cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2015.2.8.17 - Nicolas Coolman (08/02/2015)
~ Lancé par Bernard (09/02/2015 16:48:47)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17501 (Defaut)
MFIE: Mozilla Firefox 31.0

---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
Windows ID Activation : OK
~ Windows Partial Key : KF2YT
Windows License : OK
~ Windows Remaining Initializations Number : 3
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)

---\\ Logiciels de protection du système
Antivirus Pro v14.0.7.468
Malwarebytes Anti-Malware version 2.0.4.1028
Microsoft Security Client FR-FR Language Pack v2.1.1116.0
Kaspersky Security Scan v12.0.1.881
McAfee Security Scan Plus v3.8.130.8
Spybot - Search & Destroy v1.6.2
Windows Defender W7 (Activate)

---\\ Logiciels d'optimisation du système
CCleaner v5.02
Slowin' Killer v2.1.1

---\\ Logiciels de partage PeerToPeer
eMule

---\\ Surveillance de Logiciels
Adobe Flash Player 16 NPAPI
Adobe Reader XI

---\\ Informations sur le système
~ Processor: Intel64 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 12151 MB (76% free)
System Restore: Désactivé (Disabled)
System drive C: has 53 GB (33%) free of 159 GB

---\\ Mode de connexion au système
~ Computer Name: PC-BERNARD
~ User Name: Bernard
~ All Users Names: HomeGroupUser$, Emilie, Bernard, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Bernard\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Bernard\AppData\Roaming\
~ %Desktop% : C:\Users\Bernard\Desktop\
~ %Favorites% : C:\Users\Bernard\Favorites\
~ %LocalAppData% : C:\Users\Bernard\AppData\Local\
~ %StartMenu% : C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 53 Go of 159 Go)
D: Hard drive, Flash drive, Thumb drive (Free 343 Go of 772 Go)
E: CD-ROM drive (Not Inserted)
F: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
~ Security Center: 50 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.4AF089160FE082E5EA5C4AA72782DCA2] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.22/11/2014 - 02:28:21.) -- C:\Windows\System32\wininet.dll [2358272]
[MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.17/07/2014 - 03:07:24.) -- C:\Windows\System32\Winlogon.exe [455168]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.21/11/2010 - 04:24:16.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.FA886682CFC5D36718D3E436AACF10B9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:45:52.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.21/11/2010 - 04:24:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.21/11/2010 - 04:23:51.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:37:55.) -- C:\Windows\system32\Drivers\ntfs.sys [1684928]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.21/11/2010 - 04:24:33.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.70988118145F5F10EF24720B97F35F65] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:46:26.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/174
~ Mes musiques (My Musics) : 1/2
~ Mes Videos (My Videos) : 1/3
~ Mes Favoris (My Favorites) : 1/1892
~ Mes Documents (My Documents) : 2/2111
~ Mon Bureau (My Desktop) : 1/41
~ Menu demarrer (Programs) : 1/230
~ Hidden Files: Scanned in 00mn 01s



---\\ Processus lancés
[MD5.4F011F572DAC7057DF9D6E9064AA77E8] - (.NVIDIA Corporation - NVIDIA GeForce Experience Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2460488] [PID.2720]
[MD5.5EB1ED0E3F320AF5FA3E1DB5ED5C930C] - (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe [110160] [PID.2848]
[MD5.E98EA7471918E1987075815DC4C61001] - (.Yahoo! Inc. - Yahoo! Widgets.) -- C:\Program Files (x86)\Yahoo!\Widgets\YahooWidgets.exe [4742184] [PID.2912]
[MD5.A162B967A88BF374A81E01EF6E7A2655] - (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768] [PID.2416]
[MD5.8943465BEFA91044227D42E84ECB8280] - (.Renesas Electronics Corporation - USB 3.0 Monitor.) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048] [PID.2680]
[MD5.8FFDB89A0FB7C8ABC3A8825E38047341] - (.Logitech Inc. - Logitech Webcam Software.) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136] [PID.2452]
[MD5.E4C53CE8409DCFF708C790A0AC76398D] - (...) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe [264040] [PID.3764]
[MD5.0C04D13438560D24EA3A97BD7B26B5B7] - (.RaMMicHaeL - Unchecky Background Process.) -- C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe [402536] [PID.3928]
[MD5.9153F2335BCDB87F41559CF066223BF9] - (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [508800] [PID.3972]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] - (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Bernard\AppData\Local\Google\Update\GoogleUpdate.exe [116648] [PID.2532]
[MD5.883008A9B5BFF94A153D99DBA54CB5C1] - (.Hewlett-Packard - GPCore COM object.) -- C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe [362496] [PID.5800]
[MD5.F16EEA6CCA9D8A7D1193AE80E43FBBC7] - (.Hewlett-Packard Co. - HP CUE Status Root.) -- C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe [168960] [PID.7144]
[MD5.8A9FACCB684500829F7D0BCC67B386CC] - (.Hewlett-Packard Co. - HP CUE Alert Popup Window Objects.) -- C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe [559104] [PID.7064]
[MD5.16AFB34618E1286FF856DC600AC49C79] - (.Pas de propriétaire - DivX Update.) -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968] [PID.2292]
[MD5.4AE8B6C28C6FDFAF4CB8F48343273030] - (.McAfee, Inc. - SiteAdvisor.) -- C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe [1205944] [PID.5296]
[MD5.E8B7FD67DA14A7BE57A5CB80E3139E60] - (.Google Inc. - Google Toolbar Broker.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe [309704] [PID.1816]
[MD5.A24BFBAE8B50A6780B68FF3673FAB52F] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\IEXPLORE.exe [815280] [PID.4344]
[MD5.426BB96DAD5BDBDDE5583CFD1AA0F88E] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8163840] [PID.6416]
[MD5.2F442BAA7A739EDFB8CBF6BFBE8F5388] - (.IObit - Advanced SystemCare Service.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [815392] [PID.904]
[MD5.C2700D35AA42311A32DF7EA09630B401] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920] [PID.1752]
[MD5.FC5B75CA6A1DA31EDD4F8D53F5540B98] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [81088] [PID.1972]
[MD5.C2700D35AA42311A32DF7EA09630B401] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920] [PID.1964]
[MD5.C34411A244029F1C08687F7C752C4563] - (.Hewlett-Packard Company - LightScribe Service.) -- C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728] [PID.2156]
[MD5.E38775922D4A4C05B5D96733AB4CE169] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [268824] [PID.2368]
[MD5.0BB29DE40C9D9529793DCDB59A43CF5B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160] [PID.2432]
[MD5.F172AD4E906D97ED8F071896FC6789DC] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912] [PID.2532]
[MD5.7CF1B716372B89568AE4C0FE769F5869] - (.Microsoft Corporation - Machine Debug Manager.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872] [PID.2836]
[MD5.63694C307273062A2167AE4CE80730EF] - (.Sony Corporation - Device Information Provider.) -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [398176] [PID.2968]
[MD5.51138BEEA3E2C21EC44D0932C71762A8] - (...) -- ysWOW64\rundll32.exe [0] [PID.3108]
[MD5.C0C121B537DA3AD87481C0502CACE462] - (.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5426448] [PID.3336]
[MD5.FD2804048115F06FD8402C3255E0BC78] - (.RaMMicHaeL - Unchecky Service.) -- C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [126568] [PID.3424]
[MD5.02C298382359653BEC4C737C2AB7F9C5] - (.Intel Corporation - User Notification Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2320920] [PID.3444]
[MD5.7D6FFF60082AD63C5D8C67D7BDE7F034] - (.Intel Corporation - IAStorDataSvc.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [19184] [PID.3896]
[MD5.794D4B48DFB6E999537C7C3947863463] - (.Safer Networking Ltd. - Spybot-S&D Security Center integration.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368] [PID.4364]
[MD5.D0F2BD42CD3AC015BD93A81638210BC7] - (.Avira Operations GmbH & Co. KG - Antivirus MailScanner WFP Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [807672] [PID.4832]
[MD5.027820FE847A7B4245234A4E6E825BE1] - (.Avira Operations GmbH & Co. KG - AntiVir WebGuard WFP Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [993584] [PID.4852]
~ Processes Running: Scanned in 00mn 01s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Bernard\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js
C:\Users\Bernard\AppData\Roaming\Mozilla\Firefox\Profiles\y34b53cq.default\prefs.js
M2 - MFEP: RegExtension {22119944-ED35-4ab1-910B-E619EA06A115} . (...) --
~ Firefox Browser: 36 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = preserve
~ IE Browser: 21 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\System32\Userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (50)
~ Hosts File: Scanned in 00mn 00s



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: Ads Removal [64Bits] - {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} . (.Adblock - Helps you remove browser ads!.) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll
O2 - BHO: Adblock Plus for IE Browser Helper Object [64Bits] - {FFCB3198-32F3-4E8B-9539-4324694ED664} . (.Adblock Plus - Adblock Plus Module.) -- C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
~ BHO: 23 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - [HKLM]{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} . (.McAfee, Inc. - SiteAdvisor.) -- C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
O3 - Toolbar: &RoboForm Toolbar - [HKLM]{724d43a0-0d85-11d4-9908-00400523e39a} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{71576546-354D-41C9-AAE8-31F2EC22BF0D} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{724D43A0-0D85-11D4-9908-00400523E39A} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{D3028143-6145-4318-99D3-3EDCE54A95A9} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: eMule.lnk . (.http://www.emule-project.net - eMule.) -- C:\Program Files (x86)\eMule\emule.exe =>P2P.eMule
O4 - GS\Desktop [Bernard]: Ebay - Bernard.LNK . (...) -- C:\Users\Bernard\Documents\My RoboForm Data\Default Profile\Ebay - Bernard.rfp -l (.not file.) =>Toolbar.eBay
~ Global Startup: 2 Legitimates Filtered in 00mn 10s



---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [NvBackend] . (.NVIDIA Corporation - NVIDIA GeForce Experience Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
O4 - HKLM\..\Run: [EvtMgr6] . (.Logitech, Inc. - Logitech SetPoint Event Manager (UNICODE).) -- C:\Program Files\Logitech\SetPointP\SetPoint.exe
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp
O4 - HKCU\..\Run: [RoboForm] . (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
O4 - HKLM\..\Wow6432Node\Run: [GrooveMonitor] . (.Microsoft Corporation - GrooveMonitor Utility.) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe
O4 - HKLM\..\Wow6432Node\Run: [NUSB3MON] . (.Renesas Electronics Corporation - USB 3.0 Monitor.) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
O4 - HKLM\..\Wow6432Node\Run: [LWS] . (.Logitech Inc. - Logitech Webcam Software.) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe =>.Logitech Inc
O4 - HKLM\..\Wow6432Node\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe =>.RealNetworks, Inc
O4 - HKUS\S-1-5-21-2503739192-254968964-1925577246-1001\..\Run: [RoboForm] . (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
~ Application: Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Remplir les formulaires [64Bits] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: Enregistrer les formulaires [64Bits] - {320AF880-6646-11D3-ABEE-C5DBF3571F49} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: Personnaliser le menu [64Bits] - {320AF880-6646-11D3-ABEE-C5DBF3571F4E} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: Barre RoboForm [64Bits] - {724d43aa-0d85-11d4-9908-00400523e39a} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: Skype Click to Call [64Bits] - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- c:\program files (x86)\skype\toolbars\internet explorer x64\icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{0D5C9240-E3CF-402D-98BC-E4642A24EA9B}: DhcpNameServer = 192.168.1.10 192.168.1.10
O17 - HKLM\System\CS1\Services\Tcpip\..\{0D5C9240-E3CF-402D-98BC-E4642A24EA9B}: DhcpNameServer = 192.168.1.10 192.168.1.10
O17 - HKLM\System\CS2\Services\Tcpip\..\{0D5C9240-E3CF-402D-98BC-E4642A24EA9B}: DhcpNameServer = 192.168.1.10 192.168.1.10
O17 - HKLM\System\CS3\Services\Tcpip\..\{0D5C9240-E3CF-402D-98BC-E4642A24EA9B}: DhcpNameServer = 192.168.1.10 192.168.1.10
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.10 192.168.1.10
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: LBTWlgn . (.Logitech, Inc. - Logitech Bluetooth Service.) -- c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: (no name) [64Bits] - {73526E5A-FD53-4BE7-B5E2-D3C89D7413DC} - (.not file.)
~ STS/SSO: Scanned in 00mn 00s



---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (RegistryDefragBootTime.exe) - File not found
O34 - HKLM BootExecute: (@) - File not found
~ BEX: 2 Legitimates Filtered in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [DriverBoost-RTMRules] (...) -- C:\Program Files (x86)\DriverBoost\DriverBoost\DriverBoost.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [DriverBoost-RTMScan] (...) -- C:\Program Files (x86)\DriverBoost\DriverBoost\DriverBoost.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [DriverBoost-RTMScanRunOnce] (...) -- C:\Program Files (x86)\DriverBoost\DriverBoost\DriverBoost.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [DriverBoost-RTMUpdater] (...) -- C:\Program Files (x86)\DriverBoost\DriverBoost\DriverBoost.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{164C8768-29C1-4F1A-B70D-CDAA94C6D145}] (...) -- E:\Documents Ma Mule\Bernard\Watcher_Setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{1CD023A9-8ED7-4102-B909-ED3FC8032054}] (...) -- F:\Setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{1ED7B2B4-8882-461E-A5CC-E9B3F35850F2}] (...) -- E:\mura.bernard\RegCleaner V4.3.0.780.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{2C24FB4C-E1BA-4ECE-92FA-02588E01896C}] (...) -- E:\mura.bernard\WinZip 9.0 Fr + Keygen\Setup Winzip 9.0\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{2F935AB3-F37A-4E97-82E1-C1A5935AF7B8}] (...) -- E:\mura.bernard\Worldwind_1.4_IGE_PluginFrancais_1.0.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{3086A7A1-508B-4D72-9A1F-2FF0CF876247}] (...) -- D:\mura.bernard\WinAce 2.55 Fr + Key\w25b5_fr.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{332B5B5C-44C1-4E14-901A-1D969FE55662}] (...) -- E:\mura.bernard\Everio mediaBrowser HD Edition V 2.02.23.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{4242B7C6-BBB3-4B52-9D6D-1E1B7E137408}] (...) -- D:\mura.bernard\[3DMark.2006.Professional.Edition].3DMark06_v102_installer\3DMark06_v102_installer.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{48D1180A-694A-490C-A846-A2BE12A1D191}] (...) -- D:\mura.bernard\HOSTS_Install_V2.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{54E6FC19-4CBC-4D7F-9927-98AA2283C568}] (...) -- C:\Users\Bernard\Desktop\OverDisk011b.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{5E34C36D-DEA2-453E-99CD-4011E7CC9CC2}] (...) -- C:\Users\Bernard\Downloads\PC Drivers HeadQuarters\Driver Detective\Vista_Win7_R261.exe (.not file.) [0] =>DriverDetective
[MD5.00000000000000000000000000000000] [APT] [{61ECB5BE-D2E1-4175-82B4-D942287AFDF8}] (...) -- D:\mura.bernard\Q-Dir 5.68\Q-Dir_Installer.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{717ECDFE-5ED4-4136-B164-9C0C26A0BC69}] (...) -- D:\mura.bernard\RegCleaner V4.3.0.780.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{7C8C3F18-3F26-4014-B7AB-17F34B3F710E}] (...) -- E:\mura.bernard\Windirstat V 1.1.2.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{85FF3D00-AF4D-412E-8B2D-94AF61CC8B4E}] (...) -- D:\mura.bernard\Q-Dir 5.61\Q-Dir_Installer.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{899B7A70-2979-4501-A1A5-C278DDD5C980}] (...) -- E:\mura.bernard\jre-6u29-windows-i586-iftw.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{B1385BB0-CFA4-418B-B2D5-A6ADD6574377}] (...) -- E:\mura.bernard\Cities 3D.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C6CF36D1-CA8C-4062-925D-5507DC051351}] (...) -- E:\Documents Ma Mule\Bernard\Digi Watcher 2.30 + Remote View 1.40 - Webcam Spy\Digi.Watcher.v2.30.WinAll.Incl.Keygenerator-TMG\Watcher_Setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{CEF3BE90-C84F-4F4D-B9B4-4D7CE38EF454}] (...) -- C:\Users\Bernard\AppData\Local\Temp\tasks\PSSetup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{CF102249-EC4A-4DB7-BE13-A47AB839FB95}] (...) -- E:\Documents Ma Mule\Bernard\AutoCAD Architecture 2009\setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{D64C8214-B066-478C-A58D-E62F57B59B9E}] (...) -- E:\Documents Ma Mule\Bernard\Setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{E0C5BAC2-544C-4319-B76E-514260B807F2}] (...) -- F:\ScreenSaver\ScreenSaver.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{F0B39416-0058-4009-9D54-E15191210AE1}] (...) -- C:\Users\Bernard\Desktop\FSXDemo.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{F41DC170-5789-4843-A957-D840682AB270}] (...) -- E:\Documents Ma Mule\Bernard (.not file.) [0]
[MD5.3ABF1C149873E25D4E266225FBF37CBF] [APT] [{F8DBCDA0-F393-408A-89C5-27E0BC364B72}] (...) -- D:\mura.bernard\Windirstat V 1.1.2.exe [645729]
[MD5.00000000000000000000000000000000] [APT] [{F979C2E0-F74C-4670-A411-2D1621A4C1F1}] (...) -- E:\mura.bernard\Epson Stylus SX 105.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{FCB90EDB-C2C8-43AC-82B8-49F86631A228}] (...) -- C:\Users\Bernard\Desktop\internettv_setup[1].exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{FE5F614C-2B70-4C0E-8779-8DFC2FE7C1F1}] (...) -- D:\mura.bernard\favorg (mise … jour des icones)\FavOrg (gère les icones des favoris).exe (.not file.) [0]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1066]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1070]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2503739192-254968964-1925577246-1001Core [1034]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2503739192-254968964-1925577246-1001UA [1086]
O39 - APT: - (..) -- C:\Windows\Tasks\NeroLiveEpgUpdate-PC-Bernard_Bernard.job [398]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\NeroLiveEpgUpdate-PC-Bernard_Bernard [398]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\Spybot - Search & Destroy - Scheduled Task [304]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\Spybot - Search & Destroy Updater - Scheduled Task [330]
~ Scheduled Task: 70 Legitimates Filtered in 00mn 04s



---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: (HWiNFO32) . (.REALiX(tm) - HWiNFO AMD64 Kernel Driver.) - C:\Windows\sysWOW64\drivers\HWiNFO64A.sys
~ Drivers: 95 Legitimates Filtered in 00mn 00s



---\\ Logiciels installés (O42)
O42 - Logiciel: AC3File 0.6b - (.Alexander Vigovsky.) [HKLM][64Bits] -- AC3File_is1
O42 - Logiciel: Akamai NetSession Interface - (...) [HKCU][64Bits] -- Akamai
O42 - Logiciel: Billiardino 1.0 - (.Falco Software, Inc..) [HKLM][64Bits] -- Billiardino_is1
O42 - Logiciel: Billiards Club - (.FreeGamePick.com.) [HKLM][64Bits] -- Billiards Club_is1
O42 - Logiciel: Bowling Evolution 1.05 - (...) [HKLM][64Bits] -- Bowling Evolution 1.05
O42 - Logiciel: Cities of Earth 3D Screensaver v. 2.1 - (.Screenomania.com.) [HKLM][64Bits] -- Cities of Earth 3D Screensaver_is1
O42 - Logiciel: CleanTemp 1.5.5 - (.Update Computer Services.) [HKLM][64Bits] -- {536CB2B8-199F-4C8B-9C3A-D91666558772}
O42 - Logiciel: FavOrg - (.PC Magazine.) [HKLM][64Bits] -- FavOrg
O42 - Logiciel: Fmrid 4.01 - (.Fabio Chelly.) [HKLM][64Bits] -- Fmrid
O42 - Logiciel: MenuUninstaller - (.Leizer Soft.) [HKLM][64Bits] -- {52BAA6C6-FAB0-46F3-9C14-ADDD1A85F6FE}
O42 - Logiciel: Mozaik - (...) [HKLM][64Bits] -- Mozaik
O42 - Logiciel: OSSearch version 0.7.1 - (.Parcouss.) [HKLM][64Bits] -- {BFCA578C-F5EB-49BF-B1C7-4ABE70471E22}_is1
O42 - Logiciel: OverDisk (remove only) - (...) [HKLM][64Bits] -- OverDisk
O42 - Logiciel: UpStarter - (...) [HKCU][64Bits] -- UpStarter
O42 - Logiciel: Windows Tweaker - (.SuRe Softwares.) [HKLM][64Bits] -- {092D4427-C1D9-43C0-B1BB-C8BCFE67D5C0}
~ Logic: 49 Legitimates Filtered in 00mn 01s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\BeauSoft]
[HKCU\Software\Digi-Watcher C:]
[HKCU\Software\Filefacts]
[HKCU\Software\Fmrid]
[HKCU\Software\FreshWebMaster]
[HKCU\Software\FriedCookie]
[HKCU\Software\Inventivio]
[HKCU\Software\MovieCollection]
[HKCU\Software\OB]
[HKCU\Software\Parcouss Apps]
[HKCU\Software\Reg]
[HKCU\Software\Screenomania]
[HKCU\Software\TVixC]
[HKCU\Software\UCS]
[HKCU\Software\babidyxp]
[HKCU\Software\bunkus.org]
[HKCU\Software\zyceffcal]
[HKLM\Software\Wow6432Node\ADSRemoval]
[HKLM\Software\Wow6432Node\FreshWebMaster]
[HKLM\Software\Wow6432Node\Inventivio]
[HKLM\Software\Wow6432Node\Reg]
[HKLM\Software\Wow6432Node\SW.Booster] =>PUP.SafeWeb
[HKLM\Software\Wow6432Node\Screenomania]
[HKLM\Software\Wow6432Node\Secured-IE]
[HKLM\Software\Wow6432Node\Virustotal]
~ Key Software: 967 Legitimates Filtered in 00mn 01s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 08/12/2014 - 14:12:50 - [] ----D C:\Program Files (x86)\3RVX
O43 - CFD: 08/12/2014 - 14:12:51 - [] ----D C:\Program Files (x86)\AC3File
O43 - CFD: 08/01/2015 - 18:17:36 - [] ----D C:\Program Files (x86)\AHD
O43 - CFD: 08/12/2014 - 14:13:25 - [] ----D C:\Program Files (x86)\Beausoft
O43 - CFD: 08/12/2014 - 14:13:25 - [] ----D C:\Program Files (x86)\Billiardino
O43 - CFD: 08/12/2014 - 14:13:26 - [] ----D C:\Program Files (x86)\Bowling Evolution 1.05
O43 - CFD: 08/12/2014 - 14:13:26 - [] ----D C:\Program Files (x86)\Cities of Earth
O43 - CFD: 08/12/2014 - 14:13:26 - [] ----D C:\Program Files (x86)\CleanTemp 1.5
O43 - CFD: 08/12/2014 - 14:14:02 - [] ----D C:\Program Files (x86)\Crime Catcher
O43 - CFD: 08/12/2014 - 14:14:17 - [] ----D C:\Program Files (x86)\EuroThink
O43 - CFD: 08/12/2014 - 14:14:18 - [] ----D C:\Program Files (x86)\Fmrid
O43 - CFD: 08/12/2014 - 14:14:18 - [] ----D C:\Program Files (x86)\Font Explorer
O43 - CFD: 08/12/2014 - 14:14:20 - [] ----D C:\Program Files (x86)\FreshWebmaster
O43 - CFD: 08/12/2014 - 14:14:21 - [] ----D C:\Program Files (x86)\Gigaset QuickSync
O43 - CFD: 08/12/2014 - 14:18:41 - [] ----D C:\Program Files (x86)\LeeGT-Games
O43 - CFD: 08/12/2014 - 14:18:42 - [] ----D C:\Program Files (x86)\Leizer Soft
O43 - CFD: 08/12/2014 - 14:19:27 - [] ----D C:\Program Files (x86)\MalchroSoft
O43 - CFD: 08/12/2014 - 14:20:53 - [] ----D C:\Program Files (x86)\Onwijs
O43 - CFD: 25/12/2014 - 18:52:15 - [] ----D C:\Program Files (x86)\OSSearch
O43 - CFD: 08/12/2014 - 14:20:55 - [] ----D C:\Program Files (x86)\OverDisk
O43 - CFD: 08/12/2014 - 14:21:18 - [] ----D C:\Program Files (x86)\PMSSAARI
O43 - CFD: 08/12/2014 - 14:21:18 - [] ----D C:\Program Files (x86)\QTranslate
O43 - CFD: 21/07/2012 - 09:52:43 - [0] ----D C:\Program Files (x86)\Secured-IE
O43 - CFD: 08/12/2014 - 14:21:48 - [] ----D C:\Program Files (x86)\User's Guide
O43 - CFD: 23/12/2014 - 14:27:49 - [] ----D C:\Program Files (x86)\VJS Productions
O43 - CFD: 08/12/2014 - 14:21:48 - [] ----D C:\Program Files (x86)\WAN Miniport IKEv2
O43 - CFD: 08/12/2014 - 14:21:57 - [] ----D C:\Program Files (x86)\Windows Tweaker
O43 - CFD: 04/08/2011 - 17:29:56 - [0] ----D C:\Program Files (x86)\Yahoo! Jeux
O43 - CFD: 08/12/2014 - 14:14:02 - [] ----D C:\Program Files (x86)\Common Files\WAN Miniport IKEv2
O43 - CFD: 08/12/2014 - 14:22:33 - [] ----D C:\ProgramData\Advanced Uninstaller PRO
O43 - CFD: 08/12/2014 - 14:22:34 - [] ----D C:\ProgramData\bmkfieeegpeeafckaajcnajmpklckeah
O43 - CFD: 08/12/2014 - 14:22:34 - [] ----D C:\ProgramData\ClamAV
O43 - CFD: 11/05/2014 - 14:18:16 - [0] ----D C:\ProgramData\Duplicate Photo Cleaner
O43 - CFD: 08/12/2014 - 14:22:35 - [] ----D C:\ProgramData\Gigaset QuickSync
O43 - CFD: 08/02/2015 - 18:43:14 - [] ----D C:\ProgramData\ProductData
O43 - CFD: 08/12/2014 - 14:23:41 - [] ----D C:\ProgramData\SecureAge Technology
O43 - CFD: 08/12/2014 - 14:23:41 - [] ----D C:\ProgramData\SnowApp
O43 - CFD: 04/02/2015 - 10:40:46 - [] ----D C:\ProgramData\{2daef0a4-2535-ad17-2dae-ef0a4253c290}
O43 - CFD: 08/01/2015 - 00:30:08 - [0] ----D C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
O43 - CFD: 08/12/2014 - 14:24:30 - [] -SH-D C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
O43 - CFD: 08/12/2014 - 14:22:56 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AC3File
O43 - CFD: 08/01/2015 - 18:17:36 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AHD
O43 - CFD: 08/12/2014 - 14:23:00 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Billiardino
O43 - CFD: 08/12/2014 - 14:23:00 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bowling Evolution 1.05
O43 - CFD: 08/12/2014 - 14:23:01 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eReaders
O43 - CFD: 08/12/2014 - 14:23:03 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fmrid
O43 - CFD: 08/12/2014 - 14:23:04 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gigaset QuickSync
O43 - CFD: 28/01/2015 - 07:49:51 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Grand Master Chess
O43 - CFD: 08/12/2014 - 14:23:06 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I2P
O43 - CFD: 08/12/2014 - 14:23:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Manuel de l’utilisateur
O43 - CFD: 08/12/2014 - 14:23:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozaik
O43 - CFD: 25/12/2014 - 18:52:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OSSearch
O43 - CFD: 08/12/2014 - 14:23:12 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OverDisk
O43 - CFD: 03/02/2015 - 16:57:05 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reanimator
O43 - CFD: 08/12/2014 - 14:23:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Screenomania
O43 - CFD: 08/12/2014 - 14:23:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SentryVision
O43 - CFD: 12/04/2011 - 10:27:52 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 08/12/2014 - 14:23:18 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Tweaker
O43 - CFD: 08/12/2014 - 14:23:19 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Jeux
O43 - CFD: 14/01/2014 - 11:38:22 - [0] ----D C:\Users\Bernard\AppData\Roaming\7 Sticky Notes
O43 - CFD: 08/12/2014 - 14:44:06 - [] ----D C:\Users\Bernard\AppData\Roaming\Bitser
O43 - CFD: 08/12/2014 - 14:44:06 - [] ----D C:\Users\Bernard\AppData\Roaming\ClassicShell
O43 - CFD: 08/12/2014 - 14:44:09 - [] ----D C:\Users\Bernard\AppData\Roaming\Efficient Calendar Free
O43 - CFD: 08/12/2014 - 14:44:09 - [] ----D C:\Users\Bernard\AppData\Roaming\Ember_Media_Manager
O43 - CFD: 08/12/2014 - 14:44:09 - [] ----D C:\Users\Bernard\AppData\Roaming\Epic_Pen
O43 - CFD: 08/12/2014 - 14:44:09 - [] ----D C:\Users\Bernard\AppData\Roaming\Filey, Inc
O43 - CFD: 08/12/2014 - 14:44:12 - [] ----D C:\Users\Bernard\AppData\Roaming\I2P
O43 - CFD: 08/12/2014 - 14:44:12 - [] ----D C:\Users\Bernard\AppData\Roaming\Inventivio
O43 - CFD: 09/11/2014 - 09:50:25 - [0] ----D C:\Users\Bernard\AppData\Roaming\Litecoin
O43 - CFD: 08/01/2015 - 00:06:36 - [] ----D C:\Users\Bernard\AppData\Roaming\Mediatronic
O43 - CFD: 08/12/2014 - 14:44:39 - [] ----D C:\Users\Bernard\AppData\Roaming\MultiMiner
O43 - CFD: 24/01/2015 - 20:29:34 - [] ----D C:\Users\Bernard\AppData\Roaming\ProductData
O43 - CFD: 08/12/2014 - 14:44:50 - [] ----D C:\Users\Bernard\AppData\Roaming\QTranslate
O43 - CFD: 08/12/2014 - 14:59:32 - [] ----D C:\Users\Bernard\AppData\Roaming\Votre Budget 2008
O43 - CFD: 08/12/2014 - 14:59:33 - [] ----D C:\Users\Bernard\AppData\Roaming\WIPE2013
O43 - CFD: 08/12/2014 - 14:42:59 - [] ----D C:\Users\Bernard\AppData\Local\Bitser
O43 - CFD: 09/12/2014 - 08:22:25 - [] -SH-D C:\Users\Bernard\AppData\Local\EmieBrowserModeList
O43 - CFD: 08/12/2014 - 14:43:00 - [] ----D C:\Users\Bernard\AppData\Local\Films
O43 - CFD: 08/12/2014 - 14:43:06 - [] ----D C:\Users\Bernard\AppData\Local\hq
O43 - CFD: 08/12/2014 - 14:43:06 - [] ----D C:\Users\Bernard\AppData\Local\IFM38
O43 - CFD: 08/12/2014 - 14:43:17 - [] ----D C:\Users\Bernard\AppData\Local\MovieCollection
O43 - CFD: 08/12/2014 - 14:43:30 - [] ----D C:\Users\Bernard\AppData\Local\StudioGPU
O43 - CFD: 08/12/2014 - 14:44:35 - [] ----D C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Font Explorer
O43 - CFD: 08/12/2014 - 14:44:35 - [] ----D C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup
O43 - CFD: 08/12/2014 - 14:44:36 - [] ----D C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QTranslate
O43 - CFD: 08/12/2014 - 14:44:36 - [] ----D C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UpStarter
~ Program Folder: 837 Legitimates Filtered in 00mn 01s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.FD44FA80DA03EA144153A76DEBBB61B4] - 01/02/2015 - 05:58:04 ---A- . (...) -- C:\Windows\System32\Drivers\TrueSight.sys [35064]
O44 - LFC:[MD5.F21B8F08F3702CC184530CEE388770E5] - 01/02/2015 - 07:47:40 ---A- . (...) -- C:\TDSSKiller.3.0.0.44_01.02.2015_07.45.53_log.txt [237732]
O44 - LFC:[MD5.81051BCC2CF1BEDF378224B0A93E2877] - 03/02/2015 - 16:57:07 RSHA- . (...) -- C:\Windows\winstart.bat [2]
O44 - LFC:[MD5.F9C80AA8ACD3AB12F5A11DAB2B9E5010] - 04/02/2015 - 07:48:40 ---A- . (...) -- C:\Windows\Q-Dir.ini [53242]
O44 - LFC:[MD5.BE4063E7F95D87BE4EF53023688AFFE9] - 04/02/2015 - 22:27:07 --HA- . (...) -- C:\os745025.bin [655]
O44 - LFC:[MD5.49E6CF975D7847183698C272C777784D] - 05/02/2015 - 05:05:02 ---A- . (...) -- C:\Windows\System32\lvcoinst.log [25092]
O44 - LFC:[MD5.3CF03F7A43E15378A486AD117D32C02E] - 05/02/2015 - 17:20:27 ---A- . (...) -- C:\TDSSKiller.3.0.0.44_05.02.2015_17.16.46_log.txt [237842]
O44 - LFC:[MD5.76D872507DBF9E3EEA2117105B0E51CD] - 06/02/2015 - 08:42:04 --H-- . (...) -- C:\AMTAG.BIN [1024]
O44 - LFC:[MD5.814231B961760C39A5807A43D8ED71E1] - 07/02/2015 - 06:41:05 ---A- . (...) -- C:\Windows\System32\Drivers\RTAIODAT.DAT [1443340]
O44 - LFC:[MD5.1E9484BD0A31A3734587E5C57109B18A] - 08/02/2015 - 11:23:36 ---A- . (...) -- C:\Windows\Antidote.ini [151]
O44 - LFC:[MD5.D56A51D3CA83804C3955AFB1485C9E56] - 08/02/2015 - 17:22:48 ---A- . (...) -- C:\RstAssociations.txt [3357]
O44 - LFC:[MD5.6D865BF342BA6825EB493776C8E7CCA1] - 28/01/2015 - 17:57:06 ---A- . (...) -- C:\TDSSKiller.3.0.0.44_28.01.2015_17.54.06_log.txt [236626]
~ Files: 60 Legitimates Filtered in 00mn 10s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
~ MWPS: 19 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:25/02/2013 - 21:05:09 ---A- . (.Doctor Web, Ltd. - Dr.Web boot operations for Windows.) -- C:\Windows\System32\Drivers\28F881EE1.sys [23080]
O58 - SDL:01/03/2010 - 23:59:50 ---A- . (...) -- C:\Windows\System32\Drivers\cpqdfw.sys [24376]
O58 - SDL:01/03/2010 - 23:59:50 ---A- . (...) -- C:\Windows\System32\Drivers\cqcpu.sys [24376]
O58 - SDL:14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
O58 - SDL:23/05/2013 - 07:39:24 ---A- . (.ThreatTrack Security - gfiark64.sys.) -- C:\Windows\System32\Drivers\gfiark.sys [41032]
O58 - SDL:04/09/2013 - 13:57:44 ---A- . (.ThreatTrack Security - GFI Utility driver.) -- C:\Windows\System32\Drivers\gfiutil.sys [31264]
O58 - SDL:10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
O58 - SDL:25/05/2012 - 12:14:24 ---A- . (.GFI Software - GFI Anti-Rootkit Driver.) -- C:\Windows\System32\Drivers\SBREDrv.sys [57976]
O58 - SDL:14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
O58 - SDL:14/06/2010 - 08:32:54 ---A- . (.Teruten Inc - File System Mini Filter Drvier.) -- C:\Windows\System32\Drivers\TFsExDisk.sys [16448]
O58 - SDL:01/02/2015 - 05:58:04 ---A- . (...) -- C:\Windows\System32\Drivers\TrueSight.sys [35064]
O58 - SDL:18/12/2013 - 11:33:16 ---A- . (...) -- C:\Windows\System32\ampa.sys [17008]
O58 - SDL:20/01/2005 - 02:17:12 ---A- . (...) -- C:\Windows\SysWOW64\drivers\ASUSHWIO.SYS [5824]
O58 - SDL:25/10/2004 - 19:02:58 ---A- . (.EnTech Taiwan - Pas de description.) -- C:\Windows\SysWOW64\drivers\Entech.sys [21664]
O58 - SDL:22/06/2004 - 14:44:50 ---A- . (.EnTech Taiwan - EnTech driver for Windows XP 64.) -- C:\Windows\SysWOW64\drivers\Entech64.sys [5632]
O58 - SDL:04/11/2014 - 06:13:55 ---A- . (...) -- C:\Windows\SysWOW64\drivers\fsbts.sys [33920]
O58 - SDL:07/02/2015 - 05:19:30 ---A- . (.REALiX(tm) - HWiNFO AMD64 Kernel Driver.) -- C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528]
O58 - SDL:19/11/2001 - 18:05:18 ---A- . (...) -- C:\Windows\SysWOW64\drivers\PciBus.sys [3972]
O58 - SDL:27/06/2011 - 22:33:14 ---A- . (...) -- C:\Windows\SysWOW64\drivers\StarOpen.sys [5632]
O58 - SDL:27/06/2011 - 22:33:28 ---A- . (.Teruten Inc - File System Mini Filter Drvier.) -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys [16392]
O58 - SDL:06/10/2014 - 19:16:52 ---A- . (...) -- C:\Windows\SysWOW64\drivers\TrueSight.sys [33512]
O58 - SDL:18/12/2013 - 11:33:16 ---A- . (...) -- C:\Windows\SysWOW64\ampa.sys [17008]
O58 - SDL:22/05/2013 - 12:34:26 ---A- . (...) -- C:\Windows\SysWOW64\FsUsbExDisk.Sys [37344]
~ Drivers: 123 Legitimates Filtered in 00mn 01s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
O63 - Logiciel: HiJackThis - (.Trend Micro.) [HKLM] -- {45A66726-69BC-466B-A7A4-12FCBA4883D7}
~ ADS: Scanned in 00mn 00s



---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - 06/10/2009 - C:\Windows\System32\DRIVERS\ahcix64s.sys (ahcix64s) .(.Advanced Micro Devices, Inc - AMD AHCI Compatible Controller Driver for W.) - LEGACY_AHCIX64S
~ Legacy: 118 Legitimates Filtered in 00mn 00s



---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 11 Legitimates Filtered in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Not Key.)
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {1CCF4CD2-BA43-4ED0-B6C2-D7EEE8DF1982} - (https://fr.search.yahoo.com/search?fr=mcafee&type=B010FR0D20140704&p=) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {6760948A-B0DC-4609-AFCA-2AEE65C3AD83} [DefaultScope] - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {680B00AE-36F7-4D3D-B5EE-E5BE118724BD} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - http://www.google.com
O69 - SBI: SearchScopes [HKCU] {6C63A419-6B7B-456F-ABA2-36D8869EFC46} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {7070382D-FD2C-4B7F-ACE7-CDEF8E251228} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {7093A982-F0E8-4693-B604-619E6117D2CA} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {7095AA19-C6F0-4A6D-8E03-CFEE74E247C5} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {713B1771-14EC-4A5D-8D30-8B6ABB88D027} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {71A7B041-9B29-485C-8C7F-207D753129F2} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {750DD223-E10C-4C73-BA8C-20728A523D5C} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {75D949F2-029C-4523-8E7D-BB8D3DE888AA} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {766CCC20-4FD5-46B1-B442-9EC2937B059A} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {777C1A51-26BC-4C46-A1F6-3E8A3C0F51A1} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {793D00E9-3463-4545-A548-606E46785025} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {7AF6373B-CD50-4BBF-88BE-CBF5BC8DE8ED} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {7B9B1824-1483-447C-A494-B0441BCCEB4A} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {7BABBFE8-B106-4218-9357-C5B39CD9BA1B} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {7CE94BC6-BA90-4900-B4EB-68E6831D4D01} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {7DCFA240-D719-4FFD-8EAB-8425397F26DB} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {82EE3845-0A5A-40D1-94D6-8BAC9F541568} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {839C8835-EAA6-4555-94E6-B4B8CA343D2F} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {83ED10A7-8C97-4844-82FA-9562E420940A} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {8452E251-264E-4C2B-9281-A84B2DFA054A} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {84F50965-5093-4777-9696-D2667C19206C} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {89875059-E77A-4C6D-A00E-28D2D14A0A01} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {898F640C-F584-440F-8AA4-2C37FB17BAEF} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {89ECBD72-5C85-4355-A351-CDCB64DFE939} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {8A6BF24C-FA60-4CD8-9552-F71C8D44E3AE} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {8B7F5147-0904-43FA-8206-DDFC9E68490B} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {8F41C546-690A-4A6A-BE60-07F39A9050D8} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {91C09056-7206-430E-9065-3169E23F8B3D} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {91CFFD95-61CF-4146-94AC-997354E6E827} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {91F8BA3C-924F-4A0D-B5B8-0A0DFC07B0AA} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {92BC6592-9392-4724-983D-D7AD1C5B3B68} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {9331ADF0-7E47-4203-9726-B86181225E04} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {9607293F-C0EC-456F-935E-CCB32C5EDD06} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {967840D4-32F0-4EFA-A9CB-4B45EF6135B3} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {9698CE3D-878D-4B34-B497-A1A62473710E} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {96AEFB53-6BF8-4679-927E-7FB0684DD760} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {99670FE9-E19D-4CA6-B1AE-98E08E58ECF1} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {9AEB8714-BD31-4E04-AD24-759FE1CBE3BB} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {9B1A82EC-7ACC-4C30-AD33-977AAAC93C2C} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {9BDBCC7F-C322-4F0E-B6CC-29DC71488ED3} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {9C737BC3-17B1-40C4-8521-27A0A5949278} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {9C962460-A39C-4CE9-81F4-0FD5E473F847} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {9EC5420F-0ADA-4861-9DF6-CC8FA7CBD2D0} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {9F15A11E-AB36-473A-A3D4-2D6E22793A68} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {9F2F162A-F2F5-4DC1-8919-954F246FC86A} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {A0503700-09B0-425C-8220-EC9106D50C4B} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {A3C3F91B-5638-43CD-9678-0B9715AB71E2} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {A43D8C66-55EB-4C49-AC55-738EC504EA93} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {A486DCCA-82BA-4F73-8CD1-BE1DF59FFD88} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {A6304BB0-13CB-4529-BD49-2000CEAF2EE5} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {A8356583-F093-46A0-8240-6CA1D5615C72} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {A84B3839-E59C-4361-9DD0-58D81B528096} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {A8714DF6-C722-45AE-8D31-79D966F21FE6} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {AB9C1D79-4CB8-42F7-AC00-D2BDEA393F02} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {AD730D62-9A0A-4638-840E-36C22A9C31CE} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {AE79BC8D-C304-4D4C-AEE4-96EB348F2773} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {AEB4059A-D9FC-4F7F-81F1-A16594295065} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {AEBDEB6C-80DB-4F1E-92B1-05FD9D914A2C} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {AF7450BB-49DA-4ADD-849C-08709E1BEC37} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {B1289930-409B-41DF-9DB3-125D05B712B9} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {B1C8B52D-CA94-4105-9781-017030EA6E7D} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {B2341376-5F8A-4A81-A930-44B899F354AD} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {B4CA8020-CCBA-4294-860D-1AF5C7F97A15} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {B59AD0BB-6B6C-483A-A77F-F0C4D3C33D3D} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {B5FEE1D5-2243-4B18-9361-DC86734800E7} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {B64F1812-6450-46FE-8FC1-D01CCC2DB810} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {B716B04A-1CEB-4649-B347-53E6891AB71E} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {B85C702B-1C0D-488C-B293-0687C45C69E4} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {B8B9244E-5262-45B4-A14A-963D9A3D6FFC} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {BBEFE581-C103-44C7-8683-A0BD497CCA0B} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {BCADCD9C-BC2F-41C7-8FBE-EAE1D42E0843} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {BD498586-9622-4BA4-A8BD-45A1FC848843} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {BE217BB2-0217-46C0-BCDB-DB2BE73E67BE} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {BEBACB46-78DB-4E7E-A51E-4AB4ED4FC336} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {BF71A17A-7C06-44E4-9D78-E8EF805BC205} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {C0F53AFF-B5AD-4937-B2E8-AC3B4EE4B1DE} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {C1C1993C-AE0D-41F0-AC3D-B19BEEF14F8A} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {C1C90169-20AF-45F3-BE4B-8DC309EA9AB4} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {C221DE8A-625B-46AA-AAA2-35760AF999F0} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {C28DEA2A-F5BC-46C6-AB66-91134CB42616} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {C449F6EC-E3A6-4E99-A4F4-4CC9FC6AC0F7} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {C5125651-6321-4F02-8454-9BB086D8D259} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {C5493CD2-794E-464F-998F-A7C5E1EFAC7E} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {C56099FA-1A45-4331-94EC-DDE09211C8A6} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {C6BA7B14-0BC4-47FB-A743-FC472159E648} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {C78D00C5-9231-444A-B73A-2ED297E51C91} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {C8F46173-1F80-4363-B818-07D66AAB9709} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {C9280FD5-5FAE-4976-B4EF-2FDBD0C55249} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {CA278DA9-88B7-4D2D-8136-B7AA8F259341} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {CC788B36-15E2-4F73-96E7-E42DB056F467} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {CC9380A4-6A71-4904-9203-17936C6E1512} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {CE8B184B-E637-4009-9A17-590E9E08B180} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {D0667578-74C5-4CA5-BBB7-DC56DDA67A9B} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {D1B0A8C7-B9AA-4F75-8489-1A725C1578BA} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {D36F41EB-D8E6-4357-8E47-9E0B218A0CF4} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {D47112EC-A0E7-4149-94DC-A8E10AB52DC5} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {D6E8AE20-3F78-4CE9-82C5-4B8934B26D92} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {D6FB315C-9D66-4784-952E-646BDB56B64C} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {D713BF1B-3FAB-454A-A2E1-C082D7FBF732} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {D79B8227-A4C5-45D6-A18B-3DC44994E360} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {DA6446AD-C286-452D-8CFF-3FDC4A8FAEAE} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {DB15E7FE-A663-49E7-855F-DAF3F7108538} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {DD99C8DD-4080-418E-9EA2-788A9F44E6E7} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {DDF611D8-225F-4CB7-BD41-EC89E6FFF215} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {DF563934-8E7F-432E-8D58-2A7E0FBE9746} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {DF938D4F-004C-4B85-BFF6-E37FFC59C628} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {E28C9503-7D8A-4AB7-A0F3-6C4ADC39141F} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {E29680CB-944F-4DA1-90B2-F1045E410251} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {E3AF3DEE-095D-40B2-86DE-2B943B886262} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {E49C5BD7-8668-48FE-89BF-234D730F59A1} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {E5751DE8-616E-413E-8D6C-9ECDAE03A8C5} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {E577C9B6-3E94-4782-84D5-5B7FB936152D} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {E65EE812-1359-4A3C-8EF9-8543FD8760AD} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {E70FDDF1-6DA5-4399-A052-EEB7FB565DAB} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {E78C5C5F-A73D-4DD1-B926-09D360E1ACF0} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {E9CFFE87-AAB1-4C46-9059-9931C2A4ADB8} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {EA78C4BF-D3AE-446E-BC0C-1A4AEB678713} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {EA831046-FD80-49B1-A39A-05C7D8E82842} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {EA8C74C4-0146-4508-8C10-F084C2758D38} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {EB49CE94-161A-4D6D-8D3B-D679788FFC46} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {EB4F2B53-450D-457D-A293-D62FA4E99843} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {EBC96C4D-C08E-4767-A625-69F174F11C06} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {EDD6463B-1235-4A97-9E06-82F579810C02} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {EDFEC0AD-ECEC-4FC8-8646-442A73476206} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {EF25916F-55D8-45D9-B0CC-AC6B37183EC0} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {EF2F466C-D47C-467A-B721-21EC3CE0CEB1} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {EF8603CC-F4AE-4B86-936F-B61E0AF6F6D0} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {F2BDA7F2-8B55-4842-A353-59D4D4BE84A8} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {F5AFA1A5-A973-4218-BE12-B339868AC124} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {F5D41367-8F4E-4ED8-98A7-619BB6B0D709} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {F736248E-CFE5-4A23-8DD0-E8B3E6D81B66} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {F7D2798C-F003-4FF4-949A-FA1E00C7A303} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {FA490C40-4530-4EC8-8ACD-AC373F771E61} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {FB56178A-2E68-410B-B88B-84C2DA0C3A0E} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {FCE1CEA1-DFE8-4F5F-8F4E-00980E4B3771} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {FD2334D3-4CB5-4168-9FA7-5D8BF69F9F97} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {FDC8EA12-4E59-4108-8D03-AA4A64AE43FD} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {FDFE68F7-1808-47F5-9D91-5C28855ED0F0} - (Recherche sécurisée) - http://fr.search.yahoo.com
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.90A7C2C7404D877865ED6670339C51EC] [SPRF][25/12/2014] (...) -- C:\Users\Bernard\AppData\Roaming\System5908ConfigCollection.dat [24]
[MD5.E168731F246AA436A38641340C85AB2B] [SPRF][30/09/2011] (...) -- C:\Program Files (x86)\Uninstall_IGE_PluginFrancais.exe [128004]
~ Files: 2 Legitimates Filtered in 00mn 00s



---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.35C918348CBB0877BCD5A3CF24C13761] [WIS][25/11/2012] (.DeltaInstaller - Delta Chrome Toolbar.) -- C:\Windows\Installer\930f79c.msi [573440] =>Toolbar.DeltaSearch
~ WIS: 1 Legitimates Filtered in 00mn 09s



---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{320AF880-6646-11D3-ABEE-C5DBF3571F49}] (SavePass) =>PUP.CrossRider
~ BCK: 5971 Legitimates Filtered in 00mn 08s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 01/09/2011 169624 | (AdobeActiveFileMonitor10.0) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
SS - | Demand 07/02/2015 267440 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 08/03/2010 192000 | (BsHelpCS) . (.IVT Corporation.) - C:\Program Files (x86)\IVT Corporation\BlueSoleil\BsHelpCS.exe
SS - | Disabled 29/07/2009 163840 | (EPSON_EB_RPCV4_01) . (.SEIKO EPSON CORPORATION.) - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.exe
SS - | Disabled 29/07/2009 126464 | (EPSON_PM_RPCV4_01) . (.SEIKO EPSON CORPORATION.) - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.exe
SS - | Demand 19/01/2012 1030600 | (FLEXnet Licensing Service 64) . (.Macrovision Europe Ltd..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
SS - | Demand 19/06/2010 246520 | (GameConsoleService) . (.WildTangent, Inc..) - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
SS - | Auto 31/01/2015 107912 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 31/01/2015 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 11/08/2012 194032 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
SS - | Demand 09/09/2011 86072 | (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe =>.Hewlett-Packard Co
SS - | Demand 06/08/2010 291896 | (HPClientSvc) . (.Hewlett-Packard Company.) - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
SS - | Demand 01/04/2014 49464 | (HPSupportSolutionsFrameworkService) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
SS - | Demand 22/10/2004 73728 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
SS - | Demand 24/03/2014 357144 | (LBTServ) . (.Logitech, Inc..) - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
SS - | Auto 16/01/2015 2724128 | (LiveUpdateSvc) . (.IObit.) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
SS - | Demand 15/10/2014 2820424 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe
SS - | Auto 21/11/2014 969016 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
SS - | Demand 24/01/2015 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 24/09/2008 935208 | (Nero BackItUp Scheduler 4.0) . (.Nero AG.) - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
SS - | Demand 14/07/2009 27136 | C:\Windows\system32\HPZinw12.dll (Net Driver HPZ12) . (.Hewlett-Packard.) - C:\Windows\System32\svchost.exe
SS - | Disabled 17/09/2014 1795912 | (NvNetworkService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
SS - | Disabled 17/09/2014 19439944 | (NvStreamSvc) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
SS - | Demand 14/08/2013 39056 | (RealNetworks Downloader Resolver Service) . (...) - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
SS - | Disabled 06/12/2007 88560 | (Roxio UPnP Renderer 9) . (.Sonic Solutions.) - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
SS - | Disabled 06/12/2007 362992 | (Roxio Upnp Server 9) . (.Sonic Solutions.) - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUpnpService9.exe
SS - | Auto 11/04/2009 313840 | (RoxLiveShare9) . (.Sonic Solutions.) - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
SS - | Demand 11/04/2009 1108464 | (RoxMediaDB9) . (.Sonic Solutions.) - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
SS - | Disabled 11/04/2009 170480 | (RoxWatch9) . (.Sonic Solutions.) - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
SS - | Demand 05/11/2014 73200 | (SandraAgentSrv) . (.SiSoftware.) - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3\RpcAgentSrv.exe
SS - | Demand 30/06/2011 1191936 | (SgtSch2Svc) . (.Seagate.) - C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe
SS - | Demand 04/02/2013 155824 | (Sony PC Companion) . (.Avanquest Software.) - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
SS - | Disabled 02/07/2014 411936 | (Stereo Service) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
SS - | Demand 05/06/2014 93040 | (TomTomHOMEService) . (.TomTom.) - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 04/11/2014 815392 | (AdvancedSystemCareService8) . (.IObit.) - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe
SR - | Auto 17/12/2014 807672 | (AntiVirMailService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
SR - | Auto 17/12/2014 431920 | (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
SR - | Auto 17/12/2014 431920 | (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
SR - | Auto 17/12/2014 993584 | (AntiVirWebService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
SR - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Demand 14/07/2009 27136 | C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll (hpqcxs08) . (.Hewlett-Packard Co..) - C:\Windows\System32\svchost.exe
SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll (hpqddsvc) . (.Hewlett-Packard Co..) - C:\Windows\System32\svchost.exe
SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.dll (HPSLPSVC) . (.Hewlett-Packard Co..) - C:\Windows\System32\svchost.exe
SR - | Auto 04/12/2014 19184 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
SR - | Auto 04/03/2011 73728 | (LightScribeService) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
SR - | Auto 01/10/2009 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 21/11/2014 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
SR - | Auto 30/01/2015 155368 | (McAfee SiteAdvisor Service) . (.McAfee, Inc..) - C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
SR - | Auto 02/07/2014 935368 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe
SR - | Auto 26/11/2010 398176 | (PMBDeviceInfoProvider) . (.Sony Corporation.) - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
SR - | Demand 14/07/2009 27136 | C:\Windows\system32\HPZipm12.dll (Pml Driver HPZ12) . (.Hewlett-Packard.) - C:\Windows\System32\svchost.exe
SR - | Auto 04/09/2014 292568 | (RtkAudioService) . (.Realtek Semiconductor.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
SR - | Auto 26/01/2009 1153368 | (SBSDWSCService) . (.Safer Networking Ltd..) - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
SR - | Auto 15/12/2014 5426448 | (TeamViewer) . (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
SR - | Auto 01/02/2015 126568 | (Unchecky) . (.RaMMicHaeL.) - C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
SR - | Auto 01/10/2009 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Demand 22/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 09s



---\\ Scan Additionnel (O88)
Database Version : 13008 - (08/02/2015)
Clés trouvées (Keys found) : 4
Valeurs trouvées (Values found) : 2
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 3

[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7E685771E24E83F4381D1DB5A45F7B41] =>Toolbar.DeltaSearch
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2BF470E-ED1C-487F-A333-2BD8835EB6CE}] =>Toolbar.QTTabBar
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D2BF470E-ED1C-487F-A333-2BD8835EB6CE}] =>Toolbar.QTTabBar
[HKLM\Software\Classes\CLSID\{D2BF470E-ED1C-487F-A333-2BD8835EB6CE}] =>Toolbar.QTTabBar
[HKLM\Software\Wow6432Node\SW.Booster] =>PUP.SafeWeb^
C:\Windows\Installer\930f79c.msi =>Toolbar.DeltaSearch^
[HKCR\CLSID\{320AF880-6646-11D3-ABEE-C5DBF3571F49}] (SavePass) =>PUP.CrossRider^
~ Additionnel Scan: 619316 Items scanned in 00mn 42s



---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects de navigateur (O2)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ AMI: 4 Legitimates Filtered in 00mn 00s



---\\ Récapitulatif des détections trouvées sur votre station
http://www.nicolascoolman.fr/blog/ =>DriverDetective
http://nicolascoolman.fr/pup-safeweb =>PUP.SafeWeb
http://nicolascoolman.fr/toolbar-deltasearch =>Toolbar.DeltaSearch
http://nicolascoolman.fr/pup-crossrider =>PUP.CrossRider
http://www.nicolascoolman.fr/blog/ =>Toolbar.QTTabBar
~ MSI: 5 link(s) detected in 00mn 00s



~ 2106 Legitimates filtered by white list
End of the scan (838 lines in 01mn 54s)(0.11)

Publicité


Signaler le contenu de ce document

Publicité