Script ZHPFix FirewallRaz EmptyPrefetch EmptyTemp Windows Defender (Deactivate) [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified G0 - GCSP: Preferences [User Data\Default][HomePage] http://b.max-vista.men G0 - GCSP: Preferences [User Data\Default][HomePage] http://max-vista.men G0 - GCSP: Preferences [User Data\Default][HomePage] http://n.ads3-adnow.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://st-n.ads3-adnow.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://sync.users-api.com M0 - MFSP: prefs.js [Utilisateur - s697p4pv.default] http://hp.myway.com/ R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 0 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 0 O4 - GS\Desktop [Administrateur]: Continuer Installation de Adobe Flash Player.lnk . (...) C:\Users\Utilisateur\AppData\Local\Temp\ICReinstall_adobe_flash_setup(1).exe /ppn:YyhwYgxaFRAiP211FM5W /mnl /RR O4 - GS\Desktop [Administrateur]: ورقة الحضور اليوم1.LNK . (.CEM - .) D:\اكواد\ورقة الحضور اليوم1.docm O4 - GS\Desktop [Utilisateur]: Continuer Installation de Adobe Flash Player.lnk . (...) C:\Users\Utilisateur\AppData\Local\Temp\ICReinstall_adobe_flash_setup(1).exe /ppn:YyhwYgxaFRAiP211FM5W /mnl /RR O4 - GS\Desktop [Utilisateur]: ورقة الحضور اليوم1.LNK . (.CEM - .) D:\اكواد\ورقة الحضور اليوم1.docm O4 - GS\CommonDesktop [Public]: SlimCleaner Plus.lnk . (...) C:\windows\Installer\{ABA29C63-B22D-45F8-BA20-7C8EF17B5E62}\Icon.exe O4 - GS\CommonDesktop [Public]: SlimDrivers.lnk . (...) C:\windows\Installer\{746AB259-6474-4111-8966-1C62F9A6E063}\Icon.exe /byUser O4 - GS\Startup [Public]: Rupsmon Daemon.lnk . (.Mega System Technologies, Inc. - Monw32.) C:\Program Files (x86)\MegaTec\UPSilon 2000\Monw32.exe C:\Users\Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\s697p4pv.default\MyWebFace_5a O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} O42 - Logiciel: hpg3110 - (..) [HKLM][64Bits] -- {77021F03-7C6A-4278-9AE4-3AFED74C74F6} O42 - Logiciel: LaserJet 1018 - (..) [HKLM][64Bits] -- HP-LaserJet 1018 O42 - Logiciel: UPSilon 2000 - (.MegaTec.) [HKLM][64Bits] -- {E592E668-89A9-4098-B70C-0C2D59FB15CA} O43 - CFD: 25/06/2015 - [] D -- C:\Program Files (x86)\MegaTec O43 - CFD: 15/12/2016 - [] HD -- C:\Program Files (x86)\Zenographics O43 - CFD: 20/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\e-Saver O43 - CFD: 10/05/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimCleaner Plus O43 - CFD: 10/05/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers O43 - CFD: 25/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UPSilon 2000 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} HKCU\SOFTWARE\csastats HKCU\SOFTWARE\ICSW1.23 HKCU\SOFTWARE\ProductSetup HKLM\SOFTWARE\Wow6432Node\MegaTec HKLM\SOFTWARE\Wow6432Node\MVL HKLM\SOFTWARE\Wow6432Node\Zenographics HKCU\SOFTWARE\CoinisRevShare O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("browser.startup.homepage", "http://hp.myway.com/mywebface/ttab02/index.html?coId=80880ef023a2481a8d20c8304dd8c9be&subId[...] O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.bootstrappedAddons", "{\"_5aMembers_@download.mywebface.com\":{\"version\":\"7.700.10.59511\",\"type\":\"ext[...] O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.BUTTON_STRUCTURE", "[{\"b\":223756333,\"c\":\"mindspark.magnify\",\"p\":\"L.0\[...] O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.browser.startup.homepage.savedPrev", "true"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.browser.startup.homepage.tb", "http://hp.myway.com/mywebface/ttab02/index.html[...] O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.browser.startup.page.savedPrev", 1); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.browser.startup.page.tb", 1); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.browser.version.last", "53.0"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.coId", "80880ef023a2481a8d20c8304dd8c9be"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.firstKnownVersion", "7.700.10.59511"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.homepage", "http://hp.myway.com/mywebface/ttab02/index.html?coId=80880ef023a24[...] O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.hp.enabled", true); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.hp.guardType", "HPR"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.initialized", true); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.installType", "XPI"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.installation.dlpCountryCode", "DZ"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.installation.installDate", "2017040409"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.installation.partnerId", "^GR^xdm025^TTAB02^dz"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.installation.partnerSubId", "CIeJqLS2itMCFcIp0wodHi0GFw"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.installation.pixelUrl", "http://download.mywebface.com/install_pixels.jhtml?pa[...] O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.installation.success", true); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.installation.toolbarDataSource", "[\"LOCAL_STORAGE\"]"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.installation.toolbarId", "D20BFD4D-E3D3-420B-A95B-70D45FBC3BB4"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.lastActivePing", "1494404945170"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.lastKnownVersion", "7.700.10.59511"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.lssState", "{\"previousLocales\":[\"fr\",\"fr-FR\",\"en-US\",\"en\"],\"support[...] O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.options.defaultSearch", false); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.options.homePageEnabled", true); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.options.keywordEnabled", false); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.options.tabEnabled", true); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.partnerPixelFired", true); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.productDeliveryOption.language", "fr"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.productDeliveryOption.newTabURL", "http://hp.myway.com/mywebface/ttab02/index.[...] O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.productDeliveryOption.type", "ToolTab"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.successUrl", "http://download.mywebface.com/installComplete.jhtml"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.toolbar.versionChanged", false); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.toolbarCollapsed", false); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.uninstallSurveyUrl", "http://mywebface.dl.myway.com/uninstall.jhtml?surveyUrl=[...] O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark._5aMembers_.uninstallTasks", "{\"prefBranchesToDelete\":[\"extensions.toolbar.mindspark._5[...] O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark.hp.enabled", true); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "mywebface@mindspark.com"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.toolbar.mindspark.lastInstalled", "mywebface@mindspark.com"); O69 - SBI: prefs.js [Utilisateur - s697p4pv.default] user_pref("extensions.xpiState", "{\"app-profile\":{\"_5aMembers_@download.mywebface.com\":{\"d\":\"C:\\\\Users\\\\Utilisateur\\\\[...] O87 - FAEL: "{30B490CC-8BEB-4776-B8AB-3A22C73FAD24}" [In-None-P6-TRUE] .(.Mega System Technologies, Inc. - UPSilon.) -- C:\Program Files (x86)\MegaTec\UPSilon 2000\UPSilon.exe O87 - FAEL: "{7BC8DE2C-E5AA-4566-BD02-35ADAF0A5375}" [In-None-P17-TRUE] .(.Mega System Technologies, Inc. - UPSilon.) -- C:\Program Files (x86)\MegaTec\UPSilon 2000\UPSilon.exe O87 - FAEL: "{A4368AB7-00E0-47A1-9FFC-4A5DF0326F95}" [In-None-P6-TRUE] .(.Mega System Technologies, Inc. - Rupsmon Application.) -- C:\Program Files (x86)\MegaTec\UPSilon 2000\RupsMon.exe O87 - FAEL: "{AF4E63F2-6AAB-45AD-8D8B-FCF65A439051}" [In-None-P17-TRUE] .(.Mega System Technologies, Inc. - Rupsmon Application.) -- C:\Program Files (x86)\MegaTec\UPSilon 2000\RupsMon.exe