cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2013.9.27.492 - Nicolas Coolman (27/09/2013)
~ Lanc� par eric (28/09/2013 08:55:01)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activ�e par le programme
~ El�vation des Privil�ges : OK
~ User Account Control (UAC): Activate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v9.0.8112.16421 (Defaut)
MFIE: Mozilla Firefox 23.0.1

---\\ Informations sur les produits Windows
~ Langage: Fran�ais
Windows Vista Home Premium Edition, 32-bit Service Pack 2 (Build 6002)
Windows Server License Manager Script : OK
~ Vista, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : MQ3CQ
Windows License : OK
Windows Automatic Updates : OK

---\\ Logiciels de protection du syst�me
AVG 2014 v14.0.3604
Malwarebytes Anti-Malware version 1.75.0.1300
Norton Internet Security v10.1.0.26
Norton AntiVirus v14.1.0.27
Norton Protection Center v2007.1.2.11
SUPERAntiSpyware v5.6.1020

---\\ Logiciels d'optimisation du syst�me

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 11 Plugin
Adobe Reader 8
Java 7 Update 25

---\\ Informations sur le syst�me
~ Processor: x86 Family 15 Model 104 Stepping 1, AuthenticAMD
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 1022 MB (8% free)
System Restore: Activ� (Enable)
System drive C: has 3 GB (2%) free of 141 GB

---\\ Mode de connexion au syst�me
~ Computer Name: PC-DE-ERIC2
~ User Name: eric
~ All Users Names: tetard02, eric, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\eric\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\eric\AppData\Roaming\
~ %Desktop% : C:\Users\eric\Desktop\
~ %Favorites% : C:\Users\eric\Favorites\
~ %LocalAppData% : C:\Users\eric\AppData\Local\
~ %StartMenu% : C:\Users\eric\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enum�ration des unit�s disques
C: Hard drive, Flash drive, Thumb drive (Free 3 Go of 141 Go)



---\\ Etat du Centre de S�curit� Windows
~ Security Center: 37 Legitimates Filtered in 00mn 00s



---\\ Recherche particuli�re de fichiers g�n�riques
[MD5.D07D4C3038F3578FFCE1C0237F2A1253] - (.Microsoft Corporation - Explorateur Windows.) (.10/04/2009 - 22:27:38.) -- C:\Windows\Explorer.exe [2926592]
[MD5.101BA3EA053480BB5D957EF37C06B5ED] - (.Microsoft Corporation - Application de d�marrage de Windows.) (.18/01/2008 - 22:33:38.) -- C:\Windows\System32\Wininit.exe [96768]
[MD5.6839F14A2507D9273BD13565DD880377] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.25/07/2013 - 03:26:10.) -- C:\Windows\System32\wininet.dll [1129472]
[MD5.898E7C06A350D4A1A64A9EA264D55452] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.10/04/2009 - 22:28:14.) -- C:\Windows\System32\Winlogon.exe [314368]
[MD5.3911B972B55FEA0478476B2E777B29FA] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.21/04/2011 - 14:58:27.) -- C:\Windows\system32\Drivers\AFD.sys [273408]
[MD5.1F05B78AB91C9075565A9D8A4B880BC4] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.10/04/2009 - 22:32:28.) -- C:\Windows\system32\Drivers\atapi.sys [19944]
[MD5.7ADD03E75BEB9E6DD102C3081D29840A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.18/01/2008 - 20:28:04.) -- C:\Windows\system32\Drivers\Cdfs.sys [70144]
[MD5.6B4BFFB9BECD728097024276430DB314] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.10/04/2009 - 20:39:18.) -- C:\Windows\system32\Drivers\Cdrom.sys [67072]
[MD5.622C41A07CA7E6DD91770F50D532CB6C] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.14/04/2011 - 15:59:03.) -- C:\Windows\system32\Drivers\DfsC.sys [75264]
[MD5.062452B7FFD68C8C042A6261FE8DFF4A] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.10/04/2009 - 20:42:44.) -- C:\Windows\system32\Drivers\HDAudBus.sys [561152]
[MD5.22D56C8184586B7A1F6FA60BE5F5A2BD] - (.Microsoft Corporation - Pilote de port i8042.) (.18/01/2008 - 20:49:20.) -- C:\Windows\system32\Drivers\i8042prt.sys [54784]
[MD5.8793643A67B42CEC66490B2A0CF92D68] - (.Microsoft Corporation - IP Network Address Translator.) (.18/01/2008 - 20:56:30.) -- C:\Windows\system32\Drivers\IpNat.sys [100864]
[MD5.1E94971C4B446AB2290DEB71D01CF0C2] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.29/04/2011 - 14:24:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [106496]
[MD5.ECD64230A59CBD93C85F1CD1CAB9F3F6] - (.Microsoft Corporation - MBT Transport driver.) (.10/04/2009 - 20:45:38.) -- C:\Windows\system32\Drivers\netBT.sys [185856]
[MD5.2C1121F2B87E9A6B12485DF53CD848C7] - (.Microsoft Corporation - Pilote du syst�me de fichiers NT.) (.03/03/2013 - 20:07:52.) -- C:\Windows\system32\Drivers\ntfs.sys [1082232]
[MD5.0FA9B5055484649D63C303FE404E5F4D] - (.Microsoft Corporation - Pilote de port parall�le.) (.02/11/2006 - 09:51:30.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.A214ADBAF4CB47DD2728859EF31F26B0] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.18/01/2008 - 20:56:36.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [76288]
[MD5.E8BD98D46F2ED77132BA927FCCB47D8B] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.02/11/2006 - 10:03:00.) -- C:\Windows\system32\Drivers\rdpdr.sys [242688]
[MD5.7B75299A4D201D6A6533603D6914AB04] - (.Microsoft Corporation - SMB Transport driver.) (.10/04/2009 - 20:45:24.) -- C:\Windows\system32\Drivers\smb.sys [66560]
[MD5.76B06EB8A01FC8624D699E7045303E54] - (.Microsoft Corporation - TDI Translation Driver.) (.10/04/2009 - 20:45:58.) -- C:\Windows\system32\Drivers\tdx.sys [72192]
[MD5.786DB5771F05EF300390399F626BF30A] - (.Microsoft Corporation - Pilote de clich� instantan� du volume.) (.21/08/2012 - 12:47:42.) -- C:\Windows\system32\Drivers\volsnap.sys [224640]
~ Generic Processes: Scanned in 00mn 33s



---\\ Etat des fichiers cach�s (Cach�/Total)
~ Mes musiques (My Musics) : 1/3
~ Mes Favoris (My Favorites) : 1/27
~ Mes Documents (My Documents) : 1/1184
~ Mon Bureau (My Desktop) : 1/61
~ Menu demarrer (Programs) : 1/27
~ Hidden Files: Scanned in 00mn 06s



---\\ Processus lanc�s
[MD5.C3C40834D72095517D2944ED5910DC67] - (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Windows\RtHDVCpl.exe [4472832] [PID.3908]
[MD5.675253563B449B0B37E97BD09150B1ED] - (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [857648] [PID.4372]
[MD5.598AC9DA3CCD5511ECC4A986B18F7E61] - (.Google - Google Desktop.) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [243200] [PID.4548]
[MD5.333B0558329214A1E0942806C04A14D0] - (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Program Files\AVG\AVG2014\avgui.exe [4851760] [PID.4584]
[MD5.C456658AF90F42BE3CDF1048F9CDB5CA] - (.Microsoft Corporation - Notifications du contr�le parental Windows.) -- C:\Windows\System32\wpcumi.exe [176128] [PID.4592]
[MD5.D63797E8E7781EE1500A810CB6194FA6] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816] [PID.4612]
[MD5.BF08674925F151BD4537B89A493E3E0C] - (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehtray.exe [125952] [PID.4620]
[MD5.43D083268A0919F3527A2837390BAF63] - (.Macrovision Corporation - Macrovision Software Manager.) -- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032] [PID.4628]
[MD5.0F4195B9B348DE5CF9B822F81704B20E] - (.Microsoft Corporation - Media Center Media Status Aggregator Servic.) -- C:\Windows\ehome\ehmsas.exe [37376] [PID.4940]
[MD5.66008F4BCD1A9D2A2E8691004002421E] - (.Google - Google Desktop.) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe [779264] [PID.5100]
[MD5.36B9FC05B2091A5782D4A0189FE1735C] - (.ATI Technologies Inc. - Catalyst Control Center: Monitoring program.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe [49152] [PID.5152]
[MD5.0FC4CA031C46CE1BBDD8A7E91ED2251B] - (.ATI Technologies Inc. - Catalyst Control Centre: Host application.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [49152] [PID.5900]
[MD5.AD7A959A7B2883340216A2B14619AC52] - (.Google - Google Desktop.) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe [244224] [PID.6092]
[MD5.5D4BF3F62AB25C9CAE8B1FCB1CB47297] - (.AVG Technologies CZ, s.r.o. - AVG Configuration Management Application.) -- C:\Program Files\AVG\AVG2014\avgcfgex.exe [335408] [PID.9216]
[MD5.6080A176D09435FC8E6E800996656E18] - (.Microsoft Corporation - Console IME.) -- C:\Windows\system32\conime.exe [69120] [PID.2920]
[MD5.B4CF3FB7E9B8EA69757541DCE6CA20ED] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [276376] [PID.9548]
[MD5.72EF708552059546B1AAA82E7AA59439] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files\Mozilla Firefox\plugin-container.exe [17304] [PID.8772]
[MD5.8D4AFD5F4955A52C39C8C424FE5516D9] - (.Adobe Systems, Inc. - Adobe Flash Player 11.8 r800.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe [1862024] [PID.6320]
[MD5.E6378B3216716C28DF1BFC97F863EE7F] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8022528] [PID.7632]
[MD5.702F6D03C671DA99C282D8DF32FE559E] - (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) -- C:\Windows\system32\Ati2evxx.exe [602112] [PID.1200]
[MD5.862BB4CBC05D80C5B45BE430E5EF872F] - (.Microsoft Corporation - Service de gestion des licences Microsoft.) -- C:\Windows\system32\SLsvc.exe [3408896] [PID.1508]
[MD5.E7AAB1A32AC2EEA4C4B735B8D034C802] - (.Symantec Corporation - Symantec Service Framework.) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [107624] [PID.1868]
[MD5.2FE779B1A07747FED8074C433C3C4604] - (.Symantec Corporation - Symantec Application Core Service.) -- C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe [46736] [PID.1940]
[MD5.9EBE730D4B5E3FF25EAAF5A59BA6CCFF] - (.SUPERAntiSpyware.com - Core Service.) -- C:\Program Files\SUPERAntiSpyware\SASCORE.exe [119056] [PID.1680]
[MD5.D9EB91D8DD04D4DCE41C8FAE67D20449] - (.AVG Technologies CZ, s.r.o. - AVG Watchdog Service.) -- C:\Program Files\AVG\AVG2014\avgwdsvc.exe [301152] [PID.2160]
[MD5.910FBA95EE4F56449AA81315884C8EFD] - (.Sonic Solutions - RoxSniffer9 Module.) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [166648] [PID.2568]
[MD5.9638E5820858593A12005C753B03CEAE] - (.Sonic Solutions - RoxMediaDB9 Module.) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [887544] [PID.3596]
[MD5.8726802EA4FBFFA3FD54FD2449BF51D4] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe [217992] [PID.3780]
[MD5.2698CD77F4D73EA7988F0BC63DE8E3D6] - (.Symantec Corporation - Symantec Core Component.) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [1174152] [PID.8016]
[MD5.75295E1C49F068F0C7C3ED1211DF3EFB] - (.AVG Technologies CZ, s.r.o. - AVG Identity Protection Service.) -- C:\Program Files\AVG\AVG2014\avgidsagent.exe [3538480] [PID.9052]
[MD5.57AFA3E42844BA35B763E4F4DD73A2EC] - (.AVG Technologies CZ, s.r.o. - AVG E-mail Scanner.) -- C:\Program Files\AVG\AVG2014\avgemcx.exe [669232] [PID.4360]
[MD5.0CA67D54C4BEACA886293441F5722683] - (.AVG Technologies CZ, s.r.o. - AVG Online Shield Service.) -- C:\Program Files\AVG\AVG2014\avgnsx.exe [895024] [PID.3384]
[MD5.2EE572A077AC7D6203B48EF97E42A116] - (.AVG Technologies CZ, s.r.o. - AVG Resident Shield Service.) -- C:\Program Files\AVG\AVG2014\avgrsx.exe [728624] [PID.4908]
[MD5.17D85A816D56026E2E81F63229087992] - (.AVG Technologies CZ, s.r.o. - AVG Scanning Core Module - Server Part.) -- C:\Program Files\AVG\AVG2014\avgcsrvx.exe [588336] [PID.5712]
[MD5.9BE3744D295A7701EB425332014F0797] - (.Microsoft Corporation - Service de r�ception Windows Media Center.) -- C:\Windows\ehome\ehRecvr.exe [292352] [PID.9728]
[MD5.890DB30F2F61113B9CD993DC942FA020] - (.AVG Technologies CZ, s.r.o. - AVG Installer Application.) -- C:\Program Files\AVG\AVG2014\avgmfapx.exe [5911568] [PID.0]
~ Processes Running: Scanned in 00mn 19s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\eric\AppData\Roaming\Mozilla\Firefox\Profiles\ozz3fcyr.default\prefs.js
M0 - MFSP: prefs.js [eric - ozz3fcyr.default] google
~ Firefox Browser: 19 Legitimates Filtered in 00mn 02s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:8080
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 19



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: &Google - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Barre d'outils pour IE.) -- c:\program files\google\googletoolbar1.dll =>Toolbar.Google
O3 - Toolbar: Show Norton Toolbar - [HKLM]{90222687-F593-4738-B738-FBEE9C7B26DF} . (.Symantec Corporation - UIBhoImpl.) -- C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Cl� orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: AVG Anti-Rootkit Free.lnk . (.Grisoft - AVG Anti-Rootkit Beta.) -- C:\Program Files\GRISOFT\AVG Anti-Rootkit Free\avgarkt.exe
O4 - GS\Desktop [Public]: Creator 9.lnk . (...) -- C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\Main\Roxio_Central33.exe
O4 - GS\Desktop [Public]: File Extractor.lnk . (...) -- C:\Program Files\Tweaks\File Extractor\fileextractor.exe
O4 - GS\Desktop [Public]: Internet - Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O4 - GS\Desktop [Public]: OFFICE One Menu v7.lnk . (.ISSENDIS - Pas de description.) -- C:\Program Files\OFFICE One v7\OFFICE One Menu v7\oomenuv7.exe
O4 - GS\Desktop [Public]: PBUpdator.lnk . (.Packard Bell BV - PBUpdator.exe.) -- C:\Program Files\Packard Bell\Updator\PBUpdator.exe
O4 - GS\Desktop [Public]: SUPERAntiSpyware Free Edition.lnk . (.SUPERAntiSpyware - SUPERAntiSpyware Application.) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - GS\QuickLaunch [eric]: Easy Audio Cutter.lnk . (.Koyote Soft - Pas de description.) -- C:\Program Files\Free mp3 Wma Converter\Easy Audio Cutter\AudioCutter.exe
O4 - GS\QuickLaunch [eric]: Free CD Ripper.lnk . (.Koyote Soft - FreeCDRipper.) -- C:\Program Files\Free mp3 Wma Converter\Free CD Ripper\FreeCDRipper.exe
O4 - GS\QuickLaunch [eric]: Free Mp3 Wma Converter.lnk . (.Koyote Soft - Free Audio Converter.) -- C:\Program Files\Free mp3 Wma Converter\FreeConverter\FreeConverter.exe
O4 - GS\QuickLaunch [eric]: Solitaire.LNK - Cl� orpheline
O4 - GS\QuickLaunch [eric]: Windows Update.lnk . (.Microsoft Corporation - Windows Update Application Launcher.) -- C:\Windows\System32\wuapp.exe
O4 - GS\Desktop [eric]: ComboFix - Raccourci.lnk . (.Swearware - ComboFix NSIS Installer.) -- C:\Users\eric\Downloads\ComboFix.exe
O4 - GS\Desktop [eric]: Easy Audio Cutter.lnk . (.Koyote Soft - Pas de description.) -- C:\Program Files\Free mp3 Wma Converter\Easy Audio Cutter\AudioCutter.exe
O4 - GS\Desktop [eric]: Free CD Ripper.lnk . (.Koyote Soft - FreeCDRipper.) -- C:\Program Files\Free mp3 Wma Converter\Free CD Ripper\FreeCDRipper.exe
O4 - GS\Desktop [eric]: Free Mp3 Wma Converter.lnk . (.Koyote Soft - Free Audio Converter.) -- C:\Program Files\Free mp3 Wma Converter\FreeConverter\FreeConverter.exe
O4 - GS\Desktop [eric]: Revo Uninstaller.lnk . (.VS Revo Group - Revo Uninstaller.) -- C:\Program Files\VS Revo Group\Revo Uninstaller\Revouninstaller.exe
~ Global Startup: 85 Legitimates Filtered in 00mn 14s



---\\ Applications lanc�es au d�marrage du syt�me (O4)
O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Windows\RtHDVCpl.exe =>.Realtek Semiconductor Corp
O4 - HKLM\..\Run: [Skytel] . (.Realtek Semiconductor Corp. - Realtek Voice Manager.) -- C:\Windows\Skytel.exe =>.Realtek Semiconductor Corp
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [StartCCC] . (...) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Google Desktop Search] . (.Google - Google Desktop.) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O4 - HKLM\..\Run: [toolbar_eula_launcher] . (...) -- C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
O4 - HKLM\..\Run: [AVG_UI] . (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Program Files\AVG\AVG2014\avgui.exe
O4 - HKLM\..\Run: [WPCUMI] . (.Microsoft Corporation - Notifications du contr�le parental Windows.) -- C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe =>.Oracle Corporation
O4 - HKCU\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM] . (.Macrovision Corporation - Macrovision Software Manager.) -- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.
O4 - HKCU\..\Run: [WMPNSCFG] . (.Microsoft Corporation - Application de configuration du service Par.) -- C:\Program Files\Windows Media Player\WMPNSCFG.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-4206510175-4102161452-42169000-1002\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-21-4206510175-4102161452-42169000-1002\..\Run: [ISUSPM] . (.Macrovision Corporation - Macrovision Software Manager.) -- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
O4 - HKUS\S-1-5-21-4206510175-4102161452-42169000-1002\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.
O4 - HKUS\S-1-5-21-4206510175-4102161452-42169000-1002\..\Run: [WMPNSCFG] . (.Microsoft Corporation - Application de configuration du service Par.) -- C:\Program Files\Windows Media Player\WMPNSCFG.exe =>.Microsoft Corporation
~ Application: Scanned in 00mn 00s



---\\ Boutons situ�s sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} . (.Microsoft Corporation - Windows Live Messenger Companion core resources.) -- C:\Program Files\Windows Live\Companion\companionres.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{A1830B40-FCC7-4338-9238-F8F283624F39}: DhcpNameServer = 212.27.40.240 212.27.40.241
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB60A57B-FE37-406D-8B57-24A2A1572F52}: DhcpNameServer = 212.27.40.240 212.27.40.241
O17 - HKLM\System\CS1\Services\Tcpip\..\{A1830B40-FCC7-4338-9238-F8F283624F39}: DhcpNameServer = 212.27.40.240 212.27.40.241
O17 - HKLM\System\CS1\Services\Tcpip\..\{DB60A57B-FE37-406D-8B57-24A2A1572F52}: DhcpNameServer = 212.27.40.240 212.27.40.241
O17 - HKLM\System\CS2\Services\Tcpip\..\{A1830B40-FCC7-4338-9238-F8F283624F39}: DhcpNameServer = 212.27.40.240 212.27.40.241
O17 - HKLM\System\CS2\Services\Tcpip\..\{DB60A57B-FE37-406D-8B57-24A2A1572F52}: DhcpNameServer = 212.27.40.240 212.27.40.241
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.240 212.27.40.241
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Cl� de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Biblioth�que de l'interface utilisateur du.) -- C:\Windows\System32\browseui.dll
~ STS/SSO: Scanned in 00mn 00s



---\\ Enum�ration Active Desktop & MHTML Editor (O24)
O24 - Desktop General: BackupWallPaper - .(...) - C:\Windows\Web\Wallpaper\Packard Bell\Wallpaper\Wallpaper Galactic_1900x1440.jpg
O24 - Desktop General: WallPaper - .(...) - C:\Windows\Web\Wallpaper\Packard Bell\Wallpaper\Wallpaper Galactic_1900x1440.jpg
~ Desktop Component: 4 Legitimates Filtered in 00mn 00s



---\\ T�ches planifi�es en automatique (O39)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\ROC_JAN2013_TB_rmv.job [342]
[MD5.00000000000000000000000000000000] [APT] [ROC_JAN2013_TB_rmv] (...) -- C:\Program Files\AVG Secure Search\PostInstall\ROC.exe (.not file.) [0] =>Toolbar.AVGSearch
[MD5.F628086E0E5E7D6E61B551C28D730473] [APT] [{F5BE81E7-C88E-4D3C-BD11-AAF4B74B2701}] (...) -- C:\Users\eric\Desktop\WUD250B1002Setup.exe [256053]
~ Scheduled Task: 20 Legitimates Filtered in 00mn 10s



---\\ Logiciels install�s (O42)
O42 - Logiciel: GoogleToolbar - (...) [HKLM] -- GoogleToolbar =>Toolbar.Google
O42 - Logiciel: Javascript Obfuscator 4.3 Trial - (...) [HKLM] -- Javascript Obfuscator Trial_is1
~ Logic: 110 Legitimates Filtered in 00mn 01s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\JSO]
~ Key Software: 148 Legitimates Filtered in 00mn 01s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 29/09/2012 - 09:11:58 - [2,471] ----D C:\Program Files\Javascript Obfuscator
O43 - CFD: 27/08/2012 - 09:35:56 - [0] ----D C:\Program Files\Yahoo! =>Toolbar.Yahoo
O43 - CFD: 01/08/2008 - 13:14:08 - [0] ----D C:\ProgramData\beep axis mode free
O43 - CFD: 01/08/2008 - 13:09:32 - [0] ----D C:\ProgramData\Way Size More
O43 - CFD: 26/08/2012 - 15:59:47 - [0] ----D C:\ProgramData\Yahoo! =>Toolbar.Yahoo
O43 - CFD: 19/09/2013 - 07:26:19 - [31,012] ----D C:\Users\eric\AppData\Roaming\FixZeroAccess
O43 - CFD: 20/12/2008 - 10:25:25 - [0,016] ----D C:\Users\eric\AppData\Roaming\Yahoo! =>Toolbar.Yahoo
~ Program Folder: 253 Legitimates Filtered in 01mn 12s



---\\ Derniers fichiers modifi�s ou cr�es sous Windows et System32 (O44)
O44 - LFC:[MD5.908595900C21C0CEBFD9289CC99AC935] - 27/09/2013 - 19:33:06 ---A- . (...) -- C:\WinUpdateFix.txt [1350]
O44 - LFC:[MD5.3C6130FAEB882D4CCBB0421747C1E956] - 26/09/2013 - 20:39:35 ---A- . (...) -- C:\Windows\System32\userawacs.cfg [285]
O44 - LFC:[MD5.95E6ED70EE5ED076FDF11A4F6B5156EC] - 26/09/2013 - 20:39:12 ---A- . (...) -- C:\Windows\System32\outlook.cfg [50]
O44 - LFC:[MD5.4F5E83A21BB21A2173048C1574F7079B] - 26/09/2013 - 20:39:07 ---A- . (...) -- C:\Windows\System32\usergui.cfg [50]
O44 - LFC:[MD5.43118345072343DD64B61149C4FA44B7] - 26/09/2013 - 20:39:05 ---A- . (...) -- C:\Windows\System32\userguistate.cfg [60]
O44 - LFC:[MD5.D54B156731B46695F8763E514FBA9D01] - 24/09/2013 - 22:19:51 ---A- . (...) -- C:\ComboFix.txt [18652]
O44 - LFC:[MD5.3CF3D4A45CC2AF973DBC30EC8D33252B] - 24/09/2013 - 22:14:30 ---A- . (...) -- C:\Windows\system.ini [215]
O44 - LFC:[MD5.73FE8285D075FE7F0CD980870A09AF3D] - 24/09/2013 - 21:22:28 ---A- . (...) -- C:\Windows\wininit.ini [79]
O44 - LFC:[MD5.62165F37463DB73970B84072F6D1E1F3] - 23/09/2013 - 13:56:58 ---A- . (...) -- C:\TDSSKiller.2.9.2.0_23.09.2013_14.54.49_log.txt [130020]
O44 - LFC:[MD5.E29986BBA9303C8B4FF6CBFC0DB92678] - 20/09/2013 - 22:32:52 ---A- . (...) -- C:\Windows\ntbtlog.txt [49724]
O44 - LFC:[MD5.0277C027A26428DB64EF4F64F52BB4FD] - 19/09/2013 - 16:09:56 ---A- . (...) -- C:\Windows\MBR.exe [208896]
O44 - LFC:[MD5.F042EE4C8D66248D9B86DCF52ABAE416] - 19/09/2013 - 16:09:55 ---A- . (...) -- C:\Windows\PEV.exe [256000]
O44 - LFC:[MD5.9E05A9C264C8A908A8E79450FCBFF047] - 19/09/2013 - 16:09:55 ---A- . (...) -- C:\Windows\grep.exe [80412]
O44 - LFC:[MD5.2B657A67AEBB84AEA5632C53E61E23BF] - 19/09/2013 - 16:09:55 ---A- . (...) -- C:\Windows\sed.exe [98816]
O44 - LFC:[MD5.5E832F4FAF5F481F2EAF3B3A48F603B8] - 19/09/2013 - 16:09:55 ---A- . (...) -- C:\Windows\zip.exe [68096]
O44 - LFC:[MD5.5C1A5EC3284103D2BF97F2806EDA38AD] - 19/09/2013 - 13:41:12 ---A- . (...) -- C:\TDSSKiller.2.9.2.0_19.09.2013_14.36.24_log.txt [397042]
O44 - LFC:[MD5.076CCFFAFF495D2E38B5F1E8236774D7] - 19/09/2013 - 13:13:47 ---A- . (...) -- C:\TDSSKiller.2.9.2.0_19.09.2013_13.56.16_log.txt [1388166]
O44 - LFC:[MD5.C011D45D4C1E5FE989667A90B02D02D8] - 19/09/2013 - 12:50:59 ---A- . (...) -- C:\TDSSKiller.2.9.2.0_19.09.2013_13.47.16_log.txt [131054]
~ Files: 30 Legitimates Filtered in 05mn 01s



---\\ Op�rations et fonctions au d�marrage de Windows Explorer (O46)
O46 - SEH:ShellExecuteHooks - SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
~ ShellExecuteHooks: Scanned in 00mn 00s



---\\ Enum�ration des cl�s de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
~ MWPS: 20 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du syst�me (SDL) (O58)
O58 - SDL:[MD5.97AFFA9D95FFE20EEE6229BC6BE166CF] - 14/12/2006 - 08:11:58 ---A- . (.ATK0100 - ATK0100 ACPI Utility.) -- C:\Windows\System32\Drivers\ATKACPI.sys [7680]
O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 02/11/2006 - 08:09:42 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
~ Drivers: 20 Legitimates Filtered in 00mn 00s



---\\ Liste des outils de d�sinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> [HKCU\..\open\Command] (.Not Key.)
O67 - Shell Spawning: <.cmd> [HKCU\..\open\Command] (.Not Key.)
O67 - Shell Spawning: <.com> [HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 22 Legitimates Filtered in 00mn 00s



---\\ Menu de d�marrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.cc", "FR");
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.client_js_http_src", "");
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.client_js_https_src", "");
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.currLocale", "fr");
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.date", "1376570951000");
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.finished", "15.5.0.2");
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.guardCount", 0);
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.guardCountInit", 156);
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.guardKUCount", 0);
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.guardKUCountInit", 156);
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.guardPopupCountInit", -1);
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.guardSPCount", 0);
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.guardSPCountInit", 156);
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.guardSPPopupCount", 5);
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.guardSPPopupCountInit", -1);
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.guid", "{0f978c0b-9c5b-44d6-af4c-9c8b1b38597f}");
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.isHidden", true);
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.istoolbarhp", true);
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.istoolbarsearch", true);
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.lastUpdaterReq", "1380206435000");
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.laststatreq", "1380170809000");
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.newtab", false);
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.overlayVersion", "635113865525781250");
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.rewardsDisabled", true);
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.userHPSettings", "google");
O69 - SBI: prefs.js [eric - ozz3fcyr.default] user_pref("avg.install.userSPSettings", "Google");
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s



---\\ Recherche particuli�re � la racine du syst�me (SPRF) (O84)
[MD5.A21E4E9E6E3FA2B299128D0684A723CE] [SPRF][04/07/2013] (...) -- C:\Users\eric\AppData\Local\d3d9caps.dat [7268]
[MD5.9FF8053D8360C7A0CEA2EE7CF782A629] [SPRF][11/09/2012] (...) -- C:\Users\eric\AppData\Local\fusioncache.dat [92]
[MD5.7A8D0014483D71EC0E7E838078A3077C] [SPRF][03/11/2012] (.Bandoo Media Inc - Free mp3 Wma Converter Install.) -- C:\Users\eric\Desktop\Setup_FreeConverter.exe [458080] =>Adware.Bandoo
[MD5.F628086E0E5E7D6E61B551C28D730473] [SPRF][24/09/2012] (...) -- C:\Users\eric\Desktop\WUD250B1002Setup.exe [256053]
~ Files: 14 Legitimates Filtered in 01mn 59s



---\\ Liste des exceptions du parefeu (FirewallRules) (O87)
O87 - FAEL: "TCP Query User{E37493F8-C5FE-44CF-BE19-A6D716132D7A}E:\programmation\qtchat\release\qtchat.exe" |In - Public - P6 - TRUE | .(...) -- E:\programmation\qtchat\release\qtchat.exe (.not file.)
O87 - FAEL: "UDP Query User{44823339-CF28-4006-8630-458A16074A94}E:\programmation\qtchat\release\qtchat.exe" |In - Public - P17 - TRUE | .(...) -- E:\programmation\qtchat\release\qtchat.exe (.not file.)
~ Firewall: 263 Legitimates Filtered in 00mn 08s



---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.41424428B450C74CDF2AB4D757C10B65] [WIS][13/09/2012] (.Boxore OU - Boxore Client Installer.) -- C:\Windows\Installer\29a5e8.msi [480256] =>Adware.Boxore
[MD5.4C4AEC66850A2BF1BB955D15208A1B72] [WIS][01/08/2007] (.Google Inc. - Google Toolbar for Internet Explorer.) -- C:\Windows\Installer\4be62.msi [1048576] =>Toolbar.Google
[MD5.7743C2ACDCE38E3A1EECB20D5AB82C5D] [WIS][01/08/2007] (.ISSENDIS - OFFICE One 7.0.) -- C:\Windows\Installer\4bedf.msi [5453824]
~ WIS: 103 Legitimates Filtered in 00mn 12s



---\\ Etat g�n�ral des services not Microsoft (EGS) (SR=Running, SS=Stopped)
SR - | Auto 23/05/2013 119056 | (!SASCORE) . (.SUPERAntiSpyware.com.) - C:\Program Files\SUPERAntiSpyware\SASCORE.exe
SS - | Demand 28/09/2013 257416 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SR - | Auto 25/05/2007 602112 | (Ati External Event Utility) . (.ATI Technologies Inc..) - C:\Windows\System32\Ati2evxx.exe
SR - | Auto 03/09/2013 3538480 | (AVGIDSAgent) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files\AVG\AVG2014\avgidsagent.exe
SR - | Auto 22/09/2013 301152 | (avgwd) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files\AVG\AVG2014\avgwdsvc.exe
SR - | Auto 24/10/2006 107624 | (ccEvtMgr) . (.Symantec Corporation.) - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
SR - | Auto 24/10/2006 107624 | (ccSetMgr) . (.Symantec Corporation.) - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
SR - | Auto 24/10/2006 107624 | (CLTNetCnService) . (.Symantec Corporation.) - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
SS - | Demand 13/10/2006 49296 | (comHost) . (.Symantec Corporation.) - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
SS - | Auto 29/01/2010 135664 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 29/01/2010 135664 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 04/01/2007 136120 | (gusvc) . (.Google.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
SS - | Demand 27/10/2006 80552 | (ISPwdSvc) . (.Symantec Corporation.) - C:\Program Files\Norton Internet Security\isPwdSvc.exe
SS - | Demand 08/11/2006 2541248 | C:\Program Files\Symantec\LIVEUP~1\LUCOMS~1.exe (LiveUpdate) . (.Symantec Corporation.) - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.exe
SS - | Demand 17/08/2013 117656 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Auto 08/11/2006 194240 | (Planificateur LiveUpdate automatique) . (.Symantec Corporation.) - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
SR - | Demand 11/01/2007 887544 | (RoxMediaDB9) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
SR - | Auto 11/01/2007 166648 | (RoxWatch9) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
SS - | Auto 21/06/2013 162408 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SR - | Demand 01/08/2007 1174152 | (Symantec Core LC) . (.Symantec Corporation.) - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
SR - | Auto 20/09/2006 46736 | (SymAppCore) . (.Symantec Corporation.) - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
SS - | Demand 18/01/2008 21504 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 18/01/2008 21504 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 16s



---\\ Scan Additionnel (O88)
Database Version : 12930 - (27/09/2013)
Cl�s trouv�es (Keys found) : 16
Valeurs trouv�es (Values found) : 1
Dossiers trouv�s (Folders found) : 3
Fichiers trouv�s (Files found) : 5

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\GoogleToolbar] =>Toolbar.Google^
[HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110011441179}] =>Adware.GamePlayLabs
[HKLM\Software\Classes\Installer\Features\AF2CF8FE20EBB4443855807CA5D6E7A3] =>Adware.Boxore
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\AF2CF8FE20EBB4443855807CA5D6E7A3] =>Adware.Boxore
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] =>PUP.Tarma
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] =>PUP.Tarma
[HKLM\Software\Classes\Installer\Features\4301AEBD288588A40833184CFEC0AF92] =>Adware.iWinArcade
[HKLM\Software\Classes\Installer\Products\4301AEBD288588A40833184CFEC0AF92] =>Adware.iWinArcade
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4301AEBD288588A40833184CFEC0AF92] =>Adware.iWinArcade
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\80F08842F9EA1BE4BA4922DA74CDB698] =>Adware.iWinArcade
[HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110011431152}] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011431152}] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011441179}] =>PUP.CrossRider
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\38D5CDD0A851B3940A43CC50ABBA251C] =>Adware.Boxore^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BA71D41F6CC0B6247B05D473850A8AEA] =>Adware.Boxore^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =>Adware.Boxore^
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google^
C:\Program Files\Yahoo! =>Toolbar.Yahoo^
C:\ProgramData\Yahoo! =>Toolbar.Yahoo^
C:\Users\eric\AppData\Roaming\Yahoo! =>Toolbar.Yahoo^
c:\program files\google\googletoolbar1.dll =>Toolbar.Google^
C:\Users\eric\Desktop\Setup_FreeConverter.exe =>Adware.Bandoo^
C:\Windows\Installer\29a5e8.msi =>Adware.Boxore^
C:\Windows\Installer\4be62.msi =>Toolbar.Google^
~ Additionnel Scan: 234846 Items scanned in 01mn 22s



---\\ R�capitulatif des d�tections trouv�es sur votre station
~ http://nicolascoolman.webs.com/apps/blog/show/32384220-toolbar-google =>Toolbar.Google
~ http://nicolascoolman.webs.com/apps/blog/show/30268689-toolbar-yahoo =>Toolbar.Yahoo
~ http://nicolascoolman.webs.com/apps/blog/show/26611092-adware-bandoo =>Adware.Bandoo
~ http://nicolascoolman.webs.com/apps/blog/show/26626977-adware-boxore =>Adware.Boxore
~ http://nicolascoolman.webs.com/apps/blog/show/26820943-adware-gameplaylabs =>Adware.GamePlayLabs
~ http://nicolascoolman.webs.com/apps/blog/show/28766471-adware-iwinarcade =>Adware.iWinArcade
~ http://nicolascoolman.webs.com/apps/blog/show/27583526-pup-crossrider =>PUP.CrossRider
~ MSI: 7 link(s) detected in 01mn 23s



~ 1236 Legitimates filtered by white list
End of the scan (509 lines in 13mn 25s)(0)

Publicité


Signaler le contenu de ce document

Publicité