~ Rapport de ZHPDiag v2014.1.25.26 - Nicolas Coolman (25/01/2014) ~ Lancé par OD (04/02/2014 19:12:02) ~ Adresse du Site Web http://nicolascoolman.webs.com ~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/ ~ Traduit par Nicolas Coolman ~ Etat de la version : ~ Liste blanche : Activée par le programme ~ Elévation des Privilèges : OK ~ User Account Control (UAC): Activate by user ---\\ Navigateurs Internet MSIE: Internet Explorer v11.0.9600.16476 MFIE: Mozilla Firefox 26.0 (Defaut) ---\\ Informations sur les produits Windows ~ Langage: Français Windows 8.1, 64-bit (Build 9600) Windows Server License Manager Script : OK ~ ion : Windows(R) Operating System, OEM_DM channel Windows ID Activation : OK ~ Windows Partial Key : 7MFD6 Windows License : OK ~ Windows Remaining Initializations Number : 999 Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ Logiciels de protection du système avast! Pro Antivirus v9.0.2013 Trusteer Sécurité des points d'accès v3.5.1304.46 McAfee Security Scan Plus v3.8.130.10 Spybot - Search & Destroy v2.2.25 Windows Defender W8 ---\\ Logiciels d'optimisation du système ---\\ Logiciels de partage PeerToPeer ---\\ Surveillance de Logiciels Adobe Flash Player 12 Plugin Adobe Reader XI Java 7 Update 51 ---\\ Informations sur le système ~ Processor: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 3785 MB (56% free) System Restore: Activé (Enable) System drive C: has 52 GB (34%) free of 150 GB ---\\ Mode de connexion au système ~ Computer Name: AZUS ~ User Name: OD ~ All Users Names: OD, HomeGroupUser$, Administrateur, ~ Unselected Option: None Logged in as Administrator ---\\ Variables d'environnement ~ System Unit : C:\ ~ %AppZHP% : C:\Users\OD\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\OD\AppData\Roaming\ ~ %Desktop% : C:\Users\OD\Desktop\ ~ %Favorites% : C:\Users\OD\Favorites\ ~ %LocalAppData% : C:\Users\OD\AppData\Local\ ~ %StartMenu% : C:\Users\OD\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumération des unités disques C: Hard drive, Flash drive, Thumb drive (Free 52 Go of 150 Go) D: Hard drive, Flash drive, Thumb drive (Free 735 Go of 765 Go) E: CD-ROM drive (Not Inserted) F: Floppy drive, Flash card reader, USB Key (Not Inserted) G: CD-ROM drive (Free 0 Go of 0 Go) H: Hard drive, Flash drive, Thumb drive (Free 4 Go of 7 Go) K: Hard drive, Flash drive, Thumb drive (Free 317 Go of 466 Go) ---\\ Etat du Centre de Sécurité Windows [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified ~ Security Center: 49 Legitimates Filtered in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.63DC38C3E4564B2405D562855643ABA2] - (.Microsoft Corporation - Explorateur Windows.) (.22/10/2013 - 08:55:27.) -- C:\Windows\Explorer.exe [2328872] [MD5.48CFA7BE561A7BE144C29BB912055016] - (.Microsoft Corporation - Application de démarrage de Windows.) (.22/08/2013 - 10:58:29.) -- C:\Windows\System32\Wininit.exe [144384] [MD5.9B6678DB9C6A232C5A84D2FDFFF8B0E1] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.26/11/2013 - 08:07:57.) -- C:\Windows\System32\wininet.dll [2334208] [MD5.7C94FDA3809015B8F2208D2E1C221F17] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.22/08/2013 - 10:55:08.) -- C:\Windows\System32\Winlogon.exe [564736] [MD5.2F18065618E39AA2E656EE737B71E791] - (.Microsoft Corporation - Bibliothèque de licences.) (.22/08/2013 - 11:39:40.) -- C:\Windows\System32\sppcomapi.dll [447488] [MD5.239268BAB58EAE9A3FF4E08334C00451] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.22/08/2013 - 14:25:35.) -- C:\Windows\system32\Drivers\AFD.sys [567296] [MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.22/08/2013 - 13:43:41.) -- C:\Windows\system32\Drivers\atapi.sys [26464] [MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) (.22/08/2013 - 12:40:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [88576] [MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.22/08/2013 - 09:46:35.) -- C:\Windows\system32\Drivers\Cdrom.sys [164352] [MD5.5DB26D7E0216D0BF364A81D3829AD7B9] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.22/08/2013 - 12:38:00.) -- C:\Windows\system32\Drivers\DfsC.sys [134656] [MD5.03909BDBFF0DCACCABF2B2D4ADEE44DC] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.22/08/2013 - 12:38:38.) -- C:\Windows\system32\Drivers\HDAudBus.sys [78336] [MD5.84CFC5EFA97D0C965EDE1D56F116A541] - (.Microsoft Corporation - Pilote de port i8042.) (.22/08/2013 - 12:39:15.) -- C:\Windows\system32\Drivers\i8042prt.sys [107520] [MD5.B7342B3C58E91107F6E946A93D9D4EFD] - (.Microsoft Corporation - IP Network Address Translator.) (.27/11/2013 - 13:02:29.) -- C:\Windows\system32\Drivers\IpNat.sys [142848] [MD5.79B6F3DF7CDFD12159871FF71464F0CE] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.23/11/2013 - 08:08:19.) -- C:\Windows\system32\Drivers\MRxSmb.sys [403456] [MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) (.22/08/2013 - 12:37:02.) -- C:\Windows\system32\Drivers\netBT.sys [282624] [MD5.4412D565C0278C401575E11072C7DCE3] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.22/08/2013 - 14:25:41.) -- C:\Windows\system32\Drivers\ntfs.sys [2011488] [MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Pilote de port parallèle.) (.22/08/2013 - 12:40:02.) -- C:\Windows\system32\Drivers\Parport.sys [94208] [MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.22/08/2013 - 12:35:51.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [120832] [MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.30/09/2013 - 04:59:53.) -- C:\Windows\system32\Drivers\rdpdr.sys [195584] [MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) (.22/08/2013 - 14:25:35.) -- C:\Windows\system32\Drivers\tdx.sys [107520] [MD5.9F9CE33B50611A1C61A46B8911E0B30B] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.22/08/2013 - 13:39:15.) -- C:\Windows\system32\Drivers\volsnap.sys [312160] ~ Generic Processes: Scanned in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 7/4288 ~ Mes musiques (My Musics) : 4/940 ~ Mes Videos (My Videos) : 2/34 ~ Mes Favoris (My Favorites) : 1/5 ~ Mes Documents (My Documents) : 2/2772 ~ Mon Bureau (My Desktop) : 2/583 ~ Menu demarrer (Programs) : 1/39 ~ Hidden Files: Scanned in 00mn 05s ---\\ Processus lancés [MD5.ABF61886B1DA43566845CEE2071D7A70] - (.ASUSTeK Computer Inc. - Handle ASUS All-In-One any event.) -- C:\Program Files (x86)\ASUS\ASUS Key Suite\AsKeySuite.exe [707232] [PID.4360] [MD5.8C9231025FAF86B78906B6C847531FFB] - (.ASUSTeK Computer Inc. - ASUS Routine Controller.) -- C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe [2935424] [PID.4368] [MD5.20B52B09283E8A18B22319BF971A8C37] - (.Trusteer Ltd. - RapportService.) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe [2484504] [PID.4692] [MD5.2F03C763EE0DFB4DE56176737DEFB2E2] - (.Microsoft Corporation - Touch Keyboard and Handwriting Panel Helper.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe [21184] [PID.4260] [MD5.3F188126510FA73A469F42DE42252937] - (.ASUSTeK Computer Inc. - AI Suite II.) -- C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe [1504640] [PID.5892] [MD5.53AF21EEB4894CA7C84A5A65E50D7A49] - (.Gemalto N.V. - RunSanDiskSecureAccess_Win.) -- C:\Users\OD\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [30705792] [PID.4580] [MD5.9B79B2A8D2670D8C62ECA7416F02CEBE] - (.Samsung - Kies.) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564992] [PID.4544] [MD5.10E89F598469C60D8C87A8218089A87D] - (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\OD\AppData\Local\Akamai\netsession_win.exe [4489472] [PID.4592] [MD5.7D7D090E09D28AE68309D625C42B1C9B] - (.ASUSTeK Computer Inc. - ALU MFC Application.) -- C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe [195200] [PID.4424] [MD5.51E86C2B0530E37597B21C0564B3FA76] - (.Western Digital - WD Drive Auto Unlock.) -- C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe [1688008] [PID.1512] [MD5.A78AAB0D2D70EF7DD56B7328AC502059] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096] [PID.2484] [MD5.AF49D1C79EA49A7833017F290EE63B82] - (.Safer-Networking Ltd. - Spybot - Search & Destroy tray access.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784] [PID.6264] [MD5.5B6E8E09BE6401A7E022F52FDFCB2FF8] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336] [PID.6320] [MD5.849D66021A0EF43A20137BA9D85ECADF] - (.Microsoft Corporation - Internet Low-Mic Utility Tool.) -- C:\Program Files (x86)\Internet Explorer\IELowutil.exe [222720] [PID.3376] [MD5.CA25CAEEBDBE25D85565877219F684F8] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8339968] [PID.3116] ~ Processes Running: Scanned in 00mn 01s ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2) C:\Users\OD\AppData\Local\Google\Chrome\User Data\Default\Preferences ~ Google Browser: 0 Legitimates Filtered in 00mn 00s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Users\OD\AppData\Roaming\Mozilla\Firefox\Profiles\iu98m0gd.default-1390584176275\prefs.js M2 - MFEP: prefs.js [OD - iu98m0gd.default-1390584176275\rqvvkj6.f@wc-yo.co.uk] [] BolockTTheeAds v1.4 (..) ~ Firefox Browser: 3 Legitimates Filtered in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Hosts file redirection (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Hosts File: Scanned in 00mn 05s ~ Nombre de lignes (Lines number): 15514 ---\\ Internet Explorer Toolbars (O3) O3 - Toolbar: avast! Online Security - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll =>Toolbar.Google O3 - Toolbar: Bing Bar - [HKLM]{8dcb7100-df86-4384-8842-8fa844297b3f} . (.Microsoft Corporation. - Bing Client Extensions.) -- C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\amd64\BingExt.dll =>Toolbar.Bing O3 - Toolbar: avast! Online Security - [HKLM]{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll ~ Toolbar: Scanned in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\Desktop [Public]: Belarc Advisor.lnk . (.Belarc, Inc. - Belarc Advisor Computer Inventory.) -- C:\Program Files (x86)\Belarc\BelarcAdvisor\BelarcAdvisor.exe O4 - GS\Desktop [Public]: Digital Photo Professional.lnk . (.CANON INC. - DPPViewer Module.) -- C:\Program Files (x86)\Canon\Digital Photo Professional\DPPViewer.exe O4 - GS\Desktop [Public]: EOS Utility.lnk . (.CANON INC. - EOS Utility.) -- C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe O4 - GS\Desktop [Public]: EPSON Scan.lnk . (.SEIKO EPSON CORP. - EPSON Scan.) -- C:\Windows\twain_32\escndv\escndv.exe O4 - GS\Desktop [Public]: McAfee Security Scan Plus.lnk . (.McAfee, Inc. - McAfee.) -- C:\Program Files\McAfee Security Scan\3.8.130\McUICnt.exe O4 - GS\Desktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O4 - GS\Desktop [Public]: Spybot-S&D Start Center.lnk . (.Safer-Networking Ltd. - Start Center.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe O4 - GS\Desktop [Public]: Waves MAXXAudio.lnk . (...) -- C:\Program Files (x86)\Realtek\Audio\HDA\MaxxAudioControl64.exe (.not file.) O4 - GS\Desktop [Public]: Wise Registry Cleaner.lnk . (.WiseCleaner.com - Wise Registry Cleaner.) -- C:\Program Files (x86)\Wise\Wise Registry Cleaner\WiseRegCleaner.exe O4 - GS\Program [Public]: Belarc Advisor.lnk . (.Belarc, Inc. - Belarc Advisor Computer Inventory.) -- C:\Program Files (x86)\Belarc\BelarcAdvisor\BelarcAdvisor.exe O4 - GS\Program [Public]: Desktop.lnk - Clé orpheline O4 - GS\Program [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O4 - GS\Program [Public]: Spybot-S&D Start Center.lnk . (.Safer-Networking Ltd. - Start Center.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe O4 - GS\QuickLaunch [OD]: Directory Lister Pro.lnk . (.KRKsoft - Directory Lister Pro v1.61.) -- C:\Program Files (x86)\Directory Lister Pro\DirListerPro.exe O4 - GS\QuickLaunch [OD]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\TaskBar [OD]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O4 - GS\Program [OD]: Create Amazing Presentations.lnk - Clé orpheline O4 - GS\Program [OD]: Documents.lnk . (...) -- C:\Users\OD\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms O4 - GS\Program [OD]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\Program [OD]: My Passport (H).lnk . (...) -- H:\ O4 - GS\Program [OD]: Panneau de configuration.lnk - Clé orpheline O4 - GS\Program [OD]: WD Apps for Windows.lnk . (...) -- K:\WD Apps for Windows O4 - GS\Desktop [OD]: Directory Lister Pro.lnk . (.KRKsoft - Directory Lister Pro v1.61.) -- C:\Program Files (x86)\Directory Lister Pro\DirListerPro.exe O4 - GS\Desktop [OD]: WhoCrashed.lnk . (...) -- C:\Program Files\WhoCrashed\WhoCrashed.exe ~ Global Startup: 82 Legitimates Filtered in 00mn 01s ---\\ Applications lancées au démarrage du sytème (O4) O4 - GS\Startup [Public]: McAfee Security Scan Plus.lnk . (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe O4 - GS\Startup [OD]: Dropbox.lnk . (.Dropbox, Inc. - Dropbox.) -- C:\Users\OD\AppData\Roaming\Dropbox\bin\Dropbox.exe =>.Dropbox O4 - GS\Startup [OD]: LaunchU3.exe.lnk . (...) -- C:\Users\OD\AppData\Roaming\Microsoft\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe =>.Realtek Semiconductor Corp O4 - HKLM\..\Run: [RtHDVBg] . (.Realtek Semiconductor - HD Audio Background Process.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe O4 - HKLM\..\Run: [AmIcoSinglun64] . (.Alcor Micro Corp. - Single LUN Icon Utility for VID 058F PID 63.) -- C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [CanonMyPrinter] . (.CANON INC. - Canon My Printer.) -- C:\Program Files\Canon\MyPrinter\BJMyPrt.exe O4 - HKLM\..\Run: [CanonSolutionMenu] . (.CANON INC. - CNSLMAIN.) -- C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe O4 - HKCU\..\Run: [SanDiskSecureAccess_Manager.exe] . (.Gemalto N.V. - RunSanDiskSecureAccess_Win.) -- C:\Users\OD\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe O4 - HKCU\..\Run: [KiesPreload] . (.Samsung - Kies.) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe O4 - HKCU\..\Run: [Akamai NetSession Interface] . (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\OD\AppData\Local\Akamai\netsession_win.exe O4 - HKCU\..\Run: [Google+ Auto Backup] . (.Google Inc. - AutoBackup.) -- C:\Users\OD\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe O4 - HKLM\..\Wow6432Node\Run: [IAStorIcon] . (.Intel Corporation - Delayed launcher.) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe O4 - HKLM\..\Wow6432Node\Run: [ASUS Easy Update] . (.ASUSTeK Computer Inc. - ALU MFC Application.) -- C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe O4 - HKLM\..\Wow6432Node\Run: [ASUSPRP] . (.ASUSTek Computer Inc. - ASUS Product Register Program.) -- C:\Program Files (x86)\ASUS\APRP\APRP.exe O4 - HKLM\..\Wow6432Node\Run: [ASUS Ai Charger] . (.ASUSTek Computer Inc. - AiChargerAP MFC Application.) -- C:\Program Files (x86)\ASUS\ASUS Ai Charger\AiChargerAP.exe O4 - HKLM\..\Wow6432Node\Run: [RemoteControl10] . (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe O4 - HKLM\..\Wow6432Node\Run: [WD Drive Unlocker] . (.Western Digital - WD Drive Auto Unlock.) -- C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe =>.Western Digital Technologies O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe O4 - HKLM\..\Wow6432Node\Run: [autopoll] . (.Pas de propriétaire - AutoPoll Application.) -- C:\Program Files (x86)\Autopoll Application\autopoll.exe O4 - HKLM\..\Wow6432Node\Run: [KiesTrayAgent] . (.Samsung Electronics Co., Ltd. - Kies TrayAgent Application.) -- C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe =>.Samsung Electronics Co O4 - HKLM\..\Wow6432Node\Run: [SDTray] . (.Safer-Networking Ltd. - Spybot - Search & Destroy tray access.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle Corporation O4 - HKLM\..\Wow6432Node\Run: [WD Quick View] . (.Western Digital Technologies, Inc. - WD Quick View.) -- C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe =>.Western Digital Technologies O4 - HKUS\S-1-5-21-3166950008-1836483829-3207958714-1001\..\Run: [SanDiskSecureAccess_Manager.exe] . (.Gemalto N.V. - RunSanDiskSecureAccess_Win.) -- C:\Users\OD\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe O4 - HKUS\S-1-5-21-3166950008-1836483829-3207958714-1001\..\Run: [KiesPreload] . (.Samsung - Kies.) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe O4 - HKUS\S-1-5-21-3166950008-1836483829-3207958714-1001\..\Run: [Akamai NetSession Interface] . (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\OD\AppData\Local\Akamai\netsession_win.exe O4 - HKUS\S-1-5-21-3166950008-1836483829-3207958714-1001\..\Run: [Google+ Auto Backup] . (.Google Inc. - AutoBackup.) -- C:\Users\OD\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe ~ Application: Scanned in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: Se&nd to OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll =>.Microsoft Corporation O9 - Extra button: Lync Click to Call [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\lync.exe (.not file.) O9 - Extra button: OneNote Lin&ked Notes [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll =>.Microsoft Corporation ~ IE Extra Buttons: Scanned in 00mn 00s ---\\ Site dans la Zone de confiance d'Internet Explorer (O15) O15 - Trusted Zone: [HKCU\...\Domains] http.ma-config.com O15 - Trusted Zone: [HKCU\...\Domains] http.touslesdrivers.com ~ IE Zone Confiance: Scanned in 00mn 01s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{8B61816A-C164-43E6-B0A0-5542EC3BD8E8}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{DF35D20E-E5E5-41A0-A8AC-C8D95D9C9ADF}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{8B61816A-C164-43E6-B0A0-5542EC3BD8E8}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{DF35D20E-E5E5-41A0-A8AC-C8D95D9C9ADF}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) -- O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll ~ Winlogon: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - AppInit_DLLs: . (...) - C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll (.not file.) =>Toolbar.Conduit ~ AppInit DLL: Scanned in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) . (.Safer-Networking Ltd. - Windows Security Center integration..) - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe O23 - Service: WD Drive Manager (WDDriveService) . (.Western Digital Technologies, Inc. - WD Drive Service.) - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe ~ Services: 21 Legitimates Filtered in 00mn 19s ---\\ Tâches planifiées en automatique (O39) [MD5.00000000000000000000000000000000] [APT] [PCRegistryShield_Popup] (...) -- C:\Program Files (x86)\PC Registry Shield\Splash.exe (.not file.) [0] =>Rogue.PCRegistryShield [MD5.00000000000000000000000000000000] [APT] [PCRegistryShield_Start] (...) -- C:\Program Files (x86)\PC Registry Shield\PcRegistryShield.exe (.not file.) [0] =>Rogue.PCRegistryShield ~ Scheduled Task: 17 Legitimates Filtered in 00mn 04s ---\\ Logiciels installés (O42) O42 - Logiciel: BolockTTheeAds - (.BlockThEAdsi.) [HKLM][64Bits] -- {558295F0-DEC2-66EC-3830-04777EF7DA33} O42 - Logiciel: GS.Supporter 1.80 - (.Verified Publisher.) [HKLM][64Bits] -- {5F189DF5-2D05-472B-9091-84D9848AE48B}{1a34a8e0} O42 - Logiciel: OnSpec Autopoll Application - (...) [HKLM][64Bits] -- Autopoll Application V1.01 ~ Logic: 20 Legitimates Filtered in 00mn 00s ---\\ HKCU & HKLM Software Keys [HKCU\Software\Beamrise] =>Hijacker.Beamrise [HKCU\Software\PCRegistryShieldLanguage] ~ Key Software: 302 Legitimates Filtered in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 20/01/2014 - 19:03:55 - [0] ----D C:\Program Files (x86)\PC Registry Shield =>Rogue.PCRegistryShield O43 - CFD: 30/01/2014 - 22:24:52 - [0,458] ----D C:\ProgramData\BolockTTheeAds O43 - CFD: 30/01/2014 - 22:24:52 - [0,110] ----D C:\ProgramData\deafe74fc5289349 O43 - CFD: 16/01/2014 - 20:34:12 - [0] ----D C:\ProgramData\House Of Soft O43 - CFD: 16/01/2014 - 20:35:37 - [2,336] ----D C:\ProgramData\InstallMate =>PUP.Tarma O43 - CFD: 09/11/2013 - 17:44:16 - [0] ----D C:\Users\OD\AppData\Roaming\EncryptStick O43 - CFD: 25/10/2013 - 00:25:38 - [0] ----D C:\Users\OD\AppData\Local\PackageStaging O43 - CFD: 20/01/2014 - 18:24:00 - [0] ----D C:\Users\OD\AppData\Local\PCRegistryShield O43 - CFD: 19/01/2014 - 00:45:26 - [0,003] ----D C:\Users\OD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup ~ Program Folder: 201 Legitimates Filtered in 00mn 32s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.F6384487AF44E5763FD8E4F8EEF65F8B] - 22/01/2014 - 23:53:47 ---A- . (...) -- C:\Windows\System32\results.xml [17242] O44 - LFC:[MD5.4B916278E1487A5CD5F8F9A521980026] - 24/01/2014 - 00:59:50 ---A- . (...) -- C:\Windows\System32\ApnDatabase.xml [385614] O44 - LFC:[MD5.34FD838136743685A20D14C8646892A2] - 29/01/2014 - 16:49:09 ---A- . (...) -- C:\Windows\DPINST.LOG [58606] ~ Files: 61 Legitimates Filtered in 00mn 06s ---\\ Derniers fichiers créés dans Windows Prefetcher (O45) O45 - LFCP:[MD5.C409DDF2AAD6DBF5B0F561362AE46B1E] - 04/02/2014 - 18:44:58 ---A- - C:\Windows\Prefetch\dynreservedpri.db O45 - LFCP:[MD5.E39BA46BF049DB1B79B26E768EB0EDDA] - 04/02/2014 - 19:03:20 ---A- - C:\Windows\Prefetch\PfPre_ce39d6de.db O45 - LFCP:[MD5.C489093E730791767DFDF34075132A27] - 11/01/2014 - 12:44:55 ---A- - C:\Windows\Prefetch\MPNCOPY.EXE-39E0F58E.pf O45 - LFCP:[MD5.81A1AC6AF78F2C5452FBBCF025B9D002] - 14/01/2014 - 15:32:15 ---A- - C:\Windows\Prefetch\PDFREFLOW.EXE-F608E4FB.pf O45 - LFCP:[MD5.7AFB7F7D1188EBB3CE40567D91D3C583] - 16/01/2014 - 13:24:11 ---A- - C:\Windows\Prefetch\PHOTOSAPP.EXE-8FE95EC8.pf O45 - LFCP:[MD5.ED1FDB751A5533579290E44F307EDA9A] - 16/01/2014 - 20:30:52 ---A- - C:\Windows\Prefetch\NUEVA%20RUSTICIDAD%20MEXICANA-69D78165.pf O45 - LFCP:[MD5.50A73A5FBEBC81B973B8A17DF0B9A574] - 17/01/2014 - 13:21:36 ---A- - C:\Windows\Prefetch\INS5375.EXE-F987489A.pf O45 - LFCP:[MD5.EADD70E6C9E750BC28AFDDA6AE7EC8FF] - 17/01/2014 - 13:21:50 ---A- - C:\Windows\Prefetch\IMINENT_1712-B2FCAD5E.EXE-C42D963F.pf =>Adware.IMBooster O45 - LFCP:[MD5.0D1C93D90D60017C4284E59735E0E48B] - 17/01/2014 - 13:21:53 ---A- - C:\Windows\Prefetch\BIZZYBOLT_2511-5EA0573C.EXE-C3C97B8B.pf =>PUP.Bizzybolt O45 - LFCP:[MD5.5C77BFBE888E63B997BCC236CE201221] - 17/01/2014 - 13:21:53 ---A- - C:\Windows\Prefetch\METRO.EXE-255D0B05.pf O45 - LFCP:[MD5.74FCFDDAACC75C4E38AC7DAC1DF1D40D] - 17/01/2014 - 13:22:09 ---A- - C:\Windows\Prefetch\IEXPLOREINSTALLER.EXE-C8B18C3F.pf O45 - LFCP:[MD5.01761ACDD798E031D07A528F476D8868] - 17/01/2014 - 13:22:10 ---A- - C:\Windows\Prefetch\IMINENTMINIBARIE.EXE-48880A46.pf =>PUP.Minibar O45 - LFCP:[MD5.E5D43D44E9E5C8E1DDE2400523DCD2D4] - 17/01/2014 - 13:22:22 ---A- - C:\Windows\Prefetch\BEAMRISESETUP_2304-1DF765AE.E-C808A479.pf =>Hijacker.Beamrise O45 - LFCP:[MD5.39A3F7F44F7CFDAA3BF469EE5FAF25F8] - 17/01/2014 - 13:22:37 ---A- - C:\Windows\Prefetch\VISUALBEESILENT_2506-8EA7FD25-96F0F0B2.pf =>Adware.VisualBeeToolbar O45 - LFCP:[MD5.660345E575370C0234384817FB386E65] - 17/01/2014 - 21:32:28 ---A- - C:\Windows\Prefetch\SPYHUNTER-INSTALLER.EXE-F1D57026.pf =>Crapware.SpyHunter O45 - LFCP:[MD5.302167359BA2275A26898030FEB1071B] - 17/01/2014 - 23:48:43 ---A- - C:\Windows\Prefetch\HIJACKTHIS(1).EXE-3142BAC9.pf O45 - LFCP:[MD5.50E4E7335AD0290DDA849FF9BA720019] - 18/01/2014 - 13:28:46 ---A- - C:\Windows\Prefetch\SYSTEMRESET.EXE-3E7CD9FA.pf O45 - LFCP:[MD5.1ECD2BADBF15D409C09731130D35D8AC] - 18/01/2014 - 15:00:00 ---A- - C:\Windows\Prefetch\JOURNAL.EXE-39951965.pf O45 - LFCP:[MD5.C7D100AED321045EA5957AE5F52FB070] - 18/01/2014 - 16:44:32 ---A- - C:\Windows\Prefetch\MPNEX30.EXE-D974F00F.pf O45 - LFCP:[MD5.11AE86DF3D6DA40E857EEDDBEFC7FFFC] - 18/01/2014 - 18:22:41 ---A- - C:\Windows\Prefetch\FHMANAGEW.EXE-86652DB0.pf O45 - LFCP:[MD5.B1D931E8B23032A09C00BDED7AFD886F] - 18/01/2014 - 18:27:00 ---A- - C:\Windows\Prefetch\BELARCADVISOR.EXE-5FCFA06E.pf O45 - LFCP:[MD5.197ADDEBC36C7D9DBAE42BAC014D4820] - 18/01/2014 - 20:16:30 ---A- - C:\Windows\Prefetch\DIRLISTERPRO.EXE-5993ECB7.pf O45 - LFCP:[MD5.436554013A3333B972D7EC45FF785111] - 18/01/2014 - 21:07:11 ---A- - C:\Windows\Prefetch\REPLISTING.EXE-C6C24952.pf O45 - LFCP:[MD5.02F7408539E361252440B42B9AAE6F5D] - 18/01/2014 - 21:18:07 ---A- - C:\Windows\Prefetch\SETC671.TMP-362D77DE.pf O45 - LFCP:[MD5.51821047BDB4B7F1A2F421503553ECD1] - 18/01/2014 - 21:19:22 ---A- - C:\Windows\Prefetch\_IU14D2N.TMP-0345A733.pf O45 - LFCP:[MD5.594FB5ED1416A43BB5A08BC791254866] - 19/01/2014 - 00:31:52 ---A- - C:\Windows\Prefetch\SYSTEMSETTINGS.EXE-D8CC3B5E.pf O45 - LFCP:[MD5.93540067CF9BD896A285D26A73A1849C] - 20/01/2014 - 16:50:40 ---A- - C:\Windows\Prefetch\UMBRELLA.EXE-0B44C393.pf =>Adware.IMBooster O45 - LFCP:[MD5.462D25D242149A2D881F6B96114EAB1F] - 20/01/2014 - 18:16:42 ---A- - C:\Windows\Prefetch\CNSLMAIN.EXE-024AFDE5.pf O45 - LFCP:[MD5.87EFAA6718D3A8B6A836FE9154E1AA69] - 20/01/2014 - 18:16:46 ---A- - C:\Windows\Prefetch\SANDISKSECUREACCESS_MANAGER.E-49B1C1BF.pf O45 - LFCP:[MD5.77B0688C80091529C6E2FF678E0C1752] - 20/01/2014 - 18:16:51 ---A- - C:\Windows\Prefetch\RUNSANDISKSECUREACCESS_WIN.EX-DD9B547D.pf O45 - LFCP:[MD5.5B056C77A4CFB60436C1A34AAA024A6A] - 20/01/2014 - 18:24:05 ---A- - C:\Windows\Prefetch\PCREGISTRYSHIELD.EXE-63C1EAD5.pf O45 - LFCP:[MD5.31022B3B986E245D9986706F68C9E0CC] - 20/01/2014 - 18:25:28 ---A- - C:\Windows\Prefetch\INSTUP.EXE-3AF05CB9.pf O45 - LFCP:[MD5.DA2FDBDBFB712F381AFB8244752A8294] - 20/01/2014 - 18:30:36 ---A- - C:\Windows\Prefetch\SPYHUNTER4.EXE-3B4E3201.pf =>Crapware.SpyHunter O45 - LFCP:[MD5.5DA5FD2E5D4D20CE64D5BA6117BD769B] - 20/01/2014 - 18:32:51 ---A- - C:\Windows\Prefetch\REGHUNTER.EXE-CB203609.pf =>Crapware.RegHunter O45 - LFCP:[MD5.E156DE00A29E371A6F6D1AC2AE503EA0] - 20/01/2014 - 18:41:27 ---A- - C:\Windows\Prefetch\RUNSANDISKSECUREACCESS_WIN.EX-ED497DD0.pf O45 - LFCP:[MD5.66EC1C579109B2872D981CF85058A4D2] - 20/01/2014 - 18:45:17 ---A- - C:\Windows\Prefetch\WSHOST.EXE-05F0A3AF.pf O45 - LFCP:[MD5.1331B0585B4FF36DECF25C704B9CC5EF] - 20/01/2014 - 19:03:47 ---A- - C:\Windows\Prefetch\INSTACT.EXE-E7522972.pf O45 - LFCP:[MD5.0D72821D1F708014BAE0F47C25A209A9] - 20/01/2014 - 19:03:53 ---A- - C:\Windows\Prefetch\XCOPY.EXE-85839ADD.pf O45 - LFCP:[MD5.E6B12BD09B5CB2EFC3A41099306AED2F] - 20/01/2014 - 19:04:36 ---A- - C:\Windows\Prefetch\WISECUSTOMCALLA.EXE-6F681972.pf =>Crapware.SpyHunter O45 - LFCP:[MD5.955926D14D4F8BC888E77E6BD5D8B1D0] - 20/01/2014 - 19:04:50 ---A- - C:\Windows\Prefetch\WISECUSTOMCALLA1.EXE-5075C197.pf =>Crapware.SpyHunter O45 - LFCP:[MD5.4225DD1798F44D4CE03D993678F9C4D4] - 20/01/2014 - 19:08:06 ---A- - C:\Windows\Prefetch\CNMSEA0.EXE-985CFA32.pf O45 - LFCP:[MD5.BBD3E1049C00E58432739A0CBAEAAD2A] - 20/01/2014 - 19:23:01 ---A- - C:\Windows\Prefetch\WAJAM_VALIDATE.EXE-FDE9FF34.pf =>PUP.Wajam O45 - LFCP:[MD5.FCD096CFEAE177E293758811BF7E7996] - 20/01/2014 - 19:23:04 ---A- - C:\Windows\Prefetch\WRCPRO.EXE-FC42A206.pf O45 - LFCP:[MD5.86EAF1EEEAE2BE1132FF19E9C09934FA] - 20/01/2014 - 19:23:36 ---A- - C:\Windows\Prefetch\MYSEARCHDIALSRV.EXE-9836EEE8.pf =>Adware.MyWebSearch O45 - LFCP:[MD5.95A9B0051C18CD68F444925F03296BEC] - 20/01/2014 - 19:23:51 ---A- - C:\Windows\Prefetch\MYSEARCHDIAL.EXE-1DAFECD8.pf =>Adware.MyWebSearch O45 - LFCP:[MD5.4B6FA5AB84DA2D3815BDD5D0A38666BE] - 20/01/2014 - 19:23:58 ---A- - C:\Windows\Prefetch\WRCPRO [1].EXE-64059DBB.pf O45 - LFCP:[MD5.D735D88F5DFD90E03E86B6B835485B64] - 20/01/2014 - 19:23:58 ---A- - C:\Windows\Prefetch\WRCPRO [1].TMP-232F8619.pf ~ Prefetcher: 230 Legitimates Filtered in 00mn 02s ---\\ Clé de registre Shell MountPoints2 (MPKS) (O51) O51 - MPSK:{5b21c042-ab80-11e2-be8b-50465dda511d}\AutoRun\command. (...) -- F:\LaunchU3.exe (.not file.) O51 - MPSK:{6fb207fd-d5a1-11e2-be94-806e6f6e6963}\AutoRun\command. (.Western Digital - Unlock Utility for WD Encrypted Drive.) -- G:\WD Drive Unlock.exe ~ Keys: Scanned in 00mn 01s ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 17 Legitimates Filtered in 00mn 00s ---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56) O56 - MWPE:[HKCU\...\policies\Explorer] - "NoLowDiskSpaceChecks"=1 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 ~ MWPE Keys: 8 Legitimates Filtered in 00mn 00s ---\\ Liste des pilotes du système (SDL) (O58) O58 - SDL:[MD5.C04F7B373881009D7994D9BF55D24AB4] - 23/10/2013 - 19:12:55 ---A- . (...) -- C:\Windows\System32\Drivers\aswRvrt.sys [65776] O58 - SDL:[MD5.90399625F341AB76BA4B85A5E860EB1F] - 29/12/2013 - 00:56:58 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys [207904] O58 - SDL:[MD5.C1ABB0F7E3BEA48A0417BDF6FF14AB21] - 13/08/2013 - 00:25:46 ---A- . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\Drivers\bcmfn2.sys [17624] O58 - SDL:[MD5.B57C2B7900F93C72CC49E51C173A7739] - 18/06/2012 - 04:39:14 ---A- . (.ENE TECHNOLOGY INC. - enecir.) -- C:\Windows\System32\Drivers\enecir.sys [72688] O58 - SDL:[MD5.955FFE2B1D74A9E0E3E0E558E6A17F3B] - 28/10/2013 - 01:12:10 ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudbus.sys [107288] O58 - SDL:[MD5.BB94A5E2CEE5FD83BA5A72A37AECADDF] - 28/10/2013 - 01:12:12 ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudmdm.sys [204568] O58 - SDL:[MD5.366DEA74BBA65B362BCCFC6FC2ADFD8B] - 22/08/2013 - 13:43:32 ---A- . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x64.) -- C:\Windows\System32\Drivers\stexstor.sys [31072] O58 - SDL:[MD5.ADAA34740E9F6AFF94CC75D5CF8ED7E2] - 04/01/2008 - 13:34:42 ----- . (...) -- C:\Windows\SysWOW64\drivers\AsInsHelp32.sys [10216] O58 - SDL:[MD5.EDAA17CE771C696655B6585F7CAD2100] - 04/01/2008 - 13:34:48 ----- . (...) -- C:\Windows\SysWOW64\drivers\AsInsHelp64.sys [11832] O58 - SDL:[MD5.798DE15F187C1F013095BBBEB6FB6197] - 22/08/2012 - 17:54:10 ---A- . (...) -- C:\Windows\SysWOW64\drivers\AsIO.sys [15232] O58 - SDL:[MD5.1392B92179B07B672720763D9B1028A5] - 03/08/2010 - 06:21:24 ---A- . (...) -- C:\Windows\SysWOW64\drivers\AsUpIO.sys [14464] O58 - SDL:[MD5.19166026A93206F9C6A8CD3A1F010AE4] - 02/04/2009 - 13:30:14 ---A- . (...) -- C:\Windows\SysWOW64\drivers\ASUSHWIO.SYS [10296] ~ Drivers: 17 Legitimates Filtered in 00mn 04s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC: 01/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_001%20du%2031_01_2014_1098573361(1).pdf [140879] O61 - LFC: 01/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_001%20du%2031_01_2014_1098573361.pdf [140879] O61 - LFC: 01/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_005%20du%2031_05_2013_1085371011.pdf [137218] O61 - LFC: 01/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_006%20du%2001_07_2013_1086856748.pdf [136244] O61 - LFC: 01/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relevé MasterCard Débit Crédit PRET 146289551400027300301 au 2014-01-20.pdf [96353] O61 - LFC: 02/02/2014 - 19:14:21 ---A- . (...) -- C:\Users\OD\Documents\PRELEVEMENTS\Recettes Dépenses 2ème semestre 113.docx [15571] O61 - LFC: 02/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_001%20du%2031_12_2013_1096100453(1).pdf [111974] O61 - LFC: 02/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_001%20du%2031_12_2013_1096100453.pdf [111974] O61 - LFC: 02/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_9999%20du%2029_02_2012_1062940134.pdf [98194] O61 - LFC: 02/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_9999%20du%2029_09_2012_1071664316.pdf [97823] O61 - LFC: 02/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_9999%20du%2030_04_2012_1065560286.pdf [97321] O61 - LFC: 02/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_9999%20du%2030_06_2012_1068178992.pdf [97891] O61 - LFC: 02/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_9999%20du%2031_03_2012_1064183083.pdf [97935] O61 - LFC: 02/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_9999%20du%2031_05_2012_1066970536.pdf [126615] O61 - LFC: 02/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_9999%20du%2031_07_2012_1069401545.pdf [97746] O61 - LFC: 02/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_9999%20du%2031_08_2012_1070534728.pdf [97311] O61 - LFC: 02/02/2014 - 19:14:26 ---A- . (...) -- C:\Users\OD\Downloads\Relev_%20n_9999%20du%2031_10_2012_1072341526(1).pdf [97789] O61 - LFC: 03/02/2014 - 19:14:11 R--A- . (...) -- C:\Users\OD\AppData\Roaming\ZHP\HOSTS.txt [450639] =>.Nicolas Coolman O61 - LFC: 03/02/2014 - 19:14:15 ---A- . (...) -- C:\Users\OD\Documents\Farine Iturbide.xlsx [14283] O61 - LFC: 03/02/2014 - 19:14:24 ---A- . (...) -- C:\Users\OD\Documents\wincrashreport-x64\WinCrashReport.cfg [406] O61 - LFC: 04/02/2014 - 19:13:47 ---A- . (...) -- C:\Users\OD\AppData\Local\Google\Chrome\User Data\Local State [57703] O61 - LFC: 04/02/2014 - 19:13:47 ---A- . (...) -- C:\Users\OD\AppData\Local\Google\GBScreensaver\Prefs\rssUserWebAlbums.xml [50] O61 - LFC: 04/02/2014 - 19:14:11 ---A- . (...) -- C:\Users\OD\AppData\Roaming\ZHP\Log.txt [173363] =>.Nicolas Coolman O61 - LFC: 04/02/2014 - 19:14:11 ---A- . (...) -- C:\Users\OD\AppData\Roaming\ZHP\TestsZHPDiag.txt [2749] =>.Nicolas Coolman O61 - LFC: 04/02/2014 - 19:14:21 ---A- . (...) -- C:\Users\OD\Documents\PRELEVEMENTS\2014 1er semestre.docx [14860] O61 - LFC: 04/02/2014 - 19:14:25 ---A- . (...) -- C:\Users\OD\Downloads\Extrait de comptes au 2013-12-31(2).pdf [13305] O61 - LFC: 04/02/2014 - 19:14:25 ---A- . (...) -- C:\Users\OD\Downloads\Extrait de comptes au 2014-01-31.pdf [13668] O61 - LFC: 04/02/2014 - 19:14:25 ---A- . (...) -- C:\Users\OD\Downloads\adwcleaner(9).exe [1166132] ~ 60 Fichiers temporaires (Temporary files) ~ Files: 623 Legitimates Filtered in 01mn 09s ---\\ Liste des outils de désinfection (LATC) (O63) O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn 00s ---\\ Menu de démarrage Internet (SMI) (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Not Key.) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) O69 - SBI: SearchScopes [HKCU] {460C3D19-B3D4-4964-A550-77D263B0CCCB} - (WebSearch) - http://websearch.toolksearchbook.info O69 - SBI: SearchScopes [HKCU] {5037E990-3FA6-4A59-8AE6-387D03300273} - (Mysearchdial) - http://start.mysearchdial.com =>Adware.MyWebSearch O69 - SBI: SearchScopes [HKCU] {950E9E3B-5C25-4C5A-AA80-C89C95FC7DD6} - (Ask Search) - http://websearch.ask.com =>Toolbar.Ask O69 - SBI: SearchScopes [HKCU] {A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9} - (Google) - http://www.google.com ~ Keys: Scanned in 00mn 00s ---\\ Recherche particulière à la racine du système (SPRF) (O84) [MD5.47025DD5CBA8B43E9D26C960FF5B32A7] [SPRF][23/10/2013] (...) -- C:\Users\OD\AppData\Local\Temp\Quarantine.exe [344355] [MD5.630AD1674149A392A97A7B10945960CD] [SPRF][03/02/2014] (.Conduit - Search Protect by Conduit.) -- C:\Users\OD\AppData\Local\Temp\SPSetup.exe [5987944] =>Toolbar.Conduit [MD5.7E89844169E755775F09AA4724680281] [SPRF][23/01/2014] (...) -- C:\Users\OD\Desktop\vlc-2-1-1-win32.exe [24489269] ~ Files: 3 Legitimates Filtered in 00mn 00s ---\\ Enumère les codes produits des logiciels (PUC) (O90) O90 - PUC: "4031B705A49140249A9DB9AA5FE17F06" . (.WD Quick View.) -- C:\WINDOWS\Installer\{507B1304-194A-4204-A9D9-9BAAF51EF760}\icon.ico =>.Western Digital Technologies O90 - PUC: "617DD6FF01B79624F991FF0BA74CDC59" . (.Bing Bar.) -- C:\WINDOWS\Installer\{FF6DD716-7B10-4269-9F19-FFB07AC4CD95}\icon_installer_ico =>Toolbar.Bing ~ Update Products: 107 Legitimates Filtered in 00mn 00s ---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS) [MD5.39988793C0BE26963F7C8228E7F04E23] [WIS][06/01/2014] (.Google - Google+ Auto Backup.) -- C:\Windows\Installer\10cbc69.msi [3088384] [MD5.159792BDE66BF24D7CEDF70193CA4A4E] [WIS][31/05/2012] (.Fingertapps - Fingertapps Instruments.) -- C:\Windows\Installer\2d2b0.msi [148216832] [MD5.F8A2404F888C1BA507578994CF592D59] [WIS][03/02/2014] (.Trusteer - Rapport.) -- C:\Windows\Installer\c081.msi [39980544] ~ WIS: 110 Legitimates Filtered in 00mn 12s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 19/01/2014 257928 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe SS - | Auto 21/11/2011 96896 | (ATKGFNEXSrv) . (.ASUS.) - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe SS - | Auto 16/12/2013 193696 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\BBSvc.exe SS - | Demand 21/12/2013 279000 | (cphs) . (.Intel Corporation.) - C:\Windows\SysWow64\IntelCpHeciSvc.exe SS - | Demand 26/04/2011 2702848 | (FirebirdServerMAGIXInstance) . (.MAGIX®.) - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe SS - | Auto 11/04/2013 136176 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 11/04/2013 136176 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 11/04/2013 194032 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe SS - | Demand 06/09/2013 288776 | (McComponentHostService) . (.McAfee, Inc..) - C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe SS - | Demand 20/12/2013 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe SR - | Auto 21/12/2013 65432 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe SR - | Auto 11/09/2012 106880 | (ASLDRService) . (.ASUSTek Computer Inc..) - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe SR - | Auto 17/02/2012 149120 | (AsSysCtrlService) . (.ASUSTeK Computer Inc..) - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe SR - | Auto 04/02/2014 50344 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe SR - | Demand 16/12/2013 247968 | (BBUpdate) . (.Microsoft Corporation..) - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\SeaPort.exe SR - | Auto 24/05/2011 1840128 | (Fabs) . (.MAGIX AG.) - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe SR - | Auto 09/07/2012 7168 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe SR - | Demand 24/04/2012 169752 | (ICCS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe SR - | Auto 20/04/2012 635104 | (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe SR - | Auto 18/07/2012 165760 | (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe SR - | Auto 18/07/2012 276864 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe SR - | Auto 20/01/2014 2818896 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe SR - | Auto 08/04/2013 1320496 | (PDF Architect Helper Service) . (.pdfforge GmbH.) - C:\Program Files (x86)\PDF Architect\HelperService.exe SR - | Auto 08/04/2013 799280 | (PDF Architect Service) . (.pdfforge GmbH.) - C:\Program Files (x86)\PDF Architect\ConversionService.exe SR - | Auto 22/01/2014 1444120 | (RapportMgmtService) . (.Trusteer Ltd..) - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe SR - | Auto 15/10/2013 3921880 | (SDScannerService) . (.Safer-Networking Ltd..) - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe SR - | Auto 20/09/2013 1042272 | (SDUpdateService) . (.Safer-Networking Ltd..) - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe SR - | Auto 13/09/2013 171416 | (SDWSCService) . (.Safer-Networking Ltd..) - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe SR - | Auto 18/07/2012 364416 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe SR - | Auto 02/11/2013 1042808 | (WDBackup) . (.Western Digital Technologies, Inc..) - C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe SR - | Auto 02/11/2013 270704 | (WDDriveService) . (.Western Digital Technologies, Inc..) - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe SR - | Demand 10/07/1658 0 | (WdNisSvc) . (...) - C:\Program Files (x86)\Windows Defender\NisSrv.exe SR - | Demand 10/07/1658 0 | (WinDefend) . (...) - C:\Program Files (x86)\Windows Defender\MsMpEng.exe SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation SR - | Demand 22/08/2013 37768 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Services: Scanned in 00mn 14s ---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80) Run by OD at 04/02/2014 19:16:12 ~ OS 64 not supported by MBR tool ~ MBR: 0 Legitimates Filtered in 00mn 00s ---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by OD at 04/02/2014 19:16:14 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 02s ---\\ Scan Additionnel (O88) Database Version : 13030 - (25/01/2014) Clés trouvées (Keys found) : 1 Valeurs trouvées (Values found) : 1 Dossiers trouvés (Folders found) : 3 Fichiers trouvés (Files found) : 3 [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =>Adware.Boxore^ [HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google^ C:\Program Files (x86)\PC Registry Shield =>Rogue.PCRegistryShield^ C:\ProgramData\InstallMate =>PUP.Tarma^ C:\Users\OD\AppData\Local\Software =>Adware.Boxore [HKCU\Software\Beamrise] =>Hijacker.Beamrise^ C:\Users\OD\AppData\Local\Temp\SPSetup.exe =>Toolbar.Conduit^ ~ Additionnel Scan: 283627 Items scanned in 00mn 18s ---\\ Récapitulatif des détections trouvées sur votre station ~ http://nicolascoolman.webs.com/apps/blog/show/29507721-toolbar-conduit =>Toolbar.Conduit ~ http://nicolascoolman.webs.com/apps/blog/show/34065742-hijacker-beamrise =>Hijacker.Beamrise ~ http://nicolascoolman.webs.com/apps/blog/show/29637859-toolbar-tarma =>PUP.Tarma ~ http://nicolascoolman.webs.com/apps/blog/show/26684723-adware-imbooster =>Adware.IMBooster ~ http://nicolascoolman.webs.com/apps/blog/show/38533684-pup-bizzybolt =>PUP.Bizzybolt ~ http://nicolascoolman.webs.com/apps/blog/show/34407192-pup-minibar =>PUP.Minibar ~ http://nicolascoolman.webs.com/apps/blog/show/29058830-adware-visualbeetoolbar =>Adware.VisualBeeToolbar ~ http://nicolascoolman.webs.com/apps/blog/show/26609241-crapware-spyhunter =>Crapware.SpyHunter ~ http://nicolascoolman.webs.com/apps/blog/show/34571753-crapware-reghunter =>Crapware.RegHunter ~ http://nicolascoolman.webs.com/apps/blog/show/27379491-toolbar-wajam =>PUP.Wajam ~ http://nicolascoolman.webs.com/apps/blog/show/27146838-adware-mywebsearch =>Adware.MyWebSearch ~ http://nicolascoolman.webs.com/apps/blog/show/28927746-toolbar-ask =>Toolbar.Ask ~ http://nicolascoolman.webs.com/apps/blog/show/26626977-adware-boxore =>Adware.Boxore ~ MSI: 13 link(s) detected in 00mn 18s ~ 1973 Legitimates filtered by white list End of the scan (621 lines in 04mn 31s)(0)