Petit astucien | bonsoir, A partir de hier je ne peux plus ouvrir ni poste de travail, ni panneau de configuration, ni les dossiers sur les disques dur, ni personnalisation. :( Mon ordi a été infecté par 500 viruses et troyanes qui sont venus hier. Maintenant il est propre. Hier j'ai nettoyé mon ordi completement. Et j'ai fait un scan de mon ordi après le rédemarrage. Mais explorateur windows ne s'ouvre plus. J'ai essayé de le recouperer par le fichier "explorer.exe" de mon CD-ROM Windows 7, mais ça ne change rien. Je ne sais pas quoi faire. Pourriez vous m'aider de marcher "explorer.exe" (explorateur windows)? J'ai voulu mettre ici les screenshots, mais je ne sais pas comment faire ça. Aidez moi s'il vous plait, resoudre mon probleme. Je suis débutant dans l'informatique. | ||||||||
Publicité | |||||||||
| |||||||||
Astucienne | Bienvenue sur PC Astuces. https://forum.pcastuces.com/aide_au_diagnostic_un_pc_infecte_pcastuces-f25s17490.htm @+ | ||||||||
Petit astucien | Bonsoir, j'ai fait la diagnostique par ZHPdiag, mais je n'ai pas trouvé ici l'option "inserer un rapport" :( comment je peux vous envoyer le rapport? J'ai fait le nettoyage de mon ordi hier par Microsoft Windows Essentiel et Malwarebyte Antimalware. Tout est propre. Que l'explorateur windows est completement endommagé et je ne peux plus le recuperer.
| ||||||||
Astucienne | tout en bas du rapport de ZHPdiag sélectionne le dernier paragraphe Copie/coller et transmet le moi. | ||||||||
Petit astucien | Je n'arrive pas ajouter le rapport ici, car la page de votre forum me dit ça: Request object error 'ASP 0104 : 80004005' Operation not Allowed /inc_haut.asp, line 46
il y a un autre moyen pour vous envoyer le rapport? | ||||||||
Astucienne | Sélectionne uniquement le dernier paragraphe a l'aide de la souris en passant dessus en pressant clic gauche puis dans ta nouvelle réponse colle la. @
Modifié par flober le 10/03/2015 01:40 | ||||||||
Petit astucien | par ici, ça va? ---\\ List all legacy services(LALS) (O64) O64 - Services: CurCS - 10.01.2011 - C:\Windows\System32\DRIVERS\AppleCharger.sys (AppleCharger) .(...) - LEGACY_APPLECHARGER O64 - Services: CurCS - 02.12.2012 - C:\Windows\System32\drivers\gfibto.sys (gfibto) .(.GFI Software - GFI Boot Time Operations Driver.) - LEGACY_GFIBTO O64 - Services: CurCS - 27.02.2014 - C:\Windows\system32\drivers\hcmon.sys (hcmon) .(.VMware, Inc. - VMware USB monitor.) - LEGACY_HCMON O64 - Services: CurCS - 07.03.2015 - C:\Windows\sysWOW64\drivers\HWiNFO64A.sys (HWiNFO32) .(.REALiX(tm) - HWiNFO AMD64 Kernel Driver.) - LEGACY_HWINFO32 O64 - Services: CurCS - 21.11.2014 - C:\Windows\system32\drivers\mbamchameleon.sys (mbamchameleon) .(.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) - LEGACY_MBAMCHAMELEON O64 - Services: CurCS - 21.11.2014 - C:\Windows\system32\drivers\mbam.sys (MBAMProtector) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMPROTECTOR O64 - Services: CurCS - 01.03.2013 - C:\Windows\System32\drivers\npf.sys (NPF) .(.Riverbed Technology, Inc. - npf.sys (NT5/6 AMD64) Kernel Driver.) - LEGACY_NPF O64 - Services: CurCS - 10.06.2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV O64 - Services: CurCS - 01.07.2010 - C:\Program Files\Unlocker\UnlockerDriver5.sys (UnlockerDriver5) .(...) - LEGACY_UNLOCKERDRIVER5 O64 - Services: CurCS - 19.12.2012 - C:\Users\GELO\Desktop\VirtualBox 4.2.6 82870 Portable\App\VirtualBox\drivers\USB\filter\VBoxUSBMon.sys (VBoxUSBMon) .(.Oracle Corporation - VirtualBox USB Monitor Driver.) - LEGACY_VBOXUSBMON O64 - Services: CurCS - 29.10.2014 - C:\Windows\System32\DRIVERS\vmnetbridge.sys (VMnetBridge) .(.VMware, Inc. - VMware bridge driver (64-bit).) - LEGACY_VMNETBRIDGE O64 - Services: CurCS - 29.10.2014 - C:\Windows\system32\drivers\vmnetuserif.sys (VMnetuserif) .(.VMware, Inc. - VMware network application interface driver.) - LEGACY_VMNETUSERIF O64 - Services: CurCS - 29.10.2014 - C:\Windows\system32\drivers\vmx86.sys (vmx86) .(.VMware, Inc. - VMware kernel driver.) - LEGACY_VMX86 O64 - Services: CurCS - 08.10.2013 - C:\Windows\System32\drivers\vsock.sys (vsock) .(.VMware, Inc. - VMware vSockets Service.) - LEGACY_VSOCK ~ Legacy: 94 Scanned in 00mn 08s
---\\ File Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> <OperaStable>[HKLM\..\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\Launcher.exe O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Not Key.) ~ FASS Keys: 11 Scanned in 00mn 00s
---\\ Start Menu Internet (SMI) (O68) O68 - StartMenuInternet: <Aviator> <Aviator>[HKLM\..\Shell\open\Command] (.Not Key.) O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Not Key.) O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Not Key.) O68 - StartMenuInternet: <k-meleon.exe> <K-Meleon>[HKLM\..\Shell\open\Command] (.Not Key.) O68 - StartMenuInternet: <Lunascape6> <Lunascape6>[HKLM\..\Shell\open\Command] (.Not Key.) O68 - StartMenuInternet: <Opera> <Opera>[HKLM\..\Shell\open\Command] (.Not Key.) O68 - StartMenuInternet: <OperaStable> <Opera Stable>[HKLM\..\Shell\open\Command] (.Not Key.) ~ Keys: Scanned in 00mn 00s
---\\ Search Browser Infection (SBI) (O69) O69 - SBI: prefs.js [GELO - blozzve3.default] user_pref("weboftrust.search.ask.display", "Ask.com Web Search"); O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} - (e) - http://rambler.ru O69 - SBI: SearchScopes [HKCU] {231CE532-7C50-418F-AAFC-B14AA5118BD8} - (Translate.Ru) - http://rambler.ru O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} [DefaultScope] - (Google) - http://www.google.com O69 - SBI: SearchScopes [HKUS\.DEFAULT] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKUS\S-1-5-18] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com ~ Keys: Scanned in 00mn 00s
---\\ Search Svchost Services (SSS) (O83) O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [236032] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [777728] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [859648] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [680960] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [99328] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [344064] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [64512] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [359424] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [316928] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [683520] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\system32\wuaueng.dll [2477536] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [849920] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [370688] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [569344] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [30720] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70144] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [156672] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [67584] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [219136] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [121856] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136704] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1110016] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [90624] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84480] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [210432] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [44544] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864] ~ Services: 32 Scanned in 00mn 00s
---\\ Search Particular Root Folder (SPRF) (O84) [MD5.6CD985C9E791C4D9F6441C9C360CA5BB] [SPRF][14.08.2013] (...) -- C:\ProgramData\fontcacheev1.dat [389] [MD5.F1D3FF8443297732862DF21DC4E57262] [SPRF][09.08.2014] (...) -- C:\Users\GELO\AppData\Roaming\wklnhst.dat [4] [MD5.72695F5E580D1F66F933C64323520093] [SPRF][09.03.2015] (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Users\GELO\Desktop\ZHPDiag2.exe [6877328] [MD5.CFE1AF5EE9CD57726695DC11941C0FB1] [SPRF][20.04.2011] (...) -- C:\Windows\Downloaded Program Files\WebInstallRunner.dll [43008] ~ Files: 4 Scanned in 00mn 00s
---\\ Firewall Active Exception List (FirewallRules) (O87) O87 - FAEL: "TCP Query User{684C0968-BAD5-4925-A14F-B447D7ABFC88}E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe" | In - Public - P6 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe =>P2P.BitTorrent O87 - FAEL: "UDP Query User{A1262EFB-21DF-4EF3-B28D-AFAC5BC49423}E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe" | In - Public - P17 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe =>P2P.BitTorrent ~ Firewall: 2 Scanned in 00mn 18s
---\\ Windows Installer Scan (WIS) (O93) (NTFS) [MD5.013946FEC4064E014774D39623AA7CE4] [WIS][16.10.2013] (.APN, LLC - Sopcast Toolbar.) -- C:\Windows\Installer\346d8a5.msi [523264] =>Toolbar.Ask ~ WIS: 1 Scanned in 00mn 06s
---\\ General States of Services not Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 09.02.2015 267440 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe SS - | Auto 22.07.1658 0 | (AdvancedSystemCareService8) . (...) - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ASCService.exe SS - | Demand 06.04.2010 31272 | (AppleChargerSrv) . (...) - C:\Windows\System32\AppleChargerSrv.exe SS - | Auto 22.07.1658 0 | (ASCAntivirusSrv) . (...) - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ascavsvc.exe SS - | Auto 20.10.2014 107912 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 20.10.2014 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 14.08.2012 194032 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe SS - | Auto 22.07.1658 0 | (HitmanProScheduler) . (...) - C:\Program Files\HitmanPro\hmpsched.exe SS - | Demand 14.11.2005 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe SS - | Demand 31.01.2014 887232 | (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe SS - | Auto 22.07.1658 0 | (LiveUpdateSvc) . (...) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe SS - | Auto 21.11.2014 969016 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe SS - | Demand 05.03.2015 148592 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe SS - | Demand 09.10.2006 724992 | (NBService) . (.Nero AG.) - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe SS - | Auto 08.04.2013 799280 | (PDF Architect Service) . (.pdfforge GmbH.) - C:\Program Files (x86)\PDF Architect\ConversionService.exe SS - | Demand 01.03.2013 118520 | (rpcapd) . (.Riverbed Technology, Inc..) - C:\Program Files (x86)\WinPcap\rpcapd.exe SS - | Demand 04.11.2008 68760 | (SandraAgentSrv) . (.SiSoftware.) - C:\Program Files\SiSoftware\SiSoftware Sandra Business 2013\RpcAgentSrv.exe SS - | Auto 02.01.2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe SS - | Demand 14.07.2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SS - | Demand 22.07.1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation SR - | Auto 14.05.2009 759048 | (ABBYY.Licensing.FineReader.Sprint.9.0) . (.ABBYY.) - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe SR - | Auto 15.12.2011 917640 | (AcuWVSSchedulerv8) . (...) - C:\Program Files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe SR - | Auto 03.12.2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe SR - | Auto 24.01.2012 21880 | (APC Data Service) . (.Schneider Electric.) - C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe SR - | Auto 24.01.2012 705912 | (APC UPS Service) . (.Schneider Electric.) - C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe SR - | Auto 12.02.2014 43336 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe SR - | Auto 30.08.2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe SR - | Auto 06.03.2015 315240 | (cmcore) . (.Kingsoft Corporation.) - c:\program files (x86)\cmcm\Clean Master\cmcore.exe SR - | Auto 21.02.2012 151648 | (EPSON_PM_RPCV4_04) . (.SEIKO EPSON CORPORATION.) - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.exe SR - | Auto 14.02.2014 579584 | (HauppaugeTVServer) . (.Hauppauge Computer Works.) - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe SR - | Auto 20.01.2014 2818896 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe SR - | Auto 21.11.2014 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe SR - | Auto 30.01.2015 23784 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe SR - | Auto 18.08.2009 7599616 | (MySQL) . (...) - C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe SR - | Auto 31.01.2013 878368 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe SR - | Auto 19.02.2013 1259296 | (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe SR - | Auto 08.04.2013 1320496 | (PDF Architect Helper Service) . (.pdfforge GmbH.) - C:\Program Files (x86)\PDF Architect\HelperService.exe SR - | Auto 17.01.2013 8704 | (RumoteVMCService) . (.Rumote.) - C:\Program Files (x86)\Rumote\RumoteVMC\RumoteMCEService.exe SR - | Auto 10.09.2012 193392 | (SCPDFReadSpool) . (.Solid Documents, LLC.) - C:\Program Files (x86)\SolidDocuments\Solid Converter PDF\SCPDF\SolidConverterPDFServicex64.exe SR - | Auto 28.03.2012 82944 | (SLService) . (...) - C:\Windows\System32\slmdmsr.exe SR - | Demand 20.12.2014 820960 | (SystemExplorerHelpService) . (.Mister Group.) - C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe SR - | Auto 29.10.2014 86744 | (VMAuthdService) . (.VMware, Inc..) - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe SR - | Auto 22.07.1658 0 | (VMnetDHCP) . (.VMware, Inc..) - C:\Windows\system32\vmnetdhcp.exe SR - | Auto 27.02.2014 906432 | (VMUSBArbService) . (.VMware, Inc..) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe SR - | Auto 22.07.1658 0 | (VMware NAT Service) . (.VMware, Inc..) - C:\Windows\system32\vmnat.exe SR - | Auto 14.07.2009 27136 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 08.09.2014 97280 | (_wfcs) . (.BiniSoft.org.) - C:\Program Files\Windows Firewall Control\wfcs.exe ~ Services: Scanned in 00mn 11s
---\\ Search Master Boot Record Infection (MBR)(O80) Run by GELO at 09.03.2015 22:49:13 ~ OS 64 not supported by MBR tool ~ MBR: 0 Scanned in 00mn 00s
---\\ Search Master Boot Record Infection (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by GELO at 09.03.2015 22:49:15 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 02s
---\\ Scan Additionnel (O88) Database Version : 13008 - (08.03.2015) Clés trouvées (Keys found) : 6 Valeurs trouvées (Values found) : 1 Dossiers trouvés (Folders found) : 5 Fichiers trouvés (Files found) : 6
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Applian FLV Player2.0.24] =>PUP.ApplianTechnologies^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Applian FLV and Media Player] =>PUP.ApplianTechnologies^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{53504356-3700-A76A-76A7-A758B70C0600}] =>Toolbar.Ask^ [HKLM\Software\Classes\Interface\{D6094FC6-821F-474C-8D73-C13066CD178D}] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Classes\Interface\{D6094FC6-821F-474C-8D73-C13066CD178D}] =>Toolbar.Agent [HKLM\Software\Classes\AppID\secman.DLL] =>PUP.Babylon C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\blozzve3.default\extensions\pavel.sherbakov@gmail.com =>PUP.QuickShare^ C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\extensions\pavel.sherbakov@gmail.com =>PUP.QuickShare^ C:\Program Files (x86)\Applian Technologies =>PUP.ApplianTechnologies^ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Applian Technologies =>PUP.ApplianTechnologies^ C:\Users\GELO\AppData\Roaming\Applian FLV and Media Player =>PUP.ApplianTechnologies^ C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rel.job =>Toolbar.AVGSearch^ C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rel =>Toolbar.AVGSearch^ C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rmv.job =>Toolbar.AVGSearch^ C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rmv =>Toolbar.AVGSearch^ [HKLM\Software\Wow6432Node\Applian Technologies] =>PUP.ApplianTechnologies^ C:\Windows\Installer\346d8a5.msi =>Toolbar.Ask^ ~ Additionnel Scan: 388926 Items scanned in 00mn 30s
---\\ Additional information about modules ~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5) ~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects (O2) ~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer toolbars (O3) ~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Auto loading programs from Registry and folders (O4) ~ AMI: 4 Scanned in 00mn 00s
---\\ Summary of the detections found on your workstation http://nicolascoolman.fr/pup-quickshare =>PUP.QuickShare http://www.nicolascoolman.fr/blog/ =>PUP.ApplianTechnologies http://nicolascoolman.fr/toolbar-ask =>Toolbar.Ask http://www.nicolascoolman.fr/blog/ =>PUP.CorsicaTechnologies http://www.nicolascoolman.fr/blog/ =>Toolbar.Agent http://nicolascoolman.fr/pup-babylon =>PUP.Babylon ~ MSI: 6 link(s) detected in 00mn 00s
End of the scan (2423 lines in 10mn 15s)(0.10) | ||||||||
Astucienne | re Le rapport montre que tu es infecté. Attends demain qu'un Helper te prenne en charge pour remettre tout en ordre. Il serait souhaitable que tu transfert ta demande dans le forum sécurité. bonne nuit.
Modifié par flober le 10/03/2015 01:54 | ||||||||
Petit astucien | ok, bonne nuit. à demain | ||||||||
Astucienne | Ton rapport est incomplet .Héberge le sur cjoint :) .pour demander ton transfert clique sur le panneau point d'exclamation jaune et dis que tu souhaites être transférer dans sécurité | ||||||||
Petit astucien | Bonjour, Malheureusement il n'y a pas de ça ici: "Insérer un rapport", je n'ai pas trouvé. Ici il y a ça Options : J'essaye faire comme ça, je partagerai sur quelque paragraph de ce rapport ici pour que vous pouvez le lire et me conseiller quoi faire avec mon ordi. ~ Report of ZHPDiag v2015.3.8.28 - Nicolas Coolman (08.03.2015) ~ Launched by GELO (09.03.2015 22:39:36) ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ Web forum address : http://forum.nicolascoolman.fr ~ Translated by ~ Version State : Updated version. ~ White List : Deactivate by user ~ Elevation of privilege : OK ~ User Account Control : Deactivate by program
---\\ Internet browsers MSIE: Internet Explorer v11.0.9600.17633 GCIE: Google Chrome v40.0.2214.115 (Defaut) OPIE: Opera v12.17 OPIE: Opera Stable v27.0.1689.76
---\\ Windows product information ~ Langage: Anglais Windows Server License Manager Script : OK ~ Windows Operating System - Windows(R) 7, OEM_COA_NSLP channel Windows ID Activation : OK ~ Windows Partial Key : 468V7 Windows License : OK ~ Windows Remaining Initializations Number : 3 Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)
---\\ System protection software Malwarebytes Anti-Malware, версия 2.0.4.1028 Microsoft Security Client RU-RU Language Pack v2.1.1116.0 Windows Defender W7 (Deactivate)
---\\ System optimization software
---\\ Sharing software PeerToPeer
---\\ Surveillance software Adobe Flash Player 16 NPAPI Adobe Reader 64-bit fixes Adobe Reader XI Java 7 Update 60 (64-bit)
---\\ Information on the system ~ Processor: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 8175 MB (46% free) System Restore: Activé (Enable) System drive C: has 270 GB (57%) free of 466 GB
---\\ Connection to the system mode ~ Computer Name: HENRI-PC ~ User Name: GELO ~ All Users Names: UpdatusUser, GELO, Administrateur, ~ Unselected Option: None Logged in as Administrator
---\\ Environment variables ~ System Unit : C:\ ~ %AppZHP% : C:\Users\GELO\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\GELO\AppData\Roaming\ ~ %Desktop% : C:\Users\GELO\Desktop\ ~ %Favorites% : C:\Users\GELO\Favorites\ ~ %LocalAppData% : C:\Users\GELO\AppData\Local\ ~ %StartMenu% : C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\
---\\ Enumeration of the disk units C: Hard drive, Flash drive, Thumb drive (Free 270 Go of 466 Go) D: CD-ROM drive (Not Inserted) E: Hard drive, Flash drive, Thumb drive (Free 1016 Go of 1397 Go)
---\\ State of the Windows Security Center [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ~ Security Center: 41 Scanned in 00mn 00s
---\\ Search Generic System Files [MD5.AC4C51EB24AA95B77F705AB159189E24] - (.Microsoft Corporation - Explorateur Windows.) (.21.11.2010 - 4:24:12.) -- C:\Windows\Explorer.exe [2872320] [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14.07.2009 - 2:39:52.) -- C:\Windows\System32\Wininit.exe [129024] [MD5.9DFE41A69DF70AAB75CB5BA8C1109EA2] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.12.01.2015 - 2:27:32.) -- C:\Windows\System32\wininet.dll [2358272] [MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.17.07.2014 - 3:07:24.) -- C:\Windows\System32\Winlogon.exe [455168] [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.21.11.2010 - 4:24:16.) -- C:\Windows\System32\sppcomapi.dll [232448] [MD5.FA886682CFC5D36718D3E436AACF10B9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30.05.2014 - 7:45:52.) -- C:\Windows\system32\Drivers\AFD.sys [497152] [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14.07.2009 - 2:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128] [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14.07.2009 - 0:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160] [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.21.11.2010 - 4:23:47.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456] [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.21.11.2010 - 4:24:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400] [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.21.11.2010 - 4:23:47.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368] [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14.07.2009 - 0:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472] [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14.07.2009 - 1:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224] [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27.04.2011 - 3:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208] [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.21.11.2010 - 4:23:51.) -- C:\Windows\system32\Drivers\netBT.sys [261632] [MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24.01.2014 - 3:37:55.) -- C:\Windows\system32\Drivers\ntfs.sys [1684928] [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14.07.2009 - 1:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280] [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.21.11.2010 - 4:24:33.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536] [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14.07.2009 - 1:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184] [MD5.70988118145F5F10EF24720B97F35F65] - (.Microsoft Corporation - TDI Translation Driver.) (.11.11.2014 - 2:46:26.) -- C:\Windows\system32\Drivers\tdx.sys [119296] [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.21.11.2010 - 4:23:47.) -- C:\Windows\system32\Drivers\volsnap.sys [295808] ~ Generic Processes: Scanned in 00mn 00s
---\\ Hidden files state (Hidden/Total) ~ Mes images (My Pictures) : 2/3327 ~ Mes musiques (My Musics) : 3/12379 ~ Mes Videos (My Videos) : 1/7 ~ Mes Favoris (My Favorites) : 1/418 ~ Mes Documents (My Documents) : 4/564 ~ Mon Bureau (My Desktop) : 1/396 ~ Menu demarrer (Programs) : 1/61 ~ Hidden Files: Scanned in 00mn 03s
---\\ Process running [MD5.06E0199BE4653D7FEDFB3612324FF084] - (.Innovative Solutions - Application Starter.) -- C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe [1065352] [PID.2332] [MD5.43A1E2ADF070C541290084D741B0310F] - (.Kingsoft Corporation - Clean Master.) -- c:\program files (x86)\cmcm\Clean Master\cmtray.exe [468328] [PID.2340] [MD5.5CB4C3C7A74E9436273261F74625B646] - (.PIMOne Software - PIMOne.) -- C:\Program Files (x86)\PIMOne\PIMOne.exe [2883584] [PID.5032] [MD5.AD12F815BE0348F1FD7FEBF720FA307C] - (.Team MediaPortal - IR Server.) -- C:\Program Files (x86)\IR Server Suite\IR Server.exe [341504] [PID.3868] [MD5.0A2BB12C84543B68E8E2E6E4235ADE58] - (.Team MediaPortal - IR Server Tray.) -- C:\Program Files (x86)\IR Server Suite\IR Server Tray.exe [426496] [PID.4032] [MD5.39AF1CDEAFA4FC9D5185FBD9F4D141C4] - (.Octoshape ApS - Main program for Octoshape client.) -- C:\Users\GELO\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [107800] [PID.4028] [MD5.7B6CB5C60E549B746FA8DEEE82C5BB53] - (...) -- C:\Users\GELO\AppData\Roaming\ACEStream\engine\ace_engine.exe [23984] [PID.528] [MD5.99C03F5D726A415253DBF09AFDA0A72E] - (.Samsung - Kies.) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe [1565504] [PID.1116] [MD5.43DFDE6570A948A178000348950B3546] - (...) -- C:\Users\GELO\AppData\Roaming\AceWebExtension\updater\ace_web_extension.exe [22824] [PID.4620] [MD5.D3AC38E80E928CC61A22650E04423BB8] - (.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [979328] [PID.5084] [MD5.36873F8B02A1F61DEC99D00E18E6C305] - (.Hauppauge Computer Works - IR.) -- C:\Program Files (x86)\WinTV\Ir.exe [118544] [PID.4212] [MD5.0D45E25843928A8CF67959F2A382742B] - (.Hauppauge Computer Works, Inc. - WinTVTray.) -- C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe [151552] [PID.2424] [MD5.7791897A9EC247982F8B6DFA0230E6E4] - (.No owner - MDAPI_Plus Host Application.) -- C:\Program Files (x86)\MDAPI_Plus\MDAPIHost.exe [243200] [PID.5072] [MD5.16AFB34618E1286FF856DC600AC49C79] - (.No owner - DivX Update.) -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968] [PID.4628] [MD5.60D2665C567B38C96E1216E9BC6F0253] - (.4t Niagara Software - 4t Tray Minimizer Free.) -- C:\Program Files (x86)\4t Tray Minimizer\4t-min.exe [1848832] [PID.4936] [MD5.7C557FD090347693F7FD5DBFEC444D02] - (.No owner - Process Killer.) -- C:\Program Files\Process Killer 1.4.2\prkiller.exe [38400] [PID.4596] [MD5.C32E458C8DDB46220C2D9C7807EC1A3F] - (.Schneider Electric - PowerChute System Tray Power Icon.) -- C:\Program Files (x86)\APC\PowerChute Personal Edition\apcsystray.exe [673144] [PID.3924] [MD5.6B7F08FC28191D99F6FDE92949C6628A] - (.Mister Group - System Explorer.) -- C:\Program Files (x86)\System Explorer\SystemExplorer.exe [3391200] [PID.2040] [MD5.53EBC5A93B96B8590BC7F02D7316A9EE] - (.Samsung Electronics Co., Ltd. - Kies TrayAgent Application.) -- C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616] [PID.1788] [MD5.A8C1BF646DD0168E81AFAA9662CCD843] - (...) -- C:\Users\GELO\AppData\Roaming\ACEStream\updater\ace_update.exe [22824] [PID.6032] [MD5.B9D6D7E6E5C4FCD8DD7F88EC9D563085] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592] [PID.6840] [MD5.0FDA13AB12896ABB885B2781DAA950E5] - (.ABBYY. - ABBYY ScreenshotReader.) -- C:\Program Files (x86)\ABBYY FineReader 11\Bonus.ScreenshotReader.exe [925960] [PID.6044] [MD5.6B7BE218304D5DCCCBFFAE29F31F5AE7] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8184832] [PID.7212] [MD5.E6D260721A9DF6A254FEDB7990FB5E77] - (.Kingsoft Corporation - Clean Master.) -- c:\program files (x86)\cmcm\Clean Master\cmcore.exe [315240] [PID.1264] [MD5.B33CF4DE909A5B30F526D82053A63C8E] - (.ABBYY - ABBYY network license server.) -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048] [PID.1860] [MD5.8A27975A7BD3EA10E7F22553558F3A74] - (...) -- C:\Program Files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe [917640] [PID.1940] [MD5.4C72FDD915D62EAEF149BD9C73AB9CF4] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [81088] [PID.1180] [MD5.C7F8C8080B055B3DE9A8141DFD8E308A] - (.Schneider Electric - Battery Backup Management Service.) -- C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe [705912] [PID.1592] [MD5.221564CC7BE37611FE15EACF443E1BF6] - (.Apple Inc. - YSLoader.exe.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [43336] [PID.1736] [MD5.2EC3AFFE3AC7776AE9DA4028D370593F] - (.Hauppauge Computer Works - Hauppauge TV Server.) -- C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe [579584] [PID.2152] [MD5.0BB29DE40C9D9529793DCDB59A43CF5B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160] [PID.2616] [MD5.9972EDE411AA4D1FFF3341DC8819A5A4] - (.Hauppauge Computer Works - Capture plugin for the USB devices.) -- C:\Program Files (x86)\WinTV\TVServer\CaptureGenUSB.exe [405504] [PID.2824] [MD5.20372BE109FEE1C37E2D5216680DB9EB] - (.pdfforge GmbH - PDF Architect Helper Service.) -- C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496] [PID.2408] [MD5.295010C3EDECCAF760853544D0C92C03] - (.VMware, Inc. - VMware NAT Service.) -- C:\Windows\SysWOW64\vmnat.exe [437976] [PID.2548] [MD5.107AB19CC1D40B9D04537F6EEAAC34C9] - (.Schneider Electric - PowerChute Data Service.) -- C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe [21880] [PID.3296] [MD5.1AA9C2331234786211A261C8FC69EB25] - (.VMware, Inc. - VMware Authorization Service.) -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe [86744] [PID.3344] [MD5.7EEBDDF76D013181E21592D2FFD66A98] - (.VMware, Inc. - VMware VMnet DHCP service.) -- C:\Windows\SysWOW64\vmnetdhcp.exe [359128] [PID.3416] [MD5.A3A25E0509F67473B960DAF214828BE3] - (.NVIDIA Corporation - NVIDIA Settings Update Manager.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [1259296] [PID.5740] ~ Processes Running: Scanned in 00mn 00s
---\\ Opera, Plugins,Start,Search (P1,B0,B1) B0 - SPO: operaprefs.ini [GELO] Home URL=http://www.rambler.ru/ B1 - OSP: search.ini [GELO] URL=http://www.bing.com/search?q=%s&form=OPRTSD&pc=OPER B1 - OSP: search.ini [GELO] URL=http://redir.opera.com/amazon B1 - OSP: search.ini [GELO] URL=http://redir.opera.com/ebay =>Toolbar.eBay B1 - OSP: search.ini [GELO] URL=http://fr.wikipedia.org/wiki/Special:Search?search=%s P1 - OPN:Opera Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files (x86)\Opera\Program\Plugins\NPOFF12.DLL P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin.dll P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin2.dll P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin3.dll P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin4.dll P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin5.dll P1 - OPN:Opera Plugin Navigator . (...) -- C:\Program Files (x86)\Opera\Program\Plugins\NPSWF32.dll P1 - OPN:Opera Plugin Navigator . (.Adobe Systems, Inc. - Adobe Flash Player Helper 10.0 r45.) -- C:\Program Files (x86)\Opera\Program\Plugins\NPSWF32_FlashUtil.exe =>.Adobe Systems Incorporated P1 - OPN:Opera Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files (x86)\Opera\Program\Plugins\NPOFF12.DLL P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin.dll P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin2.dll P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin3.dll P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin4.dll P1 - OPN:Opera Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Opera\Program\Plugins\npqtplugin5.dll P1 - OPN:Opera Plugin Navigator . (...) -- C:\Program Files (x86)\Opera\Program\Plugins\NPSWF32.dll P1 - OPN:Opera Plugin Navigator . (.Adobe Systems, Inc. - Adobe Flash Player Helper 10.0 r45.) -- C:\Program Files (x86)\Opera\Program\Plugins\NPSWF32_FlashUtil.exe =>.Adobe Systems Incorporated ~ Opera Browser: 21 Scanned in 00mn 00s
---\\ Google Chrome, Start,Search,Extensions (G0,G1,G2) C:\Users\GELO\AppData\Local\Google\Chrome\User Data\Default\Preferences
---\\ Google Chrome Extension Folder ~ Google Lines Browser: 0 Scanned in 00mn 00s
---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (P2,M0,M1,M2,M3) C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\blozzve3.default\prefs.js C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\prefs.js M3 - MFPP: Plugins - [GELO] -- C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\searchplugins\ebook-.xml M3 - MFPP: Plugins - [GELO] -- C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\searchplugins\googletranslate.xml M3 - MFPP: Plugins - [GELO] -- C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\searchplugins\only-pdf.xml M3 - MFPP: Plugins - [GELO] -- C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\searchplugins\pdf-ebook-searches.xml M3 - MFPP: Plugins - [GELO] -- C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\searchplugins\pdf-search.xml M3 - MFPP: Plugins - [GELO] -- C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\searchplugins\translateru.xml M2 - MFEP: prefs.js [GELO - blozzve3.default\clickclean@hotcleaner.com] [] Click&Clean v4.1 (..) M2 - MFEP: prefs.js [GELO - blozzve3.default\donottrackplus@abine.com] [] Blur (Formerly DoNotTrackMe) v4.5.1334 (..) M2 - MFEP: prefs.js [GELO - blozzve3.default\idme@abine.com] [] MaskMe v1.40.366 (..) M2 - MFEP: prefs.js [GELO - blozzve3.default\iobitascsurfingprotection@iobit.com] [] Advanced SystemCare Surfing Protection v2.0 (..) M2 - MFEP: prefs.js [GELO - blozzve3.default\magicplayer@acestream.org] [] AS Magic Player v1.1.42 (..) M2 - MFEP: prefs.js [GELO - blozzve3.default\pavel.sherbakov@gmail.com] [] Speed Dial [FVD] - New Tab Page, Sync... v1.1.42 (..) =>PUP.QuickShare M2 - MFEP: prefs.js [GELO - blozzve3.default\printPages2Pdf@reinhold.ripper] [] Print pages to PDF v0.1.9.3 (..) M2 - MFEP: prefs.js [GELO - blozzve3.default\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}] [WOT] WOT v20131118 (..) M2 - MFEP: prefs.js [GELO - blozzve3.default\{dd3d7613-0246-469d-bc65-2a3cc1668adc}] [] Block site v1.1.8 (..) M2 - MFEP: Extension [GELO - blozzve3.default] {0e10f3d7-07f6-4f12-97b9-9b27e07139a5}.xpi M2 - MFEP: Extension [GELO - blozzve3.default] {146f1820-2b0d-49ef-acbf-d85a6986e10c}.xpi M2 - MFEP: Extension [GELO - blozzve3.default] {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi M2 - MFEP: Extension [GELO - blozzve3.default] {73a6fe31-595d-460b-a920-fcc0f8843232}.xpi M2 - MFEP: Extension [GELO - blozzve3.default] {9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi M2 - MFEP: Extension [GELO - blozzve3.default] {ab4b5718-3998-4a2c-91ae-18a7c2db513e}.xpi M2 - MFEP: Extension [GELO - blozzve3.default] {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Adblock Plus Extension Mozilla Firefox M2 - MFEP: Extension [GELO - blozzve3.default] {ea61041c-1e22-4400-99a0-aea461e69d04}.xpi M2 - MFEP: Extension [GELO - blozzve3.default] {fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi M2 - MFEP: Extension [GELO - blozzve3.default] {02450914-cdd9-410f-b1da-db004e18c671}.xpi M2 - MFEP: Extension [GELO - blozzve3.default] {1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi M2 - MFEP: Extension [GELO - blozzve3.default] {27c60876-b5c9-4335-b4f3-52b26782220c}.xpi M2 - MFEP: Extension [GELO - blozzve3.default] {cd617375-6743-4ee8-bac4-fbf10f35729e}.xpi M2 - MFEP: Extension [GELO - blozzve3.default] {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi M2 - MFEP: prefs.js [GELO - fi77grgz.dev-edition-default\donottrackplus@abine.com] [] Blur (Formerly DoNotTrackMe) v4.5.1334 (..) M2 - MFEP: prefs.js [GELO - fi77grgz.dev-edition-default\idme@abine.com] [] MaskMe v1.40.366 (..) M2 - MFEP: prefs.js [GELO - fi77grgz.dev-edition-default\iobitascsurfingprotection@iobit.com] [] Advanced SystemCare Surfing Protection v2.0 (..) M2 - MFEP: prefs.js [GELO - fi77grgz.dev-edition-default\pavel.sherbakov@gmail.com] [] Speed Dial [FVD] - New Tab Page, Sync... v1.1.2 (..) =>PUP.QuickShare M2 - MFEP: prefs.js [GELO - fi77grgz.dev-edition-default\printPages2Pdf@reinhold.ripper] [] Print pages to PDF v0.1.9.3 (..) M2 - MFEP: prefs.js [GELO - fi77grgz.dev-edition-default\{6d43fee4-72e7-4290-b75a-b898e4f4676d}] [] BlockSite Plus v1.1 (..) M2 - MFEP: prefs.js [GELO - fi77grgz.dev-edition-default\{dd3d7613-0246-469d-bc65-2a3cc1668adc}] [] Block site v1.1.8 (..) M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {0e10f3d7-07f6-4f12-97b9-9b27e07139a5}.xpi M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {146f1820-2b0d-49ef-acbf-d85a6986e10c}.xpi M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {73a6fe31-595d-460b-a920-fcc0f8843232}.xpi M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {ab4b5718-3998-4a2c-91ae-18a7c2db513e}.xpi M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Adblock Plus Extension Mozilla Firefox M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {ea61041c-1e22-4400-99a0-aea461e69d04}.xpi M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {02450914-cdd9-410f-b1da-db004e18c671}.xpi M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {27c60876-b5c9-4335-b4f3-52b26782220c}.xpi M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {cd617375-6743-4ee8-bac4-fbf10f35729e}.xpi M2 - MFEP: Extension [GELO - fi77grgz.dev-edition-default] {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - np-mswmp.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\np-mswmp.dll P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.10.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\nppdf32.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin2.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin3.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin4.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin5.dll P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll P2 - FPN: [HKLM] [@java.com/DTPlugin,version=11.25.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=11.25.2] - (.Oracle Corporation - Next Generation Java Plug-in 11.25.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.0.4] - (...) -- C:\Program Files\VideoLAN\VLC\npvlc.dll (.not file.) P2 - FPN: [HKCU] [@acestream.net/acestreamplugin,version=3.0.2] - (.Innovative Digital Technologies - ACE Stream Plug-in Version 2.2.5.1-next, Copyright (c) 2012-2014 Innov.) -- C:\Users\GELO\AppData\Roaming\ACEStream\player\npace_plugin.dll P2 - FPN: [HKCU] [@octoshape.com/Octoshape Streaming Services,version=1.0] - (.Octoshape ApS - Octoshape embedded video plugin.) -- C:\Users\GELO\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1401100-0-npoctoshape.dll P2 - FPN: [HKCU] [@Skype Limited.com/Facebook Video Calling Plugin] - (.Skype Limited - Facebook Video Calling Plugin.) -- C:\Users\GELO\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll P2 - FPN: [HKCU] [@talk.google.com/GoogleTalkPlugin] - (.Google - Version 5.40.2.0.) -- C:\Users\GELO\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll P2 - FPN: [HKCU] [@talk.google.com/O1DPlugin] - (.Google - Version 5.40.2.0.) -- C:\Users\GELO\AppData\Roaming\Mozilla\plugins\npo1d.dll P2 - FPN: [HKCU] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Users\GELO\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll P2 - FPN: [HKCU] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Users\GELO\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll ~ Firefox Browser: 88 Scanned in 00mn 00s
---\\ Internet Explorer Extensions, Start, Search (R4,R3,R0,R1) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://rambler.ru R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://rambler.ru R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://rambler.ru R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://encrypted.google.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rambler.ru R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://encrypted.google.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = preserve R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://encrypted.google.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://encrypted.google.com R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://encrypted.google.com R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rambler.ru R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://encrypted.google.com R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.9600.17631 (winblue_r7.150111-1500)) -- C:\Windows\SysWOW64\ieframe.dll R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1 ~ IE Browser: 21 Scanned in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s
---\\ Line Analysis F0, F1, F2, F3 - IniFiles, Auto loading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1) O1 - Hosts: 94.242.221.196 ok.ru O1 - Hosts: 94.242.221.196 m.ok.ru ~ Nombre lignes détournées 2/35 (Hosts file redirected) ~ Hosts File: Scanned in 00mn 00s
---\\ Browser Helper Objects (O2) O2 - BHO: Ghostery BHO [64Bits] - {237EB6DA-3FEA-4DD2-8A61-A901B5C489D7} . (...) -- C:\Program Files (x86)\GhosteryIEplugin\GhosteryBrowserHelperObject.dll O2 - BHO: PDF Architect Helper [64Bits] - {3A2D5EBA-F86D-4BD3-A177-019765996711} . (.pdfforge GmbH - PDF Architect Helper.) -- C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll O2 - BHO: Sopcast Toolbar BHO [64Bits] - {53504356-3700-A76A-76A7-7A786E7484D7} Orphan key O2 - BHO: Groove GFS Browser Helper [64Bits] - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Спутник@Mail.Ru [64Bits] - {8984B388-A5BB-4DF7-B274-77B879E179DB} Orphan key O2 - BHO: Programme d’aide de l’Assistant de connexion au compte Microsoft [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper [64Bits] - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: WOT Helper [64Bits] - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} . (...) -- C:\Program Files (x86)\WOT\WOT.dll O2 - BHO: CutePDF Form Filler [64Bits] - {D41289F2-69C6-417B-897E-C653D677CBAF} . (.Acro Software Inc. - CutePDF Filler Helper.) -- C:\Program Files (x86)\Acro Software\CutePDF Pro\CPFillerCo.dll O2 - BHO: Adblock Plus for IE Browser Helper Object [64Bits] - {FFCB3198-32F3-4E8B-9539-4324694ED664} . (.Eyeo GmbH - Adblock Plus BHO for Internet Explorer.) -- C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll O2 - BHO: ExplorerWnd Helper [64Bits] - {10921475-03CE-4E04-90CE-E2E7EF20C814} Orphan key O2 - BHO: Sopcast Toolbar [64Bits] - {53504356-3700-A76A-76A7-7A786E7484D7} Orphan key O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} Orphan key O2 - BHO: (no name) [64Bits] - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} Orphan key O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} Orphan key O2 - BHO: TabExplorerHelper [64Bits] - {F8A6CAA2-533D-4AED-9E05-8EB19A4021AB} Orphan key ~ BHO: 20 Scanned in 00mn 01s
---\\ Internet Explorer toolbars (O3) O3 - Toolbar: Easy Photo Print - [HKLM]{9421DD08-935F-4701-A9CA-22DF90AC4EA6} . (.SEIKO EPSON CORPORATION / CyCom Technology - Epson Easy Photo Print (TBL x64).) -- C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll O3 - Toolbar: Sopcast Toolbar - [HKLM]{53504356-3700-A76A-76A7-7A786E7484D7} . (...) -- (.not file.) O3 - Toolbar: WOT - [HKLM]{71576546-354D-41c9-AAE8-31F2EC22BF0D} . (...) -- C:\Program Files\WOT\WOT.dll O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll O3 - Toolbar\WebBrowser: (no name) - [HKCU]{6AA40521-14E7-4B1D-B1B4-98528C1388C9} Orphan key O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2B171655-A70C-5C18-B693-6CB5DC269D41} Orphan key O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Orphan key O3 - Toolbar\WebBrowser: (no name) - [HKCU]{71576546-354D-41C9-AAE8-31F2EC22BF0D} Orphan key ~ Toolbar: Scanned in 00mn 00s
---\\ Other User Links (O4) O4 - GS\Program [GELO]: Applian FLV Player.lnk . (...) -- C:\Program Files (x86)\FLV Player\FLVPlayer.exe (.not file.) =>PUP.ApplianTechnologies ~ Global Startup: 1 Scanned in 00mn 09s
---\\ Auto loading programs from Registry and folders (O4) O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- C:\Program Files\Microsoft Security Client\msseces.exe O4 - HKLM\..\Run: [Windows Firewall Control] . (.Alexandru Dicu - Windows Firewall Control.) -- C:\Windows\SysWOW64\wfc.exe O4 - HKLM\..\Run: [Fences] . (.Stardock Corporation - Fences Settings.) -- C:\Program Files (x86)\Stardock\Fences\Fences.exe O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\GELO\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc O4 - HKCU\..\Run: [PIMOne] . (.PIMOne Software - PIMOne.) -- C:\Program Files (x86)\PIMOne\PIMOne.exe O4 - HKCU\..\Run: [Allmyapps] C:\Users\GELO\AppData\Roaming\Allmyapps\Allmyapps.exe (.not file.) O4 - HKCU\..\Run: [Allmyapps Update] C:\Users\GELO\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe (.not file.) O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - Chargeur CTF.) -- C:\Windows\system32\ctfmon.exe O4 - HKCU\..\Run: [IR Server] . (.Team MediaPortal - IR Server.) -- C:\Program Files (x86)\IR Server Suite\IR Server.exe O4 - HKCU\..\Run: [IR Server Tray] . (.Team MediaPortal - IR Server Tray.) -- C:\Program Files (x86)\IR Server Suite\IR Server Tray.exe O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\GELO\AppData\Local\Facebook\Update\FacebookUpdate.exe O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHLE.exe =>.Epson Seiko Corporation O4 - HKCU\..\Run: [Octoshape Streaming Services] . (.Octoshape ApS - Main program for Octoshape client.) -- C:\Users\GELO\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe O4 - HKCU\..\Run: [AceStream] . (...) -- C:\Users\GELO\AppData\Roaming\ACEStream\engine\ace_engine.exe O4 - HKCU\..\Run: [KiesPreload] . (.Samsung - Kies.) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe O4 - HKCU\..\Run: [AceWebException] . (...) -- C:\Users\GELO\AppData\Roaming\AceWebExtension\updater\ace_web_extension.exe O4 - HKCU\..\Run: [Geotag Security] . (.No owner - Geotag Security.) -- C:\Program Files (x86)\Geotag Security\GeotagSecurity.exe O4 - HKCU\..\RunOnce: [Adobe Speed Launcher] 1425935106 O4 - HKLM\..\Wow6432Node\Run: [EEventManager] . (.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe O4 - HKLM\..\Wow6432Node\Run: [DivXMediaServer] . (.DivX, LLC - DivX Media Server Launcher.) -- C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated O4 - HKLM\..\Wow6432Node\Run: [Display] . (.Schneider Electric - Startup Notification Module.) -- C:\Program Files (x86)\APC\PowerChute Personal Edition\DataCollectionLauncher.exe O4 - HKLM\..\Wow6432Node\Run: [MDAPI_Plus] . (.No owner - MDAPI_Plus Host Application.) -- C:\Program Files (x86)\MDAPI_Plus\MDAPIHost.exe O4 - HKLM\..\Wow6432Node\Run: [WsmUpdater] . (.Web Solution Mart - Updater.) -- C:\Program Files (x86)\Web Solution Mart\Fake Webcam Codecs Pack\Updater.exe O4 - HKLM\..\Wow6432Node\Run: [DivXUpdate] . (.No owner - DivX Update.) -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe O4 - HKLM\..\Wow6432Node\Run: [SystemExplorerAutoStart] . (.Mister Group - System Explorer.) -- C:\Program Files (x86)\System Explorer\SystemExplorer.exe O4 - HKLM\..\Wow6432Node\Run: [KiesTrayAgent] . (.Samsung Electronics Co., Ltd. - Kies TrayAgent Application.) -- C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe =>.Samsung Electronics Co O4 - HKLM\..\Wow6432Node\Run: [cmsc] . (.Kingsoft Corporation - Clean Master.) -- c:\program files (x86)\cmcm\Clean Master\cmtray.exe O4 - HKLM\..\Wow6432Node\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll] C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (.not file.) O4 - HKUS\.DEFAULT\..\Run: [Adguard] C:\Program Files (x86)\Adguard\Adguard.exe (.not file.) O4 - HKUS\S-1-5-18\..\Run: [Adguard] C:\Program Files (x86)\Adguard\Adguard.exe (.not file.) O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\GELO\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [PIMOne] . (.PIMOne Software - PIMOne.) -- C:\Program Files (x86)\PIMOne\PIMOne.exe O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [Allmyapps] C:\Users\GELO\AppData\Roaming\Allmyapps\Allmyapps.exe (.not file.) O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [Allmyapps Update] C:\Users\GELO\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe (.not file.) O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [ctfmon.exe] . (.Microsoft Corporation - Chargeur CTF.) -- C:\Windows\system32\ctfmon.exe O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [IR Server] . (.Team MediaPortal - IR Server.) -- C:\Program Files (x86)\IR Server Suite\IR Server.exe O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [IR Server Tray] . (.Team MediaPortal - IR Server Tray.) -- C:\Program Files (x86)\IR Server Suite\IR Server Tray.exe O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\GELO\AppData\Local\Facebook\Update\FacebookUpdate.exe O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHLE.exe =>.Epson Seiko Corporation O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [Octoshape Streaming Services] . (.Octoshape ApS - Main program for Octoshape client.) -- C:\Users\GELO\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [AceStream] . (...) -- C:\Users\GELO\AppData\Roaming\ACEStream\engine\ace_engine.exe O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [KiesPreload] . (.Samsung - Kies.) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [AceWebException] . (...) -- C:\Users\GELO\AppData\Roaming\AceWebExtension\updater\ace_web_extension.exe O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\Run: [Geotag Security] . (.No owner - Geotag Security.) -- C:\Program Files (x86)\Geotag Security\GeotagSecurity.exe O4 - HKUS\S-1-5-21-3147391334-965059008-3150008735-1000\..\RunOnce: [Adobe Speed Launcher] 1425935106 ~ Application: Scanned in 00mn 00s | ||||||||
Petit astucien | ---\\ IE Options icon not visible in Control Panel (O5) O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no ~ IE Control Panel: 1 Scanned in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll O10 - WLSP:\000000000007\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files (x86)\Bonjour\mdnsNSP.dll O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation O10 - WLSP:\000000000009\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation ~ Winsock: 9 Scanned in 00mn 00s
---\\ Site in Trusted Zone (O15) O15 - Trusted Zone: [HKCU\...\Domains\www] http.parom.tv ~ IE Zone Confiance: Scanned in 00mn 00s
---\\ Lop.com/Domain Hijackers (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{CF459770-6FDC-42AC-8D87-9F477126D016}: DhcpNameServer = 89.2.0.1 89.2.0.2 O17 - HKLM\System\CS1\Services\Tcpip\..\{CF459770-6FDC-42AC-8D87-9F477126D016}: DhcpNameServer = 89.2.0.1 89.2.0.2 O17 - HKLM\System\CS2\Services\Tcpip\..\{CF459770-6FDC-42AC-8D87-9F477126D016}: DhcpNameServer = 89.2.0.1 89.2.0.2 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.2.0.1 89.2.0.2 ~ Domain: Scanned in 00mn 00s
---\\ Extra protocols (O18) O18 - Handler: wot [64Bits] - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} . (...) -- C:\Program Files\WOT\WOT.dll O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn 00s
---\\ ShellServiceObjectDelayLoad (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. ~ SSODL: 1 Scanned in 00mn 00s
---\\ SharedTaskScheduler (O22) O22 - SharedTaskScheduler: (no name) [64Bits] - {73526E5A-FD53-4BE7-B5E2-D3C89D7413DC} - (.not file.) O22 - SharedTaskScheduler: (no name) [64Bits] - {E31004D1-A431-41B8-826F-E902F9D95C81} . (.Microsoft Corporation - Microsoft Windows 7 Ultimate Extra: Windows.) -- C:\Windows\SysWow64\DreamScene.dll O22 - SharedTaskScheduler: (no name) [64Bits] - {1984DD45-52CF-49cd-AB77-18F378FEA264} - (.not file.) ~ STS/SSO: Scanned in 00mn 00s
---\\ Non Microsoft non disabled Windows XP/NT/2000 Services (O23) O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) . (.ABBYY - ABBYY network license server.) - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe O23 - Service: Acunetix WVS Scheduler v8 (AcuWVSSchedulerv8) . (...) - C:\Program Files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Advanced SystemCare Service 8 (AdvancedSystemCareService8) . (...) - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ASCService.exe (.not file.) O23 - Service: APC Data Service (APC Data Service) . (.Schneider Electric - PowerChute Data Service.) - C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe O23 - Service: APC UPS Service (APC UPS Service) . (.Schneider Electric - Battery Backup Management Service.) - C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - YSLoader.exe.) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: AdvancedSystemCareAntivirus (ASCAntivirusSrv) . (...) - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ascavsvc.exe (.not file.) O23 - Service: Служба Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Clean Master Core Service (cmcore) . (.Kingsoft Corporation - Clean Master.) - c:\program files (x86)\cmcm\Clean Master\cmcore.exe O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.exe =>.Epson Seiko Corporation O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc O23 - Service: HauppaugeTVServer (HauppaugeTVServer) . (.Hauppauge Computer Works - Hauppauge TV Server.) - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe O23 - Service: HitmanPro Scheduler (HitmanProScheduler) . (...) - C:\Program Files\HitmanPro\hmpsched.exe (.not file.) O23 - Service: LiveUpdate (LiveUpdateSvc) . (...) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (.not file.) O23 - Service: Ma-Config Agent (MaConfigAgent) . (.CybelSoft - Service de détection matériel.) - C:\Program Files\ma-config.com\MaConfigAgent.exe O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: MySQL (MySQL) . (...) - C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 307.8.) - C:\Windows\system32\nvvsvc.exe O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) . (.NVIDIA Corporation - NVIDIA Settings Update Manager.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: PDF Architect Helper Service (PDF Architect Helper Service) . (.pdfforge GmbH - PDF Architect Helper Service.) - C:\Program Files (x86)\PDF Architect\HelperService.exe O23 - Service: PDF Architect Service (PDF Architect Service) . (.pdfforge GmbH - PDF Architect Conversion Service.) - C:\Program Files (x86)\PDF Architect\ConversionService.exe O23 - Service: RumoteVMC Service (RumoteVMCService) . (.Rumote - RumoteMCEService.) - C:\Program Files (x86)\Rumote\RumoteVMC\RumoteMCEService.exe O23 - Service: SolidConverterPDFReadSpool (SCPDFReadSpool) . (.Solid Documents, LLC - Solid Spool Service.) - C:\Program Files (x86)\SolidDocuments\Solid Converter PDF\SCPDF\SolidConverterPDFServicex64.exe O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: VMware Authorization Service (VMAuthdService) . (.VMware, Inc. - VMware Authorization Service.) - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) . (.VMware, Inc. - VMware VMnet DHCP service.) - C:\Windows\SysWOW64\vmnetdhcp.exe O23 - Service: VMware USB Arbitration Service (VMUSBArbService) . (.VMware, Inc. - VMware USB Arbitration Service.) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe O23 - Service: VMware NAT Service (VMware NAT Service) . (.VMware, Inc. - VMware NAT Service.) - C:\Windows\SysWOW64\vmnat.exe O23 - Service: Windows Firewall Control (_wfcs) . (.BiniSoft.org - Windows Firewall Control Service.) - C:\Program Files\Windows Firewall Control\wfcs.exe ~ Services: 27 Scanned in 00mn 04s
---\\ Windows Active Desktop & MHTML Editor (O24) O24 - Default MHTML Editor: Last - .(...) - (.not file.) ~ Desktop Component: 4 Scanned in 00mn 00s
---\\ BootExecute (BEX) (O34) O34 - HKLM BootExecute: (autocheck autochk *) - File not found O34 - HKLM BootExecute: (pS) - File not found ~ BEX: 2 Scanned in 00mn 00s
---\\ Task Planned Automatically (039) [MD5.00000000000000000000000000000000] [APT] [Ad-Aware Antivirus Scheduled Scan] (...) -- C:\Program Files (x86)\AD-AWA~1\AdAwareLauncher.exe (.not file.) [0] [MD5.080255CDCB878813B481B8C348D47D8E] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [267440] [MD5.00000000000000000000000000000000] [APT] [AllmyappsUpdateTask] (...) -- C:\Users\GELO\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe (.not file.) [0] [MD5.06E0199BE4653D7FEDFB3612324FF084] [APT] [Application Starter - f1375f225883e83d52e8db9690775c3c] (.Innovative Solutions.) -- C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe [1065352] [MD5.00000000000000000000000000000000] [APT] [ASCU8_PerformanceMonitor] (...) -- C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\Monitor.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [ASCU8_SkipUac_GELO] (...) -- C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ASC.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [AVG-Secure-Search-Update_0214b_rel] (...) -- C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe (.not file.) [0] =>Toolbar.AVGSearch [MD5.00000000000000000000000000000000] [APT] [AVG-Secure-Search-Update_0214b_rmv] (...) -- C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe (.not file.) [0] =>Toolbar.AVGSearch [MD5.00000000000000000000000000000000] [APT] [AviatorUpdateTask] (...) -- C:\Program Files (x86)\WhiteHat\Aviator\Update\BatchLauncher.vbs" "C:\Program Files (x86)\WhiteHat\Aviator\Update\AviatorAutoUpdate.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [Driver Booster Scan] (...) -- C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [Driver Booster SkipUAC (GELO)] (...) -- C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [Driver Booster Update] (...) -- C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe (.not file.) [0] [MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core] (.Facebook Inc..) -- C:\Users\GELO\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA] (.Facebook Inc..) -- C:\Users\GELO\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912] [MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912] [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core] (.Google Inc..) -- C:\Users\GELO\AppData\Local\Google\Update\GoogleUpdate.exe [116648] [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA] (.Google Inc..) -- C:\Users\GELO\AppData\Local\Google\Update\GoogleUpdate.exe [116648] [MD5.9E6DA841450754056E419FC2055509BF] [APT] [Opera scheduled Autoupdate 1376993084] (.Opera Software.) -- C:\Program Files (x86)\Opera\launcher.exe [487544] [MD5.00000000000000000000000000000000] [APT] [RealUpgradeLogonTaskS-1-5-21-3147391334-965059008-3150008735-1000] (...) -- C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [RealUpgradeScheduledTaskS-1-5-21-3147391334-965059008-3150008735-1000] (...) -- C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [Uninstaller_SkipUac_GELO] (...) -- C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{0216C314-D397-45E4-95FC-DA5594765496}] (...) -- C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\SetupTv.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{179F9451-8A8A-4436-9B06-348CE593A318}] (...) -- D:\UNINSTAL.exe (.not file.) [0] [MD5.604A6F3CB699983E73880B3E91B38B5E] [APT] [{792D849D-B980-4817-8E4F-26A71359355F}] (...) -- C:\Program Files (x86)\K!TV\UninstKTV.exe [4229955] [MD5.00000000000000000000000000000000] [APT] [{ABBC8076-9041-4B14-8B8B-139F0E4DDC84}] (...) -- D:\INSTALL.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{AFFEB6F3-57E6-4CB9-B51A-7B92475A2D85}] (...) -- D:\INSTALL.exe (.not file.) [0] [MD5.D41D8CD98F00B204E9800998ECF8427E] [APT] [{B8DC7294-44CD-4C81-BC05-4A5162480BC6}] (...) -- C:\Program Files (x86)\QuickTime\QTSystem\QuickTime.cpl" [1511424] [MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [561984] O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002] O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002] O39 - APT: AllmyappsUpdateTask - (...) -- C:\Windows\Tasks\AllmyappsUpdateTask.job [392] O39 - APT: AllmyappsUpdateTask - (...) -- C:\Windows\System32\Tasks\AllmyappsUpdateTask [392] O39 - APT: Application Starter - f1375f225883e83d52e8db9690775c3c - (.Innovative Solutions.) -- C:\Windows\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c.job [302] O39 - APT: Application Starter - f1375f225883e83d52e8db9690775c3c - (.Innovative Solutions.) -- C:\Windows\System32\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c [302] O39 - APT: AVG-Secure-Search-Update_0214b_rel - (...) -- C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rel.job [374] =>Toolbar.AVGSearch O39 - APT: AVG-Secure-Search-Update_0214b_rel - (...) -- C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rel [374] =>Toolbar.AVGSearch O39 - APT: AVG-Secure-Search-Update_0214b_rmv - (...) -- C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rmv.job [376] =>Toolbar.AVGSearch O39 - APT: AVG-Secure-Search-Update_0214b_rmv - (...) -- C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rmv [376] =>Toolbar.AVGSearch O39 - APT: FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core.job [902] O39 - APT: FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core [902] O39 - APT: FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA.job [924] O39 - APT: FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA [924] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1066] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1066] O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1070] O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1070] O39 - APT: GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core.job [922] O39 - APT: GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000Core [922] O39 - APT: GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA.job [974] O39 - APT: GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3147391334-965059008-3150008735-1000UA [974] ~ Scheduled Task: 42 Scanned in 00mn 03s
---\\ ActiveSetup Installed Components (O40) O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll O40 - ASIC: Internet Explorer [64Bits] - {2D46B6DC-2207-486B-B523-A557E6D54B47} . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\system32\cmd.exe =>.Microsoft Corporation O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe =>.Microsoft Corporation O40 - ASIC: Browsing Enhancements [64Bits] - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation O40 - ASIC: Windows Desktop Update [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll ~ Active Setup: 10 Scanned in 00mn 00s
---\\ Drivers launched at startup (O41) O41 - Driver: (adgnetworktdi) . (. - .) - C:\Windows\System32\drivers\adgnetworktdi.sys (.not file.) O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys O41 - Driver: (AppleCharger) . (...) - C:\Windows\System32\DRIVERS\AppleCharger.sys O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys O41 - Driver: (HWiNFO32) . (.REALiX(tm) - HWiNFO AMD64 Kernel Driver.) - C:\Windows\sysWOW64\drivers\HWiNFO64A.sys O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\System32\DRIVERS\mssmbios.sys O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\Windows\System32\DRIVERS\serial.sys O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys O41 - Driver: Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0 (ws2ifsl) . (.Microsoft Corporation - Couche IFS Winsock2.) - C:\Windows\system32\drivers\ws2ifsl.sys ~ Drivers: 72 Scanned in 00mn 00s
---\\ Software installed (O42) O42 - Logiciel: "Солдат удачи: Расплата" версии 1.1.0.0 - (...) [HKLM][64Bits] -- SoldierofFortunePayback_is1 O42 - Logiciel: 4K Video to MP3 2.2 - (.Open Media LLC.) [HKLM][64Bits] -- 4K Video to MP3_is1 O42 - Logiciel: 4t Tray Minimizer Free 5.52 - (.4t Niagara Software.) [HKLM][64Bits] -- 4t Tray Minimizer_is1 O42 - Logiciel: 7-Zip 9.38 beta - (...) [HKLM][64Bits] -- 7-Zip O42 - Logiciel: ABBYY FineReader 9.0 Sprint - (.ABBYY.) [HKLM][64Bits] -- ABBYY FineReader 9.0 Sprint O42 - Logiciel: ABBYY FineReader 9.0 Sprint - (.ABBYY.) [HKLM][64Bits] -- {F9000000-0018-0000-0000-074957833700} O42 - Logiciel: ABBYY FineReader11 Professional Edition - (...) [HKLM][64Bits] -- ABBYY FineReader11 Professional Edition O42 - Logiciel: ACDSee Pro 2 - (.ACD Systems International.) [HKLM][64Bits] -- {4AAC95F4-A30E-4EE5-A086-6F79581D0D70} O42 - Logiciel: Ace Stream Media 3.0.2 - (.Ace Stream Media.) [HKCU][64Bits] -- AceStream O42 - Logiciel: Acunetix Web Vulnerability Scanner 8.0 - (.Acunetix.) [HKLM][64Bits] -- {DBD76811-6CF0-4A15-9436-B779C3A36929}_is1 O42 - Logiciel: AdFender - (.AdFender, Inc..) [HKLM][64Bits] -- AdFender O42 - Logiciel: Adblock Plus for IE - (...) [HKLM][64Bits] -- {fd97d1e2-368a-4cd9-af63-8eeff938044a} O42 - Logiciel: Adblock Plus для IE (32- и 64-разрядные версии) - (.Eyeo GmbH.) [HKLM][64Bits] -- {0E47CCC3-6D30-4CB7-A0A9-1375BBC02CCA} O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {7BBAEC47-1CC0-4CB8-ADB4-531B78DBD1DD} O42 - Logiciel: Adobe Acrobat 4.0 - (.Adobe Systems, Inc..) [HKLM][64Bits] -- Adobe Acrobat 4.0 O42 - Logiciel: Adobe Flash Player 16 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Flash Player 16 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI O42 - Logiciel: Adobe Reader 64-bit fixes - (.Leo Davidson / Pretentious Name.) [HKLM][64Bits] -- {6D80AAE7-FF65-4950-B1CA-3A7EA4995574}_is1 O42 - Logiciel: Adobe Reader XI (11.0.10) - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1033-7B44-AB0000000001} O42 - Logiciel: Adobe Shockwave Player 12.1 - (.Adobe Systems, Inc..) [HKLM][64Bits] -- Adobe Shockwave Player O42 - Logiciel: Allmyapps - (.Allmyapps SAS.) [HKCU][64Bits] -- Allmyapps O42 - Logiciel: AnVir Task Manager - (.AnVir Software.) [HKLM][64Bits] -- AnVir Task Manager O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM][64Bits] -- {787136D2-F0F8-4625-AA3F-72D7795AC842} O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM][64Bits] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} =>.Apple Inc O42 - Logiciel: Applian FLV Player - (.Applian Technologies Inc..) [HKLM][64Bits] -- Applian FLV Player2.0.24 =>PUP.ApplianTechnologies O42 - Logiciel: Applian FLV and Media Player 3.1.1.12 - (.Applian Technologies.) [HKLM][64Bits] -- Applian FLV and Media Player =>PUP.ApplianTechnologies O42 - Logiciel: Ashampoo MP3 Check&Convert - (...) [HKLM][64Bits] -- Ashampoo MP3 Check&Convert O42 - Logiciel: Avery Wizard 4.0 - (.Avery.) [HKLM][64Bits] -- {F97272B4-82C4-46B2-BCF1-C4D6E8CAB3E6} O42 - Logiciel: Aviator - (.WhiteHat Security, Inc..) [HKLM][64Bits] -- {B0E4AA1D-76A7-48B5-AAA1-D68BDBB1FF99} O42 - Logiciel: BlazeVideo HDTV Player 6.6 Professional - (...) [HKLM][64Bits] -- BlazeVideo HDTV Player 6.6 Professional_is1 O42 - Logiciel: BlindScanner Pro - (.Masters ITC Software.) [HKLM][64Bits] -- {3F02DFA9-EA6F-40E7-AF53-8750D6FB646B}_is1 O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] -- {6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D} O42 - Logiciel: Bullzip PDF Printer 10.8.0.2282 - (.Bullzip.) [HKLM][64Bits] -- Bullzip PDF Printer_is1 O42 - Logiciel: CacheMyWork - (.Codeplex.) [HKLM][64Bits] -- {4CD3A1CB-EB91-4DC5-B636-33B66BA56162} O42 - Logiciel: Camfrog Web Advanced 2.0 ActiveX Plugin (remove only) - (...) [HKLM][64Bits] -- CFWebAdvancedU2 O42 - Logiciel: CamfrogWEB Advanced ActiveX Plugin (remove only) - (...) [HKLM][64Bits] -- CFWebAdvancedU O42 - Logiciel: CamfrogWEB Advanced ActiveX Plugin (www.bobtv.fr) - (...) [HKLM][64Bits] -- CFWebAdvancedU_BOBTV.FR O42 - Logiciel: Cartes de Visite - (...) [HKLM][64Bits] -- {888DF9D4-876E-11D7-B60C-00C04F4351FF} O42 - Logiciel: Classic Menu for Office 2007 v5.00 - (.Addintools.) [HKLM][64Bits] -- {409ECFF1-9CC7-43A8-B28A-B7F0B7CB04D1}_is1 O42 - Logiciel: Clean Master - (.Cheetah Mobile.) [HKLM][64Bits] -- Clean Master O42 - Logiciel: Clover 3.0 - (.EJIE Technology.) [HKLM][64Bits] -- Clover O42 - Logiciel: Crystal TV 3.1.684 - (.Crystal Reality LLC.) [HKLM][64Bits] -- Crystal TV O42 - Logiciel: CutePDF Professional 3.71 - (.Acro Software Inc..) [HKLM][64Bits] -- CutePDF Professional_is1 O42 - Logiciel: CutePDF Writer 3.0 - (.Acro Software Inc..) [HKLM][64Bits] -- CutePDF Writer Installation O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} O42 - Logiciel: Daum PotPlayer 1.5.33948 RU x64 - (.©7sh3. (Сборка от 26.07.2012).) [HKLM][64Bits] -- {69764025-6925-4F66-A38B-63AD94DB6746}_is1 O42 - Logiciel: DjVuLibre+DjView - (.DjVuZone.) [HKLM][64Bits] -- DjVuLibre+DjView O42 - Logiciel: DriverMax 7 - (.Innovative Solutions.) [HKLM][64Bits] -- DMX5_is1 O42 - Logiciel: EPSON SX235 Series Printer Uninstall - (.SEIKO EPSON Corporation.) [HKLM][64Bits] -- EPSON SX235 Series O42 - Logiciel: EPSON Scan - (.Seiko Epson Corporation.) [HKLM][64Bits] -- EPSON Scanner O42 - Logiciel: Epson Easy Photo Print 2 - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {A02D7029-C4EF-44C1-9FD4-C0D3CA518113} O42 - Logiciel: Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {B2D55EB8-32C5-4B43-9006-9E97DECBA178} O42 - Logiciel: Epson Event Manager - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {8ED43F7E-A8F6-4898-AF11-B6158F2EDF94} O42 - Logiciel: EpsonNet Print - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {3E31400D-274E-4647-916C-2CACC3741799} O42 - Logiciel: Etron USB3.0 Host Controller - (.Etron Technology.) [HKLM][64Bits] -- InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27} O42 - Logiciel: Etron USB3.0 Host Controller - (.Etron Technology.) [HKLM][64Bits] -- {DFBB738C-71D8-4DC5-B8D2-D65C37680E27} O42 - Logiciel: Facebook Video Calling 3.1.0.521 - (.Skype Limited.) [HKLM][64Bits] -- {2091F234-EB58-4B80-8C96-8EB78C808CF7} O42 - Logiciel: Fake Webcam 7.3 - (.Web Solution Mart.) [HKLM][64Bits] -- fakewebcam7.3.0_is1 O42 - Logiciel: Fake Webcam Codecs Pack 1.0.0 - (.Web Solution Mart.) [HKLM][64Bits] -- fwccpsetup_is1 O42 - Logiciel: Firefox Developer Edition 38.0a2 (x86 ru) - (.Mozilla.) [HKLM][64Bits] -- Firefox Developer Edition 38.0a2 (x86 ru) O42 - Logiciel: FormMax Filler 3.51 - (.Acro Software Inc..) [HKLM][64Bits] -- FormMax Filler_is1 O42 - Logiciel: FraudEliminator 2.4.0 - (.www.FraudEliminator.com.) [HKLM][64Bits] -- {48C619B9-C4ED-41C9-8F18-94B0C06AEE2D} O42 - Logiciel: Free Folder Hider 12.03 - (.AuoBAUP, Inc..) [HKLM][64Bits] -- Free Folder Hider_is1 O42 - Logiciel: Galerie de photos - (.Microsoft Corporation.) [HKLM][64Bits] -- {F4D99A13-F63A-4FC1-8799-CFFDB78DDFB3} O42 - Logiciel: Geotag Security 1.0 - (.Geotag Security Software, Inc.) [HKLM][64Bits] -- Geotag Security_is1 O42 - Logiciel: Ghostery IE Plugin - (.Ghostery.) [HKLM][64Bits] -- Ghostery IE Plugin_is1 O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome O42 - Logiciel: Google Talk Plugin - (.Google.) [HKLM][64Bits] -- {C77CC230-7417-3F01-B70D-52583DC9FEC9} O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {18455581-E099-4BA8-BC6B-F34B2F06600C} O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F} O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} O42 - Logiciel: Guide d'utilisation EPSON SX235 Series - (...) [HKLM][64Bits] -- EPSON SX235 Series Useg O42 - Logiciel: Guide réseau EPSON SX235 Series - (...) [HKLM][64Bits] -- EPSON SX235 Series Netg O42 - Logiciel: H.264 Encoder - (.www.H264Encoder.com.) [HKLM][64Bits] -- {B99459D2-B91A-417E-9DFA-F53D569F4445}_is1 O42 - Logiciel: Hauppauge WinTV 7 - (.Hauppauge Computer Works.) [HKLM][64Bits] -- Hauppauge WinTV 7 O42 - Logiciel: ICQ 8.3 (сборка 7317) - (.ICQ.) [HKCU][64Bits] -- ICQ O42 - Logiciel: IP-TV Player 0.28.1.8834 - (.ООО АДСЛ Клуб.) [HKLM][64Bits] -- IP-TV_Player O42 - Logiciel: IR Server Suite - (.Team MediaPortal.) [HKLM][64Bits] -- IR Server Suite O42 - Logiciel: Intel(R) Control Center - (.Intel Corporation.) [HKLM][64Bits] -- {F8A9085D-4C7A-41a9-8A77-C8998A96C421} O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {1CEAC85D-2590-4760-800F-8DE5E91F3700} O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A} O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {D4FC649C-0247-4873-930D-D9E6904DCAF5} O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {3DE97849-544D-4D68-9255-11DF6F9F10D8} O42 - Logiciel: Internet Explorer (Enable DEP) - (...) [HKLM][64Bits] -- {a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb O42 - Logiciel: Java 7 Update 60 (64-bit) - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F06417060FF} O42 - Logiciel: Java 8 Update 25 (64-bit) - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F86418025F0} O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM][64Bits] -- {F6F30C28-38AA-4DBA-AE0B-7E30238E61BB} O42 - Logiciel: K!TV - (...) [HKLM][64Bits] -- K!TV O42 - Logiciel: K-Meleon 1.5.4 ru-RU (только удаление) - (.K-Meleon Team.) [HKLM][64Bits] -- K-Meleon O42 - Logiciel: Kazoo Player - (...) [HKLM][64Bits] -- Kazoo Player O42 - Logiciel: Lagarith lossless video codec (Remove Only) - (...) [HKLM][64Bits] -- LAGARITH O42 - Logiciel: Lunascape6 (All Users) - (.Lunascape.) [HKLM][64Bits] -- Lunascape6 O42 - Logiciel: MDAPI_Plus - (.Alexander Plyas.) [HKLM][64Bits] -- MDAPI_Plus O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} O42 - Logiciel: MSVCRT110 - (.Microsoft.) [HKLM][64Bits] -- {8E14DDC8-EA60-4E18-B3E3-1937104D5BDA} O42 - Logiciel: MSVCRT110_amd64 - (.Microsoft.) [HKLM][64Bits] -- {E9FA781F-3E80-4399-825A-AD3E11C28C77} O42 - Logiciel: MSVCRT_amd64 - (.Microsoft.) [HKLM][64Bits] -- {D0B44725-3666-492D-BEF6-587A14BD9BD9} O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM][64Bits] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71} O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM][64Bits] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC} O42 - Logiciel: MSXML 4.0 SP2 Parser and SDK - (.Microsoft Corporation.) [HKLM][64Bits] -- {716E0306-8318-4364-8B8F-0CC4E9376BAC} O42 - Logiciel: Ma-Config.com (64 bits) - (.Cybelsoft.) [HKLM][64Bits] -- {FCE01EE0-46F1-4A40-85A5-A180E8F7350D} O42 - Logiciel: Malwarebytes Anti-Malware, версия 2.0.4.1028 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes Anti-Malware_is1 O42 - Logiciel: ManyCam 4.0.44 - (.Visicom Media Inc..) [HKLM][64Bits] -- ManyCam O42 - Logiciel: MaxTV - (.MaxTV Technologies.) [HKLM][64Bits] -- MaxTV O42 - Logiciel: Microsoft Antimalware Service RU-RU Language Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {7F20FBE0-9939-4BA0-9290-628727D63D55} O42 - Logiciel: Microsoft Fix it Center - (.Microsoft Corporation.) [HKLM][64Bits] -- {B7588D45-AFDC-4C93-9E2E-A100F3554B64} O42 - Logiciel: Microsoft FrontPage 2002 - (.Microsoft Corporation.) [HKLM][64Bits] -- {9017040C-6000-11D3-8CFE-0050048383C9} O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM][64Bits] -- {996D32B6-F629-4764-894B-CB24D9C19051} O42 - Logiciel: Microsoft Security Client RU-RU Language Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {DC911ADF-7B60-40F2-A112-FB1EB6402D07} O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Security Client O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} O42 - Logiciel: Microsoft SkyDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- SkyDriveSetup.exe =>.Microsoft Corporation O42 - Logiciel: Microsoft Works - (.Microsoft Corporation.) [HKLM][64Bits] -- {93492218-15C0-4719-B898-05FC5769F2E6} O42 - Logiciel: Mises à jour NVIDIA 1.10.8 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update O42 - Logiciel: Monkey's Audio - (...) [HKLM][64Bits] -- Monkey's Audio_is1 O42 - Logiciel: Mozilla Firefox 35.0.1 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 35.0.1 (x86 fr) O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService O42 - Logiciel: Mp3tag v2.66 - (.Florian Heidenreich.) [HKLM][64Bits] -- Mp3tag O42 - Logiciel: MyFreeCodec - (...) [HKCU][64Bits] -- MyFreeCodec O42 - Logiciel: MySQL Server 5.1 - (.MySQL AB.) [HKLM][64Bits] -- {561AB451-B967-475C-80E0-3B6679C38B52} O42 - Logiciel: NVIDIA Display Control Panel - (.NVIDIA Corporation.) [HKLM][64Bits] -- NVIDIA Display Control Panel O42 - Logiciel: NVIDIA Pilote graphique 307.83 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver O42 - Logiciel: Nero 7 Ultra Edition - (.Nero AG.) [HKLM][64Bits] -- {30C50520-1B5E-4FD1-A87B-444F86E21049} O42 - Logiciel: ON_OFF Charge B11.0110.1 - (.GIGABYTE.) [HKLM][64Bits] -- {3DECD372-76A1-4483-BF10-B547790A3261} O42 - Logiciel: Octoshape Streaming Services - (.Octoshape ApS.) [HKCU][64Bits] -- Octoshape Streaming Services O42 - Logiciel: Office Tab FreeEdition - (.Detong Technology Ltd..) [HKLM][64Bits] -- {DE469D65-1DEB-4058-BF95-C642D733668D}_is1 O42 - Logiciel: Opera 12.17 - (.Opera Software ASA.) [HKLM][64Bits] -- Opera 12.17.1863 O42 - Logiciel: Opera Stable 27.0.1689.76 - (.Opera Software ASA.) [HKLM][64Bits] -- Opera 27.0.1689.76 O42 - Logiciel: PC Wizard 2013.2.12 - (.CPUID.) [HKLM][64Bits] -- PC Wizard 2013_is1 O42 - Logiciel: PDF Architect - (.pdfforge GmbH.) [HKLM][64Bits] -- {064A929A-4DE8-40CF-A901-BD40C14E4D25} O42 - Logiciel: PDF Unlocker - (...) [HKLM][64Bits] -- PDF Unlocker O42 - Logiciel: PDFCreator - (.pdfforge.) [HKLM][64Bits] -- {0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D} O42 - Logiciel: PIMOne 5.35 - (.PIMOne Software.) [HKLM][64Bits] -- PIMOne_is1 O42 - Logiciel: PVSonyDll - (.NVIDIA Corporation.) [HKLM][64Bits] -- {3D3E663D-4E7E-4577-A560-7ECDDD45548A} O42 - Logiciel: Pamela Basic 4.8 - (.Scendix Software-Vertriebsges. mbH.) [HKLM][64Bits] -- Pamela O42 - Logiciel: Parom.TV player - (...) [HKLM][64Bits] -- Parom.TV O42 - Logiciel: Philips SPC 900NC PC Camera - (...) [HKLM][64Bits] -- {220F6386-5D1F-4DA5-94DB-F12133C3AE2C} O42 - Logiciel: Philips VLounge - (.ArcSoft.) [HKLM][64Bits] -- {89ACA875-BDB9-443C-B7C7-D74D3BDE8FE2} O42 - Logiciel: PlayReady PC Runtime amd64 - (.Microsoft Corporation.) [HKLM][64Bits] -- {BCA9334F-B6C9-4F65-9A73-AC5A329A4D04} O42 - Logiciel: Potplayer - (.Daum Kakao Corp..) [HKLM][64Bits] -- PotPlayer O42 - Logiciel: PowerChute Personal Edition 3.0.2 - (.Schneider Electric.) [HKLM][64Bits] -- {8ED262EE-FC73-47A9-BB86-D92223246881} O42 - Logiciel: ProgDVB x64 - (.Prog.) [HKLM][64Bits] -- ProgDVB O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM][64Bits] -- {B67BAFBA-4C9F-48FA-9496-933E3B255044} O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} O42 - Logiciel: Reg Organizer, версия 6.55 - (.ChemTable Software.) [HKLM][64Bits] -- Reg Organizer_is1 O42 - Logiciel: Roadkil's Unstoppable Copier Version 5.2 - (.Roadkil.Net.) [HKLM][64Bits] -- {A306FD29-7D3A-4287-91AC-9A0180931395}_is1 O42 - Logiciel: Rumote VMC Plugin - (...) [HKLM][64Bits] -- {af46b9c7-3b0c-4ebb-86fb-349203430866} O42 - Logiciel: Rumote VMC Plugin 2.1.4 - (.Rumote.) [HKLM][64Bits] -- {93014103-9212-4AC7-9CD1-77544704BAC3} O42 - Logiciel: RunMe 0.9 - (.KSoft.) [HKLM][64Bits] -- RunMe O42 - Logiciel: SAMSUNG USB Driver for Mobile Phones - (.SAMSUNG Electronics Co., Ltd..) [HKLM][64Bits] -- {D0795B21-0CDA-4a92-AB9E-6E92D8111E44} O42 - Logiciel: Samsung Kies - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- InstallShield_{758C8301-2696-4855-AF45-534B1200980A} O42 - Logiciel: Samsung Kies - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- {758C8301-2696-4855-AF45-534B1200980A} O42 - Logiciel: Samsung Story Album Viewer - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- InstallShield_{698BBAD8-B116-495D-B879-0F07A533E57F} O42 - Logiciel: Samsung Story Album Viewer - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- {698BBAD8-B116-495D-B879-0F07A533E57F} O42 - Logiciel: Scan Tailor - (...) [HKLM][64Bits] -- Scan Tailor O42 - Logiciel: Secure Eraser - (.ASCOMP Software GmbH.) [HKLM][64Bits] -- Secure Eraser_is1 O42 - Logiciel: SiSoftware Sandra Business 2013 - (.SiSoftware.) [HKLM][64Bits] -- {C3113E55-7BCB-4de3-8EBF-60E6CE6B2396}_is1 O42 - Logiciel: Simple Adblock - (.Simple Adblock.) [HKLM][64Bits] -- {B4920103-09F6-4AD2-B150-CFC4474D2DDC} O42 - Logiciel: Skype™ 7.1 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7} O42 - Logiciel: SlimDrivers - (.SlimWare Utilities, Inc..) [HKLM][64Bits] -- {A5457401-D56A-43F2-9524-78E54A7FC07A} O42 - Logiciel: Solid Converter PDF - (.SolidDocuments.) [HKLM][64Bits] -- {56BFAA6E-2BCC-4AED-9233-84731E66B205} O42 - Logiciel: SopCast 3.9.2 - (.www.sopcast.com.) [HKLM][64Bits] -- SopCast O42 - Logiciel: Sopcast Toolbar - (.APN, LLC.) [HKLM][64Bits] -- {53504356-3700-A76A-76A7-A758B70C0600} =>Toolbar.Ask O42 - Logiciel: Stardock Fences 2 - (.Stardock Software, Inc..) [HKLM][64Bits] -- Stardock Fences 2 O42 - Logiciel: StreamTransport version: 1.1.3.0 - (...) [HKLM][64Bits] -- {FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1 O42 - Logiciel: System Explorer 5.9.5 - (.Mister Group.) [HKLM][64Bits] -- {40F485F7-6478-4896-B0D5-F94BE677EB78}_is1 O42 - Logiciel: TELL ME MORE - (...) [HKLM][64Bits] -- TMM70 O42 - Logiciel: Teleport Ultra - (.Tennyson Maxwell Information Systems, Inc..) [HKLM][64Bits] -- Teleport Ultra O42 - Logiciel: TeraCopy 2.3 - (.Code Sector.) [HKLM][64Bits] -- TeraCopy_is1 O42 - Logiciel: URL Helper - (...) [HKLM][64Bits] -- URL Helper_is1 O42 - Logiciel: URL Snooper v2.35.01 - (.DonationCoder.com.) [HKLM][64Bits] -- URLSnooper 2_is1 O42 - Logiciel: Uninstall Tool - (.CrystalIDEA Software, Inc..) [HKLM][64Bits] -- Uninstall Tool_is1 O42 - Logiciel: Unlocker 1.9.2 - (.Cedrick Collomb.) [HKLM][64Bits] -- Unlocker O42 - Logiciel: VC80CRTRedist - 8.0.50727.6195 - (.DivX, Inc.) [HKLM][64Bits] -- {933B4015-4618-4716-A828-5289FC03165F} O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN O42 - Logiciel: VMware Player - (.VMware, Inc.) [HKLM][64Bits] -- VMware_Player O42 - Logiciel: VMware Player - (.VMware, Inc..) [HKLM][64Bits] -- {E452E727-86B8-4233-8CC3-41FD817AFAFF} O42 - Logiciel: WOT for Internet Explorer - (.WOT Services Oy.) [HKLM][64Bits] -- {373B90E1-A28C-434C-92B6-7281AFA6115A} O42 - Logiciel: WinPcap 4.1.3 - (.Riverbed Technology, Inc..) [HKLM][64Bits] -- WinPcapInst O42 - Logiciel: WinRAR 5.11 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver O42 - Logiciel: Windows Firewall Control - (.Alexandru Dicu.) [HKLM][64Bits] -- WindowsFirewallControl O42 - Logiciel: Windows Firewall Control - (.BiniSoft.org.) [HKLM][64Bits] -- Windows Firewall Control O42 - Logiciel: Windows Media Player 64-bit Plug-in Fix - (...) [HKLM][64Bits] -- {00a8ce68-cb2e-4652-aecd-c05c0d9d53a7}.sdb =>.Microsoft Corporation O42 - Logiciel: Windows Media Player Firefox Plugin - (.Microsoft Corp.) [HKLM][64Bits] -- {69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} =>.Microsoft Corporation O42 - Logiciel: Windows Media Player Plus! 2.6 - (.BM-productions.) [HKLM][64Bits] -- {67E4EF06-E0D6-42E0-A2BA-67199B0143FB}_is1 =>.Microsoft Corporation O42 - Logiciel: XBMC - (.Team XBMC.) [HKCU][64Bits] -- XBMC O42 - Logiciel: Zattoo4 4.0.5 - (.Zattoo Inc..) [HKLM][64Bits] -- Zattoo4 O42 - Logiciel: ffdshow x64 v1.3.4531 [2014-06-28] - (...) [HKLM][64Bits] -- ffdshow64_is1 O42 - Logiciel: ooVoo - (.ooVoo LLC..) [HKLM][64Bits] -- {FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623} O42 - Logiciel: paint.net - (.dotPDN LLC.) [HKLM][64Bits] -- {19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42} O42 - Logiciel: rue des йcoles - Super Vacances vers le CM1 - (...) [HKLM][64Bits] -- SupVac09 O42 - Logiciel: swMSM - (.Adobe Systems, Inc.) [HKLM][64Bits] -- {612C34C7-5E90-47D8-9B5C-0F717DD82726} O42 - Logiciel: tools-freebsd - (.VMware, Inc..) [HKLM][64Bits] -- {003BFBBD-6C67-419E-A24D-0DCAFC3A5249} O42 - Logiciel: tools-linux - (.VMware, Inc..) [HKLM][64Bits] -- {D102611A-6466-4101-A51D-51069303AC65} O42 - Logiciel: tools-netware - (.VMware, Inc..) [HKLM][64Bits] -- {197597A7-AD33-4898-9D8E-73066818B464} O42 - Logiciel: tools-solaris - (.VMware, Inc..) [HKLM][64Bits] -- {AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4} O42 - Logiciel: tools-winPre2k - (.VMware, Inc..) [HKLM][64Bits] -- {AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D} O42 - Logiciel: tools-windows - (.VMware, Inc..) [HKLM][64Bits] -- {FFD9383C-01D5-4897-A954-43AF599AED30} O42 - Logiciel: Поддержка программ Apple - (.Apple Inc..) [HKLM][64Bits] -- {AAC5D43E-816D-4C2D-8E51-55FFF35BE301} O42 - Logiciel: Установка DivX - (.DivX, LLC.) [HKLM][64Bits] -- DivX Setup ~ Logic: 107 Scanned in 00mn 00s | ||||||||
Petit astucien | ---\\ HKCU & HKLM Software Keys [HKCU\Software\2LMultimedia] [HKCU\Software\2vg] [HKCU\Software\4kdownload.com] [HKCU\Software\4t Niagara Software] [HKCU\Software\7-Zip] [HKCU\Software\ABBYY] [HKCU\Software\ACD Systems] [HKCU\Software\ACE Compression Software] [HKCU\Software\APC] [HKCU\Software\ASCOMP] [HKCU\Software\ASProtect] [HKCU\Software\AVS4YOU] [HKCU\Software\Acro Software Inc] [HKCU\Software\Acunetix] [HKCU\Software\AdblockPlus] [HKCU\Software\AddinTools] [HKCU\Software\Adobe] [HKCU\Software\Ahead] [HKCU\Software\Ainvo] [HKCU\Software\All-Radio] [HKCU\Software\Anvide Labs] [HKCU\Software\Anvir] [HKCU\Software\AppDataLow\IEPro] [HKCU\Software\AppDataLow\Software\Adobe] [HKCU\Software\AppDataLow\Software\Against Intuition] [HKCU\Software\AppDataLow\Software\DivX] [HKCU\Software\AppDataLow\Software\G DATA] [HKCU\Software\AppDataLow\Software\JavaSoft] [HKCU\Software\AppDataLow\Software\Mail.Ru] [HKCU\Software\AppDataLow\Software\MarkAny] [HKCU\Software\AppDataLow\Software\ThinPrint] [HKCU\Software\AppDataLow\Software\Yahoo] [HKCU\Software\AppDataLow] [HKCU\Software\Apple Computer, Inc.] [HKCU\Software\Apple Inc.] [HKCU\Software\Auralog] [HKCU\Software\Auslogics] [HKCU\Software\Avant Browser] [HKCU\Software\Avery] [HKCU\Software\Aviator] [HKCU\Software\BExplorer] [HKCU\Software\BM-productions] [HKCU\Software\BST] [HKCU\Software\Binary Noise] [HKCU\Software\BiniSoft.org] [HKCU\Software\BlazeVideo] [HKCU\Software\Borland] [HKCU\Software\CPUID] [HKCU\Software\CSoftLab] [HKCU\Software\CamfrogWeb] [HKCU\Software\Camfrog] [HKCU\Software\Canneverbe Limited] [HKCU\Software\Carthago] [HKCU\Software\ChemTable Software] [HKCU\Software\ChrisPC JTV Player] [HKCU\Software\ChrisTV Online] [HKCU\Software\ChromePlus] [HKCU\Software\Chromium] [HKCU\Software\Classes] [HKCU\Software\Clients] [HKCU\Software\Clover] [HKCU\Software\Code Sector] [HKCU\Software\CoreFLAC] [HKCU\Software\Crystal Reality] [HKCU\Software\CrystalIdea Software] [HKCU\Software\DPP] [HKCU\Software\DSP-worx] [HKCU\Software\Dating Notifier (Wekiss)] [HKCU\Software\Daum] [HKCU\Software\David Esperalta] [HKCU\Software\Depositfiles] [HKCU\Software\DevID] [HKCU\Software\DivXNetworks] [HKCU\Software\DivX] [HKCU\Software\DjVuLibre] [HKCU\Software\Dominsoft] [HKCU\Software\DownloadCenter] [HKCU\Software\EFD Software] [HKCU\Software\EPSON] [HKCU\Software\Enterbrain] [HKCU\Software\Evernote] [HKCU\Software\Explorer++] [HKCU\Software\ExtendOffice] [HKCU\Software\Eyeball] [HKCU\Software\Facebook] [HKCU\Software\FinalWire] [HKCU\Software\Foxit Software] [HKCU\Software\FraudEliminatorToolBar] [HKCU\Software\Freecorder] [HKCU\Software\Freeware] [HKCU\Software\FreshDevices] [HKCU\Software\Froggie] [HKCU\Software\GNU] [HKCU\Software\Gabest] [HKCU\Software\Geek Uninstaller] [HKCU\Software\Ghostery] [HKCU\Software\GlarySoft] [HKCU\Software\Google] [HKCU\Software\Haali] [HKCU\Software\Hachette Multimedia] [HKCU\Software\Haihaisoft PDF Reader] [HKCU\Software\Hensense.com] [HKCU\Software\HiDownloadPlatinum] [HKCU\Software\I.R.I.S. Applications] [HKCU\Software\IM Providers] [HKCU\Software\ImgBurn] [HKCU\Software\Infium] [HKCU\Software\Innovative Solutions] [HKCU\Software\IvoSoft] [HKCU\Software\JEDI-VCL] [HKCU\Software\K-Meleon] [HKCU\Software\KC Softwares] [HKCU\Software\Kartina.TV] [HKCU\Software\LAV64] [HKCU\Software\LAV] [HKCU\Software\Licenses] [HKCU\Software\LizardTech] [HKCU\Software\Local AppWizard-Generated Applications] [HKCU\Software\LopeSoft] [HKCU\Software\Lunascape Corporation] [HKCU\Software\MCAFEE] [HKCU\Software\MONOGRAM] [HKCU\Software\Macromedia] [HKCU\Software\Mail.Ru] [HKCU\Software\MainConcept (HCW)] [HKCU\Software\MainConcept] [HKCU\Software\Makayama] [HKCU\Software\Malware Destroyer 6] [HKCU\Software\Malware Destroyer 7] [HKCU\Software\Malwarebytes' Anti-Malware (portable)] [HKCU\Software\Malwarebytes' Anti-Malware] [HKCU\Software\ManyCam] [HKCU\Software\Master Commander] [HKCU\Software\MasterMedia] [HKCU\Software\Masters ITC] [HKCU\Software\MediaLingua] [HKCU\Software\Mediachance] [HKCU\Software\Monkey's Audio] [HKCU\Software\MozillaPlugins] [HKCU\Software\Mozilla] [HKCU\Software\NVIDIA Corporation] [HKCU\Software\Nero] [HKCU\Software\Netscape] [HKCU\Software\Neuber GbR] [HKCU\Software\NewSoftware's] [HKCU\Software\NuonSoft] [HKCU\Software\ODBC] [HKCU\Software\OJOsoft Corporation] [HKCU\Software\Octoshape] [HKCU\Software\Onet Pliki] [HKCU\Software\Onet.pl] [HKCU\Software\Opera Software] [HKCU\Software\PDF Architect] [HKCU\Software\PDFCreator.net] [HKCU\Software\PDFCreator] [HKCU\Software\Paint.NET] [HKCU\Software\Parom.TV] [HKCU\Software\Pinnacle Systems] [HKCU\Software\PistonSoft] [HKCU\Software\Policies] [HKCU\Software\ProcessLasso] [HKCU\Software\ProtectedData] [HKCU\Software\QIP] [HKCU\Software\Quizo] [HKCU\Software\RDE] [HKCU\Software\RISING] [HKCU\Software\Realtek] [HKCU\Software\RegisteredApplications] [HKCU\Software\Remedy Entertainment] [HKCU\Software\Resort Labs] [HKCU\Software\Rightmark] [HKCU\Software\Rising Sun Solutions, Inc.] [HKCU\Software\Roadkil] [HKCU\Software\RocketDock] [HKCU\Software\Rumote] [HKCU\Software\SIV] [HKCU\Software\SUPERAntiSpyware.com] [HKCU\Software\Safer Networking Limited] [HKCU\Software\Samsung] [HKCU\Software\Scan Tailor] [HKCU\Software\Scanitto] [HKCU\Software\Secunia] [HKCU\Software\Settings] [HKCU\Software\SiSoftware] [HKCU\Software\SightSpeed Inc] [HKCU\Software\SimpleTV by SergeyVS#3] [HKCU\Software\Sippoint] [HKCU\Software\SkypeRS] [HKCU\Software\Skype] [HKCU\Software\SlimWare Utilities Inc] [HKCU\Software\Softland] [HKCU\Software\SolidDocuments] [HKCU\Software\Spoon] [HKCU\Software\Stardock] [HKCU\Software\Stdin2] [HKCU\Software\Streamripper] [HKCU\Software\SyncApp] [HKCU\Software\Sysinternals] [HKCU\Software\TAdvCheckList] [HKCU\Software\TL] [HKCU\Software\Tennyson Maxwell] [HKCU\Software\The Silicon Realms Toolworks] [HKCU\Software\ToolbarCleaner] [HKCU\Software\ToolbarCleaneroptions] [HKCU\Software\Trolltech] [HKCU\Software\TweakNow RegCleaner 2011] [HKCU\Software\URLHelper] [HKCU\Software\VB and VBA Program Settings] [HKCU\Software\VMware, Inc.] [HKCU\Software\VOB] [HKCU\Software\VOS] [HKCU\Software\VSO] [HKCU\Software\Valve] [HKCU\Software\VideoLAN] [HKCU\Software\VirtualDub.org] [HKCU\Software\Visicom Media Inc] [HKCU\Software\VueScan] [HKCU\Software\Web Solution Mart] [HKCU\Software\WhiteHat] [HKCU\Software\WinAbility] [HKCU\Software\WinHTTrack Website Copier] [HKCU\Software\WinRAR SFX] [HKCU\Software\WinRAR] [HKCU\Software\Winamp-BackupByWinampPortable] [HKCU\Software\Winamp] [HKCU\Software\Winreview.ru] [HKCU\Software\Winternals] [HKCU\Software\Wondershare] [HKCU\Software\Wow6432Node] [HKCU\Software\Xenocode] [HKCU\Software\Y's] [HKCU\Software\Yahoo] [HKCU\Software\Zattoo] [HKCU\Software\ZebHelpProcess Helper] [HKCU\Software\cmcm] [HKCU\Software\eBooks] [HKCU\Software\eSellerate] [HKCU\Software\fwc] [HKCU\Software\hugin] [HKCU\Software\ooVoo] [HKCU\Software\pth264] [HKCU\Software\sipXtapi] [HKCU\Software\torora.net] [HKCU\Software\zyceffab] [HKCU\Software\zyceffmorg] [HKLM\Software\ACD Systems] [HKLM\Software\ATI Technologies] [HKLM\Software\Acro Software Inc] [HKLM\Software\Adblock Plus for IE] [HKLM\Software\Ainvo] [HKLM\Software\Apple Computer, Inc.] [HKLM\Software\Apple Inc.] [HKLM\Software\Bullzip] [HKLM\Software\CBSTEST] [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\Code Sector] [HKLM\Software\Creative Tech] [HKLM\Software\Debug] [HKLM\Software\DivX] [HKLM\Software\EPSON] [HKLM\Software\EpsonNet] [HKLM\Software\ExtendOffice] [HKLM\Software\GEAR Software] [HKLM\Software\GNU] [HKLM\Software\HaaliMkx] [HKLM\Software\Hauppauge] [HKLM\Software\Hewlett-Packard] [HKLM\Software\IM Providers] [HKLM\Software\Intel] [HKLM\Software\Jasmio] [HKLM\Software\JavaSoft] [HKLM\Software\JreMetrics] [HKLM\Software\Khronos] [HKLM\Software\Licenses] [HKLM\Software\Macromedia] [HKLM\Software\MozillaPlugins] [HKLM\Software\Mozilla] [HKLM\Software\NVIDIA Corporation] [HKLM\Software\Nuance] [HKLM\Software\ODBC] [HKLM\Software\PDFCreator.net] [HKLM\Software\Policies] [HKLM\Software\RTLSetup] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\SAMSUNG] [HKLM\Software\SIV] [HKLM\Software\SRS Labs] [HKLM\Software\SUPERAntiSpyware.com] [HKLM\Software\SiSoftware] [HKLM\Software\Soft4Boost] [HKLM\Software\SolidDocuments] [HKLM\Software\Sonic] [HKLM\Software\Stardock] [HKLM\Software\Synaptics] [HKLM\Software\VMware, Inc.] [HKLM\Software\VideoLAN] [HKLM\Software\Volatile] [HKLM\Software\Waves Audio] [HKLM\Software\WinRAR] [HKLM\Software\Wow6432Node\ABBYY] [HKLM\Software\Wow6432Node\ACD Systems] [HKLM\Software\Wow6432Node\APC] [HKLM\Software\Wow6432Node\AVS4YOU] [HKLM\Software\Wow6432Node\Acro Software Inc] [HKLM\Software\Wow6432Node\Acro Software] [HKLM\Software\Wow6432Node\Acunetix] [HKLM\Software\Wow6432Node\AddinTools] [HKLM\Software\Wow6432Node\Adobe] [HKLM\Software\Wow6432Node\AdwCleaner] [HKLM\Software\Wow6432Node\Ahead] [HKLM\Software\Wow6432Node\AppDataLow] [HKLM\Software\Wow6432Node\Apple Computer, Inc.] [HKLM\Software\Wow6432Node\Apple Inc.] [HKLM\Software\Wow6432Node\Applian Technologies] =>PUP.ApplianTechnologies [HKLM\Software\Wow6432Node\ArcSoft] [HKLM\Software\Wow6432Node\Auralog] [HKLM\Software\Wow6432Node\Avg Secure Update] [HKLM\Software\Wow6432Node\AviSynth] [HKLM\Software\Wow6432Node\BM-productions] [HKLM\Software\Wow6432Node\Better Explorer Team] [HKLM\Software\Wow6432Node\Blue Ridge Networks] [HKLM\Software\Wow6432Node\Borland] [HKLM\Software\Wow6432Node\Canon] [HKLM\Software\Wow6432Node\Caphyon] [HKLM\Software\Wow6432Node\Cauldron] [HKLM\Software\Wow6432Node\Chromium] [HKLM\Software\Wow6432Node\Classes] [HKLM\Software\Wow6432Node\Clients] [HKLM\Software\Wow6432Node\ComodoGroup] [HKLM\Software\Wow6432Node\Comodo] [HKLM\Software\Wow6432Node\Cygwin] [HKLM\Software\Wow6432Node\DAUM] [HKLM\Software\Wow6432Node\Dating] [HKLM\Software\Wow6432Node\Debug] [HKLM\Software\Wow6432Node\Depositfiles] [HKLM\Software\Wow6432Node\DevID] [HKLM\Software\Wow6432Node\DivXNetworks] [HKLM\Software\Wow6432Node\DivX] [HKLM\Software\Wow6432Node\EPSON] [HKLM\Software\Wow6432Node\EpsonNet] [HKLM\Software\Wow6432Node\ExtendOffice] [HKLM\Software\Wow6432Node\Eyeball] [HKLM\Software\Wow6432Node\Florian Heidenreich] [HKLM\Software\Wow6432Node\FotoNation] [HKLM\Software\Wow6432Node\Freecorder] [HKLM\Software\Wow6432Node\FreshDevices] [HKLM\Software\Wow6432Node\GIGABYTE] [HKLM\Software\Wow6432Node\GPL Ghostscript] [HKLM\Software\Wow6432Node\GlarySoft] [HKLM\Software\Wow6432Node\Google] [HKLM\Software\Wow6432Node\HPrefs] [HKLM\Software\Wow6432Node\HaaliMkx] [HKLM\Software\Wow6432Node\Hauppauge] [HKLM\Software\Wow6432Node\IM Providers] [HKLM\Software\Wow6432Node\IObit] [HKLM\Software\Wow6432Node\Innovative Solutions] [HKLM\Software\Wow6432Node\InstallShield] [HKLM\Software\Wow6432Node\Intel] [HKLM\Software\Wow6432Node\InterVideo] [HKLM\Software\Wow6432Node\JavaSoft] [HKLM\Software\Wow6432Node\JreMetrics] [HKLM\Software\Wow6432Node\Khronos] [HKLM\Software\Wow6432Node\Kodak] [HKLM\Software\Wow6432Node\LEAD Technologies, Inc.] [HKLM\Software\Wow6432Node\Licenses] [HKLM\Software\Wow6432Node\LightWork Design] [HKLM\Software\Wow6432Node\LucasArts Entertainment Company LLC] [HKLM\Software\Wow6432Node\Lunascape Corporation] [HKLM\Software\Wow6432Node\Macromedia] [HKLM\Software\Wow6432Node\Mail.Ru] [HKLM\Software\Wow6432Node\Malware Destroyer 7] [HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware (portable)] [HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware] [HKLM\Software\Wow6432Node\McAfee.com] [HKLM\Software\Wow6432Node\Mindscape] [HKLM\Software\Wow6432Node\Moyea] [HKLM\Software\Wow6432Node\MozillaPlugins] [HKLM\Software\Wow6432Node\Mozilla] [HKLM\Software\Wow6432Node\MySQL AB] [HKLM\Software\Wow6432Node\NHN Corporation] [HKLM\Software\Wow6432Node\NVIDIA Corporation] [HKLM\Software\Wow6432Node\Naver] [HKLM\Software\Wow6432Node\Nero] [HKLM\Software\Wow6432Node\Netscape] [HKLM\Software\Wow6432Node\Nuance] [HKLM\Software\Wow6432Node\ODBC] [HKLM\Software\Wow6432Node\Onet.pl] [HKLM\Software\Wow6432Node\Opera Software] [HKLM\Software\Wow6432Node\PDFCreator] [HKLM\Software\Wow6432Node\Philips] [HKLM\Software\Wow6432Node\Pinnacle Systems] [HKLM\Software\Wow6432Node\Policies] [HKLM\Software\Wow6432Node\Quadrant International, Inc.] [HKLM\Software\Wow6432Node\Realtek Semiconductor Corp.] [HKLM\Software\Wow6432Node\Realtek] [HKLM\Software\Wow6432Node\RegisteredApplications] [HKLM\Software\Wow6432Node\Rockstar Games] [HKLM\Software\Wow6432Node\Rumote] [HKLM\Software\Wow6432Node\S3R521] [HKLM\Software\Wow6432Node\SEIKO EPSON CORPORATION] [HKLM\Software\Wow6432Node\Samsung] [HKLM\Software\Wow6432Node\Secunia] [HKLM\Software\Wow6432Node\SimpleAdblock] [HKLM\Software\Wow6432Node\Skype] [HKLM\Software\Wow6432Node\SlimWare Utilities Inc] [HKLM\Software\Wow6432Node\Soft4Boost] [HKLM\Software\Wow6432Node\SoftRM] [HKLM\Software\Wow6432Node\SolidDocuments] [HKLM\Software\Wow6432Node\Sony Corporation] [HKLM\Software\Wow6432Node\Stardock] [HKLM\Software\Wow6432Node\Stardvb] [HKLM\Software\Wow6432Node\StreamTransport] [HKLM\Software\Wow6432Node\Symantec] [HKLM\Software\Wow6432Node\SystemExplorer] [HKLM\Software\Wow6432Node\SystemInfoBapm670] [HKLM\Software\Wow6432Node\ThinPrint] [HKLM\Software\Wow6432Node\TuneUp] [HKLM\Software\Wow6432Node\VMware, Inc.] [HKLM\Software\Wow6432Node\VideoLAN] [HKLM\Software\Wow6432Node\Volatile] [HKLM\Software\Wow6432Node\Web Solution Mart] [HKLM\Software\Wow6432Node\Webteh] [HKLM\Software\Wow6432Node\WhiteHat] [HKLM\Software\Wow6432Node\WinAbility] [HKLM\Software\Wow6432Node\WinPcap] [HKLM\Software\Wow6432Node\Winmend] [HKLM\Software\Wow6432Node\Wise Solutions] [HKLM\Software\Wow6432Node\Wondershare] [HKLM\Software\Wow6432Node\Wow6432Node] [HKLM\Software\Wow6432Node\Yahoo] [HKLM\Software\Wow6432Node\ashampoo] [HKLM\Software\Wow6432Node\cmcm] [HKLM\Software\Wow6432Node\eSellerate] [HKLM\Software\Wow6432Node\fCoder] [HKLM\Software\Wow6432Node\mozilla.org] [HKLM\Software\Wow6432Node\rue des йcoles] [HKLM\Software\Wow6432Node] [HKLM\Software\cybelsoft] [HKLM\Software\fCoder] [HKLM\Software\mozilla.org] [HKLM\Software\paint.net] ~ Key Software: 766 Scanned in 00mn 00s | ||||||||
Petit astucien | ---\\ Contents of the Common Files folders (O43) O43 - CFD: 26.02.2015 - 21:25:24 - [] ----D C:\Program Files (x86)\4KDownload O43 - CFD: 19.12.2013 - 13:14:26 - [] ----D C:\Program Files (x86)\4t Tray Minimizer O43 - CFD: 08.03.2015 - 23:12:47 - [] ----D C:\Program Files (x86)\7-Zip O43 - CFD: 10.06.2012 - 3:11:26 - [] ----D C:\Program Files (x86)\ABBYY FineReader 11 O43 - CFD: 28.03.2012 - 23:55:23 - [] ----D C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint O43 - CFD: 22.04.2012 - 19:15:25 - [] ----D C:\Program Files (x86)\ACD Systems O43 - CFD: 05.09.2014 - 18:44:02 - [] ----D C:\Program Files (x86)\Acro Software O43 - CFD: 16.11.2013 - 18:50:13 - [] ----D C:\Program Files (x86)\Acunetix O43 - CFD: 27.11.2012 - 0:13:40 - [] ----D C:\Program Files (x86)\AdFender O43 - CFD: 21.07.2014 - 21:34:11 - [] ----D C:\Program Files (x86)\Adobe O43 - CFD: 17.06.2013 - 22:58:56 - [] ----D C:\Program Files (x86)\Adobe Reader 64-bit fixes O43 - CFD: 10.09.2014 - 15:56:09 - [] ----D C:\Program Files (x86)\AnVir Task Manager O43 - CFD: 12.06.2013 - 7:30:54 - [] ----D C:\Program Files (x86)\APC O43 - CFD: 02.04.2012 - 13:11:30 - [] ----D C:\Program Files (x86)\Apple Software Update =>.Apple Inc O43 - CFD: 25.04.2012 - 19:30:49 - [] ----D C:\Program Files (x86)\Applian Technologies =>PUP.ApplianTechnologies O43 - CFD: 24.06.2013 - 13:50:05 - [] ----D C:\Program Files (x86)\ASCOMP Software O43 - CFD: 28.04.2013 - 19:53:45 - [] ----D C:\Program Files (x86)\ashampoo O43 - CFD: 31.08.2013 - 22:06:23 - [] ----D C:\Program Files (x86)\Auralog O43 - CFD: 31.08.2013 - 20:26:26 - [0] ----D C:\Program Files (x86)\AVS4YOU O43 - CFD: 02.05.2012 - 23:04:43 - [] ----D C:\Program Files (x86)\BlazeVideo O43 - CFD: 08.06.2013 - 18:16:08 - [] ----D C:\Program Files (x86)\BlindScanner Pro O43 - CFD: 05.04.2012 - 22:27:00 - [] ----D C:\Program Files (x86)\Bonjour O43 - CFD: 11.12.2012 - 22:51:18 - [] ----D C:\Program Files (x86)\CacheMyWork O43 - CFD: 09.01.2015 - 11:43:52 - [0] ----D C:\Program Files (x86)\Camfrog O43 - CFD: 11.12.2014 - 18:59:58 - [] ----D C:\Program Files (x86)\CFWebAdvancedU2 O43 - CFD: 07.01.2014 - 20:06:57 - [] ----D C:\Program Files (x86)\CFWebAdvancedU_BOBTV.FR O43 - CFD: 05.04.2012 - 1:10:13 - [] ----D C:\Program Files (x86)\Classic Menu for Office O43 - CFD: 05.09.2014 - 15:31:02 - [] ----D C:\Program Files (x86)\Clover O43 - CFD: 06.03.2015 - 10:02:17 - [] ----D C:\Program Files (x86)\cmcm O43 - CFD: 09.03.2015 - 2:42:44 - [] ----D C:\Program Files (x86)\Common Files O43 - CFD: 10.09.2014 - 23:31:10 - [] ----D C:\Program Files (x86)\CPUID O43 - CFD: 08.09.2014 - 1:13:18 - [] ----D C:\Program Files (x86)\Crystal TV O43 - CFD: 14.12.2014 - 0:36:20 - [] ----D C:\Program Files (x86)\DAUM O43 - CFD: 23.05.2013 - 23:05:28 - [] ----D C:\Program Files (x86)\DepositFiles O43 - CFD: 18.09.2014 - 18:28:00 - [] ----D C:\Program Files (x86)\DivX O43 - CFD: 11.07.2012 - 0:39:36 - [] ----D C:\Program Files (x86)\DjVuZone O43 - CFD: 28.03.2012 - 23:50:12 - [] ----D C:\Program Files (x86)\epson O43 - CFD: 28.03.2012 - 23:52:22 - [] ----D C:\Program Files (x86)\Epson Software O43 - CFD: 28.03.2012 - 12:01:49 - [] ----D C:\Program Files (x86)\Etron Technology O43 - CFD: 30.12.2013 - 13:34:39 - [] ----D C:\Program Files (x86)\Fake Webcam 7.3 O43 - CFD: 09.03.2015 - 0:54:58 - [] ----D C:\Program Files (x86)\Firefox Developer Edition O43 - CFD: 27.05.2013 - 20:52:06 - [] ----D C:\Program Files (x86)\FraudEliminator O43 - CFD: 27.06.2013 - 18:30:43 - [] ----D C:\Program Files (x86)\FreeFolderHider O43 - CFD: 03.11.2012 - 19:26:42 - [] ----D C:\Program Files (x86)\FVDIEPlugin O43 - CFD: 04.02.2014 - 21:12:18 - [0] ----D C:\Program Files (x86)\G Data O43 - CFD: 28.02.2015 - 0:59:46 - [] ----D C:\Program Files (x86)\Geotag Security O43 - CFD: 26.11.2012 - 15:08:15 - [] ----D C:\Program Files (x86)\GhosteryIEplugin O43 - CFD: 28.03.2012 - 12:02:16 - [] ----D C:\Program Files (x86)\GIGABYTE O43 - CFD: 30.07.2013 - 20:06:00 - [] ----D C:\Program Files (x86)\Google O43 - CFD: 31.03.2012 - 23:09:34 - [] ----D C:\Program Files (x86)\GPLGS O43 - CFD: 22.11.2013 - 23:36:11 - [] ----D C:\Program Files (x86)\H.264 Encoder O43 - CFD: 21.04.2013 - 7:13:38 - [0] ----D C:\Program Files (x86)\Inhatch O43 - CFD: 12.12.2013 - 23:19:24 - [] ----D C:\Program Files (x86)\Innovative Solutions O43 - CFD: 08.03.2015 - 18:24:44 - [] --H-D C:\Program Files (x86)\InstallShield Installation Information O43 - CFD: 08.09.2014 - 14:09:55 - [] ----D C:\Program Files (x86)\Intel O43 - CFD: 12.02.2015 - 8:17:19 - [] ----D C:\Program Files (x86)\Internet Explorer O43 - CFD: 19.10.2014 - 2:24:02 - [] ----D C:\Program Files (x86)\IP-TV Player O43 - CFD: 25.08.2013 - 10:00:10 - [] ----D C:\Program Files (x86)\IR Server Suite O43 - CFD: 20.01.2014 - 18:03:56 - [] ----D C:\Program Files (x86)\Java O43 - CFD: 15.07.2013 - 20:02:17 - [] ----D C:\Program Files (x86)\K!TV O43 - CFD: 08.07.2013 - 9:25:42 - [] ----D C:\Program Files (x86)\K-Meleon O43 - CFD: 21.07.2014 - 19:06:10 - [0] ----D C:\Program Files (x86)\Kakao O43 - CFD: 30.06.2013 - 11:22:48 - [] ----D C:\Program Files (x86)\Links keeper O43 - CFD: 18.01.2013 - 2:43:18 - [0] ----D C:\Program Files (x86)\lpd O43 - CFD: 10.11.2012 - 3:48:45 - [] ----D C:\Program Files (x86)\ma-config.com O43 - CFD: 04.12.2014 - 21:04:04 - [] ----D C:\Program Files (x86)\Malwarebytes Anti-Malware O43 - CFD: 03.01.2014 - 0:28:23 - [] ----D C:\Program Files (x86)\ManyCam O43 - CFD: 12.11.2012 - 20:09:38 - [] ----D C:\Program Files (x86)\MarkAny O43 - CFD: 02.02.2014 - 20:34:23 - [] R---D C:\Program Files (x86)\Max Payne 2 O43 - CFD: 04.04.2013 - 0:08:07 - [] ----D C:\Program Files (x86)\MaxTV O43 - CFD: 25.08.2013 - 10:12:59 - [] ----D C:\Program Files (x86)\MDAPI_Plus O43 - CFD: 29.03.2012 - 23:15:17 - [] ----D C:\Program Files (x86)\Microsoft Office O43 - CFD: 12.02.2015 - 0:51:23 - [] ----D C:\Program Files (x86)\Microsoft Security Client O43 - CFD: 25.07.2014 - 6:45:09 - [] ----D C:\Program Files (x86)\Microsoft Silverlight O43 - CFD: 19.10.2013 - 11:55:06 - [] ----D C:\Program Files (x86)\Microsoft SkyDrive =>.Microsoft Corporation O43 - CFD: 19.10.2013 - 12:00:35 - [] ----D C:\Program Files (x86)\Microsoft SQL Server Compact Edition O43 - CFD: 25.04.2013 - 13:52:22 - [] ----D C:\Program Files (x86)\Microsoft Synchronization Services O43 - CFD: 28.03.2012 - 23:34:19 - [] ----D C:\Program Files (x86)\Microsoft Visual Studio O43 - CFD: 28.03.2012 - 23:32:55 - [] ----D C:\Program Files (x86)\Microsoft Visual Studio 8 O43 - CFD: 12.01.2013 - 14:27:24 - [] ----D C:\Program Files (x86)\Microsoft Works O43 - CFD: 28.03.2012 - 23:34:05 - [] ----D C:\Program Files (x86)\Microsoft.NET O43 - CFD: 06.08.2012 - 22:53:02 - [] ----D C:\Program Files (x86)\Monkey's Audio O43 - CFD: 29.01.2015 - 13:19:19 - [] ----D C:\Program Files (x86)\Mozilla Firefox O43 - CFD: 03.12.2014 - 13:42:16 - [] ----D C:\Program Files (x86)\Mozilla Firefox.bak O43 - CFD: 05.03.2015 - 17:04:33 - [] ----D C:\Program Files (x86)\Mozilla Maintenance Service O43 - CFD: 01.02.2015 - 13:46:28 - [] ----D C:\Program Files (x86)\Mp3tag O43 - CFD: 28.03.2012 - 23:34:27 - [] ----D C:\Program Files (x86)\MSBuild O43 - CFD: 15.07.2013 - 23:25:40 - [0] ----D C:\Program Files (x86)\MSXML 4.0 O43 - CFD: 25.12.2012 - 23:42:20 - [] ----D C:\Program Files (x86)\MyFree Codec O43 - CFD: 21.07.2014 - 18:43:32 - [0] ----D C:\Program Files (x86)\Naver O43 - CFD: 11.11.2013 - 13:20:45 - [] ----D C:\Program Files (x86)\Nero O43 - CFD: 24.02.2013 - 1:37:01 - [] ----D C:\Program Files (x86)\NVIDIA Corporation O43 - CFD: 13.03.2014 - 20:05:19 - [0] ----D C:\Program Files (x86)\Onet O43 - CFD: 08.03.2015 - 18:35:45 - [] ----D C:\Program Files (x86)\ooVoo O43 - CFD: 05.03.2015 - 7:43:06 - [] ----D C:\Program Files (x86)\Opera O43 - CFD: 30.05.2014 - 18:45:08 - [] ----D C:\Program Files (x86)\Pamela O43 - CFD: 09.03.2015 - 12:12:43 - [] ----D C:\Program Files (x86)\Parom.TV O43 - CFD: 12.11.2013 - 1:27:29 - [] ----D C:\Program Files (x86)\PDF Architect O43 - CFD: 30.10.2013 - 9:03:37 - [] ----D C:\Program Files (x86)\PDF Unlocker O43 - CFD: 23.04.2013 - 10:20:56 - [] ----D C:\Program Files (x86)\Philips O43 - CFD: 01.04.2012 - 1:10:01 - [] ----D C:\Program Files (x86)\PIMOne O43 - CFD: 09.06.2013 - 21:48:02 - [] ----D C:\Program Files (x86)\QTTabBar O43 - CFD: 29.05.2013 - 13:31:04 - [] ----D C:\Program Files (x86)\QuickTime O43 - CFD: 12.07.2014 - 18:38:21 - [0] ----D C:\Program Files (x86)\RayV O43 - CFD: 16.12.2014 - 0:53:48 - [] ----D C:\Program Files (x86)\Realtek O43 - CFD: 14.07.2009 - 6:32:38 - [] ----D C:\Program Files (x86)\Reference Assemblies O43 - CFD: 10.09.2014 - 23:40:42 - [] ----D C:\Program Files (x86)\Reg Organizer O43 - CFD: 18.02.2013 - 18:55:59 - [] ----D C:\Program Files (x86)\Roadkil.Net O43 - CFD: 28.11.2012 - 15:29:12 - [] ----D C:\Program Files (x86)\rue des йcoles O43 - CFD: 28.04.2013 - 16:29:30 - [] ----D C:\Program Files (x86)\Rumote O43 - CFD: 24.11.2014 - 22:53:03 - [] ----D C:\Program Files (x86)\Samsung O43 - CFD: 08.06.2013 - 18:16:08 - [] ----D C:\Program Files (x86)\Scanitto O43 - CFD: 05.06.2013 - 22:16:30 - [] ----D C:\Program Files (x86)\Secunia O43 - CFD: 05.02.2013 - 17:50:29 - [] ----D C:\Program Files (x86)\SimpleTV O43 - CFD: 31.01.2013 - 13:23:20 - [] ----D C:\Program Files (x86)\SimpleTV047r2 O43 - CFD: 18.02.2015 - 19:30:35 - [] R---D C:\Program Files (x86)\Skype O43 - CFD: 12.12.2013 - 23:30:30 - [] ----D C:\Program Files (x86)\SlimDrivers O43 - CFD: 30.06.2013 - 10:15:52 - [0] ----D C:\Program Files (x86)\SmElis O43 - CFD: 02.04.2012 - 3:40:22 - [] ----D C:\Program Files (x86)\Soldier of Fortune Payback O43 - CFD: 31.10.2013 - 21:18:34 - [] ----D C:\Program Files (x86)\SolidDocuments O43 - CFD: 07.03.2015 - 1:54:25 - [] ----D C:\Program Files (x86)\SopCast O43 - CFD: 01.09.2014 - 13:12:33 - [] ----D C:\Program Files (x86)\Stardock O43 - CFD: 01.07.2013 - 14:45:25 - [0] ----D C:\Program Files (x86)\Stardvb O43 - CFD: 18.06.2013 - 13:06:05 - [0] ----D C:\Program Files (x86)\stinger O43 - CFD: 10.12.2012 - 19:14:02 - [] ----D C:\Program Files (x86)\StreamingStar O43 - CFD: 06.05.2014 - 11:12:40 - [] ----D C:\Program Files (x86)\StreamTransport O43 - CFD: 07.03.2015 - 18:12:32 - [] ----D C:\Program Files (x86)\System Explorer O43 - CFD: 10.09.2013 - 21:33:55 - [] ----D C:\Program Files (x86)\Team MediaPortal O43 - CFD: 03.11.2013 - 22:43:10 - [] ----D C:\Program Files (x86)\Teleport Ultra O43 - CFD: 08.09.2014 - 13:00:02 - [0] --H-D C:\Program Files (x86)\Temp O43 - CFD: 14.07.2009 - 5:57:06 - [0] --H-D C:\Program Files (x86)\Uninstall Information O43 - CFD: 02.04.2012 - 3:29:45 - [] ----D C:\Program Files (x86)\Unlocker O43 - CFD: 08.09.2014 - 12:04:32 - [] ----D C:\Program Files (x86)\URLSnooper2 O43 - CFD: 29.03.2012 - 2:55:37 - [] ----D C:\Program Files (x86)\VideoLAN O43 - CFD: 21.11.2014 - 20:51:15 - [] ----D C:\Program Files (x86)\VMware O43 - CFD: 30.12.2013 - 13:35:41 - [] ----D C:\Program Files (x86)\Web Solution Mart O43 - CFD: 25.07.2014 - 17:17:41 - [] ----D C:\Program Files (x86)\WhiteHat O43 - CFD: 10.07.2013 - 2:04:37 - [] ----D C:\Program Files (x86)\Windows Defender O43 - CFD: 19.10.2013 - 12:00:30 - [] ----D C:\Program Files (x86)\Windows Live O43 - CFD: 12.04.2011 - 10:16:36 - [] ----D C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation O43 - CFD: 15.10.2014 - 7:53:21 - [] ----D C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation O43 - CFD: 29.05.2013 - 12:15:37 - [] ----D C:\Program Files (x86)\Windows Media Player Plus! =>.Microsoft Corporation O43 - CFD: 14.07.2009 - 6:32:38 - [] ----D C:\Program Files (x86)\Windows NT O43 - CFD: 12.04.2011 - 10:16:36 - [] ----D C:\Program Files (x86)\Windows Photo Viewer O43 - CFD: 21.11.2010 - 4:31:38 - [] ----D C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 12.04.2011 - 10:16:36 - [] ----D C:\Program Files (x86)\Windows Sidebar O43 - CFD: 08.09.2014 - 12:04:57 - [] ----D C:\Program Files (x86)\WinPcap O43 - CFD: 12.08.2014 - 10:58:17 - [] ----D C:\Program Files (x86)\WinTV O43 - CFD: 23.04.2014 - 19:14:26 - [] ----D C:\Program Files (x86)\WOT O43 - CFD: 25.08.2013 - 8:29:49 - [] ----D C:\Program Files (x86)\XBMC O43 - CFD: 08.12.2012 - 23:54:39 - [0] ----D C:\Program Files (x86)\Xenocode O43 - CFD: 28.09.2013 - 19:30:36 - [] ----D C:\Program Files (x86)\Zattoo4 O43 - CFD: 09.03.2015 - 21:32:59 - [] ----D C:\Program Files (x86)\ZHPDiag =>.Nicolas Coolman O43 - CFD: 28.03.2012 - 23:54:20 - [] ----D C:\Program Files (x86)\Common Files\ABBYY O43 - CFD: 12.11.2013 - 23:39:17 - [] ----D C:\Program Files (x86)\Common Files\ACD Systems O43 - CFD: 09.06.2013 - 0:14:18 - [] ----D C:\Program Files (x86)\Common Files\Acro Software O43 - CFD: 18.05.2014 - 1:23:39 - [] ----D C:\Program Files (x86)\Common Files\Adobe O43 - CFD: 12.11.2014 - 12:13:37 - [] ----D C:\Program Files (x86)\Common Files\Adobe AIR O43 - CFD: 11.11.2013 - 13:25:55 - [] ----D C:\Program Files (x86)\Common Files\Ahead O43 - CFD: 08.06.2014 - 17:30:11 - [] ----D C:\Program Files (x86)\Common Files\Apple O43 - CFD: 23.04.2013 - 10:24:34 - [] ----D C:\Program Files (x86)\Common Files\ArcSoft O43 - CFD: 30.08.2013 - 22:46:34 - [] ----D C:\Program Files (x86)\Common Files\AVSMedia O43 - CFD: 27.06.2012 - 9:42:06 - [] ----D C:\Program Files (x86)\Common Files\Borland Shared O43 - CFD: 30.05.2012 - 23:41:09 - [] ----D C:\Program Files (x86)\Common Files\Common Share O43 - CFD: 14.05.2014 - 16:26:45 - [] ----D C:\Program Files (x86)\Common Files\DESIGNER O43 - CFD: 26.09.2013 - 22:37:55 - [] ----D C:\Program Files (x86)\Common Files\DivX Shared O43 - CFD: 28.03.2012 - 23:49:48 - [] ----D C:\Program Files (x86)\Common Files\EPSON O43 - CFD: 31.08.2013 - 20:49:24 - [] ----D C:\Program Files (x86)\Common Files\FotoNation O43 - CFD: 29.01.2015 - 21:29:14 - [] ----D C:\Program Files (x86)\Common Files\InstallShield O43 - CFD: 08.03.2015 - 11:24:58 - [] ----D C:\Program Files (x86)\Common Files\IObit O43 - CFD: 12.11.2014 - 12:13:48 - [] ----D C:\Program Files (x86)\Common Files\Java O43 - CFD: 28.04.2013 - 22:30:06 - [0] ----D C:\Program Files (x86)\Common Files\Makayama O43 - CFD: 19.10.2013 - 11:58:20 - [] ----D C:\Program Files (x86)\Common Files\microsoft shared O43 - CFD: 12.11.2013 - 1:28:18 - [] ----D C:\Program Files (x86)\Common Files\PDF Architect O43 - CFD: 26.05.2012 - 2:30:21 - [] ----D C:\Program Files (x86)\Common Files\PX Storage Engine O43 - CFD: 14.07.2009 - 4:20:08 - [] ----D C:\Program Files (x86)\Common Files\Services O43 - CFD: 31.08.2013 - 20:13:54 - [] ----D C:\Program Files (x86)\Common Files\Simple Star Shared O43 - CFD: 21.12.2014 - 1:06:01 - [] ----D C:\Program Files (x86)\Common Files\Skype O43 - CFD: 14.07.2009 - 4:20:08 - [] ----D C:\Program Files (x86)\Common Files\SpeechEngines O43 - CFD: 12.07.2012 - 2:05:14 - [] ----D C:\Program Files (x86)\Common Files\System O43 - CFD: 21.11.2014 - 20:51:15 - [] ----D C:\Program Files (x86)\Common Files\VMware O43 - CFD: 30.12.2013 - 13:34:40 - [] ----D C:\Program Files (x86)\Common Files\Web Solution Mart O43 - CFD: 07.05.2012 - 0:37:50 - [] ----D C:\Program Files (x86)\Common Files\Windows Live O43 - CFD: 27.05.2013 - 20:51:18 - [] ----D C:\Program Files (x86)\Common Files\Wise Installation Wizard O43 - CFD: 08.06.2014 - 17:30:11 - [] ----D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 O43 - CFD: 27.06.2012 - 10:22:31 - [] ----D C:\ProgramData\ABBYY O43 - CFD: 12.11.2013 - 23:11:31 - [] ----D C:\ProgramData\ACD Systems O43 - CFD: 15.08.2013 - 15:43:53 - [] ----D C:\ProgramData\Acunetix WVS 8 O43 - CFD: 27.11.2012 - 0:13:40 - [] ----D C:\ProgramData\AdFender O43 - CFD: 06.12.2013 - 14:42:33 - [] ----D C:\ProgramData\Adguard O43 - CFD: 21.07.2014 - 21:34:16 - [] ----D C:\ProgramData\Adobe O43 - CFD: 17.02.2014 - 12:22:50 - [] ----D C:\ProgramData\Apple O43 - CFD: 14.07.2009 - 6:08:56 - [] -SH-D C:\ProgramData\Application Data O43 - CFD: 31.08.2013 - 20:23:33 - [] ----D C:\ProgramData\AVS4YOU O43 - CFD: 02.05.2012 - 23:04:52 - [] ----D C:\ProgramData\BlazeVideo O43 - CFD: 27.07.2013 - 0:16:25 - [] ----D C:\ProgramData\Blue Ridge Networks O43 - CFD: 23.06.2013 - 19:43:54 - [] ----D C:\ProgramData\BlueStacksSetup O43 - CFD: 28.03.2012 - 11:55:58 - [] -SH-D C:\ProgramData\Bureau O43 - CFD: 14.12.2014 - 1:41:20 - [0] ----D C:\ProgramData\Camfrog Update O43 - CFD: 09.06.2013 - 20:00:32 - [] ----D C:\ProgramData\Caminova O43 - CFD: 06.12.2012 - 10:22:01 - [] ----D C:\ProgramData\Canneverbe Limited O43 - CFD: 12.11.2013 - 23:11:44 - [] ----D C:\ProgramData\Caphyon O43 - CFD: 06.03.2015 - 10:02:23 - [] ----D C:\ProgramData\cmcm O43 - CFD: 27.11.2012 - 23:13:43 - [0] ----D C:\ProgramData\CMUV O43 - CFD: 25.06.2013 - 21:41:55 - [] --H-D C:\ProgramData\Common Files O43 - CFD: 27.11.2012 - 23:08:55 - [] ----D C:\ProgramData\DBC2F6FD-3140-41E0-A2A1-D6BAB77D5E21__F893F7CA-8278-41DF-A76F-CAF0437A90CD__ O43 - CFD: 14.07.2009 - 6:08:56 - [] -SH-D C:\ProgramData\Desktop O43 - CFD: 18.09.2014 - 18:28:01 - [] ----D C:\ProgramData\DivX O43 - CFD: 14.07.2009 - 6:08:56 - [] -SH-D C:\ProgramData\Documents O43 - CFD: 12.05.2012 - 23:21:52 - [] ----D C:\ProgramData\DonationCoder O43 - CFD: 24.03.2013 - 9:33:37 - [] ----D C:\ProgramData\EPSON O43 - CFD: 28.03.2012 - 11:55:58 - [] -SH-D C:\ProgramData\Favoris O43 - CFD: 14.07.2009 - 6:08:56 - [] -SH-D C:\ProgramData\Favorites O43 - CFD: 29.03.2012 - 2:08:12 - [] ----D C:\ProgramData\Google O43 - CFD: 12.08.2014 - 10:59:36 - [] ----D C:\ProgramData\Hauppauge O43 - CFD: 08.09.2014 - 14:09:40 - [] ----D C:\ProgramData\Intel O43 - CFD: 08.03.2015 - 12:30:11 - [] ----D C:\ProgramData\IObit O43 - CFD: 05.10.2014 - 11:15:18 - [] ----D C:\ProgramData\IP-TV Player O43 - CFD: 11.02.2013 - 2:55:12 - [] ----D C:\ProgramData\IPTV Distribution O43 - CFD: 25.08.2013 - 10:00:06 - [] ----D C:\ProgramData\IR Server Suite O43 - CFD: 18.12.2012 - 0:04:28 - [] ----D C:\ProgramData\Kaspersky Lab O43 - CFD: 06.03.2015 - 10:02:23 - [] ----D C:\ProgramData\Kingsoft O43 - CFD: 27.11.2012 - 22:54:46 - [] ----D C:\ProgramData\Kristanix Games O43 - CFD: 02.12.2012 - 11:03:33 - [] ----D C:\ProgramData\Lavasoft O43 - CFD: 06.09.2014 - 22:25:04 - [] ----D C:\ProgramData\Licenses O43 - CFD: 06.09.2014 - 22:25:04 - [] ----D C:\ProgramData\Logs O43 - CFD: 10.08.2014 - 9:22:24 - [] ----D C:\ProgramData\ma-config.com O43 - CFD: 23.04.2014 - 16:40:41 - [] ----D C:\ProgramData\Malwarebytes O43 - CFD: 08.06.2013 - 18:16:14 - [] ----D C:\ProgramData\Masters ITC O43 - CFD: 21.06.2013 - 0:24:29 - [] ----D C:\ProgramData\McAfee O43 - CFD: 25.08.2013 - 10:12:54 - [] ----D C:\ProgramData\MDAPI_Plus O43 - CFD: 28.03.2012 - 11:55:58 - [] -SH-D C:\ProgramData\Menu Démarrer O43 - CFD: 11.12.2014 - 0:33:17 - [] -S--D C:\ProgramData\Microsoft O43 - CFD: 12.02.2015 - 0:52:58 - [] ----D C:\ProgramData\Microsoft Help O43 - CFD: 19.10.2013 - 11:54:57 - [] ----D C:\ProgramData\Microsoft SkyDrive =>.Microsoft Corporation O43 - CFD: 28.03.2012 - 11:55:58 - [] -SH-D C:\ProgramData\Modèles O43 - CFD: 09.03.2015 - 1:15:17 - [0] ----D C:\ProgramData\Mozilla O43 - CFD: 24.08.2013 - 22:49:06 - [] ----D C:\ProgramData\MySQL O43 - CFD: 07.06.2013 - 21:00:39 - [] ----D C:\ProgramData\Nuance O43 - CFD: 24.02.2013 - 1:37:09 - [] ----D C:\ProgramData\NVIDIA O43 - CFD: 28.03.2012 - 14:18:02 - [] ----D C:\ProgramData\NVIDIA Corporation O43 - CFD: 12.11.2014 - 12:12:55 - [] ----D C:\ProgramData\Oracle O43 - CFD: 07.03.2015 - 18:50:59 - [] ----D C:\ProgramData\Package Cache O43 - CFD: 23.06.2013 - 19:37:45 - [] ----D C:\ProgramData\PDF Writer O43 - CFD: 14.09.2013 - 0:53:03 - [] ----D C:\ProgramData\Pinnacle O43 - CFD: 02.05.2012 - 23:08:18 - [] ----D C:\ProgramData\Plugins O43 - CFD: 26.05.2013 - 13:30:54 - [0] ----D C:\ProgramData\ProcessLasso O43 - CFD: 07.03.2015 - 18:43:45 - [] ----D C:\ProgramData\ProductData O43 - CFD: 16.11.2013 - 21:58:42 - [] ----D C:\ProgramData\RonyaSoft O43 - CFD: 10.08.2014 - 11:18:16 - [] ----D C:\ProgramData\Samsung O43 - CFD: 06.03.2015 - 10:31:54 - [0] ----D C:\ProgramData\Skype O43 - CFD: 30.10.2013 - 9:06:51 - [] ----D C:\ProgramData\SolidDocuments O43 - CFD: 01.09.2014 - 13:12:41 - [] ----D C:\ProgramData\Stardock O43 - CFD: 14.07.2009 - 6:08:56 - [] -SH-D C:\ProgramData\Start Menu O43 - CFD: 01.08.2014 - 7:33:00 - [] ----D C:\ProgramData\SystemExplorer O43 - CFD: 24.08.2013 - 22:49:27 - [] ----D C:\ProgramData\Team MediaPortal O43 - CFD: 09.03.2015 - 8:12:30 - [] ---AD C:\ProgramData\TEMP O43 - CFD: 14.07.2009 - 6:08:56 - [] -SH-D C:\ProgramData\Templates O43 - CFD: 25.06.2013 - 22:33:26 - [] ----D C:\ProgramData\TuneUp Software O43 - CFD: 28.03.2012 - 23:52:52 - [] ----D C:\ProgramData\UDL O43 - CFD: 09.03.2015 - 8:10:33 - [] ----D C:\ProgramData\VMware O43 - CFD: 22.06.2013 - 1:01:57 - [] ----D C:\ProgramData\VSO O43 - CFD: 30.03.2012 - 3:53:42 - [] ----D C:\ProgramData\Windows Genuine Advantage O43 - CFD: 25.06.2013 - 22:06:35 - [0] ----D C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} O43 - CFD: 08.03.2015 - 11:24:59 - [] ----D C:\ProgramData\{ACBCD40A-42A8-4FF9-BD42-ABCD14998CBA} O43 - CFD: 25.06.2013 - 22:06:35 - [0] -SH-D C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} O43 - CFD: 08.03.2015 - 11:24:59 - [] ----D C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690} O43 - CFD: 02.04.2012 - 3:40:23 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\1C O43 - CFD: 26.02.2015 - 21:26:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Download O43 - CFD: 19.12.2013 - 13:14:26 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4t Tray Minimizer O43 - CFD: 08.03.2015 - 23:12:46 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip O43 - CFD: 28.03.2012 - 23:54:53 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 9.0 Sprint O43 - CFD: 10.11.2012 - 11:48:35 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 12.11.2013 - 23:39:13 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems O43 - CFD: 16.11.2013 - 18:50:22 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acunetix Web Vulnerability Scanner 8 O43 - CFD: 27.11.2012 - 0:13:40 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdFender O43 - CFD: 06.12.2013 - 14:42:13 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adguard O43 - CFD: 14.12.2012 - 19:08:35 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 17.06.2013 - 22:58:55 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 64-bit fixes O43 - CFD: 10.09.2014 - 15:56:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnVir Task Manager O43 - CFD: 12.06.2013 - 7:31:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\APC O43 - CFD: 25.04.2012 - 19:30:56 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Applian Technologies =>PUP.ApplianTechnologies O43 - CFD: 24.06.2013 - 13:50:07 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASCOMP Software O43 - CFD: 28.04.2013 - 19:53:45 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo O43 - CFD: 02.05.2012 - 23:04:51 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlazeVideo HDTV Player 6.6 Pro O43 - CFD: 23.06.2013 - 19:37:46 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bullzip O43 - CFD: 05.04.2012 - 1:10:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Menu for Office O43 - CFD: 06.03.2015 - 10:02:22 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clean Master O43 - CFD: 05.09.2014 - 15:31:03 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clover O43 - CFD: 05.09.2014 - 18:40:27 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo O43 - CFD: 10.09.2014 - 23:31:14 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID O43 - CFD: 25.06.2013 - 0:04:03 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crystal TV O43 - CFD: 05.09.2014 - 18:44:04 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF O43 - CFD: 14.12.2014 - 0:36:22 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daum O43 - CFD: 10.09.2012 - 2:01:43 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daum PotPlayer x64 O43 - CFD: 18.09.2014 - 18:27:52 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX O43 - CFD: 11.07.2012 - 0:39:38 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DjVuLibre O43 - CFD: 19.12.2014 - 0:25:56 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverMax O43 - CFD: 04.12.2013 - 10:35:31 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON O43 - CFD: 28.03.2012 - 23:52:52 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson Software O43 - CFD: 25.06.2013 - 22:06:16 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Explorer Toolbar Editor O43 - CFD: 08.03.2015 - 11:12:11 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eyeball Chat O43 - CFD: 30.12.2013 - 13:34:41 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fake Webcam 7.3 O43 - CFD: 08.09.2014 - 11:14:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow x64 O43 - CFD: 09.06.2013 - 0:14:19 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FormMax Filler O43 - CFD: 27.06.2013 - 18:30:42 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Folder Hider O43 - CFD: 09.03.2015 - 2:42:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FVD Suite IE Plugin O43 - CFD: 30.10.2013 - 13:52:04 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 28.02.2015 - 0:59:46 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Geotag Security O43 - CFD: 09.03.2015 - 2:42:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 22.11.2013 - 23:36:11 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\H.264 Encoder O43 - CFD: 12.08.2014 - 10:59:28 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hauppauge WinTV O43 - CFD: 08.03.2015 - 18:24:44 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. Applications O43 - CFD: 28.03.2012 - 12:02:11 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel O43 - CFD: 08.03.2015 - 11:25:07 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller O43 - CFD: 25.08.2013 - 10:00:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IR Server Suite O43 - CFD: 12.11.2014 - 12:13:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java O43 - CFD: 15.07.2013 - 20:02:07 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K!TV O43 - CFD: 08.07.2013 - 9:25:42 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Meleon O43 - CFD: 31.08.2013 - 20:50:26 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kazoo Player O43 - CFD: 30.11.2014 - 19:36:21 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lunascape6 O43 - CFD: 10.08.2014 - 9:22:26 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ma-config.com O43 - CFD: 14.07.2009 - 5:57:09 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 04.12.2014 - 21:04:04 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware O43 - CFD: 08.06.2013 - 18:16:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Masters ITC O43 - CFD: 04.04.2013 - 0:08:19 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MaxTV O43 - CFD: 25.08.2013 - 10:12:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MDAPI_Plus O43 - CFD: 13.09.2013 - 7:21:17 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office O43 - CFD: 25.07.2014 - 1:20:57 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight O43 - CFD: 12.01.2013 - 14:27:25 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works O43 - CFD: 14.08.2014 - 21:17:34 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mindscape O43 - CFD: 06.08.2012 - 22:53:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Monkey's Audio O43 - CFD: 01.02.2015 - 13:46:28 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag O43 - CFD: 25.12.2012 - 23:42:20 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec O43 - CFD: 24.08.2013 - 22:49:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MySQL O43 - CFD: 11.11.2013 - 13:25:52 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition O43 - CFD: 06.09.2014 - 22:24:57 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Office Tab O43 - CFD: 08.03.2015 - 18:35:48 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ooVoo O43 - CFD: 30.07.2013 - 10:42:05 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office O43 - CFD: 30.05.2014 - 18:45:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pamela O43 - CFD: 09.06.2013 - 22:02:12 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Parom.TV O43 - CFD: 12.11.2013 - 1:27:27 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect O43 - CFD: 29.01.2015 - 14:11:41 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator O43 - CFD: 23.04.2013 - 10:24:34 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Philips SPC 900NC PC Camera O43 - CFD: 01.04.2012 - 1:07:55 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PIMOne O43 - CFD: 01.09.2013 - 3:00:34 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProgDVB O43 - CFD: 29.01.2015 - 14:13:11 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime O43 - CFD: 10.09.2014 - 23:40:42 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reg Organizer O43 - CFD: 18.02.2013 - 18:55:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roadkil.Net O43 - CFD: 28.11.2012 - 15:29:31 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\rue des йcoles O43 - CFD: 28.04.2013 - 16:29:32 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rumote O43 - CFD: 23.05.2013 - 18:59:07 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RunMe O43 - CFD: 24.11.2014 - 22:53:01 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung O43 - CFD: 08.07.2013 - 9:46:31 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scan Tailor O43 - CFD: 13.12.2012 - 21:38:16 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SiSoftware O43 - CFD: 21.12.2014 - 1:06:01 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype O43 - CFD: 12.12.2013 - 23:30:30 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers O43 - CFD: 31.10.2013 - 21:18:43 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidDocuments O43 - CFD: 29.04.2012 - 16:17:40 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast O43 - CFD: 01.09.2014 - 13:12:35 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock O43 - CFD: 06.11.2014 - 20:07:44 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 10.12.2012 - 19:14:02 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StreamingStar O43 - CFD: 06.05.2014 - 11:12:36 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StreamTransport O43 - CFD: 07.03.2015 - 18:12:31 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Explorer O43 - CFD: 12.04.2011 - 10:27:52 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 03.11.2013 - 22:43:10 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Teleport Ultra O43 - CFD: 31.08.2013 - 22:07:32 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TELL ME MORE SI PLUS O43 - CFD: 12.01.2014 - 12:13:42 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy O43 - CFD: 07.09.2014 - 20:51:51 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uninstall Tool O43 - CFD: 16.11.2013 - 0:55:36 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN O43 - CFD: 19.10.2013 - 12:01:04 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live O43 - CFD: 01.07.2013 - 19:34:43 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap O43 - CFD: 08.09.2014 - 11:15:00 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 07.03.2015 - 17:52:05 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare O43 - CFD: 28.09.2013 - 19:30:36 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zattoo4 O43 - CFD: 09.03.2015 - 21:32:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP =>.Nicolas Coolman O43 - CFD: 28.02.2015 - 14:59:04 - [] ----D C:\Users\GELO\AppData\Roaming\.ACEStream O43 - CFD: 24.10.2013 - 23:48:49 - [] ----D C:\Users\GELO\AppData\Roaming\.Torrent Stream O43 - CFD: 12.12.2012 - 0:43:33 - [] ----D C:\Users\GELO\AppData\Roaming\4t Niagara Software O43 - CFD: 29.07.2013 - 23:48:46 - [0] ----D C:\Users\GELO\AppData\Roaming\4Team O43 - CFD: 10.06.2012 - 3:11:30 - [] ----D C:\Users\GELO\AppData\Roaming\ABBYY O43 - CFD: 30.01.2015 - 12:51:57 - [] ----D C:\Users\GELO\AppData\Roaming\AC3Filter O43 - CFD: 22.04.2012 - 19:15:48 - [] ----D C:\Users\GELO\AppData\Roaming\ACD Systems O43 - CFD: 12.11.2013 - 23:01:14 - [] ----D C:\Users\GELO\AppData\Roaming\ACD Systems International Inc O43 - CFD: 08.01.2015 - 20:29:02 - [] ----D C:\Users\GELO\AppData\Roaming\ACEStream O43 - CFD: 28.02.2015 - 14:59:04 - [] ----D C:\Users\GELO\AppData\Roaming\AceWebExtension O43 - CFD: 21.07.2014 - 21:34:16 - [] ----D C:\Users\GELO\AppData\Roaming\Adobe O43 - CFD: 16.11.2013 - 14:12:33 - [] ----D C:\Users\GELO\AppData\Roaming\Ahead O43 - CFD: 15.09.2013 - 16:58:43 - [] ----D C:\Users\GELO\AppData\Roaming\Alp-Software O43 - CFD: 23.05.2013 - 18:57:58 - [] ----D C:\Users\GELO\AppData\Roaming\App Launcher Gadget O43 - CFD: 08.03.2015 - 11:25:06 - [] ----D C:\Users\GELO\AppData\Roaming\Apple Computer O43 - CFD: 25.07.2014 - 20:40:58 - [] ----D C:\Users\GELO\AppData\Roaming\Applian FLV and Media Player =>PUP.ApplianTechnologies O43 - CFD: 27.11.2012 - 23:27:02 - [] ----D C:\Users\GELO\AppData\Roaming\APP_NAME_NON_STRING O43 - CFD: 23.04.2013 - 10:30:31 - [] ----D C:\Users\GELO\AppData\Roaming\ArcSoft O43 - CFD: 24.06.2013 - 13:50:24 - [] ----D C:\Users\GELO\AppData\Roaming\ASCOMP Software O43 - CFD: 30.06.2013 - 11:15:42 - [] ----D C:\Users\GELO\AppData\Roaming\AtslegSoft O43 - CFD: 19.11.2012 - 23:02:37 - [] ----D C:\Users\GELO\AppData\Roaming\Auslogics O43 - CFD: 02.03.2014 - 1:44:42 - [0] ----D C:\Users\GELO\AppData\Roaming\AutoUpdate O43 - CFD: 12.11.2012 - 14:41:08 - [] ----D C:\Users\GELO\AppData\Roaming\Avant Profiles O43 - CFD: 25.12.2013 - 11:41:35 - [] ----D C:\Users\GELO\AppData\Roaming\Avery O43 - CFD: 31.08.2013 - 20:23:34 - [] ----D C:\Users\GELO\AppData\Roaming\AVS4YOU O43 - CFD: 30.08.2012 - 2:17:30 - [] ----D C:\Users\GELO\AppData\Roaming\BerezaTV O43 - CFD: 08.03.2015 - 11:20:30 - [] ----D C:\Users\GELO\AppData\Roaming\BExplorer O43 - CFD: 27.07.2013 - 0:20:08 - [] ----D C:\Users\GELO\AppData\Roaming\blue ridge networks O43 - CFD: 05.10.2014 - 13:37:20 - [] ----D C:\Users\GELO\AppData\Roaming\BSplayer O43 - CFD: 08.03.2015 - 11:21:17 - [] ----D C:\Users\GELO\AppData\Roaming\Camfrog O43 - CFD: 01.02.2014 - 21:04:04 - [] ----D C:\Users\GELO\AppData\Roaming\Camfrog Web O43 - CFD: 06.12.2012 - 10:22:00 - [] ----D C:\Users\GELO\AppData\Roaming\Canneverbe Limited O43 - CFD: 10.09.2014 - 23:40:48 - [] ----D C:\Users\GELO\AppData\Roaming\ChemTable Software O43 - CFD: 21.07.2014 - 21:39:51 - [] ----D C:\Users\GELO\AppData\Roaming\com.zoosk.Desktop O43 - CFD: 21.07.2014 - 21:39:52 - [] ----D C:\Users\GELO\AppData\Roaming\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1 O43 - CFD: 25.11.2012 - 23:54:44 - [] ----D C:\Users\GELO\AppData\Roaming\Comodo O43 - CFD: 05.09.2014 - 15:42:45 - [] ----D C:\Users\GELO\AppData\Roaming\CrystalIdea Software O43 - CFD: 08.09.2014 - 1:13:31 - [] ----D C:\Users\GELO\AppData\Roaming\CrystalTV O43 - CFD: 27.11.2012 - 23:08:55 - [] ----D C:\Users\GELO\AppData\Roaming\DBC2F6FD-3140-41E0-A2A1-D6BAB77D5E21__F893F7CA-8278-41DF-A76F-CAF0437A90CD__ O43 - CFD: 30.04.2013 - 19:31:25 - [] ----D C:\Users\GELO\AppData\Roaming\DivX O43 - CFD: 12.05.2012 - 23:21:22 - [] ----D C:\Users\GELO\AppData\Roaming\DonationCoder O43 - CFD: 21.12.2012 - 0:28:02 - [] ----D C:\Users\GELO\AppData\Roaming\Dropbox O43 - CFD: 15.07.2013 - 23:02:48 - [] ----D C:\Users\GELO\AppData\Roaming\DScaler4 O43 - CFD: 08.09.2014 - 18:09:53 - [] ----D C:\Users\GELO\AppData\Roaming\dvdcss O43 - CFD: 08.06.2013 - 23:25:08 - [] ----D C:\Users\GELO\AppData\Roaming\Easy Image Modifier O43 - CFD: 24.03.2013 - 9:33:37 - [] ----D C:\Users\GELO\AppData\Roaming\Epson O43 - CFD: 10.06.2013 - 7:33:17 - [] ----D C:\Users\GELO\AppData\Roaming\Foxit Software O43 - CFD: 26.05.2013 - 12:43:30 - [] ----D C:\Users\GELO\AppData\Roaming\FreshDiagnose O43 - CFD: 07.08.2012 - 12:26:38 - [] ----D C:\Users\GELO\AppData\Roaming\FVDIEPlugin O43 - CFD: 09.12.2012 - 0:19:26 - [] ----D C:\Users\GELO\AppData\Roaming\Geek Uninstaller O43 - CFD: 14.03.2013 - 20:08:12 - [] ----D C:\Users\GELO\AppData\Roaming\goalbit O43 - CFD: 05.11.2012 - 22:03:44 - [] ----D C:\Users\GELO\AppData\Roaming\Google O43 - CFD: 12.12.2012 - 13:50:57 - [] ----D C:\Users\GELO\AppData\Roaming\Haihaisoft PDF Reader O43 - CFD: 27.11.2012 - 22:50:39 - [] ----D C:\Users\GELO\AppData\Roaming\HTML Executable O43 - CFD: 07.03.2015 - 18:37:39 - [] ----D C:\Users\GELO\AppData\Roaming\ICQ-Profile O43 - CFD: 07.03.2015 - 18:37:53 - [] ----D C:\Users\GELO\AppData\Roaming\ICQM O43 - CFD: 03.06.2013 - 17:12:20 - [] ----D C:\Users\GELO\AppData\Roaming\ID3 renamer O43 - CFD: 28.03.2012 - 11:56:18 - [] ----D C:\Users\GELO\AppData\Roaming\Identities O43 - CFD: 18.06.2013 - 13:30:15 - [] ----D C:\Users\GELO\AppData\Roaming\ImgBurn O43 - CFD: 19.12.2014 - 0:25:58 - [] ----D C:\Users\GELO\AppData\Roaming\Innovative Solutions O43 - CFD: 04.10.2013 - 14:31:25 - [] ----D C:\Users\GELO\AppData\Roaming\Insoft LLC O43 - CFD: 28.03.2012 - 12:02:02 - [] ----D C:\Users\GELO\AppData\Roaming\InstallShield O43 - CFD: 08.03.2015 - 12:12:30 - [] ----D C:\Users\GELO\AppData\Roaming\IObit O43 - CFD: 25.11.2012 - 22:47:25 - [0] ----D C:\Users\GELO\AppData\Roaming\IP-TV Player O43 - CFD: 30.01.2015 - 18:08:38 - [] ----D C:\Users\GELO\AppData\Roaming\IRISPen O43 - CFD: 29.01.2015 - 22:30:48 - [] ----D C:\Users\GELO\AppData\Roaming\IrisPen6 O43 - CFD: 08.07.2013 - 9:37:46 - [] ----D C:\Users\GELO\AppData\Roaming\K-Meleon O43 - CFD: 23.05.2013 - 20:09:20 - [] ----D C:\Users\GELO\AppData\Roaming\Kartina.TV O43 - CFD: 27.11.2012 - 21:56:01 - [] ----D C:\Users\GELO\AppData\Roaming\KastorStreamRecorder O43 - CFD: 22.06.2012 - 2:39:43 - [] ----D C:\Users\GELO\AppData\Roaming\KC Softwares O43 - CFD: 13.12.2012 - 1:17:00 - [] ----D C:\Users\GELO\AppData\Roaming\KillProcess O43 - CFD: 02.12.2012 - 11:06:40 - [] ----D C:\Users\GELO\AppData\Roaming\LavasoftStatistics O43 - CFD: 26.10.2014 - 17:59:54 - [] ----D C:\Users\GELO\AppData\Roaming\livestreamer O43 - CFD: 12.11.2012 - 15:55:41 - [] ----D C:\Users\GELO\AppData\Roaming\Lunascape O43 - CFD: 28.03.2012 - 15:11:44 - [] ----D C:\Users\GELO\AppData\Roaming\Macromedia O43 - CFD: 28.04.2013 - 22:28:20 - [] ----D C:\Users\GELO\AppData\Roaming\Makayama O43 - CFD: 23.04.2014 - 16:40:49 - [0] ----D C:\Users\GELO\AppData\Roaming\Malwarebytes O43 - CFD: 03.01.2014 - 0:27:06 - [] ----D C:\Users\GELO\AppData\Roaming\ManyCam O43 - CFD: 12.04.2012 - 23:35:30 - [] ----D C:\Users\GELO\AppData\Roaming\Marine Aquarium 3 O43 - CFD: 14.11.2012 - 15:13:11 - [] ----D C:\Users\GELO\AppData\Roaming\Maxthon3 O43 - CFD: 04.04.2013 - 0:10:11 - [] ----D C:\Users\GELO\AppData\Roaming\MaxTV Technologies O43 - CFD: 12.04.2011 - 10:27:52 - [0] ----D C:\Users\GELO\AppData\Roaming\Media Center Programs O43 - CFD: 08.03.2015 - 11:34:54 - [] -S--D C:\Users\GELO\AppData\Roaming\Microsoft O43 - CFD: 30.05.2013 - 17:10:59 - [] ----D C:\Users\GELO\AppData\Roaming\MiniDm O43 - CFD: 25.08.2014 - 0:51:20 - [] ----D C:\Users\GELO\AppData\Roaming\Mozilla O43 - CFD: 01.02.2015 - 13:46:09 - [] ----D C:\Users\GELO\AppData\Roaming\Mp3tag O43 - CFD: 31.08.2013 - 23:26:19 - [] ----D C:\Users\GELO\AppData\Roaming\Nero O43 - CFD: 12.01.2013 - 4:07:37 - [] ----D C:\Users\GELO\AppData\Roaming\Notepad++ O43 - CFD: 07.06.2013 - 20:55:34 - [] ----D C:\Users\GELO\AppData\Roaming\Nuance O43 - CFD: 26.02.2015 - 21:25:35 - [] ----D C:\Users\GELO\AppData\Roaming\NVIDIA O43 - CFD: 05.09.2014 - 14:58:31 - [] ----D C:\Users\GELO\AppData\Roaming\Obnovi Soft O43 - CFD: 09.11.2014 - 20:53:34 - [] ----D C:\Users\GELO\AppData\Roaming\Octoshape O43 - CFD: 01.06.2013 - 10:25:24 - [] ----D C:\Users\GELO\AppData\Roaming\OfficeTab O43 - CFD: 26.11.2012 - 0:48:05 - [] ----D C:\Users\GELO\AppData\Roaming\Offline Explorer O43 - CFD: 15.01.2013 - 0:30:03 - [] ----D C:\Users\GELO\AppData\Roaming\ooVoo Details O43 - CFD: 19.08.2013 - 19:38:20 - [] ----D C:\Users\GELO\AppData\Roaming\Opera O43 - CFD: 03.07.2013 - 12:36:28 - [] ----D C:\Users\GELO\AppData\Roaming\Opera Software O43 - CFD: 28.12.2013 - 1:50:15 - [] ----D C:\Users\GELO\AppData\Roaming\Paltalk O43 - CFD: 31.05.2014 - 0:25:09 - [] ----D C:\Users\GELO\AppData\Roaming\Pamela O43 - CFD: 02.12.2012 - 2:23:55 - [] ----D C:\Users\GELO\AppData\Roaming\PDF Architect O43 - CFD: 12.11.2013 - 1:25:39 - [] ----D C:\Users\GELO\AppData\Roaming\PDF Software O43 - CFD: 23.06.2013 - 19:37:45 - [] ----D C:\Users\GELO\AppData\Roaming\PDF Writer O43 - CFD: 19.08.2012 - 21:18:44 - [] ----D C:\Users\GELO\AppData\Roaming\Pistonsoft O43 - CFD: 14.12.2014 - 0:39:27 - [] ----D C:\Users\GELO\AppData\Roaming\PotPlayerMini O43 - CFD: 28.04.2013 - 19:05:30 - [] ----D C:\Users\GELO\AppData\Roaming\PotPlayerMini64 O43 - CFD: 14.09.2013 - 1:18:30 - [] ----D C:\Users\GELO\AppData\Roaming\Pouchin TV Mod O43 - CFD: 26.05.2013 - 13:30:54 - [] ----D C:\Users\GELO\AppData\Roaming\ProcessLasso O43 - CFD: 08.03.2015 - 11:26:11 - [] ----D C:\Users\GELO\AppData\Roaming\ProductData O43 - CFD: 02.02.2015 - 13:57:43 - [] ----D C:\Users\GELO\AppData\Roaming\QIP O43 - CFD: 30.05.2012 - 23:03:15 - [] ----D C:\Users\GELO\AppData\Roaming\RayV O43 - CFD: 30.06.2013 - 11:31:33 - [] ----D C:\Users\GELO\AppData\Roaming\Resort Labs O43 - CFD: 25.01.2015 - 19:11:34 - [] ----D C:\Users\GELO\AppData\Roaming\Samsung O43 - CFD: 31.08.2013 - 20:19:39 - [0] ----D C:\Users\GELO\AppData\Roaming\Simple Star O43 - CFD: 14.09.2014 - 9:38:02 - [] ----D C:\Users\GELO\AppData\Roaming\SimpleTV V03 O43 - CFD: 09.03.2015 - 12:14:44 - [] ----D C:\Users\GELO\AppData\Roaming\Skype O43 - CFD: 20.06.2013 - 0:47:10 - [] ----D C:\Users\GELO\AppData\Roaming\Softland O43 - CFD: 14.07.2012 - 16:50:03 - [] ----D C:\Users\GELO\AppData\Roaming\Softplicity O43 - CFD: 01.11.2013 - 17:44:45 - [] ----D C:\Users\GELO\AppData\Roaming\SolidDocuments O43 - CFD: 01.09.2014 - 13:10:08 - [] ----D C:\Users\GELO\AppData\Roaming\Stardock O43 - CFD: 13.10.2014 - 20:50:43 - [0] ----D C:\Users\GELO\AppData\Roaming\streamripper O43 - CFD: 11.01.2013 - 20:20:19 - [] ----D C:\Users\GELO\AppData\Roaming\Template O43 - CFD: 04.04.2012 - 22:01:31 - [] ----D C:\Users\GELO\AppData\Roaming\TeraCopy O43 - CFD: 21.11.2013 - 21:27:08 - [] ----D C:\Users\GELO\AppData\Roaming\Thinstall O43 - CFD: 01.02.2014 - 18:31:03 - [] ----D C:\Users\GELO\AppData\Roaming\To the Moon - Freebird Games O43 - CFD: 24.10.2013 - 23:48:48 - [] ----D C:\Users\GELO\AppData\Roaming\TorrentStream O43 - CFD: 21.07.2014 - 22:06:13 - [] ----D C:\Users\GELO\AppData\Roaming\Trillian O43 - CFD: 25.06.2013 - 21:43:48 - [] ----D C:\Users\GELO\AppData\Roaming\TuneUp Software O43 - CFD: 27.12.2012 - 15:39:29 - [] ----D C:\Users\GELO\AppData\Roaming\TweakNow RegCleaner 2011 O43 - CFD: 08.06.2012 - 1:25:15 - [] ----D C:\Users\GELO\AppData\Roaming\UDC Profiles O43 - CFD: 15.02.2014 - 22:33:56 - [] ----D C:\Users\GELO\AppData\Roaming\vcards O43 - CFD: 06.03.2015 - 20:42:01 - [] ----D C:\Users\GELO\AppData\Roaming\vlc O43 - CFD: 31.12.2014 - 1:55:07 - [] ----D C:\Users\GELO\AppData\Roaming\VMware O43 - CFD: 05.01.2013 - 1:56:45 - [] ----D C:\Users\GELO\AppData\Roaming\VOS O43 - CFD: 27.12.2013 - 21:24:18 - [0] ----D C:\Users\GELO\AppData\Roaming\Windows Live Writer O43 - CFD: 02.11.2013 - 23:39:13 - [] ----D C:\Users\GELO\AppData\Roaming\Windows SideBar O43 - CFD: 29.03.2012 - 22:50:39 - [] ----D C:\Users\GELO\AppData\Roaming\WinRAR O43 - CFD: 10.01.2014 - 20:06:28 - [] ----D C:\Users\GELO\AppData\Roaming\Wireshark O43 - CFD: 12.12.2012 - 23:41:03 - [] ----D C:\Users\GELO\AppData\Roaming\Wise Care 365 O43 - CFD: 12.12.2012 - 23:26:01 - [] ----D C:\Users\GELO\AppData\Roaming\Wise Registry Cleaner O43 - CFD: 12.12.2012 - 23:30:00 - [] ----D C:\Users\GELO\AppData\Roaming\Wise Uninstaller O43 - CFD: 07.09.2014 - 19:11:30 - [] ----D C:\Users\GELO\AppData\Roaming\Wondershare O43 - CFD: 07.03.2015 - 18:55:48 - [] -SH-D C:\Users\GELO\AppData\Roaming\wyUpdate AU O43 - CFD: 01.12.2014 - 21:04:25 - [] ----D C:\Users\GELO\AppData\Roaming\XBMC O43 - CFD: 09.03.2015 - 22:40:07 - [] ----D C:\Users\GELO\AppData\Roaming\ZHP =>.Nicolas Coolman O43 - CFD: 26.02.2015 - 21:26:34 - [] ----D C:\Users\GELO\AppData\Local\4kdownload.com O43 - CFD: 10.06.2012 - 3:11:30 - [] ----D C:\Users\GELO\AppData\Local\ABBYY O43 - CFD: 12.11.2013 - 23:16:35 - [] ----D C:\Users\GELO\AppData\Local\ACD Systems O43 - CFD: 27.11.2012 - 0:14:22 - [] ----D C:\Users\GELO\AppData\Local\AdFender O43 - CFD: 09.02.2015 - 21:32:22 - [] ----D C:\Users\GELO\AppData\Local\Adobe O43 - CFD: 29.12.2013 - 19:32:17 - [] ----D C:\Users\GELO\AppData\Local\Ahead O43 - CFD: 24.06.2013 - 19:39:22 - [] ----D C:\Users\GELO\AppData\Local\AlbumArtDownloader O43 - CFD: 03.08.2013 - 22:32:28 - [] ----D C:\Users\GELO\AppData\Local\Anolis O43 - CFD: 10.09.2014 - 15:57:32 - [] ----D C:\Users\GELO\AppData\Local\AnVir O43 - CFD: 02.04.2012 - 13:11:31 - [] ----D C:\Users\GELO\AppData\Local\Apple O43 - CFD: 28.03.2012 - 11:56:03 - [] -SH-D C:\Users\GELO\AppData\Local\Application Data O43 - CFD: 08.10.2012 - 20:07:03 - [] ----D C:\Users\GELO\AppData\Local\Apps O43 - CFD: 25.07.2014 - 17:18:11 - [] ----D C:\Users\GELO\AppData\Local\Aviator O43 - CFD: 02.11.2013 - 23:48:48 - [] ----D C:\Users\GELO\AppData\Local\BuildAGadget Content O43 - CFD: 14.12.2014 - 1:41:28 - [] ----D C:\Users\GELO\AppData\Local\Camfrog O43 - CFD: 10.09.2014 - 23:39:14 - [] ----D C:\Users\GELO\AppData\Local\ChemTable Software O43 - CFD: 06.07.2013 - 21:55:07 - [] ----D C:\Users\GELO\AppData\Local\Chromium O43 - CFD: 31.05.2013 - 21:28:27 - [] ----D C:\Users\GELO\AppData\Local\Clover O43 - CFD: 05.09.2014 - 18:42:10 - [0] ----D C:\Users\GELO\AppData\Local\Comodo O43 - CFD: 08.03.2015 - 14:42:25 - [0] ----D C:\Users\GELO\AppData\Local\CrashDumps O43 - CFD: 01.08.2014 - 10:24:29 - [] ----D C:\Users\GELO\AppData\Local\CrashRpt O43 - CFD: 05.06.2012 - 20:28:47 - [] ----D C:\Users\GELO\AppData\Local\CustomStamp O43 - CFD: 24.10.2013 - 23:18:36 - [] ----D C:\Users\GELO\AppData\Local\CutePDF O43 - CFD: 09.03.2015 - 22:05:41 - [] ----D C:\Users\GELO\AppData\Local\CutePDF Writer O43 - CFD: 07.09.2014 - 18:34:46 - [] ----D C:\Users\GELO\AppData\Local\CutePDF_Filler O43 - CFD: 09.03.2015 - 22:06:04 - [0] ----D C:\Users\GELO\AppData\Local\CutePDF_Pro O43 - CFD: 10.09.2012 - 2:01:49 - [] ----D C:\Users\GELO\AppData\Local\Daum O43 - CFD: 20.11.2012 - 0:50:28 - [] ----D C:\Users\GELO\AppData\Local\DDMSettings O43 - CFD: 27.11.2012 - 9:07:41 - [0] ----D C:\Users\GELO\AppData\Local\Deployment O43 - CFD: 14.09.2014 - 12:36:36 - [0] ----D C:\Users\GELO\AppData\Local\Diagnostics O43 - CFD: 10.08.2014 - 11:16:57 - [] ----D C:\Users\GELO\AppData\Local\Downloaded Installations O43 - CFD: 28.12.2014 - 11:57:49 - [0] ----D C:\Users\GELO\AppData\Local\ElevatedDiagnostics O43 - CFD: 13.11.2014 - 18:36:44 - [] -SH-D C:\Users\GELO\AppData\Local\EmieBrowserModeList O43 - CFD: 30.04.2014 - 10:43:51 - [] -SH-D C:\Users\GELO\AppData\Local\EmieSiteList O43 - CFD: 30.04.2014 - 10:43:51 - [] -SH-D C:\Users\GELO\AppData\Local\EmieUserList O43 - CFD: 12.12.2012 - 14:04:39 - [] ----D C:\Users\GELO\AppData\Local\Evernote O43 - CFD: 18.05.2014 - 7:38:38 - [] ----D C:\Users\GELO\AppData\Local\Facebook O43 - CFD: 25.06.2013 - 20:05:28 - [] ----D C:\Users\GELO\AppData\Local\FixItCenter O43 - CFD: 12.12.2012 - 14:14:05 - [0] ----D C:\Users\GELO\AppData\Local\Folderico O43 - CFD: 28.02.2015 - 22:11:03 - [] ----D C:\Users\GELO\AppData\Local\Geotag Security O43 - CFD: 03.03.2015 - 18:10:15 - [] ----D C:\Users\GELO\AppData\Local\Google O43 - CFD: 02.05.2013 - 19:34:13 - [] ----D C:\Users\GELO\AppData\Local\gtk-2.0 O43 - CFD: 28.03.2012 - 11:56:03 - [] -SH-D C:\Users\GELO\AppData\Local\Historique O43 - CFD: 03.06.2013 - 16:38:02 - [] ----D C:\Users\GELO\AppData\Local\iMule O43 - CFD: 12.07.2014 - 18:34:47 - [] ----D C:\Users\GELO\AppData\Local\infidele-messenger O43 - CFD: 19.12.2014 - 0:25:57 - [] ----D C:\Users\GELO\AppData\Local\Innovative Solutions O43 - CFD: 15.07.2013 - 23:27:31 - [] ----D C:\Users\GELO\AppData\Local\IsolatedStorage O43 - CFD: 03.06.2013 - 17:12:20 - [] ----D C:\Users\GELO\AppData\Local\Jiri_Cincura_-_x2develop O43 - CFD: 08.07.2013 - 9:26:42 - [] ----D C:\Users\GELO\AppData\Local\K-Meleon O43 - CFD: 21.07.2014 - 19:06:30 - [0] ----D C:\Users\GELO\AppData\Local\Kakao O43 - CFD: 30.09.2012 - 21:10:25 - [] ----D C:\Users\GELO\AppData\Local\Kartina.TV O43 - CFD: 02.08.2012 - 23:41:33 - [] ----D C:\Users\GELO\AppData\Local\Macromedia O43 - CFD: 06.03.2015 - 10:31:54 - [0] ----D C:\Users\GELO\AppData\Local\ManyCam O43 - CFD: 04.04.2013 - 0:10:11 - [] ----D C:\Users\GELO\AppData\Local\MaxTV Technologies O43 - CFD: 30.05.2013 - 22:18:43 - [] ----D C:\Users\GELO\AppData\Local\Mgeni O43 - CFD: 08.12.2014 - 10:50:23 - [] ----D C:\Users\GELO\AppData\Local\Microsoft O43 - CFD: 16.04.2012 - 22:00:45 - [] ----D C:\Users\GELO\AppData\Local\Microsoft Games O43 - CFD: 30.07.2013 - 11:59:06 - [] ----D C:\Users\GELO\AppData\Local\Microsoft Help O43 - CFD: 16.11.2012 - 23:32:49 - [] ----D C:\Users\GELO\AppData\Local\Moonchild Productions O43 - CFD: 29.12.2013 - 22:03:48 - [] ----D C:\Users\GELO\AppData\Local\Mozilla O43 - CFD: 25.06.2013 - 20:25:13 - [] ----D C:\Users\GELO\AppData\Local\Mydownloadwin_security O43 - CFD: 09.11.2014 - 20:53:34 - [] ----D C:\Users\GELO\AppData\Local\Octoshape O43 - CFD: 19.08.2013 - 19:38:20 - [] ----D C:\Users\GELO\AppData\Local\Opera O43 - CFD: 03.07.2013 - 12:36:28 - [] ----D C:\Users\GELO\AppData\Local\Opera Software O43 - CFD: 23.04.2014 - 16:21:57 - [] ----D C:\Users\GELO\AppData\Local\Packages O43 - CFD: 16.07.2014 - 9:43:24 - [] ----D C:\Users\GELO\AppData\Local\Paint.NET O43 - CFD: 26.01.2015 - 0:55:15 - [] ----D C:\Users\GELO\AppData\Local\Parom.TV O43 - CFD: 30.07.2013 - 11:10:03 - [] ----D C:\Users\GELO\AppData\Local\PDF Writer O43 - CFD: 03.06.2013 - 22:48:11 - [] ----D C:\Users\GELO\AppData\Local\PDF24 O43 - CFD: 29.01.2015 - 19:52:31 - [0] ----D C:\Users\GELO\AppData\Local\PDFCreator O43 - CFD: 15.07.2013 - 23:27:22 - [] ----D C:\Users\GELO\AppData\Local\Pinnacle Systems GmbH O43 - CFD: 25.02.2014 - 12:18:22 - [] ----D C:\Users\GELO\AppData\Local\Programs O43 - CFD: 10.09.2013 - 22:09:08 - [] ----D C:\Users\GELO\AppData\Local\RNT O43 - CFD: 13.03.2014 - 20:52:44 - [] ----D C:\Users\GELO\AppData\Local\roulettechat-hot O43 - CFD: 10.08.2014 - 11:19:52 - [] ----D C:\Users\GELO\AppData\Local\Samsung O43 - CFD: 05.06.2013 - 22:16:49 - [0] ----D C:\Users\GELO\AppData\Local\Secunia PSI O43 - CFD: 17.02.2014 - 12:49:26 - [] ----D C:\Users\GELO\AppData\Local\Skype O43 - CFD: 11.12.2012 - 22:08:01 - [] ----D C:\Users\GELO\AppData\Local\SlimWare Utilities Inc O43 - CFD: 12.12.2012 - 19:14:34 - [] ----D C:\Users\GELO\AppData\Local\Soft4Boost O43 - CFD: 26.11.2012 - 0:04:06 - [] ----D C:\Users\GELO\AppData\Local\Spoon O43 - CFD: 01.09.2014 - 13:12:41 - [] ----D C:\Users\GELO\AppData\Local\Stardock O43 - CFD: 09.03.2015 - 22:39:09 - [] ----D C:\Users\GELO\AppData\Local\Temp O43 - CFD: 28.03.2012 - 11:56:03 - [] -SH-D C:\Users\GELO\AppData\Local\Temporary Internet Files O43 - CFD: 22.04.2012 - 17:18:59 - [] ----D C:\Users\GELO\AppData\Local\Thinstall O43 - CFD: 31.10.2012 - 1:03:29 - [] ----D C:\Users\GELO\AppData\Local\VirtualStore O43 - CFD: 31.12.2014 - 1:58:00 - [] ----D C:\Users\GELO\AppData\Local\VMware O43 - CFD: 20.06.2012 - 2:11:31 - [0] ----D C:\Users\GELO\AppData\Local\VS Revo Group O43 - CFD: 07.03.2015 - 18:27:04 - [] ----D C:\Users\GELO\AppData\Local\Windows Live O43 - CFD: 27.12.2013 - 21:24:38 - [] ----D C:\Users\GELO\AppData\Local\Windows Live Writer O43 - CFD: 07.09.2014 - 18:57:28 - [] ----D C:\Users\GELO\AppData\Local\Wondershare O43 - CFD: 05.09.2014 - 15:43:20 - [] ----D C:\Users\GELO\AppData\Local\www.obnovi-soft.ru O43 - CFD: 26.09.2012 - 0:46:30 - [] ----D C:\Users\GELO\AppData\Local\Xenocode O43 - CFD: 13.11.2013 - 1:49:03 - [] ----D C:\Users\GELO\AppData\Local\Xpom O43 - CFD: 28.09.2013 - 19:30:40 - [] ----D C:\Users\GELO\AppData\Local\Zattoo O43 - CFD: 10.06.2012 - 3:11:26 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 11 O43 - CFD: 14.07.2009 - 5:54:32 - [] R---D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 08.01.2015 - 20:27:48 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ace Stream Media O43 - CFD: 13.08.2014 - 13:50:15 - [] R---D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 10.09.2014 - 15:56:10 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVir Task Manager O43 - CFD: 03.11.2013 - 17:54:23 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 09.03.2015 - 2:42:59 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 07.03.2015 - 18:37:37 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ICQ O43 - CFD: 04.04.2012 - 8:36:00 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kartina.TV O43 - CFD: 14.07.2009 - 5:49:38 - [] R---D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 21.04.2012 - 14:25:06 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Parom.TV O43 - CFD: 13.01.2015 - 1:32:40 - [0] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Polyglossum O43 - CFD: 08.09.2014 - 12:03:27 - [0] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SopCast O43 - CFD: 14.02.2015 - 0:25:46 - [] R---D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 02.04.2012 - 3:33:37 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker O43 - CFD: 08.09.2014 - 11:15:00 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 28.07.2013 - 23:50:52 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XBMC O43 - CFD: 09.03.2015 - 2:42:59 - [] ----D C:\Users\GELO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Приложения Chrome ~ 248 Dossier CLSID vide (CLSID Empty Folder) ~ Program Folder: 880 Scanned in 00mn 00s | ||||||||
Petit astucien | ---\\ Last modified or created files under Windows and System32 (O44) O44 - LFC:[MD5.8752CC895B972F48D82F9ADB3D96E351] - 03.03.2015 - 14:17:35 ----- . (.Microsoft Corporation - Microsoft Malware Protection Signature Upda.) -- C:\Windows\System32\MpSigStub.exe [295552] O44 - LFC:[MD5.BF85D404851462FDF3157F49EA870725] - 06.03.2015 - 10:02:21 ---A- . (.Kingsoft Corporation - Kingsoft KSAPI Module.) -- C:\Windows\System32\Drivers\ksapi.sys [81768] O44 - LFC:[MD5.6968FC608A61791C13CEFE6C8496CBD2] - 06.03.2015 - 10:02:21 ---A- . (.Kingsoft Corporation - Kingsoft KSAPI Module.) -- C:\Windows\System32\Drivers\ksapi64.sys [56680] O44 - LFC:[MD5.6F593C7B14264FE2C6F3B96165BD95E5] - 07.03.2015 - 19:15:16 ---A- . (.Realtek - Realtek 8136/8168/8169 NDIS 6.20 64-bit Dri.) -- C:\Windows\System32\Drivers\Rt64win7.sys [942808] O44 - LFC:[MD5.0D2106264D437A031DD64A9DA514357F] - 07.03.2015 - 19:15:16 ---A- . (.Realtek Semiconductor Corporation - About Page.) -- C:\Windows\System32\RtNicProp64.dll [73800] O44 - LFC:[MD5.49A88E6CD77939F5F7D443628A18A317] - 07.03.2015 - 19:15:16 ---A- . (.Realtek Semiconductor Corporation - RTNUninst.) -- C:\Windows\System32\RTNUninst64.dll [107552] O44 - LFC:[MD5.B9B73E9AF77BC79C46E499A1D3B09D67] - 07.03.2015 - 19:15:47 ---A- . (.Andrea Electronics Corporation - Capture Noise Filters (64-bit).) -- C:\Windows\System32\AERTAC64.dll [560328] O44 - LFC:[MD5.814231B961760C39A5807A43D8ED71E1] - 07.03.2015 - 19:15:51 ---A- . (...) -- C:\Windows\System32\Drivers\RTAIODAT.DAT [1443340] O44 - LFC:[MD5.FFFCA96B0636F122C3A586ACBDB8CC42] - 07.03.2015 - 19:15:51 ---A- . (.Realtek Semiconductor Corp. - Realtek HD Audio Coinstaller.) -- C:\Windows\System32\RCoInstII64.dll [959704] O44 - LFC:[MD5.210A6EE42206A5A3EB5D5412906A7949] - 07.03.2015 - 19:15:51 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) LFX/GFX DSP component.) -- C:\Windows\System32\RltkAPO64.dll [2827120] O44 - LFC:[MD5.19F11159B215F80D72953DAFF11E023C] - 07.03.2015 - 19:15:52 ---A- . (.Realtek Semiconductor Corp. - HDA driver COM file.) -- C:\Windows\System32\RtDataProc64.dll [629464] O44 - LFC:[MD5.309ED3A5B26A40BA9621456367B97F94] - 07.03.2015 - 19:15:52 ---A- . (.Realtek Semiconductor Corp. - RTCOMDLL Module.) -- C:\Windows\System32\RTCOM64.dll [1287384] O44 - LFC:[MD5.5E91D529C9588FB3AB7AB1AE0A26EFDF] - 07.03.2015 - 19:15:52 ---A- . (.Realtek Semiconductor Corp. - Realtek APO API.) -- C:\Windows\System32\RtkApi64.dll [3186544] O44 - LFC:[MD5.D2B1DA73B6E8769A1BE1A55693B7F1B3] - 07.03.2015 - 19:15:52 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\Drivers\RTKVHD64.sys [4263128] O44 - LFC:[MD5.BE7AB7EDD5BCEB22D660A0E3DF0A1B5A] - 07.03.2015 - 19:15:53 ---A- . (.Realtek Semiconductor Corp. - Realtek LFX/GFX DSP UI component for Window.) -- C:\Windows\System32\RtPgEx64.dll [2860760] O44 - LFC:[MD5.C604B5CFC9DEAAA32691FC2798B86936] - 08.03.2015 - 11:32:00 --HA- . (...) -- C:\Windows\System32\Drivers\Msft_Kernel_webTinstMK_01009.Wdf [14040] =>PUP.CorsicaTechnologies O44 - LFC:[MD5.DF47B045E8113A9712903AF832BD505C] - 08.03.2015 - 12:30:08 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [6510] O44 - LFC:[MD5.12BE46F9E8BC4AF67BFE870DC423761F] - 08.03.2015 - 12:30:08 ---A- . (...) -- C:\Windows\System32\perfc009.dat [1754056] O44 - LFC:[MD5.1FCE31EAF1616CB42523C6BB9B7BB49F] - 08.03.2015 - 12:30:08 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [1795752] O44 - LFC:[MD5.A119B323D624C1530156B2A5ACE4E97D] - 08.03.2015 - 12:30:08 ---A- . (...) -- C:\Windows\System32\perfh009.dat [2404458] O44 - LFC:[MD5.B3E892E84475F165FDAFDF4724EDD909] - 08.03.2015 - 12:30:08 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [2654644] O44 - LFC:[MD5.26C43960C99EE861A5D0EDC4DCF3B1C3] - 08.03.2015 - 19:50:42 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [129752] O44 - LFC:[MD5.B4F15AEF86B3169CCCCE34DE8D3B24E5] - 09.03.2015 - 21:28:12 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1561218] O44 - LFC:[MD5.AC4C51EB24AA95B77F705AB159189E24] - 09.03.2015 - 2:08:05 ---A- . (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\explorer.exe [2872320] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 09.03.2015 - 2:10:35 ---A- . (...) -- C:\Windows\setuperr.log [0] O44 - LFC:[MD5.413FEB18799BFD8603542A6874A24F38] - 09.03.2015 - 2:10:44 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [434104] O44 - LFC:[MD5.3FAA3EC83BB54047BC03D1DC4E5CB81E] - 09.03.2015 - 2:25:51 ---A- . (...) -- C:\Windows\ntbtlog.txt [13495506] O44 - LFC:[MD5.FD267C16D3ACEDBDA7E7AD377A6C5FE5] - 09.03.2015 - 2:37:47 ---A- . (.Trend Micro Inc. - TrendMicro Common Module.) -- C:\Windows\System32\Drivers\tmcomm.sys [173504] O44 - LFC:[MD5.5A0F89DED2975FE44D07007F8D5034B6] - 09.03.2015 - 2:37:48 ---A- . (.trend_company_name - Trend Micro Anti-Rootkit Driver.) -- C:\Windows\System32\Drivers\tmrkb.sys [184768] O44 - LFC:[MD5.36586D1074280FF5F24AC4B93ADACFC3] - 09.03.2015 - 2:44:01 ---A- . (...) -- C:\Windows\PFRO.log [476] O44 - LFC:[MD5.DCFEC67F0259ACF7C612C2AEBE0D80D5] - 09.03.2015 - 8:10:06 -S-A- . (...) -- C:\Windows\bootstat.dat [67584] O44 - LFC:[MD5.640DAD2C12AB9C0D0D3070666B6CCF80] - 09.03.2015 - 8:10:11 ---A- . (...) -- C:\Windows\setupact.log [224] O44 - LFC:[MD5.3B9E2AB1F3ABC53D4A423E699EB625C8] - 25.02.2015 - 10:21:19 ---A- . (...) -- C:\Windows\System32\locale.nls [419936] ~ Files: 33 Scanned in 00mn 05s
---\\ Local Security Authority-LSA Deny (O48) O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corp. - LiveSSP.) -- C:\Windows\System32\livessp.dll ~ LSA: 9 Scanned in 00mn 00s
---\\ Safe Boot Control (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\hitmanpro37.sys . (...) -- C:\Windows\System32\Drivers\hitmanpro37.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\hitmanpro37.sys . (...) -- C:\Windows\System32\Drivers\hitmanpro37.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys ~ CSB: 15 Scanned in 00mn 00s
---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52) O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \Drivers32\"VIDC.FFDS"="ff_vfw.dll" . (.No owner - ffdshow VFW.) -- C:\Windows\System32\ff_vfw.dll O52 - TDSD: \Drivers32\"VIDC.LAGS"="lagarith.dll" . (.No owner - Lagarith.) -- C:\Windows\System32\lagarith.dll O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \drivers.desc\"ff_vfw.dll"="ffdshow video encoder" . (.No owner - ffdshow VFW.) -- C:\Windows\System32\ff_vfw.dll O52 - TDSD: \drivers.desc\"lagarith.dll"="Lagarith lossless codec [LAGS]" . (.No owner - Lagarith.) -- C:\Windows\System32\lagarith.dll ~ TDSD: 6 Scanned in 00mn 00s
---\\ Microsoft Control Security Providers (MCSP) (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll ~ MSCP: 2 Scanned in 00mn 00s
---\\ Microsoft Windows Policies System (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0 O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 16 Scanned in 00mn 00s
---\\ Microsoft Windows Policies Explorer (MWPE) (O56) O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0 ~ MWPE Keys: 3 Scanned in 00mn 00s
---\\ System Drivers List (SDL) (O58) O58 - SDL:09.12.2012 - 20:49:32 ---A- . (.NXP Semiconductors Germany GmbH - 3xHybrid.) -- C:\Windows\System32\Drivers\3xHybr64.sys [1448064] O58 - SDL:14.07.2009 - 2:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088] O58 - SDL:14.07.2009 - 2:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [339536] O58 - SDL:14.07.2009 - 2:52:21 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\Drivers\adpu320.sys [182864] O58 - SDL:14.07.2009 - 2:52:21 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [15440] O58 - SDL:11.03.2011 - 7:41:12 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [107904] O58 - SDL:14.07.2009 - 2:52:20 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows -.) -- C:\Windows\System32\Drivers\amdsbs.sys [194128] O58 - SDL:11.03.2011 - 7:41:12 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [27008] O58 - SDL:10.01.2011 - 17:16:08 ---A- . (...) -- C:\Windows\System32\Drivers\AppleCharger.sys [21104] O58 - SDL:14.07.2009 - 2:52:21 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [87632] O58 - SDL:14.07.2009 - 2:52:21 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [97856] O58 - SDL:10.06.2009 - 21:34:23 ---A- . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver..) -- C:\Windows\System32\Drivers\b57nd60a.sys [270848] O58 - SDL:10.06.2009 - 21:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [18432] O58 - SDL:10.06.2009 - 21:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [8704] O58 - SDL:14.07.2009 - 2:19:07 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [286720] O58 - SDL:10.06.2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [47104] O58 - SDL:10.06.2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [14976] O58 - SDL:10.06.2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [14720] O58 - SDL:10.06.2009 - 21:34:28 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbda.sys [468480] O58 - SDL:23.04.2007 - 13:44:12 ---A- . (...) -- C:\Windows\System32\Drivers\camdrv42.sys [1533952] O58 - SDL:30.10.2011 - 13:14:56 ---A- . (.CrystalIdea Software - Uninstall Tool 3 Driver.) -- C:\Windows\System32\Drivers\CisUtMonitor.sys [33360] O58 - SDL:14.07.2009 - 2:52:31 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [17488] O58 - SDL:14.07.2009 - 2:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496] O58 - SDL:12.02.2014 - 18:22:00 ---A- . (.Etron Technology Inc - Etron eXtensible Hub Driver..) -- C:\Windows\System32\Drivers\EtronHub3.sys [65408] O58 - SDL:12.02.2014 - 18:22:00 ---A- . (.Etron Technology Inc - Etron eXtensible Host Controller Driver..) -- C:\Windows\System32\Drivers\EtronXHCI.sys [94208] O58 - SDL:10.06.2009 - 21:34:33 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbda.sys [3286016] O58 - SDL:21.08.2012 - 12:01:20 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys [33240] O58 - SDL:02.12.2012 - 11:03:17 ---A- . (.GFI Software - GFI Boot Time Operations Driver.) -- C:\Windows\System32\Drivers\gfibto.sys [14456] O58 - SDL:02.11.2009 - 16:47:26 ---A- . (.No owner - WDM NULL filter driver.) -- C:\Windows\System32\Drivers\gMouUsb.sys [14336] O58 - SDL:27.02.2014 - 18:40:32 ---A- . (.VMware, Inc. - VMware USB monitor.) -- C:\Windows\System32\Drivers\hcmon.sys [54464] O58 - SDL:23.10.2012 - 10:55:46 ---A- . (.Hauppauge Computer Works, Inc. - WinTV-Nova-T-Mini device driver.) -- C:\Windows\System32\Drivers\hcw17b64.sys [78192] O58 - SDL:06.08.2012 - 11:18:48 ---A- . (.Hauppauge Computer Works, Inc. - WinTV-Nova-T-Mini device driver.) -- C:\Windows\System32\Drivers\hcw17bda.sys [75184] O58 - SDL:10.06.2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232] O58 - SDL:19.10.2010 - 22:34:26 ---A- . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\Drivers\HECIx64.sys [56344] O58 - SDL:21.11.2010 - 4:23:47 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [78720] O58 - SDL:11.03.2011 - 7:41:26 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\Drivers\iaStorV.sys [410496] O58 - SDL:14.07.2009 - 2:48:04 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [44112] O58 - SDL:06.03.2015 - 10:02:21 ---A- . (.Kingsoft Corporation - Kingsoft KSAPI Module.) -- C:\Windows\System32\Drivers\ksapi.sys [81768] O58 - SDL:06.03.2015 - 10:02:21 ---A- . (.Kingsoft Corporation - Kingsoft KSAPI Module.) -- C:\Windows\System32\Drivers\ksapi64.sys [56680] O58 - SDL:14.07.2009 - 2:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [114752] O58 - SDL:14.07.2009 - 2:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [106560] O58 - SDL:14.07.2009 - 2:48:04 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [65600] O58 - SDL:14.07.2009 - 2:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [115776] O58 - SDL:29.09.2012 - 20:54:26 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam,3.sys [25928] O58 - SDL:21.11.2014 - 6:14:08 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [25816] O58 - SDL:21.11.2014 - 6:14:12 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [93400] O58 - SDL:08.03.2015 - 19:50:42 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [129752] O58 - SDL:06.12.2013 - 14:37:50 ---A- . (.Visicom Media Inc. - ManyCam Virtual Microphone.) -- C:\Windows\System32\Drivers\mcaudrv_x64.sys [35232] O58 - SDL:27.11.2013 - 2:54:02 ---A- . (.Visicom Media Inc. - ManyCam Virtual Webcam Driver.) -- C:\Windows\System32\Drivers\mcvidrv.sys [42016] O58 - SDL:14.07.2009 - 2:48:04 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for.) -- C:\Windows\System32\Drivers\megasas.sys [35392] O58 - SDL:14.07.2009 - 2:48:04 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [284736] O58 - SDL:21.11.2014 - 6:14:22 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [63704] O58 - SDL:14.07.2009 - 2:48:26 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [51264] O58 - SDL:01.03.2013 - 2:49:12 ---A- . (.Riverbed Technology, Inc. - npf.sys (NT5/6 AMD64) Kernel Driver.) -- C:\Windows\System32\Drivers\npf.sys [36600] O58 - SDL:19.02.2013 - 22:32:18 ---A- . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 307.83.) -- C:\Windows\System32\Drivers\nvlddmkm.sys [13531936] O58 - SDL:11.03.2011 - 7:41:34 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [148352] O58 - SDL:11.03.2011 - 7:41:34 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [166272] O58 - SDL:03.04.2007 - 10:30:14 ---A- . (.Philips Semiconductors GmbH - Ph3xIBxx.) -- C:\Windows\System32\Drivers\Ph3xIB64.sys [1418112] O58 - SDL:14.07.2009 - 2:45:46 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1524816] O58 - SDL:14.07.2009 - 2:45:45 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [128592] O58 - SDL:07.03.2015 - 19:15:16 ---A- . (.Realtek - Realtek 8136/8168/8169 NDIS 6.20 64-bit Driver.) -- C:\Windows\System32\Drivers\Rt64win7.sys [942808] O58 - SDL:07.03.2015 - 19:15:52 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver.) -- C:\Windows\System32\Drivers\RTKVHD64.sys [4263128] O58 - SDL:10.06.2009 - 21:37:19 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [23040] O58 - SDL:14.07.2009 - 2:45:45 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [43584] O58 - SDL:14.07.2009 - 2:45:46 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [80464] O58 - SDL:20.10.2012 - 8:43:02 ---A- . (.Ray Hinchliffe - System Information Viewer X64 Driver.) -- C:\Windows\System32\Drivers\SIVX64.sys [129856] O58 - SDL:01.01.2000 - 1:00:00 ---A- . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\Windows\System32\Drivers\Smb_driver_Intel.sys [34544] O58 - SDL:22.02.2013 - 8:16:54 ---A- . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\Windows\System32\Drivers\ssadcm.sys [17224] O58 - SDL:22.02.2013 - 8:16:54 ---A- . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\Windows\System32\Drivers\ssadwh.sys [17736] O58 - SDL:14.07.2009 - 2:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656] O58 - SDL:20.03.2014 - 10:43:02 ---A- . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\Drivers\TeeDriverx64.sys [118272] O58 - SDL:09.03.2015 - 2:37:47 ---A- . (.Trend Micro Inc. - TrendMicro Common Module.) -- C:\Windows\System32\Drivers\tmcomm.sys [173504] O58 - SDL:09.03.2015 - 2:37:48 ---A- . (.trend_company_name - Trend Micro Anti-Rootkit Driver.) -- C:\Windows\System32\Drivers\tmrkb.sys [184768] O58 - SDL:14.07.2009 - 2:45:55 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [17488] O58 - SDL:08.10.2013 - 18:21:06 ---A- . (.VMware, Inc. - VMware PCI VMCI Bus Device.) -- C:\Windows\System32\Drivers\vmci.sys [85584] O58 - SDL:29.10.2014 - 15:00:50 ---A- . (.VMware, Inc. - VMware keyboard filter driver (64-bit).) -- C:\Windows\System32\Drivers\VMkbd.sys [33496] O58 - SDL:29.10.2014 - 15:00:52 ---A- . (.VMware, Inc. - VMware virtual network driver (64-bit).) -- C:\Windows\System32\Drivers\vmnet.sys [24656] O58 - SDL:29.10.2014 - 15:00:52 ---A- . (.VMware, Inc. - VMware virtual network adapter driver (64-bit).) -- C:\Windows\System32\Drivers\vmnetadapter.sys [20560] O58 - SDL:29.10.2014 - 15:00:52 ---A- . (.VMware, Inc. - VMware bridge driver (64-bit).) -- C:\Windows\System32\Drivers\vmnetbridge.sys [46160] O58 - SDL:29.10.2014 - 15:01:14 ---A- . (.VMware, Inc. - VMware network application interface driver (64-bit).) -- C:\Windows\System32\Drivers\vmnetuserif.sys [31448] O58 - SDL:29.10.2014 - 15:01:42 ---A- . (.VMware, Inc. - VMware kernel driver.) -- C:\Windows\System32\Drivers\vmx86.sys [64728] O58 - SDL:14.07.2009 - 2:45:55 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [161872] O58 - SDL:08.10.2013 - 18:21:10 ---A- . (.VMware, Inc. - VMware vSockets Service.) -- C:\Windows\System32\Drivers\vsock.sys [73296] O58 - SDL:07.03.2015 - 18:43:42 ---A- . (.REALiX(tm) - HWiNFO AMD64 Kernel Driver.) -- C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528] O58 - SDL:14.08.2013 - 8:34:04 ---A- . (...) -- C:\Windows\SysWOW64\drivers\vwifikerneldrv.sys [389] O58 - SDL:23.11.1999 - 8:17:34 ---A- . (...) -- C:\Windows\SysWOW64\dc240u.sys [7808] O58 - SDL:23.11.1999 - 8:17:36 ---A- . (...) -- C:\Windows\SysWOW64\Digita.sys [65864] O58 - SDL:05.02.2013 - 9:54:40 ---A- . (...) -- C:\Windows\SysWOW64\FsUsbExDisk.Sys [37344] ~ Drivers: 88 Scanned in 00mn 05s
---\\ Last modified or created user files (O61) O61 - LFC: 02.03.2015 - 22:41:01 ---A- . (.Microsoft Corporation.) -- C:\Users\GELO\AppData\Roaming\Microsoft\MSXML2\msxml4.dll [1275392] O61 - LFC: 02.03.2015 - 22:41:01 ---A- . (.Microsoft Corporation.) -- C:\Users\GELO\AppData\Roaming\Microsoft\MSXML2\msxml4a.dll [44544] O61 - LFC: 02.03.2015 - 22:41:01 ---A- . (.Microsoft Corporation.) -- C:\Users\GELO\AppData\Roaming\Microsoft\MSXML2\msxml4r.dll [82432] O61 - LFC: 02.03.2015 - 22:42:32 ---A- . (.Microsoft Corporation.) -- C:\Users\GELO\Downloads\1\Protéger son ordinateur avec Microsoft Security Essentials\mseinstall.exe [11555632] O61 - LFC: 05.03.2015 - 22:42:45 ---A- . (...) -- C:\Users\GELO\Downloads\gg-install.exe [395056] O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (...) -- C:\Users\GELO\AppData\Roaming\ICQM\ICQ\dll\MousePhone.dll [56840] O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (...) -- C:\Users\GELO\AppData\Roaming\ICQM\ICQ\dll\mailrusputnik.exe [4739616] O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (.ICQ.) -- C:\Users\GELO\AppData\Roaming\ICQM\icq.exe [36705800] O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (.ICQ.) -- C:\Users\GELO\AppData\Roaming\ICQM\icqsetup.exe [37968904] O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (.Mail.Ru.) -- C:\Users\GELO\AppData\Roaming\ICQM\ICQ\dll\mratag.dll [112136] O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (.Mail.Ru.) -- C:\Users\GELO\AppData\Roaming\ICQM\libvoip_x86.dll [2917384] O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (.TODO: <Company name>.) -- C:\Users\GELO\AppData\Roaming\ICQM\MRAInplaceViewer.dll [2350600] O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (.Terra Informatica Software, Inc..) -- C:\Users\GELO\AppData\Roaming\ICQM\sciter32.dll [4261888] O61 - LFC: 07.03.2015 - 22:41:00 ---A- . (.goober Networks, Inc..) -- C:\Users\GELO\AppData\Roaming\ICQM\vivo.dll [3196936] O61 - LFC: 08.03.2015 - 22:40:54 ---A- . (...) -- C:\Users\GELO\AppData\LocalLow\Microsoft\Silverlight\OutOfBrowser\index\secure3.segpay.com [0] O61 - LFC: 08.03.2015 - 22:41:08 ---A- . (...) -- C:\Users\GELO\AppData\Roaming\ooVoo Details\Users\hottboy2006\{0003A8CC-452B-0000-BD6B-05AB0E68541E}.bin [2456] O61 - LFC: 08.03.2015 - 22:42:22 ---A- . (.Clique Communications LLC.) -- C:\Users\GELO\Downloads\1\cliquevm.exe [8801672] O61 - LFC: 08.03.2015 - 22:42:23 ---A- . (.FreoMessenger LLC.) -- C:\Users\GELO\Downloads\1\freo-setup.exe [1693808] O61 - LFC: 08.03.2015 - 22:42:23 ---A- . (.ooVoo LLC.) -- C:\Users\GELO\Downloads\1\ooVooSetup.exe [2388000] O61 - LFC: 09.03.2015 - 22:40:50 ---A- . (...) -- C:\Users\GELO\AppData\Local\Temp\RootkitBuster\sqlite3.dll [914432] O61 - LFC: 09.03.2015 - 22:40:50 ---A- . (.Igor Pavlov.) -- C:\Users\GELO\AppData\Local\Temp\RootkitBuster\IAU_SDK.exe [6264669] O61 - LFC: 09.03.2015 - 22:40:50 ---A- . (.Trend Micro Inc..) -- C:\Users\GELO\AppData\Local\Temp\RootkitBuster\TMRKScan.dll [664088] O61 - LFC: 09.03.2015 - 22:40:50 ---A- . (.Trend Micro Inc..) -- C:\Users\GELO\AppData\Local\Temp\RootkitBuster\TmEngDrv.dll [420400] O61 - LFC: 09.03.2015 - 22:40:50 ---A- . (.trend_company_name.) -- C:\Users\GELO\AppData\Local\Temp\RootkitBuster\tmrkb.sys [184768] O61 - LFC: 09.03.2015 - 22:40:51 ---A- . (.Trend Micro Inc..) -- C:\Users\GELO\AppData\Local\Temp\RootkitBuster\vsapi.dll [2753552] O61 - LFC: 09.03.2015 - 22:42:21 ---A- . (.Nicolas Coolman.) -- C:\Users\GELO\Desktop\ZHPDiag2.exe [6877328] =>.Nicolas Coolman ~ 392 Fichiers temporaires (Temporary files) ~ 37 Fichiers cookies (Cookies files) ~ Files: 26 Scanned in 06mn 56s | ||||||||
Petit astucien | ---\\ List all tools cleaner (LATC) (O63) O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn 00s
---\\ List all legacy services(LALS) (O64) O64 - Services: CurCS - 10.01.2011 - C:\Windows\System32\DRIVERS\AppleCharger.sys (AppleCharger) .(...) - LEGACY_APPLECHARGER O64 - Services: CurCS - 02.12.2012 - C:\Windows\System32\drivers\gfibto.sys (gfibto) .(.GFI Software - GFI Boot Time Operations Driver.) - LEGACY_GFIBTO O64 - Services: CurCS - 27.02.2014 - C:\Windows\system32\drivers\hcmon.sys (hcmon) .(.VMware, Inc. - VMware USB monitor.) - LEGACY_HCMON O64 - Services: CurCS - 07.03.2015 - C:\Windows\sysWOW64\drivers\HWiNFO64A.sys (HWiNFO32) .(.REALiX(tm) - HWiNFO AMD64 Kernel Driver.) - LEGACY_HWINFO32 O64 - Services: CurCS - 21.11.2014 - C:\Windows\system32\drivers\mbamchameleon.sys (mbamchameleon) .(.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) - LEGACY_MBAMCHAMELEON O64 - Services: CurCS - 21.11.2014 - C:\Windows\system32\drivers\mbam.sys (MBAMProtector) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMPROTECTOR O64 - Services: CurCS - 01.03.2013 - C:\Windows\System32\drivers\npf.sys (NPF) .(.Riverbed Technology, Inc. - npf.sys (NT5/6 AMD64) Kernel Driver.) - LEGACY_NPF O64 - Services: CurCS - 10.06.2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV O64 - Services: CurCS - 01.07.2010 - C:\Program Files\Unlocker\UnlockerDriver5.sys (UnlockerDriver5) .(...) - LEGACY_UNLOCKERDRIVER5 O64 - Services: CurCS - 19.12.2012 - C:\Users\GELO\Desktop\VirtualBox 4.2.6 82870 Portable\App\VirtualBox\drivers\USB\filter\VBoxUSBMon.sys (VBoxUSBMon) .(.Oracle Corporation - VirtualBox USB Monitor Driver.) - LEGACY_VBOXUSBMON O64 - Services: CurCS - 29.10.2014 - C:\Windows\System32\DRIVERS\vmnetbridge.sys (VMnetBridge) .(.VMware, Inc. - VMware bridge driver (64-bit).) - LEGACY_VMNETBRIDGE O64 - Services: CurCS - 29.10.2014 - C:\Windows\system32\drivers\vmnetuserif.sys (VMnetuserif) .(.VMware, Inc. - VMware network application interface driver.) - LEGACY_VMNETUSERIF O64 - Services: CurCS - 29.10.2014 - C:\Windows\system32\drivers\vmx86.sys (vmx86) .(.VMware, Inc. - VMware kernel driver.) - LEGACY_VMX86 O64 - Services: CurCS - 08.10.2013 - C:\Windows\System32\drivers\vsock.sys (vsock) .(.VMware, Inc. - VMware vSockets Service.) - LEGACY_VSOCK ~ Legacy: 94 Scanned in 00mn 08s
---\\ File Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> <OperaStable>[HKLM\..\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\Launcher.exe O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Not Key.) ~ FASS Keys: 11 Scanned in 00mn 00s
---\\ Start Menu Internet (SMI) (O68) O68 - StartMenuInternet: <Aviator> <Aviator>[HKLM\..\Shell\open\Command] (.Not Key.) O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Not Key.) O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Not Key.) O68 - StartMenuInternet: <k-meleon.exe> <K-Meleon>[HKLM\..\Shell\open\Command] (.Not Key.) O68 - StartMenuInternet: <Lunascape6> <Lunascape6>[HKLM\..\Shell\open\Command] (.Not Key.) O68 - StartMenuInternet: <Opera> <Opera>[HKLM\..\Shell\open\Command] (.Not Key.) O68 - StartMenuInternet: <OperaStable> <Opera Stable>[HKLM\..\Shell\open\Command] (.Not Key.) ~ Keys: Scanned in 00mn 00s
---\\ Search Browser Infection (SBI) (O69) O69 - SBI: prefs.js [GELO - blozzve3.default] user_pref("weboftrust.search.ask.display", "Ask.com Web Search"); O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} - (e) - http://rambler.ru O69 - SBI: SearchScopes [HKCU] {231CE532-7C50-418F-AAFC-B14AA5118BD8} - (Translate.Ru) - http://rambler.ru O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} [DefaultScope] - (Google) - http://www.google.com O69 - SBI: SearchScopes [HKUS\.DEFAULT] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKUS\S-1-5-18] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com ~ Keys: Scanned in 00mn 00s
---\\ Search Svchost Services (SSS) (O83) O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [236032] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [777728] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [859648] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [680960] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [99328] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [344064] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [64512] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [359424] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [316928] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [683520] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\system32\wuaueng.dll [2477536] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [849920] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [370688] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [569344] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [30720] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70144] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [156672] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [67584] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [219136] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [121856] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136704] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1110016] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [90624] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84480] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [210432] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [44544] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864] ~ Services: 32 Scanned in 00mn 00s
---\\ Search Particular Root Folder (SPRF) (O84) [MD5.6CD985C9E791C4D9F6441C9C360CA5BB] [SPRF][14.08.2013] (...) -- C:\ProgramData\fontcacheev1.dat [389] [MD5.F1D3FF8443297732862DF21DC4E57262] [SPRF][09.08.2014] (...) -- C:\Users\GELO\AppData\Roaming\wklnhst.dat [4] [MD5.72695F5E580D1F66F933C64323520093] [SPRF][09.03.2015] (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Users\GELO\Desktop\ZHPDiag2.exe [6877328] [MD5.CFE1AF5EE9CD57726695DC11941C0FB1] [SPRF][20.04.2011] (...) -- C:\Windows\Downloaded Program Files\WebInstallRunner.dll [43008] ~ Files: 4 Scanned in 00mn 00s
---\\ Firewall Active Exception List (FirewallRules) (O87) O87 - FAEL: "TCP Query User{684C0968-BAD5-4925-A14F-B447D7ABFC88}E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe" | In - Public - P6 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe =>P2P.BitTorrent O87 - FAEL: "UDP Query User{A1262EFB-21DF-4EF3-B28D-AFAC5BC49423}E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe" | In - Public - P17 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- E:\telechargements\logiciels\portables\загрузка\utorrent portable\app\utorrent\utorrent.exe =>P2P.BitTorrent ~ Firewall: 2 Scanned in 00mn 18s
---\\ Windows Installer Scan (WIS) (O93) (NTFS) [MD5.013946FEC4064E014774D39623AA7CE4] [WIS][16.10.2013] (.APN, LLC - Sopcast Toolbar.) -- C:\Windows\Installer\346d8a5.msi [523264] =>Toolbar.Ask ~ WIS: 1 Scanned in 00mn 06s
---\\ General States of Services not Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 09.02.2015 267440 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe SS - | Auto 22.07.1658 0 | (AdvancedSystemCareService8) . (...) - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ASCService.exe SS - | Demand 06.04.2010 31272 | (AppleChargerSrv) . (...) - C:\Windows\System32\AppleChargerSrv.exe SS - | Auto 22.07.1658 0 | (ASCAntivirusSrv) . (...) - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ascavsvc.exe SS - | Auto 20.10.2014 107912 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 20.10.2014 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 14.08.2012 194032 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe SS - | Auto 22.07.1658 0 | (HitmanProScheduler) . (...) - C:\Program Files\HitmanPro\hmpsched.exe SS - | Demand 14.11.2005 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe SS - | Demand 31.01.2014 887232 | (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe SS - | Auto 22.07.1658 0 | (LiveUpdateSvc) . (...) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe SS - | Auto 21.11.2014 969016 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe SS - | Demand 05.03.2015 148592 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe SS - | Demand 09.10.2006 724992 | (NBService) . (.Nero AG.) - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe SS - | Auto 08.04.2013 799280 | (PDF Architect Service) . (.pdfforge GmbH.) - C:\Program Files (x86)\PDF Architect\ConversionService.exe SS - | Demand 01.03.2013 118520 | (rpcapd) . (.Riverbed Technology, Inc..) - C:\Program Files (x86)\WinPcap\rpcapd.exe SS - | Demand 04.11.2008 68760 | (SandraAgentSrv) . (.SiSoftware.) - C:\Program Files\SiSoftware\SiSoftware Sandra Business 2013\RpcAgentSrv.exe SS - | Auto 02.01.2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe SS - | Demand 14.07.2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SS - | Demand 22.07.1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation SR - | Auto 14.05.2009 759048 | (ABBYY.Licensing.FineReader.Sprint.9.0) . (.ABBYY.) - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe SR - | Auto 15.12.2011 917640 | (AcuWVSSchedulerv8) . (...) - C:\Program Files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe SR - | Auto 03.12.2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe SR - | Auto 24.01.2012 21880 | (APC Data Service) . (.Schneider Electric.) - C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe SR - | Auto 24.01.2012 705912 | (APC UPS Service) . (.Schneider Electric.) - C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe SR - | Auto 12.02.2014 43336 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe SR - | Auto 30.08.2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe SR - | Auto 06.03.2015 315240 | (cmcore) . (.Kingsoft Corporation.) - c:\program files (x86)\cmcm\Clean Master\cmcore.exe SR - | Auto 21.02.2012 151648 | (EPSON_PM_RPCV4_04) . (.SEIKO EPSON CORPORATION.) - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.exe SR - | Auto 14.02.2014 579584 | (HauppaugeTVServer) . (.Hauppauge Computer Works.) - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe SR - | Auto 20.01.2014 2818896 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe SR - | Auto 21.11.2014 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe SR - | Auto 30.01.2015 23784 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe SR - | Auto 18.08.2009 7599616 | (MySQL) . (...) - C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe SR - | Auto 31.01.2013 878368 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe SR - | Auto 19.02.2013 1259296 | (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe SR - | Auto 08.04.2013 1320496 | (PDF Architect Helper Service) . (.pdfforge GmbH.) - C:\Program Files (x86)\PDF Architect\HelperService.exe SR - | Auto 17.01.2013 8704 | (RumoteVMCService) . (.Rumote.) - C:\Program Files (x86)\Rumote\RumoteVMC\RumoteMCEService.exe SR - | Auto 10.09.2012 193392 | (SCPDFReadSpool) . (.Solid Documents, LLC.) - C:\Program Files (x86)\SolidDocuments\Solid Converter PDF\SCPDF\SolidConverterPDFServicex64.exe SR - | Auto 28.03.2012 82944 | (SLService) . (...) - C:\Windows\System32\slmdmsr.exe SR - | Demand 20.12.2014 820960 | (SystemExplorerHelpService) . (.Mister Group.) - C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe SR - | Auto 29.10.2014 86744 | (VMAuthdService) . (.VMware, Inc..) - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe SR - | Auto 22.07.1658 0 | (VMnetDHCP) . (.VMware, Inc..) - C:\Windows\system32\vmnetdhcp.exe SR - | Auto 27.02.2014 906432 | (VMUSBArbService) . (.VMware, Inc..) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe SR - | Auto 22.07.1658 0 | (VMware NAT Service) . (.VMware, Inc..) - C:\Windows\system32\vmnat.exe SR - | Auto 14.07.2009 27136 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 08.09.2014 97280 | (_wfcs) . (.BiniSoft.org.) - C:\Program Files\Windows Firewall Control\wfcs.exe ~ Services: Scanned in 00mn 11s
---\\ Search Master Boot Record Infection (MBR)(O80) Run by GELO at 09.03.2015 22:49:13 ~ OS 64 not supported by MBR tool ~ MBR: 0 Scanned in 00mn 00s
---\\ Search Master Boot Record Infection (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by GELO at 09.03.2015 22:49:15 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 02s
---\\ Scan Additionnel (O88) Database Version : 13008 - (08.03.2015) Clés trouvées (Keys found) : 6 Valeurs trouvées (Values found) : 1 Dossiers trouvés (Folders found) : 5 Fichiers trouvés (Files found) : 6
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Applian FLV Player2.0.24] =>PUP.ApplianTechnologies^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Applian FLV and Media Player] =>PUP.ApplianTechnologies^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{53504356-3700-A76A-76A7-A758B70C0600}] =>Toolbar.Ask^ [HKLM\Software\Classes\Interface\{D6094FC6-821F-474C-8D73-C13066CD178D}] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Classes\Interface\{D6094FC6-821F-474C-8D73-C13066CD178D}] =>Toolbar.Agent [HKLM\Software\Classes\AppID\secman.DLL] =>PUP.Babylon C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\blozzve3.default\extensions\pavel.sherbakov@gmail.com =>PUP.QuickShare^ C:\Users\GELO\AppData\Roaming\Mozilla\Firefox\Profiles\fi77grgz.dev-edition-default\extensions\pavel.sherbakov@gmail.com =>PUP.QuickShare^ C:\Program Files (x86)\Applian Technologies =>PUP.ApplianTechnologies^ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Applian Technologies =>PUP.ApplianTechnologies^ C:\Users\GELO\AppData\Roaming\Applian FLV and Media Player =>PUP.ApplianTechnologies^ C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rel.job =>Toolbar.AVGSearch^ C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rel =>Toolbar.AVGSearch^ C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rmv.job =>Toolbar.AVGSearch^ C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rmv =>Toolbar.AVGSearch^ [HKLM\Software\Wow6432Node\Applian Technologies] =>PUP.ApplianTechnologies^ C:\Windows\Installer\346d8a5.msi =>Toolbar.Ask^ ~ Additionnel Scan: 388926 Items scanned in 00mn 30s
---\\ Additional information about modules ~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5) ~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects (O2) ~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer toolbars (O3) ~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Auto loading programs from Registry and folders (O4) ~ AMI: 4 Scanned in 00mn 00s
---\\ Summary of the detections found on your workstation http://nicolascoolman.fr/pup-quickshare =>PUP.QuickShare http://www.nicolascoolman.fr/blog/ =>PUP.ApplianTechnologies http://nicolascoolman.fr/toolbar-ask =>Toolbar.Ask http://www.nicolascoolman.fr/blog/ =>PUP.CorsicaTechnologies http://www.nicolascoolman.fr/blog/ =>Toolbar.Agent http://nicolascoolman.fr/pup-babylon =>PUP.Babylon ~ MSI: 6 link(s) detected in 00mn 00s
End of the scan (2423 lines in 10mn 15s)(0.10) | ||||||||
PC Astuces a besoin de vous pour survivre. Nos conseils et astuces vous ont aidé ? Vous avez résolu un problème sur votre ordinateur ? Vous avez profité de nos bons plans ? Aidez-nous en retour avec un abonnement de soutien mensuel. 5 € par mois 10 € par mois 20 € par mois
| |||||||||
Astucienne | Héberge le rapport sur cjoint s'il te plaît | ||||||||
Petit astucien | Bonjour, J'ai lu l'article ici https://forum.pcastuces.com/aide_au_diagnostic_un_pc_infecte_pcastuces-f25s17490.htm, Mais malheureusement il n'y a pas de ça ici: "Insérer un rapport", je n'ai pas trouvé. Ici il y a que ça Options : Modifié par novotek le 10/03/2015 09:02 | ||||||||
![]() | Bonjour novotek
En cas d'absence de Insérer un rapport, utiliser cjoint.com qui donnera un lien que tu indiqueras dans ta prochaine réponse ; choisir durée de conservation 21 jours.
| ||||||||
Petit astucien | |||||||||
Petit astucien | |||||||||
Groupe Sécurité ![]() |
Votre machine est infectée. Ce sujet serait mieux à sa place sur le forum Sécurité. Cliquez sur l'icône | ||||||||
Astucienne | El Magnifico a écrit : Bonjour. Je lui ai déjà demandé. | ||||||||
Petit astucien | J'ai envoyé une demande de déplacer mon sujet vers le forum "securité" | ||||||||
Astucienne | novotek a écrit : Re bonjour. D'accord tu n'as plus qu'a attendre patiemment qu'un helper te prenne en charge. Bonne journée. flober. | ||||||||
Petit astucien | ok, j'attends. mersi | ||||||||
Equipe PC Astuces | Bonjour, Le sujet a ÚtÚ dÚplacÚ par la modÚration dans le forum SÚcuritÚ qui semble plus adÚquat. Vous pouvez continuer la discussion Ó la suite de ce message. A bient¶t. | ||||||||
Groupe Sécurité ![]() | Salut, faires les 3 scans de base de ma signature. | ||||||||
Petit astucien | Que-ce que je dois faire maintenant? | ||||||||
![]() | Bonjour novotek
Ce que t'a demandé G225, c'est-à-dire cette procédure. Cordialement.
| ||||||||
Petit astucien | J'ai fait déjà hier l'analyse par ZHPDiag. vous avez vu le rapport. donc je dois repeter l'analyse par ZHPDiag? Malwarebyte me dit que mon ordi est propre. | ||||||||
Astucienne | Bonsoir. Suis cette procédure pour pouvoir être pris en charge par G 225. La procédure en cliquant sur le lien ci-dessous https://forum.pcastuces.com/aide_au_diagnostic_un_pc_infecte_pcastuces-f25s17490.htm Je te laisse avec G225 qui t'attend. bonne soirée. | ||||||||
Groupe Sécurité ![]() | Vous avez plusieurs infections encore, si malwarebytes à été fait, faire AdwCleaner. Si tout est fait me remettre le log ZHPdiag. Modifié par G225 le 10/03/2015 19:48 | ||||||||
Petit astucien | |||||||||
Groupe Sécurité ![]() | Ok comme vous voyez dans le premier il a découvert quelque chose donc supprimer. Continuer avec les autres.
| ||||||||
Petit astucien | Le rapport d'AdwCleaner | ||||||||
Astucienne | Re bonsoir. Que se passe-t-il vous n’arrivez pas a mettre zhpdiag ? Vous avez un problème,? remettez le log ZHPdiag. A vous lire.
| ||||||||
Petit astucien | Le nouvel rapport de ZHPDiag | ||||||||
Petit astucien | Fichier joint : ZHPDiag.txt | ||||||||
Petit astucien | Pas de reponse? | ||||||||
Petit astucien | |||||||||
Les bons plans du moment PC Astuces | Tous les Bons Plans | ||||||||||||||||||
|