~ ZHPDiag v2015.8.4.110 Par Nicolas Coolman (2015/08/4) ~ Démarré par Domi (Administrator) (2015/08/05 15:06:02) ~ Site: http://www.nicolascoolman.fr ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Etat de la version: Version OK ~ Mode: Scanner ~ Rapport: C:\Users\Domi\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\Domi\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ Démarrage du système: Normal (Normal boot) ~ WIN_VISTA, 32-bit Service Pack 2 (Build 6002) ---\\ Navigateurs Internet (2) - 0s MFIE: Mozilla Firefox 39.0 (x86 fr) v39.0 MSIE: Internet Explorer v9.0.8112.16421 ---\\ Informations sur les produits Windows (3) - 13s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK (Auto) ---\\ Logiciels de protection (3) - 2s Malwarebytes Anti-Malware version 2.1.8.1057 Microsoft Security Client v4.8.0204.0 Microsoft Security Essentials v4.8.204.0 ---\\ Logiciels d'optimisation (1) - 3s CCleaner v4.03 ---\\ Surveillance de Logiciels (2) - 3s Adobe Flash Player 18 NPAPI Adobe Reader X ---\\ Informations sur le système (6) - 0s ~ Operating System: x86 Family 6 Model 15 Stepping 13, GenuineIntel ~ Operating System: 32-bit ~ Boot mode: Normal (Normal boot) Total RAM: 3074.224 MB (53% free) ~ System Restore: Activé (Enable) ~ System drive C: has 65 GB free of 142 GB ---\\ Mode de connexion au système (3) - 0s ~ Computer Name: PC-DE-SOPHIE ~ User Name: Domi ~ Logged in as Administrator ---\\ Enumération des unités disques (2) - 0s ~ Drive C: has 65 GB free of 142 GB (System) ~ Drive D: has 1 GB free of 10 GB ---\\ Etat du Centre de Sécurité Windows (13) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoClose: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ---\\ Recherche particulière de fichiers génériques (23) - 1s [MD5.D07D4C3038F3578FFCE1C0237F2A1253] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\Windows\Explorer.exe [2926592] [MD5.4B555106290BD117334E9A08761C035A] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\Windows\System32\rundll32.exe [44544] [MD5.101BA3EA053480BB5D957EF37C06B5ED] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\Windows\System32\Wininit.exe [96768] [MD5.E38E89A0939A42F5EE4292DFC48772DF] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\Windows\System32\wininet.dll [1129472] [MD5.898E7C06A350D4A1A64A9EA264D55452] - (.Microsoft Corporation - Application d'ouverture de session Windows.) () -- C:\Windows\System32\Winlogon.exe [314368] [MD5.95F5FF73B076576C41740F1A842B9B57] - (.Microsoft Corporation - DLL client de l'API uilisateur de Windows m.) () -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] [MD5.F5272A105F59A7B3B345D9D6D87DA7AD] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\Windows\System32\drivers\AFD.sys [273408] [MD5.1F05B78AB91C9075565A9D8A4B880BC4] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\Windows\System32\drivers\atapi.sys [19944] [MD5.7ADD03E75BEB9E6DD102C3081D29840A] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\Windows\System32\drivers\Cdfs.sys [70144] [MD5.6B4BFFB9BECD728097024276430DB314] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\Windows\System32\drivers\Cdrom.sys [67072] [MD5.622C41A07CA7E6DD91770F50D532CB6C] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\Windows\System32\drivers\DfsC.sys [75264] [MD5.062452B7FFD68C8C042A6261FE8DFF4A] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\Windows\System32\drivers\HDAudBus.sys [561152] [MD5.22D56C8184586B7A1F6FA60BE5F5A2BD] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\Windows\System32\drivers\i8042prt.sys [54784] [MD5.8793643A67B42CEC66490B2A0CF92D68] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\Windows\System32\drivers\IpNat.sys [100864] [MD5.1E94971C4B446AB2290DEB71D01CF0C2] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\Windows\System32\drivers\MRxSmb.sys [106496] [MD5.ECD64230A59CBD93C85F1CD1CAB9F3F6] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\Windows\System32\drivers\netBT.sys [185856] [MD5.2C1121F2B87E9A6B12485DF53CD848C7] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\Windows\System32\drivers\ntfs.sys [1082232] [MD5.0FA9B5055484649D63C303FE404E5F4D] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\Windows\System32\drivers\Parport.sys [79360] [MD5.A214ADBAF4CB47DD2728859EF31F26B0] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\Windows\System32\drivers\Rasl2tp.sys [76288] [MD5.FBC0BACD9C3D7F6956853F64A66E252D] - (.Microsoft Corporation - Microsoft RDP Device redirector.) () -- C:\Windows\System32\drivers\rdpdr.sys [248832] [MD5.7B75299A4D201D6A6533603D6914AB04] - (.Microsoft Corporation - SMB Transport driver.) () -- C:\Windows\System32\drivers\smb.sys [66560] [MD5.76B06EB8A01FC8624D699E7045303E54] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\Windows\System32\drivers\tdx.sys [72192] [MD5.786DB5771F05EF300390399F626BF30A] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\Windows\System32\drivers\volsnap.sys [224640] ---\\ Processus lancés (7) - 7s [MD5.C832A3622A35CA7C595EA8CA385BA813] - (.Broadcom Corporation. - Bluetooth Support Server.) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [555560] [PID.584] [MD5.F96C429788350DB4BA6771C3034DFD88] - (.Teruten - FsUsbDevice.) -- C:\Windows\System32\FsUsbExService.Exe [217088] [PID.1440] [MD5.43DBA6069B3FA153FA68C30DE24CD341] - (.France Telecom SA - .) -- C:\Program Files\Common Files\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [65536] [PID.356] [MD5.2063D6B51FD874E67502B31A9FDBA685] - (.SoftThinks - STServices.) -- C:\Program Files\SMINST\BLService.exe [365952] [PID.2232] [MD5.6C4878F3483B959891408B804DE4475C] - (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1410344] [PID.2592] [MD5.BED38B0ADFF5F5CC6E988A6491017E83] - (.Research In Motion Limited - Launch Agent Service.) -- C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [267792] [PID.2652] [MD5.C8649EDF4955DE896A7AED515C932B09] - (.Synaptics, Inc. - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.3004] ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2) (3) - 0s G2 - GCE: Preference [User Data\Default] [jafdhbipfdlldljdanpnlipdinjcjjid] Portail Orange G2 - GCE: Preference [User Data\Default] [nfkdglgjjpicgkbfdflchobhdiblbjgf] Menu Contextuel Orange G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) (15) - 2s M0 - MFSP: prefs.js [Domi - w0hbv0us.default-1431618661383] https://fr-mg42.mail.yahoo.com/neo/launch?.rand=95tajsjeme521 P2 - EXT FILE: (...) -- C:\Users\Domi\AppData\Roaming\Mozilla\Firefox\Profiles\w0hbv0us.default-1431618661383\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-france.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay-france.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo-france.xml P2 - EXT: (.Mozilla - Default.) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} P2 - EXT: (.WOT Services Oy - WOT.) -- C:\Users\Domi\AppData\Roaming\Mozilla\Firefox\Profiles\w0hbv0us.default-1431618661383\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\NPSWF32_18_0_0_209.dll P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll P2 - FPN: [HKLM] [@RIM.com/WebSLLauncher,version=1.0] - (.Research In Motion.) -- C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) (15) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.bing.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://www.bing.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 1 ---\\ Internet Explorer, Proxy Management (R5) (4) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs (3) - 0s F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl" ---\\ Hosts file redirection (O1) (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (4) ---\\ Browser Helper Object de navigateur (BHO) (O2) (1) - 0s O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} . (.Orbiscom Ltd. All rights reserved. - FTO CMB.) -- C:\Windows\System32\BhoECart.dll ---\\ Applications lancées au démarrage du sytème (O4) (11) - 1s O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [QlbCtrl.exe] . (.Hewlett-Packard Development Company, L.P. - Quick Launch Buttons.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe O4 - HKLM\..\Run: [RIMBBLaunchAgent.exe] . (.Research In Motion Limited - Launch Agent Service.) -- C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe O4 - HKLM\..\Run: [HP Software Update] . (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Domi\AppData\Local\Google\Update\GoogleUpdate.exe O4 - HKUS\S-1-5-21-1768449568-3379944238-3116535841-1000\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Domi\AppData\Local\Google\Update\GoogleUpdate.exe ---\\ Modification Domaine/Adresses DNS (O17) (3) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS3\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 ---\\ Liste des services NT non Microsoft et non désactivés (O23) (6) - 1s O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Bluetooth Service (btwdins) . (.Broadcom Corporation. - Bluetooth Support Server.) - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe O23 - Service: FsUsbExService (FsUsbExService) . (.Teruten - FsUsbDevice.) - C:\Windows\System32\FsUsbExService.Exe O23 - Service: France Telecom Routing Table Service (FTRTSVC) . (.France Telecom SA - .) - C:\Program Files\Common Files\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: Recovery Service for Windows (Recovery Service for Windows) . (.SoftThinks - STServices.) - C:\Program Files\SMINST\BLService.exe ---\\ Tâches planifiées en automatique (O39) (16) - 9s O39 - APT: Orphean - (...) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002] O39 - APT: Orphean - (...) -- C:\Windows\Tasks\Driver Robot.job [456] O39 - APT: Orphean - (...) -- C:\Windows\Tasks\EDPLQYG1.job [328] O39 - APT: Orphean - (...) -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1768449568-3379944238-3116535841-1000Core.job [1022] O39 - APT: Orphean - (...) -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1768449568-3379944238-3116535841-1000UA.job [1074] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [3854] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [2770] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\CreateChoiceProcessTask [3162] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\Driver Robot [3236] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\EDPLQYG1 [2850] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1768449568-3379944238-3116535841-1000Core [3560] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1768449568-3379944238-3116535841-1000UA [3956] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\RAFZERK [3562] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\RunAsStdUser Task [3300] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{569012F3-360D-476F-9003-DF1A1E232A14} [3180] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{831583BE-F14F-41D0-80B3-46FDA9C199B0} [3042] ---\\ Logiciels installés (O42) (68) - 56s O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- Adobe AIR O42 - Logiciel: Adobe Flash Player 17 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Flash Player 18 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI O42 - Logiciel: BlackBerry Desktop Software 7.1 - (.Research In Motion Ltd..) [HKLM] -- BlackBerry_Desktop O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner O42 - Logiciel: Acrobat.com - (.Adobe Systems Incorporated.) [HKLM] -- com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- HDMI O42 - Logiciel: HP Photosmart Essential 2.01 - (.HP.) [HKLM] -- HP Photosmart Essential O42 - Logiciel: HP Print Projects 1.0 - (.HP.) [HKLM] -- HP Print Projects O42 - Logiciel: HP OCR Software 9.0 - (.HP.) [HKLM] -- HPOCR O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM] -- InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D} O42 - Logiciel: Power2Go - (.CyberLink Corp..) [HKLM] -- InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658} O42 - Logiciel: PowerDirector - (.CyberLink Corp..) [HKLM] -- InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1} O42 - Logiciel: IsoBuster 2.6 - (.Smart Projects.) [HKLM] -- IsoBuster_is1 O42 - Logiciel: Malwarebytes Anti-Malware version 2.1.8.1057 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1 O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client O42 - Logiciel: Mozilla Firefox 39.0 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 39.0 (x86 fr) O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService O42 - Logiciel: Picasa 3 - (.Google, Inc..) [HKLM] -- Picasa 3 O42 - Logiciel: Revo Uninstaller 1.95 - (.VS Revo Group.) [HKLM] -- Revo Uninstaller O42 - Logiciel: SFR - Kit de connexion - (.SFR.) [HKLM] -- SFR_Kit O42 - Logiciel: Shop for HP Supplies - (.HP.) [HKLM] -- Shop for HP Supplies O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics.) [HKLM] -- SynTPDeinstKey O42 - Logiciel: Virtualis Crédit Mutuel - (...) [HKLM] -- Virtualis Crédit Mutuel O42 - Logiciel: WinRAR 4.20 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM] -- {01FB4998-33C4-4431-85ED-079E3EEFE75D} O42 - Logiciel: JavaFX 2.1.1 - (.Oracle Corporation.) [HKLM] -- {1111706F-666A-4037-7777-211328764D10} O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM] -- {2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3} O42 - Logiciel: OpenOffice.org 3.4 - (.OpenOffice.org.) [HKLM] -- {2F90A789-DD1E-41CE-BFCA-BD78213BABC7} O42 - Logiciel: Microsoft Antimalware Service FR-FR Language Pack - (.Microsoft Corporation.) [HKLM] -- {32E9C1A5-0FDA-4483-987D-DBABF9CC1DD8} O42 - Logiciel: HP Quick Launch Buttons 6.40 M1 - (.Hewlett-Packard.) [HKLM] -- {34D2AB40-150D-475D-AE32-BD23FB5EE355} O42 - Logiciel: ESU for Microsoft Vista - (.Hewlett-Packard.) [HKLM] -- {3877C901-7B90-4727-A639-B6ED2DD59D43} O42 - Logiciel: Microsoft Works - (.Microsoft Corporation.) [HKLM] -- {3B160861-7250-451E-B5EE-8B92BF30A710} O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM] -- {3F4BA3A2-7BE0-48EA-B4BC-CA4D842A409A} O42 - Logiciel: Power2Go - (.CyberLink Corp..) [HKLM] -- {40BF1E83-20EB-11D8-97C5-0009C5020658} O42 - Logiciel: Ma-Config.com - (.Cybelsoft.) [HKLM] -- {425FFD94-36BD-4933-881B-FE0B9DADF2B7} O42 - Logiciel: Microsoft Security Client FR-FR Language Pack - (.Microsoft Corporation.) [HKLM] -- {50779A29-834E-4E36-BBEB-B7CABC67A825} O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- {52E225FC-FCB4-41F7-837B-6E37FB05BD7B} O42 - Logiciel: swMSM - (.Adobe Systems, Inc.) [HKLM] -- {612C34C7-5E90-47D8-9B5C-0F717DD82726} O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {6E3939AE-9996-4D07-9A30-14C78AE93576} O42 - Logiciel: Paint.NET v3.5.11 - (.dotPDN LLC.) [HKLM] -- {72EF03F5-0507-4861-9A44-D99FD4C41417} O42 - Logiciel: HP Common Access Service Library - (.Hewlett-Packard.) [HKLM] -- {732A3F80-008B-4350-BD58-EC5AE98707B8} O42 - Logiciel: Acrobat.com - (.Adobe Systems Incorporated.) [HKLM] -- {77DCDCE3-2DED-62F3-8154-05E745472D07} O42 - Logiciel: HP Deskjet F2400 All-in-One Driver 14.0 Rel. 6 - (.HP.) [HKLM] -- {819CA3BC-2FF8-4811-B42F-421F7BFD3559} O42 - Logiciel: HPDiagnosticAlert - (.Microsoft.) [HKLM] -- {846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE} O42 - Logiciel: VC80CRTRedist - 8.0.50727.6195 - (.DivX, Inc.) [HKLM] -- {933B4015-4618-4716-A828-5289FC03165F} O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {934B3B19-8193-467A-B356-E73F82647D38} O42 - Logiciel: ArcSoft Panorama Maker 3 - (.ArcSoft.) [HKLM] -- {A5F68DC8-0278-4AD8-B413-861509B5F25B} O42 - Logiciel: 32 Bit HP CIO Components Installer - (.Hewlett-Packard.) [HKLM] -- {A80FA752-C491-4ED9-ABF0-4278563160B2} O42 - Logiciel: Software Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} O42 - Logiciel: Adobe Reader X (10.1.4) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AA1000000001} O42 - Logiciel: Adobe Shockwave Player - (.Adobe Systems, Inc..) [HKLM] -- {AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11} O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {B67BAFBA-4C9F-48FA-9496-933E3B255044} O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {BAD1449B-DF0C-4118-B76D-68C54009576C} O42 - Logiciel: BlackBerry Desktop Software 7.1 - (.Research In Motion Ltd..) [HKLM] -- {BE5B0450-DCCB-4FE9-93E2-3B38D88A745B} O42 - Logiciel: Atheros Driver Installation Program - (.Atheros.) [HKLM] -- {C3A32068-8AB1-4327-BB16-BED9C6219DC7} O42 - Logiciel: Microsoft Automated Troubleshooting Services Shim - (...) [HKLM] -- {c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb O42 - Logiciel: PowerDirector - (.CyberLink Corp..) [HKLM] -- {CB099890-1D5F-11D5-9EA9-0050BAE317E1} O42 - Logiciel: Windows 7 USB/DVD Download Tool - (.Microsoft Corporation.) [HKLM] -- {CCF298AF-9CE1-4B26-B251-486E98A34789} O42 - Logiciel: Nikon Message Center - (...) [HKLM] -- {D2FCC1AE-6311-47C5-8130-C6C66D77DD71} O42 - Logiciel: HP Photosmart All-In-One Software 9.0 - (.HP.) [HKLM] -- {D64BC2CF-0F12-47d7-B412-B4F3FD684253} O42 - Logiciel: WIDCOMM Bluetooth Software 6.2.0.5800 - (.Broadcom Corporation.) [HKLM] -- {E464702F-5433-46EC-8F65-159276C0A54F} O42 - Logiciel: PHOTOfunSTUDIO 8.0 LE - (.Panasonic Corporation.) [HKLM] -- {EF8D221C-9346-4FAA-8482-B0CF76773ABF} O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {F5266D28-E0B2-4130-BFC5-EE155AD514DC} O42 - Logiciel: PictureProject - (...) [HKLM] -- {FF3999BE-1A7B-4738-88AA-97BF14094A4A} O42 - Logiciel: Google Chrome - (.Google Inc..) [HKCU] -- Google Chrome O42 - Logiciel: MyFreeCodec - (...) [HKCU] -- MyFreeCodec O42 - Logiciel: µTorrent - (...) [HKCU] -- uTorrent ---\\ HKCU & HKLM Software Keys (188) - 56s HKLM\SOFTWARE\Adobe HKLM\SOFTWARE\AdwCleaner HKLM\SOFTWARE\AppDataLow HKLM\SOFTWARE\Apple Computer, Inc. HKLM\SOFTWARE\Apple Inc. HKLM\SOFTWARE\ArcSoft HKLM\SOFTWARE\Atheros HKLM\SOFTWARE\BrowserChoice HKLM\SOFTWARE\CDex HKLM\SOFTWARE\cybelsoft HKLM\SOFTWARE\Cyberlink HKLM\SOFTWARE\Data fellows HKLM\SOFTWARE\Debug HKLM\SOFTWARE\DevNet HKLM\SOFTWARE\DivX HKLM\SOFTWARE\DivXNetworks HKLM\SOFTWARE\Driver Robot HKLM\SOFTWARE\EasyBits HKLM\SOFTWARE\Electronic Arts HKLM\SOFTWARE\Extended Systems HKLM\SOFTWARE\FRANCE TELECOM HKLM\SOFTWARE\Google HKLM\SOFTWARE\GPL Ghostscript HKLM\SOFTWARE\Hewlett-Packard HKLM\SOFTWARE\HP HKLM\SOFTWARE\HPQ HKLM\SOFTWARE\ICE HKLM\SOFTWARE\InstalledOptions HKLM\SOFTWARE\InstallShield HKLM\SOFTWARE\Intel HKLM\SOFTWARE\JavaSoft HKLM\SOFTWARE\JreMetrics HKLM\SOFTWARE\Licenses HKLM\SOFTWARE\LightScribe HKLM\SOFTWARE\LucasArts HKLM\SOFTWARE\Macromedia HKLM\SOFTWARE\Malwarebytes' Anti-Malware HKLM\SOFTWARE\Malwarebytes' Anti-Malware (Trial) HKLM\SOFTWARE\MimarSinan HKLM\SOFTWARE\Mount&Blade Warband HKLM\SOFTWARE\Mozilla HKLM\SOFTWARE\mozilla.org HKLM\SOFTWARE\MozillaPlugins HKLM\SOFTWARE\Neuf HKLM\SOFTWARE\Nikon HKLM\SOFTWARE\ODBC HKLM\SOFTWARE\OldTimer Tools HKLM\SOFTWARE\OpenOffice.org HKLM\SOFTWARE\Oracle HKLM\SOFTWARE\Orange HKLM\SOFTWARE\Overwolf HKLM\SOFTWARE\P2G_Upgrade HKLM\SOFTWARE\Paint.NET HKLM\SOFTWARE\Panasonic HKLM\SOFTWARE\PDR_Upgrade HKLM\SOFTWARE\Piriform HKLM\SOFTWARE\pixology HKLM\SOFTWARE\Realtek HKLM\SOFTWARE\RegisteredApplications HKLM\SOFTWARE\Research In Motion HKLM\SOFTWARE\RTLSetup HKLM\SOFTWARE\Samsung HKLM\SOFTWARE\SecureDigitalServices HKLM\SOFTWARE\Skype HKLM\SOFTWARE\Software HKLM\SOFTWARE\Sun Microsystems HKLM\SOFTWARE\Synaptics HKLM\SOFTWARE\Synthesia HKLM\SOFTWARE\TeamViewer HKLM\SOFTWARE\Thomson HKLM\SOFTWARE\Trad-FR HKLM\SOFTWARE\Trolltech HKLM\SOFTWARE\Turbine HKLM\SOFTWARE\Volatile HKLM\SOFTWARE\webtogo HKLM\SOFTWARE\Widcomm HKLM\SOFTWARE\Windows HKLM\SOFTWARE\WinRAR HKLM\SOFTWARE\Yahoo HKCU\SOFTWARE\1C HKCU\SOFTWARE\AC3Filter HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\AlterGeo HKCU\SOFTWARE\AOL HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\Apple Computer, Inc. HKCU\SOFTWARE\Apple Inc. HKCU\SOFTWARE\Badoo HKCU\SOFTWARE\Binary Noise HKCU\SOFTWARE\BitTorrent HKCU\SOFTWARE\Blizzard Entertainment HKCU\SOFTWARE\Bugsplat HKCU\SOFTWARE\Chromium HKCU\SOFTWARE\Classes.crx HKCU\SOFTWARE\ClassesB HKCU\SOFTWARE\CoinisRevShare HKCU\SOFTWARE\ComNotificationV13.05 HKCU\SOFTWARE\CTPW Data HKCU\SOFTWARE\cybelsoft HKCU\SOFTWARE\CyberLink HKCU\SOFTWARE\DevNet HKCU\SOFTWARE\DivXNetworks HKCU\SOFTWARE\EasyBits HKCU\SOFTWARE\Electronic Arts HKCU\SOFTWARE\Extended Systems HKCU\SOFTWARE\FRANCE TELECOM HKCU\SOFTWARE\Games HKCU\SOFTWARE\GameSpy HKCU\SOFTWARE\GoldenGate HKCU\SOFTWARE\Google HKCU\SOFTWARE\Hewlett-Packard HKCU\SOFTWARE\HookNetwork HKCU\SOFTWARE\HP HKCU\SOFTWARE\Hs4ktZma8Sb HKCU\SOFTWARE\IADirectShow HKCU\SOFTWARE\IM Providers HKCU\SOFTWARE\ImageViewer HKCU\SOFTWARE\ImgBurn HKCU\SOFTWARE\Intel HKCU\SOFTWARE\InterVideo HKCU\SOFTWARE\Iris HKCU\SOFTWARE\JavaSoft HKCU\SOFTWARE\JEDI-VCL HKCU\SOFTWARE\kde.org HKCU\SOFTWARE\keyhole.com HKCU\SOFTWARE\Licenses HKCU\SOFTWARE\LightScribe HKCU\SOFTWARE\Local AppWizard-Generated Applications HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\MainConcept HKCU\SOFTWARE\Malwarebytes' Anti-Malware HKCU\SOFTWARE\Mediachance HKCU\SOFTWARE\MimarSinan HKCU\SOFTWARE\Mirage HKCU\SOFTWARE\MountAndBladeWarbandKeys HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\Nikon HKCU\SOFTWARE\OB HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\OpenOffice.org HKCU\SOFTWARE\Opera Software HKCU\SOFTWARE\Paint.NET HKCU\SOFTWARE\Panasonic HKCU\SOFTWARE\Patchou HKCU\SOFTWARE\Petroglyph HKCU\SOFTWARE\Piriform HKCU\SOFTWARE\Pvm HKCU\SOFTWARE\QtProject HKCU\SOFTWARE\Research In Motion HKCU\SOFTWARE\ROBLOX Corporation HKCU\SOFTWARE\RRx4T3rw2UR2fgmf HKCU\SOFTWARE\Samsung HKCU\SOFTWARE\SecuROM HKCU\SOFTWARE\Skype HKCU\SOFTWARE\Smart Projects HKCU\SOFTWARE\SOFT32 HKCU\SOFTWARE\Softthinks HKCU\SOFTWARE\Software HKCU\SOFTWARE\SuperSoftwarePackage HKCU\SOFTWARE\Synaptics HKCU\SOFTWARE\Synthesia HKCU\SOFTWARE\TeamViewer HKCU\SOFTWARE\TeleCharger HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\Unity HKCU\SOFTWARE\VSRevoGroup HKCU\SOFTWARE\Wargaming.net HKCU\SOFTWARE\Widcomm HKCU\SOFTWARE\Winamp HKCU\SOFTWARE\WinRAR HKCU\SOFTWARE\WinRAR SFX HKCU\SOFTWARE\Yahoo HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Aurigma HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\Adobe HKCU\SOFTWARE\AppDataLow\Software\Amazon HKCU\SOFTWARE\AppDataLow\Software\Google HKCU\SOFTWARE\AppDataLow\Software\JavaSoft HKCU\SOFTWARE\AppDataLow\Software\Macromedia HKCU\SOFTWARE\AppDataLow\Software\MarkAny HKCU\SOFTWARE\AppDataLow\Software\Monitored HKCU\SOFTWARE\AppDataLow\Software\Orange HKCU\SOFTWARE\AppDataLow\Software\settings HKCU\SOFTWARE\AppDataLow\Software\Unity HKCU\SOFTWARE\AppDataLow\Software\Yahoo ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) (317) - 153s O43 - CFD: 2015/05/14 21:08:19 - [0] D -- C:\Program Files\13c0c15a-7b86-4a21-b72b-22bb68b6e93f =>PUP.Optional.CrossRider O43 - CFD: 2015/05/14 21:08:19 - [0] D -- C:\Program Files\450c05ba-477a-44b0-bcc7-f474e2d95235 =>PUP.Optional.CrossRider O43 - CFD: 2015/05/14 21:08:19 - [0] D -- C:\Program Files\8fe2edcd-623c-40b1-ad3f-f290027245f7 =>PUP.Optional.CrossRider O43 - CFD: 2015/05/14 21:08:19 - [] D -- C:\Program Files\Adobe O43 - CFD: 2015/05/14 13:23:36 - [] D -- C:\Program Files\Adobe(0) O43 - CFD: 2010/07/19 10:29:50 - [] D -- C:\Program Files\Alwil Software O43 - CFD: 2009/10/24 10:39:08 - [] D -- C:\Program Files\ArcSoft O43 - CFD: 2012/02/29 23:59:23 - [] D -- C:\Program Files\Atheros O43 - CFD: 2013/07/15 14:16:10 - [] D -- C:\Program Files\CCleaner O43 - CFD: 2009/10/24 09:31:09 - [] D -- C:\Program Files\Cisco O43 - CFD: 2015/05/15 23:18:59 - [] D -- C:\Program Files\Common Files O43 - CFD: 2009/10/24 10:39:13 - [] D -- C:\Program Files\CyberLink O43 - CFD: 2013/07/03 09:31:57 - [0] D -- C:\Program Files\DevNet O43 - CFD: 2014/10/06 12:09:07 - [0] D -- C:\Program Files\EA Games O43 - CFD: 2009/06/06 14:16:41 - [0] SHD -- C:\Program Files\Fichiers communs O43 - CFD: 2012/09/02 16:44:05 - [] D -- C:\Program Files\Google O43 - CFD: 2011/06/21 11:26:49 - [] D -- C:\Program Files\GPLGS O43 - CFD: 2012/09/03 08:33:27 - [] D -- C:\Program Files\Hewlett-Packard O43 - CFD: 2013/07/03 09:31:03 - [] D -- C:\Program Files\Hosts_Anti_Adwares_PUPs O43 - CFD: 2012/09/18 12:07:47 - [] D -- C:\Program Files\HP O43 - CFD: 2015/05/15 23:16:07 - [] HD -- C:\Program Files\InstallShield Installation Information O43 - CFD: 2010/02/01 22:28:09 - [] D -- C:\Program Files\Intel O43 - CFD: 2012/03/02 16:47:16 - [0] D -- C:\Program Files\InterActual O43 - CFD: 2015/05/17 07:21:57 - [] D -- C:\Program Files\Internet Explorer O43 - CFD: 2009/06/07 12:17:59 - [] D -- C:\Program Files\Inventel O43 - CFD: 2014/10/06 11:55:14 - [] D -- C:\Program Files\Java O43 - CFD: 2012/04/24 10:56:29 - [0] D -- C:\Program Files\LucasArts O43 - CFD: 2009/10/24 13:00:34 - [] D -- C:\Program Files\ma-config.com O43 - CFD: 2015/08/04 17:02:47 - [] D -- C:\Program Files\Malwarebytes Anti-Malware O43 - CFD: 2010/12/29 12:03:35 - [] D -- C:\Program Files\MarkAny O43 - CFD: 2011/01/31 09:31:40 - [] D -- C:\Program Files\Messenger Plus! Live O43 - CFD: 2013/07/03 09:59:33 - [0] D -- C:\Program Files\Microsoft O43 - CFD: 2012/09/06 09:34:40 - [] D -- C:\Program Files\Microsoft ATS O43 - CFD: 2006/11/02 14:35:51 - [] D -- C:\Program Files\Microsoft Games O43 - CFD: 2011/10/07 09:25:42 - [] D -- C:\Program Files\Microsoft Office O43 - CFD: 2013/02/16 17:55:34 - [0] D -- C:\Program Files\Microsoft Office 15 O43 - CFD: 2015/05/14 06:14:43 - [] D -- C:\Program Files\Microsoft Security Client O43 - CFD: 2015/05/14 14:35:08 - [0] D -- C:\Program Files\Microsoft Silverlight O43 - CFD: 2012/12/24 09:01:12 - [] D -- C:\Program Files\Microsoft SQL Server Compact Edition O43 - CFD: 2009/10/22 15:47:32 - [] D -- C:\Program Files\Microsoft Sync Framework O43 - CFD: 2012/12/24 09:01:12 - [] D -- C:\Program Files\Microsoft Synchronization Services O43 - CFD: 2009/11/13 11:14:22 - [] D -- C:\Program Files\Microsoft Visual Studio O43 - CFD: 2012/10/10 05:35:59 - [] D -- C:\Program Files\Microsoft Works O43 - CFD: 2012/09/18 15:30:25 - [] D -- C:\Program Files\Microsoft.NET O43 - CFD: 2010/08/13 06:44:38 - [] D -- C:\Program Files\Movie Maker O43 - CFD: 2015/07/04 08:33:32 - [] D -- C:\Program Files\Mozilla Firefox O43 - CFD: 2015/07/04 08:33:32 - [] D -- C:\Program Files\Mozilla Maintenance Service O43 - CFD: 2006/11/02 14:35:51 - [] D -- C:\Program Files\MSBuild O43 - CFD: 2012/08/16 18:10:33 - [] D -- C:\Program Files\MyFree Codec O43 - CFD: 2009/06/06 14:19:43 - [] RD -- C:\Program Files\Online Services O43 - CFD: 2013/04/08 17:53:19 - [] D -- C:\Program Files\OpenOffice.org 3 O43 - CFD: 2015/05/14 12:14:03 - [0] D -- C:\Program Files\Opera O43 - CFD: 2012/07/03 17:17:13 - [] D -- C:\Program Files\Oracle O43 - CFD: 2014/10/06 12:04:58 - [] D -- C:\Program Files\Orange O43 - CFD: 2011/10/01 20:45:23 - [] D -- C:\Program Files\OrangeHSS O43 - CFD: 2013/08/20 18:52:15 - [] D -- C:\Program Files\Paint.NET O43 - CFD: 2012/12/24 09:01:21 - [] D -- C:\Program Files\Panasonic O43 - CFD: 2012/04/08 09:38:03 - [] D -- C:\Program Files\Pando Networks O43 - CFD: 2012/08/16 14:30:46 - [0] D -- C:\Program Files\PC Connectivity Solution O43 - CFD: 2012/07/27 20:56:43 - [] D -- C:\Program Files\Picasa2 O43 - CFD: 2010/05/01 15:25:27 - [] D -- C:\Program Files\Pvm O43 - CFD: 2013/06/27 17:13:28 - [] D -- C:\Program Files\QuickTime O43 - CFD: 2015/05/15 23:15:02 - [0] D -- C:\Program Files\Realtek O43 - CFD: 2006/11/02 14:35:51 - [] D -- C:\Program Files\Reference Assemblies O43 - CFD: 2012/08/23 20:41:13 - [] D -- C:\Program Files\Research In Motion O43 - CFD: 2012/09/18 16:13:01 - [] D -- C:\Program Files\Samsung O43 - CFD: 2012/02/29 22:01:13 - [] D -- C:\Program Files\SearchGBY O43 - CFD: 2009/10/24 10:54:01 - [] D -- C:\Program Files\Securitoo O43 - CFD: 2015/05/14 10:28:15 - [0] D -- C:\Program Files\setup O43 - CFD: 2014/01/28 09:59:55 - [] D -- C:\Program Files\SFR O43 - CFD: 2009/11/11 15:41:01 - [] D -- C:\Program Files\Smart Projects O43 - CFD: 2012/09/05 09:04:00 - [] D -- C:\Program Files\SMINST O43 - CFD: 2015/05/14 09:36:12 - [] D -- C:\Program Files\Software =>PUP.Optional.Boxore O43 - CFD: 2009/10/24 10:39:34 - [] D -- C:\Program Files\Synaptics O43 - CFD: 2014/04/02 15:49:14 - [] D -- C:\Program Files\TeamViewer O43 - CFD: 2012/04/08 17:34:54 - [] D -- C:\Program Files\Turbine O43 - CFD: 2006/11/02 14:58:18 - [0] HD -- C:\Program Files\Uninstall Information O43 - CFD: 2010/04/27 17:24:30 - [] D -- C:\Program Files\uTorrent O43 - CFD: 2013/07/03 08:48:54 - [0] D -- C:\Program Files\VideoLAN O43 - CFD: 2009/12/14 15:28:31 - [] D -- C:\Program Files\Virtualis O43 - CFD: 2014/10/06 11:44:56 - [] D -- C:\Program Files\VS Revo Group O43 - CFD: 2012/07/03 17:06:18 - [] D -- C:\Program Files\WIDCOMM O43 - CFD: 2010/02/10 22:30:37 - [] D -- C:\Program Files\Windows Calendar O43 - CFD: 2010/02/10 22:30:37 - [] D -- C:\Program Files\Windows Collaboration O43 - CFD: 2010/02/10 22:30:30 - [] D -- C:\Program Files\Windows Defender O43 - CFD: 2014/04/06 12:48:32 - [] D -- C:\Program Files\Windows Live O43 - CFD: 2012/04/12 12:06:06 - [] D -- C:\Program Files\Windows Mail O43 - CFD: 2015/08/02 22:37:02 - [] D -- C:\Program Files\Windows Media Player O43 - CFD: 2009/06/06 14:16:41 - [] D -- C:\Program Files\Windows NT O43 - CFD: 2010/02/10 22:30:36 - [] D -- C:\Program Files\Windows Photo Gallery O43 - CFD: 2010/02/12 04:19:38 - [] D -- C:\Program Files\Windows Portable Devices O43 - CFD: 2010/02/10 22:30:37 - [] D -- C:\Program Files\Windows Sidebar O43 - CFD: 2013/02/18 22:24:40 - [] D -- C:\Program Files\WinRAR O43 - CFD: 2011/04/23 09:49:11 - [] D -- C:\Program Files\Yahoo! O43 - CFD: 2015/05/15 23:25:14 - [] D -- C:\Program Files\ZHPDiag O43 - CFD: 2012/08/07 09:49:23 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2012/04/08 18:04:05 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2009/10/24 10:39:39 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft Panorama Maker 3 O43 - CFD: 2013/05/07 16:10:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry O43 - CFD: 2012/07/03 17:07:24 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDex O43 - CFD: 2008/01/21 04:56:27 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Extras and Upgrades O43 - CFD: 2014/11/15 23:38:42 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 2012/09/18 12:09:10 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP O43 - CFD: 2009/06/07 12:18:18 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Livebox O43 - CFD: 2012/04/22 09:59:14 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LucasArts O43 - CFD: 2009/10/25 09:38:37 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ma-config.com O43 - CFD: 2006/11/02 14:52:53 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2015/05/16 07:11:27 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office O43 - CFD: 2012/10/10 05:36:00 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works O43 - CFD: 2012/08/16 18:10:34 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec O43 - CFD: 2009/06/30 18:46:00 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nikon FotoShare O43 - CFD: 2009/06/06 14:19:43 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services O43 - CFD: 2013/04/08 17:53:19 - [] SD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.4 O43 - CFD: 2012/12/24 09:01:50 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panasonic O43 - CFD: 2009/07/29 15:07:14 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3 O43 - CFD: 2009/06/30 18:46:44 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PictureProject O43 - CFD: 2010/05/01 15:25:27 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pvm O43 - CFD: 2013/06/27 17:13:23 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime O43 - CFD: 2009/02/26 23:44:58 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery Manager O43 - CFD: 2009/06/06 14:19:40 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Services en ligne O43 - CFD: 2014/01/28 10:00:10 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SFR O43 - CFD: 2009/11/11 15:41:03 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Projects O43 - CFD: 2015/06/10 13:18:47 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 2012/07/03 17:10:03 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Synthesia O43 - CFD: 2013/02/18 22:24:50 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 2015/05/16 08:21:41 - [0] D -- C:\ProgramData\18b7a06c9f5a43a4b293b8ab47ed27ff O43 - CFD: 2015/05/14 09:46:05 - [] D -- C:\ProgramData\7c0535b143fc4671b6ebd202fbffe066 O43 - CFD: 2015/05/16 08:21:45 - [] D -- C:\ProgramData\acnExVZ O43 - CFD: 2013/08/02 10:08:21 - [] D -- C:\ProgramData\Adobe O43 - CFD: 2011/12/26 19:30:00 - [0] D -- C:\ProgramData\Alwil Software O43 - CFD: 2012/09/02 16:19:38 - [] D -- C:\ProgramData\Apple O43 - CFD: 2013/06/27 17:12:44 - [] D -- C:\ProgramData\Apple Computer O43 - CFD: 2006/11/02 14:59:44 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 2009/03/18 04:42:49 - [] D -- C:\ProgramData\Atheros O43 - CFD: 2010/02/01 22:35:08 - [] D -- C:\ProgramData\Blizzard O43 - CFD: 2009/06/06 14:16:41 - [0] SHD -- C:\ProgramData\Bureau O43 - CFD: 2012/04/23 21:47:55 - [] HD -- C:\ProgramData\Common Files O43 - CFD: 2009/11/22 20:12:11 - [] D -- C:\ProgramData\CyberLink O43 - CFD: 2006/11/02 14:59:44 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 2012/09/02 16:33:41 - [] D -- C:\ProgramData\DivX O43 - CFD: 2006/11/02 14:59:44 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 2012/09/23 07:53:19 - [] D -- C:\ProgramData\Downloaded Installations O43 - CFD: 2009/06/07 16:45:25 - [] D -- C:\ProgramData\EBP O43 - CFD: 2011/12/20 16:20:44 - [] D -- C:\ProgramData\f-secure O43 - CFD: 2009/06/06 14:16:41 - [0] SHD -- C:\ProgramData\Favoris O43 - CFD: 2006/11/02 14:59:44 - [0] SHD -- C:\ProgramData\Favorites O43 - CFD: 2012/02/27 11:08:51 - [] D -- C:\ProgramData\Google =>PUP.Optional.Gen O43 - CFD: 2014/10/06 12:03:13 - [0] D -- C:\ProgramData\HappyCloud O43 - CFD: 2009/06/07 17:19:24 - [] D -- C:\ProgramData\Hewlett-Packard O43 - CFD: 2012/09/18 12:08:35 - [] D -- C:\ProgramData\HP O43 - CFD: 2009/09/30 07:58:07 - [] D -- C:\ProgramData\HP Product Assistant O43 - CFD: 2009/10/24 13:00:31 - [] D -- C:\ProgramData\ma-config.com O43 - CFD: 2014/10/01 09:11:42 - [] D -- C:\ProgramData\Malwarebytes O43 - CFD: 2012/08/31 14:03:53 - [] D -- C:\ProgramData\McAfee O43 - CFD: 2009/06/06 14:16:41 - [0] SHD -- C:\ProgramData\Menu Démarrer O43 - CFD: 2014/04/06 12:40:31 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 2015/05/17 07:34:34 - [] D -- C:\ProgramData\Microsoft Help O43 - CFD: 2009/06/06 14:16:41 - [0] SHD -- C:\ProgramData\Modèles O43 - CFD: 2012/07/04 19:29:53 - [] D -- C:\ProgramData\Mozilla O43 - CFD: 2012/07/05 09:49:40 - [] D -- C:\ProgramData\Norton O43 - CFD: 2012/07/04 22:24:54 - [] D -- C:\ProgramData\NortonInstaller O43 - CFD: 2014/10/06 10:59:18 - [0] D -- C:\ProgramData\Oracle O43 - CFD: 2014/03/13 08:19:11 - [0] D -- C:\ProgramData\Orange O43 - CFD: 2012/12/24 09:07:26 - [] D -- C:\ProgramData\Panasonic O43 - CFD: 2009/07/07 18:22:26 - [] D -- C:\ProgramData\QuickTime O43 - CFD: 2012/08/23 21:11:27 - [] D -- C:\ProgramData\Research In Motion O43 - CFD: 2013/07/17 14:58:59 - [] D -- C:\ProgramData\Samsung O43 - CFD: 2014/10/04 14:19:00 - [] D -- C:\ProgramData\Skype O43 - CFD: 2006/11/02 14:59:44 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 2010/05/18 15:39:58 - [] D -- C:\ProgramData\Sun O43 - CFD: 2011/05/03 08:48:39 - [] D -- C:\ProgramData\Symantec O43 - CFD: 2009/03/18 05:16:51 - [] D -- C:\ProgramData\Temp O43 - CFD: 2006/11/02 14:59:44 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 2013/06/02 05:39:53 - [0] D -- C:\ProgramData\Turbine O43 - CFD: 2009/11/04 17:53:54 - [] D -- C:\ProgramData\UAB O43 - CFD: 2010/10/29 06:24:32 - [] D -- C:\ProgramData\VirtualizedApplications O43 - CFD: 2013/10/24 09:40:15 - [] D -- C:\ProgramData\VS Revo Group O43 - CFD: 2009/09/30 08:02:29 - [] D -- C:\ProgramData\WEBREG O43 - CFD: 2009/11/08 16:39:33 - [] D -- C:\ProgramData\WildTangent O43 - CFD: 2013/01/13 18:03:43 - [] D -- C:\ProgramData\WindowsSearch O43 - CFD: 2009/09/25 07:32:34 - [] D -- C:\ProgramData\WLInstaller O43 - CFD: 2011/04/23 09:45:47 - [0] D -- C:\ProgramData\Yahoo! O43 - CFD: 2012/08/30 14:15:35 - [] D -- C:\ProgramData\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A} O43 - CFD: 2010/03/11 22:14:55 - [] D -- C:\ProgramData\{dd9a9e7625afb6d9307f2cd8e4c1abd8} O43 - CFD: 2013/07/12 12:21:32 - [] D -- C:\Program Files\Common Files\Adobe O43 - CFD: 2013/11/14 22:48:55 - [] D -- C:\Program Files\Common Files\Adobe AIR O43 - CFD: 2010/10/07 08:38:10 - [] D -- C:\Program Files\Common Files\Adobe(6) O43 - CFD: 2012/09/02 16:19:54 - [] D -- C:\Program Files\Common Files\Apple O43 - CFD: 2011/06/23 13:27:58 - [0] D -- C:\Program Files\Common Files\Blizzard Entertainment O43 - CFD: 2014/05/14 08:02:13 - [] D -- C:\Program Files\Common Files\DESIGNER O43 - CFD: 2009/10/29 12:20:25 - [] D -- C:\Program Files\Common Files\France Telecom O43 - CFD: 2009/06/07 17:08:46 - [] D -- C:\Program Files\Common Files\Hewlett-Packard O43 - CFD: 2009/06/07 17:09:39 - [] D -- C:\Program Files\Common Files\HP O43 - CFD: 2012/02/07 20:54:16 - [] D -- C:\Program Files\Common Files\InstallShield O43 - CFD: 2009/10/24 10:46:24 - [] D -- C:\Program Files\Common Files\LightScribe O43 - CFD: 2014/04/06 12:39:39 - [] D -- C:\Program Files\Common Files\microsoft shared O43 - CFD: 2009/06/30 18:36:00 - [] D -- C:\Program Files\Common Files\Nikon O43 - CFD: 2012/12/24 09:01:47 - [] D -- C:\Program Files\Common Files\Panasonic O43 - CFD: 2012/09/02 16:33:35 - [] D -- C:\Program Files\Common Files\PX Storage Engine O43 - CFD: 2012/12/18 12:53:54 - [] D -- C:\Program Files\Common Files\Research In Motion O43 - CFD: 2010/12/29 12:04:02 - [] D -- C:\Program Files\Common Files\Samsung O43 - CFD: 2006/11/02 13:18:33 - [] D -- C:\Program Files\Common Files\Services O43 - CFD: 2006/11/02 13:18:33 - [] D -- C:\Program Files\Common Files\SpeechEngines O43 - CFD: 2013/02/27 18:42:59 - [] D -- C:\Program Files\Common Files\Steam O43 - CFD: 2012/07/11 09:09:06 - [] D -- C:\Program Files\Common Files\System O43 - CFD: 2009/10/06 15:29:15 - [] D -- C:\Program Files\Common Files\Windows Live O43 - CFD: 2009/09/25 07:35:11 - [] SHDC -- C:\Program Files\Common Files\WindowsLiveInstaller O43 - CFD: 2012/08/23 21:11:28 - [] D -- C:\Program Files\Common Files\XCPCSync.OEM O43 - CFD: 2008/01/01 18:04:26 - [] D -- C:\Users\Domi\AppData\Roaming\.minecraft O43 - CFD: 2014/01/25 16:12:00 - [] D -- C:\Users\Domi\AppData\Roaming\.mono O43 - CFD: 2015/05/16 08:21:45 - [0] D -- C:\Users\Domi\AppData\Roaming\39464E43-1431604033-5230-485A-00238B8ED55A O43 - CFD: 2013/07/16 16:02:48 - [] D -- C:\Users\Domi\AppData\Roaming\Adobe O43 - CFD: 2012/09/03 06:48:46 - [] D -- C:\Users\Domi\AppData\Roaming\Apple Computer O43 - CFD: 2012/09/05 07:30:24 - [0] D -- C:\Users\Domi\AppData\Roaming\avg O43 - CFD: 2012/08/23 20:56:59 - [] D -- C:\Users\Domi\AppData\Roaming\Blackberry Desktop O43 - CFD: 2009/10/24 12:37:11 - [] D -- C:\Users\Domi\AppData\Roaming\Blitware O43 - CFD: 2013/11/14 22:49:06 - [] D -- C:\Users\Domi\AppData\Roaming\com.zoosk.Desktop O43 - CFD: 2013/11/14 22:49:06 - [] D -- C:\Users\Domi\AppData\Roaming\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1 O43 - CFD: 2009/06/17 18:21:44 - [] D -- C:\Users\Domi\AppData\Roaming\CyberLink O43 - CFD: 2008/01/01 18:04:26 - [] D -- C:\Users\Domi\AppData\Roaming\dvdcss O43 - CFD: 2015/02/28 18:22:26 - [] HD -- C:\Users\Domi\AppData\Roaming\GoldenGate O43 - CFD: 2009/07/07 13:53:38 - [] D -- C:\Users\Domi\AppData\Roaming\Google O43 - CFD: 2009/10/24 08:48:55 - [] D -- C:\Users\Domi\AppData\Roaming\GTek O43 - CFD: 2009/06/06 14:25:05 - [] D -- C:\Users\Domi\AppData\Roaming\hewlett-packard O43 - CFD: 2009/09/30 08:02:29 - [] D -- C:\Users\Domi\AppData\Roaming\HP O43 - CFD: 2009/06/06 14:19:46 - [] D -- C:\Users\Domi\AppData\Roaming\HP TCS O43 - CFD: 2013/07/31 09:44:21 - [] D -- C:\Users\Domi\AppData\Roaming\HpUpdate O43 - CFD: 2008/01/01 18:04:40 - [] D -- C:\Users\Domi\AppData\Roaming\Icones O43 - CFD: 2009/06/06 14:24:29 - [] D -- C:\Users\Domi\AppData\Roaming\Identities O43 - CFD: 2010/04/06 17:07:03 - [] D -- C:\Users\Domi\AppData\Roaming\ImgBurn O43 - CFD: 2009/10/24 09:30:48 - [] D -- C:\Users\Domi\AppData\Roaming\InstallShield O43 - CFD: 2009/06/06 14:40:15 - [] D -- C:\Users\Domi\AppData\Roaming\Macromedia O43 - CFD: 2013/07/05 11:08:26 - [] D -- C:\Users\Domi\AppData\Roaming\Malwarebytes O43 - CFD: 2015/05/14 12:12:22 - [] SD -- C:\Users\Domi\AppData\Roaming\Microsoft O43 - CFD: 2012/07/27 11:31:23 - [] D -- C:\Users\Domi\AppData\Roaming\Mount&Blade Warband O43 - CFD: 2014/05/09 08:09:30 - [] D -- C:\Users\Domi\AppData\Roaming\Mozilla O43 - CFD: 2010/06/18 13:59:21 - [] D -- C:\Users\Domi\AppData\Roaming\OpenOffice.org O43 - CFD: 2014/01/30 00:55:53 - [0] D -- C:\Users\Domi\AppData\Roaming\Orange O43 - CFD: 2010/04/16 13:10:26 - [0] D -- C:\Users\Domi\AppData\Roaming\PeerNetworking O43 - CFD: 2012/08/23 20:43:40 - [] D -- C:\Users\Domi\AppData\Roaming\Research In Motion O43 - CFD: 2013/06/01 16:09:00 - [] D -- C:\Users\Domi\AppData\Roaming\Rovio O43 - CFD: 2012/09/16 01:39:11 - [] D -- C:\Users\Domi\AppData\Roaming\Samsung O43 - CFD: 2012/02/07 20:57:13 - [] RHD -- C:\Users\Domi\AppData\Roaming\SecuROM O43 - CFD: 2014/10/04 14:18:48 - [] D -- C:\Users\Domi\AppData\Roaming\Skype O43 - CFD: 2011/05/03 08:47:06 - [] D -- C:\Users\Domi\AppData\Roaming\SoftGrid Client O43 - CFD: 2010/05/01 14:33:05 - [] D -- C:\Users\Domi\AppData\Roaming\Synthesia O43 - CFD: 2014/04/02 16:39:12 - [] D -- C:\Users\Domi\AppData\Roaming\TeamViewer O43 - CFD: 2013/04/08 17:58:41 - [] D -- C:\Users\Domi\AppData\Roaming\Template O43 - CFD: 2010/09/30 15:31:14 - [0] D -- C:\Users\Domi\AppData\Roaming\TP O43 - CFD: 2013/11/24 12:26:54 - [] D -- C:\Users\Domi\AppData\Roaming\Unity O43 - CFD: 2015/02/25 18:54:11 - [] D -- C:\Users\Domi\AppData\Roaming\uTorrent O43 - CFD: 2008/01/01 18:04:41 - [] D -- C:\Users\Domi\AppData\Roaming\vlc O43 - CFD: 2013/02/19 09:41:47 - [] D -- C:\Users\Domi\AppData\Roaming\WinRAR O43 - CFD: 2010/04/10 13:14:28 - [] D -- C:\Users\Domi\AppData\Roaming\Wormux O43 - CFD: 2015/08/05 15:06:29 - [] D -- C:\Users\Domi\AppData\Roaming\ZHP O43 - CFD: 2015/06/10 13:12:04 - [] D -- C:\Users\Domi\AppData\Local\Adobe O43 - CFD: 2012/09/02 16:19:41 - [] D -- C:\Users\Domi\AppData\Local\Apple O43 - CFD: 2012/09/23 08:03:18 - [] D -- C:\Users\Domi\AppData\Local\Apple Computer O43 - CFD: 2009/06/06 14:16:51 - [0] SHD -- C:\Users\Domi\AppData\Local\Application Data O43 - CFD: 2008/01/01 18:04:24 - [] D -- C:\Users\Domi\AppData\Local\ApplicationHistory O43 - CFD: 2010/04/06 17:10:09 - [] D -- C:\Users\Domi\AppData\Local\Apps O43 - CFD: 2011/02/02 16:45:02 - [] D -- C:\Users\Domi\AppData\Local\assembly O43 - CFD: 2010/02/03 00:20:57 - [] D -- C:\Users\Domi\AppData\Local\Blizzard Entertainment O43 - CFD: 2015/08/02 21:58:44 - [0] D -- C:\Users\Domi\AppData\Local\CrashDumps O43 - CFD: 2015/05/14 09:46:24 - [] D -- C:\Users\Domi\AppData\Local\CrashRpt =>.Legitimate.CrashReports O43 - CFD: 2015/05/15 22:53:30 - [0] D -- C:\Users\Domi\AppData\Local\deni O43 - CFD: 2011/02/02 16:44:45 - [0] D -- C:\Users\Domi\AppData\Local\Deployment O43 - CFD: 2012/08/23 20:55:16 - [] D -- C:\Users\Domi\AppData\Local\Downloaded Installations O43 - CFD: 2012/09/06 09:35:02 - [] D -- C:\Users\Domi\AppData\Local\ElevatedDiagnostics O43 - CFD: 2012/09/03 09:14:10 - [] D -- C:\Users\Domi\AppData\Local\Google O43 - CFD: 2009/11/07 18:13:48 - [] D -- C:\Users\Domi\AppData\Local\Hewlett-Packard O43 - CFD: 2009/06/06 14:16:51 - [0] SHD -- C:\Users\Domi\AppData\Local\Historique O43 - CFD: 2012/02/27 11:12:36 - [] D -- C:\Users\Domi\AppData\Local\HP O43 - CFD: 2015/05/14 09:46:26 - [] D -- C:\Users\Domi\AppData\Local\Installer =>PUP.Optional.InstallPedia O43 - CFD: 2012/07/05 22:06:43 - [] D -- C:\Users\Domi\AppData\Local\Macromedia O43 - CFD: 2013/12/28 19:48:18 - [] D -- C:\Users\Domi\AppData\Local\Microsoft O43 - CFD: 2009/11/17 12:57:04 - [] D -- C:\Users\Domi\AppData\Local\Microsoft Games O43 - CFD: 2008/01/01 18:04:24 - [] D -- C:\Users\Domi\AppData\Local\Microsoft Help O43 - CFD: 2013/07/17 15:27:58 - [] D -- C:\Users\Domi\AppData\Local\MigWiz O43 - CFD: 2012/07/04 19:29:58 - [] D -- C:\Users\Domi\AppData\Local\Mozilla O43 - CFD: 2012/02/29 22:39:54 - [] D -- C:\Users\Domi\AppData\Local\MPlayer O43 - CFD: 2011/12/19 17:54:37 - [] D -- C:\Users\Domi\AppData\Local\Orange O43 - CFD: 2015/08/04 13:58:18 - [] D -- C:\Users\Domi\AppData\Local\Paint.NET O43 - CFD: 2012/12/24 09:02:34 - [] D -- C:\Users\Domi\AppData\Local\Panasonic O43 - CFD: 2009/07/06 18:50:09 - [0] D -- C:\Users\Domi\AppData\Local\Pixology O43 - CFD: 2012/02/24 12:26:34 - [] D -- C:\Users\Domi\AppData\Local\PunkBuster O43 - CFD: 2012/08/23 21:15:41 - [] D -- C:\Users\Domi\AppData\Local\Research In Motion O43 - CFD: 2015/05/10 10:23:57 - [] D -- C:\Users\Domi\AppData\Local\Roblox O43 - CFD: 2013/07/17 14:59:00 - [0] D -- C:\Users\Domi\AppData\Local\Samsung O43 - CFD: 2008/01/01 18:04:25 - [] D -- C:\Users\Domi\AppData\Local\Scrabble3D O43 - CFD: 2015/05/15 22:53:28 - [] D -- C:\Users\Domi\AppData\Local\Setup904587 O43 - CFD: 2009/10/22 12:38:39 - [] D -- C:\Users\Domi\AppData\Local\Seven Zip O43 - CFD: 2014/06/28 15:58:23 - [] D -- C:\Users\Domi\AppData\Local\Skype O43 - CFD: 2010/09/30 15:31:05 - [] D -- C:\Users\Domi\AppData\Local\SoftGrid Client O43 - CFD: 2008/01/01 18:04:25 - [] D -- C:\Users\Domi\AppData\Local\Solid State Networks O43 - CFD: 2015/08/05 15:05:03 - [] D -- C:\Users\Domi\AppData\Local\Temp O43 - CFD: 2014/10/03 10:48:43 - [] D -- C:\Users\Domi\AppData\Local\Temp(441) O43 - CFD: 2009/06/06 14:16:51 - [0] SHD -- C:\Users\Domi\AppData\Local\Temporary Internet Files O43 - CFD: 2012/04/08 22:14:12 - [] D -- C:\Users\Domi\AppData\Local\The Lord of the Rings Online O43 - CFD: 2008/01/01 18:04:25 - [] D -- C:\Users\Domi\AppData\Local\Turbine O43 - CFD: 2015/07/21 13:26:19 - [0] D -- C:\Users\Domi\AppData\Local\Unity O43 - CFD: 2009/06/30 18:50:36 - [] D -- C:\Users\Domi\AppData\Local\VirtualStore O43 - CFD: 2013/10/24 09:40:28 - [] D -- C:\Users\Domi\AppData\Local\VS Revo Group O43 - CFD: 2013/12/28 19:48:14 - [] D -- C:\Users\Domi\AppData\Local\Windows Live O43 - CFD: 2008/01/01 18:04:40 - [] RD -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2008/01/01 18:04:40 - [] RD -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2008/01/01 18:04:40 - [] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite O43 - CFD: 2008/01/01 18:04:40 - [] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam O43 - CFD: 2008/01/01 18:04:40 - [] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 2008/01/01 18:04:40 - [] RD -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2011/12/17 11:18:01 - [0] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My Application O43 - CFD: 2012/10/30 09:01:07 - [0] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Orange O43 - CFD: 2010/05/01 15:25:27 - [0] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pvm O43 - CFD: 2014/10/06 11:44:58 - [] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller O43 - CFD: 2015/05/16 08:03:15 - [] RD -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 2008/01/01 18:04:40 - [] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool O43 - CFD: 2008/01/01 18:04:40 - [] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ---\\ Enumération des clés de registre StartupReg (SMSR) (O53) (8) - 1s O53 - SMSR:HKLM\...\startupreg\APSDaemon [Key] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe O53 - SMSR:HKLM\...\startupreg\HPAdvisor [Key] . (...) -- C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\Malwarebytes Anti-Malware (cleanup) [Key] . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- rundll32.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\MsnMsgr [Key] . (...) -- C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe (.not file.) O53 - SMSR:HKLM\...\startupreg\Orange Installer [Key] . (...) -- C:\Program Files\Orange\Orange Installer\OrangeInstaller.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\QuickTime Task [Key] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe O53 - SMSR:HKLM\...\startupreg\SunJavaUpdateSched [Key] . (...) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\uTorrent [Key] . (.BitTorrent, Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe ---\\ Liste des pilotes du système (SDL) (O58) (79) - 24s O58 - SDL:2008/01/21 04:32:46 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [422968] O58 - SDL:2008/01/21 04:32:51 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [300600] O58 - SDL:2008/01/21 04:32:52 A . (.Adaptec, Inc. - Adaptec LH Ultra160 Driver (x86).) -- C:\Windows\System32\drivers\adpu160m.sys [101432] O58 - SDL:2008/01/21 04:32:53 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\drivers\adpu320.sys [149560] O58 - SDL:2009/02/27 06:43:10 N . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [17464] O58 - SDL:2008/01/21 04:32:49 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [79416] O58 - SDL:2008/01/21 04:32:50 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [79928] O58 - SDL:2008/12/20 01:01:46 A . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driv.) -- C:\Windows\System32\drivers\athr.sys [1093120] O58 - SDL:2006/11/02 10:24:45 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [13568] O58 - SDL:2006/11/02 10:24:46 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [5248] O58 - SDL:2006/11/02 10:25:24 A . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [71808] O58 - SDL:2006/11/02 10:24:44 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [62336] O58 - SDL:2006/11/02 10:24:44 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [12160] O58 - SDL:2006/11/02 10:24:47 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [11904] O58 - SDL:2009/02/27 06:43:10 N . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [19000] O58 - SDL:2006/11/02 11:50:11 A . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\drivers\djsvs.sys [71272] O58 - SDL:2008/01/21 04:32:50 A . (.Intel Corporation - Pilote désérialisé NDIS 6 de la carte Intel.) -- C:\Windows\System32\drivers\E1G60I32.sys [118784] O58 - SDL:2008/01/21 04:32:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [342584] O58 - SDL:2008/01/21 04:32:52 A . (.Hewlett-Packard Company - Smart Array Storport Driver.) -- C:\Windows\System32\drivers\HpCISSs.sys [40504] O58 - SDL:2007/06/18 17:12:04 A . (.Hewlett-Packard Development Company, L.P. - HpqKbFiltr Keyboard Filter Driver.) -- C:\Windows\System32\drivers\HpqKbFiltr.sys [16768] O58 - SDL:2008/01/21 04:32:49 A . (.Intel Corporation - Intel Matrix Storage Manager driver (base).) -- C:\Windows\System32\drivers\iaStorV.sys [235064] O58 - SDL:2008/10/28 10:29:36 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd32.sys [2476544] O58 - SDL:2006/11/02 11:50:17 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [41576] O58 - SDL:2008/09/22 07:49:36 A . (.Intel(R) Corporation - Intel(R) High Definition Audio HDMI.) -- C:\Windows\System32\drivers\IntcHdmi.sys [112128] O58 - SDL:2006/11/02 11:50:07 A . (.Integrated Technology Express, Inc. - ITE IT8211 ATA/ATAPI SCSI miniport.) -- C:\Windows\System32\drivers\iteatapi.sys [35944] O58 - SDL:2006/11/02 11:50:09 A . (.Integrated Technology Express, Inc. - ITE IT8212 ATA RAID SCSI miniport.) -- C:\Windows\System32\drivers\iteraid.sys [35944] O58 - SDL:2008/01/21 04:32:49 A . (.LSI Logic - LSI Logic Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [96312] O58 - SDL:2008/01/21 04:32:51 A . (.LSI Logic - LSI Logic Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [89656] O58 - SDL:2008/01/21 04:32:48 A . (.LSI Logic - LSI Logic Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [96312] O58 - SDL:2015/06/18 08:41:36 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\mbam.sys [23256] O58 - SDL:2015/06/18 08:41:42 A . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\drivers\mbamchameleon.sys [94936] O58 - SDL:2015/08/04 21:03:54 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys [98520] O58 - SDL:2008/01/21 04:32:53 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [31288] O58 - SDL:2008/01/21 04:32:52 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [386616] O58 - SDL:2006/11/02 11:49:59 A . (.LSI Logic Corporation - MegaRAID RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\Mraid35x.sys [33384] O58 - SDL:2015/06/18 08:41:50 A . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\drivers\mwac.sys [51928] O58 - SDL:2008/01/21 04:32:45 A . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\Windows\System32\drivers\NETw3v32.sys [2225664] O58 - SDL:2006/11/02 11:50:19 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [45160] O58 - SDL:2006/11/02 09:36:50 A . (.N-trig Innovative Technologies - Pilote intégré de digitalisateur de tablett.) -- C:\Windows\System32\drivers\ntrigdigi.sys [20608] O58 - SDL:2008/01/21 04:32:47 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [102968] O58 - SDL:2008/01/21 04:32:47 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [45112] O58 - SDL:2009/02/03 16:07:40 N . (.Printing Communications Assoc., Inc. (PCAUSA) - PCAUSA NDIS 5.0 MPR Protocol Driver.) -- C:\Windows\System32\drivers\PCAMp50.sys [28224] O58 - SDL:2009/02/03 16:07:42 N . (.Printing Communications Assoc., Inc. (PCAUSA) - PCAUSA NDIS 5.0 SPR Protocol Driver.) -- C:\Windows\System32\drivers\PCASp50.sys [27072] O58 - SDL:2011/11/29 04:28:28 N . (.Sonic Solutions - Px Engine Device Driver for Windows 2000/XP.) -- C:\Windows\System32\drivers\pxhelp20.sys [45648] O58 - SDL:2008/01/21 04:32:50 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1122360] O58 - SDL:2006/11/02 11:50:35 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [106088] O58 - SDL:2008/12/23 13:47:52 A . (.Realtek Corporation - Realtek 8101E/8168/8169 NDIS6 32-bit Driver.) -- C:\Windows\System32\drivers\Rtlh86.sys [138240] O58 - SDL:2006/11/02 08:37:21 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [20480] O58 - SDL:2008/01/21 04:32:52 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [74808] O58 - SDL:2006/11/02 11:50:05 A . (.LSI Logic - LSI Logic 8XX SCSI Miniport Driver.) -- C:\Windows\System32\drivers\symc8xx.sys [35944] O58 - SDL:2006/11/02 11:49:56 A . (.LSI Logic - LSI Logic Hi-Perf SCSI Miniport Driver.) -- C:\Windows\System32\drivers\sym_hi.sys [31848] O58 - SDL:2006/11/02 11:50:03 A . (.LSI Logic - LSI Logic Ultra160 SCSI Miniport Driver.) -- C:\Windows\System32\drivers\sym_u3.sys [34920] O58 - SDL:2008/12/05 00:55:14 A . (.Synaptics, Inc. - Synaptics Touchpad Driver.) -- C:\Windows\System32\drivers\SynTP.sys [204976] O58 - SDL:2008/01/21 04:32:45 A . (.ULi Electronics Inc. - ULi SATA Controller Driver.) -- C:\Windows\System32\drivers\uliahci.sys [238648] O58 - SDL:2006/11/02 11:50:35 A . (.Promise Technology, Inc. - Promise Ultra/Sata Series Driver for Win200.) -- C:\Windows\System32\drivers\ulsata.sys [98408] O58 - SDL:2008/01/21 04:32:49 A . (.Promise Technology, Inc. - Promise SATAII150 Series Windows Drivers.) -- C:\Windows\System32\drivers\ulsata2.sys [115816] O58 - SDL:2009/02/27 06:43:10 N . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [20024] O58 - SDL:2008/01/21 04:32:49 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [130616] O58 - SDL:2006/11/02 09:30:56 A . (.Marvell - Pilote miniport NDIS6.0 pour contrôleur Eth.) -- C:\Windows\System32\drivers\yk60x86.sys [194048] O58 - SDL:2008/08/29 10:49:04 A . (.ZTE Incorporated - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys [104960] O58 - SDL:2008/08/29 10:49:06 A . (.ZTE Corporation - USB NDIS Miniport Driver.) -- C:\Windows\System32\drivers\ZTEusbnet.sys [110080] O58 - SDL:2008/08/29 10:49:06 A . (.ZTE Incorporated - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\ZTEusbnmea.sys [104960] O58 - SDL:2008/08/29 10:49:06 A . (.ZTE Incorporated - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\ZTEusbser6k.sys [104960] O58 - SDL:2006/11/02 09:09:42 A . (...) -- C:\Windows\System32\ANSI.SYS [9029] O58 - SDL:2006/11/02 09:09:45 A . (...) -- C:\Windows\System32\country.sys [27097] O58 - SDL:2010/09/09 09:43:20 A . (...) -- C:\Windows\System32\FsUsbExDisk.Sys [36640] O58 - SDL:2006/11/02 09:09:41 A . (...) -- C:\Windows\System32\HIMEM.SYS [4768] O58 - SDL:2006/11/02 09:09:44 A . (...) -- C:\Windows\System32\KEY01.SYS [42809] O58 - SDL:2006/11/02 09:09:44 A . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537] O58 - SDL:2006/11/02 09:09:29 A . (...) -- C:\Windows\System32\NTDOS.SYS [27866] O58 - SDL:2006/11/02 09:09:35 A . (...) -- C:\Windows\System32\NTDOS404.SYS [29146] O58 - SDL:2006/11/02 09:09:38 A . (...) -- C:\Windows\System32\NTDOS411.SYS [29370] O58 - SDL:2006/11/02 09:09:40 A . (...) -- C:\Windows\System32\NTDOS412.SYS [29274] O58 - SDL:2006/11/02 09:09:31 A . (...) -- C:\Windows\System32\NTDOS804.SYS [29146] O58 - SDL:2006/11/02 09:09:20 A . (...) -- C:\Windows\System32\NTIO.SYS [33952] O58 - SDL:2006/11/02 09:09:23 A . (...) -- C:\Windows\System32\NTIO404.SYS [34672] O58 - SDL:2006/11/02 09:09:24 A . (...) -- C:\Windows\System32\NTIO411.SYS [35776] O58 - SDL:2006/11/02 09:09:26 A . (...) -- C:\Windows\System32\NTIO412.SYS [35536] O58 - SDL:2006/11/02 09:09:22 A . (...) -- C:\Windows\System32\NTIO804.SYS [34672] ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) (9) - 11s O61 - LFC: 2015/08/04 14:16:40 A . (..) -- C:\Users\Domi\Downloads\mbam2log_1(1).exe [948736] O61 - LFC: 2015/08/04 22:20:52 A . (..) -- C:\Users\Domi\Downloads\mbam2log_1(2).exe [948736] O61 - LFC: 2015/08/04 22:21:46 A . (..) -- C:\Users\Domi\Downloads\mbam2log_1(3).exe [948736] O61 - LFC: 2015/08/04 22:26:52 A . (..) -- C:\Users\Domi\Downloads\mbam2log_1(4).exe [948736] O61 - LFC: 2015/08/04 14:09:59 A . (..) -- C:\Users\Domi\Downloads\mbam2log_1.exe [948736] O61 - LFC: 2015/08/04 13:04:47 A . (..) -- C:\Users\Domi\Downloads\OneClick2RP.exe [739397] O61 - LFC: 2015/07/28 19:14:00 A . (..) -- C:\Users\Domi\AppData\Local\Google\Update\Install\{F97BF20E-534D-46BD-A948-B12F99C9AC66}\44.0.2403.125_43.0.2357.134_chrome_updater.exe [7371344] O61 - LFC: 2015/07/28 19:14:00 A . (..) -- C:\Users\Domi\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\44.0.2403.125\44.0.2403.125_43.0.2357.134_chrome_updater.exe [7371344] O61 - LFC: 2015/08/04 11:24:30 A . (..) -- C:\Users\Domi\AppData\Local\Adobe\Acrobat\10.0\UserCache.bin [72403] ---\\ Associations Shell Spawning (O67) (1) - 0s O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe ---\\ Menu de démarrage Internet (SMI) (O68) (12) - 1s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\Domi\AppData\Local\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- iexplore.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\Domi\AppData\Local\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Users\Domi\AppData\Local\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\Domi\AppData\Local\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) (4) - 16s O69 - SBI: prefs.js [Domi - w0hbv0us.default-1431618661383] user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine"); =>PUP.Optional.SearchEngine O69 - SBI: prefs.js [Domi - w0hbv0us.default-1431618661383] user_pref("browser.search.searchengine.ptid", "cmi"); =>PUP.Optional.SearchEngine O69 - SBI: prefs.js [Domi - w0hbv0us.default-1431618661383] user_pref("browser.search.searchengine.uid", "WDCXWD1600BEVT-60ZCT1_WD-WXE209PUA161UA161"); =>PUP.Optional.SearchEngine O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ ---\\ Enumère les services démarrés par Svchost (SSS) (O83) (32) - 1s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [24576] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [62976] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [247808] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [40448] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [40448] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [125952] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [576512] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [444928] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\audiosrv.dll [316928] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [90624] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [262144] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [68608] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [47104] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à.) -- C:\Windows\System32\ipnathlp.dll [288256] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [242688] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes Termi.) -- C:\Windows\System32\termsrv.dll [449536] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [1933848] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [758784] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [247808] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [200704] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [19968] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [33280] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [111616] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\System32\mmcss.dll [45056] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [153600] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [57344] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [162304] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [601600] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service de configuration des services Termi.) -- C:\Windows\System32\SessEnv.dll [84992] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [81920] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\KMSVC.DLL [68096] O83 - Search Svchost Services: ezSharedSvc (ezSharedSvc) . (.EasyBits Sofware AS - Shared EasyBits services for Windows.) -- C:\Windows\System32\ezsvc7.dll [129992] ---\\ Liste des exceptions du parefeu (FirewallRules) (O87) (6) - 2s O87 - FAEL: "{5B8CC3B6-74A6-40DF-A287-0B284E608198}" [In-None-P6-TRUE] .(.BitTorrent, Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe O87 - FAEL: "{226776D1-C90B-45F1-9A14-E3FBD4EEE5CA}" [In-None-P17-TRUE] .(.BitTorrent, Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe O87 - FAEL: "TCP Query User{DA1163CD-F9DE-42DB-A2DF-CB75043E4E51}C:\program files\utorrent\utorrent.exe" [In-None-P6-TRUE] .(.BitTorrent, Inc. - µTorrent.) -- C:\program files\utorrent\utorrent.exe O87 - FAEL: "UDP Query User{C341D1C7-A5CC-43D3-8EB9-171C373FFB34}C:\program files\utorrent\utorrent.exe" [In-None-P17-TRUE] .(.BitTorrent, Inc. - µTorrent.) -- C:\program files\utorrent\utorrent.exe O87 - FAEL: "{6361FD3A-BED8-49AC-B8D3-56CF3BA4301F}" [In-None-P6-TRUE] .(.Research In Motion - BlackBerry Desktop Software.) -- C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe O87 - FAEL: "{19792492-2E88-4F25-A14D-252429BD2D3D}" [In-None-P17-TRUE] .(.Research In Motion - BlackBerry Desktop Software.) -- C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe ---\\ Scan Additionnel (O88) (7) - 0s C:\Program Files\13c0c15a-7b86-4a21-b72b-22bb68b6e93f =>PUP.Optional.CrossRider C:\Program Files\450c05ba-477a-44b0-bcc7-f474e2d95235 =>PUP.Optional.CrossRider C:\Program Files\8fe2edcd-623c-40b1-ad3f-f290027245f7 =>PUP.Optional.CrossRider C:\Program Files\Software =>PUP.Optional.Boxore C:\ProgramData\Google =>PUP.Optional.Gen C:\Users\Domi\AppData\Local\CrashRpt =>.Legitimate.CrashReports C:\Users\Domi\AppData\Local\Installer =>PUP.Optional.InstallPedia ---\\ Récapitulatif des éléments trouvées sur votre station (6) - 0s http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider http://www.nicolascoolman.fr/adware-boxore/ =>PUP.Optional.Boxore http://www.nicolascoolman.fr/blog =>PUP.Optional.Gen http://www.nicolascoolman.fr/blog =>.Legitimate.CrashReports http://www.nicolascoolman.fr/adware-installpedia/ =>PUP.Optional.InstallPedia http://www.nicolascoolman.fr/blog =>PUP.Optional.SearchEngine ~ End of the scan, 28779 items in 415 seconds (915)(0)() ---\\ Navigateurs Internet (2) - 0s MFIE: Mozilla Firefox 39.0 (x86 fr) v39.0 MSIE: Internet Explorer v9.0.8112.16421 ---\\ Informations sur les produits Windows (3) - 15s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK (Auto) ---\\ Logiciels de protection (3) - 1s Malwarebytes Anti-Malware version 2.1.8.1057 Microsoft Security Client v4.8.0204.0 Microsoft Security Essentials v4.8.204.0 ---\\ Logiciels d'optimisation (1) - 1s CCleaner v4.03 ---\\ Surveillance de Logiciels (2) - 2s Adobe Flash Player 18 NPAPI Adobe Reader X ---\\ Informations sur le système (6) - 0s ~ Operating System: x86 Family 6 Model 15 Stepping 13, GenuineIntel ~ Operating System: 32-bit ~ Boot mode: Normal (Normal boot) Total RAM: 3074.224 MB (57% free) ~ System Restore: Activé (Enable) ~ System drive C: has 65 GB free of 142 GB ---\\ Mode de connexion au système (3) - 0s ~ Computer Name: PC-DE-SOPHIE ~ User Name: Domi ~ Logged in as Administrator ---\\ Enumération des unités disques (2) - 0s ~ Drive C: has 65 GB free of 142 GB (System) ~ Drive D: has 1 GB free of 10 GB ---\\ Etat du Centre de Sécurité Windows (13) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoClose: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ---\\ Recherche particulière de fichiers génériques (23) - 5s [MD5.D07D4C3038F3578FFCE1C0237F2A1253] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\Windows\Explorer.exe [2926592] [MD5.4B555106290BD117334E9A08761C035A] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\Windows\System32\rundll32.exe [44544] [MD5.101BA3EA053480BB5D957EF37C06B5ED] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\Windows\System32\Wininit.exe [96768] [MD5.E38E89A0939A42F5EE4292DFC48772DF] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\Windows\System32\wininet.dll [1129472] [MD5.898E7C06A350D4A1A64A9EA264D55452] - (.Microsoft Corporation - Application d'ouverture de session Windows.) () -- C:\Windows\System32\Winlogon.exe [314368] [MD5.95F5FF73B076576C41740F1A842B9B57] - (.Microsoft Corporation - DLL client de l'API uilisateur de Windows m.) () -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] [MD5.F5272A105F59A7B3B345D9D6D87DA7AD] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\Windows\System32\drivers\AFD.sys [273408] [MD5.1F05B78AB91C9075565A9D8A4B880BC4] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\Windows\System32\drivers\atapi.sys [19944] [MD5.7ADD03E75BEB9E6DD102C3081D29840A] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\Windows\System32\drivers\Cdfs.sys [70144] [MD5.6B4BFFB9BECD728097024276430DB314] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\Windows\System32\drivers\Cdrom.sys [67072] [MD5.622C41A07CA7E6DD91770F50D532CB6C] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\Windows\System32\drivers\DfsC.sys [75264] [MD5.062452B7FFD68C8C042A6261FE8DFF4A] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\Windows\System32\drivers\HDAudBus.sys [561152] [MD5.22D56C8184586B7A1F6FA60BE5F5A2BD] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\Windows\System32\drivers\i8042prt.sys [54784] [MD5.8793643A67B42CEC66490B2A0CF92D68] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\Windows\System32\drivers\IpNat.sys [100864] [MD5.1E94971C4B446AB2290DEB71D01CF0C2] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\Windows\System32\drivers\MRxSmb.sys [106496] [MD5.ECD64230A59CBD93C85F1CD1CAB9F3F6] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\Windows\System32\drivers\netBT.sys [185856] [MD5.2C1121F2B87E9A6B12485DF53CD848C7] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\Windows\System32\drivers\ntfs.sys [1082232] [MD5.0FA9B5055484649D63C303FE404E5F4D] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\Windows\System32\drivers\Parport.sys [79360] [MD5.A214ADBAF4CB47DD2728859EF31F26B0] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\Windows\System32\drivers\Rasl2tp.sys [76288] [MD5.FBC0BACD9C3D7F6956853F64A66E252D] - (.Microsoft Corporation - Microsoft RDP Device redirector.) () -- C:\Windows\System32\drivers\rdpdr.sys [248832] [MD5.7B75299A4D201D6A6533603D6914AB04] - (.Microsoft Corporation - SMB Transport driver.) () -- C:\Windows\System32\drivers\smb.sys [66560] [MD5.76B06EB8A01FC8624D699E7045303E54] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\Windows\System32\drivers\tdx.sys [72192] [MD5.786DB5771F05EF300390399F626BF30A] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\Windows\System32\drivers\volsnap.sys [224640] ---\\ Processus lancés (7) - 5s [MD5.C832A3622A35CA7C595EA8CA385BA813] - (.Broadcom Corporation. - Bluetooth Support Server.) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [555560] [PID.584] [MD5.F96C429788350DB4BA6771C3034DFD88] - (.Teruten - FsUsbDevice.) -- C:\Windows\System32\FsUsbExService.Exe [217088] [PID.1440] [MD5.43DBA6069B3FA153FA68C30DE24CD341] - (.France Telecom SA - .) -- C:\Program Files\Common Files\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [65536] [PID.356] [MD5.2063D6B51FD874E67502B31A9FDBA685] - (.SoftThinks - STServices.) -- C:\Program Files\SMINST\BLService.exe [365952] [PID.2232] [MD5.6C4878F3483B959891408B804DE4475C] - (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1410344] [PID.2592] [MD5.BED38B0ADFF5F5CC6E988A6491017E83] - (.Research In Motion Limited - Launch Agent Service.) -- C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [267792] [PID.2652] [MD5.C8649EDF4955DE896A7AED515C932B09] - (.Synaptics, Inc. - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.3004] ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2) (3) - 1s G2 - GCE: Preference [User Data\Default] [jafdhbipfdlldljdanpnlipdinjcjjid] Portail Orange G2 - GCE: Preference [User Data\Default] [nfkdglgjjpicgkbfdflchobhdiblbjgf] Menu Contextuel Orange G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) (15) - 5s M0 - MFSP: prefs.js [Domi - w0hbv0us.default-1431618661383] https://fr-mg42.mail.yahoo.com/neo/launch?.rand=95tajsjeme521 P2 - EXT FILE: (...) -- C:\Users\Domi\AppData\Roaming\Mozilla\Firefox\Profiles\w0hbv0us.default-1431618661383\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-france.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay-france.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo-france.xml P2 - EXT: (.Mozilla - Default.) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} P2 - EXT: (.WOT Services Oy - WOT.) -- C:\Users\Domi\AppData\Roaming\Mozilla\Firefox\Profiles\w0hbv0us.default-1431618661383\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\NPSWF32_18_0_0_209.dll P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll P2 - FPN: [HKLM] [@RIM.com/WebSLLauncher,version=1.0] - (.Research In Motion.) -- C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) (15) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.bing.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://www.bing.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 1 ---\\ Internet Explorer, Proxy Management (R5) (4) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs (3) - 0s F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl" ---\\ Hosts file redirection (O1) (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (4) ---\\ Browser Helper Object de navigateur (BHO) (O2) (1) - 1s O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} . (.Orbiscom Ltd. All rights reserved. - FTO CMB.) -- C:\Windows\System32\BhoECart.dll ---\\ Applications lancées au démarrage du sytème (O4) (11) - 1s O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [QlbCtrl.exe] . (.Hewlett-Packard Development Company, L.P. - Quick Launch Buttons.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe O4 - HKLM\..\Run: [RIMBBLaunchAgent.exe] . (.Research In Motion Limited - Launch Agent Service.) -- C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe O4 - HKLM\..\Run: [HP Software Update] . (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Domi\AppData\Local\Google\Update\GoogleUpdate.exe O4 - HKUS\S-1-5-21-1768449568-3379944238-3116535841-1000\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Domi\AppData\Local\Google\Update\GoogleUpdate.exe ---\\ Modification Domaine/Adresses DNS (O17) (3) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS3\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 ---\\ Liste des services NT non Microsoft et non désactivés (O23) (6) - 1s O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Bluetooth Service (btwdins) . (.Broadcom Corporation. - Bluetooth Support Server.) - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe O23 - Service: FsUsbExService (FsUsbExService) . (.Teruten - FsUsbDevice.) - C:\Windows\System32\FsUsbExService.Exe O23 - Service: France Telecom Routing Table Service (FTRTSVC) . (.France Telecom SA - .) - C:\Program Files\Common Files\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: Recovery Service for Windows (Recovery Service for Windows) . (.SoftThinks - STServices.) - C:\Program Files\SMINST\BLService.exe ---\\ Tâches planifiées en automatique (O39) (16) - 4s O39 - APT: Orphean - (...) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002] O39 - APT: Orphean - (...) -- C:\Windows\Tasks\Driver Robot.job [456] O39 - APT: Orphean - (...) -- C:\Windows\Tasks\EDPLQYG1.job [328] O39 - APT: Orphean - (...) -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1768449568-3379944238-3116535841-1000Core.job [1022] O39 - APT: Orphean - (...) -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1768449568-3379944238-3116535841-1000UA.job [1074] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [3854] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [2770] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\CreateChoiceProcessTask [3162] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\Driver Robot [3236] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\EDPLQYG1 [2850] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1768449568-3379944238-3116535841-1000Core [3560] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1768449568-3379944238-3116535841-1000UA [3956] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\RAFZERK [3562] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\RunAsStdUser Task [3300] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{569012F3-360D-476F-9003-DF1A1E232A14} [3180] O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{831583BE-F14F-41D0-80B3-46FDA9C199B0} [3042] ---\\ Logiciels installés (O42) (68) - 32s O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- Adobe AIR O42 - Logiciel: Adobe Flash Player 17 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Flash Player 18 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI O42 - Logiciel: BlackBerry Desktop Software 7.1 - (.Research In Motion Ltd..) [HKLM] -- BlackBerry_Desktop O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner O42 - Logiciel: Acrobat.com - (.Adobe Systems Incorporated.) [HKLM] -- com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- HDMI O42 - Logiciel: HP Photosmart Essential 2.01 - (.HP.) [HKLM] -- HP Photosmart Essential O42 - Logiciel: HP Print Projects 1.0 - (.HP.) [HKLM] -- HP Print Projects O42 - Logiciel: HP OCR Software 9.0 - (.HP.) [HKLM] -- HPOCR O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM] -- InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D} O42 - Logiciel: Power2Go - (.CyberLink Corp..) [HKLM] -- InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658} O42 - Logiciel: PowerDirector - (.CyberLink Corp..) [HKLM] -- InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1} O42 - Logiciel: IsoBuster 2.6 - (.Smart Projects.) [HKLM] -- IsoBuster_is1 O42 - Logiciel: Malwarebytes Anti-Malware version 2.1.8.1057 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1 O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client O42 - Logiciel: Mozilla Firefox 39.0 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 39.0 (x86 fr) O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService O42 - Logiciel: Picasa 3 - (.Google, Inc..) [HKLM] -- Picasa 3 O42 - Logiciel: Revo Uninstaller 1.95 - (.VS Revo Group.) [HKLM] -- Revo Uninstaller O42 - Logiciel: SFR - Kit de connexion - (.SFR.) [HKLM] -- SFR_Kit O42 - Logiciel: Shop for HP Supplies - (.HP.) [HKLM] -- Shop for HP Supplies O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics.) [HKLM] -- SynTPDeinstKey O42 - Logiciel: Virtualis Crédit Mutuel - (...) [HKLM] -- Virtualis Crédit Mutuel O42 - Logiciel: WinRAR 4.20 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM] -- {01FB4998-33C4-4431-85ED-079E3EEFE75D} O42 - Logiciel: JavaFX 2.1.1 - (.Oracle Corporation.) [HKLM] -- {1111706F-666A-4037-7777-211328764D10} O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM] -- {2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3} O42 - Logiciel: OpenOffice.org 3.4 - (.OpenOffice.org.) [HKLM] -- {2F90A789-DD1E-41CE-BFCA-BD78213BABC7} O42 - Logiciel: Microsoft Antimalware Service FR-FR Language Pack - (.Microsoft Corporation.) [HKLM] -- {32E9C1A5-0FDA-4483-987D-DBABF9CC1DD8} O42 - Logiciel: HP Quick Launch Buttons 6.40 M1 - (.Hewlett-Packard.) [HKLM] -- {34D2AB40-150D-475D-AE32-BD23FB5EE355} O42 - Logiciel: ESU for Microsoft Vista - (.Hewlett-Packard.) [HKLM] -- {3877C901-7B90-4727-A639-B6ED2DD59D43} O42 - Logiciel: Microsoft Works - (.Microsoft Corporation.) [HKLM] -- {3B160861-7250-451E-B5EE-8B92BF30A710} O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM] -- {3F4BA3A2-7BE0-48EA-B4BC-CA4D842A409A} O42 - Logiciel: Power2Go - (.CyberLink Corp..) [HKLM] -- {40BF1E83-20EB-11D8-97C5-0009C5020658} O42 - Logiciel: Ma-Config.com - (.Cybelsoft.) [HKLM] -- {425FFD94-36BD-4933-881B-FE0B9DADF2B7} O42 - Logiciel: Microsoft Security Client FR-FR Language Pack - (.Microsoft Corporation.) [HKLM] -- {50779A29-834E-4E36-BBEB-B7CABC67A825} O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- {52E225FC-FCB4-41F7-837B-6E37FB05BD7B} O42 - Logiciel: swMSM - (.Adobe Systems, Inc.) [HKLM] -- {612C34C7-5E90-47D8-9B5C-0F717DD82726} O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {6E3939AE-9996-4D07-9A30-14C78AE93576} O42 - Logiciel: Paint.NET v3.5.11 - (.dotPDN LLC.) [HKLM] -- {72EF03F5-0507-4861-9A44-D99FD4C41417} O42 - Logiciel: HP Common Access Service Library - (.Hewlett-Packard.) [HKLM] -- {732A3F80-008B-4350-BD58-EC5AE98707B8} O42 - Logiciel: Acrobat.com - (.Adobe Systems Incorporated.) [HKLM] -- {77DCDCE3-2DED-62F3-8154-05E745472D07} O42 - Logiciel: HP Deskjet F2400 All-in-One Driver 14.0 Rel. 6 - (.HP.) [HKLM] -- {819CA3BC-2FF8-4811-B42F-421F7BFD3559} O42 - Logiciel: HPDiagnosticAlert - (.Microsoft.) [HKLM] -- {846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE} O42 - Logiciel: VC80CRTRedist - 8.0.50727.6195 - (.DivX, Inc.) [HKLM] -- {933B4015-4618-4716-A828-5289FC03165F} O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {934B3B19-8193-467A-B356-E73F82647D38} O42 - Logiciel: ArcSoft Panorama Maker 3 - (.ArcSoft.) [HKLM] -- {A5F68DC8-0278-4AD8-B413-861509B5F25B} O42 - Logiciel: 32 Bit HP CIO Components Installer - (.Hewlett-Packard.) [HKLM] -- {A80FA752-C491-4ED9-ABF0-4278563160B2} O42 - Logiciel: Software Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} O42 - Logiciel: Adobe Reader X (10.1.4) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AA1000000001} O42 - Logiciel: Adobe Shockwave Player - (.Adobe Systems, Inc..) [HKLM] -- {AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11} O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {B67BAFBA-4C9F-48FA-9496-933E3B255044} O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {BAD1449B-DF0C-4118-B76D-68C54009576C} O42 - Logiciel: BlackBerry Desktop Software 7.1 - (.Research In Motion Ltd..) [HKLM] -- {BE5B0450-DCCB-4FE9-93E2-3B38D88A745B} O42 - Logiciel: Atheros Driver Installation Program - (.Atheros.) [HKLM] -- {C3A32068-8AB1-4327-BB16-BED9C6219DC7} O42 - Logiciel: Microsoft Automated Troubleshooting Services Shim - (...) [HKLM] -- {c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb O42 - Logiciel: PowerDirector - (.CyberLink Corp..) [HKLM] -- {CB099890-1D5F-11D5-9EA9-0050BAE317E1} O42 - Logiciel: Windows 7 USB/DVD Download Tool - (.Microsoft Corporation.) [HKLM] -- {CCF298AF-9CE1-4B26-B251-486E98A34789} O42 - Logiciel: Nikon Message Center - (...) [HKLM] -- {D2FCC1AE-6311-47C5-8130-C6C66D77DD71} O42 - Logiciel: HP Photosmart All-In-One Software 9.0 - (.HP.) [HKLM] -- {D64BC2CF-0F12-47d7-B412-B4F3FD684253} O42 - Logiciel: WIDCOMM Bluetooth Software 6.2.0.5800 - (.Broadcom Corporation.) [HKLM] -- {E464702F-5433-46EC-8F65-159276C0A54F} O42 - Logiciel: PHOTOfunSTUDIO 8.0 LE - (.Panasonic Corporation.) [HKLM] -- {EF8D221C-9346-4FAA-8482-B0CF76773ABF} O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {F5266D28-E0B2-4130-BFC5-EE155AD514DC} O42 - Logiciel: PictureProject - (...) [HKLM] -- {FF3999BE-1A7B-4738-88AA-97BF14094A4A} O42 - Logiciel: Google Chrome - (.Google Inc..) [HKCU] -- Google Chrome O42 - Logiciel: MyFreeCodec - (...) [HKCU] -- MyFreeCodec O42 - Logiciel: µTorrent - (...) [HKCU] -- uTorrent ---\\ HKCU & HKLM Software Keys (188) - 32s HKLM\SOFTWARE\Adobe HKLM\SOFTWARE\AdwCleaner HKLM\SOFTWARE\AppDataLow HKLM\SOFTWARE\Apple Computer, Inc. HKLM\SOFTWARE\Apple Inc. HKLM\SOFTWARE\ArcSoft HKLM\SOFTWARE\Atheros HKLM\SOFTWARE\BrowserChoice HKLM\SOFTWARE\CDex HKLM\SOFTWARE\cybelsoft HKLM\SOFTWARE\Cyberlink HKLM\SOFTWARE\Data fellows HKLM\SOFTWARE\Debug HKLM\SOFTWARE\DevNet HKLM\SOFTWARE\DivX HKLM\SOFTWARE\DivXNetworks HKLM\SOFTWARE\Driver Robot HKLM\SOFTWARE\EasyBits HKLM\SOFTWARE\Electronic Arts HKLM\SOFTWARE\Extended Systems HKLM\SOFTWARE\FRANCE TELECOM HKLM\SOFTWARE\Google HKLM\SOFTWARE\GPL Ghostscript HKLM\SOFTWARE\Hewlett-Packard HKLM\SOFTWARE\HP HKLM\SOFTWARE\HPQ HKLM\SOFTWARE\ICE HKLM\SOFTWARE\InstalledOptions HKLM\SOFTWARE\InstallShield HKLM\SOFTWARE\Intel HKLM\SOFTWARE\JavaSoft HKLM\SOFTWARE\JreMetrics HKLM\SOFTWARE\Licenses HKLM\SOFTWARE\LightScribe HKLM\SOFTWARE\LucasArts HKLM\SOFTWARE\Macromedia HKLM\SOFTWARE\Malwarebytes' Anti-Malware HKLM\SOFTWARE\Malwarebytes' Anti-Malware (Trial) HKLM\SOFTWARE\MimarSinan HKLM\SOFTWARE\Mount&Blade Warband HKLM\SOFTWARE\Mozilla HKLM\SOFTWARE\mozilla.org HKLM\SOFTWARE\MozillaPlugins HKLM\SOFTWARE\Neuf HKLM\SOFTWARE\Nikon HKLM\SOFTWARE\ODBC HKLM\SOFTWARE\OldTimer Tools HKLM\SOFTWARE\OpenOffice.org HKLM\SOFTWARE\Oracle HKLM\SOFTWARE\Orange HKLM\SOFTWARE\Overwolf HKLM\SOFTWARE\P2G_Upgrade HKLM\SOFTWARE\Paint.NET HKLM\SOFTWARE\Panasonic HKLM\SOFTWARE\PDR_Upgrade HKLM\SOFTWARE\Piriform HKLM\SOFTWARE\pixology HKLM\SOFTWARE\Realtek HKLM\SOFTWARE\RegisteredApplications HKLM\SOFTWARE\Research In Motion HKLM\SOFTWARE\RTLSetup HKLM\SOFTWARE\Samsung HKLM\SOFTWARE\SecureDigitalServices HKLM\SOFTWARE\Skype HKLM\SOFTWARE\Software HKLM\SOFTWARE\Sun Microsystems HKLM\SOFTWARE\Synaptics HKLM\SOFTWARE\Synthesia HKLM\SOFTWARE\TeamViewer HKLM\SOFTWARE\Thomson HKLM\SOFTWARE\Trad-FR HKLM\SOFTWARE\Trolltech HKLM\SOFTWARE\Turbine HKLM\SOFTWARE\Volatile HKLM\SOFTWARE\webtogo HKLM\SOFTWARE\Widcomm HKLM\SOFTWARE\Windows HKLM\SOFTWARE\WinRAR HKLM\SOFTWARE\Yahoo HKCU\SOFTWARE\1C HKCU\SOFTWARE\AC3Filter HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\AlterGeo HKCU\SOFTWARE\AOL HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\Apple Computer, Inc. HKCU\SOFTWARE\Apple Inc. HKCU\SOFTWARE\Badoo HKCU\SOFTWARE\Binary Noise HKCU\SOFTWARE\BitTorrent HKCU\SOFTWARE\Blizzard Entertainment HKCU\SOFTWARE\Bugsplat HKCU\SOFTWARE\Chromium HKCU\SOFTWARE\Classes.crx HKCU\SOFTWARE\ClassesB HKCU\SOFTWARE\CoinisRevShare HKCU\SOFTWARE\ComNotificationV13.05 HKCU\SOFTWARE\CTPW Data HKCU\SOFTWARE\cybelsoft HKCU\SOFTWARE\CyberLink HKCU\SOFTWARE\DevNet HKCU\SOFTWARE\DivXNetworks HKCU\SOFTWARE\EasyBits HKCU\SOFTWARE\Electronic Arts HKCU\SOFTWARE\Extended Systems HKCU\SOFTWARE\FRANCE TELECOM HKCU\SOFTWARE\Games HKCU\SOFTWARE\GameSpy HKCU\SOFTWARE\GoldenGate HKCU\SOFTWARE\Google HKCU\SOFTWARE\Hewlett-Packard HKCU\SOFTWARE\HookNetwork HKCU\SOFTWARE\HP HKCU\SOFTWARE\Hs4ktZma8Sb HKCU\SOFTWARE\IADirectShow HKCU\SOFTWARE\IM Providers HKCU\SOFTWARE\ImageViewer HKCU\SOFTWARE\ImgBurn HKCU\SOFTWARE\Intel HKCU\SOFTWARE\InterVideo HKCU\SOFTWARE\Iris HKCU\SOFTWARE\JavaSoft HKCU\SOFTWARE\JEDI-VCL HKCU\SOFTWARE\kde.org HKCU\SOFTWARE\keyhole.com HKCU\SOFTWARE\Licenses HKCU\SOFTWARE\LightScribe HKCU\SOFTWARE\Local AppWizard-Generated Applications HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\MainConcept HKCU\SOFTWARE\Malwarebytes' Anti-Malware HKCU\SOFTWARE\Mediachance HKCU\SOFTWARE\MimarSinan HKCU\SOFTWARE\Mirage HKCU\SOFTWARE\MountAndBladeWarbandKeys HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\Nikon HKCU\SOFTWARE\OB HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\OpenOffice.org HKCU\SOFTWARE\Opera Software HKCU\SOFTWARE\Paint.NET HKCU\SOFTWARE\Panasonic HKCU\SOFTWARE\Patchou HKCU\SOFTWARE\Petroglyph HKCU\SOFTWARE\Piriform HKCU\SOFTWARE\Pvm HKCU\SOFTWARE\QtProject HKCU\SOFTWARE\Research In Motion HKCU\SOFTWARE\ROBLOX Corporation HKCU\SOFTWARE\RRx4T3rw2UR2fgmf HKCU\SOFTWARE\Samsung HKCU\SOFTWARE\SecuROM HKCU\SOFTWARE\Skype HKCU\SOFTWARE\Smart Projects HKCU\SOFTWARE\SOFT32 HKCU\SOFTWARE\Softthinks HKCU\SOFTWARE\Software HKCU\SOFTWARE\SuperSoftwarePackage HKCU\SOFTWARE\Synaptics HKCU\SOFTWARE\Synthesia HKCU\SOFTWARE\TeamViewer HKCU\SOFTWARE\TeleCharger HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\Unity HKCU\SOFTWARE\VSRevoGroup HKCU\SOFTWARE\Wargaming.net HKCU\SOFTWARE\Widcomm HKCU\SOFTWARE\Winamp HKCU\SOFTWARE\WinRAR HKCU\SOFTWARE\WinRAR SFX HKCU\SOFTWARE\Yahoo HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Aurigma HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\Adobe HKCU\SOFTWARE\AppDataLow\Software\Amazon HKCU\SOFTWARE\AppDataLow\Software\Google HKCU\SOFTWARE\AppDataLow\Software\JavaSoft HKCU\SOFTWARE\AppDataLow\Software\Macromedia HKCU\SOFTWARE\AppDataLow\Software\MarkAny HKCU\SOFTWARE\AppDataLow\Software\Monitored HKCU\SOFTWARE\AppDataLow\Software\Orange HKCU\SOFTWARE\AppDataLow\Software\settings HKCU\SOFTWARE\AppDataLow\Software\Unity HKCU\SOFTWARE\AppDataLow\Software\Yahoo ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) (317) - 34s O43 - CFD: 2015/05/14 21:08:19 - [0] D -- C:\Program Files\13c0c15a-7b86-4a21-b72b-22bb68b6e93f =>PUP.Optional.CrossRider O43 - CFD: 2015/05/14 21:08:19 - [0] D -- C:\Program Files\450c05ba-477a-44b0-bcc7-f474e2d95235 =>PUP.Optional.CrossRider O43 - CFD: 2015/05/14 21:08:19 - [0] D -- C:\Program Files\8fe2edcd-623c-40b1-ad3f-f290027245f7 =>PUP.Optional.CrossRider O43 - CFD: 2015/05/14 21:08:19 - [] D -- C:\Program Files\Adobe O43 - CFD: 2015/05/14 13:23:36 - [] D -- C:\Program Files\Adobe(0) O43 - CFD: 2010/07/19 10:29:50 - [] D -- C:\Program Files\Alwil Software O43 - CFD: 2009/10/24 10:39:08 - [] D -- C:\Program Files\ArcSoft O43 - CFD: 2012/02/29 23:59:23 - [] D -- C:\Program Files\Atheros O43 - CFD: 2013/07/15 14:16:10 - [] D -- C:\Program Files\CCleaner O43 - CFD: 2009/10/24 09:31:09 - [] D -- C:\Program Files\Cisco O43 - CFD: 2015/05/15 23:18:59 - [] D -- C:\Program Files\Common Files O43 - CFD: 2009/10/24 10:39:13 - [] D -- C:\Program Files\CyberLink O43 - CFD: 2013/07/03 09:31:57 - [0] D -- C:\Program Files\DevNet O43 - CFD: 2014/10/06 12:09:07 - [0] D -- C:\Program Files\EA Games O43 - CFD: 2009/06/06 14:16:41 - [0] SHD -- C:\Program Files\Fichiers communs O43 - CFD: 2012/09/02 16:44:05 - [] D -- C:\Program Files\Google O43 - CFD: 2011/06/21 11:26:49 - [] D -- C:\Program Files\GPLGS O43 - CFD: 2012/09/03 08:33:27 - [] D -- C:\Program Files\Hewlett-Packard O43 - CFD: 2013/07/03 09:31:03 - [] D -- C:\Program Files\Hosts_Anti_Adwares_PUPs O43 - CFD: 2012/09/18 12:07:47 - [] D -- C:\Program Files\HP O43 - CFD: 2015/05/15 23:16:07 - [] HD -- C:\Program Files\InstallShield Installation Information O43 - CFD: 2010/02/01 22:28:09 - [] D -- C:\Program Files\Intel O43 - CFD: 2012/03/02 16:47:16 - [0] D -- C:\Program Files\InterActual O43 - CFD: 2015/05/17 07:21:57 - [] D -- C:\Program Files\Internet Explorer O43 - CFD: 2009/06/07 12:17:59 - [] D -- C:\Program Files\Inventel O43 - CFD: 2014/10/06 11:55:14 - [] D -- C:\Program Files\Java O43 - CFD: 2012/04/24 10:56:29 - [0] D -- C:\Program Files\LucasArts O43 - CFD: 2009/10/24 13:00:34 - [] D -- C:\Program Files\ma-config.com O43 - CFD: 2015/08/04 17:02:47 - [] D -- C:\Program Files\Malwarebytes Anti-Malware O43 - CFD: 2010/12/29 12:03:35 - [] D -- C:\Program Files\MarkAny O43 - CFD: 2011/01/31 09:31:40 - [] D -- C:\Program Files\Messenger Plus! Live O43 - CFD: 2013/07/03 09:59:33 - [0] D -- C:\Program Files\Microsoft O43 - CFD: 2012/09/06 09:34:40 - [] D -- C:\Program Files\Microsoft ATS O43 - CFD: 2006/11/02 14:35:51 - [] D -- C:\Program Files\Microsoft Games O43 - CFD: 2011/10/07 09:25:42 - [] D -- C:\Program Files\Microsoft Office O43 - CFD: 2013/02/16 17:55:34 - [0] D -- C:\Program Files\Microsoft Office 15 O43 - CFD: 2015/05/14 06:14:43 - [] D -- C:\Program Files\Microsoft Security Client O43 - CFD: 2015/05/14 14:35:08 - [0] D -- C:\Program Files\Microsoft Silverlight O43 - CFD: 2012/12/24 09:01:12 - [] D -- C:\Program Files\Microsoft SQL Server Compact Edition O43 - CFD: 2009/10/22 15:47:32 - [] D -- C:\Program Files\Microsoft Sync Framework O43 - CFD: 2012/12/24 09:01:12 - [] D -- C:\Program Files\Microsoft Synchronization Services O43 - CFD: 2009/11/13 11:14:22 - [] D -- C:\Program Files\Microsoft Visual Studio O43 - CFD: 2012/10/10 05:35:59 - [] D -- C:\Program Files\Microsoft Works O43 - CFD: 2012/09/18 15:30:25 - [] D -- C:\Program Files\Microsoft.NET O43 - CFD: 2010/08/13 06:44:38 - [] D -- C:\Program Files\Movie Maker O43 - CFD: 2015/07/04 08:33:32 - [] D -- C:\Program Files\Mozilla Firefox O43 - CFD: 2015/07/04 08:33:32 - [] D -- C:\Program Files\Mozilla Maintenance Service O43 - CFD: 2006/11/02 14:35:51 - [] D -- C:\Program Files\MSBuild O43 - CFD: 2012/08/16 18:10:33 - [] D -- C:\Program Files\MyFree Codec O43 - CFD: 2009/06/06 14:19:43 - [] RD -- C:\Program Files\Online Services O43 - CFD: 2013/04/08 17:53:19 - [] D -- C:\Program Files\OpenOffice.org 3 O43 - CFD: 2015/05/14 12:14:03 - [0] D -- C:\Program Files\Opera O43 - CFD: 2012/07/03 17:17:13 - [] D -- C:\Program Files\Oracle O43 - CFD: 2014/10/06 12:04:58 - [] D -- C:\Program Files\Orange O43 - CFD: 2011/10/01 20:45:23 - [] D -- C:\Program Files\OrangeHSS O43 - CFD: 2013/08/20 18:52:15 - [] D -- C:\Program Files\Paint.NET O43 - CFD: 2012/12/24 09:01:21 - [] D -- C:\Program Files\Panasonic O43 - CFD: 2012/04/08 09:38:03 - [] D -- C:\Program Files\Pando Networks O43 - CFD: 2012/08/16 14:30:46 - [0] D -- C:\Program Files\PC Connectivity Solution O43 - CFD: 2012/07/27 20:56:43 - [] D -- C:\Program Files\Picasa2 O43 - CFD: 2010/05/01 15:25:27 - [] D -- C:\Program Files\Pvm O43 - CFD: 2013/06/27 17:13:28 - [] D -- C:\Program Files\QuickTime O43 - CFD: 2015/05/15 23:15:02 - [0] D -- C:\Program Files\Realtek O43 - CFD: 2006/11/02 14:35:51 - [] D -- C:\Program Files\Reference Assemblies O43 - CFD: 2012/08/23 20:41:13 - [] D -- C:\Program Files\Research In Motion O43 - CFD: 2012/09/18 16:13:01 - [] D -- C:\Program Files\Samsung O43 - CFD: 2012/02/29 22:01:13 - [] D -- C:\Program Files\SearchGBY O43 - CFD: 2009/10/24 10:54:01 - [] D -- C:\Program Files\Securitoo O43 - CFD: 2015/05/14 10:28:15 - [0] D -- C:\Program Files\setup O43 - CFD: 2014/01/28 09:59:55 - [] D -- C:\Program Files\SFR O43 - CFD: 2009/11/11 15:41:01 - [] D -- C:\Program Files\Smart Projects O43 - CFD: 2012/09/05 09:04:00 - [] D -- C:\Program Files\SMINST O43 - CFD: 2015/05/14 09:36:12 - [] D -- C:\Program Files\Software =>PUP.Optional.Boxore O43 - CFD: 2009/10/24 10:39:34 - [] D -- C:\Program Files\Synaptics O43 - CFD: 2014/04/02 15:49:14 - [] D -- C:\Program Files\TeamViewer O43 - CFD: 2012/04/08 17:34:54 - [] D -- C:\Program Files\Turbine O43 - CFD: 2006/11/02 14:58:18 - [0] HD -- C:\Program Files\Uninstall Information O43 - CFD: 2010/04/27 17:24:30 - [] D -- C:\Program Files\uTorrent O43 - CFD: 2013/07/03 08:48:54 - [0] D -- C:\Program Files\VideoLAN O43 - CFD: 2009/12/14 15:28:31 - [] D -- C:\Program Files\Virtualis O43 - CFD: 2014/10/06 11:44:56 - [] D -- C:\Program Files\VS Revo Group O43 - CFD: 2012/07/03 17:06:18 - [] D -- C:\Program Files\WIDCOMM O43 - CFD: 2010/02/10 22:30:37 - [] D -- C:\Program Files\Windows Calendar O43 - CFD: 2010/02/10 22:30:37 - [] D -- C:\Program Files\Windows Collaboration O43 - CFD: 2010/02/10 22:30:30 - [] D -- C:\Program Files\Windows Defender O43 - CFD: 2014/04/06 12:48:32 - [] D -- C:\Program Files\Windows Live O43 - CFD: 2012/04/12 12:06:06 - [] D -- C:\Program Files\Windows Mail O43 - CFD: 2015/08/02 22:37:02 - [] D -- C:\Program Files\Windows Media Player O43 - CFD: 2009/06/06 14:16:41 - [] D -- C:\Program Files\Windows NT O43 - CFD: 2010/02/10 22:30:36 - [] D -- C:\Program Files\Windows Photo Gallery O43 - CFD: 2010/02/12 04:19:38 - [] D -- C:\Program Files\Windows Portable Devices O43 - CFD: 2010/02/10 22:30:37 - [] D -- C:\Program Files\Windows Sidebar O43 - CFD: 2013/02/18 22:24:40 - [] D -- C:\Program Files\WinRAR O43 - CFD: 2011/04/23 09:49:11 - [] D -- C:\Program Files\Yahoo! O43 - CFD: 2015/05/15 23:25:14 - [] D -- C:\Program Files\ZHPDiag O43 - CFD: 2012/08/07 09:49:23 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2012/04/08 18:04:05 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2009/10/24 10:39:39 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft Panorama Maker 3 O43 - CFD: 2013/05/07 16:10:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry O43 - CFD: 2012/07/03 17:07:24 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDex O43 - CFD: 2008/01/21 04:56:27 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Extras and Upgrades O43 - CFD: 2014/11/15 23:38:42 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 2012/09/18 12:09:10 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP O43 - CFD: 2009/06/07 12:18:18 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Livebox O43 - CFD: 2012/04/22 09:59:14 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LucasArts O43 - CFD: 2009/10/25 09:38:37 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ma-config.com O43 - CFD: 2006/11/02 14:52:53 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2015/05/16 07:11:27 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office O43 - CFD: 2012/10/10 05:36:00 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works O43 - CFD: 2012/08/16 18:10:34 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec O43 - CFD: 2009/06/30 18:46:00 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nikon FotoShare O43 - CFD: 2009/06/06 14:19:43 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services O43 - CFD: 2013/04/08 17:53:19 - [] SD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.4 O43 - CFD: 2012/12/24 09:01:50 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panasonic O43 - CFD: 2009/07/29 15:07:14 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3 O43 - CFD: 2009/06/30 18:46:44 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PictureProject O43 - CFD: 2010/05/01 15:25:27 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pvm O43 - CFD: 2013/06/27 17:13:23 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime O43 - CFD: 2009/02/26 23:44:58 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery Manager O43 - CFD: 2009/06/06 14:19:40 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Services en ligne O43 - CFD: 2014/01/28 10:00:10 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SFR O43 - CFD: 2009/11/11 15:41:03 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Projects O43 - CFD: 2015/06/10 13:18:47 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 2012/07/03 17:10:03 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Synthesia O43 - CFD: 2013/02/18 22:24:50 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 2015/05/16 08:21:41 - [0] D -- C:\ProgramData\18b7a06c9f5a43a4b293b8ab47ed27ff O43 - CFD: 2015/05/14 09:46:05 - [] D -- C:\ProgramData\7c0535b143fc4671b6ebd202fbffe066 O43 - CFD: 2015/05/16 08:21:45 - [] D -- C:\ProgramData\acnExVZ O43 - CFD: 2013/08/02 10:08:21 - [] D -- C:\ProgramData\Adobe O43 - CFD: 2011/12/26 19:30:00 - [0] D -- C:\ProgramData\Alwil Software O43 - CFD: 2012/09/02 16:19:38 - [] D -- C:\ProgramData\Apple O43 - CFD: 2013/06/27 17:12:44 - [] D -- C:\ProgramData\Apple Computer O43 - CFD: 2006/11/02 14:59:44 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 2009/03/18 04:42:49 - [] D -- C:\ProgramData\Atheros O43 - CFD: 2010/02/01 22:35:08 - [] D -- C:\ProgramData\Blizzard O43 - CFD: 2009/06/06 14:16:41 - [0] SHD -- C:\ProgramData\Bureau O43 - CFD: 2012/04/23 21:47:55 - [] HD -- C:\ProgramData\Common Files O43 - CFD: 2009/11/22 20:12:11 - [] D -- C:\ProgramData\CyberLink O43 - CFD: 2006/11/02 14:59:44 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 2012/09/02 16:33:41 - [] D -- C:\ProgramData\DivX O43 - CFD: 2006/11/02 14:59:44 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 2012/09/23 07:53:19 - [] D -- C:\ProgramData\Downloaded Installations O43 - CFD: 2009/06/07 16:45:25 - [] D -- C:\ProgramData\EBP O43 - CFD: 2011/12/20 16:20:44 - [] D -- C:\ProgramData\f-secure O43 - CFD: 2009/06/06 14:16:41 - [0] SHD -- C:\ProgramData\Favoris O43 - CFD: 2006/11/02 14:59:44 - [0] SHD -- C:\ProgramData\Favorites O43 - CFD: 2012/02/27 11:08:51 - [] D -- C:\ProgramData\Google =>PUP.Optional.Gen O43 - CFD: 2014/10/06 12:03:13 - [0] D -- C:\ProgramData\HappyCloud O43 - CFD: 2009/06/07 17:19:24 - [] D -- C:\ProgramData\Hewlett-Packard O43 - CFD: 2012/09/18 12:08:35 - [] D -- C:\ProgramData\HP O43 - CFD: 2009/09/30 07:58:07 - [] D -- C:\ProgramData\HP Product Assistant O43 - CFD: 2009/10/24 13:00:31 - [] D -- C:\ProgramData\ma-config.com O43 - CFD: 2014/10/01 09:11:42 - [] D -- C:\ProgramData\Malwarebytes O43 - CFD: 2012/08/31 14:03:53 - [] D -- C:\ProgramData\McAfee O43 - CFD: 2009/06/06 14:16:41 - [0] SHD -- C:\ProgramData\Menu Démarrer O43 - CFD: 2014/04/06 12:40:31 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 2015/05/17 07:34:34 - [] D -- C:\ProgramData\Microsoft Help O43 - CFD: 2009/06/06 14:16:41 - [0] SHD -- C:\ProgramData\Modèles O43 - CFD: 2012/07/04 19:29:53 - [] D -- C:\ProgramData\Mozilla O43 - CFD: 2012/07/05 09:49:40 - [] D -- C:\ProgramData\Norton O43 - CFD: 2012/07/04 22:24:54 - [] D -- C:\ProgramData\NortonInstaller O43 - CFD: 2014/10/06 10:59:18 - [0] D -- C:\ProgramData\Oracle O43 - CFD: 2014/03/13 08:19:11 - [0] D -- C:\ProgramData\Orange O43 - CFD: 2012/12/24 09:07:26 - [] D -- C:\ProgramData\Panasonic O43 - CFD: 2009/07/07 18:22:26 - [] D -- C:\ProgramData\QuickTime O43 - CFD: 2012/08/23 21:11:27 - [] D -- C:\ProgramData\Research In Motion O43 - CFD: 2013/07/17 14:58:59 - [] D -- C:\ProgramData\Samsung O43 - CFD: 2014/10/04 14:19:00 - [] D -- C:\ProgramData\Skype O43 - CFD: 2006/11/02 14:59:44 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 2010/05/18 15:39:58 - [] D -- C:\ProgramData\Sun O43 - CFD: 2011/05/03 08:48:39 - [] D -- C:\ProgramData\Symantec O43 - CFD: 2009/03/18 05:16:51 - [] D -- C:\ProgramData\Temp O43 - CFD: 2006/11/02 14:59:44 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 2013/06/02 05:39:53 - [0] D -- C:\ProgramData\Turbine O43 - CFD: 2009/11/04 17:53:54 - [] D -- C:\ProgramData\UAB O43 - CFD: 2010/10/29 06:24:32 - [] D -- C:\ProgramData\VirtualizedApplications O43 - CFD: 2013/10/24 09:40:15 - [] D -- C:\ProgramData\VS Revo Group O43 - CFD: 2009/09/30 08:02:29 - [] D -- C:\ProgramData\WEBREG O43 - CFD: 2009/11/08 16:39:33 - [] D -- C:\ProgramData\WildTangent O43 - CFD: 2013/01/13 18:03:43 - [] D -- C:\ProgramData\WindowsSearch O43 - CFD: 2009/09/25 07:32:34 - [] D -- C:\ProgramData\WLInstaller O43 - CFD: 2011/04/23 09:45:47 - [0] D -- C:\ProgramData\Yahoo! O43 - CFD: 2012/08/30 14:15:35 - [] D -- C:\ProgramData\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A} O43 - CFD: 2010/03/11 22:14:55 - [] D -- C:\ProgramData\{dd9a9e7625afb6d9307f2cd8e4c1abd8} O43 - CFD: 2013/07/12 12:21:32 - [] D -- C:\Program Files\Common Files\Adobe O43 - CFD: 2013/11/14 22:48:55 - [] D -- C:\Program Files\Common Files\Adobe AIR O43 - CFD: 2010/10/07 08:38:10 - [] D -- C:\Program Files\Common Files\Adobe(6) O43 - CFD: 2012/09/02 16:19:54 - [] D -- C:\Program Files\Common Files\Apple O43 - CFD: 2011/06/23 13:27:58 - [0] D -- C:\Program Files\Common Files\Blizzard Entertainment O43 - CFD: 2014/05/14 08:02:13 - [] D -- C:\Program Files\Common Files\DESIGNER O43 - CFD: 2009/10/29 12:20:25 - [] D -- C:\Program Files\Common Files\France Telecom O43 - CFD: 2009/06/07 17:08:46 - [] D -- C:\Program Files\Common Files\Hewlett-Packard O43 - CFD: 2009/06/07 17:09:39 - [] D -- C:\Program Files\Common Files\HP O43 - CFD: 2012/02/07 20:54:16 - [] D -- C:\Program Files\Common Files\InstallShield O43 - CFD: 2009/10/24 10:46:24 - [] D -- C:\Program Files\Common Files\LightScribe O43 - CFD: 2014/04/06 12:39:39 - [] D -- C:\Program Files\Common Files\microsoft shared O43 - CFD: 2009/06/30 18:36:00 - [] D -- C:\Program Files\Common Files\Nikon O43 - CFD: 2012/12/24 09:01:47 - [] D -- C:\Program Files\Common Files\Panasonic O43 - CFD: 2012/09/02 16:33:35 - [] D -- C:\Program Files\Common Files\PX Storage Engine O43 - CFD: 2012/12/18 12:53:54 - [] D -- C:\Program Files\Common Files\Research In Motion O43 - CFD: 2010/12/29 12:04:02 - [] D -- C:\Program Files\Common Files\Samsung O43 - CFD: 2006/11/02 13:18:33 - [] D -- C:\Program Files\Common Files\Services O43 - CFD: 2006/11/02 13:18:33 - [] D -- C:\Program Files\Common Files\SpeechEngines O43 - CFD: 2013/02/27 18:42:59 - [] D -- C:\Program Files\Common Files\Steam O43 - CFD: 2012/07/11 09:09:06 - [] D -- C:\Program Files\Common Files\System O43 - CFD: 2009/10/06 15:29:15 - [] D -- C:\Program Files\Common Files\Windows Live O43 - CFD: 2009/09/25 07:35:11 - [] SHDC -- C:\Program Files\Common Files\WindowsLiveInstaller O43 - CFD: 2012/08/23 21:11:28 - [] D -- C:\Program Files\Common Files\XCPCSync.OEM O43 - CFD: 2008/01/01 18:04:26 - [] D -- C:\Users\Domi\AppData\Roaming\.minecraft O43 - CFD: 2014/01/25 16:12:00 - [] D -- C:\Users\Domi\AppData\Roaming\.mono O43 - CFD: 2015/05/16 08:21:45 - [0] D -- C:\Users\Domi\AppData\Roaming\39464E43-1431604033-5230-485A-00238B8ED55A O43 - CFD: 2013/07/16 16:02:48 - [] D -- C:\Users\Domi\AppData\Roaming\Adobe O43 - CFD: 2012/09/03 06:48:46 - [] D -- C:\Users\Domi\AppData\Roaming\Apple Computer O43 - CFD: 2012/09/05 07:30:24 - [0] D -- C:\Users\Domi\AppData\Roaming\avg O43 - CFD: 2012/08/23 20:56:59 - [] D -- C:\Users\Domi\AppData\Roaming\Blackberry Desktop O43 - CFD: 2009/10/24 12:37:11 - [] D -- C:\Users\Domi\AppData\Roaming\Blitware O43 - CFD: 2013/11/14 22:49:06 - [] D -- C:\Users\Domi\AppData\Roaming\com.zoosk.Desktop O43 - CFD: 2013/11/14 22:49:06 - [] D -- C:\Users\Domi\AppData\Roaming\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1 O43 - CFD: 2009/06/17 18:21:44 - [] D -- C:\Users\Domi\AppData\Roaming\CyberLink O43 - CFD: 2008/01/01 18:04:26 - [] D -- C:\Users\Domi\AppData\Roaming\dvdcss O43 - CFD: 2015/02/28 18:22:26 - [] HD -- C:\Users\Domi\AppData\Roaming\GoldenGate O43 - CFD: 2009/07/07 13:53:38 - [] D -- C:\Users\Domi\AppData\Roaming\Google O43 - CFD: 2009/10/24 08:48:55 - [] D -- C:\Users\Domi\AppData\Roaming\GTek O43 - CFD: 2009/06/06 14:25:05 - [] D -- C:\Users\Domi\AppData\Roaming\hewlett-packard O43 - CFD: 2009/09/30 08:02:29 - [] D -- C:\Users\Domi\AppData\Roaming\HP O43 - CFD: 2009/06/06 14:19:46 - [] D -- C:\Users\Domi\AppData\Roaming\HP TCS O43 - CFD: 2013/07/31 09:44:21 - [] D -- C:\Users\Domi\AppData\Roaming\HpUpdate O43 - CFD: 2008/01/01 18:04:40 - [] D -- C:\Users\Domi\AppData\Roaming\Icones O43 - CFD: 2009/06/06 14:24:29 - [] D -- C:\Users\Domi\AppData\Roaming\Identities O43 - CFD: 2010/04/06 17:07:03 - [] D -- C:\Users\Domi\AppData\Roaming\ImgBurn O43 - CFD: 2009/10/24 09:30:48 - [] D -- C:\Users\Domi\AppData\Roaming\InstallShield O43 - CFD: 2009/06/06 14:40:15 - [] D -- C:\Users\Domi\AppData\Roaming\Macromedia O43 - CFD: 2013/07/05 11:08:26 - [] D -- C:\Users\Domi\AppData\Roaming\Malwarebytes O43 - CFD: 2015/05/14 12:12:22 - [] SD -- C:\Users\Domi\AppData\Roaming\Microsoft O43 - CFD: 2012/07/27 11:31:23 - [] D -- C:\Users\Domi\AppData\Roaming\Mount&Blade Warband O43 - CFD: 2014/05/09 08:09:30 - [] D -- C:\Users\Domi\AppData\Roaming\Mozilla O43 - CFD: 2010/06/18 13:59:21 - [] D -- C:\Users\Domi\AppData\Roaming\OpenOffice.org O43 - CFD: 2014/01/30 00:55:53 - [0] D -- C:\Users\Domi\AppData\Roaming\Orange O43 - CFD: 2010/04/16 13:10:26 - [0] D -- C:\Users\Domi\AppData\Roaming\PeerNetworking O43 - CFD: 2012/08/23 20:43:40 - [] D -- C:\Users\Domi\AppData\Roaming\Research In Motion O43 - CFD: 2013/06/01 16:09:00 - [] D -- C:\Users\Domi\AppData\Roaming\Rovio O43 - CFD: 2012/09/16 01:39:11 - [] D -- C:\Users\Domi\AppData\Roaming\Samsung O43 - CFD: 2012/02/07 20:57:13 - [] RHD -- C:\Users\Domi\AppData\Roaming\SecuROM O43 - CFD: 2014/10/04 14:18:48 - [] D -- C:\Users\Domi\AppData\Roaming\Skype O43 - CFD: 2011/05/03 08:47:06 - [] D -- C:\Users\Domi\AppData\Roaming\SoftGrid Client O43 - CFD: 2010/05/01 14:33:05 - [] D -- C:\Users\Domi\AppData\Roaming\Synthesia O43 - CFD: 2014/04/02 16:39:12 - [] D -- C:\Users\Domi\AppData\Roaming\TeamViewer O43 - CFD: 2013/04/08 17:58:41 - [] D -- C:\Users\Domi\AppData\Roaming\Template O43 - CFD: 2010/09/30 15:31:14 - [0] D -- C:\Users\Domi\AppData\Roaming\TP O43 - CFD: 2013/11/24 12:26:54 - [] D -- C:\Users\Domi\AppData\Roaming\Unity O43 - CFD: 2015/02/25 18:54:11 - [] D -- C:\Users\Domi\AppData\Roaming\uTorrent O43 - CFD: 2008/01/01 18:04:41 - [] D -- C:\Users\Domi\AppData\Roaming\vlc O43 - CFD: 2013/02/19 09:41:47 - [] D -- C:\Users\Domi\AppData\Roaming\WinRAR O43 - CFD: 2010/04/10 13:14:28 - [] D -- C:\Users\Domi\AppData\Roaming\Wormux O43 - CFD: 2015/08/05 15:01:50 - [] D -- C:\Users\Domi\AppData\Roaming\ZHP O43 - CFD: 2015/06/10 13:12:04 - [] D -- C:\Users\Domi\AppData\Local\Adobe O43 - CFD: 2012/09/02 16:19:41 - [] D -- C:\Users\Domi\AppData\Local\Apple O43 - CFD: 2012/09/23 08:03:18 - [] D -- C:\Users\Domi\AppData\Local\Apple Computer O43 - CFD: 2009/06/06 14:16:51 - [0] SHD -- C:\Users\Domi\AppData\Local\Application Data O43 - CFD: 2008/01/01 18:04:24 - [] D -- C:\Users\Domi\AppData\Local\ApplicationHistory O43 - CFD: 2010/04/06 17:10:09 - [] D -- C:\Users\Domi\AppData\Local\Apps O43 - CFD: 2011/02/02 16:45:02 - [] D -- C:\Users\Domi\AppData\Local\assembly O43 - CFD: 2010/02/03 00:20:57 - [] D -- C:\Users\Domi\AppData\Local\Blizzard Entertainment O43 - CFD: 2015/08/02 21:58:44 - [0] D -- C:\Users\Domi\AppData\Local\CrashDumps O43 - CFD: 2015/05/14 09:46:24 - [] D -- C:\Users\Domi\AppData\Local\CrashRpt =>.Legitimate.CrashReports O43 - CFD: 2015/05/15 22:53:30 - [0] D -- C:\Users\Domi\AppData\Local\deni O43 - CFD: 2011/02/02 16:44:45 - [0] D -- C:\Users\Domi\AppData\Local\Deployment O43 - CFD: 2012/08/23 20:55:16 - [] D -- C:\Users\Domi\AppData\Local\Downloaded Installations O43 - CFD: 2012/09/06 09:35:02 - [] D -- C:\Users\Domi\AppData\Local\ElevatedDiagnostics O43 - CFD: 2012/09/03 09:14:10 - [] D -- C:\Users\Domi\AppData\Local\Google O43 - CFD: 2009/11/07 18:13:48 - [] D -- C:\Users\Domi\AppData\Local\Hewlett-Packard O43 - CFD: 2009/06/06 14:16:51 - [0] SHD -- C:\Users\Domi\AppData\Local\Historique O43 - CFD: 2012/02/27 11:12:36 - [] D -- C:\Users\Domi\AppData\Local\HP O43 - CFD: 2015/05/14 09:46:26 - [] D -- C:\Users\Domi\AppData\Local\Installer =>PUP.Optional.InstallPedia O43 - CFD: 2012/07/05 22:06:43 - [] D -- C:\Users\Domi\AppData\Local\Macromedia O43 - CFD: 2013/12/28 19:48:18 - [] D -- C:\Users\Domi\AppData\Local\Microsoft O43 - CFD: 2009/11/17 12:57:04 - [] D -- C:\Users\Domi\AppData\Local\Microsoft Games O43 - CFD: 2008/01/01 18:04:24 - [] D -- C:\Users\Domi\AppData\Local\Microsoft Help O43 - CFD: 2013/07/17 15:27:58 - [] D -- C:\Users\Domi\AppData\Local\MigWiz O43 - CFD: 2012/07/04 19:29:58 - [] D -- C:\Users\Domi\AppData\Local\Mozilla O43 - CFD: 2012/02/29 22:39:54 - [] D -- C:\Users\Domi\AppData\Local\MPlayer O43 - CFD: 2011/12/19 17:54:37 - [] D -- C:\Users\Domi\AppData\Local\Orange O43 - CFD: 2015/08/04 13:58:18 - [] D -- C:\Users\Domi\AppData\Local\Paint.NET O43 - CFD: 2012/12/24 09:02:34 - [] D -- C:\Users\Domi\AppData\Local\Panasonic O43 - CFD: 2009/07/06 18:50:09 - [0] D -- C:\Users\Domi\AppData\Local\Pixology O43 - CFD: 2012/02/24 12:26:34 - [] D -- C:\Users\Domi\AppData\Local\PunkBuster O43 - CFD: 2012/08/23 21:15:41 - [] D -- C:\Users\Domi\AppData\Local\Research In Motion O43 - CFD: 2015/05/10 10:23:57 - [] D -- C:\Users\Domi\AppData\Local\Roblox O43 - CFD: 2013/07/17 14:59:00 - [0] D -- C:\Users\Domi\AppData\Local\Samsung O43 - CFD: 2008/01/01 18:04:25 - [] D -- C:\Users\Domi\AppData\Local\Scrabble3D O43 - CFD: 2015/05/15 22:53:28 - [] D -- C:\Users\Domi\AppData\Local\Setup904587 O43 - CFD: 2009/10/22 12:38:39 - [] D -- C:\Users\Domi\AppData\Local\Seven Zip O43 - CFD: 2014/06/28 15:58:23 - [] D -- C:\Users\Domi\AppData\Local\Skype O43 - CFD: 2010/09/30 15:31:05 - [] D -- C:\Users\Domi\AppData\Local\SoftGrid Client O43 - CFD: 2008/01/01 18:04:25 - [] D -- C:\Users\Domi\AppData\Local\Solid State Networks O43 - CFD: 2015/08/05 15:00:54 - [] D -- C:\Users\Domi\AppData\Local\Temp O43 - CFD: 2014/10/03 10:48:43 - [] D -- C:\Users\Domi\AppData\Local\Temp(441) O43 - CFD: 2009/06/06 14:16:51 - [0] SHD -- C:\Users\Domi\AppData\Local\Temporary Internet Files O43 - CFD: 2012/04/08 22:14:12 - [] D -- C:\Users\Domi\AppData\Local\The Lord of the Rings Online O43 - CFD: 2008/01/01 18:04:25 - [] D -- C:\Users\Domi\AppData\Local\Turbine O43 - CFD: 2015/07/21 13:26:19 - [0] D -- C:\Users\Domi\AppData\Local\Unity O43 - CFD: 2009/06/30 18:50:36 - [] D -- C:\Users\Domi\AppData\Local\VirtualStore O43 - CFD: 2013/10/24 09:40:28 - [] D -- C:\Users\Domi\AppData\Local\VS Revo Group O43 - CFD: 2013/12/28 19:48:14 - [] D -- C:\Users\Domi\AppData\Local\Windows Live O43 - CFD: 2008/01/01 18:04:40 - [] RD -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2008/01/01 18:04:40 - [] RD -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2008/01/01 18:04:40 - [] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite O43 - CFD: 2008/01/01 18:04:40 - [] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam O43 - CFD: 2008/01/01 18:04:40 - [] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 2008/01/01 18:04:40 - [] RD -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2011/12/17 11:18:01 - [0] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My Application O43 - CFD: 2012/10/30 09:01:07 - [0] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Orange O43 - CFD: 2010/05/01 15:25:27 - [0] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pvm O43 - CFD: 2014/10/06 11:44:58 - [] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller O43 - CFD: 2015/05/16 08:03:15 - [] RD -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 2008/01/01 18:04:40 - [] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool O43 - CFD: 2008/01/01 18:04:40 - [] D -- C:\Users\Domi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ---\\ Enumération des clés de registre StartupReg (SMSR) (O53) (8) - 1s O53 - SMSR:HKLM\...\startupreg\APSDaemon [Key] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe O53 - SMSR:HKLM\...\startupreg\HPAdvisor [Key] . (...) -- C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\Malwarebytes Anti-Malware (cleanup) [Key] . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- rundll32.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\MsnMsgr [Key] . (...) -- C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe (.not file.) O53 - SMSR:HKLM\...\startupreg\Orange Installer [Key] . (...) -- C:\Program Files\Orange\Orange Installer\OrangeInstaller.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\QuickTime Task [Key] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe O53 - SMSR:HKLM\...\startupreg\SunJavaUpdateSched [Key] . (...) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\uTorrent [Key] . (.BitTorrent, Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe ---\\ Liste des pilotes du système (SDL) (O58) (79) - 164s O58 - SDL:2008/01/21 04:32:46 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [422968] O58 - SDL:2008/01/21 04:32:51 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [300600] O58 - SDL:2008/01/21 04:32:52 A . (.Adaptec, Inc. - Adaptec LH Ultra160 Driver (x86).) -- C:\Windows\System32\drivers\adpu160m.sys [101432] O58 - SDL:2008/01/21 04:32:53 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\drivers\adpu320.sys [149560] O58 - SDL:2009/02/27 06:43:10 N . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [17464] O58 - SDL:2008/01/21 04:32:49 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [79416] O58 - SDL:2008/01/21 04:32:50 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [79928] O58 - SDL:2008/12/20 01:01:46 A . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driv.) -- C:\Windows\System32\drivers\athr.sys [1093120] O58 - SDL:2006/11/02 10:24:45 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [13568] O58 - SDL:2006/11/02 10:24:46 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [5248] O58 - SDL:2006/11/02 10:25:24 A . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [71808] O58 - SDL:2006/11/02 10:24:44 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [62336] O58 - SDL:2006/11/02 10:24:44 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [12160] O58 - SDL:2006/11/02 10:24:47 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [11904] O58 - SDL:2009/02/27 06:43:10 N . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [19000] O58 - SDL:2006/11/02 11:50:11 A . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\drivers\djsvs.sys [71272] O58 - SDL:2008/01/21 04:32:50 A . (.Intel Corporation - Pilote désérialisé NDIS 6 de la carte Intel.) -- C:\Windows\System32\drivers\E1G60I32.sys [118784] O58 - SDL:2008/01/21 04:32:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [342584] O58 - SDL:2008/01/21 04:32:52 A . (.Hewlett-Packard Company - Smart Array Storport Driver.) -- C:\Windows\System32\drivers\HpCISSs.sys [40504] O58 - SDL:2007/06/18 17:12:04 A . (.Hewlett-Packard Development Company, L.P. - HpqKbFiltr Keyboard Filter Driver.) -- C:\Windows\System32\drivers\HpqKbFiltr.sys [16768] O58 - SDL:2008/01/21 04:32:49 A . (.Intel Corporation - Intel Matrix Storage Manager driver (base).) -- C:\Windows\System32\drivers\iaStorV.sys [235064] O58 - SDL:2008/10/28 10:29:36 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd32.sys [2476544] O58 - SDL:2006/11/02 11:50:17 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [41576] O58 - SDL:2008/09/22 07:49:36 A . (.Intel(R) Corporation - Intel(R) High Definition Audio HDMI.) -- C:\Windows\System32\drivers\IntcHdmi.sys [112128] O58 - SDL:2006/11/02 11:50:07 A . (.Integrated Technology Express, Inc. - ITE IT8211 ATA/ATAPI SCSI miniport.) -- C:\Windows\System32\drivers\iteatapi.sys [35944] O58 - SDL:2006/11/02 11:50:09 A . (.Integrated Technology Express, Inc. - ITE IT8212 ATA RAID SCSI miniport.) -- C:\Windows\System32\drivers\iteraid.sys [35944] O58 - SDL:2008/01/21 04:32:49 A . (.LSI Logic - LSI Logic Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [96312] O58 - SDL:2008/01/21 04:32:51 A . (.LSI Logic - LSI Logic Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [89656] O58 - SDL:2008/01/21 04:32:48 A . (.LSI Logic - LSI Logic Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [96312] O58 - SDL:2015/06/18 08:41:36 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\mbam.sys [23256] O58 - SDL:2015/06/18 08:41:42 A . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\drivers\mbamchameleon.sys [94936] O58 - SDL:2015/08/04 21:03:54 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys [98520] O58 - SDL:2008/01/21 04:32:53 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [31288] O58 - SDL:2008/01/21 04:32:52 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [386616] O58 - SDL:2006/11/02 11:49:59 A . (.LSI Logic Corporation - MegaRAID RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\Mraid35x.sys [33384] O58 - SDL:2015/06/18 08:41:50 A . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\drivers\mwac.sys [51928] O58 - SDL:2008/01/21 04:32:45 A . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\Windows\System32\drivers\NETw3v32.sys [2225664] O58 - SDL:2006/11/02 11:50:19 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [45160] O58 - SDL:2006/11/02 09:36:50 A . (.N-trig Innovative Technologies - Pilote intégré de digitalisateur de tablett.) -- C:\Windows\System32\drivers\ntrigdigi.sys [20608] O58 - SDL:2008/01/21 04:32:47 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [102968] O58 - SDL:2008/01/21 04:32:47 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [45112] O58 - SDL:2009/02/03 16:07:40 N . (.Printing Communications Assoc., Inc. (PCAUSA) - PCAUSA NDIS 5.0 MPR Protocol Driver.) -- C:\Windows\System32\drivers\PCAMp50.sys [28224] O58 - SDL:2009/02/03 16:07:42 N . (.Printing Communications Assoc., Inc. (PCAUSA) - PCAUSA NDIS 5.0 SPR Protocol Driver.) -- C:\Windows\System32\drivers\PCASp50.sys [27072] O58 - SDL:2011/11/29 04:28:28 N . (.Sonic Solutions - Px Engine Device Driver for Windows 2000/XP.) -- C:\Windows\System32\drivers\pxhelp20.sys [45648] O58 - SDL:2008/01/21 04:32:50 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1122360] O58 - SDL:2006/11/02 11:50:35 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [106088] O58 - SDL:2008/12/23 13:47:52 A . (.Realtek Corporation - Realtek 8101E/8168/8169 NDIS6 32-bit Driver.) -- C:\Windows\System32\drivers\Rtlh86.sys [138240] O58 - SDL:2006/11/02 08:37:21 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [20480] O58 - SDL:2008/01/21 04:32:52 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [74808] O58 - SDL:2006/11/02 11:50:05 A . (.LSI Logic - LSI Logic 8XX SCSI Miniport Driver.) -- C:\Windows\System32\drivers\symc8xx.sys [35944] O58 - SDL:2006/11/02 11:49:56 A . (.LSI Logic - LSI Logic Hi-Perf SCSI Miniport Driver.) -- C:\Windows\System32\drivers\sym_hi.sys [31848] O58 - SDL:2006/11/02 11:50:03 A . (.LSI Logic - LSI Logic Ultra160 SCSI Miniport Driver.) -- C:\Windows\System32\drivers\sym_u3.sys [34920] O58 - SDL:2008/12/05 00:55:14 A . (.Synaptics, Inc. - Synaptics Touchpad Driver.) -- C:\Windows\System32\drivers\SynTP.sys [204976] O58 - SDL:2008/01/21 04:32:45 A . (.ULi Electronics Inc. - ULi SATA Controller Driver.) -- C:\Windows\System32\drivers\uliahci.sys [238648] O58 - SDL:2006/11/02 11:50:35 A . (.Promise Technology, Inc. - Promise Ultra/Sata Series Driver for Win200.) -- C:\Windows\System32\drivers\ulsata.sys [98408] O58 - SDL:2008/01/21 04:32:49 A . (.Promise Technology, Inc. - Promise SATAII150 Series Windows Drivers.) -- C:\Windows\System32\drivers\ulsata2.sys [115816] O58 - SDL:2009/02/27 06:43:10 N . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [20024] O58 - SDL:2008/01/21 04:32:49 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [130616] O58 - SDL:2006/11/02 09:30:56 A . (.Marvell - Pilote miniport NDIS6.0 pour contrôleur Eth.) -- C:\Windows\System32\drivers\yk60x86.sys [194048] O58 - SDL:2008/08/29 10:49:04 A . (.ZTE Incorporated - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys [104960] O58 - SDL:2008/08/29 10:49:06 A . (.ZTE Corporation - USB NDIS Miniport Driver.) -- C:\Windows\System32\drivers\ZTEusbnet.sys [110080] O58 - SDL:2008/08/29 10:49:06 A . (.ZTE Incorporated - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\ZTEusbnmea.sys [104960] O58 - SDL:2008/08/29 10:49:06 A . (.ZTE Incorporated - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\ZTEusbser6k.sys [104960] O58 - SDL:2006/11/02 09:09:42 A . (...) -- C:\Windows\System32\ANSI.SYS [9029] O58 - SDL:2006/11/02 09:09:45 A . (...) -- C:\Windows\System32\country.sys [27097] O58 - SDL:2010/09/09 09:43:20 A . (...) -- C:\Windows\System32\FsUsbExDisk.Sys [36640] O58 - SDL:2006/11/02 09:09:41 A . (...) -- C:\Windows\System32\HIMEM.SYS [4768] O58 - SDL:2006/11/02 09:09:44 A . (...) -- C:\Windows\System32\KEY01.SYS [42809] O58 - SDL:2006/11/02 09:09:44 A . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537] O58 - SDL:2006/11/02 09:09:29 A . (...) -- C:\Windows\System32\NTDOS.SYS [27866] O58 - SDL:2006/11/02 09:09:35 A . (...) -- C:\Windows\System32\NTDOS404.SYS [29146] O58 - SDL:2006/11/02 09:09:38 A . (...) -- C:\Windows\System32\NTDOS411.SYS [29370] O58 - SDL:2006/11/02 09:09:40 A . (...) -- C:\Windows\System32\NTDOS412.SYS [29274] O58 - SDL:2006/11/02 09:09:31 A . (...) -- C:\Windows\System32\NTDOS804.SYS [29146] O58 - SDL:2006/11/02 09:09:20 A . (...) -- C:\Windows\System32\NTIO.SYS [33952] O58 - SDL:2006/11/02 09:09:23 A . (...) -- C:\Windows\System32\NTIO404.SYS [34672] O58 - SDL:2006/11/02 09:09:24 A . (...) -- C:\Windows\System32\NTIO411.SYS [35776] O58 - SDL:2006/11/02 09:09:26 A . (...) -- C:\Windows\System32\NTIO412.SYS [35536] O58 - SDL:2006/11/02 09:09:22 A . (...) -- C:\Windows\System32\NTIO804.SYS [34672] ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) (9) - 81s O61 - LFC: 2015/08/04 14:16:40 A . (..) -- C:\Users\Domi\Downloads\mbam2log_1(1).exe [948736] O61 - LFC: 2015/08/04 22:20:52 A . (..) -- C:\Users\Domi\Downloads\mbam2log_1(2).exe [948736] O61 - LFC: 2015/08/04 22:21:46 A . (..) -- C:\Users\Domi\Downloads\mbam2log_1(3).exe [948736] O61 - LFC: 2015/08/04 22:26:52 A . (..) -- C:\Users\Domi\Downloads\mbam2log_1(4).exe [948736] O61 - LFC: 2015/08/04 14:09:59 A . (..) -- C:\Users\Domi\Downloads\mbam2log_1.exe [948736] O61 - LFC: 2015/08/04 13:04:47 A . (..) -- C:\Users\Domi\Downloads\OneClick2RP.exe [739397] O61 - LFC: 2015/07/28 19:14:00 A . (..) -- C:\Users\Domi\AppData\Local\Google\Update\Install\{F97BF20E-534D-46BD-A948-B12F99C9AC66}\44.0.2403.125_43.0.2357.134_chrome_updater.exe [7371344] O61 - LFC: 2015/07/28 19:14:00 A . (..) -- C:\Users\Domi\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\44.0.2403.125\44.0.2403.125_43.0.2357.134_chrome_updater.exe [7371344] O61 - LFC: 2015/08/04 11:24:30 A . (..) -- C:\Users\Domi\AppData\Local\Adobe\Acrobat\10.0\UserCache.bin [72403] ---\\ Associations Shell Spawning (O67) (1) - 1s O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe ---\\ Menu de démarrage Internet (SMI) (O68) (12) - 2s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\Domi\AppData\Local\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- iexplore.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\Domi\AppData\Local\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Users\Domi\AppData\Local\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\Domi\AppData\Local\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) (4) - 17s O69 - SBI: prefs.js [Domi - w0hbv0us.default-1431618661383] user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine"); =>PUP.Optional.SearchEngine O69 - SBI: prefs.js [Domi - w0hbv0us.default-1431618661383] user_pref("browser.search.searchengine.ptid", "cmi"); =>PUP.Optional.SearchEngine O69 - SBI: prefs.js [Domi - w0hbv0us.default-1431618661383] user_pref("browser.search.searchengine.uid", "WDCXWD1600BEVT-60ZCT1_WD-WXE209PUA161UA161"); =>PUP.Optional.SearchEngine O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ ---\\ Enumère les services démarrés par Svchost (SSS) (O83) (32) - 3s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [24576] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [62976] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [247808] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [40448] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [40448] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [125952] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [576512] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [444928] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\audiosrv.dll [316928] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [90624] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [262144] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [68608] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [47104] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à.) -- C:\Windows\System32\ipnathlp.dll [288256] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [242688] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes Termi.) -- C:\Windows\System32\termsrv.dll [449536] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [1933848] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [758784] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [247808] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [200704] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [19968] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [33280] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [111616] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\System32\mmcss.dll [45056] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [153600] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [57344] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [162304] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [601600] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service de configuration des services Termi.) -- C:\Windows\System32\SessEnv.dll [84992] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [81920] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\KMSVC.DLL [68096] O83 - Search Svchost Services: ezSharedSvc (ezSharedSvc) . (.EasyBits Sofware AS - Shared EasyBits services for Windows.) -- C:\Windows\System32\ezsvc7.dll [129992] ---\\ Liste des exceptions du parefeu (FirewallRules) (O87) (6) - 8s O87 - FAEL: "{5B8CC3B6-74A6-40DF-A287-0B284E608198}" [In-None-P6-TRUE] .(.BitTorrent, Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe O87 - FAEL: "{226776D1-C90B-45F1-9A14-E3FBD4EEE5CA}" [In-None-P17-TRUE] .(.BitTorrent, Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe O87 - FAEL: "TCP Query User{DA1163CD-F9DE-42DB-A2DF-CB75043E4E51}C:\program files\utorrent\utorrent.exe" [In-None-P6-TRUE] .(.BitTorrent, Inc. - µTorrent.) -- C:\program files\utorrent\utorrent.exe O87 - FAEL: "UDP Query User{C341D1C7-A5CC-43D3-8EB9-171C373FFB34}C:\program files\utorrent\utorrent.exe" [In-None-P17-TRUE] .(.BitTorrent, Inc. - µTorrent.) -- C:\program files\utorrent\utorrent.exe O87 - FAEL: "{6361FD3A-BED8-49AC-B8D3-56CF3BA4301F}" [In-None-P6-TRUE] .(.Research In Motion - BlackBerry Desktop Software.) -- C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe O87 - FAEL: "{19792492-2E88-4F25-A14D-252429BD2D3D}" [In-None-P17-TRUE] .(.Research In Motion - BlackBerry Desktop Software.) -- C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe ---\\ Scan Additionnel (O88) (7) - 0s C:\Program Files\13c0c15a-7b86-4a21-b72b-22bb68b6e93f =>PUP.Optional.CrossRider C:\Program Files\450c05ba-477a-44b0-bcc7-f474e2d95235 =>PUP.Optional.CrossRider C:\Program Files\8fe2edcd-623c-40b1-ad3f-f290027245f7 =>PUP.Optional.CrossRider C:\Program Files\Software =>PUP.Optional.Boxore C:\ProgramData\Google =>PUP.Optional.Gen C:\Users\Domi\AppData\Local\CrashRpt =>.Legitimate.CrashReports C:\Users\Domi\AppData\Local\Installer =>PUP.Optional.InstallPedia ---\\ Récapitulatif des éléments trouvées sur votre station (6) - 0s http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider http://www.nicolascoolman.fr/adware-boxore/ =>PUP.Optional.Boxore http://www.nicolascoolman.fr/blog =>PUP.Optional.Gen http://www.nicolascoolman.fr/blog =>.Legitimate.CrashReports http://www.nicolascoolman.fr/adware-installpedia/ =>PUP.Optional.InstallPedia http://www.nicolascoolman.fr/blog =>PUP.Optional.SearchEngine ~ End of the scan, 28778 items in 736 seconds (915)(0)()