> Tous les forums > Forum Sécurité
 Windows 7 Familial Premium: explorateur windowsSujet résolu
Ajouter un message à la discussion
Pages : [1] 2 3 ... Fin
Page 1 sur 3 [Fin]
novotek
  Posté le 10/03/2015 @ 00:37 
Aller en bas de la page 
Petit astucien

bonsoir,

A partir de hier je ne peux plus ouvrir ni poste de travail, ni panneau de configuration, ni les dossiers sur les disques dur, ni personnalisation. :(

Mon ordi a été infecté par 500 viruses et troyanes qui sont venus hier. Maintenant il est propre. Hier j'ai nettoyé mon ordi completement. Et j'ai fait un scan de mon ordi après le rédemarrage. Mais explorateur windows ne s'ouvre plus. J'ai essayé de le recouperer par le fichier "explorer.exe" de mon CD-ROM Windows 7, mais ça ne change rien. Je ne sais pas quoi faire. Pourriez vous m'aider de marcher "explorer.exe" (explorateur windows)? J'ai voulu mettre ici les screenshots, mais je ne sais pas comment faire ça.

Aidez moi s'il vous plait, resoudre mon probleme. Je suis débutant dans l'informatique.

Publicité
flober
 Posté le 10/03/2015 à 00:44 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucienne
novotek
 Posté le 10/03/2015 à 01:06 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

Bonsoir,

j'ai fait la diagnostique par ZHPdiag, mais je n'ai pas trouvé ici l'option "inserer un rapport" :(

comment je peux vous envoyer le rapport?

J'ai fait le nettoyage de mon ordi hier par Microsoft Windows Essentiel et Malwarebyte Antimalware. Tout est propre. Que l'explorateur windows est completement endommagé et je ne peux plus le recuperer.

flober
 Posté le 10/03/2015 à 01:11 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucienne

tout en bas du rapport de ZHPdiag

sélectionne le dernier paragraphe Copie/coller et transmet le moi.

novotek
 Posté le 10/03/2015 à 01:28 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

Je n'arrive pas ajouter le rapport ici, car la page de votre forum me dit ça:

Request object error 'ASP 0104 : 80004005'

Operation not Allowed

/inc_haut.asp, line 46

il y a un autre moyen pour vous envoyer le rapport?

flober
 Posté le 10/03/2015 à 01:38 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucienne

Sélectionne uniquement le dernier paragraphe a l'aide de la souris en passant dessus en pressant clic gauche puis dans ta nouvelle réponse colle la.

@



Modifié par flober le 10/03/2015 01:40
novotek
 Posté le 10/03/2015 à 01:43 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

par ici, ça va?

---\\ List all legacy services(LALS) (O64)

O64 - Services: CurCS - 10.01.2011 - C:\Windows\System32\DRIVERS\AppleCharger.sys (AppleCharger) .(...) - LEGACY_APPLECHARGER

O64 - Services: CurCS - 02.12.2012 - C:\Windows\System32\drivers\gfibto.sys (gfibto) .(.GFI Software - GFI Boot Time Operations Driver.) - LEGACY_GFIBTO

O64 - Services: CurCS - 27.02.2014 - C:\Windows\system32\drivers\hcmon.sys (hcmon) .(.VMware, Inc. - VMware USB monitor.) - LEGACY_HCMON

O64 - Services: CurCS - 07.03.2015 - C:\Windows\sysWOW64\drivers\HWiNFO64A.sys (HWiNFO32) .(.REALiX(tm) - HWiNFO AMD64 Kernel Driver.) - LEGACY_HWINFO32

O64 - Services: CurCS - 21.11.2014 - C:\Windows\system32\drivers\mbamchameleon.sys (mbamchameleon) .(.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) - LEGACY_MBAMCHAMELEON

O64 - Services: CurCS - 21.11.2014 - C:\Windows\system32\drivers\mbam.sys (MBAMProtector) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMPROTECTOR

O64 - Services: CurCS - 01.03.2013 - C:\Windows\System32\drivers\npf.sys (NPF) .(.Riverbed Technology, Inc. - npf.sys (NT5/6 AMD64) Kernel Driver.) - LEGACY_NPF

O64 - Services: CurCS - 10.06.2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV

O64 - Services: CurCS - 01.07.2010 - C:\Program Files\Unlocker\UnlockerDriver5.sys (UnlockerDriver5) .(...) - LEGACY_UNLOCKERDRIVER5

O64 - Services: CurCS - 19.12.2012 - C:\Users\GELO\Desktop\VirtualBox 4.2.6 82870 Portable\App\VirtualBox\drivers\USB\filter\VBoxUSBMon.sys (VBoxUSBMon) .(.Oracle Corporation - VirtualBox USB Monitor Driver.) - LEGACY_VBOXUSBMON

O64 - Services: CurCS - 29.10.2014 - C:\Windows\System32\DRIVERS\vmnetbridge.sys (VMnetBridge) .(.VMware, Inc. - VMware bridge driver (64-bit).) - LEGACY_VMNETBRIDGE

O64 - Services: CurCS - 29.10.2014 - C:\Windows\system32\drivers\vmnetuserif.sys (VMnetuserif) .(.VMware, Inc. - VMware network application interface driver.) - LEGACY_VMNETUSERIF

O64 - Services: CurCS - 29.10.2014 - C:\Windows\system32\drivers\vmx86.sys (vmx86) .(.VMware, Inc. - VMware kernel driver.) - LEGACY_VMX86

O64 - Services: CurCS - 08.10.2013 - C:\Windows\System32\drivers\vsock.sys (vsock) .(.VMware, Inc. - VMware vSockets Service.) - LEGACY_VSOCK

~ Legacy: 94 Scanned in 00mn 08s

---\\ File Associations Shell Spawning (O67)

O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation

O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe

O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.html> <OperaStable>[HKLM\..\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\Launcher.exe

O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe

O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe

O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S

O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Not Key.)

~ FASS Keys: 11 Scanned in 00mn 00s

---\\ Start Menu Internet (SMI) (O68)

O68 - StartMenuInternet: <Aviator> <Aviator>[HKLM\..\Shell\open\Command] (.Not Key.)

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Not Key.)

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Not Key.)

O68 - StartMenuInternet: <k-meleon.exe> <K-Meleon>[HKLM\..\Shell\open\Command] (.Not Key.)

O68 - StartMenuInternet: <Lunascape6> <Lunascape6>[HKLM\..\Shell\open\Command] (.Not Key.)

O68 - StartMenuInternet: <Opera> <Opera>[HKLM\..\Shell\open\Command] (.Not Key.)

O68 - StartMenuInternet: <OperaStable> <Opera Stable>[HKLM\..\Shell\open\Command] (.Not Key.)

~ Keys: Scanned in 00mn 00s

---\\ Search Browser Infection (SBI) (O69)

O69 - SBI: prefs.js [GELO - blozzve3.default] user_pref("weboftrust.search.ask.display", "Ask.com Web Search");

O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com

O69 - SBI: SearchScopes [HKCU] {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} - (e) - http://rambler.ru

O69 - SBI: SearchScopes [HKCU] {231CE532-7C50-418F-AAFC-B14AA5118BD8} - (Translate.Ru) - http://rambler.ru

O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} [DefaultScope] - (Google) - http://www.google.com

O69 - SBI: SearchScopes [HKUS\.DEFAULT] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com

O69 - SBI: SearchScopes [HKUS\S-1-5-18] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com

~ Keys: Scanned in 00mn 00s

---\\ Search Svchost Services (SSS) (O83)

O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192]

O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384]

O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384]

O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [236032]

O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [777728]

O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [859648]

O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [680960]

O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [99328]

O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [344064]

O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792]

O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [64512]

O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [359424]

O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [316928]

O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [683520]

O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\system32\wuaueng.dll [2477536]

O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [849920]

O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [370688]

O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [569344]

O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [30720]

O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70144]

O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [156672]

O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [67584]

O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [219136]

O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [121856]

O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136704]

O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104]

O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1110016]

O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [90624]

O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84480]

O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [210432]

O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [44544]

O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864]

~ Services: 32 Scanned in 00mn 00s

---\\ Search Particular Root Folder (SPRF) (O84)

[MD5.6CD985C9E791C4D9F6441C9C360CA5BB] [SPRF][14.08.2013] (...) -- C:\ProgramData\fontcacheev1.dat [389]

[MD5.F1D3FF8443297732862DF21DC4E57262] [SPRF][09.08.2014] (...) -- C:\Users\GELO\AppData\Roaming\wklnhst.dat [4]

[MD5.72695F5E580D1F66F933C64323520093] [SPRF][09.03.2015] (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Users\GELO\Desktop\ZHPDiag2.exe [6877328]

[MD5.CFE1AF5EE9CD57726695DC11941C0FB1] [SPRF][20.04.2011] (...) -- C:\Windows\Downloaded Program Files\WebInstallRunner.dll [43008]

~ Files: 4 Scanned in 00mn 00s

---\\ Firewall Active Exception List (FirewallRules) (O87)

O87 - FAEL: "TCP Query User{684C0968-BAD5-4925-A14F-B447D7ABFC88}E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe" | In - Public - P6 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe =>P2P.BitTorrent

O87 - FAEL: "UDP Query User{A1262EFB-21DF-4EF3-B28D-AFAC5BC49423}E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe" | In - Public - P17 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe =>P2P.BitTorrent

~ Firewall: 2 Scanned in 00mn 18s

---\\ Windows Installer Scan (WIS) (O93) (NTFS)

[MD5.013946FEC4064E014774D39623AA7CE4] [WIS][16.10.2013] (.APN, LLC - Sopcast Toolbar.) -- C:\Windows\Installer\346d8a5.msi [523264] =>Toolbar.Ask

~ WIS: 1 Scanned in 00mn 06s

---\\ General States of Services not Microsoft (EGS) (SR=Running, SS=Stopped)

SS - | Demand 09.02.2015 267440 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

SS - | Auto 22.07.1658 0 | (AdvancedSystemCareService8) . (...) - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ASCService.exe

SS - | Demand 06.04.2010 31272 | (AppleChargerSrv) . (...) - C:\Windows\System32\AppleChargerSrv.exe

SS - | Auto 22.07.1658 0 | (ASCAntivirusSrv) . (...) - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ascavsvc.exe

SS - | Auto 20.10.2014 107912 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

SS - | Demand 20.10.2014 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

SS - | Demand 14.08.2012 194032 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

SS - | Auto 22.07.1658 0 | (HitmanProScheduler) . (...) - C:\Program Files\HitmanPro\hmpsched.exe

SS - | Demand 14.11.2005 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

SS - | Demand 31.01.2014 887232 | (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe

SS - | Auto 22.07.1658 0 | (LiveUpdateSvc) . (...) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe

SS - | Auto 21.11.2014 969016 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe

SS - | Demand 05.03.2015 148592 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

SS - | Demand 09.10.2006 724992 | (NBService) . (.Nero AG.) - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe

SS - | Auto 08.04.2013 799280 | (PDF Architect Service) . (.pdfforge GmbH.) - C:\Program Files (x86)\PDF Architect\ConversionService.exe

SS - | Demand 01.03.2013 118520 | (rpcapd) . (.Riverbed Technology, Inc..) - C:\Program Files (x86)\WinPcap\rpcapd.exe

SS - | Demand 04.11.2008 68760 | (SandraAgentSrv) . (.SiSoftware.) - C:\Program Files\SiSoftware\SiSoftware Sandra Business 2013\RpcAgentSrv.exe

SS - | Auto 02.01.2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe

SS - | Demand 14.07.2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

SS - | Demand 22.07.1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation

SR - | Auto 14.05.2009 759048 | (ABBYY.Licensing.FineReader.Sprint.9.0) . (.ABBYY.) - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe

SR - | Auto 15.12.2011 917640 | (AcuWVSSchedulerv8) . (...) - C:\Program Files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe

SR - | Auto 03.12.2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

SR - | Auto 24.01.2012 21880 | (APC Data Service) . (.Schneider Electric.) - C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe

SR - | Auto 24.01.2012 705912 | (APC UPS Service) . (.Schneider Electric.) - C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe

SR - | Auto 12.02.2014 43336 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

SR - | Auto 30.08.2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe

SR - | Auto 06.03.2015 315240 | (cmcore) . (.Kingsoft Corporation.) - c:\program files (x86)\cmcm\Clean Master\cmcore.exe

SR - | Auto 21.02.2012 151648 | (EPSON_PM_RPCV4_04) . (.SEIKO EPSON CORPORATION.) - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.exe

SR - | Auto 14.02.2014 579584 | (HauppaugeTVServer) . (.Hauppauge Computer Works.) - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe

SR - | Auto 20.01.2014 2818896 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe

SR - | Auto 21.11.2014 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe

SR - | Auto 30.01.2015 23784 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe

SR - | Auto 18.08.2009 7599616 | (MySQL) . (...) - C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe

SR - | Auto 31.01.2013 878368 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe

SR - | Auto 19.02.2013 1259296 | (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

SR - | Auto 08.04.2013 1320496 | (PDF Architect Helper Service) . (.pdfforge GmbH.) - C:\Program Files (x86)\PDF Architect\HelperService.exe

SR - | Auto 17.01.2013 8704 | (RumoteVMCService) . (.Rumote.) - C:\Program Files (x86)\Rumote\RumoteVMC\RumoteMCEService.exe

SR - | Auto 10.09.2012 193392 | (SCPDFReadSpool) . (.Solid Documents, LLC.) - C:\Program Files (x86)\SolidDocuments\Solid Converter PDF\SCPDF\SolidConverterPDFServicex64.exe

SR - | Auto 28.03.2012 82944 | (SLService) . (...) - C:\Windows\System32\slmdmsr.exe

SR - | Demand 20.12.2014 820960 | (SystemExplorerHelpService) . (.Mister Group.) - C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe

SR - | Auto 29.10.2014 86744 | (VMAuthdService) . (.VMware, Inc..) - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe

SR - | Auto 22.07.1658 0 | (VMnetDHCP) . (.VMware, Inc..) - C:\Windows\system32\vmnetdhcp.exe

SR - | Auto 27.02.2014 906432 | (VMUSBArbService) . (.VMware, Inc..) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe

SR - | Auto 22.07.1658 0 | (VMware NAT Service) . (.VMware, Inc..) - C:\Windows\system32\vmnat.exe

SR - | Auto 14.07.2009 27136 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

SR - | Auto 08.09.2014 97280 | (_wfcs) . (.BiniSoft.org.) - C:\Program Files\Windows Firewall Control\wfcs.exe

~ Services: Scanned in 00mn 11s

---\\ Search Master Boot Record Infection (MBR)(O80)

Run by GELO at 09.03.2015 22:49:13

~ OS 64 not supported by MBR tool

~ MBR: 0 Scanned in 00mn 00s

---\\ Search Master Boot Record Infection (MBRCheck)(O80)

Written by ad13, http://ad13.geekstog

Run by GELO at 09.03.2015 22:49:15

********* Dump file Name *********

C:\PhysicalDisk0_MBR.bin

~ MBR: Scanned in 00mn 02s

---\\ Scan Additionnel (O88)

Database Version : 13008 - (08.03.2015)

Clés trouvées (Keys found) : 6

Valeurs trouvées (Values found) : 1

Dossiers trouvés (Folders found) : 5

Fichiers trouvés (Files found) : 6

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Applian FLV Player2.0.24] =>PUP.ApplianTechnologies^

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Applian FLV and Media Player] =>PUP.ApplianTechnologies^

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{53504356-3700-A76A-76A7-A758B70C0600}] =>Toolbar.Ask^

[HKLM\Software\Classes\Interface\{D6094FC6-821F-474C-8D73-C13066CD178D}] =>Toolbar.Agent

[HKLM\Software\Wow6432Node\Classes\Interface\{D6094FC6-821F-474C-8D73-C13066CD178D}] =>Toolbar.Agent

[HKLM\Software\Classes\AppID\secman.DLL] =>PUP.Babylon

C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\blozzve3.default\extensions\pavel.sherbakov@gmail.com =>PUP.QuickShare^

C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\extensions\pavel.sherbakov@gmail.com =>PUP.QuickShare^

C:\Program Files (x86)\Applian Technologies =>PUP.ApplianTechnologies^

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Applian Technologies =>PUP.ApplianTechnologies^

C:\Users\GELO\AppData\Roaming\Applian FLV and Media Player =>PUP.ApplianTechnologies^

C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rel.job =>Toolbar.AVGSearch^

C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rel =>Toolbar.AVGSearch^

C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rmv.job =>Toolbar.AVGSearch^

C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rmv =>Toolbar.AVGSearch^

[HKLM\Software\Wow6432Node\Applian Technologies] =>PUP.ApplianTechnologies^

C:\Windows\Installer\346d8a5.msi =>Toolbar.Ask^

~ Additionnel Scan: 388926 Items scanned in 00mn 30s

---\\ Additional information about modules

~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)

~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects (O2)

~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer toolbars (O3)

~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Auto loading programs from Registry and folders (O4)

~ AMI: 4 Scanned in 00mn 00s

---\\ Summary of the detections found on your workstation

http://nicolascoolman.fr/pup-quickshare =>PUP.QuickShare

http://www.nicolascoolman.fr/blog/ =>PUP.ApplianTechnologies

http://nicolascoolman.fr/toolbar-ask =>Toolbar.Ask

http://www.nicolascoolman.fr/blog/ =>PUP.CorsicaTechnologies

http://www.nicolascoolman.fr/blog/ =>Toolbar.Agent

http://nicolascoolman.fr/pup-babylon =>PUP.Babylon

~ MSI: 6 link(s) detected in 00mn 00s

End of the scan (2423 lines in 10mn 15s)(0.10)

flober
 Posté le 10/03/2015 à 01:52 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucienne

re

Le rapport montre que tu es infecté.

Attends demain qu'un Helper te prenne en charge pour remettre tout en ordre.

Il serait souhaitable que tu transfert ta demande dans le forum sécurité.

bonne nuit.



Modifié par flober le 10/03/2015 01:54
novotek
 Posté le 10/03/2015 à 01:57 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

ok, bonne nuit. à demain

lilidurhone
 Posté le 10/03/2015 à 06:40 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucienne

Ton rapport est incomplet .Héberge le sur cjoint :) .pour demander ton transfert clique sur le panneau point d'exclamation jaune et dis que tu souhaites être transférer dans sécurité

novotek
 Posté le 10/03/2015 à 08:35 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

Bonjour,

Malheureusement il n'y a pas de ça ici: "Insérer un rapport", je n'ai pas trouvé. Ici il y a ça Options : Ne plus suivre le sujet | Marquer comme résolu, donc je ne sais pas où et comment je peux vous envoyer le rapport en totalité.

J'essaye faire comme ça, je partagerai sur quelque paragraph de ce rapport ici pour que vous pouvez le lire et me conseiller quoi faire avec mon ordi.

~ Report of ZHPDiag v2015.3.8.28 - Nicolas Coolman (08.03.2015)

~ Launched by GELO (09.03.2015 22:39:36)

~ Facebook : https://www.facebook.com/nicolascoolman1

~ Web forum address : http://forum.nicolascoolman.fr

~ Translated by

~ Version State : Updated version.

~ White List : Deactivate by user

~ Elevation of privilege : OK

~ User Account Control : Deactivate by program

---\\ Internet browsers

MSIE: Internet Explorer v11.0.9600.17633

MFIE: Mozilla Firefox 35.0.1

GCIE: Google Chrome v40.0.2214.115 (Defaut)

OPIE: Opera v12.17

OPIE: Opera Stable v27.0.1689.76

---\\ Windows product information

~ Langage: Anglais

Windows Server License Manager Script : OK

~ Windows Operating System - Windows(R) 7, OEM_COA_NSLP channel

Windows ID Activation : OK

~ Windows Partial Key : 468V7

Windows License : OK

~ Windows Remaining Initializations Number : 3

Software Protection Service (Protection logicielle) : OK

Windows Automatic Updates : OK

Windows Activation Technologies : OK

Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)

---\\ System protection software

Malwarebytes Anti-Malware, версия 2.0.4.1028

Microsoft Security Client RU-RU Language Pack v2.1.1116.0

Windows Defender W7 (Deactivate)

---\\ System optimization software

---\\ Sharing software PeerToPeer

---\\ Surveillance software

Adobe Flash Player 16 NPAPI

Adobe Reader 64-bit fixes

Adobe Reader XI

Java 7 Update 60 (64-bit)

---\\ Information on the system

~ Processor: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel

~ Operating System: 64 Bits

Boot mode: Normal (Normal boot)

Total RAM: 8175 MB (46% free)

System Restore: Activé (Enable)

System drive C: has 270 GB (57%) free of 466 GB

---\\ Connection to the system mode

~ Computer Name: HENRI-PC

~ User Name: GELO

~ All Users Names: UpdatusUser, GELO, Administrateur,

~ Unselected Option: None

Logged in as Administrator

---\\ Environment variables

~ System Unit : C:\

~ %AppZHP% : C:\Users\GELO\AppData\Roaming\ZHP\

~ %AppData% : C:\Users\GELO\AppData\Roaming\

~ %Desktop% : C:\Users\GELO\Desktop\

~ %Favorites% : C:\Users\GELO\Favorites\

~ %LocalAppData% : C:\Users\GELO\AppData\Local\

~ %StartMenu% : C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\

~ %Windir% : C:\Windows\

~ %System% : C:\Windows\System32\

---\\ Enumeration of the disk units

C: Hard drive, Flash drive, Thumb drive (Free 270 Go of 466 Go)

D: CD-ROM drive (Not Inserted)

E: Hard drive, Flash drive, Thumb drive (Free 1016 Go of 1397 Go)

---\\ State of the Windows Security Center

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK

[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

~ Security Center: 41 Scanned in 00mn 00s

---\\ Search Generic System Files

[MD5.AC4C51EB24AA95B77F705AB159189E24] - (.Microsoft Corporation - Explorateur Windows.) (.21.11.2010 - 4:24:12.) -- C:\Windows\Explorer.exe [2872320]

[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14.07.2009 - 2:39:52.) -- C:\Windows\System32\Wininit.exe [129024]

[MD5.9DFE41A69DF70AAB75CB5BA8C1109EA2] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.12.01.2015 - 2:27:32.) -- C:\Windows\System32\wininet.dll [2358272]

[MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.17.07.2014 - 3:07:24.) -- C:\Windows\System32\Winlogon.exe [455168]

[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.21.11.2010 - 4:24:16.) -- C:\Windows\System32\sppcomapi.dll [232448]

[MD5.FA886682CFC5D36718D3E436AACF10B9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30.05.2014 - 7:45:52.) -- C:\Windows\system32\Drivers\AFD.sys [497152]

[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14.07.2009 - 2:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]

[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14.07.2009 - 0:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]

[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.21.11.2010 - 4:23:47.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]

[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.21.11.2010 - 4:24:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]

[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.21.11.2010 - 4:23:47.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]

[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14.07.2009 - 0:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]

[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14.07.2009 - 1:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]

[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27.04.2011 - 3:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]

[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.21.11.2010 - 4:23:51.) -- C:\Windows\system32\Drivers\netBT.sys [261632]

[MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24.01.2014 - 3:37:55.) -- C:\Windows\system32\Drivers\ntfs.sys [1684928]

[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14.07.2009 - 1:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]

[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.21.11.2010 - 4:24:33.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]

[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14.07.2009 - 1:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]

[MD5.70988118145F5F10EF24720B97F35F65] - (.Microsoft Corporation - TDI Translation Driver.) (.11.11.2014 - 2:46:26.) -- C:\Windows\system32\Drivers\tdx.sys [119296]

[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.21.11.2010 - 4:23:47.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]

~ Generic Processes: Scanned in 00mn 00s

---\\ Hidden files state (Hidden/Total)

~ Mes images (My Pictures) : 2/3327

~ Mes musiques (My Musics) : 3/12379

~ Mes Videos (My Videos) : 1/7

~ Mes Favoris (My Favorites) : 1/418

~ Mes Documents (My Documents) : 4/564

~ Mon Bureau (My Desktop) : 1/396

~ Menu demarrer (Programs) : 1/61

~ Hidden Files: Scanned in 00mn 03s

---\\ Process running

[MD5.06E0199BE4653D7FEDFB3612324FF084] - (.Innovative Solutions - Application Starter.) -- C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe [1065352] [PID.2332]

[MD5.43A1E2ADF070C541290084D741B0310F] - (.Kingsoft Corporation - Clean Master.) -- c:\program files (x86)\cmcm\Clean Master\cmtray.exe [468328] [PID.2340]

[MD5.5CB4C3C7A74E9436273261F74625B646] - (.PIMOne Software - PIMOne.) -- C:\Program Files (x86)\PIMOne\PIMOne.exe [2883584] [PID.5032]

[MD5.AD12F815BE0348F1FD7FEBF720FA307C] - (.Team MediaPortal - IR Server.) -- C:\Program Files (x86)\IR Server Suite\IR Server.exe [341504] [PID.3868]

[MD5.0A2BB12C84543B68E8E2E6E4235ADE58] - (.Team MediaPortal - IR Server Tray.) -- C:\Program Files (x86)\IR Server Suite\IR Server Tray.exe [426496] [PID.4032]

[MD5.39AF1CDEAFA4FC9D5185FBD9F4D141C4] - (.Octoshape ApS - Main program for Octoshape client.) -- C:\Users\GELO\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [107800] [PID.4028]

[MD5.7B6CB5C60E549B746FA8DEEE82C5BB53] - (...) -- C:\Users\GELO\AppData\Roaming\ACEStream\engine\ace_engine.exe [23984] [PID.528]

[MD5.99C03F5D726A415253DBF09AFDA0A72E] - (.Samsung - Kies.) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe [1565504] [PID.1116]

[MD5.43DFDE6570A948A178000348950B3546] - (...) -- C:\Users\GELO\AppData\Roaming\AceWebExtension\updater\ace_web_extension.exe [22824] [PID.4620]

[MD5.D3AC38E80E928CC61A22650E04423BB8] - (.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [979328] [PID.5084]

[MD5.36873F8B02A1F61DEC99D00E18E6C305] - (.Hauppauge Computer Works - IR.) -- C:\Program Files (x86)\WinTV\Ir.exe [118544] [PID.4212]

[MD5.0D45E25843928A8CF67959F2A382742B] - (.Hauppauge Computer Works, Inc. - WinTVTray.) -- C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe [151552] [PID.2424]

[MD5.7791897A9EC247982F8B6DFA0230E6E4] - (.No owner - MDAPI_Plus Host Application.) -- C:\Program Files (x86)\MDAPI_Plus\MDAPIHost.exe [243200] [PID.5072]

[MD5.16AFB34618E1286FF856DC600AC49C79] - (.No owner - DivX Update.) -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968] [PID.4628]

[MD5.60D2665C567B38C96E1216E9BC6F0253] - (.4t Niagara Software - 4t Tray Minimizer Free.) -- C:\Program Files (x86)\4t Tray Minimizer\4t-min.exe [1848832] [PID.4936]

[MD5.7C557FD090347693F7FD5DBFEC444D02] - (.No owner - Process Killer.) -- C:\Program Files\Process Killer 1.4.2\prkiller.exe [38400] [PID.4596]

[MD5.C32E458C8DDB46220C2D9C7807EC1A3F] - (.Schneider Electric - PowerChute System Tray Power Icon.) -- C:\Program Files (x86)\APC\PowerChute Personal Edition\apcsystray.exe [673144] [PID.3924]

[MD5.6B7F08FC28191D99F6FDE92949C6628A] - (.Mister Group - System Explorer.) -- C:\Program Files (x86)\System Explorer\SystemExplorer.exe [3391200] [PID.2040]

[MD5.53EBC5A93B96B8590BC7F02D7316A9EE] - (.Samsung Electronics Co., Ltd. - Kies TrayAgent Application.) -- C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616] [PID.1788]

[MD5.A8C1BF646DD0168E81AFAA9662CCD843] - (...) -- C:\Users\GELO\AppData\Roaming\ACEStream\updater\ace_update.exe [22824] [PID.6032]

[MD5.B9D6D7E6E5C4FCD8DD7F88EC9D563085] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592] [PID.6840]

[MD5.0FDA13AB12896ABB885B2781DAA950E5] - (.ABBYY. - ABBYY ScreenshotReader.) -- C:\Program Files (x86)\ABBYY FineReader 11\Bonus.ScreenshotReader.exe [925960] [PID.6044]

[MD5.6B7BE218304D5DCCCBFFAE29F31F5AE7] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8184832] [PID.7212]

[MD5.E6D260721A9DF6A254FEDB7990FB5E77] - (.Kingsoft Corporation - Clean Master.) -- c:\program files (x86)\cmcm\Clean Master\cmcore.exe [315240] [PID.1264]

[MD5.B33CF4DE909A5B30F526D82053A63C8E] - (.ABBYY - ABBYY network license server.) -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048] [PID.1860]

[MD5.8A27975A7BD3EA10E7F22553558F3A74] - (...) -- C:\Program Files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe [917640] [PID.1940]

[MD5.4C72FDD915D62EAEF149BD9C73AB9CF4] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [81088] [PID.1180]

[MD5.C7F8C8080B055B3DE9A8141DFD8E308A] - (.Schneider Electric - Battery Backup Management Service.) -- C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe [705912] [PID.1592]

[MD5.221564CC7BE37611FE15EACF443E1BF6] - (.Apple Inc. - YSLoader.exe.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [43336] [PID.1736]

[MD5.2EC3AFFE3AC7776AE9DA4028D370593F] - (.Hauppauge Computer Works - Hauppauge TV Server.) -- C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe [579584] [PID.2152]

[MD5.0BB29DE40C9D9529793DCDB59A43CF5B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160] [PID.2616]

[MD5.9972EDE411AA4D1FFF3341DC8819A5A4] - (.Hauppauge Computer Works - Capture plugin for the USB devices.) -- C:\Program Files (x86)\WinTV\TVServer\CaptureGenUSB.exe [405504] [PID.2824]

[MD5.20372BE109FEE1C37E2D5216680DB9EB] - (.pdfforge GmbH - PDF Architect Helper Service.) -- C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496] [PID.2408]

[MD5.295010C3EDECCAF760853544D0C92C03] - (.VMware, Inc. - VMware NAT Service.) -- C:\Windows\SysWOW64\vmnat.exe [437976] [PID.2548]

[MD5.107AB19CC1D40B9D04537F6EEAAC34C9] - (.Schneider Electric - PowerChute Data Service.) -- C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe [21880] [PID.3296]

[MD5.1AA9C2331234786211A261C8FC69EB25] - (.VMware, Inc. - VMware Authorization Service.) -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe [86744] [PID.3344]

[MD5.7EEBDDF76D013181E21592D2FFD66A98] - (.VMware, Inc. - VMware VMnet DHCP service.) -- C:\Windows\SysWOW64\vmnetdhcp.exe [359128] [PID.3416]

[MD5.A3A25E0509F67473B960DAF214828BE3] - (.NVIDIA Corporation - NVIDIA Settings Update Manager.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [1259296] [PID.5740]

~ Processes Running: Scanned in 00mn 00s

---\\ Opera, Plugins,Start,Search (P1,B0,B1)

B0 - SPO: operaprefs.ini [GELO] Home URL=http://www.rambler.ru/

B1 - OSP: search.ini [GELO] URL=http://www.bing.com/search?q=%s&form=OPRTSD&pc=OPER

B1 - OSP: search.ini [GELO] URL=http://redir.opera.com/amazon

B1 - OSP: search.ini [GELO] URL=http://redir.opera.com/ebay =>Toolbar.eBay

B1 - OSP: search.ini [GELO] URL=http://fr.wikipedia.org/wiki/Special:Search?search=%s

P1 - OPN:Opera Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files (x86)\Opera\Program\Plugins\NPOFF12.DLL

P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin.dll

P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin2.dll

P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin3.dll

P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin4.dll

P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin5.dll

P1 - OPN:Opera Plugin Navigator . (...) -- C:\Program Files (x86)\Opera\Program\Plugins\NPSWF32.dll

P1 - OPN:Opera Plugin Navigator . (.Adobe Systems, Inc. - Adobe Flash Player Helper 10.0 r45.) -- C:\Program Files (x86)\Opera\Program\Plugins\NPSWF32_FlashUtil.exe =>.Adobe Systems Incorporated

P1 - OPN:Opera Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files (x86)\Opera\Program\Plugins\NPOFF12.DLL

P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin.dll

P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin2.dll

P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin3.dll

P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin4.dll

P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin5.dll

P1 - OPN:Opera Plugin Navigator . (...) -- C:\Program Files (x86)\Opera\Program\Plugins\NPSWF32.dll

P1 - OPN:Opera Plugin Navigator . (.Adobe Systems, Inc. - Adobe Flash Player Helper 10.0 r45.) -- C:\Program Files (x86)\Opera\Program\Plugins\NPSWF32_FlashUtil.exe =>.Adobe Systems Incorporated

~ Opera Browser: 21 Scanned in 00mn 00s

---\\ Google Chrome, Start,Search,Extensions (G0,G1,G2)

C:\Users\GELO\AppData\Local\Google\Chrome\User Data\Default\Preferences

---\\ Google Chrome Extension Folder

~ Google Lines Browser: 0 Scanned in 00mn 00s

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (P2,M0,M1,M2,M3)

C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\blozzve3.default\prefs.js

C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\prefs.js

M3 - MFPP: Plugins - [GELO] -- C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\searchplugins\ebook-.xml

M3 - MFPP: Plugins - [GELO] -- C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\searchplugins\googletranslate.xml

M3 - MFPP: Plugins - [GELO] -- C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\searchplugins\only-pdf.xml

M3 - MFPP: Plugins - [GELO] -- C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\searchplugins\pdf-ebook-searches.xml

M3 - MFPP: Plugins - [GELO] -- C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\searchplugins\pdf-search.xml

M3 - MFPP: Plugins - [GELO] -- C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\searchplugins\translateru.xml

M2 - MFEP: prefs.js [GELO - blozzve3.default\clickclean@hotcleaner.com] [] Click&amp;Clean v4.1 (..)

M2 - MFEP: prefs.js [GELO - blozzve3.default\donottrackplus@abine.com] [] Blur (Formerly DoNotTrackMe) v4.5.1334 (..)

M2 - MFEP: prefs.js [GELO - blozzve3.default\idme@abine.com] [] MaskMe v1.40.366 (..)

M2 - MFEP: prefs.js [GELO - blozzve3.default\iobitascsurfingprotection@iobit.com] [] Advanced SystemCare Surfing Protection v2.0 (..)

M2 - MFEP: prefs.js [GELO - blozzve3.default\magicplayer@acestream.org] [] AS Magic Player v1.1.42 (..)

M2 - MFEP: prefs.js [GELO - blozzve3.default\pavel.sherbakov@gmail.com] [] Speed Dial [FVD] - New Tab Page, Sync... v1.1.42 (..) =>PUP.QuickShare

M2 - MFEP: prefs.js [GELO - blozzve3.default\printPages2Pdf@reinhold.ripper] [] Print pages to PDF v0.1.9.3 (..)

M2 - MFEP: prefs.js [GELO - blozzve3.default\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}] [WOT] WOT v20131118 (..)

M2 - MFEP: prefs.js [GELO - blozzve3.default\{dd3d7613-0246-469d-bc65-2a3cc1668adc}] [] Block site v1.1.8 (..)

M2 - MFEP: Extension [GELO - blozzve3.default] {0e10f3d7-07f6-4f12-97b9-9b27e07139a5}.xpi

M2 - MFEP: Extension [GELO - blozzve3.default] {146f1820-2b0d-49ef-acbf-d85a6986e10c}.xpi

M2 - MFEP: Extension [GELO - blozzve3.default] {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi

M2 - MFEP: Extension [GELO - blozzve3.default] {73a6fe31-595d-460b-a920-fcc0f8843232}.xpi

M2 - MFEP: Extension [GELO - blozzve3.default] {9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi

M2 - MFEP: Extension [GELO - blozzve3.default] {ab4b5718-3998-4a2c-91ae-18a7c2db513e}.xpi

M2 - MFEP: Extension [GELO - blozzve3.default] {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Adblock Plus Extension Mozilla Firefox

M2 - MFEP: Extension [GELO - blozzve3.default] {ea61041c-1e22-4400-99a0-aea461e69d04}.xpi

M2 - MFEP: Extension [GELO - blozzve3.default] {fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi

M2 - MFEP: Extension [GELO - blozzve3.default] {02450914-cdd9-410f-b1da-db004e18c671}.xpi

M2 - MFEP: Extension [GELO - blozzve3.default] {1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi

M2 - MFEP: Extension [GELO - blozzve3.default] {27c60876-b5c9-4335-b4f3-52b26782220c}.xpi

M2 - MFEP: Extension [GELO - blozzve3.default] {cd617375-6743-4ee8-bac4-fbf10f35729e}.xpi

M2 - MFEP: Extension [GELO - blozzve3.default] {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi

M2 - MFEP: prefs.js [GELO - fi77grgz.dev-edition-default\donottrackplus@abine.com] [] Blur (Formerly DoNotTrackMe) v4.5.1334 (..)

M2 - MFEP: prefs.js [GELO - fi77grgz.dev-edition-default\idme@abine.com] [] MaskMe v1.40.366 (..)

M2 - MFEP: prefs.js [GELO - fi77grgz.dev-edition-default\iobitascsurfingprotection@iobit.com] [] Advanced SystemCare Surfing Protection v2.0 (..)

M2 - MFEP: prefs.js [GELO - fi77grgz.dev-edition-default\pavel.sherbakov@gmail.com] [] Speed Dial [FVD] - New Tab Page, Sync... v1.1.2 (..) =>PUP.QuickShare

M2 - MFEP: prefs.js [GELO - fi77grgz.dev-edition-default\printPages2Pdf@reinhold.ripper] [] Print pages to PDF v0.1.9.3 (..)

M2 - MFEP: prefs.js [GELO - fi77grgz.dev-edition-default\{6d43fee4-72e7-4290-b75a-b898e4f4676d}] [] BlockSite Plus v1.1 (..)

M2 - MFEP: prefs.js [GELO - fi77grgz.dev-edition-default\{dd3d7613-0246-469d-bc65-2a3cc1668adc}] [] Block site v1.1.8 (..)

M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {0e10f3d7-07f6-4f12-97b9-9b27e07139a5}.xpi

M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {146f1820-2b0d-49ef-acbf-d85a6986e10c}.xpi

M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi

M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {73a6fe31-595d-460b-a920-fcc0f8843232}.xpi

M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi

M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {ab4b5718-3998-4a2c-91ae-18a7c2db513e}.xpi

M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Adblock Plus Extension Mozilla Firefox

M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {ea61041c-1e22-4400-99a0-aea461e69d04}.xpi

M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi

M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {02450914-cdd9-410f-b1da-db004e18c671}.xpi

M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi

M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {27c60876-b5c9-4335-b4f3-52b26782220c}.xpi

M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {cd617375-6743-4ee8-bac4-fbf10f35729e}.xpi

M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi

P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - np-mswmp.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\np-mswmp.dll

P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.10.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\nppdf32.dll

P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin.dll

P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin2.dll

P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin3.dll

P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin4.dll

P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin5.dll

P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll

P2 - FPN: [HKLM] [@java.com/DTPlugin,version=11.25.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll

P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=11.25.2] - (.Oracle Corporation - Next Generation Java Plug-in 11.25.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll

P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.0.4] - (...) -- C:\Program Files\VideoLAN\VLC\npvlc.dll (.not file.)

P2 - FPN: [HKCU] [@acestream.net/acestreamplugin,version=3.0.2] - (.Innovative Digital Technologies - ACE Stream Plug-in Version 2.2.5.1-next, Copyright (c) 2012-2014 Innov.) -- C:\Users\GELO\AppData\Roaming\ACEStream\player\npace_plugin.dll

P2 - FPN: [HKCU] [@octoshape.com/Octoshape Streaming Services,version=1.0] - (.Octoshape ApS - Octoshape embedded video plugin.) -- C:\Users\GELO\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1401100-0-npoctoshape.dll

P2 - FPN: [HKCU] [@Skype Limited.com/Facebook Video Calling Plugin] - (.Skype Limited - Facebook Video Calling Plugin.) -- C:\Users\GELO\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll

P2 - FPN: [HKCU] [@talk.google.com/GoogleTalkPlugin] - (.Google - Version 5.40.2.0.) -- C:\Users\GELO\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll

P2 - FPN: [HKCU] [@talk.google.com/O1DPlugin] - (.Google - Version 5.40.2.0.) -- C:\Users\GELO\AppData\Roaming\Mozilla\plugins\npo1d.dll

P2 - FPN: [HKCU] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Users\GELO\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll

P2 - FPN: [HKCU] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Users\GELO\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll

~ Firefox Browser: 88 Scanned in 00mn 00s

---\\ Internet Explorer Extensions, Start, Search (R4,R3,R0,R1)

R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://rambler.ru

R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://rambler.ru

R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://rambler.ru

R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://encrypted.google.com

R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rambler.ru

R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://encrypted.google.com

R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = preserve

R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://encrypted.google.com

R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com

R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons

R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk

R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://encrypted.google.com

R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm

R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://encrypted.google.com

R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rambler.ru

R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://encrypted.google.com

R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons

R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk

R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.9600.17631 (winblue_r7.150111-1500)) -- C:\Windows\SysWOW64\ieframe.dll

R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1

R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1

~ IE Browser: 21 Scanned in 00mn 00s

---\\ Internet Explorer, Proxy Management (R5)

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

~ Proxy management: Scanned in 00mn 00s

---\\ Line Analysis F0, F1, F2, F3 - IniFiles, Auto loading programs

F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,

F2 - REG:system.ini: Shell=C:\Windows\explorer.exe

F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe

~ Keys: Scanned in 00mn 00s

---\\ Hosts file redirection (O1)

O1 - Hosts: 94.242.221.196 ok.ru

O1 - Hosts: 94.242.221.196 m.ok.ru

~ Nombre lignes détournées 2/35 (Hosts file redirected)

~ Hosts File: Scanned in 00mn 00s

---\\ Browser Helper Objects (O2)

O2 - BHO: Ghostery BHO [64Bits] - {237EB6DA-3FEA-4DD2-8A61-A901B5C489D7} . (...) -- C:\Program Files (x86)\GhosteryIEplugin\GhosteryBrowserHelperObject.dll

O2 - BHO: PDF Architect Helper [64Bits] - {3A2D5EBA-F86D-4BD3-A177-019765996711} . (.pdfforge GmbH - PDF Architect Helper.) -- C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll

O2 - BHO: Sopcast Toolbar BHO [64Bits] - {53504356-3700-A76A-76A7-7A786E7484D7} Orphan key

O2 - BHO: Groove GFS Browser Helper [64Bits] - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Спутник@Mail.Ru [64Bits] - {8984B388-A5BB-4DF7-B274-77B879E179DB} Orphan key

O2 - BHO: Programme d’aide de l’Assistant de connexion au compte Microsoft [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper [64Bits] - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: WOT Helper [64Bits] - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} . (...) -- C:\Program Files (x86)\WOT\WOT.dll

O2 - BHO: CutePDF Form Filler [64Bits] - {D41289F2-69C6-417B-897E-C653D677CBAF} . (.Acro Software Inc. - CutePDF Filler Helper.) -- C:\Program Files (x86)\Acro Software\CutePDF Pro\CPFillerCo.dll

O2 - BHO: Adblock Plus for IE Browser Helper Object [64Bits] - {FFCB3198-32F3-4E8B-9539-4324694ED664} . (.Eyeo GmbH - Adblock Plus BHO for Internet Explorer.) -- C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll

O2 - BHO: ExplorerWnd Helper [64Bits] - {10921475-03CE-4E04-90CE-E2E7EF20C814} Orphan key

O2 - BHO: Sopcast Toolbar [64Bits] - {53504356-3700-A76A-76A7-7A786E7484D7} Orphan key

O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} Orphan key

O2 - BHO: (no name) [64Bits] - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} Orphan key

O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} Orphan key

O2 - BHO: TabExplorerHelper [64Bits] - {F8A6CAA2-533D-4AED-9E05-8EB19A4021AB} Orphan key

~ BHO: 20 Scanned in 00mn 01s

---\\ Internet Explorer toolbars (O3)

O3 - Toolbar: Easy Photo Print - [HKLM]{9421DD08-935F-4701-A9CA-22DF90AC4EA6} . (.SEIKO EPSON CORPORATION / CyCom Technology - Epson Easy Photo Print (TBL x64).) -- C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll

O3 - Toolbar: Sopcast Toolbar - [HKLM]{53504356-3700-A76A-76A7-7A786E7484D7} . (...) -- (.not file.)

O3 - Toolbar: WOT - [HKLM]{71576546-354D-41c9-AAE8-31F2EC22BF0D} . (...) -- C:\Program Files\WOT\WOT.dll

O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll

O3 - Toolbar\WebBrowser: (no name) - [HKCU]{6AA40521-14E7-4B1D-B1B4-98528C1388C9} Orphan key

O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2B171655-A70C-5C18-B693-6CB5DC269D41} Orphan key

O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Orphan key

O3 - Toolbar\WebBrowser: (no name) - [HKCU]{71576546-354D-41C9-AAE8-31F2EC22BF0D} Orphan key

~ Toolbar: Scanned in 00mn 00s

---\\ Other User Links (O4)

O4 - GS\Program [GELO]: Applian FLV Player.lnk . (...) -- C:\Program Files (x86)\FLV Player\FLVPlayer.exe (.not file.) =>PUP.ApplianTechnologies

~ Global Startup: 1 Scanned in 00mn 09s

---\\ Auto loading programs from Registry and folders (O4)

O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- C:\Program Files\Microsoft Security Client\msseces.exe

O4 - HKLM\..\Run: [Windows Firewall Control] . (.Alexandru Dicu - Windows Firewall Control.) -- C:\Windows\SysWOW64\wfc.exe

O4 - HKLM\..\Run: [Fences] . (.Stardock Corporation - Fences Settings.) -- C:\Program Files (x86)\Stardock\Fences\Fences.exe

O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp

O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation

O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\GELO\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc

O4 - HKCU\..\Run: [PIMOne] . (.PIMOne Software - PIMOne.) -- C:\Program Files (x86)\PIMOne\PIMOne.exe

O4 - HKCU\..\Run: [Allmyapps] C:\Users\GELO\AppData\Roaming\Allmyapps\Allmyapps.exe (.not file.)

O4 - HKCU\..\Run: [Allmyapps Update] C:\Users\GELO\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe (.not file.)

O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - Chargeur CTF.) -- C:\Windows\system32\ctfmon.exe

O4 - HKCU\..\Run: [IR Server] . (.Team MediaPortal - IR Server.) -- C:\Program Files (x86)\IR Server Suite\IR Server.exe

O4 - HKCU\..\Run: [IR Server Tray] . (.Team MediaPortal - IR Server Tray.) -- C:\Program Files (x86)\IR Server Suite\IR Server Tray.exe

O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\GELO\AppData\Local\Facebook\Update\FacebookUpdate.exe

O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHLE.exe =>.Epson Seiko Corporation

O4 - HKCU\..\Run: [Octoshape Streaming Services] . (.Octoshape ApS - Main program for Octoshape client.) -- C:\Users\GELO\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe

O4 - HKCU\..\Run: [AceStream] . (...) -- C:\Users\GELO\AppData\Roaming\ACEStream\engine\ace_engine.exe

O4 - HKCU\..\Run: [KiesPreload] . (.Samsung - Kies.) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe

O4 - HKCU\..\Run: [AceWebException] . (...) -- C:\Users\GELO\AppData\Roaming\AceWebExtension\updater\ace_web_extension.exe

O4 - HKCU\..\Run: [Geotag Security] . (.No owner - Geotag Security.) -- C:\Program Files (x86)\Geotag Security\GeotagSecurity.exe

O4 - HKCU\..\RunOnce: [Adobe Speed Launcher] 1425935106

O4 - HKLM\..\Wow6432Node\Run: [EEventManager] . (.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe

O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe

O4 - HKLM\..\Wow6432Node\Run: [DivXMediaServer] . (.DivX, LLC - DivX Media Server Launcher.) -- C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe

O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated

O4 - HKLM\..\Wow6432Node\Run: [Display] . (.Schneider Electric - Startup Notification Module.) -- C:\Program Files (x86)\APC\PowerChute Personal Edition\DataCollectionLauncher.exe

O4 - HKLM\..\Wow6432Node\Run: [MDAPI_Plus] . (.No owner - MDAPI_Plus Host Application.) -- C:\Program Files (x86)\MDAPI_Plus\MDAPIHost.exe

O4 - HKLM\..\Wow6432Node\Run: [WsmUpdater] . (.Web Solution Mart - Updater.) -- C:\Program Files (x86)\Web Solution Mart\Fake Webcam Codecs Pack\Updater.exe

O4 - HKLM\..\Wow6432Node\Run: [DivXUpdate] . (.No owner - DivX Update.) -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe

O4 - HKLM\..\Wow6432Node\Run: [SystemExplorerAutoStart] . (.Mister Group - System Explorer.) -- C:\Program Files (x86)\System Explorer\SystemExplorer.exe

O4 - HKLM\..\Wow6432Node\Run: [KiesTrayAgent] . (.Samsung Electronics Co., Ltd. - Kies TrayAgent Application.) -- C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe =>.Samsung Electronics Co

O4 - HKLM\..\Wow6432Node\Run: [cmsc] . (.Kingsoft Corporation - Clean Master.) -- c:\program files (x86)\cmcm\Clean Master\cmtray.exe

O4 - HKLM\..\Wow6432Node\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll] C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (.not file.)

O4 - HKUS\.DEFAULT\..\Run: [Adguard] C:\Program Files (x86)\Adguard\Adguard.exe (.not file.)

O4 - HKUS\S-1-5-18\..\Run: [Adguard] C:\Program Files (x86)\Adguard\Adguard.exe (.not file.)

O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation

O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\GELO\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [PIMOne] . (.PIMOne Software - PIMOne.) -- C:\Program Files (x86)\PIMOne\PIMOne.exe

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [Allmyapps] C:\Users\GELO\AppData\Roaming\Allmyapps\Allmyapps.exe (.not file.)

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [Allmyapps Update] C:\Users\GELO\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe (.not file.)

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [ctfmon.exe] . (.Microsoft Corporation - Chargeur CTF.) -- C:\Windows\system32\ctfmon.exe

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [IR Server] . (.Team MediaPortal - IR Server.) -- C:\Program Files (x86)\IR Server Suite\IR Server.exe

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [IR Server Tray] . (.Team MediaPortal - IR Server Tray.) -- C:\Program Files (x86)\IR Server Suite\IR Server Tray.exe

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\GELO\AppData\Local\Facebook\Update\FacebookUpdate.exe

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHLE.exe =>.Epson Seiko Corporation

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [Octoshape Streaming Services] . (.Octoshape ApS - Main program for Octoshape client.) -- C:\Users\GELO\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [AceStream] . (...) -- C:\Users\GELO\AppData\Roaming\ACEStream\engine\ace_engine.exe

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [KiesPreload] . (.Samsung - Kies.) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [AceWebException] . (...) -- C:\Users\GELO\AppData\Roaming\AceWebExtension\updater\ace_web_extension.exe

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [Geotag Security] . (.No owner - Geotag Security.) -- C:\Program Files (x86)\Geotag Security\GeotagSecurity.exe

O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\RunOnce: [Adobe Speed Launcher] 1425935106

~ Application: Scanned in 00mn 00s

novotek
 Posté le 10/03/2015 à 08:37 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

---\\ IE Options icon not visible in Control Panel (O5)

O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no

~ IE Control Panel: 1 Scanned in 00mn 00s

---\\ Winsock hijacker (Layered Service Provider) (O10)

O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll

O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll

O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll

O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll

O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation

O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll

O10 - WLSP:\000000000007\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files (x86)\Bonjour\mdnsNSP.dll

O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation

O10 - WLSP:\000000000009\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation

~ Winsock: 9 Scanned in 00mn 00s

---\\ Site in Trusted Zone (O15)

O15 - Trusted Zone: [HKCU\...\Domains\www] http.parom.tv

~ IE Zone Confiance: Scanned in 00mn 00s

---\\ Lop.com/Domain Hijackers (O17)

O17 - HKLM\System\CCS\Services\Tcpip\..\{CF459770-6FDC-42AC-8D87-9F477126D016}: DhcpNameServer = 89.2.0.1 89.2.0.2

O17 - HKLM\System\CS1\Services\Tcpip\..\{CF459770-6FDC-42AC-8D87-9F477126D016}: DhcpNameServer = 89.2.0.1 89.2.0.2

O17 - HKLM\System\CS2\Services\Tcpip\..\{CF459770-6FDC-42AC-8D87-9F477126D016}: DhcpNameServer = 89.2.0.1 89.2.0.2

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.2.0.1 89.2.0.2

~ Domain: Scanned in 00mn 00s

---\\ Extra protocols (O18)

O18 - Handler: wot [64Bits] - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} . (...) -- C:\Program Files\WOT\WOT.dll

O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation

~ Protocole Additionnel: Scanned in 00mn 00s

---\\ ShellServiceObjectDelayLoad (O21)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

~ SSODL: 1 Scanned in 00mn 00s

---\\ SharedTaskScheduler (O22)

O22 - SharedTaskScheduler: (no name) [64Bits] - {73526E5A-FD53-4BE7-B5E2-D3C89D7413DC} - (.not file.)

O22 - SharedTaskScheduler: (no name) [64Bits] - {E31004D1-A431-41B8-826F-E902F9D95C81} . (.Microsoft Corporation - Microsoft Windows 7 Ultimate Extra: Windows.) -- C:\Windows\SysWow64\DreamScene.dll

O22 - SharedTaskScheduler: (no name) [64Bits] - {1984DD45-52CF-49cd-AB77-18F378FEA264} - (.not file.)

~ STS/SSO: Scanned in 00mn 00s

---\\ Non Microsoft non disabled Windows XP/NT/2000 Services (O23)

O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) . (.ABBYY - ABBYY network license server.) - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe

O23 - Service: Acunetix WVS Scheduler v8 (AcuWVSSchedulerv8) . (...) - C:\Program Files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: Advanced SystemCare Service 8 (AdvancedSystemCareService8) . (...) - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ASCService.exe (.not file.)

O23 - Service: APC Data Service (APC Data Service) . (.Schneider Electric - PowerChute Data Service.) - C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe

O23 - Service: APC UPS Service (APC UPS Service) . (.Schneider Electric - Battery Backup Management Service.) - C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe

O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - YSLoader.exe.) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: AdvancedSystemCareAntivirus (ASCAntivirusSrv) . (...) - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ascavsvc.exe (.not file.)

O23 - Service: Служба Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Clean Master Core Service (cmcore) . (.Kingsoft Corporation - Clean Master.) - c:\program files (x86)\cmcm\Clean Master\cmcore.exe

O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.exe =>.Epson Seiko Corporation

O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc

O23 - Service: HauppaugeTVServer (HauppaugeTVServer) . (.Hauppauge Computer Works - Hauppauge TV Server.) - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe

O23 - Service: HitmanPro Scheduler (HitmanProScheduler) . (...) - C:\Program Files\HitmanPro\hmpsched.exe (.not file.)

O23 - Service: LiveUpdate (LiveUpdateSvc) . (...) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (.not file.)

O23 - Service: Ma-Config Agent (MaConfigAgent) . (.CybelSoft - Service de détection matériel.) - C:\Program Files\ma-config.com\MaConfigAgent.exe

O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe

O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe

O23 - Service: MySQL (MySQL) . (...) - C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 307.8.) - C:\Windows\system32\nvvsvc.exe

O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) . (.NVIDIA Corporation - NVIDIA Settings Update Manager.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

O23 - Service: PDF Architect Helper Service (PDF Architect Helper Service) . (.pdfforge GmbH - PDF Architect Helper Service.) - C:\Program Files (x86)\PDF Architect\HelperService.exe

O23 - Service: PDF Architect Service (PDF Architect Service) . (.pdfforge GmbH - PDF Architect Conversion Service.) - C:\Program Files (x86)\PDF Architect\ConversionService.exe

O23 - Service: RumoteVMC Service (RumoteVMCService) . (.Rumote - RumoteMCEService.) - C:\Program Files (x86)\Rumote\RumoteVMC\RumoteMCEService.exe

O23 - Service: SolidConverterPDFReadSpool (SCPDFReadSpool) . (.Solid Documents, LLC - Solid Spool Service.) - C:\Program Files (x86)\SolidDocuments\Solid Converter PDF\SCPDF\SolidConverterPDFServicex64.exe

O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe

O23 - Service: VMware Authorization Service (VMAuthdService) . (.VMware, Inc. - VMware Authorization Service.) - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe

O23 - Service: VMware DHCP Service (VMnetDHCP) . (.VMware, Inc. - VMware VMnet DHCP service.) - C:\Windows\SysWOW64\vmnetdhcp.exe

O23 - Service: VMware USB Arbitration Service (VMUSBArbService) . (.VMware, Inc. - VMware USB Arbitration Service.) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe

O23 - Service: VMware NAT Service (VMware NAT Service) . (.VMware, Inc. - VMware NAT Service.) - C:\Windows\SysWOW64\vmnat.exe

O23 - Service: Windows Firewall Control (_wfcs) . (.BiniSoft.org - Windows Firewall Control Service.) - C:\Program Files\Windows Firewall Control\wfcs.exe

~ Services: 27 Scanned in 00mn 04s

---\\ Windows Active Desktop & MHTML Editor (O24)

O24 - Default MHTML Editor: Last - .(...) - (.not file.)

~ Desktop Component: 4 Scanned in 00mn 00s

---\\ BootExecute (BEX) (O34)

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O34 - HKLM BootExecute: (pS›) - File not found

~ BEX: 2 Scanned in 00mn 00s

---\\ Task Planned Automatically (039)

[MD5.00000000000000000000000000000000] [APT] [Ad-Aware Antivirus Scheduled Scan] (...) -- C:\Program Files (x86)\AD-AWA~1\AdAwareLauncher.exe (.not file.) [0]

[MD5.080255CDCB878813B481B8C348D47D8E] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [267440]

[MD5.00000000000000000000000000000000] [APT] [AllmyappsUpdateTask] (...) -- C:\Users\GELO\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe (.not file.) [0]

[MD5.06E0199BE4653D7FEDFB3612324FF084] [APT] [Application Starter - f1375f225883e83d52e8db9690775c3c] (.Innovative Solutions.) -- C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe [1065352]

[MD5.00000000000000000000000000000000] [APT] [ASCU8_PerformanceMonitor] (...) -- C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\Monitor.exe (.not file.) [0]

[MD5.00000000000000000000000000000000] [APT] [ASCU8_SkipUac_GELO] (...) -- C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ASC.exe (.not file.) [0]

[MD5.00000000000000000000000000000000] [APT] [AVG-Secure-Search-Update_0214b_rel] (...) -- C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe (.not file.) [0] =>Toolbar.AVGSearch

[MD5.00000000000000000000000000000000] [APT] [AVG-Secure-Search-Update_0214b_rmv] (...) -- C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe (.not file.) [0] =>Toolbar.AVGSearch

[MD5.00000000000000000000000000000000] [APT] [AviatorUpdateTask] (...) -- C:\Program Files (x86)\WhiteHat\Aviator\Update\BatchLauncher.vbs" "C:\Program Files (x86)\WhiteHat\Aviator\Update\AviatorAutoUpdate.exe (.not file.) [0]

[MD5.00000000000000000000000000000000] [APT] [Driver Booster Scan] (...) -- C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe (.not file.) [0]

[MD5.00000000000000000000000000000000] [APT] [Driver Booster SkipUAC (GELO)] (...) -- C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe (.not file.) [0]

[MD5.00000000000000000000000000000000] [APT] [Driver Booster Update] (...) -- C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe (.not file.) [0]

[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core] (.Facebook Inc..) -- C:\Users\GELO\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096]

[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA] (.Facebook Inc..) -- C:\Users\GELO\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096]

[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912]

[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912]

[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core] (.Google Inc..) -- C:\Users\GELO\AppData\Local\Google\Update\GoogleUpdate.exe [116648]

[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA] (.Google Inc..) -- C:\Users\GELO\AppData\Local\Google\Update\GoogleUpdate.exe [116648]

[MD5.9E6DA841450754056E419FC2055509BF] [APT] [Opera scheduled Autoupdate 1376993084] (.Opera Software.) -- C:\Program Files (x86)\Opera\launcher.exe [487544]

[MD5.00000000000000000000000000000000] [APT] [RealUpgradeLogonTaskS-1-5-21-3147391334-965059008-3150008735-1000] (...) -- C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe (.not file.) [0]

[MD5.00000000000000000000000000000000] [APT] [RealUpgradeScheduledTaskS-1-5-21-3147391334-965059008-3150008735-1000] (...) -- C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe (.not file.) [0]

[MD5.00000000000000000000000000000000] [APT] [Uninstaller_SkipUac_GELO] (...) -- C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe (.not file.) [0]

[MD5.00000000000000000000000000000000] [APT] [{0216C314-D397-45E4-95FC-DA5594765496}] (...) -- C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\SetupTv.exe (.not file.) [0]

[MD5.00000000000000000000000000000000] [APT] [{179F9451-8A8A-4436-9B06-348CE593A318}] (...) -- D:\UNINSTAL.exe (.not file.) [0]

[MD5.604A6F3CB699983E73880B3E91B38B5E] [APT] [{792D849D-B980-4817-8E4F-26A71359355F}] (...) -- C:\Program Files (x86)\K!TV\UninstKTV.exe [4229955]

[MD5.00000000000000000000000000000000] [APT] [{ABBC8076-9041-4B14-8B8B-139F0E4DDC84}] (...) -- D:\INSTALL.exe (.not file.) [0]

[MD5.00000000000000000000000000000000] [APT] [{AFFEB6F3-57E6-4CB9-B51A-7B92475A2D85}] (...) -- D:\INSTALL.exe (.not file.) [0]

[MD5.D41D8CD98F00B204E9800998ECF8427E] [APT] [{B8DC7294-44CD-4C81-BC05-4A5162480BC6}] (...) -- C:\Program Files (x86)\QuickTime\QTSystem\QuickTime.cpl" [1511424]

[MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [561984]

O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]

O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]

O39 - APT: AllmyappsUpdateTask - (...) -- C:\Windows\Tasks\AllmyappsUpdateTask.job [392]

O39 - APT: AllmyappsUpdateTask - (...) -- C:\Windows\System32\Tasks\AllmyappsUpdateTask [392]

O39 - APT: Application Starter - f1375f225883e83d52e8db9690775c3c - (.Innovative Solutions.) -- C:\Windows\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c.job [302]

O39 - APT: Application Starter - f1375f225883e83d52e8db9690775c3c - (.Innovative Solutions.) -- C:\Windows\System32\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c [302]

O39 - APT: AVG-Secure-Search-Update_0214b_rel - (...) -- C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rel.job [374] =>Toolbar.AVGSearch

O39 - APT: AVG-Secure-Search-Update_0214b_rel - (...) -- C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rel [374] =>Toolbar.AVGSearch

O39 - APT: AVG-Secure-Search-Update_0214b_rmv - (...) -- C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rmv.job [376] =>Toolbar.AVGSearch

O39 - APT: AVG-Secure-Search-Update_0214b_rmv - (...) -- C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rmv [376] =>Toolbar.AVGSearch

O39 - APT: FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core.job [902]

O39 - APT: FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core [902]

O39 - APT: FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA.job [924]

O39 - APT: FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA [924]

O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1066]

O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1066]

O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1070]

O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1070]

O39 - APT: GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core.job [922]

O39 - APT: GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core [922]

O39 - APT: GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA.job [974]

O39 - APT: GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA [974]

~ Scheduled Task: 42 Scanned in 00mn 03s

---\\ ActiveSetup Installed Components (O40)

O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation

O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation

O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll

O40 - ASIC: Internet Explorer [64Bits] - {2D46B6DC-2207-486B-B523-A557E6D54B47} . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\system32\cmd.exe =>.Microsoft Corporation

O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe =>.Microsoft Corporation

O40 - ASIC: Browsing Enhancements [64Bits] - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll

O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation

O40 - ASIC: Windows Desktop Update [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll

O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe

O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll

~ Active Setup: 10 Scanned in 00mn 00s

---\\ Drivers launched at startup (O41)

O41 - Driver: (adgnetworktdi) . (. - .) - C:\Windows\System32\drivers\adgnetworktdi.sys (.not file.)

O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys

O41 - Driver: (AppleCharger) . (...) - C:\Windows\System32\DRIVERS\AppleCharger.sys

O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys

O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys

O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys

O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys

O41 - Driver: (HWiNFO32) . (.REALiX(tm) - HWiNFO AMD64 Kernel Driver.) - C:\Windows\sysWOW64\drivers\HWiNFO64A.sys

O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\System32\DRIVERS\mssmbios.sys

O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys

O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys

O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys

O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys

O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys

O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys

O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys

O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys

O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\Windows\System32\DRIVERS\serial.sys

O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys

O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys

O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys

O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys

O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys

O41 - Driver: Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0 (ws2ifsl) . (.Microsoft Corporation - Couche IFS Winsock2.) - C:\Windows\system32\drivers\ws2ifsl.sys

~ Drivers: 72 Scanned in 00mn 00s

---\\ Software installed (O42)

O42 - Logiciel: "Солдат удачи: Расплата" версии 1.1.0.0 - (...) [HKLM][64Bits] -- SoldierofFortunePayback_is1

O42 - Logiciel: 4K Video to MP3 2.2 - (.Open Media LLC.) [HKLM][64Bits] -- 4K Video to MP3_is1

O42 - Logiciel: 4t Tray Minimizer Free 5.52 - (.4t Niagara Software.) [HKLM][64Bits] -- 4t Tray Minimizer_is1

O42 - Logiciel: 7-Zip 9.38 beta - (...) [HKLM][64Bits] -- 7-Zip

O42 - Logiciel: ABBYY FineReader 9.0 Sprint - (.ABBYY.) [HKLM][64Bits] -- ABBYY FineReader 9.0 Sprint

O42 - Logiciel: ABBYY FineReader 9.0 Sprint - (.ABBYY.) [HKLM][64Bits] -- {F9000000-0018-0000-0000-074957833700}

O42 - Logiciel: ABBYY FineReader11 Professional Edition - (...) [HKLM][64Bits] -- ABBYY FineReader11 Professional Edition

O42 - Logiciel: ACDSee Pro 2 - (.ACD Systems International.) [HKLM][64Bits] -- {4AAC95F4-A30E-4EE5-A086-6F79581D0D70}

O42 - Logiciel: Ace Stream Media 3.0.2 - (.Ace Stream Media.) [HKCU][64Bits] -- AceStream

O42 - Logiciel: Acunetix Web Vulnerability Scanner 8.0 - (.Acunetix.) [HKLM][64Bits] -- {DBD76811-6CF0-4A15-9436-B779C3A36929}_is1

O42 - Logiciel: AdFender - (.AdFender, Inc..) [HKLM][64Bits] -- AdFender

O42 - Logiciel: Adblock Plus for IE - (...) [HKLM][64Bits] -- {fd97d1e2-368a-4cd9-af63-8eeff938044a}

O42 - Logiciel: Adblock Plus для IE (32- и 64-разрядные версии) - (.Eyeo GmbH.) [HKLM][64Bits] -- {0E47CCC3-6D30-4CB7-A0A9-1375BBC02CCA}

O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR

O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {7BBAEC47-1CC0-4CB8-ADB4-531B78DBD1DD}

O42 - Logiciel: Adobe Acrobat 4.0 - (.Adobe Systems, Inc..) [HKLM][64Bits] -- Adobe Acrobat 4.0

O42 - Logiciel: Adobe Flash Player 16 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX

O42 - Logiciel: Adobe Flash Player 16 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI

O42 - Logiciel: Adobe Reader 64-bit fixes - (.Leo Davidson / Pretentious Name.) [HKLM][64Bits] -- {6D80AAE7-FF65-4950-B1CA-3A7EA4995574}_is1

O42 - Logiciel: Adobe Reader XI (11.0.10) - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1033-7B44-AB0000000001}

O42 - Logiciel: Adobe Shockwave Player 12.1 - (.Adobe Systems, Inc..) [HKLM][64Bits] -- Adobe Shockwave Player

O42 - Logiciel: Allmyapps - (.Allmyapps SAS.) [HKCU][64Bits] -- Allmyapps

O42 - Logiciel: AnVir Task Manager - (.AnVir Software.) [HKLM][64Bits] -- AnVir Task Manager

O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM][64Bits] -- {787136D2-F0F8-4625-AA3F-72D7795AC842}

O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM][64Bits] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} =>.Apple Inc

O42 - Logiciel: Applian FLV Player - (.Applian Technologies Inc..) [HKLM][64Bits] -- Applian FLV Player2.0.24 =>PUP.ApplianTechnologies

O42 - Logiciel: Applian FLV and Media Player 3.1.1.12 - (.Applian Technologies.) [HKLM][64Bits] -- Applian FLV and Media Player =>PUP.ApplianTechnologies

O42 - Logiciel: Ashampoo MP3 Check&Convert - (...) [HKLM][64Bits] -- Ashampoo MP3 Check&Convert

O42 - Logiciel: Avery Wizard 4.0 - (.Avery.) [HKLM][64Bits] -- {F97272B4-82C4-46B2-BCF1-C4D6E8CAB3E6}

O42 - Logiciel: Aviator - (.WhiteHat Security, Inc..) [HKLM][64Bits] -- {B0E4AA1D-76A7-48B5-AAA1-D68BDBB1FF99}

O42 - Logiciel: BlazeVideo HDTV Player 6.6 Professional - (...) [HKLM][64Bits] -- BlazeVideo HDTV Player 6.6 Professional_is1

O42 - Logiciel: BlindScanner Pro - (.Masters ITC Software.) [HKLM][64Bits] -- {3F02DFA9-EA6F-40E7-AF53-8750D6FB646B}_is1

O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] -- {6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}

O42 - Logiciel: Bullzip PDF Printer 10.8.0.2282 - (.Bullzip.) [HKLM][64Bits] -- Bullzip PDF Printer_is1

O42 - Logiciel: CacheMyWork - (.Codeplex.) [HKLM][64Bits] -- {4CD3A1CB-EB91-4DC5-B636-33B66BA56162}

O42 - Logiciel: Camfrog Web Advanced 2.0 ActiveX Plugin (remove only) - (...) [HKLM][64Bits] -- CFWebAdvancedU2

O42 - Logiciel: CamfrogWEB Advanced ActiveX Plugin (remove only) - (...) [HKLM][64Bits] -- CFWebAdvancedU

O42 - Logiciel: CamfrogWEB Advanced ActiveX Plugin (www.bobtv.fr) - (...) [HKLM][64Bits] -- CFWebAdvancedU_BOBTV.FR

O42 - Logiciel: Cartes de Visite - (...) [HKLM][64Bits] -- {888DF9D4-876E-11D7-B60C-00C04F4351FF}

O42 - Logiciel: Classic Menu for Office 2007 v5.00 - (.Addintools.) [HKLM][64Bits] -- {409ECFF1-9CC7-43A8-B28A-B7F0B7CB04D1}_is1

O42 - Logiciel: Clean Master - (.Cheetah Mobile.) [HKLM][64Bits] -- Clean Master

O42 - Logiciel: Clover 3.0 - (.EJIE Technology.) [HKLM][64Bits] -- Clover

O42 - Logiciel: Crystal TV 3.1.684 - (.Crystal Reality LLC.) [HKLM][64Bits] -- Crystal TV

O42 - Logiciel: CutePDF Professional 3.71 - (.Acro Software Inc..) [HKLM][64Bits] -- CutePDF Professional_is1

O42 - Logiciel: CutePDF Writer 3.0 - (.Acro Software Inc..) [HKLM][64Bits] -- CutePDF Writer Installation

O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}

O42 - Logiciel: Daum PotPlayer 1.5.33948 RU x64 - (.©7sh3. (Сборка от 26.07.2012).) [HKLM][64Bits] -- {69764025-6925-4F66-A38B-63AD94DB6746}_is1

O42 - Logiciel: DjVuLibre+DjView - (.DjVuZone.) [HKLM][64Bits] -- DjVuLibre+DjView

O42 - Logiciel: DriverMax 7 - (.Innovative Solutions.) [HKLM][64Bits] -- DMX5_is1

O42 - Logiciel: EPSON SX235 Series Printer Uninstall - (.SEIKO EPSON Corporation.) [HKLM][64Bits] -- EPSON SX235 Series

O42 - Logiciel: EPSON Scan - (.Seiko Epson Corporation.) [HKLM][64Bits] -- EPSON Scanner

O42 - Logiciel: Epson Easy Photo Print 2 - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {A02D7029-C4EF-44C1-9FD4-C0D3CA518113}

O42 - Logiciel: Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {B2D55EB8-32C5-4B43-9006-9E97DECBA178}

O42 - Logiciel: Epson Event Manager - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {8ED43F7E-A8F6-4898-AF11-B6158F2EDF94}

O42 - Logiciel: EpsonNet Print - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {3E31400D-274E-4647-916C-2CACC3741799}

O42 - Logiciel: Etron USB3.0 Host Controller - (.Etron Technology.) [HKLM][64Bits] -- InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}

O42 - Logiciel: Etron USB3.0 Host Controller - (.Etron Technology.) [HKLM][64Bits] -- {DFBB738C-71D8-4DC5-B8D2-D65C37680E27}

O42 - Logiciel: Facebook Video Calling 3.1.0.521 - (.Skype Limited.) [HKLM][64Bits] -- {2091F234-EB58-4B80-8C96-8EB78C808CF7}

O42 - Logiciel: Fake Webcam 7.3 - (.Web Solution Mart.) [HKLM][64Bits] -- fakewebcam7.3.0_is1

O42 - Logiciel: Fake Webcam Codecs Pack 1.0.0 - (.Web Solution Mart.) [HKLM][64Bits] -- fwccpsetup_is1

O42 - Logiciel: Firefox Developer Edition 38.0a2 (x86 ru) - (.Mozilla.) [HKLM][64Bits] -- Firefox Developer Edition 38.0a2 (x86 ru)

O42 - Logiciel: FormMax Filler 3.51 - (.Acro Software Inc..) [HKLM][64Bits] -- FormMax Filler_is1

O42 - Logiciel: FraudEliminator 2.4.0 - (.www.FraudEliminator.com.) [HKLM][64Bits] -- {48C619B9-C4ED-41C9-8F18-94B0C06AEE2D}

O42 - Logiciel: Free Folder Hider 12.03 - (.AuoBAUP, Inc..) [HKLM][64Bits] -- Free Folder Hider_is1

O42 - Logiciel: Galerie de photos - (.Microsoft Corporation.) [HKLM][64Bits] -- {F4D99A13-F63A-4FC1-8799-CFFDB78DDFB3}

O42 - Logiciel: Geotag Security 1.0 - (.Geotag Security Software, Inc.) [HKLM][64Bits] -- Geotag Security_is1

O42 - Logiciel: Ghostery IE Plugin - (.Ghostery.) [HKLM][64Bits] -- Ghostery IE Plugin_is1

O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome

O42 - Logiciel: Google Talk Plugin - (.Google.) [HKLM][64Bits] -- {C77CC230-7417-3F01-B70D-52583DC9FEC9}

O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {18455581-E099-4BA8-BC6B-F34B2F06600C}

O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F}

O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}

O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

O42 - Logiciel: Guide d'utilisation EPSON SX235 Series - (...) [HKLM][64Bits] -- EPSON SX235 Series Useg

O42 - Logiciel: Guide réseau EPSON SX235 Series - (...) [HKLM][64Bits] -- EPSON SX235 Series Netg

O42 - Logiciel: H.264 Encoder - (.www.H264Encoder.com.) [HKLM][64Bits] -- {B99459D2-B91A-417E-9DFA-F53D569F4445}_is1

O42 - Logiciel: Hauppauge WinTV 7 - (.Hauppauge Computer Works.) [HKLM][64Bits] -- Hauppauge WinTV 7

O42 - Logiciel: ICQ 8.3 (сборка 7317) - (.ICQ.) [HKCU][64Bits] -- ICQ

O42 - Logiciel: IP-TV Player 0.28.1.8834 - (.ООО АДСЛ Клуб.) [HKLM][64Bits] -- IP-TV_Player

O42 - Logiciel: IR Server Suite - (.Team MediaPortal.) [HKLM][64Bits] -- IR Server Suite

O42 - Logiciel: Intel(R) Control Center - (.Intel Corporation.) [HKLM][64Bits] -- {F8A9085D-4C7A-41a9-8A77-C8998A96C421}

O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {1CEAC85D-2590-4760-800F-8DE5E91F3700}

O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}

O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {D4FC649C-0247-4873-930D-D9E6904DCAF5}

O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {3DE97849-544D-4D68-9255-11DF6F9F10D8}

O42 - Logiciel: Internet Explorer (Enable DEP) - (...) [HKLM][64Bits] -- {a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb

O42 - Logiciel: Java 7 Update 60 (64-bit) - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F06417060FF}

O42 - Logiciel: Java 8 Update 25 (64-bit) - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F86418025F0}

O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM][64Bits] -- {F6F30C28-38AA-4DBA-AE0B-7E30238E61BB}

O42 - Logiciel: K!TV - (...) [HKLM][64Bits] -- K!TV

O42 - Logiciel: K-Meleon 1.5.4 ru-RU (только удаление) - (.K-Meleon Team.) [HKLM][64Bits] -- K-Meleon

O42 - Logiciel: Kazoo Player - (...) [HKLM][64Bits] -- Kazoo Player

O42 - Logiciel: Lagarith lossless video codec (Remove Only) - (...) [HKLM][64Bits] -- LAGARITH

O42 - Logiciel: Lunascape6 (All Users) - (.Lunascape.) [HKLM][64Bits] -- Lunascape6

O42 - Logiciel: MDAPI_Plus - (.Alexander Plyas.) [HKLM][64Bits] -- MDAPI_Plus

O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}

O42 - Logiciel: MSVCRT110 - (.Microsoft.) [HKLM][64Bits] -- {8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}

O42 - Logiciel: MSVCRT110_amd64 - (.Microsoft.) [HKLM][64Bits] -- {E9FA781F-3E80-4399-825A-AD3E11C28C77}

O42 - Logiciel: MSVCRT_amd64 - (.Microsoft.) [HKLM][64Bits] -- {D0B44725-3666-492D-BEF6-587A14BD9BD9}

O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM][64Bits] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}

O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM][64Bits] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}

O42 - Logiciel: MSXML 4.0 SP2 Parser and SDK - (.Microsoft Corporation.) [HKLM][64Bits] -- {716E0306-8318-4364-8B8F-0CC4E9376BAC}

O42 - Logiciel: Ma-Config.com (64 bits) - (.Cybelsoft.) [HKLM][64Bits] -- {FCE01EE0-46F1-4A40-85A5-A180E8F7350D}

O42 - Logiciel: Malwarebytes Anti-Malware, версия 2.0.4.1028 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes Anti-Malware_is1

O42 - Logiciel: ManyCam 4.0.44 - (.Visicom Media Inc..) [HKLM][64Bits] -- ManyCam

O42 - Logiciel: MaxTV - (.MaxTV Technologies.) [HKLM][64Bits] -- MaxTV

O42 - Logiciel: Microsoft Antimalware Service RU-RU Language Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {7F20FBE0-9939-4BA0-9290-628727D63D55}

O42 - Logiciel: Microsoft Fix it Center - (.Microsoft Corporation.) [HKLM][64Bits] -- {B7588D45-AFDC-4C93-9E2E-A100F3554B64}

O42 - Logiciel: Microsoft FrontPage 2002 - (.Microsoft Corporation.) [HKLM][64Bits] -- {9017040C-6000-11D3-8CFE-0050048383C9}

O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM][64Bits] -- {996D32B6-F629-4764-894B-CB24D9C19051}

O42 - Logiciel: Microsoft Security Client RU-RU Language Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {DC911ADF-7B60-40F2-A112-FB1EB6402D07}

O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Security Client

O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}

O42 - Logiciel: Microsoft SkyDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- SkyDriveSetup.exe =>.Microsoft Corporation

O42 - Logiciel: Microsoft Works - (.Microsoft Corporation.) [HKLM][64Bits] -- {93492218-15C0-4719-B898-05FC5769F2E6}

O42 - Logiciel: Mises à jour NVIDIA 1.10.8 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update

O42 - Logiciel: Monkey's Audio - (...) [HKLM][64Bits] -- Monkey's Audio_is1

O42 - Logiciel: Mozilla Firefox 35.0.1 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 35.0.1 (x86 fr)

O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService

O42 - Logiciel: Mp3tag v2.66 - (.Florian Heidenreich.) [HKLM][64Bits] -- Mp3tag

O42 - Logiciel: MyFreeCodec - (...) [HKCU][64Bits] -- MyFreeCodec

O42 - Logiciel: MySQL Server 5.1 - (.MySQL AB.) [HKLM][64Bits] -- {561AB451-B967-475C-80E0-3B6679C38B52}

O42 - Logiciel: NVIDIA Display Control Panel - (.NVIDIA Corporation.) [HKLM][64Bits] -- NVIDIA Display Control Panel

O42 - Logiciel: NVIDIA Pilote graphique 307.83 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver

O42 - Logiciel: Nero 7 Ultra Edition - (.Nero AG.) [HKLM][64Bits] -- {30C50520-1B5E-4FD1-A87B-444F86E21049}

O42 - Logiciel: ON_OFF Charge B11.0110.1 - (.GIGABYTE.) [HKLM][64Bits] -- {3DECD372-76A1-4483-BF10-B547790A3261}

O42 - Logiciel: Octoshape Streaming Services - (.Octoshape ApS.) [HKCU][64Bits] -- Octoshape Streaming Services

O42 - Logiciel: Office Tab FreeEdition - (.Detong Technology Ltd..) [HKLM][64Bits] -- {DE469D65-1DEB-4058-BF95-C642D733668D}_is1

O42 - Logiciel: Opera 12.17 - (.Opera Software ASA.) [HKLM][64Bits] -- Opera 12.17.1863

O42 - Logiciel: Opera Stable 27.0.1689.76 - (.Opera Software ASA.) [HKLM][64Bits] -- Opera 27.0.1689.76

O42 - Logiciel: PC Wizard 2013.2.12 - (.CPUID.) [HKLM][64Bits] -- PC Wizard 2013_is1

O42 - Logiciel: PDF Architect - (.pdfforge GmbH.) [HKLM][64Bits] -- {064A929A-4DE8-40CF-A901-BD40C14E4D25}

O42 - Logiciel: PDF Unlocker - (...) [HKLM][64Bits] -- PDF Unlocker

O42 - Logiciel: PDFCreator - (.pdfforge.) [HKLM][64Bits] -- {0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}

O42 - Logiciel: PIMOne 5.35 - (.PIMOne Software.) [HKLM][64Bits] -- PIMOne_is1

O42 - Logiciel: PVSonyDll - (.NVIDIA Corporation.) [HKLM][64Bits] -- {3D3E663D-4E7E-4577-A560-7ECDDD45548A}

O42 - Logiciel: Pamela Basic 4.8 - (.Scendix Software-Vertriebsges. mbH.) [HKLM][64Bits] -- Pamela

O42 - Logiciel: Parom.TV player - (...) [HKLM][64Bits] -- Parom.TV

O42 - Logiciel: Philips SPC 900NC PC Camera - (...) [HKLM][64Bits] -- {220F6386-5D1F-4DA5-94DB-F12133C3AE2C}

O42 - Logiciel: Philips VLounge - (.ArcSoft.) [HKLM][64Bits] -- {89ACA875-BDB9-443C-B7C7-D74D3BDE8FE2}

O42 - Logiciel: PlayReady PC Runtime amd64 - (.Microsoft Corporation.) [HKLM][64Bits] -- {BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}

O42 - Logiciel: Potplayer - (.Daum Kakao Corp..) [HKLM][64Bits] -- PotPlayer

O42 - Logiciel: PowerChute Personal Edition 3.0.2 - (.Schneider Electric.) [HKLM][64Bits] -- {8ED262EE-FC73-47A9-BB86-D92223246881}

O42 - Logiciel: ProgDVB x64 - (.Prog.) [HKLM][64Bits] -- ProgDVB

O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM][64Bits] -- {B67BAFBA-4C9F-48FA-9496-933E3B255044}

O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476}

O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}

O42 - Logiciel: Reg Organizer, версия 6.55 - (.ChemTable Software.) [HKLM][64Bits] -- Reg Organizer_is1

O42 - Logiciel: Roadkil's Unstoppable Copier Version 5.2 - (.Roadkil.Net.) [HKLM][64Bits] -- {A306FD29-7D3A-4287-91AC-9A0180931395}_is1

O42 - Logiciel: Rumote VMC Plugin - (...) [HKLM][64Bits] -- {af46b9c7-3b0c-4ebb-86fb-349203430866}

O42 - Logiciel: Rumote VMC Plugin 2.1.4 - (.Rumote.) [HKLM][64Bits] -- {93014103-9212-4AC7-9CD1-77544704BAC3}

O42 - Logiciel: RunMe 0.9 - (.KSoft.) [HKLM][64Bits] -- RunMe

O42 - Logiciel: SAMSUNG USB Driver for Mobile Phones - (.SAMSUNG Electronics Co., Ltd..) [HKLM][64Bits] -- {D0795B21-0CDA-4a92-AB9E-6E92D8111E44}

O42 - Logiciel: Samsung Kies - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- InstallShield_{758C8301-2696-4855-AF45-534B1200980A}

O42 - Logiciel: Samsung Kies - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- {758C8301-2696-4855-AF45-534B1200980A}

O42 - Logiciel: Samsung Story Album Viewer - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- InstallShield_{698BBAD8-B116-495D-B879-0F07A533E57F}

O42 - Logiciel: Samsung Story Album Viewer - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- {698BBAD8-B116-495D-B879-0F07A533E57F}

O42 - Logiciel: Scan Tailor - (...) [HKLM][64Bits] -- Scan Tailor

O42 - Logiciel: Secure Eraser - (.ASCOMP Software GmbH.) [HKLM][64Bits] -- Secure Eraser_is1

O42 - Logiciel: SiSoftware Sandra Business 2013 - (.SiSoftware.) [HKLM][64Bits] -- {C3113E55-7BCB-4de3-8EBF-60E6CE6B2396}_is1

O42 - Logiciel: Simple Adblock - (.Simple Adblock.) [HKLM][64Bits] -- {B4920103-09F6-4AD2-B150-CFC4474D2DDC}

O42 - Logiciel: Skype™ 7.1 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}

O42 - Logiciel: SlimDrivers - (.SlimWare Utilities, Inc..) [HKLM][64Bits] -- {A5457401-D56A-43F2-9524-78E54A7FC07A}

O42 - Logiciel: Solid Converter PDF - (.SolidDocuments.) [HKLM][64Bits] -- {56BFAA6E-2BCC-4AED-9233-84731E66B205}

O42 - Logiciel: SopCast 3.9.2 - (.www.sopcast.com.) [HKLM][64Bits] -- SopCast

O42 - Logiciel: Sopcast Toolbar - (.APN, LLC.) [HKLM][64Bits] -- {53504356-3700-A76A-76A7-A758B70C0600} =>Toolbar.Ask

O42 - Logiciel: Stardock Fences 2 - (.Stardock Software, Inc..) [HKLM][64Bits] -- Stardock Fences 2

O42 - Logiciel: StreamTransport version: 1.1.3.0 - (...) [HKLM][64Bits] -- {FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1

O42 - Logiciel: System Explorer 5.9.5 - (.Mister Group.) [HKLM][64Bits] -- {40F485F7-6478-4896-B0D5-F94BE677EB78}_is1

O42 - Logiciel: TELL ME MORE - (...) [HKLM][64Bits] -- TMM70

O42 - Logiciel: Teleport Ultra - (.Tennyson Maxwell Information Systems, Inc..) [HKLM][64Bits] -- Teleport Ultra

O42 - Logiciel: TeraCopy 2.3 - (.Code Sector.) [HKLM][64Bits] -- TeraCopy_is1

O42 - Logiciel: URL Helper - (...) [HKLM][64Bits] -- URL Helper_is1

O42 - Logiciel: URL Snooper v2.35.01 - (.DonationCoder.com.) [HKLM][64Bits] -- URLSnooper 2_is1

O42 - Logiciel: Uninstall Tool - (.CrystalIDEA Software, Inc..) [HKLM][64Bits] -- Uninstall Tool_is1

O42 - Logiciel: Unlocker 1.9.2 - (.Cedrick Collomb.) [HKLM][64Bits] -- Unlocker

O42 - Logiciel: VC80CRTRedist - 8.0.50727.6195 - (.DivX, Inc.) [HKLM][64Bits] -- {933B4015-4618-4716-A828-5289FC03165F}

O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN

O42 - Logiciel: VMware Player - (.VMware, Inc.) [HKLM][64Bits] -- VMware_Player

O42 - Logiciel: VMware Player - (.VMware, Inc..) [HKLM][64Bits] -- {E452E727-86B8-4233-8CC3-41FD817AFAFF}

O42 - Logiciel: WOT for Internet Explorer - (.WOT Services Oy.) [HKLM][64Bits] -- {373B90E1-A28C-434C-92B6-7281AFA6115A}

O42 - Logiciel: WinPcap 4.1.3 - (.Riverbed Technology, Inc..) [HKLM][64Bits] -- WinPcapInst

O42 - Logiciel: WinRAR 5.11 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver

O42 - Logiciel: Windows Firewall Control - (.Alexandru Dicu.) [HKLM][64Bits] -- WindowsFirewallControl

O42 - Logiciel: Windows Firewall Control - (.BiniSoft.org.) [HKLM][64Bits] -- Windows Firewall Control

O42 - Logiciel: Windows Media Player 64-bit Plug-in Fix - (...) [HKLM][64Bits] -- {00a8ce68-cb2e-4652-aecd-c05c0d9d53a7}.sdb =>.Microsoft Corporation

O42 - Logiciel: Windows Media Player Firefox Plugin - (.Microsoft Corp.) [HKLM][64Bits] -- {69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} =>.Microsoft Corporation

O42 - Logiciel: Windows Media Player Plus! 2.6 - (.BM-productions.) [HKLM][64Bits] -- {67E4EF06-E0D6-42E0-A2BA-67199B0143FB}_is1 =>.Microsoft Corporation

O42 - Logiciel: XBMC - (.Team XBMC.) [HKCU][64Bits] -- XBMC

O42 - Logiciel: Zattoo4 4.0.5 - (.Zattoo Inc..) [HKLM][64Bits] -- Zattoo4

O42 - Logiciel: ffdshow x64 v1.3.4531 [2014-06-28] - (...) [HKLM][64Bits] -- ffdshow64_is1

O42 - Logiciel: ooVoo - (.ooVoo LLC..) [HKLM][64Bits] -- {FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}

O42 - Logiciel: paint.net - (.dotPDN LLC.) [HKLM][64Bits] -- {19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}

O42 - Logiciel: rue des йcoles - Super Vacances vers le CM1 - (...) [HKLM][64Bits] -- SupVac09

O42 - Logiciel: swMSM - (.Adobe Systems, Inc.) [HKLM][64Bits] -- {612C34C7-5E90-47D8-9B5C-0F717DD82726}

O42 - Logiciel: tools-freebsd - (.VMware, Inc..) [HKLM][64Bits] -- {003BFBBD-6C67-419E-A24D-0DCAFC3A5249}

O42 - Logiciel: tools-linux - (.VMware, Inc..) [HKLM][64Bits] -- {D102611A-6466-4101-A51D-51069303AC65}

O42 - Logiciel: tools-netware - (.VMware, Inc..) [HKLM][64Bits] -- {197597A7-AD33-4898-9D8E-73066818B464}

O42 - Logiciel: tools-solaris - (.VMware, Inc..) [HKLM][64Bits] -- {AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}

O42 - Logiciel: tools-winPre2k - (.VMware, Inc..) [HKLM][64Bits] -- {AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}

O42 - Logiciel: tools-windows - (.VMware, Inc..) [HKLM][64Bits] -- {FFD9383C-01D5-4897-A954-43AF599AED30}

O42 - Logiciel: Поддержка программ Apple - (.Apple Inc..) [HKLM][64Bits] -- {AAC5D43E-816D-4C2D-8E51-55FFF35BE301}

O42 - Logiciel: Установка DivX - (.DivX, LLC.) [HKLM][64Bits] -- DivX Setup

~ Logic: 107 Scanned in 00mn 00s

novotek
 Posté le 10/03/2015 à 08:39 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

---\\ HKCU & HKLM Software Keys

[HKCU\Software\2LMultimedia]

[HKCU\Software\2vg]

[HKCU\Software\4kdownload.com]

[HKCU\Software\4t Niagara Software]

[HKCU\Software\7-Zip]

[HKCU\Software\ABBYY]

[HKCU\Software\ACD Systems]

[HKCU\Software\ACE Compression Software]

[HKCU\Software\APC]

[HKCU\Software\ASCOMP]

[HKCU\Software\ASProtect]

[HKCU\Software\AVS4YOU]

[HKCU\Software\Acro Software Inc]

[HKCU\Software\Acunetix]

[HKCU\Software\AdblockPlus]

[HKCU\Software\AddinTools]

[HKCU\Software\Adobe]

[HKCU\Software\Ahead]

[HKCU\Software\Ainvo]

[HKCU\Software\All-Radio]

[HKCU\Software\Anvide Labs]

[HKCU\Software\Anvir]

[HKCU\Software\AppDataLow\IEPro]

[HKCU\Software\AppDataLow\Software\Adobe]

[HKCU\Software\AppDataLow\Software\Against Intuition]

[HKCU\Software\AppDataLow\Software\DivX]

[HKCU\Software\AppDataLow\Software\G DATA]

[HKCU\Software\AppDataLow\Software\JavaSoft]

[HKCU\Software\AppDataLow\Software\Mail.Ru]

[HKCU\Software\AppDataLow\Software\MarkAny]

[HKCU\Software\AppDataLow\Software\ThinPrint]

[HKCU\Software\AppDataLow\Software\Yahoo]

[HKCU\Software\AppDataLow]

[HKCU\Software\Apple Computer, Inc.]

[HKCU\Software\Apple Inc.]

[HKCU\Software\Auralog]

[HKCU\Software\Auslogics]

[HKCU\Software\Avant Browser]

[HKCU\Software\Avery]

[HKCU\Software\Aviator]

[HKCU\Software\BExplorer]

[HKCU\Software\BM-productions]

[HKCU\Software\BST]

[HKCU\Software\Binary Noise]

[HKCU\Software\BiniSoft.org]

[HKCU\Software\BlazeVideo]

[HKCU\Software\Borland]

[HKCU\Software\CPUID]

[HKCU\Software\CSoftLab]

[HKCU\Software\CamfrogWeb]

[HKCU\Software\Camfrog]

[HKCU\Software\Canneverbe Limited]

[HKCU\Software\Carthago]

[HKCU\Software\ChemTable Software]

[HKCU\Software\ChrisPC JTV Player]

[HKCU\Software\ChrisTV Online]

[HKCU\Software\ChromePlus]

[HKCU\Software\Chromium]

[HKCU\Software\Classes]

[HKCU\Software\Clients]

[HKCU\Software\Clover]

[HKCU\Software\Code Sector]

[HKCU\Software\CoreFLAC]

[HKCU\Software\Crystal Reality]

[HKCU\Software\CrystalIdea Software]

[HKCU\Software\DPP]

[HKCU\Software\DSP-worx]

[HKCU\Software\Dating Notifier (Wekiss)]

[HKCU\Software\Daum]

[HKCU\Software\David Esperalta]

[HKCU\Software\Depositfiles]

[HKCU\Software\DevID]

[HKCU\Software\DivXNetworks]

[HKCU\Software\DivX]

[HKCU\Software\DjVuLibre]

[HKCU\Software\Dominsoft]

[HKCU\Software\DownloadCenter]

[HKCU\Software\EFD Software]

[HKCU\Software\EPSON]

[HKCU\Software\Enterbrain]

[HKCU\Software\Evernote]

[HKCU\Software\Explorer++]

[HKCU\Software\ExtendOffice]

[HKCU\Software\Eyeball]

[HKCU\Software\Facebook]

[HKCU\Software\FinalWire]

[HKCU\Software\Foxit Software]

[HKCU\Software\FraudEliminatorToolBar]

[HKCU\Software\Freecorder]

[HKCU\Software\Freeware]

[HKCU\Software\FreshDevices]

[HKCU\Software\Froggie]

[HKCU\Software\GNU]

[HKCU\Software\Gabest]

[HKCU\Software\Geek Uninstaller]

[HKCU\Software\Ghostery]

[HKCU\Software\GlarySoft]

[HKCU\Software\Google]

[HKCU\Software\Haali]

[HKCU\Software\Hachette Multimedia]

[HKCU\Software\Haihaisoft PDF Reader]

[HKCU\Software\Hensense.com]

[HKCU\Software\HiDownloadPlatinum]

[HKCU\Software\I.R.I.S. Applications]

[HKCU\Software\IM Providers]

[HKCU\Software\ImgBurn]

[HKCU\Software\Infium]

[HKCU\Software\Innovative Solutions]

[HKCU\Software\IvoSoft]

[HKCU\Software\JEDI-VCL]

[HKCU\Software\K-Meleon]

[HKCU\Software\KC Softwares]

[HKCU\Software\Kartina.TV]

[HKCU\Software\LAV64]

[HKCU\Software\LAV]

[HKCU\Software\Licenses]

[HKCU\Software\LizardTech]

[HKCU\Software\Local AppWizard-Generated Applications]

[HKCU\Software\LopeSoft]

[HKCU\Software\Lunascape Corporation]

[HKCU\Software\MCAFEE]

[HKCU\Software\MONOGRAM]

[HKCU\Software\Macromedia]

[HKCU\Software\Mail.Ru]

[HKCU\Software\MainConcept (HCW)]

[HKCU\Software\MainConcept]

[HKCU\Software\Makayama]

[HKCU\Software\Malware Destroyer 6]

[HKCU\Software\Malware Destroyer 7]

[HKCU\Software\Malwarebytes' Anti-Malware (portable)]

[HKCU\Software\Malwarebytes' Anti-Malware]

[HKCU\Software\ManyCam]

[HKCU\Software\Master Commander]

[HKCU\Software\MasterMedia]

[HKCU\Software\Masters ITC]

[HKCU\Software\MediaLingua]

[HKCU\Software\Mediachance]

[HKCU\Software\Monkey's Audio]

[HKCU\Software\MozillaPlugins]

[HKCU\Software\Mozilla]

[HKCU\Software\NVIDIA Corporation]

[HKCU\Software\Nero]

[HKCU\Software\Netscape]

[HKCU\Software\Neuber GbR]

[HKCU\Software\NewSoftware's]

[HKCU\Software\NuonSoft]

[HKCU\Software\ODBC]

[HKCU\Software\OJOsoft Corporation]

[HKCU\Software\Octoshape]

[HKCU\Software\Onet Pliki]

[HKCU\Software\Onet.pl]

[HKCU\Software\Opera Software]

[HKCU\Software\PDF Architect]

[HKCU\Software\PDFCreator.net]

[HKCU\Software\PDFCreator]

[HKCU\Software\Paint.NET]

[HKCU\Software\Parom.TV]

[HKCU\Software\Pinnacle Systems]

[HKCU\Software\PistonSoft]

[HKCU\Software\Policies]

[HKCU\Software\ProcessLasso]

[HKCU\Software\ProtectedData]

[HKCU\Software\QIP]

[HKCU\Software\Quizo]

[HKCU\Software\RDE]

[HKCU\Software\RISING]

[HKCU\Software\Realtek]

[HKCU\Software\RegisteredApplications]

[HKCU\Software\Remedy Entertainment]

[HKCU\Software\Resort Labs]

[HKCU\Software\Rightmark]

[HKCU\Software\Rising Sun Solutions, Inc.]

[HKCU\Software\Roadkil]

[HKCU\Software\RocketDock]

[HKCU\Software\Rumote]

[HKCU\Software\SIV]

[HKCU\Software\SUPERAntiSpyware.com]

[HKCU\Software\Safer Networking Limited]

[HKCU\Software\Samsung]

[HKCU\Software\Scan Tailor]

[HKCU\Software\Scanitto]

[HKCU\Software\Secunia]

[HKCU\Software\Settings]

[HKCU\Software\SiSoftware]

[HKCU\Software\SightSpeed Inc]

[HKCU\Software\SimpleTV by SergeyVS#3]

[HKCU\Software\Sippoint]

[HKCU\Software\SkypeRS]

[HKCU\Software\Skype]

[HKCU\Software\SlimWare Utilities Inc]

[HKCU\Software\Softland]

[HKCU\Software\SolidDocuments]

[HKCU\Software\Spoon]

[HKCU\Software\Stardock]

[HKCU\Software\Stdin2]

[HKCU\Software\Streamripper]

[HKCU\Software\SyncApp]

[HKCU\Software\Sysinternals]

[HKCU\Software\TAdvCheckList]

[HKCU\Software\TL]

[HKCU\Software\Tennyson Maxwell]

[HKCU\Software\The Silicon Realms Toolworks]

[HKCU\Software\ToolbarCleaner]

[HKCU\Software\ToolbarCleaneroptions]

[HKCU\Software\Trolltech]

[HKCU\Software\TweakNow RegCleaner 2011]

[HKCU\Software\URLHelper]

[HKCU\Software\VB and VBA Program Settings]

[HKCU\Software\VMware, Inc.]

[HKCU\Software\VOB]

[HKCU\Software\VOS]

[HKCU\Software\VSO]

[HKCU\Software\Valve]

[HKCU\Software\VideoLAN]

[HKCU\Software\VirtualDub.org]

[HKCU\Software\Visicom Media Inc]

[HKCU\Software\VueScan]

[HKCU\Software\Web Solution Mart]

[HKCU\Software\WhiteHat]

[HKCU\Software\WinAbility]

[HKCU\Software\WinHTTrack Website Copier]

[HKCU\Software\WinRAR SFX]

[HKCU\Software\WinRAR]

[HKCU\Software\Winamp-BackupByWinampPortable]

[HKCU\Software\Winamp]

[HKCU\Software\Winreview.ru]

[HKCU\Software\Winternals]

[HKCU\Software\Wondershare]

[HKCU\Software\Wow6432Node]

[HKCU\Software\Xenocode]

[HKCU\Software\Y's]

[HKCU\Software\Yahoo]

[HKCU\Software\Zattoo]

[HKCU\Software\ZebHelpProcess Helper]

[HKCU\Software\cmcm]

[HKCU\Software\eBooks]

[HKCU\Software\eSellerate]

[HKCU\Software\fwc]

[HKCU\Software\hugin]

[HKCU\Software\ooVoo]

[HKCU\Software\pth264]

[HKCU\Software\sipXtapi]

[HKCU\Software\torora.net]

[HKCU\Software\zyceffab]

[HKCU\Software\zyceffmorg]

[HKLM\Software\ACD Systems]

[HKLM\Software\ATI Technologies]

[HKLM\Software\Acro Software Inc]

[HKLM\Software\Adblock Plus for IE]

[HKLM\Software\Ainvo]

[HKLM\Software\Apple Computer, Inc.]

[HKLM\Software\Apple Inc.]

[HKLM\Software\Bullzip]

[HKLM\Software\CBSTEST]

[HKLM\Software\Classes]

[HKLM\Software\Clients]

[HKLM\Software\Code Sector]

[HKLM\Software\Creative Tech]

[HKLM\Software\Debug]

[HKLM\Software\DivX]

[HKLM\Software\EPSON]

[HKLM\Software\EpsonNet]

[HKLM\Software\ExtendOffice]

[HKLM\Software\GEAR Software]

[HKLM\Software\GNU]

[HKLM\Software\HaaliMkx]

[HKLM\Software\Hauppauge]

[HKLM\Software\Hewlett-Packard]

[HKLM\Software\IM Providers]

[HKLM\Software\Intel]

[HKLM\Software\Jasmio]

[HKLM\Software\JavaSoft]

[HKLM\Software\JreMetrics]

[HKLM\Software\Khronos]

[HKLM\Software\Licenses]

[HKLM\Software\Macromedia]

[HKLM\Software\MozillaPlugins]

[HKLM\Software\Mozilla]

[HKLM\Software\NVIDIA Corporation]

[HKLM\Software\Nuance]

[HKLM\Software\ODBC]

[HKLM\Software\PDFCreator.net]

[HKLM\Software\Policies]

[HKLM\Software\RTLSetup]

[HKLM\Software\Realtek]

[HKLM\Software\RegisteredApplications]

[HKLM\Software\SAMSUNG]

[HKLM\Software\SIV]

[HKLM\Software\SRS Labs]

[HKLM\Software\SUPERAntiSpyware.com]

[HKLM\Software\SiSoftware]

[HKLM\Software\Soft4Boost]

[HKLM\Software\SolidDocuments]

[HKLM\Software\Sonic]

[HKLM\Software\Stardock]

[HKLM\Software\Synaptics]

[HKLM\Software\VMware, Inc.]

[HKLM\Software\VideoLAN]

[HKLM\Software\Volatile]

[HKLM\Software\Waves Audio]

[HKLM\Software\WinRAR]

[HKLM\Software\Wow6432Node\ABBYY]

[HKLM\Software\Wow6432Node\ACD Systems]

[HKLM\Software\Wow6432Node\APC]

[HKLM\Software\Wow6432Node\AVS4YOU]

[HKLM\Software\Wow6432Node\Acro Software Inc]

[HKLM\Software\Wow6432Node\Acro Software]

[HKLM\Software\Wow6432Node\Acunetix]

[HKLM\Software\Wow6432Node\AddinTools]

[HKLM\Software\Wow6432Node\Adobe]

[HKLM\Software\Wow6432Node\AdwCleaner]

[HKLM\Software\Wow6432Node\Ahead]

[HKLM\Software\Wow6432Node\AppDataLow]

[HKLM\Software\Wow6432Node\Apple Computer, Inc.]

[HKLM\Software\Wow6432Node\Apple Inc.]

[HKLM\Software\Wow6432Node\Applian Technologies] =>PUP.ApplianTechnologies

[HKLM\Software\Wow6432Node\ArcSoft]

[HKLM\Software\Wow6432Node\Auralog]

[HKLM\Software\Wow6432Node\Avg Secure Update]

[HKLM\Software\Wow6432Node\AviSynth]

[HKLM\Software\Wow6432Node\BM-productions]

[HKLM\Software\Wow6432Node\Better Explorer Team]

[HKLM\Software\Wow6432Node\Blue Ridge Networks]

[HKLM\Software\Wow6432Node\Borland]

[HKLM\Software\Wow6432Node\Canon]

[HKLM\Software\Wow6432Node\Caphyon]

[HKLM\Software\Wow6432Node\Cauldron]

[HKLM\Software\Wow6432Node\Chromium]

[HKLM\Software\Wow6432Node\Classes]

[HKLM\Software\Wow6432Node\Clients]

[HKLM\Software\Wow6432Node\ComodoGroup]

[HKLM\Software\Wow6432Node\Comodo]

[HKLM\Software\Wow6432Node\Cygwin]

[HKLM\Software\Wow6432Node\DAUM]

[HKLM\Software\Wow6432Node\Dating]

[HKLM\Software\Wow6432Node\Debug]

[HKLM\Software\Wow6432Node\Depositfiles]

[HKLM\Software\Wow6432Node\DevID]

[HKLM\Software\Wow6432Node\DivXNetworks]

[HKLM\Software\Wow6432Node\DivX]

[HKLM\Software\Wow6432Node\EPSON]

[HKLM\Software\Wow6432Node\EpsonNet]

[HKLM\Software\Wow6432Node\ExtendOffice]

[HKLM\Software\Wow6432Node\Eyeball]

[HKLM\Software\Wow6432Node\Florian Heidenreich]

[HKLM\Software\Wow6432Node\FotoNation]

[HKLM\Software\Wow6432Node\Freecorder]

[HKLM\Software\Wow6432Node\FreshDevices]

[HKLM\Software\Wow6432Node\GIGABYTE]

[HKLM\Software\Wow6432Node\GPL Ghostscript]

[HKLM\Software\Wow6432Node\GlarySoft]

[HKLM\Software\Wow6432Node\Google]

[HKLM\Software\Wow6432Node\HPrefs]

[HKLM\Software\Wow6432Node\HaaliMkx]

[HKLM\Software\Wow6432Node\Hauppauge]

[HKLM\Software\Wow6432Node\IM Providers]

[HKLM\Software\Wow6432Node\IObit]

[HKLM\Software\Wow6432Node\Innovative Solutions]

[HKLM\Software\Wow6432Node\InstallShield]

[HKLM\Software\Wow6432Node\Intel]

[HKLM\Software\Wow6432Node\InterVideo]

[HKLM\Software\Wow6432Node\JavaSoft]

[HKLM\Software\Wow6432Node\JreMetrics]

[HKLM\Software\Wow6432Node\Khronos]

[HKLM\Software\Wow6432Node\Kodak]

[HKLM\Software\Wow6432Node\LEAD Technologies, Inc.]

[HKLM\Software\Wow6432Node\Licenses]

[HKLM\Software\Wow6432Node\LightWork Design]

[HKLM\Software\Wow6432Node\LucasArts Entertainment Company LLC]

[HKLM\Software\Wow6432Node\Lunascape Corporation]

[HKLM\Software\Wow6432Node\Macromedia]

[HKLM\Software\Wow6432Node\Mail.Ru]

[HKLM\Software\Wow6432Node\Malware Destroyer 7]

[HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware (portable)]

[HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware]

[HKLM\Software\Wow6432Node\McAfee.com]

[HKLM\Software\Wow6432Node\Mindscape]

[HKLM\Software\Wow6432Node\Moyea]

[HKLM\Software\Wow6432Node\MozillaPlugins]

[HKLM\Software\Wow6432Node\Mozilla]

[HKLM\Software\Wow6432Node\MySQL AB]

[HKLM\Software\Wow6432Node\NHN Corporation]

[HKLM\Software\Wow6432Node\NVIDIA Corporation]

[HKLM\Software\Wow6432Node\Naver]

[HKLM\Software\Wow6432Node\Nero]

[HKLM\Software\Wow6432Node\Netscape]

[HKLM\Software\Wow6432Node\Nuance]

[HKLM\Software\Wow6432Node\ODBC]

[HKLM\Software\Wow6432Node\Onet.pl]

[HKLM\Software\Wow6432Node\Opera Software]

[HKLM\Software\Wow6432Node\PDFCreator]

[HKLM\Software\Wow6432Node\Philips]

[HKLM\Software\Wow6432Node\Pinnacle Systems]

[HKLM\Software\Wow6432Node\Policies]

[HKLM\Software\Wow6432Node\Quadrant International, Inc.]

[HKLM\Software\Wow6432Node\Realtek Semiconductor Corp.]

[HKLM\Software\Wow6432Node\Realtek]

[HKLM\Software\Wow6432Node\RegisteredApplications]

[HKLM\Software\Wow6432Node\Rockstar Games]

[HKLM\Software\Wow6432Node\Rumote]

[HKLM\Software\Wow6432Node\S3R521]

[HKLM\Software\Wow6432Node\SEIKO EPSON CORPORATION]

[HKLM\Software\Wow6432Node\Samsung]

[HKLM\Software\Wow6432Node\Secunia]

[HKLM\Software\Wow6432Node\SimpleAdblock]

[HKLM\Software\Wow6432Node\Skype]

[HKLM\Software\Wow6432Node\SlimWare Utilities Inc]

[HKLM\Software\Wow6432Node\Soft4Boost]

[HKLM\Software\Wow6432Node\SoftRM]

[HKLM\Software\Wow6432Node\SolidDocuments]

[HKLM\Software\Wow6432Node\Sony Corporation]

[HKLM\Software\Wow6432Node\Stardock]

[HKLM\Software\Wow6432Node\Stardvb]

[HKLM\Software\Wow6432Node\StreamTransport]

[HKLM\Software\Wow6432Node\Symantec]

[HKLM\Software\Wow6432Node\SystemExplorer]

[HKLM\Software\Wow6432Node\SystemInfoBapm670]

[HKLM\Software\Wow6432Node\ThinPrint]

[HKLM\Software\Wow6432Node\TuneUp]

[HKLM\Software\Wow6432Node\VMware, Inc.]

[HKLM\Software\Wow6432Node\VideoLAN]

[HKLM\Software\Wow6432Node\Volatile]

[HKLM\Software\Wow6432Node\Web Solution Mart]

[HKLM\Software\Wow6432Node\Webteh]

[HKLM\Software\Wow6432Node\WhiteHat]

[HKLM\Software\Wow6432Node\WinAbility]

[HKLM\Software\Wow6432Node\WinPcap]

[HKLM\Software\Wow6432Node\Winmend]

[HKLM\Software\Wow6432Node\Wise Solutions]

[HKLM\Software\Wow6432Node\Wondershare]

[HKLM\Software\Wow6432Node\Wow6432Node]

[HKLM\Software\Wow6432Node\Yahoo]

[HKLM\Software\Wow6432Node\ashampoo]

[HKLM\Software\Wow6432Node\cmcm]

[HKLM\Software\Wow6432Node\eSellerate]

[HKLM\Software\Wow6432Node\fCoder]

[HKLM\Software\Wow6432Node\mozilla.org]

[HKLM\Software\Wow6432Node\rue des йcoles]

[HKLM\Software\Wow6432Node]

[HKLM\Software\cybelsoft]

[HKLM\Software\fCoder]

[HKLM\Software\mozilla.org]

[HKLM\Software\paint.net]

~ Key Software: 766 Scanned in 00mn 00s

novotek
 Posté le 10/03/2015 à 08:40 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

---\\ Contents of the Common Files folders (O43)

O43 - CFD: 26.02.2015 - 21:25:24 - [] ----D C:\Program Files (x86)\4KDownload

O43 - CFD: 19.12.2013 - 13:14:26 - [] ----D C:\Program Files (x86)\4t Tray Minimizer

O43 - CFD: 08.03.2015 - 23:12:47 - [] ----D C:\Program Files (x86)\7-Zip

O43 - CFD: 10.06.2012 - 3:11:26 - [] ----D C:\Program Files (x86)\ABBYY FineReader 11

O43 - CFD: 28.03.2012 - 23:55:23 - [] ----D C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint

O43 - CFD: 22.04.2012 - 19:15:25 - [] ----D C:\Program Files (x86)\ACD Systems

O43 - CFD: 05.09.2014 - 18:44:02 - [] ----D C:\Program Files (x86)\Acro Software

O43 - CFD: 16.11.2013 - 18:50:13 - [] ----D C:\Program Files (x86)\Acunetix

O43 - CFD: 27.11.2012 - 0:13:40 - [] ----D C:\Program Files (x86)\AdFender

O43 - CFD: 21.07.2014 - 21:34:11 - [] ----D C:\Program Files (x86)\Adobe

O43 - CFD: 17.06.2013 - 22:58:56 - [] ----D C:\Program Files (x86)\Adobe Reader 64-bit fixes

O43 - CFD: 10.09.2014 - 15:56:09 - [] ----D C:\Program Files (x86)\AnVir Task Manager

O43 - CFD: 12.06.2013 - 7:30:54 - [] ----D C:\Program Files (x86)\APC

O43 - CFD: 02.04.2012 - 13:11:30 - [] ----D C:\Program Files (x86)\Apple Software Update =>.Apple Inc

O43 - CFD: 25.04.2012 - 19:30:49 - [] ----D C:\Program Files (x86)\Applian Technologies =>PUP.ApplianTechnologies

O43 - CFD: 24.06.2013 - 13:50:05 - [] ----D C:\Program Files (x86)\ASCOMP Software

O43 - CFD: 28.04.2013 - 19:53:45 - [] ----D C:\Program Files (x86)\ashampoo

O43 - CFD: 31.08.2013 - 22:06:23 - [] ----D C:\Program Files (x86)\Auralog

O43 - CFD: 31.08.2013 - 20:26:26 - [0] ----D C:\Program Files (x86)\AVS4YOU

O43 - CFD: 02.05.2012 - 23:04:43 - [] ----D C:\Program Files (x86)\BlazeVideo

O43 - CFD: 08.06.2013 - 18:16:08 - [] ----D C:\Program Files (x86)\BlindScanner Pro

O43 - CFD: 05.04.2012 - 22:27:00 - [] ----D C:\Program Files (x86)\Bonjour

O43 - CFD: 11.12.2012 - 22:51:18 - [] ----D C:\Program Files (x86)\CacheMyWork

O43 - CFD: 09.01.2015 - 11:43:52 - [0] ----D C:\Program Files (x86)\Camfrog

O43 - CFD: 11.12.2014 - 18:59:58 - [] ----D C:\Program Files (x86)\CFWebAdvancedU2

O43 - CFD: 07.01.2014 - 20:06:57 - [] ----D C:\Program Files (x86)\CFWebAdvancedU_BOBTV.FR

O43 - CFD: 05.04.2012 - 1:10:13 - [] ----D C:\Program Files (x86)\Classic Menu for Office

O43 - CFD: 05.09.2014 - 15:31:02 - [] ----D C:\Program Files (x86)\Clover

O43 - CFD: 06.03.2015 - 10:02:17 - [] ----D C:\Program Files (x86)\cmcm

O43 - CFD: 09.03.2015 - 2:42:44 - [] ----D C:\Program Files (x86)\Common Files

O43 - CFD: 10.09.2014 - 23:31:10 - [] ----D C:\Program Files (x86)\CPUID

O43 - CFD: 08.09.2014 - 1:13:18 - [] ----D C:\Program Files (x86)\Crystal TV

O43 - CFD: 14.12.2014 - 0:36:20 - [] ----D C:\Program Files (x86)\DAUM

O43 - CFD: 23.05.2013 - 23:05:28 - [] ----D C:\Program Files (x86)\DepositFiles

O43 - CFD: 18.09.2014 - 18:28:00 - [] ----D C:\Program Files (x86)\DivX

O43 - CFD: 11.07.2012 - 0:39:36 - [] ----D C:\Program Files (x86)\DjVuZone

O43 - CFD: 28.03.2012 - 23:50:12 - [] ----D C:\Program Files (x86)\epson

O43 - CFD: 28.03.2012 - 23:52:22 - [] ----D C:\Program Files (x86)\Epson Software

O43 - CFD: 28.03.2012 - 12:01:49 - [] ----D C:\Program Files (x86)\Etron Technology

O43 - CFD: 30.12.2013 - 13:34:39 - [] ----D C:\Program Files (x86)\Fake Webcam 7.3

O43 - CFD: 09.03.2015 - 0:54:58 - [] ----D C:\Program Files (x86)\Firefox Developer Edition

O43 - CFD: 27.05.2013 - 20:52:06 - [] ----D C:\Program Files (x86)\FraudEliminator

O43 - CFD: 27.06.2013 - 18:30:43 - [] ----D C:\Program Files (x86)\FreeFolderHider

O43 - CFD: 03.11.2012 - 19:26:42 - [] ----D C:\Program Files (x86)\FVDIEPlugin

O43 - CFD: 04.02.2014 - 21:12:18 - [0] ----D C:\Program Files (x86)\G Data

O43 - CFD: 28.02.2015 - 0:59:46 - [] ----D C:\Program Files (x86)\Geotag Security

O43 - CFD: 26.11.2012 - 15:08:15 - [] ----D C:\Program Files (x86)\GhosteryIEplugin

O43 - CFD: 28.03.2012 - 12:02:16 - [] ----D C:\Program Files (x86)\GIGABYTE

O43 - CFD: 30.07.2013 - 20:06:00 - [] ----D C:\Program Files (x86)\Google

O43 - CFD: 31.03.2012 - 23:09:34 - [] ----D C:\Program Files (x86)\GPLGS

O43 - CFD: 22.11.2013 - 23:36:11 - [] ----D C:\Program Files (x86)\H.264 Encoder

O43 - CFD: 21.04.2013 - 7:13:38 - [0] ----D C:\Program Files (x86)\Inhatch

O43 - CFD: 12.12.2013 - 23:19:24 - [] ----D C:\Program Files (x86)\Innovative Solutions

O43 - CFD: 08.03.2015 - 18:24:44 - [] --H-D C:\Program Files (x86)\InstallShield Installation Information

O43 - CFD: 08.09.2014 - 14:09:55 - [] ----D C:\Program Files (x86)\Intel

O43 - CFD: 12.02.2015 - 8:17:19 - [] ----D C:\Program Files (x86)\Internet Explorer

O43 - CFD: 19.10.2014 - 2:24:02 - [] ----D C:\Program Files (x86)\IP-TV Player

O43 - CFD: 25.08.2013 - 10:00:10 - [] ----D C:\Program Files (x86)\IR Server Suite

O43 - CFD: 20.01.2014 - 18:03:56 - [] ----D C:\Program Files (x86)\Java

O43 - CFD: 15.07.2013 - 20:02:17 - [] ----D C:\Program Files (x86)\K!TV

O43 - CFD: 08.07.2013 - 9:25:42 - [] ----D C:\Program Files (x86)\K-Meleon

O43 - CFD: 21.07.2014 - 19:06:10 - [0] ----D C:\Program Files (x86)\Kakao

O43 - CFD: 30.06.2013 - 11:22:48 - [] ----D C:\Program Files (x86)\Links keeper

O43 - CFD: 18.01.2013 - 2:43:18 - [0] ----D C:\Program Files (x86)\lpd

O43 - CFD: 10.11.2012 - 3:48:45 - [] ----D C:\Program Files (x86)\ma-config.com

O43 - CFD: 04.12.2014 - 21:04:04 - [] ----D C:\Program Files (x86)\Malwarebytes Anti-Malware

O43 - CFD: 03.01.2014 - 0:28:23 - [] ----D C:\Program Files (x86)\ManyCam

O43 - CFD: 12.11.2012 - 20:09:38 - [] ----D C:\Program Files (x86)\MarkAny

O43 - CFD: 02.02.2014 - 20:34:23 - [] R---D C:\Program Files (x86)\Max Payne 2

O43 - CFD: 04.04.2013 - 0:08:07 - [] ----D C:\Program Files (x86)\MaxTV

O43 - CFD: 25.08.2013 - 10:12:59 - [] ----D C:\Program Files (x86)\MDAPI_Plus

O43 - CFD: 29.03.2012 - 23:15:17 - [] ----D C:\Program Files (x86)\Microsoft Office

O43 - CFD: 12.02.2015 - 0:51:23 - [] ----D C:\Program Files (x86)\Microsoft Security Client

O43 - CFD: 25.07.2014 - 6:45:09 - [] ----D C:\Program Files (x86)\Microsoft Silverlight

O43 - CFD: 19.10.2013 - 11:55:06 - [] ----D C:\Program Files (x86)\Microsoft SkyDrive =>.Microsoft Corporation

O43 - CFD: 19.10.2013 - 12:00:35 - [] ----D C:\Program Files (x86)\Microsoft SQL Server Compact Edition

O43 - CFD: 25.04.2013 - 13:52:22 - [] ----D C:\Program Files (x86)\Microsoft Synchronization Services

O43 - CFD: 28.03.2012 - 23:34:19 - [] ----D C:\Program Files (x86)\Microsoft Visual Studio

O43 - CFD: 28.03.2012 - 23:32:55 - [] ----D C:\Program Files (x86)\Microsoft Visual Studio 8

O43 - CFD: 12.01.2013 - 14:27:24 - [] ----D C:\Program Files (x86)\Microsoft Works

O43 - CFD: 28.03.2012 - 23:34:05 - [] ----D C:\Program Files (x86)\Microsoft.NET

O43 - CFD: 06.08.2012 - 22:53:02 - [] ----D C:\Program Files (x86)\Monkey's Audio

O43 - CFD: 29.01.2015 - 13:19:19 - [] ----D C:\Program Files (x86)\Mozilla Firefox

O43 - CFD: 03.12.2014 - 13:42:16 - [] ----D C:\Program Files (x86)\Mozilla Firefox.bak

O43 - CFD: 05.03.2015 - 17:04:33 - [] ----D C:\Program Files (x86)\Mozilla Maintenance Service

O43 - CFD: 01.02.2015 - 13:46:28 - [] ----D C:\Program Files (x86)\Mp3tag

O43 - CFD: 28.03.2012 - 23:34:27 - [] ----D C:\Program Files (x86)\MSBuild

O43 - CFD: 15.07.2013 - 23:25:40 - [0] ----D C:\Program Files (x86)\MSXML 4.0

O43 - CFD: 25.12.2012 - 23:42:20 - [] ----D C:\Program Files (x86)\MyFree Codec

O43 - CFD: 21.07.2014 - 18:43:32 - [0] ----D C:\Program Files (x86)\Naver

O43 - CFD: 11.11.2013 - 13:20:45 - [] ----D C:\Program Files (x86)\Nero

O43 - CFD: 24.02.2013 - 1:37:01 - [] ----D C:\Program Files (x86)\NVIDIA Corporation

O43 - CFD: 13.03.2014 - 20:05:19 - [0] ----D C:\Program Files (x86)\Onet

O43 - CFD: 08.03.2015 - 18:35:45 - [] ----D C:\Program Files (x86)\ooVoo

O43 - CFD: 05.03.2015 - 7:43:06 - [] ----D C:\Program Files (x86)\Opera

O43 - CFD: 30.05.2014 - 18:45:08 - [] ----D C:\Program Files (x86)\Pamela

O43 - CFD: 09.03.2015 - 12:12:43 - [] ----D C:\Program Files (x86)\Parom.TV

O43 - CFD: 12.11.2013 - 1:27:29 - [] ----D C:\Program Files (x86)\PDF Architect

O43 - CFD: 30.10.2013 - 9:03:37 - [] ----D C:\Program Files (x86)\PDF Unlocker

O43 - CFD: 23.04.2013 - 10:20:56 - [] ----D C:\Program Files (x86)\Philips

O43 - CFD: 01.04.2012 - 1:10:01 - [] ----D C:\Program Files (x86)\PIMOne

O43 - CFD: 09.06.2013 - 21:48:02 - [] ----D C:\Program Files (x86)\QTTabBar

O43 - CFD: 29.05.2013 - 13:31:04 - [] ----D C:\Program Files (x86)\QuickTime

O43 - CFD: 12.07.2014 - 18:38:21 - [0] ----D C:\Program Files (x86)\RayV

O43 - CFD: 16.12.2014 - 0:53:48 - [] ----D C:\Program Files (x86)\Realtek

O43 - CFD: 14.07.2009 - 6:32:38 - [] ----D C:\Program Files (x86)\Reference Assemblies

O43 - CFD: 10.09.2014 - 23:40:42 - [] ----D C:\Program Files (x86)\Reg Organizer

O43 - CFD: 18.02.2013 - 18:55:59 - [] ----D C:\Program Files (x86)\Roadkil.Net

O43 - CFD: 28.11.2012 - 15:29:12 - [] ----D C:\Program Files (x86)\rue des йcoles

O43 - CFD: 28.04.2013 - 16:29:30 - [] ----D C:\Program Files (x86)\Rumote

O43 - CFD: 24.11.2014 - 22:53:03 - [] ----D C:\Program Files (x86)\Samsung

O43 - CFD: 08.06.2013 - 18:16:08 - [] ----D C:\Program Files (x86)\Scanitto

O43 - CFD: 05.06.2013 - 22:16:30 - [] ----D C:\Program Files (x86)\Secunia

O43 - CFD: 05.02.2013 - 17:50:29 - [] ----D C:\Program Files (x86)\SimpleTV

O43 - CFD: 31.01.2013 - 13:23:20 - [] ----D C:\Program Files (x86)\SimpleTV047r2

O43 - CFD: 18.02.2015 - 19:30:35 - [] R---D C:\Program Files (x86)\Skype

O43 - CFD: 12.12.2013 - 23:30:30 - [] ----D C:\Program Files (x86)\SlimDrivers

O43 - CFD: 30.06.2013 - 10:15:52 - [0] ----D C:\Program Files (x86)\SmElis

O43 - CFD: 02.04.2012 - 3:40:22 - [] ----D C:\Program Files (x86)\Soldier of Fortune Payback

O43 - CFD: 31.10.2013 - 21:18:34 - [] ----D C:\Program Files (x86)\SolidDocuments

O43 - CFD: 07.03.2015 - 1:54:25 - [] ----D C:\Program Files (x86)\SopCast

O43 - CFD: 01.09.2014 - 13:12:33 - [] ----D C:\Program Files (x86)\Stardock

O43 - CFD: 01.07.2013 - 14:45:25 - [0] ----D C:\Program Files (x86)\Stardvb

O43 - CFD: 18.06.2013 - 13:06:05 - [0] ----D C:\Program Files (x86)\stinger

O43 - CFD: 10.12.2012 - 19:14:02 - [] ----D C:\Program Files (x86)\StreamingStar

O43 - CFD: 06.05.2014 - 11:12:40 - [] ----D C:\Program Files (x86)\StreamTransport

O43 - CFD: 07.03.2015 - 18:12:32 - [] ----D C:\Program Files (x86)\System Explorer

O43 - CFD: 10.09.2013 - 21:33:55 - [] ----D C:\Program Files (x86)\Team MediaPortal

O43 - CFD: 03.11.2013 - 22:43:10 - [] ----D C:\Program Files (x86)\Teleport Ultra

O43 - CFD: 08.09.2014 - 13:00:02 - [0] --H-D C:\Program Files (x86)\Temp

O43 - CFD: 14.07.2009 - 5:57:06 - [0] --H-D C:\Program Files (x86)\Uninstall Information

O43 - CFD: 02.04.2012 - 3:29:45 - [] ----D C:\Program Files (x86)\Unlocker

O43 - CFD: 08.09.2014 - 12:04:32 - [] ----D C:\Program Files (x86)\URLSnooper2

O43 - CFD: 29.03.2012 - 2:55:37 - [] ----D C:\Program Files (x86)\VideoLAN

O43 - CFD: 21.11.2014 - 20:51:15 - [] ----D C:\Program Files (x86)\VMware

O43 - CFD: 30.12.2013 - 13:35:41 - [] ----D C:\Program Files (x86)\Web Solution Mart

O43 - CFD: 25.07.2014 - 17:17:41 - [] ----D C:\Program Files (x86)\WhiteHat

O43 - CFD: 10.07.2013 - 2:04:37 - [] ----D C:\Program Files (x86)\Windows Defender

O43 - CFD: 19.10.2013 - 12:00:30 - [] ----D C:\Program Files (x86)\Windows Live

O43 - CFD: 12.04.2011 - 10:16:36 - [] ----D C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation

O43 - CFD: 15.10.2014 - 7:53:21 - [] ----D C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation

O43 - CFD: 29.05.2013 - 12:15:37 - [] ----D C:\Program Files (x86)\Windows Media Player Plus! =>.Microsoft Corporation

O43 - CFD: 14.07.2009 - 6:32:38 - [] ----D C:\Program Files (x86)\Windows NT

O43 - CFD: 12.04.2011 - 10:16:36 - [] ----D C:\Program Files (x86)\Windows Photo Viewer

O43 - CFD: 21.11.2010 - 4:31:38 - [] ----D C:\Program Files (x86)\Windows Portable Devices

O43 - CFD: 12.04.2011 - 10:16:36 - [] ----D C:\Program Files (x86)\Windows Sidebar

O43 - CFD: 08.09.2014 - 12:04:57 - [] ----D C:\Program Files (x86)\WinPcap

O43 - CFD: 12.08.2014 - 10:58:17 - [] ----D C:\Program Files (x86)\WinTV

O43 - CFD: 23.04.2014 - 19:14:26 - [] ----D C:\Program Files (x86)\WOT

O43 - CFD: 25.08.2013 - 8:29:49 - [] ----D C:\Program Files (x86)\XBMC

O43 - CFD: 08.12.2012 - 23:54:39 - [0] ----D C:\Program Files (x86)\Xenocode

O43 - CFD: 28.09.2013 - 19:30:36 - [] ----D C:\Program Files (x86)\Zattoo4

O43 - CFD: 09.03.2015 - 21:32:59 - [] ----D C:\Program Files (x86)\ZHPDiag =>.Nicolas Coolman

O43 - CFD: 28.03.2012 - 23:54:20 - [] ----D C:\Program Files (x86)\Common Files\ABBYY

O43 - CFD: 12.11.2013 - 23:39:17 - [] ----D C:\Program Files (x86)\Common Files\ACD Systems

O43 - CFD: 09.06.2013 - 0:14:18 - [] ----D C:\Program Files (x86)\Common Files\Acro Software

O43 - CFD: 18.05.2014 - 1:23:39 - [] ----D C:\Program Files (x86)\Common Files\Adobe

O43 - CFD: 12.11.2014 - 12:13:37 - [] ----D C:\Program Files (x86)\Common Files\Adobe AIR

O43 - CFD: 11.11.2013 - 13:25:55 - [] ----D C:\Program Files (x86)\Common Files\Ahead

O43 - CFD: 08.06.2014 - 17:30:11 - [] ----D C:\Program Files (x86)\Common Files\Apple

O43 - CFD: 23.04.2013 - 10:24:34 - [] ----D C:\Program Files (x86)\Common Files\ArcSoft

O43 - CFD: 30.08.2013 - 22:46:34 - [] ----D C:\Program Files (x86)\Common Files\AVSMedia

O43 - CFD: 27.06.2012 - 9:42:06 - [] ----D C:\Program Files (x86)\Common Files\Borland Shared

O43 - CFD: 30.05.2012 - 23:41:09 - [] ----D C:\Program Files (x86)\Common Files\Common Share

O43 - CFD: 14.05.2014 - 16:26:45 - [] ----D C:\Program Files (x86)\Common Files\DESIGNER

O43 - CFD: 26.09.2013 - 22:37:55 - [] ----D C:\Program Files (x86)\Common Files\DivX Shared

O43 - CFD: 28.03.2012 - 23:49:48 - [] ----D C:\Program Files (x86)\Common Files\EPSON

O43 - CFD: 31.08.2013 - 20:49:24 - [] ----D C:\Program Files (x86)\Common Files\FotoNation

O43 - CFD: 29.01.2015 - 21:29:14 - [] ----D C:\Program Files (x86)\Common Files\InstallShield

O43 - CFD: 08.03.2015 - 11:24:58 - [] ----D C:\Program Files (x86)\Common Files\IObit

O43 - CFD: 12.11.2014 - 12:13:48 - [] ----D C:\Program Files (x86)\Common Files\Java

O43 - CFD: 28.04.2013 - 22:30:06 - [0] ----D C:\Program Files (x86)\Common Files\Makayama

O43 - CFD: 19.10.2013 - 11:58:20 - [] ----D C:\Program Files (x86)\Common Files\microsoft shared

O43 - CFD: 12.11.2013 - 1:28:18 - [] ----D C:\Program Files (x86)\Common Files\PDF Architect

O43 - CFD: 26.05.2012 - 2:30:21 - [] ----D C:\Program Files (x86)\Common Files\PX Storage Engine

O43 - CFD: 14.07.2009 - 4:20:08 - [] ----D C:\Program Files (x86)\Common Files\Services

O43 - CFD: 31.08.2013 - 20:13:54 - [] ----D C:\Program Files (x86)\Common Files\Simple Star Shared

O43 - CFD: 21.12.2014 - 1:06:01 - [] ----D C:\Program Files (x86)\Common Files\Skype

O43 - CFD: 14.07.2009 - 4:20:08 - [] ----D C:\Program Files (x86)\Common Files\SpeechEngines

O43 - CFD: 12.07.2012 - 2:05:14 - [] ----D C:\Program Files (x86)\Common Files\System

O43 - CFD: 21.11.2014 - 20:51:15 - [] ----D C:\Program Files (x86)\Common Files\VMware

O43 - CFD: 30.12.2013 - 13:34:40 - [] ----D C:\Program Files (x86)\Common Files\Web Solution Mart

O43 - CFD: 07.05.2012 - 0:37:50 - [] ----D C:\Program Files (x86)\Common Files\Windows Live

O43 - CFD: 27.05.2013 - 20:51:18 - [] ----D C:\Program Files (x86)\Common Files\Wise Installation Wizard

O43 - CFD: 08.06.2014 - 17:30:11 - [] ----D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69

O43 - CFD: 27.06.2012 - 10:22:31 - [] ----D C:\ProgramData\ABBYY

O43 - CFD: 12.11.2013 - 23:11:31 - [] ----D C:\ProgramData\ACD Systems

O43 - CFD: 15.08.2013 - 15:43:53 - [] ----D C:\ProgramData\Acunetix WVS 8

O43 - CFD: 27.11.2012 - 0:13:40 - [] ----D C:\ProgramData\AdFender

O43 - CFD: 06.12.2013 - 14:42:33 - [] ----D C:\ProgramData\Adguard

O43 - CFD: 21.07.2014 - 21:34:16 - [] ----D C:\ProgramData\Adobe

O43 - CFD: 17.02.2014 - 12:22:50 - [] ----D C:\ProgramData\Apple

O43 - CFD: 14.07.2009 - 6:08:56 - [] -SH-D C:\ProgramData\Application Data

O43 - CFD: 31.08.2013 - 20:23:33 - [] ----D C:\ProgramData\AVS4YOU

O43 - CFD: 02.05.2012 - 23:04:52 - [] ----D C:\ProgramData\BlazeVideo

O43 - CFD: 27.07.2013 - 0:16:25 - [] ----D C:\ProgramData\Blue Ridge Networks

O43 - CFD: 23.06.2013 - 19:43:54 - [] ----D C:\ProgramData\BlueStacksSetup

O43 - CFD: 28.03.2012 - 11:55:58 - [] -SH-D C:\ProgramData\Bureau

O43 - CFD: 14.12.2014 - 1:41:20 - [0] ----D C:\ProgramData\Camfrog Update

O43 - CFD: 09.06.2013 - 20:00:32 - [] ----D C:\ProgramData\Caminova

O43 - CFD: 06.12.2012 - 10:22:01 - [] ----D C:\ProgramData\Canneverbe Limited

O43 - CFD: 12.11.2013 - 23:11:44 - [] ----D C:\ProgramData\Caphyon

O43 - CFD: 06.03.2015 - 10:02:23 - [] ----D C:\ProgramData\cmcm

O43 - CFD: 27.11.2012 - 23:13:43 - [0] ----D C:\ProgramData\CMUV

O43 - CFD: 25.06.2013 - 21:41:55 - [] --H-D C:\ProgramData\Common Files

O43 - CFD: 27.11.2012 - 23:08:55 - [] ----D C:\ProgramData\DBC2F6FD-3140-41E0-A2A1-D6BAB77D5E21__F893F7CA-8278-41DF-A76F-CAF0437A90CD__

O43 - CFD: 14.07.2009 - 6:08:56 - [] -SH-D C:\ProgramData\Desktop

O43 - CFD: 18.09.2014 - 18:28:01 - [] ----D C:\ProgramData\DivX

O43 - CFD: 14.07.2009 - 6:08:56 - [] -SH-D C:\ProgramData\Documents

O43 - CFD: 12.05.2012 - 23:21:52 - [] ----D C:\ProgramData\DonationCoder

O43 - CFD: 24.03.2013 - 9:33:37 - [] ----D C:\ProgramData\EPSON

O43 - CFD: 28.03.2012 - 11:55:58 - [] -SH-D C:\ProgramData\Favoris

O43 - CFD: 14.07.2009 - 6:08:56 - [] -SH-D C:\ProgramData\Favorites

O43 - CFD: 29.03.2012 - 2:08:12 - [] ----D C:\ProgramData\Google

O43 - CFD: 12.08.2014 - 10:59:36 - [] ----D C:\ProgramData\Hauppauge

O43 - CFD: 08.09.2014 - 14:09:40 - [] ----D C:\ProgramData\Intel

O43 - CFD: 08.03.2015 - 12:30:11 - [] ----D C:\ProgramData\IObit

O43 - CFD: 05.10.2014 - 11:15:18 - [] ----D C:\ProgramData\IP-TV Player

O43 - CFD: 11.02.2013 - 2:55:12 - [] ----D C:\ProgramData\IPTV Distribution

O43 - CFD: 25.08.2013 - 10:00:06 - [] ----D C:\ProgramData\IR Server Suite

O43 - CFD: 18.12.2012 - 0:04:28 - [] ----D C:\ProgramData\Kaspersky Lab

O43 - CFD: 06.03.2015 - 10:02:23 - [] ----D C:\ProgramData\Kingsoft

O43 - CFD: 27.11.2012 - 22:54:46 - [] ----D C:\ProgramData\Kristanix Games

O43 - CFD: 02.12.2012 - 11:03:33 - [] ----D C:\ProgramData\Lavasoft

O43 - CFD: 06.09.2014 - 22:25:04 - [] ----D C:\ProgramData\Licenses

O43 - CFD: 06.09.2014 - 22:25:04 - [] ----D C:\ProgramData\Logs

O43 - CFD: 10.08.2014 - 9:22:24 - [] ----D C:\ProgramData\ma-config.com

O43 - CFD: 23.04.2014 - 16:40:41 - [] ----D C:\ProgramData\Malwarebytes

O43 - CFD: 08.06.2013 - 18:16:14 - [] ----D C:\ProgramData\Masters ITC

O43 - CFD: 21.06.2013 - 0:24:29 - [] ----D C:\ProgramData\McAfee

O43 - CFD: 25.08.2013 - 10:12:54 - [] ----D C:\ProgramData\MDAPI_Plus

O43 - CFD: 28.03.2012 - 11:55:58 - [] -SH-D C:\ProgramData\Menu Démarrer

O43 - CFD: 11.12.2014 - 0:33:17 - [] -S--D C:\ProgramData\Microsoft

O43 - CFD: 12.02.2015 - 0:52:58 - [] ----D C:\ProgramData\Microsoft Help

O43 - CFD: 19.10.2013 - 11:54:57 - [] ----D C:\ProgramData\Microsoft SkyDrive =>.Microsoft Corporation

O43 - CFD: 28.03.2012 - 11:55:58 - [] -SH-D C:\ProgramData\Modèles

O43 - CFD: 09.03.2015 - 1:15:17 - [0] ----D C:\ProgramData\Mozilla

O43 - CFD: 24.08.2013 - 22:49:06 - [] ----D C:\ProgramData\MySQL

O43 - CFD: 07.06.2013 - 21:00:39 - [] ----D C:\ProgramData\Nuance

O43 - CFD: 24.02.2013 - 1:37:09 - [] ----D C:\ProgramData\NVIDIA

O43 - CFD: 28.03.2012 - 14:18:02 - [] ----D C:\ProgramData\NVIDIA Corporation

O43 - CFD: 12.11.2014 - 12:12:55 - [] ----D C:\ProgramData\Oracle

O43 - CFD: 07.03.2015 - 18:50:59 - [] ----D C:\ProgramData\Package Cache

O43 - CFD: 23.06.2013 - 19:37:45 - [] ----D C:\ProgramData\PDF Writer

O43 - CFD: 14.09.2013 - 0:53:03 - [] ----D C:\ProgramData\Pinnacle

O43 - CFD: 02.05.2012 - 23:08:18 - [] ----D C:\ProgramData\Plugins

O43 - CFD: 26.05.2013 - 13:30:54 - [0] ----D C:\ProgramData\ProcessLasso

O43 - CFD: 07.03.2015 - 18:43:45 - [] ----D C:\ProgramData\ProductData

O43 - CFD: 16.11.2013 - 21:58:42 - [] ----D C:\ProgramData\RonyaSoft

O43 - CFD: 10.08.2014 - 11:18:16 - [] ----D C:\ProgramData\Samsung

O43 - CFD: 06.03.2015 - 10:31:54 - [0] ----D C:\ProgramData\Skype

O43 - CFD: 30.10.2013 - 9:06:51 - [] ----D C:\ProgramData\SolidDocuments

O43 - CFD: 01.09.2014 - 13:12:41 - [] ----D C:\ProgramData\Stardock

O43 - CFD: 14.07.2009 - 6:08:56 - [] -SH-D C:\ProgramData\Start Menu

O43 - CFD: 01.08.2014 - 7:33:00 - [] ----D C:\ProgramData\SystemExplorer

O43 - CFD: 24.08.2013 - 22:49:27 - [] ----D C:\ProgramData\Team MediaPortal

O43 - CFD: 09.03.2015 - 8:12:30 - [] ---AD C:\ProgramData\TEMP

O43 - CFD: 14.07.2009 - 6:08:56 - [] -SH-D C:\ProgramData\Templates

O43 - CFD: 25.06.2013 - 22:33:26 - [] ----D C:\ProgramData\TuneUp Software

O43 - CFD: 28.03.2012 - 23:52:52 - [] ----D C:\ProgramData\UDL

O43 - CFD: 09.03.2015 - 8:10:33 - [] ----D C:\ProgramData\VMware

O43 - CFD: 22.06.2013 - 1:01:57 - [] ----D C:\ProgramData\VSO

O43 - CFD: 30.03.2012 - 3:53:42 - [] ----D C:\ProgramData\Windows Genuine Advantage

O43 - CFD: 25.06.2013 - 22:06:35 - [0] ----D C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}

O43 - CFD: 08.03.2015 - 11:24:59 - [] ----D C:\ProgramData\{ACBCD40A-42A8-4FF9-BD42-ABCD14998CBA}

O43 - CFD: 25.06.2013 - 22:06:35 - [0] -SH-D C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}

O43 - CFD: 08.03.2015 - 11:24:59 - [] ----D C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690}

O43 - CFD: 02.04.2012 - 3:40:23 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\1C

O43 - CFD: 26.02.2015 - 21:26:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Download

O43 - CFD: 19.12.2013 - 13:14:26 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4t Tray Minimizer

O43 - CFD: 08.03.2015 - 23:12:46 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip

O43 - CFD: 28.03.2012 - 23:54:53 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 9.0 Sprint

O43 - CFD: 10.11.2012 - 11:48:35 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories

O43 - CFD: 12.11.2013 - 23:39:13 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems

O43 - CFD: 16.11.2013 - 18:50:22 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acunetix Web Vulnerability Scanner 8

O43 - CFD: 27.11.2012 - 0:13:40 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdFender

O43 - CFD: 06.12.2013 - 14:42:13 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adguard

O43 - CFD: 14.12.2012 - 19:08:35 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools

O43 - CFD: 17.06.2013 - 22:58:55 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 64-bit fixes

O43 - CFD: 10.09.2014 - 15:56:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnVir Task Manager

O43 - CFD: 12.06.2013 - 7:31:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\APC

O43 - CFD: 25.04.2012 - 19:30:56 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Applian Technologies =>PUP.ApplianTechnologies

O43 - CFD: 24.06.2013 - 13:50:07 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASCOMP Software

O43 - CFD: 28.04.2013 - 19:53:45 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo

O43 - CFD: 02.05.2012 - 23:04:51 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlazeVideo HDTV Player 6.6 Pro

O43 - CFD: 23.06.2013 - 19:37:46 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bullzip

O43 - CFD: 05.04.2012 - 1:10:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Menu for Office

O43 - CFD: 06.03.2015 - 10:02:22 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clean Master

O43 - CFD: 05.09.2014 - 15:31:03 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clover

O43 - CFD: 05.09.2014 - 18:40:27 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo

O43 - CFD: 10.09.2014 - 23:31:14 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID

O43 - CFD: 25.06.2013 - 0:04:03 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crystal TV

O43 - CFD: 05.09.2014 - 18:44:04 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF

O43 - CFD: 14.12.2014 - 0:36:22 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daum

O43 - CFD: 10.09.2012 - 2:01:43 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daum PotPlayer x64

O43 - CFD: 18.09.2014 - 18:27:52 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX

O43 - CFD: 11.07.2012 - 0:39:38 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DjVuLibre

O43 - CFD: 19.12.2014 - 0:25:56 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverMax

O43 - CFD: 04.12.2013 - 10:35:31 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON

O43 - CFD: 28.03.2012 - 23:52:52 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson Software

O43 - CFD: 25.06.2013 - 22:06:16 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Explorer Toolbar Editor

O43 - CFD: 08.03.2015 - 11:12:11 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eyeball Chat

O43 - CFD: 30.12.2013 - 13:34:41 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fake Webcam 7.3

O43 - CFD: 08.09.2014 - 11:14:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow x64

O43 - CFD: 09.06.2013 - 0:14:19 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FormMax Filler

O43 - CFD: 27.06.2013 - 18:30:42 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Folder Hider

O43 - CFD: 09.03.2015 - 2:42:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FVD Suite IE Plugin

O43 - CFD: 30.10.2013 - 13:52:04 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games

O43 - CFD: 28.02.2015 - 0:59:46 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Geotag Security

O43 - CFD: 09.03.2015 - 2:42:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome

O43 - CFD: 22.11.2013 - 23:36:11 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\H.264 Encoder

O43 - CFD: 12.08.2014 - 10:59:28 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hauppauge WinTV

O43 - CFD: 08.03.2015 - 18:24:44 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. Applications

O43 - CFD: 28.03.2012 - 12:02:11 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel

O43 - CFD: 08.03.2015 - 11:25:07 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller

O43 - CFD: 25.08.2013 - 10:00:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IR Server Suite

O43 - CFD: 12.11.2014 - 12:13:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java

O43 - CFD: 15.07.2013 - 20:02:07 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K!TV

O43 - CFD: 08.07.2013 - 9:25:42 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Meleon

O43 - CFD: 31.08.2013 - 20:50:26 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kazoo Player

O43 - CFD: 30.11.2014 - 19:36:21 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lunascape6

O43 - CFD: 10.08.2014 - 9:22:26 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ma-config.com

O43 - CFD: 14.07.2009 - 5:57:09 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance

O43 - CFD: 04.12.2014 - 21:04:04 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware

O43 - CFD: 08.06.2013 - 18:16:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Masters ITC

O43 - CFD: 04.04.2013 - 0:08:19 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MaxTV

O43 - CFD: 25.08.2013 - 10:12:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MDAPI_Plus

O43 - CFD: 13.09.2013 - 7:21:17 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office

O43 - CFD: 25.07.2014 - 1:20:57 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight

O43 - CFD: 12.01.2013 - 14:27:25 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works

O43 - CFD: 14.08.2014 - 21:17:34 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mindscape

O43 - CFD: 06.08.2012 - 22:53:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Monkey's Audio

O43 - CFD: 01.02.2015 - 13:46:28 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag

O43 - CFD: 25.12.2012 - 23:42:20 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec

O43 - CFD: 24.08.2013 - 22:49:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MySQL

O43 - CFD: 11.11.2013 - 13:25:52 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition

O43 - CFD: 06.09.2014 - 22:24:57 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Office Tab

O43 - CFD: 08.03.2015 - 18:35:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ooVoo

O43 - CFD: 30.07.2013 - 10:42:05 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office

O43 - CFD: 30.05.2014 - 18:45:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pamela

O43 - CFD: 09.06.2013 - 22:02:12 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Parom.TV

O43 - CFD: 12.11.2013 - 1:27:27 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect

O43 - CFD: 29.01.2015 - 14:11:41 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator

O43 - CFD: 23.04.2013 - 10:24:34 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Philips SPC 900NC PC Camera

O43 - CFD: 01.04.2012 - 1:07:55 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PIMOne

O43 - CFD: 01.09.2013 - 3:00:34 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProgDVB

O43 - CFD: 29.01.2015 - 14:13:11 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime

O43 - CFD: 10.09.2014 - 23:40:42 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reg Organizer

O43 - CFD: 18.02.2013 - 18:55:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roadkil.Net

O43 - CFD: 28.11.2012 - 15:29:31 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\rue des йcoles

O43 - CFD: 28.04.2013 - 16:29:32 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rumote

O43 - CFD: 23.05.2013 - 18:59:07 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RunMe

O43 - CFD: 24.11.2014 - 22:53:01 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung

O43 - CFD: 08.07.2013 - 9:46:31 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scan Tailor

O43 - CFD: 13.12.2012 - 21:38:16 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SiSoftware

O43 - CFD: 21.12.2014 - 1:06:01 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype

O43 - CFD: 12.12.2013 - 23:30:30 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers

O43 - CFD: 31.10.2013 - 21:18:43 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidDocuments

O43 - CFD: 29.04.2012 - 16:17:40 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast

O43 - CFD: 01.09.2014 - 13:12:35 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock

O43 - CFD: 06.11.2014 - 20:07:44 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup

O43 - CFD: 10.12.2012 - 19:14:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StreamingStar

O43 - CFD: 06.05.2014 - 11:12:36 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StreamTransport

O43 - CFD: 07.03.2015 - 18:12:31 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Explorer

O43 - CFD: 12.04.2011 - 10:27:52 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC

O43 - CFD: 03.11.2013 - 22:43:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Teleport Ultra

O43 - CFD: 31.08.2013 - 22:07:32 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TELL ME MORE SI PLUS

O43 - CFD: 12.01.2014 - 12:13:42 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy

O43 - CFD: 07.09.2014 - 20:51:51 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uninstall Tool

O43 - CFD: 16.11.2013 - 0:55:36 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN

O43 - CFD: 19.10.2013 - 12:01:04 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live

O43 - CFD: 01.07.2013 - 19:34:43 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap

O43 - CFD: 08.09.2014 - 11:15:00 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR

O43 - CFD: 07.03.2015 - 17:52:05 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare

O43 - CFD: 28.09.2013 - 19:30:36 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zattoo4

O43 - CFD: 09.03.2015 - 21:32:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP =>.Nicolas Coolman

O43 - CFD: 28.02.2015 - 14:59:04 - [] ----D C:\Users\GELO\AppData\Roaming\.ACEStream

O43 - CFD: 24.10.2013 - 23:48:49 - [] ----D C:\Users\GELO\AppData\Roaming\.Torrent Stream

O43 - CFD: 12.12.2012 - 0:43:33 - [] ----D C:\Users\GELO\AppData\Roaming\4t Niagara Software

O43 - CFD: 29.07.2013 - 23:48:46 - [0] ----D C:\Users\GELO\AppData\Roaming\4Team

O43 - CFD: 10.06.2012 - 3:11:30 - [] ----D C:\Users\GELO\AppData\Roaming\ABBYY

O43 - CFD: 30.01.2015 - 12:51:57 - [] ----D C:\Users\GELO\AppData\Roaming\AC3Filter

O43 - CFD: 22.04.2012 - 19:15:48 - [] ----D C:\Users\GELO\AppData\Roaming\ACD Systems

O43 - CFD: 12.11.2013 - 23:01:14 - [] ----D C:\Users\GELO\AppData\Roaming\ACD Systems International Inc

O43 - CFD: 08.01.2015 - 20:29:02 - [] ----D C:\Users\GELO\AppData\Roaming\ACEStream

O43 - CFD: 28.02.2015 - 14:59:04 - [] ----D C:\Users\GELO\AppData\Roaming\AceWebExtension

O43 - CFD: 21.07.2014 - 21:34:16 - [] ----D C:\Users\GELO\AppData\Roaming\Adobe

O43 - CFD: 16.11.2013 - 14:12:33 - [] ----D C:\Users\GELO\AppData\Roaming\Ahead

O43 - CFD: 15.09.2013 - 16:58:43 - [] ----D C:\Users\GELO\AppData\Roaming\Alp-Software

O43 - CFD: 23.05.2013 - 18:57:58 - [] ----D C:\Users\GELO\AppData\Roaming\App Launcher Gadget

O43 - CFD: 08.03.2015 - 11:25:06 - [] ----D C:\Users\GELO\AppData\Roaming\Apple Computer

O43 - CFD: 25.07.2014 - 20:40:58 - [] ----D C:\Users\GELO\AppData\Roaming\Applian FLV and Media Player =>PUP.ApplianTechnologies

O43 - CFD: 27.11.2012 - 23:27:02 - [] ----D C:\Users\GELO\AppData\Roaming\APP_NAME_NON_STRING

O43 - CFD: 23.04.2013 - 10:30:31 - [] ----D C:\Users\GELO\AppData\Roaming\ArcSoft

O43 - CFD: 24.06.2013 - 13:50:24 - [] ----D C:\Users\GELO\AppData\Roaming\ASCOMP Software

O43 - CFD: 30.06.2013 - 11:15:42 - [] ----D C:\Users\GELO\AppData\Roaming\AtslegSoft

O43 - CFD: 19.11.2012 - 23:02:37 - [] ----D C:\Users\GELO\AppData\Roaming\Auslogics

O43 - CFD: 02.03.2014 - 1:44:42 - [0] ----D C:\Users\GELO\AppData\Roaming\AutoUpdate

O43 - CFD: 12.11.2012 - 14:41:08 - [] ----D C:\Users\GELO\AppData\Roaming\Avant Profiles

O43 - CFD: 25.12.2013 - 11:41:35 - [] ----D C:\Users\GELO\AppData\Roaming\Avery

O43 - CFD: 31.08.2013 - 20:23:34 - [] ----D C:\Users\GELO\AppData\Roaming\AVS4YOU

O43 - CFD: 30.08.2012 - 2:17:30 - [] ----D C:\Users\GELO\AppData\Roaming\BerezaTV

O43 - CFD: 08.03.2015 - 11:20:30 - [] ----D C:\Users\GELO\AppData\Roaming\BExplorer

O43 - CFD: 27.07.2013 - 0:20:08 - [] ----D C:\Users\GELO\AppData\Roaming\blue ridge networks

O43 - CFD: 05.10.2014 - 13:37:20 - [] ----D C:\Users\GELO\AppData\Roaming\BSplayer

O43 - CFD: 08.03.2015 - 11:21:17 - [] ----D C:\Users\GELO\AppData\Roaming\Camfrog

O43 - CFD: 01.02.2014 - 21:04:04 - [] ----D C:\Users\GELO\AppData\Roaming\Camfrog Web

O43 - CFD: 06.12.2012 - 10:22:00 - [] ----D C:\Users\GELO\AppData\Roaming\Canneverbe Limited

O43 - CFD: 10.09.2014 - 23:40:48 - [] ----D C:\Users\GELO\AppData\Roaming\ChemTable Software

O43 - CFD: 21.07.2014 - 21:39:51 - [] ----D C:\Users\GELO\AppData\Roaming\com.zoosk.Desktop

O43 - CFD: 21.07.2014 - 21:39:52 - [] ----D C:\Users\GELO\AppData\Roaming\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1

O43 - CFD: 25.11.2012 - 23:54:44 - [] ----D C:\Users\GELO\AppData\Roaming\Comodo

O43 - CFD: 05.09.2014 - 15:42:45 - [] ----D C:\Users\GELO\AppData\Roaming\CrystalIdea Software

O43 - CFD: 08.09.2014 - 1:13:31 - [] ----D C:\Users\GELO\AppData\Roaming\CrystalTV

O43 - CFD: 27.11.2012 - 23:08:55 - [] ----D C:\Users\GELO\AppData\Roaming\DBC2F6FD-3140-41E0-A2A1-D6BAB77D5E21__F893F7CA-8278-41DF-A76F-CAF0437A90CD__

O43 - CFD: 30.04.2013 - 19:31:25 - [] ----D C:\Users\GELO\AppData\Roaming\DivX

O43 - CFD: 12.05.2012 - 23:21:22 - [] ----D C:\Users\GELO\AppData\Roaming\DonationCoder

O43 - CFD: 21.12.2012 - 0:28:02 - [] ----D C:\Users\GELO\AppData\Roaming\Dropbox

O43 - CFD: 15.07.2013 - 23:02:48 - [] ----D C:\Users\GELO\AppData\Roaming\DScaler4

O43 - CFD: 08.09.2014 - 18:09:53 - [] ----D C:\Users\GELO\AppData\Roaming\dvdcss

O43 - CFD: 08.06.2013 - 23:25:08 - [] ----D C:\Users\GELO\AppData\Roaming\Easy Image Modifier

O43 - CFD: 24.03.2013 - 9:33:37 - [] ----D C:\Users\GELO\AppData\Roaming\Epson

O43 - CFD: 10.06.2013 - 7:33:17 - [] ----D C:\Users\GELO\AppData\Roaming\Foxit Software

O43 - CFD: 26.05.2013 - 12:43:30 - [] ----D C:\Users\GELO\AppData\Roaming\FreshDiagnose

O43 - CFD: 07.08.2012 - 12:26:38 - [] ----D C:\Users\GELO\AppData\Roaming\FVDIEPlugin

O43 - CFD: 09.12.2012 - 0:19:26 - [] ----D C:\Users\GELO\AppData\Roaming\Geek Uninstaller

O43 - CFD: 14.03.2013 - 20:08:12 - [] ----D C:\Users\GELO\AppData\Roaming\goalbit

O43 - CFD: 05.11.2012 - 22:03:44 - [] ----D C:\Users\GELO\AppData\Roaming\Google

O43 - CFD: 12.12.2012 - 13:50:57 - [] ----D C:\Users\GELO\AppData\Roaming\Haihaisoft PDF Reader

O43 - CFD: 27.11.2012 - 22:50:39 - [] ----D C:\Users\GELO\AppData\Roaming\HTML Executable

O43 - CFD: 07.03.2015 - 18:37:39 - [] ----D C:\Users\GELO\AppData\Roaming\ICQ-Profile

O43 - CFD: 07.03.2015 - 18:37:53 - [] ----D C:\Users\GELO\AppData\Roaming\ICQM

O43 - CFD: 03.06.2013 - 17:12:20 - [] ----D C:\Users\GELO\AppData\Roaming\ID3 renamer

O43 - CFD: 28.03.2012 - 11:56:18 - [] ----D C:\Users\GELO\AppData\Roaming\Identities

O43 - CFD: 18.06.2013 - 13:30:15 - [] ----D C:\Users\GELO\AppData\Roaming\ImgBurn

O43 - CFD: 19.12.2014 - 0:25:58 - [] ----D C:\Users\GELO\AppData\Roaming\Innovative Solutions

O43 - CFD: 04.10.2013 - 14:31:25 - [] ----D C:\Users\GELO\AppData\Roaming\Insoft LLC

O43 - CFD: 28.03.2012 - 12:02:02 - [] ----D C:\Users\GELO\AppData\Roaming\InstallShield

O43 - CFD: 08.03.2015 - 12:12:30 - [] ----D C:\Users\GELO\AppData\Roaming\IObit

O43 - CFD: 25.11.2012 - 22:47:25 - [0] ----D C:\Users\GELO\AppData\Roaming\IP-TV Player

O43 - CFD: 30.01.2015 - 18:08:38 - [] ----D C:\Users\GELO\AppData\Roaming\IRISPen

O43 - CFD: 29.01.2015 - 22:30:48 - [] ----D C:\Users\GELO\AppData\Roaming\IrisPen6

O43 - CFD: 08.07.2013 - 9:37:46 - [] ----D C:\Users\GELO\AppData\Roaming\K-Meleon

O43 - CFD: 23.05.2013 - 20:09:20 - [] ----D C:\Users\GELO\AppData\Roaming\Kartina.TV

O43 - CFD: 27.11.2012 - 21:56:01 - [] ----D C:\Users\GELO\AppData\Roaming\KastorStreamRecorder

O43 - CFD: 22.06.2012 - 2:39:43 - [] ----D C:\Users\GELO\AppData\Roaming\KC Softwares

O43 - CFD: 13.12.2012 - 1:17:00 - [] ----D C:\Users\GELO\AppData\Roaming\KillProcess

O43 - CFD: 02.12.2012 - 11:06:40 - [] ----D C:\Users\GELO\AppData\Roaming\LavasoftStatistics

O43 - CFD: 26.10.2014 - 17:59:54 - [] ----D C:\Users\GELO\AppData\Roaming\livestreamer

O43 - CFD: 12.11.2012 - 15:55:41 - [] ----D C:\Users\GELO\AppData\Roaming\Lunascape

O43 - CFD: 28.03.2012 - 15:11:44 - [] ----D C:\Users\GELO\AppData\Roaming\Macromedia

O43 - CFD: 28.04.2013 - 22:28:20 - [] ----D C:\Users\GELO\AppData\Roaming\Makayama

O43 - CFD: 23.04.2014 - 16:40:49 - [0] ----D C:\Users\GELO\AppData\Roaming\Malwarebytes

O43 - CFD: 03.01.2014 - 0:27:06 - [] ----D C:\Users\GELO\AppData\Roaming\ManyCam

O43 - CFD: 12.04.2012 - 23:35:30 - [] ----D C:\Users\GELO\AppData\Roaming\Marine Aquarium 3

O43 - CFD: 14.11.2012 - 15:13:11 - [] ----D C:\Users\GELO\AppData\Roaming\Maxthon3

O43 - CFD: 04.04.2013 - 0:10:11 - [] ----D C:\Users\GELO\AppData\Roaming\MaxTV Technologies

O43 - CFD: 12.04.2011 - 10:27:52 - [0] ----D C:\Users\GELO\AppData\Roaming\Media Center Programs

O43 - CFD: 08.03.2015 - 11:34:54 - [] -S--D C:\Users\GELO\AppData\Roaming\Microsoft

O43 - CFD: 30.05.2013 - 17:10:59 - [] ----D C:\Users\GELO\AppData\Roaming\MiniDm

O43 - CFD: 25.08.2014 - 0:51:20 - [] ----D C:\Users\GELO\AppData\Roaming\Mozilla

O43 - CFD: 01.02.2015 - 13:46:09 - [] ----D C:\Users\GELO\AppData\Roaming\Mp3tag

O43 - CFD: 31.08.2013 - 23:26:19 - [] ----D C:\Users\GELO\AppData\Roaming\Nero

O43 - CFD: 12.01.2013 - 4:07:37 - [] ----D C:\Users\GELO\AppData\Roaming\Notepad++

O43 - CFD: 07.06.2013 - 20:55:34 - [] ----D C:\Users\GELO\AppData\Roaming\Nuance

O43 - CFD: 26.02.2015 - 21:25:35 - [] ----D C:\Users\GELO\AppData\Roaming\NVIDIA

O43 - CFD: 05.09.2014 - 14:58:31 - [] ----D C:\Users\GELO\AppData\Roaming\Obnovi Soft

O43 - CFD: 09.11.2014 - 20:53:34 - [] ----D C:\Users\GELO\AppData\Roaming\Octoshape

O43 - CFD: 01.06.2013 - 10:25:24 - [] ----D C:\Users\GELO\AppData\Roaming\OfficeTab

O43 - CFD: 26.11.2012 - 0:48:05 - [] ----D C:\Users\GELO\AppData\Roaming\Offline Explorer

O43 - CFD: 15.01.2013 - 0:30:03 - [] ----D C:\Users\GELO\AppData\Roaming\ooVoo Details

O43 - CFD: 19.08.2013 - 19:38:20 - [] ----D C:\Users\GELO\AppData\Roaming\Opera

O43 - CFD: 03.07.2013 - 12:36:28 - [] ----D C:\Users\GELO\AppData\Roaming\Opera Software

O43 - CFD: 28.12.2013 - 1:50:15 - [] ----D C:\Users\GELO\AppData\Roaming\Paltalk

O43 - CFD: 31.05.2014 - 0:25:09 - [] ----D C:\Users\GELO\AppData\Roaming\Pamela

O43 - CFD: 02.12.2012 - 2:23:55 - [] ----D C:\Users\GELO\AppData\Roaming\PDF Architect

O43 - CFD: 12.11.2013 - 1:25:39 - [] ----D C:\Users\GELO\AppData\Roaming\PDF Software

O43 - CFD: 23.06.2013 - 19:37:45 - [] ----D C:\Users\GELO\AppData\Roaming\PDF Writer

O43 - CFD: 19.08.2012 - 21:18:44 - [] ----D C:\Users\GELO\AppData\Roaming\Pistonsoft

O43 - CFD: 14.12.2014 - 0:39:27 - [] ----D C:\Users\GELO\AppData\Roaming\PotPlayerMini

O43 - CFD: 28.04.2013 - 19:05:30 - [] ----D C:\Users\GELO\AppData\Roaming\PotPlayerMini64

O43 - CFD: 14.09.2013 - 1:18:30 - [] ----D C:\Users\GELO\AppData\Roaming\Pouchin TV Mod

O43 - CFD: 26.05.2013 - 13:30:54 - [] ----D C:\Users\GELO\AppData\Roaming\ProcessLasso

O43 - CFD: 08.03.2015 - 11:26:11 - [] ----D C:\Users\GELO\AppData\Roaming\ProductData

O43 - CFD: 02.02.2015 - 13:57:43 - [] ----D C:\Users\GELO\AppData\Roaming\QIP

O43 - CFD: 30.05.2012 - 23:03:15 - [] ----D C:\Users\GELO\AppData\Roaming\RayV

O43 - CFD: 30.06.2013 - 11:31:33 - [] ----D C:\Users\GELO\AppData\Roaming\Resort Labs

O43 - CFD: 25.01.2015 - 19:11:34 - [] ----D C:\Users\GELO\AppData\Roaming\Samsung

O43 - CFD: 31.08.2013 - 20:19:39 - [0] ----D C:\Users\GELO\AppData\Roaming\Simple Star

O43 - CFD: 14.09.2014 - 9:38:02 - [] ----D C:\Users\GELO\AppData\Roaming\SimpleTV V03

O43 - CFD: 09.03.2015 - 12:14:44 - [] ----D C:\Users\GELO\AppData\Roaming\Skype

O43 - CFD: 20.06.2013 - 0:47:10 - [] ----D C:\Users\GELO\AppData\Roaming\Softland

O43 - CFD: 14.07.2012 - 16:50:03 - [] ----D C:\Users\GELO\AppData\Roaming\Softplicity

O43 - CFD: 01.11.2013 - 17:44:45 - [] ----D C:\Users\GELO\AppData\Roaming\SolidDocuments

O43 - CFD: 01.09.2014 - 13:10:08 - [] ----D C:\Users\GELO\AppData\Roaming\Stardock

O43 - CFD: 13.10.2014 - 20:50:43 - [0] ----D C:\Users\GELO\AppData\Roaming\streamripper

O43 - CFD: 11.01.2013 - 20:20:19 - [] ----D C:\Users\GELO\AppData\Roaming\Template

O43 - CFD: 04.04.2012 - 22:01:31 - [] ----D C:\Users\GELO\AppData\Roaming\TeraCopy

O43 - CFD: 21.11.2013 - 21:27:08 - [] ----D C:\Users\GELO\AppData\Roaming\Thinstall

O43 - CFD: 01.02.2014 - 18:31:03 - [] ----D C:\Users\GELO\AppData\Roaming\To the Moon - Freebird Games

O43 - CFD: 24.10.2013 - 23:48:48 - [] ----D C:\Users\GELO\AppData\Roaming\TorrentStream

O43 - CFD: 21.07.2014 - 22:06:13 - [] ----D C:\Users\GELO\AppData\Roaming\Trillian

O43 - CFD: 25.06.2013 - 21:43:48 - [] ----D C:\Users\GELO\AppData\Roaming\TuneUp Software

O43 - CFD: 27.12.2012 - 15:39:29 - [] ----D C:\Users\GELO\AppData\Roaming\TweakNow RegCleaner 2011

O43 - CFD: 08.06.2012 - 1:25:15 - [] ----D C:\Users\GELO\AppData\Roaming\UDC Profiles

O43 - CFD: 15.02.2014 - 22:33:56 - [] ----D C:\Users\GELO\AppData\Roaming\vcards

O43 - CFD: 06.03.2015 - 20:42:01 - [] ----D C:\Users\GELO\AppData\Roaming\vlc

O43 - CFD: 31.12.2014 - 1:55:07 - [] ----D C:\Users\GELO\AppData\Roaming\VMware

O43 - CFD: 05.01.2013 - 1:56:45 - [] ----D C:\Users\GELO\AppData\Roaming\VOS

O43 - CFD: 27.12.2013 - 21:24:18 - [0] ----D C:\Users\GELO\AppData\Roaming\Windows Live Writer

O43 - CFD: 02.11.2013 - 23:39:13 - [] ----D C:\Users\GELO\AppData\Roaming\Windows SideBar

O43 - CFD: 29.03.2012 - 22:50:39 - [] ----D C:\Users\GELO\AppData\Roaming\WinRAR

O43 - CFD: 10.01.2014 - 20:06:28 - [] ----D C:\Users\GELO\AppData\Roaming\Wireshark

O43 - CFD: 12.12.2012 - 23:41:03 - [] ----D C:\Users\GELO\AppData\Roaming\Wise Care 365

O43 - CFD: 12.12.2012 - 23:26:01 - [] ----D C:\Users\GELO\AppData\Roaming\Wise Registry Cleaner

O43 - CFD: 12.12.2012 - 23:30:00 - [] ----D C:\Users\GELO\AppData\Roaming\Wise Uninstaller

O43 - CFD: 07.09.2014 - 19:11:30 - [] ----D C:\Users\GELO\AppData\Roaming\Wondershare

O43 - CFD: 07.03.2015 - 18:55:48 - [] -SH-D C:\Users\GELO\AppData\Roaming\wyUpdate AU

O43 - CFD: 01.12.2014 - 21:04:25 - [] ----D C:\Users\GELO\AppData\Roaming\XBMC

O43 - CFD: 09.03.2015 - 22:40:07 - [] ----D C:\Users\GELO\AppData\Roaming\ZHP =>.Nicolas Coolman

O43 - CFD: 26.02.2015 - 21:26:34 - [] ----D C:\Users\GELO\AppData\Local\4kdownload.com

O43 - CFD: 10.06.2012 - 3:11:30 - [] ----D C:\Users\GELO\AppData\Local\ABBYY

O43 - CFD: 12.11.2013 - 23:16:35 - [] ----D C:\Users\GELO\AppData\Local\ACD Systems

O43 - CFD: 27.11.2012 - 0:14:22 - [] ----D C:\Users\GELO\AppData\Local\AdFender

O43 - CFD: 09.02.2015 - 21:32:22 - [] ----D C:\Users\GELO\AppData\Local\Adobe

O43 - CFD: 29.12.2013 - 19:32:17 - [] ----D C:\Users\GELO\AppData\Local\Ahead

O43 - CFD: 24.06.2013 - 19:39:22 - [] ----D C:\Users\GELO\AppData\Local\AlbumArtDownloader

O43 - CFD: 03.08.2013 - 22:32:28 - [] ----D C:\Users\GELO\AppData\Local\Anolis

O43 - CFD: 10.09.2014 - 15:57:32 - [] ----D C:\Users\GELO\AppData\Local\AnVir

O43 - CFD: 02.04.2012 - 13:11:31 - [] ----D C:\Users\GELO\AppData\Local\Apple

O43 - CFD: 28.03.2012 - 11:56:03 - [] -SH-D C:\Users\GELO\AppData\Local\Application Data

O43 - CFD: 08.10.2012 - 20:07:03 - [] ----D C:\Users\GELO\AppData\Local\Apps

O43 - CFD: 25.07.2014 - 17:18:11 - [] ----D C:\Users\GELO\AppData\Local\Aviator

O43 - CFD: 02.11.2013 - 23:48:48 - [] ----D C:\Users\GELO\AppData\Local\BuildAGadget Content

O43 - CFD: 14.12.2014 - 1:41:28 - [] ----D C:\Users\GELO\AppData\Local\Camfrog

O43 - CFD: 10.09.2014 - 23:39:14 - [] ----D C:\Users\GELO\AppData\Local\ChemTable Software

O43 - CFD: 06.07.2013 - 21:55:07 - [] ----D C:\Users\GELO\AppData\Local\Chromium

O43 - CFD: 31.05.2013 - 21:28:27 - [] ----D C:\Users\GELO\AppData\Local\Clover

O43 - CFD: 05.09.2014 - 18:42:10 - [0] ----D C:\Users\GELO\AppData\Local\Comodo

O43 - CFD: 08.03.2015 - 14:42:25 - [0] ----D C:\Users\GELO\AppData\Local\CrashDumps

O43 - CFD: 01.08.2014 - 10:24:29 - [] ----D C:\Users\GELO\AppData\Local\CrashRpt

O43 - CFD: 05.06.2012 - 20:28:47 - [] ----D C:\Users\GELO\AppData\Local\CustomStamp

O43 - CFD: 24.10.2013 - 23:18:36 - [] ----D C:\Users\GELO\AppData\Local\CutePDF

O43 - CFD: 09.03.2015 - 22:05:41 - [] ----D C:\Users\GELO\AppData\Local\CutePDF Writer

O43 - CFD: 07.09.2014 - 18:34:46 - [] ----D C:\Users\GELO\AppData\Local\CutePDF_Filler

O43 - CFD: 09.03.2015 - 22:06:04 - [0] ----D C:\Users\GELO\AppData\Local\CutePDF_Pro

O43 - CFD: 10.09.2012 - 2:01:49 - [] ----D C:\Users\GELO\AppData\Local\Daum

O43 - CFD: 20.11.2012 - 0:50:28 - [] ----D C:\Users\GELO\AppData\Local\DDMSettings

O43 - CFD: 27.11.2012 - 9:07:41 - [0] ----D C:\Users\GELO\AppData\Local\Deployment

O43 - CFD: 14.09.2014 - 12:36:36 - [0] ----D C:\Users\GELO\AppData\Local\Diagnostics

O43 - CFD: 10.08.2014 - 11:16:57 - [] ----D C:\Users\GELO\AppData\Local\Downloaded Installations

O43 - CFD: 28.12.2014 - 11:57:49 - [0] ----D C:\Users\GELO\AppData\Local\ElevatedDiagnostics

O43 - CFD: 13.11.2014 - 18:36:44 - [] -SH-D C:\Users\GELO\AppData\Local\EmieBrowserModeList

O43 - CFD: 30.04.2014 - 10:43:51 - [] -SH-D C:\Users\GELO\AppData\Local\EmieSiteList

O43 - CFD: 30.04.2014 - 10:43:51 - [] -SH-D C:\Users\GELO\AppData\Local\EmieUserList

O43 - CFD: 12.12.2012 - 14:04:39 - [] ----D C:\Users\GELO\AppData\Local\Evernote

O43 - CFD: 18.05.2014 - 7:38:38 - [] ----D C:\Users\GELO\AppData\Local\Facebook

O43 - CFD: 25.06.2013 - 20:05:28 - [] ----D C:\Users\GELO\AppData\Local\FixItCenter

O43 - CFD: 12.12.2012 - 14:14:05 - [0] ----D C:\Users\GELO\AppData\Local\Folderico

O43 - CFD: 28.02.2015 - 22:11:03 - [] ----D C:\Users\GELO\AppData\Local\Geotag Security

O43 - CFD: 03.03.2015 - 18:10:15 - [] ----D C:\Users\GELO\AppData\Local\Google

O43 - CFD: 02.05.2013 - 19:34:13 - [] ----D C:\Users\GELO\AppData\Local\gtk-2.0

O43 - CFD: 28.03.2012 - 11:56:03 - [] -SH-D C:\Users\GELO\AppData\Local\Historique

O43 - CFD: 03.06.2013 - 16:38:02 - [] ----D C:\Users\GELO\AppData\Local\iMule

O43 - CFD: 12.07.2014 - 18:34:47 - [] ----D C:\Users\GELO\AppData\Local\infidele-messenger

O43 - CFD: 19.12.2014 - 0:25:57 - [] ----D C:\Users\GELO\AppData\Local\Innovative Solutions

O43 - CFD: 15.07.2013 - 23:27:31 - [] ----D C:\Users\GELO\AppData\Local\IsolatedStorage

O43 - CFD: 03.06.2013 - 17:12:20 - [] ----D C:\Users\GELO\AppData\Local\Jiri_Cincura_-_x2develop

O43 - CFD: 08.07.2013 - 9:26:42 - [] ----D C:\Users\GELO\AppData\Local\K-Meleon

O43 - CFD: 21.07.2014 - 19:06:30 - [0] ----D C:\Users\GELO\AppData\Local\Kakao

O43 - CFD: 30.09.2012 - 21:10:25 - [] ----D C:\Users\GELO\AppData\Local\Kartina.TV

O43 - CFD: 02.08.2012 - 23:41:33 - [] ----D C:\Users\GELO\AppData\Local\Macromedia

O43 - CFD: 06.03.2015 - 10:31:54 - [0] ----D C:\Users\GELO\AppData\Local\ManyCam

O43 - CFD: 04.04.2013 - 0:10:11 - [] ----D C:\Users\GELO\AppData\Local\MaxTV Technologies

O43 - CFD: 30.05.2013 - 22:18:43 - [] ----D C:\Users\GELO\AppData\Local\Mgeni

O43 - CFD: 08.12.2014 - 10:50:23 - [] ----D C:\Users\GELO\AppData\Local\Microsoft

O43 - CFD: 16.04.2012 - 22:00:45 - [] ----D C:\Users\GELO\AppData\Local\Microsoft Games

O43 - CFD: 30.07.2013 - 11:59:06 - [] ----D C:\Users\GELO\AppData\Local\Microsoft Help

O43 - CFD: 16.11.2012 - 23:32:49 - [] ----D C:\Users\GELO\AppData\Local\Moonchild Productions

O43 - CFD: 29.12.2013 - 22:03:48 - [] ----D C:\Users\GELO\AppData\Local\Mozilla

O43 - CFD: 25.06.2013 - 20:25:13 - [] ----D C:\Users\GELO\AppData\Local\Mydownloadwin_security

O43 - CFD: 09.11.2014 - 20:53:34 - [] ----D C:\Users\GELO\AppData\Local\Octoshape

O43 - CFD: 19.08.2013 - 19:38:20 - [] ----D C:\Users\GELO\AppData\Local\Opera

O43 - CFD: 03.07.2013 - 12:36:28 - [] ----D C:\Users\GELO\AppData\Local\Opera Software

O43 - CFD: 23.04.2014 - 16:21:57 - [] ----D C:\Users\GELO\AppData\Local\Packages

O43 - CFD: 16.07.2014 - 9:43:24 - [] ----D C:\Users\GELO\AppData\Local\Paint.NET

O43 - CFD: 26.01.2015 - 0:55:15 - [] ----D C:\Users\GELO\AppData\Local\Parom.TV

O43 - CFD: 30.07.2013 - 11:10:03 - [] ----D C:\Users\GELO\AppData\Local\PDF Writer

O43 - CFD: 03.06.2013 - 22:48:11 - [] ----D C:\Users\GELO\AppData\Local\PDF24

O43 - CFD: 29.01.2015 - 19:52:31 - [0] ----D C:\Users\GELO\AppData\Local\PDFCreator

O43 - CFD: 15.07.2013 - 23:27:22 - [] ----D C:\Users\GELO\AppData\Local\Pinnacle Systems GmbH

O43 - CFD: 25.02.2014 - 12:18:22 - [] ----D C:\Users\GELO\AppData\Local\Programs

O43 - CFD: 10.09.2013 - 22:09:08 - [] ----D C:\Users\GELO\AppData\Local\RNT

O43 - CFD: 13.03.2014 - 20:52:44 - [] ----D C:\Users\GELO\AppData\Local\roulettechat-hot

O43 - CFD: 10.08.2014 - 11:19:52 - [] ----D C:\Users\GELO\AppData\Local\Samsung

O43 - CFD: 05.06.2013 - 22:16:49 - [0] ----D C:\Users\GELO\AppData\Local\Secunia PSI

O43 - CFD: 17.02.2014 - 12:49:26 - [] ----D C:\Users\GELO\AppData\Local\Skype

O43 - CFD: 11.12.2012 - 22:08:01 - [] ----D C:\Users\GELO\AppData\Local\SlimWare Utilities Inc

O43 - CFD: 12.12.2012 - 19:14:34 - [] ----D C:\Users\GELO\AppData\Local\Soft4Boost

O43 - CFD: 26.11.2012 - 0:04:06 - [] ----D C:\Users\GELO\AppData\Local\Spoon

O43 - CFD: 01.09.2014 - 13:12:41 - [] ----D C:\Users\GELO\AppData\Local\Stardock

O43 - CFD: 09.03.2015 - 22:39:09 - [] ----D C:\Users\GELO\AppData\Local\Temp

O43 - CFD: 28.03.2012 - 11:56:03 - [] -SH-D C:\Users\GELO\AppData\Local\Temporary Internet Files

O43 - CFD: 22.04.2012 - 17:18:59 - [] ----D C:\Users\GELO\AppData\Local\Thinstall

O43 - CFD: 31.10.2012 - 1:03:29 - [] ----D C:\Users\GELO\AppData\Local\VirtualStore

O43 - CFD: 31.12.2014 - 1:58:00 - [] ----D C:\Users\GELO\AppData\Local\VMware

O43 - CFD: 20.06.2012 - 2:11:31 - [0] ----D C:\Users\GELO\AppData\Local\VS Revo Group

O43 - CFD: 07.03.2015 - 18:27:04 - [] ----D C:\Users\GELO\AppData\Local\Windows Live

O43 - CFD: 27.12.2013 - 21:24:38 - [] ----D C:\Users\GELO\AppData\Local\Windows Live Writer

O43 - CFD: 07.09.2014 - 18:57:28 - [] ----D C:\Users\GELO\AppData\Local\Wondershare

O43 - CFD: 05.09.2014 - 15:43:20 - [] ----D C:\Users\GELO\AppData\Local\www.obnovi-soft.ru

O43 - CFD: 26.09.2012 - 0:46:30 - [] ----D C:\Users\GELO\AppData\Local\Xenocode

O43 - CFD: 13.11.2013 - 1:49:03 - [] ----D C:\Users\GELO\AppData\Local\Xpom

O43 - CFD: 28.09.2013 - 19:30:40 - [] ----D C:\Users\GELO\AppData\Local\Zattoo

O43 - CFD: 10.06.2012 - 3:11:26 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 11

O43 - CFD: 14.07.2009 - 5:54:32 - [] R---D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories

O43 - CFD: 08.01.2015 - 20:27:48 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ace Stream Media

O43 - CFD: 13.08.2014 - 13:50:15 - [] R---D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools

O43 - CFD: 10.09.2014 - 15:56:10 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVir Task Manager

O43 - CFD: 03.11.2013 - 17:54:23 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games

O43 - CFD: 09.03.2015 - 2:42:59 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome

O43 - CFD: 07.03.2015 - 18:37:37 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ICQ

O43 - CFD: 04.04.2012 - 8:36:00 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kartina.TV

O43 - CFD: 14.07.2009 - 5:49:38 - [] R---D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

O43 - CFD: 21.04.2012 - 14:25:06 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Parom.TV

O43 - CFD: 13.01.2015 - 1:32:40 - [0] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Polyglossum

O43 - CFD: 08.09.2014 - 12:03:27 - [0] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SopCast

O43 - CFD: 14.02.2015 - 0:25:46 - [] R---D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

O43 - CFD: 02.04.2012 - 3:33:37 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker

O43 - CFD: 08.09.2014 - 11:15:00 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR

O43 - CFD: 28.07.2013 - 23:50:52 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XBMC

O43 - CFD: 09.03.2015 - 2:42:59 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Приложения Chrome

~ 248 Dossier CLSID vide (CLSID Empty Folder)

~ Program Folder: 880 Scanned in 00mn 00s

novotek
 Posté le 10/03/2015 à 08:40 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

---\\ Last modified or created files under Windows and System32 (O44)

O44 - LFC:[MD5.8752CC895B972F48D82F9ADB3D96E351] - 03.03.2015 - 14:17:35 ----- . (.Microsoft Corporation - Microsoft Malware Protection Signature Upda.) -- C:\Windows\System32\MpSigStub.exe [295552]

O44 - LFC:[MD5.BF85D404851462FDF3157F49EA870725] - 06.03.2015 - 10:02:21 ---A- . (.Kingsoft Corporation - Kingsoft KSAPI Module.) -- C:\Windows\System32\Drivers\ksapi.sys [81768]

O44 - LFC:[MD5.6968FC608A61791C13CEFE6C8496CBD2] - 06.03.2015 - 10:02:21 ---A- . (.Kingsoft Corporation - Kingsoft KSAPI Module.) -- C:\Windows\System32\Drivers\ksapi64.sys [56680]

O44 - LFC:[MD5.6F593C7B14264FE2C6F3B96165BD95E5] - 07.03.2015 - 19:15:16 ---A- . (.Realtek - Realtek 8136/8168/8169 NDIS 6.20 64-bit Dri.) -- C:\Windows\System32\Drivers\Rt64win7.sys [942808]

O44 - LFC:[MD5.0D2106264D437A031DD64A9DA514357F] - 07.03.2015 - 19:15:16 ---A- . (.Realtek Semiconductor Corporation - About Page.) -- C:\Windows\System32\RtNicProp64.dll [73800]

O44 - LFC:[MD5.49A88E6CD77939F5F7D443628A18A317] - 07.03.2015 - 19:15:16 ---A- . (.Realtek Semiconductor Corporation - RTNUninst.) -- C:\Windows\System32\RTNUninst64.dll [107552]

O44 - LFC:[MD5.B9B73E9AF77BC79C46E499A1D3B09D67] - 07.03.2015 - 19:15:47 ---A- . (.Andrea Electronics Corporation - Capture Noise Filters (64-bit).) -- C:\Windows\System32\AERTAC64.dll [560328]

O44 - LFC:[MD5.814231B961760C39A5807A43D8ED71E1] - 07.03.2015 - 19:15:51 ---A- . (...) -- C:\Windows\System32\Drivers\RTAIODAT.DAT [1443340]

O44 - LFC:[MD5.FFFCA96B0636F122C3A586ACBDB8CC42] - 07.03.2015 - 19:15:51 ---A- . (.Realtek Semiconductor Corp. - Realtek HD Audio Coinstaller.) -- C:\Windows\System32\RCoInstII64.dll [959704]

O44 - LFC:[MD5.210A6EE42206A5A3EB5D5412906A7949] - 07.03.2015 - 19:15:51 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) LFX/GFX DSP component.) -- C:\Windows\System32\RltkAPO64.dll [2827120]

O44 - LFC:[MD5.19F11159B215F80D72953DAFF11E023C] - 07.03.2015 - 19:15:52 ---A- . (.Realtek Semiconductor Corp. - HDA driver COM file.) -- C:\Windows\System32\RtDataProc64.dll [629464]

O44 - LFC:[MD5.309ED3A5B26A40BA9621456367B97F94] - 07.03.2015 - 19:15:52 ---A- . (.Realtek Semiconductor Corp. - RTCOMDLL Module.) -- C:\Windows\System32\RTCOM64.dll [1287384]

O44 - LFC:[MD5.5E91D529C9588FB3AB7AB1AE0A26EFDF] - 07.03.2015 - 19:15:52 ---A- . (.Realtek Semiconductor Corp. - Realtek APO API.) -- C:\Windows\System32\RtkApi64.dll [3186544]

O44 - LFC:[MD5.D2B1DA73B6E8769A1BE1A55693B7F1B3] - 07.03.2015 - 19:15:52 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\Drivers\RTKVHD64.sys [4263128]

O44 - LFC:[MD5.BE7AB7EDD5BCEB22D660A0E3DF0A1B5A] - 07.03.2015 - 19:15:53 ---A- . (.Realtek Semiconductor Corp. - Realtek LFX/GFX DSP UI component for Window.) -- C:\Windows\System32\RtPgEx64.dll [2860760]

O44 - LFC:[MD5.C604B5CFC9DEAAA32691FC2798B86936] - 08.03.2015 - 11:32:00 --HA- . (...) -- C:\Windows\System32\Drivers\Msft_Kernel_webTinstMK_01009.Wdf [14040] =>PUP.CorsicaTechnologies

O44 - LFC:[MD5.DF47B045E8113A9712903AF832BD505C] - 08.03.2015 - 12:30:08 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [6510]

O44 - LFC:[MD5.12BE46F9E8BC4AF67BFE870DC423761F] - 08.03.2015 - 12:30:08 ---A- . (...) -- C:\Windows\System32\perfc009.dat [1754056]

O44 - LFC:[MD5.1FCE31EAF1616CB42523C6BB9B7BB49F] - 08.03.2015 - 12:30:08 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [1795752]

O44 - LFC:[MD5.A119B323D624C1530156B2A5ACE4E97D] - 08.03.2015 - 12:30:08 ---A- . (...) -- C:\Windows\System32\perfh009.dat [2404458]

O44 - LFC:[MD5.B3E892E84475F165FDAFDF4724EDD909] - 08.03.2015 - 12:30:08 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [2654644]

O44 - LFC:[MD5.26C43960C99EE861A5D0EDC4DCF3B1C3] - 08.03.2015 - 19:50:42 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [129752]

O44 - LFC:[MD5.B4F15AEF86B3169CCCCE34DE8D3B24E5] - 09.03.2015 - 21:28:12 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1561218]

O44 - LFC:[MD5.AC4C51EB24AA95B77F705AB159189E24] - 09.03.2015 - 2:08:05 ---A- . (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\explorer.exe [2872320]

O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 09.03.2015 - 2:10:35 ---A- . (...) -- C:\Windows\setuperr.log [0]

O44 - LFC:[MD5.413FEB18799BFD8603542A6874A24F38] - 09.03.2015 - 2:10:44 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [434104]

O44 - LFC:[MD5.3FAA3EC83BB54047BC03D1DC4E5CB81E] - 09.03.2015 - 2:25:51 ---A- . (...) -- C:\Windows\ntbtlog.txt [13495506]

O44 - LFC:[MD5.FD267C16D3ACEDBDA7E7AD377A6C5FE5] - 09.03.2015 - 2:37:47 ---A- . (.Trend Micro Inc. - TrendMicro Common Module.) -- C:\Windows\System32\Drivers\tmcomm.sys [173504]

O44 - LFC:[MD5.5A0F89DED2975FE44D07007F8D5034B6] - 09.03.2015 - 2:37:48 ---A- . (.trend_company_name - Trend Micro Anti-Rootkit Driver.) -- C:\Windows\System32\Drivers\tmrkb.sys [184768]

O44 - LFC:[MD5.36586D1074280FF5F24AC4B93ADACFC3] - 09.03.2015 - 2:44:01 ---A- . (...) -- C:\Windows\PFRO.log [476]

O44 - LFC:[MD5.DCFEC67F0259ACF7C612C2AEBE0D80D5] - 09.03.2015 - 8:10:06 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]

O44 - LFC:[MD5.640DAD2C12AB9C0D0D3070666B6CCF80] - 09.03.2015 - 8:10:11 ---A- . (...) -- C:\Windows\setupact.log [224]

O44 - LFC:[MD5.3B9E2AB1F3ABC53D4A423E699EB625C8] - 25.02.2015 - 10:21:19 ---A- . (...) -- C:\Windows\System32\locale.nls [419936]

~ Files: 33 Scanned in 00mn 05s

---\\ Local Security Authority-LSA Deny (O48)

O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll

O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corp. - LiveSSP.) -- C:\Windows\System32\livessp.dll

~ LSA: 9 Scanned in 00mn 00s

---\\ Safe Boot Control (O49)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\hitmanpro37.sys . (...) -- C:\Windows\System32\Drivers\hitmanpro37.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\hitmanpro37.sys . (...) -- C:\Windows\System32\Drivers\hitmanpro37.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys

~ CSB: 15 Scanned in 00mn 00s

---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52)

O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm

O52 - TDSD: \Drivers32\"VIDC.FFDS"="ff_vfw.dll" . (.No owner - ffdshow VFW.) -- C:\Windows\System32\ff_vfw.dll

O52 - TDSD: \Drivers32\"VIDC.LAGS"="lagarith.dll" . (.No owner - Lagarith.) -- C:\Windows\System32\lagarith.dll

O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm

O52 - TDSD: \drivers.desc\"ff_vfw.dll"="ffdshow video encoder" . (.No owner - ffdshow VFW.) -- C:\Windows\System32\ff_vfw.dll

O52 - TDSD: \drivers.desc\"lagarith.dll"="Lagarith lossless codec [LAGS]" . (.No owner - Lagarith.) -- C:\Windows\System32\lagarith.dll

~ TDSD: 6 Scanned in 00mn 00s

---\\ Microsoft Control Security Providers (MCSP) (O54)

O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll

O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll

~ MSCP: 2 Scanned in 00mn 00s

---\\ Microsoft Windows Policies System (MWPS) (O55)

O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5

O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3

O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0

O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1

O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1

O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0

O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0

O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0

O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0

O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0

O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1

O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1

O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0

~ MWPS: 16 Scanned in 00mn 00s

---\\ Microsoft Windows Policies Explorer (MWPE) (O56)

O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1

O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1

O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0

~ MWPE Keys: 3 Scanned in 00mn 00s

---\\ System Drivers List (SDL) (O58)

O58 - SDL:09.12.2012 - 20:49:32 ---A- . (.NXP Semiconductors Germany GmbH - 3xHybrid.) -- C:\Windows\System32\Drivers\3xHybr64.sys [1448064]

O58 - SDL:14.07.2009 - 2:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088]

O58 - SDL:14.07.2009 - 2:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [339536]

O58 - SDL:14.07.2009 - 2:52:21 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\Drivers\adpu320.sys [182864]

O58 - SDL:14.07.2009 - 2:52:21 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [15440]

O58 - SDL:11.03.2011 - 7:41:12 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [107904]

O58 - SDL:14.07.2009 - 2:52:20 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows -.) -- C:\Windows\System32\Drivers\amdsbs.sys [194128]

O58 - SDL:11.03.2011 - 7:41:12 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [27008]

O58 - SDL:10.01.2011 - 17:16:08 ---A- . (...) -- C:\Windows\System32\Drivers\AppleCharger.sys [21104]

O58 - SDL:14.07.2009 - 2:52:21 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [87632]

O58 - SDL:14.07.2009 - 2:52:21 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [97856]

O58 - SDL:10.06.2009 - 21:34:23 ---A- . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver..) -- C:\Windows\System32\Drivers\b57nd60a.sys [270848]

O58 - SDL:10.06.2009 - 21:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [18432]

O58 - SDL:10.06.2009 - 21:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [8704]

O58 - SDL:14.07.2009 - 2:19:07 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [286720]

O58 - SDL:10.06.2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [47104]

O58 - SDL:10.06.2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [14976]

O58 - SDL:10.06.2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [14720]

O58 - SDL:10.06.2009 - 21:34:28 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbda.sys [468480]

O58 - SDL:23.04.2007 - 13:44:12 ---A- . (...) -- C:\Windows\System32\Drivers\camdrv42.sys [1533952]

O58 - SDL:30.10.2011 - 13:14:56 ---A- . (.CrystalIdea Software - Uninstall Tool 3 Driver.) -- C:\Windows\System32\Drivers\CisUtMonitor.sys [33360]

O58 - SDL:14.07.2009 - 2:52:31 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [17488]

O58 - SDL:14.07.2009 - 2:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]

O58 - SDL:12.02.2014 - 18:22:00 ---A- . (.Etron Technology Inc - Etron eXtensible Hub Driver..) -- C:\Windows\System32\Drivers\EtronHub3.sys [65408]

O58 - SDL:12.02.2014 - 18:22:00 ---A- . (.Etron Technology Inc - Etron eXtensible Host Controller Driver..) -- C:\Windows\System32\Drivers\EtronXHCI.sys [94208]

O58 - SDL:10.06.2009 - 21:34:33 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbda.sys [3286016]

O58 - SDL:21.08.2012 - 12:01:20 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys [33240]

O58 - SDL:02.12.2012 - 11:03:17 ---A- . (.GFI Software - GFI Boot Time Operations Driver.) -- C:\Windows\System32\Drivers\gfibto.sys [14456]

O58 - SDL:02.11.2009 - 16:47:26 ---A- . (.No owner - WDM NULL filter driver.) -- C:\Windows\System32\Drivers\gMouUsb.sys [14336]

O58 - SDL:27.02.2014 - 18:40:32 ---A- . (.VMware, Inc. - VMware USB monitor.) -- C:\Windows\System32\Drivers\hcmon.sys [54464]

O58 - SDL:23.10.2012 - 10:55:46 ---A- . (.Hauppauge Computer Works, Inc. - WinTV-Nova-T-Mini device driver.) -- C:\Windows\System32\Drivers\hcw17b64.sys [78192]

O58 - SDL:06.08.2012 - 11:18:48 ---A- . (.Hauppauge Computer Works, Inc. - WinTV-Nova-T-Mini device driver.) -- C:\Windows\System32\Drivers\hcw17bda.sys [75184]

O58 - SDL:10.06.2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]

O58 - SDL:19.10.2010 - 22:34:26 ---A- . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\Drivers\HECIx64.sys [56344]

O58 - SDL:21.11.2010 - 4:23:47 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [78720]

O58 - SDL:11.03.2011 - 7:41:26 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\Drivers\iaStorV.sys [410496]

O58 - SDL:14.07.2009 - 2:48:04 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [44112]

O58 - SDL:06.03.2015 - 10:02:21 ---A- . (.Kingsoft Corporation - Kingsoft KSAPI Module.) -- C:\Windows\System32\Drivers\ksapi.sys [81768]

O58 - SDL:06.03.2015 - 10:02:21 ---A- . (.Kingsoft Corporation - Kingsoft KSAPI Module.) -- C:\Windows\System32\Drivers\ksapi64.sys [56680]

O58 - SDL:14.07.2009 - 2:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [114752]

O58 - SDL:14.07.2009 - 2:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [106560]

O58 - SDL:14.07.2009 - 2:48:04 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [65600]

O58 - SDL:14.07.2009 - 2:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [115776]

O58 - SDL:29.09.2012 - 20:54:26 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam,3.sys [25928]

O58 - SDL:21.11.2014 - 6:14:08 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [25816]

O58 - SDL:21.11.2014 - 6:14:12 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [93400]

O58 - SDL:08.03.2015 - 19:50:42 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [129752]

O58 - SDL:06.12.2013 - 14:37:50 ---A- . (.Visicom Media Inc. - ManyCam Virtual Microphone.) -- C:\Windows\System32\Drivers\mcaudrv_x64.sys [35232]

O58 - SDL:27.11.2013 - 2:54:02 ---A- . (.Visicom Media Inc. - ManyCam Virtual Webcam Driver.) -- C:\Windows\System32\Drivers\mcvidrv.sys [42016]

O58 - SDL:14.07.2009 - 2:48:04 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for.) -- C:\Windows\System32\Drivers\megasas.sys [35392]

O58 - SDL:14.07.2009 - 2:48:04 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [284736]

O58 - SDL:21.11.2014 - 6:14:22 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [63704]

O58 - SDL:14.07.2009 - 2:48:26 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [51264]

O58 - SDL:01.03.2013 - 2:49:12 ---A- . (.Riverbed Technology, Inc. - npf.sys (NT5/6 AMD64) Kernel Driver.) -- C:\Windows\System32\Drivers\npf.sys [36600]

O58 - SDL:19.02.2013 - 22:32:18 ---A- . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 307.83.) -- C:\Windows\System32\Drivers\nvlddmkm.sys [13531936]

O58 - SDL:11.03.2011 - 7:41:34 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [148352]

O58 - SDL:11.03.2011 - 7:41:34 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [166272]

O58 - SDL:03.04.2007 - 10:30:14 ---A- . (.Philips Semiconductors GmbH - Ph3xIBxx.) -- C:\Windows\System32\Drivers\Ph3xIB64.sys [1418112]

O58 - SDL:14.07.2009 - 2:45:46 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1524816]

O58 - SDL:14.07.2009 - 2:45:45 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [128592]

O58 - SDL:07.03.2015 - 19:15:16 ---A- . (.Realtek - Realtek 8136/8168/8169 NDIS 6.20 64-bit Driver.) -- C:\Windows\System32\Drivers\Rt64win7.sys [942808]

O58 - SDL:07.03.2015 - 19:15:52 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver.) -- C:\Windows\System32\Drivers\RTKVHD64.sys [4263128]

O58 - SDL:10.06.2009 - 21:37:19 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [23040]

O58 - SDL:14.07.2009 - 2:45:45 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [43584]

O58 - SDL:14.07.2009 - 2:45:46 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [80464]

O58 - SDL:20.10.2012 - 8:43:02 ---A- . (.Ray Hinchliffe - System Information Viewer X64 Driver.) -- C:\Windows\System32\Drivers\SIVX64.sys [129856]

O58 - SDL:01.01.2000 - 1:00:00 ---A- . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\Windows\System32\Drivers\Smb_driver_Intel.sys [34544]

O58 - SDL:22.02.2013 - 8:16:54 ---A- . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\Windows\System32\Drivers\ssadcm.sys [17224]

O58 - SDL:22.02.2013 - 8:16:54 ---A- . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\Windows\System32\Drivers\ssadwh.sys [17736]

O58 - SDL:14.07.2009 - 2:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]

O58 - SDL:20.03.2014 - 10:43:02 ---A- . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\Drivers\TeeDriverx64.sys [118272]

O58 - SDL:09.03.2015 - 2:37:47 ---A- . (.Trend Micro Inc. - TrendMicro Common Module.) -- C:\Windows\System32\Drivers\tmcomm.sys [173504]

O58 - SDL:09.03.2015 - 2:37:48 ---A- . (.trend_company_name - Trend Micro Anti-Rootkit Driver.) -- C:\Windows\System32\Drivers\tmrkb.sys [184768]

O58 - SDL:14.07.2009 - 2:45:55 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [17488]

O58 - SDL:08.10.2013 - 18:21:06 ---A- . (.VMware, Inc. - VMware PCI VMCI Bus Device.) -- C:\Windows\System32\Drivers\vmci.sys [85584]

O58 - SDL:29.10.2014 - 15:00:50 ---A- . (.VMware, Inc. - VMware keyboard filter driver (64-bit).) -- C:\Windows\System32\Drivers\VMkbd.sys [33496]

O58 - SDL:29.10.2014 - 15:00:52 ---A- . (.VMware, Inc. - VMware virtual network driver (64-bit).) -- C:\Windows\System32\Drivers\vmnet.sys [24656]

O58 - SDL:29.10.2014 - 15:00:52 ---A- . (.VMware, Inc. - VMware virtual network adapter driver (64-bit).) -- C:\Windows\System32\Drivers\vmnetadapter.sys [20560]

O58 - SDL:29.10.2014 - 15:00:52 ---A- . (.VMware, Inc. - VMware bridge driver (64-bit).) -- C:\Windows\System32\Drivers\vmnetbridge.sys [46160]

O58 - SDL:29.10.2014 - 15:01:14 ---A- . (.VMware, Inc. - VMware network application interface driver (64-bit).) -- C:\Windows\System32\Drivers\vmnetuserif.sys [31448]

O58 - SDL:29.10.2014 - 15:01:42 ---A- . (.VMware, Inc. - VMware kernel driver.) -- C:\Windows\System32\Drivers\vmx86.sys [64728]

O58 - SDL:14.07.2009 - 2:45:55 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [161872]

O58 - SDL:08.10.2013 - 18:21:10 ---A- . (.VMware, Inc. - VMware vSockets Service.) -- C:\Windows\System32\Drivers\vsock.sys [73296]

O58 - SDL:07.03.2015 - 18:43:42 ---A- . (.REALiX(tm) - HWiNFO AMD64 Kernel Driver.) -- C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528]

O58 - SDL:14.08.2013 - 8:34:04 ---A- . (...) -- C:\Windows\SysWOW64\drivers\vwifikerneldrv.sys [389]

O58 - SDL:23.11.1999 - 8:17:34 ---A- . (...) -- C:\Windows\SysWOW64\dc240u.sys [7808]

O58 - SDL:23.11.1999 - 8:17:36 ---A- . (...) -- C:\Windows\SysWOW64\Digita.sys [65864]

O58 - SDL:05.02.2013 - 9:54:40 ---A- . (...) -- C:\Windows\SysWOW64\FsUsbExDisk.Sys [37344]

~ Drivers: 88 Scanned in 00mn 05s

---\\ Last modified or created user files (O61)

O61 - LFC: 02.03.2015 - 22:41:01 ---A- . (.Microsoft Corporation.) -- C:\Users\GELO\AppData\Roaming\Microsoft\MSXML2\msxml4.dll [1275392]

O61 - LFC: 02.03.2015 - 22:41:01 ---A- . (.Microsoft Corporation.) -- C:\Users\GELO\AppData\Roaming\Microsoft\MSXML2\msxml4a.dll [44544]

O61 - LFC: 02.03.2015 - 22:41:01 ---A- . (.Microsoft Corporation.) -- C:\Users\GELO\AppData\Roaming\Microsoft\MSXML2\msxml4r.dll [82432]

O61 - LFC: 02.03.2015 - 22:42:32 ---A- . (.Microsoft Corporation.) -- C:\Users\GELO\Downloads\1\Protéger son ordinateur avec Microsoft Security Essentials\mseinstall.exe [11555632]

O61 - LFC: 05.03.2015 - 22:42:45 ---A- . (...) -- C:\Users\GELO\Downloads\gg-install.exe [395056]

O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (...) -- C:\Users\GELO\AppData\Roaming\ICQM\ICQ\dll\MousePhone.dll [56840]

O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (...) -- C:\Users\GELO\AppData\Roaming\ICQM\ICQ\dll\mailrusputnik.exe [4739616]

O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (.ICQ.) -- C:\Users\GELO\AppData\Roaming\ICQM\icq.exe [36705800]

O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (.ICQ.) -- C:\Users\GELO\AppData\Roaming\ICQM\icqsetup.exe [37968904]

O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (.Mail.Ru.) -- C:\Users\GELO\AppData\Roaming\ICQM\ICQ\dll\mratag.dll [112136]

O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (.Mail.Ru.) -- C:\Users\GELO\AppData\Roaming\ICQM\libvoip_x86.dll [2917384]

O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (.TODO: <Company name>.) -- C:\Users\GELO\AppData\Roaming\ICQM\MRAInplaceViewer.dll [2350600]

O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (.Terra Informatica Software, Inc..) -- C:\Users\GELO\AppData\Roaming\ICQM\sciter32.dll [4261888]

O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (.goober Networks, Inc..) -- C:\Users\GELO\AppData\Roaming\ICQM\vivo.dll [3196936]

O61 - LFC: 08.03.2015 - 22:40:54 ---A- . (...) -- C:\Users\GELO\AppData\LocalLow\Microsoft\Silverlight\OutOfBrowser\index\secure3.segpay.com [0]

O61 - LFC: 08.03.2015 - 22:41:08 ---A- . (...) -- C:\Users\GELO\AppData\Roaming\ooVoo Details\Users\hottboy2006\{0003A8CC-452B-0000-BD6B-05AB0E68541E}.bin [2456]

O61 - LFC: 08.03.2015 - 22:42:22 ---A- . (.Clique Communications LLC.) -- C:\Users\GELO\Downloads\1\cliquevm.exe [8801672]

O61 - LFC: 08.03.2015 - 22:42:23 ---A- . (.FreoMessenger LLC.) -- C:\Users\GELO\Downloads\1\freo-setup.exe [1693808]

O61 - LFC: 08.03.2015 - 22:42:23 ---A- . (.ooVoo LLC.) -- C:\Users\GELO\Downloads\1\ooVooSetup.exe [2388000]

O61 - LFC: 09.03.2015 - 22:40:50 ---A- . (...) -- C:\Users\GELO\AppData\Local\Temp\RootkitBuster\sqlite3.dll [914432]

O61 - LFC: 09.03.2015 - 22:40:50 ---A- . (.Igor Pavlov.) -- C:\Users\GELO\AppData\Local\Temp\RootkitBuster\IAU_SDK.exe [6264669]

O61 - LFC: 09.03.2015 - 22:40:50 ---A- . (.Trend Micro Inc..) -- C:\Users\GELO\AppData\Local\Temp\RootkitBuster\TMRKScan.dll [664088]

O61 - LFC: 09.03.2015 - 22:40:50 ---A- . (.Trend Micro Inc..) -- C:\Users\GELO\AppData\Local\Temp\RootkitBuster\TmEngDrv.dll [420400]

O61 - LFC: 09.03.2015 - 22:40:50 ---A- . (.trend_company_name.) -- C:\Users\GELO\AppData\Local\Temp\RootkitBuster\tmrkb.sys [184768]

O61 - LFC: 09.03.2015 - 22:40:51 ---A- . (.Trend Micro Inc..) -- C:\Users\GELO\AppData\Local\Temp\RootkitBuster\vsapi.dll [2753552]

O61 - LFC: 09.03.2015 - 22:42:21 ---A- . (.Nicolas Coolman.) -- C:\Users\GELO\Desktop\ZHPDiag2.exe [6877328] =>.Nicolas Coolman

~ 392 Fichiers temporaires (Temporary files)

~ 37 Fichiers cookies (Cookies files)

~ Files: 26 Scanned in 06mn 56s

novotek
 Posté le 10/03/2015 à 08:41 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

---\\ List all tools cleaner (LATC) (O63)

O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman

~ ADS: Scanned in 00mn 00s

---\\ List all legacy services(LALS) (O64)

O64 - Services: CurCS - 10.01.2011 - C:\Windows\System32\DRIVERS\AppleCharger.sys (AppleCharger) .(...) - LEGACY_APPLECHARGER

O64 - Services: CurCS - 02.12.2012 - C:\Windows\System32\drivers\gfibto.sys (gfibto) .(.GFI Software - GFI Boot Time Operations Driver.) - LEGACY_GFIBTO

O64 - Services: CurCS - 27.02.2014 - C:\Windows\system32\drivers\hcmon.sys (hcmon) .(.VMware, Inc. - VMware USB monitor.) - LEGACY_HCMON

O64 - Services: CurCS - 07.03.2015 - C:\Windows\sysWOW64\drivers\HWiNFO64A.sys (HWiNFO32) .(.REALiX(tm) - HWiNFO AMD64 Kernel Driver.) - LEGACY_HWINFO32

O64 - Services: CurCS - 21.11.2014 - C:\Windows\system32\drivers\mbamchameleon.sys (mbamchameleon) .(.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) - LEGACY_MBAMCHAMELEON

O64 - Services: CurCS - 21.11.2014 - C:\Windows\system32\drivers\mbam.sys (MBAMProtector) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMPROTECTOR

O64 - Services: CurCS - 01.03.2013 - C:\Windows\System32\drivers\npf.sys (NPF) .(.Riverbed Technology, Inc. - npf.sys (NT5/6 AMD64) Kernel Driver.) - LEGACY_NPF

O64 - Services: CurCS - 10.06.2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV

O64 - Services: CurCS - 01.07.2010 - C:\Program Files\Unlocker\UnlockerDriver5.sys (UnlockerDriver5) .(...) - LEGACY_UNLOCKERDRIVER5

O64 - Services: CurCS - 19.12.2012 - C:\Users\GELO\Desktop\VirtualBox 4.2.6 82870 Portable\App\VirtualBox\drivers\USB\filter\VBoxUSBMon.sys (VBoxUSBMon) .(.Oracle Corporation - VirtualBox USB Monitor Driver.) - LEGACY_VBOXUSBMON

O64 - Services: CurCS - 29.10.2014 - C:\Windows\System32\DRIVERS\vmnetbridge.sys (VMnetBridge) .(.VMware, Inc. - VMware bridge driver (64-bit).) - LEGACY_VMNETBRIDGE

O64 - Services: CurCS - 29.10.2014 - C:\Windows\system32\drivers\vmnetuserif.sys (VMnetuserif) .(.VMware, Inc. - VMware network application interface driver.) - LEGACY_VMNETUSERIF

O64 - Services: CurCS - 29.10.2014 - C:\Windows\system32\drivers\vmx86.sys (vmx86) .(.VMware, Inc. - VMware kernel driver.) - LEGACY_VMX86

O64 - Services: CurCS - 08.10.2013 - C:\Windows\System32\drivers\vsock.sys (vsock) .(.VMware, Inc. - VMware vSockets Service.) - LEGACY_VSOCK

~ Legacy: 94 Scanned in 00mn 08s

---\\ File Associations Shell Spawning (O67)

O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation

O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe

O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.html> <OperaStable>[HKLM\..\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\Launcher.exe

O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe

O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe

O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S

O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Not Key.)

~ FASS Keys: 11 Scanned in 00mn 00s

---\\ Start Menu Internet (SMI) (O68)

O68 - StartMenuInternet: <Aviator> <Aviator>[HKLM\..\Shell\open\Command] (.Not Key.)

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Not Key.)

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Not Key.)

O68 - StartMenuInternet: <k-meleon.exe> <K-Meleon>[HKLM\..\Shell\open\Command] (.Not Key.)

O68 - StartMenuInternet: <Lunascape6> <Lunascape6>[HKLM\..\Shell\open\Command] (.Not Key.)

O68 - StartMenuInternet: <Opera> <Opera>[HKLM\..\Shell\open\Command] (.Not Key.)

O68 - StartMenuInternet: <OperaStable> <Opera Stable>[HKLM\..\Shell\open\Command] (.Not Key.)

~ Keys: Scanned in 00mn 00s

---\\ Search Browser Infection (SBI) (O69)

O69 - SBI: prefs.js [GELO - blozzve3.default] user_pref("weboftrust.search.ask.display", "Ask.com Web Search");

O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com

O69 - SBI: SearchScopes [HKCU] {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} - (e) - http://rambler.ru

O69 - SBI: SearchScopes [HKCU] {231CE532-7C50-418F-AAFC-B14AA5118BD8} - (Translate.Ru) - http://rambler.ru

O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} [DefaultScope] - (Google) - http://www.google.com

O69 - SBI: SearchScopes [HKUS\.DEFAULT] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com

O69 - SBI: SearchScopes [HKUS\S-1-5-18] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com

~ Keys: Scanned in 00mn 00s

---\\ Search Svchost Services (SSS) (O83)

O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192]

O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384]

O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384]

O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [236032]

O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [777728]

O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [859648]

O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [680960]

O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [99328]

O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [344064]

O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792]

O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [64512]

O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [359424]

O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [316928]

O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [683520]

O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\system32\wuaueng.dll [2477536]

O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [849920]

O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [370688]

O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [569344]

O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [30720]

O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70144]

O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [156672]

O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [67584]

O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [219136]

O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [121856]

O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136704]

O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104]

O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1110016]

O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [90624]

O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84480]

O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [210432]

O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [44544]

O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864]

~ Services: 32 Scanned in 00mn 00s

---\\ Search Particular Root Folder (SPRF) (O84)

[MD5.6CD985C9E791C4D9F6441C9C360CA5BB] [SPRF][14.08.2013] (...) -- C:\ProgramData\fontcacheev1.dat [389]

[MD5.F1D3FF8443297732862DF21DC4E57262] [SPRF][09.08.2014] (...) -- C:\Users\GELO\AppData\Roaming\wklnhst.dat [4]

[MD5.72695F5E580D1F66F933C64323520093] [SPRF][09.03.2015] (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Users\GELO\Desktop\ZHPDiag2.exe [6877328]

[MD5.CFE1AF5EE9CD57726695DC11941C0FB1] [SPRF][20.04.2011] (...) -- C:\Windows\Downloaded Program Files\WebInstallRunner.dll [43008]

~ Files: 4 Scanned in 00mn 00s

---\\ Firewall Active Exception List (FirewallRules) (O87)

O87 - FAEL: "TCP Query User{684C0968-BAD5-4925-A14F-B447D7ABFC88}E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe" | In - Public - P6 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe =>P2P.BitTorrent

O87 - FAEL: "UDP Query User{A1262EFB-21DF-4EF3-B28D-AFAC5BC49423}E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe" | In - Public - P17 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe =>P2P.BitTorrent

~ Firewall: 2 Scanned in 00mn 18s

---\\ Windows Installer Scan (WIS) (O93) (NTFS)

[MD5.013946FEC4064E014774D39623AA7CE4] [WIS][16.10.2013] (.APN, LLC - Sopcast Toolbar.) -- C:\Windows\Installer\346d8a5.msi [523264] =>Toolbar.Ask

~ WIS: 1 Scanned in 00mn 06s

---\\ General States of Services not Microsoft (EGS) (SR=Running, SS=Stopped)

SS - | Demand 09.02.2015 267440 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

SS - | Auto 22.07.1658 0 | (AdvancedSystemCareService8) . (...) - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ASCService.exe

SS - | Demand 06.04.2010 31272 | (AppleChargerSrv) . (...) - C:\Windows\System32\AppleChargerSrv.exe

SS - | Auto 22.07.1658 0 | (ASCAntivirusSrv) . (...) - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ascavsvc.exe

SS - | Auto 20.10.2014 107912 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

SS - | Demand 20.10.2014 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

SS - | Demand 14.08.2012 194032 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

SS - | Auto 22.07.1658 0 | (HitmanProScheduler) . (...) - C:\Program Files\HitmanPro\hmpsched.exe

SS - | Demand 14.11.2005 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

SS - | Demand 31.01.2014 887232 | (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe

SS - | Auto 22.07.1658 0 | (LiveUpdateSvc) . (...) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe

SS - | Auto 21.11.2014 969016 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe

SS - | Demand 05.03.2015 148592 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

SS - | Demand 09.10.2006 724992 | (NBService) . (.Nero AG.) - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe

SS - | Auto 08.04.2013 799280 | (PDF Architect Service) . (.pdfforge GmbH.) - C:\Program Files (x86)\PDF Architect\ConversionService.exe

SS - | Demand 01.03.2013 118520 | (rpcapd) . (.Riverbed Technology, Inc..) - C:\Program Files (x86)\WinPcap\rpcapd.exe

SS - | Demand 04.11.2008 68760 | (SandraAgentSrv) . (.SiSoftware.) - C:\Program Files\SiSoftware\SiSoftware Sandra Business 2013\RpcAgentSrv.exe

SS - | Auto 02.01.2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe

SS - | Demand 14.07.2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

SS - | Demand 22.07.1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation

SR - | Auto 14.05.2009 759048 | (ABBYY.Licensing.FineReader.Sprint.9.0) . (.ABBYY.) - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe

SR - | Auto 15.12.2011 917640 | (AcuWVSSchedulerv8) . (...) - C:\Program Files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe

SR - | Auto 03.12.2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

SR - | Auto 24.01.2012 21880 | (APC Data Service) . (.Schneider Electric.) - C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe

SR - | Auto 24.01.2012 705912 | (APC UPS Service) . (.Schneider Electric.) - C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe

SR - | Auto 12.02.2014 43336 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

SR - | Auto 30.08.2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe

SR - | Auto 06.03.2015 315240 | (cmcore) . (.Kingsoft Corporation.) - c:\program files (x86)\cmcm\Clean Master\cmcore.exe

SR - | Auto 21.02.2012 151648 | (EPSON_PM_RPCV4_04) . (.SEIKO EPSON CORPORATION.) - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.exe

SR - | Auto 14.02.2014 579584 | (HauppaugeTVServer) . (.Hauppauge Computer Works.) - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe

SR - | Auto 20.01.2014 2818896 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe

SR - | Auto 21.11.2014 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe

SR - | Auto 30.01.2015 23784 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe

SR - | Auto 18.08.2009 7599616 | (MySQL) . (...) - C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe

SR - | Auto 31.01.2013 878368 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe

SR - | Auto 19.02.2013 1259296 | (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

SR - | Auto 08.04.2013 1320496 | (PDF Architect Helper Service) . (.pdfforge GmbH.) - C:\Program Files (x86)\PDF Architect\HelperService.exe

SR - | Auto 17.01.2013 8704 | (RumoteVMCService) . (.Rumote.) - C:\Program Files (x86)\Rumote\RumoteVMC\RumoteMCEService.exe

SR - | Auto 10.09.2012 193392 | (SCPDFReadSpool) . (.Solid Documents, LLC.) - C:\Program Files (x86)\SolidDocuments\Solid Converter PDF\SCPDF\SolidConverterPDFServicex64.exe

SR - | Auto 28.03.2012 82944 | (SLService) . (...) - C:\Windows\System32\slmdmsr.exe

SR - | Demand 20.12.2014 820960 | (SystemExplorerHelpService) . (.Mister Group.) - C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe

SR - | Auto 29.10.2014 86744 | (VMAuthdService) . (.VMware, Inc..) - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe

SR - | Auto 22.07.1658 0 | (VMnetDHCP) . (.VMware, Inc..) - C:\Windows\system32\vmnetdhcp.exe

SR - | Auto 27.02.2014 906432 | (VMUSBArbService) . (.VMware, Inc..) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe

SR - | Auto 22.07.1658 0 | (VMware NAT Service) . (.VMware, Inc..) - C:\Windows\system32\vmnat.exe

SR - | Auto 14.07.2009 27136 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

SR - | Auto 08.09.2014 97280 | (_wfcs) . (.BiniSoft.org.) - C:\Program Files\Windows Firewall Control\wfcs.exe

~ Services: Scanned in 00mn 11s

---\\ Search Master Boot Record Infection (MBR)(O80)

Run by GELO at 09.03.2015 22:49:13

~ OS 64 not supported by MBR tool

~ MBR: 0 Scanned in 00mn 00s

---\\ Search Master Boot Record Infection (MBRCheck)(O80)

Written by ad13, http://ad13.geekstog

Run by GELO at 09.03.2015 22:49:15

********* Dump file Name *********

C:\PhysicalDisk0_MBR.bin

~ MBR: Scanned in 00mn 02s

---\\ Scan Additionnel (O88)

Database Version : 13008 - (08.03.2015)

Clés trouvées (Keys found) : 6

Valeurs trouvées (Values found) : 1

Dossiers trouvés (Folders found) : 5

Fichiers trouvés (Files found) : 6

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Applian FLV Player2.0.24] =>PUP.ApplianTechnologies^

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Applian FLV and Media Player] =>PUP.ApplianTechnologies^

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{53504356-3700-A76A-76A7-A758B70C0600}] =>Toolbar.Ask^

[HKLM\Software\Classes\Interface\{D6094FC6-821F-474C-8D73-C13066CD178D}] =>Toolbar.Agent

[HKLM\Software\Wow6432Node\Classes\Interface\{D6094FC6-821F-474C-8D73-C13066CD178D}] =>Toolbar.Agent

[HKLM\Software\Classes\AppID\secman.DLL] =>PUP.Babylon

C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\blozzve3.default\extensions\pavel.sherbakov@gmail.com =>PUP.QuickShare^

C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\extensions\pavel.sherbakov@gmail.com =>PUP.QuickShare^

C:\Program Files (x86)\Applian Technologies =>PUP.ApplianTechnologies^

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Applian Technologies =>PUP.ApplianTechnologies^

C:\Users\GELO\AppData\Roaming\Applian FLV and Media Player =>PUP.ApplianTechnologies^

C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rel.job =>Toolbar.AVGSearch^

C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rel =>Toolbar.AVGSearch^

C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rmv.job =>Toolbar.AVGSearch^

C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rmv =>Toolbar.AVGSearch^

[HKLM\Software\Wow6432Node\Applian Technologies] =>PUP.ApplianTechnologies^

C:\Windows\Installer\346d8a5.msi =>Toolbar.Ask^

~ Additionnel Scan: 388926 Items scanned in 00mn 30s

---\\ Additional information about modules

~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)

~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects (O2)

~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer toolbars (O3)

~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Auto loading programs from Registry and folders (O4)

~ AMI: 4 Scanned in 00mn 00s

---\\ Summary of the detections found on your workstation

http://nicolascoolman.fr/pup-quickshare =>PUP.QuickShare

http://www.nicolascoolman.fr/blog/ =>PUP.ApplianTechnologies

http://nicolascoolman.fr/toolbar-ask =>Toolbar.Ask

http://www.nicolascoolman.fr/blog/ =>PUP.CorsicaTechnologies

http://www.nicolascoolman.fr/blog/ =>Toolbar.Agent

http://nicolascoolman.fr/pup-babylon =>PUP.Babylon

~ MSI: 6 link(s) detected in 00mn 00s

End of the scan (2423 lines in 10mn 15s)(0.10)

Soutenez PC Astuces

PC Astuces a besoin de vous pour survivre. Nos conseils et astuces vous ont aidé ? Vous avez résolu un problème sur votre ordinateur ? Vous avez profité de nos bons plans ? Aidez-nous en retour avec un abonnement de soutien mensuel.


5 € par mois 10 € par mois 20 € par mois


Gérer son abonnement

lilidurhone
 Posté le 10/03/2015 à 08:52 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucienne

Héberge le rapport sur cjoint s'il te plaît

novotek
 Posté le 10/03/2015 à 09:01 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

Bonjour,

J'ai lu l'article ici https://forum.pcastuces.com/aide_au_diagnostic_un_pc_infecte_pcastuces-f25s17490.htm, Mais malheureusement il n'y a pas de ça ici: "Insérer un rapport", je n'ai pas trouvé. Ici il y a que ça Options : Ne plus suivre le sujet | Marquer comme résolu, donc je ne sais pas où et comment je peux vous envoyer le rapport en totalité. Je dois clicker sur: option "ne plus suivre le sujet" pour ajouter le rapport?



Modifié par novotek le 10/03/2015 09:02
clbugnot
 Posté le 10/03/2015 à 09:07 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
  Grand Maître astucien

Bonjour novotek

En cas d'absence de Insérer un rapport, utiliser cjoint.com qui donnera un lien que tu indiqueras dans ta prochaine réponse ; choisir durée de conservation 21 jours.

Cordialement

novotek
 Posté le 10/03/2015 à 09:10 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien
novotek
 Posté le 10/03/2015 à 09:26 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien
El Magnifico
 Posté le 10/03/2015 à 09:40 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Groupe Sécurité

novotek

Votre machine est infectée. Ce sujet serait mieux à sa place sur le forum Sécurité. Cliquez sur l'icône dans le bandeau au-dessus de votre message et dans la fenêtre qui s'affiche, demandez au modérateur de déplacer votre sujet vers le forum indiqué puis cliquez sur Envoyer. Si vos problèmes subsistent après la désinfection, revenez sur ce forum.

flober
 Posté le 10/03/2015 à 09:50 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucienne
El Magnifico a écrit :

novotek

Votre machine est infectée. Ce sujet serait mieux à sa place sur le forum Sécurité. Cliquez sur l'icône dans le bandeau au-dessus de votre message et dans la fenêtre qui s'affiche, demandez au modérateur de déplacer votre sujet vers le forum indiqué puis cliquez sur Envoyer. Si vos problèmes subsistent après la désinfection, revenez sur ce forum.

Bonjour.

Je lui ai déjà demandé.

flober Posté le 10/03/2015 à 01:52 Modifier la réponse Supprimer la réponseRépondre en citant ce message
Astucienne

1112 Messages

re

Le rapport montre que tu es infecté.

Attends demain qu'un Helper te prenne en charge pour remettre tout en ordre.

Il serait souhaitable que tu transfert ta demande dans le forum sécurité.

bonne nuit.



Modifié par flober le 10/03/2015 01:54
novotek
 Posté le 10/03/2015 à 09:59 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

J'ai envoyé une demande de déplacer mon sujet vers le forum "securité"

flober
 Posté le 10/03/2015 à 10:01 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucienne
novotek a écrit :

J'ai envoyé une demande de déplacer mon sujet vers le forum "securité"

Re bonjour.

D'accord tu n'as plus qu'a attendre patiemment qu'un helper te prenne en charge.

Bonne journée.

flober.

novotek
 Posté le 10/03/2015 à 10:05 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

ok, j'attends. mersi

pcastuces
 Posté le 10/03/2015 à 14:20 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Equipe PC Astuces
Bonjour,

Le sujet a ÚtÚ dÚplacÚ par la modÚration dans le forum SÚcuritÚ qui semble plus adÚquat.

Vous pouvez continuer la discussion Ó la suite de ce message.

A bient¶t.
G225
 Posté le 10/03/2015 à 15:18 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Groupe Sécurité

Salut, faires les 3 scans de base de ma signature.

novotek
 Posté le 10/03/2015 à 16:58 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

Que-ce que je dois faire maintenant?

clbugnot
 Posté le 10/03/2015 à 17:32 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
  Grand Maître astucien

Bonjour novotek

Que-ce que je dois faire maintenant?

Ce que t'a demandé G225, c'est-à-dire cette procédure.

Cordialement.

novotek
 Posté le 10/03/2015 à 18:14 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

J'ai fait déjà hier l'analyse par ZHPDiag. vous avez vu le rapport. donc je dois repeter l'analyse par ZHPDiag? Malwarebyte me dit que mon ordi est propre.

flober
 Posté le 10/03/2015 à 19:04 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucienne

Bonsoir.

Suis cette procédure pour pouvoir être pris en charge par G 225.

La procédure en cliquant sur le lien ci-dessous

https://forum.pcastuces.com/aide_au_diagnostic_un_pc_infecte_pcastuces-f25s17490.htm

Je te laisse avec G225 qui t'attend.

bonne soirée.

G225
 Posté le 10/03/2015 à 19:47 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Groupe Sécurité

Vous avez plusieurs infections encore, si malwarebytes à été fait, faire AdwCleaner.

Si tout est fait me remettre le log ZHPdiag.



Modifié par G225 le 10/03/2015 19:48
novotek
 Posté le 10/03/2015 à 19:53 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien
G225
 Posté le 10/03/2015 à 20:50 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Groupe Sécurité

Ok comme vous voyez dans le premier il a découvert quelque chose donc supprimer. Continuer avec les autres.

novotek
 Posté le 10/03/2015 à 21:06 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

Le rapport d'AdwCleaner

http://cjoint.com/?3CkvrB4TbYE

flober
 Posté le 10/03/2015 à 21:09 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucienne

Re bonsoir.

Que se passe-t-il vous n’arrivez pas a mettre zhpdiag ?

Vous avez un problème,?

remettez le log ZHPdiag.

A vous lire.

novotek
 Posté le 10/03/2015 à 21:33 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

Le nouvel rapport de ZHPDiag

http://cjoint.com/?3CkvRUMYXiY

novotek
 Posté le 10/03/2015 à 22:15 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

Fichier joint : ZHPDiag.txt

novotek
 Posté le 10/03/2015 à 22:24 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

Pas de reponse?

novotek
 Posté le 10/03/2015 à 22:42 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Petit astucien

Pages : [1] 2 3 ... Fin
Page 1 sur 3 [Fin]

Vous devez être connecté pour participer à la discussion.
Cliquez ici pour vous identifier.

Vous n'avez pas de compte ? Créez-en un gratuitement !
Recevoir PC Astuces par e-mail


La Lettre quotidienne +226 000 inscrits
Avec l'actu, des logiciels, des applis, des astuces, des bons plans, ...

Les bonnes affaires
Une fois par semaine, un récap des meilleurs offres.

Les fonds d'écran
De jolies photos pour personnaliser votre bureau. Une fois par semaine.

Les nouveaux Bons Plans
Des notifications pour ne pas rater les bons plans publiés sur le site.

Les bons plans du moment PC Astuces

Tous les Bons Plans
Tondeuse à gazon sans fil Bosch CityMower 18 (18V, 1 batterie 4.0 Ah, 32 cm, 300 m²)
219,58 € 316,99 € -31%
@Amazon Allemagne
SSD Crucial P3 Plus 1 To (NVMe, PCIe, M.2, 5000 Mo/s)
56,66 € 75 € -24%
@Amazon Allemagne
Logitech G Saitek Pro Flight Yoke
120,99 € 160 € -24%
@Amazon
Batterie Bosch Professional 18V System 5Ah
62,01 € 72 € -14%
@Amazon Allemagne
Clavier sans-fil bluetooth Logitech MX Keys Plus + souris Logitech MX Master 3S (Azerty FR)
134,39 € 189,99 € -29%
@Amazon Allemagne
Carte mémoire microSDXC UHS-I SanDisk Ultra 512 Go
35,99 € 55 € -35%
@Amazon

Sujets relatifs
Explorateur windows qui cesse de fonctionner
Noouveaux documents apparaissant dans l'Explorateur Windows
Comment réparer l'Explorateur Windows
Explorateur windows qui se ferme
L'explorateur windows se bloque
Lenteur extrême de mon ordinateur de bureau windows xp familial
Changer de langue sur Windows 7 Home premium
Explorateur cesse de fonctionner (Windows 7)
explorateur windows
Explorateur windows se désactive
Plus de sujets relatifs à Windows 7 Familial Premium: explorateur windows
 > Tous les forums > Forum Sécurité