Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 17.03.2019 Exécuté par claude (administrateur) sur CLAUDE-PC (08-04-2019 14:56:21) Exécuté depuis C:\Users\claude\Downloads Profils chargés: claude (Profils disponibles: claude & DefaultAppPool) Platform: Windows 10 Pro Version 1809 17763.379 (X64) Langue: Français (France) Navigateur par défaut: Chrome Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (AMD) [Fichier non signé] C:\Windows\System32\atiesrxx.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe (Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Huawei Technologies Co., Ltd. -> ) [Fichier non signé] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\snmp.exe (PacketVideo Corporation -> PacketVideo) C:\Program Files (x86)\Serveur Media\twonkymediaserverwatchdog.exe (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\MSI\MSIRegister\MSIRegisterService.exe (AVerMedia TECHNOLOGIES, INC. -> AVerMedia TECHNOLOGIES, Inc.) C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mqsvc.exe (TeamViewer -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (PacketVideo Corporation -> ) C:\Program Files (x86)\Serveur Media\twonkymediaserver.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (AMD) [Fichier non signé] C:\Windows\System32\atieclxx.exe (PacketVideo Corporation -> PacketVideo) C:\Program Files (x86)\Serveur Media\twonkymediaserverconfig.exe (VIA Technologies, Inc.) [Fichier non signé] C:\Program Files (x86)\VIA XHCI UASP Utility\usb3Monitor.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Nero AG -> Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE () [Fichier non signé] C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1812.10048.0_x64__8wekyb3d8bbwe\Calculator.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Optimizer Host\Avira.OptimizerHost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WWAHost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleCrashHandler.exe (Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleCrashHandler64.exe () [Fichier non signé] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.42.60.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe (Microsoft Corporation) [Fichier non signé] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.42.60.0_x64__kzf8qxf38zg5c\SkypeApp.exe () [Fichier non signé] C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19031.57.0_x64__8wekyb3d8bbwe\YourPhone.exe (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IAMTFDE.EXE () [Fichier non signé] C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19031.11411.0_x64__8wekyb3d8bbwe\Video.UI.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\ProtectedService.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\update.exe () [Fichier non signé] C:\Users\claude\Desktop\Dox.exe () [Fichier non signé] C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.19021.18010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe () [Fichier non signé] C:\Program Files (x86)\FormatFactory\FFModules\Encoder\ffmpeg.exe () [Fichier non signé] C:\Program Files (x86)\FormatFactory\FFModules\Encoder\ffmpeg.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\ipmgui.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech -> Logitech, Inc.) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [98024 2019-03-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [VIAxHCUtl] => C:\Program Files (x86)\VIA XHCI UASP Utility\usb3Monitor.exe**:**R:*`Š<*`Š<*\€<*è‘<***:*¬‡s*****C:\P HKLM-x32\...\Run: [Avira System Speedup User Starter] => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [323632 2018-12-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) HKU\S-1-5-21-3076573596-196789805-4040178887-1000\...\Run: [19418] => C:\Users\claude\19418\svhost.exe HKU\S-1-5-21-3076573596-196789805-4040178887-1000\...\Policies\system: [DisableTaskMgr] 1 HKLM\...\Drivers32: [VIDC.LAGS] => C:\WINDOWS\system32\lagarith.dll [148992 2011-12-07] ( ) [Fichier non signé] HKLM\...\Drivers32: [VIDC.X264] => C:\WINDOWS\system32\x264vfw64.dll [3571200 2015-02-28] (x264vfw project) [Fichier non signé] HKLM\...\Drivers32: [vidc.XVID] => C:\WINDOWS\system32\xvidvfw.dll [255488 2011-05-30] () [Fichier non signé] HKLM\...\Drivers32: [VIDC.FFDS] => C:\WINDOWS\system32\ff_vfw.dll [126976 2015-10-24] () [Fichier non signé] HKLM\...\Drivers32: [msacm.ac3acm] => C:\WINDOWS\system32\ac3acm.acm [180736 2012-07-21] (fccHandler) [Fichier non signé] HKLM\...\Drivers32: [msacm.lameacm] => C:\WINDOWS\system32\LameACM.acm [389120 2006-09-24] (hxxp://www.mp3dev.org/) [Fichier non signé] HKLM\...\Drivers32: [VIDC.LAGS] => C:\WINDOWS\SysWOW64\lagarith.dll [216064 2011-12-07] ( ) [Fichier non signé] HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\SysWOW64\x264vfw.dll [3591680 2015-02-28] (x264vfw project) [Fichier non signé] HKLM\...\Drivers32: [VIDC.XVID] => C:\WINDOWS\SysWOW64\xvidvfw.dll [240640 2011-05-30] () [Fichier non signé] HKLM\...\Drivers32: [VIDC.FFDS] => C:\WINDOWS\SysWOW64\ff_vfw.dll [112128 2015-10-24] () [Fichier non signé] HKLM\...\Drivers32: [msacm.ac3acm] => C:\WINDOWS\SysWOW64\ac3acm.acm [122880 2012-07-21] (fccHandler) [Fichier non signé] HKLM\...\Drivers32-x32: [vidc.yv12] => yv12vfw.dll HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\73.0.3683.86\Installer\chrmstp.exe [2019-03-26] (Google LLC -> Google Inc.) HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] -> Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Agent Serveur Média.lnk [2016-10-06] ShortcutTarget: Agent Serveur Média.lnk -> C:\Program Files (x86)\Serveur Media\twonkymediaserverconfig.exe (PacketVideo Corporation -> PacketVideo) ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{0b1fd43e-8555-4f91-b603-3d4e8b5fd484}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{33aba2a2-bb2f-48c5-a2df-5bae7324c1ba}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{be340dfd-4e78-483f-8583-a2b77c1d5850}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://google.com SearchScopes: HKLM -> {6586d803-df30-46d3-a89a-4136c8571d45} URL = hxxp://www.palikan.com/results.php?f=4&q={searchTerms}&a=plk_ir_15_44&cd=2XzuyEtN2Y1L1QzutDtDtByDzy0CyBtC0EtCyDzy0ByCyEtDtN0D0Tzu0StCtAzyyEtN1L2XzutAtFtCtBtFyDtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyEyByDtCyDtA0E0FtGyBzz0BtCtGzyyCtD0BtGtDtBtAzytGzzyBzz0FyBtCzzyD0EyD0C0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0F0EtDzztCyDtCtGzyyDtAyDtGyEyDtB0BtG0B0E0DyBtGyDzz0F0Fzz0E0BtDyD0EyDyC2QtN0A0LzutB&cr=1806128940&ir= SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3076573596-196789805-4040178887-1000 -> {6586d803-df30-46d3-a89a-4136c8571d45} URL = hxxp://www.palikan.com/results.php?f=4&q={searchTerms}&a=plk_ir_15_44&cd=2XzuyEtN2Y1L1QzutDtDtByDzy0CyBtC0EtCyDzy0ByCyEtDtN0D0Tzu0StCtAzyzztN1L2XzutAtFtCyEtFtDtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2SyEtCtByDzytCzyyDtGtCtC0D0EtG0BtDyC0AtGyBzz0C0FtGyE0FtAyDyC0Ezyzz0AyCtCtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0F0EtDzztCyDtCtGzyyDtAyDtGyEyDtB0BtG0B0E0DyBtGyDzz0F0Fzz0E0BtDyD0EyDyC2QtN0A0LzutBtN1B2Z1V1T1S1NzutCtCyEzz&cr=2030427605&ir= BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: AC-Pro -> {0FB6A909-6086-458F-BD92-1F8EE10042A0} -> C:\Program Files (x86)\AutocompletePro\AutocompletePro.dll [2010-02-17] (SimplyGen Ltd -> SimplyGen) [Fichier non signé] BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\ssv.dll [2018-04-17] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\Program Files (x86)\Avira\Browser Safety\Avira Browser Safety.dll [2015-03-11] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-04-17] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Pas de nom -> {E6E66045-E911-4C01-961D-42487CE12089} -> C:\Users\claude\AppData\LocalLow\Browser-Security\safe_url.dll [2016-06-22] () [Fichier non signé] Handler-x32: abs - {E00957BD-D0E1-4eb9-A025-7743FDC8B27B} - C:\Program Files (x86)\Avira\Browser Safety\Avira Browser Safety.dll [2015-03-11] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) FireFox: ======== FF ProfilePath: C:\Users\claude\AppData\Roaming\Mozilla\Firefox\Profiles\IkxHjfN9.default [2017-06-29] FF user.js: detected! => C:\Users\claude\AppData\Roaming\Mozilla\Firefox\Profiles\IkxHjfN9.default\user.js [2017-06-29] FF Extension: (Avira Browser Safety) - C:\Users\claude\AppData\Roaming\Mozilla\Firefox\Profiles\IkxHjfN9.default\Extensions\abs@avira.com [2017-10-02] [Legacy] FF Extension: (Avira Browser Safety) - C:\Users\claude\AppData\Roaming\Mozilla\Firefox\Profiles\IkxHjfN9.default\Extensions\abs@avira.com.xpi [2016-02-14] [Legacy] FF Extension: (Avira Password Manager) - C:\Users\claude\AppData\Roaming\Mozilla\Firefox\Profiles\IkxHjfN9.default\Extensions\passwordmanager@avira.com [2019-02-24] FF HKLM-x32\...\Firefox\Extensions: [support@predictad.com] - C:\Program Files (x86)\AutocompletePro\support@predictad.com FF Extension: (AutocompletePro - Your handy search suggestions tool) - C:\Program Files (x86)\AutocompletePro\support@predictad.com [2016-11-19] [Legacy] [non signé] FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-08-10] (VideoLAN -> VideoLAN) FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1234204.dll [2018-06-06] (Adobe Systems, Inc.) [Fichier non signé] FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [Pas de fichier] FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [Pas de fichier] FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [Pas de fichier] FF Plugin-x32: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-04-17] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-04-17] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2013-08-20] (Nero AG -> Nero AG) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-10-27] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [Fichier non signé] FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-10-27] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [Fichier non signé] FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.7\npGoogleUpdate3.dll [2019-03-28] (Google Inc -> Google LLC) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.7\npGoogleUpdate3.dll [2019-03-28] (Google Inc -> Google LLC) FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [Pas de fichier] FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [Pas de fichier] FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-02-01] (Adobe Systems, Incorporated -> Adobe Systems Inc.) Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxp://www.google.fr/ CHR StartupUrls: Default -> "hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK217RbjR1YFa37oBy_U-nTnTbDY5BLiS4cCE-YWhTJw8FV1rhTWju24bDQv8KQmRI-h_sGSj4TCAdhoopaeCVmwIgKUuF8Ao3uxdPYILJIRubTLC51XzfWsutgAcIpU4wRnaCVl5MxcW0wPaim1Opd5Dm3VNjqDF6lXGN7KgqTX9J81tQ2DvJGnJXOgXXjJW46x6voEjHQ,,","hxxp://www.istartsurf.com/?type=hp&ts=1426980106&from=smt&uid=STM3250318AS_5VM3CYV6XXXX5VM3CYV6","hxxp://www.mystartsearch.com/?type=hp&ts=1426980150&from=smt&uid=STM3250318AS_5VM3CYV6XXXX5VM3CYV6","hxxp://www.mystartsearch.com/?type=hp&ts=1427214594&from=cvs5&uid=STM3250318AS_5VM3CYV6XXXX5VM3CYV6","hxxp://www.palikan.com/?f=7&a=plk_ir_15_43&cd=2XzuyEtN2Y1L1QzutDtDtByDzy0CyBtC0EtCyDzy0ByCyEtDtN0D0Tzu0StCtAzytCtN1L2XzutAtFtCtBtFyDtFtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyC0A0BtAyC0A0CyCtGyB0DyDtAtGyE0BtB0AtGtAtBtCtCtG0BtCtByCyD0A0EzzzytC0CtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0F0EtDzztCyDtCtGzyyDtAyDtGyEyDtB0BtG0B0E0DyBtGyDzz0F0Fzz0E0BtDyD0EyDyC2QtN0A0LzutB&cr=1209980643&ir=","hxxp://www.palikan.com/?f=7&a=plk_ir_15_43&cd=2XzuyEtN2Y1L1QzutDtDtByDzy0CyBtC0EtCyDzy0ByCyEtDtN0D0Tzu0StCtAzytAtN1L2XzutAtFtCtBtFyDtFtDtN1L1Czu1RtN1L1G1B1V1N2Y1L1Qzu2StB0E0Azy0AyBzytDtGtDtByEzytGtD0AyByEtGyEyBtC0BtGyDzy0FtDyDyDyBtCtDyD0ByE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0F0EtDzztCyDtCtGzyyDtAyDtGyEyDtB0BtG0B0E0DyBtGyDzz0F0Fzz0E0BtDyD0EyDyC2QtN0A0LzutB&cr=449237809&ir=","hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK217RbjR1YFa37oBy_U-nTnTbDY5BLiS4cCE-YWhTJw8FV1rhTWju24bDQv8KQmRI-h_sGSj4TCAdhoopaeCVmwIgKUuF8Ao3uxdPYILJIRubTLC51XzfWsutgAcIpU4wRnaCVl5MxcW0wPaim1Opd5Dm3VNjqDF6lXGN7KgqTX9J81tQ2DvJGnJXOgXXjJW46x6voEjHQ,","hxxp://www.palikan.com/?f=7&a=plk_ir_15_43&cd=2XzuyEtN2Y1L1QzutDtDtByDzy0CyBtC0EtCyDzy0ByCyEtDtN0D0Tzu0StCtAzytAtN1L2XzutAtFtCtBtFyDtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2StAyDtD0B0AyEtCyCtGtByB0FzztGzy0D0E0AtGtCyCtB0DtGyEtC0ByCtDyCyBzzyCtBzytD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0F0EtDzztCyDtCtGzyyDtAyDtGyEyDtB0BtG0B0E0DyBtGyDzz0F0Fzz0E0BtDyD0EyDyC2QtN0A0LzutB&cr=679453642&ir=","hxxp://www.palikan.com/?f=7&a=plk_ir_15_44&cd=2XzuyEtN2Y1L1QzutDtDtByDzy0CyBtC0EtCyDzy0ByCyEtDtN0D0Tzu0StCtAzyyEtN1L2XzutAtFtCtBtFyDtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyEyByDtCyDtA0E0FtGyBzz0BtCtGzyyCtD0BtGtDtBtAzytGzzyBzz0FyBtCzzyD0EyD0C0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0F0EtDzztCyDtCtGzyyDtAyDtGyEyDtB0BtG0B0E0DyBtGyDzz0F0Fzz0E0BtDyD0EyDyC2QtN0A0LzutB&cr=1806128940&ir=","hxxp://www.palikan.com/?f=7&a=plk_ir_15_44&cd=2XzuyEtN2Y1L1QzutDtDtByDzy0CyBtC0EtCyDzy0ByCyEtDtN0D0Tzu0StCtAzyzztN1L2XzutAtFtCyEtFtDtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2SyEtCtByDzytCzyyDtGtCtC0D0EtG0BtDyC0AtGyBzz0C0FtGyE0FtAyDyC0Ezyzz0AyCtCtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0F0EtDzztCyDtCtGzyyDtAyDtGyEyDtB0BtG0B0E0DyBtGyDzz0F0Fzz0E0BtDyD0EyDyC2QtN0A0LzutBtN1B2Z1V1T1S1NzutCtCyEzz&cr=2030427605&ir=" CHR DefaultSearchURL: Default -> hxxps://search.avira.com/#web/result?source=omnibar&q={searchTerms} CHR DefaultSearchKeyword: Default -> Avira CHR DefaultSuggestURL: Default -> hxxps://search.avira.com/suggestions?q={searchTerms}&li=ff&hl=en CHR Profile: C:\Users\claude\AppData\Local\Google\Chrome\User Data\Default [2019-04-08] CHR Extension: (Slides) - C:\Users\claude\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12] CHR Extension: (Docs) - C:\Users\claude\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12] CHR Extension: (Google Drive) - C:\Users\claude\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-17] CHR Extension: (YouTube) - C:\Users\claude\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24] CHR Extension: (Avira Password Manager) - C:\Users\claude\AppData\Local\Google\Chrome\User Data\Default\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2019-03-26] CHR Extension: (Recherche Google) - C:\Users\claude\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (Sheets) - C:\Users\claude\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12] CHR Extension: (Protection Web Avira) - C:\Users\claude\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2019-03-18] CHR Extension: (Google Docs hors connexion) - C:\Users\claude\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-10] CHR Extension: (AdBlock) - C:\Users\claude\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2019-03-22] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\claude\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04] CHR Extension: (Gmail) - C:\Users\claude\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28] CHR Extension: (Chrome Media Router) - C:\Users\claude\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-03-26] CHR Profile: C:\Users\claude\AppData\Local\Google\Chrome\User Data\System Profile [2018-06-28] CHR HKLM\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [ljibkigjccbegnbeojkoafejpoiachej] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-3076573596-196789805-4040178887-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-3076573596-196789805-4040178887-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ljibkigjccbegnbeojkoafejpoiachej] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ljibkigjccbegnbeojkoafejpoiachej] - hxxps://clients2.google.com/service/update2/crx Opera: ======= OPR Extension: (Protection Web Avira) - C:\Users\claude\AppData\Roaming\Opera Software\Opera Stable\Extensions\dalelnnofafalcmkmnhdbigbjjkloabo [2019-02-24] OPR Extension: (Avira Password Manager) - C:\Users\claude\AppData\Roaming\Opera Software\Opera Stable\Extensions\ngohaaocccbohaffogpbgfpmpgbcgccg [2019-02-24]