~ Rapport de ZHPDiag v2014.10.18.148 - Nicolas Coolman (18/10/2014) ~ Lancé par judiflo (20/10/2014 10:37:00) ~ Adresse du Site Web http://nicolascoolman.fr ~ Adresse du Forum http://forum.nicolascoolman.fr ~ Traduit par Nicolas Coolman ~ Etat de la version : Nouvelle version disponible ~ Liste blanche : Désactivée par l'utilisateur ~ Elévation des Privilèges : OK ~ User Account Control (UAC): Activate by user ---\\ Navigateurs Internet MSIE: Internet Explorer v11.0.9600.17358 MFIE: Mozilla Firefox 33.0 GCIE: Google Chrome v38.0.2125.104 (Defaut) ---\\ Informations sur les produits Windows ~ Langage: Français Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601) Windows Server License Manager Script : OK ~ Windows Operating System - Windows(R) 7, OEM_SLP channel System Locked Preinstallation (OEM_SLP) : OK Windows ID Activation : OK ~ Windows Partial Key : 7QJB7 Windows License : OK ~ Windows Remaining Initializations Number : 3 Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ Logiciels de protection du système AVG 2015 v15.0.4181 COMODO Firewall v7.0.55655.4142 Windows Defender W7 (Deactivate) ---\\ Logiciels d'optimisation du système CCleaner v4.18 ---\\ Logiciels de partage PeerToPeer ---\\ Surveillance de Logiciels Adobe Flash Player 9 ActiveX Adobe Reader 9.1 MUI ---\\ Informations sur le système ~ Processor: Intel64 Family 6 Model 37 Stepping 2, GenuineIntel ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 3956 MB (55% free) System Restore: Activé (Enable) System drive C: has 547 GB (91%) free of 596 GB ---\\ Mode de connexion au système ~ Computer Name: JUDIFLO-PC ~ User Name: judiflo ~ All Users Names: judiflo, Administrateur, ~ Unselected Option: None Logged in as Administrator ---\\ Variables d'environnement ~ System Unit : C:\ ~ %AppZHP% : C:\Users\judiflo\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\judiflo\AppData\Roaming\ ~ %Desktop% : C:\Users\judiflo\Desktop\ ~ %Favorites% : C:\Users\judiflo\Favorites\ ~ %LocalAppData% : C:\Users\judiflo\AppData\Local\ ~ %StartMenu% : C:\Users\judiflo\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumération des unités disques C: Hard drive, Flash drive, Thumb drive (Free 547 Go of 596 Go) D: Hard drive, Flash drive, Thumb drive (Free 300 Go of 581 Go) H: CD-ROM drive (Not Inserted) ---\\ Etat du Centre de Sécurité Windows [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ~ Security Center: 41 Scanned in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808] [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024] [MD5.9D98D4F390F0B14A782F3B931E613A1A] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.19/09/2014 - 01:33:18.) -- C:\Windows\System32\wininet.dll [2309632] [MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.17/07/2014 - 03:07:24.) -- C:\Windows\System32\Winlogon.exe [455168] [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448] [MD5.FA886682CFC5D36718D3E436AACF10B9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:45:52.) -- C:\Windows\system32\Drivers\AFD.sys [497152] [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128] [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160] [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456] [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400] [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368] [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472] [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224] [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208] [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632] [MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:37:55.) -- C:\Windows\system32\Drivers\ntfs.sys [1684928] [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280] [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536] [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184] [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296] [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808] ~ Generic Processes: Scanned in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes Favoris (My Favorites) : 1/30 ~ Mes Documents (My Documents) : 1/81 ~ Mon Bureau (My Desktop) : 1/32 ~ Menu demarrer (Programs) : 1/27 ~ Hidden Files: Scanned in 00mn 00s ---\\ Processus lancés [MD5.4938ABEE1650FF4E147FC6890D158788] - (.Innovative Solutions - Application Starter.) -- C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe [1065352] [PID.3476] [MD5.B36DFFCD2B20AF39223847D691B49357] - (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3593744] [PID.4784] [MD5.B53D59915A356B06C1D7DE5B22B4177C] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [854344] [PID.4896] [MD5.7787F1E659DCDF85E47BBF374B502FAC] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8113664] [PID.5440] [MD5.6FB5A57EC4B989A439162F8439B43FFE] - (.Egis Technology Inc. - Pas de description.) -- C:\Program Files (x86)\Acer Bio Protection\CompPtcVUI.exe [3360256] [PID.1856] [MD5.4187E691A71B65955CA3DB9FBA31031C] - (.AVG Technologies CZ, s.r.o. - AVG Identity Protection Service.) -- C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3364368] [PID.1056] [MD5.3218AA21B739C1C338DC8A555A66B755] - (.AVG Technologies CZ, s.r.o. - AVG Watchdog Service.) -- C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [293448] [PID.1660] [MD5.73686FE0B2E0469F89FD2075BE724704] - (.Apple Computer, Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe [229376] [PID.1792] [MD5.B6572CC49E8D0DBCCAB230B4DAB06FB1] - (.CHENGDU YIWO Tech Development Co., Ltd - EaseUS Todo Backup Agent Application.) -- C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [37448] [PID.1268] [MD5.816FD5A6F3C2F3D600900096632FC60E] - (.Acer Incorporated - Global Registration Service.) -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [1150496] [PID.2152] [MD5.DE6086A0DB400EEE10C16F100BBEF594] - (.Egis Technology Inc. - BASVC.exe.) -- C:\Program Files (x86)\Acer Bio Protection\BASVC.exe [3450368] [PID.2192] [MD5.A1C148801B4AF64847AEB9F3AD9594EF] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [262144] [PID.2416] [MD5.CDFF5D0F87B39D0993BC95E166D0CD4C] - (...) -- C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe [240712] [PID.2520] [MD5.3589BFAF27183772B7F0F976AAAEDE43] - (.NewTech Infosystems, Inc. - Backup Manager Module.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [255744] [PID.2628] [MD5.B5071E15D4C3F5EF5018AFF7E85A85E5] - (.NewTech Infosystems, Inc. - NTI Backup Now 5 SchedulerSvc NT Service.) -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [144640] [PID.2676] [MD5.B5A4B7D779CF4070DF408DE18BD33B02] - (.Acer Incorporated - Raw Socket Service.) -- C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [253952] [PID.3236] [MD5.70DDE3A86DBEB1D6C3C30AD687B1877A] - (.Acer - Acer Update Service.) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe [240160] [PID.3456] [MD5.660BF3255A1EB18ED803FD2FBA6AE400] - (.Intel Corporation - RAID Monitor.) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe [354840] [PID.3632] [MD5.41118D920B2B268C0ADC36421248CDCF] - (.Intel Corporation - User Notification Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2314240] [PID.5904] ~ Processes Running: Scanned in 00mn 00s ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2) C:\Users\judiflo\AppData\Local\Google\Chrome\User Data\Default\Preferences ---\\ Liste des dossiers d'extension Google Chrome ~ Google Lines Browser: 0 Scanned in 00mn 16s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.1.3] - (.VideoLAN - VLC media player Web Plugin 2.2.0.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll =>.VideoLAN P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.1.5] - (.VideoLAN - VLC media player Web Plugin 2.2.0.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll =>.VideoLAN ~ Firefox Browser: 4 Scanned in 00mn 00s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blank R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.9600.17239 (winblue_gdr.140724-2228)) -- C:\Windows\SysWOW64\ieframe.dll R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1 ~ IE Browser: 18 Scanned in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=c:\windows\system32\userinit.exe F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Hosts file redirection (O1) ~ Le fichier hôte est sain (The hosts file is clean) (21) ~ Hosts File: Scanned in 00mn 00s ---\\ Browser Helper Objects de navigateur (O2) O2 - BHO: AcroIEHelperStub [64Bits] - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) [64Bits] - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline O2 - BHO: Partner BHO Class [64Bits] - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} . (.Google Inc. - Partner application.) -- C:\ProgramData\Partner\Partner.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper [64Bits] - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO [64Bits] - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll O2 - BHO: Google Dictionary Compression sdch [64Bits] - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} . (.Google Inc. - Fast Search.) -- C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll O2 - BHO: PrivDogExtension [64Bits] - {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} . (.AdTrustMedia - PrivDog Extension.) -- C:\Program Files (x86)\AdTrustMedia\PrivDog\1.8.0.15\trustedads.dll ~ BHO: 13 Scanned in 00mn 00s ---\\ Internet Explorer Toolbars (O3) O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline ~ Toolbar: Scanned in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\QuickLaunch [judiflo]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Users\judiflo\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent ~ Global Startup: 1 Scanned in 00mn 01s ---\\ Applications lancées au démarrage du système (O4) O4 - HKLM\..\Run: [COMODO Internet Security] . (.COMODO - COMODO Internet Security.) -- C:\Program Files\COMODO\COMODO Internet Security\cistray.exe O4 - HKCU\..\Run: [POP Peeper] . (.Mortal Universe - POP Peeper Email Notifier.) -- C:\Program Files (x86)\POP Peeper\POPPeeper.exe O4 - HKLM\..\Wow6432Node\Run: [AVG_UI] . (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Program Files (x86)\AVG\AVG2015\avgui.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-3598627129-2418806855-3480489139-1000\..\Run: [POP Peeper] . (.Mortal Universe - POP Peeper Email Notifier.) -- C:\Program Files (x86)\POP Peeper\POPPeeper.exe ~ Application: Scanned in 00mn 00s ---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5) O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no ~ IE Control Panel: 1 Scanned in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: Quick-Launch Area [64Bits] - {10954C80-4F0F-11d3-B17C-00C0DFE39736} . (...) -- C:\Program Files (x86)\Acer Bio Protection\IETag.ico O9 - Extra button: PrivDog [64Bits] - {2F5C139F-79BD-4C84-A95A-E7140525BC55} . (.AdTrustMedia - PrivDog Extension.) -- C:\Program Files\AdTrustMedia\PrivDog\1.8.0.15\trustedads.dll ~ IE Extra Buttons: Scanned in 00mn 00s ---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll O10 - WLSP:\000000000009\Winsock LSP File . (.Apple Computer, Inc. - Bonjour Namespace Provider.) -- C:\Program Files (x86)\Bonjour\mdnsNSP.dll ~ Winsock: 9 Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{B1F994D8-662A-4830-96B5-5E04D4A37B03}: NameServer = 156.154.70.25,156.154.71.25 O17 - HKLM\System\CCS\Services\Tcpip\..\{BEA3D6BF-23BB-4FDF-BD85-867F7436CE1A}: NameServer = 156.154.70.25,156.154.71.25 O17 - HKLM\System\CCS\Services\Tcpip\..\{BEA3D6BF-23BB-4FDF-BD85-867F7436CE1A}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CCS\Services\Tcpip\..\{BEA3D6BF-23BB-4FDF-BD85-867F7436CE1A}: DhcpDomain = lan O17 - HKLM\System\CS1\Services\Tcpip\..\{B1F994D8-662A-4830-96B5-5E04D4A37B03}: NameServer = 156.154.70.25,156.154.71.25 O17 - HKLM\System\CS1\Services\Tcpip\..\{BEA3D6BF-23BB-4FDF-BD85-867F7436CE1A}: NameServer = 156.154.70.25,156.154.71.25 O17 - HKLM\System\CS1\Services\Tcpip\..\{BEA3D6BF-23BB-4FDF-BD85-867F7436CE1A}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CS1\Services\Tcpip\..\{BEA3D6BF-23BB-4FDF-BD85-867F7436CE1A}: DhcpDomain = lan O17 - HKLM\System\CS2\Services\Tcpip\..\{B1F994D8-662A-4830-96B5-5E04D4A37B03}: NameServer = 156.154.70.25,156.154.71.25 O17 - HKLM\System\CS2\Services\Tcpip\..\{BEA3D6BF-23BB-4FDF-BD85-867F7436CE1A}: NameServer = 156.154.70.25,156.154.71.25 O17 - HKLM\System\CS2\Services\Tcpip\..\{BEA3D6BF-23BB-4FDF-BD85-867F7436CE1A}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CS2\Services\Tcpip\..\{BEA3D6BF-23BB-4FDF-BD85-867F7436CE1A}: DhcpDomain = lan O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: wlmailhtml [64Bits] - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (...) -- O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. ~ SSODL: 1 Scanned in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\System32\atiesrxx.exe O23 - Service: AVGIDSAgent (AVGIDSAgent) . (.AVG Technologies CZ, s.r.o. - AVG Identity Protection Service.) - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe O23 - Service: AVG WatchDog (avgwd) . (.AVG Technologies CZ, s.r.o. - AVG Watchdog Service.) - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) . (.Apple Computer, Inc. - Bonjour Service.) - C:\Program Files (x86)\Bonjour\mDNSResponder.exe O23 - Service: COMODO Internet Security Helper Service (CmdAgent) . (.COMODO - COMODO Internet Security.) - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe O23 - Service: Service Agent EaseUS (EaseUS Agent) . (.CHENGDU YIWO Tech Development Co., Ltd - EaseUS Todo Backup Agent Application.) - C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe O23 - Service: Acer ePower Service (ePowerSvc) . (.Acer Incorporated - ePowerSvc.) - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe O23 - Service: GRegService (Greg_Service) . (.Acer Incorporated - Global Registration Service.) - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) . (.Intel Corporation - RAID Monitor.) - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: EgisTec Service (IGBASVC) . (.Egis Technology Inc. - BASVC.exe.) - C:\Program Files (x86)\Acer Bio Protection\BASVC.exe O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: Ma-Config Agent (MaConfigAgent) . (.CybelSoft - Service de détection matériel.) - C:\Program Files\ma-config.com\MaConfigAgent.exe O23 - Service: NTI IScheduleSvc (NTI IScheduleSvc) . (.NewTech Infosystems, Inc. - Backup Manager Module.) - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) . (.NewTech Infosystems, Inc. - NTI Backup Now 5 SchedulerSvc NT Service.) - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe O23 - Service: Raw Socket Service (RS_Service) . (.Acer Incorporated - Raw Socket Service.) - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe O23 - Service: Intel(R) Management & Security Application User Notificatio (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: Updater Service (Updater Service) . (.Acer - Acer Update Service.) - C:\Program Files\Acer\Acer Updater\UpdaterService.exe ~ Services: 18 Scanned in 00mn 27s ---\\ Enumération Active Desktop & MHTML Editor (O24) O24 - Default MHTML Editor: Last - .(...) - (.not file.) ~ Desktop Component: 4 Scanned in 00mn 00s ---\\ Enumère les données de BootExecute (BEX) (O34) O34 - HKLM BootExecute: (autocheck autochk *) - File not found ~ BEX: 1 Scanned in 00mn 00s ---\\ Tâches planifiées en automatique (O39) [MD5.C234BC05EF8320ABBF1AA04B95886E16] [APT] [Acer Registration Data Sending] (.Acer Incorporated.) -- C:\Program Files (x86)\Acer\Registration\GREG.exe [2846240] [MD5.FBB312C9DA3863673EC18F4AE4101778] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [267440] [MD5.4938ABEE1650FF4E147FC6890D158788] [APT] [Application Starter - f1375f225883e83d52e8db9690775c3c] (.Innovative Solutions.) -- C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe [1065352] [MD5.F308D7378BF60B91DA495FCAA1C216E7] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [4811032] [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648] [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648] [MD5.581CFAF4DD80E1028C347364CCAD89BB] [APT] [McQcModifier-5c47-a7b0] (...) -- C:\ProgramData\McQcModifier-5c47-a7b0\McQcModifier-5c47-a7b0.cmd [289] [MD5.9DED6CF0A6053F65A7D74A006A739ABA] [APT] [COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}] (.COMODO.) -- C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [5181144] [MD5.9DED6CF0A6053F65A7D74A006A739ABA] [APT] [COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}] (.COMODO.) -- C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [5181144] O39 - APT: Acer Registration Data Sending - (.Acer Incorporated.) -- C:\Windows\Tasks\Acer Registration Data Sending.job [348] O39 - APT: Acer Registration Data Sending - (.Acer Incorporated.) -- C:\Windows\System32\Tasks\Acer Registration Data Sending [348] O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002] O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002] O39 - APT: Application Starter - f1375f225883e83d52e8db9690775c3c - (.Innovative Solutions.) -- C:\Windows\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c.job [308] O39 - APT: Application Starter - f1375f225883e83d52e8db9690775c3c - (.Innovative Solutions.) -- C:\Windows\System32\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c [308] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1066] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1066] O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1070] O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1070] ~ Scheduled Task: 17 Scanned in 00mn 06s ---\\ Composants installés (ActiveSetup Installed Components) (O40) O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe =>.Microsoft Corporation O40 - ASIC: Browsing Enhancements [64Bits] - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation O40 - ASIC: Windows Desktop Update [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll ~ Active Setup: 9 Scanned in 00mn 00s ---\\ Pilotes lancés au démarrage du système (O41) O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys O41 - Driver: (Avgdiska) . (.AVG Technologies CZ, s.r.o. - AVG File Vault Driver.) - C:\Windows\System32\DRIVERS\avgdiska.sys O41 - Driver: (AVGIDSDriver) . (.AVG Technologies CZ, s.r.o. - AVG IDS Application Activity Monitor Driver.) - C:\Windows\System32\DRIVERS\avgidsdrivera.sys O41 - Driver: (Avgldx64) . (.AVG Technologies CZ, s.r.o. - AVG AVI Loader Driver.) - C:\Windows\System32\DRIVERS\avgldx64.sys O41 - Driver: (Avgtdia) . (.AVG Technologies CZ, s.r.o. - AVG Network connection watcher.) - C:\Windows\System32\DRIVERS\avgtdia.sys O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\system32\DRIVERS\blbdrive.sys O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\drivers\cdrom.sys O41 - Driver: (cmderd) . (.COMODO - COMODO Internet Security Eradication Driver.) - C:\Windows\System32\DRIVERS\cmderd.sys O41 - Driver: (cmdGuard) . (.COMODO - COMODO Internet Security Sandbox Driver.) - C:\Windows\System32\DRIVERS\cmdguard.sys O41 - Driver: (cmdHlp) . (.COMODO - COMODO Internet Security Helper Driver.) - C:\Windows\System32\DRIVERS\cmdhlp.sys O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys O41 - Driver: (EUDSKACS) . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Access Driver.) - C:\Windows\system32\drivers\eudskacs.sys O41 - Driver: (EUFDDISK) . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Backup Image Preview Driver.) - C:\Windows\system32\drivers\EuFdDisk.sys O41 - Driver: (inspect) . (.COMODO - COMODO Internet Security Firewall Driver.) - C:\Windows\System32\DRIVERS\inspect.sys O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys O41 - Driver: (mwlPSDFilter) . (.Egis Technology Inc. - PSD Filter Driver.) - C:\Windows\System32\DRIVERS\mwlPSDFilter.sys O41 - Driver: (mwlPSDNServ) . (.Egis Technology Inc. - MyWinLocker PSD Named Pipe Driver.) - C:\Windows\System32\DRIVERS\mwlPSDNServ.sys O41 - Driver: (mwlPSDVDisk) . (.Egis Technology Inc. - MyWinLocker PSD Virtual Disk Driver.) - C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys ~ Drivers: 99 Scanned in 00mn 00s ---\\ Logiciels installés (O42) O42 - Logiciel: AHV content for Acrobat and Flash - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD} O42 - Logiciel: ATI AVIVO64 Codecs - (.ATI Technologies Inc..) [HKLM][64Bits] -- {1F6E8D55-B357-924F-4D4F-A9362F8DE508} O42 - Logiciel: AVG 2015 - (.AVG Technologies.) [HKLM][64Bits] -- AVG O42 - Logiciel: AVG 2015 - (.AVG Technologies.) [HKLM][64Bits] -- {426E8080-E591-436B-9F7A-3C61D0AB742D} O42 - Logiciel: AVG 2015 - (.AVG Technologies.) [HKLM][64Bits] -- {959AD6B6-4122-4498-B91A-19C455DCFE35} O42 - Logiciel: Acer Arcade Deluxe - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761} O42 - Logiciel: Acer Arcade Deluxe - (.CyberLink Corp..) [HKLM][64Bits] -- {2637C347-9DAD-11D6-9EA2-00055D0CA761} O42 - Logiciel: Acer Backup Manager - (.NewTech Infosystems.) [HKLM][64Bits] -- InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121} O42 - Logiciel: Acer Bio Protection - (.Egis Technology Inc..) [HKLM][64Bits] -- InstallShield_{E09664BB-BB08-45FA-87D1-33EAB0E017F5} O42 - Logiciel: Acer Crystal Eye Webcam - (.Suyin Optronics Corp.) [HKLM][64Bits] -- {7760D94E-B1B5-40A0-9AA0-ABF942108755} O42 - Logiciel: Acer GameZone Console - (.Oberon Media, Inc..) [HKLM][64Bits] -- {8ed9688e-4f79-4308-91ca-f1c37ca142b4}_is1 O42 - Logiciel: Acer GridVista - (.Acer Inc..) [HKLM][64Bits] -- GridVista O42 - Logiciel: Acer PowerSmart Manager - (.Acer Incorporated.) [HKLM][64Bits] -- {3DB0448D-AD82-4923-B305-D001E521A964} O42 - Logiciel: Acer Registration - (.Acer Incorporated.) [HKLM][64Bits] -- Acer Registration O42 - Logiciel: Acer ScreenSaver - (.Acer Incorporated.) [HKLM][64Bits] -- Acer Screensaver O42 - Logiciel: Acer Updater - (.Acer Incorporated.) [HKLM][64Bits] -- {EE171732-BEB4-4576-887D-CB62727F01CA} O42 - Logiciel: Acer VCM - (.Acer Incorporated.) [HKLM][64Bits] -- {047F790A-7A2A-4B6A-AD02-38092BA63DAC} O42 - Logiciel: Acer eRecovery Management - (.Acer Incorporated.) [HKLM][64Bits] -- {7F811A54-5A09-4579-90E1-C93498E230D9} O42 - Logiciel: Acrobat.com - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {287ECFA4-719A-2143-A09B-D6A12DE54E40} O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM][64Bits] -- Adobe AIR O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM][64Bits] -- {A2BCA9F1-566C-4805-97D1-7FDC93386723} O42 - Logiciel: Adobe Anchor Service CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {90176341-0A8B-4CCC-A78D-F862228A6B95} O42 - Logiciel: Adobe Asset Services CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61} O42 - Logiciel: Adobe Bridge CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {9C9824D9-9000-4373-A6A5-D0E5D4831394} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Bridge Start Meeting - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {08B32819-6EEF-4057-AEDA-5AB681A36A23} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe BridgeTalk Plugin CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe CMaps - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {A2B242BD-FF8D-4840-9DAA-9170EABEC59C} O42 - Logiciel: Adobe Camera Raw 4.0 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C} O42 - Logiciel: Adobe Color - Photoshop Specific - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {A2D81E70-2A98-4A08-A628-94388B063C5E} O42 - Logiciel: Adobe Color Common Settings - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9} O42 - Logiciel: Adobe Color EU Recommended Settings - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {73B5D990-04EA-4751-B10F-5534770B91F2} O42 - Logiciel: Adobe Color JA Extra Settings - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029} O42 - Logiciel: Adobe Color NA Extra Settings - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {FF29A7E2-FF40-4D07-B7E4-2093DE59E10A} O42 - Logiciel: Adobe Creative Suite 3 Design Premium - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {BEE8E835-BB38-4042-A80E-7F8CEDD5612A} O42 - Logiciel: Adobe Default Language CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {B9B35331-B7E4-4E5C-BF4C-7BC87856124D} O42 - Logiciel: Adobe Device Central CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {8D2BA474-F406-4710-9AE4-D4F22D21F0DD} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe ExtendScript Toolkit 2 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {C2D69781-F392-4118-A5A7-C7E9C38DBFC2} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Extension Manager CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {BE5F3842-8309-4754-92D5-83E02E6077A3} O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Flash Player 15 Plugin - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player Plugin O42 - Logiciel: Adobe Flash Player 9 ActiveX - (.Adobe Systems, Inc..) [HKLM][64Bits] -- {BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C} O42 - Logiciel: Adobe Fonts All - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {6ABE0BEE-D572-4FE8-B434-9E72A289431B} O42 - Logiciel: Adobe Help Viewer CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {04AF207D-9A77-465A-8B76-991F6AB66245} O42 - Logiciel: Adobe InDesign CS3 Icon Handler - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {EA7B3CC4-366D-4CF6-8350-FD7A7034116E} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Linguistics CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {54793AA1-5001-42F4-ABB6-C364617C6078} O42 - Logiciel: Adobe MotionPicture Color Files - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {6B708481-748A-4EB4-97C1-CD386244FF77} O42 - Logiciel: Adobe PDF Library Files - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {D2559B88-CC9D-4B48-81BB-F492BAA9C48C} O42 - Logiciel: Adobe Photoshop CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {C1FA4B3B-1625-4922-9C9D-780E8FCE161A} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Reader 9.1 MUI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-FFFF-7B44-A91000000001} O42 - Logiciel: Adobe SING CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {B671CBFD-4109-4D35-9252-3062D3CCB7B2} O42 - Logiciel: Adobe Setup - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {EAE2C948-26FA-49C1-8C80-99EBE55DD9E1} O42 - Logiciel: Adobe Stock Photos CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {29E5EA97-5F74-4A57-B8B2-D4F169117183} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Type Support - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {8E6808E2-613D-4FCD-81A2-6C8FA8E03312} O42 - Logiciel: Adobe Update Manager CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {E69AE897-9E0B-485C-8552-7841F48D42D8} O42 - Logiciel: Adobe Version Cue CS3 Client - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {D0DFF92A-492E-4C40-B862-A74A173C25C5} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe WAS CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {C5BD220A-EFE8-48A5-B70E-9503D535FACE} O42 - Logiciel: Adobe WinSoft Linguistics Plugin - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {184CE391-7E0E-4C63-9935-D7A10EDFD3C6} O42 - Logiciel: Adobe XMP Panels CS3 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {802771A9-A856-4A41-ACF7-1450E523C923} O42 - Logiciel: Ajouter ou supprimer Adobe Creative Suite 3 Design Premium - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe_5647dddec81b3798d8bab8c5ac5fcb0 O42 - Logiciel: Alice Greenfingers - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767} O42 - Logiciel: Amazonia - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11273477} O42 - Logiciel: Backup Manager Advance - (.NewTech Infosystems.) [HKLM][64Bits] -- {30075A70-B5D2-440B-AFA3-FB2021740121} O42 - Logiciel: Broadcom Gigabit NetLink Controller - (.Broadcom Corporation.) [HKLM][64Bits] -- {A325B368-A9EC-40EF-A95C-9DEAD3683AE3} O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner O42 - Logiciel: COMODO Firewall - (.COMODO Security Solutions Inc..) [HKLM][64Bits] -- {2736B6BD-31EC-4FC8-A48C-F0A5C914C0B6} O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM][64Bits] -- {34A0D249-747E-4D6C-803D-329C120C6B79} O42 - Logiciel: Chicken Invaders 2 - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593} O42 - Logiciel: CrystalDiskInfo 6.2.1 - (.Crystal Dew World.) [HKLM][64Bits] -- CrystalDiskInfo_is1 O42 - Logiciel: Dairy Dash - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115053100} O42 - Logiciel: Dream Day First Home - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110} O42 - Logiciel: DriverMax 7 - (.Innovative Solutions.) [HKLM][64Bits] -- DMX5_is1 O42 - Logiciel: EaseUS Partition Master 10.0 - (.EaseUS.) [HKLM][64Bits] -- EaseUS Partition Master_is1 O42 - Logiciel: EaseUS Todo Backup Free 7.0 - (.CHENGDU YIWO Tech Development Co., Ltd.) [HKLM][64Bits] -- EaseUS Todo Backup_is1 O42 - Logiciel: Farm Frenzy 2 - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173} O42 - Logiciel: Fingerprint Solution - (.Egis Technology Inc..) [HKLM][64Bits] -- {E09664BB-BB08-45FA-87D1-33EAB0E017F5} O42 - Logiciel: First Class Flurry - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115208410} O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome O42 - Logiciel: Google Drive - (.Google, Inc..) [HKLM][64Bits] -- {C6640705-7479-4EE5-BC86-879F05F65E74} O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {18455581-E099-4BA8-BC6B-F34B2F06600C} O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F} O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} O42 - Logiciel: Granny In Paradise - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110551697} O42 - Logiciel: Heroes of Hellas - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380} O42 - Logiciel: Identity Card - (.Acer Incorporated.) [HKLM][64Bits] -- Identity Card O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A} O42 - Logiciel: Intel(R) Turbo Boost Technology Driver - (.Intel Corporation.) [HKLM][64Bits] -- {D6C630BF-8DBB-4042-8562-DC9A52CB6E7E} O42 - Logiciel: Intel® Matrix Storage Manager - (.Intel Corporation.) [HKLM][64Bits] -- {9068B2BE-D93A-4C0A-861C-5E35E2C0E09E} O42 - Logiciel: JMicron 1394 Filter Driver - (.JMicron Technology Corp..) [HKLM][64Bits] -- {13C96625-28E4-4c58-ADE0-CDAFC64752EB} O42 - Logiciel: JMicron Flash Media Controller Driver - (.JMicron Technology Corp..) [HKLM][64Bits] -- {26604C7E-A313-4D12-867F-7C6E7820BE4C} O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM][64Bits] -- {E2DFE069-083E-4631-9B6C-43C48E991DE5} O42 - Logiciel: Launch Manager - (.Acer Inc..) [HKLM][64Bits] -- LManager O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94} O42 - Logiciel: MSXML 4.0 SP3 Parser (KB2758694) - (.Microsoft Corporation.) [HKLM][64Bits] -- {1D95BA90-F4F8-47EC-A882-441C99D30C1E} O42 - Logiciel: MSXML 4.0 SP3 Parser (KB973685) - (.Microsoft Corporation.) [HKLM][64Bits] -- {859DFA95-E4A6-48CD-B88E-A3E483E89B44} O42 - Logiciel: Ma-Config.com (64 bits) - (.Cybelsoft.) [HKLM][64Bits] -- {9A3C5DC9-EEA9-4FB2-855A-26FE6DA733EA} O42 - Logiciel: Merriam Websters Spell Jam - (.Oberon Media.) [HKLM][64Bits] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477} O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} O42 - Logiciel: Microsoft Works - (.Microsoft Corporation.) [HKLM][64Bits] -- {0214A441-A4AB-43A8-8DEF-2F73C5364673} O42 - Logiciel: Moniteur de la technologie Intel® Turbo Boost - (.Intel.) [HKLM][64Bits] -- {39F4C6F9-618A-4E5B-8FB2-6BD661174E32} O42 - Logiciel: Mozilla Firefox 33.0 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 33.0 (x86 fr) O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService O42 - Logiciel: MyWinLocker - (.Egis Technology Inc..) [HKLM][64Bits] -- {68301905-2DEA-41CE-A4D4-E8B443B099BA} O42 - Logiciel: NTI Backup Now 5 - (.NewTech Infosystems.) [HKLM][64Bits] -- InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403} O42 - Logiciel: NTI Media Maker 8 - (.NewTech Infosystems.) [HKLM][64Bits] -- InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC} O42 - Logiciel: Nuvoton CIR Device Drivers - (.Nuvoton Technology Corporation.) [HKLM][64Bits] -- {FBC79D04-051E-4367-8051-1DB0C893FBE0} O42 - Logiciel: PDF Settings - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC5B0C19-D851-42F4-BDA0-410ECF7F70A5} O42 - Logiciel: PDFCreator - (.pdfforge.) [HKLM][64Bits] -- {0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D} O42 - Logiciel: POP Peeper - (.Mortal Universe.) [HKLM][64Bits] -- POP Peeper O42 - Logiciel: PeaZip 5.4.1 (WIN64) - (.Giorgio Tani.) [HKLM][64Bits] -- {5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1 O42 - Logiciel: PrivDog - (.privdog.com.) [HKLM][64Bits] -- PrivDog O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN O42 - Logiciel: Visual Studio 2012 x64 Redistributables - (.AVG Technologies.) [HKLM][64Bits] -- {8C775E70-A791-4DA8-BCC3-6AB7136F4484} O42 - Logiciel: Visual Studio 2012 x86 Redistributables - (.AVG Technologies CZ, s.r.o..) [HKLM][64Bits] -- {98EFF19A-30AB-4E4B-B943-F06B1C63EBF8} O42 - Logiciel: Welcome Center - (.Acer Incorporated.) [HKLM][64Bits] -- Acer Welcome Center O42 - Logiciel: Zedeo version 0.3 - (.czmaster.) [HKLM][64Bits] -- {095074AE-E4BD-41EC-AE78-21969805AB7C}_is1 O42 - Logiciel: eSobi v2 - (.esobi Inc..) [HKLM][64Bits] -- InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA} O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU][64Bits] -- uTorrent =>P2P.BitTorrent ~ Logic: 52 Scanned in 00mn 00s ---\\ HKCU & HKLM Software Keys [HKCU\Software\ATI] [HKCU\Software\Acer] [HKCU\Software\AdTrustMedia] [HKCU\Software\Adobe] [HKCU\Software\Aerofox] [HKCU\Software\AppDataLow\Software\Google] [HKCU\Software\AppDataLow] [HKCU\Software\Avg] [HKCU\Software\BitTorrent] =>P2P.BitTorrent [HKCU\Software\Chromium] [HKCU\Software\Classes] [HKCU\Software\Clients] [HKCU\Software\ComodoGroup] [HKCU\Software\Cyberlink] [HKCU\Software\EaseUS] [HKCU\Software\EpmNewsInfo] [HKCU\Software\Google] [HKCU\Software\Innovative Solutions] [HKCU\Software\Local AppWizard-Generated Applications] [HKCU\Software\Macromedia] [HKCU\Software\MozillaPlugins] [HKCU\Software\Mozilla] [HKCU\Software\Netscape] [HKCU\Software\NewTech Infosystems] [HKCU\Software\O&O] [HKCU\Software\ODBC] [HKCU\Software\OEM] [HKCU\Software\PDF Architect 2] [HKCU\Software\PDFCreator] [HKCU\Software\Piriform] [HKCU\Software\Policies] [HKCU\Software\Quanta] [HKCU\Software\Realtek] [HKCU\Software\SlimWare Utilities Inc] [HKCU\Software\Sonix] [HKCU\Software\Synaptics] [HKCU\Software\TAdvCheckList] [HKCU\Software\Wow6432Node] [HKCU\Software\ZebHelpProcess Helper] [HKLM\Software\AMD] [HKLM\Software\ATI Technologies] [HKLM\Software\ATI] [HKLM\Software\Acer] [HKLM\Software\AdTrustMedia] [HKLM\Software\BrowserChoice] [HKLM\Software\COMODO] [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\CyberLink] [HKLM\Software\EgisTec] [HKLM\Software\Google] [HKLM\Software\InstalledOptions] [HKLM\Software\Intel] [HKLM\Software\Khronos] [HKLM\Software\Macromedia] [HKLM\Software\MozillaPlugins] [HKLM\Software\Mozilla] [HKLM\Software\Nuvoton Technology Corporation] [HKLM\Software\O&O] [HKLM\Software\ODBC] [HKLM\Software\OEM] [HKLM\Software\OemSetup] [HKLM\Software\PeaZip] [HKLM\Software\PeaZip_additional] [HKLM\Software\Piriform] [HKLM\Software\Policies] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\SONIX] [HKLM\Software\SRS Labs] [HKLM\Software\Salsita] [HKLM\Software\Soluto] [HKLM\Software\Sonic] [HKLM\Software\Synaptics] [HKLM\Software\VideoLAN] [HKLM\Software\Waves Audio] [HKLM\Software\Wow6432Node\AMD] [HKLM\Software\Wow6432Node\ATI Technologies] [HKLM\Software\Wow6432Node\ATI] [HKLM\Software\Wow6432Node\Acer Incorporated] [HKLM\Software\Wow6432Node\Acer] [HKLM\Software\Wow6432Node\AdTrustMedia] [HKLM\Software\Wow6432Node\Adobe] [HKLM\Software\Wow6432Node\America Online] [HKLM\Software\Wow6432Node\Apple Computer, Inc.] [HKLM\Software\Wow6432Node\Avg Secure Update] [HKLM\Software\Wow6432Node\Avg] [HKLM\Software\Wow6432Node\Chromium] [HKLM\Software\Wow6432Node\Classes] [HKLM\Software\Wow6432Node\Clients] [HKLM\Software\Wow6432Node\Comodo] [HKLM\Software\Wow6432Node\CyberLink] [HKLM\Software\Wow6432Node\Digital River] [HKLM\Software\Wow6432Node\EASEUSTODOBACKUPCHECK] [HKLM\Software\Wow6432Node\EaseUS Todo Backup] [HKLM\Software\Wow6432Node\EaseUS] [HKLM\Software\Wow6432Node\EgisTec Egis Software Update] [HKLM\Software\Wow6432Node\EgisTec IPS] [HKLM\Software\Wow6432Node\EgisTec] [HKLM\Software\Wow6432Node\Google] [HKLM\Software\Wow6432Node\Innovative Solutions] [HKLM\Software\Wow6432Node\InstallShield] [HKLM\Software\Wow6432Node\Intel] [HKLM\Software\Wow6432Node\Khronos] [HKLM\Software\Wow6432Node\Macromedia] [HKLM\Software\Wow6432Node\Macrovision] [HKLM\Software\Wow6432Node\McAfeeInstaller] [HKLM\Software\Wow6432Node\MozillaPlugins] [HKLM\Software\Wow6432Node\Mozilla] [HKLM\Software\Wow6432Node\NewTech Infosystems] [HKLM\Software\Wow6432Node\ODBC] [HKLM\Software\Wow6432Node\OEM] [HKLM\Software\Wow6432Node\Oberon Media] [HKLM\Software\Wow6432Node\PDF Architect 2] [HKLM\Software\Wow6432Node\PDFCreator] [HKLM\Software\Wow6432Node\Policies] [HKLM\Software\Wow6432Node\Product Key Reader] [HKLM\Software\Wow6432Node\Quanta] [HKLM\Software\Wow6432Node\Realtek Semiconductor Corp.] [HKLM\Software\Wow6432Node\Realtek] [HKLM\Software\Wow6432Node\RegisteredApplications] [HKLM\Software\Wow6432Node\Salsita] [HKLM\Software\Wow6432Node\SiteAdvisor] [HKLM\Software\Wow6432Node\SlimWare Utilities Inc] [HKLM\Software\Wow6432Node\Suyin Optronics Corp] [HKLM\Software\Wow6432Node\Wow6432Node] [HKLM\Software\Wow6432Node\mozilla.org] [HKLM\Software\Wow6432Node\nSplitter] [HKLM\Software\Wow6432Node] [HKLM\Software\cybelsoft] [HKLM\Software\nSplitter] ~ Key Software: 305 Scanned in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 02/12/2009 - 06:29:53 - [] ----D C:\Program Files (x86)\Acer O43 - CFD: 28/09/2014 - 20:44:45 - [] ----D C:\Program Files (x86)\Acer Arcade Deluxe O43 - CFD: 28/09/2014 - 20:19:34 - [] ----D C:\Program Files (x86)\Acer Bio Protection O43 - CFD: 02/12/2009 - 06:01:17 - [] ----D C:\Program Files (x86)\Acer GameZone O43 - CFD: 02/12/2009 - 06:27:40 - [] ----D C:\Program Files (x86)\Acer Inc O43 - CFD: 08/10/2014 - 18:25:16 - [] ----D C:\Program Files (x86)\Adobe O43 - CFD: 28/09/2014 - 20:45:38 - [] ----D C:\Program Files (x86)\AdTrustMedia O43 - CFD: 28/09/2014 - 18:36:03 - [] ----D C:\Program Files (x86)\ATI Technologies O43 - CFD: 13/10/2014 - 14:37:53 - [] ----D C:\Program Files (x86)\AVG O43 - CFD: 08/10/2014 - 18:25:24 - [] ----D C:\Program Files (x86)\Bonjour O43 - CFD: 08/10/2014 - 19:26:27 - [] ----D C:\Program Files (x86)\Common Files O43 - CFD: 12/10/2014 - 11:57:03 - [] ----D C:\Program Files (x86)\CrystalDiskInfo O43 - CFD: 28/09/2014 - 20:43:11 - [] ----D C:\Program Files (x86)\Cyberlink O43 - CFD: 15/10/2014 - 17:55:16 - [] ----D C:\Program Files (x86)\EaseUS O43 - CFD: 02/12/2009 - 06:12:32 - [] ----D C:\Program Files (x86)\EgisTec O43 - CFD: 02/12/2009 - 06:12:37 - [] ----D C:\Program Files (x86)\EgisTec Egis Software Update O43 - CFD: 28/09/2014 - 20:12:41 - [] ----D C:\Program Files (x86)\EgisTec IPS O43 - CFD: 02/12/2009 - 06:24:00 - [] ----D C:\Program Files (x86)\eSobi O43 - CFD: 06/10/2014 - 11:12:50 - [] ----D C:\Program Files (x86)\Google O43 - CFD: 07/10/2014 - 20:38:02 - [] ----D C:\Program Files (x86)\Innovative Solutions O43 - CFD: 28/09/2014 - 20:44:46 - [] --H-D C:\Program Files (x86)\InstallShield Installation Information O43 - CFD: 28/09/2014 - 19:21:50 - [] ----D C:\Program Files (x86)\Intel O43 - CFD: 17/10/2014 - 15:48:14 - [] ----D C:\Program Files (x86)\Internet Explorer O43 - CFD: 02/12/2009 - 05:52:09 - [] ----D C:\Program Files (x86)\JMicron O43 - CFD: 28/09/2014 - 19:13:37 - [] ----D C:\Program Files (x86)\Launch Manager O43 - CFD: 08/10/2014 - 19:11:36 - [] ----D C:\Program Files (x86)\Microsoft Office O43 - CFD: 02/12/2009 - 06:07:35 - [] ----D C:\Program Files (x86)\Microsoft Office Suite Activation Assistant O43 - CFD: 28/09/2014 - 22:06:54 - [] ----D C:\Program Files (x86)\Microsoft Silverlight O43 - CFD: 08/10/2014 - 19:26:27 - [] ----D C:\Program Files (x86)\Microsoft Visual Studio O43 - CFD: 08/10/2014 - 20:28:40 - [] ----D C:\Program Files (x86)\Microsoft Visual Studio 8 O43 - CFD: 29/09/2014 - 21:30:10 - [] ----D C:\Program Files (x86)\Microsoft Works O43 - CFD: 08/10/2014 - 19:23:35 - [] ----D C:\Program Files (x86)\Microsoft.NET O43 - CFD: 15/10/2014 - 19:55:59 - [] ----D C:\Program Files (x86)\Mozilla Firefox O43 - CFD: 02/10/2014 - 08:45:42 - [] ----D C:\Program Files (x86)\Mozilla Maintenance Service O43 - CFD: 14/07/2009 - 07:32:38 - [] ----D C:\Program Files (x86)\MSBuild O43 - CFD: 28/09/2014 - 19:08:18 - [] ----D C:\Program Files (x86)\MSXML 4.0 O43 - CFD: 02/12/2009 - 06:23:26 - [] ----D C:\Program Files (x86)\NewTech Infosystems O43 - CFD: 02/12/2009 - 05:48:06 - [] ----D C:\Program Files (x86)\Nuvoton Technology Corporation O43 - CFD: 04/10/2014 - 20:50:51 - [] ----D C:\Program Files (x86)\PDFCreator O43 - CFD: 30/09/2014 - 18:44:05 - [] ----D C:\Program Files (x86)\POP Peeper O43 - CFD: 28/09/2014 - 18:33:49 - [] ----D C:\Program Files (x86)\Realtek O43 - CFD: 14/07/2009 - 07:32:38 - [] ----D C:\Program Files (x86)\Reference Assemblies O43 - CFD: 28/09/2014 - 18:34:10 - [0] --H-D C:\Program Files (x86)\Temp O43 - CFD: 14/07/2009 - 06:57:06 - [0] --H-D C:\Program Files (x86)\Uninstall Information O43 - CFD: 30/09/2014 - 03:45:41 - [] ----D C:\Program Files (x86)\Windows Defender O43 - CFD: 28/09/2014 - 23:26:55 - [] ----D C:\Program Files (x86)\Windows Live O43 - CFD: 29/09/2014 - 03:06:32 - [] ----D C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation O43 - CFD: 30/09/2014 - 03:47:30 - [] ----D C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation O43 - CFD: 14/07/2009 - 07:32:38 - [] ----D C:\Program Files (x86)\Windows NT O43 - CFD: 29/09/2014 - 03:06:31 - [] ----D C:\Program Files (x86)\Windows Photo Viewer O43 - CFD: 29/09/2014 - 03:06:31 - [] ----D C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 29/09/2014 - 03:06:32 - [] ----D C:\Program Files (x86)\Windows Sidebar O43 - CFD: 14/10/2014 - 21:02:13 - [] ----D C:\Program Files (x86)\Zedeo O43 - CFD: 20/10/2014 - 10:36:05 - [] ----D C:\Program Files (x86)\ZHPDiag =>.Nicolas Coolman O43 - CFD: 08/10/2014 - 18:37:48 - [] ----D C:\Program Files (x86)\Common Files\Adobe O43 - CFD: 02/12/2009 - 06:22:54 - [] ----D C:\Program Files (x86)\Common Files\Adobe AIR O43 - CFD: 08/10/2014 - 19:26:27 - [] ----D C:\Program Files (x86)\Common Files\DESIGNER O43 - CFD: 02/12/2009 - 06:12:37 - [] ----D C:\Program Files (x86)\Common Files\EgisTec O43 - CFD: 28/09/2014 - 20:43:37 - [] ----D C:\Program Files (x86)\Common Files\InstallShield O43 - CFD: 08/10/2014 - 18:20:27 - [] ----D C:\Program Files (x86)\Common Files\Macrovision Shared O43 - CFD: 11/10/2014 - 19:10:02 - [] ----D C:\Program Files (x86)\Common Files\microsoft shared O43 - CFD: 02/12/2009 - 05:54:24 - [] ----D C:\Program Files (x86)\Common Files\Oberon Media O43 - CFD: 28/09/2014 - 19:21:54 - [] ----D C:\Program Files (x86)\Common Files\postureAgent O43 - CFD: 14/07/2009 - 05:20:08 - [] ----D C:\Program Files (x86)\Common Files\Services O43 - CFD: 14/07/2009 - 05:20:08 - [] ----D C:\Program Files (x86)\Common Files\SpeechEngines O43 - CFD: 10/10/2014 - 21:14:50 - [] ----D C:\Program Files (x86)\Common Files\System O43 - CFD: 28/09/2014 - 19:22:58 - [] ----D C:\Program Files (x86)\Common Files\Windows Live O43 - CFD: 02/12/2009 - 06:10:09 - [] ----D C:\ProgramData\Acer O43 - CFD: 08/10/2014 - 20:31:38 - [] ----D C:\ProgramData\Adobe O43 - CFD: 28/09/2014 - 20:45:34 - [] ----D C:\ProgramData\Adtrustmedia O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Application Data O43 - CFD: 28/09/2014 - 18:47:56 - [] ----D C:\ProgramData\ATI O43 - CFD: 13/10/2014 - 14:39:11 - [] ----D C:\ProgramData\AVG2015 O43 - CFD: 02/12/2009 - 06:23:46 - [] ----D C:\ProgramData\BackupManager O43 - CFD: 28/09/2014 - 18:43:45 - [] -SH-D C:\ProgramData\Bureau O43 - CFD: 13/10/2014 - 14:33:17 - [] --H-D C:\ProgramData\Common Files O43 - CFD: 13/10/2014 - 14:48:25 - [] ----D C:\ProgramData\Comodo O43 - CFD: 13/10/2014 - 14:47:12 - [] ----D C:\ProgramData\Comodo Downloader O43 - CFD: 28/09/2014 - 20:43:11 - [] ----D C:\ProgramData\CyberLink O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Desktop O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Documents O43 - CFD: 02/12/2009 - 06:26:46 - [] ----D C:\ProgramData\EgisTec O43 - CFD: 28/09/2014 - 20:58:59 - [] ----D C:\ProgramData\EgisTec IPS O43 - CFD: 02/12/2009 - 06:24:04 - [] ----D C:\ProgramData\eSobi O43 - CFD: 28/09/2014 - 18:43:45 - [] -SH-D C:\ProgramData\Favoris O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Favorites O43 - CFD: 08/10/2014 - 18:40:15 - [] ----D C:\ProgramData\FLEXnet O43 - CFD: 02/12/2009 - 06:12:21 - [] ----D C:\ProgramData\Google O43 - CFD: 06/10/2014 - 20:00:40 - [] ----D C:\ProgramData\ma-config.com O43 - CFD: 28/09/2014 - 19:47:18 - [] ----D C:\ProgramData\McAfee O43 - CFD: 28/09/2014 - 18:47:12 - [] ----D C:\ProgramData\McQcModifier-5c47-a7b0 O43 - CFD: 28/09/2014 - 18:43:45 - [] -SH-D C:\ProgramData\Menu Démarrer O43 - CFD: 20/10/2014 - 10:19:58 - [] ----D C:\ProgramData\MFAData O43 - CFD: 02/10/2014 - 09:01:36 - [] -S--D C:\ProgramData\Microsoft O43 - CFD: 16/10/2014 - 21:51:38 - [] ----D C:\ProgramData\Microsoft Help O43 - CFD: 28/09/2014 - 18:43:45 - [] -SH-D C:\ProgramData\Modèles O43 - CFD: 30/09/2014 - 19:27:38 - [] ----D C:\ProgramData\Mozilla O43 - CFD: 28/09/2014 - 18:44:25 - [] ----D C:\ProgramData\OEM O43 - CFD: 02/12/2009 - 06:12:22 - [] ----D C:\ProgramData\Partner O43 - CFD: 02/10/2014 - 18:42:11 - [] ----D C:\ProgramData\PDF Architect 2 O43 - CFD: 13/10/2014 - 14:48:26 - [] -S--D C:\ProgramData\Shared Space O43 - CFD: 02/12/2009 - 06:18:24 - [] ----D C:\ProgramData\SiteAdvisor O43 - CFD: 19/10/2014 - 10:29:14 - [] ----D C:\ProgramData\Soluto O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Start Menu O43 - CFD: 28/09/2014 - 20:20:55 - [] ----D C:\ProgramData\Temp O43 - CFD: 14/07/2009 - 07:08:56 - [] -SH-D C:\ProgramData\Templates O43 - CFD: 09/10/2014 - 17:50:51 - [] ----D C:\Users\judiflo\AppData\Roaming\Adobe O43 - CFD: 28/09/2014 - 18:47:55 - [] ----D C:\Users\judiflo\AppData\Roaming\ATI O43 - CFD: 13/10/2014 - 14:39:22 - [] ----D C:\Users\judiflo\AppData\Roaming\AVG2015 O43 - CFD: 30/09/2014 - 20:04:09 - [] ----D C:\Users\judiflo\AppData\Roaming\Foxmail7 O43 - CFD: 28/09/2014 - 18:53:26 - [] ----D C:\Users\judiflo\AppData\Roaming\Google O43 - CFD: 28/09/2014 - 18:46:41 - [] ----D C:\Users\judiflo\AppData\Roaming\Identities O43 - CFD: 28/09/2014 - 19:16:39 - [] ----D C:\Users\judiflo\AppData\Roaming\InstallShield O43 - CFD: 28/09/2014 - 18:47:13 - [] ----D C:\Users\judiflo\AppData\Roaming\Macromedia O43 - CFD: 14/07/2009 - 09:44:38 - [0] ----D C:\Users\judiflo\AppData\Roaming\Media Center Programs O43 - CFD: 20/10/2014 - 09:25:32 - [] -S--D C:\Users\judiflo\AppData\Roaming\Microsoft O43 - CFD: 15/10/2014 - 19:56:05 - [] ----D C:\Users\judiflo\AppData\Roaming\Mozilla O43 - CFD: 02/10/2014 - 18:41:28 - [] ----D C:\Users\judiflo\AppData\Roaming\pdfforge O43 - CFD: 06/10/2014 - 12:14:51 - [] ----D C:\Users\judiflo\AppData\Roaming\PeaZip O43 - CFD: 20/10/2014 - 10:01:45 - [] ----D C:\Users\judiflo\AppData\Roaming\POP Peeper O43 - CFD: 30/09/2014 - 19:28:12 - [] ----D C:\Users\judiflo\AppData\Roaming\Thunderbird =>.Mozilla Corporation O43 - CFD: 13/10/2014 - 14:38:48 - [] ----D C:\Users\judiflo\AppData\Roaming\TuneUp Software O43 - CFD: 15/10/2014 - 17:35:17 - [] ----D C:\Users\judiflo\AppData\Roaming\uTorrent =>P2P.µTorrent O43 - CFD: 14/10/2014 - 20:44:20 - [] ----D C:\Users\judiflo\AppData\Roaming\vlc O43 - CFD: 20/10/2014 - 10:38:00 - [] ----D C:\Users\judiflo\AppData\Roaming\ZHP =>.Nicolas Coolman O43 - CFD: 09/10/2014 - 17:50:51 - [] ----D C:\Users\judiflo\AppData\Local\Adobe O43 - CFD: 02/10/2014 - 08:50:45 - [] ----D C:\Users\judiflo\AppData\Local\AdTrustMedia O43 - CFD: 28/09/2014 - 18:43:58 - [] -SH-D C:\Users\judiflo\AppData\Local\Application Data O43 - CFD: 28/09/2014 - 19:00:04 - [] ----D C:\Users\judiflo\AppData\Local\Apps O43 - CFD: 28/09/2014 - 18:47:55 - [] ----D C:\Users\judiflo\AppData\Local\ATI O43 - CFD: 13/10/2014 - 14:48:37 - [] ----D C:\Users\judiflo\AppData\Local\Avg2015 O43 - CFD: 20/10/2014 - 09:18:52 - [] ----D C:\Users\judiflo\AppData\Local\CrashDumps O43 - CFD: 28/09/2014 - 19:00:27 - [0] ----D C:\Users\judiflo\AppData\Local\Deployment O43 - CFD: 18/10/2014 - 11:04:53 - [] ----D C:\Users\judiflo\AppData\Local\Diagnostics O43 - CFD: 18/10/2014 - 18:47:31 - [] ----D C:\Users\judiflo\AppData\Local\Downloaded Installations O43 - CFD: 28/09/2014 - 18:47:12 - [] ----D C:\Users\judiflo\AppData\Local\EgisTec O43 - CFD: 28/09/2014 - 20:58:59 - [] ----D C:\Users\judiflo\AppData\Local\EgisTec IPS O43 - CFD: 19/10/2014 - 09:53:41 - [] ----D C:\Users\judiflo\AppData\Local\ElevatedDiagnostics O43 - CFD: 13/10/2014 - 18:15:14 - [] -SH-D C:\Users\judiflo\AppData\Local\EmieSiteList O43 - CFD: 13/10/2014 - 18:15:14 - [] -SH-D C:\Users\judiflo\AppData\Local\EmieUserList O43 - CFD: 06/10/2014 - 11:12:54 - [] ----D C:\Users\judiflo\AppData\Local\Google O43 - CFD: 28/09/2014 - 18:43:58 - [] -SH-D C:\Users\judiflo\AppData\Local\Historique O43 - CFD: 07/10/2014 - 20:38:05 - [] ----D C:\Users\judiflo\AppData\Local\Innovative Solutions O43 - CFD: 13/10/2014 - 14:33:17 - [] ----D C:\Users\judiflo\AppData\Local\MFAData O43 - CFD: 02/10/2014 - 09:51:53 - [] ----D C:\Users\judiflo\AppData\Local\Microsoft O43 - CFD: 08/10/2014 - 19:11:38 - [0] ----D C:\Users\judiflo\AppData\Local\Microsoft Help O43 - CFD: 15/10/2014 - 19:58:26 - [] ----D C:\Users\judiflo\AppData\Local\Mozilla O43 - CFD: 18/10/2014 - 18:57:51 - [] ----D C:\Users\judiflo\AppData\Local\O&O O43 - CFD: 02/10/2014 - 18:24:10 - [] ----D C:\Users\judiflo\AppData\Local\Programs O43 - CFD: 07/10/2014 - 20:25:27 - [] ----D C:\Users\judiflo\AppData\Local\SlimWare Utilities Inc O43 - CFD: 20/10/2014 - 10:36:09 - [] ----D C:\Users\judiflo\AppData\Local\Temp O43 - CFD: 28/09/2014 - 18:43:58 - [] -SH-D C:\Users\judiflo\AppData\Local\Temporary Internet Files O43 - CFD: 30/09/2014 - 19:28:12 - [] ----D C:\Users\judiflo\AppData\Local\Thunderbird =>.Mozilla Corporation O43 - CFD: 29/09/2014 - 20:03:27 - [] ----D C:\Users\judiflo\AppData\Local\VirtualStore O43 - CFD: 28/09/2014 - 22:35:55 - [] ----D C:\Users\judiflo\AppData\Local\Windows Live O43 - CFD: 14/07/2009 - 06:54:32 - [] R---D C:\Users\judiflo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 30/09/2014 - 03:59:50 - [] R---D C:\Users\judiflo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 14/07/2009 - 06:49:38 - [] R---D C:\Users\judiflo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 29/09/2014 - 20:02:51 - [] ----D C:\Users\judiflo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\POP Peeper O43 - CFD: 30/09/2014 - 03:59:50 - [] R---D C:\Users\judiflo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup ~ Program Folder: 160 Scanned in 00mn 00s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.87D14AF9A2C3F3D5233B613CFA9C321D] - 07/10/2014 - 03:54:03 ---A- . (.Microsoft Corporation - Personnalisation d’IEAK.) -- C:\Windows\System32\iedkcs32.dll [378552] O44 - LFC:[MD5.DEA40050BBD55F6F5FF895B50D15646B] - 07/10/2014 - 19:56:09 ---A- . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\Windows\System32\Drivers\athrx.sys [4059136] O44 - LFC:[MD5.011E2478A810FF05AA76557E68C8720B] - 07/10/2014 - 19:59:11 ---A- . (.Christian Gulden - Pluralinput Mouse Driver.) -- C:\Windows\System32\Drivers\pimou.sys [23608] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 07/10/2014 - 19:59:33 --HA- . (...) -- C:\Windows\System32\Drivers\Msft_Kernel_pimou_01009.Wdf [0] O44 - LFC:[MD5.779010324CCB6B974C4D737DDAABB2D5] - 08/10/2014 - 20:45:45 ---A- . (.Broadcom Corporation - Broadcom NetLink (TM) Gigabit Ethernet NDIS.) -- C:\Windows\System32\Drivers\k57nd60a.sys [458960] O44 - LFC:[MD5.DEA325B8099A1F8D62A0B15471BF849B] - 08/10/2014 - 20:49:50 ---A- . (.Sonix Technology Co., Ltd. - DefaultSettingEXE.) -- C:\Windows\PLFSetL.exe [99712] O44 - LFC:[MD5.681A54D355E577A934AB532CD997FBF8] - 08/10/2014 - 20:49:55 ---A- . (.Pas de propriétaire - DisplaySettingMonitor MFC Application.) -- C:\Windows\snuvcdsm.exe [30080] O44 - LFC:[MD5.A5130A50C3B297B72BA85EEE4636C780] - 08/10/2014 - 20:49:59 ---A- . (.Pas de propriétaire - USBCAMD for Sonix UVC.) -- C:\Windows\System32\Drivers\sncduvc.sys [40960] O44 - LFC:[MD5.68500E60195F959EE1CA947BE123D725] - 08/10/2014 - 20:49:59 ---A- . (.Pas de propriétaire - UVC Camera Streaming Driver.) -- C:\Windows\System32\Drivers\snp2uvc.sys [1806592] O44 - LFC:[MD5.767D478BB4B2F84B47B3C0956E6A5A05] - 10/10/2014 - 03:00:38 ---A- . (.Microsoft Corporation - Application Experience Program Inventory Co.) -- C:\Windows\System32\aeinv.dll [424448] O44 - LFC:[MD5.510D5492BCA9E63E10E3CE0285965722] - 10/10/2014 - 03:05:42 ---A- . (.Microsoft Corporation - Mise à jour des données de compatibilité de.) -- C:\Windows\System32\aepdu.dll [507392] O44 - LFC:[MD5.974F83636F841739FEA5CC6219BFB241] - 10/10/2014 - 03:05:59 ---A- . (.Microsoft Corporation - General Telemetry.) -- C:\Windows\System32\generaltel.dll [276480] O44 - LFC:[MD5.C667A0A4D08227ED19D7720FAF7E2D54] - 10/10/2014 - 20:14:50 ---A- . (...) -- C:\Windows\win.ini [510] O44 - LFC:[MD5.092EBA8638125100E9034088B94E3ED9] - 13/10/2014 - 14:38:56 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1668256] O44 - LFC:[MD5.1DD32111187BBEE60D96D88744B12E63] - 13/10/2014 - 14:38:56 ---A- . (...) -- C:\Windows\System32\perfc009.dat [122012] O44 - LFC:[MD5.66B699B8EA51E858B5BF7B18F47AC6F9] - 13/10/2014 - 14:38:56 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [150062] O44 - LFC:[MD5.5B0DFF35C60082403301C795CA504F67] - 13/10/2014 - 14:38:56 ---A- . (...) -- C:\Windows\System32\perfh009.dat [654140] O44 - LFC:[MD5.CA81A24817AE4B10BF4D2D8AAC0EF870] - 13/10/2014 - 14:38:56 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [747570] O44 - LFC:[MD5.BBECD819E5D264F99BA5875C61CE5623] - 15/10/2014 - 16:46:35 ---A- . (...) -- C:\Windows\System32\BootMan.exe [3382440] O44 - LFC:[MD5.991C04A31777ED77CB92A4F96F14C2E2] - 15/10/2014 - 16:46:35 ---A- . (...) -- C:\Windows\System32\EuGdiDrv.sys [9800] O44 - LFC:[MD5.6106653B08F4F72EEAA7F099E7C408A4] - 15/10/2014 - 16:46:35 ---A- . (...) -- C:\Windows\System32\epmntdrv.sys [17480] O44 - LFC:[MD5.65355919686BE70BE3B5781CBC0999CF] - 15/10/2014 - 16:46:35 ---A- . (...) -- C:\Windows\System32\setupempdrvx64.exe [100936] O44 - LFC:[MD5.C773F06312FA82C7517D0F9101CFC4CF] - 15/10/2014 - 16:46:36 ---A- . (...) -- C:\Windows\System32\EuEpmGdi.dll [16256] O44 - LFC:[MD5.62B76ED789404895898F1A3B74348596] - 15/10/2014 - 16:55:37 ---A- . (.CHENGDU YIWO Tech Development Co., Ltd - EaseUS Todo Backup Application.) -- C:\Windows\System32\fbnative.exe [24136] O44 - LFC:[MD5.23A4CFFF224CD9FA2226B64F1DCC4B4A] - 15/10/2014 - 16:58:35 ---A- . (...) -- C:\Windows\System32\Drivers\EUBKMON.sys [48200] O44 - LFC:[MD5.38A68D8706F79429ACAD043BE3533B97] - 15/10/2014 - 16:59:34 ---A- . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Access Driver.) -- C:\Windows\System32\Drivers\eudskacs.sys [18504] O44 - LFC:[MD5.A40A3A4653A18A0DA6522CEC69547B9F] - 15/10/2014 - 16:59:34 ---A- . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Backup Driver.) -- C:\Windows\System32\Drivers\eubakup.sys [61000] O44 - LFC:[MD5.06BB97B21EF082703B7F3AE97F2DFFD8] - 15/10/2014 - 16:59:34 ---A- . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Backup Image Preview Driver.) -- C:\Windows\System32\Drivers\EuFdDisk.sys [189000] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 16/10/2014 - 16:38:19 ---A- . (...) -- C:\Windows\setuperr.log [0] O44 - LFC:[MD5.F669DAB1142D80DEED3D05687A1D99C4] - 16/10/2014 - 16:48:48 ---A- . (.Microsoft Corporation - Outil de suppression de logiciels malveilla.) -- C:\Windows\System32\MRT.exe [103265616] O44 - LFC:[MD5.1DB68B8A1E3BDE3C19F1D3612CE436CA] - 16/10/2014 - 17:33:29 ---A- . (.Microsoft Corporation - Gestionnaire de liaisons d’objets2.) -- C:\Windows\System32\packager.dll [77312] O44 - LFC:[MD5.6DD73E4E947DB3B0608321AE13210D94] - 16/10/2014 - 17:33:34 ---A- . (.Microsoft Corporation - Client ActiveX des services Bureau à distan.) -- C:\Windows\System32\mstscax.dll [6584320] O44 - LFC:[MD5.ADD3F2C3E6B89BD16D4BFC61B3658DD9] - 16/10/2014 - 17:34:10 ---A- . (.Microsoft Corporation - Windows Installer.) -- C:\Windows\System32\msi.dll [3241472] O44 - LFC:[MD5.560CF90C026C0FE51CC6820302FF94FE] - 16/10/2014 - 17:35:15 ---A- . (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll [22016] O44 - LFC:[MD5.E232A3B43A894BB327FC161529BD9ED1] - 16/10/2014 - 17:35:15 ---A- . (.Microsoft Corporation - TS Security Filter Driver.) -- C:\Windows\System32\Drivers\tssecsrv.sys [39936] O44 - LFC:[MD5.85E03B6E05939845BC924C91AEDE0E24] - 16/10/2014 - 17:35:16 ---A- . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\TSpkg.dll [86528] O44 - LFC:[MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - 16/10/2014 - 17:35:17 ---A- . (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\winlogon.exe [455168] O44 - LFC:[MD5.0374D83D003043E7DE33036294A2EFAE] - 16/10/2014 - 17:35:17 ---A- . (.Microsoft Corporation - DLL RDPCore Terminal Server (KM).) -- C:\Windows\System32\rdpcorekmts.dll [150528] O44 - LFC:[MD5.FE571E088C2D83619D2D48D4E961BF41] - 16/10/2014 - 17:35:17 ---A- . (.Microsoft Corporation - Pilote de pile RDP Terminal.) -- C:\Windows\System32\Drivers\rdpwd.sys [212480] O44 - LFC:[MD5.C23B6D9D16FD86F446BE607CA18389D9] - 16/10/2014 - 17:35:18 ---A- . (.Microsoft Corporation - Winstation Library.) -- C:\Windows\System32\winsta.dll [235520] O44 - LFC:[MD5.4FC4C50985E5B840F4D72E57286887B8] - 16/10/2014 - 17:35:22 ---A- . (.Microsoft Corporation - Gestionnaire des connexions distantes du se.) -- C:\Windows\System32\termsrv.dll [681984] O44 - LFC:[MD5.DD7C31F12936795C0516BB6C59CBCCD8] - 16/10/2014 - 17:35:41 ---A- . (.Microsoft Corporation - Accès distant PPP EAP-TLS.) -- C:\Windows\System32\rastls.dll [424448] O44 - LFC:[MD5.15847E14811FEDDF77E934AF4F0BEF45] - 16/10/2014 - 17:37:31 ---A- . (.Microsoft Corporation - Microsoft Spell Checking Facility.) -- C:\Windows\System32\MsSpellCheckingFacility.exe [940032] O44 - LFC:[MD5.7415B29AFE2E4494A57358B8C7E78600] - 16/10/2014 - 17:37:31 ---A- . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll [23631360] O44 - LFC:[MD5.30FB9ABB6C45C3299CFA5F556904DD5F] - 16/10/2014 - 17:37:32 ---A- . (.Microsoft Corporation - DAC for Trident DOM.) -- C:\Windows\System32\MshtmlDac.dll [83968] O44 - LFC:[MD5.EB710A3AF29BEC4EE7475A1ED5C575DE] - 16/10/2014 - 17:37:32 ---A- . (.Microsoft Corporation - DLL de gestion d'utilisateur local et de co.) -- C:\Windows\System32\msrating.dll [195584] O44 - LFC:[MD5.9D98D4F390F0B14A782F3B931E613A1A] - 16/10/2014 - 17:37:32 ---A- . (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [2309632] O44 - LFC:[MD5.2E5AF1507CBE735B4D7EBFF1908EA0E1] - 16/10/2014 - 17:37:32 ---A- . (.Microsoft Corporation - Microsoft SmartScreen Filter.) -- C:\Windows\System32\ieapfltr.dll [775168] O44 - LFC:[MD5.328143D6BC5951E1797BD524C4E98CDC] - 16/10/2014 - 17:37:33 ---A- . (.Microsoft Corporation - Microsoft ® VBScript.) -- C:\Windows\System32\vbscript.dll [547328] O44 - LFC:[MD5.D3B07C2FABEAE749E4E51F1E93CABA23] - 16/10/2014 - 17:37:34 ---A- . (.Microsoft Corporation - Microsoft (R) JScript.) -- C:\Windows\System32\jscript9.dll [5829632] O44 - LFC:[MD5.DB101A62F9BF8E7765685950169EF52B] - 16/10/2014 - 17:37:34 ---A- . (.Microsoft Corporation - Microsoft ® JScript Diagnostics.) -- C:\Windows\System32\jscript9diag.dll [758272] O44 - LFC:[MD5.F9FA80C1CB6EAC55A7F534937F6AC4E4] - 16/10/2014 - 17:37:34 ---A- . (.Microsoft Corporation - Outil d’installation sans assistance d’IE 7.) -- C:\Windows\System32\ieUnatt.exe [139264] O44 - LFC:[MD5.70527367E5779C3537992F0768D9C59A] - 16/10/2014 - 17:37:35 ---A- . (.Microsoft Corporation - Microsoft (R) HTML Media DLL.) -- C:\Windows\System32\mshtmlmedia.dll [1249280] O44 - LFC:[MD5.A2105E46DC9CE38A1D57FB124436E1BC] - 16/10/2014 - 17:37:35 ---A- . (.Microsoft Corporation - Microsoft® HTML Editing Component.) -- C:\Windows\System32\mshtmled.dll [85504] O44 - LFC:[MD5.7E60EE8A68F7270D1E1662CBA275D4FA] - 16/10/2014 - 17:37:36 ---A- . (.Microsoft Corporation - Navigateur Internet.) -- C:\Windows\System32\ieframe.dll [13619200] O44 - LFC:[MD5.88D2165E07CEDC3F34CBE1A5A807673D] - 16/10/2014 - 17:37:37 ---A- . (.Microsoft Corporation - Moteur de l’interface utilisateur d’Interne.) -- C:\Windows\System32\ieui.dll [595968] O44 - LFC:[MD5.BE37AA454460539877420951EEA16EF0] - 16/10/2014 - 17:37:38 ---A- . (.Microsoft Corporation - JScript Proxy Auto-Configuration.) -- C:\Windows\System32\jsproxy.dll [51200] O44 - LFC:[MD5.646C004F58AA4762F92BF7C595216C37] - 16/10/2014 - 17:37:39 ---A- . (.Microsoft Corporation - Panneau de configuration Internet.) -- C:\Windows\System32\inetcpl.cpl [2108416] O44 - LFC:[MD5.050FD78BA4EFA62417F61F4C098B5B25] - 16/10/2014 - 17:37:39 ---A- . (.Microsoft Corporation - Run time utility for Internet Explorer.) -- C:\Windows\System32\iertutil.dll [2796032] O44 - LFC:[MD5.0467A4DDA6B2CE8E27A8178BF035BA18] - 16/10/2014 - 17:37:40 ---A- . (.Microsoft Corporation - IOD Version Map.) -- C:\Windows\System32\iesetup.dll [66048] O44 - LFC:[MD5.45B736E3184B68515FDB71D4083A9BCF] - 16/10/2014 - 17:37:40 ---A- . (.Microsoft Corporation - Microsoft Feeds Manager.) -- C:\Windows\System32\msfeeds.dll [731136] O44 - LFC:[MD5.B07E9AFF50DC007E7D5AC54736AA5A25] - 16/10/2014 - 17:37:41 ---A- . (.Microsoft Corporation - IE ETW Collector Service Resources.) -- C:\Windows\System32\ieetwcollectorres.dll [4096] O44 - LFC:[MD5.E9109E91BB8366759822DC2FC9B5DA8B] - 16/10/2014 - 17:37:41 ---A- . (.Microsoft Corporation - IE ETW Collector Service.) -- C:\Windows\System32\ieetwcollector.exe [111616] O44 - LFC:[MD5.0F5A279522FA6A30C9C5A297A1064933] - 16/10/2014 - 17:37:42 ---A- . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [1447936] O44 - LFC:[MD5.DD8E9C85F9F428859713055183661956] - 16/10/2014 - 17:37:44 ---A- . (.Microsoft Corporation - IE ETW Collector Proxy Stub Resources.) -- C:\Windows\System32\ieetwproxystub.dll [48640] O44 - LFC:[MD5.4D21F4FDF57DF86FAD9149ED1C071D15] - 16/10/2014 - 17:37:44 ---A- . (.Microsoft Corporation - JavaScript Performance Collection Agent.) -- C:\Windows\System32\JavaScriptCollectionAgent.dll [72704] O44 - LFC:[MD5.C109D5136DF0A6CA668C7AD888AA125F] - 16/10/2014 - 17:37:44 ---A- . (.Microsoft Corporation - Microsoft® MSHTML Typelib.) -- C:\Windows\System32\mshtml.tlb [2724864] O44 - LFC:[MD5.739D9C9F220CCEDAFD8212C6B976B60D] - 16/10/2014 - 17:37:44 ---A- . (.Microsoft Corporation - Traitement de RunOnce complet avec interfac.) -- C:\Windows\System32\iernonce.dll [33792] O44 - LFC:[MD5.29C0530E0F120AC3E583889DCD6A63DD] - 16/10/2014 - 17:37:44 ---A- . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe [710656] O44 - LFC:[MD5.E9CB5F138943D383DB67F29AAB60453F] - 16/10/2014 - 17:38:28 ---A- . (.Microsoft Corporation - DLL RDPCore TS.) -- C:\Windows\System32\rdpcorets.dll [3179520] O44 - LFC:[MD5.50EC828370CB5F5E9FF08B10F1B701C8] - 16/10/2014 - 17:38:58 ---A- . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll [73880] O44 - LFC:[MD5.2D6C77A3DB3D8EE00FB55834A67E4073] - 16/10/2014 - 17:38:59 ---A- . (.Microsoft Corporation - Microsoft .NET Runtime IE resources.) -- C:\Windows\System32\mscorier.dll [156312] O44 - LFC:[MD5.5083CC5456FE8A5D21ECF9E32ACC779F] - 16/10/2014 - 17:38:59 ---A- . (.Microsoft Corporation - Bibliothèque d'assistance au déploiement de.) -- C:\Windows\System32\dfshim.dll [1943696] O44 - LFC:[MD5.5602D4C331FD7938ADE06D9242138922] - 16/10/2014 - 17:39:01 ---A- . (.Microsoft Corporation - Pilote Win32 multi-utilisateurs.) -- C:\Windows\System32\win32k.sys [3198976] O44 - LFC:[MD5.4F03A88AB4C01BFD1DCC6313A52D0569] - 17/10/2014 - 15:00:33 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [2312704] O44 - LFC:[MD5.6F7599F8CC7BEC99711493FD772F0ACD] - 18/10/2014 - 18:37:45 ---A- . (.Advanced Micro Devices - AMD ACP Kernel Service Driver.) -- C:\Windows\System32\Drivers\amdacpksd.sys [293064] O44 - LFC:[MD5.E21AEB56788D25AEFDB7C9C705CF93C6] - 18/10/2014 - 18:37:46 ---A- . (...) -- C:\Windows\System32\amde31a.dat [157224] O44 - LFC:[MD5.489BFFD143E70BA7BEEB45CC88E60BBE] - 18/10/2014 - 18:37:50 ---A- . (...) -- C:\Windows\System32\amdicdxx.dat [759301] O44 - LFC:[MD5.B0B0054A3A017F0E6B3534298B559DED] - 18/10/2014 - 18:37:51 ---A- . (.Advanced Micro Devices, Inc. - Mantle driver, support for SI family and ab.) -- C:\Windows\System32\amdmantle64.dll [5639168] O44 - LFC:[MD5.6F440E82FCF345FE754F506FD44A398A] - 18/10/2014 - 18:37:52 ---A- . (.Advanced Micro Devices, Inc. - Radeon MMOCL Universal Driver.) -- C:\Windows\System32\amdmmcl6.dll [48128] O44 - LFC:[MD5.ECC9D68F5BEF5CD67BE2D2F758661980] - 18/10/2014 - 18:37:56 ---A- . (...) -- C:\Windows\System32\amdocl_as64.exe [1187342] O44 - LFC:[MD5.A1438ACC0BD3D501EE0BC45EC72EB164] - 18/10/2014 - 18:37:56 ---A- . (.Advanced Micro Devices Inc. - AMD Accelerated Parallel Processing OpenCL.) -- C:\Windows\System32\amdocl64.dll [33867264] O44 - LFC:[MD5.DD3E0FE46F9AB3F9A339F4DD3B2B2E4C] - 18/10/2014 - 18:37:57 ---A- . (...) -- C:\Windows\System32\amdocl_ld64.exe [1061902] O44 - LFC:[MD5.5E6900DCAE38E8A31D230691538F2F9E] - 18/10/2014 - 18:37:57 ---A- . (.Khronos Group - OpenCL Client DLL.) -- C:\Windows\System32\OpenCL.dll [65024] O44 - LFC:[MD5.C61E5273F841ACA92B4EC45D80DF16D7] - 18/10/2014 - 18:37:59 ---A- . (...) -- C:\Windows\System32\atiapfxx.blb [609280] O44 - LFC:[MD5.FF4A738A1BD54C804853338489B0A5D4] - 18/10/2014 - 18:37:59 ---A- . (.Advanced Micro Devices, Inc. - atiapfxx Application.) -- C:\Windows\System32\atiapfxx.exe [367104] O44 - LFC:[MD5.F2861038ADC506F1C9FC1A7A8EDE915E] - 18/10/2014 - 18:38:02 ---A- . (.Advanced Micro Devices, Inc. - Graphics DEM.) -- C:\Windows\System32\atidemgy.dll [442368] O44 - LFC:[MD5.0B730C2F93D0FCC3E8FF23C9E71869AE] - 18/10/2014 - 18:38:02 ---A- . (.Advanced Micro Devices, Inc. - aticfx64.dll.) -- C:\Windows\System32\aticfx64.dll [1335544] O44 - LFC:[MD5.45AD64B725E2BEC258240DC4B0BF2A0A] - 18/10/2014 - 18:38:04 ---A- . (.Advanced Micro Devices, Inc. - atiglpxx.dll.) -- C:\Windows\System32\atig6pxx.dll [75264] O44 - LFC:[MD5.522D0E408A2F22F3D2B4549ED072067D] - 18/10/2014 - 18:38:05 ---A- . (.Advanced Micro Devices, Inc. - atigktxx.dll.) -- C:\Windows\System32\atig6txx.dll [146944] O44 - LFC:[MD5.AD75711435A44347C497451C3F2CB09A] - 18/10/2014 - 18:38:05 ---A- . (.Advanced Micro Devices, Inc. - atiglpxx.dll.) -- C:\Windows\System32\atiglpxx.dll [69632] O44 - LFC:[MD5.FCC736D52A832A81707BE50EF94A3E18] - 18/10/2014 - 18:38:06 ---A- . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\System32\Drivers\atikmpag.sys [576000] O44 - LFC:[MD5.64A0869F18560CD529120ADE00155C3E] - 18/10/2014 - 18:38:10 ---A- . (...) -- C:\Windows\System32\atipblag.dat [3917] O44 - LFC:[MD5.2C265AA9CCA9B416D2E035414226A99E] - 18/10/2014 - 18:38:10 ---A- . (.Advanced Micro Devices, Inc. - atiu9pag.dll.) -- C:\Windows\System32\atiu9p64.dll [118096] O44 - LFC:[MD5.96DD12EAF8A0A580112D1947638BEAA2] - 18/10/2014 - 18:38:14 ---A- . (.Advanced Micro Devices, Inc. - atiuxpag.dll.) -- C:\Windows\System32\atiuxp64.dll [144328] O44 - LFC:[MD5.DE78F78604554B0F6C5449D5474578EC] - 18/10/2014 - 18:38:15 ---A- . (...) -- C:\Windows\System32\ativce02.dat [82128] O44 - LFC:[MD5.9F21B884ACCE17577F732A991CD162AF] - 18/10/2014 - 18:38:15 ---A- . (...) -- C:\Windows\System32\ativce03.dat [158928] O44 - LFC:[MD5.B84E305D4E56C994967851F2CF6BDBB5] - 18/10/2014 - 18:38:15 ---A- . (...) -- C:\Windows\System32\ativvaxy_cik.dat [234164] O44 - LFC:[MD5.BF121C92EB46F38E3AE080A32C73E453] - 18/10/2014 - 18:38:15 ---A- . (...) -- C:\Windows\System32\ativvaxy_cik_nd.dat [232752] O44 - LFC:[MD5.F4D88CAA7A24A9712FE2C1BBA6A1157D] - 18/10/2014 - 18:38:15 ---A- . (...) -- C:\Windows\System32\ativvaxy_cz_nd.dat [290080] O44 - LFC:[MD5.08F891562BCE188E1FDA279AE75812CF] - 18/10/2014 - 18:38:15 ---A- . (...) -- C:\Windows\System32\ativvaxy_vi.dat [322868] O44 - LFC:[MD5.B43DD8D415AAFFFDD885451CCDEA283B] - 18/10/2014 - 18:38:15 ---A- . (...) -- C:\Windows\System32\ativvaxy_vi_nd.dat [321200] O44 - LFC:[MD5.7C163EDE63854539828F5B2C1BC529FD] - 18/10/2014 - 18:38:15 ---A- . (...) -- C:\Windows\System32\ativvsva.dat [157144] O44 - LFC:[MD5.219D7091DD1D93728392337FE9C7ADD6] - 18/10/2014 - 18:38:16 ---A- . (...) -- C:\Windows\System32\ativvsvl.dat [204952] O44 - LFC:[MD5.73743336776F4E01D55E294FC4405798] - 18/10/2014 - 18:38:16 ---A- . (...) -- C:\Windows\System32\clinfo.exe [235008] O44 - LFC:[MD5.5624173ECDDE2C30F89226B1BC7C33AA] - 18/10/2014 - 18:38:16 ---A- . (.AMD - CoInstaller DLL.) -- C:\Windows\System32\coinst_14.30.dll [827392] O44 - LFC:[MD5.B11E3A8CB6A1D071B28AC50501478E54] - 18/10/2014 - 18:38:18 ---A- . (.Advanced Micro Devices Inc. - AMD Accelerated Parallel Processing OpenVid.) -- C:\Windows\System32\OpenVideo64.dll [98816] O44 - LFC:[MD5.79CD6C0CED596B28693F00BB92B7BC73] - 18/10/2014 - 18:38:18 ---A- . (.Advanced Micro Devices, Inc. - Mantle extension library.) -- C:\Windows\System32\mantleaxl64.dll [91648] O44 - LFC:[MD5.6511DE9F9DA777A69E5FD281D2C0F17C] - 18/10/2014 - 18:38:18 ---A- . (.Advanced Micro Devices, Inc. - Mantle loader.) -- C:\Windows\System32\mantle64.dll [127488] O44 - LFC:[MD5.C8758F59D47FE183328C2E2E67FF9F8C] - 18/10/2014 - 18:38:19 ---A- . (.Advanced Micro Devices Inc. - AMD Accelerated Parallel Processing OVDecod.) -- C:\Windows\System32\OVDecode64.dll [86528] O44 - LFC:[MD5.5C6BD003E82EEC61B940D26D98ABD61E] - 18/10/2014 - 18:39:49 ---A- . (...) -- C:\Windows\DPINST.LOG [4950] O44 - LFC:[MD5.F31D5BA4252F67F9CFE027F1A2813D86] - 18/10/2014 - 18:51:28 ---A- . (...) -- C:\Windows\MEMORY.DMP [738842298] O44 - LFC:[MD5.2621D7A27BD96309F7DFB2FEDFF676FF] - 19/10/2014 - 17:31:04 ---A- . (.AMD - AMD External Events Client Module.) -- C:\Windows\System32\atieclxx.exe [438784] O44 - LFC:[MD5.9C5536848A328BDF37E3C2C5784D8F01] - 19/10/2014 - 17:31:04 ---A- . (.AMD - AMD External Events Service Module.) -- C:\Windows\System32\atiesrxx.exe [202752] O44 - LFC:[MD5.2EF80188419DD3535687D61203CEF876] - 19/10/2014 - 17:31:04 ---A- . (.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\Drivers\atikmdag.sys [6107136] O44 - LFC:[MD5.8CD60F7A090B670462E22BD294C5B034] - 19/10/2014 - 17:31:04 ---A- . (.ATI Technologies Inc. - atidxx64.dll.) -- C:\Windows\System32\atidxx64.dll [3624448] O44 - LFC:[MD5.5E01EF8D6431BA034D5DE0BF1475498D] - 19/10/2014 - 17:31:04 ---A- . (.ATI Technologies Inc. - eRecord Message Resource File.) -- C:\Windows\System32\Drivers\ati2erec.dll [53248] O44 - LFC:[MD5.AF48D6084B4D5994446DF005F94516DD] - 19/10/2014 - 17:31:04 ---A- . (.ATI Technologies, Inc. - atiedu64.) -- C:\Windows\System32\atiedu64.dll [59392] O44 - LFC:[MD5.8F1D2A0A0FB61298828B17D112F16276] - 19/10/2014 - 17:31:04 ---A- . (.Advanced Micro Devices Inc. - ATI CAL DD.) -- C:\Windows\System32\aticaldd64.dll [4634112] O44 - LFC:[MD5.7747E1701DEFE29F5B4C19377BF27F44] - 19/10/2014 - 17:31:04 ---A- . (.Advanced Micro Devices Inc. - ATI CAL compiler runtime.) -- C:\Windows\System32\aticalcl64.dll [39936] O44 - LFC:[MD5.91DA8E3103AC6E7EA5CC5947C4C96E86] - 19/10/2014 - 17:31:04 ---A- . (.Advanced Micro Devices Inc. - ATI CAL runtime.) -- C:\Windows\System32\aticalrt64.dll [43008] O44 - LFC:[MD5.6F34F452C09EB6B7C79AB6D847AC9E4F] - 19/10/2014 - 17:31:04 ---A- . (.Advanced Micro Devices, Inc. - ADL.) -- C:\Windows\System32\atiadlxx.dll [302592] O44 - LFC:[MD5.75FFC2EB7982D5FBF07388611E557385] - 19/10/2014 - 17:31:04 ---A- . (.Advanced Micro Devices, Inc. - Graphics DEM.) -- C:\Windows\System32\ATIDEMGX.dll [479232] O44 - LFC:[MD5.2BF700E203910A9FA2DC401AC99249D9] - 19/10/2014 - 17:31:05 ---A- . (...) -- C:\Windows\System32\atiumd6a.cap [402016] O44 - LFC:[MD5.D74E7C77834FCF9F07BDDCDE26F63A3D] - 19/10/2014 - 17:31:05 ---A- . (.AMD - Multi-language DPPE DLL.) -- C:\Windows\System32\atimuixx.dll [12288] O44 - LFC:[MD5.469384292F2393A49AB9B3BD75BD2DBE] - 19/10/2014 - 17:31:05 ---A- . (.AMD - TMM Clone Control Module.) -- C:\Windows\System32\atitmm64.dll [120320] O44 - LFC:[MD5.5855D1B4C76ADA89C88FC980C09530FE] - 19/10/2014 - 17:31:05 ---A- . (.ATI Technologies Inc. - ATI OpenGL driver.) -- C:\Windows\System32\atio6axx.dll [17199616] O44 - LFC:[MD5.8A09E666D9E7BB6EE30E3605D25870BB] - 19/10/2014 - 17:31:05 ---A- . (.ATI Technologies Inc. - atiumdag.dll.) -- C:\Windows\System32\atiumd64.dll [4661760] O44 - LFC:[MD5.FEEA9CE01470375FC5A431ED0F614B42] - 19/10/2014 - 17:31:05 ---A- . (.ATI Technologies, Inc. - ATI Desktop CWDDEDI DLL.) -- C:\Windows\System32\atipdl64.dll [421376] O44 - LFC:[MD5.3628582C36424AE27F16151FB43F968D] - 19/10/2014 - 17:31:05 ---A- . (.Advanced Micro Devices, Inc. - Radeon PCOM Universal Driver.) -- C:\Windows\System32\amdpcom64.dll [53248] O44 - LFC:[MD5.3628582C36424AE27F16151FB43F968D] - 19/10/2014 - 17:31:05 ---A- . (.Advanced Micro Devices, Inc. - Radeon PCOM Universal Driver.) -- C:\Windows\System32\atimpc64.dll [53248] O44 - LFC:[MD5.6A16E8290462633E6E8636381FE55523] - 19/10/2014 - 17:31:05 ---A- . (.Advanced Micro Devices, Inc. - Radeon Video Acceleration Universal Driver.) -- C:\Windows\System32\atiumd6a.dll [2599424] O44 - LFC:[MD5.2DD84D95E2B7C5CEA88C1DB0ACDF27FD] - 20/10/2014 - 09:13:43 -S-A- . (...) -- C:\Windows\bootstat.dat [67584] O44 - LFC:[MD5.77DCF3E67E7D03C7C3D7C22FD0A30EF4] - 20/10/2014 - 09:13:55 ---A- . (...) -- C:\Windows\setupact.log [672] O44 - LFC:[MD5.FD2F27F301D91973204E825E391771E6] - 20/10/2014 - 09:32:36 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1345522] ~ Files: 137 Scanned in 00mn 33s ---\\ Déni du service (Local Security Authority) (O48) O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corp. - LiveSSP.) -- C:\Windows\System32\livessp.dll ~ LSA: 8 Scanned in 00mn 00s ---\\ Contrôle du Safe Boot (CSB) (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys ~ CSB: 13 Scanned in 00mn 00s ---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52) O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm ~ TDSD: 2 Scanned in 00mn 00s ---\\ Enumération des clés de registre StartupReg (SMSR) (O53) O53 - SMSR:HKLM\...\startupreg\Acer ePower Management [Key] . (.Acer Incorporated - ePowerTrayLauncher.) -- C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe O53 - SMSR:HKLM\...\startupreg\Adobe Reader Speed Launcher [Key] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe O53 - SMSR:HKLM\...\startupreg\ArcadeDeluxeAgent [Key] . (.CyberLink Corp. - Acer Arcade Deluxe Resident Program.) -- C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe O53 - SMSR:HKLM\...\startupreg\BackupManagerTray [Key] . (.NewTech Infosystems, Inc. - Acer Backup Manager.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe O53 - SMSR:HKLM\...\startupreg\DriverMax_RESTART [Key] . (.Innovative Solutions - DriverMax.) -- C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe O53 - SMSR:HKLM\...\startupreg\EaseUS EPM tray [Key] . (.CHENGDU YIWO Tech Development Co., Ltd - EaseUS Partition Master Free Edition Applic.) -- C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.0\bin\EpmNews.exe O53 - SMSR:HKLM\...\startupreg\EgisTecLiveUpdate [Key] . (.Egis Technology Inc. - EgisUpdate Release Application.) -- C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe O53 - SMSR:HKLM\...\startupreg\EgisTecPMMUpdate [Key] . (.Egis Technology Inc. - PMM Update Application.) -- C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe O53 - SMSR:HKLM\...\startupreg\EgisUpdate [Key] . (.Egis Technology Inc. - EgisUpdate Release Application.) -- C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe O53 - SMSR:HKLM\...\startupreg\GoogleDriveSync [Key] . (.Google - Google Drive.) -- C:\Program Files (x86)\Google\Drive\googledrivesync.exe O53 - SMSR:HKLM\...\startupreg\IAAnotif [Key] . (.Intel Corporation - Event Monitor User Notification Tool.) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe O53 - SMSR:HKLM\...\startupreg\LManager [Key] . (.Dritek System Inc. - Launch Manager.) -- C:\Program Files (x86)\Launch Manager\LManager.exe O53 - SMSR:HKLM\...\startupreg\mwlDaemon [Key] . (.Egis Technology Inc. - MyWinLocker.) -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe O53 - SMSR:HKLM\...\startupreg\OODefragTray [Key] . (...) -- C:\Program Files\OO Software\Defrag\oodtray.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\PlayMovie [Key] . (.Acer Corp. - Acer Arcade Deluxe PlayMovie Resident Progr.) -- C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe O53 - SMSR:HKLM\...\startupreg\PLFSetI [Key] . (.Pas de propriétaire - DefaultSettingEXE MFC Application.) -- C:\Windows\PLFSetI.exe O53 - SMSR:HKLM\...\startupreg\PLFSetL [Key] . (.Sonix Technology Co., Ltd. - DefaultSettingEXE.) -- C:\Windows\PLFSetL.exe O53 - SMSR:HKLM\...\startupreg\PrivDogService [Key] . (.AdTrustMedia - PrivDog Service.) -- C:\Program Files (x86)\AdTrustMedia\PrivDog\1.8.0.15\trustedadssvc.exe O53 - SMSR:HKLM\...\startupreg\RESTART_STICKY_NOTES [Key] . (.Microsoft Corporation - Pense-bête.) -- C:\Windows\System32\StikyNot.exe =>.Microsoft Corporation O53 - SMSR:HKLM\...\startupreg\RtHDVCpl [Key] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp O53 - SMSR:HKLM\...\startupreg\SNUVCDSM [Key] . (.Pas de propriétaire - DisplaySettingMonitor MFC Application.) -- C:\Windows\snuvcdsm.exe O53 - SMSR:HKLM\...\startupreg\StartCCC [Key] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe =>.Advanced Micro Devices, Inc O53 - SMSR:HKLM\...\startupreg\swg [Key] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O53 - SMSR:HKLM\...\startupreg\SynTPEnh [Key] . (...) -- C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\VitaKeyPdtWzd [Key] . (.Egis Technology Inc. - PdtWzd.exe.) -- C:\Program Files (x86)\Acer Bio Protection\PdtWzd.exe ~ SMSR Keys: 25 Scanned in 00mn 00s ---\\ Enumération des clés de registre SecurityProviders (MCSP) (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll ~ MSCP: 2 Scanned in 00mn 00s ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0 O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 16 Scanned in 00mn 00s ---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56) O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0 ~ MWPE Keys: 3 Scanned in 00mn 00s ---\\ Liste des pilotes du système (SDL) (O58) O58 - SDL:14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088] O58 - SDL:14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [339536] O58 - SDL:14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\Drivers\adpu320.sys [182864] O58 - SDL:14/07/2009 - 02:52:21 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [15440] O58 - SDL:05/10/2014 - 03:05:58 ---A- . (.Advanced Micro Devices - AMD ACP Kernel Service Driver.) -- C:\Windows\System32\Drivers\amdacpksd.sys [293064] O58 - SDL:11/03/2011 - 07:41:12 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [107904] O58 - SDL:14/07/2009 - 02:52:20 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows -.) -- C:\Windows\System32\Drivers\amdsbs.sys [194128] O58 - SDL:11/03/2011 - 07:41:12 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [27008] O58 - SDL:14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [87632] O58 - SDL:14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [97856] O58 - SDL:13/07/2014 - 19:37:34 ---A- . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN device driver.) -- C:\Windows\System32\Drivers\athrx.sys [4059136] O58 - SDL:13/11/2009 - 01:58:52 ---A- . (.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\Drivers\atikmdag.sys [6107136] O58 - SDL:05/10/2014 - 02:31:18 ---A- . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\System32\Drivers\atikmpag.sys [576000] O58 - SDL:18/06/2014 - 20:03:34 ---A- . (.AVG Technologies CZ, s.r.o. - AVG File Vault Driver.) -- C:\Windows\System32\Drivers\avgdiska.sys [153368] O58 - SDL:24/07/2014 - 13:06:36 ---A- . (.AVG Technologies CZ, s.r.o. - AVG IDS Application Activity Monitor Driver..) -- C:\Windows\System32\Drivers\avgidsdrivera.sys [247576] O58 - SDL:18/06/2014 - 20:03:34 ---A- . (.AVG Technologies CZ, s.r.o. - AVG Application Activity Monitor Helper Driver.) -- C:\Windows\System32\Drivers\avgidsha.sys [190744] O58 - SDL:20/08/2014 - 20:45:10 ---A- . (.AVG Technologies CZ, s.r.o. - AVG AVI Loader Driver.) -- C:\Windows\System32\Drivers\avgldx64.sys [243480] O58 - SDL:18/07/2014 - 14:53:26 ---A- . (.AVG Technologies CZ, s.r.o. - AVG Logging Driver.) -- C:\Windows\System32\Drivers\avgloga.sys [313624] O58 - SDL:06/08/2014 - 20:39:52 ---A- . (.AVG Technologies CZ, s.r.o. - AVG Resident Shield Minifilter Driver.) -- C:\Windows\System32\Drivers\avgmfx64.sys [123672] O58 - SDL:18/06/2014 - 20:03:20 ---A- . (.AVG Technologies CZ, s.r.o. - AVG Anti-Rootkit Driver.) -- C:\Windows\System32\Drivers\avgrkx64.sys [31512] O58 - SDL:02/07/2014 - 08:58:24 ---A- . (.AVG Technologies CZ, s.r.o. - AVG Network connection watcher.) -- C:\Windows\System32\Drivers\avgtdia.sys [270616] O58 - SDL:10/06/2009 - 21:34:23 ---A- . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver..) -- C:\Windows\System32\Drivers\b57nd60a.sys [270848] O58 - SDL:10/06/2009 - 21:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [18432] O58 - SDL:10/06/2009 - 21:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [8704] O58 - SDL:14/07/2009 - 02:19:07 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [286720] O58 - SDL:10/06/2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [47104] O58 - SDL:10/06/2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [14976] O58 - SDL:10/06/2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [14720] O58 - SDL:10/06/2009 - 21:34:28 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbda.sys [468480] O58 - SDL:16/04/2014 - 21:12:56 ---A- . (.COMODO - COMODO Internet Security Eradication Driver.) -- C:\Windows\System32\Drivers\cmderd.sys [23168] O58 - SDL:16/04/2014 - 21:12:56 ---A- . (.COMODO - COMODO Internet Security Sandbox Driver.) -- C:\Windows\System32\Drivers\cmdguard.sys [738472] O58 - SDL:16/04/2014 - 21:12:58 ---A- . (.COMODO - COMODO Internet Security Helper Driver.) -- C:\Windows\System32\Drivers\cmdhlp.sys [48360] O58 - SDL:14/07/2009 - 02:52:31 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [17488] O58 - SDL:14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496] O58 - SDL:13/08/2014 - 23:52:08 ---A- . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Backup Driver.) -- C:\Windows\System32\Drivers\eubakup.sys [61000] O58 - SDL:13/08/2014 - 23:52:08 ---A- . (...) -- C:\Windows\System32\Drivers\EUBKMON.sys [48200] O58 - SDL:13/08/2014 - 23:52:08 ---A- . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Access Driver.) -- C:\Windows\System32\Drivers\eudskacs.sys [18504] O58 - SDL:13/08/2014 - 23:52:08 ---A- . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Backup Image Preview Driver.) -- C:\Windows\System32\Drivers\EuFdDisk.sys [189000] O58 - SDL:10/06/2009 - 21:34:33 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbda.sys [3286016] O58 - SDL:28/09/2014 - 19:18:58 ---A- . (.EgisTec - Fingerprint Sensor Driver.) -- C:\Windows\System32\Drivers\FPSensor.sys [36400] O58 - SDL:10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232] O58 - SDL:17/09/2009 - 18:54:54 ---A- . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\Drivers\HECIx64.sys [56344] O58 - SDL:01/09/2009 - 00:36:18 ---A- . (.Windows (R) Win 7 DDK provider - SHIM filter for KMDF HIDMINI driver.) -- C:\Windows\System32\Drivers\hidshim.sys [6656] O58 - SDL:20/11/2010 - 14:33:35 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [78720] O58 - SDL:13/10/2009 - 20:16:40 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\Drivers\iaStor.sys [409624] O58 - SDL:11/03/2011 - 07:41:26 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\Drivers\iaStorV.sys [410496] O58 - SDL:14/07/2009 - 02:48:04 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [44112] O58 - SDL:12/10/2009 - 12:00:52 ---A- . (.Intel Corporation - Intel(R) Turbo Boost Technology Driver.) -- C:\Windows\System32\Drivers\Impcd.sys [151040] O58 - SDL:16/04/2014 - 21:12:58 ---A- . (.COMODO - COMODO Internet Security Firewall Driver.) -- C:\Windows\System32\Drivers\inspect.sys [105552] O58 - SDL:24/08/2009 - 13:10:40 ---A- . (.JMicron - OHCI1394 upper filter driver.) -- C:\Windows\System32\Drivers\johci.sys [22640] O58 - SDL:05/11/2013 - 05:02:16 ---A- . (.Broadcom Corporation - Broadcom NetLink (TM) Gigabit Ethernet NDIS6.x Unified Driver..) -- C:\Windows\System32\Drivers\k57nd60a.sys [458960] O58 - SDL:14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [114752] O58 - SDL:14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [106560] O58 - SDL:14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [65600] O58 - SDL:14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [115776] O58 - SDL:14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for.) -- C:\Windows\System32\Drivers\megasas.sys [35392] O58 - SDL:14/07/2009 - 02:48:04 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [284736] O58 - SDL:02/06/2009 - 12:15:30 ---A- . (.Egis Technology Inc. - PSD Filter Driver.) -- C:\Windows\System32\Drivers\mwlPSDFilter.sys [22576] O58 - SDL:02/06/2009 - 12:15:30 ---A- . (.Egis Technology Inc. - MyWinLocker PSD Named Pipe Driver.) -- C:\Windows\System32\Drivers\mwlPSDNserv.sys [20016] O58 - SDL:02/06/2009 - 12:15:30 ---A- . (.Egis Technology Inc. - MyWinLocker PSD Virtual Disk Driver.) -- C:\Windows\System32\Drivers\mwlPSDVDisk.sys [60464] O58 - SDL:15/09/2009 - 05:40:42 ---A- . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\Windows\System32\Drivers\NETw5s64.sys [6952960] O58 - SDL:14/07/2009 - 02:48:26 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [51264] O58 - SDL:05/05/2009 - 09:46:08 ---A- . (.NewTech Infosystems, Inc. - NTI CD-ROM Filter Driver.) -- C:\Windows\System32\Drivers\NTIDrvr.sys [18432] O58 - SDL:31/08/2009 - 21:42:04 ---A- . (.Nuvoton Technology Corporation - Nuvoton MCE CIR Port Driver.) -- C:\Windows\System32\Drivers\nuvotoncir.sys [48128] O58 - SDL:01/09/2009 - 00:36:16 ---A- . (.Nuvoton Technology Corporation - Nuvoton HID CIR Receiver.) -- C:\Windows\System32\Drivers\nuvotonhidcir.sys [26624] O58 - SDL:31/08/2009 - 22:45:20 ---A- . (.Nuvoton Technology Corporation - Nuvoton MC CIR Port Driver.) -- C:\Windows\System32\Drivers\nuvotonir.sys [68096] O58 - SDL:11/03/2011 - 07:41:34 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [148352] O58 - SDL:11/03/2011 - 07:41:34 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [166272] O58 - SDL:13/01/2014 - 22:50:42 ---A- . (.Christian Gulden - Pluralinput Mouse Driver.) -- C:\Windows\System32\Drivers\pimou.sys [23608] O58 - SDL:14/07/2009 - 02:45:46 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1524816] O58 - SDL:14/07/2009 - 02:45:45 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [128592] O58 - SDL:24/06/2009 - 11:23:00 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver.) -- C:\Windows\System32\Drivers\RtHDMIVX.sys [205472] O58 - SDL:13/10/2009 - 10:39:00 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver.) -- C:\Windows\System32\Drivers\RTKVHD64.sys [2015520] O58 - SDL:10/06/2009 - 21:37:19 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [23040] O58 - SDL:14/07/2009 - 02:45:45 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [43584] O58 - SDL:14/07/2009 - 02:45:46 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [80464] O58 - SDL:12/02/2010 - 15:12:00 ---A- . (.Pas de propriétaire - USBCAMD for Sonix UVC.) -- C:\Windows\System32\Drivers\sncduvc.sys [40960] O58 - SDL:12/02/2010 - 15:12:00 ---A- . (.Pas de propriétaire - UVC Camera Streaming Driver.) -- C:\Windows\System32\Drivers\snp2uvc.sys [1806592] O58 - SDL:14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656] O58 - SDL:17/09/2009 - 13:12:06 ---A- . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\Windows\System32\Drivers\SynTP.sys [292912] O58 - SDL:02/11/2009 - 11:48:02 ---A- . (...) -- C:\Windows\System32\Drivers\TurboB.sys [13784] O58 - SDL:05/05/2009 - 09:46:08 ---A- . (.NewTech Infosystems Corporation - NTI CDROM Filter Driver.) -- C:\Windows\System32\Drivers\UBHelper.sys [16896] O58 - SDL:14/07/2009 - 02:45:55 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [17488] O58 - SDL:14/07/2009 - 02:45:55 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [161872] O58 - SDL:07/03/2013 - 08:49:18 ---A- . (...) -- C:\Windows\System32\epmntdrv.sys [17480] O58 - SDL:07/03/2013 - 08:49:18 ---A- . (...) -- C:\Windows\System32\EuGdiDrv.sys [9800] O58 - SDL:26/03/2009 - 04:16:08 ---A- . (.Dritek System Inc. - Dritek 64-bit PS/2 Keyboard Filter Driver.) -- C:\Windows\SysWOW64\drivers\DKbFltr.sys [25608] O58 - SDL:07/03/2013 - 08:49:20 ---A- . (...) -- C:\Windows\SysWOW64\epmntdrv.sys [13896] O58 - SDL:07/03/2013 - 08:49:20 ---A- . (...) -- C:\Windows\SysWOW64\EuGdiDrv.sys [9160] ~ Drivers: 89 Scanned in 00mn 05s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC: 13/10/2014 - 10:38:59 ---A- . (.AVAST Software.) -- C:\Users\judiflo\Downloads\avast_free_antivirus_setup_online.exe [4862664] O61 - LFC: 14/10/2014 - 10:38:54 ---A- . (...) -- C:\Users\judiflo\AppData\Local\Temp\vlc-2.1.5-win64.exe [24658468] O61 - LFC: 14/10/2014 - 10:38:54 ---A- . (.Microsoft Corporation.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\gdi32.dll [287744] O61 - LFC: 14/10/2014 - 10:38:54 ---A- . (.Microsoft Corporation.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\kernel32.dll [990208] O61 - LFC: 14/10/2014 - 10:38:54 ---A- . (.Microsoft Corporation.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\mfc90.dll [1156600] O61 - LFC: 14/10/2014 - 10:38:54 ---A- . (.Microsoft Corporation.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\mfc90u.dll [1162744] O61 - LFC: 14/10/2014 - 10:38:54 ---A- . (.Microsoft Corporation.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\mfcm90.dll [59904] O61 - LFC: 14/10/2014 - 10:38:54 ---A- . (.Microsoft Corporation.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\mfcm90u.dll [59904] O61 - LFC: 14/10/2014 - 10:38:54 ---A- . (.Microsoft Corporation.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\msvcp100.dll [421200] O61 - LFC: 14/10/2014 - 10:38:54 ---A- . (.Microsoft Corporation.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\msvcr100.dll [773968] O61 - LFC: 14/10/2014 - 10:38:54 ---A- . (.Microsoft Corporation.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\psapi.dll [23040] O61 - LFC: 14/10/2014 - 10:38:55 ---A- . (...) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\PyWinTypes27.dll [110080] O61 - LFC: 14/10/2014 - 10:38:55 ---A- . (...) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\pythoncom27.dll [364544] O61 - LFC: 14/10/2014 - 10:38:55 ---A- . (.Microsoft Corporation.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\shell32.dll [8462848] O61 - LFC: 14/10/2014 - 10:38:55 ---A- . (.Python Software Foundation.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\python27.dll [2449920] O61 - LFC: 14/10/2014 - 10:38:55 ---A- . (.wxWidgets development team.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\wxbase294u_net_vc90.dll [154112] O61 - LFC: 14/10/2014 - 10:38:56 ---A- . (.wxWidgets development team.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\wxbase294u_vc90.dll [1985024] O61 - LFC: 14/10/2014 - 10:38:56 ---A- . (.wxWidgets development team.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\wxmsw294u_adv_vc90.dll [1234944] O61 - LFC: 14/10/2014 - 10:38:56 ---A- . (.wxWidgets development team.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\wxmsw294u_core_vc90.dll [4598272] O61 - LFC: 14/10/2014 - 10:38:56 ---A- . (.wxWidgets development team.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\wxmsw294u_html_vc90.dll [595968] O61 - LFC: 14/10/2014 - 10:38:56 ---A- . (.wxWidgets development team.) -- C:\Users\judiflo\AppData\Local\Temp\_MEI47842\wxmsw294u_webview_vc90.dll [91648] O61 - LFC: 15/10/2014 - 10:38:51 ---A- . (...) -- C:\Users\judiflo\AppData\Local\Microsoft\Internet Explorer\UrlBlockManager\urlblocklist.bin [0] O61 - LFC: 15/10/2014 - 10:39:01 ---A- . (.EaseUS.) -- C:\Users\judiflo\Downloads\easeus-partition-master-free_10_fr_306186.exe [39417760] O61 - LFC: 18/10/2014 - 10:38:54 ---A- . (...) -- C:\Users\judiflo\AppData\Local\Temp\MCConfigNsis\mcsetup.exe [5923168] O61 - LFC: 18/10/2014 - 10:38:56 ---A- . (.Acresso Software Inc..) -- C:\Users\judiflo\AppData\Local\Temp\{7693B3B9-A8D2-4AD5-A294-0781EB928E95}\ISBEW64.exe [107320] O61 - LFC: 18/10/2014 - 10:38:56 ---A- . (.Acresso Software Inc..) -- C:\Users\judiflo\AppData\Local\Temp\{7693B3B9-A8D2-4AD5-A294-0781EB928E95}\ISRT.dll [261424] O61 - LFC: 18/10/2014 - 10:38:56 ---A- . (.Acresso Software Inc..) -- C:\Users\judiflo\AppData\Local\Temp\{7693B3B9-A8D2-4AD5-A294-0781EB928E95}\_isres_0x0409.dll [558512] O61 - LFC: 18/10/2014 - 10:39:00 ---A- . (...) -- C:\Users\judiflo\Downloads\defraggler-portable_2-18-945_fr_44314\statistics.bin [1456] O61 - LFC: 19/10/2014 - 10:38:46 ---A- . (...) -- C:\Users\judiflo\AppData\Local\Google\Chrome\User Data\nacl_validation_cache.bin [128] O61 - LFC: 19/10/2014 - 10:38:56 ----- . (.Macrovision Corporation.) -- C:\Users\judiflo\AppData\Local\Temp\{372171F5-80FB-4216-AEFB-76FF51A743E6}\ISBEW64.exe [115200] O61 - LFC: 19/10/2014 - 10:38:56 ----- . (.Macrovision Corporation.) -- C:\Users\judiflo\AppData\Local\Temp\{7D53ACF3-6D97-436D-8CF2-68EBD7934A82}\ISBEW64.exe [115200] O61 - LFC: 19/10/2014 - 10:38:56 ----- . (.Macrovision Corporation.) -- C:\Users\judiflo\AppData\Local\Temp\{7E34C7EB-2C6E-4EC0-B263-CDD1EAD26DE6}\ISBEW64.exe [115200] O61 - LFC: 19/10/2014 - 10:39:01 ---A- . (.Soluto Inc.) -- C:\Users\judiflo\Downloads\soluto_1-3-1328-0_fr_429536.exe [1511488] O61 - LFC: 20/10/2014 - 10:38:56 R--A- . (...) -- C:\Users\judiflo\AppData\Roaming\Microsoft\Installer\{251FE4A5-6769-60A5-8442-8D7B30610C0C}\ARPPRODUCTICON.exe [10134] O61 - LFC: 20/10/2014 - 10:38:59 ---A- . (.Nicolas Coolman.) -- C:\Users\judiflo\Desktop\ZHPDiag2.exe [6862284] =>.Nicolas Coolman ~ 384 Fichiers temporaires (Temporary files) ~ 47 Fichiers cookies (Cookies files) ~ Files: 35 Scanned in 00mn 21s ---\\ Liste des outils de désinfection (LATC) (O63) O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn 00s ---\\ Liste les services legacy du registre (LALS) (O64) O64 - Services: CurCS - 18/06/2014 - C:\Windows\System32\DRIVERS\avgdiska.sys (Avgdiska) .(.AVG Technologies CZ, s.r.o. - AVG File Vault Driver.) - LEGACY_AVGDISKA O64 - Services: CurCS - 24/07/2014 - C:\Windows\System32\DRIVERS\avgidsdrivera.sys (AVGIDSDriver) .(.AVG Technologies CZ, s.r.o. - AVG IDS Application Activity Monitor Driver.) - LEGACY_AVGIDSDRIVER O64 - Services: CurCS - 18/06/2014 - C:\Windows\System32\DRIVERS\avgidsha.sys (AVGIDSHA) .(.AVG Technologies CZ, s.r.o. - AVG Application Activity Monitor Helper Dri.) - LEGACY_AVGIDSHA O64 - Services: CurCS - 20/08/2014 - C:\Windows\System32\DRIVERS\avgldx64.sys (Avgldx64) .(.AVG Technologies CZ, s.r.o. - AVG AVI Loader Driver.) - LEGACY_AVGLDX64 O64 - Services: CurCS - 18/07/2014 - C:\Windows\System32\DRIVERS\avgloga.sys (Avgloga) .(.AVG Technologies CZ, s.r.o. - AVG Logging Driver.) - LEGACY_AVGLOGA O64 - Services: CurCS - 06/08/2014 - C:\Windows\System32\DRIVERS\avgmfx64.sys (Avgmfx64) .(.AVG Technologies CZ, s.r.o. - AVG Resident Shield Minifilter Driver.) - LEGACY_AVGMFX64 O64 - Services: CurCS - 18/06/2014 - C:\Windows\System32\DRIVERS\avgrkx64.sys (Avgrkx64) .(.AVG Technologies CZ, s.r.o. - AVG Anti-Rootkit Driver.) - LEGACY_AVGRKX64 O64 - Services: CurCS - 02/07/2014 - C:\Windows\System32\DRIVERS\avgtdia.sys (Avgtdia) .(.AVG Technologies CZ, s.r.o. - AVG Network connection watcher.) - LEGACY_AVGTDIA O64 - Services: CurCS - 16/04/2014 - C:\Windows\System32\DRIVERS\cmderd.sys (cmderd) .(.COMODO - COMODO Internet Security Eradication Driver.) - LEGACY_CMDERD O64 - Services: CurCS - 16/04/2014 - C:\Windows\System32\DRIVERS\cmdguard.sys (cmdGuard) .(.COMODO - COMODO Internet Security Sandbox Driver.) - LEGACY_CMDGUARD O64 - Services: CurCS - 16/04/2014 - C:\Windows\System32\DRIVERS\cmdhlp.sys (cmdHlp) .(.COMODO - COMODO Internet Security Helper Driver.) - LEGACY_CMDHLP O64 - Services: CurCS - 13/08/2014 - C:\Windows\System32\drivers\EUBKMON.sys (EUBKMON) .(...) - LEGACY_EUBKMON O64 - Services: CurCS - 13/08/2014 - C:\Windows\system32\drivers\eudskacs.sys (EUDSKACS) .(.CHENGDU YIWO Tech Development Co., Ltd - Disk Access Driver.) - LEGACY_EUDSKACS O64 - Services: CurCS - 13/08/2014 - C:\Windows\system32\drivers\EuFdDisk.sys (EUFDDISK) .(.CHENGDU YIWO Tech Development Co., Ltd - Disk Backup Image Preview Driver.) - LEGACY_EUFDDISK O64 - Services: CurCS - 16/04/2014 - C:\Windows\System32\DRIVERS\inspect.sys (inspect) .(.COMODO - COMODO Internet Security Firewall Driver.) - LEGACY_INSPECT O64 - Services: CurCS - 24/08/2009 - C:\Windows\System32\DRIVERS\johci.sys (johci) .(.JMicron - OHCI1394 upper filter driver.) - LEGACY_JOHCI O64 - Services: CurCS - 02/06/2009 - C:\Windows\System32\DRIVERS\mwlPSDFilter.sys (mwlPSDFilter) .(.Egis Technology Inc. - PSD Filter Driver.) - LEGACY_MWLPSDFILTER O64 - Services: CurCS - 02/06/2009 - C:\Windows\System32\DRIVERS\mwlPSDNServ.sys (mwlPSDNServ) .(.Egis Technology Inc. - MyWinLocker PSD Named Pipe Driver.) - LEGACY_MWLPSDNSERV O64 - Services: CurCS - 02/06/2009 - C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys (mwlPSDVDisk) .(.Egis Technology Inc. - MyWinLocker PSD Virtual Disk Driver.) - LEGACY_MWLPSDVDISK O64 - Services: CurCS - 10/06/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV O64 - Services: CurCS - 02/11/2009 - C:\Windows\System32\DRIVERS\TurboB.sys (TurboB) .(...) - LEGACY_TURBOB ~ Legacy: 100 Scanned in 00mn 00s ---\\ Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Not Key.) ~ FASS Keys: 11 Scanned in 00mn 00s ---\\ Menu de démarrage Internet (SMI) (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {67A2568C-7A0A-4EED-AECC-B5405DE63B64} - (Google) - http://www.google.com O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - http://www.google.com O69 - SBI: SearchScopes [HKCU] {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} - (Yahoo! Search) - http://fr.search.yahoo.com ~ Keys: Scanned in 00mn 00s ---\\ Enumère les service demarrés par Svchost (SSS) (O83) O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [236032] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [777728] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [859648] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [679424] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [99328] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [344064] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [64512] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [359424] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [316928] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [681984] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2477536] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [849920] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [370688] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [569344] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [30720] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70144] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [156672] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [67584] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [242688] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [121856] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136704] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1110016] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [90624] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84480] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [209920] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [44544] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864] ~ Services: 32 Scanned in 00mn 00s ---\\ Recherche particulière à la racine du système (SPRF) (O84) [MD5.62B7C506B092D460898F3296DA94B728] [SPRF][18/07/2009] (.Oberon Media - FullRemove.) -- C:\ProgramData\FullRemove.exe [36136] [MD5.D41D8CD98F00B204E9800998ECF8427E] [SPRF][28/09/2014] (...) -- C:\Users\judiflo\AppData\Roaming\wklnhst.dat [0] [MD5.3D451F62411C7E1758924458A69703C1] [SPRF][20/10/2014] (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Users\judiflo\Desktop\ZHPDiag2.exe [6862284] ~ Files: 3 Scanned in 00mn 00s ---\\ Liste des exceptions du parefeu (FirewallRules) (O87) O87 - FAEL: "{9EDAEC3A-7F42-4E04-A43A-4C6330A02B68}" | In - None - P6 - TRUE | .(.BitTorrent Inc. - µTorrent.) -- C:\Users\judiflo\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent O87 - FAEL: "{11E0552C-D7F1-4D17-AFE4-79BECC75B850}" | In - None - P17 - TRUE | .(.BitTorrent Inc. - µTorrent.) -- C:\Users\judiflo\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent ~ Firewall: 2 Scanned in 00mn 01s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 19/10/2014 267440 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe SS - | Demand 25/03/2014 2264280 | (cmdvirth) . (.COMODO.) - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe SS - | Demand 08/10/2014 654848 | (FLEXnet Licensing Service) . (.Macrovision Europe Ltd..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe SS - | Auto 28/09/2014 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 28/09/2014 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 02/12/2009 182768 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe SS - | Demand 24/09/2014 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe SS - | Demand 10/09/2009 305448 | (MWLService) . (.Egis Technology Inc..) - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe SS - | Demand 06/11/2009 50432 | (NTIBackupSvc) . (.NewTech InfoSystems, Inc..) - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe SS - | Demand 02/12/2009 332272 | (Partner Service) . (.Google Inc..) - C:\ProgramData\Partner\Partner.exe SS - | Demand 02/11/2009 126352 | (TurboBoost) . (.Intel(R) Corporation.) - C:\Program Files\Intel\TurboBoost\TurboBoost.exe SS - | Demand 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 13/11/2009 202752 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe SR - | Auto 05/09/2014 3364368 | (AVGIDSAgent) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe SR - | Auto 05/09/2014 293448 | (avgwd) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe SR - | Auto 28/02/2006 229376 | (Bonjour Service) . (.Apple Computer, Inc..) - C:\Program Files (x86)\Bonjour\mDNSResponder.exe SR - | Auto 16/04/2014 6817544 | (CmdAgent) . (.COMODO.) - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe SR - | Auto 13/08/2014 37448 | (EaseUS Agent) . (.CHENGDU YIWO Tech Development Co., Ltd.) - C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe SR - | Auto 03/12/2009 788512 | (ePowerSvc) . (.Acer Incorporated.) - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe SR - | Auto 28/08/2009 1150496 | (Greg_Service) . (.Acer Incorporated.) - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe SR - | Auto 13/10/2009 354840 | (IAANTMON) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe SR - | Auto 11/12/2009 3450368 | (IGBASVC) . (.Egis Technology Inc..) - C:\Program Files (x86)\Acer Bio Protection\BASVC.exe SR - | Auto 30/09/2009 262144 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe SR - | Auto 24/06/2014 2820424 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe SR - | Auto 29/10/2009 255744 | (NTI IScheduleSvc) . (.NewTech Infosystems, Inc..) - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe SR - | Auto 06/11/2009 144640 | (NTISchedulerSvc) . (.NewTech Infosystems, Inc..) - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe SR - | Auto 10/07/2009 253952 | (RS_Service) . (.Acer Incorporated.) - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe SR - | Auto 30/09/2009 2314240 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe SR - | Auto 04/07/2009 240160 | (Updater Service) . (.Acer.) - C:\Program Files\Acer\Acer Updater\UpdaterService.exe SR - | Demand 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Services: Scanned in 00mn 07s ---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80) Run by judiflo at 20/10/2014 10:40:03 ~ OS 64 not supported by MBR tool ~ MBR: 0 Scanned in 00mn 00s ---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by judiflo at 20/10/2014 10:40:05 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 02s ---\\ Scan Additionnel (O88) Database Version : 13026 - (18/10/2014) Clés trouvées (Keys found) : 10 Valeurs trouvées (Values found) : 1 Dossiers trouvés (Folders found) : 1 Fichiers trouvés (Files found) : 1 [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent] =>P2P.BitTorrent^ [HKLM\Software\Classes\AppID\{28A88B70-D874-4f73-BBBA-9B2B222FB7D6}] =>Adware.BHO [HKLM\Software\Wow6432Node\Classes\AppID\{28A88B70-D874-4f73-BBBA-9B2B222FB7D6}] =>Adware.BHO [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}] =>Spyware.BHO [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}] =>Spyware.BHO [HKLM\Software\Classes\CLSID\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}] =>Spyware.BHO [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}] =>Spyware.BHO [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}] =>Spyware.BHO [HKLM\Software\Classes\protector_dll.protectorbho.1] =>PUP.BProtector [HKLM\Software\Classes\protector_dll.protectorbho] =>PUP.BProtector C:\Users\judiflo\AppData\Roaming\uTorrent =>P2P.µTorrent^ [HKCU\Software\BitTorrent] =>P2P.BitTorrent^ ~ Additionnel Scan: 291958 Items scanned in 00mn 26s ---\\ Informations complémentaires sur les modules ~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5) ~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects de navigateur (O2) ~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3) ~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4) ~ AMI: 4 Scanned in 00mn 00s ---\\ Récapitulatif des détections trouvées sur votre station http://www.nicolascoolman.fr/blog/ =>Adware.BHO http://www.nicolascoolman.fr/blog/ =>Spyware.BHO http://nicolascoolman.fr/pup-bprotector =>PUP.BProtector ~ MSI: 3 link(s) detected in 00mn 00s End of the scan (1439 lines in 03mn 35s)(0)