~ ZHPDiag v2015.10.2.147 Par Nicolas Coolman (2015/10/02) ~ Démarré par Gaïarac (Administrator) (2015/10/10 19:14:03) ~ Site: http://www.nicolascoolman.fr ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Etat de la version: Pas de fichier réseau ~ Mode: Scanner ~ Rapport: C:\Users\Gaïarac\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\Gaïarac\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ Démarrage du système: Normal (Normal boot) Windows 10 Home, 64-bit (Build 10240) ---\\ Navigateurs Internet (3) - 0s GCIE: Google Chrome v45.0.2454.101 MFIE: Mozilla Firefox 39.0 (x86 fr) v39.0 MSIE: Internet Explorer v11.0.10240.16431 ---\\ Informations sur les produits Windows (3) - 3s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK ---\\ Logiciels de protection (2) - 4s Avast Free Antivirus v10.2.2218 Windows Defender W10 (Deactivate) ---\\ Logiciels d'optimisation (1) - 5s CCleaner v5.06 ---\\ Surveillance de Logiciels (1) - 5s Adobe Reader XI ---\\ Informations sur le système (6) - 0s ~ Operating System: Intel64 Family 6 Model 37 Stepping 2, GenuineIntel ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 4116.98 MB (16% free) ~ System Restore: Activé (Enable) ~ System drive C: has 176 GB free of 461 GB ---\\ Mode de connexion au système (3) - 0s ~ Computer Name: GAÏA ~ User Name: Gaïarac ~ Logged in as Administrator ---\\ Enumération des unités disques (1) - 0s ~ Drive C: has 176 GB free of 461 GB (System) ---\\ Etat du Centre de Sécurité Windows (9) - 0s [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableRegistryTools: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK ---\\ Recherche particulière de fichiers génériques (25) - 1s [MD5.F1CBCB7FA6F3B309639AA2D4EF74469C] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\WINDOWS\Explorer.exe [4532304] © [MD5.5DED2A3F11AE916C8F2724947E736261] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\WINDOWS\System32\rundll32.exe [59392] © [MD5.7718A2A9B2BFB2C8E2BAEB03310CA3FD] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\WINDOWS\System32\Wininit.exe [290312] © [MD5.FE32B8423711B4B4378C0BA3C3560ED4] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\WINDOWS\System32\wininet.dll [2741760] © [MD5.84B1FE2E4615A89293F1FD4DE52EE26E] - (.Microsoft Corporation - Application d’ouverture de session Windows.) () -- C:\WINDOWS\System32\Winlogon.exe [578560] © [MD5.ECB1943967424DFB96E03F6A098434EF] - (.Microsoft Corporation - Bibliothèque de licences.) () -- C:\WINDOWS\System32\sppcomapi.dll [430592] © [MD5.C287D0E32771E3222A444DC527A29477] - (.Microsoft Corporation - DNS DLL de l’API Client.) () -- C:\WINDOWS\System32\dnsapi.dll [680256] © [MD5.BB5BBD0E4D04047585E4ED0F07AA51E7] - (.Microsoft Corporation - DNS DLL de l’API Client.) () -- C:\WINDOWS\Syswow64\dnsapi.dll [534064] © [MD5.8C795953726C7D2DE72CE4748208C5ED] - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) () -- C:\WINDOWS\System32\fr-FR\user32.dll.mui [20480] © [MD5.6C12C7E01A4F64E0AA9C88AF66955CC9] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) () -- C:\WINDOWS\System32\drivers\AFD.sys [577888] © [MD5.8921DF6060DB5C7700AA48CB12E9EA08] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\WINDOWS\System32\drivers\atapi.sys [28512] © [MD5.F2829DC6D292DCAC5029893BB2E9FEE3] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\WINDOWS\System32\drivers\Cdfs.sys [92672] © [MD5.CA160E02F35A61C6F5C681FB4669C519] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\WINDOWS\System32\drivers\Cdrom.sys [174080] © [MD5.25435407D97419627F4B10653433BF2B] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\WINDOWS\System32\drivers\DfsC.sys [138240] © [MD5.C277A49F8A8295840DEBC9240B75A282] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\WINDOWS\System32\drivers\HDAudBus.sys [80896] © [MD5.D4CDEE4A62BDFFF6E8558A9552148EA7] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\WINDOWS\System32\drivers\i8042prt.sys [114688] © [MD5.5D3744E6FDEC1A6FB3FA9B1DD4AF0694] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\WINDOWS\System32\drivers\IpNat.sys [143360] © [MD5.1DF2C5FD2710A13B07E663A12F0E0EEA] - (.Microsoft Corporation - Minirdr SMB Windows NT.) () -- C:\WINDOWS\System32\drivers\MRxSmb.sys [415232] © [MD5.F0D791348AD254360CC3C3E501CCB745] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\WINDOWS\System32\drivers\netBT.sys [273408] © [MD5.466EC5659C02ED53DBD47DC1BC2B8086] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\WINDOWS\System32\drivers\ntfs.sys [2116448] © [MD5.38F1AE32339731F6E5A7281AE8042545] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\WINDOWS\System32\drivers\Parport.sys [96768] © [MD5.CA60F6C03611AF1710BC903ED9F566FB] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [104960] © [MD5.A32AED8C644734B283A7C9D08D76064D] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) () -- C:\WINDOWS\System32\drivers\rdpdr.sys [176128] © [MD5.28E1E63A1AC65E17B3194238FA2CF3BF] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\WINDOWS\System32\drivers\tdx.sys [116576] © [MD5.823A237D871CD652C6BFD47BECB6810A] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\WINDOWS\System32\drivers\volsnap.sys [378720] © ---\\ Processus lancés (49) - 3s [MD5.53E30A6E86AA93C0FFC0BC0439E3E636] - (.Sensible Vision - FastAccess.) -- C:\Program Files\Alienware\Command Center\AlienSense\FAService.exe [2409800] [PID.1540] © [MD5.1FCAF9C8A17985A28507338F36200320] - (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_056607ee0106e5e8\stacsv64.exe [240640] [PID.1572] © [MD5.54236E79A44F909612391C8A2D70D512] - (.Avast Software s.r.o. - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336] [PID.2016] © [MD5.013697369EAFFA675D0671607F036020] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [82128] [PID.2508] © [MD5.8CD92502FEC49E837155B9F20E5E2D2C] - (...) -- C:\Program Files (x86)\OSD\OSD_Service.exe [16384] [PID.2572] [MD5.A6FB9DB8F1A86861D955FD6975977AE0] - (.Andrea Electronics Corporation - Andrea filters APO access service (64-bit).) -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_056607ee0106e5e8\AESTSr64.exe [89600] [PID.2600] © [MD5.EBBCD5DFBB1DE70E8F4AF8FA59E401FD] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [462184] [PID.2628] © [MD5.A99E57669390F265D25288C8BA042D78] - (.Alienware - AlienFusionService.) -- C:\Program Files\Alienware\Command Center\AlienFusionService.exe [14648] [PID.2648] © [MD5.30E3850F303EAE5C364782EA78579CC9] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55624] [PID.2772] © [MD5.660BF3255A1EB18ED803FD2FBA6AE400] - (.Intel Corporation - RAID Monitor.) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe [354840] [PID.2788] © [MD5.9C58665F465646B0784F595240237C10] - (.Synaptics Incorporated - 64-bit Synaptics Pointing Enhance Service.) -- C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [247968] [PID.2896] © [MD5.74EC60E20516AAA573BE74F31175270F] - (.SoftThinks SAS - SoftThinks Agent Service.) -- C:\Program Files (x86)\AlienRespawn\sftservice.EXE [1692480] [PID.2948] © [MD5.7D2633295EB6FF2B938185874884059D] - (.Nero AG - Nero BackItUp.) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [935208] [PID.3036] © [MD5.46C430FE178028F7AD151B62EBA3EEC5] - (.Avast Software - AvastVirtualBox Interface.) -- C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4034896] [PID.4432] © [MD5.A72BB48D9014A7D7C05F02F595F52D60] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe [245576] [PID.4748] © [MD5.E337785DA1958E9AB02DDB2369EF46E8] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe [307016] [PID.2660] © [MD5.D0117917EB976A484B3A9E3AA7142108] - (.AVAST Software - avast! NG service.) -- C:\Program Files\AVAST Software\Avast\ng\ngservice.exe [171896] [PID.5976] © [MD5.3CBF73052CE14F1455779FE501BCDA38] - (.Apple Inc. - iPodService Module (64-bit).) -- C:\Program Files\iPod\bin\iPodService.exe [641352] [PID.7880] © [MD5.6DD5B6F43B389A058FA92C2C955F1296] - (.AMD - AMD External Events Service Module.) -- C:\WINDOWS\system32\atiesrxx.exe [255472] [PID.421732] © [MD5.E9DAAABF8CBD6B8F645CCA1BF58FE7C8] - (.SoftThinks - Dell - AlienRespawn.) -- C:\Program Files (x86)\AlienRespawn\Toaster.exe [3970880] [PID.456332] © [MD5.784627E486E9671615B45435EE676FA8] - (.SoftThinks - Dell - AlienRespawn Update Launcher.) -- C:\Program Files (x86)\AlienRespawn\Components\DSUpdate\DSUpd.exe [315712] [PID.474768] © [MD5.CD4F7B90CB09831BCDEDE0A206CCDB35] - (.© 2007-2011 SoftThinks SAS - ST Service Scheduling.) -- C:\Program Files (x86)\AlienRespawn\COMPONENTS\SCHEDULER\STSERVICE.EXE [2751808] [PID.462884] © [MD5.2FEF28D0506C0A13F9CA066E4BF99666] - (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray64.exe [487424] [PID.475248] © [MD5.D1930CA970D4250D891F432419E3D6C9] - (.Intel Corporation - Event Monitor User Notification Tool.) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe [186904] [PID.476216] © [MD5.95FAB969D756CA7C80CDE1FD7D74A2B4] - (.Alienware Corporation - Alienware AlienFX Controller.) -- C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe [63304] [PID.473812] [MD5.C39D00A2D683C37D713673C8C29AE29C] - (.Synaptics Incorporated - Synaptics TouchPad 64-bit Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3952800] [PID.476924] © [MD5.6C83D6FDCE5CA49634988B96F788FEEC] - (...) -- C:\Program Files (x86)\WSE_Astromenda\BRS\brs.exe [1043968] [PID.476660] =>PUP.Optional.Astromenda [MD5.CB4B4EB8287D28710FAE928B434EB70B] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\PROGRAM FILES\SYNAPTICS\SynTP\SYNTPHELPER.EXE [211616] [PID.475220] © [MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.475212] © [MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.439268] © [MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.472500] © [MD5.362A07AA3055C61F386C807C56BC8F97] - (.Sony - Sony PC Companion.) -- C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [457088] [PID.456864] © [MD5.AA1600118E222FCBE3F3BFEC1ABEC309] - (...) -- C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe [113024] [PID.476476] [MD5.AEFFC5990BA4E5F037108DBAAEE96F13] - (.Alienware - AlienFXHook32 Manager.) -- C:\Program Files\Alienware\Command Center\AlienFXHook32Mngr.exe [13624] [PID.472008] © [MD5.058F7CACD0E60BCDC5C3E38BE2539958] - (.Microsoft - .) -- C:\Program Files (x86)\OSD\OSD_Main.exe [86016] [PID.456308] © [MD5.65C6AA484AD2287D20541C7735989437] - (.Avast Software s.r.o. - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastui.exe [5515496] [PID.456256] © [MD5.E7FB068FE918DE0CA412A072EE252329] - (.Alienware - AlienFXHook64 Manager.) -- C:\Program Files\Alienware\Command Center\AlienFXHook64Mngr.exe [13112] [PID.474904] © [MD5.E3AECB28EBE04FFD535745912839D72D] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392] [PID.477296] © [MD5.F9559F6BADB5B3ED3FCBFBD25F3E767E] - (.Sensible Vision - FATrayMon.) -- C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe [95560] [PID.477340] © [MD5.FABBD13CBD83F18D046FFCE01947F3EB] - (.Sensible Vision - FATrayAlert Application.) -- C:\Program Files\Alienware\Command Center\AlienSense\FATrayAlert.exe [1992008] [PID.477484] © [MD5.E61CA2821C853D02FA71CB4EDEC89C71] - (.Advanced Micro Devices Inc. - Catalyst Control Center: Monitoring program.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe [307400] [PID.477596] © [MD5.09266319529C342813EA013E24200568] - (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe [8322328] [PID.477776] © [MD5.FD5FCA422BD5D9DF440F2F823E772BEA] - (.Advanced Micro Devices Inc. - Catalyst Control Center: Host application.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [307912] [PID.477888] © [MD5.499F1C3C03BE85A60DD32EC2D3CE16E8] - (.Copyright © 2009 - AlienFusionController.) -- C:\Program Files\Alienware\Command Center\AlienFusionController.exe [16704] [PID.478320] [MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.456880] © [MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.473136] © [MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.478996] © [MD5.DD7DAC8A6913EB893372091E96871F95] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Gaïarac\Downloads\ZHPDiag3.exe [1940992] [PID.479076] © [MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.475580] © ---\\ Google Chrome, Démarrage,Recherche,Extensions (11) - 0s G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.ecosia.org G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [clellnciejhoedgepbdilbkdkaoecgpc] __MSG_search_string__ G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [lccekmodgklaepjeofjdjpbminllajkg] Chrome Hotword Shared Module G2 - GCE: Preference [User Data\Default] [mlokkcjedhnbjnefdocneanhofenlhkg] EcoLink - Plant trees for free! G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [pfhldcakmgpmglboaclpfdedehjblalp] 20-20 3D Viewer for IKEA G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc. ---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (20) - 2s M1 - SPR:Search Page Redirection - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} M1 - SPR:Search Page Redirection - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} M1 - SPR:Search Page Redirection - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} P2 - EXT FILE: (...) -- C:\Users\Gaïarac\AppData\Roaming\Mozilla\Firefox\Profiles\6a6z47go.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi P2 - EXT FILE: (...) -- C:\Users\Gaïarac\AppData\Roaming\Mozilla\Firefox\Profiles\6a6z47go.default\searchplugins\trovi-search.xml =>PUP.Optional.TroviCom P2 - EXT FILE: (...) -- C:\Users\Gaïarac\AppData\Roaming\Mozilla\Firefox\Profiles\6a6z47go.default\searchplugins\yahoo-avast.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\amazon-france.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\bing.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\ddg.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\eBay-france.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\google.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\sweet-page.xml =>PUP.Optional.SweetPage P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\yahoo-france.xml P2 - EXT: (.Mozilla - Default.) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} © P2 - EXT: (.savesense.com - SaveSense.) -- C:\Users\Gaïarac\AppData\Roaming\Mozilla\Firefox\Profiles\6a6z47go.default\extensions\{8b337819-d1e8-48d3-8178-168ae8c99c36} P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Apple Inc..) -- C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll © P2 - FPN: [HKLM] [@tools.updaterss.com/SaveSenseLive Update;version=3] - (.SaveSense.) -- C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll =>PUP.Optional.SaveSense P2 - FPN: [HKLM] [@tools.updaterss.com/SaveSenseLive Update;version=9] - (.SaveSense.) -- C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll =>PUP.Optional.SaveSense ---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (20) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://fr.yhs4.search.yahoo.com/ =>PUP.Optional.Browser R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/ =>PUP.Optional.SweetPage R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://support.alienware.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://fr.yahoo.com?fr=hp-avast&type=avastbcl R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 ---\\ Internet Explorer,Proxy Management (5) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s F2 - REG:system.ini: UserInit= F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) © F2 - REG:system.ini: VMApplet= ---\\ Etude du fichier hosts (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (21) ---\\ Browser Helper Object de navigateur (BHO) (5) - 0s O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\ssv.dll © O2 - BHO: avast! Online Security [64Bits] - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.Avast Software s.r.o. - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll © O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL © O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll © O2 - BHO: DVDVideoSoft.WebPageAdjuster [64Bits] - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} (Orphean) ---\\ Applications lancées au démarrage du système (28) - 1s O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray64.exe © O4 - HKLM\..\Run: [IAAnotif] . (.Intel Corporation - Event Monitor User Notification Tool.) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe © O4 - HKLM\..\Run: [AlienFX Controller] . (.Alienware Corporation - Alienware AlienFX Controller.) -- C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe O4 - HKLM\..\Run: [WindowsDefender] C:\Program Files (x86)\Windows Defender\MSASCui.exe (.not file.) O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.) O4 - HKCU\..\Run: [BRS] . (...) -- C:\Program Files (x86)\WSE_Astromenda\BRS\brs.exe =>PUP.Optional.Astromenda O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_DFFD2D953F1DBD000854A33AB8AAD6E7] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe © O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Gaïarac\AppData\Local\Microsoft\OneDrive\OneDrive.exe © O4 - HKCU\..\Run: [Sony PC Companion] . (.Sony - Sony PC Companion.) -- C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe © O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Gaïarac\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe © O4 - HKLM\..\Wow6432Node\Run: [OSD_LAUNCH] . (.HH - .) -- c:\Program Files (x86)\OSD\Launch.exe O4 - HKLM\..\Wow6432Node\Run: [FAStartup] (Orphean) O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.Avast Software s.r.o. - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastui.exe © O4 - HKLM\..\Wow6432Node\Run: [UCam_Menu] . (.CyberLink Corp. - MUI StartMenu Application.) -- c:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe © O4 - HKLM\..\Wow6432Node\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files (x86)\QuickTime\QTTask.exe © O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe © O4 - HKLM\..\Wow6432Node\Run: [FATrayAlert] . (.Sensible Vision - FATrayMon.) -- C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe © O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe © O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe © O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe © O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe © O4 - HKUS\S-1-5-21-726566939-3289756832-2678918575-1001\..\Run: [BRS] . (...) -- C:\Program Files (x86)\WSE_Astromenda\BRS\brs.exe =>PUP.Optional.Astromenda O4 - HKUS\S-1-5-21-726566939-3289756832-2678918575-1001\..\Run: [GoogleChromeAutoLaunch_DFFD2D953F1DBD000854A33AB8AAD6E7] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © O4 - HKUS\S-1-5-21-726566939-3289756832-2678918575-1001\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe © O4 - HKUS\S-1-5-21-726566939-3289756832-2678918575-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Gaïarac\AppData\Local\Microsoft\OneDrive\OneDrive.exe © O4 - HKUS\S-1-5-21-726566939-3289756832-2678918575-1001\..\Run: [Sony PC Companion] . (.Sony - Sony PC Companion.) -- C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe © O4 - HKUS\S-1-5-21-726566939-3289756832-2678918575-1001\..\RunOnce: [Uninstall C:\Users\Gaïarac\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe © ---\\ Modification Domaine/Adresses DNS (4) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.65.105.1 10.65.105.2 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 10.65.105.1 10.65.105.2 ---\\ Protocole additionnel (25) - 1s O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll © O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll © O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll © O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll © O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll © O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll © O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll © O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll © O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll © O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll © O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll © O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll © O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll © O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll © O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll © O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll © O18 - Handler: skype-ie-addon-data [64Bits] - {91774881-D725-4E58-B298-07617B9B86A8} . (.Skype Technologies S.A. - Skype Click to Call for Internet Explorer.) -- C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll © O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll © O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll © O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll © O18 - Handler: wlmailhtml [64Bits] - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll © O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll © O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll © O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll © O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL © ---\\ Liste des services NT non Microsoft et non désactivés (17) - 0s O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe © O23 - Service: Andrea ST Filters Service (AESTFilters) . (.Andrea Electronics Corporation - Andrea filters APO access service (64-bit).) - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_056607ee0106e5e8\AESTSr64.exe © O23 - Service: Alienware Fusion Service (AlienFusionService) . (.Alienware - AlienFusionService.) - C:\Program Files\Alienware\Command Center\AlienFusionService.exe © O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\WINDOWS\system32\atiesrxx.exe © O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe © O23 - Service: Avast Antivirus (avast! Antivirus) . (.Avast Software s.r.o. - avast! Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe © O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe © O23 - Service: FAService (FAService) . (.Sensible Vision - FastAccess.) - C:\Program Files\Alienware\Command Center\AlienSense\FAService.exe © O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe © O23 - Service: HappyOSD (HappyOSD) . (...) - C:\Program Files (x86)\OSD\OSD_Service.exe O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) . (.Intel Corporation - RAID Monitor.) - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe © O23 - Service: Nero BackItUp Scheduler 4.0 (Nero BackItUp Scheduler 4.0) . (.Nero AG - Nero BackItUp.) - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe © O23 - Service: SaveSenseLive Service (savesenselive) (savesenselive) . (.SaveSense - SaveSenseLive Update.) - C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe =>PUP.Optional.SaveSense O23 - Service: SoftThinks Agent Service (SftService) . (.SoftThinks SAS - SoftThinks Agent Service.) - C:\Program Files (x86)\AlienRespawn\sftservice.EXE © O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe © O23 - Service: Audio Service (STacSV) . (.IDT, Inc. - IDT PC Audio.) - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_056607ee0106e5e8\stacsv64.exe © O23 - Service: SynTPEnh Caller Service (SynTPEnhService) . (.Synaptics Incorporated - 64-bit Synaptics Pointing Enhance Service.) - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe © ---\\ Tâches planifiées en automatique (39) - 5s [MD5.E3FB05F33E1404AD606B1E1FE7C323C3] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [998104] © [MD5.C50B830CA9BCD63754928CD6C0E2B114] [APT] [avast! Emergency Update] (.Avast Software s.r.o..) -- C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [1298688] © [MD5.EE526B0428581B57FFC571FF57309E28] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6369048] © [MD5.00000000000000000000000000000000] [APT] [FacebookUpdateTaskUserS-1-5-21-726566939-3289756832-2678918575-1001Core] (...) -- C:\Users\Ga‹arac\AppData\Local\Facebook\Update\FacebookUpdate.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [FacebookUpdateTaskUserS-1-5-21-726566939-3289756832-2678918575-1001UA] (...) -- C:\Users\Ga‹arac\AppData\Local\Facebook\Update\FacebookUpdate.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [GlaryInitialize 5] (...) -- C:\Program Files (x86)\Glary Utilities 5\Initialize.exe (.not file.) [0] [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] © [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] © [MD5.C495D8665A32539660625182D23D5C59] [APT] [SaveSenseLiveUpdateTaskMachineCore] (.SaveSense.) -- C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [146920] =>PUP.Optional.SaveSense [MD5.C495D8665A32539660625182D23D5C59] [APT] [SaveSenseLiveUpdateTaskMachineUA] (.SaveSense.) -- C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [146920] =>PUP.Optional.SaveSense [MD5.00000000000000000000000000000000] [APT] [Vosteran_helper] (...) -- C:\Users\GAARAC~1\AppData\Local\Vosteran\APPLIC~1\Vosteran\helper.exe (.not file.) [0] =>PUP.Optional.Vosteran [MD5.E2E3D191AD68F9C360AAC18947CAA555] [APT] [WSE_Astromenda] (...) -- C:\Users\Gaïarac\AppData\Roaming\WSE_Astromenda\UpdateProc\UpdateTask.exe [455168] =>PUP.Optional.Astromenda [MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] [APT] [{2DF8B188-D616-4EC2-B46F-A42198D93A6D}] (.Google Inc..) -- c:\program files (x86)\Google\Chrome\application\chrome.exe [815944] © [MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] [APT] [{3FC41557-2380-4EE7-894C-D345526FB7EF}] (.Google Inc..) -- c:\program files (x86)\Google\Chrome\application\chrome.exe [815944] © [MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] [APT] [{40F1650F-BC10-43BD-B261-4DFBEFD6F467}] (.Google Inc..) -- c:\program files (x86)\Google\Chrome\application\chrome.exe [815944] © [MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] [APT] [{4752D22B-94B8-4B59-AD97-E90A8380A383}] (.Google Inc..) -- c:\program files (x86)\Google\Chrome\application\chrome.exe [815944] © [MD5.71DCFA65CC4349CF08BFFF7A14D8BAE4] [APT] [{BEF22EA0-C24C-4BCE-BDF4-506FD09E885B}] (.Google Inc..) -- c:\program files (x86)\Google\Chrome\application\chrome.exe [815944] © [MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [Apple\AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [561984] © O39 - APT: FacebookUpdateTaskUserS-1-5-21-726566939-3289756832-2678918575-1001Core - (...) -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-726566939-3289756832-2678918575-1001Core.job [914] O39 - APT: FacebookUpdateTaskUserS-1-5-21-726566939-3289756832-2678918575-1001UA - (...) -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-726566939-3289756832-2678918575-1001UA.job [936] O39 - APT: GlaryInitialize 5 - (...) -- C:\WINDOWS\Tasks\GlaryInitialize 5.job [336] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [1082] © O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [1086] © O39 - APT: SaveSenseLiveUpdateTaskMachineCore - (.SaveSense.) -- C:\WINDOWS\Tasks\SaveSenseLiveUpdateTaskMachineCore.job [930] =>PUP.Optional.SaveSense O39 - APT: SaveSenseLiveUpdateTaskMachineUA - (.SaveSense.) -- C:\WINDOWS\Tasks\SaveSenseLiveUpdateTaskMachineUA.job [934] =>PUP.Optional.SaveSense O39 - APT: Vosteran_helper - (...) -- C:\WINDOWS\Tasks\Vosteran_helper.job [312] =>PUP.Optional.Vosteran O39 - APT: WSE_Astromenda - (...) -- C:\WINDOWS\Tasks\WSE_Astromenda.job [302] =>PUP.Optional.Astromenda O39 - APT: Adobe Acrobat Update Task - (.Adobe Systems Incorporated.) -- C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task [3996] © O39 - APT: avast! Emergency Update - (.Avast Software s.r.o..) -- C:\WINDOWS\System32\Tasks\avast! Emergency Update [4280] © O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\WINDOWS\System32\Tasks\CCleanerSkipUAC [2886] © O39 - APT: FacebookUpdateTaskUserS-1-5-21-726566939-3289756832-2678918575-1001Core - (...) -- C:\WINDOWS\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-726566939-3289756832-2678918575-1001Core [3658] O39 - APT: FacebookUpdateTaskUserS-1-5-21-726566939-3289756832-2678918575-1001UA - (...) -- C:\WINDOWS\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-726566939-3289756832-2678918575-1001UA [4026] O39 - APT: GlaryInitialize 5 - (...) -- C:\WINDOWS\System32\Tasks\GlaryInitialize 5 [2738] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore [3912] © O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA [4144] © O39 - APT: SaveSenseLiveUpdateTaskMachineCore - (.SaveSense.) -- C:\WINDOWS\System32\Tasks\SaveSenseLiveUpdateTaskMachineCore [3788] =>PUP.Optional.SaveSense O39 - APT: SaveSenseLiveUpdateTaskMachineUA - (.SaveSense.) -- C:\WINDOWS\System32\Tasks\SaveSenseLiveUpdateTaskMachineUA [4040] =>PUP.Optional.SaveSense O39 - APT: Vosteran_helper - (...) -- C:\WINDOWS\System32\Tasks\Vosteran_helper [3358] =>PUP.Optional.Vosteran O39 - APT: WSE_Astromenda - (...) -- C:\WINDOWS\System32\Tasks\WSE_Astromenda [3348] =>PUP.Optional.Astromenda ---\\ Logiciels installés (97) - 7s O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner © O42 - Logiciel: Intel(R) Network Connections 14.8.43.0 - (.Intel.) [HKLM][64Bits] -- PROSetDX © O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey © O42 - Logiciel: Intel(R) Network Connections 14.8.43.0 - (.Intel.) [HKLM][64Bits] -- {11107A2A-AD44-4BC8-ABB5-E88E63BCA785} © O42 - Logiciel: Java 7 Update 45 (64-bit) - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F86417045FF} © O42 - Logiciel: MPC-HC 1.7.8 (64-bit) - (.MPC-HC Team.) [HKLM][64Bits] -- {2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1 © O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM][64Bits] -- {2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C} © O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM][64Bits] -- {37D0157F-45C6-4DB2-9AE5-489DD98CE169} © O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] -- {6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D} © O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} © O42 - Logiciel: Intel® Matrix Storage Manager - (.Intel Corporation.) [HKLM][64Bits] -- {9068B2BE-D93A-4C0A-861C-5E35E2C0E09E} © O42 - Logiciel: Microsoft DVD App Installation for Microsoft.WindowsDVDPlayer_2019.6.11761. - (.Microsoft Corporation.) [HKLM][64Bits] -- {986E003C-E56D-5A47-110E-D3C81F0E8535} © O42 - Logiciel: WIDCOMM Bluetooth Software - (.Broadcom Corporation.) [HKLM][64Bits] -- {9E9D49A4-1DF4-4138-B7DB-5D87A893088E} © O42 - Logiciel: PDF-Viewer - (.Tracker Software Products Ltd.) [HKLM][64Bits] -- {A278382D-4F1B-4D47-9885-8523F7261E8D}_is1 © O42 - Logiciel: Command Center - (.Alienware Corp..) [HKLM][64Bits] -- {AE1E0DFB-A3D9-451C-AA7F-46FD390400D4} © O42 - Logiciel: 7-Zip 9.20 - (...) [HKLM][64Bits] -- 7-Zip O42 - Logiciel: Adobe Shockwave Player 12.1 - (.Adobe Systems, Inc..) [HKLM][64Bits] -- Adobe Shockwave Player © O42 - Logiciel: Age of Empires III Complete Collection version 1.14 - (.Alucard2.) [HKLM][64Bits] -- Age of Empires III Complete Collection_is1 O42 - Logiciel: Avast Free Antivirus - (.AVAST Software.) [HKLM][64Bits] -- Avast © O42 - Logiciel: Battle.net - (.Blizzard Entertainment.) [HKLM][64Bits] -- Battle.net © O42 - Logiciel: dBpoweramp Music Converter - (.Illustrate.) [HKLM][64Bits] -- dBpoweramp Music Converter © O42 - Logiciel: dBpoweramp Windows Media Audio 10 Codec - (.Illustrate.) [HKLM][64Bits] -- dBpoweramp Windows Media Audio 10 Codec © O42 - Logiciel: Diablo III - (.Blizzard Entertainment.) [HKLM][64Bits] -- Diablo III © O42 - Logiciel: Free YouTube to MP3 Converter version 3.12.29.304 - (.DVDVideoSoft Ltd..) [HKLM][64Bits] -- Free YouTube to MP3 Converter_is1 © O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome © O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D} © O42 - Logiciel: Command Center - (.Alienware Corp..) [HKLM][64Bits] -- InstallShield_{AE1E0DFB-A3D9-451C-AA7F-46FD390400D4} © O42 - Logiciel: Fable - The Lost Chapters - (.Microsoft Game Studios.) [HKLM][64Bits] -- InstallShield_{C3C9EB3D-24FA-4462-B784-0EC6AAFCD2DD} © O42 - Logiciel: Middle Earth Shadow of Mordor - (...) [HKLM][64Bits] -- Middle Earth Shadow of Mordor_is1 O42 - Logiciel: Mozilla Firefox 39.0 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 39.0 (x86 fr) © O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService © O42 - Logiciel: Microsoft Project Professionnel 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- Office14.PRJPROR © O42 - Logiciel: Revo Uninstaller 1.95 - (.VS Revo Group.) [HKLM][64Bits] -- Revo Uninstaller © O42 - Logiciel: SaveSense (remove only) - (.SaveSense.) [HKLM][64Bits] -- SaveSense O42 - Logiciel: sweet-page uninstall - (.sweet-page.) [HKLM][64Bits] -- sweet-page uninstall =>PUP.Optional.SweetPage O42 - Logiciel: Switch Sound File Converter - (.NCH Software.) [HKLM][64Bits] -- Switch © O42 - Logiciel: Sony Mobile Update Engine - (.Sony Mobile Communications Inc..) [HKLM][64Bits] -- Update Engine © O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player © O42 - Logiciel: WSE_Astromenda - (.WSE_Astromenda.) [HKLM][64Bits] -- WSE_Astromenda =>PUP.Optional.Astromenda O42 - Logiciel: AMD Catalyst Control Center - (.AMD.) [HKLM][64Bits] -- WUCCCApp © O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM][64Bits] -- {01FB4998-33C4-4431-85ED-079E3EEFE75D} © O42 - Logiciel: AlienRespawn - (.Alienware.) [HKLM][64Bits] -- {0ED7EE95-6A97-47AA-AD73-152C08A15B04} © O42 - Logiciel: Catalyst Control Center - Branding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {11087D24-567D-7D88-69C6-D7A08B5F4C47} © O42 - Logiciel: MSXML 4.0 SP3 Parser - (.Microsoft Corporation.) [HKLM][64Bits] -- {196467F1-C11F-4F76-858B-5812ADC83B94} © O42 - Logiciel: MSXML 4.0 SP3 Parser (KB2758694) - (.Microsoft Corporation.) [HKLM][64Bits] -- {1D95BA90-F4F8-47EC-A882-441C99D30C1E} © O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM][64Bits] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4} © O42 - Logiciel: Nero InfoTool Help - (.Nero AG.) [HKLM][64Bits] -- {20400DBD-E6DB-45B8-9B6B-1DD7033818EC} © O42 - Logiciel: Facebook Video Calling 3.1.0.521 - (.Skype Limited.) [HKLM][64Bits] -- {2091F234-EB58-4B80-8C96-8EB78C808CF7} © O42 - Logiciel: Nero StartSmart Help - (.Nero AG.) [HKLM][64Bits] -- {2348B586-C9AE-46CE-936C-A68E9426E214} © O42 - Logiciel: Java 7 Update 45 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83217045FF} © O42 - Logiciel: Nero DriveSpeed - (.Nero AG.) [HKLM][64Bits] -- {33CF58F5-48D8-4575-83D6-96F574E4D83A} © O42 - Logiciel: Nero Rescue Agent - (.Nero AG.) [HKLM][64Bits] -- {368BA326-73AD-4351-84ED-3C0A7A52CC53} © O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM][64Bits] -- {46F044A5-CE8B-4196-984E-5BD6525E361D} © O42 - Logiciel: Google Earth - (.Google.) [HKLM][64Bits] -- {4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E} © O42 - Logiciel: neroxml - (.Nero AG.) [HKLM][64Bits] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B} © O42 - Logiciel: NeroExpress - (.Nero AG.) [HKLM][64Bits] -- {595A3116-40BB-4E0F-A2E8-D7951DA56270} © O42 - Logiciel: RICOH R5C83x/84x Flash Media Controller Driver Ver.3.57.01 - (.RICOH.) [HKLM][64Bits] -- {59F6A514-9813-47A3-948C-8A155460CC2A} © O42 - Logiciel: Nero RescueAgent Help - (.Nero AG.) [HKLM][64Bits] -- {5E08ECD1-C98E-4711-BF65-8FD736B3F969} © O42 - Logiciel: Nero Disc Copy Gadget Help - (.Nero AG.) [HKLM][64Bits] -- {60C731FB-C951-41CE-AD41-8E54C8594609} © O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} © O42 - Logiciel: Nero CoverDesigner - (.Nero AG.) [HKLM][64Bits] -- {62AC81F6-BDD3-4110-9D36-3E9EAAB40999} © O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM][64Bits] -- {69533745-1E2D-4C98-8B4A-B7643EF9E1A2} © O42 - Logiciel: Skype™ 7.8 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {6A0549A9-1B96-498C-ACBC-3943001FEB19} © O42 - Logiciel: LSDA Le Retour du Roi tm - (...) [HKLM][64Bits] -- {6E298B0A-558C-4138-0096-740677B382CD} O42 - Logiciel: Nero StartSmart - (.Nero AG.) [HKLM][64Bits] -- {7748AC8C-18E3-43BB-959B-088FAEA16FB2} © O42 - Logiciel: Nero BurnRights - (.Nero AG.) [HKLM][64Bits] -- {7829DB6F-A066-4E40-8912-CB07887C20BB} © O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM][64Bits] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} © O42 - Logiciel: Nero Express Help - (.Nero AG.) [HKLM][64Bits] -- {83202942-84B3-4C50-8622-B8C0AA2D2885} © O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM][64Bits] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71} © O42 - Logiciel: Nero DiscSpeed - (.Nero AG.) [HKLM][64Bits] -- {869200DB-287A-4DC0-B02B-2B6787FBCD4C} © O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} © O42 - Logiciel: OSD Setup - (.MyOSD.) [HKLM][64Bits] -- {98E5A0C3-86ED-4429-9386-F0DB49E958EA} © O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} © O42 - Logiciel: AlienRespawn - Support Software - (.Alienware.) [HKLM][64Bits] -- {A9668246-FB70-4103-A1E3-66C9BC2EFB49} © O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001824147215} © O42 - Logiciel: Adobe Reader XI (11.0.12) - Français - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1036-7B44-AB0000000001} © O42 - Logiciel: Advertising Center - (.Nero AG.) [HKLM][64Bits] -- {B2EC4A38-B545-4A00-8214-13FE0E915E6D} © O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM][64Bits] -- {B67BAFBA-4C9F-48FA-9496-933E3B255044} © O42 - Logiciel: Skype Click to Call - (.Skype Technologies S.A..) [HKLM][64Bits] -- {B6CF2967-C81E-40C0-9815-C05774FEF120} © O42 - Logiciel: DartViewer - (.Dartfish.) [HKLM][64Bits] -- {BBF7D230-8F25-4041-90A9-73FD03BE8640} O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM][64Bits] -- {BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A} © O42 - Logiciel: Nero Online Upgrade - (.Nero AG.) [HKLM][64Bits] -- {C81A2FE0-3574-00A9-CED4-BDAA334CBE8E} © O42 - Logiciel: Nero DiscSpeed Help - (.Nero AG.) [HKLM][64Bits] -- {CC019E3F-59D2-4486-8D4B-878105B62A71} © O42 - Logiciel: Nero CoverDesigner Help - (.Nero AG.) [HKLM][64Bits] -- {CE96F5A5-584D-4F8F-AA3E-9BAED413DB72} © O42 - Logiciel: MSVCRT_amd64 - (.Microsoft.) [HKLM][64Bits] -- {D0B44725-3666-492D-BEF6-587A14BD9BD9} © O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} © O42 - Logiciel: Nero DriveSpeed Help - (.Nero AG.) [HKLM][64Bits] -- {E5C7D048-F9B4-4219-B323-8BDB01A2563D} © O42 - Logiciel: Nero Installer - (.Nero AG.) [HKLM][64Bits] -- {E8A80433-302B-4FF1-815D-FCC8EAC482FF} © O42 - Logiciel: Sony PC Companion 2.10.281 - (.Sony.) [HKLM][64Bits] -- {F09EF8F2-0976-42C1-8D9D-8DF78337C6E3} © O42 - Logiciel: Nero Disc Copy Gadget - (.Nero AG.) [HKLM][64Bits] -- {F1861F30-3419-44DB-B2A1-C274825698B3} © O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM][64Bits] -- {F4041DCE-3FE1-4E18-8A9E-9DE65231EE36} © O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM][64Bits] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC} © O42 - Logiciel: Nero BurnRights Help - (.Nero AG.) [HKLM][64Bits] -- {F6BDD7C5-89ED-4569-9318-469AA9732572} © O42 - Logiciel: Nero InfoTool - (.Nero AG.) [HKLM][64Bits] -- {FBCDFD61-7DCF-4E71-9226-873BA0053139} © O42 - Logiciel: Nero 9 Essentials - (.Nero AG.) [HKLM][64Bits] -- {fd42b0f2-78d9-4e35-80c9-4980ffda1ed0} © O42 - Logiciel: Image Resizer Packages - (...) [HKCU][64Bits] -- Image Resizer Packages =>Adware.InstallCore O42 - Logiciel: SaveSense - (...) [HKCU][64Bits] -- SaveSense ---\\ HKCU & HKLM Software Keys (125) - 7s HKLM\SOFTWARE\Wow6432Node\7-Zip HKLM\SOFTWARE\Wow6432Node\Adobe HKLM\SOFTWARE\Wow6432Node\Alienware HKLM\SOFTWARE\Wow6432Node\AppDataLow HKLM\SOFTWARE\Wow6432Node\Apple Computer, Inc. HKLM\SOFTWARE\Wow6432Node\Apple Inc. HKLM\SOFTWARE\Wow6432Node\ATI HKLM\SOFTWARE\Wow6432Node\ATI Technologies HKLM\SOFTWARE\Wow6432Node\ATK0100 HKLM\SOFTWARE\Wow6432Node\Auslogics HKLM\SOFTWARE\Wow6432Node\AVAST Software HKLM\SOFTWARE\Wow6432Node\Blizzard Entertainment HKLM\SOFTWARE\Wow6432Node\Bunndle HKLM\SOFTWARE\Wow6432Node\CyberLink HKLM\SOFTWARE\Wow6432Node\Dartfish HKLM\SOFTWARE\Wow6432Node\Dell HKLM\SOFTWARE\Wow6432Node\Dell Computer Corporation HKLM\SOFTWARE\Wow6432Node\DT Soft HKLM\SOFTWARE\Wow6432Node\DVDVideoSoft HKLM\SOFTWARE\Wow6432Node\EA GAMES HKLM\SOFTWARE\Wow6432Node\Electronic Arts HKLM\SOFTWARE\Wow6432Node\Google HKLM\SOFTWARE\Wow6432Node\IM Providers HKLM\SOFTWARE\Wow6432Node\Iminent =>PUP.Optional.IMBooster HKLM\SOFTWARE\Wow6432Node\InstallCore =>Adware.InstallCore HKLM\SOFTWARE\Wow6432Node\InstallShield HKLM\SOFTWARE\Wow6432Node\Intel HKLM\SOFTWARE\Wow6432Node\JavaSoft HKLM\SOFTWARE\Wow6432Node\JreMetrics HKLM\SOFTWARE\Wow6432Node\Khronos HKLM\SOFTWARE\Wow6432Node\Macromedia HKLM\SOFTWARE\Wow6432Node\magnet HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware HKLM\SOFTWARE\Wow6432Node\Mozilla HKLM\SOFTWARE\Wow6432Node\mozilla.org HKLM\SOFTWARE\Wow6432Node\MozillaPlugins HKLM\SOFTWARE\Wow6432Node\NCH Software HKLM\SOFTWARE\Wow6432Node\Nero HKLM\SOFTWARE\Wow6432Node\ODBC HKLM\SOFTWARE\Wow6432Node\PocketSoft HKLM\SOFTWARE\Wow6432Node\SaveSense HKLM\SOFTWARE\Wow6432Node\SaveSenseLive =>PUP.Optional.SaveSense HKLM\SOFTWARE\Wow6432Node\Secunia HKLM\SOFTWARE\Wow6432Node\Sensible Vision HKLM\SOFTWARE\Wow6432Node\Skype HKLM\SOFTWARE\Wow6432Node\SoftThinks HKLM\SOFTWARE\Wow6432Node\Software FX, Inc. HKLM\SOFTWARE\Wow6432Node\Sony HKLM\SOFTWARE\Wow6432Node\Sony Mobile HKLM\SOFTWARE\Wow6432Node\SupDp =>PUP.Optional.SupTab HKLM\SOFTWARE\Wow6432Node\sweet-pageSoftware =>PUP.Optional.SweetPage HKLM\SOFTWARE\Wow6432Node\Symantec HKLM\SOFTWARE\Wow6432Node\VideoLAN HKLM\SOFTWARE\Wow6432Node\Volatile HKLM\SOFTWARE\Wow6432Node\Wow6432Node HKLM\SOFTWARE\Wow6432Node\RegisteredApplications HKCU\SOFTWARE\1ClickDownload =>PUP.Optional.1ClickDownloader HKCU\SOFTWARE\7-Zip HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\Alienware HKCU\SOFTWARE\Alucard HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\Apple Computer, Inc. HKCU\SOFTWARE\Apple Inc. HKCU\SOFTWARE\ATI HKCU\SOFTWARE\AVAST Software HKCU\SOFTWARE\Blizzard Entertainment HKCU\SOFTWARE\BRS HKCU\SOFTWARE\BVRP Software HKCU\SOFTWARE\Chromium HKCU\SOFTWARE\CoSoSys HKCU\SOFTWARE\CyberLink HKCU\SOFTWARE\Dell HKCU\SOFTWARE\DriverTuner =>PUP.Optional.DriverTuner HKCU\SOFTWARE\DriverTuner_Init =>PUP.Optional.DriverTuner HKCU\SOFTWARE\DT Soft HKCU\SOFTWARE\DVDVideoSoft HKCU\SOFTWARE\ej-technologies HKCU\SOFTWARE\Facebook HKCU\SOFTWARE\Glarysoft HKCU\SOFTWARE\Google HKCU\SOFTWARE\Hewlett-Packard HKCU\SOFTWARE\HookNetwork HKCU\SOFTWARE\Illustrate HKCU\SOFTWARE\IM Providers HKCU\SOFTWARE\InstallCore =>Adware.InstallCore HKCU\SOFTWARE\JavaSoft HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\Malwarebytes' Anti-Malware HKCU\SOFTWARE\Mine HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\MPC-HC HKCU\SOFTWARE\NCH Software HKCU\SOFTWARE\Nero HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\Piriform HKCU\SOFTWARE\QtProject HKCU\SOFTWARE\RegisteredApplications HKCU\SOFTWARE\SaveSense HKCU\SOFTWARE\SaveSenseLive =>PUP.Optional.SaveSense HKCU\SOFTWARE\SCC HKCU\SOFTWARE\Secunia HKCU\SOFTWARE\SecuredDownload HKCU\SOFTWARE\Sensible Vision HKCU\SOFTWARE\Skype HKCU\SOFTWARE\SkypeRS HKCU\SOFTWARE\Sony HKCU\SOFTWARE\SpoonInstall HKCU\SOFTWARE\Synaptics HKCU\SOFTWARE\Tracker Software HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\Valve HKCU\SOFTWARE\Vosteran Browser =>PUP.Optional.Vosteran HKCU\SOFTWARE\VSRevoGroup HKCU\SOFTWARE\Widcomm HKCU\SOFTWARE\WinRAR HKCU\SOFTWARE\WinRAR SFX HKCU\SOFTWARE\Wow6432Node HKCU\SOFTWARE\wse_astromenda =>PUP.Optional.Astromenda HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\Adobe HKCU\SOFTWARE\AppDataLow\Software\JavaSoft ---\\ Contenu des dossiers Programmes (251) - 8s O43 - CFD: 2014/06/07 21:11:39 - [] D -- C:\Program Files (x86)\7-Zip O43 - CFD: 2013/07/05 20:31:33 - [] D -- C:\Program Files (x86)\Adobe O43 - CFD: 2015/10/10 15:21:03 - [] D -- C:\Program Files (x86)\AlienRespawn O43 - CFD: 2013/02/21 11:08:07 - [] D -- C:\Program Files (x86)\Apple Software Update O43 - CFD: 2015/10/07 15:14:48 - [] D -- C:\Program Files (x86)\ATI Technologies O43 - CFD: 2015/10/10 18:50:16 - [] D -- C:\Program Files (x86)\Battle.net O43 - CFD: 2013/02/26 13:10:00 - [] D -- C:\Program Files (x86)\Bonjour O43 - CFD: 2015/08/26 20:13:03 - [] D -- C:\Program Files (x86)\Common Files O43 - CFD: 2010/07/29 04:29:28 - [] D -- C:\Program Files (x86)\CyberLink O43 - CFD: 2015/08/06 20:25:49 - [] D -- C:\Program Files (x86)\DAEMON Tools Lite O43 - CFD: 2012/06/11 23:17:47 - [] D -- C:\Program Files (x86)\Dartfish O43 - CFD: 2015/09/22 20:40:26 - [] D -- C:\Program Files (x86)\Diablo III O43 - CFD: 2014/03/28 12:45:10 - [] D -- C:\Program Files (x86)\DriverTuner =>PUP.Optional.DriverTuner O43 - CFD: 2014/03/07 23:27:24 - [] D -- C:\Program Files (x86)\DVDVideoSoft O43 - CFD: 2012/01/29 12:57:50 - [] D -- C:\Program Files (x86)\EA GAMES O43 - CFD: 2014/12/31 15:18:08 - [0] D -- C:\Program Files (x86)\FrostWire 5 O43 - CFD: 2014/02/15 15:30:50 - [] D -- C:\Program Files (x86)\Google O43 - CFD: 2012/07/21 18:45:04 - [] D -- C:\Program Files (x86)\Illustrate O43 - CFD: 2014/12/23 17:49:39 - [] D -- C:\Program Files (x86)\Image Resizer O43 - CFD: 2015/09/01 17:57:16 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information O43 - CFD: 2010/07/29 04:02:37 - [] D -- C:\Program Files (x86)\Intel O43 - CFD: 2015/08/20 20:09:02 - [] D -- C:\Program Files (x86)\Internet Explorer O43 - CFD: 2013/10/29 00:39:56 - [] D -- C:\Program Files (x86)\iTunes O43 - CFD: 2013/04/21 12:05:02 - [] D -- C:\Program Files (x86)\Java O43 - CFD: 2012/08/26 12:51:27 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services O43 - CFD: 2011/10/22 19:48:22 - [] D -- C:\Program Files (x86)\Microsoft Games O43 - CFD: 2012/08/26 12:52:03 - [] D -- C:\Program Files (x86)\Microsoft Office O43 - CFD: 2015/08/20 19:56:12 - [] D -- C:\Program Files (x86)\Microsoft Silverlight O43 - CFD: 2011/10/21 19:34:31 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio O43 - CFD: 2011/10/21 19:32:40 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio 8 O43 - CFD: 2011/11/07 17:26:03 - [] D -- C:\Program Files (x86)\Microsoft Works O43 - CFD: 2015/08/06 21:54:00 - [] D -- C:\Program Files (x86)\Microsoft.NET O43 - CFD: 2014/11/01 18:37:45 - [] D -- C:\Program Files (x86)\Middle Earth Shadow of Mordor O43 - CFD: 2015/07/14 08:32:10 - [] D -- C:\Program Files (x86)\Mozilla Firefox O43 - CFD: 2015/07/15 12:59:05 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\Program Files (x86)\MSBuild O43 - CFD: 2013/07/06 00:39:26 - [] D -- C:\Program Files (x86)\MSXML 4.0 O43 - CFD: 2012/11/22 19:39:01 - [] D -- C:\Program Files (x86)\NCH Software O43 - CFD: 2010/07/29 04:26:19 - [] D -- C:\Program Files (x86)\Nero O43 - CFD: 2010/07/29 04:00:05 - [] D -- C:\Program Files (x86)\OSD O43 - CFD: 2013/05/31 12:51:19 - [] D -- C:\Program Files (x86)\QuickTime O43 - CFD: 2015/08/06 22:17:54 - [] D -- C:\Program Files (x86)\Reference Assemblies O43 - CFD: 2013/11/20 11:59:59 - [] D -- C:\Program Files (x86)\SaveSense =>PUP.Optional.SaveSense O43 - CFD: 2013/11/20 12:00:18 - [] D -- C:\Program Files (x86)\SaveSenseLive =>PUP.Optional.SaveSense O43 - CFD: 2014/01/02 20:16:48 - [0] D -- C:\Program Files (x86)\SecretSauce =>PUP.Optional.SecretSauce O43 - CFD: 2013/07/06 00:30:38 - [] D -- C:\Program Files (x86)\Secunia O43 - CFD: 2015/08/26 20:13:03 - [] RD -- C:\Program Files (x86)\Skype O43 - CFD: 2015/01/01 14:44:34 - [0] D -- C:\Program Files (x86)\Solution Real =>PUP.Optional.SolutionReal O43 - CFD: 2015/09/01 17:57:16 - [] D -- C:\Program Files (x86)\Sony O43 - CFD: 2015/09/01 18:02:12 - [] D -- C:\Program Files (x86)\Sony Mobile O43 - CFD: 2014/12/30 05:01:40 - [] D -- C:\Program Files (x86)\SupTab =>PUP.Optional.SupTab O43 - CFD: 2014/01/02 20:03:11 - [] D -- C:\Program Files (x86)\TornTV.com =>PUP.Optional.TornTV O43 - CFD: 2013/07/06 12:02:24 - [0] D -- C:\Program Files (x86)\Trend Micro O43 - CFD: 2009/07/14 06:57:06 - [0] HD -- C:\Program Files (x86)\Uninstall Information O43 - CFD: 2012/03/22 17:27:51 - [] D -- C:\Program Files (x86)\VideoLAN O43 - CFD: 2014/06/06 19:31:56 - [] D -- C:\Program Files (x86)\VS Revo Group O43 - CFD: 2012/04/11 18:34:48 - [] D -- C:\Program Files (x86)\Vuze O43 - CFD: 2015/07/10 18:23:55 - [] D -- C:\Program Files (x86)\Windows Defender O43 - CFD: 2013/04/01 17:37:51 - [] D -- C:\Program Files (x86)\Windows Live O43 - CFD: 2015/08/06 21:54:01 - [] D -- C:\Program Files (x86)\Windows Mail O43 - CFD: 2015/07/10 18:23:55 - [] D -- C:\Program Files (x86)\Windows Media Player O43 - CFD: 2015/07/10 13:04:26 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform O43 - CFD: 2015/07/10 13:04:22 - [] D -- C:\Program Files (x86)\Windows NT O43 - CFD: 2015/07/10 18:23:55 - [] D -- C:\Program Files (x86)\Windows Photo Viewer O43 - CFD: 2015/07/10 13:04:26 - [] D -- C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 2015/08/06 21:54:01 - [] SHD -- C:\Program Files (x86)\Windows Sidebar O43 - CFD: 2015/07/10 13:04:22 - [] SD -- C:\Program Files (x86)\WindowsPowerShell O43 - CFD: 2013/03/16 14:42:30 - [] D -- C:\Program Files (x86)\WinRAR O43 - CFD: 2014/10/28 18:00:42 - [] D -- C:\Program Files (x86)\WSE_Astromenda =>PUP.Optional.Astromenda O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip O43 - CFD: 2015/07/10 13:04:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 2015/08/06 22:04:38 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2015/07/10 13:04:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Age of Empires III Complete Collection O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AlienRespawn O43 - CFD: 2015/08/06 21:54:06 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alienware O43 - CFD: 2015/10/07 15:15:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\dBpoweramp Music Converter O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft O43 - CFD: 2015/08/06 21:54:08 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES O43 - CFD: 2015/08/06 22:04:38 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel® Matrix Storage Manager O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java O43 - CFD: 2015/07/10 13:04:26 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2015/08/06 21:54:10 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office O43 - CFD: 2015/08/12 14:41:28 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Middle Earth Shadow of Mordor O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64 O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero O43 - CFD: 2014/06/06 21:21:12 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange 3 O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime O43 - CFD: 2015/08/26 20:13:06 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype O43 - CFD: 2015/09/01 17:57:31 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony O43 - CFD: 2015/07/10 13:04:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp O43 - CFD: 2015/07/10 13:04:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 2015/07/10 18:28:36 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 2015/08/06 22:04:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN O43 - CFD: 2013/10/29 00:39:59 - [] D -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 O43 - CFD: 2013/07/05 20:31:36 - [] D -- C:\ProgramData\Adobe O43 - CFD: 2014/09/20 18:48:44 - [] D -- C:\ProgramData\Age of Empires 3 O43 - CFD: 2013/05/27 22:47:21 - [] D -- C:\ProgramData\Alienware O43 - CFD: 2013/02/26 13:10:17 - [] D -- C:\ProgramData\Apple O43 - CFD: 2013/02/26 13:10:35 - [] D -- C:\ProgramData\Apple Computer O43 - CFD: 2015/07/10 14:21:38 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 2013/07/12 12:58:00 - [] D -- C:\ProgramData\Applications O43 - CFD: 2015/10/07 23:24:05 - [] D -- C:\ProgramData\ATI O43 - CFD: 2014/06/07 21:46:36 - [] D -- C:\ProgramData\AVAST Software O43 - CFD: 2011/12/19 20:41:24 - [] D -- C:\ProgramData\Azureus O43 - CFD: 2012/05/18 15:40:21 - [] D -- C:\ProgramData\Battle.net O43 - CFD: 2012/05/18 16:20:22 - [] D -- C:\ProgramData\Blizzard Entertainment O43 - CFD: 2011/10/20 19:27:44 - [0] SHD -- C:\ProgramData\Bureau O43 - CFD: 2015/07/10 13:04:22 - [0] D -- C:\ProgramData\Comms O43 - CFD: 2011/10/22 19:18:47 - [] D -- C:\ProgramData\CyberLink O43 - CFD: 2011/10/22 09:23:28 - [] D -- C:\ProgramData\DAEMON Tools Lite O43 - CFD: 2015/07/10 14:21:38 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 2015/07/10 14:21:38 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 2011/10/20 19:27:44 - [0] SHD -- C:\ProgramData\Favoris O43 - CFD: 2011/10/20 19:27:44 - [0] SHD -- C:\ProgramData\Menu Démarrer O43 - CFD: 2015/08/06 21:54:14 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 2015/09/09 14:29:18 - [] D -- C:\ProgramData\Microsoft Help O43 - CFD: 2015/08/06 22:24:20 - [] D -- C:\ProgramData\Microsoft OneDrive O43 - CFD: 2011/10/20 19:27:44 - [0] SHD -- C:\ProgramData\Modèles O43 - CFD: 2013/07/06 00:42:38 - [] D -- C:\ProgramData\Mozilla O43 - CFD: 2012/04/08 18:32:21 - [] D -- C:\ProgramData\NCH Software O43 - CFD: 2010/07/29 04:24:29 - [] D -- C:\ProgramData\Nero O43 - CFD: 2015/03/12 23:56:28 - [] D -- C:\ProgramData\Norton O43 - CFD: 2015/03/12 17:57:08 - [] D -- C:\ProgramData\NortonInstaller O43 - CFD: 2015/10/07 15:14:42 - [] D -- C:\ProgramData\Package Cache O43 - CFD: 2015/07/10 18:28:36 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft O43 - CFD: 2013/11/20 12:00:18 - [] D -- C:\ProgramData\SaveSenseLive =>PUP.Optional.SaveSense O43 - CFD: 2015/08/26 20:13:14 - [] D -- C:\ProgramData\Skype O43 - CFD: 2015/07/10 13:04:22 - [0] D -- C:\ProgramData\SoftwareDistribution O43 - CFD: 2015/09/01 17:57:16 - [] D -- C:\ProgramData\Sony O43 - CFD: 2015/09/01 18:02:12 - [] D -- C:\ProgramData\Sony Mobile O43 - CFD: 2015/07/10 14:21:38 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 2010/07/29 03:59:04 - [] D -- C:\ProgramData\Sun O43 - CFD: 2010/07/29 04:29:06 - [] D -- C:\ProgramData\Temp O43 - CFD: 2015/07/10 14:21:38 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 2015/07/10 14:22:45 - [] D -- C:\ProgramData\USOPrivate O43 - CFD: 2015/07/10 14:22:45 - [] D -- C:\ProgramData\USOShared O43 - CFD: 2013/06/17 15:08:44 - [0] D -- C:\ProgramData\WinZip O43 - CFD: 2013/07/05 20:31:35 - [] D -- C:\Program Files (x86)\Common Files\Adobe O43 - CFD: 2013/10/29 00:38:48 - [] D -- C:\Program Files (x86)\Common Files\Apple O43 - CFD: 2014/08/27 20:12:43 - [] D -- C:\Program Files (x86)\Common Files\Blizzard Entertainment O43 - CFD: 2014/05/14 00:16:38 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER O43 - CFD: 2014/03/07 23:26:37 - [] D -- C:\Program Files (x86)\Common Files\DVDVideoSoft O43 - CFD: 2011/10/22 19:47:20 - [] D -- C:\Program Files (x86)\Common Files\InstallShield O43 - CFD: 2015/08/06 21:53:59 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared O43 - CFD: 2010/07/29 04:28:37 - [] D -- C:\Program Files (x86)\Common Files\Nero O43 - CFD: 2015/07/10 13:04:26 - [] D -- C:\Program Files (x86)\Common Files\Services O43 - CFD: 2015/08/26 20:13:03 - [] D -- C:\Program Files (x86)\Common Files\Skype O43 - CFD: 2015/08/06 21:53:59 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines O43 - CFD: 2015/08/06 21:53:59 - [] D -- C:\Program Files (x86)\Common Files\System O43 - CFD: 2011/11/06 13:17:54 - [] D -- C:\Program Files (x86)\Common Files\Windows Live O43 - CFD: 2014/12/22 01:00:44 - [] D -- C:\Users\Gaïarac\AppData\Roaming\1H1Q1V1N1N1O1R =>Adware.InstallCore O43 - CFD: 2012/07/21 18:45:08 - [0] D -- C:\Users\Gaïarac\AppData\Roaming\AccurateRip O43 - CFD: 2011/10/26 16:09:59 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Adobe O43 - CFD: 2015/08/09 20:40:59 - [] D -- C:\Users\Gaïarac\AppData\Roaming\AMD O43 - CFD: 2015/03/27 20:11:53 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Apple Computer O43 - CFD: 2014/11/01 13:43:16 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Astromenda =>PUP.Optional.Astromenda O43 - CFD: 2011/10/20 19:28:35 - [] D -- C:\Users\Gaïarac\AppData\Roaming\ATI O43 - CFD: 2014/06/07 21:48:14 - [] D -- C:\Users\Gaïarac\AppData\Roaming\AVAST Software O43 - CFD: 2014/06/05 19:23:50 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Azureus O43 - CFD: 2014/09/09 12:28:59 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Battle.net O43 - CFD: 2015/06/26 20:30:42 - [] D -- C:\Users\Gaïarac\AppData\Roaming\DAEMON Tools Lite O43 - CFD: 2012/07/27 10:32:44 - [] D -- C:\Users\Gaïarac\AppData\Roaming\dBpoweramp O43 - CFD: 2014/06/06 22:59:17 - [] D -- C:\Users\Gaïarac\AppData\Roaming\DiskDefrag O43 - CFD: 2012/12/10 23:34:40 - [] D -- C:\Users\Gaïarac\AppData\Roaming\dvdcss O43 - CFD: 2014/03/07 23:26:26 - [] D -- C:\Users\Gaïarac\AppData\Roaming\DVDVideoSoft O43 - CFD: 2012/02/08 10:57:36 - [] D -- C:\Users\Gaïarac\AppData\Roaming\GetRightToGo O43 - CFD: 2011/10/20 19:28:19 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Identities O43 - CFD: 2011/10/20 20:30:50 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Macromedia O43 - CFD: 2009/07/14 17:35:05 - [0] D -- C:\Users\Gaïarac\AppData\Roaming\Media Center Programs O43 - CFD: 2015/08/14 18:15:40 - [] SD -- C:\Users\Gaïarac\AppData\Roaming\Microsoft O43 - CFD: 2012/04/01 18:13:57 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Mozilla O43 - CFD: 2015/05/11 16:19:23 - [] D -- C:\Users\Gaïarac\AppData\Roaming\MPC-HC O43 - CFD: 2012/11/22 19:39:00 - [] D -- C:\Users\Gaïarac\AppData\Roaming\NCH Software O43 - CFD: 2012/07/21 19:39:47 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Nero O43 - CFD: 2014/11/01 18:17:12 - [] D -- C:\Users\Gaïarac\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy O43 - CFD: 2014/11/01 18:17:14 - [] D -- C:\Users\Gaïarac\AppData\Roaming\RHEng =>PUP.Optional.Conduit O43 - CFD: 2013/11/20 12:00:11 - [] D -- C:\Users\Gaïarac\AppData\Roaming\SaveSense =>PUP.Optional.SaveSense O43 - CFD: 2015/10/10 18:44:20 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Skype O43 - CFD: 2014/11/01 18:42:04 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Steam O43 - CFD: 2014/12/30 05:01:07 - [] D -- C:\Users\Gaïarac\AppData\Roaming\sweet-page =>PUP.Optional.SweetPage O43 - CFD: 2015/05/10 12:03:06 - [] D -- C:\Users\Gaïarac\AppData\Roaming\vlc O43 - CFD: 2015/04/02 22:28:18 - [0] D -- C:\Users\Gaïarac\AppData\Roaming\Windows Live Writer O43 - CFD: 2012/02/08 11:00:08 - [] D -- C:\Users\Gaïarac\AppData\Roaming\WinRAR O43 - CFD: 2014/10/28 18:00:52 - [] D -- C:\Users\Gaïarac\AppData\Roaming\WSE_Astromenda =>PUP.Optional.Astromenda O43 - CFD: 2015/10/10 19:14:23 - [] D -- C:\Users\Gaïarac\AppData\Roaming\ZHP O43 - CFD: 2013/11/13 16:48:54 - [] D -- C:\Users\Gaïarac\AppData\Local\Adobe O43 - CFD: 2013/02/21 11:08:09 - [] D -- C:\Users\Gaïarac\AppData\Local\Apple O43 - CFD: 2013/02/26 13:11:22 - [] D -- C:\Users\Gaïarac\AppData\Local\Apple Computer O43 - CFD: 2015/08/06 21:47:58 - [0] SHD -- C:\Users\Gaïarac\AppData\Local\Application Data O43 - CFD: 2011/10/20 20:11:37 - [] D -- C:\Users\Gaïarac\AppData\Local\Apps O43 - CFD: 2011/10/20 19:28:35 - [] D -- C:\Users\Gaïarac\AppData\Local\ATI O43 - CFD: 2015/10/10 18:53:11 - [] D -- C:\Users\Gaïarac\AppData\Local\Battle.net O43 - CFD: 2014/02/27 03:06:36 - [] D -- C:\Users\Gaïarac\AppData\Local\Blizzard Entertainment O43 - CFD: 2011/10/20 19:28:36 - [] D -- C:\Users\Gaïarac\AppData\Local\Broadcom O43 - CFD: 2015/08/07 13:52:03 - [] D -- C:\Users\Gaïarac\AppData\Local\Comms O43 - CFD: 2014/12/02 21:18:50 - [0] D -- C:\Users\Gaïarac\AppData\Local\Diagnostics O43 - CFD: 2014/03/08 17:00:31 - [0] D -- C:\Users\Gaïarac\AppData\Local\DriverTuner =>PUP.Optional.DriverTuner O43 - CFD: 2014/12/02 18:00:57 - [] SHD -- C:\Users\Gaïarac\AppData\Local\EmieBrowserModeList O43 - CFD: 2014/06/05 19:11:09 - [] SHD -- C:\Users\Gaïarac\AppData\Local\EmieSiteList O43 - CFD: 2014/06/05 19:11:09 - [] SHD -- C:\Users\Gaïarac\AppData\Local\EmieUserList O43 - CFD: 2012/10/23 21:31:57 - [] D -- C:\Users\Gaïarac\AppData\Local\Facebook O43 - CFD: 2014/12/31 15:17:01 - [0] D -- C:\Users\Gaïarac\AppData\Local\GGEmpire O43 - CFD: 2015/09/17 15:37:07 - [] D -- C:\Users\Gaïarac\AppData\Local\Google O43 - CFD: 2015/06/01 13:46:51 - [] D -- C:\Users\Gaïarac\AppData\Local\GWX O43 - CFD: 2015/08/06 21:47:58 - [0] SHD -- C:\Users\Gaïarac\AppData\Local\Historique O43 - CFD: 2012/10/05 23:38:56 - [] D -- C:\Users\Gaïarac\AppData\Local\Macromedia O43 - CFD: 2015/08/24 18:39:14 - [] D -- C:\Users\Gaïarac\AppData\Local\Microsoft O43 - CFD: 2011/12/27 14:43:46 - [] D -- C:\Users\Gaïarac\AppData\Local\Microsoft Games O43 - CFD: 2012/01/22 14:24:20 - [] D -- C:\Users\Gaïarac\AppData\Local\Microsoft Help O43 - CFD: 2015/08/13 18:40:50 - [] D -- C:\Users\Gaïarac\AppData\Local\MicrosoftEdge O43 - CFD: 2011/12/28 17:45:54 - [] D -- C:\Users\Gaïarac\AppData\Local\Mindjet O43 - CFD: 2014/12/02 18:01:42 - [] D -- C:\Users\Gaïarac\AppData\Local\Mozilla O43 - CFD: 2015/08/07 16:23:54 - [0] D -- C:\Users\Gaïarac\AppData\Local\NetworkTiles O43 - CFD: 2015/09/17 15:39:52 - [] D -- C:\Users\Gaïarac\AppData\Local\Packages O43 - CFD: 2013/04/09 14:16:01 - [] D -- C:\Users\Gaïarac\AppData\Local\Programs O43 - CFD: 2015/08/06 22:21:09 - [] D -- C:\Users\Gaïarac\AppData\Local\Publishers O43 - CFD: 2013/11/20 12:00:18 - [] D -- C:\Users\Gaïarac\AppData\Local\SaveSenseLive =>PUP.Optional.SaveSense O43 - CFD: 2015/04/26 01:57:50 - [] D -- C:\Users\Gaïarac\AppData\Local\Skype O43 - CFD: 2011/11/19 20:49:59 - [] D -- C:\Users\Gaïarac\AppData\Local\SoftThinks O43 - CFD: 2015/10/10 19:14:01 - [] D -- C:\Users\Gaïarac\AppData\Local\Temp O43 - CFD: 2015/08/06 21:47:58 - [0] SHD -- C:\Users\Gaïarac\AppData\Local\Temporary Internet Files O43 - CFD: 2015/08/06 22:19:01 - [] D -- C:\Users\Gaïarac\AppData\Local\TileDataLayer O43 - CFD: 2013/06/11 12:54:00 - [] D -- C:\Users\Gaïarac\AppData\Local\VirtualStore O43 - CFD: 2014/12/31 15:20:35 - [] D -- C:\Users\Gaïarac\AppData\Local\Vosteran =>PUP.Optional.Vosteran O43 - CFD: 2015/04/02 22:27:58 - [] D -- C:\Users\Gaïarac\AppData\Local\Windows Live O43 - CFD: 2015/04/02 22:28:25 - [] D -- C:\Users\Gaïarac\AppData\Local\Windows Live Writer O43 - CFD: 2015/07/10 13:04:26 - [] RD -- C:\Users\Gaïarac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 2015/08/06 22:19:01 - [] RD -- C:\Users\Gaïarac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2015/09/09 13:20:25 - [] RD -- C:\Users\Gaïarac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2015/08/06 22:04:37 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam O43 - CFD: 2015/08/06 22:04:37 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 2015/07/10 13:04:26 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2015/08/06 22:04:37 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller O43 - CFD: 2015/08/06 22:04:37 - [] D -- C:\Users\Gaïarac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense =>PUP.Optional.SaveSense O43 - CFD: 2015/09/09 13:20:25 - [] RD -- C:\Users\Gaïarac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 2015/07/10 13:04:26 - [] RD -- C:\Users\Gaïarac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 2014/06/05 19:23:27 - [0] D -- C:\Users\Gaïarac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com =>PUP.Optional.TornTV O43 - CFD: 2015/07/10 13:04:45 - [] RSD -- C:\Users\Gaïarac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell ---\\ Derniers fichiers créés dans Windows Prefetcher (2) - 8s O45 - LFCP:[MD5.06C656EE2B707D37A30CE4580ED100C1] 2015/10/10 19:05:01 A -- C:\WINDOWS\Prefetch\SAVESENSELIVE.EXE-6ACC223B.pf =>PUP.Optional.SaveSense O45 - LFCP:[MD5.A0681A21235A72E145A80751FE90DD93] 2015/10/08 22:50:20 A -- C:\WINDOWS\Prefetch\SAVESENSELIVEHANDLER.EXE-A43C936C.pf =>PUP.Optional.SaveSense ---\\ ShellIconOverlayIdentifiers (SIOI) (6) - 0s O106 - SIOI: ErrorOverlayHandler Class [ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Gaïarac\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll © O106 - SIOI: SharedOverlayHandler Class [ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Gaïarac\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll © O106 - SIOI: SharedSyncingOverlayHandler Class [ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Gaïarac\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll © O106 - SIOI: UpToDateOverlayHandler Class [ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Gaïarac\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll © O106 - SIOI: SyncingOverlayHandler Class [ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Gaïarac\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll © O106 - SIOI: avast [00avast] - {472083B0-C522-11CF-8763-00608CC02F24}. (.Avast Software s.r.o. - avast! Shell Extension.) -- C:\Program Files\AVAST Software\Avast\ashShell.dll © ---\\ Liste des pilotes du système (75) - 9s O58 - SDL:2015/07/10 12:59:38 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107360] © O58 - SDL:2009/12/02 09:45:32 A . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\WINDOWS\System32\drivers\Acceler.sys [25136] © O58 - SDL:2015/07/10 12:59:38 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135456] © O58 - SDL:2015/07/10 12:59:38 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83296] © O58 - SDL:2015/07/10 12:59:38 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259424] © O58 - SDL:2015/07/10 12:59:38 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [26976] © O58 - SDL:2015/07/10 12:59:38 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [131936] © O58 - SDL:2015/07/01 16:53:01 A . (...) -- C:\WINDOWS\System32\drivers\aswHwid.sys [29168] O58 - SDL:2015/07/01 16:53:01 A . (.Avast Software s.r.o. - avast! File System Minifilter for Windows 2.) -- C:\WINDOWS\System32\drivers\aswMonFlt.sys [89944] © O58 - SDL:2015/07/01 16:53:00 A . (.Avast Software s.r.o. - avast! WFP Redirect Driver.) -- C:\WINDOWS\System32\drivers\aswRdr2.sys [93528] © O58 - SDL:2015/07/01 16:53:01 A . (...) -- C:\WINDOWS\System32\drivers\aswRvrt.sys [65736] O58 - SDL:2015/07/01 16:52:24 A . (.Avast Software s.r.o. - avast! Virtualization Driver.) -- C:\WINDOWS\System32\drivers\aswSnx.sys [1047320] © O58 - SDL:2015/07/02 18:13:56 A . (.Avast Software s.r.o. - avast! self protection module.) -- C:\WINDOWS\System32\drivers\aswsp.sys [442264] © O58 - SDL:2015/07/01 16:53:01 A . (.Avast Software s.r.o. - Stream Filter.) -- C:\WINDOWS\System32\drivers\aswStm.sys [137288] © O58 - SDL:2015/07/01 16:53:01 A . (...) -- C:\WINDOWS\System32\drivers\aswVmm.sys [272248] O58 - SDL:2015/05/28 07:00:44 A . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\WINDOWS\System32\drivers\AtihdWT6.sys [102912] © O58 - SDL:2015/10/07 15:07:41 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\atikmdag.sys [21648880] © O58 - SDL:2015/10/07 15:07:41 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\WINDOWS\System32\drivers\atikmpag.sys [674288] © O58 - SDL:2015/07/10 12:59:38 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [17624] © O58 - SDL:2015/07/10 12:59:38 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [531296] © O58 - SDL:2015/07/10 12:59:36 A . (.Intel Corporation - Intel(R) Gigabit Adapter NDIS 6.x driver.) -- C:\WINDOWS\System32\drivers\e1i63x64.sys [482328] © O58 - SDL:2015/07/10 12:59:38 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3436896] © O58 - SDL:2008/09/25 04:36:14 A . (.Sensible Vision - faCap WebCam Capture.) -- C:\WINDOWS\System32\drivers\facap.sys [238848] © O58 - SDL:2012/08/21 14:01:20 A . (.GEAR Software Inc. - CD DVD Filter.) -- C:\WINDOWS\System32\drivers\GEARAspiWDM.sys [33240] © O58 - SDL:2015/07/10 12:59:38 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64352] © O58 - SDL:2015/07/10 12:59:36 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] © O58 - SDL:2015/07/10 12:59:36 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [122608] © O58 - SDL:2007/04/11 16:30:04 A . (.Intel Corporation - Intel® Active Management Technology – KCS.) -- C:\WINDOWS\System32\drivers\IAMTVE.sys [43416] © O58 - SDL:2007/04/11 16:29:58 A . (.Intel Corporation - Intel® Active Management Technology – KCS.) -- C:\WINDOWS\System32\drivers\IAMTXPE.sys [51096] © O58 - SDL:2009/09/28 23:06:12 A . (.Intel Corporation - NDIS 6.1 Advanced Networking Services..) -- C:\WINDOWS\System32\drivers\iANSW60e.sys [152040] © O58 - SDL:2009/10/13 18:16:40 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStor.sys [409624] © O58 - SDL:2015/07/10 12:59:38 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [673120] © O58 - SDL:2015/07/10 12:59:38 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412000] © O58 - SDL:2015/07/10 12:59:39 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [424800] © O58 - SDL:2009/07/13 21:42:44 A . (.Intel Corporation - Intel(R) 5000 Series Chipsets Integrated De.) -- C:\WINDOWS\System32\drivers\ioatdma.sys [46792] © O58 - SDL:2009/10/14 19:29:54 A . (.Intel Corporation - Intel(R) Network Adapter Diagnostic Driver.) -- C:\WINDOWS\System32\drivers\iqvw64e.sys [34472] © O58 - SDL:2009/10/13 07:22:02 A . (.Intel Corporation - Intel(R) iSCSI Setup Driver.) -- C:\WINDOWS\System32\drivers\iSSetup.sys [178400] © O58 - SDL:2009/03/09 10:58:00 A . (.ITE Tech. Inc. - ITE Consumer IR Driver for eHome.) -- C:\WINDOWS\System32\drivers\itecir.sys [60416] © O58 - SDL:2015/07/10 12:59:38 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [108896] © O58 - SDL:2015/07/10 12:59:38 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [104800] © O58 - SDL:2015/07/10 12:59:38 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [99168] © O58 - SDL:2015/07/10 12:59:38 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82784] © O58 - SDL:2015/07/10 12:59:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59744] © O58 - SDL:2015/07/10 12:59:39 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575840] © O58 - SDL:2015/07/10 12:59:39 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [705376] © O58 - SDL:2015/07/10 12:59:39 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63840] © O58 - SDL:2015/07/10 12:59:39 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [76128] © O58 - SDL:2015/07/10 12:59:36 A . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\WINDOWS\System32\drivers\NETwNs64.sys [8604672] © O58 - SDL:2015/07/10 12:59:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150368] © O58 - SDL:2015/07/10 12:59:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166240] © O58 - SDL:2015/07/10 12:59:39 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58208] © O58 - SDL:2015/07/10 12:59:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [58720] © O58 - SDL:2009/07/13 21:42:46 A . (.Intel Corporation - Intel(R) 5000 Series Chipsets Integrated De.) -- C:\WINDOWS\System32\drivers\qd160x64.sys [40144] © O58 - SDL:2009/07/13 21:53:42 A . (.Intel Corporation - Intel(R) 5000 Series Chipsets Integrated De.) -- C:\WINDOWS\System32\drivers\qd162x64.sys [40144] © O58 - SDL:2009/07/13 21:42:50 A . (.Intel Corporation - Intel(R) 5000 Series Chipsets Integrated De.) -- C:\WINDOWS\System32\drivers\qd252x64.sys [47824] © O58 - SDL:2009/07/13 21:53:46 A . (.Intel Corporation - Intel(R) 5000 Series Chipsets Integrated De.) -- C:\WINDOWS\System32\drivers\qd262x64.sys [42192] © O58 - SDL:2008/10/03 22:39:00 A . (.REDC - RICOH MMC Driver.) -- C:\WINDOWS\System32\drivers\rimmpx64.sys [68608] © O58 - SDL:2008/03/04 01:19:04 A . (.REDC - RICOH MS Driver.) -- C:\WINDOWS\System32\drivers\rimspx64.sys [55296] © O58 - SDL:2007/07/28 02:45:52 A . (.REDC - RICOH xD SM Driver.) -- C:\WINDOWS\System32\drivers\rixdpx64.sys [57856] © O58 - SDL:2015/07/10 12:59:39 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44896] © O58 - SDL:2015/07/10 12:59:39 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81760] © O58 - SDL:2015/09/01 15:30:15 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\WINDOWS\System32\drivers\Smb_driver_AMDASF_Aux.sys [43680] © O58 - SDL:2015/09/01 15:30:15 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [44192] © O58 - SDL:2015/09/01 15:30:15 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\WINDOWS\System32\drivers\Smb_driver_Intel_Aux.sys [44192] © O58 - SDL:2015/07/10 12:59:39 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31072] © O58 - SDL:2009/09/15 21:49:02 A . (.IDT, Inc. - IDT PC Audio.) -- C:\WINDOWS\System32\drivers\stwrt64.sys [499712] © O58 - SDL:2015/09/01 15:30:19 A . (.Synaptics Incorporated - Synaptics Touchpad Win64 Driver.) -- C:\WINDOWS\System32\drivers\SynTP.sys [630944] © O58 - SDL:2015/07/10 12:59:48 A . (...) -- C:\WINDOWS\System32\drivers\Udecx.sys [44032] O58 - SDL:2015/07/10 12:59:39 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166752] © O58 - SDL:2015/07/10 12:59:39 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305504] © O58 - SDL:2015/07/10 12:59:39 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [26976] © O58 - SDL:2015/07/10 12:59:39 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [59232] © O58 - SDL:2014/12/22 04:24:32 A . (.StdLib - StdLib.) -- C:\WINDOWS\System32\drivers\{8aefbcaf-640f-4dca-9a92-ed05ee387238}w64.sys [48776] =>PUP.Optional.LinkiDoo O58 - SDL:2014/12/30 19:38:32 A . (.StdLib - StdLib.) -- C:\WINDOWS\System32\drivers\{a5c25b9e-3974-4e91-9864-34f9aca33ff3}w64.sys [48792] =>PUP.Optional.LinkiDoo O58 - SDL:2014/12/31 21:44:24 A . (.StdLib - StdLib.) -- C:\WINDOWS\System32\drivers\{edf2e803-e64b-4078-9a9f-33672590ad18}w64.sys [48792] =>PUP.Optional.LinkiDoo ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (4) - 42s O61 - LFC: 2015/10/10 00:02:04 A . (..) -- C:\Users\Gaïarac\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\speech_onecorereg.bin [8192] O61 - LFC: 2015/10/10 15:21:33 A . (..) -- C:\Users\Gaïarac\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [674082] O61 - LFC: 2015/10/10 18:10:54 A . (..) -- C:\Users\Gaïarac\AppData\Local\Google\Chrome\User Data\nacl_validation_cache.bin [560] O61 - LFC: 2015/10/10 15:21:53 A . (..) -- C:\Users\Gaïarac\AppData\Local\ATI\ACE\Manifest.Bin [29892] ---\\ Associations Shell Spawning (10) - 0s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe © O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe © O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe © O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe © O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S ---\\ Menu de démarrage Internet (12) - 0s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe © O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe © ---\\ Recherche d'infection sur les navigateurs (7) - 3s O69 - SBI: prefs.js [Gaïarac - 6a6z47go.default] user_pref("browser.search.defaulturl", "http://fr.yhs4.search.yahoo.com/yhs/search"); =>PUP.Optional.Browser O69 - SBI: SearchScopes [HKCU] {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} - (Trovi search) - http://www.trovi.com/ =>PUP.Optional.Trovigo O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKCU] {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} - (Yahoo! (Avast)) - http://fr.yhs4.search.yahoo.com/ =>PUP.Optional.Browser O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} - (sweet-page) - http://www.sweet-page.com/ =>PUP.Optional.SweetPage O69 - SBI: SearchScopes [HKCU] {9CB96984-43C3-4D44-90EF-01466EFCF7BB} [DefaultScope] - (Vosteran) - http://Vosteran.com/ =>PUP.Optional.Vosteran O69 - SBI: SearchScopes [HKCU] {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} - (Vosteran) - http://Vosteran.com/ =>PUP.Optional.Vosteran ---\\ Enumère les services démarrés par Svchost (41) - 2s O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [192000] © O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [192000] © O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\WINDOWS\system32\srvsvc.dll [283136] © O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\WINDOWS\System32\gpsvc.dll [1335296] © O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\WINDOWS\System32\ikeext.dll [954368] © O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\WINDOWS\System32\iphlpsvc.dll [954880] © O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\WINDOWS\system32\seclogon.dll [31232] © O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\WINDOWS\System32\appinfo.dll [93696] © O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\WINDOWS\system32\iscsiexe.dll [151040] © O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\WINDOWS\System32\eapsvc.dll [106496] © O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\WINDOWS\system32\schedsvc.dll [1008640] © O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [226304] © O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\WINDOWS\System32\browser.dll [133120] © O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\system32\profsvc.dll [324608] © O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [371200] © O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\WINDOWS\System32\wercplsupport.dll [95744] © O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\WINDOWS\system32\wlidsvc.dll [2093056] © O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) -- C:\WINDOWS\system32\dcpsvc.dll [196096] © O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\WINDOWS\System32\ncasvc.dll [167424] © O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Service Configuration du réseau.) -- C:\WINDOWS\System32\NetSetupSvc.dll [187392] © O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\WINDOWS\System32\rasauto.dll [106496] © O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\WINDOWS\System32\rasmans.dll [679936] © O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [497152] © O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\WINDOWS\System32\sens.dll [72192] © O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\WINDOWS\System32\ipnathlp.dll [452608] © O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [311808] © O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\WINDOWS\system32\wuaueng.dll [2235904] © O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\WINDOWS\System32\qmgr.dll [1168896] © O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [593920] © O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\WINDOWS\system32\dmwappushsvc.dll [63488] © O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\WINDOWS\System32\XblGameSave.dll [1149440] © O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\WINDOWS\system32\XboxNetApiSvc.dll [1019392] © O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Mettre à jour la session Orchestrator Core.) -- C:\WINDOWS\system32\usocore.dll [343040] © O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\WINDOWS\System32\usermgr.dll [717312] © O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service de géolocalisation.) -- C:\Windows\System32\lfsvc.dll [27136] © O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL Windows Management Service.) -- C:\Windows\System32\Windows.Internal.Management.dll [267776] © O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\WINDOWS\System32\XblAuthManager.dll [918016] © O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) -- C:\WINDOWS\system32\RDXService.dll [996352] © O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\WINDOWS\System32\bdesvc.dll [359936] © O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [237568] © O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\WINDOWS\system32\themeservice.dll [58368] © ---\\ Liste des exceptions du parefeu Windows (6) - 3s O87 - FAEL: "{D2BA390C-E3EC-403D-870A-A2527625C610}" [In-None-P17-FALSE] .(.WB Games, Inc. - Middle-earth: Shadow of Mordor™.) -- C:\Program Files (x86)\Middle Earth Shadow of Mordor\x64\ShadowOfMordor.exe O87 - FAEL: "{B1E024E1-8F88-4AD1-8973-98C81C629AC7}" [In-None-P6-FALSE] .(.WB Games, Inc. - Middle-earth: Shadow of Mordor™.) -- C:\Program Files (x86)\Middle Earth Shadow of Mordor\x64\ShadowOfMordor.exe O87 - FAEL: "{07449CA7-CB4C-48E4-AEDE-48B5EA479A07}" [In-None-P17-TRUE] .(.WB Games, Inc. - Middle-earth: Shadow of Mordor™.) -- C:\Program Files (x86)\Middle Earth Shadow of Mordor\x64\ShadowOfMordor.exe O87 - FAEL: "{0BDD0DE5-038A-4125-89B3-C0F89A67ECF0}" [In-None-P6-TRUE] .(.WB Games, Inc. - Middle-earth: Shadow of Mordor™.) -- C:\Program Files (x86)\Middle Earth Shadow of Mordor\x64\ShadowOfMordor.exe O87 - FAEL: "{CCC0BC9B-39A9-4681-830D-4DA851F4C024}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe O87 - FAEL: "{E15521D9-7189-4603-9998-CB5BEA55B1FE}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe ---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (25) - 19s SR - Auto [2015/07/07 20:12:28] [ 82128] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe © SR - Auto [2009/03/02 20:42:58] [ 89600] Andrea ST Filters Service (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_056607ee0106e5e8\AESTSr64.exe © SR - Auto [2010/05/21 17:39:22] [ 14648] Alienware Fusion Service (AlienFusionService) . (.Alienware.) - C:\Program Files\Alienware\Command Center\AlienFusionService.exe © SR - Auto [2015/10/07 15:07:39] [ 255472] (AMD External Events Utility) . (.AMD.) - C:\WINDOWS\system32\atiesrxx.exe © SR - Auto [2013/09/07 09:13:38] [ 55624] Apple Mobile Device (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe © SR - Auto [2015/07/01 16:52:48] [ 343336] Avast Antivirus (avast! Antivirus) . (.Avast Software s.r.o..) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe © SR - Demand [2015/07/01 16:52:11] [ 4034896] AvastVBox COM Service (AvastVBoxSvc) . (.Avast Software.) - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe © SR - Auto [2011/08/31 00:05:32] [ 462184] Service Bonjour (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe © SR - Auto [2010/04/04 20:43:38] [ 2409800] FAService (FAService) . (.Sensible Vision.) - C:\Program Files\Alienware\Command Center\AlienSense\FAService.exe © SS - Auto [2015/08/30 19:31:07] [ 144200] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe © SS - Demand [2015/08/30 19:31:07] [ 144200] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe © SR - Auto [2010/01/04 21:10:00] [ 16384] HappyOSD (HappyOSD) . (...) - C:\Program Files (x86)\OSD\OSD_Service.exe SR - Auto [2009/10/13 18:25:30] [ 354840] Intel(R) Matrix Storage Event Monitor (IAANTMON) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe © SS - Demand [2004/10/22 03:24:18] [ 73728] InstallDriver Table Manager (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe © SR - Demand [2013/10/19 06:31:16] [ 641352] Service de l’iPod (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe © SS - Demand [2015/07/01 04:30:36] [ 148136] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe © SR - Auto [2009/10/13 15:39:04] [ 935208] Nero BackItUp Scheduler 4.0 (Nero BackItUp Scheduler 4.0) . (.Nero AG.) - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe © SS - Auto [2013/11/20 12:00:14] [ 146920] SaveSenseLive Service (savesenselive) (savesenselive) . (.SaveSense.) - C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe =>PUP.Optional.SaveSense SS - Demand [2013/11/20 12:00:14] [ 146920] SaveSenseLive Service (savesenselivem) (savesenselivem) . (.SaveSense.) - C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe =>PUP.Optional.SaveSense SR - Auto [2011/08/18 18:05:46] [ 1692480] SoftThinks Agent Service (SftService) . (.SoftThinks SAS.) - C:\Program Files (x86)\AlienRespawn\sftservice.EXE © SS - Auto [2015/07/09 13:14:04] [ 327296] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe © SS - Demand [2015/06/10 11:11:26] [ 155520] Sony PC Companion (Sony PC Companion) . (.Avanquest Software.) - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe © SR - Auto [2009/09/15 21:49:02] [ 240640] Audio Service (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_056607ee0106e5e8\stacsv64.exe © SR - Auto [2015/09/01 15:30:19] [ 247968] SynTPEnh Caller Service (SynTPEnhService) . (.Synaptics Incorporated.) - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe © ---\\ Scan Additionnel (57) - 0s C:\Program Files (x86)\WSE_Astromenda\BRS\brs.exe =>PUP.Optional.Astromenda C:\Users\Gaïarac\AppData\Roaming\Mozilla\Firefox\Profiles\6a6z47go.default\searchplugins\trovi-search.xml =>PUP.Optional.TroviCom C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\sweet-page.xml =>PUP.Optional.SweetPage C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll =>PUP.Optional.SaveSense HKLM\SYSTEM\CurrentControlSet\Services\savesenselive =>PUP.Optional.SaveSense C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe =>PUP.Optional.SaveSense C:\Users\Gaïarac\AppData\Roaming\WSE_Astromenda\UpdateProc\UpdateTask.exe =>PUP.Optional.Astromenda C:\WINDOWS\Tasks\SaveSenseLiveUpdateTaskMachineCore.job =>PUP.Optional.SaveSense C:\WINDOWS\Tasks\SaveSenseLiveUpdateTaskMachineUA.job =>PUP.Optional.SaveSense C:\WINDOWS\Tasks\Vosteran_helper.job =>PUP.Optional.Vosteran C:\WINDOWS\Tasks\WSE_Astromenda.job =>PUP.Optional.Astromenda C:\WINDOWS\System32\Tasks\SaveSenseLiveUpdateTaskMachineCore =>PUP.Optional.SaveSense C:\WINDOWS\System32\Tasks\SaveSenseLiveUpdateTaskMachineUA =>PUP.Optional.SaveSense C:\WINDOWS\System32\Tasks\Vosteran_helper =>PUP.Optional.Vosteran C:\WINDOWS\System32\Tasks\WSE_Astromenda =>PUP.Optional.Astromenda HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\sweet-page uninstall =>PUP.Optional.SweetPage HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WSE_Astromenda =>PUP.Optional.Astromenda HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Image Resizer Packages =>Adware.InstallCore HKLM\SOFTWARE\Wow6432Node\Iminent =>PUP.Optional.IMBooster HKLM\SOFTWARE\Wow6432Node\InstallCore =>Adware.InstallCore HKLM\SOFTWARE\Wow6432Node\SaveSenseLive =>PUP.Optional.SaveSense HKLM\SOFTWARE\Wow6432Node\SupDp =>PUP.Optional.SupTab HKLM\SOFTWARE\Wow6432Node\sweet-pageSoftware =>PUP.Optional.SweetPage HKCU\SOFTWARE\1ClickDownload =>PUP.Optional.1ClickDownloader HKCU\SOFTWARE\DriverTuner =>PUP.Optional.DriverTuner HKCU\SOFTWARE\DriverTuner_Init =>PUP.Optional.DriverTuner HKCU\SOFTWARE\InstallCore =>Adware.InstallCore HKCU\SOFTWARE\SaveSenseLive =>PUP.Optional.SaveSense HKCU\SOFTWARE\Vosteran Browser =>PUP.Optional.Vosteran HKCU\SOFTWARE\wse_astromenda =>PUP.Optional.Astromenda C:\Program Files (x86)\DriverTuner =>PUP.Optional.DriverTuner C:\Program Files (x86)\SaveSense =>PUP.Optional.SaveSense C:\Program Files (x86)\SaveSenseLive =>PUP.Optional.SaveSense C:\Program Files (x86)\SecretSauce =>PUP.Optional.SecretSauce C:\Program Files (x86)\Solution Real =>PUP.Optional.SolutionReal C:\Program Files (x86)\SupTab =>PUP.Optional.SupTab C:\Program Files (x86)\TornTV.com =>PUP.Optional.TornTV C:\Program Files (x86)\WSE_Astromenda =>PUP.Optional.Astromenda C:\ProgramData\SaveSenseLive =>PUP.Optional.SaveSense C:\Users\Gaïarac\AppData\Roaming\1H1Q1V1N1N1O1R =>Adware.InstallCore C:\Users\Gaïarac\AppData\Roaming\Astromenda =>PUP.Optional.Astromenda C:\Users\Gaïarac\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy C:\Users\Gaïarac\AppData\Roaming\RHEng =>PUP.Optional.Conduit C:\Users\Gaïarac\AppData\Roaming\SaveSense =>PUP.Optional.SaveSense C:\Users\Gaïarac\AppData\Roaming\sweet-page =>PUP.Optional.SweetPage C:\Users\Gaïarac\AppData\Roaming\WSE_Astromenda =>PUP.Optional.Astromenda C:\Users\Gaïarac\AppData\Local\DriverTuner =>PUP.Optional.DriverTuner C:\Users\Gaïarac\AppData\Local\SaveSenseLive =>PUP.Optional.SaveSense C:\Users\Gaïarac\AppData\Local\Vosteran =>PUP.Optional.Vosteran C:\Users\Gaïarac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense =>PUP.Optional.SaveSense C:\Users\Gaïarac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com =>PUP.Optional.TornTV C:\WINDOWS\Prefetch\SAVESENSELIVE.EXE-6ACC223B.pf =>PUP.Optional.SaveSense C:\WINDOWS\Prefetch\SAVESENSELIVEHANDLER.EXE-A43C936C.pf =>PUP.Optional.SaveSense C:\WINDOWS\System32\drivers\{8aefbcaf-640f-4dca-9a92-ed05ee387238}w64.sys =>PUP.Optional.LinkiDoo C:\WINDOWS\System32\drivers\{a5c25b9e-3974-4e91-9864-34f9aca33ff3}w64.sys =>PUP.Optional.LinkiDoo C:\WINDOWS\System32\drivers\{edf2e803-e64b-4078-9a9f-33672590ad18}w64.sys =>PUP.Optional.LinkiDoo HKLM\SYSTEM\CurrentControlSet\Services\savesenselivem =>PUP.Optional.SaveSense ---\\ Récapitulatif des éléments trouvées sur votre station (18) - 0s http://www.nicolascoolman.fr/pup-astromenda/ =>PUP.Optional.Astromenda http://www.nicolascoolman.fr/hijacker-trovicom/ =>PUP.Optional.TroviCom http://www.nicolascoolman.fr/pup-sweetpage/ =>PUP.Optional.SweetPage http://www.nicolascoolman.fr/pup-savesense/ =>PUP.Optional.SaveSense http://www.nicolascoolman.fr/hijacker-browsers/ =>PUP.Optional.Browser http://www.nicolascoolman.fr/blog =>PUP.Optional.Vosteran http://www.nicolascoolman.fr/adware-installcore/ =>Adware.InstallCore http://www.nicolascoolman.fr/adware-imbooster/ =>PUP.Optional.IMBooster http://www.nicolascoolman.fr/pup-suptab/ =>PUP.Optional.SupTab http://www.nicolascoolman.fr/pup-1clickdownloader/ =>PUP.Optional.1ClickDownloader http://www.nicolascoolman.fr/blog =>PUP.Optional.DriverTuner http://www.nicolascoolman.fr/adware-secretsauce / =>PUP.Optional.SecretSauce http://www.nicolascoolman.fr/blog =>PUP.Optional.SolutionReal http://www.nicolascoolman.fr/hijacker-torntv/ =>PUP.Optional.TornTV http://www.nicolascoolman.fr/adware-opencandy/ =>PUP.Optional.OpenCandy http://www.nicolascoolman.fr/toolbar-conduit/ =>PUP.Optional.Conduit http://www.nicolascoolman.fr/pup-linkidoo/ =>PUP.Optional.LinkiDoo http://www.nicolascoolman.fr/hijacker-trovigo/ =>PUP.Optional.Trovigo ~ End of the scan, 53199 items in 158 seconds (1055)(0)()