~ ZHPDiag v2015.11.13.167 Par Nicolas Coolman (2015/11/13) ~ Démarré par Abderrahim (Administrator) (2015/11/14 21:20:38) ~ Site: http://www.nicolascoolman.fr ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Etat de la version: Version OK ~ Mode: Scanner ~ Rapport: C:\Users\Abderrahim\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\Abderrahim\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ Démarrage du système: Normal (Normal boot) Windows 8 Pro, 32-bit (Build 9200) ---\\ Navigateurs Internet (3) - 0s GCIE: Google Chrome v46.0.2490.86 MFIE: Mozilla Firefox 42.0 (x86 fr) v42.0 MSIE: Internet Explorer v10.0.9200.17413 ---\\ Informations sur les produits Windows (9) - 3s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK ~ Windows(R) Operating System, VOLUME_KMSCLIENT channel Windows ID Activation : OK ~ Windows Partial Key : J8CK4 Windows License : OK Expiration Licence Windows : 259048 minute(s) (180 jour(s)) ~ Windows Remaining Initializations Number : 1000 Windows Automatic Updates : OK ---\\ Logiciels de protection (2) - 1s ESET Smart Security v9.0.318.0 Windows Defender W8 (Deactivate) ---\\ Surveillance de Logiciels (2) - 1s Adobe Flash Player 19 NPAPI Adobe Reader 9 ---\\ Informations sur le système (6) - 0s ~ Operating System: x86 Family 6 Model 23 Stepping 10, GenuineIntel ~ Operating System: 32-bit ~ Boot mode: Normal (Normal boot) Total RAM: 3273.972 MB (62% free) System Restore: Activé (Enable) System drive C: has 41 GB () free of 132 GB ---\\ Mode de connexion au système (3) - 0s ~ Computer Name: THEPES ~ User Name: Abderrahim ~ Logged in as Administrator ---\\ Enumération des unités disques (2) - 0s ~ Drive C: has 41 GB free of 132 GB (System) ~ Drive E: has 16 GB free of 104 GB ---\\ Etat du Centre de Sécurité Windows (11) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ---\\ Recherche particulière de fichiers génériques (24) - 1s [MD5.EAFE46B0292D2BD2467835E2ACF717CC] - 01/06/2013 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [2106176] © [MD5.224F6B374852153C8C24BED141AE3A20] - 26/07/2012 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [48640] © [MD5.7109FF769FFF962869C50D720F7AA7D7] - 26/07/2012 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [101376] © [MD5.E0103806C6CD91CFA8696A8A9EB4C822] - 15/06/2015 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [1763328] © [MD5.89D6AFD5B257049375008BAA512910EE] - 12/04/2014 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [429056] © [MD5.FAB11E1AC62579A9BE21593319F8E464] - 26/07/2012 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [246784] © [MD5.0BE9606A1175C7400ED862991453A847] - 09/10/2014 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [458240] © [MD5.65AA2DE8787146679BB8A7D14BFFB6A3] - 26/07/2012 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [18944] © [MD5.B92C9A8C3CAE22129CC5B4A920B00608] - 29/05/2014 - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\Windows\System32\drivers\AFD.sys [439296] © [MD5.48D8C3F2006698691F5AE0BB595FDCC8] - 26/07/2012 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [22768] © [MD5.00B4FA77732C7823D292ECD672660882] - 26/07/2012 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [89088] © [MD5.4E707EC5071DD8F5C29A7410780BD4C3] - 26/07/2012 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [135680] © [MD5.E608E26B536A42B5ACC145D25CB9F2AC] - 16/01/2014 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [92160] © [MD5.6BFEBBA25AD34E5922E60349C721B1DD] - 15/07/2014 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [62464] © [MD5.11EDC37780E8A2F8E311D73F7658A4D7] - 26/07/2012 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [89600] © [MD5.57B0C0D982013C72911A3F5CBA795034] - 26/07/2012 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [126976] © [MD5.60978139E6942772545EAB1BC2DB1393] - 07/01/2015 - (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\Windows\System32\drivers\MRxSmb.sys [341504] © [MD5.303A053C25E468B9925C22288BEF8484] - 26/07/2012 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [254464] © [MD5.6C816842AC5E2B0E033ED0BD1058E077] - 27/01/2014 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [1618264] © [MD5.8BCE63AF5B52642E832630F862DE96EF] - 26/07/2012 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [90624] © [MD5.6E0649D7325D85C47C844EB3267E4625] - 26/07/2012 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [88064] © [MD5.2CAD2A13569741C67CD9C52F97E0F992] - 26/07/2012 - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\Windows\System32\drivers\rdpdr.sys [156160] © [MD5.0886D9F1B5A5334FBB143A260E4BFB5C] - 26/07/2012 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [97792] © [MD5.BF079843E272759BAE587FB980163293] - 04/07/2014 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [281408] © ---\\ Liste des services NT non Microsoft et non désactivés (11) - 0s O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\System32\atiesrxx.exe © O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) . (...) - C:\Program Files\BlueStacks\HD-Service.exe (.not file.) O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) . (...) - C:\Program Files\BlueStacks\HD-LogRotatorService.exe (.not file.) O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) . (...) - C:\Program Files\BlueStacks\HD-UpdaterService.exe (.not file.) O23 - Service: COMODO Dragon Update Service (DragonUpdater) . (.Comodo - Comodo Dragon.) - C:\Program Files\Comodo\Dragon\dragon_updater.exe © O23 - Service: ESET Service (ekrn) . (.ESET - ESET Service.) - C:\Program Files\ESET\ESET Smart Security\ekrn.exe © O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe © O23 - Service: PnkBstrA (PnkBstrA) . (...) - C:\Windows\System32\PnkBstrA.exe O23 - Service: PnkBstrB (PnkBstrB) . (...) - C:\Windows\System32\PnkBstrB.exe O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe © O23 - Service: TeamViewer 10 (TeamViewer) . (.TeamViewer GmbH - TeamViewer 10.) - C:\Program Files\TeamViewer\TeamViewer_Service.exe © ---\\ Tâches planifiées en automatique (30) - 4s [MD5.280A526E8111AC6A5BCC1A059E1E0340] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [269000] © [MD5.DD3A4BEBE7EA3E75F71F3D9E9E2AA016] [APT] [AutoKMS] (.CODYQX4.) -- C:\Windows\AutoKMS\AutoKMS.exe [3798528] =>HackTool.AutoKMS [MD5.00000000000000000000000000000000] [APT] [ba603409-2b75-4b03-a95c-a8e001a8cd64-1-6] (...) -- C:\Program Files\iWebar\ba603409-2b75-4b03-a95c-a8e001a8cd64-1-6.exe (.not file.) [0] =>PUP.Optional.CrossRider [MD5.00000000000000000000000000000000] [APT] [ba603409-2b75-4b03-a95c-a8e001a8cd64-1-7] (...) -- C:\Program Files\iWebar\ba603409-2b75-4b03-a95c-a8e001a8cd64-1-7.exe (.not file.) [0] =>PUP.Optional.CrossRider [MD5.00000000000000000000000000000000] [APT] [ba603409-2b75-4b03-a95c-a8e001a8cd64-5] (...) -- C:\Program Files\iWebar\ba603409-2b75-4b03-a95c-a8e001a8cd64-5.exe (.not file.) [0] =>PUP.Optional.CrossRider [MD5.00000000000000000000000000000000] [APT] [ba603409-2b75-4b03-a95c-a8e001a8cd64-5_user] (...) -- C:\Program Files\iWebar\ba603409-2b75-4b03-a95c-a8e001a8cd64-5.exe (.not file.) [0] =>PUP.Optional.CrossRider [MD5.00000000000000000000000000000000] [APT] [Driver Robot] (...) -- C:\Program Files\Driver Robot\Driver Robot.lnk --scan --stack=from-scheduler (.not file.) [0] [MD5.0C079BCA88FCE407E3180BE0A06105D0] [APT] [gg_uac_daemon_Abderrahim] (.Copyright (C) 2013.) -- C:\Program Files\Garena Plus\ggdllhost.exe [56256] [MD5.E1B44A75947137F4143308D566889837] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107848] © [MD5.E1B44A75947137F4143308D566889837] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107848] © [MD5.ACFC43D5862543BB3D29AA07D1BB6F89] [APT] [MaxigetMasterUpdate] (...) -- C:\Users\Abderrahim\AppData\Roaming\Maxiget\Master\Updater\MasterUpdater.exe [565008] O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002] © O39 - APT: ba603409-2b75-4b03-a95c-a8e001a8cd64-1-6 - (...) -- C:\Windows\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-1-6.job [3458] =>PUP.Optional.CrossRider O39 - APT: ba603409-2b75-4b03-a95c-a8e001a8cd64-1-7 - (...) -- C:\Windows\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-1-7.job [3458] =>PUP.Optional.CrossRider O39 - APT: ba603409-2b75-4b03-a95c-a8e001a8cd64-5 - (...) -- C:\Windows\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-5.job [2774] =>PUP.Optional.CrossRider O39 - APT: ba603409-2b75-4b03-a95c-a8e001a8cd64-5_user - (...) -- C:\Windows\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-5_user.job [2774] =>PUP.Optional.CrossRider O39 - APT: Driver Robot - (...) -- C:\Windows\Tasks\Driver Robot.job [340] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1076] © O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1080] © O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [3890] © O39 - APT: AutoKMS - (.CODYQX4.) -- C:\Windows\System32\Tasks\AutoKMS [3756] =>HackTool.AutoKMS O39 - APT: ba603409-2b75-4b03-a95c-a8e001a8cd64-1-6 - (...) -- C:\Windows\System32\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-1-6 [6462] =>PUP.Optional.CrossRider O39 - APT: ba603409-2b75-4b03-a95c-a8e001a8cd64-1-7 - (...) -- C:\Windows\System32\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-1-7 [6462] =>PUP.Optional.CrossRider O39 - APT: ba603409-2b75-4b03-a95c-a8e001a8cd64-5 - (...) -- C:\Windows\System32\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-5 [5778] =>PUP.Optional.CrossRider O39 - APT: ba603409-2b75-4b03-a95c-a8e001a8cd64-5_user - (...) -- C:\Windows\System32\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-5_user [5782] =>PUP.Optional.CrossRider O39 - APT: Driver Robot - (...) -- C:\Windows\System32\Tasks\Driver Robot [3112] O39 - APT: gg_uac_daemon_Abderrahim - (.Copyright (C) 2013.) -- C:\Windows\System32\Tasks\gg_uac_daemon_Abderrahim [3440] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [3816] © O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [4052] © O39 - APT: MaxigetMasterUpdate - (...) -- C:\Windows\System32\Tasks\MaxigetMasterUpdate [3842] ---\\ Processus lancés (17) - 1s [MD5.05D36FCAB501C67DEA797FAFB5C42AC5] - (.ESET - ESET Service.) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1971968] [PID.708] © [MD5.20883D2D6E1D94321246AFF39AFCE56C] - (.AMD - AMD External Events Service Module.) -- C:\Windows\System32\atiesrxx.exe [219136] [PID.808] © [MD5.E48C4113F81783222BFAF33C45117146] - (.AMD - AMD External Events Client Module.) -- C:\Windows\System32\atieclxx.exe [482304] [PID.1124] © [MD5.8A5F7CFD8BA2F731FB0403B909716F9D] - (.Comodo - Comodo Dragon.) -- C:\Program Files\Comodo\Dragon\dragon_updater.exe [1984696] [PID.1976] © [MD5.19E83B09AB8EE1D837665DA941E2AC44] - (...) -- C:\Windows\System32\PnkBstrA.exe [66872] [PID.692] [MD5.D27C75A9690CAEE8B29CFEC2274CB6FE] - (...) -- C:\Windows\System32\PnkBstrB.exe [202040] [PID.888] [MD5.758B320E709CBF1D0C34A18390EEE6E8] - (.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files\TeamViewer\TeamViewer_Service.exe [5495056] [PID.1628] © [MD5.0C079BCA88FCE407E3180BE0A06105D0] - (.Copyright (C) 2013 - Windows host process (Rundll32).) -- C:\Program Files\Garena Plus\ggdllhost.exe [56256] [PID.3396] [MD5.E0ED4A85D35E3874A85A25C222326B81] - (.ESET - ESET Main GUI.) -- C:\Program Files\ESET\ESET Smart Security\egui.exe [5532872] [PID.3496] © [MD5.A72BB48D9014A7D7C05F02F595F52D60] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files\Google\Update\1.3.28.15\GoogleCrashHandler.exe [245576] [PID.4016] © [MD5.F916BA0DA28A4B4F7B1ADE76EB42F088] - (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [597552] [PID.3996] © [MD5.B5622C1549F75A2E2312B59CE2293A09] - (...) -- C:\Program Files\WebcamMax\wcmmon.exe [1038848] [PID.2288] [MD5.4B0583A0A6A22D9F453BFFD467E68190] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [392872] [PID.3324] © [MD5.344CC9339BA1022F335B46B95AABF32F] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files\Mozilla Firefox\plugin-container.exe [277672] [PID.5544] © [MD5.BC13FFE3F1B6582AE1ADC2B536AF8CC5] - (.Adobe Systems, Inc. - Adobe Flash Player 19.0 r0.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_19_0_0_245.exe [3426504] [PID.5516] © [MD5.BC13FFE3F1B6582AE1ADC2B536AF8CC5] - (.Adobe Systems, Inc. - Adobe Flash Player 19.0 r0.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_19_0_0_245.exe [3426504] [PID.5460] © [MD5.C76ED9E6D9E432DE096236B09E81A77F] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Abderrahim\Downloads\ZHPDiag3.exe [1968640] [PID.2756] © ---\\ Google Chrome, Démarrage,Recherche,Extensions (15) - 0s G0 - GCSP: Preferences [User Data\Default][HomePage] http://accounts.google.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://accounts.youtube.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://chrome.google.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://fonts.gstatic.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.dz G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.googleapis.com G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake]Docs G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf]Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo]Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf]Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [jmolcgpienlcieaajfkkdamlngancncm]IDM Integration G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda]Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [npdicihegicnhaangkdmcgbjceoemeoo]__MSG_newtab_chrome_extension_name__ G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia]Google Chrome manifest =>.Google Inc. ---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (8) - 1s M0 - MFSP: prefs.js [Abderrahim - nv2a014w.default] https://es.yahoo.com/?fr=yset_ff_syc_oracle&type=orcl_hpset P2 - EXT FILE: (...) -- C:\Users\Abderrahim\AppData\Roaming\Mozilla\Firefox\Profiles\nv2a014w.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml P2 - EXT: (.Mozilla - Default.) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} © P2 - EXT: (.lightningnewtab.com - Istart.) -- C:\Users\Abderrahim\AppData\Roaming\Mozilla\Firefox\Profiles\nv2a014w.default\extensions\istart_ffnt@gmail.com =>PUP.Optional.LightningNewTab P2 - EXT: (.iMacros Team, iOpus Software GmbH - iMacros for Firefox.) -- C:\Users\Abderrahim\AppData\Roaming\Mozilla\Firefox\Profiles\nv2a014w.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} P2 - EXT: (.V@no - Cookies Manager+.) -- C:\Users\Abderrahim\AppData\Roaming\Mozilla\Firefox\Profiles\nv2a014w.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d} P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\NPSWF32_19_0_0_245.dll © ---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (12) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://es.yahoo.com/ R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/ =>PUP.Optional.StartSearch R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 ---\\ Internet Explorer,Proxy Management (4) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) © F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) © F2 - REG:system.ini: VMApplet=C:\Windows\system32\SystemPropertiesPerformance.exe (.Microsoft Corporation.) © ---\\ Etude du fichier hosts (5) - 0s 149.202 77.72 149.202 77.72 ~ Nombre lignes détournées 149.202 5 (Hosts file redirected) ---\\ Browser Helper Object de navigateur (BHO) (7) - 1s O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files\Internet Download Manager\IDMIECC.dll © O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll © O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll © O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll © O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll © O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll © O2 - BHO: AliBar BHO - {E4E012DC-1925-48E9-8010-2D195574642A} . (.B1 - AliTab.) -- C:\Program Files\Internet Explorer\alitab.dll ---\\ Internet Explorer, Barre d'outil (1) - 0s O3 - Toolbar: 0xE3EFEB7F196B494398D2FFB09D4B49CA00CC040000 - [HKCU]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} . (...) -- (.not file.) ---\\ Applications lancées au démarrage du système (27) - 0s O4 - HKLM\..\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe © O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe © O4 - HKLM\..\Run: [NPSStartup] (Orphean) O4 - HKLM\..\Run: [KeyScrambler] . (.QFX Software Corporation - KeyScrambler.) -- C:\Program Files\KeyScrambler\keyscrambler.exe © O4 - HKLM\..\Run: [NeroFilterCheck] . (.Ahead Software Gmbh - NeroCheck.) -- C:\Windows\System32\NeroCheck.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe © O4 - HKLM\..\Run: [GrooveMonitor] . (.Microsoft Corporation - GrooveMonitor Utility.) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe © O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe © O4 - HKCU\..\Run: [GarenaPlus] . (.Copyright (C) 2010-2012 Garena Online Pte Ltd - Garena Plus.) -- C:\Program Files\Garena Plus\GarenaMessenger.exe O4 - HKCU\..\Run: [EpicScale] C:\ProgramData\EpicScale\0\EpicScale.exe (.not file.) =>PUP.Optional.EpicScale O4 - HKCU\..\Run: [urlspace] E:\jinsoft.exe (.not file.) O4 - HKCU\..\Run: [f3dfad1bbc2cef691bfbf9bbf8d49eb5] C:\Users\Abderrahim\AppData\Local\Temp\IDMGrHlp.exe (.not file.) O4 - HKCU\..\Run: [MaxigetMasterUpdate] . (...) -- C:\Users\Abderrahim\AppData\Roaming\Maxiget\Master\Updater\MasterUpdater.exe O4 - HKCU\..\Run: [AntiSnooper] . (.Bagrify Solutions - AntiSnooper.) -- C:\Program Files\AntiSnooper Pro\AntiSnooper.exe O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe © O4 - HKCU\..\Run: [WebcamMaxAutoRun] . (...) -- C:\Program Files\WebcamMax\wcmmon.exe O4 - HKCU\..\Run: [Steam] . (.Valve Corporation - Steam Client Bootstrapper.) -- C:\Program Files\Steam\Steam.exe © O4 - HKUS\S-1-5-21-3996179234-1296658072-3002143054-1001\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe © O4 - HKUS\S-1-5-21-3996179234-1296658072-3002143054-1001\..\Run: [GarenaPlus] . (.Copyright (C) 2010-2012 Garena Online Pte Ltd - Garena Plus.) -- C:\Program Files\Garena Plus\GarenaMessenger.exe O4 - HKUS\S-1-5-21-3996179234-1296658072-3002143054-1001\..\Run: [EpicScale] C:\ProgramData\EpicScale\0\EpicScale.exe (.not file.) =>PUP.Optional.EpicScale O4 - HKUS\S-1-5-21-3996179234-1296658072-3002143054-1001\..\Run: [urlspace] E:\jinsoft.exe (.not file.) O4 - HKUS\S-1-5-21-3996179234-1296658072-3002143054-1001\..\Run: [f3dfad1bbc2cef691bfbf9bbf8d49eb5] C:\Users\Abderrahim\AppData\Local\Temp\IDMGrHlp.exe (.not file.) O4 - HKUS\S-1-5-21-3996179234-1296658072-3002143054-1001\..\Run: [MaxigetMasterUpdate] . (...) -- C:\Users\Abderrahim\AppData\Roaming\Maxiget\Master\Updater\MasterUpdater.exe O4 - HKUS\S-1-5-21-3996179234-1296658072-3002143054-1001\..\Run: [AntiSnooper] . (.Bagrify Solutions - AntiSnooper.) -- C:\Program Files\AntiSnooper Pro\AntiSnooper.exe O4 - HKUS\S-1-5-21-3996179234-1296658072-3002143054-1001\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe © O4 - HKUS\S-1-5-21-3996179234-1296658072-3002143054-1001\..\Run: [WebcamMaxAutoRun] . (...) -- C:\Program Files\WebcamMax\wcmmon.exe O4 - HKUS\S-1-5-21-3996179234-1296658072-3002143054-1001\..\Run: [Steam] . (.Valve Corporation - Steam Client Bootstrapper.) -- C:\Program Files\Steam\Steam.exe © ---\\ Modification Domaine/Adresses DNS (4) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.42.129 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.42.129 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 ---\\ Protocole additionnel (24) - 1s O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll © O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} . (.Microsoft Corporation - GrooveSystemServices Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll © O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll © O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll © O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll © O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll © O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll © O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll © O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll © O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll © O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll © O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll © O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL © ---\\ Logiciels installés (84) - 10s O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU] -- uTorrent O42 - Logiciel: 7-Zip 9.20 - (...) [HKLM] -- 7-Zip O42 - Logiciel: AAA Logo 2014 v4.0 - (.SWGSoft.) [HKLM] -- AAA Logo 2014_is1 © O42 - Logiciel: Acrobat.com - (.Adobe Systems Incorporated.) [HKLM] -- {77DCDCE3-2DED-62F3-8154-05E745472D07} © O42 - Logiciel: Acrobat.com - (.Adobe Systems Incorporated.) [HKLM] -- com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 © O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- {7B77622E-DE90-48EA-B2C7-227B1DE58A01} © O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- Adobe AIR © O42 - Logiciel: Adobe Flash Player 19 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI © O42 - Logiciel: Adobe Reader 9 - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1033-7B44-A90000000001} © O42 - Logiciel: AMD Accelerated Video Transcoding - (.Advanced Micro Devices, Inc..) [HKLM] -- {541B6B75-A7DE-984D-2817-F2E320832E15} © O42 - Logiciel: AMD APP SDK Runtime - (.Advanced Micro Devices Inc..) [HKLM] -- {A25FF1C0-80B6-4B8B-A551-DC525697A408} © O42 - Logiciel: AMD Catalyst Install Manager - (.Advanced Micro Devices, Inc..) [HKLM] -- {F132512A-358F-CCE7-02C3-8CCD582BAA3B} © O42 - Logiciel: ANDY OS - (.andyroid.net.) [HKLM] -- ANDY OS O42 - Logiciel: Angry IP Scanner - (.Angry IP Scanner.) [HKLM] -- Angry IP Scanner O42 - Logiciel: AntiSnooper Pro version 2.0 - (.Bagrify Solutions.) [HKLM] -- {1CF3C108-D084-4F0C-A1D5-778E7C7EA4EB}_is1 O42 - Logiciel: ASIO4ALL - (.Michael Tippach.) [HKLM] -- ASIO4ALL © O42 - Logiciel: Aurous - (.Aurous Group.) [HKLM] -- {49296734-B696-4A16-A553-9FCDA82872C7} O42 - Logiciel: Aurous - (.Aurous Group.) [HKLM] -- Aurous 0.1.1 O42 - Logiciel: Bandicam - (.Bandisoft.com.) [HKLM] -- Bandicam © O42 - Logiciel: Bandisoft MPEG-1 Decoder - (.Bandisoft.com.) [HKLM] -- BandiMPEG1 © O42 - Logiciel: BloodFrontier - (...) [HKLM] -- BloodFrontier O42 - Logiciel: Call Of Duty.Black Ops.v Update 6 - (.Fenixx--Repack--(07.07.2011).) [HKLM] -- Call Of Duty.Black Ops.v Update 6_is1 O42 - Logiciel: Catalyst Control Center - Branding - (.Advanced Micro Devices, Inc..) [HKLM] -- {E2F0AF23-FE2F-4222-9A43-55E63CC41EF1} © O42 - Logiciel: Comodo Dragon - (.Comodo.) [HKLM] -- Comodo Dragon © O42 - Logiciel: DriverToolkit version 8.1.1.0 - (.Megaify Software.) [HKLM] -- {D66BF89F-B0A2-48F5-A2E4-242EB645AB76}_is1 =>PUP.Optional.DriverToolkit O42 - Logiciel: EpicScale Application - (.EpicScale, Inc..) [HKCU] -- EpicScaleApp =>PUP.Optional.EpicScale O42 - Logiciel: ESET Smart Security - (.ESET, spol. s r.o..) [HKLM] -- {7E42F3C8-713E-4BFD-998E-FC08F31C3C9F} O42 - Logiciel: Euro Truck Simulator 2 - Going East! - (...) [HKLM] -- Euro Truck Simulator 2 - Going East!_is1 O42 - Logiciel: Farming Simulator 15 v.1.2.1 - (...) [HKLM] -- Farming Simulator 15_is1 O42 - Logiciel: FIFA 11 - (.Electronic Arts.) [HKLM] -- {3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C} © O42 - Logiciel: FL Studio 11 - (.Image-Line.) [HKLM] -- FL Studio 11 © O42 - Logiciel: FlowStone FL 3.0 - (...) [HKLM] -- FlowStone O42 - Logiciel: fps boost gta eflc - (...) [HKLM] -- fps boost gta eflc O42 - Logiciel: FreeArc 0.666 - (.Bulat Ziganshin.) [HKLM] -- FreeArc O42 - Logiciel: GameRanger - (.GameRanger Technologies.) [HKCU] -- GameRanger © O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome © O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {817750FA-EC6A-485D-9901-0683AE6FFDF1} © O42 - Logiciel: Google Earth Plug-in - (.Google.) [HKLM] -- {57BB4801-61C8-4E74-9672-2160728A461E} © O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} © O42 - Logiciel: IIS Express Application Compatibility Database for x86 - (...) [HKLM] -- {fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb O42 - Logiciel: IIS 8.0 Express - (.Microsoft Corporation.) [HKLM] -- {B8FFB7D6-6ABD-47C3-8BAD-86FF5D8F3EDC} © O42 - Logiciel: IL Shared Libraries - (.Image-Line.) [HKLM] -- IL Shared Libraries © O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM] -- Internet Download Manager © O42 - Logiciel: Java 8 Update 60 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83218060F0} © O42 - Logiciel: KeyScrambler - (.QFX Software Corporation.) [HKLM] -- KeyScrambler © O42 - Logiciel: MEGAsync - (.Mega Limited.) [HKLM] -- MEGAsync © O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} © O42 - Logiciel: Microsoft System CLR Types for SQL Server 2012 - (.Microsoft Corporation.) [HKLM] -- {E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB} © O42 - Logiciel: Microsoft Web Deploy 3.0 - (.Microsoft Corporation.) [HKLM] -- {E43AC95E-66B0-4CEC-AADD-C9BFEF5A4C0A} © O42 - Logiciel: Microsoft Web Platform Installer 5.0 - (.Microsoft Corporation.) [HKLM] -- {1D39E015-C3D2-45DE-B070-A69C5F2FB309} © O42 - Logiciel: Microsoft WebMatrix 3 - (.Microsoft Corporation.) [HKLM] -- {D093B71B-8575-4656-9CE0-0E6C006F8818} © O42 - Logiciel: Mozilla Firefox 42.0 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 42.0 (x86 fr) © O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService © O42 - Logiciel: MSVC80_x86 - (.Nokia.) [HKLM] -- {212748BB-0DA5-46DE-82A1-403736DC9F27} © O42 - Logiciel: MSXML 4.0 SP2 Parser and SDK - (.Microsoft Corporation.) [HKLM] -- {716E0306-8318-4364-8B8F-0CC4E9376BAC} © O42 - Logiciel: Need for Speed Most Wanted - (...) [HKLM] -- Need for Speed Most Wanted_is1 O42 - Logiciel: Need for Speed(TM) Hot Pursuit - (.Electronic Arts.) [HKLM] -- {83A606F5-BF6F-42ED-9F33-B9F74297CDED} © O42 - Logiciel: Notepad++ - (.Notepad++ Team.) [HKLM] -- Notepad++ © O42 - Logiciel: PC Connectivity Solution - (.Nokia.) [HKLM] -- {34610DE0-3C13-42CA-8E32-01FFA38AB6E8} © O42 - Logiciel: PDF Eraser V1.4 - (.http://www.PDFEraser.net.) [HKLM] -- PDF Eraser_is1 O42 - Logiciel: PdfGrabber 7.0 (32bit) - (.PixelPlanet.) [HKLM] -- {01517A48-9217-431B-821C-F89F53918E3D} O42 - Logiciel: Pro Evolution Soccer 2016 - (...) [HKLM] -- UHJvRXZvbHV0aW9uU29jY2VyMjAxNg==_is1 O42 - Logiciel: RarmaRadio 2.69.1 - (.RaimerSoft.) [HKLM] -- RarmaRadio_is1 © O42 - Logiciel: SamsungConnectivityCableDriver - (.Samsung.) [HKLM] -- {7E84FAC8-C518-40F9-9807-7455301D6D25} © O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701} © O42 - Logiciel: Skype™ 7.10 - (.Skype Technologies S.A..) [HKLM] -- {6A0549A9-1B96-498C-ACBC-3943001FEB19} © O42 - Logiciel: Software Management Module - (.Maxiget Ltd..) [HKCU] -- Software Management Module O42 - Logiciel: Steam - (.Valve Corporation.) [HKLM] -- Steam © O42 - Logiciel: System Requirements Lab - (.Husdawg, LLC.) [HKLM] -- {0F659036-14C7-4622-9505-35A0DC93526A} © O42 - Logiciel: TeamViewer 10 - (.TeamViewer.) [HKLM] -- TeamViewer © O42 - Logiciel: TeraCopy 2.3 - (.Code Sector.) [HKLM] -- TeraCopy_is1 O42 - Logiciel: Tom Clancy`s H.A.W.X. 2 - (.R.G. Element Arts.) [HKLM] -- Tom Clancy`s H.A.W.X. 2_R.G._Element_Arts_is1 O42 - Logiciel: TopTv version 2.0 - (.Alsersawy.stream, Inc..) [HKLM] -- {FCCEA808-0710-4650-AE1D-BFC8848D373B}_is1 O42 - Logiciel: TRANSFORMERS - War for Cybertron - (.R.G. Mechanics, ProZorg_tm.) [HKLM] -- TRANSFORMERS - War for Cybertron_R.G. Mechanics_is1 O42 - Logiciel: Ubisoft Game Launcher - (.UBISOFT.) [HKLM] -- {888F1505-C2B3-4FDE-835D-36353EBD4754} © O42 - Logiciel: UltraISO Premium V9.12 - (...) [HKLM] -- UltraISO_is1 O42 - Logiciel: Visual Studio 2012 x86 Redistributables - (.AVG Technologies CZ, s.r.o..) [HKLM] -- {98EFF19A-30AB-4E4B-B943-F06B1C63EBF8} © O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM] -- VLC media player © O42 - Logiciel: WebcamMax - (.COOLWAREMAX.) [HKLM] -- WebcamMax O42 - Logiciel: WinPcap 4.1.3 - (.Riverbed Technology, Inc..) [HKLM] -- WinPcapInst © O42 - Logiciel: WinRAR 5.21 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver © O42 - Logiciel: WinZip 18.0 - (.WinZip Computing, S.L. .) [HKLM] -- {CD95F661-A5C4-44F5-A6AA-ECDD91C240E0} © O42 - Logiciel: Wireshark 1.12.5 (32-bit) - (.The Wireshark developer community, http://www.wireshark.org.) [HKLM] -- Wireshark © O42 - Logiciel: XnView 2.25 - (.Gougelet Pierre-e.) [HKLM] -- XnView_is1 © ---\\ HKCU & HKLM Software Keys (205) - 10s HKLM\SOFTWARE\7-Zip HKLM\SOFTWARE\Activision HKLM\SOFTWARE\Adobe HKLM\SOFTWARE\Ahead HKLM\SOFTWARE\AIM Toolbar HKLM\SOFTWARE\AMD HKLM\SOFTWARE\Ammyy HKLM\SOFTWARE\Angry IP Scanner HKLM\SOFTWARE\AppDataLow HKLM\SOFTWARE\Apple Inc. HKLM\SOFTWARE\ASIO HKLM\SOFTWARE\ASIO4ALL HKLM\SOFTWARE\AskPartnerNetwork =>Toolbar.AskBar HKLM\SOFTWARE\ATI HKLM\SOFTWARE\ATI Technologies HKLM\SOFTWARE\Aurous Group HKLM\SOFTWARE\Baidu HKLM\SOFTWARE\BandiMPEG1 HKLM\SOFTWARE\BANDISOFT HKLM\SOFTWARE\BloodFrontier HKLM\SOFTWARE\BlueStacks HKLM\SOFTWARE\Caphyon HKLM\SOFTWARE\Chromium HKLM\SOFTWARE\CloudOPTInfo HKLM\SOFTWARE\Code Sector HKLM\SOFTWARE\COMODO HKLM\SOFTWARE\ComodoGroup HKLM\SOFTWARE\Conduit =>PUP.Optional.Conduit HKLM\SOFTWARE\Debug HKLM\SOFTWARE\Dell HKLM\SOFTWARE\Dragon HKLM\SOFTWARE\DSPRobotics HKLM\SOFTWARE\DTP HKLM\SOFTWARE\EA GAMES HKLM\SOFTWARE\EA Sports HKLM\SOFTWARE\EasyBoot Systems HKLM\SOFTWARE\Elcom HKLM\SOFTWARE\Electronic Arts HKLM\SOFTWARE\ESET HKLM\SOFTWARE\F-Secure HKLM\SOFTWARE\FreeArc HKLM\SOFTWARE\GlobalUpdate =>PUP.Optional.GlobalUpdate HKLM\SOFTWARE\GN2 HKLM\SOFTWARE\Goobzo =>PUP.Optional.Goobzo HKLM\SOFTWARE\Google HKLM\SOFTWARE\IHProtect =>PUP.Optional.AgentODR HKLM\SOFTWARE\IM Providers HKLM\SOFTWARE\Image-Line HKLM\SOFTWARE\Iminent =>PUP.Optional.IMBooster HKLM\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions HKLM\SOFTWARE\Intel HKLM\SOFTWARE\Internet Download Manager HKLM\SOFTWARE\iWebar =>PUP.Optional.CrossRider HKLM\SOFTWARE\iWebar-nv-ie =>PUP.Optional.CrossRider HKLM\SOFTWARE\JavaSoft HKLM\SOFTWARE\JreMetrics HKLM\SOFTWARE\Khronos HKLM\SOFTWARE\KONAMI HKLM\SOFTWARE\KONAMIPES6 HKLM\SOFTWARE\Licenses HKLM\SOFTWARE\m0d_s0beit_3.5 HKLM\SOFTWARE\Macromedia HKLM\SOFTWARE\MarkAny HKLM\SOFTWARE\Maxiget HKLM\SOFTWARE\Mozilla HKLM\SOFTWARE\mozilla.org HKLM\SOFTWARE\MozillaPlugins HKLM\SOFTWARE\mystartsearchSoftware =>PUP.Optional.StartSearch HKLM\SOFTWARE\Nero HKLM\SOFTWARE\Nico Mak Computing HKLM\SOFTWARE\Notepad++ HKLM\SOFTWARE\ODBC HKLM\SOFTWARE\PC Connectivity Solution HKLM\SOFTWARE\PCSuite HKLM\SOFTWARE\PES 2016 Selector Tool HKLM\SOFTWARE\Propellerhead Software HKLM\SOFTWARE\QFX Software HKLM\SOFTWARE\RegisteredApplications HKLM\SOFTWARE\Samsung HKLM\SOFTWARE\SearchProtect =>PUP.Optional.SearchProtect HKLM\SOFTWARE\Skype HKLM\SOFTWARE\SoftVoice HKLM\SOFTWARE\SOFTWARE HKLM\SOFTWARE\SpeedBit HKLM\SOFTWARE\SupDp =>PUP.Optional.SupTab HKLM\SOFTWARE\supTab =>PUP.Optional.SupTab HKLM\SOFTWARE\Synetic HKLM\SOFTWARE\TeamViewer HKLM\SOFTWARE\TechSmith HKLM\SOFTWARE\Ubisoft HKLM\SOFTWARE\Valve HKLM\SOFTWARE\VideoLAN HKLM\SOFTWARE\Volatile HKLM\SOFTWARE\WafCX HKLM\SOFTWARE\WajIntEnhance =>PUP.Optional.Wajam HKLM\SOFTWARE\WebcamMax HKLM\SOFTWARE\WinPcap HKLM\SOFTWARE\WinRAR HKLM\SOFTWARE\Wondershare HKLM\SOFTWARE\XnView HKLM\SOFTWARE\Yahoo HKLM\SOFTWARE\Even Balance HKCU\SOFTWARE\4shared HKCU\SOFTWARE\7-Zip HKCU\SOFTWARE\AAA Logo 2014 HKCU\SOFTWARE\AAA_LOGO HKCU\SOFTWARE\Ada99 HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\Ahead HKCU\SOFTWARE\Ammyy HKCU\SOFTWARE\AOL HKCU\SOFTWARE\APN PIP =>PUP.Optional.Conduit HKCU\SOFTWARE\APNDTX HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\ARAR HKCU\SOFTWARE\Atheros HKCU\SOFTWARE\ATI HKCU\SOFTWARE\Avg Secure Update HKCU\SOFTWARE\Bagrify HKCU\SOFTWARE\Baidu HKCU\SOFTWARE\BandiMPEG1 HKCU\SOFTWARE\BANDISOFT HKCU\SOFTWARE\BitTorrent HKCU\SOFTWARE\Camfrog HKCU\SOFTWARE\Chromium HKCU\SOFTWARE\Code Sector HKCU\SOFTWARE\DownloadManager HKCU\SOFTWARE\Driver Robot HKCU\SOFTWARE\DriverToolkit =>PUP.Optional.DriverToolkit HKCU\SOFTWARE\DSPRobotics HKCU\SOFTWARE\EA Sports HKCU\SOFTWARE\EasyBoot Systems HKCU\SOFTWARE\Elcom HKCU\SOFTWARE\Electronic Arts HKCU\SOFTWARE\EpicScale =>PUP.Optional.EpicScale HKCU\SOFTWARE\ESET HKCU\SOFTWARE\F-Secure HKCU\SOFTWARE\f3dfad1bbc2cef691bfbf9bbf8d49eb5 =>PUP.Optional.CrossRider HKCU\SOFTWARE\Facebook HKCU\SOFTWARE\Foxit Software HKCU\SOFTWARE\GameRanger HKCU\SOFTWARE\globalUpdate =>PUP.Optional.GlobalUpdate HKCU\SOFTWARE\GN2 HKCU\SOFTWARE\Goobzo =>PUP.Optional.Goobzo HKCU\SOFTWARE\Google HKCU\SOFTWARE\Gunman HKCU\SOFTWARE\HomeTab =>PUP.Optional.CertifiedToolbar HKCU\SOFTWARE\iLivid =>PUP.Optional.Bandoo HKCU\SOFTWARE\ilividbandoomoviestoolbar =>PUP.Optional.Bandoo HKCU\SOFTWARE\IM Providers HKCU\SOFTWARE\iMacros HKCU\SOFTWARE\Image-Line HKCU\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions HKCU\SOFTWARE\iWebar-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\JavaSoft HKCU\SOFTWARE\Kiloo Games HKCU\SOFTWARE\Kromtech HKCU\SOFTWARE\Leadertech HKCU\SOFTWARE\Linkey =>PUP.Optional.LinkeySearch HKCU\SOFTWARE\Local AppWizard-Generated Applications HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\Maxiget HKCU\SOFTWARE\Mine HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\Nico Mak Computing HKCU\SOFTWARE\Norton HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\QFX Software HKCU\SOFTWARE\QtProject HKCU\SOFTWARE\Raimasoft HKCU\SOFTWARE\RegisteredApplications HKCU\SOFTWARE\SAMP HKCU\SOFTWARE\Samsung HKCU\SOFTWARE\SearchProtectWS =>PUP.Optional.SearchProtect HKCU\SOFTWARE\SensePlus-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\SimplyTech =>PUP.Optional.SimplyTech HKCU\SOFTWARE\Skype HKCU\SOFTWARE\SoftVoice HKCU\SOFTWARE\SWiSHE.net HKCU\SOFTWARE\System Requirements Lab HKCU\SOFTWARE\TeamViewer HKCU\SOFTWARE\TechSmith HKCU\SOFTWARE\Thraex Software HKCU\SOFTWARE\TNT2 =>PUP.Optional.Freshy HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\Valve HKCU\SOFTWARE\VB and VBA Program Settings HKCU\SOFTWARE\Visicom Media HKCU\SOFTWARE\WajIntEnhance =>PUP.Optional.Wajam HKCU\SOFTWARE\WComVista64 HKCU\SOFTWARE\WinRAR HKCU\SOFTWARE\WinRAR SFX HKCU\SOFTWARE\WinZip Computing HKCU\SOFTWARE\Wireshark HKCU\SOFTWARE\Wondershare HKCU\SOFTWARE\Wow6432Node HKCU\SOFTWARE\Yahoo HKCU\SOFTWARE\Yandex HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\COMODO HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider HKCU\SOFTWARE\AppDataLow\Software\JavaSoft ---\\ Contenu des dossiers Programmes (350) - 11s O43 - CFD: 11/09/2015 - [] D -- C:\Program Files\7-Zip O43 - CFD: 07/09/2015 - [] D -- C:\Program Files\AAALOGO O43 - CFD: 14/02/2015 - [] D -- C:\Program Files\Adobe O43 - CFD: 20/03/2015 - [] D -- C:\Program Files\Ahead O43 - CFD: 26/07/2012 - [] D -- C:\Program Files\AMD APP O43 - CFD: 26/07/2012 - [] D -- C:\Program Files\AMD AVT O43 - CFD: 24/03/2015 - [] D -- C:\Program Files\Andy O43 - CFD: 14/07/2015 - [] D -- C:\Program Files\Angry IP Scanner O43 - CFD: 07/07/2015 - [] D -- C:\Program Files\AntiSnooper Pro O43 - CFD: 08/06/2015 - [] D -- C:\Program Files\ARAR O43 - CFD: 20/08/2015 - [] D -- C:\Program Files\ASIO4ALL v2 O43 - CFD: 26/07/2012 - [] D -- C:\Program Files\ATI O43 - CFD: 26/07/2012 - [] D -- C:\Program Files\ATI Technologies O43 - CFD: 22/10/2015 - [] D -- C:\Program Files\Aurous Group O43 - CFD: 13/11/2015 - [] D -- C:\Program Files\baidu O43 - CFD: 09/10/2015 - [] D -- C:\Program Files\Bandicam O43 - CFD: 09/10/2015 - [] D -- C:\Program Files\BandiMPEG1 O43 - CFD: 03/10/2015 - [0] D -- C:\Program Files\BlueStacks O43 - CFD: 27/07/2015 - [] D -- C:\Program Files\Call of duty 4 Multiplayer O43 - CFD: 01/04/2015 - [] D -- C:\Program Files\Call Of Duty.Black Ops.v Update 6 O43 - CFD: 03/10/2015 - [] D -- C:\Program Files\Common Files O43 - CFD: 18/10/2015 - [] D -- C:\Program Files\Comodo O43 - CFD: 14/02/2015 - [] D -- C:\Program Files\DIFX O43 - CFD: 01/07/2015 - [0] D -- C:\Program Files\Driver Robot O43 - CFD: 26/06/2015 - [] D -- C:\Program Files\DriverToolkit =>PUP.Optional.DriverToolkit O43 - CFD: 27/06/2015 - [] D -- C:\Program Files\Droid4Xext O43 - CFD: 20/08/2015 - [] D -- C:\Program Files\DSPRobotics O43 - CFD: 26/06/2015 - [] D -- C:\Program Files\EA Sports O43 - CFD: 05/06/2015 - [] D -- C:\Program Files\ElcomSoft O43 - CFD: 05/05/2015 - [] D -- C:\Program Files\Electronic Arts O43 - CFD: 27/05/2015 - [] D -- C:\Program Files\ESET O43 - CFD: 26/07/2012 - [0] SHD -- C:\Program Files\Fichiers communs O43 - CFD: 14/06/2015 - [] D -- C:\Program Files\FreeArc O43 - CFD: 26/06/2015 - [] D -- C:\Program Files\Game O43 - CFD: 27/07/2015 - [] D -- C:\Program Files\Garena Plus O43 - CFD: 06/02/2015 - [] D -- C:\Program Files\globalUpdate =>PUP.Optional.GlobalUpdate O43 - CFD: 13/11/2015 - [] D -- C:\Program Files\Google O43 - CFD: 17/06/2015 - [] D -- C:\Program Files\IIS O43 - CFD: 17/06/2015 - [] D -- C:\Program Files\IIS Express O43 - CFD: 11/02/2015 - [] D -- C:\Program Files\ilividbandoomoviestoolbar =>PUP.Optional.Bandoo O43 - CFD: 22/08/2015 - [] D -- C:\Program Files\Image-Line O43 - CFD: 06/04/2015 - [] HD -- C:\Program Files\InstallShield Installation Information O43 - CFD: 01/07/2015 - [] D -- C:\Program Files\Intel O43 - CFD: 18/03/2015 - [] D -- C:\Program Files\Internet Download Manager O43 - CFD: 03/08/2015 - [] D -- C:\Program Files\Internet Explorer O43 - CFD: 04/04/2015 - [] D -- C:\Program Files\iWebar =>PUP.Optional.CrossRider O43 - CFD: 30/08/2015 - [] D -- C:\Program Files\Java O43 - CFD: 27/02/2015 - [] D -- C:\Program Files\KeyScrambler O43 - CFD: 15/03/2015 - [0] D -- C:\Program Files\Maxiget O43 - CFD: 17/06/2015 - [] D -- C:\Program Files\Microsoft O43 - CFD: 19/02/2015 - [] D -- C:\Program Files\Microsoft Analysis Services O43 - CFD: 10/11/2015 - [] D -- C:\Program Files\Microsoft Office O43 - CFD: 17/06/2015 - [] D -- C:\Program Files\Microsoft SDKs O43 - CFD: 31/08/2015 - [] D -- C:\Program Files\Microsoft Silverlight O43 - CFD: 17/06/2015 - [] D -- C:\Program Files\Microsoft SQL Server O43 - CFD: 10/11/2015 - [] D -- C:\Program Files\Microsoft Visual Studio O43 - CFD: 10/11/2015 - [] D -- C:\Program Files\Microsoft Visual Studio 8 O43 - CFD: 17/06/2015 - [] D -- C:\Program Files\Microsoft WebMatrix O43 - CFD: 10/11/2015 - [] D -- C:\Program Files\Microsoft Works O43 - CFD: 22/11/2014 - [] D -- C:\Program Files\Microsoft.NET O43 - CFD: 13/11/2015 - [] D -- C:\Program Files\Mozilla Firefox O43 - CFD: 13/11/2015 - [] D -- C:\Program Files\Mozilla Maintenance Service O43 - CFD: 10/11/2015 - [] D -- C:\Program Files\MSBuild O43 - CFD: 14/02/2015 - [0] D -- C:\Program Files\MSXML 4.0 O43 - CFD: 11/09/2015 - [] D -- C:\Program Files\Notepad++ O43 - CFD: 14/02/2015 - [] D -- C:\Program Files\PC Connectivity Solution O43 - CFD: 07/09/2015 - [] D -- C:\Program Files\PDF Eraser O43 - CFD: 04/09/2015 - [] D -- C:\Program Files\PixelPlanet O43 - CFD: 07/11/2015 - [] D -- C:\Program Files\Pro Evolution Soccer 2016 O43 - CFD: 04/04/2015 - [] D -- C:\Program Files\R.G. Element Arts O43 - CFD: 11/04/2015 - [0] D -- C:\Program Files\R.G. Mechanics O43 - CFD: 06/02/2015 - [] D -- C:\Program Files\RarmaRadio O43 - CFD: 29/03/2015 - [] D -- C:\Program Files\Reference Assemblies O43 - CFD: 14/02/2015 - [] D -- C:\Program Files\Samsung O43 - CFD: 07/04/2015 - [] D -- C:\Program Files\SCS Software O43 - CFD: 14/10/2015 - [] RD -- C:\Program Files\Skype O43 - CFD: 13/11/2015 - [] D -- C:\Program Files\Steam O43 - CFD: 26/06/2015 - [] D -- C:\Program Files\Support O43 - CFD: 13/11/2015 - [] D -- C:\Program Files\SystemRequirementsLab O43 - CFD: 24/08/2015 - [] D -- C:\Program Files\TeamViewer O43 - CFD: 18/03/2015 - [] D -- C:\Program Files\TeraCopy O43 - CFD: 06/06/2015 - [] D -- C:\Program Files\TopTv O43 - CFD: 06/04/2015 - [] D -- C:\Program Files\Ubisoft O43 - CFD: 26/07/2012 - [] D -- C:\Program Files\UltraISO O43 - CFD: 26/07/2012 - [0] HD -- C:\Program Files\Uninstall Information O43 - CFD: 26/07/2012 - [] D -- C:\Program Files\VideoLAN O43 - CFD: 20/08/2015 - [] D -- C:\Program Files\VstPlugins O43 - CFD: 26/09/2015 - [] D -- C:\Program Files\WebcamMax O43 - CFD: 29/03/2015 - [] D -- C:\Program Files\Windows Defender O43 - CFD: 03/08/2015 - [] D -- C:\Program Files\Windows Journal O43 - CFD: 26/07/2012 - [] D -- C:\Program Files\Windows Mail O43 - CFD: 22/11/2014 - [] D -- C:\Program Files\Windows Media Player O43 - CFD: 26/07/2012 - [] D -- C:\Program Files\Windows Multimedia Platform O43 - CFD: 26/07/2012 - [] D -- C:\Program Files\Windows NT O43 - CFD: 09/02/2015 - [] D -- C:\Program Files\Windows Photo Viewer O43 - CFD: 26/07/2012 - [] D -- C:\Program Files\Windows Portable Devices O43 - CFD: 22/11/2014 - [] SHD -- C:\Program Files\Windows Sidebar O43 - CFD: 06/11/2015 - [] HD -- C:\Program Files\WindowsApps O43 - CFD: 31/05/2015 - [] D -- C:\Program Files\WinPcap O43 - CFD: 28/02/2015 - [] D -- C:\Program Files\WinRAR O43 - CFD: 11/09/2015 - [] D -- C:\Program Files\WinZip O43 - CFD: 31/05/2015 - [] D -- C:\Program Files\Wireshark O43 - CFD: 31/01/2015 - [] D -- C:\Program Files\XnView O43 - CFD: 27/05/2015 - [] D -- C:\Program Files\XTab =>PUP.Optional.XTab O43 - CFD: 26/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2014-15 patch for FIFA 11 O43 - CFD: 11/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip O43 - CFD: 07/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AAA Logo O43 - CFD: 26/07/2012 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 09/02/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 10/11/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 20/03/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Archive Password Recovery O43 - CFD: 05/06/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced RAR Repair O43 - CFD: 07/07/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntiSnooper Pro - Privacy Protection O43 - CFD: 22/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aurous O43 - CFD: 09/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam O43 - CFD: 27/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BloodFrontier O43 - CFD: 22/07/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks O43 - CFD: 26/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Buziol Games O43 - CFD: 08/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\by.xatab O43 - CFD: 22/11/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center O43 - CFD: 14/07/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Chatango =>PUP.Optional.Chatango O43 - CFD: 23/02/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo O43 - CFD: 26/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverToolkit =>PUP.Optional.DriverToolkit O43 - CFD: 24/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET O43 - CFD: 14/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\fps boost gta eflc O43 - CFD: 14/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeArc O43 - CFD: 04/04/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 22/11/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garena O43 - CFD: 13/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 20/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line O43 - CFD: 22/11/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager O43 - CFD: 30/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java O43 - CFD: 27/02/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyScrambler O43 - CFD: 26/07/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 10/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office O43 - CFD: 30/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight O43 - CFD: 10/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005 O43 - CFD: 17/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft WebMatrix O43 - CFD: 11/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ O43 - CFD: 07/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Eraser O43 - CFD: 04/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PixelPlanet O43 - CFD: 11/04/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics O43 - CFD: 22/11/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RarmaRadio O43 - CFD: 07/03/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer O43 - CFD: 07/04/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SCS Software O43 - CFD: 10/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype O43 - CFD: 30/03/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarGame O43 - CFD: 11/09/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp O43 - CFD: 03/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam O43 - CFD: 10/02/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 26/07/2012 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 18/03/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy O43 - CFD: 06/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TopTv O43 - CFD: 22/11/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO O43 - CFD: 22/11/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN O43 - CFD: 26/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebcamMax O43 - CFD: 31/05/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap O43 - CFD: 28/02/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 11/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip O43 - CFD: 22/11/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView O43 - CFD: 14/02/2015 - [] D -- C:\ProgramData\Adobe O43 - CFD: 26/07/2012 - [] D -- C:\ProgramData\AMD O43 - CFD: 27/03/2015 - [] D -- C:\ProgramData\AMMYY O43 - CFD: 26/07/2012 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 26/07/2012 - [] D -- C:\ProgramData\ATI O43 - CFD: 11/11/2015 - [] D -- C:\ProgramData\Baidu O43 - CFD: 21/07/2015 - [] D -- C:\ProgramData\BlueStacks O43 - CFD: 21/07/2015 - [] D -- C:\ProgramData\BlueStacksSetup O43 - CFD: 26/07/2012 - [0] SHD -- C:\ProgramData\Bureau O43 - CFD: 29/03/2015 - [] HD -- C:\ProgramData\Common Files O43 - CFD: 11/02/2015 - [0] D -- C:\ProgramData\Datamngr =>PUP.Optional.Datamngr O43 - CFD: 26/07/2012 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 26/07/2012 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 05/05/2015 - [] D -- C:\ProgramData\EA Core O43 - CFD: 05/05/2015 - [] D -- C:\ProgramData\Electronic Arts O43 - CFD: 27/05/2015 - [] D -- C:\ProgramData\EpicScale =>PUP.Optional.EpicScale O43 - CFD: 24/10/2015 - [] D -- C:\ProgramData\ESET O43 - CFD: 30/09/2015 - [] D -- C:\ProgramData\F-Secure O43 - CFD: 16/10/2015 - [] D -- C:\ProgramData\GarenaMessenger O43 - CFD: 26/07/2012 - [0] D -- C:\ProgramData\IDM O43 - CFD: 15/03/2015 - [] D -- C:\ProgramData\IHProtectUpDate =>PUP.Optional.AgentODR O43 - CFD: 14/02/2015 - [] D -- C:\ProgramData\Installations O43 - CFD: 26/09/2015 - [] D -- C:\ProgramData\KONAMI O43 - CFD: 28/07/2015 - [] D -- C:\ProgramData\Malwarebytes O43 - CFD: 26/07/2012 - [0] SHD -- C:\ProgramData\Menu Démarrer O43 - CFD: 10/11/2015 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 10/11/2015 - [] D -- C:\ProgramData\Microsoft Help O43 - CFD: 19/02/2015 - [] D -- C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS O43 - CFD: 26/07/2012 - [0] SHD -- C:\ProgramData\Modèles O43 - CFD: 02/03/2015 - [] D -- C:\ProgramData\Mozilla O43 - CFD: 29/03/2015 - [] D -- C:\ProgramData\Norton O43 - CFD: 27/03/2015 - [] D -- C:\ProgramData\NortonInstaller O43 - CFD: 30/08/2015 - [] D -- C:\ProgramData\Oracle O43 - CFD: 07/10/2015 - [] D -- C:\ProgramData\Package Cache O43 - CFD: 15/02/2015 - [] D -- C:\ProgramData\PC Suite O43 - CFD: 04/09/2015 - [] D -- C:\ProgramData\PixelPlanet O43 - CFD: 22/11/2014 - [] D -- C:\ProgramData\PRICache O43 - CFD: 27/02/2015 - [] D -- C:\ProgramData\QFX Software O43 - CFD: 09/11/2015 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft O43 - CFD: 14/02/2015 - [] D -- C:\ProgramData\Samsung O43 - CFD: 26/09/2015 - [] D -- C:\ProgramData\Skype O43 - CFD: 05/05/2015 - [] D -- C:\ProgramData\Solidshield O43 - CFD: 26/07/2012 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 01/09/2015 - [] D -- C:\ProgramData\Steam O43 - CFD: 01/03/2015 - [] D -- C:\ProgramData\Sun O43 - CFD: 04/04/2015 - [0] D -- C:\ProgramData\Synetic O43 - CFD: 30/03/2015 - [] D -- C:\ProgramData\SystemRequirementsLab O43 - CFD: 26/02/2015 - [] D -- C:\ProgramData\TechSmith O43 - CFD: 06/02/2015 - [0] AD -- C:\ProgramData\TEMP O43 - CFD: 26/07/2012 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 11/09/2015 - [] D -- C:\ProgramData\UniqueId O43 - CFD: 03/10/2015 - [] D -- C:\ProgramData\WebcamMax O43 - CFD: 29/03/2015 - [] D -- C:\ProgramData\WindowsMangerProtect =>PUP.Optional.WpManager O43 - CFD: 11/09/2015 - [] D -- C:\ProgramData\WinZip O43 - CFD: 04/04/2015 - [0] D -- C:\ProgramData\YTAHelper =>PUP.Optional.Goobzo O43 - CFD: 13/02/2015 - [] D -- C:\Program Files\Common Files\Adobe O43 - CFD: 13/03/2015 - [] D -- C:\Program Files\Common Files\Adobe AIR O43 - CFD: 20/03/2015 - [] D -- C:\Program Files\Common Files\Ahead O43 - CFD: 26/07/2012 - [] D -- C:\Program Files\Common Files\ATI Technologies O43 - CFD: 10/11/2015 - [] D -- C:\Program Files\Common Files\DESIGNER O43 - CFD: 26/07/2012 - [] D -- C:\Program Files\Common Files\EZB Systems O43 - CFD: 30/08/2015 - [] D -- C:\Program Files\Common Files\Java O43 - CFD: 10/11/2015 - [] D -- C:\Program Files\Common Files\microsoft shared O43 - CFD: 04/09/2015 - [] D -- C:\Program Files\Common Files\PixelPlanet O43 - CFD: 26/07/2012 - [] D -- C:\Program Files\Common Files\Services O43 - CFD: 10/09/2015 - [] D -- C:\Program Files\Common Files\Skype O43 - CFD: 03/10/2015 - [] D -- C:\Program Files\Common Files\Steam O43 - CFD: 22/11/2014 - [] D -- C:\Program Files\Common Files\System O43 - CFD: 04/09/2015 - [] D -- C:\Program Files\Common Files\XPressUpdate O43 - CFD: 14/02/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Adobe O43 - CFD: 26/07/2012 - [] D -- C:\Users\Abderrahim\AppData\Roaming\ATI O43 - CFD: 22/10/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\aurous O43 - CFD: 13/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\baidu O43 - CFD: 24/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\BaiduYunGuanjia O43 - CFD: 24/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\BaiduYunKernel O43 - CFD: 09/10/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\BANDISOFT O43 - CFD: 24/02/2015 - [0] D -- C:\Users\Abderrahim\AppData\Roaming\BitTorrent O43 - CFD: 19/06/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\BitTorrent Maelstrom O43 - CFD: 10/04/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Black Sea Studios O43 - CFD: 14/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\DMCache O43 - CFD: 13/10/2015 - [0] D -- C:\Users\Abderrahim\AppData\Roaming\EncryptStick O43 - CFD: 29/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\ESET O43 - CFD: 13/09/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\FileZilla O43 - CFD: 01/09/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\FlowStone O43 - CFD: 14/06/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\FreeArc O43 - CFD: 09/02/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\GameRanger O43 - CFD: 16/10/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\GarenaPlus O43 - CFD: 10/10/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Group FPEdit O43 - CFD: 23/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\gtk-2.0 O43 - CFD: 26/06/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\HaiYuInst O43 - CFD: 13/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\IDM O43 - CFD: 20/08/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Image-Line O43 - CFD: 26/06/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Leadertech O43 - CFD: 10/06/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\livestreamer O43 - CFD: 31/01/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Macromedia O43 - CFD: 15/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Maxiget O43 - CFD: 10/11/2015 - [] SD -- C:\Users\Abderrahim\AppData\Roaming\Microsoft O43 - CFD: 17/06/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Microsoft Corporation O43 - CFD: 02/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Mozilla O43 - CFD: 27/05/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\mystartsearch =>PUP.Optional.StartSearch O43 - CFD: 11/09/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Notepad++ O43 - CFD: 24/02/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy O43 - CFD: 14/02/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\PC Suite O43 - CFD: 04/09/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\PixelPlanet O43 - CFD: 27/02/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\QFX Software O43 - CFD: 06/02/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\RaimaRadioPro O43 - CFD: 14/02/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Samsung O43 - CFD: 26/09/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Skype O43 - CFD: 26/09/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\SmartSteamEmu O43 - CFD: 04/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Spiritsoft O43 - CFD: 30/08/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Sun O43 - CFD: 11/06/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\TeamViewer O43 - CFD: 04/04/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Tera Copy Pro 2.3 O43 - CFD: 18/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\TeraCopy O43 - CFD: 11/04/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\TRANSFORMERS - War for Cybertron O43 - CFD: 29/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\TuneUp Software O43 - CFD: 01/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\uTorrent O43 - CFD: 14/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\vlc O43 - CFD: 22/07/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\WebcamMax O43 - CFD: 26/07/2012 - [] D -- C:\Users\Abderrahim\AppData\Roaming\WinRAR O43 - CFD: 31/05/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Wireshark O43 - CFD: 13/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\XnView O43 - CFD: 07/09/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\YCanPDF O43 - CFD: 14/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\ZHP O43 - CFD: 01/04/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Activision O43 - CFD: 14/02/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Adobe O43 - CFD: 20/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Ahead O43 - CFD: 07/07/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\AntiSnooper O43 - CFD: 26/07/2012 - [0] SHD -- C:\Users\Abderrahim\AppData\Local\Application Data O43 - CFD: 26/02/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\assembly O43 - CFD: 26/07/2012 - [] D -- C:\Users\Abderrahim\AppData\Local\ATI O43 - CFD: 24/05/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Avg O43 - CFD: 03/10/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\CEF O43 - CFD: 26/07/2012 - [] D -- C:\Users\Abderrahim\AppData\Local\Comodo O43 - CFD: 13/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\CrashDumps O43 - CFD: 06/02/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\CrashRpt =>.Superfluous.CrashReports O43 - CFD: 11/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Diagnostics O43 - CFD: 04/09/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Downloaded Installations O43 - CFD: 26/06/2015 - [0] D -- C:\Users\Abderrahim\AppData\Local\DriverToolkit =>PUP.Optional.DriverToolkit O43 - CFD: 31/10/2015 - [0] D -- C:\Users\Abderrahim\AppData\Local\ElevatedDiagnostics O43 - CFD: 29/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\ESET O43 - CFD: 30/09/2015 - [0] D -- C:\Users\Abderrahim\AppData\Local\F-Secure O43 - CFD: 28/05/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Facebook O43 - CFD: 06/06/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Geckofx O43 - CFD: 06/02/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\globalUpdate =>PUP.Optional.GlobalUpdate O43 - CFD: 13/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Google O43 - CFD: 26/07/2012 - [0] SHD -- C:\Users\Abderrahim\AppData\Local\Historique O43 - CFD: 06/02/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Installer =>PUP.Optional.InstallPedia O43 - CFD: 01/07/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Intel O43 - CFD: 02/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Macromedia O43 - CFD: 19/06/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Maelstrom O43 - CFD: 15/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Maxiget O43 - CFD: 01/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Mega Limited O43 - CFD: 01/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\MEGAsync O43 - CFD: 17/06/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Microsoft O43 - CFD: 13/02/2015 - [0] D -- C:\Users\Abderrahim\AppData\Local\Microsoft Help O43 - CFD: 02/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Mozilla O43 - CFD: 26/05/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\next car game pre-alpha O43 - CFD: 14/10/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Packages O43 - CFD: 17/10/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\PES_2016_Selector_Tool O43 - CFD: 15/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Programs O43 - CFD: 20/06/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\PunkBuster O43 - CFD: 14/06/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Rockstar Games O43 - CFD: 14/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\SanDiskSecureAccessV2_win O43 - CFD: 07/04/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\SKIDROW O43 - CFD: 24/02/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Skype O43 - CFD: 03/10/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Steam O43 - CFD: 26/02/2015 - [0] D -- C:\Users\Abderrahim\AppData\Local\TechSmith O43 - CFD: 14/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\Temp O43 - CFD: 26/07/2012 - [0] SHD -- C:\Users\Abderrahim\AppData\Local\Temporary Internet Files O43 - CFD: 22/03/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\VirtualStore O43 - CFD: 11/09/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\WinZip O43 - CFD: 16/07/2015 - [] D -- C:\Users\Abderrahim\AppData\Local\YSearchUtil O43 - CFD: 26/07/2012 - [] RD -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 26/07/2012 - [] RD -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 20/03/2015 - [] RD -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 20/08/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2 O43 - CFD: 27/08/2015 - [0] D -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BloodFrontier O43 - CFD: 14/06/2015 - [0] D -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\fps boost gta eflc O43 - CFD: 14/06/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeArc O43 - CFD: 04/07/2015 - [0] D -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 22/08/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line O43 - CFD: 22/11/2014 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager O43 - CFD: 26/07/2012 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 01/11/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MEGAsync O43 - CFD: 11/09/2015 - [0] D -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++ O43 - CFD: 07/03/2015 - [0] D -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer O43 - CFD: 01/11/2015 - [] RD -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 22/11/2014 - [] RD -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 28/02/2015 - [] D -- C:\Users\Abderrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ---\\ ShellIconOverlayIdentifiers (SIOI) (11) - 0s O106 - SIOI: ###MegaShellExtPending [###MegaShellExtPending] - {056D528D-CE28-4194-9BA3-BA2E9197FF8C}. (...) -- C:\Users\Abderrahim\AppData\Local\MEGAsync\ShellExtX32.dll O106 - SIOI: ###MegaShellExtSynced [###MegaShellExtSynced] - {05B38830-F4E9-4329-978B-1DD28605D202}. (...) -- C:\Users\Abderrahim\AppData\Local\MEGAsync\ShellExtX32.dll O106 - SIOI: ###MegaShellExtSyncing [###MegaShellExtSyncing] - {0596C850-7BDD-4C9D-AFDF-873BE6890637}. (...) -- C:\Users\Abderrahim\AppData\Local\MEGAsync\ShellExtX32.dll O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll © O106 - SIOI: Groove Explorer Icon Overlay 1 (GFS Unread Stub) [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] - {99FD978C-D287-4F50-827F-B2C658EDA8E7}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll © O106 - SIOI: Groove Explorer Icon Overlay 2 (GFS Stub) [Groove Explorer Icon Overlay 2 (GFS Stub)] - {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll © O106 - SIOI: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] - {920E6DB1-9907-4370-B3A0-BAFC03D81399}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll © O106 - SIOI: Groove Explorer Icon Overlay 3 (GFS Folder) [Groove Explorer Icon Overlay 3 (GFS Folder)] - {16F3DD56-1AF5-4347-846D-7C10C4192619}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll © O106 - SIOI: Groove Explorer Icon Overlay 4 (GFS Unread Mark) [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] - {2916C86E-86A6-43FE-8112-43ABE6BF8DCC}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll © O106 - SIOI: IDM Shell Extension [IDM Shell Extension] - {CDC95B92-E27C-4745-A8C5-64A52A78855D}. (.Tonec Inc. - Internet Download Manager module.) -- C:\Program Files\Internet Download Manager\IDMShellExt.dll © O106 - SIOI: [Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81}. (.Microsoft Corporation - IU de cache côté client.) -- C:\Windows\System32\cscui.dll © ---\\ Liste des pilotes du système (71) - 5s O58 - SDL:2012/07/26 04:42:31 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\drivers\3ware.sys [85232] © O58 - SDL:2012/07/26 04:42:31 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [424176] © O58 - SDL:2012/07/26 04:42:31 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [298736] © O58 - SDL:2012/07/26 04:42:31 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\drivers\adpu320.sys [147696] © O58 - SDL:2012/12/19 21:49:12 A . (.Advanced Micro Devices, Inc. - AMD Audio Bus Lower Filter.) -- C:\Windows\System32\drivers\amdkmafd.sys [16120] © O58 - SDL:2012/07/26 04:42:31 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [67312] © O58 - SDL:2012/07/26 04:42:31 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [213744] © O58 - SDL:2012/07/26 04:42:31 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [22256] © O58 - SDL:2012/07/26 04:42:30 A . (.PMC-Sierra, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [91888] © O58 - SDL:2012/07/26 04:42:30 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [94448] © O58 - SDL:2012/12/21 07:46:28 A . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\Windows\System32\drivers\AtihdW83.sys [93432] © O58 - SDL:2012/12/19 21:47:46 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\drivers\atikmdag.sys [9647104] © O58 - SDL:2012/12/19 20:32:06 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\System32\drivers\atikmpag.sys [442368] © O58 - SDL:2015/07/30 11:41:36 A . (.ESET - Amon monitor.) -- C:\Windows\System32\drivers\eamonm.sys [205800] © O58 - SDL:2015/07/14 14:29:08 A . (.ESET - Devmon monitor.) -- C:\Windows\System32\drivers\edevmon.sys [199608] © O58 - SDL:2015/07/30 11:41:36 A . (.ESET - ESET Helper driver.) -- C:\Windows\System32\drivers\ehdrv.sys [145512] © O58 - SDL:2015/10/07 05:16:32 A . (.ESET - ESET OPP Keyboard Filter.) -- C:\Windows\System32\drivers\ekbdflt.sys [111040] © O58 - SDL:2015/07/30 11:41:36 A . (.ESET - ESET Personal Firewall driver.) -- C:\Windows\System32\drivers\epfw.sys [161992] © O58 - SDL:2015/07/30 11:41:36 A . (.ESET - Epfw NDIS LightWeight Filter.) -- C:\Windows\System32\drivers\EpfwLWF.sys [44608] © O58 - SDL:2015/07/30 11:41:36 A . (.ESET - ESET Personal Firewall driver.) -- C:\Windows\System32\drivers\epfwwfp.sys [56944] © O58 - SDL:2012/07/26 04:42:33 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [56048] © O58 - SDL:2012/07/26 04:42:33 A . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\drivers\iaStorV.sys [333552] © O58 - SDL:2012/11/22 01:43:14 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\drivers\idmwfp.sys [100216] © O58 - SDL:2012/06/02 15:32:31 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd32.sys [9036288] © O58 - SDL:2012/07/26 04:42:33 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [42224] © O58 - SDL:2005/09/01 11:03:04 N . (.Ahead Software AG - NERO IMAGEDRIVE SCSI miniport.) -- C:\Windows\System32\drivers\imagedrv.sys [5888] © O58 - SDL:2005/09/01 11:03:04 N . (.Ahead Software AG - Nero Image Server.) -- C:\Windows\System32\drivers\imagesrv.sys [127488] © O58 - SDL:2015/02/07 04:37:08 A . (.QFX Software Corporation - KeyScrambler Keyboard Encryption Driver.) -- C:\Windows\System32\drivers\keyscrambler.sys [210512] © O58 - SDL:2012/07/26 04:42:33 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [93424] © O58 - SDL:2012/07/26 04:42:33 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [78576] © O58 - SDL:2012/07/26 04:42:33 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [100592] © O58 - SDL:2012/07/26 04:42:33 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sss.sys [68848] © O58 - SDL:2012/07/26 04:42:33 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [45296] © O58 - SDL:2012/07/26 04:42:15 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [283888] © O58 - SDL:2012/07/26 04:42:15 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\drivers\mvumis.sys [59120] © O58 - SDL:2012/07/26 04:42:15 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [45808] © O58 - SDL:2013/03/01 02:48:42 A . (.Riverbed Technology, Inc. - npf.sys (NT5/6 x86) Kernel Driver.) -- C:\Windows\System32\drivers\npf.sys [36600] © O58 - SDL:2012/07/26 04:42:15 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [120048] © O58 - SDL:2012/07/26 04:42:15 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [141552] © O58 - SDL:2008/08/26 09:26:12 A . (.Nokia - PCCS Mode Change Filter Driver.) -- C:\Windows\System32\drivers\pccsmcfd.sys [18816] © O58 - SDL:2015/07/27 20:59:44 A . (...) -- C:\Windows\System32\drivers\PnkBstrK.sys [137688] O58 - SDL:2012/07/25 23:49:40 A . (.Realtek - Pilote Realtek 8101E/8168/8169 NDIS 6.30 32.) -- C:\Windows\System32\drivers\Rt630x86.sys [495104] © O58 - SDL:2012/07/26 07:52:42 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [20480] © O58 - SDL:2012/07/26 04:42:15 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [41200] © O58 - SDL:2012/07/26 04:42:16 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [79088] © O58 - SDL:2014/01/22 07:52:12 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudbus.sys [88576] © O58 - SDL:2014/01/22 07:52:12 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudmdm.sys [184192] © O58 - SDL:2007/10/25 17:26:10 A . (...) -- C:\Windows\System32\drivers\StarOpen.sys [5632] O58 - SDL:2012/07/26 04:42:15 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\Windows\System32\drivers\stexstor.sys [26352] © O58 - SDL:2015/07/09 11:16:46 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Host-Only Network Adapt.) -- C:\Windows\System32\drivers\VBoxNetAdp6.sys [98704] © O58 - SDL:2015/07/09 11:16:46 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Lightweight Filter Driv.) -- C:\Windows\System32\drivers\VBoxNetLwf.sys [119304] © O58 - SDL:2012/07/26 04:42:18 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [18160] © O58 - SDL:2012/07/26 04:42:19 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [155376] © O58 - SDL:2012/07/26 04:42:19 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\drivers\VSTXRAID.SYS [285424] © O58 - SDL:2012/04/15 22:32:14 A . (.Windows (R) Win 7 DDK provider - WebcamMax Capture.) -- C:\Windows\System32\drivers\wcmvcam.sys [1068216] © O58 - SDL:2012/07/25 23:52:51 A . (...) -- C:\Windows\System32\ANSI.SYS [9029] O58 - SDL:2012/07/25 23:52:51 A . (...) -- C:\Windows\System32\country.sys [27097] O58 - SDL:2010/06/14 09:32:54 A . (...) -- C:\Windows\System32\FsUsbExDisk.Sys [36608] O58 - SDL:2012/07/25 23:52:51 A . (...) -- C:\Windows\System32\HIMEM.SYS [4768] O58 - SDL:2012/07/25 23:52:52 A . (...) -- C:\Windows\System32\KEY01.SYS [42809] O58 - SDL:2012/07/25 23:52:52 A . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537] O58 - SDL:2012/07/25 23:52:54 A . (...) -- C:\Windows\System32\NTDOS.SYS [27866] O58 - SDL:2012/07/25 23:52:54 A . (...) -- C:\Windows\System32\NTDOS404.SYS [29146] O58 - SDL:2012/07/25 23:52:54 A . (...) -- C:\Windows\System32\NTDOS411.SYS [29370] O58 - SDL:2012/07/25 23:52:54 A . (...) -- C:\Windows\System32\NTDOS412.SYS [29274] O58 - SDL:2012/07/25 23:52:54 A . (...) -- C:\Windows\System32\NTDOS804.SYS [29146] O58 - SDL:2012/07/25 23:52:51 A . (...) -- C:\Windows\System32\NTIO.SYS [33968] O58 - SDL:2012/07/25 23:52:51 A . (...) -- C:\Windows\System32\NTIO404.SYS [34688] O58 - SDL:2012/07/25 23:52:51 A . (...) -- C:\Windows\System32\NTIO411.SYS [35776] O58 - SDL:2012/07/25 23:52:51 A . (...) -- C:\Windows\System32\NTIO412.SYS [35552] O58 - SDL:2012/07/25 23:52:51 A . (...) -- C:\Windows\System32\NTIO804.SYS [34688] ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (34) - 48s O61 - LFC: 2015/11/14 18:46:45 A . (..) -- C:\Users\Abderrahim\AppData\Roaming\Adobe\Acrobat\9.0\UserCache.bin [75713] O61 - LFC: 2015/11/11 14:47:41 A . (..) -- C:\Users\Abderrahim\AppData\Local\SKIDROW\CONFIG\42700\Stats.bin [4] O61 - LFC: 2015/11/14 11:37:35 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\LocalState\Cache\cacheWeatherMapsPanoResponseCache\_CacheMetadata.bin [652] O61 - LFC: 2015/11/14 11:37:35 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\LocalState\Cache\cacheWeatherInteractiveMapsClusterCache\_CacheMetadata.bin [590] O61 - LFC: 2015/11/14 11:37:35 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\LocalState\Cache\cacheVirtualEarthSearchByNameCache\_CacheMetadata.bin [688] O61 - LFC: 2015/11/14 11:37:35 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\LocalState\Cache\cacheTodayAdFeedCache\_CacheMetadata.bin [465] O61 - LFC: 2015/11/14 11:37:35 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\LocalState\Cache\cacheStaticMapsImageCache\_CacheMetadata.bin [3277] O61 - LFC: 2015/11/14 11:37:35 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\LocalState\Cache\cacheNextStepsCache\_CacheMetadata.bin [424] O61 - LFC: 2015/11/14 11:37:35 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\LocalState\Cache\cacheNearbyResortsByLatLongCache\_CacheMetadata.bin [516] O61 - LFC: 2015/11/14 11:37:54 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\LocalState\Cache\cacheMapsImageFrameCache\_CacheMetadata.bin [15733] O61 - LFC: 2015/11/14 11:37:35 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\LocalState\Cache\cacheHourlyForecastWeatherCache\_CacheMetadata.bin [796] O61 - LFC: 2015/11/14 11:37:35 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\LocalState\Cache\cacheHistoricalWeatherCache\_CacheMetadata.bin [820] O61 - LFC: 2015/11/14 11:37:35 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\LocalState\Cache\cacheGetStartedCache\_CacheMetadata.bin [428] O61 - LFC: 2015/11/14 11:37:35 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\LocalState\Cache\cacheCurrentConditionsAndForecastCache\_CacheMetadata.bin [988] O61 - LFC: 2015/11/14 11:37:35 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\LocalState\Cache\cacheConfigurationCache\_CacheMetadata.bin [499] O61 - LFC: 2015/11/14 11:36:46 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\AC\Microsoft\Windows\1036\StructuredQuerySchema.bin [361866] O61 - LFC: 2015/11/13 13:24:01 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingTravel_8wekyb3d8bbwe\LocalState\Cache\cacheNextStepsCache\_CacheMetadata.bin [460] O61 - LFC: 2015/11/13 13:24:01 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingTravel_8wekyb3d8bbwe\LocalState\Cache\cacheFeaturedArticles\_CacheMetadata.bin [519] O61 - LFC: 2015/11/13 13:24:01 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingTravel_8wekyb3d8bbwe\LocalState\Cache\cacheConfigurationCache\_CacheMetadata.bin [344] O61 - LFC: 2015/11/13 21:47:04 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\LocalState\Cache\cacheTickersMinuteData\_CacheMetadata.bin [495] O61 - LFC: 2015/11/13 21:47:04 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\LocalState\Cache\cachePlatformTopEdgyImageCache\_CacheMetadata.bin [5484] O61 - LFC: 2015/11/14 00:55:45 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\LocalState\Cache\cachePlatformImageCache\_CacheMetadata.bin [9672] O61 - LFC: 2015/11/13 21:47:04 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\LocalState\Cache\cacheMinuteCache\_CacheMetadata.bin [1175] O61 - LFC: 2015/11/13 21:47:04 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\LocalState\Cache\cacheInfoCache\_CacheMetadata.bin [935] O61 - LFC: 2015/11/13 21:47:04 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\LocalState\Cache\cacheFinanceHeroData\_CacheMetadata.bin [933] O61 - LFC: 2015/11/13 21:47:04 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\LocalState\Cache\cacheEditorial\_CacheMetadata.bin [1145] O61 - LFC: 2015/11/14 00:55:45 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\LocalState\Cache\cacheConfigurationCache\_CacheMetadata.bin [1410] O61 - LFC: 2015/11/13 21:47:04 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\LocalState\Cache\cacheBingNews\_CacheMetadata.bin [733] O61 - LFC: 2015/11/13 21:46:55 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\AC\Microsoft\Windows\1036\StructuredQuerySchema.bin [361866] O61 - LFC: 2015/11/14 18:19:21 A . (.Copyright © 2012.) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0_32\NativeImages\Microsoft.W64cef312#\fbda2967aeb39338276796117541522f\Microsoft.WindowsAzure.Messaging.Managed.ni.dll [753664] O61 - LFC: 2015/11/14 18:19:11 A . (..) -- C:\Users\Abderrahim\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0_32\NativeImages\Microsoft.PerfTrack\c0e9d4bd9847d13e71f319a0499688c7\Microsoft.PerfTrack.ni.dll [17408] O61 - LFC: 2015/11/09 19:50:39 A . (..) -- C:\Users\Abderrahim\AppData\Local\Microsoft\Windows\1036\StructuredQuerySchema.bin [361866] O61 - LFC: 2015/11/14 17:25:26 A . (..) -- C:\Users\Abderrahim\AppData\Local\Comodo\Dragon\User Data\ev_hashes_whitelist.bin [674082] O61 - LFC: 2015/11/07 21:20:43 A . (..) -- C:\Users\Abderrahim\AppData\Local\ATI\ACE\Manifest.Bin [27266] ---\\ Associations Shell Spawning (9) - 1s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe © O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe © O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe © O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe © O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S ---\\ Menu de démarrage Internet (16) - 0s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Comodo - Comodo Dragon.) -- C:\Program Files\Comodo\Dragon\dragon.exe © O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe © O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Internet Explorer\iexplore.ex http://www.mystartsearch.com/ =>PUP.Optional.StartSearch O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Comodo - Comodo Dragon.) -- C:\Program Files\Comodo\Dragon\dragon.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - 'Firefox' Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Comodo - Comodo Dragon.) -- C:\Program Files\Comodo\Dragon\dragon.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - 'Firefox' Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Comodo - Comodo Dragon.) -- C:\Program Files\Comodo\Dragon\dragon.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - 'Firefox' Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe © ---\\ Recherche d'infection sur les navigateurs (21) - 3s O69 - SBI: prefs.js [Abderrahim - nv2a014w.default] user_pref("browser.search.hiddenOneOffs", "mystartsearch"); =>PUP.Optional.StartSearch O69 - SBI: prefs.js [Abderrahim - nv2a014w.default] user_pref("browser.search.searchengine.alias", "mystartsearch"); =>PUP.Optional.SearchEngine O69 - SBI: prefs.js [Abderrahim - nv2a014w.default] user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine"); =>PUP.Optional.SearchEngine O69 - SBI: prefs.js [Abderrahim - nv2a014w.default] user_pref("browser.search.searchengine.iconURL", "http://www.mystartsearch.com/web/favicon.ico"); =>PUP.Optional.StartSearch O69 - SBI: prefs.js [Abderrahim - nv2a014w.default] user_pref("browser.search.searchengine.name", "mystartsearch"); =>PUP.Optional.SearchEngine O69 - SBI: prefs.js [Abderrahim - nv2a014w.default] user_pref("browser.search.searchengine.ptid", "epom2"); =>PUP.Optional.SearchEngine O69 - SBI: prefs.js [Abderrahim - nv2a014w.default] user_pref("browser.search.searchengine.uid", "SAMSUNGXHD253GJ_S24JJ90Z635749"); =>PUP.Optional.SearchEngine O69 - SBI: prefs.js [Abderrahim - nv2a014w.default] user_pref("browser.search.searchengine.url", "http://www.mystartsearch.com/web/?type=dspp&ts=1426415214&from=epom2&uid=SAMSUNGXHD2[...] =>PUP.Optional.StartSearch O69 - SBI: prefs.js [Abderrahim - nv2a014w.default] user_pref("browser.search.selectedEngine", "AVG Secure Search"); =>Toolbar.AVGSearch O69 - SBI: prefs.js [Abderrahim - nv2a014w.default] user_pref("extensions.quick_start.enable_search1", false); =>PUP.Optional.QuickStart O69 - SBI: prefs.js [Abderrahim - nv2a014w.default] user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false); =>PUP.Optional.QuickStart O69 - SBI: prefs.js [Abderrahim - nv2a014w.default] user_pref("extensions.xpiState", "{\"app-profile\":{\"istart_ffnt@gmail.com\":{\"d\":\"C:\\\\Users\\\\Abderrahim\\\\AppData\\\\Roa[...] =>PUP.Optional.IsStart O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.mystartsearch.com/ O69 - SBI: SearchScopes [HKCU] {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} [DefaultScope] - (e) - http://www.mystartsearch.com/ O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} - (mystartsearch) - http://www.mystartsearch.com/ O69 - SBI: SearchScopes [HKCU] {95B7759C-8C7F-4BF1-B163-73684A933233} - (AVG Secure Search) - http://mysearch.avg.com/ O69 - SBI: SearchScopes [HKCU] {9783BBF2-B069-4DD6-82E5-9B72E13B02E1} - (Yahoo Search) - http://es.search.yahoo.com/ O69 - SBI: SearchScopes [HKCU] {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} - (Ask.com) - http://www.mystartsearch.com/ O69 - SBI: SearchScopes [HKCU] {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} - (Norton Safe Search) - http://nortonsafe.search.ask.com/ O69 - SBI: SearchScopes [HKCU] {E4E012DC-1925-48E9-8010-2D195574642A} - () - http://www.mystartsearch.com/ O69 - SBI: SearchScopes [HKCU] {E733165D-CBCF-4FDA-883E-ADEF965B476C} - (Google) - http://www.mystartsearch.com/ ---\\ Enumère les services démarrés par Svchost (35) - 0s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [168960] © O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [115200] © O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [115200] © O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [236544] © O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [1285632] © O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [683520] © O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [87552] © O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\Windows\System32\rasmans.dll [302080] © O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [81920] © O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [49152] © O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [392192] © O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [245760] © O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [2601472] © O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [630272] © O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [506368] © O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [741376] © O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [20992] © O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [52224] © O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [115200] © O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [89088] © O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [944640] © O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [166400] © O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\System32\mmcss.dll [60928] © O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [105472] © O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [170496] © O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [249344] © O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [59392] © O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\KMSVC.DLL [73216] © O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [33280] © O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\Windows\System32\wlidsvc.dll [1532928] © O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [154112] © O83 - Search Svchost Services: SystemEventsBroker (SystemEventsBroker) . (.Microsoft Corporation - Service Broker pour les événements système.) -- C:\Windows\System32\SystemEventsBrokerServer.dll [117760] © O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\Windows\System32\DeviceSetupManager.dll [161792] © O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\Windows\System32\NcaSvc.dll [138752] © O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [152064] © ---\\ Liste des exceptions du parefeu Windows (49) - 2s O87 - FAEL: "TCP Query User{61C45F16-3D3A-4983-A973-2C9CF7E6A6F4}E:\games\pc\nfs most wanted 2005\need for speed most wanted1\speed.exe" [In-None-P6-TRUE] .(...) -- E:\games\pc\nfs most wanted 2005\need for speed most wanted1\speed.exe O87 - FAEL: "UDP Query User{4FAD98D8-B510-4243-85D7-C017DB0E5102}E:\games\pc\nfs most wanted 2005\need for speed most wanted1\speed.exe" [In-None-P17-TRUE] .(...) -- E:\games\pc\nfs most wanted 2005\need for speed most wanted1\speed.exe O87 - FAEL: "{3DBC7BCB-D7F7-43A8-BF6A-799B8EC18C24}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe (.not file.) O87 - FAEL: "{2F86D3BD-D36F-4AA8-A861-1C412583ABD5}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe (.not file.) O87 - FAEL: "{FEC8B781-D8CC-4D90-BCD1-0B7A4AD0C18A}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe (.not file.) O87 - FAEL: "{5B18BB7F-5F5C-480D-9325-30997968F736}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe (.not file.) O87 - FAEL: "TCP Query User{F56CFFC5-1B8F-4AE3-BB3A-5348C9D6E4D3}C:\program files\youwave android\vb\vboxsdl.exe" [In-None-P6-TRUE] .(...) -- C:\program files\youwave android\vb\vboxsdl.exe (.not file.) O87 - FAEL: "UDP Query User{400DFF11-894B-4948-ABC0-291AC95F361C}C:\program files\youwave android\vb\vboxsdl.exe" [In-None-P17-TRUE] .(...) -- C:\program files\youwave android\vb\vboxsdl.exe (.not file.) O87 - FAEL: "TCP Query User{12A99063-5C9C-40A9-9541-CB7FBD82EBD5}C:\users\abderrahim\appdata\roaming\baidu\baiduyunguanjia\baiduyunguanjia.exe" [In-None-P6-TRUE] .(...) -- C:\users\abderrahim\appdata\roaming\baidu\baiduyunguanjia\baiduyunguanjia.exe (.not file.) O87 - FAEL: "UDP Query User{870CA153-DB5F-47F1-AF54-458696876E2E}C:\users\abderrahim\appdata\roaming\baidu\baiduyunguanjia\baiduyunguanjia.exe" [In-None-P17-TRUE] .(...) -- C:\users\abderrahim\appdata\roaming\baidu\baiduyunguanjia\baiduyunguanjia.exe (.not file.) O87 - FAEL: "{D3F1A4C6-F5F5-4E03-8EA5-229311AB9F18}" [In-None-P6-TRUE] .(...) -- C:\Program Files\AVG\AVG2015\avgmfapx.exe (.not file.) O87 - FAEL: "{680ADD91-A899-42F7-9121-6A7DA9BBE901}" [In-None-P17-TRUE] .(...) -- C:\Program Files\AVG\AVG2015\avgmfapx.exe (.not file.) O87 - FAEL: "{C533AB7C-F1E5-437C-B6AF-FE96E5625543}" [In-None-P6-TRUE] .(...) -- C:\Program Files\PES 13\myPES.exe (.not file.) O87 - FAEL: "{90CCBF70-A2DF-4DDA-8F9A-14F90A1801AA}" [In-None-P17-TRUE] .(...) -- C:\Program Files\PES 13\myPES.exe (.not file.) O87 - FAEL: "{9B913537-4772-44D1-BDA1-FEB89587A466}" [In-None-P6-TRUE] .(...) -- C:\Program Files\PES 13\pes2013.exe (.not file.) O87 - FAEL: "{D76C5AF6-1987-45B3-B6C6-7E15708C6D82}" [In-None-P17-TRUE] .(...) -- C:\Program Files\PES 13\pes2013.exe (.not file.) O87 - FAEL: "{EFDA8B0A-5D8E-41A2-B874-36832B4B7F84}" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Abderrahim\AppData\Roaming\uTorrent\uTorrent.exe O87 - FAEL: "{38BB04C4-213C-452B-B2DC-0E681DA25A3E}" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Abderrahim\AppData\Roaming\uTorrent\uTorrent.exe O87 - FAEL: "{810F1E3C-42B8-4BD6-9E5D-6305B32FEF3E}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe O87 - FAEL: "{A858D090-DE23-4CA5-A972-8E878E7DE357}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe O87 - FAEL: "{DF8E268F-12BA-41F2-A2ED-4CCDA3AEF13F}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Microsoft Office\Office15\UcMapi.exe (.not file.) O87 - FAEL: "{205D7C2A-C1D7-4D8D-8CA9-5B630856C857}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Microsoft Office\Office15\UcMapi.exe (.not file.) O87 - FAEL: "{D654E518-3228-472F-BEF1-D4DB416CB40C}" [In-None-P17-TRUE] .(.Copyright (C) 2013 - Windows host process (Rundll32).) -- C:\Program Files\Garena Plus\ggdllhost.exe O87 - FAEL: "{55F5ADF5-78AA-4CB5-92D5-07E2086B3030}" [In-None-P6-TRUE] .(...) -- C:\Program Files\AVG\AVG2015\avgnsx.exe (.not file.) O87 - FAEL: "{6C9BC2B0-AFE1-45E2-B2C0-C98E135BFB64}" [In-None-P17-TRUE] .(...) -- C:\Program Files\AVG\AVG2015\avgnsx.exe (.not file.) O87 - FAEL: "{21F4CC57-9908-457E-B26A-9B2E97F782E3}" [In-None-P6-TRUE] .(...) -- C:\Program Files\AVG\AVG2015\avgdiagex.exe (.not file.) O87 - FAEL: "{FD7C4110-449E-4767-9510-FBC4BDB5E458}" [In-None-P17-TRUE] .(...) -- C:\Program Files\AVG\AVG2015\avgdiagex.exe (.not file.) O87 - FAEL: "{C53954DF-0769-4290-95A8-4B4DC83E652B}" [In-None-P6-TRUE] .(...) -- C:\Program Files\AVG\AVG2015\avgemcx.exe (.not file.) O87 - FAEL: "{4656F31D-7B63-4A46-AB87-DA93F4DF2808}" [In-None-P17-TRUE] .(...) -- C:\Program Files\AVG\AVG2015\avgemcx.exe (.not file.) O87 - FAEL: "{1D73FECD-D731-4673-AD3C-5A06B82D2865}" [In-None-P6-TRUE] .(...) -- C:\Users\Abderrahim\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe (.not file.) O87 - FAEL: "{C44EFD73-E142-439A-BE0D-0C2871BDC1D3}" [In-None-P17-TRUE] .(...) -- C:\Users\Abderrahim\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe (.not file.) O87 - FAEL: "{184B09EF-32D7-4417-80A3-B4734AAA3ADB}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Droid4X\Droid4X.exe (.not file.) O87 - FAEL: "{30C49D71-B188-4648-A1C8-A956472A3DB7}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Oracle\VirtualBox\vboxheadless.exe (.not file.) O87 - FAEL: "{412CA2FD-2B96-4FE7-8332-D61238028FCF}" [In-None-P6-TRUE] .(...) -- C:\Program Files\PES 13\myPES.exe (.not file.) O87 - FAEL: "{18A97E3F-ABBC-433A-BBFB-57A1005AAAD8}" [In-None-P17-TRUE] .(...) -- C:\Program Files\PES 13\myPES.exe (.not file.) O87 - FAEL: "TCP Query User{C7149EA5-5FC1-4F82-8031-C5F1EED08020}C:\program files\call of duty.black ops.v update 6\blackops.exe" [In-None-P6-TRUE] .(...) -- C:\program files\call of duty.black ops.v update 6\blackops.exe O87 - FAEL: "UDP Query User{F9EF8077-FB0B-4F3F-9DD2-8117BA659C82}C:\program files\call of duty.black ops.v update 6\blackops.exe" [In-None-P17-TRUE] .(...) -- C:\program files\call of duty.black ops.v update 6\blackops.exe O87 - FAEL: "TCP Query User{E37075BF-2028-4E33-B2CB-FF36A094AB50}C:\program files\baloooo\pro evolution soccer 2016\pes2016.exe" [In-None-P6-TRUE] .(...) -- C:\program files\baloooo\pro evolution soccer 2016\pes2016.exe (.not file.) O87 - FAEL: "UDP Query User{6F13ED9C-97DA-4CE0-933B-AF3573CC50B4}C:\program files\baloooo\pro evolution soccer 2016\pes2016.exe" [In-None-P17-TRUE] .(...) -- C:\program files\baloooo\pro evolution soccer 2016\pes2016.exe (.not file.) O87 - FAEL: "TCP Query User{9ED0293F-C8B6-4E48-AB39-011399904111}C:\program files\r.g. element arts\tom clancy`s h.a.w.x. 2\tom clancy's h.a.w.x. 2\hawx2_dx11.exe" [In-None-P6-TRUE] .(...) -- C:\program files\r.g. element arts\tom clancy`s h.a.w.x. 2\tom clancy's h.a.w.x. 2\hawx2_dx11.exe O87 - FAEL: "UDP Query User{EEDE5C3A-C28A-4AD4-BC36-FF204384B278}C:\program files\r.g. element arts\tom clancy`s h.a.w.x. 2\tom clancy's h.a.w.x. 2\hawx2_dx11.exe" [In-None-P17-TRUE] .(...) -- C:\program files\r.g. element arts\tom clancy`s h.a.w.x. 2\tom clancy's h.a.w.x. 2\hawx2_dx11.exe O87 - FAEL: "TCP Query User{1D16C553-81DE-4B20-9EF8-ECA9A8599BA1}C:\program files\call of duty.black ops.v update 6\blackops.exe" [In-None-P6-TRUE] .(...) -- C:\program files\call of duty.black ops.v update 6\blackops.exe O87 - FAEL: "UDP Query User{386A3B69-BA7E-423D-92F6-C08C490BCE22}C:\program files\call of duty.black ops.v update 6\blackops.exe" [In-None-P17-TRUE] .(...) -- C:\program files\call of duty.black ops.v update 6\blackops.exe O87 - FAEL: "TCP Query User{EBEFDF7F-29B4-4B0C-A8E2-8A2662B53A67}C:\program files\r.g. element arts\tom clancy`s h.a.w.x. 2\tom clancy's h.a.w.x. 2\hawx2_dx11.exe" [In-None-P6-TRUE] .(...) -- C:\program files\r.g. element arts\tom clancy`s h.a.w.x. 2\tom clancy's h.a.w.x. 2\hawx2_dx11.exe O87 - FAEL: "UDP Query User{FA89256B-2167-4DC7-B89C-1966800004B4}C:\program files\r.g. element arts\tom clancy`s h.a.w.x. 2\tom clancy's h.a.w.x. 2\hawx2_dx11.exe" [In-None-P17-TRUE] .(...) -- C:\program files\r.g. element arts\tom clancy`s h.a.w.x. 2\tom clancy's h.a.w.x. 2\hawx2_dx11.exe O87 - FAEL: "{FAB2545E-3A57-4999-AEF3-CB2142763C50}" [In-None-P6-TRUE] .(...) -- C:\Program Files\baidu\Spark\Spark.exe (.not file.) O87 - FAEL: "{D7643EFA-0A20-4C02-A19F-A9FDACBEAFCC}" [In-None-P17-TRUE] .(...) -- C:\Program Files\baidu\Spark\Spark.exe (.not file.) O87 - FAEL: "{21ADA303-1A7A-4BCC-B891-74695B2DBF06}" [In-None-P6-TRUE] .(...) -- C:\Program Files\baidu\Spark\bdtray.exe (.not file.) O87 - FAEL: "{9C51E1B2-3E72-43BE-A35C-DC77A9879432}" [In-None-P17-TRUE] .(...) -- C:\Program Files\baidu\Spark\bdtray.exe (.not file.) ---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (15) - 12s SS - Demand [10/11/2015] [ 269000] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe © SR - Auto [19/12/2012] [ 219136] (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe © SR - Auto [14/10/2015] [ 1984696] COMODO Dragon Update Service (DragonUpdater) . (.Comodo.) - C:\Program Files\Comodo\Dragon\dragon_updater.exe © SR - Auto [09/10/2015] [ 1971968] ESET Service (ekrn) . (.ESET.) - C:\Program Files\ESET\ESET Smart Security\ekrn.exe © SS - Auto [29/03/2015] [ 107848] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe © SS - Demand [29/03/2015] [ 107848] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe © SS - Demand [30/10/2015] [ 147624] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe © SR - Auto [20/06/2015] [ 66872] PnkBstrA (PnkBstrA) . (...) - C:\Windows\System32\PnkBstrA.exe SR - Auto [27/07/2015] [ 202040] PnkBstrB (PnkBstrB) . (...) - C:\Windows\System32\PnkBstrB.exe SS - Demand [01/03/2013] [ 118520] Remote Packet Capture Protocol v.0 (experimental) (rpcapd) . (.Riverbed Technology, Inc..) - C:\Program Files\WinPcap\rpcapd.exe © SS - Demand [11/11/2008] [ 620544] ServiceLayer (ServiceLayer) . (.Nokia..) - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe © SS - Auto [09/07/2015] [ 327296] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe © SS - Demand [19/08/2015] [ 838336] Steam Client Service (Steam Client Service) . (.Valve Corporation.) - C:\Program Files\Common Files\Steam\SteamService.exe © SR - Auto [01/06/2015] [ 5495056] TeamViewer 10 (TeamViewer) . (.TeamViewer GmbH.) - C:\Program Files\TeamViewer\TeamViewer_Service.exe © ---\\ Scan Additionnel (64) - 0s C:\Windows\AutoKMS\AutoKMS.exe =>HackTool.AutoKMS C:\Windows\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-1-6.job =>PUP.Optional.CrossRider C:\Windows\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-1-7.job =>PUP.Optional.CrossRider C:\Windows\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-5.job =>PUP.Optional.CrossRider C:\Windows\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-5_user.job =>PUP.Optional.CrossRider C:\Windows\System32\Tasks\AutoKMS =>HackTool.AutoKMS C:\Windows\System32\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-1-6 =>PUP.Optional.CrossRider C:\Windows\System32\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-1-7 =>PUP.Optional.CrossRider C:\Windows\System32\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-5 =>PUP.Optional.CrossRider C:\Windows\System32\Tasks\ba603409-2b75-4b03-a95c-a8e001a8cd64-5_user =>PUP.Optional.CrossRider C:\Users\Abderrahim\AppData\Roaming\Mozilla\Firefox\Profiles\nv2a014w.default\extensions\istart_ffnt@gmail.com =>PUP.Optional.LightningNewTab HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D66BF89F-B0A2-48F5-A2E4-242EB645AB76}_is1 =>PUP.Optional.DriverToolkit HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EpicScaleApp =>PUP.Optional.EpicScale HKLM\SOFTWARE\AskPartnerNetwork =>Toolbar.AskBar HKLM\SOFTWARE\Conduit =>PUP.Optional.Conduit HKLM\SOFTWARE\GlobalUpdate =>PUP.Optional.GlobalUpdate HKLM\SOFTWARE\Goobzo =>PUP.Optional.Goobzo HKLM\SOFTWARE\IHProtect =>PUP.Optional.AgentODR HKLM\SOFTWARE\Iminent =>PUP.Optional.IMBooster HKLM\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions HKLM\SOFTWARE\iWebar =>PUP.Optional.CrossRider HKLM\SOFTWARE\iWebar-nv-ie =>PUP.Optional.CrossRider HKLM\SOFTWARE\mystartsearchSoftware =>PUP.Optional.StartSearch HKLM\SOFTWARE\SearchProtect =>PUP.Optional.SearchProtect HKLM\SOFTWARE\SupDp =>PUP.Optional.SupTab HKLM\SOFTWARE\supTab =>PUP.Optional.SupTab HKLM\SOFTWARE\WajIntEnhance =>PUP.Optional.Wajam HKCU\SOFTWARE\APN PIP =>PUP.Optional.Conduit HKCU\SOFTWARE\DriverToolkit =>PUP.Optional.DriverToolkit HKCU\SOFTWARE\EpicScale =>PUP.Optional.EpicScale HKCU\SOFTWARE\f3dfad1bbc2cef691bfbf9bbf8d49eb5 =>PUP.Optional.CrossRider HKCU\SOFTWARE\globalUpdate =>PUP.Optional.GlobalUpdate HKCU\SOFTWARE\Goobzo =>PUP.Optional.Goobzo HKCU\SOFTWARE\HomeTab =>PUP.Optional.CertifiedToolbar HKCU\SOFTWARE\iLivid =>PUP.Optional.Bandoo HKCU\SOFTWARE\ilividbandoomoviestoolbar =>PUP.Optional.Bandoo HKCU\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions HKCU\SOFTWARE\iWebar-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\Linkey =>PUP.Optional.LinkeySearch HKCU\SOFTWARE\SearchProtectWS =>PUP.Optional.SearchProtect HKCU\SOFTWARE\SensePlus-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\SimplyTech =>PUP.Optional.SimplyTech HKCU\SOFTWARE\TNT2 =>PUP.Optional.Freshy HKCU\SOFTWARE\WajIntEnhance =>PUP.Optional.Wajam HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider C:\Program Files\DriverToolkit =>PUP.Optional.DriverToolkit C:\Program Files\globalUpdate =>PUP.Optional.GlobalUpdate C:\Program Files\ilividbandoomoviestoolbar =>PUP.Optional.Bandoo C:\Program Files\iWebar =>PUP.Optional.CrossRider C:\Program Files\XTab =>PUP.Optional.XTab C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Chatango =>PUP.Optional.Chatango C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverToolkit =>PUP.Optional.DriverToolkit C:\ProgramData\Datamngr =>PUP.Optional.Datamngr C:\ProgramData\EpicScale =>PUP.Optional.EpicScale C:\ProgramData\IHProtectUpDate =>PUP.Optional.AgentODR C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS C:\ProgramData\WindowsMangerProtect =>PUP.Optional.WpManager C:\ProgramData\YTAHelper =>PUP.Optional.Goobzo C:\Users\Abderrahim\AppData\Roaming\mystartsearch =>PUP.Optional.StartSearch C:\Users\Abderrahim\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy C:\Users\Abderrahim\AppData\Local\CrashRpt =>.Superfluous.CrashReports C:\Users\Abderrahim\AppData\Local\DriverToolkit =>PUP.Optional.DriverToolkit C:\Users\Abderrahim\AppData\Local\globalUpdate =>PUP.Optional.GlobalUpdate C:\Users\Abderrahim\AppData\Local\Installer =>PUP.Optional.InstallPedia ---\\ Récapitulatif des éléments trouvées sur votre station (32) - 0s http://www.nicolascoolman.fr/trojan-autokms/ =>HackTool.AutoKMS http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider http://www.nicolascoolman.fr/blog =>PUP.Optional.DriverToolkit http://www.nicolascoolman.fr/blog =>PUP.Optional.LightningNewTab http://www.nicolascoolman.fr/pup-optional-startsearch/ =>PUP.Optional.StartSearch http://www.nicolascoolman.fr/blog =>PUP.Optional.EpicScale http://www.nicolascoolman.fr/blog =>Toolbar.AskBar http://www.nicolascoolman.fr/toolbar-conduit/ =>PUP.Optional.Conduit http://www.nicolascoolman.fr/pup-globalupdate/ =>PUP.Optional.GlobalUpdate http://www.nicolascoolman.fr/pup-goobzo/ =>PUP.Optional.Goobzo http://www.nicolascoolman.fr/blog =>PUP.Optional.AgentODR http://www.nicolascoolman.fr/adware-imbooster/ =>PUP.Optional.IMBooster http://www.nicolascoolman.fr/blog =>PUP.Optional.BrowserExtensions http://www.nicolascoolman.fr/pup-searchprotect/ =>PUP.Optional.SearchProtect http://www.nicolascoolman.fr/pup-suptab/ =>PUP.Optional.SupTab http://www.nicolascoolman.fr/pup-wajam/ =>PUP.Optional.Wajam http://www.nicolascoolman.fr/pup-certifiedtoolbar/ =>PUP.Optional.CertifiedToolbar http://www.nicolascoolman.fr/adware-bandoo/ =>PUP.Optional.Bandoo http://www.nicolascoolman.fr/pup-linkeysearch/ =>PUP.Optional.LinkeySearch http://www.nicolascoolman.fr/blog =>PUP.Optional.SimplyTech http://www.nicolascoolman.fr/blog =>PUP.Optional.Freshy http://www.nicolascoolman.fr/blog =>PUP.Optional.XTab http://www.nicolascoolman.fr/blog =>PUP.Optional.Chatango http://www.nicolascoolman.fr/pup-datamngr/ =>PUP.Optional.Datamngr http://www.nicolascoolman.fr/pup-wpmanager/ =>PUP.Optional.WpManager http://www.nicolascoolman.fr/adware-opencandy/ =>PUP.Optional.OpenCandy http://www.nicolascoolman.fr/blog =>.Superfluous.CrashReports http://www.nicolascoolman.fr/adware-installpedia/ =>PUP.Optional.InstallPedia http://www.nicolascoolman.fr/blog =>PUP.Optional.SearchEngine http://www.nicolascoolman.fr/blog =>Toolbar.AVGSearch http://www.nicolascoolman.fr/pup-quickstart/ =>PUP.Optional.QuickStart http://www.nicolascoolman.fr/pup-isstart/ =>PUP.Optional.IsStart ~ End of the scan, 25762 items in 124 seconds (1263)(0)