cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.8.1.107 Par Nicolas Coolman (2015/08/1)
~ Démarré par kal (Administrator) (2015/08/01 19:49:27)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\kal\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\kal\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
~ Windows 7 Ultimate, 32-bit Service Pack 1 (Build 7601)

---\\ Navigateurs Internet (2) - 0s
MFIE: Mozilla Firefox 39.0 (x86 fr) v39.0
MSIE: Internet Explorer v11.0.9600.17843

---\\ Logiciels de protection (1) - 2s
Avast Free Antivirus v10.3.2225

---\\ Logiciels d'optimisation (1) - 3s
CCleaner v4.00

---\\ Surveillance de Logiciels (2) - 3s
Adobe Flash Player 18 NPAPI
Adobe Reader XI

---\\ Informations sur le système (6) - 0s
~ Operating System: x86 Family 15 Model 4 Stepping 9, GenuineIntel
~ Operating System: 32-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 2096.44 MB (41% free)
~ System Restore: Activé (Enable)
~ System drive C: has 4 GB free of 66 GB

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: KAL-PC
~ User Name: kal
~ Logged in as Administrator

---\\ Enumération des unités disques (3) - 1s
~ Drive C: has 4 GB free of 66 GB (System)
~ Drive D: has 25 GB free of 127 GB
~ Drive F: has 119 GB free of 152 GB

---\\ Etat du Centre de Sécurité Windows (11) - 1s
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Recherche particulière de fichiers génériques (24) - 0s
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\Windows\Explorer.exe [2616320]
[MD5.51138BEEA3E2C21EC44D0932C71762A8] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\Windows\System32\rundll32.exe [44544]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\Windows\System32\Wininit.exe [96256]
[MD5.E4EB138060BAE0DBAB1A3B71A3141FE7] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\Windows\System32\wininet.dll [1950720]
[MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - Application d’ouverture de session Windows.) () -- C:\Windows\System32\Winlogon.exe [304128]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) () -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.129F80D7868E30DF3E3DE33A1D3132B4] - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) () -- C:\Windows\System32\fr-FR\user32.dll.mui [20480]
[MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\Windows\System32\drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\Windows\System32\drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\Windows\System32\drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\Windows\System32\drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\Windows\System32\drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\Windows\System32\drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\Windows\System32\drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\Windows\System32\drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\Windows\System32\drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\Windows\System32\drivers\netBT.sys [187904]
[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\Windows\System32\drivers\ntfs.sys [1212352]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\Windows\System32\drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\Windows\System32\drivers\Rasl2tp.sys [78848]
[MD5.B973FCFC50DC1434E1970A146F7E3885] - (.Microsoft Corporation - Microsoft RDP Device redirector.) () -- C:\Windows\System32\drivers\rdpdr.sys [133632]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) () -- C:\Windows\System32\drivers\smb.sys [71168]
[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\Windows\System32\drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\Windows\System32\drivers\volsnap.sys [245632]

---\\ Processus lancés (8) - 2s
[MD5.4956380A54B1C9E6BFDF3D80DACB9698] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600] [PID.1584]
[MD5.B70BCC55743C5A5BD7C7C6D6A02BB6F9] - (.Realtek Semiconductor Corp. - Realtek Sound Manager.) -- C:\Windows\SOUNDMAN.EXE [604704] [PID.3008]
[MD5.D6FE9E0F705794A86F87A01B222290EF] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [6109776] [PID.3344]
[MD5.EB7711A785E5B12F153C715CC91BC76F] - (.Copyright © 2010. All rights reserved. - CDA Server.) -- C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [350072] [PID.3352]
[MD5.A4C778C47836C9786C6A648C828DFF2B] - (.Avast Software - AvastVirtualBox Interface.) -- C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3218624] [PID.2356]
[MD5.734414E94C52909DDCDEB9EEDC3C2BFC] - (.Client Connect LTD - Search Protect.) -- C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe [3238672] [PID.3168] =>PUP.Optional.SearchProtect
[MD5.2D602EE732D28309CF0A950DCF3E95C9] - (.Client Connect LTD - Search Protect.) -- C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe [4275472] [PID.5852] =>PUP.Optional.SearchProtect
[MD5.4E3FA451B0441DBECF23CC72D2A2084F] - (.Client Connect LTD - Search Protect.) -- C:\Program Files\SearchProtect\UI\bin\cltmngui.exe [3285264] [PID.4280] =>PUP.Optional.SearchProtect

---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) (22) - 3s
M0 - MFSP: prefs.js [kal - hiqhotpw.default] http://www.trovi.com/?gd=&ctid=CT3333004&octid=EB_ORIGINAL_CTID&ISID=4924A5E4-B293-42CF-970A-7A1AF4DFA551&SearchSource=55&CUI=&UM=8&UP=SPE6BA5069-717D-4457-A3A3-C317D5B8C9CD&D=080115&SSPV= =>PUP.Optional.Trovigo
M1 - SPR:Search Page Redirection - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
M1 - SPR:Search Page Redirection - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
M1 - SPR:Search Page Redirection - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
P2 - EXT: (.BitComet - BitCometAgent v1.30 for Firefox.) -- C:\Program Files\Mozilla Firefox\Plugins\npBitCometAgent.dll
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.FRA
P2 - EXT FILE: (...) -- C:\Users\kal\AppData\Roaming\Mozilla\Firefox\Profiles\hiqhotpw.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
P2 - EXT FILE: (...) -- C:\Users\kal\AppData\Roaming\Mozilla\Firefox\Profiles\hiqhotpw.default\searchplugins\Web Search.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-france.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay-france.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo-france.xml
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
P2 - EXT: (. - SialeSMagnet.) -- C:\Users\kal\AppData\Roaming\Mozilla\Firefox\Profiles\hiqhotpw.default\extensions\JBp@i.net
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\NPSWF32_18_0_0_209.dll
P2 - FPN: [HKLM] [@playstation.com/PsndlCheck,version=1.00] - (.Sony Computer Entertainment Inc..) -- C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll
P2 - FPN: [HKLM] [@www.duuqu.com/omaha/tools//Duuqu Update;version=3] - (.Duuqu Group.) -- C:\Program Files\Duuqu\Update\1.3.37.0\npDuuquUpdate3.dll =>PUP.Optional.Duuqu
P2 - FPN: [HKLM] [@www.duuqu.com/omaha/tools//Duuqu Update;version=9] - (.Duuqu Group.) -- C:\Program Files\Duuqu\Update\1.3.37.0\npDuuquUpdate3.dll =>PUP.Optional.Duuqu

---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) (13) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.trovi.com/ =>PUP.Optional.Trovigo
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/ =>PUP.Optional.SmartBar
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/ =>PUP.Optional.SmartBar
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/ =>PUP.Optional.SmartBar
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/ =>PUP.Optional.SmartBar
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://feed.snapdo.com/ =>PUP.Optional.SmartBar
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer

---\\ Internet Explorer, Proxy Management (R5) (3) - 1s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.)
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.)
F2 - REG:system.ini: VMApplet=C:\Windows\system32\SystemPropertiesPerformance.exe (.Microsoft Corporation.)

---\\ Hosts file redirection (O1) (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (34)

---\\ Browser Helper Object de navigateur (BHO) (O2) (1) - 0s
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

---\\ Internet Explorer Toolbars (O3) (1) - 0s
O3 - Toolbar: Smartbar - [HKLM]{ae07101b-46d4-4a98-af68-0333ea26e113} . (...) -- (.not file.) =>PUP.Optional.QuickShare

---\\ Applications lancées au démarrage du sytème (O4) (8) - 1s
O4 - HKLM\..\Run: [SoundMan] . (.Realtek Semiconductor Corp. - Realtek Sound Manager.) -- C:\Windows\SOUNDMAN.EXE
O4 - HKLM\..\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
O4 - HKLM\..\Run: [CDAServer] . (.Copyright © 2010. All rights reserved. - CDA Server.) -- C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe

---\\ Modification Domaine/Adresses DNS (O17) (9) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) (1) - 0s
O20 - AppInit_DLLs: . (...) - C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll (.not file.) =>PUP.Optional.SearchProtect

---\\ Liste des services NT non Microsoft et non désactivés (O23) (6) - 1s
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Avast Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Search Protect Service (CltMngSvc) . (.Client Connect LTD - Search Protect.) - C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe =>PUP.Optional.SearchProtect
O23 - Service: Duuqu Update Service (dqupdate) (dqupdate) . (...) - C:\Program Files\Duuqu\Update\DuuquUpdate.exe (.not file.) =>PUP.Optional.Duuqu
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 258.9.) - C:\Windows\System32\nvvsvc.exe

---\\ Enumère les données de BootExecute (BEX) (O34) (1) - 0s
O34 - HKLM BootExecute: (aswBoot.exe /M:d029a1991 /dir:"C:\Program Files\AVAST Software\Avast") (.AVAST Software - avast! start-up scanner.) -- aswBoot.exe

---\\ Tâches planifiées en automatique (O39) (25) - 7s
[MD5.E3FB05F33E1404AD606B1E1FE7C323C3] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [998104]
[MD5.9B3355B29942AF67F014EA90CE1EA960] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [268976]
[MD5.76F586CEF7018BD376CBBD74AEAC93F5] [APT] [avast! Emergency Update] (.AVAST Software.) -- C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [1373872]
[MD5.00000000000000000000000000000000] [APT] [bvxvbvef] (...) -- C:\Users\kal\AppData\Local\bvxvbvef\bvxvbvef.exe (.not file.) [0]
[MD5.A9DA5B43CF597F83B1EB441968E24891] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [3497240]
[MD5.00000000000000000000000000000000] [APT] [DuuquUpdateTaskMachineCore] (...) -- C:\Program Files\Duuqu\Update\DuuquUpdate.exe (.not file.) [0] =>PUP.Optional.Duuqu
[MD5.00000000000000000000000000000000] [APT] [DuuquUpdateTaskMachineUA] (...) -- C:\Program Files\Duuqu\Update\DuuquUpdate.exe (.not file.) [0] =>PUP.Optional.Duuqu
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [116648]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [116648]
O39 - APT: Adobe Flash Player Updater - (...) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT: DuuquUpdateTaskMachineCore - (...) -- C:\Windows\Tasks\DuuquUpdateTaskMachineCore.job [866] =>PUP.Optional.Duuqu
O39 - APT: DuuquUpdateTaskMachineUA - (...) -- C:\Windows\Tasks\DuuquUpdateTaskMachineUA.job [870] =>PUP.Optional.Duuqu
O39 - APT: GoogleUpdateTaskMachineCore - (...) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1054]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1058]
O39 - APT: Adobe Acrobat Update Task - (...) -- C:\Windows\System32\Tasks\Adobe Acrobat Update Task [3874]
O39 - APT: Adobe Flash Player Updater - (...) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [3940]
O39 - APT: avast! Emergency Update - (...) -- C:\Windows\System32\Tasks\avast! Emergency Update [4182]
O39 - APT: bvxvbvef - (...) -- C:\Windows\System32\Tasks\bvxvbvef [3438]
O39 - APT: CCleanerSkipUAC - (...) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [2768]
O39 - APT: DuuquUpdateTaskMachineCore - (...) -- C:\Windows\System32\Tasks\DuuquUpdateTaskMachineCore [3614] =>PUP.Optional.Duuqu
O39 - APT: DuuquUpdateTaskMachineUA - (...) -- C:\Windows\System32\Tasks\DuuquUpdateTaskMachineUA [3866] =>PUP.Optional.Duuqu
O39 - APT: GoogleUpdateTaskMachineCore - (...) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [3802]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [4054]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{E3D33CA0-5CF3-4C29-A210-69B4A515CFF2} [3138]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{F08A9F06-F83F-4573-9700-0B7F9D5382F5} [3144]

---\\ Logiciels installés (O42) (51) - 18s
O42 - Logiciel: Adobe Flash Player 18 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 18 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI
O42 - Logiciel: Audacity 2.0.3 - (.Audacity Team.) [HKLM] -- Audacity_is1
O42 - Logiciel: Avast Free Antivirus - (.AVAST Software.) [HKLM] -- avast
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: CDex - Open Source Digital Audio CD Extractor - (.Georgy Berdyshev.) [HKLM] -- CDex
O42 - Logiciel: Samsung Easy Wireless Setup - (.Samsung Electronics Co., Ltd..) [HKLM] -- Easy Wireless Setup
O42 - Logiciel: Farming Simulator 2013 - (.GIANTS Software.) [HKLM] -- FarmingSimulator2013INT_is1
O42 - Logiciel: FormatFactory 3.3.4.0 - (.Format Factory.) [HKLM] -- FormatFactory
O42 - Logiciel: LAME v3.99.3 (for Windows) - (...) [HKLM] -- LAME_is1
O42 - Logiciel: Mozilla Firefox 39.0 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 39.0 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: NVIDIA Display Control Panel - (.NVIDIA Corporation.) [HKLM] -- NVIDIA Display Control Panel
O42 - Logiciel: NVIDIA Drivers - (.NVIDIA Corporation.) [HKLM] -- NVIDIA Drivers
O42 - Logiciel: PowerISO - (.Power Software Ltd.) [HKLM] -- PowerISO
O42 - Logiciel: Samsung Easy Document Creator - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung Easy Document Creator
O42 - Logiciel: Samsung Easy Printer Manager - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung Easy Printer Manager
O42 - Logiciel: Samsung M2070 Series - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung M2070 Series
O42 - Logiciel: Samsung Printer Live Update - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung Printer Live Update
O42 - Logiciel: Samsung Scan Process Machine - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung Scan Process Machine
O42 - Logiciel: Search Protect - (.Client Connect LTD.) [HKLM] -- SearchProtect =>SearchProtect
O42 - Logiciel: TeraCopy 2.27 - (.Code Sector.) [HKLM] -- TeraCopy_is1
O42 - Logiciel: Sony Mobile Update Engine - (.Sony Mobile Communications Inc..) [HKLM] -- Update Engine
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM] -- VLC media player
O42 - Logiciel: World of Warcraft - (.Blizzard Entertainment.) [HKLM] -- World of Warcraft
O42 - Logiciel: Common Desktop Agent - (.OEM.) [HKLM] -- {031A0E14-0413-4C97-9772-2639B782F46F}
O42 - Logiciel: PlayStation(R)Store - (.Sony Computer Entertainment Inc..) [HKLM] -- {0E532C84-4275-41B3-9D81-D4A1A20D8EE7}
O42 - Logiciel: SystemRaise - (.Software Publisher.) [HKLM] -- {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{438e213f} =>PUP.Optional.Graftor
O42 - Logiciel: Java 7 Update 80 - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F03217080FF}
O42 - Logiciel: Java 8 Update 51 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83218051F0}
O42 - Logiciel: SalESMagnet - (."".) [HKLM] -- {3119AFD3-545C-0955-573A-494F62E61990} =>PUP.Optional.Multiplug
O42 - Logiciel: Utilitaire de configuration sans fil TP-LINK - (.TP-LINK.) [HKLM] -- {319D91C6-3D44-436C-9F79-36C0D22372DC}
O42 - Logiciel: PVSonyDll - (.NVIDIA Corporation.) [HKLM] -- {3D3E663D-4E7E-4577-A560-7ECDDD45548A}
O42 - Logiciel: SimCity 4 Deluxe - (...) [HKLM] -- {3F0D0ABE-CDAF-431A-00BC-CBBE018EA74E}
O42 - Logiciel: Google Earth Plug-in - (.Google.) [HKLM] -- {4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}
O42 - Logiciel: neroxml - (.Nero AG.) [HKLM] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
O42 - Logiciel: LG NASDetector - (.LG Electronics Inc..) [HKLM] -- {81388290-5DFA-493E-83D6-244B652DE5AA}
O42 - Logiciel: TP-LINK 300Mbps Wireless USB Adapter Pilote - (.TP-LINK.) [HKLM] -- {852E893E-E4FD-45BB-8B17-72ADDF686974}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: LG NAS Installation Wizard - (.LG Electronics Inc..) [HKLM] -- {8F1D1ADF-E009-4654-AD7A-C82D3D4606B3}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-0804-1033-1959-001824147215}
O42 - Logiciel: Adobe Reader XI (11.0.12) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AB0000000001}
O42 - Logiciel: Distortion Control Data - (.Nikon.) [HKLM] -- {B08B4896-886C-4644-8664-BBA4CE99D318}
O42 - Logiciel: PlayStation(R)Network Downloader - (.Sony Computer Entertainment Inc..) [HKLM] -- {B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}
O42 - Logiciel: SNS Upload for Easy Document Creator - (.Samsung Electronics Co.,Ltd.) [HKLM] -- {B6B5F07C-88D5-49D3-A1A7-A6D4BC37DCCC}
O42 - Logiciel: Nero 7 Essentials - (.Nero AG.) [HKLM] -- {C3CF41F1-0373-4DD7-BE99-F33B00E51036}
O42 - Logiciel: Sony PC Companion 2.10.251 - (.Sony.) [HKLM] -- {F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: Realtek AC'97 Audio - (...) [HKLM] -- {FB08F381-6533-4108-B7DD-039E11FBC27E}

---\\ HKCU & HKLM Software Keys (116) - 18s
HKLM\SOFTWARE\a1bf8dcb-9769-e288-a1ca-7b7484e7c251 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Adobe
HKLM\SOFTWARE\Ahead
HKLM\SOFTWARE\ATI Technologies
HKLM\SOFTWARE\Audible
HKLM\SOFTWARE\AVAST Software
HKLM\SOFTWARE\AviSynth
HKLM\SOFTWARE\Blizzard Entertainment
HKLM\SOFTWARE\Boxore =>PUP.Optional.Boxore
HKLM\SOFTWARE\C07ft5Y
HKLM\SOFTWARE\CDDB
HKLM\SOFTWARE\Code Sector
HKLM\SOFTWARE\Common Desktop Agent
HKLM\SOFTWARE\D-Link
HKLM\SOFTWARE\Duuqu =>PUP.Optional.FrameFox
HKLM\SOFTWARE\Electronic Arts
HKLM\SOFTWARE\GNU
HKLM\SOFTWARE\Google
HKLM\SOFTWARE\HaaliMkx
HKLM\SOFTWARE\InstallShield
HKLM\SOFTWARE\Intel
HKLM\SOFTWARE\JavaSoft
HKLM\SOFTWARE\JreMetrics
HKLM\SOFTWARE\Khronos
HKLM\SOFTWARE\Lame For Audacity
HKLM\SOFTWARE\LG Electronics Inc.
HKLM\SOFTWARE\Macromedia
HKLM\SOFTWARE\Maxis
HKLM\SOFTWARE\Maxtor
HKLM\SOFTWARE\McAfee.com
HKLM\SOFTWARE\Mozilla
HKLM\SOFTWARE\mozilla.org
HKLM\SOFTWARE\MozillaPlugins
HKLM\SOFTWARE\Nero
HKLM\SOFTWARE\Nikon
HKLM\SOFTWARE\NVIDIA Corporation
HKLM\SOFTWARE\ODBC
HKLM\SOFTWARE\ORBTR =>PUP.Optional.Conduit
HKLM\SOFTWARE\Piriform
HKLM\SOFTWARE\PowerISO
HKLM\SOFTWARE\Realtek
HKLM\SOFTWARE\RegisteredApplications
HKLM\SOFTWARE\RtWlan
HKLM\SOFTWARE\Samsung
HKLM\SOFTWARE\SCS Software
HKLM\SOFTWARE\SearchProtect =>PUP.Optional.SearchProtect
HKLM\SOFTWARE\Sonic
HKLM\SOFTWARE\Sony
HKLM\SOFTWARE\Sony Corporation
HKLM\SOFTWARE\Sony Mobile
HKLM\SOFTWARE\SPPDCOM =>PUP.Optional.PCSpeedUp
HKLM\SOFTWARE\SRS Labs
HKLM\SOFTWARE\SSPrint
HKLM\SOFTWARE\SSScan
HKLM\SOFTWARE\TP-LINK
HKLM\SOFTWARE\VBMZ
HKLM\SOFTWARE\VideoLAN
HKLM\SOFTWARE\Volatile
HKLM\SOFTWARE\Windows
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\Ahead
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\Audacity
HKCU\SOFTWARE\Avance
HKCU\SOFTWARE\AVAST Software
HKCU\SOFTWARE\BitComet
HKCU\SOFTWARE\BitTorrent
HKCU\SOFTWARE\Blizzard Entertainment
HKCU\SOFTWARE\Bugsplat
HKCU\SOFTWARE\CDAS2PC2
HKCU\SOFTWARE\CDDB
HKCU\SOFTWARE\Code Sector
HKCU\SOFTWARE\Common Desktop Agent
HKCU\SOFTWARE\Comnso
HKCU\SOFTWARE\Duuqu =>PUP.Optional.FrameFox
HKCU\SOFTWARE\EA Sports
HKCU\SOFTWARE\FreeTime
HKCU\SOFTWARE\Gabest
HKCU\SOFTWARE\GNU
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\Haali
HKCU\SOFTWARE\JavaSoft
HKCU\SOFTWARE\LexmarkPhoto
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\MarineCat
HKCU\SOFTWARE\MCAFEE
HKCU\SOFTWARE\Modern UI Test
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\NVIDIA Corporation
HKCU\SOFTWARE\ODBC
HKCU\SOFTWARE\Piriform
HKCU\SOFTWARE\PowerISO
HKCU\SOFTWARE\ProductSetup =>PUP.Optional.InstallCore
HKCU\SOFTWARE\Realtek
HKCU\SOFTWARE\Samsung
HKCU\SOFTWARE\Smartbar =>PUP.Optional.SmartBar
HKCU\SOFTWARE\Softonic =>PUP.Optional.Softonic
HKCU\SOFTWARE\Sony
HKCU\SOFTWARE\Sony Ericsson
HKCU\SOFTWARE\SSPrint
HKCU\SOFTWARE\SSScan
HKCU\SOFTWARE\System Optimizer =>PUP.Optional.SystemOptimizer
HKCU\SOFTWARE\TeleCharger
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\Valve
HKCU\SOFTWARE\VB and VBA Program Settings
HKCU\SOFTWARE\Visualbee =>PUP.Optional.VisualBeeToolbar
HKCU\SOFTWARE\Winamp
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft

---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) (188) - 17s
O43 - CFD: 2014/10/16 18:14:00 - [] D -- C:\Program Files\Adobe
O43 - CFD: 2014/05/18 12:09:36 - [] D -- C:\Program Files\Audacity
O43 - CFD: 2011/12/27 17:36:24 - [] D -- C:\Program Files\AVAST Software
O43 - CFD: 2013/04/28 17:20:31 - [] D -- C:\Program Files\CCleaner
O43 - CFD: 2013/06/11 20:13:49 - [] D -- C:\Program Files\CDex
O43 - CFD: 2015/08/01 16:01:37 - [] D -- C:\Program Files\Common Files
O43 - CFD: 2011/12/25 21:33:51 - [] D -- C:\Program Files\DVD Maker
O43 - CFD: 2013/10/31 17:14:15 - [] D -- C:\Program Files\Farming Simulator 2013
O43 - CFD: 2011/12/23 23:22:57 - [0] SHD -- C:\Program Files\Fichiers communs
O43 - CFD: 2014/05/23 20:11:33 - [] D -- C:\Program Files\FreeTime
O43 - CFD: 2013/12/17 22:38:47 - [] D -- C:\Program Files\Google
O43 - CFD: 2015/04/19 18:25:55 - [] HD -- C:\Program Files\InstallShield Installation Information
O43 - CFD: 2015/07/03 20:23:10 - [] D -- C:\Program Files\Internet Explorer
O43 - CFD: 2015/08/01 16:00:10 - [] D -- C:\Program Files\Java
O43 - CFD: 2014/05/23 20:10:45 - [] D -- C:\Program Files\Lame For Audacity
O43 - CFD: 2013/12/08 18:36:04 - [] D -- C:\Program Files\LGNAS
O43 - CFD: 2013/12/08 18:55:03 - [] D -- C:\Program Files\LGNASInsW
O43 - CFD: 2013/03/17 15:02:18 - [] D -- C:\Program Files\Maxis
O43 - CFD: 2009/07/14 11:01:21 - [] D -- C:\Program Files\Microsoft Games
O43 - CFD: 2011/12/27 17:34:57 - [] D -- C:\Program Files\Microsoft Office
O43 - CFD: 2011/12/27 17:17:50 - [] D -- C:\Program Files\Microsoft Visual Studio
O43 - CFD: 2015/07/02 21:52:18 - [] D -- C:\Program Files\Microsoft Works
O43 - CFD: 2011/12/27 17:17:45 - [] D -- C:\Program Files\Microsoft.NET
O43 - CFD: 2015/08/01 15:51:58 - [] D -- C:\Program Files\Mozilla Firefox
O43 - CFD: 2015/07/22 09:44:46 - [] D -- C:\Program Files\Mozilla Firefox.bak
O43 - CFD: 2015/08/01 15:51:58 - [] D -- C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 2009/07/14 06:52:30 - [] D -- C:\Program Files\MSBuild
O43 - CFD: 2011/12/27 17:34:34 - [] D -- C:\Program Files\MSECache
O43 - CFD: 2011/12/31 15:54:07 - [0] D -- C:\Program Files\MSXML 4.0
O43 - CFD: 2011/12/31 13:17:00 - [] D -- C:\Program Files\Nero
O43 - CFD: 2015/08/01 19:15:56 - [] D -- C:\Program Files\New Tab Redirect
O43 - CFD: 2011/12/26 18:12:17 - [] D -- C:\Program Files\NVIDIA Corporation
O43 - CFD: 2015/08/01 19:46:01 - [] D -- C:\Program Files\ORBTR =>PUP.Optional.Conduit
O43 - CFD: 2013/10/31 16:58:40 - [] D -- C:\Program Files\PowerISO
O43 - CFD: 2009/07/14 06:52:30 - [] D -- C:\Program Files\Reference Assemblies
O43 - CFD: 2015/08/01 19:15:56 - [] D -- C:\Program Files\SalESMagnet =>PUP.Optional.Multiplug
O43 - CFD: 2015/08/01 19:15:56 - [] D -- C:\Program Files\SallesMMagnEt =>PUP.Optional.Multiplug
O43 - CFD: 2014/10/02 17:39:20 - [] D -- C:\Program Files\Samsung
O43 - CFD: 2014/10/02 17:40:49 - [] D -- C:\Program Files\SamsungPrinterLiveUpdate
O43 - CFD: 2014/10/02 17:40:27 - [] D -- C:\Program Files\SamsungPrinterLiveUpdateInstaller
O43 - CFD: 2015/08/01 19:46:19 - [] D -- C:\Program Files\SearchProtect =>PUP.Optional.SearchProtect
O43 - CFD: 2015/08/01 19:15:56 - [] D -- C:\Program Files\SialeSMagnet =>PUP.Optional.Multiplug
O43 - CFD: 2014/04/13 18:26:41 - [] D -- C:\Program Files\Sony
O43 - CFD: 2015/04/19 19:25:06 - [0] D -- C:\Program Files\Sony Ericsson
O43 - CFD: 2012/05/06 19:37:25 - [] D -- C:\Program Files\Sony Media Go Install
O43 - CFD: 2015/04/19 19:27:13 - [] D -- C:\Program Files\Sony Mobile
O43 - CFD: 2015/08/01 19:15:55 - [0] D -- C:\Program Files\SystemRaise
O43 - CFD: 2011/12/23 23:34:33 - [] D -- C:\Program Files\TeraCopy
O43 - CFD: 2014/11/29 20:37:35 - [] D -- C:\Program Files\TP-LINK
O43 - CFD: 2009/07/14 06:53:23 - [0] HD -- C:\Program Files\Uninstall Information
O43 - CFD: 2011/12/31 10:55:04 - [] D -- C:\Program Files\VideoLAN
O43 - CFD: 2015/07/03 20:23:14 - [] D -- C:\Program Files\Windows Defender
O43 - CFD: 2015/07/03 20:23:28 - [] D -- C:\Program Files\Windows Journal
O43 - CFD: 2011/12/25 21:33:51 - [] D -- C:\Program Files\Windows Mail
O43 - CFD: 2015/07/03 20:23:23 - [] D -- C:\Program Files\Windows Media Player
O43 - CFD: 2011/12/23 23:22:57 - [] D -- C:\Program Files\Windows NT
O43 - CFD: 2011/12/25 21:33:50 - [] D -- C:\Program Files\Windows Photo Viewer
O43 - CFD: 2011/12/25 21:33:50 - [] D -- C:\Program Files\Windows Portable Devices
O43 - CFD: 2011/12/25 21:33:51 - [] D -- C:\Program Files\Windows Sidebar
O43 - CFD: 2009/08/16 17:31:41 - [] D -- C:\Program Files\Windows Virtual PC
O43 - CFD: 2011/12/31 11:03:16 - [] D -- C:\Program Files\WinRAR
O43 - CFD: 2012/07/13 22:12:18 - [] HD -- C:\Program Files\Zero G Registry
O43 - CFD: 2012/04/01 21:12:12 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2012/12/22 17:47:17 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2012/07/14 09:28:17 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audiograbber
O43 - CFD: 2013/06/11 20:13:49 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDex
O43 - CFD: 2013/10/31 17:14:15 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Farming Simulator 2013
O43 - CFD: 2013/06/13 17:31:30 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 2013/12/17 22:38:54 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
O43 - CFD: 2015/08/01 16:00:45 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 2013/12/08 18:36:05 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LG NAS
O43 - CFD: 2013/10/17 15:23:33 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ma Cuisine Lapeyre
O43 - CFD: 2009/07/14 06:42:30 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2013/03/17 15:04:56 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxis
O43 - CFD: 2015/07/04 03:17:32 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O43 - CFD: 2011/12/31 13:25:22 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Essentials
O43 - CFD: 2013/12/08 18:46:54 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils LG
O43 - CFD: 2013/10/31 16:58:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO
O43 - CFD: 2014/10/02 18:10:04 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers
O43 - CFD: 2015/04/19 18:26:23 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
O43 - CFD: 2014/12/01 21:17:32 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2009/07/14 11:00:32 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 2011/12/23 23:34:33 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy
O43 - CFD: 2014/11/29 20:37:53 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK
O43 - CFD: 2013/04/25 10:28:29 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
O43 - CFD: 2011/12/23 23:19:27 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Virtual PC
O43 - CFD: 2014/09/25 23:10:40 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
O43 - CFD: 2015/07/27 09:21:23 - [] D -- C:\ProgramData\14440207410132670205
O43 - CFD: 2015/07/27 01:00:39 - [] D -- C:\ProgramData\3adfa5700005265
O43 - CFD: 2014/10/16 18:14:07 - [] D -- C:\ProgramData\Adobe
O43 - CFD: 2011/12/31 13:18:43 - [] D -- C:\ProgramData\Ahead
O43 - CFD: 2009/07/14 06:53:55 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 2012/04/02 15:22:16 - [] D -- C:\ProgramData\Avanquest Bluetooth SDK
O43 - CFD: 2013/11/21 10:07:48 - [] D -- C:\ProgramData\AVAST Software
O43 - CFD: 2014/09/25 20:18:51 - [] D -- C:\ProgramData\Blizzard
O43 - CFD: 2011/12/23 23:22:57 - [0] SHD -- C:\ProgramData\Bureau
O43 - CFD: 2009/07/14 06:53:55 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 2009/07/14 06:53:55 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 2011/12/23 23:22:57 - [0] SHD -- C:\ProgramData\Favoris
O43 - CFD: 2009/07/14 06:53:55 - [0] SHD -- C:\ProgramData\Favorites
O43 - CFD: 2013/04/13 12:16:03 - [] D -- C:\ProgramData\Google
O43 - CFD: 2013/12/08 18:55:05 - [] D -- C:\ProgramData\LGNASInsW
O43 - CFD: 2011/12/23 23:22:57 - [0] SHD -- C:\ProgramData\Menu Démarrer
O43 - CFD: 2015/07/03 20:23:46 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 2011/12/23 23:22:57 - [0] SHD -- C:\ProgramData\Modèles
O43 - CFD: 2012/04/30 15:59:16 - [] D -- C:\ProgramData\Mozilla
O43 - CFD: 2011/12/31 13:17:01 - [] D -- C:\ProgramData\Nero
O43 - CFD: 2011/12/26 18:14:53 - [] D -- C:\ProgramData\NVIDIA
O43 - CFD: 2011/12/26 18:11:36 - [] D -- C:\ProgramData\NVIDIA Corporation
O43 - CFD: 2015/08/01 16:02:49 - [] D -- C:\ProgramData\Oracle
O43 - CFD: 2014/07/06 15:52:34 - [] D -- C:\ProgramData\Package Cache
O43 - CFD: 2014/01/18 22:55:23 - [] D -- C:\ProgramData\PMS
O43 - CFD: 2014/07/06 15:16:06 - [] D -- C:\ProgramData\RetroExp
O43 - CFD: 2014/10/02 17:37:41 - [] D -- C:\ProgramData\Samsung
O43 - CFD: 2012/04/01 21:29:06 - [] D -- C:\ProgramData\Sony
O43 - CFD: 2012/05/06 19:37:01 - [] D -- C:\ProgramData\Sony Corporation
O43 - CFD: 2015/04/19 19:25:07 - [0] D -- C:\ProgramData\Sony Ericsson
O43 - CFD: 2015/04/19 19:27:13 - [] D -- C:\ProgramData\Sony Mobile
O43 - CFD: 2009/07/14 06:53:55 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 2012/04/01 21:33:40 - [] D -- C:\ProgramData\Sun
O43 - CFD: 2009/07/14 06:53:55 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 2014/11/29 20:37:05 - [] D -- C:\ProgramData\TP-LINK
O43 - CFD: 2014/10/16 18:14:04 - [] D -- C:\Program Files\Common Files\Adobe
O43 - CFD: 2011/12/31 13:18:17 - [] D -- C:\Program Files\Common Files\Ahead
O43 - CFD: 2014/09/25 15:26:01 - [] D -- C:\Program Files\Common Files\Blizzard Entertainment
O43 - CFD: 2014/10/02 17:37:44 - [] D -- C:\Program Files\Common Files\Common Desktop Agent
O43 - CFD: 2011/12/27 17:18:08 - [] D -- C:\Program Files\Common Files\DESIGNER
O43 - CFD: 2012/12/22 17:45:20 - [] D -- C:\Program Files\Common Files\InstallShield
O43 - CFD: 2015/08/01 16:01:37 - [] D -- C:\Program Files\Common Files\Java
O43 - CFD: 2015/07/04 03:17:31 - [] D -- C:\Program Files\Common Files\microsoft shared
O43 - CFD: 2014/10/02 17:38:56 - [] D -- C:\Program Files\Common Files\Scan Process Machine
O43 - CFD: 2009/07/14 04:37:05 - [] D -- C:\Program Files\Common Files\Services
O43 - CFD: 2012/05/06 19:38:39 - [] D -- C:\Program Files\Common Files\Sony Shared
O43 - CFD: 2009/07/14 04:37:05 - [] D -- C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 2011/12/25 21:33:50 - [] D -- C:\Program Files\Common Files\System
O43 - CFD: 2015/07/01 09:02:52 - [] D -- C:\Program Files\Common Files\Windows Live
O43 - CFD: 2015/05/12 08:45:34 - [] D -- C:\Users\kal\AppData\Roaming\Adobe
O43 - CFD: 2012/02/20 21:57:08 - [] D -- C:\Users\kal\AppData\Roaming\Ahead
O43 - CFD: 2015/07/01 08:54:31 - [] D -- C:\Users\kal\AppData\Roaming\Audacity
O43 - CFD: 2013/11/21 12:00:41 - [] D -- C:\Users\kal\AppData\Roaming\AVAST Software
O43 - CFD: 2015/08/01 15:45:03 - [] D -- C:\Users\kal\AppData\Roaming\BitComet
O43 - CFD: 2012/12/31 13:07:33 - [] D -- C:\Users\kal\AppData\Roaming\dvdcss
O43 - CFD: 2012/05/12 10:12:53 - [] D -- C:\Users\kal\AppData\Roaming\GetRightToGo
O43 - CFD: 2013/04/13 12:16:03 - [] D -- C:\Users\kal\AppData\Roaming\Google
O43 - CFD: 2011/12/23 23:23:22 - [] D -- C:\Users\kal\AppData\Roaming\Identities
O43 - CFD: 2012/01/01 11:33:49 - [] D -- C:\Users\kal\AppData\Roaming\Macromedia
O43 - CFD: 2009/07/14 11:00:32 - [0] D -- C:\Users\kal\AppData\Roaming\Media Center Programs
O43 - CFD: 2015/03/14 17:20:52 - [] SD -- C:\Users\kal\AppData\Roaming\Microsoft
O43 - CFD: 2011/12/23 23:29:55 - [] D -- C:\Users\kal\AppData\Roaming\Mozilla
O43 - CFD: 2014/10/02 18:03:00 - [] D -- C:\Users\kal\AppData\Roaming\Samsung
O43 - CFD: 2012/05/06 19:38:52 - [] D -- C:\Users\kal\AppData\Roaming\Sony
O43 - CFD: 2012/07/14 10:11:52 - [] D -- C:\Users\kal\AppData\Roaming\Sports Interactive
O43 - CFD: 2011/12/24 01:48:40 - [] D -- C:\Users\kal\AppData\Roaming\TeraCopy
O43 - CFD: 2014/11/29 20:39:11 - [] D -- C:\Users\kal\AppData\Roaming\TP-LINK
O43 - CFD: 2015/08/01 19:45:13 - [] D -- C:\Users\kal\AppData\Roaming\uTorrent
O43 - CFD: 2015/07/29 09:17:32 - [] D -- C:\Users\kal\AppData\Roaming\vlc
O43 - CFD: 2015/08/01 19:49:48 - [] D -- C:\Users\kal\AppData\Roaming\ZHP
O43 - CFD: 2015/03/19 13:02:17 - [] D -- C:\Users\kal\AppData\Local\Adobe
O43 - CFD: 2012/02/20 21:56:56 - [] D -- C:\Users\kal\AppData\Local\Ahead
O43 - CFD: 2011/12/23 23:23:10 - [0] SHD -- C:\Users\kal\AppData\Local\Application Data
O43 - CFD: 2014/07/06 15:16:08 - [] D -- C:\Users\kal\AppData\Local\ApplicationHistory
O43 - CFD: 2015/08/01 19:47:00 - [] D -- C:\Users\kal\AppData\Local\bvxvbvef
O43 - CFD: 2015/07/01 08:30:16 - [0] D -- C:\Users\kal\AppData\Local\Diagnostics
O43 - CFD: 2013/12/08 18:35:23 - [] D -- C:\Users\kal\AppData\Local\Downloaded Installations
O43 - CFD: 2013/07/27 14:35:18 - [] D -- C:\Users\kal\AppData\Local\Duuqu =>PUP.Optional.Duuqu
O43 - CFD: 2013/07/23 09:37:27 - [0] D -- C:\Users\kal\AppData\Local\ElevatedDiagnostics
O43 - CFD: 2013/07/27 14:31:16 - [] D -- C:\Users\kal\AppData\Local\emaze
O43 - CFD: 2013/09/10 10:20:44 - [] D -- C:\Users\kal\AppData\Local\Google
O43 - CFD: 2011/12/23 23:23:10 - [0] SHD -- C:\Users\kal\AppData\Local\Historique
O43 - CFD: 2012/06/28 16:58:06 - [] D -- C:\Users\kal\AppData\Local\Macromedia
O43 - CFD: 2015/07/03 20:32:10 - [] D -- C:\Users\kal\AppData\Local\Microsoft
O43 - CFD: 2014/06/13 19:26:52 - [] D -- C:\Users\kal\AppData\Local\Microsoft Games
O43 - CFD: 2013/09/21 11:10:31 - [] D -- C:\Users\kal\AppData\Local\Mozilla
O43 - CFD: 2013/05/05 10:24:32 - [] D -- C:\Users\kal\AppData\Local\Programs
O43 - CFD: 2015/08/01 19:46:59 - [] D -- C:\Users\kal\AppData\Local\SearchProtect =>PUP.Optional.SearchProtect
O43 - CFD: 2014/04/12 13:48:03 - [] D -- C:\Users\kal\AppData\Local\Sony
O43 - CFD: 2015/08/01 19:49:17 - [] D -- C:\Users\kal\AppData\Local\Temp
O43 - CFD: 2011/12/23 23:23:10 - [0] SHD -- C:\Users\kal\AppData\Local\Temporary Internet Files
O43 - CFD: 2014/10/18 20:09:57 - [] D -- C:\Users\kal\AppData\Local\VirtualStore
O43 - CFD: 2013/07/27 14:53:42 - [0] D -- C:\Users\kal\AppData\Local\VisualBeeExe =>PUP.Optional.VisualBeeToolbar
O43 - CFD: 2015/07/01 09:41:54 - [] D -- C:\Users\kal\AppData\Local\Windows Live
O43 - CFD: 2009/07/14 06:42:04 - [] RD -- C:\Users\kal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2015/07/03 20:33:48 - [] RD -- C:\Users\kal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2014/05/23 20:12:21 - [] D -- C:\Users\kal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
O43 - CFD: 2014/09/25 17:51:09 - [] D -- C:\Users\kal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 2013/10/17 15:23:33 - [0] D -- C:\Users\kal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ma Cuisine Lapeyre
O43 - CFD: 2009/07/14 06:37:42 - [] RD -- C:\Users\kal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/07/03 20:33:48 - [] RD -- C:\Users\kal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

---\\ Enumération des clés de registre StartupReg (SMSR) (O53) (4) - 0s
O53 - SMSR:HKLM\...\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} [Key] . (.Nero AG - Nero Home.) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
O53 - SMSR:HKLM\...\startupreg\NeroFilterCheck [Key] . (.Nero AG - NeroCheck.) -- C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O53 - SMSR:HKLM\...\startupreg\PWRISOVM.EXE [Key] . (.Power Software Ltd - PowerISO Virtual Drive Manager.) -- C:\Program Files\PowerISO\PWRISOVM.EXE
O53 - SMSR:HKLM\...\startupreg\SunJavaUpdateSched [Key] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe

---\\ Liste des pilotes du système (SDL) (O58) (78) - 12s
O58 - SDL:2009/07/14 03:26:15 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [422976]
O58 - SDL:2009/07/14 03:26:17 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [297552]
O58 - SDL:2009/07/14 03:26:15 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\drivers\adpu320.sys [146512]
O58 - SDL:2009/07/14 03:26:15 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [14400]
O58 - SDL:2011/03/11 07:38:37 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [80256]
O58 - SDL:2009/07/14 03:26:15 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [159312]
O58 - SDL:2011/03/11 07:38:37 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [22400]
O58 - SDL:2009/07/14 03:26:15 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [76368]
O58 - SDL:2009/07/14 03:26:15 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [86608]
O58 - SDL:2015/08/01 15:57:51 A . (.AVAST Software - avast! HWID.) -- C:\Windows\System32\drivers\aswHwid.sys [24016]
O58 - SDL:2015/08/01 15:57:51 A . (.AVAST Software - avast! File System Minifilter for Windows 2.) -- C:\Windows\System32\drivers\aswMonFlt.sys [76000]
O58 - SDL:2011/11/28 19:52:19 A . (.AVAST Software - avast! TDI RDR Driver.) -- C:\Windows\System32\drivers\aswRdr.sys [34392]
O58 - SDL:2015/08/01 15:57:51 A . (.AVAST Software - avast! WFP Redirect Driver.) -- C:\Windows\System32\drivers\aswRdr2.sys [81728]
O58 - SDL:2015/08/01 15:57:51 A . (.AVAST Software - avast! Revert.) -- C:\Windows\System32\drivers\aswRvrt.sys [49776]
O58 - SDL:2015/08/01 15:57:36 A . (.AVAST Software - avast! Virtualization Driver.) -- C:\Windows\System32\drivers\aswSnx.sys [788784]
O58 - SDL:2015/08/01 15:57:51 A . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\drivers\aswSP.sys [433264]
O58 - SDL:2015/08/01 15:57:51 A . (.AVAST Software - Stream Filter.) -- C:\Windows\System32\drivers\aswStm.sys [113592]
O58 - SDL:2015/08/01 15:57:51 A . (.AVAST Software - avast! VM Monitor.) -- C:\Windows\System32\drivers\aswVmm.sys [208664]
O58 - SDL:2009/07/14 00:02:49 A . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gi.) -- C:\Windows\System32\drivers\b57nd60x.sys [229888]
O58 - SDL:2009/07/14 00:53:28 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [13568]
O58 - SDL:2009/07/14 00:53:28 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [5248]
O58 - SDL:2009/07/14 02:57:25 A . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [272128]
O58 - SDL:2009/07/14 00:53:32 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [62336]
O58 - SDL:2009/07/14 00:53:33 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [12160]
O58 - SDL:2009/07/14 00:53:33 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [11904]
O58 - SDL:2009/07/14 00:02:48 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbdx.sys [430080]
O58 - SDL:2009/07/14 03:26:21 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [15952]
O58 - SDL:2009/07/14 03:20:28 A . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\drivers\djsvs.sys [70720]
O58 - SDL:2009/07/14 03:20:28 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [453712]
O58 - SDL:2009/07/14 00:02:48 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbdx.sys [3100160]
O58 - SDL:2009/07/14 00:02:53 A . (.VIA Technologies, Inc. - NDIS 6.0 miniport driver.) -- C:\Windows\System32\drivers\fetnd6.sys [44032]
O58 - SDL:2012/08/16 22:37:44 A . (.Sony Ericsson Mobile Communications - SEMC USB Flash Driver Filter.) -- C:\Windows\System32\drivers\ggflt.sys [12400]
O58 - SDL:2012/08/16 22:37:44 A . (.Sony Ericsson Mobile Communications - SEMC USB Flash Driver.) -- C:\Windows\System32\drivers\ggsemc.sys [25200]
O58 - SDL:2009/07/14 00:54:14 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [26624]
O58 - SDL:2009/07/14 03:20:28 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [67152]
O58 - SDL:2011/03/11 07:38:51 A . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\drivers\iaStorV.sys [332160]
O58 - SDL:2009/07/14 03:20:36 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [41040]
O58 - SDL:2009/07/14 03:20:36 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [95824]
O58 - SDL:2009/07/14 03:20:37 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [89168]
O58 - SDL:2009/07/14 03:20:36 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [54864]
O58 - SDL:2009/07/14 03:20:36 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [96848]
O58 - SDL:2009/07/14 03:20:36 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [30800]
O58 - SDL:2009/07/14 03:20:36 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [235584]
O58 - SDL:2003/03/13 07:23:28 A . (.Maxtor Corp. - 1394 Storage Front-Panel driver.) -- C:\Windows\System32\drivers\mxofwfp.sys [19712]
O58 - SDL:2009/07/14 03:20:44 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [44624]
O58 - SDL:2015/08/01 15:57:35 A . (.AVAST Software - avast! NG snapshot driver.) -- C:\Windows\System32\drivers\ngvss.sys [95112]
O58 - SDL:2010/07/10 06:37:00 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\Windows\System32\drivers\nvlddmkm.sys [11008040]
O58 - SDL:2011/03/11 07:39:00 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [117120]
O58 - SDL:2011/03/11 07:39:00 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [143744]
O58 - SDL:2009/07/14 03:19:04 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1383488]
O58 - SDL:2009/07/14 03:19:04 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [106064]
O58 - SDL:2009/06/18 20:45:02 A . (.Realtek Semiconductor Corp. - Realtek AC'97 Audio Driver (WDM).) -- C:\Windows\System32\drivers\RTKVAC.SYS [4172832]
O58 - SDL:2012/10/25 17:20:12 A . (.Realtek Semiconductor Corporation - Realtek RTL8192C USB NDIS Driver.) -- C:\Windows\System32\drivers\RTL8192cu.sys [801896]
O58 - SDL:2011/11/15 05:50:16 A . (.Power Software Ltd - PowerISO Virtual Drive.) -- C:\Windows\System32\drivers\scdemu.sys [112096]
O58 - SDL:2009/07/13 22:50:20 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [20480]
O58 - SDL:2009/07/14 03:19:04 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [40016]
O58 - SDL:2009/07/14 03:19:04 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [77888]
O58 - SDL:2013/04/10 11:38:16 A . (.Samsung Electronics - 32bit Port Contention Driver.) -- C:\Windows\System32\drivers\SSPORT.SYS [5120]
O58 - SDL:2006/07/24 16:05:00 A . (...) -- C:\Windows\System32\drivers\StarOpen.sys [5632]
O58 - SDL:2009/07/14 03:19:04 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [21072]
O58 - SDL:2009/07/14 03:19:10 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [16976]
O58 - SDL:2009/07/14 03:19:11 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [141904]
O58 - SDL:2009/07/13 23:40:41 A . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:2009/07/13 23:40:44 A . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:2009/07/13 23:40:40 A . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:2009/07/13 23:40:43 A . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:2009/07/13 23:40:43 A . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:2009/07/13 23:40:23 A . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:2009/07/13 23:40:31 A . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:2009/07/13 23:40:35 A . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:2009/07/13 23:40:39 A . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:2009/07/13 23:40:27 A . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:2009/07/13 23:40:11 A . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:2009/07/13 23:40:15 A . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:2009/07/13 23:40:17 A . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:2009/07/13 23:40:19 A . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:2009/07/13 23:40:13 A . (...) -- C:\Windows\System32\NTIO804.SYS [34672]
O58 - SDL:2012/10/25 17:20:12 A . (.Realtek Semiconductor Corporation - Realtek RTL8192C USB NDIS Driver.) -- C:\Windows\System32\rtl8192cu.sys [801896]

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) (3) - 7s
O61 - LFC: 2015/08/01 19:29:37 A . (.BitTorrent Inc..) -- C:\Users\kal\Logiciels\torrent_3-4-4-build-40760_fr_18245.exe [1996896]
O61 - LFC: 2015/08/01 19:29:37 A . (.BitTorrent Inc..) -- C:\Users\kal\AppData\Roaming\uTorrent\updates\3.4.3_40633.exe [1996896]
O61 - LFC: 2015/07/28 18:13:42 A . (..) -- C:\Users\kal\AppData\Local\Adobe\Acrobat\11.0\UserCache.bin [97013]

---\\ Associations Shell Spawning (O67) (1) - 0s
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe

---\\ Menu de démarrage Internet (SMI) (O68) (8) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe

---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) (16) - 29s
O69 - SBI: prefs.js [kal - hiqhotpw.default] user_pref("browser.newtab.url", "http://www.trovi.com/?gd=&ctid=CT3333004&octid=EB_ORIGINAL_CTID&ISID=4924A5E4-B293-42CF-970A-7A1A[...] =>PUP.Optional.Trovigo
O69 - SBI: prefs.js [kal - hiqhotpw.default] user_pref("browser.startup.homepage", "http://www.trovi.com/?gd=&ctid=CT3333004&octid=EB_ORIGINAL_CTID&ISID=4924A5E4-B293-42CF-970[...] =>PUP.Optional.Trovigo
O69 - SBI: prefs.js [kal - hiqhotpw.default] user_pref("extensions.crossrider.bic", "1402027058016c3bb22dcc1e01fa3119"); =>PUP.Optional.CrossRider
O69 - SBI: prefs.js [kal - hiqhotpw.default] user_pref("extensions.helperbar.DockingPositionDown", false); =>PUP.Optional.HelperBar
O69 - SBI: prefs.js [kal - hiqhotpw.default] user_pref("extensions.helperbar.SmartbarDisabled", false); =>PUP.Optional.HelperBar
O69 - SBI: prefs.js [kal - hiqhotpw.default] user_pref("extensions.helperbar.SmartbarStateMinimaized", false); =>PUP.Optional.HelperBar
O69 - SBI: prefs.js [kal - hiqhotpw.default] user_pref("extensions.helperbar.Visibility", true); =>PUP.Optional.HelperBar
O69 - SBI: prefs.js [kal - hiqhotpw.default] user_pref("extensions.helperbar.countryiso", "fr"); =>PUP.Optional.HelperBar
O69 - SBI: prefs.js [kal - hiqhotpw.default] user_pref("extensions.helperbar.downloadprovider", "snapdovbyb"); =>PUP.Optional.HelperBar
O69 - SBI: prefs.js [kal - hiqhotpw.default] user_pref("extensions.helperbar.installationid", "ea2de814-0ece-46d3-a1db-7ddb2cc42822"); =>PUP.Optional.HelperBar
O69 - SBI: prefs.js [kal - hiqhotpw.default] user_pref("extensions.helperbar.installdate", "27/07/2013"); =>PUP.Optional.HelperBar
O69 - SBI: prefs.js [kal - hiqhotpw.default] user_pref("extensions.helperbar.publisher", "snapdovbyb"); =>PUP.Optional.HelperBar
O69 - SBI: prefs.js [kal - hiqhotpw.default] user_pref("keyword.URL", "http://feed.snapdo.com/?publisher=SnapdoVBYB&dpid=SnapdoVBYB&co=FR&userid=ea2de814-0ece-46d3-a1db-7ddb2c[...] =>PUP.Optional.SmartBar
O69 - SBI: SearchScopes [HKCU] {006ee092-9658-4fd6-bd8e-a21a348e59f5} [DefaultScope] - (Web Search) - http://feed.snapdo.com/ =>PUP.Optional.SmartBar
O69 - SBI: SearchScopes [HKCU] {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} - (Trovi) - http://www.trovi.com/ =>PUP.Optional.Trovigo
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/

---\\ Enumère les services démarrés par Svchost (SSS) (O83) (34) - 2s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [679424]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\audiosrv.dll [475136]
O83 - Search Svchost Services: Irmon (Irmon) . (.Microsoft Corporation - Moniteur infrarouge.) -- C:\Windows\System32\irmon.dll [19968]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du se.) -- C:\Windows\System32\termsrv.dll [523776]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [2020864]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [499712]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [47104]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\System32\mmcss.dll [49664]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164864]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\KMSVC.DLL [71168]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [113664]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [102912]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800]
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [149504]

---\\ Liste des exceptions du parefeu (FirewallRules) (O87) (32) - 11s
O87 - FAEL: "{2C91BA3E-BF0E-401C-8C25-48A4D6A82C61}" [In-None-P6-TRUE] .(...) -- C:\Program Files\BitComet\BitComet.exe (.not file.)
O87 - FAEL: "{C90C16E9-28B2-4336-B57C-4A419EC8C711}" [In-None-P17-TRUE] .(...) -- C:\Program Files\BitComet\BitComet.exe (.not file.)
O87 - FAEL: "{1A0CD9F2-986E-4987-A2BD-85AD05F41D46}" [In-None-P6-TRUE] .(...) -- C:\Windows\System32\lxczcoms.exe (.not file.)
O87 - FAEL: "{D9F6637E-9A5A-4792-B37C-A8DCA4920EC8}" [In-None-P17-TRUE] .(...) -- C:\Windows\System32\lxczcoms.exe (.not file.)
O87 - FAEL: "{00154246-84B5-4C01-A059-73C298310958}" [In-None-P6-TRUE] .(...) -- C:\Windows\System32\spool\drivers\w32x86\3\lxczpswx.exe (.not file.)
O87 - FAEL: "{DC15DBB9-04DD-43A0-9570-51132BDA1D4B}" [In-None-P17-TRUE] .(...) -- C:\Windows\System32\spool\drivers\w32x86\3\lxczpswx.exe (.not file.)
O87 - FAEL: "TCP Query User{B88070F9-9E7C-49F6-A4CC-3FC2291565A2}C:\program files\bitcomet\bitcomet.exe" [In-None-P6-TRUE] .(...) -- C:\program files\bitcomet\bitcomet.exe (.not file.)
O87 - FAEL: "UDP Query User{FB31B3C2-8E79-497A-B846-61299F0FCE4F}C:\program files\bitcomet\bitcomet.exe" [In-None-P17-TRUE] .(...) -- C:\program files\bitcomet\bitcomet.exe (.not file.)
O87 - FAEL: "{E1BF9482-A058-4F31-A500-FF2DA1494942}" [In-None-P6-FALSE] .(...) -- C:\Program Files\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (.not file.)
O87 - FAEL: "{41DD5DF3-273F-4FB8-A75B-164BDA84D97C}" [In-None-P17-FALSE] .(...) -- C:\Program Files\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (.not file.)
O87 - FAEL: "{7F78584D-AD02-4707-A039-D07B1A171372}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Sony Ericsson\Update Engine\Sony Ericsson Update Engine.exe (.not file.)
O87 - FAEL: "{85DC20F7-596A-49DA-A3A9-22AFF6FECA50}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Sony Ericsson\Update Engine\Sony Ericsson Update Engine.exe (.not file.)
O87 - FAEL: "{296B11D9-28D9-4209-9C84-EB35A4D4A750}" [In-None-P6-FALSE] .(...) -- C:\Program Files\Sports Interactive\Football Manager 2010\fm.exe (.not file.)
O87 - FAEL: "{424255FE-8FC3-4DB4-954D-D484DE3A47FA}" [In-None-P17-FALSE] .(...) -- C:\Program Files\Sports Interactive\Football Manager 2010\fm.exe (.not file.)
O87 - FAEL: "{28EC9BD1-4E29-4A2B-9E14-89D2C1A9B945}" [In-None-P6-TRUE] .(.GIANTS Software GmbH - GIANTS Launcher.) -- C:\Program Files\Farming Simulator 2013\FarmingSimulator2013.exe
O87 - FAEL: "{1E284232-7998-46B8-B263-0A7D0DA87729}" [In-None-P17-TRUE] .(.GIANTS Software GmbH - GIANTS Launcher.) -- C:\Program Files\Farming Simulator 2013\FarmingSimulator2013.exe
O87 - FAEL: "{BD445E4D-0A6B-4952-BB49-91AB80153614}" [In-None-P6-TRUE] .(.GIANTS Software GmbH - GIANTS Engine.) -- C:\Program Files\Farming Simulator 2013\FarmingSimulator2013Game.exe
O87 - FAEL: "{803559D7-50BD-455C-B040-6DDA5175353F}" [In-None-P17-TRUE] .(.GIANTS Software GmbH - GIANTS Engine.) -- C:\Program Files\Farming Simulator 2013\FarmingSimulator2013Game.exe
O87 - FAEL: "TCP Query User{097505AE-C509-49F0-BD87-89D56C9F4B14}C:\program files\ps3 media server\jre\bin\javaw.exe" [In-None-P6-TRUE] .(...) -- C:\program files\ps3 media server\jre\bin\javaw.exe (.not file.)
O87 - FAEL: "UDP Query User{B54B4D33-6639-44C5-B44C-ABDEF163C2AB}C:\program files\ps3 media server\jre\bin\javaw.exe" [In-None-P17-TRUE] .(...) -- C:\program files\ps3 media server\jre\bin\javaw.exe (.not file.)
O87 - FAEL: "{A27BAFBB-D3EC-499F-9A95-04A4A63E6B27}" [In-None-P6-TRUE] .(.LG Electronics, Inc. - LGNAS Detector.) -- C:\Program Files\LGNAS\NASDetector\nasdetector.exe
O87 - FAEL: "{6ECE48F8-174E-4355-BD1F-5DB84D8707F1}" [In-None-P17-TRUE] .(.LG Electronics, Inc. - LGNAS Detector.) -- C:\Program Files\LGNAS\NASDetector\nasdetector.exe
O87 - FAEL: "{EA6C0D37-0207-40AB-B061-46022374139D}" [In-None-P6-TRUE] .(.BIT LEADER - LG NAS Installation Wizard.) -- C:\Program Files\LGNASInsW\LGNASINSW.exe
O87 - FAEL: "{0349C1BF-99B7-4ACF-B7BE-7439AC747764}" [In-None-P17-TRUE] .(.BIT LEADER - LG NAS Installation Wizard.) -- C:\Program Files\LGNASInsW\LGNASINSW.exe
O87 - FAEL: "{9697FFBF-F4E0-4539-9B8A-C7CEF961C393}" [In-None-P6-TRUE] .(...) -- C:\Windows\twain_32\Samsung\SLM2070\ScanCDLM\ScanCDLM.exe
O87 - FAEL: "{317A9DDC-FBF2-460F-B2C3-FE0D639B1CE4}" [In-None-P17-TRUE] .(...) -- C:\Windows\twain_32\Samsung\SLM2070\ScanCDLM\ScanCDLM.exe
O87 - FAEL: "{6A2D0F65-7773-4522-AE3E-2BFC3A7A44C7}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Samsung\Easy Document Creator\EDC.exe
O87 - FAEL: "{33E29748-5924-4C8B-91B1-9224F28A3842}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Samsung\Easy Document Creator\EDC.exe
O87 - FAEL: "{7DC4979C-8631-4D21-82D2-2FD1FEF7E6F1}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe
O87 - FAEL: "{BBA8B19D-7CEA-4F45-A9D1-DBF7CD6AC081}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe
O87 - FAEL: "{561E921A-BE2D-40A9-9745-3A53AC90DF73}" [In-None-P6-TRUE] .(.AVAST Software - avast! NG front end.) -- C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
O87 - FAEL: "{06196802-A5CE-4880-A667-444BCC1C4D04}" [In-None-P17-TRUE] .(.AVAST Software - avast! NG front end.) -- C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe

---\\ Scan Additionnel (O88) (32) - 0s
C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe =>PUP.Optional.SearchProtect
C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe =>PUP.Optional.SearchProtect
C:\Program Files\SearchProtect\UI\bin\cltmngui.exe =>PUP.Optional.SearchProtect
HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc =>PUP.Optional.SearchProtect
HKLM\SYSTEM\CurrentControlSet\Services\dqupdate =>PUP.Optional.Duuqu
C:\Windows\Tasks\DuuquUpdateTaskMachineCore.job =>PUP.Optional.Duuqu
C:\Windows\Tasks\DuuquUpdateTaskMachineUA.job =>PUP.Optional.Duuqu
C:\Windows\System32\Tasks\DuuquUpdateTaskMachineCore =>PUP.Optional.Duuqu
C:\Windows\System32\Tasks\DuuquUpdateTaskMachineUA =>PUP.Optional.Duuqu
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect =>SearchProtect
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{438e213f} =>PUP.Optional.Graftor
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3119AFD3-545C-0955-573A-494F62E61990} =>PUP.Optional.Multiplug
HKLM\SOFTWARE\Boxore =>PUP.Optional.Boxore
HKLM\SOFTWARE\Duuqu =>PUP.Optional.FrameFox
HKLM\SOFTWARE\ORBTR =>PUP.Optional.Conduit
HKLM\SOFTWARE\SearchProtect =>PUP.Optional.SearchProtect
HKLM\SOFTWARE\SPPDCOM =>PUP.Optional.PCSpeedUp
HKCU\SOFTWARE\Duuqu =>PUP.Optional.FrameFox
HKCU\SOFTWARE\ProductSetup =>PUP.Optional.InstallCore
HKCU\SOFTWARE\Smartbar =>PUP.Optional.SmartBar
HKCU\SOFTWARE\Softonic =>PUP.Optional.Softonic
HKCU\SOFTWARE\System Optimizer =>PUP.Optional.SystemOptimizer
HKCU\SOFTWARE\Visualbee =>PUP.Optional.VisualBeeToolbar
HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider =>PUP.Optional.CrossRider
C:\Program Files\ORBTR =>PUP.Optional.Conduit
C:\Program Files\SalESMagnet =>PUP.Optional.Multiplug
C:\Program Files\SallesMMagnEt =>PUP.Optional.Multiplug
C:\Program Files\SearchProtect =>PUP.Optional.SearchProtect
C:\Program Files\SialeSMagnet =>PUP.Optional.Multiplug
C:\Users\kal\AppData\Local\Duuqu =>PUP.Optional.Duuqu
C:\Users\kal\AppData\Local\SearchProtect =>PUP.Optional.SearchProtect
C:\Users\kal\AppData\Local\VisualBeeExe =>PUP.Optional.VisualBeeToolbar

---\\ Récapitulatif des éléments trouvées sur votre station (18) - 0s
http://www.nicolascoolman.fr/pup-searchprotect/ =>PUP.Optional.SearchProtect
http://www.nicolascoolman.fr/hijacker-trovigo/ =>PUP.Optional.Trovigo
http://www.nicolascoolman.fr/pup-duuqu/ =>PUP.Optional.Duuqu
http://www.nicolascoolman.fr/hijacker-smartbar/ =>PUP.Optional.SmartBar
http://www.nicolascoolman.fr/pup-quickshare/ =>PUP.Optional.QuickShare
http://www.nicolascoolman.fr/blog =>SearchProtect
http://www.nicolascoolman.fr/blog =>PUP.Optional.Graftor
http://www.nicolascoolman.fr/pup-mutiplug/ =>PUP.Optional.Multiplug
http://www.nicolascoolman.fr/adware-boxore/ =>PUP.Optional.Boxore
http://www.nicolascoolman.fr/pup-framefox / =>PUP.Optional.FrameFox
http://www.nicolascoolman.fr/toolbar-conduit/ =>PUP.Optional.Conduit
http://www.nicolascoolman.fr/rogue-pcspeedup/ =>PUP.Optional.PCSpeedUp
http://www.nicolascoolman.fr/adware-installcore/ =>PUP.Optional.InstallCore
http://www.nicolascoolman.fr/blog =>PUP.Optional.Softonic
http://www.nicolascoolman.fr/blog =>PUP.Optional.SystemOptimizer
http://www.nicolascoolman.fr/adware-visualbeetoolbar/ =>PUP.Optional.VisualBeeToolbar
http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider
http://www.nicolascoolman.fr/pup-helperbar/ =>PUP.Optional.HelperBar

~ End of the scan, 19694 items in 201 seconds (772)(0)()

Publicité


Signaler le contenu de ce document

Publicité