hello i have problems when i navigate: i have new popup pages who open extremely often

i did use awdcleaner and there is the rapport :

# AdwCleaner v5.115 - Rapport créé le 02/05/2016 à 23:42:13 # Mis à jour le 01/05/2016 par Xplode # Base de données : 2016-05-01.2 [Locale] # Système d'exploitation : Windows 8.1 Connected  (X64) # Nom d'utilisateur : thomas - THOMAS # Exécuté depuis : C:\Users\thomas\Downloads\adwcleaner_5.115.exe # Option : Nettoyer # Support : http://toolslib.net/forum

***** [ Services ] *****

***** [ Dossiers ] *****

[-] Dossier supprimé : C:\ProgramData\867eb036-1e67-0 [-] Dossier supprimé : C:\ProgramData\9a76cd05-0667-1 [-] Dossier supprimé : C:\ProgramData\9a76cd05-4cd1-0 [-] Dossier supprimé : C:\ProgramData\ef26dbc2 [-] Dossier supprimé : C:\ProgramData\{08714ed9-012c-1} [-] Dossier supprimé : C:\ProgramData\{0fb4b915-012c-0} [-] Dossier supprimé : C:\ProgramData\{13f7b864-212c-0} [#] Dossier supprimé : C:\ProgramData\Application Data\867eb036-1e67-0 [#] Dossier supprimé : C:\ProgramData\Application Data\9a76cd05-0667-1 [#] Dossier supprimé : C:\ProgramData\Application Data\9a76cd05-4cd1-0 [#] Dossier supprimé : C:\ProgramData\Application Data\ef26dbc2 [#] Dossier supprimé : C:\ProgramData\Application Data\{08714ed9-012c-1} [#] Dossier supprimé : C:\ProgramData\Application Data\{0fb4b915-012c-0} [#] Dossier supprimé : C:\ProgramData\Application Data\{13f7b864-212c-0} [-] Dossier supprimé : C:\Program Files (x86)\DNS Unlocker [-] Dossier supprimé : C:\Program Files\Booking.com

***** [ Fichiers ] *****

[-] Fichier supprimé : C:\Users\Public\Desktop\eBay.lnk [-] Fichier supprimé : C:\Users\Public\Desktop\Booking.com.lnk [-] Fichier supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HowToRemove.html.lnk [-] Fichier supprimé : C:\Users\thomas\AppData\Roaming\Mozilla\Firefox\Profiles\etd4xcjq.default\searchplugins\Web Search.xml [-] Fichier supprimé : C:\Users\thomas\AppData\Roaming\Mozilla\Firefox\Profiles\etd4xcjq.default\searchplugins\Search Provided by Yahoo.xml [-] Fichier supprimé : C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.bestpriceninja.com_0.localstorage [-] Fichier supprimé : C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.bestpriceninja.com_0.localstorage-journal [-] Fichier supprimé : C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.eshopcomp.com_0.localstorage [-] Fichier supprimé : C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.eshopcomp.com_0.localstorage-journal [-] Fichier supprimé : C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.re-markit00.re-markit.co_0.localstorage [-] Fichier supprimé : C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.re-markit00.re-markit.co_0.localstorage-journal [-] Fichier supprimé : C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_utop.it_0.localstorage [-] Fichier supprimé : C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_utop.it_0.localstorage-journal [-] Fichier supprimé : C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage [-] Fichier supprimé : C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage-journal [-] Fichier supprimé : C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.eshopcomp.com_0.localstorage [-] Fichier supprimé : C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.eshopcomp.com_0.localstorage-journal [-] Fichier supprimé : C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_utop.it_0.localstorage [-] Fichier supprimé : C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_utop.it_0.localstorage-journal

***** [ DLLs ] *****

***** [ WMI ] *****

***** [ Raccourcis ] *****

***** [ Tâches planifiées ] *****

[-] Tâche supprimée : One System CarePeriod [-] Tâche supprimée : ShareLinks5 [-] Tâche supprimée : ShareLinks4 [-] Tâche supprimée : ShareLinks3 [-] Tâche supprimée : ShareLinks2 [-] Tâche supprimée : ACC [-] Tâche supprimée : DNSLOCKINGTON

***** [ Registre ] *****

[-] Clé supprimée : HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E [-] Valeur supprimée : HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION [SystemCash.exe] [-] Valeur supprimée : HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION [SystemCash.exe] [-] Clé supprimée : HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b [-] Clé supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ef26dbc2} [-] Clé supprimée : HKCU\Software\Classes\pokki [-] Clé supprimée : HKLM\SOFTWARE\Classes\protector_dll.Protector [-] Clé supprimée : HKLM\SOFTWARE\Classes\protector_dll.Protector.1 [-] Clé supprimée : HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib [-] Clé supprimée : HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1 [-] Clé supprimée : HKCU\Software\One System Care [-] Clé supprimée : HKCU\Software\PRODUCTSETUP [-] Clé supprimée : HKCU\Software\csastats [-] Clé supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E1527582-8509-4011-B922-29E3FB548882}_is1 [-] Clé supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\yahooprovidedsearch [-] Clé supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564 [-] Clé supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E1527582-8509-4011-B922-29E3FB548882}_is1 [-] Donnée restaurée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] [-] Donnée restaurée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{04CBE6BF-2244-11E5-8261-3065EC67D611} [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [-] Donnée restaurée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1b31c9d2-7135-442b-bb93-7c002172adc6} [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} [-] Clé supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} [-] Clé supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [-] Donnée restaurée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] [-] Clé supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1b31c9d2-7135-442b-bb93-7c002172adc6} [-] Clé supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} [-] Donnée restaurée : HKU\S-1-5-21-1704502057-2460348180-801270001-1001\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] [-] Donnée restaurée : HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{37F650BF-BA0B-48A5-9CEA-54F1E05D1189} [NameServer] [-] Donnée restaurée : HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{59CD288B-4E76-4638-A0D8-0CCAA58F9BF6} [NameServer] [-] Donnée restaurée : HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{7ECB9E90-E1B4-476D-BEE7-AC32B32EB2DF} [NameServer] [-] Donnée restaurée : HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{D5FB136A-FD22-4F9C-84EC-A0FF350762E2} [NameServer] [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\eshopcomp.com [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\pstatic.eshopcomp.com [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\re-markit.co [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\static.re-markit00.re-markit.co [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\akamaihd.net [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\eshopcomp.com [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\gamingwonderland.dl.tb.ask.com [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\homepage-web.com [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pstatic.eshopcomp.com [-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\utop.it

***** [ Navigateurs ] *****

[-] [C:\Users\thomas\AppData\Roaming\Mozilla\Firefox\Profiles\etd4xcjq.default\prefs.js] supprimée : user_pref("browser.search.defaultenginename", "Search Provided by Yahoo"); [-] [C:\Users\thomas\AppData\Roaming\Mozilla\Firefox\Profiles\etd4xcjq.default\prefs.js] supprimée : user_pref("browser.search.selectedEngine", "Search Provided by Yahoo");

*************************

:: Clés "Tracing" supprimées :: Paramètres Winsock réinitialisés

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [9585 octets] - [02/05/2016 23:42:13] C:\AdwCleaner\AdwCleaner[S1].txt - [11513 octets] - [02/05/2016 23:37:51]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [9734 octets] ##########

 

Re: internet navigation problem

Hello :)

First I'm not really sure, but are you French ? If so we will continue in French, it will be easer for us :)

I'm going to help you remove those pop-ups. ADWCleaner have done a great job, removing a lot of threats, but it might be not enough !

Then we will start by analysing your computer with ZHPDiag from Nicolas Coolman :

  • Download ZHPDiag from Nicolas on his website
  • Then run it with administrator's rights (with right click)
  • Then upload the log file on up2share (you will find it on your desktop, just drop the file on the upload zone)
  • Then post the link in your reply

A+

Chapi

Re: internet navigation problem

Bonjour,

Oui je suis francais, on peut continuer en francais

Je ne comprends pas quel fichier je dois upload sur up2share.

Merci

Re: internet navigation problem

Bonjour,

Bienvenue sur le forum ! Nous allons essayer de régler ton problème ensemble. D'abord, quelques rappels :

  • N'ouvre pas d'autres sujets pour le même problème (que ce soit sur ce forum ou sur un autre)
  • N'hésite pas à poser des questions en cas de besoin ;)
  • Sois patient(e) quand tu postes un message, je ne réponds pas instantanément : je suis bénévole et je ne suis pas en permanence devant mon ordinateur. Mais rassure toi, je ne laisse jamais tomber personne ;)
  • La désinfection (si nécessaire) va se dérouler en plusieurs étapes. Même si les symptômes de l'infection disparaissent, la désinfection ne sera terminée que quand je te le confirmerai --> Merci de revenir jusqu'au bout, sinon ce qu'on a fait n'aura servi à rien.

 

Revoilà des instructions plus détaillées :)

Commence par utiliser ZHPDiag, un logiciel de diagnostic de Nicolas Coolman, ça me permettra de t'aider :

  • Rends toi sur la page de téléchargement de ZHPDiag, puis clique sur le bouton bleu "Nicolas Coolman - Télécharger".
  • Enregistre le fichier où tu veux et lance le (si tu es sous Windows Vista, 7 ou 8, fais le par un clic-droit -> Exécuter en temps qu'administrateur).
  • Clique sur l'icône "Scanner" pour faire une analyse complète puis patiente, ça peut durer quelques minutes.
  • A la fin de l'analyse, clique sur l'icône "Rapport", un rapport va s'ouvrir, et s'enregistre sur ton bureau.
  • Rends toi sur up2share, héberge ton rapport et poste le lien dans ta prochaine réponse.

Bon courage,

Chapi

Re: internet navigation problem

voila c'est fait,

https://up2sha.re/file?f=CMK2qNvn6cuB

Merci de ton aide

Re: internet navigation problem

Salut !

Ok, donc il reste effectivement du monde.

Il y a des applications de jeux de poker, de paris... tu t'en sert ou c'est contre ta volonté ?

Utilise ce logiciel de désinfection généraliste pour nettoyer un peu :

  • Télécharge Malwarebytes Anti-Malware.
  • Installe-le en laissant les options par défaut (décoche juste à l'installation "Activer l'essai gratuit de MBAM Premium"), une icône sera créée sur le bureau et Malwarebytes démarrera.
  • Il te sera demandé de mettre à jour la base de données, fais-le.
  • Onglet "Analyse" choisis "Analyse des Menaces", puis clique sur "Lancer l'analyse".
  • Si un élément est détecté, choisis de tout supprimer. S'il t'est demandé de redémarrer l'ordinateur, accepte.
  • Après démarrage, relance Malwarebytes -> clique sur Historique -> Journaux de l'application -> Sélectionne le dernier Journal d'examen -> Afficher.
  • Clique en bas sur [Exporter] -> fichier texte (*.txt) -> Choisis le bureau comme emplacement, nomme le rapport-mbam par exemple, puis clique sur [Enregistrer].
  • Poste le rapport dans ta prochaine réponse sur le forum.

Bon courage,

Chapi

Re: internet navigation problem

salut,

oui je joue au poker et fait des paris sportifs

j'ai fait tout ce que tu m'as dit voici le rapport:

Malwarebytes Anti-Malware www.malwarebytes.org

Date de l'analyse: 03/05/2016 Heure de l'analyse: 15:11 Fichier journal: rapport mbam.txt Administrateur: Oui

Version: 2.2.1.1043 Base de données de programmes malveillants: v2016.05.03.05 Base de données de rootkits: v2016.04.17.01 Licence: Gratuit Protection contre les programmes malveillants: Désactivé Protection contre les sites Web malveillants: Désactivé Autoprotection: Désactivé

Système d'exploitation: Windows 8.1 Processeur: x64 Système de fichiers: NTFS Utilisateur: thomas

Type d'analyse: Analyse des menaces Résultat: Terminé Objets analysés: 350834 Temps écoulé: 33 min, 58 s

Mémoire: Activé Démarrage: Activé Système de fichiers: Activé Archives: Activé Rootkits: Désactivé Heuristique: Activé PUP: Activé PUM: Activé

Processus: 0 (Aucun élément malveillant détecté)

Modules: 0 (Aucun élément malveillant détecté)

Clés du Registre: 1 PUP.Optional.CloudScout, HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b, En quarantaine, [e69bb21fa3f6ab8b10e69bcf7e8629d7],

Valeurs du Registre: 0 (Aucun élément malveillant détecté)

Données du Registre: 1 Trojan.DNSChanger.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS|NameServer, 82.163.142.7 95.211.158.134, Bon : (8.8.8.8), Mauvais : (82.163.142.7 95.211.158.134),Remplacé,[c8b950819cfd0630f4ba94bfba4b926e]

Dossiers: 0 (Aucun élément malveillant détecté)

Fichiers: 5 PUP.Optional.InstallCore, C:\Users\thomas\Downloads\VideoPlayerSetup.exe, En quarantaine, [bdc49839d0c9280ef49768bf19e9db25], PUP.Optional.CrossRider, C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage, En quarantaine, [7c05a1306930fd393afd3a709173c33d], PUP.Optional.CrossRider, C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal, En quarantaine, [1f627a57ddbcb284de5983276e968878], PUP.Optional.SearchManager.ChrPRST, C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bahkljhhdeciiaodlkppoonappfnheoi_0.localstorage, En quarantaine, [e29fe7ea8514f83ee7293e7ae420758b], PUP.Optional.TerraClicks.ShrtCln, C:\Users\thomas\AppData\Local\Microsoft\Windows\INetCookies\Low\GJ4GBODX.txt, En quarantaine, [acd52aa76435360021968ef0e02524dc],

Secteurs physiques: 0 (Aucun élément malveillant détecté)

 

Re: internet navigation problem

Re !

Ok, MBAM a bien vu les mauvais DNS et a supprimé quelques extensions chromes illégitimes !

La navigation devrait s'améliorer !

On continue le nettoyage avec ZHPCleaner :

On va utiliser ZHPCleaner, un logiciel de nettoyage des navigateurs de Nicolas Coolman, ça me permettra de t'aider :

  • Rends toi sur la page de téléchargement de ZHPCleaner, puis clique sur le bouton bleu "Nicolas Coolman - Télécharger".
  • Enregistre le fichier où tu veux et lance le (si tu es sous Windows Vista, 7 ou 8, fais le par un clic-droit -> Exécuter en temps qu'administrateur).
  • Clique sur l'icône "Scanner" pour faire une analyse complète puis patiente, ça peut durer quelques minutes.
  • A la fin de l'analyse, clique sur l'icône "Rapport", un rapport va s'ouvrir, et s'enregistre sur ton bureau.
  • Copie colle le contenu du rapport dans ta réponse

Bon courage,

Chapi

Re: internet navigation problem

~ ZHPDiag v2016.5.3.93 Par Nicolas Coolman (2016/05/03) ~ Démarré par thomas (Administrator)  (2016/05/03 17:06:16) ~ Site: http://www.nicolascoolman.com ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Etat de la version:  Version OK ~ Mode: Scanner ~ Rapport: C:\Users\thomas\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\thomas\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ Démarrage du système: Normal (Normal boot) Windows 8.1 Connected, 64-bit  (Build 9600)

---\\ Navigateurs Internet (2) - 0s MFIE: Mozilla Firefox 46.0 (x86 fr) MSIE: Internet Explorer v11.0.9600.18283

---\\ Informations sur les produits Windows (8) - 0s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK ~ Windows(R) Operating System, OEM_DM channel Windows ID Activation : OK ~ Windows Partial Key : BY36R Windows License : OK ~ Windows Remaining Initializations Number :  998 Windows Automatic Updates : OK

---\\ Logiciels de protection (2) - 6s Malwarebytes Anti-Malware version 2.2.1.1043 Windows Defender  (Deactivate)

---\\ Surveillance de Logiciels (1) - 7s Adobe Flash Player 21 NPAPI

---\\ Informations sur le système (6) - 0s ~ Operating System: Intel64 Family 6 Model 55 Stepping 8, GenuineIntel ~ Operating System:  64-bit  ~ Boot mode: Normal (Normal boot) Total RAM: 4073.448 MB (65% free) System Restore: Activé (Enable) System drive C: has 416 GB () free of 461 GB

---\\ Mode de connexion au système (3) - 0s ~ Computer Name: THOMAS ~ User Name: thomas ~ Logged in as Administrator

---\\ Enumération des unités disques (1) - 0s ~ Drive C: has 416 GB free of 461 GB  (System)

---\\ Etat du Centre de Sécurité Windows (11) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Recherche particulière de fichiers génériques (25) - 1s [MD5.B3541A5A20C6264781909B1B7FE54836] - 09/02/2016 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [2757616]  =>.Microsoft Windows® [MD5.6C308D32AFA41D26CE2A0EA8F7B79565] - 29/10/2014 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [54784]  =>.Microsoft Corporation [MD5.EC302D06155F8E3C383750993FCB6B27] - 05/10/2015 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [146432]  =>.Microsoft Corporation [MD5.D2E3B1DEDF6F6177D8C32B2516703A93] - 31/03/2016 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [2596864]  =>.Microsoft Corporation [MD5.B1102BBDDD9C87B3D609D6C08F7A3DBD] - 05/01/2016 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [570880]  =>.Microsoft Corporation [MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - 18/03/2014 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [447488]  =>.Microsoft Corporation [MD5.A5675939CF0F99B20B5A3CFCC3C1B46A] - 29/10/2014 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [657920]  =>.Microsoft Corporation [MD5.BD9C7A068C46053F8747CEA73B5930AB] - 29/10/2014 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\Syswow64\dnsapi.dll [498688]  =>.Microsoft Corporation [MD5.E37F897ED7B5AFF79B1398258DB96BD9] - 14/01/2015 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [19456]  =>.Microsoft Corporation [MD5.A460C3AF3755A2A79A3C8EFE72E147B5] - 13/10/2015 - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\Windows\System32\drivers\AFD.sys [559616]  =>.Microsoft Corporation [MD5.74B14192CF79A72F7536B27CB8814FBD] - 22/08/2013 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [26464]  =>.Microsoft Windows® [MD5.2FA6510E33F7DEFEC03658B74101A9B9] - 22/08/2013 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [88576]  =>.Microsoft Corporation [MD5.C6796EA22B513E3457514D92DCDB1A3D] - 22/08/2013 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [164352]  =>.Microsoft Corporation [MD5.A03F362C5557E238CBFA914689C77248] - 06/03/2014 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [134144]  =>.Microsoft Corporation [MD5.D4B7ED39C7900384D9E5C1283F1E7926] - 24/07/2014 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [76800]  =>.Microsoft Corporation [MD5.49EE0AE9E5B64FFBBD06D55C4984B598] - 04/11/2014 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [108544]  =>.Microsoft Corporation [MD5.B7342B3C58E91107F6E946A93D9D4EFD] - 18/03/2014 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [142848]  =>.Microsoft Corporation [MD5.5F2BB54E0223E46646789E90BB4CCD81] - 10/03/2016 - (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\Windows\System32\drivers\MRxSmb.sys [401920]  =>.Microsoft Corporation [MD5.0217532E19A748F0E5D569307363D5FD] - 22/08/2013 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [282624]  =>.Microsoft Corporation [MD5.9980B262DBE439AE6BDC91AA985F19EE] - 30/12/2015 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [2017624]  =>.Microsoft Windows® [MD5.764B1121867B2D9B31C491668AC72B2B] - 22/08/2013 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [94208]  =>.Microsoft Corporation [MD5.235624C147E3CB4C288D5D3D8E8D64A2] - 02/02/2016 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [112640]  =>.Microsoft Corporation [MD5.680C1DAE268B6FB67FA21B389A8B79EF] - 18/03/2014 - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\Windows\System32\drivers\rdpdr.sys [195584]  =>.Microsoft Corporation [MD5.E0BD2D83875464FEEEB242CBA8B7E073] - 13/10/2015 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [108032]  =>.Microsoft Corporation [MD5.D537962695CAFEC1301F3EB7C8C3A1D2] - 07/02/2016 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [316760]  =>.Microsoft Windows®

---\\ Liste des services NT non Microsoft et non désactivés (10) - 3s O23 - Service: AtherosSvc (AtherosSvc) . (.Windows (R) Win 7 DDK provider - Windows Setup API.) - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe  =>.Windows (R) Win 7 DDK provider O23 - Service: Avast Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe  =>.AVAST Software a.s.® O23 - Service: CCDMonitorService (CCDMonitorService) . (.Acer Incorporated - CCD Monitor Service.) - C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe  =>.Acer Incorporated® O23 - Service: GamesAppIntegrationService (GamesAppIntegrationService) . (.WildTangent - WildTangent Games App Integration Service.) - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe  =>.WildTangent Inc® O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  =>.Google Inc® O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\Windows\System32\igfxCUIService.exe  =>.Intel Corporation - Software and Firmware Products® O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe  =>.Intel(R) Corporation O23 - Service: Launch Manager Service (LMSvc) . (.Acer Incorporate - LMSvc.) - C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe  =>.Acer Incorporated® O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) . (.Copyright 2004 - RichVideo Module.) - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe  =>.CyberLink® O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe  =>.Skype Software Sarl®

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (24) - 31s

SS - Demand [07/04/2016] [  269504]  Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe  =>.Adobe Systems Incorporated® SR - Auto   [29/04/2014] [  319104]  AtherosSvc (AtherosSvc) . (.Windows (R) Win 7 DDK provider.) - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe  =>.Windows (R) Win 7 DDK provider SR - Auto   [29/04/2016] [  243296]  Avast Antivirus (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe  =>.AVAST Software a.s.® SR - Auto   [18/04/2016] [ 2860760]  CCDMonitorService (CCDMonitorService) . (.Acer Incorporated.) - C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe  =>.Acer Incorporated® SS - Demand [09/06/2014] [  279024]  Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe  =>.Intel Corporation - Software and Firmware Products® SR - Demand [12/06/2014] [ 2573032]  ePower Service (ePowerSvc) . (.Acer Incorporated.) - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe  =>.Acer Incorporated® SR - Auto   [24/04/2014] [  227904]  GamesAppIntegrationService (GamesAppIntegrationService) . (.WildTangent.) - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe  =>.WildTangent Inc® SS - Demand [24/04/2014] [  203344]  GamesAppService (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe  =>.WildTangent Inc® SS - Auto   [29/04/2016] [  154440]  Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  =>.Google Inc® SS - Demand [29/04/2016] [  154440]  Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  =>.Google Inc® SS - Demand [29/04/2016] [  194032]  Google Software Updater (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe  =>.Google Inc® SS - Demand [24/04/2012] [  169752]  Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe  =>.Intel Corporation® SR - Auto   [09/06/2014] [  315376]  Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation.) - C:\Windows\System32\igfxCUIService.exe  =>.Intel Corporation SR - Auto   [01/07/2013] [  733696]  Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe  =>.Intel(R) Corporation SS - Demand [01/07/2013] [  822232]  Intel(R) Capability Licensing Service TCP IP Interface (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe  =>.Intel® Trusted Connect Service® SR - Auto   [28/07/2014] [  469736]  Launch Manager Service (LMSvc) . (.Acer Incorporate.) - C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe  =>.Acer Incorporated® SS - Demand [11/03/2016] [  293128]  McAfee Security Scan Component Host Service (McComponentHostService) . (.McAfee, Inc..) - C:\Program Files\McAfee Security Scan\3.11.309\McCHSvc.exe  =>.McAfee, Inc.® SS - Demand [22/04/2016] [  146888]  Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe  =>.Mozilla Corporation® SR - Demand [26/06/2014] [  458984]  Quick Access Service (QASvc) . (.Acer Incorporate.) - C:\Program Files\Acer\Acer Quick Access\QASvc.exe  =>.Acer Incorporated® SR - Auto   [24/04/2012] [  254512]  Cyberlink RichVideo Service(CRVS) (RichVideo) . (.Copyright 2004.) - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe  =>.CyberLink® SR - Demand [26/06/2014] [  449768]  Quick Access RadioMgr Service (RMSvc) . (.Acer Incorporate.) - C:\Program Files\Acer\Acer Quick Access\RMSvc.exe  =>.Acer Incorporated® SS - Auto   [23/03/2016] [  327808]  Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe  =>.Skype Software Sarl® SR - Demand [15/07/2014] [  234240]  User Experience Improvement Program (UEIPSvc) . (.acer.) - C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe  =>.Acer Incorporated®

---\\ Tâches planifiées en automatique (35) - 5s [MD5.D246B77DF1B4302BDC1332986F26815C] [APT] [abDocsDllLoader] (...) -- C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe   [1769312] (.Activate.)  =>.Acer Incorporated® [MD5.192551432A694B27E9EEBDA5794CCB12] [APT] [ACCAgent] (.(C) All rights reserved.) -- C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe   [41728] (.Activate.)  =>.Acer Incorporated® [MD5.7E2857D4C8F7732AABB68CEBD8C8A239] [APT] [AcerCloud] (.Acer.) -- C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe   [2732760] (.Activate.)  =>.Acer Incorporated® [MD5.28FFB14117CCEDD7D2F124596AA9B785] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe   [269504] (.Activate.)  =>.Adobe Systems Incorporated® [MD5.1282F8C897DBF180BCF3F6F6968DE2C3] [APT] [avast! Emergency Update] (.AVAST Software.) -- C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe   [1517200] (.Activate.)  =>.AVAST Software a.s.® [MD5.962C647021EF055DEDDAD5539701F4E5] [APT] [BacKGroundAgent] (.Acer Incorporated.) -- C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe   [65752] (.Activate.)  =>.Acer Incorporated® [MD5.750446ED76A5D13E902174DDDDA1A62B] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe   [154440] (.Activate.)  =>.Google Inc® [MD5.750446ED76A5D13E902174DDDDA1A62B] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe   [154440] (.Activate.)  =>.Google Inc® [MD5.5F3DD75B6509495B32CE535153C8DC4A] [APT] [Launch Manager] (.Acer Incorporate.) -- C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe   [439016] (.Activate.)  =>.Acer Incorporated® [MD5.31A7FBA1017E8D625FDA12A670316ACC] [APT] [Power Management] (.Acer Incorporated.) -- C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe   [384232] (.Activate.)  =>.Acer Incorporated® [MD5.E88CD2B99BA576F98EC267E10101A979] [APT] [Quick Access] (.Acer Incorporate.) -- C:\Program Files\Acer\Acer Quick Access\QALauncher.exe   [324328] (.Activate.)  =>.Acer Incorporated® [MD5.E88CD2B99BA576F98EC267E10101A979] [APT] [Quick Access Quick Launcher] (.Acer Incorporate.) -- C:\Program Files\Acer\Acer Quick Access\QALauncher.exe   [324328] (.Activate.)  =>.Acer Incorporated® [MD5.2E696C90B2D1DD842F59E38FD212D225] [APT] [SafeZone scheduled Autoupdate 1461941188] (.Avast Software.) -- C:\Program Files\AVAST Software\SZBrowser\launcher.exe   [735736] (.Activate.)  =>.AVAST Software s.r.o.® [MD5.896E37BE296D7A4061355453F4AE6949] [APT] [Software Update Application] (.Acer Incorporated.) -- C:\ProgramData\OEM\UpgradeTool\ListCheck.exe   [474344] (.Activate.)  =>.Acer Incorporated® [MD5.6C531EBEFA4718C279D1C1729C77D230] [APT] [UbtFrameworkService] (.TODO: <Company name>.) -- C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe   [216296] (.Activate.)  =>.Acer Incorporated® [MD5.E589CA68E70D8821ACC5717F68FB0438] [APT] [{C328AB93-ED7A-443D-9AFC-347EC3A6E97F}] (.Blizzard Entertainment.) -- C:\ProgramData\Battle.net\Agent\Blizzard Uninstaller.exe   [1420264] (.Activate.)  =>.Blizzard Entertainment, Inc.® [MD5.00000000000000000000000000000000] [APT] [AVAST Software\] (...) -- C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe (.not file.)   [0] (.Activate.)  =>.Superfluous.Empty O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job  [1002]   =>.Adobe Systems Incorporated® O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job  [1086]   =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job  [1090]   =>.Google Inc® O39 - APT: abDocsDllLoader - (...) -- C:\Windows\System32\Tasks\abDocsDllLoader  [3338]   =>.Acer Incorporated® O39 - APT: ACCAgent - (.(C) All rights reserved.) -- C:\Windows\System32\Tasks\ACCAgent  [4562]   =>.Acer Incorporated® O39 - APT: AcerCloud - (.Acer.) -- C:\Windows\System32\Tasks\AcerCloud  [3334]   =>.Acer Incorporated® O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater  [3890]   =>.Adobe Systems Incorporated® O39 - APT: avast! Emergency Update - (.AVAST Software.) -- C:\Windows\System32\Tasks\avast! Emergency Update  [4182]   =>.AVAST Software a.s.® O39 - APT: BacKGroundAgent - (.Acer Incorporated.) -- C:\Windows\System32\Tasks\BacKGroundAgent  [3442]   =>.Acer Incorporated® O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore  [3826]   =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA  [4062]   =>.Google Inc® O39 - APT: Launch Manager - (.Acer Incorporate.) -- C:\Windows\System32\Tasks\Launch Manager  [2904]   =>.Acer Incorporated® O39 - APT: Power Management - (.Acer Incorporated.) -- C:\Windows\System32\Tasks\Power Management  [2930]   =>.Acer Incorporated® O39 - APT: Quick Access - (.Acer Incorporate.) -- C:\Windows\System32\Tasks\Quick Access  [2896]   =>.Acer Incorporated® O39 - APT: Quick Access Quick Launcher - (.Acer Incorporate.) -- C:\Windows\System32\Tasks\Quick Access Quick Launcher  [3016]   =>.Acer Incorporated® O39 - APT: SafeZone scheduled Autoupdate 1461941188 - (.Avast Software.) -- C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1461941188  [3912]   =>.AVAST Software s.r.o.® O39 - APT: Software Update Application - (.Acer Incorporated.) -- C:\Windows\System32\Tasks\Software Update Application  [5314]   =>.Acer Incorporated® O39 - APT: UbtFrameworkService - (.TODO: <Company name>.) -- C:\Windows\System32\Tasks\UbtFrameworkService  [3268]   =>.Acer Incorporated®

---\\ Processus lancés (40) - 3s [MD5.5264EE143875DDEA0E8CF8540C2AA743] - (.Intel Corporation - igfxCUIService Module.) -- C:\Windows\System32\igfxCUIService.exe [315376] [PID.780]  =>.Intel Corporation - Software and Firmware Products® [MD5.A24AF1F8186B4B69D54DCC4B059CA695] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296] [PID.1200]  =>.AVAST Software a.s.® [MD5.23C3686D98C650878602066093BAFDCA] - (.Windows (R) Win 7 DDK provider - Windows Setup API.) -- C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [319104] [PID.1448]  =>.Windows (R) Win 7 DDK provider [MD5.41D709EB4211F6F6411F6105FA39518F] - (.Acer Incorporated - CCD Monitor Service.) -- C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2860760] [PID.1528]  =>.Acer Incorporated® [MD5.33AB22661E4DE1701F41CAFFB9DA1FEF] - (.Acer Cloud Technology - AcerCloud Client.) -- C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe [9685208] [PID.1584]  =>.Acer Incorporated® [MD5.768DD5CB66952BC4A3BD474757AEE34F] - (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) -- C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696] [PID.1912]  =>.Intel(R) Corporation [MD5.33B494BAED00188832C86C3E9456CFF6] - (.Acer Incorporate - LMSvc.) -- C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [469736] [PID.1952]  =>.Acer Incorporated® [MD5.41DDCF1ADD1FB7DE23DCF671740DDBE6] - (.Copyright 2004 - RichVideo Module.) -- C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512] [PID.2032]  =>.CyberLink® [MD5.4A336C92A790A3F7C2D9952C73FCFA16] - (.WildTangent - WildTangent Games App Integration Service.) -- C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904] [PID.3776]  =>.WildTangent Inc® [MD5.C013945767C5777250220330A377E6E0] - (.Acer Incorporate - LMEvent.) -- C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe [488168] [PID.844]  =>.Acer Incorporated® [MD5.D3D4EA7E66F5094B6E37BD742935D684] - (.Intel Corporation - igfxEM Module.) -- C:\Windows\System32\igfxEM.exe [501744] [PID.2352]  =>.Intel Corporation - Software and Firmware Products® [MD5.0C396D2FEFBB85F78DCB573993B8EF01] - (.Intel Corporation - igfxHK Module.) -- C:\Windows\System32\igfxHK.exe [244208] [PID.3100]  =>.Intel Corporation - Software and Firmware Products® [MD5.2ACAB8C99FFCB2555A5979944D26EB50] - (.Acer Incorporate - QASvc.) -- C:\Program Files\Acer\Acer Quick Access\QASvc.exe [458984] [PID.1220]  =>.Acer Incorporated® [MD5.BBB2E8CB493FA6BCAA2D2F87DFCE2F71] - (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxTray.exe [443888] [PID.3060]  =>.Intel Corporation - Software and Firmware Products® [MD5.3C9C7EEEEFD793CDEF34ED27728C43A3] - (.Acer Incorporate - LockHandler.) -- C:\Program Files\Acer\Acer Launch Manager\LMLockHandler.exe [455912] [PID.1464]  =>.Acer Incorporated® [MD5.0D1DF703F823DC9B93A0E8182AC67219] - (.Acer Incorporate - QAEvent.) -- C:\Program Files\Acer\Acer Quick Access\QAEvent.exe [521960] [PID.3520]  =>.Acer Incorporated® [MD5.09080EB3EFE34B0673424126F6DD3EB3] - (.Acer Incorporate - LMTray.) -- C:\Program Files\Acer\Acer Launch Manager\LMTray.exe [467176] [PID.4060]  =>.Acer Incorporated® [MD5.F1B23CCDFF34381C148DFF00C724858B] - (.Acer Incorporate - QAMsg.) -- C:\Program Files\Acer\Acer Quick Access\QAMsg.exe [447720] [PID.4092]  =>.Acer Incorporated® [MD5.F800FEA3F6865E506AC2B218F25F1E38] - (.Acer Incorporated - ePowerSvc.) -- C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573032] [PID.2924]  =>.Acer Incorporated® [MD5.0059DF176F4DDA8BC21DF1D62EED37D1] - (.Acer Incorporated - ePowerTray.) -- C:\Program Files\Acer\Acer Power Management\ePowerTray.exe [5471976] [PID.984]  =>.Acer Incorporated® [MD5.216B50CA20FFB633F61263D3F7AD4AA9] - (.Intel Corporation - igfxext Module.) -- C:\Windows\System32\igfxext.exe [191472] [PID.4212]  =>.Intel Corporation - Software and Firmware Products® [MD5.868471D645DD04EBECE7E15252E3BB03] - (.Acer Incorporated - ePowerEvent.) -- C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe [394472] [PID.4392]  =>.Acer Incorporated® [MD5.315B9B9977B03AC004E3B375A39591D6] - (.Acer Incorporated - ePowerWinMonitor.) -- C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe [259304] [PID.4448]  =>.Acer Incorporated® [MD5.858DB87C457D2B44DDEF876B170AAACE] - (.Acer Incorporate - RMSvc.) -- C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [449768] [PID.4808]  =>.Acer Incorporated® [MD5.7E2857D4C8F7732AABB68CEBD8C8A239] - (.Acer - Acer Portal.) -- C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2732760] [PID.4816]  =>.Acer Incorporated® [MD5.962C647021EF055DEDDAD5539701F4E5] - (.Acer Incorporated - Background Agent.) -- C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [65752] [PID.4752]  =>.Acer Incorporated® [MD5.D246B77DF1B4302BDC1332986F26815C] - (...) -- C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe [1769312] [PID.4344]  =>.Acer Incorporated® [MD5.C91635CC2BF215F9D7A5A7FC2E385D1D] - (...) -- C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe [91488] [PID.3440]  =>.Acer Incorporated® [MD5.EB7E8BF35D31BC9F111E282C2F263854] - (.acer - UEIPSvc.) -- C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [234240] [PID.1144]  =>.Acer Incorporated® [MD5.3DB9682912F54D6E38BD2545914E6657] - (.TODO: <Company name> - AppMonitorPlugIn.) -- C:\Program Files\Acer\User Experience Improvement Program\Plugin\AppMonitor\AppMonitorPlugIn.exe [434944] [PID.3152]  =>.Acer Incorporated® [MD5.60C7EEBDA66DBBE45A3D63D4502F8FEE] - (.Qualcomm®Atheros® - Extension Core.) -- C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [134784] [PID.2324]  =>.Qualcomm®Atheros® [MD5.6BECBB538954FA2E01194A686AE57D83] - (...) -- C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe [12928] [PID.4552] [MD5.DA2D7BED47EF71BDFEEDDEEE76C965FD] - (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672664] [PID.1832]  =>.Realtek Semiconductor Corp® [MD5.CC436BB2A26391F3DEBE316F6FB0474F] - (.© 2015 Microsoft Corporation - Microsoft Bing Service.) -- C:\Users\thomas\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008] [PID.908]  =>.Microsoft Corporation® [MD5.0C03FB91E17987EED93F60007B08DAA0] - (.Google Inc. - Programme d'installation de Google.) -- C:\Users\thomas\AppData\Local\Google\Update\GoogleUpdate.exe [144200] [PID.2208]  =>.Google Inc® [MD5.E6ABF2F9E5CB1B1C3E61B923D9F1773F] - (.acer - abFiles.) -- C:\Program Files (x86)\Acer\abFiles\abFilesTrayIcon.exe [2289880] [PID.5272]  =>.Acer Incorporated® [MD5.1DBD44E4C19F6EC1665A89ABC884DF56] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe [51662464] [PID.5696]  =>.Skype Software Sarl® [MD5.8E43AB1178841FE8F84C0E8610E44F3D] - (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe [334088] [PID.6004]  =>.McAfee, Inc.® [MD5.B667FA2111F989360E54BBF2C4D35740] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [7391632] [PID.5492]  =>.AVAST Software a.s.® [MD5.C0BEFA3AC43EF008058330BBF4F01BCA] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\thomas\ZHPDiag3.exe [2200576] [PID.11184]  =>.Nicolas Coolman

---\\ Google Chrome, Démarrage,Recherche,Extensions (19) - 1s G0 - GCSP: Preferences [User Data\Default][HomePage] http://a.global-cdn.co G0 - GCSP: Preferences [User Data\Default][HomePage] http://apis.google.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://chrome.google.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://clients2.google.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://clients2.googleusercontent.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://m77.dnsqa365.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.fr G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.gstatic.com G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest  =>.Google Inc. G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest  =>.Google Inc. G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest  =>.Google Inc. G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest  =>.Google Inc. G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest  =>.Google Inc. G2 - GCE: Preference [User Data\Default] [fheoggkfdfchfphceeifdbepaooicaho] SiteAdvisor G2 - GCE: Preference [User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] Google Chrome manifest  =>.Google Inc. G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest  =>.Google Inc. G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest  =>.Google Inc.

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (7) - 2s P2 - EXT FILE: (...) -- C:\Users\thomas\AppData\Roaming\Mozilla\Firefox\Profiles\etd4xcjq.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi P2 - EXT FILE: (...) -- C:\Users\thomas\AppData\Roaming\Mozilla\Firefox\Profiles\etd4xcjq.default\searchplugins\McSiteAdvisor.xml P2 - EXT: (.Microsoft Corporation - Bing Search.) -- C:\Users\thomas\AppData\Roaming\Mozilla\Firefox\Profiles\etd4xcjq.default\extensions\bingsearch.full@microsoft.com  =>.Microsoft Corporation P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll  =>.Adobe Systems Incorporated P2 - FPN: [HKLM] [@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf] - (...) -- C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll P2 - FPN: [HKLM] [@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf] - (...) -- C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll P2 - FPN: [HKLM] [@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (.WildTangent.) -- C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll  =>.WildTangent

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (18) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean  =>.Microsoft Internet Explorer R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1

---\\ Internet Explorer,Proxy Management (4) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.)  =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.)  =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.)  =>.Microsoft Corporation

---\\ Etude du fichier hosts (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (30)

---\\ Browser Helper Object de navigateur (BHO) (5) - 1s O2 - BHO: Lync Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA}  (Orphean) O2 - BHO: avast! Online Security [64Bits] - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll  =>.AVAST Software a.s.® O2 - BHO: Google Toolbar Helper [64Bits] - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll  =>.Google Inc® O2 - BHO: SkypeIEPluginBHO [64Bits] - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll  =>.Skype Software Sarl® O2 - BHO: Microsoft OneDrive for Business Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}  (Orphean)

---\\ Applications lancées au démarrage du système (20) - 1s O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe  =>.Realtek Semiconductor Corp® O4 - HKCU\..\Run: [BingSvc] . (.© 2015 Microsoft Corporation - Microsoft Bing Service.) -- C:\Users\thomas\AppData\Local\Microsoft\BingSvc\BingSvc.exe  =>.Microsoft Corporation® O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\thomas\AppData\Local\Google\Update\GoogleUpdate.exe  =>.Google Inc® O4 - HKCU\..\Run: [RemoteFilesTrayIcon] . (.acer - abFiles.) -- C:\Program Files (x86)\Acer\abFiles\abFilesTrayIcon.exe  =>.Acer Incorporated® O4 - HKCU\..\Run: [AcerPortal] . (.Acer - Acer Portal.) -- C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe  =>.Acer Incorporated® O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe  =>.Skype Software Sarl® O4 - HKCU\..\Run: [Chromium] c:\users\thomas\appdata\local\chromium\application\chrome.exe (.not file.) O4 - HKCU\..\RunOnce: [Application Restart #1] C:\Users\thomas\AppData\Local\Pokki\Engine\ServiceHostApp.exe (.not file.) O4 - HKCU\..\RunOnce: [Application Restart #0] C:\Users\thomas\AppData\Local\Pokki\Engine\ServiceHostApp.exe (.not file.) O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe  =>.AVAST Software a.s.® O4 - HKLM\..\Wow6432Node\RunOnce: [Gohabi] . (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\SysWOW64\wscript.exe  =>.Microsoft Corporation O4 - HKLM\..\policies\Explorer\Run: [BtvStack] . (.Qualcomm®Atheros® - Extension Core.) -- C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe  =>.Qualcomm®Atheros® O4 - HKUS\S-1-5-21-1704502057-2460348180-801270001-1001\..\Run: [BingSvc] . (.© 2015 Microsoft Corporation - Microsoft Bing Service.) -- C:\Users\thomas\AppData\Local\Microsoft\BingSvc\BingSvc.exe  =>.Microsoft Corporation® O4 - HKUS\S-1-5-21-1704502057-2460348180-801270001-1001\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\thomas\AppData\Local\Google\Update\GoogleUpdate.exe  =>.Google Inc® O4 - HKUS\S-1-5-21-1704502057-2460348180-801270001-1001\..\Run: [RemoteFilesTrayIcon] . (.acer - abFiles.) -- C:\Program Files (x86)\Acer\abFiles\abFilesTrayIcon.exe  =>.Acer Incorporated® O4 - HKUS\S-1-5-21-1704502057-2460348180-801270001-1001\..\Run: [AcerPortal] . (.Acer - Acer Portal.) -- C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe  =>.Acer Incorporated® O4 - HKUS\S-1-5-21-1704502057-2460348180-801270001-1001\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe  =>.Skype Software Sarl® O4 - HKUS\S-1-5-21-1704502057-2460348180-801270001-1001\..\Run: [Chromium] c:\users\thomas\appdata\local\chromium\application\chrome.exe (.not file.) O4 - HKUS\S-1-5-21-1704502057-2460348180-801270001-1001\..\RunOnce: [Application Restart #1] C:\Users\thomas\AppData\Local\Pokki\Engine\ServiceHostApp.exe (.not file.) O4 - HKUS\S-1-5-21-1704502057-2460348180-801270001-1001\..\RunOnce: [Application Restart #0] C:\Users\thomas\AppData\Local\Pokki\Engine\ServiceHostApp.exe (.not file.)

---\\ Raccourcis Global Startup (29) - 9s O4 - GS\Desktop [Administrateur]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\thomas\ZHPDiag3.exe  =>.Nicolas Coolman O4 - GS\sendTo [Administrateur]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe  =>.Skype Software Sarl® O4 - GS\TaskBar [Administrateur]: abPhoto.lnk . (.Acer Incorporated - abPhoto.) C:\Program Files (x86)\Acer\abPhoto\abPhoto.exe  =>.Acer Incorporated® O4 - GS\TaskBar [Administrateur]: Acer Quick Access.lnk . (.Acer Incorporate - .) C:\Program Files (x86)\Acer\Acer Quick Access\QuickAccess.exe  =>.Acer Incorporate O4 - GS\Desktop [thomas]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\thomas\ZHPDiag3.exe  =>.Nicolas Coolman O4 - GS\sendTo [thomas]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe  =>.Skype Software Sarl® O4 - GS\TaskBar [thomas]: abPhoto.lnk . (.Acer Incorporated - abPhoto.) C:\Program Files (x86)\Acer\abPhoto\abPhoto.exe  =>.Acer Incorporated® O4 - GS\TaskBar [thomas]: Acer Quick Access.lnk . (.Acer Incorporate - .) C:\Program Files (x86)\Acer\Acer Quick Access\QuickAccess.exe  =>.Acer Incorporate O4 - GS\CommonDesktop [Public]: abDocs.lnk . (.acer - abDocs.) C:\Program Files (x86)\Acer\abDocs\abDocs.exe  =>.Acer Incorporated® O4 - GS\CommonDesktop [Public]: abFiles.lnk . (.acer - abFiles.) C:\Program Files (x86)\Acer\abFiles\abFilesTrayIcon.exe  =>.Acer Incorporated® O4 - GS\CommonDesktop [Public]: abMusic.lnk . (.Acer Incorporated - abMusic.) C:\Program Files (x86)\Acer\abMusic\abMusic.exe  =>.Acer Incorporated® O4 - GS\CommonDesktop [Public]: abPhoto.lnk . (.Acer Incorporated - abPhoto.) C:\Program Files (x86)\Acer\abPhoto\abPhoto.exe  =>.Acer Incorporated® O4 - GS\CommonDesktop [Public]: Acer Care Center.lnk . (.(C)All rights reserved - CareCenter.) C:\Program Files (x86)\Acer\Care Center\CareCenter.exe  =>.Acer Incorporated® O4 - GS\CommonDesktop [Public]: Acer Portal.lnk . (.Acer - Acer Portal.) C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe  =>.Acer Incorporated® O4 - GS\CommonDesktop [Public]: Acheter en ligne.lnk . (...) C:\Program Files (x86)\Accessory Store\StartUrl.exe O4 - GS\CommonDesktop [Public]: Avast Antivirus Gratuit.lnk . (.AVAST Software - .) C:\Program Files (x86)\AVAST Software\Avast\AvastUI.exe  =>.AVAST Software O4 - GS\CommonDesktop [Public]: Avast SafeZone Browser.lnk . (.Avast Software - .) C:\Program Files (x86)\AVAST Software\SZBrowser\launcher.exe  =>.AVAST Software O4 - GS\CommonDesktop [Public]: CyberLink PhotoDirector 3.lnk . (.CyberLink Corp. - CyberLink PhotoDirector 3.) C:\Program Files (x86)\CyberLink\PhotoDirector3\PhotoDirector3.exe  =>.CyberLink Corp.® O4 - GS\CommonDesktop [Public]: CyberLink PowerDirector 10.lnk . (.CyberLink Corp. - PowerDirector 10.) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.exe  =>.CyberLink Corp.® O4 - GS\CommonDesktop [Public]: Dropbox.lnk . (...) C:\Program Files (x86)\Dropbox\StartURL.exe O4 - GS\CommonDesktop [Public]: Foxit PhantomPDF.lnk . (.Foxit Corporation - Foxit PhantomPDF 6.0.) C:\Program Files (x86)\Foxit PhantomPDF\FoxitPhantomPDF.exe  =>.Foxit Corporation® O4 - GS\CommonDesktop [Public]: Malwarebytes Anti-Malware.lnk . (.Malwarebytes - Malwarebytes Anti-Malware.) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe  =>.Malwarebytes Corporation® O4 - GS\CommonDesktop [Public]: McAfee Security Scan Plus.lnk . (.McAfee, Inc. - .) C:\Program Files (x86)\McAfee Security Scan\3.11.309\McUICnt.exe  =>.McAfee, Inc. O4 - GS\CommonDesktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe  =>.Mozilla Corporation® O4 - GS\CommonDesktop [Public]: Skype.lnk . (...) C:\Windows\Installer\{FC965A47-4839-40CA-B618-18F486F042C6}\SkypeIcon.exe O4 - GS\Startup [Public]: McAfee Security Scan Plus.lnk . (.McAfee, Inc. - .) C:\Program Files (x86)\McAfee Security Scan\3.11.309\SSScheduler.exe  =>.McAfee, Inc. O4 - GS\Programs [Public]: Documents.lnk . (...) C:\Users\thomas\Documents O4 - GS\Programs [Public]: Gestionnaire audio HD.lnk . (.Realtek Semiconductor - .) C:\Program Files (x86)\Realtek\Audio\HDA\RAVCpl64.exe  =>.Realtek Semiconductor O4 - GS\Programs [Public]: Pictures.lnk . (...) C:\Users\thomas\Pictures

 

Re: internet navigation problem

---\\ Modification Domaine/Adresses DNS (6) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.8.4  =>.Google Public DNS O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{37F650BF-BA0B-48A5-9CEA-54F1E05D1189}: DhcpNameServer = 82.163.142.7  =>PUP.Optional.DNSUnlocker O17 - HKLM\System\CCS\Services\Tcpip\..\{59CD288B-4E76-4638-A0D8-0CCAA58F9BF6}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{7ECB9E90-E1B4-476D-BEE7-AC32B32EB2DF}: DhcpNameServer = 82.163.142.7  =>PUP.Optional.DNSUnlocker O17 - HKLM\System\CCS\Services\Tcpip\..\{D5FB136A-FD22-4F9C-84EC-A0FF350762E2}: DhcpNameServer = 82.163.142.7  =>PUP.Optional.DNSUnlocker

---\\ Protocole additionnel (25) - 1s O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll  =>.Microsoft Corporation O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll  =>.Microsoft Corporation O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll  =>.Microsoft Corporation O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll  =>.Microsoft Corporation O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll  =>.Microsoft Corporation O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll  =>.Microsoft Corporation O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll  =>.Microsoft Corporation O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll  =>.Microsoft Corporation O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll  =>.Microsoft Corporation O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll  =>.Microsoft Corporation O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll  =>.Microsoft Corporation O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll  =>.Microsoft Corporation O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll  =>.Microsoft Corporation O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll  =>.Microsoft Corporation O18 - Handler: mso-minsb-roaming.16 [64Bits] - {83C25742-A9F7-49FB-9138-434302C88D07} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL  =>.Microsoft Corporation® O18 - Handler: mso-minsb.16 [64Bits] - {42089D2D-912D-4018-9087-2B87803E93FB} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL  =>.Microsoft Corporation® O18 - Handler: osf-roaming.16 [64Bits] - {42089D2D-912D-4018-9087-2B87803E93FB} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL  =>.Microsoft Corporation® O18 - Handler: osf.16 [64Bits] - {5504BE45-A83B-4808-900A-3A5C36E7F77A} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL  =>.Microsoft Corporation® O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll  =>.Microsoft Corporation O18 - Handler: skypec2c [64Bits] - {91774881-D725-4E58-B298-07617B9B86A8} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll  =>.Skype Software Sarl® O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll  =>.Microsoft Corporation O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll  =>.Microsoft Corporation O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll  =>.Microsoft Corporation O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll  =>.Microsoft Corporation O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll  =>.Microsoft Corporation

---\\ Logiciels installés (79) - 13s O42 - Logiciel: abDocs - (.Acer Incorporated.) [HKLM][64Bits] -- {CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}  =>.Acer Incorporated® O42 - Logiciel: abDocs Office AddIn - (.Acer Incorporated.) [HKLM][64Bits] -- {DCBF3379-246B-47E1-8173-639B63940838}  =>.Acer Incorporated O42 - Logiciel: abFiles - (.Acer Incorporated.) [HKLM][64Bits] -- {13885028-098C-4799-9B71-27DAC96502D5}  =>.Acer Incorporated® O42 - Logiciel: abMusic - (.Acer Incorporated.) [HKLM][64Bits] -- {E9AF1707-3F3A-49E2-8345-4F2D629D0876}  =>.Acer Incorporated® O42 - Logiciel: abPhoto - (.Acer Incorporated.) [HKLM][64Bits] -- {B5AD89F2-03D3-4206-8487-018298007DD0}  =>.Acer Incorporated® O42 - Logiciel: Acer Care Center - (.Acer Incorporated.) [HKLM][64Bits] -- {A424844F-CDB3-45E2-BB77-1DDE4A091E76}  =>.Acer Incorporated O42 - Logiciel: Acer Explorer Agent - (.Acer Incorporated.) [HKLM][64Bits] -- {4D0F42CF-1693-43D9-BDC8-19141D023EE0}  =>.Acer Incorporated O42 - Logiciel: Acer Launch Manager - (.Acer Incorporated.) [HKLM][64Bits] -- {C18D55BD-1EC6-466D-B763-8EEDDDA9100E}  =>.Acer Incorporated O42 - Logiciel: Acer Portal - (.Acer Incorporated.) [HKLM][64Bits] -- {A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}  =>.Acer Incorporated® O42 - Logiciel: Acer Power Management - (.Acer Incorporated.) [HKLM][64Bits] -- {91F52DE4-B789-42B0-9311-A349F10E5479}  =>.Acer Incorporated O42 - Logiciel: Acer Quick Access - (.Acer Incorporated.) [HKLM][64Bits] -- {C1FA525F-D701-4B31-9D32-504FC0CF0B98}  =>.Acer Incorporated O42 - Logiciel: Acer Recovery Management - (.Acer Incorporated.) [HKLM][64Bits] -- {07F2005A-8CAC-4A4B-83A2-DA98A722CA61}  =>.Acer Incorporated O42 - Logiciel: Acer User Experience Improvement Program App Monitor Plugin - (.Acer Incorporated.) [HKLM][64Bits] -- {978724F6-1863-4DD5-9E66-FB77F5AB5613}  =>.Acer Incorporated O42 - Logiciel: Acer User Experience Improvement Program Framework - (.Acer Incorporated.) [HKLM][64Bits] -- {12A718F2-2357-4D41-9E1F-18583A4745F7}  =>.Acer Incorporated O42 - Logiciel: Acer Video Player - (.Acer Incorporated.) [HKLM][64Bits] -- {B6846F20-4821-11E3-8F96-0800200C9A66}  =>.Acer Incorporated® O42 - Logiciel: Adobe Flash Player 21 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI  =>.Adobe Systems Incorporated® O42 - Logiciel: Aloha TriPeaks - (.WildTangent.) [HKLM][64Bits] -- WTA-c8a8163c-57d4-47f6-968a-4e2034d246cf  =>.WildTangent Inc® O42 - Logiciel: AOP Framework - (.Acer Incorporated.) [HKLM][64Bits] -- {4A37A114-702F-4055-A4B6-16571D4A5353}  =>.Acer Incorporated® O42 - Logiciel: Avast Antivirus Gratuit - (.AVAST Software.) [HKLM][64Bits] -- Avast  =>.AVAST Software a.s.® O42 - Logiciel: Battle.net - (.Blizzard Entertainment.) [HKLM][64Bits] -- Battle.net  =>.Blizzard Entertainment, Inc.® O42 - Logiciel: Bejeweled 2 Deluxe - (.WildTangent.) [HKLM][64Bits] -- WTA-e166a577-4513-495a-9dbe-96a72c2ad755  =>.WildTangent Inc® O42 - Logiciel: Betclic Poker.fr - (...) [HKCU][64Bits] -- BetclicPoker.fr {6B5F59AF1247A2E7A051034FF79F008A} O42 - Logiciel: CyberLink PhotoDirector 3 - (.CyberLink Corp..) [HKLM][64Bits] -- {39337565-330E-4ab6-A9AE-AC81E0720B10}  =>.CyberLink Corp.® O42 - Logiciel: CyberLink PhotoDirector 3 - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}  =>.CyberLink Corp.® O42 - Logiciel: CyberLink PowerDirector 10 - (.CyberLink Corp..) [HKLM][64Bits] -- {B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}  =>.CyberLink Corp.® O42 - Logiciel: CyberLink PowerDirector 10 - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}  =>.CyberLink Corp.® O42 - Logiciel: eBay Worldwide - (.OEM.) [HKLM][64Bits] -- {91589413-6675-4C27-8AFC-EFB9103B90A5}  =>.OEM O42 - Logiciel: Farm to Fork Collector's Edition - (.WildTangent.) [HKLM][64Bits] -- WTA-6e4545af-3e2e-4027-a561-d66ae5840bbb  =>.WildTangent Inc® O42 - Logiciel: Foxit PhantomPDF - (.Foxit Corporation.) [HKLM][64Bits] -- {D4DF5498-C95C-4A02-9951-725FB2D7BC0D}  =>.Foxit Corporation O42 - Logiciel: Game Explorer Categories - genres - (.WildTangent, Inc..) [HKLM][64Bits] -- WildTangentGameProvider-acer-genres  =>.WildTangent, Inc. O42 - Logiciel: Game Explorer Categories - main - (.WildTangent, Inc..) [HKLM][64Bits] -- WildTangentGameProvider-acer-main  =>.WildTangent, Inc. O42 - Logiciel: Google Talk Plugin - (.Google.) [HKLM][64Bits] -- {F9B579C2-D854-300A-BE62-A09EB9D722E4}  =>.Google O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {18455581-E099-4BA8-BC6B-F34B2F06600C}  =>.Google Inc. O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F}  =>.Google Inc® O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}  =>.Google Inc. O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}  =>Heuristic.Suspect O42 - Logiciel: Governor of Poker 2 Premium Edition - (.WildTangent.) [HKLM][64Bits] -- WTA-76ca1901-3f54-493f-81b5-c79808454dff  =>.WildTangent Inc® O42 - Logiciel: Intel(R) Control Center - (.Intel Corporation.) [HKLM][64Bits] -- {F8A9085D-4C7A-41a9-8A77-C8998A96C421}  =>.Intel Corporation - pGFX® O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}  =>.Intel Corporation - Software and Firmware Products® O42 - Logiciel: Intel(R) Trusted Execution Engine - (.Intel Corporation.) [HKLM][64Bits] -- {176E2755-0A17-42C6-88E2-192AB2131278}  =>.Intel Corporation O42 - Logiciel: Intel(R) Trusted Execution Engine - (.Intel Corporation.) [HKLM][64Bits] -- {2D6248C0-4693-4CAB-9922-F05E4015F62A}  =>.Intel Corporation O42 - Logiciel: Intel(R) Trusted Execution Engine Driver - (.Intel Corporation.) [HKLM][64Bits] -- {6307E820-0317-4DCE-AAE0-7B6CAD867055}  =>.Intel Corporation O42 - Logiciel: Jewel Match 3 - (.WildTangent.) [HKLM][64Bits] -- WTA-5755ee5c-133b-4207-b4c3-7dbd077d0c8b  =>.WildTangent Inc® O42 - Logiciel: King Oddball - (.WildTangent.) [HKLM][64Bits] -- WTA-238fe9f9-b6cf-4229-ac6c-6d098ab63f37  =>.WildTangent Inc® O42 - Logiciel: LUXOR Evolved - (.WildTangent.) [HKLM][64Bits] -- WTA-8fa673ea-77d1-4458-9ff7-57255c515186  =>.WildTangent Inc® O42 - Logiciel: Magic Academy - (.WildTangent.) [HKLM][64Bits] -- WTA-f0a00875-9924-4842-8297-cd4535da7589  =>.WildTangent Inc® O42 - Logiciel: Malwarebytes Anti-Malware version 2.2.1.1043 - (.Malwarebytes.) [HKLM][64Bits] -- Malwarebytes Anti-Malware_is1  =>.Malwarebytes O42 - Logiciel: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM][64Bits] -- McAfee Security Scan  =>.McAfee, Inc.® O42 - Logiciel: Microsoft OneDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- OneDriveSetup.exe  =>.Microsoft Corporation® O42 - Logiciel: Mozilla Firefox 46.0 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 46.0 (x86 fr)  =>.Mozilla Corporation® O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService  =>.Mozilla O42 - Logiciel: Office 16 Click-to-Run Extensibility Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-008C-0000-0000-0000000FF1CE}  =>.Microsoft Corporation O42 - Logiciel: Office 16 Click-to-Run Licensing Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-008F-0000-1000-0000000FF1CE}  =>.Microsoft Corporation O42 - Logiciel: Office 16 Click-to-Run Localization Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-008C-040C-0000-0000000FF1CE}  =>.Microsoft Corporation O42 - Logiciel: Peggle Nights - (.WildTangent.) [HKLM][64Bits] -- WTA-01303eba-7d07-4a8c-aedd-4bbbc4303cd5  =>.WildTangent Inc® O42 - Logiciel: Plants vs. Zombies - Game of the Year - (.WildTangent.) [HKLM][64Bits] -- WTA-a9ce2a46-b987-410f-b7f7-5c046691c30a  =>.WildTangent Inc® O42 - Logiciel: Polar Bowler 1st Frame - (.WildTangent.) [HKLM][64Bits] -- WTA-bae20991-9609-4614-86db-d2d89ab99842  =>.WildTangent Inc® O42 - Logiciel: Qualcomm Atheros Bluetooth Suite (64) - (.Qualcomm Atheros Communications.) [HKLM][64Bits] -- {A84A4FB1-D703-48DB-89E0-68B6499D2801}  =>.Qualcomm Atheros Communications O42 - Logiciel: Qualcomm Atheros WLAN and Bluetooth Client Installation Program - (.Qualcomm Atheros.) [HKLM][64Bits] -- {28006915-2739-4EBE-B5E8-49B25D32EB33}  =>.Qualcomm Atheros O42 - Logiciel: Realtek Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {5BC2B5AB-80DE-4E83-B8CF-426902051D0A}  =>.Realtek Semiconductor Corp® O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476}  =>.Realtek Semiconductor Corp® O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}  =>.Realtek Semiconductor Corp. O42 - Logiciel: SafeZone Stable 1.48.2066.101 - (.Avast Software.) [HKLM][64Bits] -- SafeZone 1.48.2066.101  =>.AVAST Software s.r.o.® O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM][64Bits] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701}  =>.Microsoft Corporation O42 - Logiciel: Skype™ 7.22 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {FC965A47-4839-40CA-B618-18F486F042C6}  =>.Skype Technologies S.A. O42 - Logiciel: The Chronicles of Emerland Solitaire - (.WildTangent.) [HKLM][64Bits] -- WTA-384663e7-70fc-4b6e-b0e2-d0e43378bae1  =>.WildTangent Inc® O42 - Logiciel: Trinklit Supreme - (.WildTangent.) [HKLM][64Bits] -- WTA-de98649c-aca3-431a-b8f8-21431f7f8089  =>.WildTangent Inc® O42 - Logiciel: Unity Web Player - (.Unity Technologies ApS.) [HKCU][64Bits] -- UnityWebPlayer  =>.Unity Technologies ApS O42 - Logiciel: Update Installer for WildTangent Games App - (.WildTangent.) [HKLM][64Bits] -- {2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App  =>.WildTangent Inc® O42 - Logiciel: WildTangent Games - (.WildTangent.) [HKLM][64Bits] -- WildTangent wildgames Master Uninstall  =>.WildTangent Inc® O42 - Logiciel: WildTangent Games App - (.WildTangent.) [HKLM][64Bits] -- {70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer  =>.WildTangent Inc® O42 - Logiciel: Winamax - (.Winamax.) [HKCU][64Bits] -- Winamax 4.0.0  =>.Winamax O42 - Logiciel: Winamax - (.Winamax.) [HKCU][64Bits] -- Winamax 4.1.1  =>.Winamax O42 - Logiciel: Winamax - (.Winamax.) [HKCU][64Bits] -- Winamax 4.2.0  =>.Winamax O42 - Logiciel: Winamax - (.Winamax.) [HKCU][64Bits] -- Winamax 4.2.1  =>.Winamax O42 - Logiciel: Winamax - (.Winamax.) [HKCU][64Bits] -- Winamax 4.2.2  =>.Winamax O42 - Logiciel: Winamax - (.Winamax.) [HKCU][64Bits] -- Winamax 4.2.3  =>.Winamax O42 - Logiciel: Winamax - (.Winamax.) [HKCU][64Bits] -- Winamax 4.4.2  =>.Winamax O42 - Logiciel: Zuma's Revenge - (.WildTangent.) [HKLM][64Bits] -- WTA-fddc3f7a-8382-4eae-b627-1cde9b7049bb  =>.WildTangent Inc®

---\\ HKCU & HKLM Software Keys (66) - 13s HKLM\SOFTWARE\Wow6432Node\ATHEROS HKLM\SOFTWARE\Wow6432Node\AVAST Software HKLM\SOFTWARE\Wow6432Node\Blizzard Entertainment HKLM\SOFTWARE\Wow6432Node\Clearfi HKLM\SOFTWARE\Wow6432Node\CyberLink HKLM\SOFTWARE\Wow6432Node\Foxit Software HKLM\SOFTWARE\Wow6432Node\Google HKLM\SOFTWARE\Wow6432Node\IM Providers HKLM\SOFTWARE\Wow6432Node\Intel HKLM\SOFTWARE\Wow6432Node\Khronos HKLM\SOFTWARE\Wow6432Node\Macromedia HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware HKLM\SOFTWARE\Wow6432Node\McAfee HKLM\SOFTWARE\Wow6432Node\mcafeeupdater HKLM\SOFTWARE\Wow6432Node\Mozilla HKLM\SOFTWARE\Wow6432Node\mozilla.org HKLM\SOFTWARE\Wow6432Node\MozillaPlugins HKLM\SOFTWARE\Wow6432Node\Network Associates HKLM\SOFTWARE\Wow6432Node\Notepad HKLM\SOFTWARE\Wow6432Node\Nuance HKLM\SOFTWARE\Wow6432Node\ODBC HKLM\SOFTWARE\Wow6432Node\OEM HKLM\SOFTWARE\Wow6432Node\Qualcomm Atheros WLAN and Bluetooth Client Installation Program HKLM\SOFTWARE\Wow6432Node\Realtek HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp. HKLM\SOFTWARE\Wow6432Node\Skype HKLM\SOFTWARE\Wow6432Node\Volatile HKLM\SOFTWARE\Wow6432Node\WildTangent HKLM\SOFTWARE\Wow6432Node\RegisteredApplications HKCU\SOFTWARE\Acer HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\Atheros HKCU\SOFTWARE\AVAST Software HKCU\SOFTWARE\BetclicPoker.fr HKCU\SOFTWARE\Blizzard Entertainment HKCU\SOFTWARE\Foxit Software HKCU\SOFTWARE\Google HKCU\SOFTWARE\IM Providers HKCU\SOFTWARE\Intel HKCU\SOFTWARE\Local AppWizard-Generated Applications HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\Merge Gaming HKCU\SOFTWARE\Mine HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\OEM HKCU\SOFTWARE\pacificpoker HKCU\SOFTWARE\PartyFrance  =>.Superfluous.OnlineGames HKCU\SOFTWARE\PMU HKCU\SOFTWARE\pokerinstaller HKCU\SOFTWARE\PTECH HKCU\SOFTWARE\QtProject HKCU\SOFTWARE\Realtek HKCU\SOFTWARE\RegisteredApplications HKCU\SOFTWARE\Skype HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\undefined  =>.Superfluous.Downloader HKCU\SOFTWARE\Unity HKCU\SOFTWARE\VB and VBA Program Settings HKCU\SOFTWARE\VHLD HKCU\SOFTWARE\Wow6432Node HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\Unity

---\\ Contenu des dossiers Programmes (183) - 68s O43 - CFD: 24/06/2015 - [] D -- C:\Program Files\Accessory Store  =>.Acer Incorporated® O43 - CFD: 13/01/2015 - [] D -- C:\Program Files\Acer  =>.Acer Incorporated® O43 - CFD: 29/04/2016 - [] D -- C:\Program Files\AVAST Software  =>.AVAST Software s.r.o.® O43 - CFD: 29/04/2016 - [] D -- C:\Program Files\Common Files O43 - CFD: 13/01/2015 - [] D -- C:\Program Files\Dropbox  =>.Acer Incorporated® O43 - CFD: 24/06/2015 - [0] SHD -- C:\Program Files\Fichiers communs O43 - CFD: 29/04/2016 - [] D -- C:\Program Files\Google O43 - CFD: 13/01/2015 - [] D -- C:\Program Files\Intel O43 - CFD: 14/04/2016 - [] D -- C:\Program Files\Internet Explorer O43 - CFD: 06/04/2016 - [] D -- C:\Program Files\McAfee Security Scan  =>.McAfee, Inc.® O43 - CFD: 14/11/2015 - [] D -- C:\Program Files\Microsoft Office 15  =>.Microsoft Corporation® O43 - CFD: 25/07/2014 - [] D -- C:\Program Files\MSBuild O43 - CFD: 13/01/2015 - [] D -- C:\Program Files\Realtek  =>.Andrea Electronics® O43 - CFD: 25/07/2014 - [] D -- C:\Program Files\Reference Assemblies O43 - CFD: 22/08/2013 - [0] HD -- C:\Program Files\Uninstall Information O43 - CFD: 15/08/2015 - [] D -- C:\Program Files\Windows Defender  =>.Microsoft Corporation® O43 - CFD: 11/02/2016 - [] D -- C:\Program Files\Windows Journal O43 - CFD: 28/06/2015 - [] D -- C:\Program Files\Windows Mail O43 - CFD: 28/06/2015 - [] D -- C:\Program Files\Windows Media Player O43 - CFD: 28/06/2015 - [] D -- C:\Program Files\Windows Multimedia Platform O43 - CFD: 24/06/2015 - [] D -- C:\Program Files\Windows NT O43 - CFD: 28/06/2015 - [] D -- C:\Program Files\Windows Photo Viewer  =>.Microsoft Corporation® O43 - CFD: 28/06/2015 - [] D -- C:\Program Files\Windows Portable Devices O43 - CFD: 22/08/2013 - [] SHD -- C:\Program Files\Windows Sidebar O43 - CFD: 29/04/2016 - [] HD -- C:\Program Files\WindowsApps O43 - CFD: 28/06/2015 - [] D -- C:\Program Files\WindowsPowerShell O43 - CFD: 01/04/2016 - [] D -- C:\Program Files (x86)\Acer  =>.Acer Incorporated® O43 - CFD: 03/05/2016 - [] D -- C:\Program Files (x86)\Common Files O43 - CFD: 25/07/2014 - [] D -- C:\Program Files (x86)\CyberLink  =>.CyberLink® O43 - CFD: 25/07/2014 - [] D -- C:\Program Files (x86)\Foxit PhantomPDF  =>.Foxit Corporation® O43 - CFD: 29/04/2016 - [] D -- C:\Program Files (x86)\Google  =>.Google Inc® O43 - CFD: 13/01/2015 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information  =>.Macrovision Corporation® O43 - CFD: 13/01/2015 - [] D -- C:\Program Files (x86)\Intel  =>.Intel Corporation - Software and Firmware Products® O43 - CFD: 14/04/2016 - [] D -- C:\Program Files (x86)\Internet Explorer O43 - CFD: 03/05/2016 - [] D -- C:\Program Files (x86)\Malwarebytes Anti-Malware  =>.Malwarebytes Corporation® O43 - CFD: 03/05/2016 - [] D -- C:\Program Files (x86)\Microsoft Office  =>.Microsoft Corporation® O43 - CFD: 14/11/2015 - [] D -- C:\Program Files (x86)\Microsoft.NET O43 - CFD: 29/04/2016 - [] D -- C:\Program Files (x86)\Mozilla Firefox  =>.Mozilla Corporation® O43 - CFD: 29/04/2016 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service  =>.Mozilla Corporation® O43 - CFD: 25/07/2014 - [] D -- C:\Program Files (x86)\MSBuild O43 - CFD: 24/06/2015 - [] D -- C:\Program Files (x86)\OEM O43 - CFD: 15/02/2016 - [0] D -- C:\Program Files (x86)\PokerStars.FR O43 - CFD: 13/01/2015 - [] D -- C:\Program Files (x86)\Qualcomm Atheros O43 - CFD: 13/01/2015 - [] D -- C:\Program Files (x86)\Realtek  =>.Realtek Semiconductor Corp® O43 - CFD: 25/07/2014 - [] D -- C:\Program Files (x86)\Reference Assemblies O43 - CFD: 25/04/2016 - [] RD -- C:\Program Files (x86)\Skype  =>.Skype Software Sarl® O43 - CFD: 13/01/2015 - [0] HD -- C:\Program Files (x86)\Temp O43 - CFD: 02/05/2016 - [0] D -- C:\Program Files (x86)\VS Revo Group O43 - CFD: 25/07/2014 - [] D -- C:\Program Files (x86)\WildGames  =>.WildTangent Inc® O43 - CFD: 25/07/2014 - [] D -- C:\Program Files (x86)\WildTangent Games  =>.WildTangent Inc® O43 - CFD: 15/08/2015 - [] D -- C:\Program Files (x86)\Windows Defender O43 - CFD: 28/06/2015 - [] D -- C:\Program Files (x86)\Windows Mail O43 - CFD: 28/06/2015 - [] D -- C:\Program Files (x86)\Windows Media Player O43 - CFD: 28/06/2015 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Windows NT O43 - CFD: 28/06/2015 - [] D -- C:\Program Files (x86)\Windows Photo Viewer  =>.Microsoft Corporation® O43 - CFD: 28/06/2015 - [] D -- C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 22/08/2013 - [] SHD -- C:\Program Files (x86)\Windows Sidebar O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\WindowsPowerShell O43 - CFD: 28/06/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 28/06/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 28/04/2016 - [] SD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer O43 - CFD: 28/06/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 29/04/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software O43 - CFD: 28/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net O43 - CFD: 25/07/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PhotoDirector 3 O43 - CFD: 25/07/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector 10 O43 - CFD: 25/07/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit PhantomPDF O43 - CFD: 15/02/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 13/01/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel O43 - CFD: 22/08/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 03/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware O43 - CFD: 06/04/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus O43 - CFD: 03/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office 2016 O43 - CFD: 15/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerStars.FR O43 - CFD: 11/12/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype O43 - CFD: 29/04/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp O43 - CFD: 28/06/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 18/03/2014 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 03/08/2015 - [] D -- C:\ProgramData\acer O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 13/01/2015 - [] D -- C:\ProgramData\Atheros O43 - CFD: 29/04/2016 - [] D -- C:\ProgramData\AVAST Software O43 - CFD: 02/05/2016 - [] D -- C:\ProgramData\Battle.net O43 - CFD: 28/06/2015 - [] D -- C:\ProgramData\Blizzard Entertainment O43 - CFD: 24/06/2015 - [0] SHD -- C:\ProgramData\Bureau O43 - CFD: 25/07/2014 - [] D -- C:\ProgramData\CyberLink O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 29/04/2016 - [] D -- C:\ProgramData\Google O43 - CFD: 25/07/2014 - [] D -- C:\ProgramData\install_clap O43 - CFD: 13/01/2015 - [] D -- C:\ProgramData\Intel O43 - CFD: 03/05/2016 - [] D -- C:\ProgramData\Malwarebytes O43 - CFD: 29/04/2016 - [] D -- C:\ProgramData\McAfee O43 - CFD: 24/07/2015 - [] D -- C:\ProgramData\McAfee Security Scan O43 - CFD: 24/06/2015 - [0] SHD -- C:\ProgramData\Menu Démarrer O43 - CFD: 14/11/2015 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 14/11/2015 - [] D -- C:\ProgramData\Microsoft OneDrive O43 - CFD: 24/06/2015 - [0] SHD -- C:\ProgramData\Modèles O43 - CFD: 24/06/2015 - [] D -- C:\ProgramData\Mozilla O43 - CFD: 07/11/2015 - [] D -- C:\ProgramData\OEM O43 - CFD: 24/06/2015 - [] D -- C:\ProgramData\OEM_YAHOO O43 - CFD: 25/07/2014 - [] D -- C:\ProgramData\Package Cache O43 - CFD: 13/01/2015 - [] D -- C:\ProgramData\Qualcomm Atheros O43 - CFD: 03/05/2016 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft O43 - CFD: 25/04/2016 - [] D -- C:\ProgramData\Skype O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 25/07/2014 - [] D -- C:\ProgramData\Temp O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 25/07/2014 - [] D -- C:\ProgramData\WildTangent O43 - CFD: 13/01/2015 - [] D -- C:\ProgramData\{69533018-33A8-4C46-869A-11AA2CDF4EDC} O43 - CFD: 13/01/2015 - [] D -- C:\Program Files (x86)\Common Files\Atheros O43 - CFD: 29/04/2016 - [] D -- C:\Program Files (x86)\Common Files\AV O43 - CFD: 28/06/2015 - [0] D -- C:\Program Files (x86)\Common Files\Blizzard Entertainment O43 - CFD: 03/05/2016 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER O43 - CFD: 13/01/2015 - [] D -- C:\Program Files (x86)\Common Files\InstallShield O43 - CFD: 13/01/2015 - [] D -- C:\Program Files (x86)\Common Files\Intel O43 - CFD: 29/04/2016 - [] D -- C:\Program Files (x86)\Common Files\mcafee O43 - CFD: 03/05/2016 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared O43 - CFD: 25/07/2014 - [] D -- C:\Program Files (x86)\Common Files\Nikon O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Common Files\Services O43 - CFD: 23/03/2016 - [] D -- C:\Program Files (x86)\Common Files\Skype O43 - CFD: 28/06/2015 - [] D -- C:\Program Files (x86)\Common Files\System O43 - CFD: 24/06/2015 - [] D -- C:\Users\thomas\AppData\Roaming\Adobe O43 - CFD: 24/06/2015 - [] D -- C:\Users\thomas\AppData\Roaming\Atheros O43 - CFD: 29/04/2016 - [] D -- C:\Users\thomas\AppData\Roaming\AVAST Software O43 - CFD: 02/05/2016 - [] D -- C:\Users\thomas\AppData\Roaming\Battle.net O43 - CFD: 15/02/2016 - [] D -- C:\Users\thomas\AppData\Roaming\cef-cache O43 - CFD: 11/02/2016 - [] D -- C:\Users\thomas\AppData\Roaming\com.winamax.chat O43 - CFD: 08/10/2015 - [] D -- C:\Users\thomas\AppData\Roaming\Foxit Software O43 - CFD: 28/06/2015 - [] D -- C:\Users\thomas\AppData\Roaming\Identities O43 - CFD: 24/06/2015 - [] D -- C:\Users\thomas\AppData\Roaming\Macromedia O43 - CFD: 14/11/2015 - [] SD -- C:\Users\thomas\AppData\Roaming\Microsoft O43 - CFD: 16/12/2015 - [] D -- C:\Users\thomas\AppData\Roaming\Mozilla O43 - CFD: 15/02/2016 - [] D -- C:\Users\thomas\AppData\Roaming\PartyFrance O43 - CFD: 30/06/2015 - [] D -- C:\Users\thomas\AppData\Roaming\PMU O43 - CFD: 03/05/2016 - [] D -- C:\Users\thomas\AppData\Roaming\Skype O43 - CFD: 09/04/2016 - [] D -- C:\Users\thomas\AppData\Roaming\Unity O43 - CFD: 24/06/2015 - [] D -- C:\Users\thomas\AppData\Roaming\wam.04351C371E530C3762CBA45FA283ED972DCDEFB6.1 O43 - CFD: 03/05/2016 - [] D -- C:\Users\thomas\AppData\Roaming\ZHP O43 - CFD: 27/04/2016 - [] HD -- C:\Users\thomas\AppData\Local\22e891d9788f4141 O43 - CFD: 07/11/2015 - [] D -- C:\Users\thomas\AppData\Local\acer O43 - CFD: 24/06/2015 - [] D -- C:\Users\thomas\AppData\Local\Acer Aspire R7 Tutorial O43 - CFD: 24/06/2015 - [0] D -- C:\Users\thomas\AppData\Local\Adobe O43 - CFD: 24/06/2015 - [] D -- C:\Users\thomas\AppData\Local\AOP SDK O43 - CFD: 24/06/2015 - [0] SHD -- C:\Users\thomas\AppData\Local\Application Data O43 - CFD: 03/05/2016 - [] D -- C:\Users\thomas\AppData\Local\AVAST Software O43 - CFD: 01/10/2015 - [] D -- C:\Users\thomas\AppData\Local\Battle.net O43 - CFD: 29/04/2016 - [] D -- C:\Users\thomas\AppData\Local\Betclic Poker.fr O43 - CFD: 28/06/2015 - [] D -- C:\Users\thomas\AppData\Local\Blizzard O43 - CFD: 28/06/2015 - [] D -- C:\Users\thomas\AppData\Local\Blizzard Entertainment O43 - CFD: 30/10/2015 - [] D -- C:\Users\thomas\AppData\Local\CarbonPoker O43 - CFD: 04/11/2015 - [] D -- C:\Users\thomas\AppData\Local\CEF O43 - CFD: 15/04/2016 - [] D -- C:\Users\thomas\AppData\Local\Chromium O43 - CFD: 28/04/2016 - [] D -- C:\Users\thomas\AppData\Local\clear.fi O43 - CFD: 29/04/2016 - [] D -- C:\Users\thomas\AppData\Local\CrashDumps O43 - CFD: 02/05/2016 - [] D -- C:\Users\thomas\AppData\Local\Diagnostics O43 - CFD: 28/06/2015 - [0] SHD -- C:\Users\thomas\AppData\Local\EmieSiteList O43 - CFD: 28/06/2015 - [0] SHD -- C:\Users\thomas\AppData\Local\EmieUserList O43 - CFD: 06/04/2016 - [] D -- C:\Users\thomas\AppData\Local\Google O43 - CFD: 24/06/2015 - [] D -- C:\Users\thomas\AppData\Local\GWX O43 - CFD: 24/06/2015 - [0] SHD -- C:\Users\thomas\AppData\Local\Historique O43 - CFD: 24/06/2015 - [] D -- C:\Users\thomas\AppData\Local\Macromedia O43 - CFD: 05/02/2016 - [] D -- C:\Users\thomas\AppData\Local\Microsoft O43 - CFD: 24/06/2015 - [] D -- C:\Users\thomas\AppData\Local\Mozilla O43 - CFD: 24/06/2015 - [] D -- C:\Users\thomas\AppData\Local\OEM O43 - CFD: 18/01/2016 - [] D -- C:\Users\thomas\AppData\Local\Packages O43 - CFD: 06/03/2016 - [] D -- C:\Users\thomas\AppData\Local\PokerClient O43 - CFD: 15/02/2016 - [] D -- C:\Users\thomas\AppData\Local\PokerStars.FR O43 - CFD: 27/04/2016 - [] D -- C:\Users\thomas\AppData\Local\Programs O43 - CFD: 11/12/2015 - [0] D -- C:\Users\thomas\AppData\Local\Skype O43 - CFD: 03/05/2016 - [] D -- C:\Users\thomas\AppData\Local\Temp O43 - CFD: 24/06/2015 - [0] SHD -- C:\Users\thomas\AppData\Local\Temporary Internet Files O43 - CFD: 09/04/2016 - [] D -- C:\Users\thomas\AppData\Local\Unity O43 - CFD: 29/04/2016 - [] D -- C:\Users\thomas\AppData\Local\VirtualStore O43 - CFD: 29/04/2016 - [] D -- C:\Users\thomas\AppData\Local\{8557B30B-A1FF-DFB3-CC67-FA5BE80F06C3} O43 - CFD: 27/04/2016 - [0] D -- C:\Users\thomas\AppData\Local\Programs\Common O43 - CFD: 18/03/2014 - [] RD -- C:\Users\thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 22/08/2013 - [] RD -- C:\Users\thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 15/04/2016 - [] RD -- C:\Users\thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 22/08/2013 - [] D -- C:\Users\thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 15/04/2016 - [] RD -- C:\Users\thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 25/07/2014 - [] RD -- C:\Users\thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools

---\\ Derniers fichiers créés dans Windows Prefetcher (1) - 21s O45 - LFCP:[MD5.5CC39A3702070C41F478A37661C6D292] 06/04/2016 A -- C:\Windows\Prefetch\ONESYSTEMCARE.EXE-2CCD2217.pf  =>PUP.Optional.OneSystemCare

---\\ ShellIconOverlayIdentifiers (SIOI) (1) - 0s O106 - SIOI: avast [00avast] - {472083B0-C522-11CF-8763-00608CC02F24}. (.AVAST Software - avast! Shell Extension.) -- C:\Program Files\AVAST Software\Avast\ashShell.dll  =>.AVAST Software a.s.®  

Re: internet navigation problem

---\\ Liste des pilotes du système (63) - 13s O58 - SDL:2013/08/22 14:43:41 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\drivers\3ware.sys   [108896]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:41 A . (.PMC-Sierra - PMC-Sierra Storport  Driver For SPC8x6G SAS.) -- C:\Windows\System32\drivers\adp80xx.sys   [782176]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:41 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys   [79200]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:41 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys   [259424]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:40 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys   [25952]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:41 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys   [114016]  =>.Microsoft Windows® O58 - SDL:2016/04/29 16:39:37 A . (.AVAST Software - avast! HWID.) -- C:\Windows\System32\drivers\aswHwid.sys   [37656]  =>.AVAST Software a.s.® (ALWIL Software) O58 - SDL:2016/04/29 16:42:59 A . (.AVAST Software - avast! Keyboard Filter Driver.) -- C:\Windows\System32\drivers\aswKbd.sys   [37144]  =>.AVAST Software a.s.® O58 - SDL:2016/04/29 16:39:37 A . (.AVAST Software - avast! File System Minifilter for Windows 2.) -- C:\Windows\System32\drivers\aswMonFlt.sys   [107792]  =>.AVAST Software a.s.® O58 - SDL:2016/04/29 16:39:36 A . (.AVAST Software - avast! WFP Redirect Driver.) -- C:\Windows\System32\drivers\aswRdr2.sys   [103064]  =>.AVAST Software a.s.® O58 - SDL:2016/04/29 16:39:37 A . (.AVAST Software - avast! Revert.) -- C:\Windows\System32\drivers\aswRvrt.sys   [74544]  =>.AVAST Software a.s.® (ALWIL Software) O58 - SDL:2016/04/29 16:39:14 A . (.AVAST Software - avast! Virtualization Driver.) -- C:\Windows\System32\drivers\aswSnx.sys   [1070904]  =>.AVAST Software a.s.® O58 - SDL:2016/04/29 16:39:37 A . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\drivers\aswSP.sys   [465792]  =>.AVAST Software a.s.® O58 - SDL:2016/04/29 16:39:37 A . (.AVAST Software - Stream Filter.) -- C:\Windows\System32\drivers\aswStm.sys   [166432]  =>.AVAST Software a.s.® O58 - SDL:2016/04/29 16:39:37 A . (.AVAST Software - avast! VM Monitor.) -- C:\Windows\System32\drivers\aswVmm.sys   [287528]  =>.AVAST Software a.s.® (ALWIL Software) O58 - SDL:2014/04/02 20:02:18 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\Windows\System32\drivers\athwbx.sys   [3893248]  =>.Qualcomm Atheros Communications, Inc. O58 - SDL:2013/08/13 01:25:46 A . (.Windows (R) Win 7 DDK provider - BCM Function 2  Device Driver.) -- C:\Windows\System32\drivers\bcmfn2.sys   [17624]  =>.Broadcom Corporation® O58 - SDL:2014/04/29 03:15:50 A . (.Qualcomm Atheros - Qualcomm Atheros A2DP driver.) -- C:\Windows\System32\drivers\btath_a2dp.sys   [338120]  =>.Qualcomm Atheros® O58 - SDL:2014/04/29 03:15:50 A . (.Qualcomm Atheros - Qualcomm Atheros Bluetooth AVDT driver.) -- C:\Windows\System32\drivers\btath_avdt.sys   [116424]  =>.Qualcomm Atheros® O58 - SDL:2014/04/29 03:15:50 A . (.Qualcomm Atheros - Qualcomm Atheros BUS driver.) -- C:\Windows\System32\drivers\btath_bus.sys   [35016]  =>.Qualcomm Atheros® O58 - SDL:2014/04/29 03:15:50 A . (.Qualcomm Atheros - Qualcomm Atheros FILTER driver.) -- C:\Windows\System32\drivers\btath_flt.sys   [89800]  =>.Qualcomm Atheros® O58 - SDL:2014/04/29 03:15:50 A . (.Qualcomm Atheros - Qualcomm Atheros FILTER driver.) -- C:\Windows\System32\drivers\btath_lwflt.sys   [77464]  =>.Atheros Communications Inc.® O58 - SDL:2014/04/29 03:15:50 A . (.Qualcomm Atheros - Qualcomm Atheros AVRCP driver.) -- C:\Windows\System32\drivers\btath_rcp.sys   [137928]  =>.Qualcomm Atheros® O58 - SDL:2014/04/29 03:15:50 A . (.Qualcomm Atheros - Qualcomm Atheros BtFilter Driver.) -- C:\Windows\System32\drivers\btfilter.sys   [599240]  =>.Qualcomm Atheros® O58 - SDL:2013/08/22 14:43:41 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys   [531296]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:45 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys   [3357024]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:45 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys   [64352]  =>.Microsoft Windows® O58 - SDL:2014/06/09 08:20:30 A . (.Intel Corporation - GPIO Controller Driver E.) -- C:\Windows\System32\drivers\iaiogpioe.sys   [31232]  =>.Intel Corporation O58 - SDL:2014/06/09 08:20:30 A . (.Intel Corporation - I2C Controller Driver E.) -- C:\Windows\System32\drivers\iaioi2ce.sys   [69632]  =>.Intel Corporation O58 - SDL:2013/07/30 20:47:35 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_GPIO.sys   [24568]  =>.Intel Corporation - Software and Firmware Products® O58 - SDL:2013/07/25 21:05:39 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_I2C.sys   [99320]  =>.Intel Corporation - Software and Firmware Products® O58 - SDL:2013/08/10 02:39:30 A . (.Intel Corporation - Intel Rapid Storage Technology driver (inbo.) -- C:\Windows\System32\drivers\iaStorAV.sys   [651248]  =>.Intel Corporation - Intel® Rapid Storage Technology® O58 - SDL:2013/08/22 14:43:45 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys   [412000]  =>.Microsoft Windows® O58 - SDL:2014/04/23 22:32:30 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd64.sys   [3789824]  =>.Intel Corporation O58 - SDL:2014/04/23 22:41:34 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\drivers\IntcDAud.sys   [450520]  =>.Intel Corporation - Software and Firmware Products® O58 - SDL:2014/03/26 01:31:04 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\Windows\System32\drivers\intelaud.sys   [38296]  =>.Intel Wireless Display® O58 - SDL:2014/03/26 01:31:04 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\Windows\System32\drivers\iwdbus.sys   [27032]  =>.Intel Wireless Display® O58 - SDL:2013/07/17 18:59:00 A . (.Acer Incorporated - LMDriver.) -- C:\Windows\System32\drivers\LMDriver.sys   [21360]  =>.Acer Incorporated® O58 - SDL:2013/08/22 14:43:44 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys   [109408]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys   [93536]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:44 A . (.LSI Corporation - LSI SAS Gen3 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas3.sys   [81760]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sss.sys   [82784]  =>.Microsoft Windows® O58 - SDL:2016/03/10 14:08:54 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\mbam.sys   [27008]  =>.Malwarebytes Corporation® O58 - SDL:2016/03/10 14:08:58 A . (.Malwarebytes - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\drivers\mbamchameleon.sys   [140672]  =>.Malwarebytes Corporation® O58 - SDL:2016/05/03 16:02:25 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys   [192216]  =>.Malwarebytes Corporation® O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys   [56672]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\megasr.sys   [575840]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:49 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\drivers\mvumis.sys   [63840]  =>.Microsoft Windows® O58 - SDL:2016/03/10 14:09:10 A . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\drivers\mwac.sys   [65408]  =>.Malwarebytes Corporation® O58 - SDL:2013/08/22 14:43:31 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys   [150368]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:32 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys   [168288]  =>.Microsoft Windows® O58 - SDL:2013/07/17 18:59:00 A . (.Acer Incorporated - RadioShim.) -- C:\Windows\System32\drivers\RadioShim.sys   [14680]  =>.Acer Incorporated® O58 - SDL:2014/05/29 09:55:48 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.30 64-bit Dr.) -- C:\Windows\System32\drivers\Rt630x64.sys   [873176]  =>.Realtek Semiconductor Corp® O58 - SDL:2014/07/08 13:16:38 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHD64.sys   [4007512]  =>.Realtek Semiconductor Corp® O58 - SDL:2014/03/27 05:06:40 A . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/V.) -- C:\Windows\System32\drivers\RtsUVStor.sys   [331992]  =>.Realtek Semiconductor Corp® O58 - SDL:2013/08/22 17:35:09 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys   [23040]  =>.Macrovision Corporation, Macrovision Europe Limited, O58 - SDL:2013/08/22 14:43:31 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys   [44896]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:32 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys   [81760]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:32 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\Windows\System32\drivers\stexstor.sys   [31072]  =>.Microsoft Windows® O58 - SDL:2014/01/15 15:21:46 A . (.Intel Corporation - Intel(R) Trusted Execution Engine Interface.) -- C:\Windows\System32\drivers\TXEIx64.sys   [88592]  =>.Intel Corporation - Client Components Group® O58 - SDL:2013/08/22 14:43:34 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys   [19808]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:34 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys   [168800]  =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:34 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\drivers\VSTXRAID.SYS   [305504]  =>.Microsoft Windows®

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (8) - 39s O61 - LFC: 2016/04/29 16:36:35 A . (..) -- C:\Users\thomas\Downloads\avast_free_antivirus_setup_online.exe   [0] O61 - LFC: 2016/04/30 12:48:03 A . (.Copyright ©  2013.) -- C:\Users\thomas\AppData\Local\Packages\Microsoft.BingSports_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Microsoft.B2e1870ee#\c3d2cf3f267b533bad46cf52fc81e8f1\Microsoft.Bing.AppEx.Telemetry.ni.dll   [2207232] O61 - LFC: 2016/04/30 12:48:49 A . (..) -- C:\Users\thomas\AppData\Local\Packages\Microsoft.BingSports_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Microsoft.Ad256fa43#\72fbf2455513b5bcaf2caa9c56a889ee\Microsoft.AppEx.Sports.SportsEnums.ni.dll   [60416] O61 - LFC: 2016/04/30 12:48:43 A . (.Copyright ©  2013.) -- C:\Users\thomas\AppData\Local\Packages\Microsoft.BingSports_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Microsoft.Ab11fe181#\dd9bb113750249f912def405bd3c0087\Microsoft.AppEx.Sports.TransformEngine.BaseSchemas.ni.dll   [181248] O61 - LFC: 2016/04/30 12:48:33 A . (..) -- C:\Users\thomas\AppData\Local\Packages\Microsoft.BingSports_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Microsoft.A615ea4af#\28ae82d3d9e8bc4d645d2e5c6346908a\Microsoft.AppEx.Sports.BaseEnums.ni.dll   [79872] O61 - LFC: 2016/04/30 12:48:42 A . (.Copyright ©  2013.) -- C:\Users\thomas\AppData\Local\Packages\Microsoft.BingSports_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Microsoft.A46d31238#\3a9b184ff38d00bf091381593f17c6af\Microsoft.AppEx.Sports.Schemas.ni.dll   [4854272] O61 - LFC: 2016/04/30 12:47:04 A . (.Copyright ©  2013.) -- C:\Users\thomas\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Microsoft.B2e1870ee#\548a3dfc7ad8d8f7ddff8570b173d28f\Microsoft.Bing.AppEx.Telemetry.ni.dll   [2207232] O61 - LFC: 2016/05/03 15:56:36 A . (..) -- C:\Users\thomas\AppData\Local\AOP SDK\Acer Infra\acer\SyncAgent\cc\cache\users\0000000000a5dbc9\userdata.bin   [4456]

---\\ Associations Shell Spawning (10) - 1s O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe  =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe  =>.Microsoft Corporation O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe  =>.Microsoft Corporation® O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe  =>.Microsoft Corporation O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe  =>.Microsoft Corporation O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S

---\\ Menu de démarrage Internet (12) - 0s O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe   =>.Mozilla Corporation® O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (...) -- iexplore.exe  O68 - StartMenuInternet: <SafeZoneStable> <SafeZone Stable>[HKLM\..\Shell\open\Command] (.Avast Software - Avast SafeZone Browser.) -- C:\Program Files\AVAST Software\SZBrowser\Launcher.exe   =>.AVAST Software s.r.o.® O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe  =>.Mozilla Corporation O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe  =>.Microsoft Corporation O68 - StartMenuInternet: <SafeZoneStable> <SafeZone Stable>[HKLM\..\InstallInfo\ShowIconsCommand] (.Avast Software - Avast SafeZone Browser.) -- C:\Program Files\AVAST Software\SZBrowser\launcher.exe  =>.AVAST Software O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe  =>.Mozilla Corporation O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe  =>.Microsoft Corporation O68 - StartMenuInternet: <SafeZoneStable> <SafeZone Stable>[HKLM\..\InstallInfo\ReinstallCommand] (.Avast Software - Avast SafeZone Browser.) -- C:\Program Files\AVAST Software\SZBrowser\launcher.exe  =>.AVAST Software O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe  =>.Mozilla Corporation O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe  =>.Microsoft Corporation O68 - StartMenuInternet: <SafeZoneStable> <SafeZone Stable>[HKLM\..\InstallInfo\HideIconsCommand] (.Avast Software - Avast SafeZone Browser.) -- C:\Program Files\AVAST Software\SZBrowser\launcher.exe  =>.AVAST Software

---\\ Recherche d'infection sur les navigateurs (2) - 13s O69 - SBI: SearchScopes [HKCU] {2f23ab71-4ac6-41f2-a955-ea576e553146} - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/

---\\ Enumère les services démarrés par Svchost (34) - 1s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll   [214528]  =>.Microsoft Corporation O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll   [156160]  =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll   [156160]  =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\system32\srvsvc.dll   [329216]  =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll   [1360896]  =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll   [1083904]  =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll   [926208]  =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\system32\seclogon.dll   [31744]  =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll   [110080]  =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\system32\iscsiexe.dll   [151040]  =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll   [110592]  =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\system32\schedsvc.dll   [1265152]  =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll   [230400]  =>.Microsoft Corporation O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\system32\mmcss.dll   [71168]  =>.Microsoft Corporation O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll   [135168]  =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll   [228864]  =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll   [339968]  =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll   [84992]  =>.Microsoft Corporation O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\system32\kmsvc.dll   [101376]  =>.Microsoft Corporation O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll   [348672]  =>.Microsoft Corporation O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service d’infrastructure de localisation Wi.) -- C:\Windows\System32\GeofenceMonitorService.dll   [522240]  =>.Microsoft Corporation O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\Windows\system32\wlidsvc.dll   [1639424]  =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\system32\themeservice.dll   [59392]  =>.Microsoft Corporation O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\Windows\System32\DeviceSetupManager.dll   [206848]  =>.Microsoft Corporation O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\Windows\System32\ncasvc.dll   [166400]  =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll   [102912]  =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\Windows\System32\rasmans.dll   [542208]  =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll   [226816]  =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\sens.dll   [73728]  =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll   [452608]  =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll   [313344]  =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\system32\wuaueng.dll   [3708416]  =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll   [933376]  =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll   [640000]  =>.Microsoft Corporation

---\\ Liste des exceptions du parefeu Windows (42) - 7s O87 - FAEL: "{0BF25D37-7A6B-4E41-A12B-62590D2F2C8F}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe (.not file.) O87 - FAEL: "{3984ECD5-0A07-4416-87DB-87548048FB6A}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Spotify\spotify.exe (.not file.) O87 - FAEL: "{1928A080-1C0B-4035-9166-7F6B268C655C}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Spotify\spotify.exe (.not file.) O87 - FAEL: "{9FA58926-2187-4829-860E-DAEB3250F9BB}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe (.not file.) O87 - FAEL: "{89A70AFD-9BAF-44B8-9EEC-F2A9CD567226}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe (.not file.) O87 - FAEL: "{6EA82B28-385F-4C4F-9E30-556B8F5F11DB}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{851DE818-3BFA-42DC-A6A3-DAA32F62D7E1}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{8001557A-C198-4A4E-8C5C-F0E2B106AF5F}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{7A65562C-642D-4BB6-824B-149812AD6E23}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{1C588F05-AC48-443E-A5E0-1EF2B099DD73}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{F0C61676-C046-4F12-A1C6-F0CFC7F8A629}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{7A1D00B0-ADB2-486E-BEA0-FC6A8347E08E}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{FDF840FD-78B7-4936-A37A-E719D39E5B98}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{E7253E85-8D9F-4F95-A966-89C9A03759CC}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{FEF61805-B742-4FAE-BD93-E10D1F734991}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{A94E36F6-E23B-4C9C-828A-EBD6D4EAE8D9}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{0E01D66D-147D-4BC6-A951-B9A8E20AC8E7}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{ADE3ECE9-3C35-4E56-A3BC-230114CA18A7}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{A97104B4-E174-4A1A-BE5E-A733A37B55E8}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{2652CDAA-4D9A-4DAB-9575-FEF730D340CF}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{AA85E6AB-5FB2-4091-B127-1536F1A82274}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{149D2256-7EDF-411F-97F3-5243EB7BBAAB}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Battle.net\Battle.net.exe (.not file.) O87 - FAEL: "{13DF1353-DA97-4650-96E4-771C49B2AA1B}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Battle.net\Battle.net.exe (.not file.) O87 - FAEL: "{83352746-EC39-40C4-9177-ADDAD0BC7529}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Hearthstone\Hearthstone.exe (.not file.) O87 - FAEL: "{37DC2BF1-0A4D-4106-BB23-F66896DCF670}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Hearthstone\Hearthstone.exe (.not file.) O87 - FAEL: "{BFF481A2-4204-4E70-94B3-E2E444B446C4}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{58EA6E7A-5B7F-42C6-99D6-C9C12586775C}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{F02896EE-7673-4D0E-8976-35EF61921F50}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{288CD372-C163-4426-8C34-84B78CFF0963}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{DFB70669-FECA-4EA0-AAD0-C52DB804C7A6}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{31518F1F-D94C-49BC-BE04-EF881F4854F7}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{77236DE8-5F12-458B-B962-E26928719721}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{FDAB51AD-68F8-4C75-90A4-64CE74E082FB}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{8E5F343B-5FE5-4D74-B9C8-D48A3EE19F8B}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{0BAFEE98-724D-4E90-8F9C-8499FE8BB289}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{243477C6-51D5-4A2F-BF52-AFB9162A2D44}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{D52BBE96-15F7-4DCB-BCE0-6C3FFCF5A89B}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{2DBDC986-8942-4D40-BF80-FCBC215B2233}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{3169519E-BCBA-4339-A0DE-EAEC3EB9383E}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe (.not file.) O87 - FAEL: "{0758AA3E-34F9-4840-959D-797416A9B206}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{4169672F-3142-4C09-81B9-1CC0059C101C}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe (.not file.) O87 - FAEL: "{AEF4AE1E-90EE-4F3B-A2C7-4F6BAFBE99A7}" [In-None-P17-TRUE] .(...) -- C:\Users\thomas\AppData\Local\Chromium\Application\chrome.exe (.not file.)

---\\ Scan Additionnel (5) - 0s HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}  =>Heuristic.Suspect HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}  =>Heuristic.Suspect HKCU\SOFTWARE\PartyFrance  =>.Superfluous.OnlineGames HKCU\SOFTWARE\undefined  =>.Superfluous.Downloader C:\Windows\Prefetch\ONESYSTEMCARE.EXE-2CCD2217.pf  =>PUP.Optional.OneSystemCare

---\\ Récapitulatif des éléments trouvés sur votre station (5) - 0s http://www.nicolascoolman.fr/?p=4664  =>PUP.Optional.DNSUnlocker http://www.nicolascoolman.info/2016/04/22/heuristic-suspect/  =>Heuristic.Suspect http://www.nicolascoolman.fr/?p=5145  =>.Superfluous.OnlineGames http://www.nicolascoolman.fr/?p=5145  =>.Superfluous.Downloader http://www.nicolascoolman.fr/?p=4664  =>PUP.Optional.OneSystemCare

~ End of the scan, 25905 items in 00h08mn00s (854)(0)

Re: internet navigation problem

ZHPCleaner ! Pas ZHPDiag, c'est un autre logiciel qu'il te faut télécharger.

Re: internet navigation problem

salut,

désolé voila zhp cleaner:

~ ZHPCleaner v2016.5.3.61 by Nicolas Coolman (2016/05/03) ~ Run by thomas (Administrator)  (03/05/2016 18:31:10) ~ Site : http://www.nicolascoolman.com ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Type : Nettoyer ~ Report : C:\Users\thomas\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\thomas\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 8.1 Connected, 64-bit  (Build 9600)

---\\  Service. (0) ~ Aucun élément malicieux ou superflu trouvé.

---\\  Navigateur internet. (0) ~ Aucun élément malicieux ou superflu trouvé.

---\\  Fichier hôte. (2) REMPLACÉ: 0.0.0.1    mssplus.mcafee.com ~ Nombre de redirections trouvées 1/31

---\\  Tâche planifiée. (0) ~ Aucun élément malicieux ou superflu trouvé.

---\\  Explorateur  ( Dossiers, Fichiers ). (36) DEPLACÉ fichier: C:\Windows\Prefetch\ONESYSTEMCARE.EXE-2CCD2217.pf    =>PUP.Optional.OneSystemCare DEPLACÉ fichier: C:\Users\thomas\Downloads\VideoPlayerSetup [1].exe [MediaPlayAir - MediaPlayAir Setup]  =>PUP.Optional.CrossRider DEPLACÉ fichier: C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.coupontime00.coupontime.co_0.localstorage    =>PUP.Optional.CouponTime DEPLACÉ fichier: C:\Users\thomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.coupontime00.coupontime.co_0.localstorage-journal    =>PUP.Optional.CouponTime DEPLACÉ dossier: C:\Windows\Installer\MSI26A1.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI2BB7.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI388C.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI38E9.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI4507.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI5463.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI625B.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI7383.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI7A34.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI7CA6.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI866C.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI8CC4.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI94BA.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI96D3.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI98FA.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI9CAE.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSI9F16.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIA1A4.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIA6C9.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIA9E7.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIB0E.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIB41A.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIB649.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIB654.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIB89.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIC1BA.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIC6BB.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIC6D0.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIC9EE.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIE62F.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIEA63.tmp-  =>Empty DEPLACÉ dossier: C:\Windows\Installer\MSIF992.tmp-  =>Empty

---\\  Base de Registres ( Clés, Valeurs, Données ). (11) SUPPRIMÉ clé*: HKEY_USERS\S-1-5-21-1704502057-2460348180-801270001-1001\SOFTWARE\PartyFrance []  =>.Superfluous.OnlineGames SUPPRIMÉ clé*: HKEY_USERS\S-1-5-21-1704502057-2460348180-801270001-1001\SOFTWARE\Classes\launcher-partypokerfr []  =>PUP.Optional.Casino SUPPRIMÉ clé: HKCU\Software\PartyFrance []  =>.Superfluous.OnlineGames SUPPRIMÉ clé*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\chatango.com []  =>PUP.Optional.Chatango SUPPRIMÉ clé*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d16fk4ms6rqz1v.cloudfront.net [1222]  =>.Superfluous.CloudfrontNet SUPPRIMÉ clé*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d22j4fzzszoii2.cloudfront.net [1359]  =>.Superfluous.CloudfrontNet SUPPRIMÉ clé*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\soundcloud.com [654]  =>PUP.Optional.SoundCloud SUPPRIMÉ clé*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\st.chatango.com [33]  =>PUP.Optional.Chatango SUPPRIMÉ clé*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.audienceinsights.net [43]  =>.Superfluous.AudienceInsights SUPPRIMÉ clé*: HKCU\Software\undefined []  =>.Superfluous.Downloader SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} [Google Inc.]  =>Heuristic.Suspect

---\\  Récapitulatif des éléments trouvés sur votre station. (11) http://www.nicolascoolman.fr/?p=4664  =>PUP.Optional.OneSystemCare http://www.nicolascoolman.fr/http://www.nicolascoolman.info/2016/04/30/pup-optional-crossrider/  =>PUP.Optional.CrossRider http://www.nicolascoolman.fr/?p=4664  =>PUP.Optional.CouponTime http://www.nicolascoolman.fr/?p=5145  =>.Superfluous.OnlineGames http://www.nicolascoolman.fr/?p=4664  =>PUP.Optional.Casino http://www.nicolascoolman.fr/?p=4664  =>PUP.Optional.Chatango http://www.nicolascoolman.fr/?p=5145  =>.Superfluous.CloudfrontNet http://www.nicolascoolman.fr/?p=4664  =>PUP.Optional.SoundCloud http://www.nicolascoolman.fr/?p=5145  =>.Superfluous.AudienceInsights http://www.nicolascoolman.fr/?p=5145  =>.Superfluous.Downloader http://www.nicolascoolman.fr/http://www.nicolascoolman.info/2016/04/22/heuristic-suspect/  =>Heuristic.Suspect

---\\  Nettoyage Additionnel. (16) ~ Suppression des Clés de registre Tracing. (16) ~ Suppression des anciens rapports ZHPCleaner. (0)

---\\ Bilan de la réparation ~ Réparation réalisée avec succès. ~ Ce navigateur est absent  (Opera Software)

---\\ Statistiques ~ Items scannés : 709 ~ Items trouvés : 1 ~ Items annulés : 0 ~ Items réparés : 47

~ End of clean in 00h00mn35s ~==================== ZHPCleaner-[R]-03052016-18_31_45.txt ZHPCleaner-[S]-03052016-18_30_43.txt  

 

Re: internet navigation problem

Aie Aie Aie,

Tu as fais nettoyer et non pas juste scanner !

Du coup il a visiblement flinguer ton jeu de poker, que visiblement il n'aime pas. Le plus simple sera de le réinstaller si tu y tiens, en faisant attention à décocher tous les logiciels bonus qui viennent s'agriper à ton navigateur...

Maitenant tu peux refaire un scan ZHPDiag en l'hébergant sur up2sha.re.

Dis moi également si il y a toujours des problèmes de navigations

Bon courage.

Chapi

Re: internet navigation problem

salut,

ok pas grave pr le poker, je comptais arreter.

https://up2sha.re/file?f=UfyqjWb9UA8c

Merci

Re: internet navigation problem

ah oui, j'ai moins de pb de navigation mais toujours un peu.

c'est ce fichier dns qui bloque pas mal je pense

Re: internet navigation problem

Ok, effectivement les DNS malveillants sont toujours là.

On va les faire sauter manuellement :

  • Rend toi dans le panneau de configuration
  • Clique sur l'icône → Réseau et Internet.
  • Puis sur → Centre réseau et partage
  • Puis sur → Connexion au réseau local
  • Choisi ensuite Propriétés
  • Clique sur Protocole Internet Version 4
  • Puis de nouveau sur Propriétés
  • Enfin choisi Obtenir les adresses des serveurs DNS automatiquement

Ensuite redémarre et refait un scan ZHPDiag.

Bon courage.

Chapi

Re: internet navigation problem

salut,

j'ai fait ce que tu m'as dit et jai toujours les fichiers dns

https://up2sha.re/file?f=vy3OLkc1ac1x

dans propriété jai décoché les autres protocole sans faire expres c'est grave?

Re: internet navigation problem

Bonsoir,

Il n'y a aucune raison de les décocher, tu peux les remettre.

On va essayer de faire sauter ça avec RogueKiller :

  • Télécharge RogueKiller de Tigzy sur le Bureau.
  • Quitte tous tes programmes en cours.
  • Lance le en faisant un clic-droit dessus et choisis "Exécuter en tant qu'administrateur".
  • Si le filtre SmartScreen réagit clique sur [Exécuter quand même].
  • Accepte les conditions d'utilisations.
  • Clique sur le bouton "Scan".
  • A la fin, ça prend un peu de temps, clique sur "Rapport", puis "Ouvrir TXT".
  • Un rapport doit être créé sur le Bureau, poste le dans ta prochaine réponse.

Bon courage

Chapi

Re: internet navigation problem

salut,

désolé j'étais un peu occupé aujourdhui,voici le rapport:

RogueKiller V12.1.5.0 (x64) [May  2 2016] (Gratuit) par Adlice Software email : http://www.adlice.com/contact/ Remontées : http://forum.adlice.com Site web : http://www.adlice.com/fr/logiciels/roguekiller/ Blog : http://www.adlice.com

Système d'exploitation : Windows 8.1 (6.3.9600) 64 bits version Démarré en  : Mode normal Utilisateur : thomas [Administrateur] Démarré depuis : C:\Users\thomas\Downloads\RogueKillerX64.exe Mode : Scan -- Date : 05/04/2016 16:34:23

¤¤¤ Processus : 0 ¤¤¤

¤¤¤ Registre : 8 ¤¤¤ [Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-1704502057-2460348180-801270001-1001\Software\Microsoft\Windows\CurrentVersion\Run | Chromium : "c:\users\thomas\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session --restore-last-session [x][x][x][x][x] -> Trouvé(e) [Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-1704502057-2460348180-801270001-1001\Software\Microsoft\Windows\CurrentVersion\Run | Chromium : "c:\users\thomas\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session --restore-last-session [x][x][x][x][x] -> Trouvé(e) [PUP] (X64) HKEY_USERS\S-1-5-21-1704502057-2460348180-801270001-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce | Application Restart #1 : C:\Users\thomas\AppData\Local\Pokki\Engine\ServiceHostApp.exe  --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend="C:\Users\thomas\AppData\Local\Pokki\Engine\inspector" --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --flag-switches-begin --flag-switches-end --restore-last-session [x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x] -> Trouvé(e) [PUP] (X64) HKEY_USERS\S-1-5-21-1704502057-2460348180-801270001-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce | Application Restart #0 : C:\Users\thomas\AppData\Local\Pokki\Engine\ServiceHostApp.exe  --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend="C:\Users\thomas\AppData\Local\Pokki\Engine\inspector" --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --flag-switches-begin --flag-switches-end --restore-last-session [x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x] -> Trouvé(e) [PUP] (X86) HKEY_USERS\S-1-5-21-1704502057-2460348180-801270001-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce | Application Restart #1 : C:\Users\thomas\AppData\Local\Pokki\Engine\ServiceHostApp.exe  --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend="C:\Users\thomas\AppData\Local\Pokki\Engine\inspector" --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --flag-switches-begin --flag-switches-end --restore-last-session [x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x] -> Trouvé(e) [PUP] (X86) HKEY_USERS\S-1-5-21-1704502057-2460348180-801270001-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce | Application Restart #0 : C:\Users\thomas\AppData\Local\Pokki\Engine\ServiceHostApp.exe  --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend="C:\Users\thomas\AppData\Local\Pokki\Engine\inspector" --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --flag-switches-begin --flag-switches-end --restore-last-session [x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x][x] -> Trouvé(e) [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1704502057-2460348180-801270001-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://acer13.msn.com/?pc=ACJB  -> Trouvé(e) [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1704502057-2460348180-801270001-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://acer13.msn.com/?pc=ACJB  -> Trouvé(e)

¤¤¤ Tâches : 0 ¤¤¤

¤¤¤ Fichiers : 0 ¤¤¤

¤¤¤ Fichier Hosts : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Vérification MBR : ¤¤¤ +++++ PhysicalDrive0: WDC WD5000LPVX-22V0TT0 +++++ --- User --- [MBR] efdc55bbd73292fb949dc7e0ac3ea131 [BSP] 06a66828c1925fbb132895953148eb0e : Empty|VT.Unknown MBR Code Partition table: 0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 600 MB 1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 1230848 | Size: 300 MB 2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 1845248 | Size: 128 MB 3 - Basic data partition | Offset (sectors): 2107392 | Size: 461426 MB 4 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 947107840 | Size: 14485 MB User = LL1 ... OK User = LL2 ... OK

Re: internet navigation problem

Bonsoir,

J'ai vu ce post sur CCM, tu continue avec Malekal ou avec moi ?

On va donc partir sur un script ZHPFix :

On va utiliser ZHPFix, un logiciel de Nicolas Coolman, afin de supprimer quelques éléments :

  • Rends toi sur la page de téléchargement de ZHPFix, puis clique sur le bouton bleu "Nicolas Coolman - Télécharger".
  • Enregistre le fichier où tu veux et lance le (fais le par un clic-droit -> Exécuter en temps qu'administrateur).
  • Laisse toi guider pendant l'installation, à la fin, un raccourci se crée sur ton bureau, lance le (fais le par un clic-droit -> Exécuter en temps qu'administrateur).
  • Clique sur l'icône "Importer".
  • Copie colle le script suivant, en partant de Script ZHPFix :
Script ZHPFix

G0 - GCSP: Preferences [User Data\Default][HomePage] http://a.global-cdn.co
G0 - GCSP: Preferences [User Data\Default][HomePage] http://m77.dnsqa365.com

O4 - HKUS\S-1-5-21-1704502057-2460348180-801270001-1001\..\RunOnce: [Application Restart #1] C:\Users\thomas\AppData\Local\Pokki\Engine\ServiceHostApp.exe (.not file.)
O4 - HKUS\S-1-5-21-1704502057-2460348180-801270001-1001\..\RunOnce: [Application Restart #0] C:\Users\thomas\AppData\Local\Pokki\Engine\ServiceHostApp.exe (.not file.)

O17 - HKLM\System\CCS\Services\Tcpip\..\{37F650BF-BA0B-48A5-9CEA-54F1E05D1189}: DhcpNameServer = 82.163.142.7
O17 - HKLM\System\CCS\Services\Tcpip\..\{7ECB9E90-E1B4-476D-BEE7-AC32B32EB2DF}: DhcpNameServer = 82.163.142.7
O17 - HKLM\System\CCS\Services\Tcpip\..\{D5FB136A-FD22-4F9C-84EC-A0FF350762E2}: DhcpNameServer = 82.163.142.7

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{37F650BF-BA0B-48A5-9CEA-54F1E05D1189}: DhcpNameServer = 82.163.142.7
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7ECB9E90-E1B4-476D-BEE7-AC32B32EB2DF}: DhcpNameServer = 82.163.142.7
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D5FB136A-FD22-4F9C-84EC-A0FF350762E2}: DhcpNameServer = 82.163.142.7

FirewallRaz
EmptyPrefetch
EmptyTemp
EmptyFlash
  • Clique sur le bouton "GO" pour lancer le nettoyage, confirme et patiente pendant le traitement.
  • A la fin, un rapport nommé ZHPFixReport.txt sera créé et sauvegardé sur le bureau.
  • Copie/colle la totalité du rapport dans ta prochaine réponse.

Redémarre et refais un scan ZHPDiag.

Bon courage.

Et pas de réponse de ma part avant dimanche, c'est le week-end !

Chapi