cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2014.1.2.5 - Nicolas Coolman (02/01/2014)
~ Lancé par portable jean pierre (08/01/2014 21:11:57)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.16476
MFIE: Mozilla Firefox 26.0 (Defaut)
GCIE: Google Chrome v31.0.1650.63

---\\ Informations sur les produits Windows
~ Langage: Français
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK

---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft Security Client v4.4.0304.0
Windows Defender W7

---\\ Logiciels d'optimisation du système
CCleaner v4.09 =>Piriform Ltd

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 11 Plugin
Adobe Reader XI
Java 7 Update 25
Java 7 Update 25

---\\ Informations sur le système
~ Processor: Intel64 Family 6 Model 37 Stepping 2, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 7980 MB (75% free)
System Restore: Activé (Enable)
System drive C: has 103 GB (59%) free of 173 GB

---\\ Mode de connexion au système
~ Computer Name: PORTABLEJEANPIE
~ User Name: portable jean pierre
~ All Users Names: _ocster_backup_, UpdatusUser, portable jean pierre, NeroMediaHomeUser.4, HomeGroupUser$, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\portable jean pierre\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\portable jean pierre\AppData\Roaming\
~ %Desktop% : C:\Users\portable jean pierre\Desktop\
~ %Favorites% : C:\Users\portable jean pierre\Favorites\
~ %LocalAppData% : C:\Users\portable jean pierre\AppData\Local\
~ %StartMenu% : C:\Users\portable jean pierre\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 103 Go of 173 Go)
D: Hard drive, Flash drive, Thumb drive (Free 67 Go of 133 Go)
E: CD-ROM drive (Not Inserted)
F: Hard drive, Flash drive, Thumb drive (Free 35 Go of 165 Go)
I: Hard drive, Flash drive, Thumb drive (Free 32 Go of 125 Go)



---\\ Etat du Centre de Sécurité Windows
~ Security Center: 49 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.9B6678DB9C6A232C5A84D2FDFFF8B0E1] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.26/11/2013 - 08:07:57.) -- C:\Windows\System32\wininet.dll [2334208]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.21/11/2010 - 04:24:29.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.21/11/2010 - 04:24:16.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/09/2013 - 02:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.21/11/2010 - 04:24:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.21/11/2010 - 04:23:51.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.21/11/2010 - 04:24:33.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.21/11/2010 - 04:24:32.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/19
Mes musiques (My Musics) : 4/4 (Modified)
~ Mes Favoris (My Favorites) : 1/647
~ Mes Documents (My Documents) : 1/2666
~ Mon Bureau (My Desktop) : 1/242
~ Menu demarrer (Programs) : 1/38
~ Hidden Files: Scanned in 00mn 00s



---\\ Processus lancés
[MD5.03D85DFD60B899D368B099F7ED49E537] - (.ASUS - A tool used to switch network environment.) -- C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe [1160320] [PID.1116]
[MD5.567CF354AF896856319D424AAF278380] - (.Ashampoo Development GmbH & Co. KG - Ashampoo Core Tuner 2 Client.) -- C:\Program Files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2.exe [5220768] [PID.6116]
[MD5.1C5A81304F4B3A24914E10E339E3D51A] - (.BitTorrent Inc. - µTorrent.) -- C:\Users\portable jean pierre\AppData\Roaming\uTorrent\uTorrent.exe [900440] [PID.3860] =>P2P.BitTorrent
[MD5.CC02FE4520CA886508069245D9A6962F] - (.Microsoft Corporation - Internet Low-Mic Utility Tool.) -- C:\Program Files (x86)\Internet Explorer\IELowutil.exe [222720] [PID.6328]
[MD5.A9EEFAEE36BF899340494A5BD5DF7E47] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3825232] [PID.5948]
[MD5.486BDC196F8914845302745A15310D62] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8321024] [PID.3360]
~ Processes Running: Scanned in 00mn 00s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\portable jean pierre\AppData\Local\Google\Chrome\User Data\Default\Preferences
G1 - GCS: Preference [User Data\Default] http://search.conduit.com
G0 - GCSP: Preference [User Data\Default][HomePage] http://search.conduit.com
G0 - GCSP: Preference [User Data\Default] http://startme.com
G2 - GCE: Preference [User Data\Default] [afbpdhiclgghnffhkinjikglgmolhpee] Torrent Search v.1.2.0.3 (Activé)
G2 - GCE: Preference [User Data\Default] [bmhjjbgkiekoppopopkkjepdepealime] La M\u00C3\u00A9t\u00C3\u00A9o en direct - LiveMeteo v.1.1 (Activé)
G2 - GCE: Preference [User Data\Default] [gegpgpjbmbggplclldecdbpcmopmlbll] Supernova v.1 (Activé)
G2 - GCE: Preference [User Data\Default] [hkiamopcpjmaoflokfdmgljdibglodjc] Clubic v.1.1.0 (Activé)
G2 - GCE: Preference [User Data\Default] [kfkcangbigakljkjeglcofaomihpejif] WhiteSmoke US New v.10.13.20.29 (Désactivé) =>PUP.WhiteSmoke
G2 - GCE: Preference [User Data\Default] [lniahgcddkbgipmbmlhjpoafdeephgcf] Spanning Backup for Google Apps\u00E2\u201E\u00A2 v.3.0.1.3 (Activé)
G2 - GCE: Preference [User Data\Default] [mbmphdinbmonlcogmljkkahppnkannma] Fileminx v.2.0 (Activé)
G2 - GCE: Preference [User Data\Default] [mihcahmgecmbnbcchbopgniflfhgnkff] V\u00C3\u00A9rificateur de messages Google v.4.4.0 (Activé)
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google\u00C2 Wallet v.0.0.6.0 (Activé)
G2 - GCE: Preference [User Data\Default] [npnconcoeefpjfphlaapaocomlkcblhf] Blague et humour en francais - Jookees v.1.2 (Activé)
~ Google Browser: 36 Legitimates Filtered in 00mn 08s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\portable jean pierre\AppData\Roaming\Mozilla\Firefox\Profiles\atg2zecz.default-1385579971338\prefs.js
C:\Users\portable jean pierre\AppData\Roaming\Mozilla\Firefox\Profiles\atg2zecz.default-1385579971338\user.js
C:\Users\portable jean pierre\AppData\Roaming\Mozilla\Firefox\Profiles\y4b7tp3d.default\prefs.js
M0 - MFSP: prefs.js [portable jean pierre - atg2zecz.default-1385579971338] http://www.netvibes.com
M2 - MFEP: prefs.js [portable jean pierre - atg2zecz.default-1385579971338\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}] [] Forecastfox v2.2.2 (..)
~ Firefox Browser: 11 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://majax31isback.blogspot.fr
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = preserve
~ IE Browser: 22 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 24



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: LastPass Vault [64Bits] - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} . (.LastPass - LastPass Toolbar.) -- C:\Program Files (x86)\LastPass\LPToolbar.dll =>Toolbar.LastPass
~ BHO: 8 Legitimates Filtered in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: AOMEI Data Backuper.lnk . (.AOMEI Tech Co., Ltd. - AOMEI Data Backuper.) -- C:\Program Files (x86)\AOMEI Data Backuper\Backuper.exe
O4 - GS\Desktop [Public]: AOMEI Partition Assistant Home.lnk . (.AOMEI Technology Co., Ltd - AOMEI Partition Assistant.) -- C:\Program Files (x86)\AOMEI Partition Assistant Home Edition 5.1\PartAssist.exe
O4 - GS\Desktop [Public]: Ashampoo Core Tuner 2.lnk . (.Ashampoo Development GmbH & Co. KG - Ashampoo Core Tuner 2 Client.) -- C:\Program Files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2.exe
O4 - GS\Desktop [Public]: Ashampoo Photo Commander 9.lnk . (.ashampoo GmbH & Co. KG - Ashampoo Photo Commander 9.) -- C:\Program Files (x86)\Ashampoo\Ashampoo Photo Commander 9\apc.exe
O4 - GS\Desktop [Public]: BatteryCare.lnk . (.Filipe Lourenço - BatteryCare.) -- C:\Program Files (x86)\BatteryCare\BatteryCare.exe
O4 - GS\Desktop [Public]: DivX Converter.lnk . (.DivX, Inc. - DivX Converter.) -- C:\Program Files (x86)\DivX\DivX Converter\DivXConverterLauncher.exe
O4 - GS\Desktop [Public]: DivX Player.lnk . (...) -- C:\Program Files (x86)\DivX\DivX Player\DivX Player.exe
O4 - GS\Desktop [Public]: eManual.Lnk . (.ASUSTek Computer Inc. - EManual Application.) -- C:\eSupport\Manual\eManual.exe
O4 - GS\Desktop [Public]: Hardwipe.lnk . (...) -- C:\Program Files (x86)\Hardwipe\hwipe.exe
O4 - GS\Desktop [Public]: IObit Uninstaller.lnk . (.IObit - IObit Uninstaller.) -- C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
O4 - GS\Desktop [Public]: Lidl-Photos FR.lnk . (...) -- C:\Program Files (x86)\Lidl-Photos\Lidl-Photos FR\Lidl-Photos FR.exe
O4 - GS\Desktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Desktop [Public]: My LastPass Vault.lnk - Clé orpheline
O4 - GS\Desktop [Public]: Ocster Backup Pro.lnk . (...) -- C:\Program Files\Ocster Backup\bin\backupClient-ox.exe
O4 - GS\Desktop [Public]: Panorama Maker 6.lnk . (.ArcSoft Inc. - ArcSoft Panorama Maker.) -- C:\Program Files (x86)\ArcSoft\Panorama Maker 6\PMK.exe
O4 - GS\Desktop [Public]: ProShow Producer.lnk . (.Photodex - ProShow.) -- C:\Program Files (x86)\Photodex\ProShowProducer\proshow.exe
O4 - GS\Desktop [Public]: Quicksys RegDefrag.lnk . (.Quicksys - Quicksys RegDefrag.) -- C:\Program Files (x86)\Quicksys\RegDefrag\QRegDefrag.exe
O4 - GS\Desktop [Public]: Songr.lnk . (.Xamasoft - Songr.) -- C:\Program Files (x86)\Songr\Songr.exe
O4 - GS\Desktop [Public]: Wise Disk Cleaner.lnk . (.WiseCleaner.com - Wise Disk Cleaner.) -- C:\Program Files (x86)\Wise\Wise Disk Cleaner\WiseDiskCleaner.exe
O4 - GS\Program [Public]: Hardwipe.lnk . (...) -- C:\Program Files (x86)\Hardwipe\hwipe.exe
O4 - GS\Program [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Program [Public]: Songr.lnk . (.Xamasoft - Songr.) -- C:\Program Files (x86)\Songr\Songr.exe
O4 - GS\QuickLaunch [UpdatusUser]: uTorrent Turbo Accelerator.lnk . (.WebSpeeders LLC - uTorrent Turbo Accelerator.) -- C:\Program Files (x86)\uTorrent Turbo Accelerator\uTorrent Turbo Accelerator.exe =>P2P.µTorrent
O4 - GS\Desktop [UpdatusUser]: Bit Che.lnk . (.Convivea, Inc. - Bit Che -- a fast bit torrent search tool.) -- C:\Program Files (x86)\Bit Che\Bit_Che.exe
O4 - GS\Desktop [UpdatusUser]: PowerpointImageExtractor V1.2.lnk . (.--- - Pas de description.) -- C:\Program Files (x86)\PowerpointImageExtractor_V1_2\PowerpointImageExtractor.exe
O4 - GS\QuickLaunch [portable jean pierre]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch [portable jean pierre]: My LastPass Vault.lnk - Clé orpheline
O4 - GS\QuickLaunch [portable jean pierre]: ProShow Producer.lnk . (.Photodex - ProShow.) -- C:\Program Files (x86)\Photodex\ProShowProducer\proshow.exe
O4 - GS\TaskBar [portable jean pierre]: Gmail (1).lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://mail.google.com =>Hijacker.Browsers
O4 - GS\TaskBar [portable jean pierre]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\TaskBar [portable jean pierre]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\TaskBar [portable jean pierre]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Program [portable jean pierre]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\SystemTools [portable jean pierre]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Desktop [portable jean pierre]: 01net_N_786_WwW.Vosbooks.NeT_.pdf - Raccourci.lnk . (...) -- F:\Mes documents\Downloads\Compressed\Documents\01net_N_786_WwW.Vosbooks.NeT_.pdf
O4 - GS\Desktop [portable jean pierre]: Auslogics DiskDefrag.lnk . (.Auslogics - Disk Defrag.) -- C:\Program Files (x86)\Auslogics\DiskDefrag\DiskDefrag.exe
O4 - GS\Desktop [portable jean pierre]: Bit Che.lnk . (.Convivea, Inc. - Bit Che -- a fast bit torrent search tool.) -- C:\Program Files (x86)\Bit Che\Bit_Che.exe
O4 - GS\Desktop [portable jean pierre]: Cacheman.lnk . (.Outertech - Cacheman Control Panel.) -- C:\Program Files (x86)\Cacheman\CachemanControl.exe
O4 - GS\Desktop [portable jean pierre]: DivX Converter.lnk . (.DivX, Inc. - DivX Converter.) -- C:\Program Files (x86)\DivX\DivX Converter\DivXConverterLauncher.exe
O4 - GS\Desktop [portable jean pierre]: FILEminimizer.lnk . (.balesio AG - FILEminimizer.) -- C:\Program Files (x86)\FILEminimizer Pictures\FILEminimizer.exe
O4 - GS\Desktop [portable jean pierre]: Gmail.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://mail.google.com =>Hijacker.Browsers
O4 - GS\Desktop [portable jean pierre]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\Desktop [portable jean pierre]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Desktop [portable jean pierre]: Ma musique.lnk . (...) -- F:\Ma musique
O4 - GS\Desktop [portable jean pierre]: Mes documents.lnk . (...) -- F:\Mes documents
O4 - GS\Desktop [portable jean pierre]: Mes photos.lnk . (...) -- F:\Mes photos
O4 - GS\Desktop [portable jean pierre]: Mes videos.lnk . (...) -- F:\Mes videos
O4 - GS\Desktop [portable jean pierre]: Transcend Elite_Users_Manual_WIN__FR.pdf - Raccourci.lnk . (...) -- F:\Mes documents\Downloads\Compressed\Documents\Transcend Elite_Users_Manual_WIN__FR.pdf
O4 - GS\Desktop [portable jean pierre]: windows 8.1.lnk . (...) -- F:\Mes documents\Downloads\Compressed\Documents\WindowsPCTrucs&AstucesN12WwW.VosBooks.NeT.pdf
O4 - GS\Desktop [portable jean pierre]: WinZip 17.5.lnk . (...) -- C:\Program Files (x86)\WinZip\WINZIP64.exe (.not file.)
O4 - GS\Desktop [portable jean pierre]: Your Unin-staller!.lnk . (.URSoft,Inc - Your Uninstaller! - New way to uninstall pr.) -- C:\Program Files (x86)\Your Uninstaller! 7\urmain.exe
O4 - GS\Desktop [portable jean pierre]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Users\portable jean pierre\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent
O4 - GS\QuickLaunch [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\QuickLaunch [Administrateur]: My LastPass Vault.lnk - Clé orpheline
O4 - GS\QuickLaunch [Administrateur]: uTorrent Turbo Accelerator.lnk . (.WebSpeeders LLC - uTorrent Turbo Accelerator.) -- C:\Program Files (x86)\uTorrent Turbo Accelerator\uTorrent Turbo Accelerator.exe =>P2P.µTorrent
O4 - GS\TaskBar [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\TaskBar [Administrateur]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\TaskBar [Administrateur]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Desktop [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
~ Global Startup: 145 Legitimates Filtered in 00mn 00s



---\\ Applications lancées au démarrage du sytème (O4)
O4 - GS\Startup [Public]: Install LastPass FF RunOnce.lnk . (.LastPass - LastPass Installer.) -- C:\Program Files (x86)\Common Files\lpuninstall.exe
O4 - GS\Startup [Public]: Install LastPass IE RunOnce.lnk . (.LastPass - LastPass Installer.) -- C:\Program Files (x86)\Common Files\lpuninstall.exe
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKLM\..\Run: [Ashampoo Core Tuner 2] . (.Ashampoo Development GmbH & Co. KG - Ashampoo Core Tuner 2 Client.) -- C:\Program Files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2.exe
O4 - HKCU\..\Run: [BatteryCare] . (.Filipe Lourenço - BatteryCare.) -- C:\Program Files (x86)\BatteryCare\BatteryCare.exe
O4 - HKCU\..\Run: [uTorrent] . (.BitTorrent Inc. - µTorrent.) -- C:\Users\portable jean pierre\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (.not file.)
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (.not file.)
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-829731559-937865049-3600913985-1001\..\Run: [BatteryCare] . (.Filipe Lourenço - BatteryCare.) -- C:\Program Files (x86)\BatteryCare\BatteryCare.exe
O4 - HKUS\S-1-5-21-829731559-937865049-3600913985-1001\..\Run: [uTorrent] . (.BitTorrent Inc. - µTorrent.) -- C:\Users\portable jean pierre\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent
~ Application: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{7851868A-7C6D-4605-8488-B3807518F20B}: NameServer = 86.64.145.140,86.64.145.143
O17 - HKLM\System\CCS\Services\Tcpip\..\{44E3FF94-05A8-457F-9BB6-05DB23A19465}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{7851868A-7C6D-4605-8488-B3807518F20B}: NameServer = 86.64.145.140,86.64.145.143
O17 - HKLM\System\CS1\Services\Tcpip\..\{44E3FF94-05A8-457F-9BB6-05DB23A19465}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{7851868A-7C6D-4605-8488-B3807518F20B}: NameServer = 86.64.145.140,86.64.145.143
O17 - HKLM\System\CS2\Services\Tcpip\..\{44E3FF94-05A8-457F-9BB6-05DB23A19465}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - AppInit_DLLs: . (.NVIDIA Corporation - NVIDIA shim initialization dll, Version 327.) - C:\Windows\system32\nvinitx.dll
~ AppInit DLL: Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Ashampoo Core Tuner 2 Service (ACT2_Service) . (...) - C:\Program Files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2Service.exe
O23 - Service: Ocster Backup (ocster_backup) . (...) - c:\Program Files\Ocster Backup\bin\backupService-ox.exe
O23 - Service: ScsiAccess (ScsiAccess) . (...) - C:\Program Files (x86)\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) . (.TuneUp Software - TuneUp Utilities Service.) - C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
~ Services: 15 Legitimates Filtered in 00mn 06s



---\\ Tâches planifiées en automatique (O39)
[MD5.C34968C46A99BBD6248D30F9F1B778C2] [APT] [BoxSoftwareUpdate] (...) -- C:\ProgramData\BoxUpdChk\updchk.exe [177152] =>Adware.Boxore
[MD5.00000000000000000000000000000000] [APT] [Freemium1ClickMaint] (...) -- C:\Program Files (x86)\Covus Freemium\Free System Utilities\1Click.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [Go for FilesUpdate] (...) -- C:\Program Files (x86)\GoforFiles\GFFUpdater.exe (.not file.) [0] =>P2P.GoforFiles
[MD5.00000000000000000000000000000000] [APT] [{0771B462-22DE-4AF3-BA8D-B92D154A6E88}] (...) -- C:\Users\portable jean pierre\Downloads\Programs\air-media-server-air-media-center_air_media_server_1.0.14_anglais_408436.msi" (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{52EB2ACE-03FE-42C0-8CAD-F0C98D2C87E2}] (...) -- C:\Users\portable jean pierre\Downloads\Programs\pxsetup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{E411C278-4C55-49B9-B4EF-F84A8F6B673C}] (...) -- C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{F08B36B2-6A0E-496C-B1ED-5704A3D9B1E6}] (...) -- C:\Users\portable jean pierre\Downloads\Nero Media Home 4 Essentials [2011] + InBuilt Serial Key - {RedDragon}\Nero MediaHome 4 Essentials\ipclog.exe (.not file.) [0]
~ Scheduled Task: 27 Legitimates Filtered in 00mn 03s



---\\ Logiciels installés (O42)
O42 - Logiciel: Hardwipe 3.1.1 - (.Big Angry Dog.) [HKLM][64Bits] -- {BB5BF528-F731-445D-A31A-57F0EB24D7A7}
O42 - Logiciel: MP3 AddIn - (.TopByteLabs Ltd..) [HKLM][64Bits] -- {D19E4F5B-C6E8-4DC2-BAEA-99E4E661675E}
O42 - Logiciel: Ocster Backup Pro - (.Ocster GmbH & Co. KG.) [HKLM][64Bits] -- Ocster Backup
O42 - Logiciel: Presente3D - (.Presente3D LLC.) [HKLM][64Bits] -- {4DF08D9B-219A-4599-8496-78FA540D4A42}
~ Logic: 2 Legitimates Filtered in 00mn 01s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\2345Explorer]
[HKCU\Software\4kdownload.com]
[HKCU\Software\Audio Units]
[HKCU\Software\Big Angry Dog]
[HKCU\Software\Drivers]
[HKCU\Software\Markement]
[HKCU\Software\Ocster]
[HKCU\Software\Pando Networks]
[HKCU\Software\System32]
[HKCU\Software\TheGreenBow]
[HKCU\Software\ToolbarCleaner]
[HKCU\Software\TopByteLabs]
[HKCU\Software\Win]
[HKCU\Software\[eMo] Web Browse Optimizer]
[HKLM\Software\Ocster]
[HKLM\Software\Presente3D LLC]
[HKLM\Software\Wow6432Node\2345Explorer]
[HKLM\Software\Wow6432Node\BarCodeWiz]
[HKLM\Software\Wow6432Node\Droppix]
[HKLM\Software\Wow6432Node\Pando Networks]
[HKLM\Software\Wow6432Node\Presente3D LLC]
[HKLM\Software\Wow6432Node\SB]
~ Key Software: 437 Legitimates Filtered in 00mn 01s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 20/12/2013 - 22:30:02 - [15,082] ----D C:\Program Files (x86)\Hardwipe
O43 - CFD: 14/12/2013 - 18:39:49 - [34,999] ----D C:\Program Files (x86)\Presente3D
O43 - CFD: 14/12/2013 - 18:40:22 - [1,273] ----D C:\Program Files (x86)\TopByteLabs
O43 - CFD: 14/12/2013 - 18:35:14 - [8,171] ----D C:\Program Files (x86)\Common Files\Droppix
O43 - CFD: 14/12/2013 - 18:41:00 - [0,004] ----D C:\ProgramData\Advanced Uninstaller PRO
O43 - CFD: 15/12/2013 - 21:54:24 - [0] ----D C:\ProgramData\boost_interprocess
O43 - CFD: 30/12/2013 - 18:23:00 - [0,169] ----D C:\ProgramData\BoxUpdChk =>Adware.Boxore
O43 - CFD: 14/12/2013 - 18:41:04 - [1,200] ----D C:\ProgramData\InstallMate =>PUP.Tarma
O43 - CFD: 14/12/2013 - 18:42:00 - [0,016] ----D C:\ProgramData\Ocster Backup
O43 - CFD: 06/12/2013 - 18:12:50 - [0] ----D C:\ProgramData\oxInstall
O43 - CFD: 30/12/2013 - 17:05:36 - [0] ----D C:\ProgramData\ProductData
O43 - CFD: 14/12/2013 - 18:42:10 - [0] ----D C:\ProgramData\sysnfxo
O43 - CFD: 12/11/2013 - 17:05:55 - [0] -SH-D C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
O43 - CFD: 14/12/2013 - 19:14:55 - [1,288] ----D C:\Users\portable jean pierre\AppData\Roaming\2345Explorer
O43 - CFD: 20/12/2013 - 22:30:06 - [0,001] ----D C:\Users\portable jean pierre\AppData\Roaming\Big Angry Dog
O43 - CFD: 04/08/2013 - 22:22:11 - [0] ----D C:\Users\portable jean pierre\AppData\Roaming\Boost Windows
O43 - CFD: 14/12/2013 - 19:14:58 - [0,001] ----D C:\Users\portable jean pierre\AppData\Roaming\Booster
O43 - CFD: 14/12/2013 - 19:14:58 - [1,423] ----D C:\Users\portable jean pierre\AppData\Roaming\com.flash.WidgetBrowser
O43 - CFD: 14/12/2013 - 19:15:31 - [0] ----D C:\Users\portable jean pierre\AppData\Roaming\Presente3D LLC
O43 - CFD: 14/12/2013 - 19:15:31 - [0] ----D C:\Users\portable jean pierre\AppData\Roaming\SystemSpeedBooster
O43 - CFD: 17/12/2013 - 20:55:45 - [0] ----D C:\Users\portable jean pierre\AppData\Local\4kdownload.com
O43 - CFD: 20/12/2013 - 22:34:40 - [0] ----D C:\Users\portable jean pierre\AppData\Local\BigAngryDog_HWipe
O43 - CFD: 02/01/2014 - 09:21:10 - [0,099] ----D C:\Users\portable jean pierre\AppData\Local\Ocster Backup
O43 - CFD: 14/12/2013 - 18:55:53 - [5,370] ----D C:\Users\portable jean pierre\AppData\Local\Pando_Temp
O43 - CFD: 14/12/2013 - 19:14:32 - [0,001] ----D C:\Users\portable jean pierre\AppData\Local\Techlogix
O43 - CFD: 14/12/2013 - 18:54:36 - [0] ----D C:\Users\portable jean pierre\AppData\Local\_NkvMail@
O43 - CFD: 16/12/2013 - 11:50:02 - [0] ----D C:\Users\portable jean pierre\AppData\Local\_temp
O43 - CFD: 29/12/2013 - 10:28:53 - [0,003] ----D C:\Users\portable jean pierre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup
~ Program Folder: 298 Legitimates Filtered in 00mn 32s



---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"VIDC.FICV"="ficvdec_x64.dll" . (...) -- C:\Windows\System32\ficvdec_x64.dll
~ TDSD: 3 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre StartupReg (SMSR) (O53)
O53 - SMSR:HKLM\...\startupreg\Ocster Backup [Key] . (...) -- C:\Program Files\Ocster Backup\bin\backupClient-ox.exe
O53 - SMSR:HKLM\...\startupreg\Plex Media Server [Key] . (...) -- C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\uTorrent [Key] . (.BitTorrent Inc. - µTorrent.) -- C:\Users\portable jean pierre\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent
~ SMSR Keys: 20 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLinkedConnections"=1
O55 - MWPS:[HKLM\...\Policies\System] - "RunStartupScriptSync"=0
O55 - MWPS:[HKLM\...\Policies\System] - "SynchronousMachineGroupPolicy"=0
O55 - MWPS:[HKLM\...\Policies\System] - "SynchronousUserGroupPolicy"=0
O55 - MWPS:[HKLM\...\Policies\System] - "VerboseStatus"=0
~ MWPS: 21 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDesktopCleanupWizard"=1
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoLowDiskSpaceChecks"=1
~ MWPE Keys: 11 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
O58 - SDL:[MD5.3C38648375B7F3988691F53A7AAE10A9] - 15/10/2009 - 10:23:20 ---A- . (.ELAN Microelectronic Corp. - ETD Control Center.) -- C:\Windows\System32\Drivers\ETD.sys [117760]
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
O58 - SDL:[MD5.37B08E0921417BEB7A39FA80E47D43FC] - 15/11/2012 - 02:33:20 ---A- . (.AnchorFree Inc. - Hotspot Shield Routing Driver.) -- C:\Windows\System32\Drivers\hssdrv6.sys [42248]
O58 - SDL:[MD5.03F5F3EE4E8DB1CE944A6FA6DBE148CB] - 08/11/2013 - 00:41:38 ---A- . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\Drivers\idmwfp.sys [174968]
O58 - SDL:[MD5.E63EF8C3271D014F14E2469CE75FECB4] - 20/07/2009 - 10:29:40 ---A- . (.Pas de propriétaire - Keyboard Filter Driver.) -- C:\Windows\System32\Drivers\kbfiltr.sys [15416]
O58 - SDL:[MD5.1CDADE078F46F10919F21E08E22D227D] - 29/12/2008 - 10:14:28 ---A- . (.Pas de propriétaire - USBCAMD for Sonix UVC.) -- C:\Windows\System32\Drivers\sncduvc.sys [35456]
O58 - SDL:[MD5.2114518E55B380A3ACC28B2C27FD499A] - 20/08/2009 - 03:41:38 ---A- . (.Pas de propriétaire - UVC Camera Streaming Driver.) -- C:\Windows\System32\Drivers\snp2uvc.sys [1800192]
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
O58 - SDL:[MD5.A8D3F11BC8F37C3D7D026C3E1219B5AC] - 28/10/2012 - 16:09:54 ---A- . (.The OpenVPN Project - TAP-Win32 Virtual Network Driver.) -- C:\Windows\System32\Drivers\tap0901.sys [38624]
O58 - SDL:[MD5.8B9FD32C71F29DF235A27CE9FF4F19DC] - 15/11/2012 - 02:38:20 ---A- . (.Anchorfree Inc. - Anchorfree HSS VPN Adapter.) -- C:\Windows\System32\Drivers\taphss6.sys [40712]
O58 - SDL:[MD5.185C2170CFD84F9D708276FBB5ABD77D] - 15/05/2013 - 15:12:06 ---A- . (.Spotflux, Inc. - Spotflux Network Device Driver.) -- C:\Windows\System32\Drivers\tapSF0901.sys [39104]
O58 - SDL:[MD5.65ACC76048B484DE7E4F1132D4977F44] - 13/02/2012 - 18:06:26 ---A- . (.TheGreenBow - TheGreenBow VPN Miniport Enumerator.) -- C:\Windows\System32\Drivers\TGBMPEnum.sys [40624]
O58 - SDL:[MD5.C45A3E051C65106A28982CAED125F855] - 06/08/2009 - 14:17:34 ---A- . (...) -- C:\Windows\System32\Drivers\TurboB.sys [13784]
O58 - SDL:[MD5.ABDFE286F5BA0BB591D715B40181A9AE] - 14/12/2012 - 17:10:48 ---A- . (...) -- C:\Windows\System32\ambakdrv.sys [31160]
O58 - SDL:[MD5.FE24ED97422FEEEAF9FF98CBF003E67C] - 14/12/2012 - 17:10:48 ---A- . (...) -- C:\Windows\System32\ammntdrv.sys [151480]
O58 - SDL:[MD5.E3C6DAE5493E9B07EE98711D04D863FF] - 26/12/2011 - 15:27:24 ---A- . (...) -- C:\Windows\System32\ampa.sys [15288]
O58 - SDL:[MD5.861E991C28594C2464196F35C07CC130] - 14/12/2012 - 17:10:48 ---A- . (...) -- C:\Windows\System32\amwrtdrv.sys [17848]
O58 - SDL:[MD5.47E6301D245AB061B9853B90A46AE55A] - 26/12/2011 - 15:27:22 ---A- . (...) -- C:\Windows\SysWOW64\ampa.sys [12728]
~ Drivers: 21 Legitimates Filtered in 00mn 00s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - 10/06/2011 - C:\Program Files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2ProcessMonitor64.sys (ACT2PM) .(...) - LEGACY_ACT2PM
O64 - Services: CurCS - 14/12/2012 - C:\Windows\system32\ammntdrv.sys (ammntdrv) .(...) - LEGACY_AMMNTDRV
O64 - Services: CurCS - 14/12/2012 - C:\Windows\system32\amwrtdrv.sys (amwrtdrv) .(...) - LEGACY_AMWRTDRV
O64 - Services: CurCS - 03/08/2007 - C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys (ghaio) .(...) - LEGACY_GHAIO
~ Legacy: 94 Legitimates Filtered in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <2345Explorer.exe> <2345智能浏览器>[HKLM\..\Shell\open\Command] (.Not Key.)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {11BB41CF-E225-9CE6-650C-6261EFE42D8F} [DefaultScope] - (Google) - http://www.google.com
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.C46D0746D2852CFFCE45A7EA94F080E9] [SPRF][22/11/2013] (...) -- C:\Users\portable jean pierre\AppData\LocalLow\lpm.dat [10498]
~ Files: 1 Legitimates Filtered in 00mn 00s



---\\ Enumère les codes produits des logiciels (PUC) (O90)
O90 - PUC: "4F17D8711BFDCE04D95923F68D3A7E0A" . (.Motion Graphics Toolkit for Studio.) -- C:\Windows\Installer\{178D71F4-DFB1-40EC-9D95-326FD8A3E7A0}\ARPPRODUCTICON.exe
O90 - PUC: "5C271FC4121FAF140B0BD09448B00F30" . (..) -- C:\Windows\Installer\{4CF172C5-F121-41FA-B0B0-0D49840BF003}\ARPPRODUCTICON.exe
O90 - PUC: "825FB5BB137FD5443AA1750FBE427D7A" . (.Hardwipe 3.1.1.) -- C:\Windows\Installer\{BB5BF528-F731-445D-A31A-57F0EB24D7A7}\main_icon.ico
O90 - PUC: "B9D80FD4A9129954486987AF45D0A424" . (.Presente3D.) -- C:\Windows\Installer\{4DF08D9B-219A-4599-8496-78FA540D4A42}\small.exe
~ Update Products: 74 Legitimates Filtered in 00mn 00s



---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.CFC98E2D585C85C878A2136C2904FB72] [WIS][20/12/2013] (.Big Angry Dog - File & Drive Wiper.) -- C:\Windows\Installer\249f5d.msi [6397952]
[MD5.0EF7D650F8459BC3ADAAC267187CDD8A] [WIS][10/12/2012] (.Spotflux - Spotflux.) -- C:\Windows\Installer\2b49b0.msi [2898432]
[MD5.5A381D88FEF1C4D00F056C514A74ED0E] [WIS][23/12/2013] (.Google - Google+ Auto Backup.) -- C:\Windows\Installer\63614.msi [3088384]
[MD5.EE86935B6CB6357818992B5E22C0F938] [WIS][20/11/2012] (.Presente3D LLC - Presente3D.) -- C:\Windows\Installer\7ad486.msi [11776]
~ WIS: 75 Legitimates Filtered in 00mn 27s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Disabled 11/05/2013 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SS - | Disabled 20/12/2013 257416 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 31/03/2008 225280 | (ADSMService) . (.ASUSTek Computer Inc..) - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
SS - | Disabled 03/03/2011 379520 | (AFBAgent) . (.ASUSTeK Computer Inc..) - C:\Windows\system32\FBAgent.exe
SS - | Demand 28/08/2009 221184 | (Droppix Service) . (.Droppix.) - C:\Program Files (x86)\Common Files\Droppix\DxService.exe
SS - | Auto 23/10/2012 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 23/10/2012 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 09/05/2011 136120 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
SS - | Disabled 09/06/2013 2635600 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe
SS - | Auto 04/04/2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
SS - | Demand 15/12/2013 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 03/08/2007 125496 | (spmgr) . (...) - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
SS - | Demand 06/08/2009 118672 | (TurboBoost) . (.Intel(R) Corporation.) - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
SS - | Auto 14/07/2009 27136 | C:\Windows\System32\uxtuneup.dll (UxTuneUp) . (.TuneUp Software.) - C:\Windows\System32\svchost.exe
SS - | Demand 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

SR - | Auto 22/08/2011 1421216 | (ACT2_Service) . (...) - C:\Program Files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2Service.exe
SR - | Auto 15/06/2009 84536 | (ASLDRService) . (.ASUS.) - C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
SR - | Auto 08/08/2007 94208 | (ATKGFNEXSrv) . (...) - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
SR - | Auto 16/05/2009 210944 | (CachemanService) . (.Outertech.) - C:\Program Files (x86)\Cacheman\CachemanServ.exe
SR - | Auto 30/04/2013 15344 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
SR - | Auto 26/11/2013 2151744 | (LiveUpdateSvc) . (.IObit.) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
SR - | Auto 04/04/2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
SR - | Auto 23/10/2013 23808 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 29/08/2013 920864 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe
SR - | Auto 05/09/2013 1364256 | (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
SR - | Auto 28/11/2013 23896 | (ocster_backup) . (...) - c:\Program Files\Ocster Backup\bin\backupService-ox.exe
SR - | Auto 16/10/2013 289496 | (RtkAudioService) . (.Realtek Semiconductor.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
SR - | Auto 24/10/2012 186760 | (ScsiAccess) . (...) - C:\Program Files (x86)\Photodex\ProShowProducer\ScsiAccess.exe
SR - | Auto 30/10/2013 2099512 | (TuneUp.UtilitiesSvc) . (.TuneUp Software.) - C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

~ Services: Scanned in 00mn 29s



---\\ Scan Additionnel (O88)
Database Version : 13018 - (02/01/2014)
Clés trouvées (Keys found) : 9
Valeurs trouvées (Values found) : 6
Dossiers trouvés (Folders found) : 5
Fichiers trouvés (Files found) : 2

[HKLM\Software\Google\Chrome\Extensions\kfkcangbigakljkjeglcofaomihpejif] =>PUP.WhiteSmoke^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95D9ECF5-2A4D-4550-BE49-70D42F71296E}] =>Toolbar.LastPass^
[HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\uTorrent] =>P2P.BitTorrent^
[HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\HssSrv] =>Toolbar.Agent
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] =>PUP.Tarma
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] =>PUP.Tarma
[HKCU\Software\usyndication.com] =>Trojan.USyndication
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110111991162}] =>PUP.CrossRider
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =>Adware.Boxore^
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:uTorrent =>P2P.BitTorrent^
C:\Users\portable jean pierre\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif =>PUP.WhiteSmoke^
C:\ProgramData\BoxUpdChk =>Adware.Boxore^
C:\ProgramData\InstallMate =>PUP.Tarma^
C:\Program Files (x86)\Software =>Adware.Boxore
C:\Users\portable jean pierre\AppData\Local\Software =>Adware.Boxore
C:\Users\portable jean pierre\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent^
C:\ProgramData\BoxUpdChk\updchk.exe =>Adware.Boxore^
~ Additionnel Scan: 294893 Items scanned in 00mn 29s



---\\ Récapitulatif des détections trouvées sur votre station
~ http://nicolascoolman.webs.com/apps/blog/show/27636417-pup-whitesmoke =>PUP.WhiteSmoke
~ http://nicolascoolman.webs.com/apps/blog/show/33962622-toolbar-lastpass =>Toolbar.LastPass
~ http://nicolascoolman.webs.com/apps/blog/show/33263878-hijacker-browser =>Hijacker.Browsers
~ http://nicolascoolman.webs.com/apps/blog/show/26626977-adware-boxore =>Adware.Boxore
~ http://nicolascoolman.webs.com/apps/blog/show/29637859-toolbar-tarma =>PUP.Tarma
~ http://nicolascoolman.webs.com/apps/blog/show/27328365-trojan-usyndication =>Trojan.USyndication
~ http://nicolascoolman.webs.com/apps/blog/show/27583526-pup-crossrider =>PUP.CrossRider
~ MSI: 7 link(s) detected in 00mn 29s



~ 1388 Legitimates filtered by white list
End of the scan (591 lines in 02mn 18s)(0)

Publicité


Signaler le contenu de ce document

Publicité