~ Rapport de ZHPDiag v2014.5.4.54 - Nicolas Coolman (04/05/2014) ~ Lancé par PC Jean-Marie (08/05/2014 08:43:25) ~ Adresse du Site Web http://nicolascoolman.webs.com ~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/ ~ Traduit par Nicolas Coolman ~ Etat de la version : ~ Liste blanche : Activée par le programme ~ Elévation des Privilèges : OK ~ User Account Control (UAC): Deactivate by user ---\\ Navigateurs Internet MSIE: Internet Explorer v11.0.9600.17105 MFIE: Mozilla Firefox 27.0.1 (Defaut) ---\\ Informations sur les produits Windows ~ Langage: Français Windows 7 Ultimate, 64-bit Service Pack 1 (Build 7601) Windows Server License Manager Script : OK ---\\ Logiciels de protection du système Secunia PSI Windows Defender W7 ---\\ Logiciels d'optimisation du système CCleaner v4.12 ---\\ Logiciels de partage PeerToPeer ---\\ Surveillance de Logiciels Adobe Flash Player 13 ActiveX Java 7 Update 55 ---\\ Informations sur le système ~ Processor: Intel64 Family 6 Model 60 Stepping 3, GenuineIntel ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 24511 MB (87% free) System Restore: Activé (Enable) System drive C: has 61 GB (30%) free of 200 GB ---\\ Mode de connexion au système ~ Computer Name: PC-JEAN-MARIE ~ User Name: PC Jean-Marie ~ All Users Names: UpdatusUser, PC Jean-Marie, Administrateur, ~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89 Logged in as Administrator ---\\ Variables d'environnement ~ System Unit : C:\ ~ %AppZHP% : C:\Users\PC Jean-Marie\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\PC Jean-Marie\AppData\Roaming\ ~ %Desktop% : C:\Users\PC Jean-Marie\Desktop\ ~ %Favorites% : C:\Users\PC Jean-Marie\Favorites\ ~ %LocalAppData% : C:\Users\PC Jean-Marie\AppData\Local\ ~ %StartMenu% : C:\Users\PC Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumération des unités disques C: Hard drive, Flash drive, Thumb drive (Free 61 Go of 200 Go) D: Hard drive, Flash drive, Thumb drive (Free 1658 Go of 1863 Go) E: CD-ROM drive (Not Inserted) H: Hard drive, Flash drive, Thumb drive (Free 2735 Go of 3726 Go) M: Floppy drive, Flash card reader, USB Key (Not Inserted) N: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go) O: Hard drive, Flash drive, Thumb drive (Free 307 Go of 448 Go) Q: Hard drive, Flash drive, Thumb drive (Free 456 Go of 466 Go) ---\\ Etat du Centre de Sécurité Windows [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowMyGames: Modified [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowPrinters: Modified ~ Security Center: 49 Legitimates Filtered in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.BAE75BF6405C876A710EA1257FEA1760] - (.Microsoft Corporation - Explorateur Windows.) (.27/11/2011 - 16:00:23.) -- C:\Windows\Explorer.exe [3208704] [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024] [MD5.F220BA78AB542C70211D73AE4729B2CD] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.06/03/2014 - 07:22:40.) -- C:\Windows\System32\wininet.dll [2260480] [MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.21/11/2010 - 04:24:50.) -- C:\Windows\System32\Winlogon.exe [390656] [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.21/11/2010 - 04:24:43.) -- C:\Windows\System32\sppcomapi.dll [232448] [MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/09/2013 - 02:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152] [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128] [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160] [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.21/11/2010 - 04:24:15.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456] [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.21/11/2010 - 04:24:59.) -- C:\Windows\system32\Drivers\DfsC.sys [102400] [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.21/11/2010 - 04:24:15.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368] [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472] [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224] [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.29/12/2011 - 20:19:38.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208] [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.21/11/2010 - 04:24:18.) -- C:\Windows\system32\Drivers\netBT.sys [261632] [MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680] [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280] [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.21/11/2010 - 04:25:00.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536] [MD5.1B6163C503398B23FF8B939C67747683] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.21/11/2010 - 04:25:23.) -- C:\Windows\system32\Drivers\rdpdr.sys [165888] [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184] [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.21/11/2010 - 04:24:57.) -- C:\Windows\system32\Drivers\tdx.sys [119296] [MD5.DF8126BD41180351A093A3AD2FC8903B] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.25/02/2011 - 07:25:38.) -- C:\Windows\system32\Drivers\volsnap.sys [296320] ~ Generic Processes: Scanned in 00mn 01s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 1/66 ~ Mes Videos (My Videos) : 1/2 ~ Mes Favoris (My Favorites) : 1/5 ~ Mes Documents (My Documents) : 1/7386 ~ Mon Bureau (My Desktop) : 1/47 ~ Menu demarrer (Programs) : 1/53 ~ Hidden Files: Scanned in 00mn 06s ---\\ Processus lancés [MD5.DB367E8C8F46C26A05BA982715CC0DB5] - (.Pixart Imaging Inc - pximouse.) -- C:\Windows\System32\TiltWheelMouse.exe [241152] [PID.2208] [MD5.9246CCD53B60DD5D907E4A7AF9EC4AB9] - (...) -- C:\Program Files\ASUSTeKcomputer.Inc\RTKSM\UserInterface\RTKSMUILauncher.exe [2621272] [PID.2216] [MD5.6BF7676296D5359AFC135A5397000053] - (.Acresso Corporation - Acresso Software Manager.) -- C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496] [PID.1856] [MD5.CC78200C3ECFFA178E78308A0E160D80] - (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\PC Jean-Marie\AppData\Local\Akamai\netsession_win.exe [4672920] [PID.432] [MD5.A4FAF57D17E6446125CE94618E7B0EFB] - (.Synapse Développement - Application Bureautique.) -- C:\Program Files (x86)\Cordial\PopupLexical.exe [3719168] [PID.1152] [MD5.05F9C30DE442AA8FCC690703F49813B2] - (.Synapse Développement - Intégration de Cordial.) -- C:\Program Files (x86)\Cordial\Integration_Cordial.exe [491603] [PID.1380] [MD5.D8E0D3E5290246A31B12B03A5728F4F5] - (...) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bordure.exe [402789] [PID.3992] [MD5.FBB33D6550559030FE42615572FE9FC3] - (.Secunia - Secunia PSI Tray.) -- C:\Program Files (x86)\Secunia\PSI\psi_tray.exe [565464] [PID.3916] [MD5.06B8605FF741FE9D58A994CC253A3DEF] - (.TechSmith Corporation - SnagIt 9.) -- C:\Program Files (x86)\TechSmith\SnagIt 9\SnagIt32.exe [6825288] [PID.1808] [MD5.9673485626808B1BB6B30D7F388A93FC] - (...) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Transparence.exe [402263] [PID.1776] [MD5.094E4E76FB9AB960A73F841BC6733F42] - (.Intel Corporation - iusb3mon.) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848] [PID.960] [MD5.A3A82800FF19B26B94D2327A2F11067E] - (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe [821144] [PID.1704] [MD5.7E6EFC5383FEF3EF852F2C7D41DEE83F] - (.Brother Industries, Ltd. - Brother Status Monitor MFC Application.) -- C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [663552] [PID.3208] [MD5.E5F1D2C7D51C816437BBE2306828BC4B] - (.Nuance Communications, Inc. - PaperPort Print to Desktop for NT.) -- C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [29984] [PID.1052] [MD5.47F73264CBAAC4981C3393BA8E4339CD] - (.Brother Industries, Ltd. - Control Center 3 Main Program.) -- C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe [536576] [PID.4012] [MD5.9F0ACAA725CF5A391AF7E2067AE45746] - (.Nuance Communications, Inc. - PdfCreateHook Application.) -- C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe [636192] [PID.2864] [MD5.8EAB8042F6DF802664EF57560B229F2D] - (.Brother Industries, Ltd. - Brother Status Monitor Application.) -- C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2629632] [PID.2224] [MD5.577E8E6BD12F557E645C0D001A7E7AED] - (.Pas de propriétaire - Cabinet - A Backup Application.) -- C:\Program Files (x86)\Cabinet\Cabinet.exe [581632] [PID.2788] [MD5.09622B465C5F98600CBA53B758A266F4] - (.Brother Industries, Ltd. - Status Monitor (Local).) -- C:\Program Files (x86)\Brother\Brmfcmon\BrMfcmon.exe [98304] [PID.3772] [MD5.E3564D023DCCA4A1854DC2226C99120D] - (.Brother Industries, Ltd. - ControlCenter Main Process.) -- C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe [335872] [PID.1924] [MD5.47E933B1FC14CFBFEFCB9867D68C3366] - (.TechSmith Corporation - TechSmith HTML Help Helper.) -- C:\Program Files (x86)\TechSmith\SnagIt 9\TSCHelp.exe [54600] [PID.3424] [MD5.B16DD477163168F814353BE9F275B527] - (.TechSmith Corporation - SnagIt RPC Helper.) -- C:\Program Files (x86)\TechSmith\SnagIt 9\SnagPriv.exe [75080] [PID.3148] [MD5.DE44BC19C3FC1098613487CA7A01B646] - (.ASUSTeKcomputer.Inc - Nahimic APO User Interface.) -- C:\Program Files\ASUSTeKcomputer.Inc\RTKSM\UserInterface\RTKSMSMConfig.exe [230400] [PID.4156] [MD5.7CFD44EDD74553FC8EE8479A79987579] - (.Brother Industries, Ltd. - ControlCenter UX System.) -- C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe [1204224] [PID.4572] [MD5.67B93A70D7D8029D963D17E984BC7B3F] - (.TechSmith Corporation - SnagIt Editor 9.) -- C:\Program Files (x86)\TechSmith\SnagIt 9\snagiteditor.exe [7335240] [PID.4772] [MD5.50650A6B920C576FC1C8266E17DD28BD] - (.Intel Corporation - IAStorIcon.) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284480] [PID.4932] [MD5.9233EE8EF479551CBE721B7523A8CF45] - (.Autodesk Inc. - Autodesk Application Manager.) -- C:\Users\PC Jean-Marie\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe [477064] [PID.4172] [MD5.D9184C5FF3FD526761D518A95ABA74A3] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [275568] [PID.4964] [MD5.700803AC9B451FB67DF35EF0E05382E7] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [7869952] [PID.4708] ~ Processes Running: Scanned in 00mn 00s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Users\PC Jean-Marie\AppData\Roaming\Mozilla\Firefox\Profiles\FreeZConfig.default\prefs.js M3 - MFPP: Plugins - [PC Jean-Marie] -- C:\Users\PC Jean-Marie\AppData\Roaming\Mozilla\Firefox\Profiles\FreeZConfig.default\searchplugins\MyOnlineSearch.xml M2 - MFEP: prefs.js [PC Jean-Marie - FreeZConfig.default\fastdial@telega.phpnet.us] [fastdial] Fast Dial v4.11 (..) M2 - MFEP: prefs.js [PC Jean-Marie - FreeZConfig.default\{0545b830-f0aa-4d7e-8820-50a4629a56fe}] [] ColorfulTabs v4.11 (..) M2 - MFEP: prefs.js [PC Jean-Marie - FreeZConfig.default\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}(213)] [] FireFTP v1.0.3 (..) M2 - MFEP: prefs.js [PC Jean-Marie - FreeZConfig.default\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}] [] Download Statusbar v0.9.10 (..) ~ Firefox Browser: 9 Legitimates Filtered in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:8080 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Hosts file redirection (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Hosts File: Scanned in 00mn 00s ~ Nombre de lignes (Lines number): 1 ---\\ Internet Explorer Toolbars (O3) O3 - Toolbar: SnagIt - [HKLM]{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} . (.TechSmith Corporation - SnagIt Add-in for Internet Explorer.) -- C:\Program Files (x86)\TechSmith\SnagIt 9\dllx64\SnagItIEAddin64.dll ~ Toolbar: Scanned in 00mn 00s ---\\ Applications lancées au démarrage du système (O4) O4 - HKLM\..\Run: [FirefoxUltimateOptimizer] . (.felipEx [http://felipex.net] - Firefox Ultimate Optimizer.) -- C:\Programmes -[ NoInstall ]-\Mozilla Optimizer\Firefox Ultimate Optimizer.exe O4 - HKLM\..\Run: [egui] . (.ESET - ESET GUI.) -- C:\Program Files\ESET\ESET Smart Security\egui.exe O4 - HKLM\..\Run: [MouseDriver] . (.Pixart Imaging Inc - pximouse.) -- C:\Windows\System32\TiltWheelMouse.exe O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe =>.Realtek Semiconductor Corp O4 - HKLM\..\Run: [BCSSync] . (.Microsoft Corporation - Microsoft Office 2010 component.) -- C:\Program Files\Microsoft Office\Office14\BCSSync.exe =>.Microsoft Corporation O4 - HKCU\..\Run: [adsl TV] . (.adsl TV / FM - adsl TV.) -- C:\Program Files (x86)\adslTV\adsltv.exe O4 - HKCU\..\Run: [RTKSMUILauncher] . (...) -- C:\Program Files\ASUSTeKcomputer.Inc\RTKSM\UserInterface\RTKSMUILauncher.exe O4 - HKCU\..\Run: [ISUSPM] . (.Acresso Corporation - Acresso Software Manager.) -- C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe O4 - HKCU\..\Run: [ccleaner] . (.Piriform Ltd - CCleaner.) -- C:\Programmes -[ NoInstall ]-\CCleaner\CCleaner64.exe =>.Piriform Ltd O4 - HKCU\..\Run: [PopupLexical] . (.Synapse Développement - Application Bureautique.) -- C:\Program Files (x86)\Cordial\PopupLexical.exe O4 - HKCU\..\Run: [Integration de Cordial] . (.Synapse Développement - Intégration de Cordial.) -- C:\PROGRAM FILES (X86)\CORDIAL\INTEGRATION_CORDIAL.exe O4 - HKCU\..\Run: [Autodesk Sync] . (.Autodesk, Inc. - Autodesk 360.) -- C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe O4 - HKCU\..\Run: [ultracopier] . (.ultracopier.first-world.info - Ultracopier under GPL3.) -- C:\Program Files\Ultracopier\ultracopier.exe O4 - HKLM\..\Wow6432Node\Run: [USB3MON] . (.Intel Corporation - iusb3mon.) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe O4 - HKLM\..\Wow6432Node\Run: [IAStorIcon] . (.Intel Corporation - Delayed launcher.) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe O4 - HKLM\..\Wow6432Node\Run: [Adobe Acrobat Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe O4 - HKLM\..\Wow6432Node\Run: [Acrobat Assistant 8.0] . (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe O4 - HKLM\..\Wow6432Node\Run: [BrMfcWnd] . (.Brother Industries, Ltd. - Brother Status Monitor MFC Application.) -- C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe O4 - HKLM\..\Wow6432Node\Run: [ControlCenter3] . (.Brother Industries, Ltd. - ControlCenter Program.) -- C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe O4 - HKLM\..\Wow6432Node\Run: [IndexSearch] . (.Nuance Communications, Inc. - PaperPort IndexSearch.) -- C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe O4 - HKLM\..\Wow6432Node\Run: [PaperPort PTD] . (.Nuance Communications, Inc. - PaperPort Print to Desktop for NT.) -- C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe O4 - HKLM\..\Wow6432Node\Run: [PPort12reminder] . (.Nuance Communications, Inc. - Ereg.) -- C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe O4 - HKLM\..\Wow6432Node\Run: [PDFHook] . (.Nuance Communications, Inc. - PdfCreateHook Application.) -- C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe O4 - HKLM\..\Wow6432Node\Run: [PDF5 Registry Controller] . (.Nuance Communications, Inc. - PDF Converter Registry Controller.) -- C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe O4 - HKLM\..\Wow6432Node\Run: [ControlCenter4] . (.Brother Industries, Ltd. - ControlCenter Launcher.) -- C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe O4 - HKLM\..\Wow6432Node\Run: [BrStsMon00] . (.Brother Industries, Ltd. - Brother Status Monitor Application.) -- C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe O4 - HKLM\..\Wow6432Node\Run: [Cabinet] . (.Pas de propriétaire - Cabinet - A Backup Application.) -- C:\Program Files (x86)\Cabinet\Cabinet.exe O4 - HKLM\..\Wow6432Node\Run: [ADSKAppManager] . (.Autodesk Inc. - Autodesk Application Manager.) -- C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe O4 - HKUS\.DEFAULT\..\Run: [RTKSMUILauncher] . (...) -- C:\Program Files\ASUSTeKcomputer.Inc\RTKSM\UserInterface\RTKSMUILauncher.exe O4 - HKUS\.DEFAULT\..\Run: [Autodesk Sync] . (.Autodesk, Inc. - Autodesk 360.) -- C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe O4 - HKUS\S-1-5-18\..\Run: [RTKSMUILauncher] . (...) -- C:\Program Files\ASUSTeKcomputer.Inc\RTKSM\UserInterface\RTKSMUILauncher.exe O4 - HKUS\S-1-5-18\..\Run: [Autodesk Sync] . (.Autodesk, Inc. - Autodesk 360.) -- C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe O4 - HKUS\S-1-5-21-892844921-2746744295-2308959209-1000\..\Run: [adsl TV] . (.adsl TV / FM - adsl TV.) -- C:\Program Files (x86)\adslTV\adsltv.exe O4 - HKUS\S-1-5-21-892844921-2746744295-2308959209-1000\..\Run: [RTKSMUILauncher] . (...) -- C:\Program Files\ASUSTeKcomputer.Inc\RTKSM\UserInterface\RTKSMUILauncher.exe O4 - HKUS\S-1-5-21-892844921-2746744295-2308959209-1000\..\Run: [ISUSPM] . (.Acresso Corporation - Acresso Software Manager.) -- C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe O4 - HKUS\S-1-5-21-892844921-2746744295-2308959209-1000\..\Run: [ccleaner] . (.Piriform Ltd - CCleaner.) -- C:\Programmes -[ NoInstall ]-\CCleaner\CCleaner64.exe =>.Piriform Ltd O4 - HKUS\S-1-5-21-892844921-2746744295-2308959209-1000\..\Run: [PopupLexical] . (.Synapse Développement - Application Bureautique.) -- C:\Program Files (x86)\Cordial\PopupLexical.exe O4 - HKUS\S-1-5-21-892844921-2746744295-2308959209-1000\..\Run: [Integration de Cordial] . (.Synapse Développement - Intégration de Cordial.) -- C:\PROGRAM FILES (X86)\CORDIAL\INTEGRATION_CORDIAL.exe O4 - HKUS\S-1-5-21-892844921-2746744295-2308959209-1000\..\Run: [Autodesk Sync] . (.Autodesk, Inc. - Autodesk 360.) -- C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe O4 - HKUS\S-1-5-21-892844921-2746744295-2308959209-1000\..\Run: [ultracopier] . (.ultracopier.first-world.info - Ultracopier under GPL3.) -- C:\Program Files\Ultracopier\ultracopier.exe ~ Application: Scanned in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: &Envoyer à OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} -- C:\Program Files (x86)\MICROS~3\Office14\ONBttnIE.dll (.not file.) O9 - Extra button: Notes &liées OneNote [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -- C:\Program Files (x86)\MICROS~3\Office14\ONBTTN~1.dll (.not file.) ~ IE Extra Buttons: Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{5B4BCA2E-2CBA-4171-BA20-AE6D653098AA}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CCS\Services\Tcpip\..\{C7065090-1EE7-4679-89B6-E71FF34D256B}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CS1\Services\Tcpip\..\{5B4BCA2E-2CBA-4171-BA20-AE6D653098AA}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CS1\Services\Tcpip\..\{C7065090-1EE7-4679-89B6-E71FF34D256B}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CS2\Services\Tcpip\..\{5B4BCA2E-2CBA-4171-BA20-AE6D653098AA}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CS2\Services\Tcpip\..\{C7065090-1EE7-4679-89B6-E71FF34D256B}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.240 212.27.40.241 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: wlmailhtml [64Bits] - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (...) -- O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll ~ Winlogon: Scanned in 00mn 00s ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22) O22 - SharedTaskScheduler: (no name) [64Bits] - {73526E5A-FD53-4BE7-B5E2-D3C89D7413DC} - (.not file.) ~ STS/SSO: Scanned in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: eBoostr Service (EBOOSTRSVC) . (.eBoostr.com - eBoostr cache generator.) - C:\Program Files\eBoostr\EBstrSvc.exe ~ Services: 17 Legitimates Filtered in 00mn 02s ---\\ Tâches planifiées en automatique (O39) [MD5.00000000000000000000000000000000] [APT] [Install_SSD] (...) -- C:\Users\PC Jean-Marie\AppData\Roaming\systweak\ssd\SSDPTstub.exe (.not file.) [0] O39 - APT: - (..) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002] ~ Scheduled Task: 4 Legitimates Filtered in 00mn 02s ---\\ Pilotes lancés au démarrage du système (O41) O41 - Driver: (netfilter64) . (.NetFilterSDK.com - NetFilter SDK TDI Hook Driver (WPP).) - C:\Windows\System32\drivers\netfilter64.sys O41 - Driver: (SDHookDriver) . (. - .) - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookDrv64.sys (.not file.) ~ Drivers: 84 Legitimates Filtered in 00mn 00s ---\\ Logiciels installés (O42) O42 - Logiciel: ACE-HIGH MP3 WAV WMA OGG Converter - (.audio-converter.com.) [HKLM][64Bits] -- ACE-HIGH MP3 WAV WMA OGG Converter O42 - Logiciel: Cabinet-1.10 - (...) [HKLM][64Bits] -- Cabinet O42 - Logiciel: Vbsedit - (.Adersoft.) [HKLM][64Bits] -- Vbsedit O42 - Logiciel: Vbsedit 32-bit - (.Adersoft.) [HKLM][64Bits] -- Vbsedit 32-bit O42 - Logiciel: eBoostr 4 - (.eBoostr.) [HKLM][64Bits] -- eBoostr 1 ~ Logic: 21 Legitimates Filtered in 00mn 00s ---\\ HKCU & HKLM Software Keys [HKCU\Software\Adersoft] [HKCU\Software\Cabinet] [HKCU\Software\Kemtoa] [HKCU\Software\eboostr] [HKLM\Software\Adersoft] [HKLM\Software\Wow6432Node\Adersoft] [HKLM\Software\eBoostr] ~ Key Software: 356 Legitimates Filtered in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 28/11/2012 - 20:17:11 - [] ----D C:\Program Files (x86)\ACE-HIGH MP3 WAV WMA OGG Converter O43 - CFD: 30/03/2014 - 21:07:13 - [] ----D C:\Program Files (x86)\Cabinet O43 - CFD: 29/04/2014 - 21:10:08 - [] ----D C:\Program Files (x86)\firedrive-downloader.com O43 - CFD: 03/05/2014 - 16:04:39 - [] ----D C:\Program Files (x86)\Vbsedit O43 - CFD: 14/03/2014 - 16:53:03 - [] ----D C:\Program Files (x86)\Video Converter v11.6.1 O43 - CFD: 07/05/2014 - 22:38:34 - [] ----D C:\ProgramData\eboostr O43 - CFD: 03/05/2014 - 16:04:42 - [] ----D C:\ProgramData\Vbsedit O43 - CFD: 12/02/2014 - 22:46:53 - [] -SH-D C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} O43 - CFD: 06/05/2014 - 15:58:12 - [] ----D C:\Users\PC Jean-Marie\AppData\Roaming\Adersoft O43 - CFD: 30/03/2014 - 21:07:22 - [0] ----D C:\Users\PC Jean-Marie\AppData\Roaming\Cabinet O43 - CFD: 03/05/2014 - 15:46:23 - [0] ----D C:\Users\PC Jean-Marie\AppData\Roaming\{772d7071-ced3-40ae-a49c-b7ea03801a4d} O43 - CFD: 03/05/2014 - 16:04:52 - [] ----D C:\Users\PC Jean-Marie\AppData\Local\Adersoft O43 - CFD: 10/02/2014 - 16:05:06 - [] ----D C:\Users\PC Jean-Marie\AppData\Local\RTKSM1.0.3 O43 - CFD: 28/11/2012 - 20:15:28 - [0] ----D C:\Users\PC Jean-Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ACE-HIGH MP3 WAV WMA OGG Converter ~ Program Folder: 223 Legitimates Filtered in 00mn 01s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.39E55F0BE3F93DBCB307FA4101C54615] - 03/05/2014 - 17:29:59 ---A- . (...) -- C:\Windows\cdplayer.ini [34] O44 - LFC:[MD5.0277C027A26428DB64EF4F64F52BB4FD] - 06/05/2014 - 16:56:07 ---A- . (...) -- C:\Windows\MBR.exe [208896] O44 - LFC:[MD5.F042EE4C8D66248D9B86DCF52ABAE416] - 06/05/2014 - 16:56:07 ---A- . (...) -- C:\Windows\PEV.exe [256000] O44 - LFC:[MD5.9E05A9C264C8A908A8E79450FCBFF047] - 06/05/2014 - 16:56:07 ---A- . (...) -- C:\Windows\grep.exe [80412] O44 - LFC:[MD5.2B657A67AEBB84AEA5632C53E61E23BF] - 06/05/2014 - 16:56:07 ---A- . (...) -- C:\Windows\sed.exe [98816] O44 - LFC:[MD5.5E832F4FAF5F481F2EAF3B3A48F603B8] - 06/05/2014 - 16:56:07 ---A- . (...) -- C:\Windows\zip.exe [68096] O44 - LFC:[MD5.3CF3D4A45CC2AF973DBC30EC8D33252B] - 06/05/2014 - 17:01:29 ---A- . (...) -- C:\Windows\system.ini [215] O44 - LFC:[MD5.E52B5374E20977B0B951CEC0F361146A] - 06/05/2014 - 17:02:39 ---A- . (...) -- C:\ComboFix.txt [38485] O44 - LFC:[MD5.0A34066D56D57C0DA73BFFC1E4169FF2] - 07/05/2014 - 21:25:49 ---A- . (...) -- C:\Windows\wininit.ini [85] O44 - LFC:[MD5.77FE137CCD96029F0BCF90D48293CFAB] - 23/04/2014 - 08:26:55 ---A- . (...) -- C:\Windows\System32\SavingsBullFilterService.log [765346871] =>PUP.SavingsBull O44 - LFC:[MD5.871CFAC7770A9ECFC20E4BD84F9F1A7E] - 27/04/2014 - 08:04:18 R--A- . (...) -- C:\Windows\hosts.20140427-090440.backup [449885] O44 - LFC:[MD5.679B63D7003DEAAC424A699D6E8CD254] - 29/04/2014 - 14:21:16 ---A- . (...) -- C:\Windows\System32\GDIPFONTCACHEV1.DAT [8224] ~ Files: 31 Legitimates Filtered in 00mn 59s ---\\ Opérations et fonctions au démarrage de Windows Explorer (O46) O46 - SEH:ShellExecuteHooks - Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL O46 - SEH:ShellExecuteHooks - Groove GFS Stub Execution Hook [64Bits] - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL ~ ShellExecuteHooks: Scanned in 00mn 00s ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 19 Legitimates Filtered in 00mn 00s ---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56) O56 - MWPE:[HKCU\...\policies\Explorer] - "NoCDBurning"=1 ~ MWPE Keys: 6 Legitimates Filtered in 00mn 00s ---\\ Liste des pilotes du système (SDL) (O58) O58 - SDL:03/06/2009 - 00:58:24 ---A- . (.ITETech - AF9015 BDA Driver.) -- C:\Windows\System32\Drivers\AF15BDA.sys [507392] O58 - SDL:15/04/2010 - 14:58:52 ---A- . (.eBoostr.com - eBoostr Filter Driver.) -- C:\Windows\System32\Drivers\eBoost.sys [185048] O58 - SDL:14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496] O58 - SDL:10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232] O58 - SDL:17/12/2013 - 16:09:02 ---A- . (.NetFilterSDK.com - NetFilter SDK TDI Hook Driver (WPP).) -- C:\Windows\System32\Drivers\netfilter64.sys [61592] O58 - SDL:06/12/2013 - 15:47:12 ---A- . (.Secunia - Secunia PSI Driver.) -- C:\Windows\System32\Drivers\psi_mf_amd64.sys [18456] O58 - SDL:16/02/2014 - 23:59:44 ---A- . (.Feitian Technologies Co., Ltd. - Rockey Device Driver.) -- C:\Windows\System32\Drivers\Rockey4.sys [36904] O58 - SDL:16/02/2014 - 23:59:44 ---A- . (.Feitian Technologies Co., Ltd. - Rockey USB Driver.) -- C:\Windows\System32\Drivers\Rockey4USB.sys [23592] O58 - SDL:14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656] O58 - SDL:19/12/2012 - 08:42:10 ---A- . (...) -- C:\Windows\System32\Drivers\t_mouse.sys [6144] O58 - SDL:07/03/2013 - 09:49:18 ---A- . (...) -- C:\Windows\System32\epmntdrv.sys [17480] O58 - SDL:07/03/2013 - 09:49:18 ---A- . (...) -- C:\Windows\System32\EuGdiDrv.sys [9800] O58 - SDL:21/08/2012 - 19:54:10 R--A- . (...) -- C:\Windows\SysWOW64\drivers\AsIO.sys [15232] O58 - SDL:02/04/2009 - 13:30:14 ---A- . (...) -- C:\Windows\SysWOW64\drivers\ASUSHWIO.SYS [10296] O58 - SDL:07/03/2013 - 09:49:20 ---A- . (...) -- C:\Windows\SysWOW64\epmntdrv.sys [14920] O58 - SDL:07/03/2013 - 09:49:20 ---A- . (...) -- C:\Windows\SysWOW64\EuGdiDrv.sys [9160] ~ Drivers: 82 Legitimates Filtered in 00mn 01s ---\\ Liste des outils de désinfection (LATC) (O63) O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn 00s ---\\ Liste les services legacy du registre (LALS) (O64) O64 - Services: CurCS - 15/04/2010 - C:\Windows\System32\drivers\eBoost.sys (eBoost) .(.eBoostr.com - eBoostr Filter Driver.) - LEGACY_EBOOST O64 - Services: CurCS - 17/12/2013 - C:\Windows\System32\drivers\netfilter64.sys (netfilter64) .(.NetFilterSDK.com - NetFilter SDK TDI Hook Driver (WPP).) - LEGACY_NETFILTER64 O64 - Services: CurCS - 06/12/2013 - C:\Windows\System32\DRIVERS\psi_mf_amd64.sys (PSI) .(.Secunia - Secunia PSI Driver.) - LEGACY_PSI ~ Legacy: 87 Legitimates Filtered in 00mn 00s ---\\ Menu de démarrage Internet (SMI) (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Recherche particulière à la racine du système (SPRF) (O84) [MD5.A53555B250CBEDCA6544D13648F83FFE] [SPRF][05/05/2014] (...) -- C:\Users\PC Jean-Marie\Desktop\adwcleaner.exe [1316991] ~ Files: 4 Legitimates Filtered in 00mn 00s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 06/05/2014 257712 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe SS - | Auto 07/02/2014 31192 | (Autodesk Content Service) . (.Autodesk, Inc..) - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe SS - | Demand 25/05/2009 25216 | (EverestDriver) . (...) - C:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 SS - | Demand 16/02/2014 1087792 | (FlexNet Licensing Service) . (.Flexera Software LLC.) - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe SS - | Demand 14/04/2014 1357104 | (FlexNet Licensing Service 64) . (.Flexera Software LLC.) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe SS - | Demand 13/02/2013 820184 | (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe SS - | Demand 05/03/2014 118896 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe SR - | Auto 22/12/2013 576904 | (AdAppMgrSvc) . (.Autodesk Inc..) - C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe SR - | Auto 29/10/2012 927232 | (asComSvc) . (...) - C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe SR - | Demand 25/01/2010 245760 | (BrYNSvc) . (.Brother Industries, Ltd..) - C:\Program Files (x86)\Browny02\BrYNSvc.exe SR - | Auto 15/04/2010 811136 | (EBOOSTRSVC) . (.eBoostr.com.) - C:\Program Files\eBoostr\EBstrSvc.exe SR - | Auto 07/03/2012 913144 | (ekrn) . (.ESET.) - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe SR - | Auto 30/05/2012 13632 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe SR - | Auto 13/02/2013 731648 | (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe SR - | Auto 03/01/2013 183200 | (Intel(R) PROSet Monitoring Service) . (.Intel Corporation.) - C:\Windows\system32\IProsetMonitor.exe SR - | Auto 12/03/2013 169432 | (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe SR - | Auto 12/03/2013 366552 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe SR - | Auto 20/01/2014 2818896 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe SR - | Auto 23/10/2013 922912 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe SR - | Auto 27/10/2013 1364256 | (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe SR - | Auto 09/03/2010 144672 | (PDFProFiltSrvPP) . (.Nuance Communications, Inc..) - C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe SR - | Auto 06/12/2013 1229528 | (Secunia PSI Agent) . (.Secunia.) - C:\Program Files (x86)\Secunia\PSI\PSIA.exe SR - | Auto 06/12/2013 662232 | (Secunia Update Agent) . (.Secunia.) - C:\Program Files (x86)\Secunia\PSI\sua.exe SR - | Auto 23/10/2013 414496 | (Stereo Service) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Services: Scanned in 00mn 05s ---\\ Scan Additionnel (O88) Database Version : 13045 - (04/05/2014) Clés trouvées (Keys found) : 0 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 0 Fichiers trouvés (Files found) : 0 ~ Additionnel Scan: 408886 Items scanned in 00mn 23s ---\\ Récapitulatif des détections trouvées sur votre station http://nicolascoolman.webs.com/apps/blog/show/41823682-pup-savingsbull =>PUP.SavingsBull ~ MSI: 1 link(s) detected in 00mn 00s ~ 902 Legitimates filtered by white list End of the scan (474 lines in 02mn 03s)(0)