~ Rapport de ZHPDiag v2015.2.19.22 - Nicolas Coolman (19/02/2015) ~ Lancé par Bernard (24/02/2015 17:49:55) ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ Adresse du Forum http://forum.nicolascoolman.fr ~ Traduit par Nicolas Coolman ~ Etat de la version : Nouvelle version disponible ~ Liste blanche : Activée par le programme ~ Elévation des Privilèges : OK ~ User Account Control (UAC): Deactivate by user ---\\ Navigateurs Internet MSIE: Internet Explorer v11.0.9600.17633 (Defaut) MFIE: Mozilla Firefox 31.0 ---\\ Informations sur les produits Windows ~ Langage: Français Windows Server License Manager Script : OK ~ Windows Operating System - Windows(R) 7, OEM_COA_SLP channel Windows ID Activation : OK ~ Windows Partial Key : KF2YT Windows License : OK ~ Windows Remaining Initializations Number : 3 Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601) ---\\ Logiciels de protection du système Antivirus Pro v14.0.7.468 Malwarebytes Anti-Malware version 2.0.4.1028 Microsoft Security Client FR-FR Language Pack v2.1.1116.0 Kaspersky Security Scan v12.0.1.881 Windows Defender W7 (Activate) ---\\ Logiciels d'optimisation du système CCleaner v5.02 ---\\ Logiciels de partage PeerToPeer eMule ---\\ Surveillance de Logiciels Adobe Flash Player 16 NPAPI Adobe Reader XI ---\\ Informations sur le système ~ Processor: Intel64 Family 6 Model 37 Stepping 5, GenuineIntel ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 12151 MB (73% free) System Restore: Désactivé (Disabled) System drive C: has 55 GB (34%) free of 159 GB ---\\ Mode de connexion au système ~ Computer Name: PC-BERNARD ~ User Name: Bernard ~ All Users Names: HomeGroupUser$, Emilie, Bernard, Administrateur, ~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89 Logged in as Administrator ---\\ Variables d'environnement ~ System Unit : C:\ ~ %AppZHP% : C:\Users\Bernard\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\Bernard\AppData\Roaming\ ~ %Desktop% : C:\Users\Bernard\Desktop\ ~ %Favorites% : C:\Users\Bernard\Favorites\ ~ %LocalAppData% : C:\Users\Bernard\AppData\Local\ ~ %StartMenu% : C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumération des unités disques C: Hard drive, Flash drive, Thumb drive (Free 55 Go of 159 Go) D: Hard drive, Flash drive, Thumb drive (Free 321 Go of 772 Go) E: CD-ROM drive (Not Inserted) F: CD-ROM drive (Not Inserted) ---\\ Etat du Centre de Sécurité Windows [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified ~ Security Center: 50 Legitimates Filtered in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808] [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024] [MD5.9DFE41A69DF70AAB75CB5BA8C1109EA2] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.12/01/2015 - 02:27:32.) -- C:\Windows\System32\wininet.dll [2358272] [MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.17/07/2014 - 03:07:24.) -- C:\Windows\System32\Winlogon.exe [455168] [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.21/11/2010 - 04:24:16.) -- C:\Windows\System32\sppcomapi.dll [232448] [MD5.FA886682CFC5D36718D3E436AACF10B9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:45:52.) -- C:\Windows\system32\Drivers\AFD.sys [497152] [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128] [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160] [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456] [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.21/11/2010 - 04:24:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400] [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368] [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472] [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224] [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208] [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.21/11/2010 - 04:23:51.) -- C:\Windows\system32\Drivers\netBT.sys [261632] [MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:37:55.) -- C:\Windows\system32\Drivers\ntfs.sys [1684928] [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280] [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.21/11/2010 - 04:24:33.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536] [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184] [MD5.70988118145F5F10EF24720B97F35F65] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:46:26.) -- C:\Windows\system32\Drivers\tdx.sys [119296] [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\volsnap.sys [295808] ~ Generic Processes: Scanned in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 1/161 ~ Mes musiques (My Musics) : 1/2 ~ Mes Videos (My Videos) : 1/3 ~ Mes Favoris (My Favorites) : 1/1824 ~ Mes Documents (My Documents) : 2/2083 ~ Mon Bureau (My Desktop) : 1/41 ~ Menu demarrer (Programs) : 1/230 ~ Hidden Files: Scanned in 00mn 03s ---\\ Processus lancés [MD5.4F011F572DAC7057DF9D6E9064AA77E8] - (.NVIDIA Corporation - NVIDIA GeForce Experience Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2460488] [PID.2428] [MD5.A2DBDE21B550F57EC83AEAC2034D12A5] - (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe [110160] [PID.2552] [MD5.A162B967A88BF374A81E01EF6E7A2655] - (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768] [PID.2716] [MD5.8943465BEFA91044227D42E84ECB8280] - (.Renesas Electronics Corporation - USB 3.0 Monitor.) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048] [PID.2852] [MD5.8FFDB89A0FB7C8ABC3A8825E38047341] - (.Logitech Inc. - Logitech Webcam Software.) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136] [PID.3040] [MD5.E4C53CE8409DCFF708C790A0AC76398D] - (...) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe [264040] [PID.3424] [MD5.0C04D13438560D24EA3A97BD7B26B5B7] - (.RaMMicHaeL - Unchecky Background Process.) -- C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe [402536] [PID.372] [MD5.B17B3A8C3A11D20F9D9C8F4D83DAF050] - (.Intel Corporation - IAStorIcon.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [323312] [PID.4984] [MD5.E98EA7471918E1987075815DC4C61001] - (.Yahoo! Inc. - Yahoo! Widgets.) -- C:\Program Files (x86)\Yahoo!\Widgets\YahooWidgets.exe [4742184] [PID.6788] [MD5.F3F709C2D49DD6636F4EDE5C2CAE5448] - (.http://www.emule-project.net - eMule.) -- C:\Program Files (x86)\eMule\emule.exe [5758976] [PID.6036] =>P2P.eMule [MD5.9153F2335BCDB87F41559CF066223BF9] - (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [508800] [PID.7964] [MD5.506708142BC63DABA64F2D3AD1DCD5BF] - (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Bernard\AppData\Local\Google\Update\GoogleUpdate.exe [116648] [PID.2300] [MD5.883008A9B5BFF94A153D99DBA54CB5C1] - (.Hewlett-Packard - GPCore COM object.) -- C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe [362496] [PID.5132] [MD5.F16EEA6CCA9D8A7D1193AE80E43FBBC7] - (.Hewlett-Packard Co. - HP CUE Status Root.) -- C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe [168960] [PID.7284] [MD5.8A9FACCB684500829F7D0BCC67B386CC] - (.Hewlett-Packard Co. - HP CUE Alert Popup Window Objects.) -- C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe [559104] [PID.6516] [MD5.F6158734F1E24C6C510155CF0D363911] - (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512] [PID.5944] [MD5.51138BEEA3E2C21EC44D0932C71762A8] - (...) -- ysWOW64\RUNDLL32.exe [0] [PID.3256] [MD5.16AFB34618E1286FF856DC600AC49C79] - (.Pas de propriétaire - DivX Update.) -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968] [PID.3284] [MD5.24FF7E8C2F71E3E5C11936EE948BB68D] - (.McAfee, Inc. - SiteAdvisor.) -- C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe [1205944] [PID.6352] [MD5.363BC25BACB34E9D40441968B1B3D5BE] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\IEXPLORE.exe [815288] [PID.5640] [MD5.E8B7FD67DA14A7BE57A5CB80E3139E60] - (.Google Inc. - Google Toolbar Broker.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe [309704] [PID.2280] [MD5.3A482BF9D10776B2EB0A52C9C87158E0] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8176128] [PID.3620] [MD5.A63DC5C2EA944E6657203E0C8EDEAF61] - (.Microsoft Corporation - COM Surrogate.) -- C:\Windows\SysWOW64\DllHost.exe [7168] [PID.0] [MD5.2F442BAA7A739EDFB8CBF6BFBE8F5388] - (.IObit - Advanced SystemCare Service.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [815392] [PID.948] [MD5.C2700D35AA42311A32DF7EA09630B401] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920] [PID.1672] [MD5.FC5B75CA6A1DA31EDD4F8D53F5540B98] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [81088] [PID.1028] [MD5.C2700D35AA42311A32DF7EA09630B401] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920] [PID.1212] [MD5.C34411A244029F1C08687F7C752C4563] - (.Hewlett-Packard Company - LightScribe Service.) -- C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728] [PID.1692] [MD5.E38775922D4A4C05B5D96733AB4CE169] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [268824] [PID.2192] [MD5.F172AD4E906D97ED8F071896FC6789DC] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912] [PID.2300] [MD5.83BB030C71C9727DCFB2737005772C4E] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe [232264] [PID.2416] [MD5.7CF1B716372B89568AE4C0FE769F5869] - (.Microsoft Corporation - Machine Debug Manager.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872] [PID.2924] [MD5.63694C307273062A2167AE4CE80730EF] - (.Sony Corporation - Device Information Provider.) -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [398176] [PID.1516] [MD5.E1E13735B6D2FE4FFEAEB91989B9C46F] - (.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5436176] [PID.3580] [MD5.FD2804048115F06FD8402C3255E0BC78] - (.RaMMicHaeL - Unchecky Service.) -- C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [126568] [PID.3776] [MD5.02C298382359653BEC4C737C2AB7F9C5] - (.Intel Corporation - User Notification Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2320920] [PID.3796] [MD5.7D6FFF60082AD63C5D8C67D7BDE7F034] - (.Intel Corporation - IAStorDataSvc.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [19184] [PID.816] [MD5.D0F2BD42CD3AC015BD93A81638210BC7] - (.Avira Operations GmbH & Co. KG - Antivirus MailScanner WFP Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [807672] [PID.4856] [MD5.027820FE847A7B4245234A4E6E825BE1] - (.Avira Operations GmbH & Co. KG - AntiVir WebGuard WFP Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [993584] [PID.4692] [MD5.C7F5C284B6F46FCAF6910EA4E644700B] - (.Nero AG - Nero BackItUp.) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [935208] [PID.6136] ~ Processes Running: Scanned in 00mn 01s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Users\Bernard\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js C:\Users\Bernard\AppData\Roaming\Mozilla\Firefox\Profiles\y34b53cq.default\prefs.js M2 - MFEP: RegExtension {22119944-ED35-4ab1-910B-E619EA06A115} . (...) -- ~ Firefox Browser: 36 Legitimates Filtered in 00mn 00s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = preserve ~ IE Browser: 21 Legitimates Filtered in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 0 ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\System32\Userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Hosts file redirection (O1) ~ Le fichier hôte est sain (The hosts file is clean) (15546) ~ Hosts File: Scanned in 00mn 07s ---\\ Browser Helper Objects de navigateur (O2) O2 - BHO: Ads Removal [64Bits] - {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} . (.Adblock - Helps you remove browser ads!.) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll O2 - BHO: Adblock Plus for IE Browser Helper Object [64Bits] - {FFCB3198-32F3-4E8B-9539-4324694ED664} . (.Adblock Plus - Adblock Plus Module.) -- C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll ~ BHO: 23 Legitimates Filtered in 00mn 00s ---\\ Internet Explorer Toolbars (O3) O3 - Toolbar: McAfee SiteAdvisor Toolbar - [HKLM]{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} . (.McAfee, Inc. - SiteAdvisor.) -- C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll O3 - Toolbar: &RoboForm Toolbar - [HKLM]{724d43a0-0d85-11d4-9908-00400523e39a} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline O3 - Toolbar\WebBrowser: (no name) - [HKCU]{71576546-354D-41C9-AAE8-31F2EC22BF0D} Clé orpheline O3 - Toolbar\WebBrowser: (no name) - [HKCU]{724D43A0-0D85-11D4-9908-00400523E39A} Clé orpheline O3 - Toolbar\WebBrowser: (no name) - [HKCU]{D3028143-6145-4318-99D3-3EDCE54A95A9} Clé orpheline ~ Toolbar: Scanned in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\Desktop [Public]: eMule.lnk . (.http://www.emule-project.net - eMule.) -- C:\Program Files (x86)\eMule\emule.exe =>P2P.eMule O4 - GS\Desktop [Bernard]: Ebay - Bernard.LNK . (...) -- C:\Users\Bernard\Documents\My RoboForm Data\Default Profile\Ebay - Bernard.rfp -l (.not file.) =>Toolbar.eBay ~ Global Startup: 2 Legitimates Filtered in 00mn 13s ---\\ Applications lancées au démarrage du système (O4) O4 - HKLM\..\Run: [NvBackend] . (.NVIDIA Corporation - NVIDIA GeForce Experience Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe O4 - HKLM\..\Run: [EvtMgr6] . (.Logitech, Inc. - Logitech SetPoint Event Manager (UNICODE).) -- C:\Program Files\Logitech\SetPointP\SetPoint.exe O4 - HKLM\..\Run: [IAStorIcon] . (.Intel Corporation - Delayed launcher.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp O4 - HKCU\..\Run: [RoboForm] . (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] . (.Disc Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe =>.DT Soft Ltd O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe O4 - HKLM\..\Wow6432Node\Run: [GrooveMonitor] . (.Microsoft Corporation - GrooveMonitor Utility.) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe O4 - HKLM\..\Wow6432Node\Run: [NUSB3MON] . (.Renesas Electronics Corporation - USB 3.0 Monitor.) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe O4 - HKLM\..\Wow6432Node\Run: [LWS] . (.Logitech Inc. - Logitech Webcam Software.) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe =>.Logitech Inc O4 - HKUS\S-1-5-21-2503739192-254968964-1925577246-1001\..\Run: [RoboForm] . (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe O4 - HKUS\S-1-5-21-2503739192-254968964-1925577246-1001\..\Run: [DAEMON Tools Lite] . (.Disc Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe =>.DT Soft Ltd O4 - HKUS\S-1-5-21-2503739192-254968964-1925577246-1001\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ~ Application: Scanned in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: Remplir les formulaires [64Bits] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll O9 - Extra button: Enregistrer les formulaires [64Bits] - {320AF880-6646-11D3-ABEE-C5DBF3571F49} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll O9 - Extra button: Personnaliser le menu [64Bits] - {320AF880-6646-11D3-ABEE-C5DBF3571F4E} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll O9 - Extra button: Barre RoboForm [64Bits] - {724d43aa-0d85-11d4-9908-00400523e39a} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll O9 - Extra button: Skype Click to Call [64Bits] - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- c:\program files (x86)\skype\toolbars\internet explorer x64\icon.ico ~ IE Extra Buttons: Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{0D5C9240-E3CF-402D-98BC-E4642A24EA9B}: DhcpNameServer = 192.168.1.10 192.168.1.10 O17 - HKLM\System\CS1\Services\Tcpip\..\{0D5C9240-E3CF-402D-98BC-E4642A24EA9B}: DhcpNameServer = 192.168.1.10 192.168.1.10 O17 - HKLM\System\CS2\Services\Tcpip\..\{0D5C9240-E3CF-402D-98BC-E4642A24EA9B}: DhcpNameServer = 192.168.1.10 192.168.1.10 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.10 192.168.1.10 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: wot [64Bits] - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} . (...) -- O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: LBTWlgn . (.Logitech, Inc. - Logitech Bluetooth Service.) -- c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll ~ Winlogon: Scanned in 00mn 00s ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22) O22 - SharedTaskScheduler: (no name) [64Bits] - {73526E5A-FD53-4BE7-B5E2-D3C89D7413DC} - (.not file.) ~ STS/SSO: Scanned in 00mn 00s ---\\ Tâches planifiées en automatique (O39) [MD5.00000000000000000000000000000000] [APT] [{164C8768-29C1-4F1A-B70D-CDAA94C6D145}] (...) -- E:\Documents Ma Mule\Bernard\Watcher_Setup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{1CD023A9-8ED7-4102-B909-ED3FC8032054}] (...) -- F:\Setup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{1ED7B2B4-8882-461E-A5CC-E9B3F35850F2}] (...) -- E:\mura.bernard\RegCleaner V4.3.0.780.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{2C24FB4C-E1BA-4ECE-92FA-02588E01896C}] (...) -- E:\mura.bernard\WinZip 9.0 Fr + Keygen\Setup Winzip 9.0\SETUP.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{2F935AB3-F37A-4E97-82E1-C1A5935AF7B8}] (...) -- E:\mura.bernard\Worldwind_1.4_IGE_PluginFrancais_1.0.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{3086A7A1-508B-4D72-9A1F-2FF0CF876247}] (...) -- D:\mura.bernard\WinAce 2.55 Fr + Key\w25b5_fr.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{332B5B5C-44C1-4E14-901A-1D969FE55662}] (...) -- E:\mura.bernard\Everio mediaBrowser HD Edition V 2.02.23.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{4242B7C6-BBB3-4B52-9D6D-1E1B7E137408}] (...) -- D:\mura.bernard\[3DMark.2006.Professional.Edition].3DMark06_v102_installer\3DMark06_v102_installer.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{48D1180A-694A-490C-A846-A2BE12A1D191}] (...) -- D:\mura.bernard\HOSTS_Install_V2.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{54E6FC19-4CBC-4D7F-9927-98AA2283C568}] (...) -- C:\Users\Bernard\Desktop\OverDisk011b.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{61ECB5BE-D2E1-4175-82B4-D942287AFDF8}] (...) -- D:\mura.bernard\Q-Dir 5.68\Q-Dir_Installer.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{717ECDFE-5ED4-4136-B164-9C0C26A0BC69}] (...) -- D:\mura.bernard\RegCleaner V4.3.0.780.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{7C8C3F18-3F26-4014-B7AB-17F34B3F710E}] (...) -- E:\mura.bernard\Windirstat V 1.1.2.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{85FF3D00-AF4D-412E-8B2D-94AF61CC8B4E}] (...) -- D:\mura.bernard\Q-Dir 5.61\Q-Dir_Installer.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{899B7A70-2979-4501-A1A5-C278DDD5C980}] (...) -- E:\mura.bernard\jre-6u29-windows-i586-iftw.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{B1385BB0-CFA4-418B-B2D5-A6ADD6574377}] (...) -- E:\mura.bernard\Cities 3D.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{C6CF36D1-CA8C-4062-925D-5507DC051351}] (...) -- E:\Documents Ma Mule\Bernard\Digi Watcher 2.30 + Remote View 1.40 - Webcam Spy\Digi.Watcher.v2.30.WinAll.Incl.Keygenerator-TMG\Watcher_Setup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{CEF3BE90-C84F-4F4D-B9B4-4D7CE38EF454}] (...) -- C:\Users\Bernard\AppData\Local\Temp\tasks\PSSetup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{CF102249-EC4A-4DB7-BE13-A47AB839FB95}] (...) -- E:\Documents Ma Mule\Bernard\AutoCAD Architecture 2009\setup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{D64C8214-B066-478C-A58D-E62F57B59B9E}] (...) -- E:\Documents Ma Mule\Bernard\Setup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{E0C5BAC2-544C-4319-B76E-514260B807F2}] (...) -- F:\ScreenSaver\ScreenSaver.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{F0B39416-0058-4009-9D54-E15191210AE1}] (...) -- C:\Users\Bernard\Desktop\FSXDemo.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{F41DC170-5789-4843-A957-D840682AB270}] (...) -- E:\Documents Ma Mule\Bernard (.not file.) [0] [MD5.3ABF1C149873E25D4E266225FBF37CBF] [APT] [{F8DBCDA0-F393-408A-89C5-27E0BC364B72}] (...) -- D:\mura.bernard\Windirstat V 1.1.2.exe [645729] [MD5.00000000000000000000000000000000] [APT] [{F979C2E0-F74C-4670-A411-2D1621A4C1F1}] (...) -- E:\mura.bernard\Epson Stylus SX 105.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{FCB90EDB-C2C8-43AC-82B8-49F86631A228}] (...) -- C:\Users\Bernard\Desktop\internettv_setup[1].exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{FE5F614C-2B70-4C0E-8779-8DFC2FE7C1F1}] (...) -- D:\mura.bernard\favorg (mise … jour des icones)\FavOrg (gère les icones des favoris).exe (.not file.) [0] O39 - APT: - (..) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002] O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1066] O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1070] O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2503739192-254968964-1925577246-1001Core [1034] O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2503739192-254968964-1925577246-1001UA [1086] O39 - APT: - (..) -- C:\Windows\System32\Tasks\Spybot - Search & Destroy - Scheduled Task [304] O39 - APT: - (..) -- C:\Windows\System32\Tasks\Spybot - Search & Destroy Updater - Scheduled Task [330] ~ Scheduled Task: 57 Legitimates Filtered in 00mn 05s ---\\ Logiciels installés (O42) O42 - Logiciel: AC3File 0.6b - (.Alexander Vigovsky.) [HKLM][64Bits] -- AC3File_is1 O42 - Logiciel: Billiardino 1.0 - (.Falco Software, Inc..) [HKLM][64Bits] -- Billiardino_is1 O42 - Logiciel: Billiards Club - (.FreeGamePick.com.) [HKLM][64Bits] -- Billiards Club_is1 O42 - Logiciel: Bowling Evolution 1.05 - (...) [HKLM][64Bits] -- Bowling Evolution 1.05 O42 - Logiciel: Cities of Earth 3D Screensaver v. 2.1 - (.Screenomania.com.) [HKLM][64Bits] -- Cities of Earth 3D Screensaver_is1 O42 - Logiciel: FavOrg - (.PC Magazine.) [HKLM][64Bits] -- FavOrg O42 - Logiciel: Fmrid 4.01 - (.Fabio Chelly.) [HKLM][64Bits] -- Fmrid O42 - Logiciel: MenuUninstaller - (.Leizer Soft.) [HKLM][64Bits] -- {52BAA6C6-FAB0-46F3-9C14-ADDD1A85F6FE} O42 - Logiciel: Mozaik - (...) [HKLM][64Bits] -- Mozaik O42 - Logiciel: OSSearch version 0.7.1 - (.Parcouss.) [HKLM][64Bits] -- {BFCA578C-F5EB-49BF-B1C7-4ABE70471E22}_is1 O42 - Logiciel: OverDisk (remove only) - (...) [HKLM][64Bits] -- OverDisk O42 - Logiciel: UpStarter - (...) [HKCU][64Bits] -- UpStarter O42 - Logiciel: Windows Tweaker - (.SuRe Softwares.) [HKLM][64Bits] -- {092D4427-C1D9-43C0-B1BB-C8BCFE67D5C0} ~ Logic: 48 Legitimates Filtered in 00mn 01s ---\\ HKCU & HKLM Software Keys [HKCU\Software\BeauSoft] [HKCU\Software\Digi-Watcher C:] [HKCU\Software\Filefacts] [HKCU\Software\Fmrid] [HKCU\Software\FreshWebMaster] [HKCU\Software\FriedCookie] [HKCU\Software\Inventivio] [HKCU\Software\MovieCollection] [HKCU\Software\OB] [HKCU\Software\Parcouss Apps] [HKCU\Software\Reg] [HKCU\Software\Screenomania] [HKCU\Software\TVixC] [HKCU\Software\UCS] [HKCU\Software\babidyxp] [HKCU\Software\bunkus.org] [HKCU\Software\zyceffcal] [HKLM\Software\Wow6432Node\ADSRemoval] [HKLM\Software\Wow6432Node\FreshWebMaster] [HKLM\Software\Wow6432Node\Inventivio] [HKLM\Software\Wow6432Node\Reg] [HKLM\Software\Wow6432Node\Screenomania] [HKLM\Software\Wow6432Node\Secured-IE] [HKLM\Software\Wow6432Node\Virustotal] ~ Key Software: 963 Legitimates Filtered in 00mn 01s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 08/12/2014 - 14:12:50 - [] ----D C:\Program Files (x86)\3RVX O43 - CFD: 08/12/2014 - 14:12:51 - [] ----D C:\Program Files (x86)\AC3File O43 - CFD: 08/01/2015 - 18:17:36 - [] ----D C:\Program Files (x86)\AHD O43 - CFD: 08/12/2014 - 14:13:25 - [] ----D C:\Program Files (x86)\Beausoft O43 - CFD: 08/12/2014 - 14:13:25 - [] ----D C:\Program Files (x86)\Billiardino O43 - CFD: 08/12/2014 - 14:13:26 - [] ----D C:\Program Files (x86)\Bowling Evolution 1.05 O43 - CFD: 08/12/2014 - 14:13:26 - [] ----D C:\Program Files (x86)\Cities of Earth O43 - CFD: 08/12/2014 - 14:14:02 - [] ----D C:\Program Files (x86)\Crime Catcher O43 - CFD: 08/12/2014 - 14:14:17 - [] ----D C:\Program Files (x86)\EuroThink O43 - CFD: 08/12/2014 - 14:14:18 - [] ----D C:\Program Files (x86)\Fmrid O43 - CFD: 08/12/2014 - 14:14:18 - [] ----D C:\Program Files (x86)\Font Explorer O43 - CFD: 08/12/2014 - 14:14:20 - [] ----D C:\Program Files (x86)\FreshWebmaster O43 - CFD: 08/12/2014 - 14:14:21 - [] ----D C:\Program Files (x86)\Gigaset QuickSync O43 - CFD: 08/12/2014 - 14:18:41 - [] ----D C:\Program Files (x86)\LeeGT-Games O43 - CFD: 08/12/2014 - 14:18:42 - [] ----D C:\Program Files (x86)\Leizer Soft O43 - CFD: 08/12/2014 - 14:19:27 - [] ----D C:\Program Files (x86)\MalchroSoft O43 - CFD: 08/12/2014 - 14:20:53 - [] ----D C:\Program Files (x86)\Onwijs O43 - CFD: 25/12/2014 - 18:52:15 - [] ----D C:\Program Files (x86)\OSSearch O43 - CFD: 08/12/2014 - 14:20:55 - [] ----D C:\Program Files (x86)\OverDisk O43 - CFD: 08/12/2014 - 14:21:18 - [] ----D C:\Program Files (x86)\PMSSAARI O43 - CFD: 08/12/2014 - 14:21:18 - [] ----D C:\Program Files (x86)\QTranslate O43 - CFD: 21/07/2012 - 09:52:43 - [0] ----D C:\Program Files (x86)\Secured-IE O43 - CFD: 08/12/2014 - 14:21:48 - [] ----D C:\Program Files (x86)\User's Guide O43 - CFD: 23/12/2014 - 14:27:49 - [] ----D C:\Program Files (x86)\VJS Productions O43 - CFD: 08/12/2014 - 14:21:48 - [] ----D C:\Program Files (x86)\WAN Miniport IKEv2 O43 - CFD: 08/12/2014 - 14:21:57 - [] ----D C:\Program Files (x86)\Windows Tweaker O43 - CFD: 04/08/2011 - 17:29:56 - [0] ----D C:\Program Files (x86)\Yahoo! Jeux O43 - CFD: 08/12/2014 - 14:14:02 - [] ----D C:\Program Files (x86)\Common Files\WAN Miniport IKEv2 O43 - CFD: 08/12/2014 - 14:22:33 - [] ----D C:\ProgramData\Advanced Uninstaller PRO O43 - CFD: 08/12/2014 - 14:22:34 - [] ----D C:\ProgramData\bmkfieeegpeeafckaajcnajmpklckeah O43 - CFD: 08/12/2014 - 14:22:34 - [] ----D C:\ProgramData\ClamAV O43 - CFD: 11/05/2014 - 14:18:16 - [0] ----D C:\ProgramData\Duplicate Photo Cleaner O43 - CFD: 08/12/2014 - 14:22:35 - [] ----D C:\ProgramData\Gigaset QuickSync O43 - CFD: 22/02/2015 - 10:54:18 - [] ----D C:\ProgramData\ProductData O43 - CFD: 08/12/2014 - 14:23:41 - [] ----D C:\ProgramData\SecureAge Technology O43 - CFD: 08/12/2014 - 14:23:41 - [] ----D C:\ProgramData\SnowApp O43 - CFD: 08/01/2015 - 00:30:08 - [0] ----D C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} O43 - CFD: 08/12/2014 - 14:24:30 - [] -SH-D C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} O43 - CFD: 08/12/2014 - 14:22:56 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AC3File O43 - CFD: 08/01/2015 - 18:17:36 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AHD O43 - CFD: 08/12/2014 - 14:23:00 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Billiardino O43 - CFD: 08/12/2014 - 14:23:00 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bowling Evolution 1.05 O43 - CFD: 08/12/2014 - 14:23:01 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eReaders O43 - CFD: 08/12/2014 - 14:23:03 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fmrid O43 - CFD: 08/12/2014 - 14:23:04 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gigaset QuickSync O43 - CFD: 28/01/2015 - 07:49:51 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Grand Master Chess O43 - CFD: 08/12/2014 - 14:23:06 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I2P O43 - CFD: 08/12/2014 - 14:23:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Manuel de l’utilisateur O43 - CFD: 08/12/2014 - 14:23:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozaik O43 - CFD: 25/12/2014 - 18:52:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OSSearch O43 - CFD: 08/12/2014 - 14:23:12 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OverDisk O43 - CFD: 03/02/2015 - 16:57:05 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reanimator O43 - CFD: 08/12/2014 - 14:23:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Screenomania O43 - CFD: 08/12/2014 - 14:23:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SentryVision O43 - CFD: 12/04/2011 - 10:27:52 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 08/12/2014 - 14:23:18 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Tweaker O43 - CFD: 14/01/2014 - 11:38:22 - [0] ----D C:\Users\Bernard\AppData\Roaming\7 Sticky Notes O43 - CFD: 08/12/2014 - 14:44:06 - [] ----D C:\Users\Bernard\AppData\Roaming\Bitser O43 - CFD: 08/12/2014 - 14:44:06 - [] ----D C:\Users\Bernard\AppData\Roaming\ClassicShell O43 - CFD: 24/02/2015 - 12:56:27 - [] ----D C:\Users\Bernard\AppData\Roaming\CrazyPixels O43 - CFD: 08/12/2014 - 14:44:09 - [] ----D C:\Users\Bernard\AppData\Roaming\Efficient Calendar Free O43 - CFD: 08/12/2014 - 14:44:09 - [] ----D C:\Users\Bernard\AppData\Roaming\Ember_Media_Manager O43 - CFD: 08/12/2014 - 14:44:09 - [] ----D C:\Users\Bernard\AppData\Roaming\Epic_Pen O43 - CFD: 08/12/2014 - 14:44:09 - [] ----D C:\Users\Bernard\AppData\Roaming\Filey, Inc O43 - CFD: 08/12/2014 - 14:44:12 - [] ----D C:\Users\Bernard\AppData\Roaming\I2P O43 - CFD: 08/12/2014 - 14:44:12 - [] ----D C:\Users\Bernard\AppData\Roaming\Inventivio O43 - CFD: 09/11/2014 - 09:50:25 - [0] ----D C:\Users\Bernard\AppData\Roaming\Litecoin O43 - CFD: 08/01/2015 - 00:06:36 - [] ----D C:\Users\Bernard\AppData\Roaming\Mediatronic O43 - CFD: 08/12/2014 - 14:44:39 - [] ----D C:\Users\Bernard\AppData\Roaming\MultiMiner O43 - CFD: 20/02/2015 - 17:08:44 - [] ----D C:\Users\Bernard\AppData\Roaming\ProductData O43 - CFD: 08/12/2014 - 14:44:50 - [] ----D C:\Users\Bernard\AppData\Roaming\QTranslate O43 - CFD: 08/12/2014 - 14:59:32 - [] ----D C:\Users\Bernard\AppData\Roaming\Votre Budget 2008 O43 - CFD: 08/12/2014 - 14:59:33 - [] ----D C:\Users\Bernard\AppData\Roaming\WIPE2013 O43 - CFD: 08/01/2015 - 18:21:59 - [] ----D C:\Users\Bernard\AppData\Local\AHD O43 - CFD: 08/12/2014 - 14:42:59 - [] ----D C:\Users\Bernard\AppData\Local\Bitser O43 - CFD: 09/12/2014 - 08:22:25 - [] -SH-D C:\Users\Bernard\AppData\Local\EmieBrowserModeList O43 - CFD: 08/12/2014 - 14:43:00 - [] ----D C:\Users\Bernard\AppData\Local\Films O43 - CFD: 08/12/2014 - 14:43:06 - [] ----D C:\Users\Bernard\AppData\Local\hq O43 - CFD: 08/12/2014 - 14:43:06 - [] ----D C:\Users\Bernard\AppData\Local\IFM38 O43 - CFD: 08/12/2014 - 14:43:17 - [] ----D C:\Users\Bernard\AppData\Local\MovieCollection O43 - CFD: 08/12/2014 - 14:43:30 - [] ----D C:\Users\Bernard\AppData\Local\StudioGPU O43 - CFD: 08/12/2014 - 14:44:35 - [] ----D C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Font Explorer O43 - CFD: 08/12/2014 - 14:44:35 - [] ----D C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup O43 - CFD: 08/12/2014 - 14:44:36 - [] ----D C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QTranslate O43 - CFD: 08/12/2014 - 14:44:36 - [] ----D C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UpStarter ~ Program Folder: 834 Legitimates Filtered in 00mn 01s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.814231B961760C39A5807A43D8ED71E1] - 12/02/2015 - 13:01:14 ---A- . (...) -- C:\Windows\System32\Drivers\RTAIODAT.DAT [1443340] O44 - LFC:[MD5.531121E7ED50084B493A69F8F8A7A927] - 19/02/2015 - 17:48:06 ---A- . (...) -- C:\Windows\System32\Drivers\TrueSight.sys [37624] O44 - LFC:[MD5.C7BC96C3711C0D269DA26D1F0ECEC547] - 20/02/2015 - 10:50:20 ---A- . (...) -- C:\Windows\NeroDigital.ini [69] O44 - LFC:[MD5.64623C1D083F03D9BCC7FCA4944D685D] - 21/02/2015 - 07:21:57 ---A- . (...) -- C:\Windows\Q-Dir.ini [53241] O44 - LFC:[MD5.9A187570176002D975A7BEFF5C7D85EC] - 21/02/2015 - 07:24:01 ---A- . (...) -- C:\Windows\System32\TeamViewer10_Hooks.log [1001] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 22/02/2015 - 04:32:22 --HA- . (...) -- C:\asc_rdflag [0] O44 - LFC:[MD5.1E9484BD0A31A3734587E5C57109B18A] - 23/02/2015 - 07:57:24 ---A- . (...) -- C:\Windows\Antidote.ini [151] O44 - LFC:[MD5.BBEDE42CC460774922F542C746B4ED39] - 24/02/2015 - 05:08:11 ---A- . (...) -- C:\Windows\DirectX.log [872] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 24/02/2015 - 13:03:28 ---A- . (...) -- C:\media.avi [7146519552] O44 - LFC:[MD5.E86D31F57C99C05D9E21883B97B06DB9] - 24/02/2015 - 17:38:44 --HA- . (...) -- C:\os245053.bin [770] ~ Files: 125 Legitimates Filtered in 00mn 43s ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0 ~ MWPS: 19 Legitimates Filtered in 00mn 00s ---\\ Liste des pilotes du système (SDL) (O58) O58 - SDL:25/02/2013 - 21:05:09 ---A- . (.Doctor Web, Ltd. - Dr.Web boot operations for Windows.) -- C:\Windows\System32\Drivers\28F881EE1.sys [23080] O58 - SDL:01/03/2010 - 23:59:50 ---A- . (...) -- C:\Windows\System32\Drivers\cpqdfw.sys [24376] O58 - SDL:01/03/2010 - 23:59:50 ---A- . (...) -- C:\Windows\System32\Drivers\cqcpu.sys [24376] O58 - SDL:14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496] O58 - SDL:23/05/2013 - 07:39:24 ---A- . (.ThreatTrack Security - gfiark64.sys.) -- C:\Windows\System32\Drivers\gfiark.sys [41032] O58 - SDL:04/09/2013 - 13:57:44 ---A- . (.ThreatTrack Security - GFI Utility driver.) -- C:\Windows\System32\Drivers\gfiutil.sys [31264] O58 - SDL:10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232] O58 - SDL:25/05/2012 - 12:14:24 ---A- . (.GFI Software - GFI Anti-Rootkit Driver.) -- C:\Windows\System32\Drivers\SBREDrv.sys [57976] O58 - SDL:14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656] O58 - SDL:14/06/2010 - 08:32:54 ---A- . (.Teruten Inc - File System Mini Filter Drvier.) -- C:\Windows\System32\Drivers\TFsExDisk.sys [16448] O58 - SDL:19/02/2015 - 17:48:06 ---A- . (...) -- C:\Windows\System32\Drivers\TrueSight.sys [37624] O58 - SDL:18/12/2013 - 11:33:16 ---A- . (...) -- C:\Windows\System32\ampa.sys [17008] O58 - SDL:20/01/2005 - 02:17:12 ---A- . (...) -- C:\Windows\SysWOW64\drivers\ASUSHWIO.SYS [5824] O58 - SDL:25/10/2004 - 19:02:58 ---A- . (.EnTech Taiwan - Pas de description.) -- C:\Windows\SysWOW64\drivers\Entech.sys [21664] O58 - SDL:22/06/2004 - 14:44:50 ---A- . (.EnTech Taiwan - EnTech driver for Windows XP 64.) -- C:\Windows\SysWOW64\drivers\Entech64.sys [5632] O58 - SDL:04/11/2014 - 06:13:55 ---A- . (...) -- C:\Windows\SysWOW64\drivers\fsbts.sys [33920] O58 - SDL:19/11/2001 - 18:05:18 ---A- . (...) -- C:\Windows\SysWOW64\drivers\PciBus.sys [3972] O58 - SDL:07/11/2003 - 01:41:54 ---A- . (.Padus, Inc. - Padus(R) ASPI Shell.) -- C:\Windows\SysWOW64\drivers\pfc.sys [14604] O58 - SDL:27/06/2011 - 22:33:14 ---A- . (...) -- C:\Windows\SysWOW64\drivers\StarOpen.sys [5632] O58 - SDL:27/06/2011 - 22:33:28 ---A- . (.Teruten Inc - File System Mini Filter Drvier.) -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys [16392] O58 - SDL:06/10/2014 - 19:16:52 ---A- . (...) -- C:\Windows\SysWOW64\drivers\TrueSight.sys [33512] O58 - SDL:18/12/2013 - 11:33:16 ---A- . (...) -- C:\Windows\SysWOW64\ampa.sys [17008] O58 - SDL:22/05/2013 - 12:34:26 ---A- . (...) -- C:\Windows\SysWOW64\FsUsbExDisk.Sys [37344] ~ Drivers: 123 Legitimates Filtered in 00mn 01s ---\\ Liste des outils de désinfection (LATC) (O63) O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn 00s ---\\ Liste les services legacy du registre (LALS) (O64) O64 - Services: CurCS - 06/10/2009 - C:\Windows\System32\DRIVERS\ahcix64s.sys (ahcix64s) .(.Advanced Micro Devices, Inc - AMD AHCI Compatible Controller Driver for W.) - LEGACY_AHCIX64S ~ Legacy: 131 Legitimates Filtered in 00mn 00s ---\\ Menu de démarrage Internet (SMI) (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Not Key.) ~ Keys: Scanned in 00mn 00s ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {6760948A-B0DC-4609-AFCA-2AEE65C3AD83} [DefaultScope] - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {67E8070E-1367-4084-9842-1CC2529F8450} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - http://www.google.com O69 - SBI: SearchScopes [HKCU] {6A456D83-F537-4AE7-8CF7-C5F360467DF4} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {6A6CBE01-B002-40DD-8FCB-D3A9C443891B} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {6D29CC17-6070-489D-965C-2D71D7E12517} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {6E277445-A8BB-478B-AE65-127D85B42D91} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {6F9891E3-CF7F-4AC5-AA0B-54162E02F4D7} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {700763A0-827D-4AFB-87EB-E08D259EB903} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {71616FF6-880E-4A24-B09A-620DABD154B8} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {7340887D-0E7C-4226-AE34-43D5DDB7148F} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {734E0E7B-1A8A-46DF-8D6F-4D54A6E280A4} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {767261D4-63C1-4C53-9689-5F7D87104025} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {77D33A51-76CA-450C-88FF-627EBCD04902} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {815F5752-FF2E-48EA-B99F-756133D306E4} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {85266C11-0EB0-4688-98FC-F8352FDC2338} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {864C701A-86AF-4B4D-A83C-798D45E95CF1} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {8CC1BBF7-066C-4E6A-B4A2-F3C060643903} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {8CCD62F4-E0B0-4DE1-AD63-675F0A990366} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {8DCC93F7-8A7A-40A2-9EE8-09038885255E} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {8E1F7D78-DF08-4D2B-B1A9-68F3FB1DF20C} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {8F9B3F6A-9338-4153-A5D3-09383F322C58} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {97FED262-4930-4533-AF5C-C8AC5D0E8C85} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {9A61D469-914A-49CC-8C20-B96F29D63052} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {9AA05C71-A2DC-4B24-BBEE-8AB988DDB1F4} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {9C52C36C-F1F3-4403-A2FB-44DEF8402D19} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {A06B9CA9-EA6E-4A43-A8F2-1BD2979D7F31} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {A093DEBB-885B-4FB9-9A35-C1329E4C1AC2} - ((www.google.com) Google) - http://www.google.com O69 - SBI: SearchScopes [HKCU] {A0E1990F-8304-4ECD-84DD-56E26CEE0B21} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {A0F8DEA2-5D48-471A-911F-153F121A14AE} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {A2A449C8-C594-41D3-BF9E-354B31559BF3} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {A4417D08-AF66-478A-B815-82D7552CFDDB} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {A4D0AE10-451C-4F95-AAB5-C138C6CD339E} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {A5474D0B-ECC9-43DA-ACEC-D7D82B8C748E} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {A99B3E01-72A0-4FA7-9926-52AA105FD225} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {AD12731A-EC99-4AF9-839F-15223997B1F1} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {AD53B075-B03B-4198-BCA9-D6E37DA1C2C4} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {AE5BAB5F-82F7-4641-B323-87CD8B277A8D} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {AEF32450-A5AF-44C8-AC5E-96E9D3EAF447} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {AF0E3BF9-B731-4A04-9156-22988C071292} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {B4C85AEB-8C6C-470A-9F3A-8B4CBE6D1F4B} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {B6857709-B8A4-4FDA-9139-2546FB441DFA} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {B7F8CB05-1EF6-46A5-871E-EDAD1594FEEC} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {B868D93D-0058-4265-8F08-836D3E1C70B7} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {BDA971AA-2418-4B35-92D5-1DA6D4FDB568} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {C1172CEB-C6E9-4764-9689-A3AE7F30D4BE} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {C196A6BC-720E-4F16-AB30-C28ACA83F2CB} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {C212D322-F4AB-41C2-A4B4-336E9DA51876} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {C37A7AC1-F219-4847-8607-4C9145881120} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {C4DAE33B-CDF1-48C9-B264-D685465CDBE1} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {C64555A4-5198-48A1-9326-51C15D72EC9D} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {C87402E8-2ED8-43A4-8DA3-8FC9C28F282E} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {CA33C749-B8DF-481A-A3C2-7F81278A15BB} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {CB4A976D-3939-4959-8A11-7294D2017020} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {CB77D594-F256-4706-8FA6-C7EABDAE7B1A} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {CD005917-1752-4AFE-B77C-48FD4E253733} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {CD13888C-6BC6-4888-923B-1EFD99E84B51} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {CE273388-D6EC-4D03-AC8B-0675FAAB1165} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {CEC1B3A8-F90A-4EA6-8E9A-FD208C708BED} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {CF675203-1FD8-463B-8198-9941555CB819} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {D0318125-1D0B-42EE-AF57-DEB3DEA6C29B} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {D5D6E0A2-7EDB-43C7-936E-0B3178D3081B} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {D5F4A24E-B770-420E-A8DA-13089430ACBF} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {DBB3E13A-5564-4887-A702-DDA06E8A52FC} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {DC3E5B7D-DAB5-411C-9D60-15CC6FAA3AEC} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {DCDB4F81-C284-45D3-B7D3-29BE2957C6EE} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {E4642100-1838-4D29-BCC8-66EAF64A16D7} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {E60A5B34-AE11-425D-84CA-9C955235A0C1} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {E7079DAD-9875-487B-B43A-CA7868684E43} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {E826F700-F9E3-4521-A9D3-E941AD743EC9} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {EA394FAC-CBA6-4162-947C-0A4FABBF5384} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {EBE17A59-2D5D-444D-998F-31AC03635CED} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {EE411575-B3FE-4E87-9C10-CB52C4CB6387} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {EFDB6A6E-74DF-466B-832E-8AC2357A8442} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {F1B89E0E-AFB8-4873-9B5C-94D12C8E05C6} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {F3A96E86-5349-4CAA-94D8-D3C7C457C936} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {F3C6387E-547F-47B3-A5CE-3CB4FAA80314} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {FAC5EB2E-1021-4261-A6A2-6C9EF3F62D45} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {FE419FC8-3C2C-49E0-8256-BCC38C62BD75} - (Recherche sécurisée) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {FE4917DE-E58A-4D9A-A773-79D8816CD6FC} - (Recherche sécurisée) - http://fr.search.yahoo.com ~ Keys: Scanned in 00mn 00s ---\\ Recherche particulière à la racine du système (SPRF) (O84) [MD5.90A7C2C7404D877865ED6670339C51EC] [SPRF][25/12/2014] (...) -- C:\Users\Bernard\AppData\Roaming\System5908ConfigCollection.dat [24] [MD5.E168731F246AA436A38641340C85AB2B] [SPRF][30/09/2011] (...) -- C:\Program Files (x86)\Uninstall_IGE_PluginFrancais.exe [128004] ~ Files: 2 Legitimates Filtered in 00mn 00s ---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS) [MD5.35C918348CBB0877BCD5A3CF24C13761] [WIS][25/11/2012] (.DeltaInstaller - Delta Chrome Toolbar.) -- C:\Windows\Installer\930f79c.msi [573440] =>Toolbar.DeltaSearch ~ WIS: 1 Legitimates Filtered in 00mn 13s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Auto 09/01/2012 827456 | C:\Windows\TEMP\017012~1.exe (0170121424774047mcinstcleanup) . (.McAfee, Inc..) - C:\Windows\Temp\0170121424774047mcinst.exe SS - | Demand 01/09/2011 169624 | (AdobeActiveFileMonitor10.0) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe SS - | Demand 12/02/2015 267440 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe SS - | Demand 08/03/2010 192000 | (BsHelpCS) . (.IVT Corporation.) - C:\Program Files (x86)\IVT Corporation\BlueSoleil\BsHelpCS.exe SS - | Disabled 29/07/2009 163840 | (EPSON_EB_RPCV4_01) . (.SEIKO EPSON CORPORATION.) - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.exe SS - | Disabled 29/07/2009 126464 | (EPSON_PM_RPCV4_01) . (.SEIKO EPSON CORPORATION.) - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.exe SS - | Demand 19/01/2012 1030600 | (FLEXnet Licensing Service 64) . (.Macrovision Europe Ltd..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe SS - | Demand 19/06/2010 246520 | (GameConsoleService) . (.WildTangent, Inc..) - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe SS - | Auto 31/01/2015 107912 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 31/01/2015 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 11/08/2012 194032 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe SS - | Demand 09/09/2011 86072 | (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe =>.Hewlett-Packard Co SS - | Demand 06/08/2010 291896 | (HPClientSvc) . (.Hewlett-Packard Company.) - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe SS - | Demand 01/04/2014 49464 | (HPSupportSolutionsFrameworkService) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe SS - | Demand 22/10/2004 73728 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe SS - | Demand 24/03/2014 357144 | (LBTServ) . (.Logitech, Inc..) - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe SS - | Auto 16/01/2015 2724128 | (LiveUpdateSvc) . (.IObit.) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe SS - | Demand 15/10/2014 2820424 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe SS - | Auto 21/11/2014 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe SS - | Auto 21/11/2014 969016 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe SS - | Demand 24/01/2015 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe SS - | Demand 14/07/2009 27136 | C:\Windows\system32\HPZinw12.dll (Net Driver HPZ12) . (.Hewlett-Packard.) - C:\Windows\System32\svchost.exe SS - | Disabled 17/09/2014 1795912 | (NvNetworkService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe SS - | Disabled 17/09/2014 19439944 | (NvStreamSvc) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe SS - | Disabled 02/07/2014 935368 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe SS - | Demand 14/08/2013 39056 | (RealNetworks Downloader Resolver Service) . (...) - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe SS - | Disabled 06/12/2007 88560 | (Roxio UPnP Renderer 9) . (.Sonic Solutions.) - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe SS - | Disabled 06/12/2007 362992 | (Roxio Upnp Server 9) . (.Sonic Solutions.) - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUpnpService9.exe SS - | Auto 11/04/2009 313840 | (RoxLiveShare9) . (.Sonic Solutions.) - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe SS - | Demand 11/04/2009 1108464 | (RoxMediaDB9) . (.Sonic Solutions.) - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe SS - | Disabled 11/04/2009 170480 | (RoxWatch9) . (.Sonic Solutions.) - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe SS - | Demand 05/11/2014 73200 | (SandraAgentSrv) . (.SiSoftware.) - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3\RpcAgentSrv.exe SS - | Demand 30/06/2011 1191936 | (SgtSch2Svc) . (.Seagate.) - C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe SS - | Demand 04/02/2013 155824 | (Sony PC Companion) . (.Avanquest Software.) - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe SS - | Disabled 02/07/2014 411936 | (Stereo Service) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe SS - | Demand 05/06/2014 93040 | (TomTomHOMEService) . (.TomTom.) - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe SR - | Auto 04/11/2014 815392 | (AdvancedSystemCareService8) . (.IObit.) - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe SR - | Auto 17/12/2014 807672 | (AntiVirMailService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe SR - | Auto 17/12/2014 431920 | (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe SR - | Auto 17/12/2014 431920 | (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe SR - | Auto 17/12/2014 993584 | (AntiVirWebService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe SR - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe SR - | Demand 14/07/2009 27136 | C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll (hpqcxs08) . (.Hewlett-Packard Co..) - C:\Windows\System32\svchost.exe SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll (hpqddsvc) . (.Hewlett-Packard Co..) - C:\Windows\System32\svchost.exe SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.dll (HPSLPSVC) . (.Hewlett-Packard Co..) - C:\Windows\System32\svchost.exe SR - | Auto 04/12/2014 19184 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe SR - | Auto 04/03/2011 73728 | (LightScribeService) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe SR - | Auto 01/10/2009 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe SR - | Auto 12/02/2015 155368 | (McAfee SiteAdvisor Service) . (.McAfee, Inc..) - C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe SR - | Demand 24/09/2008 935208 | (Nero BackItUp Scheduler 4.0) . (.Nero AG.) - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe SR - | Auto 26/11/2010 398176 | (PMBDeviceInfoProvider) . (.Sony Corporation.) - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe SR - | Demand 14/07/2009 27136 | C:\Windows\system32\HPZipm12.dll (Pml Driver HPZ12) . (.Hewlett-Packard.) - C:\Windows\System32\svchost.exe SR - | Auto 04/09/2014 292568 | (RtkAudioService) . (.Realtek Semiconductor.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe SR - | Auto 17/02/2015 5436176 | (TeamViewer) . (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe SR - | Auto 01/02/2015 126568 | (Unchecky) . (.RaMMicHaeL.) - C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe SR - | Auto 01/10/2009 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Demand 22/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Services: Scanned in 00mn 09s ---\\ Scan Additionnel (O88) Database Version : 13008 - (19/02/2015) Clés trouvées (Keys found) : 0 Valeurs trouvées (Values found) : 2 Dossiers trouvés (Folders found) : 0 Fichiers trouvés (Files found) : 2 C:\Program Files (x86)\eMule\emule.exe =>P2P.eMule^ C:\Windows\Installer\930f79c.msi =>Toolbar.DeltaSearch^ ~ Additionnel Scan: 610494 Items scanned in 00mn 32s ---\\ Informations complémentaires sur les modules ~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5) ~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects de navigateur (O2) ~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3) ~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4) ~ AMI: 4 Legitimates Filtered in 00mn 00s ---\\ Récapitulatif des détections trouvées sur votre station http://nicolascoolman.fr/toolbar-deltasearch =>Toolbar.DeltaSearch ~ MSI: 1 link(s) detected in 00mn 00s ~ 2139 Legitimates filtered by white list End of the scan (733 lines in 02mn 37s)(0.11)