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\InstallPath
HKCU\SOFTWARE\Intel
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\Mine
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\NVIDIA Corporation
HKCU\SOFTWARE\RegisteredApplications
HKCU\SOFTWARE\SafeZoneBrowser
HKCU\SOFTWARE\Spotify
HKCU\SOFTWARE\TeamSpeak 3 Client
HKCU\SOFTWARE\Unity
HKCU\SOFTWARE\Valve
HKCU\SOFTWARE\WajIEnhance =>PUP.Optional.Wajam
HKCU\SOFTWARE\Wow6432Node
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\DynConIE =>PUP.Optional.DynConIE

---\\ Contenu des dossiers Programmes (111) - 2s
O43 - CFD: 2015/10/08 20:09:32 - [] D -- C:\Program Files (x86)\Adobe
O43 - CFD: 2015/10/07 20:50:39 - [] D -- C:\Program Files (x86)\ASUS
O43 - CFD: 2015/10/08 20:16:07 - [] D -- C:\Program Files (x86)\Bamboo Dock
O43 - CFD: 2015/10/07 20:58:41 - [] D -- C:\Program Files (x86)\Battle.net
O43 - CFD: 2015/10/08 20:09:31 - [] D -- C:\Program Files (x86)\Common Files
O43 - CFD: 2015/10/08 10:38:56 - [] D -- C:\Program Files (x86)\Fast-Search
O43 - CFD: 2015/10/08 10:41:29 - [] D -- C:\Program Files (x86)\Google
O43 - CFD: 2015/10/07 21:19:17 - [] D -- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 2015/10/08 10:37:56 - [] D -- C:\Program Files (x86)\MediaPlayerVideos 1.2 =>PUP.Optional.CrossRider
O43 - CFD: 2015/10/07 21:16:58 - [] D -- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 2015/10/07 21:19:52 - [] D -- C:\Program Files (x86)\MSBuild
O43 - CFD: 2015/10/08 10:38:57 - [] D -- C:\Program Files (x86)\RayDld
O43 - CFD: 2015/10/07 21:19:52 - [] D -- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 2015/10/07 21:19:17 - [] D -- C:\Program Files (x86)\Windows Defender
O43 - CFD: 2015/10/07 21:19:17 - [] D -- C:\Program Files (x86)\Windows Mail
O43 - CFD: 2015/10/07 21:19:17 - [] D -- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 2015/10/07 21:17:00 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform
O43 - CFD: 2015/10/07 21:16:58 - [] D -- C:\Program Files (x86)\Windows NT
O43 - CFD: 2015/10/07 21:19:17 - [] D -- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 2015/10/07 21:17:00 - [] D -- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 2015/10/07 21:16:58 - [] SHD -- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 2015/10/07 21:16:58 - [] SD -- C:\Program Files (x86)\WindowsPowerShell
O43 - CFD: 2015/10/07 21:17:01 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 2015/10/07 21:17:01 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2015/10/07 21:17:01 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2015/10/08 10:55:23 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
O43 - CFD: 2015/10/08 20:09:35 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bamboo Dock
O43 - CFD: 2015/10/07 20:58:13 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
O43 - CFD: 2015/10/07 20:24:55 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant
O43 - CFD: 2015/10/08 10:41:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 2015/10/07 21:17:01 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/10/07 21:17:01 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
O43 - CFD: 2015/10/07 21:17:01 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 2015/10/07 21:16:58 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 2015/10/08 10:39:13 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WaInterEn
O43 - CFD: 2015/10/08 20:09:33 - [] D -- C:\ProgramData\Adobe
O43 - CFD: 2015/10/07 20:29:10 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 2015/10/08 10:31:15 - [] D -- C:\ProgramData\ASUS Smart Gesture
O43 - CFD: 2015/10/08 10:46:09 - [] D -- C:\ProgramData\AVAST Software
O43 - CFD: 2015/10/07 20:54:18 - [] D -- C:\ProgramData\Battle.net
O43 - CFD: 2015/10/07 20:54:18 - [] D -- C:\ProgramData\Blizzard Entertainment
O43 - CFD: 2015/10/07 23:22:57 - [] D -- C:\ProgramData\boost_interprocess
O43 - CFD: 2015/10/07 20:29:10 - [0] SHD -- C:\ProgramData\Bureau
O43 - CFD: 2015/10/07 21:16:58 - [0] D -- C:\ProgramData\Comms
O43 - CFD: 2015/10/07 20:37:08 - [] D -- C:\ProgramData\Conexant
O43 - CFD: 2015/10/07 20:29:10 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 2015/10/07 20:29:10 - [0] SHD -- C:\ProgramData\Menu Démarrer
O43 - CFD: 2015/10/07 20:43:37 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 2015/10/07 20:36:37 - [] D -- C:\ProgramData\Microsoft OneDrive
O43 - CFD: 2015/10/07 20:29:10 - [0] SHD -- C:\ProgramData\Modèles
O43 - CFD: 2015/10/08 10:44:16 - [] D -- C:\ProgramData\Nneledoh
O43 - CFD: 2015/10/07 20:26:14 - [] D -- C:\ProgramData\NVIDIA
O43 - CFD: 2015/10/07 20:25:59 - [] D -- C:\ProgramData\NVIDIA Corporation
O43 - CFD: 2015/10/07 21:50:57 - [] D -- C:\ProgramData\Package Cache
O43 - CFD: 2015/10/07 23:24:37 - [] D -- C:\ProgramData\regid.1986-12.com.adobe
O43 - CFD: 2015/10/07 21:17:01 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 2015/10/07 20:50:27 - [] D -- C:\ProgramData\SetupTPDriver
O43 - CFD: 2015/10/07 21:16:58 - [0] D -- C:\ProgramData\SoftwareDistribution
O43 - CFD: 2015/10/08 10:39:15 - [] D -- C:\ProgramData\stVjnfds
O43 - CFD: 2015/10/07 20:24:47 - [] D -- C:\ProgramData\USOPrivate
O43 - CFD: 2015/10/07 20:24:46 - [] D -- C:\ProgramData\USOShared
O43 - CFD: 2015/10/08 20:16:16 - [] D -- C:\ProgramData\Wacom
O43 - CFD: 2015/10/08 10:39:13 - [] D -- C:\ProgramData\WebShield =>PUP.Optional.WebShield
O43 - CFD: 2015/10/07 22:50:48 - [] D -- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 2015/10/08 20:09:31 - [] D -- C:\Program Files (x86)\Common Files\Adobe AIR
O43 - CFD: 2015/10/07 20:25:10 - [] D -- C:\Program Files (x86)\Common Files\Intel
O43 - CFD: 2015/10/07 21:50:45 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared
O43 - CFD: 2015/10/07 21:17:00 - [] D -- C:\Program Files (x86)\Common Files\Services
O43 - CFD: 2015/10/07 20:52:10 - [] D -- C:\Program Files (x86)\Common Files\Steam
O43 - CFD: 2015/10/07 21:19:17 - [] D -- C:\Program Files (x86)\Common Files\System
O43 - CFD: 2015/10/08 20:09:26 - [] D -- C:\Users\chris_000\AppData\Roaming\Adobe
O43 - CFD: 2015/10/08 10:57:00 - [] D -- C:\Users\chris_000\AppData\Roaming\AVAST Software
O43 - CFD: 2015/10/07 20:58:40 - [] D -- C:\Users\chris_000\AppData\Roaming\Battle.net
O43 - CFD: 2015/10/07 20:44:37 - [] D -- C:\Users\chris_000\AppData\Roaming\Macromedia
O43 - CFD: 2015/10/07 20:36:26 - [] SD -- C:\Users\chris_000\AppData\Roaming\Microsoft
O43 - CFD: 2015/10/08 10:38:59 - [] D -- C:\Users\chris_000\AppData\Roaming\mystartsearch =>PUP.Optional.StartSearch
O43 - CFD: 2015/10/07 23:24:40 - [] D -- C:\Users\chris_000\AppData\Roaming\NVIDIA
O43 - CFD: 2015/10/07 23:24:29 - [] D -- C:\Users\chris_000\AppData\Roaming\PDAppFlex
O43 - CFD: 2015/10/08 19:19:50 - [] D -- C:\Users\chris_000\AppData\Roaming\Spotify
O43 - CFD: 2015/10/08 20:16:15 - [] D -- C:\Users\chris_000\AppData\Roaming\Wacom
O43 - CFD: 2015/10/08 20:16:04 - [] D -- C:\Users\chris_000\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
O43 - CFD: 2015/10/08 20:30:10 - [] D -- C:\Users\chris_000\AppData\Roaming\ZHP
O43 - CFD: 2015/10/08 20:09:23 - [] D -- C:\Users\chris_000\AppData\Local\Adobe
O43 - CFD: 2015/10/07 20:28:33 - [0] SHD -- C:\Users\chris_000\AppData\Local\Application Data
O43 - CFD: 2015/10/07 20:58:43 - [] D -- C:\Users\chris_000\AppData\Local\Battle.net
O43 - CFD: 2015/10/07 20:54:14 - [] D -- C:\Users\chris_000\AppData\Local\Blizzard
O43 - CFD: 2015/10/07 20:58:46 - [] D -- C:\Users\chris_000\AppData\Local\Blizzard Entertainment
O43 - CFD: 2015/10/07 20:52:12 - [] D -- C:\Users\chris_000\AppData\Local\CEF
O43 - CFD: 2015/10/07 20:39:12 - [] D -- C:\Users\chris_000\AppData\Local\Comms
O43 - CFD: 2015/10/07 20:37:08 - [] D -- C:\Users\chris_000\AppData\Local\Conexant
O43 - CFD: 2015/10/08 10:38:03 - [] D -- C:\Users\chris_000\AppData\Local\Google
O43 - CFD: 2015/10/07 20:28:33 - [0] SHD -- C:\Users\chris_000\AppData\Local\Historique
O43 - CFD: 2015/10/08 10:39:18 - [] D -- C:\Users\chris_000\AppData\Local\Microsoft
O43 - CFD: 2015/10/07 20:42:18 - [] D -- C:\Users\chris_000\AppData\Local\MicrosoftEdge
O43 - CFD: 2015/10/07 21:10:21 - [0] D -- C:\Users\chris_000\AppData\Local\NetworkTiles
O43 - CFD: 2015/10/08 18:03:44 - [] D -- C:\Users\chris_000\AppData\Local\Packages
O43 - CFD: 2015/10/07 20:35:16 - [] D -- C:\Users\chris_000\AppData\Local\Publishers
O43 - CFD: 2015/10/08 19:14:49 - [] D -- C:\Users\chris_000\AppData\Local\Spotify
O43 - CFD: 2015/10/07 20:52:12 - [] D -- C:\Users\chris_000\AppData\Local\Steam
O43 - CFD: 2015/10/08 20:30:13 - [] D -- C:\Users\chris_000\AppData\Local\Temp
O43 - CFD: 2015/10/07 20:28:33 - [0] SHD -- C:\Users\chris_000\AppData\Local\Temporary Internet Files
O43 - CFD: 2015/10/07 20:35:07 - [] D -- C:\Users\chris_000\AppData\Local\TileDataLayer
O43 - CFD: 2015/10/08 20:23:11 - [] D -- C:\Users\chris_000\AppData\Local\VirtualStore
O43 - CFD: 2015/10/08 20:29:26 - [] D -- C:\Users\chris_000\AppData\Local\WebShield =>PUP.Optional.WebShield
O43 - CFD: 2015/10/07 21:17:01 - [] RD -- C:\Users\chris_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 2015/10/07 20:35:07 - [] RD -- C:\Users\chris_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2015/10/07 20:35:08 - [] RD -- C:\Users\chris_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2015/10/07 21:17:01 - [] D -- C:\Users\chris_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/10/07 20:35:08 - [] RD -- C:\Users\chris_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2015/10/07 21:17:01 - [] RD -- C:\Users\chris_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 2015/10/07 21:17:12 - [] RSD -- C:\Users\chris_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell

---\\ Derniers fichiers créés dans Windows Prefetcher (4) - 2s
O45 - LFCP:[MD5.EC0B0AB4F044B96342B9E59EA92E669C] 2015/10/08 10:39:07 A -- C:\WINDOWS\Prefetch\ACENGINE.EXE-2DAEF85F.pf =>PUP.Optional.Abengine
O45 - LFCP:[MD5.0EB20850725D91E161638AF192A608A4] 2015/10/08 20:27:05 A -- C:\WINDOWS\Prefetch\WAJAM.EXE-1C99DDFE.pf =>PUP.Optional.Wajam
O45 - LFCP:[MD5.8798D093480F3800EBA15778CD077398] 2015/10/08 10:43:54 A -- C:\WINDOWS\Prefetch\WAJAM_64.EXE-310E257B.pf =>PUP.Optional.Wajam
O45 - LFCP:[MD5.2122C9289EE0221B29FF3C5D5F22CA6C] 2015/10/08 10:39:13 A -- C:\WINDOWS\Prefetch\WEBSHIELDINSTALL.EXE-81D4DEA4.pf =>PUP.Optional.WebShield

---\\ Liste des pilotes du système (64) - 2s
O58 - SDL:2015/07/10 07:09:24 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107360]
O58 - SDL:2015/09/23 21:16:26 A . (.Abengine - WFP driver.) -- C:\WINDOWS\System32\drivers\acwfp64.sys [45280] =>PUP.Optional.Abengine
O58 - SDL:2015/07/10 07:03:12 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135456]
O58 - SDL:2015/07/10 07:05:17 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83296]
O58 - SDL:2015/07/10 07:03:16 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259424]
O58 - SDL:2015/07/10 07:05:17 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [26976]
O58 - SDL:2015/07/10 07:03:12 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [131936]
O58 - SDL:2015/05/13 05:44:24 A . (.ASUS - HID driver for ASUS Wireless Radio Control.) -- C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [19976]
O58 - SDL:2015/09/23 20:52:58 A . (.ASUS Corporation - Asus TP Filter Driver(X64).) -- C:\WINDOWS\System32\drivers\AsusTP.sys [101368]
O58 - SDL:2015/10/08 10:55:03 A . (.AVAST Software - avast! HWID.) -- C:\WINDOWS\System32\drivers\aswHwid.sys [28656]
O58 - SDL:2015/10/08 10:54:58 A . (.AVAST Software - avast! Keyboard Filter Driver.) -- C:\WINDOWS\System32\drivers\aswKbd.sys [28144]
O58 - SDL:2015/10/08 10:55:03 A . (.AVAST Software - avast! File System Minifilter for Windows 2.) -- C:\WINDOWS\System32\drivers\aswMonFlt.sys [90968]
O58 - SDL:2015/10/08 10:54:56 A . (.AVAST Software - avast! Filtering NDIS driver.) -- C:\WINDOWS\System32\drivers\aswNdisFlt.sys [454528]
O58 - SDL:2015/10/08 10:55:02 A . (.AVAST Software - avast! WFP Redirect Driver.) -- C:\WINDOWS\System32\drivers\aswRdr2.sys [93528]
O58 - SDL:2015/10/08 10:55:03 A . (.AVAST Software - avast! Revert.) -- C:\WINDOWS\System32\drivers\aswRvrt.sys [65224]
O58 - SDL:2015/10/08 10:54:58 A . (.AVAST Software - avast! Virtualization Driver.) -- C:\WINDOWS\System32\drivers\aswSnx.sys [1049880]
O58 - SDL:2015/10/08 10:55:03 A . (.AVAST Software - avast! self protection module.) -- C:\WINDOWS\System32\drivers\aswSP.sys [448968]
O58 - SDL:2015/10/08 10:55:03 A . (.AVAST Software - Stream Filter.) -- C:\WINDOWS\System32\drivers\aswStm.sys [153744]
O58 - SDL:2015/10/08 10:55:03 A . (.AVAST Software - avast! VM Monitor.) -- C:\WINDOWS\System32\drivers\aswVmm.sys [274808]
O58 - SDL:2015/06/18 03:04:00 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [17624]
O58 - SDL:2015/07/10 06:55:09 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [531296]
O58 - SDL:2015/05/13 10:40:48 A . (.Conexant Systems Inc. - 64-bit High Definition Audio Function Drive.) -- C:\WINDOWS\System32\drivers\CHDRT64.sys [1536528]
O58 - SDL:2015/07/10 06:55:06 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3436896]
O58 - SDL:2015/07/10 07:07:32 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64352]
O58 - SDL:2015/06/18 03:03:50 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128]
O58 - SDL:2015/06/18 03:04:39 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [122608]
O58 - SDL:2014/10/16 05:20:34 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver -.) -- C:\WINDOWS\System32\drivers\iaStorA.sys [1398936]
O58 - SDL:2015/07/10 07:06:06 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [673120]
O58 - SDL:2015/07/10 07:06:06 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412000]
O58 - SDL:2015/07/10 06:54:54 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [424800]
O58 - SDL:2015/07/15 23:35:00 A . (.Intel Corporation - Intel(R) Wireless Bluetooth(R) USB Driver.) -- C:\WINDOWS\System32\drivers\ibtusb.sys [266512]
O58 - SDL:2015/07/18 00:36:32 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd64.sys [6389688]
O58 - SDL:2015/03/24 13:48:58 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\WINDOWS\System32\drivers\IntcDAud.sys [460048]
O58 - SDL:2014/10/16 05:27:46 A . (.Intel Corporation - Intel Collaborative Processor Performance C.) -- C:\WINDOWS\System32\drivers\IntelPcc.sys [79528]
O58 - SDL:2015/03/04 23:08:34 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\iwdbus.sys [30512]
O58 - SDL:2015/07/10 07:09:24 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [108896]
O58 - SDL:2015/07/10 07:09:24 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [104800]
O58 - SDL:2015/07/10 07:09:24 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [99168]
O58 - SDL:2015/07/10 07:09:24 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82784]
O58 - SDL:2015/07/10 07:09:24 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59744]
O58 - SDL:2015/07/10 07:09:24 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575840]
O58 - SDL:2015/07/10 06:54:54 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [705376]
O58 - SDL:2015/07/10 07:03:10 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63840]
O58 - SDL:2015/07/10 06:54:53 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [76128]
O58 - SDL:2015/06/18 03:04:03 . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\WINDOWS\System32\drivers\Netwbw02.sys [3496216]
O58 - SDL:2015/07/13 20:45:08 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\WINDOWS\System32\drivers\nvlddmkm.sys [11139216]
O58 - SDL:2015/07/10 07:07:35 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150368]
O58 - SDL:2015/07/10 07:07:35 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166240]
O58 - SDL:2015/04/27 23:21:20 A . (.NVIDIA Corporation - Stereoscopic 3D USB controller driver.) -- C:\WINDOWS\System32\drivers\nvstusb.sys [452240]
O58 - SDL:2014/09/05 19:03:10 A . (.Windows (R) Win 7 DDK provider - Filter Driver for the blake Device (Framewo.) -- C:\WINDOWS\System32\drivers\nvswcfilter.sys [19616]
O58 - SDL:2015/07/10 07:09:24 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58208]
O58 - SDL:2015/07/10 07:09:24 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [58720]
O58 - SDL:2011/07/29 11:53:12 A . (...) -- C:\WINDOWS\System32\drivers\PXGX112.sys [23552]
O58 - SDL:2015/07/07 23:25:38 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.40 64-bit Dr.) -- C:\WINDOWS\System32\drivers\rt640x64.sys [895256]
O58 - SDL:2015/05/14 11:44:38 A . (.Realsil Semiconductor Corporation - RTS PCIE READER Driver.) -- C:\WINDOWS\System32\drivers\RtsPer.sys [751632]
O58 - SDL:2015/07/10 07:03:13 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44896]
O58 - SDL:2015/07/10 07:03:13 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81760]
O58 - SDL:2015/07/10 07:03:16 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31072]
O58 - SDL:2014/09/03 12:03:32 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\TeeDriverx64.sys [126976]
O58 - SDL:2015/07/10 05:21:44 A . (...) -- C:\WINDOWS\System32\drivers\Udecx.sys [44032]
O58 - SDL:2015/07/10 07:07:40 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166752]
O58 - SDL:2015/07/10 07:07:40 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305504]
O58 - SDL:2015/07/10 06:54:54 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [26976]
O58 - SDL:2015/07/10 06:54:53 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [59232]

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (17) - 13s
O61 - LFC: 2015/10/08 10:36:56 A . (..) -- C:\Users\chris_000\Downloads\ChromeSetup (1).exe [568104]
O61 - LFC: 2015/10/08 20:09:07 A . (..) -- C:\Users\chris_000\Downloads\dock_setup.exe [30011936]
O61 - LFC: 2015/10/02 22:14:11 A . (..) -- C:\Users\chris_000\Desktop\Hearthstone.exe [16109104]
O61 - LFC: 2015/10/08 19:14:47 A . (.Copyright (C) 2015 The Chromium Embedded Framework Au.) -- C:\Users\chris_000\AppData\Roaming\Spotify\libcef.dll [50680424]
O61 - LFC: 2015/10/08 19:14:47 A . (.Copyright (C) 2015 Google Inc..) -- C:\Users\chris_000\AppData\Roaming\Spotify\libEGL.dll [83048]
O61 - LFC: 2015/10/08 19:14:47 A . (.Copyright (C) 2015 Google Inc..) -- C:\Users\chris_000\AppData\Roaming\Spotify\libGLESv2.dll [1882728]
O61 - LFC: 2015/10/08 19:14:47 A . (..) -- C:\Users\chris_000\AppData\Roaming\Spotify\natives_blob.bin [410849]
O61 - LFC: 2015/10/08 19:14:47 A . (..) -- C:\Users\chris_000\AppData\Roaming\Spotify\snapshot_blob.bin [463444]
O61 - LFC: 2015/10/08 19:14:47 A . (.The Chromium Authors.) -- C:\Users\chris_000\AppData\Roaming\Spotify\widevinecdmadapter.dll [210024]
O61 - LFC: 2015/10/08 19:14:47 A . (..) -- C:\Users\chris_000\AppData\Roaming\Spotify\wow_helper.exe [74856]
O61 - LFC: 2015/10/08 10:38:59 A . (.Copyright 2015.) -- C:\Users\chris_000\AppData\Roaming\mystartsearch\Uninstall.exe [630784] =>PUP.Optional.StartSearch
O61 - LFC: 2015/10/08 11:43:18 A . (..) -- C:\Users\chris_000\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_125_0_Data.bin [3381540]
O61 - LFC: 2015/10/07 20:35:16 A . (..) -- C:\Users\chris_000\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_125_0_Header.bin [9640]
O61 - LFC: 2015/10/08 18:04:46 A . (..) -- C:\Users\chris_000\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\speech_onecorereg.bin [8192]
O61 - LFC: 2015/10/08 10:31:58 A . (..) -- C:\Users\chris_000\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\UrlBlock\urlblock_635798866523424494.bin [33988]
O61 - LFC: 2015/10/07 20:43:13 A . (..) -- C:\Users\chris_000\AppData\Local\Microsoft\Windows\1036\StructuredQuerySchema.bin [433477]
O61 - LFC: 2015/10/08 20:23:58 A . (..) -- C:\Users\chris_000\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [674082]

---\\ Associations Shell Spawning (10) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S

---\\ Menu de démarrage Internet (8) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe

---\\ Recherche d'infection sur les navigateurs (2) - 0s
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/
O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} [DefaultScope] - (mystartsearch) - http://www.mystartsearch.com/ =>PUP.Optional.StartSearch

---\\ Enumère les services démarrés par Svchost (41) - 1s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [192000]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [192000]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\WINDOWS\system32\srvsvc.dll [283136]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\WINDOWS\System32\gpsvc.dll [1335296]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\WINDOWS\System32\ikeext.dll [954368]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\WINDOWS\System32\iphlpsvc.dll [954880]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\WINDOWS\system32\seclogon.dll [31232]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\WINDOWS\System32\appinfo.dll [93696]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\WINDOWS\system32\iscsiexe.dll [151040]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\WINDOWS\System32\eapsvc.dll [106496]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\WINDOWS\system32\schedsvc.dll [1008640]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [226304]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\WINDOWS\System32\browser.dll [133120]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\system32\profsvc.dll [324608]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [371200]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\WINDOWS\System32\wercplsupport.dll [95744]
O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) -- C:\WINDOWS\system32\dcpsvc.dll [196096]
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\WINDOWS\System32\ncasvc.dll [167424]
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\WINDOWS\system32\wlidsvc.dll [2093056]
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Service Configuration du réseau.) -- C:\WINDOWS\System32\NetSetupSvc.dll [186368]
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\WINDOWS\System32\XblGameSave.dll [1149440]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\WINDOWS\system32\themeservice.dll [58368]
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\WINDOWS\System32\usermgr.dll [717312]
O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) -- C:\WINDOWS\system32\RDXService.dll [956928]
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL Windows Management Service.) -- C:\Windows\System32\Windows.Internal.Management.dll [267776]
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service de géolocalisation.) -- C:\Windows\System32\lfsvc.dll [27136]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\WINDOWS\System32\bdesvc.dll [359936]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\WINDOWS\System32\rasauto.dll [106496]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\WINDOWS\System32\rasmans.dll [679936]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [497152]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\WINDOWS\System32\sens.dll [72192]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\WINDOWS\System32\ipnathlp.dll [452608]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [311808]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\WINDOWS\system32\wuaueng.dll [2239488]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\WINDOWS\System32\qmgr.dll [1168896]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [593920]
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\WINDOWS\system32\dmwappushsvc.dll [63488]
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\WINDOWS\system32\XboxNetApiSvc.dll [1019392]
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Mettre à jour la session Orchestrator Core.) -- C:\WINDOWS\system32\usocore.dll [343040]
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\WINDOWS\System32\XblAuthManager.dll [918016]
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [237568]

---\\ Liste des exceptions du parefeu Windows (7) - 3s
O87 - FAEL: "{F48EFDA1-96D5-472B-BC4B-1914AD01D332}" [In-None-P6-TRUE] .(...) -- G:\Steam\Steam.exe (.not file.)
O87 - FAEL: "{459FBF2E-8C56-4B16-AA2F-CB47BFF13C9C}" [In-None-P17-TRUE] .(...) -- G:\Steam\Steam.exe (.not file.)
O87 - FAEL: "{E7857D0B-9447-4DA7-B12F-B028DEDF0B16}" [In-None-P6-TRUE] .(...) -- G:\Steam\bin\steamwebhelper.exe (.not file.)
O87 - FAEL: "{B3093B84-D088-46B6-AE31-18E01BCB6BA8}" [In-None-P17-TRUE] .(...) -- G:\Steam\bin\steamwebhelper.exe (.not file.)
O87 - FAEL: "TCP Query User{4AF74FEA-8116-4B98-A8EF-3AB6FA0F942A}D:\hearthstone\hearthstone.exe" [In-None-P6-TRUE] .(...) -- D:\hearthstone\hearthstone.exe
O87 - FAEL: "UDP Query User{5F63892B-9F7E-4AE0-AFA6-BBC912E448F7}D:\hearthstone\hearthstone.exe" [In-None-P17-TRUE] .(...) -- D:\hearthstone\hearthstone.exe
O87 - FAEL: "{B2C2CCA6-FC04-45ED-B2FF-286FB5A1459E}" [In-None-P17-TRUE] .(.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (8) - 9s
SR - Auto [2015/09/03 05:16:12] [ 2327712] acengine (acengine) . (.Abengine.) - C:\Program Files (x86)\Fast-Search\acengine.exe =>PUP.Optional.Abengine
SR - Auto [2015/09/29 10:05:14] [ 2015936] Adobe Genuine Software Integrity Service (AGSService) . (.Adobe Systems, Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
SR - Auto [2014/10/20 14:54:28] [ 207576] @C:\WINDOWS\system32\CxAudMsg64.exe,-100 (CxAudMsg) . (.Conexant Systems Inc..) - C:\WINDOWS\system32\CxAudMsg64.exe
SS - Auto [2015/10/08 10:44:04] [ 144200] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - Demand [2015/10/08 10:44:04] [ 144200] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SR - Auto [2015/09/25 09:32:20] [ 268520] ihpmServer (ihpmServer) . (.Copyright 2015. All rights reserved..) - C:\Program Files (x86)\RayDld\ihpmServer.exe
SR - Auto [2015/10/08 10:39:11] [ 3000824] uauEEWZ (uauEEWZ) . (.Irrational Number Applications.) - C:\ProgramData\stVjnfds\uauEEWZ.exe =>PUP.Optional.WebShield
SR - Auto [2015/10/06 15:38:44] [ 2244096] WaInterEn Monitor (WaInterEn Monitor) . (.Copyright (C) 2014.) - C:\Program Files\WaInterEn\wajam_64.exe =>PUP.Optional.Wajam

---\\ Scan Additionnel (32) - 0s
C:\Program Files (x86)\MediaPlayerVideos 1.2\mediaplayervideos_1.2_helper_service.exe =>PUP.Optional.CrossRider
C:\Program Files (x86)\Fast-Search\acengine.exe =>PUP.Optional.Abengine
C:\Program Files\WaInterEn\wajam_64.exe =>PUP.Optional.Wajam
C:\ProgramData\stVjnfds\uauEEWZ.exe =>PUP.Optional.WebShield
C:\WINDOWS\system32\acengine64.dll =>Hijacker.Winsock
HKLM\SYSTEM\CurrentControlSet\Services\acengine =>PUP.Optional.Abengine
HKLM\SYSTEM\CurrentControlSet\Services\uauEEWZ =>PUP.Optional.WebShield
HKLM\SYSTEM\CurrentControlSet\Services\WaInterEn Monitor =>PUP.Optional.Wajam
C:\Program Files (x86)\MediaPlayerVideos 1.2\mediaplayervideos_1.2_updating_service.exe =>PUP.Optional.CrossRider
C:\ProgramData\Nneledoh\1.0.6.1\iirubsao.exe =>Heuristic.PullUpdate
C:\WINDOWS\Tasks\mediaplayervideos_1.2_helper_service.job =>PUP.Optional.CrossRider
C:\WINDOWS\Tasks\mediaplayervideos_1.2_updating_service.job =>PUP.Optional.CrossRider
C:\WINDOWS\System32\Tasks\mediaplayervideos_1.2_helper_service =>PUP.Optional.CrossRider
C:\WINDOWS\System32\Tasks\mediaplayervideos_1.2_updating_service =>PUP.Optional.CrossRider
C:\WINDOWS\System32\Tasks\Nneledoh =>Heuristic.PullUpdate
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MediaPlayerVideos 1.2 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch =>PUP.Optional.StartSearch
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WaInterEn =>PUP.Optional.Wajam
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WebShield =>PUP.Optional.WebShield
HKLM\SOFTWARE\Wow6432Node\mystartsearchSoftware =>PUP.Optional.StartSearch
HKCU\SOFTWARE\WajIEnhance =>PUP.Optional.Wajam
HKCU\SOFTWARE\AppDataLow\Software\DynConIE =>PUP.Optional.DynConIE
C:\Program Files (x86)\MediaPlayerVideos 1.2 =>PUP.Optional.CrossRider
C:\ProgramData\WebShield =>PUP.Optional.WebShield
C:\Users\chris_000\AppData\Roaming\mystartsearch =>PUP.Optional.StartSearch
C:\Users\chris_000\AppData\Local\WebShield =>PUP.Optional.WebShield
C:\WINDOWS\Prefetch\ACENGINE.EXE-2DAEF85F.pf =>PUP.Optional.Abengine
C:\WINDOWS\Prefetch\WAJAM.EXE-1C99DDFE.pf =>PUP.Optional.Wajam
C:\WINDOWS\Prefetch\WAJAM_64.EXE-310E257B.pf =>PUP.Optional.Wajam
C:\WINDOWS\Prefetch\WEBSHIELDINSTALL.EXE-81D4DEA4.pf =>PUP.Optional.WebShield
C:\WINDOWS\System32\drivers\acwfp64.sys =>PUP.Optional.Abengine
C:\Users\chris_000\AppData\Roaming\mystartsearch\Uninstall.exe =>PUP.Optional.StartSearch

---\\ Récapitulatif des éléments trouvées sur votre station (7) - 0s
http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider
http://www.nicolascoolman.fr/blog =>PUP.Optional.Abengine
http://www.nicolascoolman.fr/pup-wajam/ =>PUP.Optional.Wajam
http://www.nicolascoolman.fr/blog =>PUP.Optional.WebShield
http://www.nicolascoolman.fr/pup-optional-startsearch/ =>PUP.Optional.StartSearch
http://www.nicolascoolman.fr/blog =>Heuristic.PullUpdate
http://www.nicolascoolman.fr/blog =>PUP.Optional.DynConIE

~ End of the scan, 12295 items in 51 seconds (621)(0)()

Publicité


Signaler le contenu de ce document

Publicité