~ ZHPDiag v2015.9.17.143 Par Nicolas Coolman (2015/09/19) ~ Démarré par HP (Administrator) (2015/09/19 15:22:01) ~ Site: http://www.nicolascoolman.fr ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Etat de la version: Version OK ~ Mode: Scanner ~ Rapport: C:\Users\HP\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\HP\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ Démarrage du système: Normal (Normal boot) Windows 7 Home Premium N, 64-bit Service Pack 1 (Build 7601) ---\\ Navigateurs Internet (4) - 0s GCIE: Google Chrome v45.0.2454.93 MFIE: Mozilla Firefox 30.0 (x86 fr) v30.0 OPIE: Opera 32.0.1948.25 v32.0.1948.25 MSIE: Internet Explorer v9.0.8112.16421 ---\\ Informations sur les produits Windows (4) - 5s ~ Windows Server License Manager Script : OK System - VBScript Engine not found Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ Logiciels de protection (2) - 65s Malwarebytes Anti-Malware version 1.75.0.1300 Windows Defender W7 (Activate) ---\\ Logiciels d'optimisation (1) - 66s CCleaner v4.14 ---\\ Surveillance de Logiciels (2) - 66s Adobe Flash Player 9 ActiveX Adobe Reader 8.1.2 - Français ---\\ Informations sur le système (6) - 0s ~ Operating System: AMD64 Family 20 Model 1 Stepping 0, AuthenticAMD ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 1682.332 MB (15% free) ~ System Restore: Activé (Enable) ~ System drive C: has 50 GB free of 119 GB ---\\ Mode de connexion au système (3) - 0s ~ Computer Name: HP-PC ~ User Name: HP ~ Logged in as Administrator ---\\ Enumération des unités disques (4) - 0s ~ Drive C: has 50 GB free of 119 GB (System) ~ Drive D: has 105 GB free of 119 GB ~ Drive E: has 0 GB free of 0 GB ~ Drive F: has GB free of 3 GB ---\\ Etat du Centre de Sécurité Windows (14) - 1s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableRegistryTools: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ---\\ Recherche particulière de fichiers génériques (25) - 6s [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\Windows\Explorer.exe [2871808] © [MD5.DD81D91FF3B0763C392422865C9AC12E] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\Windows\System32\rundll32.exe [45568] © [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\Windows\System32\Wininit.exe [129024] © [MD5.A2E24197853DF27F5799BDA2F6D5A904] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\Windows\System32\wininet.dll [1392128] © [MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - (.Microsoft Corporation - Application d’ouverture de session Windows.) () -- C:\Windows\System32\Winlogon.exe [455168] © [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) () -- C:\Windows\System32\sppcomapi.dll [232448] © [MD5.492D07D79E7024CA310867B526D9636D] - (.Microsoft Corporation - DNS DLL de l’API Client.) () -- C:\Windows\System32\dnsapi.dll [357888] © [MD5.B40420876B9288E0A1C8CCA8A84E5DC9] - (.Microsoft Corporation - DNS DLL de l’API Client.) () -- C:\Windows\Syswow64\dnsapi.dll [270336] © [MD5.0D57D091E06BB1E58E72E5D08479FDDF] - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) () -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] © [MD5.FA886682CFC5D36718D3E436AACF10B9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\Windows\System32\drivers\AFD.sys [497152] © [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\Windows\System32\drivers\atapi.sys [24128] © [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\Windows\System32\drivers\Cdfs.sys [92160] © [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\Windows\System32\drivers\Cdrom.sys [147456] © [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\Windows\System32\drivers\DfsC.sys [102400] © [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\Windows\System32\drivers\HDAudBus.sys [122368] © [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\Windows\System32\drivers\i8042prt.sys [105472] © [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\Windows\System32\drivers\IpNat.sys [116224] © [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\Windows\System32\drivers\MRxSmb.sys [158208] © [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\Windows\System32\drivers\netBT.sys [261632] © [MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\Windows\System32\drivers\ntfs.sys [1684928] © [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\Windows\System32\drivers\Parport.sys [97280] © [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\Windows\System32\drivers\Rasl2tp.sys [129536] © [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) () -- C:\Windows\System32\drivers\smb.sys [93184] © [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\Windows\System32\drivers\tdx.sys [119296] © [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\Windows\System32\drivers\volsnap.sys [295808] © ---\\ Processus lancés (34) - 35s [MD5.7A094E697E8B7B4B495AFA3D522A8E8D] - (.Beijing Rising Information Technology Co., Ltd. - RsMgrSvc Application.) -- C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe [196288] [PID.768] © [MD5.99490F146FF04911DA9C7F9457E2AD5A] - (.Beijing Rising Information Technology Co., Ltd. - ravmond.) -- C:\Program Files (x86)\Rising\RAV\RavMonD.exe [264448] [PID.856] © [MD5.FC5B75CA6A1DA31EDD4F8D53F5540B98] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [81088] [PID.1520] © [MD5.221564CC7BE37611FE15EACF443E1BF6] - (.Apple Inc. - YSLoader.exe.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [43336] [PID.1552] © [MD5.EBBCD5DFBB1DE70E8F4AF8FA59E401FD] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [462184] [PID.1672] © [MD5.4E9CAE3200A46135DE01CE22BAF832BE] - (.HP - HP Smart-Install Service.) -- C:\Windows\system32\HPSIsvc.exe [127800] [PID.1700] © [MD5.E90DA42B87D684DEBFB73B38A718A006] - (.Copyright (C) 2008 - DCSHOST.) -- C:\ProgramData\DatacardService\HWDeviceService64.exe [346976] [PID.1736] [MD5.65085456FD9A74D7F1A999520C299ECB] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376] [PID.1776] © [MD5.E0D7732F2D2E24B2DB3F67B6750295B8] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512] [PID.1804] © [MD5.0AF74CD12F12F3DCAB26C1F5C09AB79A] - (...) -- C:\ProgramData\TigoNet\OnlineUpdate\ouc.exe [234496] [PID.1932] [MD5.622FCF264119F7DF127BE353F796B319] - (.COMPANYVERS_NAME - PRODUCTVERS_TITLE.) -- C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe [42504] [PID.1944] =>PUP.Optional.VideoDownloadConverter [MD5.AB6E5B9333101E414D8F04BC570064F1] - (.Intel Corporation - Intel® Centrino® Wireless Bluetooth® 3.0 +.) -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [659968] [PID.992] © [MD5.588762F716C2B7A2054AFBC3D58E5C21] - (.Intel(R) Corporation - Intel(R) BlueTooth(R) HS Security Manager S.) -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [135952] [PID.2344] © [MD5.D1D5DAB39DCB4BE0359943738D87409B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [532040] [PID.1112] © [MD5.349AB4F70E2AC44970894E7F03E1576E] - (.Huawei Technologies Co., Ltd. - DataCardMonitor MFC Application.) -- C:\ProgramData\DatacardService\DCSHelper.exe [236384] [PID.1032] © [MD5.02555AAE46B904A77A4E48E0FD11EA1B] - (.DT Soft Ltd - DAEMON Tools Shell Extensions Helper.) -- C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe [382272] [PID.3000] © [MD5.6E4020D918F14049188E0D8B5BB27F27] - (.DT Soft Ltd - DAEMON Tools Pro Agent.) -- C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [842048] [PID.1596] © [MD5.BDDC15805B7E16FF043CECA648653AE4] - (.ManyCam LLC - ManyCam Virtual Webcam.) -- C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe [5408080] [PID.2284] © [MD5.43539A629C06FF5F1B4BBF5DF1BE2EC1] - (.Pay By Ads LTD - .) -- C:\Users\HP\AppData\Local\onlysearch\onlysearch\1.3.26.12\onlysearch.exe [660736] [PID.2312] =>PUP.Optional.OnlySearch [MD5.D3AE1A1CF8DE0E56FD0656825BA5AAD8] - (.Copyright (C) 2000 - Application MFC hyperappel.) -- C:\Program Files (x86)\Larousse\Petit Larousse 2010\bin\Hyperappel.exe [237568] [PID.2848] [MD5.F173BAE1189317A00FC254F495261A21] - (.Babylon Ltd. - Babylon Information Tool.) -- C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe [3656272] [PID.3044] =>PUP.Optional.Babylon [MD5.9FC8D62CD7E5C9DB50B515C26B968E00] - (.Beijing Rising Information Technology Co., Ltd. - tray 应用程序.) -- C:\Program Files (x86)\Rising\RSD\popwndexe.exe [126808] [PID.1436] © [MD5.D65ADC7AD95E88FAB486707B8C228F17] - (.Beijing Rising Information Technology Co., Ltd. - Rising tray framework.) -- C:\Program Files (x86)\Rising\RAV\RsTray.exe [178840] [PID.588] © [MD5.D2E3E6D94A9E1CFA1561D9C748136FD0] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392] [PID.3252] © [MD5.4281BF9B8FD5F888E0671EF389DC1C8F] - (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe [3498728] [PID.3548] © [MD5.CE5C9977DA751DDC30952AC4DCBCA788] - (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208] [PID.3780] © [MD5.96AA8ECA99C90C07F64AB0FE60B6F7F1] - (.BlackBerry Limited - Launch Agent Service.) -- C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [443640] [PID.3668] [MD5.FBCF6C6B5FF25AFC7A9CBE485ABFCF6E] - (.BlackBerry Limited - BlackBerry Device Manager.) -- C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [588024] [PID.3456] [MD5.835FC2EA0631B734BB06C12B0665F01D] - (.Apple Inc. - iPodService Module (64-bit).) -- C:\Program Files\iPod\bin\iPodService.exe [641352] [PID.2528] © [MD5.637E3B556D125F6029AED4D24BFDB5D1] - (.Babylon - Support for 64-bit OS.) -- C:\Program Files\Babylon\Babylon-Pro\BabylonHelper64.exe [129024] [PID.3476] =>PUP.Optional.Babylon [MD5.B1E01D636350983E94171E229C759468] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [275568] [PID.4616] © [MD5.3E04F1E482357B1FC8B088197C3D9FF8] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152] [PID.5004] © [MD5.B087EF1FC51DD028A255C134E465DA21] - (.Pay By Ads LTD - .) -- C:\Users\HP\AppData\Local\onlysearch\onlysearch\1.3.26.12\onlysetup.exe [457472] [PID.4456] =>PUP.Optional.OnlySearch [MD5.F9AF5292174EC3D8D6A4EAA33C2321B4] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\HP\Downloads\ZHPDiag3.exe [1934848] [PID.4556] © ---\\ Google Chrome, Démarrage,Recherche,Extensions (16) - 4s G0 - GCSP: Preferences [User Data\Default][HomePage] http://r15---sn-woc7en7s.gvt1.com/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://r20---sn-woc7en7z.gvt1.com/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://redirector.gvt1.com/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://clients2.google.com/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://clients2.googleusercontent.com/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.cd/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.googleapis.com/ G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.google.com/ G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [efaidnbmnnnibpcajpcglclefindmkaj] __MSG_web2pdfExtnName__ G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc. ---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (18) - 7s M0 - MFSP: prefs.js [HP - dptezhql.default] http://www.only-search.com/?babsrc=HP_kms&affID=970000001 =>PUP.Optional.OnlySearch P2 - EXT FILE: (...) -- C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\dptezhql.default\searchplugins\ask-web-search.xml P2 - EXT FILE: (...) -- C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\dptezhql.default\searchplugins\buenosearch.xml =>PUP.Optional.BuenoSearch P2 - EXT FILE: (...) -- C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\dptezhql.default\searchplugins\google-avast.xml P2 - EXT FILE: (...) -- C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\dptezhql.default\searchplugins\onlysearchkms1.xml =>PUP.Optional.OnlySearch P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\amazon-france.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\bing.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\eBay-france.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\google.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\yahoo-france.xml P2 - EXT: (.Mozilla - Default.) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} © P2 - EXT: (.Mindspark - VideoScavenger.) -- C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\dptezhql.default\extensions\1effxtbr@www.videoscavenger.com P2 - EXT: (...) -- C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\dptezhql.default\extensions\staged P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll © P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Apple Inc..) -- C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll © P2 - FPN: [HKLM] [@VideoDownloadConverter_4z.com/Plugin] - (.MindSpark.) -- C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll =>PUP.Optional.VideoDownloadConverter ---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (16) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.only-search.com/ =>PUP.Optional.OnlySearch R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = about:newtab R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = about:newtab R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R3 - URLSearchHook: (no name) - {D8278076-BC68-4484-9233-6E7F1628B56C} Orphean R3 - URLSearchHook: (no name) - {93a3111f-4f74-4ed8-895e-d9708497629e} Orphean R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer ---\\ Internet Explorer,Proxy Management (5) - 1s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) ---\\ Etude du fichier hosts (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (21) ---\\ Browser Helper Object de navigateur (BHO) (3) - 1s O2 - BHO: (no name) [64Bits] - {4D594332-2D56-3700-76A7-7A786E7484D7} (Orphean) O2 - BHO: Adobe Acrobat Create PDF Helper [64Bits] - {AE7CD045-E861-484f-8273-0445EE161910} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll © O2 - BHO: SmartSelect [64Bits] - {F4971EE7-DAA0-4053-9964-665D8EE6A077} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll © ---\\ Internet Explorer, Barre d'outil (4) - 0s O3 - Toolbar: 0x3243594D562D003776A77A786E7484D7 - [HKCU]{4D594332-2D56-3700-76A7-7A786E7484D7} . (...) -- (.not file.) O3 - Toolbar: (no name) - [HKLM]{48586425-6bb7-4f51-8dc6-38c88e3ebb58} (Orphean) (.not file.) O3 - Toolbar: (no name) - [HKLM]{4D594332-2D56-3700-76A7-7A786E7484D7} (Orphean) (.not file.) O3 - Toolbar: buenosearch Toolbar - [HKLM]{828DC97A-2277-4E10-92A9-4907FA0922A9} . (...) -- (.not file.) =>PUP.Optional.BuenoSearch ---\\ Applications lancées au démarrage du système (23) - 4s O4 - HKLM\..\Run: [VideoDownloadConverter Home Page Guard 64 bit] C:\PROGRA~2\VIDEOD~2\bar\1.bin\AppIntegrator64.exe (.not file.) O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe © O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] . (.DT Soft Ltd - DAEMON Tools Pro Agent.) -- C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe © O4 - HKCU\..\Run: [E09FXLRD_1501852] . (.Microsoft Corporation - Microsoft Encarta Dictionaries.) -- C:\Program Files (x86)\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\EDICT.EXE © O4 - HKCU\..\Run: [ManyCam] . (.ManyCam LLC - ManyCam Virtual Webcam.) -- C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe © O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe © O4 - HKCU\..\Run: [Only-search] . (.Pay By Ads LTD - .) -- C:\Users\HP\AppData\Local\onlysearch\onlysearch\1.3.26.12\onlysearch.exe =>PUP.Optional.OnlySearch O4 - HKLM\..\Wow6432Node\Run: [Babylon Client] . (.Babylon Ltd. - Babylon Information Tool.) -- C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe =>PUP.Optional.Babylon O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe © O4 - HKLM\..\Wow6432Node\Run: [RSDTRAY] . (.Beijing Rising Information Technology Co., Ltd. - tray 应用程序.) -- C:\Program Files (x86)\Rising\RSD\popwndexe.exe © O4 - HKLM\..\Wow6432Node\Run: [RavTRAY] . (.Beijing Rising Information Technology Co., Ltd. - Rising tray framework.) -- C:\Program Files (x86)\Rising\RAV\RsTray.exe © O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe © O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\sidebar.exe © O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\sidebar.exe © O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe © O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe © O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe © O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe © O4 - HKUS\S-1-5-21-1376588600-2814803266-276705316-1000\..\Run: [DAEMON Tools Pro Agent] . (.DT Soft Ltd - DAEMON Tools Pro Agent.) -- C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe © O4 - HKUS\S-1-5-21-1376588600-2814803266-276705316-1000\..\Run: [E09FXLRD_1501852] . (.Microsoft Corporation - Microsoft Encarta Dictionaries.) -- C:\Program Files (x86)\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\EDICT.EXE © O4 - HKUS\S-1-5-21-1376588600-2814803266-276705316-1000\..\Run: [ManyCam] . (.ManyCam LLC - ManyCam Virtual Webcam.) -- C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe © O4 - HKUS\S-1-5-21-1376588600-2814803266-276705316-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe © O4 - HKUS\S-1-5-21-1376588600-2814803266-276705316-1000\..\Run: [Only-search] . (.Pay By Ads LTD - .) -- C:\Users\HP\AppData\Local\onlysearch\onlysearch\1.3.26.12\onlysearch.exe =>PUP.Optional.OnlySearch ---\\ Raccourcis Global Startup (4) - 20s O4 - GS\Quicklaunch [Administrateur]: Babylon.lnk . (.Babylon Ltd. - Babylon Information Tool.) C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe =>PUP.Optional.Babylon O4 - GS\Quicklaunch [HP]: Babylon.lnk . (.Babylon Ltd. - Babylon Information Tool.) C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe =>PUP.Optional.Babylon O4 - GS\Quicklaunch [Invité]: Babylon.lnk . (.Babylon Ltd. - Babylon Information Tool.) C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe =>PUP.Optional.Babylon O4 - GS\CommonDesktop [Public]: Babylon.lnk . (.Babylon Ltd. - Babylon Information Tool.) C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe =>PUP.Optional.Babylon ---\\ Modification Domaine/Adresses DNS (12) - 2s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.4.4 =>.Google Public DNS O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.88.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 81.199.168.3 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.4.4 =>.Google Public DNS O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 10.108.4.130 194.7.1.4 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.85.1 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.4.4 =>.Google Public DNS O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 192.168.88.1 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 81.199.168.3 O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.4.4 =>.Google Public DNS O17 - HKLM\System\CS3\Services\Tcpip\Parameters: DhcpNameServer = 192.168.88.1 O17 - HKLM\System\CS3\Services\Tcpip\Parameters: DhcpNameServer = 81.199.168.3 ---\\ Protocole additionnel (21) - 2s O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll © O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll © O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll © O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll © O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll © O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll © O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll © O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll © O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL © ---\\ Liste des services NT non Microsoft et non désactivés (14) - 3s O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe © O23 - Service: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Servi (AMPPALR3) . (.Intel Corporation - Intel® Centrino® Wireless Bluetooth® 3.0 +.) - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe © O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - YSLoader.exe.) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe © O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe © O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed (BTHSSecurityMgr) . (.Intel(R) Corporation - Intel(R) BlueTooth(R) HS Security Manager S.) - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe © O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe © O23 - Service: HP SI Service (HPSIService) . (.HP - HP Smart-Install Service.) - C:\Windows\system32\HPSIsvc.exe © O23 - Service: HWDeviceService64.exe (HWDeviceService64.exe) . (.Copyright (C) 2008 - DCSHOST.) - C:\ProgramData\DatacardService\HWDeviceService64.exe O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe © O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe © O23 - Service: Rsd Service (RsMgrSvc) . (.Beijing Rising Information Technology Co., Ltd. - RsMgrSvc Application.) - C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe © O23 - Service: Rav Service (RsRavMon) . (.Beijing Rising Information Technology Co., Ltd. - ravmond.) - C:\Program Files (x86)\Rising\RAV\RavMonD.exe © O23 - Service: TigoNet. OUC (TigoNet. RunOuc) . (...) - C:\Program Files (x86)\TigoNet\UpdateDog\ouc.exe O23 - Service: VideoDownloadConverterService (VideoDownloadConverter_4zService) . (.COMPANYVERS_NAME - PRODUCTVERS_TITLE.) - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe =>PUP.Optional.VideoDownloadConverter ---\\ Enumère les données de BootExecute (1) - 0s O34 - HKLM BootExecute: ( bsmain) ---\\ Logiciels installés (57) - 46s O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner © O42 - Logiciel: HP LaserJet Professional M1130-M1210 MFP Series - (...) [HKLM][64Bits] -- HP LaserJet Professional M1130-M1210 MFP Series O42 - Logiciel: Recuva - (.Piriform.) [HKLM][64Bits] -- Recuva © O42 - Logiciel: TeraCopy 2.07 beta - (.Code Sector Inc..) [HKLM][64Bits] -- TeraCopy_is1 O42 - Logiciel: WinRAR 5.01 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver © O42 - Logiciel: Barre de recherche Encarta (64 bits) - (.Microsoft.) [HKLM][64Bits] -- {08184040-959A-4B0D-8825-2C533F0DDB19} © O42 - Logiciel: Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed - (.Intel Corporation.) [HKLM][64Bits] -- {2C0E6BD4-65B1-4E82-B2AC-43EFFC8F100C} © O42 - Logiciel: Étude pour l'amélioration du produit HP Deskjet 1000 J110 series - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {39268F0B-E97D-4C92-97B7-11A32F0F2999} © O42 - Logiciel: Canon MF4700 Series - (.CANON INC..) [HKLM][64Bits] -- {47A8DB42-4E21-4d55-9931-D4F44CC3F03B} © O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM][64Bits] -- {5A68A656-979F-4168-8795-E2E368AA4DC2} © O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] -- {6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D} © O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM][64Bits] -- {787136D2-F0F8-4625-AA3F-72D7795AC842} © O42 - Logiciel: Logiciel de base du périphérique HP Deskjet 1000 J110 series - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {A47ED3FB-6BFC-4EC3-8C32-B4730B5C09D8} © O42 - Logiciel: Scan To - (.HP.) [HKLM][64Bits] -- {E8A34AC8-0137-4515-A94B-0A0946DDC251} © O42 - Logiciel: Adobe Flash Player 14 Plugin - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player Plugin © O42 - Logiciel: Free Bible 0.92 - (.BibleGratuite.org.) [HKLM][64Bits] -- BibleGratuite_is1 O42 - Logiciel: BlackBerry Device Manager 8.0 - (.BlackBerry Ltd..) [HKLM][64Bits] -- BlackBerry_HandheldManager O42 - Logiciel: DAEMON Tools Pro - (.DT Soft Ltd.) [HKLM][64Bits] -- DAEMON Tools Pro © O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome © O42 - Logiciel: HP Photo Creations - (.HP.) [HKLM][64Bits] -- HP Photo Creations © O42 - Logiciel: Malwarebytes Anti-Malware version 1.75.0.1300 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes' Anti-Malware_is1 © O42 - Logiciel: ManyCam 3.1.64 - (.ManyCam LLC.) [HKLM][64Bits] -- ManyCam © O42 - Logiciel: Mortal Kombat 4 - www.classic-gaming.net - (.Classic Gaming Network.) [HKLM][64Bits] -- Mortal Kombat 4_is1 O42 - Logiciel: Mozilla Firefox 30.0 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 30.0 (x86 fr) © O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService © O42 - Logiciel: Nero 8 Lite 8.3.2.1b - (.Updatepack.nl.) [HKLM][64Bits] -- Nero8Lite_is1 O42 - Logiciel: Opera Stable 32.0.1948.25 - (.Opera Software.) [HKLM][64Bits] -- Opera 32.0.1948.25 © O42 - Logiciel: Sweet Home 3D version 3.3 - (.eTeks.) [HKLM][64Bits] -- Sweet Home 3D_is1 © O42 - Logiciel: TigoNet - (.Huawei Technologies Co.,Ltd.) [HKLM][64Bits] -- TigoNet © O42 - Logiciel: VLC media player 2.1.3 - (.VideoLAN.) [HKLM][64Bits] -- VLC media player © O42 - Logiciel: Warid Mobile Partner - (.Huawei Technologies Co.,Ltd.) [HKLM][64Bits] -- Warid Mobile Partner © O42 - Logiciel: Logiciel d'archivage WinRAR - (...) [HKLM][64Bits] -- WinRAR archiver O42 - Logiciel: Microsoft Encarta 2009 - Collection - (.Microsoft Corporation.) [HKLM][64Bits] -- {09180081-2C94-4A67-8E55-8483C019C7D2} © O42 - Logiciel: BlackBerry Device Manager 8.0 - (.BlackBerry Ltd..) [HKLM][64Bits] -- {35724492-A89F-40BD-9CB0-51C3FFDE9035} O42 - Logiciel: Petit Larousse 2010 - (...) [HKLM][64Bits] -- {422FADA9-FED2-41D7-B5FA-472BB98B7784} O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM][64Bits] -- {51C7AD07-C3F6-4635-8E8A-231306D810FE} © O42 - Logiciel: Adobe Flash Player 9 ActiveX - (.Adobe Systems, Inc..) [HKLM][64Bits] -- {58BAA8D0-404E-4585-9FD3-ED1BB72AC2EE} © O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} © O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM][64Bits] -- {64BF0187-F3D2-498B-99EA-163AF9AE6EC9} © O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM][64Bits] -- {6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5} © O42 - Logiciel: Analyseur et SDK MSXML 4.0 SP2 - (.Microsoft Corporation.) [HKLM][64Bits] -- {716E0306-8318-4364-8B8F-0CC4E9376BAC} © O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM][64Bits] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} © O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM][64Bits] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71} © O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} © O42 - Logiciel: TypingMaster Pro - (.TypingMaster Inc.) [HKLM][64Bits] -- {98B6FB8A-8638-4037-AD44-CF7D0EEAB875}_is1 O42 - Logiciel: REALTEK Wireless LAN Driver - (.REALTEK Semiconductor Corp..) [HKLM][64Bits] -- {9D3D8C60-A55F-4123-B2B9-173F09590E16} © O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} © O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001802114130} © O42 - Logiciel: Adobe Acrobat XI Pro - (.Adobe Systems.) [HKLM][64Bits] -- {AC76BA86-1033-FFFF-7760-000000000006} © O42 - Logiciel: Adobe Reader 8.1.2 - Français - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1036-7B44-A81200000003} © O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM][64Bits] -- {D9DAD0FF-495A-472B-9F10-BAE430A26682} © O42 - Logiciel: HP Deskjet 1000 J110 series Aide - (.Hewlett Packard.) [HKLM][64Bits] -- {DDDFCC77-7F9C-45E9-B38E-721BA599BA0C} © O42 - Logiciel: jetAudio - (...) [HKLM][64Bits] -- {DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A} O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM][64Bits] -- {ED5776D5-59B4-46B7-AF81-5F2D94D7C640} © O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM][64Bits] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC} © O42 - Logiciel: Only-search - (.onlysearch.) [HKCU][64Bits] -- onlysearch =>PUP.Optional.OnlySearch O42 - Logiciel: Unity Web Player - (.Unity Technologies ApS.) [HKCU][64Bits] -- UnityWebPlayer © ---\\ HKCU & HKLM Software Keys (94) - 46s HKLM\SOFTWARE\Wow6432Node\Adobe HKLM\SOFTWARE\Wow6432Node\Ahead HKLM\SOFTWARE\Wow6432Node\Apple Computer, Inc. HKLM\SOFTWARE\Wow6432Node\Apple Inc. HKLM\SOFTWARE\Wow6432Node\Babylon =>PUP.Optional.Babylon HKLM\SOFTWARE\Wow6432Node\buenosearch LTD =>PUP.Optional.BuenoSearch HKLM\SOFTWARE\Wow6432Node\Canon HKLM\SOFTWARE\Wow6432Node\COWON HKLM\SOFTWARE\Wow6432Node\DT Soft HKLM\SOFTWARE\Wow6432Node\FlashGet Network HKLM\SOFTWARE\Wow6432Node\Google HKLM\SOFTWARE\Wow6432Node\GT Interactive HKLM\SOFTWARE\Wow6432Node\Havas Interactive HKLM\SOFTWARE\Wow6432Node\Hewlett-Packard HKLM\SOFTWARE\Wow6432Node\HewlettPackard HKLM\SOFTWARE\Wow6432Node\Huawei technologies HKLM\SOFTWARE\Wow6432Node\Intel HKLM\SOFTWARE\Wow6432Node\JavaSoft HKLM\SOFTWARE\Wow6432Node\JreMetrics HKLM\SOFTWARE\Wow6432Node\KONAMIPES5 HKLM\SOFTWARE\Wow6432Node\Larousse HKLM\SOFTWARE\Wow6432Node\Licenses HKLM\SOFTWARE\Wow6432Node\Macromedia HKLM\SOFTWARE\Wow6432Node\Macrovision HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware (Trial) HKLM\SOFTWARE\Wow6432Node\ManyCam HKLM\SOFTWARE\Wow6432Node\MAXSOFT-OCRON HKLM\SOFTWARE\Wow6432Node\mcafeeupdater HKLM\SOFTWARE\Wow6432Node\Mozilla HKLM\SOFTWARE\Wow6432Node\mozilla.org HKLM\SOFTWARE\Wow6432Node\MozillaPlugins HKLM\SOFTWARE\Wow6432Node\Nero HKLM\SOFTWARE\Wow6432Node\ODBC HKLM\SOFTWARE\Wow6432Node\Research In Motion HKLM\SOFTWARE\Wow6432Node\rising HKLM\SOFTWARE\Wow6432Node\RocketLife HKLM\SOFTWARE\Wow6432Node\RtWLan HKLM\SOFTWARE\Wow6432Node\Skype HKLM\SOFTWARE\Wow6432Node\TypingMaster Inc HKLM\SOFTWARE\Wow6432Node\VideoDownloadConverter_4z =>PUP.Optional.MindSpark HKLM\SOFTWARE\Wow6432Node\VideoLAN HKLM\SOFTWARE\Wow6432Node\Visan HKLM\SOFTWARE\Wow6432Node\WinRAR HKLM\SOFTWARE\Wow6432Node\RegisteredApplications HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\APN PIP =>PUP.Optional.Conduit HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\Apple Computer, Inc. HKCU\SOFTWARE\Apple Inc. HKCU\SOFTWARE\AskPartnerNetwork =>Toolbar.AskBar HKCU\SOFTWARE\BabSolution =>PUP.Optional.BabSolution HKCU\SOFTWARE\Babylon =>PUP.Optional.Babylon HKCU\SOFTWARE\buenosearch LTD =>PUP.Optional.BuenoSearch HKCU\SOFTWARE\Code Sector HKCU\SOFTWARE\COWON HKCU\SOFTWARE\DriverToolkit =>PUP.Optional.DriverToolkit HKCU\SOFTWARE\DT Soft HKCU\SOFTWARE\Google HKCU\SOFTWARE\Hewlett-Packard HKCU\SOFTWARE\HotHouse Creations Ltd HKCU\SOFTWARE\HP HKCU\SOFTWARE\Intel HKCU\SOFTWARE\JEDI-VCL HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\Malwarebytes' Anti-Malware HKCU\SOFTWARE\ManyCam HKCU\SOFTWARE\MCAFEE HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\Nero HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\Opera Software HKCU\SOFTWARE\PC Speed Maximizer =>PUP.Optional.PCSpeedMaximizer HKCU\SOFTWARE\Piriform HKCU\SOFTWARE\PopCap HKCU\SOFTWARE\Research In Motion HKCU\SOFTWARE\Rising HKCU\SOFTWARE\ShieldBt HKCU\SOFTWARE\SMADΔV HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\Unity HKCU\SOFTWARE\VideoDownloadConverter_4z =>PUP.Optional.MindSpark HKCU\SOFTWARE\Visicom Media Inc HKCU\SOFTWARE\WinRAR HKCU\SOFTWARE\WinRAR SFX HKCU\SOFTWARE\Wow6432Node HKCU\SOFTWARE\WPI HKCU\SOFTWARE\yahooinstall HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\Unity HKCU\SOFTWARE\AppDataLow\Software\VideoDownloadConverter_4z =>PUP.Optional.MindSpark ---\\ Contenu des dossiers Programmes (214) - 260s O43 - CFD: 2014/07/08 08:27:56 - [] D -- C:\Program Files (x86)\Adobe O43 - CFD: 2014/02/10 15:02:12 - [] D -- C:\Program Files (x86)\Apple Software Update O43 - CFD: 2013/08/23 18:51:16 - [] D -- C:\Program Files (x86)\AskPartnerNetwork =>Toolbar.AskBar O43 - CFD: 2013/03/13 13:52:34 - [] D -- C:\Program Files (x86)\AVG O43 - CFD: 2014/01/09 17:38:56 - [] D -- C:\Program Files (x86)\Babylon =>PUP.Optional.Babylon O43 - CFD: 2013/02/09 08:53:00 - [] D -- C:\Program Files (x86)\BibleGratuite O43 - CFD: 2014/02/10 15:00:17 - [] D -- C:\Program Files (x86)\Bonjour O43 - CFD: 2014/01/09 17:01:18 - [] D -- C:\Program Files (x86)\buenosearch LTD =>PUP.Optional.BuenoSearch O43 - CFD: 2014/01/17 18:45:35 - [] D -- C:\Program Files (x86)\CGN O43 - CFD: 2013/03/20 18:10:13 - [] D -- C:\Program Files (x86)\Cisco O43 - CFD: 2015/07/28 15:25:34 - [] D -- C:\Program Files (x86)\Common Files O43 - CFD: 2013/03/20 18:16:28 - [] D -- C:\Program Files (x86)\DAEMON Tools Pro O43 - CFD: 2013/02/11 16:49:08 - [] D -- C:\Program Files (x86)\directx O43 - CFD: 2014/07/22 14:36:51 - [] D -- C:\Program Files (x86)\DriverToolkit =>PUP.Optional.DriverToolkit O43 - CFD: 2014/10/13 07:20:12 - [] D -- C:\Program Files (x86)\Google O43 - CFD: 2013/05/16 09:31:12 - [] D -- C:\Program Files (x86)\GUM1A63.tmp O43 - CFD: 2013/10/04 16:48:45 - [] D -- C:\Program Files (x86)\GUM2FE5.tmp O43 - CFD: 2014/07/30 17:00:57 - [] D -- C:\Program Files (x86)\Hewlett-Packard O43 - CFD: 2014/07/30 16:59:24 - [] D -- C:\Program Files (x86)\HP O43 - CFD: 2014/07/30 17:00:53 - [] D -- C:\Program Files (x86)\HP Photo Creations O43 - CFD: 2013/03/20 18:10:16 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information O43 - CFD: 2014/10/23 17:12:36 - [] D -- C:\Program Files (x86)\Internet Explorer O43 - CFD: 2014/05/30 12:37:50 - [] D -- C:\Program Files (x86)\iTunes O43 - CFD: 2013/03/20 18:16:29 - [] D -- C:\Program Files (x86)\JetAudio O43 - CFD: 2013/03/20 18:10:24 - [] D -- C:\Program Files (x86)\Larousse O43 - CFD: 2015/09/18 16:11:05 - [] D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware O43 - CFD: 2013/12/05 16:06:26 - [] D -- C:\Program Files (x86)\ManyCam O43 - CFD: 2013/03/20 18:10:24 - [] D -- C:\Program Files (x86)\Microsoft Encarta O43 - CFD: 2013/09/26 17:16:25 - [] D -- C:\Program Files (x86)\Microsoft Office O43 - CFD: 2013/09/26 17:16:19 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio O43 - CFD: 2013/09/26 17:10:29 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio 8 O43 - CFD: 2013/09/26 17:17:07 - [] D -- C:\Program Files (x86)\Microsoft Works O43 - CFD: 2014/06/05 12:25:22 - [] D -- C:\Program Files (x86)\Microsoft.NET O43 - CFD: 2014/07/20 18:13:24 - [] D -- C:\Program Files (x86)\Mozilla Firefox O43 - CFD: 2014/01/17 21:34:43 - [] D -- C:\Program Files (x86)\Mozilla Firefox.bak O43 - CFD: 2014/07/20 18:13:24 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service O43 - CFD: 2013/09/26 17:16:46 - [] D -- C:\Program Files (x86)\MSBuild O43 - CFD: 2013/03/20 18:10:25 - [] D -- C:\Program Files (x86)\MSECache O43 - CFD: 2013/02/11 16:47:50 - [0] D -- C:\Program Files (x86)\MSXML 4.0 O43 - CFD: 2013/03/20 18:10:25 - [] D -- C:\Program Files (x86)\Nero O43 - CFD: 2013/03/20 15:37:21 - [] D -- C:\Program Files (x86)\Norton Internet Security O43 - CFD: 2013/03/20 15:11:22 - [] D -- C:\Program Files (x86)\NortonInstaller O43 - CFD: 2015/09/18 12:55:16 - [] D -- C:\Program Files (x86)\Opera O43 - CFD: 2013/03/20 18:10:25 - [] D -- C:\Program Files (x86)\Realtek O43 - CFD: 2013/03/20 18:10:25 - [] D -- C:\Program Files (x86)\Reference Assemblies O43 - CFD: 2015/07/28 15:25:33 - [] D -- C:\Program Files (x86)\Research In Motion O43 - CFD: 2014/04/10 14:00:56 - [] D -- C:\Program Files (x86)\Rising O43 - CFD: 2015/09/18 15:57:16 - [0] D -- C:\Program Files (x86)\SMADAV O43 - CFD: 2013/12/24 09:14:53 - [] D -- C:\Program Files (x86)\Sweet Home 3D O43 - CFD: 2013/02/09 08:54:39 - [] D -- C:\Program Files (x86)\TeraCopy O43 - CFD: 2015/08/07 14:52:05 - [] D -- C:\Program Files (x86)\TigoNet O43 - CFD: 2013/03/20 18:10:25 - [] RD -- C:\Program Files (x86)\TypingMaster O43 - CFD: 2009/07/14 05:08:21 - [0] HD -- C:\Program Files (x86)\Uninstall Information O43 - CFD: 2013/07/06 14:55:41 - [] D -- C:\Program Files (x86)\VideoDownloadConverter_4z =>PUP.Optional.VideoDownloadConverter O43 - CFD: 2013/03/20 18:10:25 - [] D -- C:\Program Files (x86)\VideoLAN O43 - CFD: 2013/06/19 21:06:09 - [] D -- C:\Program Files (x86)\Warid Mobile Partner O43 - CFD: 2014/08/02 09:08:09 - [] D -- C:\Program Files (x86)\Windows Defender O43 - CFD: 2014/07/17 12:51:56 - [] D -- C:\Program Files (x86)\Windows Mail O43 - CFD: 2013/03/20 18:10:25 - [] D -- C:\Program Files (x86)\Windows NT O43 - CFD: 2014/07/17 12:51:56 - [] D -- C:\Program Files (x86)\Windows Photo Viewer O43 - CFD: 2014/07/17 12:51:56 - [] D -- C:\Program Files (x86)\Windows Sidebar O43 - CFD: 2015/02/09 09:27:47 - [] D -- C:\Program Files (x86)\WinRAR O43 - CFD: 2013/03/20 18:19:31 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2013/03/20 18:19:27 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2014/01/09 17:39:13 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Babylon =>PUP.Optional.Babylon O43 - CFD: 2015/09/07 00:20:13 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry O43 - CFD: 2014/07/18 15:03:07 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon O43 - CFD: 2014/07/22 14:12:11 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner O43 - CFD: 2014/01/17 18:47:22 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Gaming Network O43 - CFD: 2013/02/11 16:41:12 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Pro O43 - CFD: 2014/01/14 16:50:31 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dictionnaire O43 - CFD: 2013/12/24 09:14:53 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eTeks Sweet Home 3D O43 - CFD: 2013/03/20 18:19:27 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 2014/01/09 17:14:46 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 2014/07/30 17:00:53 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP O43 - CFD: 2014/05/30 12:38:25 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes O43 - CFD: 2013/03/20 18:16:37 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jetAudio O43 - CFD: 2013/03/20 18:10:35 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Larousse O43 - CFD: 2013/03/20 18:19:27 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2015/09/18 16:11:04 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware O43 - CFD: 2013/08/23 18:47:31 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ManyCam O43 - CFD: 2014/06/02 13:21:36 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Encarta O43 - CFD: 2013/09/26 17:20:17 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office O43 - CFD: 2013/03/20 18:10:35 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero O43 - CFD: 2013/03/20 15:37:18 - [0] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security O43 - CFD: 2014/07/17 13:51:08 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva O43 - CFD: 2014/04/10 14:01:34 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rising Antivirus O43 - CFD: 2014/06/02 13:19:01 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 2009/09/01 01:31:01 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 2013/02/09 08:54:23 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy O43 - CFD: 2015/08/07 14:51:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TigoNet O43 - CFD: 2013/02/09 08:49:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TypingMaster O43 - CFD: 2014/01/16 16:58:09 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN O43 - CFD: 2013/06/19 21:05:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warid Mobile Partner O43 - CFD: 2014/01/22 23:02:48 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 2014/05/30 12:37:57 - [] D -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 O43 - CFD: 2014/11/28 14:55:27 - [] D -- C:\ProgramData\Adobe O43 - CFD: 2013/02/09 09:14:07 - [] D -- C:\ProgramData\Alwil Software O43 - CFD: 2013/08/23 18:48:03 - [] D -- C:\ProgramData\APN =>Toolbar.Ask O43 - CFD: 2014/05/30 12:11:57 - [] D -- C:\ProgramData\Apple O43 - CFD: 2014/02/10 15:04:20 - [] D -- C:\ProgramData\Apple Computer O43 - CFD: 2009/07/14 05:08:10 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 2013/08/23 18:51:16 - [] D -- C:\ProgramData\AskPartnerNetwork =>Toolbar.YahooPartner O43 - CFD: 2015/09/18 16:01:09 - [] D -- C:\ProgramData\AVAST Software O43 - CFD: 2013/03/20 18:16:16 - [] D -- C:\ProgramData\AVG Security Toolbar =>Toolbar.AVGSearch O43 - CFD: 2013/03/20 18:16:16 - [] D -- C:\ProgramData\avg9 O43 - CFD: 2015/09/19 15:20:39 - [] D -- C:\ProgramData\Babylon =>PUP.Optional.Babylon O43 - CFD: 2013/02/04 11:57:50 - [0] SHD -- C:\ProgramData\Bureau O43 - CFD: 2013/02/11 16:39:49 - [] D -- C:\ProgramData\DAEMON Tools Pro O43 - CFD: 2015/08/07 14:51:17 - [] D -- C:\ProgramData\DatacardService O43 - CFD: 2009/07/14 05:08:10 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 2009/07/14 05:08:10 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 2013/02/04 11:57:50 - [0] SHD -- C:\ProgramData\Favoris O43 - CFD: 2009/07/14 05:08:10 - [0] SHD -- C:\ProgramData\Favorites O43 - CFD: 2013/02/04 17:23:16 - [] D -- C:\ProgramData\FLEXnet O43 - CFD: 2014/07/30 16:57:44 - [] D -- C:\ProgramData\HP O43 - CFD: 2014/07/30 17:00:51 - [] D -- C:\ProgramData\HP Photo Creations O43 - CFD: 2013/02/07 06:05:42 - [0] D -- C:\ProgramData\Intel O43 - CFD: 2015/09/18 16:11:02 - [] D -- C:\ProgramData\Malwarebytes O43 - CFD: 2013/08/23 18:46:08 - [] D -- C:\ProgramData\ManyCam O43 - CFD: 2014/01/22 14:31:02 - [] D -- C:\ProgramData\McAfee O43 - CFD: 2013/02/04 11:57:50 - [0] SHD -- C:\ProgramData\Menu Démarrer O43 - CFD: 2013/09/26 17:14:52 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 2014/10/22 07:44:35 - [] D -- C:\ProgramData\Microsoft Help O43 - CFD: 2013/02/04 11:57:50 - [0] SHD -- C:\ProgramData\Modèles O43 - CFD: 2013/09/26 18:21:28 - [] D -- C:\ProgramData\Mozilla O43 - CFD: 2013/02/09 08:55:23 - [] D -- C:\ProgramData\Nero O43 - CFD: 2013/03/20 15:37:18 - [] D -- C:\ProgramData\Norton O43 - CFD: 2013/03/20 15:11:22 - [] D -- C:\ProgramData\NortonInstaller O43 - CFD: 2013/04/04 07:49:04 - [] D -- C:\ProgramData\PopCap Games O43 - CFD: 2014/07/08 08:40:14 - [] D -- C:\ProgramData\regid.1986-12.com.adobe O43 - CFD: 2014/04/06 12:25:20 - [] D -- C:\ProgramData\Rising O43 - CFD: 2013/02/07 06:05:41 - [0] D -- C:\ProgramData\Roaming O43 - CFD: 2009/07/14 05:08:10 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 2013/12/05 16:10:08 - [] D -- C:\ProgramData\Temp O43 - CFD: 2009/07/14 05:08:10 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 2015/08/07 14:54:00 - [] D -- C:\ProgramData\TigoNet O43 - CFD: 2014/07/30 17:00:49 - [] D -- C:\ProgramData\Visan O43 - CFD: 2014/07/08 08:40:13 - [] D -- C:\Program Files (x86)\Common Files\Adobe O43 - CFD: 2014/05/30 12:33:39 - [] D -- C:\Program Files (x86)\Common Files\Apple O43 - CFD: 2013/09/26 17:16:18 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER O43 - CFD: 2013/03/20 18:10:14 - [] D -- C:\Program Files (x86)\Common Files\InstallShield O43 - CFD: 2013/09/26 17:16:58 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared O43 - CFD: 2013/03/20 18:10:16 - [] D -- C:\Program Files (x86)\Common Files\Nero O43 - CFD: 2015/09/07 00:19:59 - [] D -- C:\Program Files (x86)\Common Files\Research In Motion O43 - CFD: 2009/07/14 03:20:08 - [] D -- C:\Program Files (x86)\Common Files\Services O43 - CFD: 2013/03/20 18:10:16 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines O43 - CFD: 2013/03/20 15:21:01 - [] D -- C:\Program Files (x86)\Common Files\Symantec Shared O43 - CFD: 2014/07/17 12:51:54 - [] D -- C:\Program Files (x86)\Common Files\System O43 - CFD: 2014/07/09 13:02:35 - [] D -- C:\Users\HP\AppData\Roaming\Adobe O43 - CFD: 2015/07/26 17:35:47 - [] D -- C:\Users\HP\AppData\Roaming\Apple Computer O43 - CFD: 2014/01/09 17:01:38 - [] D -- C:\Users\HP\AppData\Roaming\BabSolution =>PUP.Optional.BabSolution O43 - CFD: 2014/02/12 13:21:15 - [] D -- C:\Users\HP\AppData\Roaming\Babylon =>PUP.Optional.Babylon O43 - CFD: 2013/03/20 18:10:44 - [] D -- C:\Users\HP\AppData\Roaming\COWON O43 - CFD: 2014/07/22 14:27:17 - [] D -- C:\Users\HP\AppData\Roaming\DAEMON Tools Pro O43 - CFD: 2015/07/01 15:31:40 - [] D -- C:\Users\HP\AppData\Roaming\dvdcss O43 - CFD: 2014/01/22 12:37:56 - [] D -- C:\Users\HP\AppData\Roaming\eTeks O43 - CFD: 2014/08/07 12:07:33 - [] D -- C:\Users\HP\AppData\Roaming\HpUpdate O43 - CFD: 2013/02/04 11:58:50 - [] D -- C:\Users\HP\AppData\Roaming\Identities O43 - CFD: 2013/02/07 06:05:41 - [0] D -- C:\Users\HP\AppData\Roaming\Intel O43 - CFD: 2013/03/20 18:10:44 - [] D -- C:\Users\HP\AppData\Roaming\Macromedia O43 - CFD: 2015/09/18 16:11:21 - [] D -- C:\Users\HP\AppData\Roaming\Malwarebytes O43 - CFD: 2013/08/23 21:08:17 - [] D -- C:\Users\HP\AppData\Roaming\ManyCam O43 - CFD: 2015/03/20 14:56:26 - [] SD -- C:\Users\HP\AppData\Roaming\Microsoft O43 - CFD: 2013/09/26 18:22:20 - [] D -- C:\Users\HP\AppData\Roaming\Mozilla O43 - CFD: 2013/02/09 16:32:06 - [] D -- C:\Users\HP\AppData\Roaming\Nero O43 - CFD: 2014/03/29 13:11:38 - [] D -- C:\Users\HP\AppData\Roaming\Opera Software O43 - CFD: 2014/08/22 13:18:29 - [] D -- C:\Users\HP\AppData\Roaming\PC Speed Maximizer =>PUP.Optional.PCSpeedMaximizer O43 - CFD: 2014/08/22 13:18:29 - [] D -- C:\Users\HP\AppData\Roaming\RegistryKeys O43 - CFD: 2014/11/28 15:55:44 - [] D -- C:\Users\HP\AppData\Roaming\SolidDocuments O43 - CFD: 2013/02/09 09:16:16 - [] D -- C:\Users\HP\AppData\Roaming\TeraCopy O43 - CFD: 2013/07/21 12:17:48 - [] D -- C:\Users\HP\AppData\Roaming\TypingMaster7 O43 - CFD: 2015/09/12 16:51:09 - [] D -- C:\Users\HP\AppData\Roaming\vlc O43 - CFD: 2013/02/04 16:18:29 - [] D -- C:\Users\HP\AppData\Roaming\WinRAR O43 - CFD: 2015/09/19 15:24:44 - [] D -- C:\Users\HP\AppData\Roaming\ZHP O43 - CFD: 2014/11/28 15:07:20 - [] D -- C:\Users\HP\AppData\Local\Adobe O43 - CFD: 2014/02/10 15:02:17 - [] D -- C:\Users\HP\AppData\Local\Apple O43 - CFD: 2014/02/10 15:06:17 - [] D -- C:\Users\HP\AppData\Local\Apple Computer O43 - CFD: 2013/02/04 11:58:21 - [0] SHD -- C:\Users\HP\AppData\Local\Application Data O43 - CFD: 2013/05/16 09:21:49 - [] D -- C:\Users\HP\AppData\Local\Apps O43 - CFD: 2013/09/09 14:02:28 - [] D -- C:\Users\HP\AppData\Local\AskPartnerNetwork =>Toolbar.AskBar O43 - CFD: 2014/08/23 08:00:35 - [] D -- C:\Users\HP\AppData\Local\Babylon =>PUP.Optional.Babylon O43 - CFD: 2013/05/16 09:30:53 - [0] D -- C:\Users\HP\AppData\Local\Deployment O43 - CFD: 2015/03/09 09:16:42 - [] D -- C:\Users\HP\AppData\Local\Diagnostics O43 - CFD: 2014/07/22 14:31:16 - [0] D -- C:\Users\HP\AppData\Local\DriverToolkit =>PUP.Optional.DriverToolkit O43 - CFD: 2014/11/21 16:17:14 - [0] D -- C:\Users\HP\AppData\Local\ElevatedDiagnostics O43 - CFD: 2014/01/09 17:15:13 - [] D -- C:\Users\HP\AppData\Local\Google O43 - CFD: 2013/02/04 11:58:21 - [0] SHD -- C:\Users\HP\AppData\Local\Historique O43 - CFD: 2014/07/30 17:01:58 - [] D -- C:\Users\HP\AppData\Local\HP O43 - CFD: 2013/10/05 18:09:20 - [] D -- C:\Users\HP\AppData\Local\Macromedia O43 - CFD: 2013/02/04 17:00:27 - [] D -- C:\Users\HP\AppData\Local\ManyCam O43 - CFD: 2014/08/19 13:20:06 - [] D -- C:\Users\HP\AppData\Local\Microsoft O43 - CFD: 2013/03/20 18:10:37 - [] D -- C:\Users\HP\AppData\Local\Microsoft Games O43 - CFD: 2013/07/07 20:03:35 - [] D -- C:\Users\HP\AppData\Local\Microsoft Help O43 - CFD: 2013/12/02 08:08:34 - [] D -- C:\Users\HP\AppData\Local\Mozilla O43 - CFD: 2015/06/03 12:59:25 - [] D -- C:\Users\HP\AppData\Local\onlysearch =>PUP.Optional.OnlySearch O43 - CFD: 2014/03/29 13:11:39 - [] D -- C:\Users\HP\AppData\Local\Opera Software O43 - CFD: 2014/07/22 14:29:17 - [] D -- C:\Users\HP\AppData\Local\Programs O43 - CFD: 2015/06/03 11:52:52 - [] D -- C:\Users\HP\AppData\Local\RtbSync O43 - CFD: 2015/06/03 11:52:39 - [] D -- C:\Users\HP\AppData\Local\ShdUpdate O43 - CFD: 2015/09/19 15:27:42 - [] AD -- C:\Users\HP\AppData\Local\Temp O43 - CFD: 2013/02/04 11:58:21 - [0] SHD -- C:\Users\HP\AppData\Local\Temporary Internet Files O43 - CFD: 2013/12/20 13:38:41 - [] D -- C:\Users\HP\AppData\Local\Unity O43 - CFD: 2013/07/06 15:24:57 - [] D -- C:\Users\HP\AppData\Local\VideoDownloadConverter_4z =>PUP.Optional.VideoDownloadConverter O43 - CFD: 2013/10/24 14:09:33 - [] D -- C:\Users\HP\AppData\Local\VideoScavenger_1e O43 - CFD: 2014/01/14 21:39:59 - [] D -- C:\Users\HP\AppData\Local\VirtualStore O43 - CFD: 2015/06/03 13:40:26 - [] D -- C:\Users\HP\AppData\Local\VLCUpdate O43 - CFD: 2013/03/29 10:45:22 - [] D -- C:\Users\HP\AppData\Local\WindowsUpdate O43 - CFD: 2013/03/20 18:16:44 - [] RD -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2014/08/13 15:39:02 - [] RD -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2014/01/14 16:47:46 - [0] D -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dictionnaire O43 - CFD: 2013/03/20 18:16:44 - [] RD -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2014/08/13 15:39:02 - [] RD -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 2014/01/22 23:02:48 - [] D -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ---\\ Derniers fichiers créés dans Windows Prefetcher (2) - 194s O45 - LFCP:[MD5.A9A4A1ABEBADFEFB7DC916B9FABE453F] 2015/09/19 14:18:44 A -- C:\Windows\Prefetch\BABYLON.EXE-9D5C5354.pf =>PUP.Optional.Babylon O45 - LFCP:[MD5.C68266C2E9133E40FC1F24CCB2BF87F4] 2015/09/19 14:20:32 A -- C:\Windows\Prefetch\BABYLONHELPER64.EXE-31FFE3EB.pf =>PUP.Optional.Babylon ---\\ Liste des pilotes du système (73) - 44s O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [491088] © O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [339536] © O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\drivers\adpu320.sys [182864] © O58 - SDL:2009/07/14 01:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [15440] © O58 - SDL:2011/03/11 06:41:12 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [107904] © O58 - SDL:2009/07/14 01:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [194128] © O58 - SDL:2011/03/11 06:41:12 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [27008] © O58 - SDL:2011/12/05 08:22:58 A . (.Windows (R) Win 7 DDK provider - Intel® Centrino® Wireless Bluetooth® 3.0 +.) -- C:\Windows\System32\drivers\AmpPal.sys [195584] © O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [87632] © O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [97856] © O58 - SDL:2009/06/10 20:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60a.sys [270848] © O58 - SDL:2015/01/23 11:49:10 A . (.BlackBerry Limited - BlackBerry CDC/NCM Driver.) -- C:\Windows\System32\drivers\blackberryncm6_AMD64.sys [25600] O58 - SDL:2009/06/10 20:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [18432] © O58 - SDL:2009/06/10 20:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [8704] © O58 - SDL:2009/07/14 01:19:07 A . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [286720] © O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [47104] © O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [14976] © O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [14720] © O58 - SDL:2009/06/10 20:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [468480] © O58 - SDL:2009/07/14 01:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [17488] © O58 - SDL:2009/07/14 01:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [530496] © O58 - SDL:2009/06/10 20:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3286016] © O58 - SDL:2015/08/07 14:47:55 A . (.Huawei Tech. Co., Ltd. - HUAWEI USB Smart Card Driver.) -- C:\Windows\System32\drivers\ewdcsc.sys [32768] © O58 - SDL:2015/08/07 14:47:55 A . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\ewusbmdm.sys [221312] © O58 - SDL:2015/08/07 14:47:56 A . (.Huawei Technologies Co., Ltd. - USB NDIS Miniport Driver.) -- C:\Windows\System32\drivers\ewusbwwan.sys [421376] © O58 - SDL:2015/08/07 14:47:56 A . (.Huawei Technologies Co., Ltd. - ew_hwupgrade Driver.) -- C:\Windows\System32\drivers\ew_hwupgrade.sys [22016] © O58 - SDL:2015/08/07 14:47:56 A . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\ew_hwusbdev.sys [117248] © O58 - SDL:2015/08/07 14:47:56 A . (.Huawei Technologies Co., Ltd. - ew_jubusenum Driver.) -- C:\Windows\System32\drivers\ew_jubusenum.sys [86016] © O58 - SDL:2015/08/07 14:47:56 A . (.Huawei Technologies Co., Ltd. - ew_jucdcacm Driver.) -- C:\Windows\System32\drivers\ew_jucdcacm.sys [98816] © O58 - SDL:2015/08/07 14:47:57 A . (.Huawei Technologies Co., Ltd. - ew_jucdcndis Driver.) -- C:\Windows\System32\drivers\ew_jucdcecm.sys [69632] © O58 - SDL:2015/08/07 14:47:57 A . (.Huawei Technologies Co., Ltd. - ew_juextctrl Driver.) -- C:\Windows\System32\drivers\ew_juextctrl.sys [28672] © O58 - SDL:2015/08/07 14:47:57 A . (.Huawei Technologies Co., Ltd. - ew_jucdcndis Driver.) -- C:\Windows\System32\drivers\ew_juwwanecm.sys [212992] © O58 - SDL:2015/08/07 14:47:57 A . (.Huawei Technologies Co., Ltd. - Filter Driver.) -- C:\Windows\System32\drivers\ew_usbenumfilter.sys [13952] © O58 - SDL:2012/08/21 13:01:20 A . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\drivers\GEARAspiWDM.sys [33240] © O58 - SDL:2009/06/10 20:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [31232] © O58 - SDL:2011/01/27 09:35:45 N . (.Beijing Rising Information Technology Co., Ltd. - HookHelp for AMD64.) -- C:\Windows\System32\drivers\HookHelp.sys [27288] © O58 - SDL:2010/09/14 05:58:06 N . (.Beijing Rising Information Technology Co., Ltd. - Hooksys for AMD64.) -- C:\Windows\System32\drivers\Hooksys.sys [37016] © O58 - SDL:2011/04/14 08:41:42 N . (.Beijing Rising Information Technology Co., Ltd. - hooktdi_64.sys.) -- C:\Windows\System32\drivers\HookTdi.sys [30360] © O58 - SDL:2010/11/20 13:33:35 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [78720] © O58 - SDL:2010/07/13 12:46:03 N . (.Beijing Rising Information Technology Co., Ltd. - VM Monitor.) -- C:\Windows\System32\drivers\hvm.sys [41048] © O58 - SDL:2011/03/11 06:41:26 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [410496] © O58 - SDL:2009/07/14 01:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [44112] © O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [114752] © O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [106560] © O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [65600] © O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [115776] © O58 - SDL:2011/09/29 07:04:22 A . (.ManyCam LLC. - ManyCam Virtual Webcam, WDM Video Capture D.) -- C:\Windows\System32\drivers\ManyCam_x64.sys [27136] O58 - SDL:2013/04/04 14:50:32 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\mbam.sys [25928] © O58 - SDL:2013/01/31 09:50:58 A . (.ManyCam LLC - ManyCam Virtual Microphone.) -- C:\Windows\System32\drivers\mcaudrv_x64.sys [28160] © O58 - SDL:2012/10/11 03:08:10 A . (.ManyCam LLC - ManyCam Virtual Webcam.) -- C:\Windows\System32\drivers\mcvidrv_x64.sys [44928] © O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [35392] © O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [284736] © O58 - SDL:2015/08/07 14:47:58 A . (.DiBcom SA - DiBcom AVSTREAM BDA driver.) -- C:\Windows\System32\drivers\mod7700.sys [1001472] O58 - SDL:2010/04/28 15:49:50 A . (.Marvell Semiconductor, Inc. - USB EWS Device Driver.) -- C:\Windows\System32\drivers\mvusbews.sys [20480] © O58 - SDL:2009/06/10 20:35:36 A . (.Ralink Technology Corp. - Ralink 802.11n Wireless Adapter Driver.) -- C:\Windows\System32\drivers\netr28ux.sys [867328] © O58 - SDL:2009/06/10 20:35:38 A . (.Ralink Technology, Corp. - Ralink 802.11 USB Wireless Adapter Driver.) -- C:\Windows\System32\drivers\netr7364.sys [707072] © O58 - SDL:2009/07/14 01:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [51264] © O58 - SDL:2011/03/11 06:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [148352] © O58 - SDL:2011/03/11 06:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [166272] © O58 - SDL:2009/07/14 01:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1524816] © O58 - SDL:2009/07/14 01:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [128592] © O58 - SDL:2012/12/10 15:48:02 A . (.Research in Motion Ltd - RIM Virtual Serial Driver.) -- C:\Windows\System32\drivers\RimSerial_AMD64.sys [44544] © O58 - SDL:2015/01/14 09:47:20 A . (.BlackBerry Limited - BlackBerry Device Driver.) -- C:\Windows\System32\drivers\RimUsb_AMD64.sys [80384] O58 - SDL:2011/03/04 22:16:20 A . (.Realtek - Realtek 8136/8168/8169 NDIS 6.20 64-bit Dri.) -- C:\Windows\System32\drivers\Rt64win7.sys [436840] © O58 - SDL:2011/01/05 01:08:58 A . (.Realtek Semiconductor Corporation - Realtek RTL81892CE NDIS Driverr.) -- C:\Windows\System32\drivers\rtl8192ce.sys [1109096] © O58 - SDL:2009/06/10 20:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] © O58 - SDL:2009/07/14 01:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [43584] © O58 - SDL:2009/07/14 01:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [80464] © O58 - SDL:2013/02/11 16:41:08 A . (...) -- C:\Windows\System32\drivers\sptd.sys [526392] O58 - SDL:2009/07/14 01:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [24656] © O58 - SDL:2012/12/13 14:50:36 A . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\drivers\usbaapl64.sys [54784] © O58 - SDL:2009/07/14 01:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [17488] © O58 - SDL:2009/07/14 01:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [161872] © ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (1) - 251s O61 - LFC: 2015/09/19 14:23:11 A . (..) -- C:\Users\HP\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [1113849] ---\\ Associations Shell Spawning (11) - 3s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe © O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe © O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\launcher.exe © O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe © O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe © O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe © ---\\ Menu de démarrage Internet (16) - 1s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe © O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe © O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\Launcher.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\launcher.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\launcher.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\launcher.exe © ---\\ Recherche d'infection sur les navigateurs (97) - 33s O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("browser.newtab.url", "http://www.only-search.com/?babsrc=NT_kms&affID=970000001"); =>PUP.Optional.OnlySearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("browser.search.defaultenginename", "Search The Web (Only-Search)"); =>PUP.Optional.OnlySearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("browser.search.selectedEngine", "Search The Web (Only-Search)"); =>PUP.Optional.OnlySearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("browser.startup.homepage", "http://www.only-search.com/?babsrc=HP_kms&affID=970000001"); =>PUP.Optional.OnlySearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.admin", false); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.aflt", "orgnl"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.autoRvrt", "false"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.dfltLng", "fr"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.excTlbr", false); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.ffxUnstlRst", true); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.id", "f06889ef00000000000068a3c49d01ed"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.instlDay", "16079"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.instlRef", "sst"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.newTab", false); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.prdct", "buenosearch"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.prtnrId", "buenosearch"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.rvrt", "false"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.smplGrp", "none"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.tb_url", "http://www.buenosearch.com/?q={searchTerms}&babsrc=TB_def&mntrId=F06868A3C49D01ED&affI[...] =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.tlbrId", "base"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.tlbrSrchUrl", "http://www.buenosearch.com/?q={searchTerms}&babsrc=TB_def&mntrId=F06868A3C49D01ED[...] =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.vrsn", "1.8.28.7"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.vrsnTs", "1.8.28.717:01:22"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.buenosearch.vrsni", "1.8.28.7"); =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"4zffxtbr@VideoDownloadConverter_4z.com\":{\"d[...] =>PUP.Optional.MindSpark O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.mywebsearch.prevKwdEnabled", false); =>PUP.Optional.MyWebSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.BUTTON_STRUCTURE", "[{\"b\":221350624,\"c\":\"mindspark.magnify\",\"p\":\"L.0\[...] =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.browser.version.last", "30.0"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.firstKnownVersion", "5.40.2.29179"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.homepage", "http://home.tb.ask.com/index.jhtml?n=77fd80ec&p2=^Z8^xpi000^YYA^")[...] =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.hp.enabled", false); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.hp.guardType", "HPG"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.initialized", true); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.installation.contextKey", ""); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.installation.installDate", "2013102316"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.installation.partnerId", "^Z8^xpi000^YYA^"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.installation.partnerSubId", ""); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.installation.success", false); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.isCompliantUninstallImplementation", true); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.lastKnownVersion", "7.13.6.44387"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.options.defaultSearch", false); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.options.homePageEnabled", false); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.options.keywordEnabled", false); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.options.tabEnabled", false); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.partnerPixelFired", false); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.searchHistory", "la thesorisation des operateurs economique cas de la province[...] =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.toolbarCollapsed", false); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._1eMembers_.weather.location", "10001"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.browser.search.defaultenginename.prev", "Wikipédia (fr)"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.browser.search.defaultenginename.savedPrev", "true"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.browser.search.defaultenginename.tb", "Ask Web Search"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.browser.search.selectedEngine.prev", "Wikipédia (fr)"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.browser.search.selectedEngine.savedPrev", "true"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.browser.search.selectedEngine.tb", "Ask Web Search"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.browser.startup.homepage.prev", "http://www.buenosearch.com/?babsrc=HP_def&mnt[...] =>PUP.Optional.BuenoSearch O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.browser.startup.homepage.savedPrev", "true"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.browser.startup.homepage.tb", "http://home.tb.ask.com/index.jhtml?ptb=22CA9A05[...] =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.browser.startup.page.savedPrev", 1); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.browser.startup.page.tb", 1); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.firstKnownVersion", "5.79.3.19015"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.homepage", "http://home.tb.ask.com/index.jhtml?ptb=22CA9A05-F355-4AEC-8CDB-288[...] =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.hp.enabled", true); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.hp.guardType", "HPG"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.hp.lastGuardTime", -38837771); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.hp.numGuards", 1); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.initialized", true); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.installKeysSource", "Cookies"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.installType", "XPI"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.installation.contextKey", ""); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.installation.installDate", "2014021902"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.installation.partnerId", "^XP^xdm116^YYA^cd"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.installation.partnerSubId", "CMHEl6qV2LwCFcY7OgodiioA0A"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.installation.pixelUrl", "http://download.televisionfanatic.com/install_pixels.[...] =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.installation.success", true); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.installation.toolbarId", "22CA9A05-F355-4AEC-8CDB-2888AB188C1C"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.isCompliantUninstallImplementation", true); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.lastActivePing", "1416322268127"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.lastKnownVersion", "6.72.5.25812"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.options.defaultSearch", true); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.options.homePageEnabled", true); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.options.keywordEnabled", true); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.options.tabEnabled", true); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.partnerPixelFired", true); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.searchHistory", "cas particulier du parc a bois"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.toolbarCollapsed", false); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark._64Members_.weather.location", "10001"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark.hp.enabled", false); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark.hp.enabled.guid", ""); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("extensions.toolbar.mindspark.lastInstalled", "televisionfanatic@mindspark.com"); =>PUP.Optional.Bandoo O69 - SBI: prefs.js [HP - dptezhql.default] user_pref("keyword.URL", "http://www.only-search.com/?babsrc=KW_kms&affID=$afltId$&q="); =>PUP.Optional.OnlySearch O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Bueno Search) - http://www.buenosearch.com/ =>PUP.Optional.BuenoSearch O69 - SBI: SearchScopes [HKCU] {427F33BB-8C0D-43EF-9A74-5368A56D4C03} - (Ask Search) - http://www.search.ask.com/ =>Toolbar.Ask O69 - SBI: SearchScopes [HKCU] {C47FDF02-6D6D-4741-88A3-2A5664CEE056} - (Search The Web (Only-Search)) - http://www.only-search.com/ =>PUP.Optional.OnlySearch O69 - SBI: SearchScopes [HKCU] {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} - (Ask Web Search) - http://search.tb.ask.com/ =>Toolbar.Ask O69 - SBI: SearchScopes [HKCU] {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} [DefaultScope] - (Google) - http://www.google.com/ ---\\ Enumère les fichiers Crack & Keygen (1) - 102s O82 - LFC: 2013/02/07 14:01:04 A . (.j2k-codec.com.) -- C:\Users\HP\Desktop\music\Zumas.Revenge.v1.0.Cracked.Popcap\setup\j2k-codec.dll [94208] =>.Crack,Keygen ---\\ Enumère les services démarrés par Svchost (32) - 6s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192] © O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [80384] © O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [80384] © O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\system32\srvsvc.dll [236032] © O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [777728] © O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [859648] © O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [679424] © O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [99328] © O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [344064] © O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792] © O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [64512] © O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [359424] © O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [316928] © O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du se.) -- C:\Windows\System32\termsrv.dll [681984] © O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\system32\wuaueng.dll [2477536] © O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [849920] © O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [370688] © O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [569344] © O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\system32\seclogon.dll [30720] © O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70144] © O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\system32\iscsiexe.dll [156672] © O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\system32\mmcss.dll [67584] © O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [242688] © O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [121856] © O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136704] © O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104] © O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\system32\schedsvc.dll [1110016] © O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\system32\kmsvc.dll [90624] © O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84480] © O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [209920] © O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\system32\themeservice.dll [44544] © O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864] © ---\\ Enumère les codes produits des logiciels (1) - 7s O90 - PUC: "233495D465D20073677A7A857BC0A000" . (.Ask Toolbar.) -- C:\Windows\Installer\{4D594332-2D56-3700-76A7-A758B70C0A00}\ToolbarIcon.exe =>Toolbar.AsktBar ---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (20) - 233s SR - Auto [2014/12/19 08:48:18] [ 81088] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe © SS - Demand [2014/07/08 07:40:21] [ 262320] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe © SR - Auto [2011/12/05 08:30:50] [ 659968] Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Servi (AMPPALR3) . (.Intel Corporation.) - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe © SR - Auto [2014/02/12 15:50:20] [ 43336] Apple Mobile Device (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe © SR - Demand [2014/10/31 15:56:04] [ 588024] BlackBerry Device Manager (BlackBerry Device Manager) . (.BlackBerry Limited.) - C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe SR - Auto [2011/08/30 23:05:32] [ 462184] Service Bonjour (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe © SR - Auto [2011/12/05 07:55:36] [ 135952] Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed (BTHSSecurityMgr) . (.Intel(R) Corporation.) - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe © SS - Auto [2015/09/18 12:29:48] [ 144200] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe © SS - Demand [2015/09/18 12:29:48] [ 144200] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe © SR - Auto [2010/04/29 17:10:40] [ 127800] HP SI Service (HPSIService) . (.HP.) - C:\Windows\system32\HPSIsvc.exe © SR - Auto [2011/03/14 15:27:34] [ 346976] HWDeviceService64.exe (HWDeviceService64.exe) . (.Copyright (C) 2008.) - C:\ProgramData\DatacardService\HWDeviceService64.exe SR - Demand [2014/05/26 18:12:34] [ 641352] Service de l’iPod (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe © SR - Auto [2013/04/04 14:50:32] [ 418376] (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe © SR - Auto [2013/04/04 14:50:32] [ 701512] (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe © SS - Demand [2014/06/06 04:38:37] [ 119408] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe © SR - Auto [2015/09/18 11:29:31] [ 196288] Rsd Service (RsMgrSvc) . (.Beijing Rising Information Technology Co., Ltd..) - C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe © SR - Auto [2010/12/15 09:51:52] [ 264448] Rav Service (RsRavMon) . (.Beijing Rising Information Technology Co., Ltd..) - C:\Program Files (x86)\Rising\RAV\RavMonD.exe © SS - Auto [2015/08/07 14:47:20] [ 234496] TigoNet. OUC (TigoNet. RunOuc) . (...) - C:\Program Files (x86)\TigoNet\UpdateDog\ouc.exe SR - Auto [2013/07/06 14:55:41] [ 42504] VideoDownloadConverterService (VideoDownloadConverter_4zService) . (.COMPANYVERS_NAME.) - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe =>PUP.Optional.VideoDownloadConverter ---\\ Recherche de clés de registre Tracing (8) - 25s HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BabMaint_RASAPI32 =>PUP.Optional.BabSolution HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BabMaint_RASMANCS =>PUP.Optional.BabSolution HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Babylon_RASAPI32 =>PUP.Optional.Babylon HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Babylon_RASMANCS =>PUP.Optional.Babylon HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Offercast2802_MYC__RASAPI32 =>Toolbar.Ask HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Offercast2802_MYC__RASMANCS =>Toolbar.Ask HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\OnlySearch_RASAPI32 =>PUP.Optional.OnlySearch HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\OnlySearch_RASMANCS =>PUP.Optional.OnlySearch ---\\ Scan Additionnel (53) - 1s C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe =>PUP.Optional.VideoDownloadConverter C:\Users\HP\AppData\Local\onlysearch\onlysearch\1.3.26.12\onlysearch.exe =>PUP.Optional.OnlySearch C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe =>PUP.Optional.Babylon C:\Program Files\Babylon\Babylon-Pro\BabylonHelper64.exe =>PUP.Optional.Babylon C:\Users\HP\AppData\Local\onlysearch\onlysearch\1.3.26.12\onlysetup.exe =>PUP.Optional.OnlySearch C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\dptezhql.default\searchplugins\buenosearch.xml =>PUP.Optional.BuenoSearch C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\dptezhql.default\searchplugins\onlysearchkms1.xml =>PUP.Optional.OnlySearch C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll =>PUP.Optional.VideoDownloadConverter HKLM\SYSTEM\CurrentControlSet\Services\VideoDownloadConverter_4zService =>PUP.Optional.VideoDownloadConverter HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\onlysearch =>PUP.Optional.OnlySearch HKLM\SOFTWARE\Wow6432Node\Babylon =>PUP.Optional.Babylon HKLM\SOFTWARE\Wow6432Node\buenosearch LTD =>PUP.Optional.BuenoSearch HKLM\SOFTWARE\Wow6432Node\VideoDownloadConverter_4z =>PUP.Optional.MindSpark HKCU\SOFTWARE\APN PIP =>PUP.Optional.Conduit HKCU\SOFTWARE\AskPartnerNetwork =>Toolbar.AskBar HKCU\SOFTWARE\BabSolution =>PUP.Optional.BabSolution HKCU\SOFTWARE\Babylon =>PUP.Optional.Babylon HKCU\SOFTWARE\buenosearch LTD =>PUP.Optional.BuenoSearch HKCU\SOFTWARE\DriverToolkit =>PUP.Optional.DriverToolkit HKCU\SOFTWARE\PC Speed Maximizer =>PUP.Optional.PCSpeedMaximizer HKCU\SOFTWARE\VideoDownloadConverter_4z =>PUP.Optional.MindSpark HKCU\SOFTWARE\AppDataLow\Software\VideoDownloadConverter_4z =>PUP.Optional.MindSpark C:\Program Files (x86)\AskPartnerNetwork =>Toolbar.AskBar C:\Program Files (x86)\Babylon =>PUP.Optional.Babylon C:\Program Files (x86)\buenosearch LTD =>PUP.Optional.BuenoSearch C:\Program Files (x86)\DriverToolkit =>PUP.Optional.DriverToolkit C:\Program Files (x86)\VideoDownloadConverter_4z =>PUP.Optional.VideoDownloadConverter C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Babylon =>PUP.Optional.Babylon C:\ProgramData\APN =>Toolbar.Ask C:\ProgramData\AskPartnerNetwork =>Toolbar.YahooPartner C:\ProgramData\AVG Security Toolbar =>Toolbar.AVGSearch C:\ProgramData\Babylon =>PUP.Optional.Babylon C:\Users\HP\AppData\Roaming\BabSolution =>PUP.Optional.BabSolution C:\Users\HP\AppData\Roaming\Babylon =>PUP.Optional.Babylon C:\Users\HP\AppData\Roaming\PC Speed Maximizer =>PUP.Optional.PCSpeedMaximizer C:\Users\HP\AppData\Local\AskPartnerNetwork =>Toolbar.AskBar C:\Users\HP\AppData\Local\Babylon =>PUP.Optional.Babylon C:\Users\HP\AppData\Local\DriverToolkit =>PUP.Optional.DriverToolkit C:\Users\HP\AppData\Local\onlysearch =>PUP.Optional.OnlySearch C:\Users\HP\AppData\Local\VideoDownloadConverter_4z =>PUP.Optional.VideoDownloadConverter C:\Windows\Prefetch\BABYLON.EXE-9D5C5354.pf =>PUP.Optional.Babylon C:\Windows\Prefetch\BABYLONHELPER64.EXE-31FFE3EB.pf =>PUP.Optional.Babylon C:\Windows\Installer\{4D594332-2D56-3700-76A7-A758B70C0A00}\ToolbarIcon.exe =>Toolbar.AsktBar HKLM\Software\Classes\Installer\Products\233495D465D20073677A7A857BC0A000 =>Toolbar.AsktBar HKLM\Software\Classes\Installer\Features\233495D465D20073677A7A857BC0A000 =>Toolbar.AsktBar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BabMaint_RASAPI32 =>PUP.Optional.BabSolution HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BabMaint_RASMANCS =>PUP.Optional.BabSolution HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Babylon_RASAPI32 =>PUP.Optional.Babylon HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Babylon_RASMANCS =>PUP.Optional.Babylon HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Offercast2802_MYC__RASAPI32 =>Toolbar.Ask HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Offercast2802_MYC__RASMANCS =>Toolbar.Ask HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\OnlySearch_RASAPI32 =>PUP.Optional.OnlySearch HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\OnlySearch_RASMANCS =>PUP.Optional.OnlySearch ---\\ Récapitulatif des éléments trouvées sur votre station (16) - 0s http://www.nicolascoolman.fr/blog =>PUP.Optional.VideoDownloadConverter http://www.nicolascoolman.fr/blog =>PUP.Optional.OnlySearch http://www.nicolascoolman.fr/pup-babylon/ =>PUP.Optional.Babylon http://www.nicolascoolman.fr/pup-buenosearch/ =>PUP.Optional.BuenoSearch http://www.nicolascoolman.fr/hijacker-babsolution/ =>PUP.Optional.BabSolution http://www.nicolascoolman.fr/pup-mindspark/ =>PUP.Optional.MindSpark http://www.nicolascoolman.fr/toolbar-conduit/ =>PUP.Optional.Conduit http://www.nicolascoolman.fr/blog =>Toolbar.AskBar http://www.nicolascoolman.fr/blog =>PUP.Optional.DriverToolkit http://www.nicolascoolman.fr/rogue-pcspeedmaximizer/ =>PUP.Optional.PCSpeedMaximizer http://www.nicolascoolman.fr/toolbar-ask/ =>Toolbar.Ask http://www.nicolascoolman.fr/blog =>Toolbar.YahooPartner http://www.nicolascoolman.fr/blog =>Toolbar.AVGSearch http://www.nicolascoolman.fr/adware-mywebsearch/ =>PUP.Optional.MyWebSearch http://www.nicolascoolman.fr/adware-bandoo/ =>PUP.Optional.Bandoo http://www.nicolascoolman.fr/blog =>Toolbar.AsktBar ~ End of the scan, 29103 items in 1390 seconds (977)(1)()