~ ZHPDiag v2015.7.21.98 Par Nicolas Coolman (2015/07/21) ~ Démarré par Rachel (Administrator) (2015/07/21 20:39:53) ~ Site: http://www.nicolascoolman.fr ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Etat de la version: Version OK ~ Mode: Scanner ~ Rapport: C:\Users\Rachel\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\Rachel\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ Démarrage du système: Normal (Normal boot) ~ Windows 8.1, 64-bit (Build 9600) ---\\ Navigateurs Internet (3) - 0s GCIE: Google Chrome v43.0.2357.134 MFIE: Mozilla Firefox 38.0.5 (x86 fr) v38.0.5 MSIE: Internet Explorer v11.0.9600.17905 ---\\ Informations sur les produits Windows (9) - 2s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK (Auto) Windows Activation Technologies : OK ~ Windows(R) Operating System, OEM_DM channel Windows ID Activation : OK ~ Windows Partial Key : BKH36 Windows License : OK ~ Windows Remaining Initializations Number : 1000 ---\\ Logiciels de protection (2) - 1s Avira Free Antivirus v14.0.7.468 Norton Internet Security v20.6.0.27 ---\\ Surveillance de Logiciels (1) - 1s Adobe Flash Player 17 NPAPI ---\\ Informations sur le système (7) - 0s ~ Operating System: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 4083.992 MB (48% free) ~ System Restore: Activé (Enable) ~ System drive C: has 779 GB free of 926 GB Total RAM: 4083.992 MB (51% free) ---\\ Mode de connexion au système (3) - 0s ~ Computer Name: RACHELSF ~ User Name: Rachel ~ Logged in as Administrator ---\\ Enumération des unités disques (3) - 0s ~ Drive C: has 779 GB free of 926 GB (System) ~ Drive D: has 2 GB free of 26 GB ~ Drive E: has GB free of 6 GB ---\\ Etat du Centre de Sécurité Windows (11) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ---\\ Recherche particulière de fichiers génériques (23) - 2s [MD5.C10A66189DC8C090E7C84873EDCEBC88] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\WINDOWS\Explorer.exe [2501368] [MD5.6C308D32AFA41D26CE2A0EA8F7B79565] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\WINDOWS\System32\rundll32.exe [54784] [MD5.A570A64292214C43E0BA50E6A72A6380] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\WINDOWS\System32\Wininit.exe [145920] [MD5.98C6A46E9E2822BF83196C2EAE43DBD4] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\WINDOWS\System32\wininet.dll [2427392] [MD5.EC498BAE1F0D3E0E401C963F8D76C437] - (.Microsoft Corporation - Application d’ouverture de session Windows.) () -- C:\WINDOWS\System32\Winlogon.exe [572416] [MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - (.Microsoft Corporation - Bibliothèque de licences.) () -- C:\WINDOWS\System32\sppcomapi.dll [447488] [MD5.E37F897ED7B5AFF79B1398258DB96BD9] - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) () -- C:\WINDOWS\System32\fr-FR\user32.dll.mui [19456] [MD5.374E27295F0A9DCAA8FC96370F9BEEA5] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) () -- C:\WINDOWS\System32\drivers\AFD.sys [563200] [MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\WINDOWS\System32\drivers\atapi.sys [26464] [MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\WINDOWS\System32\drivers\Cdfs.sys [88576] [MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\WINDOWS\System32\drivers\Cdrom.sys [164352] [MD5.A03F362C5557E238CBFA914689C77248] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\WINDOWS\System32\drivers\DfsC.sys [134144] [MD5.D4B7ED39C7900384D9E5C1283F1E7926] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\WINDOWS\System32\drivers\HDAudBus.sys [76800] [MD5.49EE0AE9E5B64FFBBD06D55C4984B598] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\WINDOWS\System32\drivers\i8042prt.sys [108544] [MD5.B7342B3C58E91107F6E946A93D9D4EFD] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\WINDOWS\System32\drivers\IpNat.sys [142848] [MD5.6FBDF2B1B025A8E6E069234362FFFFB7] - (.Microsoft Corporation - Minirdr SMB Windows NT.) () -- C:\WINDOWS\System32\drivers\MRxSmb.sys [401408] [MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\WINDOWS\System32\drivers\netBT.sys [282624] [MD5.7F68063A5A0461E02BC860CE0E6BFDDC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\WINDOWS\System32\drivers\ntfs.sys [2025792] [MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\WINDOWS\System32\drivers\Parport.sys [94208] [MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [120832] [MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) () -- C:\WINDOWS\System32\drivers\rdpdr.sys [195584] [MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\WINDOWS\System32\drivers\tdx.sys [107520] [MD5.64CA2B4A49A8EAF495E435623ECCE7DB] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\WINDOWS\System32\drivers\volsnap.sys [310080] ---\\ Processus lancés (13) - 2s [MD5.3422B50A39334D276528D37E2F9E18A9] - (.AMD - AMD External Events Service Module.) -- C:\WINDOWS\system32\atiesrxx.exe [239616] [PID.868] [MD5.C6128F2E3DC6156C6F8828F9F1B96010] - (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160] [PID.1820] [MD5.5C21AA8A566CAAD38C0D0E2DAD010DD8] - (...) -- C:\Program Files (x86)\Sour Fix\Sour Fix.exe [8016129] [PID.2024] [MD5.1BF9D6476061B31CD7FC2BF848529A56] - (.Symantec Corporation - Symantec Service Framework.) -- C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\ccsvchst.exe [144368] [PID.3172] [MD5.C6D3E5C465817D8E2B7FC5D78F0AF309] - (.AMD - AMD External Events Client Module.) -- C:\WINDOWS\system32\atieclxx.exe [571904] [PID.5168] [MD5.1BF9D6476061B31CD7FC2BF848529A56] - (.Symantec Corporation - Symantec Service Framework.) -- C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\ccsvchst.exe [144368] [PID.4760] [MD5.724CB7A116F7E1A67009D751BCF86586] - (.CyberLink - CyberLink MediaLibray Service.) -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120] [PID.2420] [MD5.B7F55E2AE978D3D34F7876EE5D689AAE] - (.CyberLink - YouCam Mirage.) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488] [PID.6880] [MD5.97AE945EE0E20833E0345C9A5A780DB2] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3015920] [PID.4872] [MD5.0339BDA118909EE81141B618430F642B] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\PROGRAM FILES\SYNAPTICS\SynTP\SYNTPHELPER.EXE [126704] [PID.10364] [MD5.A2221900B57AEC20577996744FA4A56A] - (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296] [PID.8828] [MD5.1E09DFA4048196C9D3CC40C485A39422] - (.Advanced Micro Devices Inc. - Catalyst Control Center: Monitoring program.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe [299008] [PID.7792] [MD5.74CDE657245C114B98816E89B8D4CCD1] - (.ATI Technologies Inc. - Catalyst Control Center: Host application.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [299008] [PID.7252] ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2) (21) - 0s G0 - GCSP: Preferences [User Data\Default][HomePage] http://gethexnow.info/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://accounts.google.com/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://accounts.youtube.com/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://android.clients.google.com/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://clients4.google.com/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://s2.googleusercontent.com/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.fr/ G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.googleapis.com/ G2 - GCE: Preference [User Data\Default] [bejnhdlplbjhffionohbdnpcbobfejcc] Norton Security Toolbar G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [bpjdjkonibhggbbjchphchlbonaijjme] Reddit Link Opener G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [flliilndjeohchalpbbcdekjklbdgfkk] Avira Browser Safety G2 - GCE: Preference [User Data\Default] [iikflkcanblccfahdhdonehdalibjnif] Norton Identity Safe G2 - GCE: Preference [User Data\Default] [iplbmjolljikncjboeofgmjoaacheemi] Patr Pats Flickr App G2 - GCE: Preference [User Data\Default] [jmchmkecamhbiokiopfpnfgbidieafmd] Markdown Preview G2 - GCE: Preference [User Data\Default] [lccekmodgklaepjeofjdjpbminllajkg] Chrome Hotword Shared Module G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc. ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) (20) - 2s P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\amazon-france.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\bing.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\eBay-france.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\google.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\yahoo-france.xml P2 - EXT: (.Mozilla - Default.) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} P2 - EXT: (. - saiLeprizes.) -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\SjmJkVmy.default\extensions\1qK@V.net P2 - EXT: (.Avira - Segurança do navegador Avira.) -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\SjmJkVmy.default\extensions\abs@avira.com P2 - EXT: (. - CooloncHeap.) -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\SjmJkVmy.default\extensions\abt@63m.edu P2 - EXT: (. - OFferSoofT.) -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\SjmJkVmy.default\extensions\F@Q.co.uk P2 - EXT: (. - LoaWraTe.) -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\SjmJkVmy.default\extensions\G5Kfv0@U1.org P2 - EXT: (. - fastsalerr.) -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\SjmJkVmy.default\extensions\h9@MC9.com P2 - EXT: (. - rroccketsale.) -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\SjmJkVmy.default\extensions\tVL@4j4n.com P2 - EXT: (. - rooccketssale.) -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\SjmJkVmy.default\extensions\V@A0N.edu P2 - EXT: (. - lowwprices.) -- C:\Users\Rachel\AppData\Roaming\Mozilla\Firefox\Profiles\SjmJkVmy.default\extensions\W0GVEa@ur.net P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Apple Inc..) -- C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.1.5] - (.VideoLAN.) -- C:\Users\Rachel\Desktop\VLC\npvlc.dll ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) (18) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 ---\\ Internet Explorer, Proxy Management (R5) (4) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs (3) - 0s F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) F2 - REG:system.ini: VMApplet=C:\WINDOWS\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) ---\\ Hosts file redirection (O1) (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (21) ---\\ Browser Helper Object de navigateur (BHO) (O2) (3) - 0s O2 - BHO: Norton Identity Protection [64Bits] - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} (Orphean) O2 - BHO: Norton Vulnerability Protection [64Bits] - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} (Orphean) O2 - BHO: (no name) [64Bits] - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Orphean) ---\\ Internet Explorer Toolbars (O3) (2) - 0s O3 - Toolbar: 0xE3EFEB7F196B494398D2FFB09D4B49CA003A050000 - [HKCU]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} . (.Symantec Corporation - coIEPlugIn.) -- C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\coieplg.dll O3 - Toolbar: Norton Toolbar - [HKLM]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} . (.Symantec Corporation - coIEPlugIn.) -- C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\coieplg.dll ---\\ Applications lancées au démarrage du sytème (O4) (20) - 1s O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe O4 - HKCU\..\Run: [iCloudServices] . (.Apple Inc. - iCloud.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe O4 - HKCU\..\Run: [ApplePhotoStreams] . (.Apple Inc. - iCloud Photos.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe O4 - HKCU\..\Run: [iCloudDrive] . (.Apple Inc. - iCloud Drive.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe O4 - HKCU\..\Run: [Dropbox Update] . (.Dropbox, Inc. - Dropbox Update.) -- C:\Users\Rachel\AppData\Local\Dropbox\Update\DropboxUpdate.exe O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe O4 - HKLM\..\Wow6432Node\Run: [RemoteControl10] . (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe O4 - HKLM\..\Wow6432Node\Run: [HPMessageService] . (.Hewlett-Packard Development Company, L.P. - HP Message Service.) -- C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe O4 - HKLM\..\Wow6432Node\Run: [HP CoolSense] . (.Hewlett-Packard Development Company, L.P. - HP CoolSense.) -- C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe O4 - HKLM\..\Wow6432Node\Run: [GrooveMonitor] . (.Microsoft Corporation - GrooveMonitor Utility.) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe O4 - HKLM\..\Wow6432Node\Run: [Avira Systray] . (.Avira Operations GmbH & Co. KG - Avira.) -- C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe O4 - HKUS\S-1-5-21-1526133523-4088359028-3217712336-1002\..\Run: [iCloudServices] . (.Apple Inc. - iCloud.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe O4 - HKUS\S-1-5-21-1526133523-4088359028-3217712336-1002\..\Run: [ApplePhotoStreams] . (.Apple Inc. - iCloud Photos.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe O4 - HKUS\S-1-5-21-1526133523-4088359028-3217712336-1002\..\Run: [iCloudDrive] . (.Apple Inc. - iCloud Drive.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe O4 - HKUS\S-1-5-21-1526133523-4088359028-3217712336-1002\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe O4 - HKUS\S-1-5-21-1526133523-4088359028-3217712336-1002\..\Run: [Dropbox Update] . (.Dropbox, Inc. - Dropbox Update.) -- C:\Users\Rachel\AppData\Local\Dropbox\Update\DropboxUpdate.exe ---\\ Modification Domaine/Adresses DNS (O17) (2) - 1s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240 ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) (1) - 0s O20 - AppInit_DLLs: . (.Auteurs - .) - C:\WINDOWS\System32\ ---\\ Liste des services NT non Microsoft et non désactivés (O23) (44) - 1s O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\WINDOWS\system32\atiesrxx.exe O23 - Service: Avira Real-Time Protection (AntiVirService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe O23 - Service: Avira Web Protection (AntiVirWebService) . (.Avira Operations GmbH & Co. KG - AntiVir WebGuard WFP Service.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Avira Service Host (Avira.ServiceHost) . (.Avira Operations GmbH & Co. KG - Avira.ServiceHost.) - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: HP Support Assistant Service (HP Support Assistant Service) . (.Hewlett-Packard Company - HP Support Assistant Service.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe O23 - Service: @oem11.inf,%hpservice_desc%;HP Service (hpsrv) . (.Hewlett-Packard Company - HpService.) - C:\WINDOWS\system32\Hpservice.exe O23 - Service: HPWMISVC (HPWMISVC) . (.Hewlett-Packard Development Company, L.P. - HP WMI Service.) - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\WINDOWS\system32\igfxCUIService.exe O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) ME Service (Intel(R) ME Service) . (.Intel Corporation - Intel(R) ME Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: Norton Internet Security (NIS) . (.Symantec Corporation - Symantec Service Framework.) - C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\ccsvchst.exe O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: Sour Fix (Sour Fix) . (...) - C:\Program Files (x86)\Sour Fix\Sour Fix.exe O23 - Service: Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe SR - Auto [2013/12/12 07:25:12] [ 239616] (AMD External Events Utility) . (.AMD.) - C:\WINDOWS\system32\atiesrxx.exe SR - Auto [2014/11/24 11:23:22] [ 431920] Avira Real-Time Protection (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe SR - Auto [2014/11/24 11:23:24] [ 993584] Avira Web Protection (AntiVirWebService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe SR - Auto [2014/10/07 16:09:50] [ 60744] Apple Mobile Device (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe SR - Auto [2015/06/02 17:14:58] [ 217280] Avira Service Host (Avira.ServiceHost) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe SR - Auto [2011/08/31 00:05:32] [ 462184] Service Bonjour (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe SS - Demand [2014/10/01 20:54:28] [ 281488] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe SS - Auto [2015/02/25 23:10:04] [ 107848] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - Demand [2015/02/25 23:10:04] [ 107848] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SR - Auto [2015/05/19 17:22:06] [ 99128] HP Support Assistant Service (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe SR - Demand [2012/11/05 17:14:34] [ 1001376] HP Software Framework Service (hpqwmiex) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe SR - Auto [2012/09/24 14:40:56] [ 31040] @oem11.inf,%hpservice_desc%;HP Service (hpsrv) . (.Hewlett-Packard Company.) - C:\WINDOWS\system32\Hpservice.exe SR - Auto [2013/02/01 17:00:28] [ 1039160] HPWMISVC (HPWMISVC) . (.Hewlett-Packard Development Company, L.P..) - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe SS - Demand [2012/04/24 15:37:56] [ 169752] Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe SR - Auto [2014/10/01 20:54:24] [ 319376] Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation.) - C:\WINDOWS\system32\igfxCUIService.exe SR - Auto [2012/12/10 15:31:28] [ 732160] Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe SS - Demand [2012/12/10 15:31:44] [ 803872] Intel(R) Capability Licensing Service TCP IP Interface (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe SR - Auto [2013/01/14 20:29:50] [ 131032] Intel(R) ME Service (Intel(R) ME Service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe SR - Demand [2014/10/15 06:42:08] [ 643880] Service de l’iPod (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe SR - Auto [2013/01/14 20:29:50] [ 165336] Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe SR - Auto [2013/01/14 20:29:52] [ 279000] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe SR - Auto [2013/05/21 06:44:22] [ 144368] Norton Internet Security (NIS) . (.Symantec Corporation.) - C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\ccsvchst.exe SS - Auto [2015/01/02 19:45:12] [ 315488] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe SR - Auto [2015/07/12 19:13:59] [ 8016129] Sour Fix (Sour Fix) . (...) - C:\Program Files (x86)\Sour Fix\Sour Fix.exe SR - Auto [2013/01/14 20:29:52] [ 366040] Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ---\\ Tâches planifiées en automatique (O39) (16) - 2s O39 - APT: - (...) -- C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1526133523-4088359028-3217712336-1002Core.job [1166] O39 - APT: - (...) -- C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1526133523-4088359028-3217712336-1002UA.job [1218] O39 - APT: - (...) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [1090] O39 - APT: - (...) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [1094] O39 - APT: - (...) -- C:\WINDOWS\Tasks\HPCeeScheduleForRachel.job [354] O39 - APT: - (...) -- C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job [264] O39 - APT: - (...) -- C:\WINDOWS\System32\Tasks\CLMLSvc_P2G8 [3160] O39 - APT: - (...) -- C:\WINDOWS\System32\Tasks\CLVDLauncher [3160] O39 - APT: - (...) -- C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1526133523-4088359028-3217712336-1002Core [3786] O39 - APT: - (...) -- C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1526133523-4088359028-3217712336-1002UA [4166] O39 - APT: - (...) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore [3830] O39 - APT: - (...) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA [4066] O39 - APT: - (...) -- C:\WINDOWS\System32\Tasks\HPCeeScheduleForRachel [3170] O39 - APT: - (...) -- C:\WINDOWS\System32\Tasks\MirageAgent [3148] O39 - APT: - (...) -- C:\WINDOWS\System32\Tasks\Norton WSC Integration [3234] O39 - APT: - (...) -- C:\WINDOWS\System32\Tasks\Synaptics TouchPad Enhancements [2982] ---\\ Logiciels installés (O42) (64) - 5s O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM][64Bits] -- {2ABBBD91-91E5-4AD7-929A-FE15D1DC0576} O42 - Logiciel: iCloud - (.Apple Inc..) [HKLM][64Bits] -- {309768A4-A2BB-4930-A5A2-8169678C9B4C} O42 - Logiciel: AMD APP SDK Runtime - (.Advanced Micro Devices Inc..) [HKLM][64Bits] -- {503F672D-6C84-448A-8F8F-4BC35AC83441} O42 - Logiciel: HP Postscript Converter - (.Hewlett-Packard.) [HKLM][64Bits] -- {6E14E6D6-3175-4E1A-B934-CAB5A86367CD} O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] -- {6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D} O42 - Logiciel: HP Utility Center - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {73237EBB-B26F-4628-8754-4EFE563D72E9} O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM][64Bits] -- {BDD99690-3541-4619-9D2A-3CDDB3E15F9E} O42 - Logiciel: MSVCRT110_amd64 - (.Microsoft.) [HKLM][64Bits] -- {E9FA781F-3E80-4399-825A-AD3E11C28C77} O42 - Logiciel: AMD Catalyst Install Manager - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {EA5160BE-7558-2716-01DB-FFE7F316957A} O42 - Logiciel: HP 3D DriveGuard - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {F9E399CB-046F-45FD-A67F-CF399E2128E4} O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {FA00A3CC-7440-4938-A271-F186F50DD40D} O42 - Logiciel: Adobe Flash Player 17 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI O42 - Logiciel: Adobe Shockwave Player 11.6 - (.Adobe Systems, Inc..) [HKLM][64Bits] -- Adobe Shockwave Player O42 - Logiciel: Avira Free Antivirus v14.0.7.468 - (.Avira.) [HKLM][64Bits] -- Avira AntiVir Desktop O42 - Logiciel: Celtx (2.7) - (.Greyfirst.) [HKLM][64Bits] -- Celtx (2.7) O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D} O42 - Logiciel: CyberLink Media Suite 10 - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79} O42 - Logiciel: CyberLink Power2Go 8 - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2} O42 - Logiciel: Cyberlink PhotoDirector - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10} O42 - Logiciel: CyberLink PowerDirector 10 - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32} O42 - Logiciel: CyberLink LabelPrint - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243} O42 - Logiciel: CyberLink PowerDVD - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B} O42 - Logiciel: Mozilla Firefox 38.0.5 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 38.0.5 (x86 fr) O42 - Logiciel: Norton Internet Security - (.Symantec Corporation.) [HKLM][64Bits] -- NIS O42 - Logiciel: HP Connected Music (Meridian - installer) - (.Meridian Audio Ltd.) [HKLM][64Bits] -- StartHPConnectedMusic O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM][64Bits] -- {01FB4998-33C4-4431-85ED-079E3EEFE75D} O42 - Logiciel: HP Customer Experience Enhancements - (.Hewlett-Packard.) [HKLM][64Bits] -- {07FA4960-B038-49EB-891B-9F95930AA544} O42 - Logiciel: HP CoolSense - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {11AF9A96-6D83-4C3B-8DCB-16EA2A358E3F} O42 - Logiciel: BorderlineRunner - (.Software Publisher.) [HKLM][64Bits] -- {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{a8501310} =>PUP.Optional.Graftor O42 - Logiciel: HP Recovery Manager - (.Hewlett-Packard.) [HKLM][64Bits] -- {1AE37508-089E-41AC-95BD-99FF06887C2F} O42 - Logiciel: CyberLink Media Suite 10 - (.CyberLink Corp..) [HKLM][64Bits] -- {1FBF6C24-C1fD-4101-A42B-0C564F9E8E79} O42 - Logiciel: Skype™ 7.2 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7} O42 - Logiciel: Catalyst Control Center - Branding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {28129194-A7E2-46BC-88EA-2D1EE48663F3} O42 - Logiciel: CyberLink Power2Go 8 - (.CyberLink Corp..) [HKLM][64Bits] -- {2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2} O42 - Logiciel: Cyberlink PhotoDirector - (.CyberLink Corp..) [HKLM][64Bits] -- {39337565-330E-4ab6-A9AE-AC81E0720B10} O42 - Logiciel: Galerie de photos - (.Microsoft Corporation.) [HKLM][64Bits] -- {446CC8CE-0E90-44F7-ADD0-774B243EF090} O42 - Logiciel: LoaWraTe - (."".) [HKLM][64Bits] -- {5A1EDE4C-67FF-6CB4-C08E-A23CAB1557D4} O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} O42 - Logiciel: swMSM - (.Adobe Systems, Inc.) [HKLM][64Bits] -- {612C34C7-5E90-47D8-9B5C-0F717DD82726} O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A} O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM][64Bits] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701} O42 - Logiciel: Hewlett-Packard ACLM.NET v1.2.1.1 - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {6F340107-F9AA-47C6-B54C-C3A19F11553F} O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM][64Bits] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM][64Bits] -- {83CAF0DE-8D3B-4C37-A631-2B8F16EC3031} O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} O42 - Logiciel: MSVCRT110 - (.Microsoft.) [HKLM][64Bits] -- {8E14DDC8-EA60-4E18-B3E3-1937104D5BDA} O42 - Logiciel: HP Wireless Button Driver - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {941DE69D-6CEE-4171-8F1F-3D7E352AA498} O42 - Logiciel: Avira v1.1.40.29239 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] -- {A4D3E7B8-410D-443A-B6AB-F32CDD4BD28C} O42 - Logiciel: CyberLink PowerDirector 10 - (.CyberLink Corp..) [HKLM][64Bits] -- {B0B4F6D2-F2AE-451A-9496-6F2F6A897B32} O42 - Logiciel: HP Quick Start - (.Hewlett-Packard.) [HKLM][64Bits] -- {B9494F9E-5EA9-4C70-9F38-659F5E6C0BF3} O42 - Logiciel: HP System Event Utility - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {C27D60E4-3132-45A3-A71A-E3BD1DA3F794} O42 - Logiciel: CyberLink LabelPrint - (.CyberLink Corp..) [HKLM][64Bits] -- {C59C179C-668D-49A9-B6EA-0121CCFC1243} O42 - Logiciel: OEM Application Profile - (.Nom de votre société.) [HKLM][64Bits] -- {C89A97B6-F991-EBB5-77B7-927BCF420EBE} O42 - Logiciel: CyberLink PowerDVD - (.CyberLink Corp..) [HKLM][64Bits] -- {DEC235ED-58A4-4517-A278-C41E8DAEAB3B} O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} O42 - Logiciel: HP Documentation - (.Hewlett-Packard.) [HKLM][64Bits] -- {F2481209-98FE-4943-8903-90D19E1B7062} O42 - Logiciel: Energy Star - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7} O42 - Logiciel: Dropbox - (.Dropbox, Inc..) [HKCU][64Bits] -- Dropbox O42 - Logiciel: HP Connected Music (Meridian - player) - (.Meridian Audio Ltd.) [HKCU][64Bits] -- HPConnectedMusic O42 - Logiciel: Popcorn Time - (.Popcorn Official.) [HKCU][64Bits] -- Popcorn Time O42 - Logiciel: Microsoft SkyDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- SkyDriveSetup.exe ---\\ HKCU & HKLM Software Keys (65) - 5s HKLM\SOFTWARE\Wow6432Node\557e0f4f-cfda-40b0-2dde-2d617525b60e =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\Adobe HKLM\SOFTWARE\Wow6432Node\AppDataLow HKLM\SOFTWARE\Wow6432Node\Apple Computer, Inc. HKLM\SOFTWARE\Wow6432Node\Apple Inc. HKLM\SOFTWARE\Wow6432Node\ATI HKLM\SOFTWARE\Wow6432Node\ATI Technologies HKLM\SOFTWARE\Wow6432Node\Avira HKLM\SOFTWARE\Wow6432Node\Caphyon HKLM\SOFTWARE\Wow6432Node\CLSID HKLM\SOFTWARE\Wow6432Node\CyberLink HKLM\SOFTWARE\Wow6432Node\Google HKLM\SOFTWARE\Wow6432Node\Greyfirst HKLM\SOFTWARE\Wow6432Node\greyfirst.ca HKLM\SOFTWARE\Wow6432Node\Hewlett-Packard HKLM\SOFTWARE\Wow6432Node\IM Providers HKLM\SOFTWARE\Wow6432Node\Insyde HKLM\SOFTWARE\Wow6432Node\Intel HKLM\SOFTWARE\Wow6432Node\Khronos HKLM\SOFTWARE\Wow6432Node\Lake HKLM\SOFTWARE\Wow6432Node\Macromedia HKLM\SOFTWARE\Wow6432Node\Mozilla HKLM\SOFTWARE\Wow6432Node\mozilla.org HKLM\SOFTWARE\Wow6432Node\MozillaPlugins HKLM\SOFTWARE\Wow6432Node\Norton HKLM\SOFTWARE\Wow6432Node\ODBC HKLM\SOFTWARE\Wow6432Node\OldTimer Tools HKLM\SOFTWARE\Wow6432Node\Realtek HKLM\SOFTWARE\Wow6432Node\Skype HKLM\SOFTWARE\Wow6432Node\Symantec HKLM\SOFTWARE\Wow6432Node\VideoLAN HKLM\SOFTWARE\Wow6432Node\WildTangent HKLM\SOFTWARE\Wow6432Node\X-AVCSD HKLM\SOFTWARE\Wow6432Node\RegisteredApplications HKCU\SOFTWARE\7-Zip HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\Apple Computer, Inc. HKCU\SOFTWARE\Apple Inc. HKCU\SOFTWARE\ATI HKCU\SOFTWARE\Avira HKCU\SOFTWARE\Chromium HKCU\SOFTWARE\CyberLink HKCU\SOFTWARE\Dropbox HKCU\SOFTWARE\DropboxUpdate HKCU\SOFTWARE\Google HKCU\SOFTWARE\Hewlett-Packard HKCU\SOFTWARE\IM Providers HKCU\SOFTWARE\Intel HKCU\SOFTWARE\LogiShrd HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\Mine HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\Norton HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\Realtek HKCU\SOFTWARE\RegisteredApplications HKCU\SOFTWARE\Skype HKCU\SOFTWARE\Symantec HKCU\SOFTWARE\Synaptics HKCU\SOFTWARE\TeleCharger HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\Adobe ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) (196) - 4s O43 - CFD: 2014/11/21 13:45:01 - [] D -- C:\Program Files (x86)\AMD APP O43 - CFD: 2014/12/20 17:42:21 - [] D -- C:\Program Files (x86)\Apple Software Update O43 - CFD: 2015/07/20 10:16:30 - [] D -- C:\Program Files (x86)\ATI Technologies O43 - CFD: 2015/07/15 19:38:42 - [] D -- C:\Program Files (x86)\Avira O43 - CFD: 2014/11/21 13:50:04 - [] D -- C:\Program Files (x86)\Bonjour O43 - CFD: 2015/05/07 15:09:38 - [] D -- C:\Program Files (x86)\BorderlineRunner O43 - CFD: 2015/05/02 14:21:10 - [] D -- C:\Program Files (x86)\brOwsEandshop O43 - CFD: 2015/03/09 21:32:03 - [] D -- C:\Program Files (x86)\Celtx O43 - CFD: 2015/03/10 01:24:36 - [] D -- C:\Program Files (x86)\Common Files O43 - CFD: 2014/11/21 14:06:59 - [] D -- C:\Program Files (x86)\CyberLink O43 - CFD: 2015/07/20 00:48:58 - [] D -- C:\Program Files (x86)\Elex-tech =>PUP.Optional.Elex O43 - CFD: 2015/05/02 14:21:29 - [] D -- C:\Program Files (x86)\fAstsaalEr O43 - CFD: 2015/04/13 15:24:44 - [] D -- C:\Program Files (x86)\freae2you O43 - CFD: 2015/03/09 19:39:12 - [] D -- C:\Program Files (x86)\FRReEE2you O43 - CFD: 2015/02/25 23:11:01 - [] D -- C:\Program Files (x86)\Google O43 - CFD: 2014/11/21 14:09:53 - [] D -- C:\Program Files (x86)\Hewlett-Packard O43 - CFD: 2013/03/25 18:14:09 - [] D -- C:\Program Files (x86)\HPConnectedMusic O43 - CFD: 2015/05/07 14:59:13 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information O43 - CFD: 2015/05/07 15:03:07 - [] D -- C:\Program Files (x86)\Intel O43 - CFD: 2015/07/17 08:23:04 - [] D -- C:\Program Files (x86)\Internet Explorer O43 - CFD: 2014/12/20 17:44:00 - [] D -- C:\Program Files (x86)\iTunes O43 - CFD: 2015/03/09 19:35:14 - [] D -- C:\Program Files (x86)\LoaWraTe O43 - CFD: 2015/03/31 16:15:25 - [] D -- C:\Program Files (x86)\lowwprices O43 - CFD: 2015/03/08 17:22:51 - [] D -- C:\Program Files (x86)\Microsoft Office O43 - CFD: 2013/03/25 18:10:13 - [] D -- C:\Program Files (x86)\Microsoft SkyDrive O43 - CFD: 2013/03/25 18:11:05 - [] D -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition O43 - CFD: 2015/03/08 17:22:39 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio O43 - CFD: 2015/03/08 17:17:56 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio 8 O43 - CFD: 2015/03/09 22:23:03 - [] D -- C:\Program Files (x86)\Microsoft Works O43 - CFD: 2015/03/08 17:21:52 - [] D -- C:\Program Files (x86)\Microsoft.NET O43 - CFD: 2015/06/12 12:49:50 - [] D -- C:\Program Files (x86)\Mozilla Firefox O43 - CFD: 2015/03/08 17:23:08 - [] D -- C:\Program Files (x86)\MSBuild O43 - CFD: 2014/11/21 14:08:24 - [] D -- C:\Program Files (x86)\Norton Internet Security O43 - CFD: 2015/06/12 19:14:56 - [] D -- C:\Program Files (x86)\NortonInstaller O43 - CFD: 2015/02/17 14:54:34 - [] D -- C:\Program Files (x86)\ofFeRsale O43 - CFD: 2014/11/21 15:34:18 - [] RD -- C:\Program Files (x86)\Online Services O43 - CFD: 2015/05/07 15:11:44 - [] D -- C:\Program Files (x86)\Realtek O43 - CFD: 2014/12/15 20:27:33 - [] D -- C:\Program Files (x86)\Reference Assemblies O43 - CFD: 2015/02/16 21:38:31 - [] D -- C:\Program Files (x86)\saiLeprizes O43 - CFD: 2015/05/02 14:21:16 - [] D -- C:\Program Files (x86)\salepraizes O43 - CFD: 2015/05/28 12:02:19 - [] RD -- C:\Program Files (x86)\Skype O43 - CFD: 2015/07/12 19:14:12 - [] D -- C:\Program Files (x86)\Sour Fix O43 - CFD: 2014/11/21 14:09:07 - [] D -- C:\Program Files (x86)\SymSilent O43 - CFD: 2014/11/21 13:48:40 - [0] HD -- C:\Program Files (x86)\Temp O43 - CFD: 2015/03/09 19:35:10 - [] D -- C:\Program Files (x86)\WatchClient for Twitter Real Time Twitter Update O43 - CFD: 2015/02/16 18:03:26 - [] D -- C:\Program Files (x86)\WildTangent Games O43 - CFD: 2015/03/14 04:43:59 - [] D -- C:\Program Files (x86)\Windows Defender O43 - CFD: 2013/03/25 18:11:03 - [] D -- C:\Program Files (x86)\Windows Live O43 - CFD: 2015/03/14 04:44:10 - [] D -- C:\Program Files (x86)\Windows Mail O43 - CFD: 2015/03/14 04:44:09 - [] D -- C:\Program Files (x86)\Windows Media Player O43 - CFD: 2015/03/14 04:44:09 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform O43 - CFD: 2013/08/22 17:36:30 - [] D -- C:\Program Files (x86)\Windows NT O43 - CFD: 2015/03/14 04:44:09 - [] D -- C:\Program Files (x86)\Windows Photo Viewer O43 - CFD: 2015/03/14 04:44:09 - [] D -- C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 2014/12/15 20:53:13 - [] SHD -- C:\Program Files (x86)\Windows Sidebar O43 - CFD: 2013/08/22 17:36:30 - [] D -- C:\Program Files (x86)\WindowsPowerShell O43 - CFD: 2015/03/14 04:46:30 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 2015/03/14 04:46:30 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2015/03/14 04:46:30 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2015/07/15 19:38:48 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira O43 - CFD: 2014/12/15 20:56:13 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center O43 - CFD: 2015/03/09 21:32:07 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Celtx O43 - CFD: 2014/12/15 20:56:13 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat O43 - CFD: 2014/09/24 20:10:43 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Embedded Lockdown Manager O43 - CFD: 2014/12/15 20:56:13 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 2015/02/25 23:11:07 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 2014/12/15 20:56:13 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support O43 - CFD: 2014/12/22 13:18:30 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud O43 - CFD: 2014/12/20 17:44:17 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes O43 - CFD: 2013/08/22 17:36:33 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2015/03/08 17:24:16 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office O43 - CFD: 2014/12/15 20:56:13 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos O43 - CFD: 2014/12/17 12:04:57 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security O43 - CFD: 2014/12/15 20:56:13 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools O43 - CFD: 2014/12/15 20:53:15 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection O43 - CFD: 2014/12/15 20:53:15 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services O43 - CFD: 2015/01/26 10:37:44 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype O43 - CFD: 2013/08/22 17:36:33 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp O43 - CFD: 2015/03/14 04:46:30 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 2014/09/24 17:03:53 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 2015/01/30 20:33:18 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN O43 - CFD: 2015/05/28 12:18:35 - [] D -- C:\ProgramData\16466077874091300779 O43 - CFD: 2015/05/07 15:09:52 - [0] D -- C:\ProgramData\88d5bd4000005b7e O43 - CFD: 2015/02/16 21:38:51 - [] D -- C:\ProgramData\appcgembagkcopdbkbjcbcnkonjdkjci O43 - CFD: 2014/12/20 17:42:19 - [] D -- C:\ProgramData\Apple O43 - CFD: 2014/12/20 17:43:36 - [] D -- C:\ProgramData\Apple Computer O43 - CFD: 2013/08/22 16:45:52 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 2014/11/21 14:18:20 - [] D -- C:\ProgramData\ATI O43 - CFD: 2015/06/12 12:55:00 - [] D -- C:\ProgramData\Avira O43 - CFD: 2014/11/21 15:32:16 - [0] SHD -- C:\ProgramData\Bureau O43 - CFD: 2015/02/15 12:27:16 - [0] D -- C:\ProgramData\c6572d70000554f O43 - CFD: 2014/12/03 01:32:17 - [] D -- C:\ProgramData\CyberLink O43 - CFD: 2013/08/22 16:45:52 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 2013/08/22 16:45:52 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 2015/06/22 10:51:18 - [] D -- C:\ProgramData\Dropbox O43 - CFD: 2015/01/12 01:51:05 - [] D -- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 O43 - CFD: 2015/05/07 19:05:01 - [] D -- C:\ProgramData\e4834295e12197ab O43 - CFD: 2014/12/04 00:13:13 - [] D -- C:\ProgramData\Hewlett-Packard O43 - CFD: 2015/07/20 10:16:48 - [0] D -- C:\ProgramData\install_clap O43 - CFD: 2015/05/07 15:04:25 - [] D -- C:\ProgramData\Intel O43 - CFD: 2014/11/21 15:32:16 - [0] SHD -- C:\ProgramData\Menu Démarrer O43 - CFD: 2015/03/08 17:21:52 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 2015/07/15 22:23:55 - [] D -- C:\ProgramData\Microsoft Help O43 - CFD: 2013/03/25 18:10:00 - [] D -- C:\ProgramData\Microsoft SkyDrive O43 - CFD: 2014/11/21 15:32:16 - [0] SHD -- C:\ProgramData\Modèles O43 - CFD: 2015/04/27 21:10:05 - [] D -- C:\ProgramData\Mozilla O43 - CFD: 2015/07/15 20:11:11 - [] D -- C:\ProgramData\Norton O43 - CFD: 2014/11/21 14:07:58 - [] D -- C:\ProgramData\NortonInstaller O43 - CFD: 2015/07/15 19:38:53 - [] D -- C:\ProgramData\Package Cache O43 - CFD: 2014/12/15 20:53:16 - [] D -- C:\ProgramData\PRICache O43 - CFD: 2015/03/14 04:44:07 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft O43 - CFD: 2015/05/03 12:53:53 - [] D -- C:\ProgramData\Skype O43 - CFD: 2013/08/22 16:45:52 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 2014/11/21 13:52:10 - [] D -- C:\ProgramData\Synaptics O43 - CFD: 2014/11/21 14:06:42 - [] D -- C:\ProgramData\Temp O43 - CFD: 2013/08/22 16:45:52 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 2015/02/16 18:03:24 - [] D -- C:\ProgramData\WildTangent O43 - CFD: 2013/03/25 18:15:19 - [] D -- C:\ProgramData\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF} O43 - CFD: 2014/12/22 13:18:25 - [] D -- C:\Program Files (x86)\Common Files\Apple O43 - CFD: 2014/11/21 14:00:17 - [] D -- C:\Program Files (x86)\Common Files\CyberLink O43 - CFD: 2015/03/10 01:24:36 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER O43 - CFD: 2014/12/15 20:42:39 - [] D -- C:\Program Files (x86)\Common Files\InstallShield O43 - CFD: 2014/12/15 20:40:56 - [] D -- C:\Program Files (x86)\Common Files\Intel O43 - CFD: 2014/11/21 13:46:21 - [] D -- C:\Program Files (x86)\Common Files\Intel Corporation O43 - CFD: 2015/07/21 18:32:11 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared O43 - CFD: 2014/11/21 14:07:14 - [] D -- C:\Program Files (x86)\Common Files\Nikon O43 - CFD: 2014/11/21 13:46:14 - [] D -- C:\Program Files (x86)\Common Files\postureAgent O43 - CFD: 2013/08/22 17:36:33 - [] D -- C:\Program Files (x86)\Common Files\Services O43 - CFD: 2015/01/26 10:37:42 - [] D -- C:\Program Files (x86)\Common Files\Skype O43 - CFD: 2014/12/02 12:54:58 - [] D -- C:\Program Files (x86)\Common Files\Symantec Shared O43 - CFD: 2015/03/14 04:44:07 - [] D -- C:\Program Files (x86)\Common Files\System O43 - CFD: 2013/03/25 18:09:51 - [] D -- C:\Program Files (x86)\Common Files\Windows Live O43 - CFD: 2014/12/02 12:35:39 - [] D -- C:\Users\Rachel\AppData\Roaming\Adobe O43 - CFD: 2015/07/16 00:20:11 - [] D -- C:\Users\Rachel\AppData\Roaming\Apple Computer O43 - CFD: 2014/12/02 12:36:42 - [] D -- C:\Users\Rachel\AppData\Roaming\ATI O43 - CFD: 2015/02/16 22:03:59 - [] D -- C:\Users\Rachel\AppData\Roaming\Avira O43 - CFD: 2015/01/08 12:44:26 - [] D -- C:\Users\Rachel\AppData\Roaming\CyberLink O43 - CFD: 2015/07/21 18:29:48 - [] D -- C:\Users\Rachel\AppData\Roaming\Dropbox O43 - CFD: 2015/07/20 10:16:53 - [0] D -- C:\Users\Rachel\AppData\Roaming\dvdcss O43 - CFD: 2014/12/02 19:00:36 - [] D -- C:\Users\Rachel\AppData\Roaming\Hewlett-Packard O43 - CFD: 2014/12/02 18:59:54 - [0] D -- C:\Users\Rachel\AppData\Roaming\hpqlog O43 - CFD: 2014/12/15 21:07:38 - [] D -- C:\Users\Rachel\AppData\Roaming\Identities O43 - CFD: 2014/12/02 12:37:48 - [] D -- C:\Users\Rachel\AppData\Roaming\Macromedia O43 - CFD: 2015/04/26 20:52:08 - [] SD -- C:\Users\Rachel\AppData\Roaming\Microsoft O43 - CFD: 2015/04/27 21:10:26 - [] D -- C:\Users\Rachel\AppData\Roaming\Mozilla O43 - CFD: 2015/07/21 18:29:46 - [] D -- C:\Users\Rachel\AppData\Roaming\Skype O43 - CFD: 2014/12/02 12:35:19 - [] D -- C:\Users\Rachel\AppData\Roaming\Synaptics O43 - CFD: 2015/06/12 04:05:39 - [] D -- C:\Users\Rachel\AppData\Roaming\vlc O43 - CFD: 2014/12/03 02:59:44 - [] D -- C:\Users\Rachel\AppData\Roaming\WebApp O43 - CFD: 2015/07/21 18:45:31 - [] D -- C:\Users\Rachel\AppData\Roaming\ZHP O43 - CFD: 2015/07/19 03:37:13 - [] D -- C:\Users\Rachel\AppData\Local\0222BE3C-3D02-4E67-A96A-47D2EF63072D.aplzod O43 - CFD: 2015/05/05 18:08:09 - [0] D -- C:\Users\Rachel\AppData\Local\Adobe O43 - CFD: 2014/12/20 17:42:23 - [] D -- C:\Users\Rachel\AppData\Local\Apple O43 - CFD: 2015/07/16 00:20:00 - [] D -- C:\Users\Rachel\AppData\Local\Apple Computer O43 - CFD: 2014/12/22 15:17:36 - [] D -- C:\Users\Rachel\AppData\Local\Apple Inc O43 - CFD: 2014/12/15 20:49:32 - [0] SHD -- C:\Users\Rachel\AppData\Local\Application Data O43 - CFD: 2014/12/04 01:45:17 - [] D -- C:\Users\Rachel\AppData\Local\Apps O43 - CFD: 2014/12/02 12:36:42 - [] D -- C:\Users\Rachel\AppData\Local\ATI O43 - CFD: 2015/03/01 04:23:10 - [] D -- C:\Users\Rachel\AppData\Local\CyberLink O43 - CFD: 2015/02/25 23:09:57 - [0] D -- C:\Users\Rachel\AppData\Local\Deployment O43 - CFD: 2015/05/29 21:02:08 - [0] D -- C:\Users\Rachel\AppData\Local\Diagnostics O43 - CFD: 2015/06/22 10:51:18 - [] D -- C:\Users\Rachel\AppData\Local\Dropbox O43 - CFD: 2015/06/12 12:54:33 - [0] SHD -- C:\Users\Rachel\AppData\Local\EmieBrowserModeList O43 - CFD: 2015/06/12 12:54:33 - [0] SHD -- C:\Users\Rachel\AppData\Local\EmieSiteList O43 - CFD: 2015/06/12 12:54:33 - [0] SHD -- C:\Users\Rachel\AppData\Local\EmieUserList O43 - CFD: 2015/02/25 23:11:11 - [] D -- C:\Users\Rachel\AppData\Local\Google O43 - CFD: 2015/06/22 10:33:06 - [] D -- C:\Users\Rachel\AppData\Local\GWX O43 - CFD: 2015/01/21 19:13:57 - [] D -- C:\Users\Rachel\AppData\Local\Hewlett-Packard O43 - CFD: 2014/12/15 20:49:32 - [0] SHD -- C:\Users\Rachel\AppData\Local\Historique O43 - CFD: 2015/04/23 19:23:51 - [0] D -- C:\Users\Rachel\AppData\Local\HP Quick Start O43 - CFD: 2015/06/13 07:39:58 - [] D -- C:\Users\Rachel\AppData\Local\HPConnectedMusic O43 - CFD: 2015/05/07 12:54:48 - [] D -- C:\Users\Rachel\AppData\Local\Macromedia O43 - CFD: 2015/04/26 20:52:08 - [] D -- C:\Users\Rachel\AppData\Local\Microsoft O43 - CFD: 2015/03/08 17:17:12 - [0] D -- C:\Users\Rachel\AppData\Local\Microsoft Help O43 - CFD: 2015/04/27 21:10:30 - [] D -- C:\Users\Rachel\AppData\Local\Mozilla O43 - CFD: 2015/03/04 21:44:07 - [] D -- C:\Users\Rachel\AppData\Local\Packages O43 - CFD: 2015/06/15 02:18:08 - [] D -- C:\Users\Rachel\AppData\Local\Popcorn Time O43 - CFD: 2015/07/16 22:40:59 - [] D -- C:\Users\Rachel\AppData\Local\Popcorn-Time O43 - CFD: 2014/12/02 12:35:10 - [] D -- C:\Users\Rachel\AppData\Local\Power2Go8 O43 - CFD: 2015/01/26 10:36:17 - [] D -- C:\Users\Rachel\AppData\Local\Programs O43 - CFD: 2015/01/26 10:37:56 - [] D -- C:\Users\Rachel\AppData\Local\Skype O43 - CFD: 2015/07/21 18:43:28 - [] D -- C:\Users\Rachel\AppData\Local\Temp O43 - CFD: 2014/12/15 20:49:32 - [0] SHD -- C:\Users\Rachel\AppData\Local\Temporary Internet Files O43 - CFD: 2014/12/16 00:00:42 - [] D -- C:\Users\Rachel\AppData\Local\VirtualStore O43 - CFD: 2015/03/31 19:17:18 - [] D -- C:\Users\Rachel\AppData\Local\Windows Live O43 - CFD: 2014/12/15 20:50:38 - [] RD -- C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 2013/08/22 17:36:32 - [] RD -- C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2015/07/17 08:32:45 - [] RD -- C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2015/07/14 14:04:34 - [] D -- C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox O43 - CFD: 2013/08/22 17:36:32 - [] D -- C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2015/06/15 02:18:08 - [] D -- C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time O43 - CFD: 2015/07/17 08:32:45 - [] RD -- C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 2014/12/15 20:50:38 - [] RD -- C:\Users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 2015/07/21 20:40:16 - [] D -- C:\Users\Rachel\AppData\Roaming\Skype O43 - CFD: 2015/07/21 20:40:02 - [] D -- C:\Users\Rachel\AppData\Roaming\ZHP O43 - CFD: 2015/07/21 20:40:21 - [] D -- C:\Users\Rachel\AppData\Local\Temp ---\\ Liste des pilotes du système (SDL) (O58) (56) - 8s O58 - SDL:2013/08/22 14:43:41 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [108896] O58 - SDL:2012/09/24 14:40:56 A . (.Hewlett-Packard Company - HP Accelerometer.) -- C:\WINDOWS\System32\drivers\Accelerometer.sys [43840] O58 - SDL:2013/08/22 14:43:41 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [782176] O58 - SDL:2013/08/22 14:43:41 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [79200] O58 - SDL:2013/08/22 14:43:41 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259424] O58 - SDL:2013/08/22 14:43:40 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [25952] O58 - SDL:2013/08/22 14:43:41 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [114016] O58 - SDL:2013/12/12 07:25:12 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\atikmdag.sys [12521472] O58 - SDL:2013/12/12 07:25:14 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\WINDOWS\System32\drivers\atikmpag.sys [617472] O58 - SDL:2014/11/24 11:23:22 A . (.Avira Operations GmbH & Co. KG - Avira Minifilter Driver.) -- C:\WINDOWS\System32\drivers\avgntflt.sys [119272] O58 - SDL:2014/11/24 11:23:22 A . (.Avira Operations GmbH & Co. KG - Avira Driver for Security Enhancement.) -- C:\WINDOWS\System32\drivers\avipbb.sys [131608] O58 - SDL:2014/11/24 11:23:23 A . (.Avira Operations GmbH & Co. KG - Avira Manager Driver.) -- C:\WINDOWS\System32\drivers\avkmgr.sys [28600] O58 - SDL:2014/11/24 11:23:23 A . (.Avira Operations GmbH & Co. KG - Avira WFP Network Driver.) -- C:\WINDOWS\System32\drivers\avnetflt.sys [43064] O58 - SDL:2013/08/13 01:25:46 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [17624] O58 - SDL:2013/08/22 14:43:41 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [531296] O58 - SDL:2012/06/25 11:24:50 A . (.CyberLink - It is a virtual device driver which could c.) -- C:\WINDOWS\System32\drivers\CLVirtualDrive.sys [92536] O58 - SDL:2013/08/22 14:43:45 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3357024] O58 - SDL:2012/10/03 17:14:56 A . (.GEAR Software Inc. - CD DVD Filter.) -- C:\WINDOWS\System32\drivers\GEARAspiWDM.sys [33240] O58 - SDL:2012/07/13 04:56:32 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\HECIx64.sys [62784] O58 - SDL:2012/09/24 14:40:56 A . (.Hewlett-Packard Company - HP Disk Filter - SATA/RAID.) -- C:\WINDOWS\System32\drivers\hpdskflt.sys [31040] O58 - SDL:2013/08/22 14:43:45 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64352] O58 - SDL:2013/07/30 20:47:35 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [24568] O58 - SDL:2013/07/25 21:05:39 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [99320] O58 - SDL:2013/04/10 10:48:38 A . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorA.sys [653808] O58 - SDL:2013/08/10 02:39:30 A . (.Intel Corporation - Intel Rapid Storage Technology driver (inbo.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [651248] O58 - SDL:2013/08/22 14:43:45 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412000] O58 - SDL:2014/10/01 20:54:16 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd64.sys [3828152] O58 - SDL:2013/03/07 17:14:22 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\WINDOWS\System32\drivers\IntcDAud.sys [442368] O58 - SDL:2015/04/16 10:55:45 A . (.Elex do Brasil Participações Ltda - iSafe Kernel Boot Driver.) -- C:\WINDOWS\System32\drivers\iSafeKrnlBoot.sys [53568] =>PUP.Optional.YetAnotherCleaner O58 - SDL:2014/08/01 22:18:33 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\iwdbus.sys [27032] O58 - SDL:2013/08/22 14:43:44 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [109408] O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2.sys [93536] O58 - SDL:2013/08/22 14:43:44 A . (.LSI Corporation - LSI SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3.sys [81760] O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82784] O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [56672] O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575840] O58 - SDL:2013/08/22 14:43:49 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63840] O58 - SDL:2014/08/16 00:13:34 A . (.Apple Inc. - Apple Mobile Device Ethernet.) -- C:\WINDOWS\System32\drivers\netaapl64.sys [23040] O58 - SDL:2013/08/22 14:43:31 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150368] O58 - SDL:2013/08/22 14:43:32 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [168288] O58 - SDL:2013/06/18 16:46:17 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.30 64-bit Dr.) -- C:\WINDOWS\System32\drivers\Rt630x64.sys [591360] O58 - SDL:2013/07/31 20:25:43 A . (.Realtek Semiconductor Corporation - Realtek PCIE NDIS Driverr.) -- C:\WINDOWS\System32\drivers\rtwlane.sys [1936088] O58 - SDL:2013/08/22 17:35:09 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\WINDOWS\System32\drivers\secdrv.sys [23040] O58 - SDL:2013/08/22 14:43:31 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44896] O58 - SDL:2013/08/22 14:43:32 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81760] O58 - SDL:2013/02/06 06:54:16 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [28400] O58 - SDL:2013/02/06 06:54:16 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [31984] O58 - SDL:2013/08/22 14:43:32 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31072] O58 - SDL:2014/12/02 21:05:57 A . (.Symantec Corporation - Symantec Event Library.) -- C:\WINDOWS\System32\drivers\SYMEVENT64x86.SYS [177312] O58 - SDL:2013/02/06 06:54:18 A . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\WINDOWS\System32\drivers\SynTP.sys [469232] O58 - SDL:2014/08/16 00:35:00 A . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\WINDOWS\System32\drivers\usbaapl64.sys [54784] O58 - SDL:2013/08/22 14:43:34 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\WINDOWS\System32\drivers\viaide.sys [19808] O58 - SDL:2013/08/22 14:43:34 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [168800] O58 - SDL:2013/08/22 14:43:34 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305504] O58 - SDL:2012/08/31 10:40:24 A . (.Hewlett-Packard Development Company, L.P. - HP Wireless Button Driver.) -- C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [20800] O58 - SDL:2015/01/25 19:40:30 A . (.StdLib - StdLib.) -- C:\WINDOWS\System32\drivers\{1d7d694e-604c-4da2-9100-b2601d3a1c57}Gw64.sys [48792] =>PUP.Optional.LinkiDoo ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) (4) - 9s O61 - LFC: 2015/07/21 18:30:43 A . (..) -- C:\Users\Rachel\AppData\Roaming\appdataFr25.bin [24] O61 - LFC: 2015/07/21 15:08:32 A . (..) -- C:\Users\Rachel\AppData\Local\Microsoft\Windows\INetCache\IE\WX65BO2N\urlblockindex[1].bin [16] O61 - LFC: 2015/07/21 18:30:55 A . (..) -- C:\Users\Rachel\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [1113849] O61 - LFC: 2015/07/21 18:21:35 A . (..) -- C:\Users\Rachel\AppData\Local\ATI\ACE\Manifest.Bin [28362] ---\\ Associations Shell Spawning (O67) (1) - 0s O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe ---\\ Menu de démarrage Internet (SMI) (O68) (12) - 0s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) (3) - 3s O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKCU] {B74F68DF-F58E-4663-9FA4-AF195A3E73A1} - (Propositions de recherche Amazon.fr) - http://www.amazon.fr/ O69 - SBI: SearchScopes [HKCU] {D944BB61-2E34-4DBF-A683-47E505C587DC} - (eBay) - http://rover.ebay.com/ ---\\ Enumère les services démarrés par Svchost (SSS) (O83) (34) - 1s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\WINDOWS\System32\aelupsvc.dll [214528] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [156160] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [156160] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\WINDOWS\system32\srvsvc.dll [329216] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\WINDOWS\System32\gpsvc.dll [1360896] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\WINDOWS\System32\ikeext.dll [1084416] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\WINDOWS\System32\iphlpsvc.dll [926208] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\WINDOWS\system32\seclogon.dll [31744] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\WINDOWS\System32\appinfo.dll [110080] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\WINDOWS\system32\iscsiexe.dll [151040] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\WINDOWS\System32\eapsvc.dll [110592] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\WINDOWS\system32\schedsvc.dll [1265152] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [230400] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\WINDOWS\system32\mmcss.dll [71168] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\WINDOWS\System32\browser.dll [135168] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\system32\profsvc.dll [227328] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [339968] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\WINDOWS\System32\wercplsupport.dll [84992] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\WINDOWS\system32\kmsvc.dll [101376] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\WINDOWS\System32\bdesvc.dll [348672] O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service d’infrastructure de localisation Wi.) -- C:\Windows\System32\GeofenceMonitorService.dll [522240] O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\WINDOWS\system32\wlidsvc.dll [1639424] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\WINDOWS\system32\themeservice.dll [59392] O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [206848] O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\WINDOWS\System32\ncasvc.dll [166400] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\WINDOWS\System32\rasauto.dll [102912] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\WINDOWS\System32\rasmans.dll [542208] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [226816] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\WINDOWS\System32\sens.dll [73728] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\WINDOWS\System32\ipnathlp.dll [452608] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [313344] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\WINDOWS\system32\wuaueng.dll [3701760] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\WINDOWS\System32\qmgr.dll [933376] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [640000] ---\\ Liste des exceptions du parefeu (FirewallRules) (O87) (4) - 2s O87 - FAEL: "{44CEEA50-05D5-4386-B3C0-FEFA45870D4B}" [In-None-P17-TRUE] .(.CyberLink Corp. - PowerDirector 10.) -- C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE O87 - FAEL: "{B511B381-BA9D-4C92-8A78-D957D06522B4}" [In-None-P17-TRUE] .(.CyberLink Corp. - PowerDVD 10.0.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE O87 - FAEL: "{360F1EBD-CD40-4012-ACBF-D73EA0827FC6}" [In-None-P6-TRUE] .(.Meridian Audio Ltd - HP Connected Music.) -- C:\Program Files (x86)\HPConnectedMusic\HPConnectedMusic.exe O87 - FAEL: "{7D88178E-AA08-4E08-92E5-70F292DF3603}" [Out-None-P6-TRUE] .(.Meridian Audio Ltd - HP Connected Music.) -- C:\Program Files (x86)\HPConnectedMusic\HPConnectedMusic.exe ---\\ Recherche de clés de registre Tracing (O100) (6) - 1s HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\DriverRestore_RASAPI32 =>PUP.Optional.DriverRestore HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\DriverRestore_RASMANCS =>PUP.Optional.DriverRestore HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateSolutionReal_RASAPI32 =>PUP.Optional.SolutionReal HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateSolutionReal_RASMANCS =>PUP.Optional.SolutionReal HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilSolutionReal_RASAPI32 =>PUP.Optional.SolutionReal HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilSolutionReal_RASMANCS =>PUP.Optional.SolutionReal ---\\ Scan Additionnel (O88) (10) - 0s HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{a8501310} =>PUP.Optional.Graftor C:\Program Files (x86)\Elex-tech =>PUP.Optional.Elex C:\WINDOWS\System32\drivers\iSafeKrnlBoot.sys =>PUP.Optional.YetAnotherCleaner C:\WINDOWS\System32\drivers\{1d7d694e-604c-4da2-9100-b2601d3a1c57}Gw64.sys =>PUP.Optional.LinkiDoo HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\DriverRestore_RASAPI32 =>PUP.Optional.DriverRestore HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\DriverRestore_RASMANCS =>PUP.Optional.DriverRestore HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateSolutionReal_RASAPI32 =>PUP.Optional.SolutionReal HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateSolutionReal_RASMANCS =>PUP.Optional.SolutionReal HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilSolutionReal_RASAPI32 =>PUP.Optional.SolutionReal HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilSolutionReal_RASMANCS =>PUP.Optional.SolutionReal ---\\ Récapitulatif des éléments trouvées sur votre station (6) - 0s http://www.nicolascoolman.fr/blog =>PUP.Optional.Graftor http://www.nicolascoolman.fr/pup-elex/ =>PUP.Optional.Elex http://www.nicolascoolman.fr/blog =>PUP.Optional.YetAnotherCleaner http://www.nicolascoolman.fr/pup-linkidoo/ =>PUP.Optional.LinkiDoo http://www.nicolascoolman.fr/blog =>PUP.Optional.DriverRestore http://www.nicolascoolman.fr/blog =>PUP.Optional.SolutionReal ~ End of the scan, 56575 items in 326 seconds (727)(0)()