cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.8.31.131 Par Nicolas Coolman (2015/08/31)
~ Démarré par fouziamara (Administrator) (2015/08/31 17:43:29)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\fouziamara\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\fouziamara\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
Windows 8.1, 32-bit (Build 9600)

---\\ Navigateurs Internet (3) - 0s
MFIE: Mozilla Firefox 40.0.3 (x86 ar) v40.0.3
OPIE: Opera 18.0.1284.68 v18.0.1284.68
MSIE: Internet Explorer v11.0.9600.17937

---\\ Informations sur les produits Windows (8) - 4s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
~ Windows(R) Operating System, RETAIL channel
Windows ID Activation : OK
~ Windows Partial Key : D3VPT
~ Windows Remaining Initializations Number : 1000
Windows Automatic Updates : OK (Demand)
Windows Activation Technologies : OK

---\\ Logiciels de protection (1) - 0s
Windows Defender (Activate)

---\\ Surveillance de Logiciels (1) - 1s
Adobe Flash Player 18 NPAPI

---\\ Informations sur le système (6) - 0s
~ Operating System: x86 Family 6 Model 15 Stepping 6, GenuineIntel
~ Operating System: 32-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 2095.156 MB (53% free)
~ System Restore: Activé (Enable)
~ System drive C: has 23 GB free of 75 GB

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: FOUZI
~ User Name: fouziamara
~ Logged in as Administrator

---\\ Enumération des unités disques (1) - 0s
~ Drive C: has 23 GB free of 75 GB (System)

---\\ Etat du Centre de Sécurité Windows (11) - 0s
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Recherche particulière de fichiers génériques (23) - 3s
[MD5.91E24273FCA076EA9E65DAFA98901225] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\Windows\Explorer.exe [2207488] ©
[MD5.8BFE805555CDAF6387912A34D7978DAA] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\Windows\System32\rundll32.exe [51200] ©
[MD5.DC02677945BDABD6B0C6A29914AA21EF] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\Windows\System32\Wininit.exe [115712] ©
[MD5.0AC8CD2138FD10C4A0E2FF08F892359C] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\Windows\System32\wininet.dll [1951232] ©
[MD5.E36FB29A2158B7D5DCA0F4E08DE75442] - (.Microsoft Corporation - Application d’ouverture de session Windows.) () -- C:\Windows\System32\Winlogon.exe [465408] ©
[MD5.BFB9E1202225113991F981D29BFB9029] - (.Microsoft Corporation - Bibliothèque de licences.) () -- C:\Windows\System32\sppcomapi.dll [438272] ©
[MD5.E37F897ED7B5AFF79B1398258DB96BD9] - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) () -- C:\Windows\System32\fr-FR\user32.dll.mui [19456] ©
[MD5.D75FB05E8DBF21FA0EF313C7503243F1] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) () -- C:\Windows\System32\drivers\AFD.sys [461312] ©
[MD5.72FCAE2CE6DFEAB2AB072435017F3417] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\Windows\System32\drivers\atapi.sys [23392] ©
[MD5.CE232BB0965C0C0B786C3F976CCBFB7D] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\Windows\System32\drivers\Cdfs.sys [73728] ©
[MD5.E2FC132D48EA4E8B04432C33EFB77801] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\Windows\System32\drivers\Cdrom.sys [124928] ©
[MD5.55758EBBC45E1628161121D7CFEAD4A1] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\Windows\System32\drivers\DfsC.sys [102400] ©
[MD5.7E0EDA9EE53E344D1604EB2A7E8DED47] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\Windows\System32\drivers\HDAudBus.sys [69632] ©
[MD5.7A708934CC652100A94944EC808C3916] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\Windows\System32\drivers\i8042prt.sys [83456] ©
[MD5.FA6C94C754A566EA8A61D658932F32DE] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\Windows\System32\drivers\IpNat.sys [126976] ©
[MD5.49EDA7967848465645E2D809384D0EBA] - (.Microsoft Corporation - Minirdr SMB Windows NT.) () -- C:\Windows\System32\drivers\MRxSmb.sys [328704] ©
[MD5.BC242922B0D08F61CF7C87FD08FAFA8B] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\Windows\System32\drivers\netBT.sys [218624] ©
[MD5.C52E578E3F8182C2EE6AAF0AC2B61C9B] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\Windows\System32\drivers\ntfs.sys [1689408] ©
[MD5.4F30970F15ADCC382544B31D5D7E368E] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\Windows\System32\drivers\Parport.sys [81408] ©
[MD5.C51AB62AB41A2E8560D12472B204CC00] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\Windows\System32\drivers\Rasl2tp.sys [81920] ©
[MD5.67E91843B0344411820A012063E876B2] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) () -- C:\Windows\System32\drivers\rdpdr.sys [143872] ©
[MD5.DB0C184142CF9FA1746F598A16EE92B2] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\Windows\System32\drivers\tdx.sys [87040] ©
[MD5.31A2AA48C1ECD390E2707E5C21B75DCE] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\Windows\System32\drivers\volsnap.sys [264512] ©

---\\ Processus lancés (14) - 1s
[MD5.9B9CFF0D95FB89B766603A84ED24B3FD] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 307.6.) -- C:\Windows\System32\nvvsvc.exe [645992] [PID.792] ©
[MD5.67EB80A2DCEE12170085F902EAF34039] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [864616] [PID.840] ©
[MD5.9B9CFF0D95FB89B766603A84ED24B3FD] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 307.6.) -- C:\Windows\System32\nvvsvc.exe [645992] [PID.852] ©
[MD5.E0344E54C8327EBF7269B0FC47D38533] - (.NVIDIA Corporation - NVIDIA Settings.) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe [1821032] [PID.3456] ©
[MD5.8F89E6CB82E6DB45BC993D423CD0FDBD] - (.Hewlett-Packard Development Company, L.P. - Quick Launch Buttons.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe [323640] [PID.3744] ©
[MD5.62B3C9786081ECAAB272A118408D2817] - (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1045800] [PID.3764]
[MD5.1F373C5DB440D92839DDDF63F5BA2E8A] - (.Synaptics, Inc. - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [95528] [PID.3928]
[MD5.DC7B578A97F82AAB19906DAEB3693D1C] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe [3878480] [PID.3960] ©
[MD5.FDF273A845F1FFCCEADF363AAF47582F] - (.Hewlett-Packard Development Company, L.P. - hpqwmiex Module.) -- C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe [229944] [PID.3984] ©
[MD5.C7A0E61D5714AC20DE52D4F66EC773B8] - (.Hewlett-Packard Development Company, L.P. - Com for QLB application.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [227896] [PID.4088] ©
[MD5.BD95E822E7A958BBCA842D078426A151] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe [269848] [PID.1900] ©
[MD5.05299546F243159CB8A42906ACB219A8] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [377000] [PID.2100] ©
[MD5.C9610C4EF9C20777AE0B1B63F523BB3F] - (.NVIDIA Corporation - NVIDIA Settings Update Manager.) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [1258856] [PID.2416] ©
[MD5.FE4DD1A2E417A772052A142AEAFE5EDD] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\fouziamara\AppData\Roaming\ZHP\ZHPDiag3.exe [1915392] [PID.3868] ©

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (10) - 1s
M0 - MFSP: prefs.js [fouziamara - 2lx6rfrf.default] http://home.tb.ask.com/index.jhtml?ptb=C403876B-820D-4EEC-BD3A-0A0A1B995EE7&n=781b8c4e&p2=^BQP^xdm173^YYA^dz&si=COqUg9_42MYCFYYfwwodgdsOvA =>Toolbar.Ask
P2 - EXT FILE: (...) -- C:\Users\fouziamara\AppData\Roaming\Mozilla\Firefox\Profiles\2lx6rfrf.default\extensions\jid1-yuNlgYDr5nIP2w@jetpack.xpi
P2 - EXT FILE: (...) -- C:\Users\fouziamara\AppData\Roaming\Mozilla\Firefox\Profiles\2lx6rfrf.default\searchplugins\ask-web-search.xml
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ©
P2 - EXT: (.Mindspark - YourVideoChat.) -- C:\Users\fouziamara\AppData\Roaming\Mozilla\Firefox\Profiles\2lx6rfrf.default\extensions\86ffxtbr@download.yourvideochat.com
P2 - EXT: (.Mindspark - Allin1Convert.) -- C:\Users\fouziamara\AppData\Roaming\Mozilla\Firefox\Profiles\2lx6rfrf.default\extensions\8hffxtbr@download.allin1convert.com =>PUP.Optional.MindSpark
P2 - EXT: (.Microsoft Corporation - Bing Search Engine.) -- C:\Users\fouziamara\AppData\Roaming\Mozilla\Firefox\Profiles\2lx6rfrf.default\extensions\bingsearch.full@microsoft.com ©
P2 - EXT: (.Mindspark - Cats and Catapults.) -- C:\Users\fouziamara\AppData\Roaming\Mozilla\Firefox\Profiles\2lx6rfrf.default\extensions\btffxtbr@free.catsandcatapults.com
P2 - EXT: (.Mindspark - GamingWonderland.) -- C:\Users\fouziamara\AppData\Roaming\Mozilla\Firefox\Profiles\2lx6rfrf.default\extensions\gtffxtbr@free.gamingwonderland.com
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\NPSWF32_18_0_0_232.dll ©

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (10) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1

---\\ Internet Explorer,Proxy Management (4) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.)
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.)
F2 - REG:system.ini: VMApplet=C:\Windows\system32\SystemPropertiesPerformance.exe (.Microsoft Corporation.)

---\\ Etude du fichier hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ Browser Helper Object de navigateur (BHO) (2) - 1s
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll ©

---\\ Applications lancées au démarrage du système (6) - 0s
O4 - HKLM\..\Run: [QlbCtrl.exe] . (.Hewlett-Packard Development Company, L.P. - Quick Launch Buttons.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe ©
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\fouziamara\AppData\Local\Facebook\Update\FacebookUpdate.exe ©
O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe ©
O4 - HKUS\S-1-5-21-1869252270-2785501833-3554448809-1001\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\fouziamara\AppData\Local\Facebook\Update\FacebookUpdate.exe ©
O4 - HKUS\S-1-5-21-1869252270-2785501833-3554448809-1001\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe ©

---\\ Modification Domaine/Adresses DNS (2) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

---\\ Protocole additionnel (22) - 1s
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll ©
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll ©
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll ©
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll ©
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} . (.Skype Technologies - Skype4COM.) -- C:\Program Files\Common Files\Skype\Skype4COM.dll ©
O18 - Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll ©
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll ©
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©
O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©

---\\ Liste des services NT non Microsoft et non désactivés (3) - 1s
O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 307.6.) - C:\Windows\System32\nvvsvc.exe ©
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) . (.NVIDIA Corporation - NVIDIA Settings Update Manager.) - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe ©
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe ©

---\\ Tâches planifiées en automatique (15) - 3s
[MD5.368290D0A612D62DA6F3D798B1BB8FE7] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [269000] ©
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-1869252270-2785501833-3554448809-1001Core] (.Facebook Inc..) -- C:\Users\fouziamara\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] ©
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-1869252270-2785501833-3554448809-1001UA] (.Facebook Inc..) -- C:\Users\fouziamara\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] ©
[MD5.00000000000000000000000000000000] [APT] [LaunchSignup] (...) -- C:\Program Files\MyPC Backup\Signup Wizard.exe (.not file.) [0] =>PUP.Optional.MyPCBackup
[MD5.00000000000000000000000000000000] [APT] [PCRegistryShield_Popup] (...) -- C:\Program Files\PC Registry Shield\Splash.exe (.not file.) [0] =>PUP.Optional.PCRegistryShield
[MD5.00000000000000000000000000000000] [APT] [PCRegistryShield_Start] (...) -- C:\Program Files\PC Registry Shield\PcRegistryShield.exe (.not file.) [0] =>PUP.Optional.PCRegistryShield
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002] ©
O39 - APT: FacebookUpdateTaskUserS-1-5-21-1869252270-2785501833-3554448809-1001Core - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1869252270-2785501833-3554448809-1001Core.job [938] ©
O39 - APT: FacebookUpdateTaskUserS-1-5-21-1869252270-2785501833-3554448809-1001UA - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1869252270-2785501833-3554448809-1001UA.job [960] ©
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [3890] ©
O39 - APT: FacebookUpdateTaskUserS-1-5-21-1869252270-2785501833-3554448809-1001Core - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1869252270-2785501833-3554448809-1001Core [3468] ©
O39 - APT: FacebookUpdateTaskUserS-1-5-21-1869252270-2785501833-3554448809-1001UA - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1869252270-2785501833-3554448809-1001UA [3818] ©
O39 - APT: LaunchSignup - (...) -- C:\Windows\System32\Tasks\LaunchSignup [4018] =>PUP.Optional.MyPCBackup
O39 - APT: PCRegistryShield_Popup - (...) -- C:\Windows\System32\Tasks\PCRegistryShield_Popup [3468] =>PUP.Optional.PCRegistryShield
O39 - APT: PCRegistryShield_Start - (...) -- C:\Windows\System32\Tasks\PCRegistryShield_Start [3204] =>PUP.Optional.PCRegistryShield

---\\ Logiciels installés (16) - 5s
O42 - Logiciel: Adobe Flash Player 18 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI ©
O42 - Logiciel: GTA: San Andreas RIP PT-BR by TemDono - #GTABrasil - BrasNET - (.TemDono Design 2005.) [HKLM] -- Grand Theft Auto San Andreas_is1
O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM] -- Internet Download Manager ©
O42 - Logiciel: Mozilla Firefox 40.0.3 (x86 ar) - (.Mozilla.) [HKLM] -- Mozilla Firefox 40.0.3 (x86 ar) ©
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService ©
O42 - Logiciel: Opera Stable 18.0.1284.68 - (.Opera Software ASA.) [HKLM] -- Opera 18.0.1284.68 ©
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics.) [HKLM] -- SynTPDeinstKey ©
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM] -- VLC media player ©
O42 - Logiciel: WinRAR 5.11 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver ©
O42 - Logiciel: Facebook Video Calling 3.1.0.521 - (.Skype Limited.) [HKLM] -- {2091F234-EB58-4B80-8C96-8EB78C808CF7} ©
O42 - Logiciel: HP Quick Launch Buttons - (.Hewlett-Packard Company.) [HKLM] -- {34D2AB40-150D-475D-AE32-BD23FB5EE355} ©
O42 - Logiciel: Skype™ 7.8 - (.Skype Technologies S.A..) [HKLM] -- {6A0549A9-1B96-498C-ACBC-3943001FEB19} ©
O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701} ©
O42 - Logiciel: NVIDIA Pilote graphique 307.68 - (.NVIDIA Corporation.) [HKLM] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver ©
O42 - Logiciel: Mises à jour NVIDIA 1.10.8 - (.NVIDIA Corporation.) [HKLM] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update ©
O42 - Logiciel: QLBCASL - (.Hewlett-Packard.) [HKLM] -- {F1D7AC58-554A-4A58-B784-B61558B1449A} ©

---\\ HKCU & HKLM Software Keys (47) - 5s
HKLM\SOFTWARE\AVAST Software
HKLM\SOFTWARE\Caphyon
HKLM\SOFTWARE\CXT
HKLM\SOFTWARE\Google
HKLM\SOFTWARE\Hewlett-Packard
HKLM\SOFTWARE\IM Providers
HKLM\SOFTWARE\InstalledOptions
HKLM\SOFTWARE\Intel
HKLM\SOFTWARE\Internet Download Manager
HKLM\SOFTWARE\Khronos
HKLM\SOFTWARE\Macromedia
HKLM\SOFTWARE\Mozilla
HKLM\SOFTWARE\mozilla.org
HKLM\SOFTWARE\MozillaPlugins
HKLM\SOFTWARE\NVIDIA Corporation
HKLM\SOFTWARE\ODBC
HKLM\SOFTWARE\RegisteredApplications
HKLM\SOFTWARE\Rockstar Games
HKLM\SOFTWARE\Skype
HKLM\SOFTWARE\Synaptics
HKLM\SOFTWARE\VideoLAN
HKLM\SOFTWARE\WinRAR
HKLM\SOFTWARE\Wow6432Node
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\DownloadManager
HKCU\SOFTWARE\Facebook
HKCU\SOFTWARE\Hewlett-Packard
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\InstallCore =>Adware.InstallCore
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\Mine
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\NVIDIA Corporation
HKCU\SOFTWARE\Opera Software
HKCU\SOFTWARE\PCRegistryShieldConfig
HKCU\SOFTWARE\PCRegistryShieldLanguage
HKCU\SOFTWARE\RegisteredApplications
HKCU\SOFTWARE\Skype
HKCU\SOFTWARE\SkypeRS
HKCU\SOFTWARE\spookie
HKCU\SOFTWARE\Synaptics
HKCU\SOFTWARE\TeleCharger
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\Software

---\\ Contenu des dossiers Programmes (102) - 18s
O43 - CFD: 2015/08/19 15:11:57 - [] D -- C:\Program Files\Common Files
O43 - CFD: 2014/08/05 20:57:26 - [0] SHD -- C:\Program Files\Fichiers communs
O43 - CFD: 2014/08/06 20:24:30 - [] D -- C:\Program Files\Hewlett-Packard
O43 - CFD: 2014/08/06 20:24:06 - [] HD -- C:\Program Files\InstallShield Installation Information
O43 - CFD: 2015/03/11 22:39:44 - [] D -- C:\Program Files\Internet Download Manager
O43 - CFD: 2015/08/14 04:36:44 - [] D -- C:\Program Files\Internet Explorer
O43 - CFD: 2013/08/22 10:17:26 - [] D -- C:\Program Files\Microsoft.NET
O43 - CFD: 2015/08/30 23:08:59 - [] D -- C:\Program Files\Mozilla Firefox
O43 - CFD: 2015/08/30 23:08:59 - [] D -- C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 2014/08/28 03:35:47 - [] D -- C:\Program Files\MSBuild
O43 - CFD: 2014/09/03 02:23:19 - [] D -- C:\Program Files\NVIDIA Corporation
O43 - CFD: 2015/06/01 00:54:29 - [] D -- C:\Program Files\Opera
O43 - CFD: 2014/09/03 01:26:45 - [] D -- C:\Program Files\PC Registry Shield =>PUP.Optional.PCRegistryShield
O43 - CFD: 2014/08/28 03:35:47 - [] D -- C:\Program Files\Reference Assemblies
O43 - CFD: 2015/08/27 20:55:31 - [] D -- C:\Program Files\Rockstar Games
O43 - CFD: 2015/08/19 15:11:58 - [] RD -- C:\Program Files\Skype
O43 - CFD: 2014/08/06 20:34:33 - [] D -- C:\Program Files\Synaptics
O43 - CFD: 2013/08/22 09:24:44 - [0] HD -- C:\Program Files\Uninstall Information
O43 - CFD: 2014/10/24 18:08:06 - [] D -- C:\Program Files\VideoLAN
O43 - CFD: 2015/08/14 04:36:46 - [] D -- C:\Program Files\Windows Defender
O43 - CFD: 2015/05/17 00:48:57 - [] D -- C:\Program Files\Windows Journal
O43 - CFD: 2015/03/15 01:12:43 - [] D -- C:\Program Files\Windows Mail
O43 - CFD: 2015/03/15 01:12:43 - [] D -- C:\Program Files\Windows Media Player
O43 - CFD: 2015/03/15 01:12:43 - [] D -- C:\Program Files\Windows Multimedia Platform
O43 - CFD: 2014/08/05 20:57:26 - [] D -- C:\Program Files\Windows NT
O43 - CFD: 2015/03/15 01:12:42 - [] D -- C:\Program Files\Windows Photo Viewer
O43 - CFD: 2015/03/15 01:12:43 - [] D -- C:\Program Files\Windows Portable Devices
O43 - CFD: 2013/08/22 10:17:26 - [] SHD -- C:\Program Files\Windows Sidebar
O43 - CFD: 2015/08/13 19:19:51 - [] HD -- C:\Program Files\WindowsApps
O43 - CFD: 2015/03/15 01:10:36 - [] D -- C:\Program Files\WindowsPowerShell
O43 - CFD: 2015/08/25 21:54:19 - [] D -- C:\Program Files\WinRAR
O43 - CFD: 2015/03/15 01:13:01 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 2015/03/15 01:13:01 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2015/03/15 01:13:01 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2014/10/05 18:29:54 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 2013/08/22 10:17:27 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/08/27 21:04:44 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
O43 - CFD: 2015/08/19 15:12:00 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 2013/08/22 10:17:27 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
O43 - CFD: 2015/03/15 01:13:01 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 2013/08/22 16:36:28 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 2014/10/24 18:08:55 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
O43 - CFD: 2015/08/25 21:59:08 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 2013/08/22 09:23:42 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 2015/01/20 01:28:03 - [] D -- C:\ProgramData\AVAST Software
O43 - CFD: 2014/08/05 20:57:26 - [0] SHD -- C:\ProgramData\Bureau
O43 - CFD: 2013/08/22 09:23:42 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 2013/08/22 09:23:42 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 2014/08/05 21:28:14 - [0] D -- C:\ProgramData\IDM
O43 - CFD: 2014/08/05 20:57:26 - [0] SHD -- C:\ProgramData\Menu Démarrer
O43 - CFD: 2015/04/23 15:25:28 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 2014/08/05 20:57:26 - [0] SHD -- C:\ProgramData\Modèles
O43 - CFD: 2014/08/05 21:53:47 - [] D -- C:\ProgramData\Mozilla
O43 - CFD: 2014/09/03 02:23:25 - [] D -- C:\ProgramData\NVIDIA
O43 - CFD: 2014/09/03 02:21:00 - [] D -- C:\ProgramData\NVIDIA Corporation
O43 - CFD: 2015/03/15 01:10:42 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 2015/08/19 15:11:46 - [] D -- C:\ProgramData\Skype
O43 - CFD: 2013/08/22 09:23:42 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 2013/08/22 09:23:42 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 2013/08/22 16:33:34 - [] D -- C:\Program Files\Common Files\microsoft shared
O43 - CFD: 2013/08/22 10:17:35 - [] D -- C:\Program Files\Common Files\Services
O43 - CFD: 2015/08/19 15:11:57 - [] D -- C:\Program Files\Common Files\Skype
O43 - CFD: 2015/03/15 01:12:41 - [] D -- C:\Program Files\Common Files\System
O43 - CFD: 2014/08/05 21:09:26 - [] D -- C:\Users\fouziamara\AppData\Roaming\Adobe
O43 - CFD: 2015/08/31 16:58:07 - [] D -- C:\Users\fouziamara\AppData\Roaming\DMCache
O43 - CFD: 2014/09/03 01:24:25 - [] D -- C:\Users\fouziamara\AppData\Roaming\hpqLog
O43 - CFD: 2015/03/15 01:25:19 - [] D -- C:\Users\fouziamara\AppData\Roaming\Identities
O43 - CFD: 2015/08/28 19:37:36 - [] D -- C:\Users\fouziamara\AppData\Roaming\IDM
O43 - CFD: 2014/08/05 21:29:25 - [] D -- C:\Users\fouziamara\AppData\Roaming\Macromedia
O43 - CFD: 2014/09/03 01:24:03 - [] SD -- C:\Users\fouziamara\AppData\Roaming\Microsoft
O43 - CFD: 2014/08/05 21:53:59 - [] D -- C:\Users\fouziamara\AppData\Roaming\Mozilla
O43 - CFD: 2014/08/08 20:17:00 - [] D -- C:\Users\fouziamara\AppData\Roaming\Opera Software
O43 - CFD: 2015/08/31 16:41:34 - [] D -- C:\Users\fouziamara\AppData\Roaming\Skype
O43 - CFD: 2015/08/30 23:14:24 - [] D -- C:\Users\fouziamara\AppData\Roaming\vlc
O43 - CFD: 2014/09/24 23:32:04 - [] D -- C:\Users\fouziamara\AppData\Roaming\WinRAR
O43 - CFD: 2015/08/31 17:44:03 - [] D -- C:\Users\fouziamara\AppData\Roaming\ZHP
O43 - CFD: 2014/08/05 21:09:21 - [0] SHD -- C:\Users\fouziamara\AppData\Local\Application Data
O43 - CFD: 2015/08/09 00:31:34 - [] D -- C:\Users\fouziamara\AppData\Local\Diagnostics
O43 - CFD: 2015/08/11 18:57:43 - [0] D -- C:\Users\fouziamara\AppData\Local\ElevatedDiagnostics
O43 - CFD: 2015/06/11 02:36:37 - [0] SHD -- C:\Users\fouziamara\AppData\Local\EmieBrowserModeList
O43 - CFD: 2015/06/11 02:36:37 - [0] SHD -- C:\Users\fouziamara\AppData\Local\EmieSiteList
O43 - CFD: 2015/06/11 02:36:37 - [0] SHD -- C:\Users\fouziamara\AppData\Local\EmieUserList
O43 - CFD: 2014/10/02 23:28:34 - [] D -- C:\Users\fouziamara\AppData\Local\Facebook
O43 - CFD: 2014/08/05 21:09:21 - [0] SHD -- C:\Users\fouziamara\AppData\Local\Historique
O43 - CFD: 2014/08/06 00:08:56 - [] D -- C:\Users\fouziamara\AppData\Local\Macromedia
O43 - CFD: 2015/03/15 01:25:16 - [] D -- C:\Users\fouziamara\AppData\Local\Microsoft
O43 - CFD: 2014/08/05 21:53:52 - [] D -- C:\Users\fouziamara\AppData\Local\Mozilla
O43 - CFD: 2014/08/08 20:17:02 - [] D -- C:\Users\fouziamara\AppData\Local\Opera Software
O43 - CFD: 2015/08/06 00:02:49 - [] D -- C:\Users\fouziamara\AppData\Local\Packages
O43 - CFD: 2014/08/29 19:52:00 - [] D -- C:\Users\fouziamara\AppData\Local\ShieldApps
O43 - CFD: 2014/08/05 21:25:38 - [] D -- C:\Users\fouziamara\AppData\Local\Skype
O43 - CFD: 2015/08/31 17:42:37 - [] D -- C:\Users\fouziamara\AppData\Local\Temp
O43 - CFD: 2014/08/05 21:09:21 - [0] SHD -- C:\Users\fouziamara\AppData\Local\Temporary Internet Files
O43 - CFD: 2014/08/05 21:09:28 - [0] D -- C:\Users\fouziamara\AppData\Local\VirtualStore
O43 - CFD: 2013/08/22 10:17:27 - [] RD -- C:\Users\fouziamara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 2013/08/22 10:17:27 - [] RD -- C:\Users\fouziamara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2015/07/16 14:39:11 - [] RD -- C:\Users\fouziamara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2014/10/05 18:29:54 - [] D -- C:\Users\fouziamara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 2013/08/22 10:17:27 - [] D -- C:\Users\fouziamara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/07/16 14:39:11 - [] RD -- C:\Users\fouziamara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2013/08/22 10:17:27 - [] RD -- C:\Users\fouziamara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 2015/08/25 21:59:08 - [] D -- C:\Users\fouziamara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR

---\\ Liste des pilotes du système (44) - 14s
O58 - SDL:2013/08/22 07:33:26 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\drivers\3ware.sys [86368] ©
O58 - SDL:2013/08/22 07:33:25 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\Windows\System32\drivers\adp80xx.sys [773472] ©
O58 - SDL:2013/08/22 07:33:25 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [72544] ©
O58 - SDL:2013/08/22 07:33:26 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [215392] ©
O58 - SDL:2013/08/22 07:33:24 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [22880] ©
O58 - SDL:2013/08/22 07:33:26 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [101728] ©
O58 - SDL:2013/08/13 01:25:32 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\drivers\bcmfn2.sys [16088] ©
O58 - SDL:2010/02/25 00:02:30 A . (.Hewlett-Packard Company - HP Tablet PC Key Button HID Driver.) -- C:\Windows\System32\drivers\CPQBTTN.sys [15544] ©
O58 - SDL:2013/06/18 14:21:39 A . (.Intel Corporation - Intel(R) PRO/1000 Adapter NDIS 6 deserializ.) -- C:\Windows\System32\drivers\e1e6032.sys [214016] ©
O58 - SDL:2009/04/29 07:46:54 A . (.Hewlett-Packard Development Company, L.P. - HpqKbFiltr Keyboard Filter Driver.) -- C:\Windows\System32\drivers\HpqKbFiltr.sys [15872] ©
O58 - SDL:2013/08/22 07:33:29 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [56672] ©
O58 - SDL:2013/07/23 23:18:30 AC . (.Intel Corporation - Intel(R) Atom(TM) Processor GPIO Controller.) -- C:\Windows\System32\drivers\iaiogpio.sys [22016] ©
O58 - SDL:2013/07/23 23:18:30 AC . (.Intel Corporation - Intel(R) Atom(TM) Processor I2C Controller.) -- C:\Windows\System32\drivers\iaioi2c.sys [61936] ©
O58 - SDL:2013/08/10 02:39:44 A . (.Intel Corporation - Intel Rapid Storage Technology driver (inbo.) -- C:\Windows\System32\drivers\iaStorAV.sys [524784] ©
O58 - SDL:2013/08/22 07:33:29 A . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\drivers\iaStorV.sys [333664] ©
O58 - SDL:2014/10/01 08:19:10 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\drivers\idmwfp.sys [115240] ©
O58 - SDL:2013/08/22 07:33:29 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [94048] ©
O58 - SDL:2013/08/22 07:33:30 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [79712] ©
O58 - SDL:2013/08/22 07:33:30 A . (.LSI Corporation - LSI SAS Gen3 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas3.sys [68960] ©
O58 - SDL:2013/08/22 07:33:29 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sss.sys [69472] ©
O58 - SDL:2013/08/22 07:33:30 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [51552] ©
O58 - SDL:2013/08/22 07:33:29 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\megasr.sys [464736] ©
O58 - SDL:2013/08/22 07:33:32 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\drivers\mvumis.sys [58208] ©
O58 - SDL:2013/06/18 14:22:16 A . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\Windows\System32\drivers\netwlv32.sys [6637056] ©
O58 - SDL:2012/12/18 03:22:46 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\Windows\System32\drivers\nvlddmkm.sys [10908520] ©
O58 - SDL:2013/08/22 07:33:32 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [120160] ©
O58 - SDL:2013/08/22 07:33:33 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [141664] ©
O58 - SDL:2006/12/18 22:31:46 A . (.Ricoh - Description string for UvcFilter driver.) -- C:\Windows\System32\drivers\R5U870FLx86.sys [73472] ©
O58 - SDL:2006/12/18 22:31:46 A . (.Ricoh - Description string for UvcUpperFilter drive.) -- C:\Windows\System32\drivers\R5U870FUx86.sys [43904] ©
O58 - SDL:2006/11/14 17:35:20 A . (.REDC - RICOH XD SM Driver.) -- C:\Windows\System32\drivers\rixdptsk.sys [37376] ©
O58 - SDL:2013/08/22 10:16:47 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [20480] ©
O58 - SDL:2013/08/22 07:32:56 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [41312] ©
O58 - SDL:2013/08/22 07:32:57 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [79200] ©
O58 - SDL:2014/01/22 09:52:12 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudbus.sys [88576] ©
O58 - SDL:2014/01/22 09:52:12 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudmdm.sys [184192] ©
O58 - SDL:2013/08/22 07:32:57 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\Windows\System32\drivers\stexstor.sys [26976] ©
O58 - SDL:2008/03/28 02:06:00 A . (.Synaptics, Inc. - Synaptics Touchpad Driver.) -- C:\Windows\System32\drivers\SynTP.sys [199472]
O58 - SDL:2013/08/22 07:33:00 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [18272] ©
O58 - SDL:2013/08/22 07:33:01 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR X86-32.) -- C:\Windows\System32\drivers\vsmraid.sys [148832] ©
O58 - SDL:2013/06/18 14:35:26 A . (.Conexant Systems, Inc. - HSF_HWAZL WDM driver.) -- C:\Windows\System32\drivers\VSTAZL3.SYS [207360] ©
O58 - SDL:2013/06/18 14:35:26 A . (.Conexant Systems, Inc. - HSF_CNXT driver.) -- C:\Windows\System32\drivers\VSTCNXT3.SYS [661504] ©
O58 - SDL:2013/06/18 14:35:26 A . (.Conexant Systems, Inc. - HSF_DP driver.) -- C:\Windows\System32\drivers\VSTDPV3.SYS [980992] ©
O58 - SDL:2013/08/22 07:33:01 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\drivers\VSTXRAID.SYS [276832] ©
O58 - SDL:2014/08/27 17:37:32 A . (.StdLib - StdLib.) -- C:\Windows\System32\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw.sys [52368] =>PUP.Optional.LinkiDoo

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (3) - 93s
O61 - LFC: 2015/08/27 20:54:46 A . (.TemDono Design 2005.) -- C:\Users\fouziamara\Downloads\Programs\pc game - gta san andreas rip by temdono canalgtabrasil brasnet_2.exe [689588326]
O61 - LFC: 2015/08/25 21:49:08 A . (..) -- C:\Users\fouziamara\Downloads\Programs\wrar511_2.exe [1745176]
O61 - LFC: 2015/08/28 04:16:53 A . (..) -- C:\Users\fouziamara\AppData\Local\Microsoft\Windows\INetCache\IE\RM9PVTJU\urlblockindex[1].bin [16]

---\\ Associations Shell Spawning (11) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe ©
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe ©
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ©
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe ©
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe ©
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe ©

---\\ Menu de démarrage Internet (12) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\Launcher.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe ©

---\\ Recherche d'infection sur les navigateurs (179) - 8s
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("browser.startup.homepage", "http://home.tb.ask.com/index.jhtml?ptb=C403876B-820D-4EEC-BD3A-0A0A1B995EE7&n=781b8c4e&p2=^[...] =>Toolbar.Ask
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.enabledAddons", "gtffxtbr%40free.gamingwonderland.com:7.35.8.14844,8hffxtbr%40download.allin1convert.com:7.3[...] =>PUP.Optional.MindSpark
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark.Mindspark.MindsparkFF_.browser.version.last", "40.0"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark.MindsparkFF_.lssState", "{\"previousLocales\":[\"ar\",\"en-US\",\"en\"],\"supportedLocales[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.BUTTON_STRUCTURE", "[{\"b\":212025602,\"c\":\"mindspark.magnify\",\"p\":\"L.0\[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.browser.search.defaultenginename.prev", "Ask Web Search"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.browser.search.defaultenginename.savedPrev", "true"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.browser.search.defaultenginename.tb", "Ask Web Search"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.browser.search.selectedEngine.prev", "Ask Web Search"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.browser.search.selectedEngine.savedPrev", "true"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.browser.search.selectedEngine.tb", "Ask Web Search"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.browser.startup.homepage.prev", "http://home.tb.ask.com/index.jhtml?ptb=93B1FB[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.browser.startup.homepage.savedPrev", "true"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.browser.startup.homepage.tb", "http://home.tb.ask.com/index.jhtml?ptb=A5820EDE[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.browser.startup.page.savedPrev", 1); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.browser.startup.page.tb", 1); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.browser.version.last", "40.0"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.competitorDNS", "{\"comment\":\"refresh every 1 week (7*24*60*60*1000)\",\"ref[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.firstKnownVersion", "6.85.5.65394"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.homepage", "http://home.tb.ask.com/index.jhtml?ptb=A5820EDE-EB91-496A-883B-819[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.hp.enabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.hp.guardType", "HPR"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.initialized", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.installKeysSource", "LocalStorage"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.installType", "XPI"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.installation.contextKey", ""); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.installation.dlpCountryCode", "DZ"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.installation.installDate", "2014111105"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.installation.partnerId", "^AVV^xdm007^YYA^dz"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.installation.partnerSubId", "CKa375P78sECFTHLtAod1T4AyA"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.installation.pixelUrl", "http://download.yourvideochat.com/install_pixels.jhtm[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.installation.success", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.installation.toolbarId", "A5820EDE-EB91-496A-883B-8195FB08DE15"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.isCompliantUninstallImplementation", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.lastActivePing", "1441016226369"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.lastKnownVersion", "1.0.1.16857"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.options.defaultSearch", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.options.homePageEnabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.options.keywordEnabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.options.tabEnabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.partnerPixelFired", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.searchHistory", "BirdHistoryDesertSpeedYou and I\r\nWe get married onc[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.successUrl", "http://download.yourvideochat.com/installComplete.jhtml"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.toolbar.versionChanged", false); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.toolbarCollapsed", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._86Members_.weather.location", "10001"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.BUTTON_STRUCTURE", "[{\"b\":224540224,\"c\":\"mindspark.magnify\",\"p\":\"L.0\[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.browser.search.defaultenginename.prev", "Ask Web Search"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.browser.search.defaultenginename.savedPrev", "true"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.browser.search.defaultenginename.tb", "Ask Web Search"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.browser.search.selectedEngine.prev", "Ask Web Search"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.browser.search.selectedEngine.savedPrev", "true"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.browser.search.selectedEngine.tb", "Ask Web Search"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.browser.startup.homepage.prev", "http://home.tb.ask.com/index.jhtml?ptb=A5820E[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.browser.startup.homepage.savedPrev", "true"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.browser.startup.homepage.tb", "http://home.tb.ask.com/index.jhtml?ptb=C4E68743[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.browser.startup.page.savedPrev", 1); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.browser.startup.page.tb", 1); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.browser.version.last", "40.0"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.competitorDNS", "{\"comment\":\"refresh every 1 week (7*24*60*60*1000)\",\"ref[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.firstKnownVersion", "6.85.5.64990"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.homepage", "http://home.tb.ask.com/index.jhtml?ptb=C4E68743-D21D-4841-87C8-2BF[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.hp.enabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.hp.guardType", "HPR"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.initialized", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.installKeysSource", "LocalStorage"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.installType", "XPI"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.installation.contextKey", ""); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.installation.dlpCountryCode", "DZ"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.installation.installDate", "2015010601"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.installation.partnerId", "^AYY^xdm399^YYA^dz"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.installation.partnerSubId", "network_pppfc_1XXXXngi0t2o9pvr6"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.installation.pixelUrl", "http://download.allin1convert.com/install_pixels.jhtm[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.installation.success", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.installation.toolbarId", "C4E68743-D21D-4841-87C8-2BF052B1B4EC"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.isCompliantUninstallImplementation", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.lastActivePing", "1440848267026"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.lastKnownVersion", "7.18.7.19706"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.options.defaultSearch", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.options.homePageEnabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.options.keywordEnabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.options.tabEnabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.partnerPixelFired", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.successUrl", "http://download.allin1convert.com/installComplete.jhtml"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.toolbar.versionChanged", false); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.toolbarCollapsed", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._8hMembers_.weather.location", "10001"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.BUTTON_STRUCTURE", "[{\"b\":224519243,\"c\":\"mindspark.magnify\",\"p\":\"L.0\[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.browser.search.defaultenginename.prev", "Google"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.browser.search.defaultenginename.savedPrev", "true"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.browser.search.defaultenginename.tb", "Ask Web Search"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.browser.search.selectedEngine.prev", "Google"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.browser.search.selectedEngine.savedPrev", "true"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.browser.search.selectedEngine.tb", "Ask Web Search"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.browser.startup.homepage.prev", "http://home.tb.ask.com/index.jhtml?ptb=C4E687[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.browser.startup.homepage.savedPrev", "true"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.browser.startup.homepage.tb", "http://home.tb.ask.com/index.jhtml?ptb=C403876B[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.browser.startup.page.savedPrev", 1); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.browser.startup.page.tb", 1); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.browser.version.last", "40.0"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.competitorDNS", "{\"comment\":\"refresh every 1 week (7*24*60*60*1000)\",\"ref[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.firstKnownVersion", "7.18.7.20434"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.homepage", "http://home.tb.ask.com/index.jhtml?ptb=C403876B-820D-4EEC-BD3A-0A0[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.hp.enabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.hp.guardType", "HPR"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.initialized", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.installKeysSource", "Cookies"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.installType", "XPI"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.installation.contextKey", ""); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.installation.dlpCountryCode", "DZ"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.installation.installDate", "2015071310"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.installation.partnerId", "^BQP^xdm173^YYA^dz"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.installation.partnerSubId", "COqUg9_42MYCFYYfwwodgdsOvA"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.installation.pixelUrl", "http://free.catsandcatapults.com/install_pixels.jhtml[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.installation.success", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.installation.toolbarId", "C403876B-820D-4EEC-BD3A-0A0A1B995EE7"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.isCompliantUninstallImplementation", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.lastActivePing", "1440848267035"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.lastKnownVersion", "7.18.7.20434"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.options.defaultSearch", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.options.homePageEnabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.options.keywordEnabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.options.tabEnabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.partnerPixelFired", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.searchHistory", "Manel Twahri"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.successUrl", "http://free.catsandcatapults.com/installComplete.jhtml"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.toolbar.ownSearch", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.toolbar.versionChanged", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._btMembers_.toolbarCollapsed", false); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.BUTTON_STRUCTURE", "[{\"b\":224540899,\"c\":\"mindspark.magnify\",\"p\":\"L.0\[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.browser.search.defaultenginename.prev", "Ask Web Search"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.browser.search.defaultenginename.savedPrev", "true"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.browser.search.defaultenginename.tb", "Ask Web Search"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.browser.search.selectedEngine.prev", "Ask Web Search"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.browser.search.selectedEngine.savedPrev", "true"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.browser.search.selectedEngine.tb", "Ask Web Search"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.browser.startup.homepage.savedPrev", "true"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.browser.startup.homepage.tb", "http://home.tb.ask.com/index.jhtml?ptb=93B1FB53[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.browser.startup.page.savedPrev", 1); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.browser.startup.page.tb", 1); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.browser.version.last", "40.0"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.competitorDNS", "{\"comment\":\"refresh every 1 week (7*24*60*60*1000)\",\"ref[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.firstKnownVersion", "6.85.5.64984"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.homepage", "http://home.tb.ask.com/index.jhtml?ptb=93B1FB53-2085-4582-A035-B16[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.hp.enabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.hp.guardType", "HPR"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.hp.user.defined", false); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.initialized", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.installKeysSource", "LocalStorage"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.installType", "XPI"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.installation.contextKey", ""); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.installation.dlpCountryCode", "DZ"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.installation.installDate", "2014082907"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.installation.partnerId", "^Z7^xdm353^YYA^dz"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.installation.partnerSubId", "124514_psg_gcAFR"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.installation.pixelUrl", "http://gamingwonderland.dl.tb.ask.com/install_pixels.[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.installation.success", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.installation.toolbarId", "93B1FB53-2085-4582-A035-B16ECF9E3514"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.isCompliantUninstallImplementation", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.lastActivePing", "1440848267008"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.lastKnownVersion", "7.18.7.7634"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.options.defaultSearch", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.options.homePageEnabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.options.keywordEnabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.options.tabEnabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.partnerPixelFired", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.searchHistory", "E,D) 4GF'2 DD.J'7)"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.successUrl", "http://www.playsides.com/shooting-games/palisade-guardian-3.html[...] =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.toolbar.versionChanged", false); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.toolbarCollapsed", false); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark._gtMembers_.weather.location", "10001"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark.hp.enabled", true); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "64ffxtbr@TelevisionFanatic.com"); =>PUP.Optional.Bandoo
O69 - SBI: prefs.js [fouziamara - 2lx6rfrf.default] user_pref("extensions.toolbar.mindspark.lastInstalled", "coolpopulargames@mindspark.com"); =>PUP.Optional.Bandoo
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/

---\\ Enumère les services démarrés par Svchost (34) - 2s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [161792] ©
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [126976] ©
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [126976] ©
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [250368] ©
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [1212928] ©
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [733696] ©
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [822784] ©
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [24064] ©
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [89600] ©
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [115712] ©
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [93696] ©
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1015808] ©
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [185856] ©
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\System32\mmcss.dll [74752] ©
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [108032] ©
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [190464] ©
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [296448] ©
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [64512] ©
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\KMSVC.DLL [75264] ©
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [41984] ©
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\Windows\System32\wlidsvc.dll [1245184] ©
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service d’infrastructure de localisation Wi.) -- C:\Windows\System32\GeofenceMonitorService.dll [367104] ©
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [297984] ©
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\Windows\System32\DeviceSetupManager.dll [167424] ©
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\Windows\System32\NcaSvc.dll [142848] ©
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [95232] ©
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\Windows\System32\rasmans.dll [461824] ©
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [183296] ©
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [58368] ©
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [390144] ©
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [254464] ©
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [3065856] ©
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [734208] ©
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [576512] ©

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (8) - 15s

SS - Demand [2015/08/11 21:23:17] [ 269000] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe ©
SR - Demand [2010/01/12 08:57:38] [ 227896] Com4QLBEx (Com4QLBEx) . (.Hewlett-Packard Development Company, L.P..) - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe ©
SR - Demand [2009/04/30 15:58:44] [ 229944] hpqwmiex (hpqwmiex) . (.Hewlett-Packard Development Company, L.P..) - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe ©
SS - Demand [2015/08/28 17:58:18] [ 149160] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe ©
SR - Auto [2012/12/07 10:47:22] [ 645992] NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\System32\nvvsvc.exe ©
SR - Auto [2012/12/18 03:22:54] [ 1258856] NVIDIA Update Service Daemon (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe ©
SS - Auto [2015/07/09 13:14:04] [ 327296] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe ©

---\\ Recherche de clés de registre Tracing (2) - 2s
HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32 =>PUP.Optional.MyPCBackup
HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS =>PUP.Optional.MyPCBackup

---\\ Scan Additionnel (9) - 0s
C:\Users\fouziamara\AppData\Roaming\Mozilla\Firefox\Profiles\2lx6rfrf.default\extensions\8hffxtbr@download.allin1convert.com =>PUP.Optional.MindSpark
C:\Windows\System32\Tasks\LaunchSignup =>PUP.Optional.MyPCBackup
C:\Windows\System32\Tasks\PCRegistryShield_Popup =>PUP.Optional.PCRegistryShield
C:\Windows\System32\Tasks\PCRegistryShield_Start =>PUP.Optional.PCRegistryShield
HKCU\SOFTWARE\InstallCore =>Adware.InstallCore
C:\Program Files\PC Registry Shield =>PUP.Optional.PCRegistryShield
C:\Windows\System32\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw.sys =>PUP.Optional.LinkiDoo
HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32 =>PUP.Optional.MyPCBackup
HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS =>PUP.Optional.MyPCBackup

---\\ Récapitulatif des éléments trouvées sur votre station (7) - 0s
http://www.nicolascoolman.fr/toolbar-ask/ =>Toolbar.Ask
http://www.nicolascoolman.fr/pup-mindspark/ =>PUP.Optional.MindSpark
http://www.nicolascoolman.fr/pup-mypcbackup/ =>PUP.Optional.MyPCBackup
http://www.nicolascoolman.fr/rogue-pcregistryshield/ =>PUP.Optional.PCRegistryShield
http://www.nicolascoolman.fr/adware-installcore/ =>Adware.InstallCore
http://www.nicolascoolman.fr/pup-linkidoo/ =>PUP.Optional.LinkiDoo
http://www.nicolascoolman.fr/adware-bandoo/ =>PUP.Optional.Bandoo

~ End of the scan, 10358 items in 298 seconds (657)(0)()

Publicité


Signaler le contenu de ce document

Publicité