cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2014.4.19.35 - Nicolas Coolman (19/04/2014)
~ Lancé par Yannn (20/04/2014 23:45:48)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by program


---\\ Navigateurs Internet
MSIE: Internet Explorer v10.0.9200.16863
GCIE: Google Chrome v34.0.1847.116 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows 8, 64-bit (Build 9200)
Windows Server License Manager Script : OK
~ Windows(R) Operating System, OEM_DM channel
Windows ID Activation : OK
~ Windows Partial Key : G6JYG
Windows License : OK
~ Windows Remaining Initializations Number : 999
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 2.0.1.1004
Norton Internet Security v20.0.0.136
Windows Defender W8

---\\ Logiciels d'optimisation du système
CCleaner v4.11 =>.Piriform Ltd

---\\ Logiciels de partage PeerToPeer
Pando Media Booster v2.6.0.7

---\\ Surveillance de Logiciels

---\\ Informations sur le système
~ Processor: Intel64 Family 6 Model 60 Stepping 3, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 4016 MB (12% free)
System Restore: Activé (Enable)
System drive C: has 304 GB (53%) free of 572 GB

---\\ Mode de connexion au système
~ Computer Name: YANN_HOUSTY_PC
~ User Name: Yannn
~ All Users Names: Yannn, UpdatusUser, HomeGroupUser$, Administrateur,
~ Unselected Option: None
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Yannn\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Yannn\AppData\Roaming\
~ %Desktop% : C:\Users\Yannn\Desktop\
~ %Favorites% : C:\Users\Yannn\Favorites\
~ %LocalAppData% : C:\Users\Yannn\AppData\Local\
~ %StartMenu% : C:\Users\Yannn\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 304 Go of 572 Go)
D: Hard drive, Flash drive, Thumb drive (Free 340 Go of 340 Go)
E: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
~ Security Center: 41 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.0E8E6463F81C80AFBED533E0F1F8895D] - (.Microsoft Corporation - Explorateur Windows.) (.01/06/2013 - 12:34:21.) -- C:\Windows\Explorer.exe [2391280]
[MD5.FE9AB232B56A12224E8A3F3F9878C9A3] - (.Microsoft Corporation - Application de démarrage de Windows.) (.26/07/2012 - 04:08:50.) -- C:\Windows\System32\Wininit.exe [132608]
[MD5.2B7920C7885AC45FD0E27DD860F095A1] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.07/03/2014 - 01:08:30.) -- C:\Windows\System32\wininet.dll [2240000]
[MD5.BCF2036A0DD579E47C008C133550283E] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.10/07/2013 - 14:32:47.) -- C:\Windows\System32\Winlogon.exe [517120]
[MD5.9448F5740A037EC0C18F0E9177232DD0] - (.Microsoft Corporation - Bibliothèque de licences.) (.26/07/2012 - 04:07:20.) -- C:\Windows\System32\sppcomapi.dll [273408]
[MD5.7C0E0EDF18D6CC565D7BFBB451709FA5] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.04/09/2013 - 04:11:23.) -- C:\Windows\system32\Drivers\AFD.sys [576512]
[MD5.A721FF570C2387E383BDDEA9632863C9] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.26/07/2012 - 06:00:48.) -- C:\Windows\system32\Drivers\atapi.sys [25840]
[MD5.990B1BABE6E81FB18E65A87EBEFB1772] - (.Microsoft Corporation - CD-ROM File System Driver.) (.26/07/2012 - 03:30:10.) -- C:\Windows\system32\Drivers\Cdfs.sys [108544]
[MD5.339BFF85D788268752DA8C9644B188EE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.26/07/2012 - 03:26:36.) -- C:\Windows\system32\Drivers\Cdrom.sys [174080]
[MD5.431141C6859990824D17F71C30A78728] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.16/01/2014 - 00:42:58.) -- C:\Windows\system32\Drivers\DfsC.sys [118784]
[MD5.7D87B5B6C7188D553E11B59DC7F0B111] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.10/07/2013 - 14:08:33.) -- C:\Windows\system32\Drivers\HDAudBus.sys [71168]
[MD5.C9E9CBF73AFFBFE3E801EFB516787BA3] - (.Microsoft Corporation - Pilote de port i8042.) (.26/07/2012 - 03:28:51.) -- C:\Windows\system32\Drivers\i8042prt.sys [112640]
[MD5.3969B9C218DD3FAA9F4ED2FFC3651C02] - (.Microsoft Corporation - IP Network Address Translator.) (.26/07/2012 - 03:23:01.) -- C:\Windows\system32\Drivers\IpNat.sys [145920]
[MD5.93179D48066918323628CB016D8C94DC] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.05/02/2013 - 23:29:09.) -- C:\Windows\system32\Drivers\MRxSmb.sys [370688]
[MD5.7CEC25C682D319D484630B3952C31A11] - (.Microsoft Corporation - MBT Transport driver.) (.26/07/2012 - 03:24:28.) -- C:\Windows\system32\Drivers\netBT.sys [331776]
[MD5.7BE3EDFFA3216F989A6BDCB14795DD08] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.27/01/2014 - 04:39:40.) -- C:\Windows\system32\Drivers\ntfs.sys [1939288]
[MD5.4563DAF8C6A740AD7F501E219BD10766] - (.Microsoft Corporation - Pilote de port parallèle.) (.26/07/2012 - 03:29:53.) -- C:\Windows\system32\Drivers\Parport.sys [105984]
[MD5.A14D625C5AEE5FFE0F47D1A1D419FAAE] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.26/07/2012 - 03:23:17.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [124928]
[MD5.B2A3AD74FF2E2FFA73AF2567108231B3] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.26/07/2012 - 03:25:18.) -- C:\Windows\system32\Drivers\rdpdr.sys [179712]
[MD5.73DC722CE5DF26D7638CE2446F2655C7] - (.Microsoft Corporation - TDI Translation Driver.) (.26/07/2012 - 06:26:47.) -- C:\Windows\system32\Drivers\tdx.sys [117248]
[MD5.78A5BBA3819FFFC62FFEC3E2220D102D] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.01/06/2013 - 12:26:33.) -- C:\Windows\system32\Drivers\volsnap.sys [327936]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 2/74
~ Mes Videos (My Videos) : 2/129
~ Mes Favoris (My Favorites) : 1/5
~ Mes Documents (My Documents) : 1/1790
~ Mon Bureau (My Desktop) : 1/863
~ Menu demarrer (Programs) : 1/33
~ Hidden Files: Scanned in 00mn 05s



---\\ Processus lancés
[MD5.41AD6110110A2E89957F831DCBFAF892] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe [6963512] [PID.44180]
[MD5.2F86BE1818C2D7AC90478E3323EE7FCB] - (.Symantec Corporation - Symantec Service Framework.) -- C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\ccSvcHst.exe [126392] [PID.2252]
[MD5.3A3DA76220AF37207B80F7D7405A1D70] - (.Electronic Arts - Origin.) -- C:\Program Files (x86)\Origin\Origin.exe [3588952] [PID.46904]
[MD5.9D4A0ECBF734E2EECDD5B473A2D705FE] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016] [PID.46404]
[MD5.CF61EC0DDF6431D727FE13C4AD95C5FD] - (.Creative Technology Ltd - Sound Blaster Cinema.) -- C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680] [PID.46480]
[MD5.6536ED4BEF24A01D772B36FFB8A289CF] - (.MSI - Super-Charger.) -- C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [490480] [PID.47056]
[MD5.B7995C675014EEBE77A0BEB7AFCCFC08] - (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432] [PID.46460]
[MD5.67034C4E8331385BEEE31A64098C545A] - (.BlueStack Systems, Inc. - BlueStacks Agent.) -- C:\Program Files (x86)\BlueStacks\HD-Agent.exe [815888] [PID.47084]
[MD5.2EBBBFC120593C683796092F2DDA0EFC] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [841032] [PID.43816]
[MD5.E0E7BD7828EA7B8721BE29375C0D04DF] - (.Intel Corporation - IAStorIcon.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704] [PID.44100]
[MD5.DE7F11C59789AD6616F2381BBC48A97F] - (.Valve Corporation - Steam Client Bootstrapper.) -- C:\Program Files (x86)\Steam\Steam.exe [1821888] [PID.46696]
[MD5.A1C1669580EF1D8F54D7EAFF527AB6A9] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8219648] [PID.44936]
~ Processes Running: Scanned in 00mn 00s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Yannn\AppData\Local\Google\Chrome\User Data\Default\Preferences
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Drive v.6.3 (Activé)
G2 - GCE: Preference [User Data\Default] [lndipknmjijnalnkamonmljeaojdbpna] video-high v.1.26.22, (Activé) =>PUP.CrossRider
G2 - GCE: Preference [User Data\Default] [neajdppkdcdipfabeoofebfddakdcjhd] Google Network Speech v.1.0 (Activé)
G2 - GCE: Preference [User Data\Default] [nkeimhogjdpnpccoofpliimaahmaaome] Hangout Services v.1.0 (Activé)
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.6.1 (Activé)

---\\ Liste des dossiers d'extension Google Chrome

~ Google Lines Browser: 17 Legitimates Filtered in 00mn 04s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com =>PUP.Awesomehp
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com =>PUP.Awesomehp
~ IE Browser: 16 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21



---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: Apps.lnk . (...) -- C:\Users\Public\Libraries\Apps.library-ms
O4 - GS\Desktop [Public]: BurnRecovery Help.lnk . (...) -- C:\Program Files\BurnRecovery\BurnRecovery Help.exe
O4 - GS\Desktop [Public]: BurnRecovery.lnk . (...) -- C:\Program Files\BurnRecovery\BurnRecovery.exe
O4 - GS\Desktop [Public]: Dead Space.lnk . (...) -- C:\Program Files (x86)\Origin Games\Dead Space\Dead Space.exe
O4 - GS\Desktop [Public]: Dll-Files Fixer.lnk . (.Dll-FIles.Com - DLL-Files Fixer.) -- C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
O4 - GS\Desktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\Desktop [Public]: LOL Recorder.lnk . (.LOL Replay - LOL Replay Recorder.) -- C:\Program Files (x86)\LOLReplay\LOLRecorder.exe
O4 - GS\Desktop [Public]: MAGIX MX Suite.lnk . (.MAGIX AG - MAGIX Media Suite.) -- C:\Program Files (x86)\MAGIX\MX Suite\MediaSuite.exe
O4 - GS\Desktop [Public]: Norton PC Checkup.LNK . (.Symantec Corporation - Norton PC Checkup Application Launcher.) -- C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\Norton PC Checkup.exe
O4 - GS\Desktop [Public]: OnlineRegister.exe.lnk . (...) -- c:\Windows\Installer\{7359585E-A828-4EFC-8177-7D1883DDA0B5}\_EA57226A0469CF586CE9C9.exe
O4 - GS\Desktop [Public]: SCM.lnk . (.MSI - SCM.) -- C:\Program Files (x86)\SCM\SCM.exe
O4 - GS\Desktop [Public]: Start BlueStacks.lnk . (.BlueStack Systems, Inc. - BlueStacks StartLauncher.) -- C:\Program Files (x86)\BlueStacks\HD-StartLauncher.exe
O4 - GS\Desktop [Public]: Super-Charger.lnk . (.MSI - Super-Charger.) -- C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
O4 - GS\Desktop [Public]: Vegas Pro 12.0 (64-bit).lnk . (...) -- C:\Program Files (x86)\Sony\Vegas Pro 12.0\vegas120.exe (.not file.)
O4 - GS\Program [Public]: Desktop.lnk - Clé orpheline
O4 - GS\Program [Public]: LOL Recorder.lnk . (.LOL Replay - LOL Replay Recorder.) -- C:\Program Files (x86)\LOLReplay\LOLRecorder.exe
O4 - GS\Program [Public]: SCM.lnk . (.MSI - SCM.) -- C:\Program Files (x86)\SCM\SCM.exe
O4 - GS\QuickLaunch [Yannn]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\QuickLaunch [Yannn]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\TaskBar [Yannn]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\Program [Yannn]: Corbeille.lnk - Clé orpheline
O4 - GS\Program [Yannn]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\Desktop [Yannn]: Fraps.lnk . (.Beepa P/L - Fraps.) -- C:\Fraps\fraps.exe
~ Global Startup: 65 Legitimates Filtered in 00mn 01s



---\\ Applications lancées au démarrage du système (O4)
O4 - GS\Startup [Public]: LOLRecorder.lnk . (.LOL Replay - LOL Replay Recorder.) -- C:\Program Files (x86)\LOLReplay\LOLRecorder.exe
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp
O4 - HKLM\..\Run: [BtServer] . (.Realtek Semiconductor Corporation - Realtek Bluetooth BTServer Application.) -- C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe
O4 - HKLM\..\Run: [IAStorIcon] . (.Intel Corporation - Delayed launcher.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
O4 - HKLM\..\Run: [ETDCtrl] C:\Program Files (x86)\Elantech\ETDCtrl.exe (.not file.)
O4 - HKLM\..\Run: [MBCfg64] . (.Creative Technology Ltd. - Pas de description.) -- C:\Windows\system32\MBCfg64.dll
O4 - HKLM\..\Run: [Radio Manager] . (.MSI - Radio Manager.) -- C:\Program Files (x86)\SCM\Radio Manager.exe
O4 - HKLM\..\Run: [SCM] . (.MSI - SCM.) -- C:\Program Files (x86)\SCM\SCM.exe
O4 - HKCU\..\Run: [EADM] . (.Electronic Arts - Origin.) -- C:\Program Files (x86)\Origin\Origin.exe
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKLM\..\Wow6432Node\Run: [Sound Blaster Cinema] . (.Creative Technology Ltd - Sound Blaster Cinema.) -- C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
O4 - HKLM\..\Wow6432Node\Run: [UpdReg] . (.Creative Technology Ltd. - Creative UpdReg.) -- C:\Windows\UpdReg.exe
O4 - HKLM\..\Wow6432Node\Run: [Super-Charger] . (.MSI - Super-Charger.) -- C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
O4 - HKLM\..\Wow6432Node\Run: [RemoteControl10] . (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
O4 - HKLM\..\Wow6432Node\Run: [BlueStacks Agent] . (.BlueStack Systems, Inc. - BlueStacks Agent.) -- C:\Program Files (x86)\BlueStacks\HD-Agent.exe
~ Application: Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Se&nd to OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll =>.Microsoft Corporation
O9 - Extra button: Lync Click to Call [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\lync.exe (.not file.)
O9 - Extra button: OneNote Lin&ked Notes [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll =>.Microsoft Corporation
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] *.clonewarsadventures.com
O15 - Trusted Zone: [HKCU\...\Domains] *.freerealms.com
O15 - Trusted Zone: [HKCU\...\Domains] *.soe.com
O15 - Trusted Zone: [HKCU\...\Domains] *.sony.com
~ IE Zone Confiance: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{13C43E79-C124-4F8D-A80C-5709BFD24871}: DhcpNameServer = 192.168.100.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC0C589F-7662-486A-A03D-7B61CDC87FF6}: DhcpNameServer = 192.168.0.254
O17 - HKLM\System\CCS\Services\Tcpip\..\{13C43E79-C124-4F8D-A80C-5709BFD24871}: DhcpDomain = ADKSERVER
O17 - HKLM\System\CCS\Services\Tcpip\..\{3920E3E4-C7FD-43A5-950A-A79B5B6EBE06}: DhcpDomain = hc2.hc2
O17 - HKLM\System\CS1\Services\Tcpip\..\{13C43E79-C124-4F8D-A80C-5709BFD24871}: DhcpNameServer = 192.168.100.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{EC0C589F-7662-486A-A03D-7B61CDC87FF6}: DhcpNameServer = 192.168.0.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{13C43E79-C124-4F8D-A80C-5709BFD24871}: DhcpDomain = ADKSERVER
O17 - HKLM\System\CS1\Services\Tcpip\..\{3920E3E4-C7FD-43A5-950A-A79B5B6EBE06}: DhcpDomain = hc2.hc2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - AppInit_DLLs: . (.NVIDIA Corporation - NVIDIA shim initialization dll, Version 311.) - C:\Windows\system32\nvinitx.dll
~ AppInit DLL: Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: BTDevManager (BTDevManager) . (.Pas de propriétaire - Realtek Bluetooth BTDevManager Service Appl.) - C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
O23 - Service: Elan Service (ETDService) . (.ELAN Microelectronics Corp. - Elan Service.) - C:\Program Files\Elantech\ETDService.exe
~ Services: 23 Legitimates Filtered in 00mn 04s



---\\ Tâches planifiées en automatique (O39)
O39 - APT: - (..) -- C:\Windows\Tasks\DLL-Files FixerASKUSER.job [314]
~ Scheduled Task: 17 Legitimates Filtered in 00mn 02s



---\\ Logiciels installés (O42)
O42 - Logiciel: FileParade bundle uninstaller - (.FileParade.) [HKLM][64Bits] -- FileParade bundle uninstaller =>PUP.FileParadeBundle
~ Logic: 32 Legitimates Filtered in 00mn 00s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\Conduit] =>Toolbar.Conduit
[HKCU\Software\Condut]
[HKCU\Software\Drivers]
[HKCU\Software\ELIGCHK]
[HKCU\Software\IM]
[HKCU\Software\InstalledBrowserExtensions] =>Adware.VidSaver
[HKCU\Software\Pando Networks]
[HKCU\Software\System32]
[HKCU\Software\Win]
[HKLM\Software\InstalledBrowserExtensions] =>Adware.VidSaver
[HKLM\Software\Wow6432Node\InstalledBrowserExtensions] =>Adware.VidSaver
[HKLM\Software\Wow6432Node\Pando Networks]
[HKLM\Software\Wow6432Node\SWEETIM] =>PUP.SweetIM
[HKLM\Software\Wow6432Node\WAJAM] =>PUP.Wajam
[HKLM\Software\Wow6432Node\anset]
[HKLM\Software\Wow6432Node\supTab] =>PUP.SupTab
[HKLM\Software\Wow6432Node\supWPM] =>PUP.WpManager
~ Key Software: 303 Legitimates Filtered in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 18/01/2014 - 15:56:15 - [] ----D C:\Program Files (x86)\Pando Networks
O43 - CFD: 19/04/2014 - 19:54:50 - [0] ----D C:\Program Files (x86)\SupTab =>PUP.SupTab
O43 - CFD: 08/03/2014 - 23:17:37 - [] ----D C:\Program Files (x86)\sweetpacks bundle uninstaller =>PUP.SweetIM
O43 - CFD: 22/02/2013 - 08:31:22 - [] ----D C:\ProgramData\boost_interprocess
O43 - CFD: 14/03/2014 - 18:29:30 - [] ----D C:\ProgramData\WPM =>PUP.WpManager
O43 - CFD: 14/03/2014 - 20:45:49 - [0] ----D C:\Users\Yannn\AppData\Roaming\SupTab =>PUP.SupTab
O43 - CFD: 07/03/2014 - 19:31:00 - [] ----D C:\Users\Yannn\AppData\Local\Ahri.tw
~ Program Folder: 169 Legitimates Filtered in 00mn 00s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.110BE5198A63D3FF3CE9C30F1DC12EC3] - 11/04/2014 - 20:36:00 ---A- . (...) -- C:\Windows\System32\ApnDatabase.xml [386722]
~ Files: 36 Legitimates Filtered in 00mn 02s



---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.185B722AE01CC55A363628AA389ACA5A] - 12/04/2014 - 10:29:59 ---A- - C:\Windows\Prefetch\DEAD SPACE.EXE-0401BE5C.pf
O45 - LFCP:[MD5.28169BC37D1957EDB9D4AF2DD8A2E3B6] - 12/04/2014 - 12:51:16 ---A- - C:\Windows\Prefetch\VEGAS120.EXE-B828C1C6.pf
O45 - LFCP:[MD5.6CF601E5EF2FD2538F4D036FE3A0CD62] - 14/04/2014 - 05:35:12 ---A- - C:\Windows\Prefetch\SYSTEMSETTINGS.EXE-D8CC3B5E.pf
O45 - LFCP:[MD5.DE1789691FBC64EEB6BA6EE8E657705A] - 16/04/2014 - 21:39:04 ---A- - C:\Windows\Prefetch\LAUNCHTM.EXE-B444BC8E.pf
O45 - LFCP:[MD5.AA76C6E0AFEAC5CF0E2A2F1CBAACF3BE] - 19/04/2014 - 12:29:00 ---A- - C:\Windows\Prefetch\VIDEO-HIGH-ENABLER.EXE-D478C549.pf =>PUP.CrossRider
O45 - LFCP:[MD5.3BBF52D8A3F474AF58AFFE3D24CAE505] - 19/04/2014 - 12:29:03 ---A- - C:\Windows\Prefetch\VIDEO-HIGH-FIREFOXINSTALLER.E-53BA0A51.pf =>PUP.CrossRider
O45 - LFCP:[MD5.DA6F37DE23552844BE58D30D49B9FF09] - 19/04/2014 - 18:37:52 ---A- - C:\Windows\Prefetch\UPDREG.EXE-A07E2F17.pf
O45 - LFCP:[MD5.E988085C1906ED92C0520D0C8C863953] - 19/04/2014 - 18:37:52 ---A- - C:\Windows\Prefetch\WEBSTEROIDS.EXE-239D52F1.pf =>PUP.TubeDimmer
O45 - LFCP:[MD5.903C9DF372A6B71A1DB59513B1134A3C] - 19/04/2014 - 20:56:44 ---A- - C:\Windows\Prefetch\CLTMNG.EXE-C60707AC.pf
O45 - LFCP:[MD5.0C89A27495D393EAFB3E32A01FF240DF] - 19/04/2014 - 20:56:44 ---A- - C:\Windows\Prefetch\CLTMNGUI.EXE-8AC9A995.pf
O45 - LFCP:[MD5.4A1F2E7B98F71D544AD9E7275C487629] - 20/04/2014 - 12:29:49 ---A- - C:\Windows\Prefetch\dynreservedpri.db
O45 - LFCP:[MD5.E825EE5799391AEBA4199FC7E7173FAC] - 20/04/2014 - 12:38:08 ---A- - C:\Windows\Prefetch\SCM.EXE-B712F3D1.pf
O45 - LFCP:[MD5.9BC7B33CCDFF9C15DAF2989D33B90261] - 20/04/2014 - 12:45:41 ---A- - C:\Windows\Prefetch\SBCINEMA.EXE-A7520DEA.pf
O45 - LFCP:[MD5.DDD46DCFFB76A818B7E1C2958CCB9EDD] - 20/04/2014 - 12:53:22 ---A- - C:\Windows\Prefetch\SYMCPCCULAUNCHSVC.EXE-86FD0F09.pf
O45 - LFCP:[MD5.13C7540D06FEAD9E4972581F739C5BAB] - 20/04/2014 - 18:22:29 ---A- - C:\Windows\Prefetch\WARFRAME.X64.EXE-5207870E.pf
O45 - LFCP:[MD5.88C041600824E6D7BF7B04CCA5A9AC5F] - 20/04/2014 - 20:48:07 ---A- - C:\Windows\Prefetch\DLLFIXER.EXE-2D65F908.pf
O45 - LFCP:[MD5.738CD5DB5AC6F984A33C9CC6D5284E9B] - 20/04/2014 - 23:03:05 ---A- - C:\Windows\Prefetch\BTSERVER.EXE-B0D56206.pf
O45 - LFCP:[MD5.DB2F61703A3AB5677B91FFF0C647A802] - 20/04/2014 - 23:03:27 ---A- - C:\Windows\Prefetch\PDVD10SERV.EXE-99C8A7B5.pf
O45 - LFCP:[MD5.849F64A7468C96D3AD2F4C6854154860] - 20/04/2014 - 23:32:41 ---A- - C:\Windows\Prefetch\DEVICECOUNT.EXE-9E648573.pf
O45 - LFCP:[MD5.286FA56A170B449FC75C3C89F1886FB9] - 22/03/2014 - 11:59:36 ---A- - C:\Windows\Prefetch\LOLRECORDER.EXE-CDB07140.pf
O45 - LFCP:[MD5.19EDA1E20400C4057D5690D700249DBD] - 22/03/2014 - 13:50:56 ---A- - C:\Windows\Prefetch\NSL6174.EXE-85B05412.pf
O45 - LFCP:[MD5.F5C389A29B4E7BD8D315C0ACA9F9CB30] - 22/03/2014 - 13:52:02 ---A- - C:\Windows\Prefetch\NSQ9E5A.EXE-8319FE3D.pf
O45 - LFCP:[MD5.10B1FF0679224204F49A9D3C3C3A00C1] - 22/03/2014 - 13:52:14 ---A- - C:\Windows\Prefetch\NSQD1C0.EXE-EBC8A749.pf
O45 - LFCP:[MD5.7679936C0E4CF80B356A66C918530BFF] - 30/03/2014 - 15:19:49 ---A- - C:\Windows\Prefetch\ACTION.EXE-605E2649.pf
O45 - LFCP:[MD5.9A88AD2FB76CECE64FCE353A010F78FC] - 30/03/2014 - 21:37:02 ---A- - C:\Windows\Prefetch\UPDATETOOL.EXE-18BAEE18.pf
~ Prefetcher: 25 Legitimates Filtered in 00mn 00s



---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"VIDC.FICV"="ficvdec_x64.dll" . (...) -- C:\Windows\System32\ficvdec_x64.dll
~ TDSD: 5 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 17 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 3 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.39EC51A5BC3E1C0D438E8AC70956DE0A] - 09/07/2013 - 16:21:15 ---A- . (.ELAN Microelectronics Corp. - ETD Kernel Center.) -- C:\Windows\System32\Drivers\ETD.sys [357200]
O58 - SDL:[MD5.4E85355B94CFCB67C135F6521A4895A7] - 26/07/2012 - 06:00:55 ---A- . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x64.) -- C:\Windows\System32\Drivers\stexstor.sys [30960]
~ Drivers: 17 Legitimates Filtered in 00mn 00s



---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 19/04/2014 - 23:46:30 ---A- . (...) -- C:\Users\Yannn\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat [1954] =>Toolbar.Conduit
O61 - LFC: 20/04/2014 - 23:46:19 ---A- . (...) -- C:\Users\Yannn\AppData\Local\Google\Chrome\User Data\Certificate Revocation Lists [305614]
O61 - LFC: 20/04/2014 - 23:46:20 ---A- . (...) -- C:\Users\Yannn\AppData\Local\Google\Chrome\User Data\Local State [70207]
O61 - LFC: 20/04/2014 - 23:46:30 ---A- . (...) -- C:\Users\Yannn\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat [1093430] =>Toolbar.Conduit
O61 - LFC: 20/04/2014 - 23:46:30 ---A- . (...) -- C:\Users\Yannn\AppData\Local\Warframe\6D18F3DA12CCFA249476B73586EE0087\settings [5913]
O61 - LFC: 20/04/2014 - 23:46:30 ---A- . (...) -- C:\Users\Yannn\AppData\Local\Warframe\Editor.cfg [1708]
O61 - LFC: 20/04/2014 - 23:46:30 ---A- . (...) -- C:\Users\Yannn\AppData\Roaming\dll-files.com\Fixer\Version 1.0\ExcludeList.rcp [6]
O61 - LFC: 20/04/2014 - 23:46:30 ---A- . (...) -- C:\Users\Yannn\AppData\Roaming\dll-files.com\Fixer\Version 1.0\TempHLList.rcp [6]
O61 - LFC: 20/04/2014 - 23:46:30 ---A- . (...) -- C:\Users\Yannn\AppData\Roaming\dll-files.com\Fixer\Version 1.0\results.rcp [60]
O61 - LFC: 20/04/2014 - 23:46:31 -SHA- . (...) -- C:\Users\Yannn\Videos\2v5\Thumbs.db [16384]
O61 - LFC: 20/04/2014 - 23:46:31 -SHA- . (...) -- C:\Users\Yannn\Videos\EXPOSE DIEUDONNE\Thumbs.db [26112]
O61 - LFC: 20/04/2014 - 23:46:31 -SHA- . (...) -- C:\Users\Yannn\Videos\Thumbs.db [143872]
~ Files: 317 Legitimates Filtered in 00mn 12s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 11 Legitimates Filtered in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} [DefaultScope] - (Conduit Search) - http://search.conduit.com
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.240DDA08F6EE9290747D1A04A99D1CCA] [SPRF][19/04/2014] (...) -- C:\Users\Yannn\Desktop\RogueKiller.exe [3972608]
~ Files: 1 Legitimates Filtered in 00mn 00s



---\\ Enumère les codes produits des logiciels (PUC) (O90)
O90 - PUC: "6571134D598306F46975C6C522E81BCD" . (.WD Boost.) -- C:\Windows\Installer\{D4311756-3895-4F60-9657-6C5C228EB1DC}\ARPPRODUCTICON.exe
~ Update Products: 198 Legitimates Filtered in 00mn 00s



---\\ Enumère les données de la clé NameSpace (MNS) (O92)
O92 - MNS: Bluetooth FTP - {F34020BE-4CE5-489A-A352-5D69BDFC7F54}
~ MNS: 1 Legitimates Filtered in 00mn 00s



---\\ Recherche de clés de registre Tracing (O100)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WebsteroidsService_RASAPI32 =>PUP.TubeDimmer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WebsteroidsService_RASMANCS =>PUP.TubeDimmer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Websteroids_RASAPI32 =>PUP.TubeDimmer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Websteroids_RASMANCS =>PUP.TubeDimmer
~ BTK: 43 Legitimates Filtered in 00mn 00s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 09/07/2013 279024 | (cphs) . (.Intel Corporation.) - C:\Windows\SysWow64\IntelCpHeciSvc.exe
SS - | Auto 01/04/2014 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 01/04/2014 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 10/12/2012 803872 | (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
SS - | Demand 28/01/2013 4230016 | (NOBU) . (.Symantec Corporation.) - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe =>.Symantec Corporation
SS - | Auto 23/10/2013 172192 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SS - | Demand 10/07/2013 29696 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

SR - | Auto 18/02/2014 402192 | (BstHdAndroidSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-Service.exe
SR - | Auto 18/02/2014 385808 | (BstHdLogRotatorSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
SR - | Auto 18/02/2014 766736 | (BstHdUpdaterSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
SR - | Auto 07/12/2012 39424 | (BTDevManager) . (...) - C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
SR - | Auto 09/07/2013 99664 | (ETDService) . (.ELAN Microelectronics Corp..) - C:\Program Files\Elantech\ETDService.exe
SR - | Auto 22/03/2013 15344 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
SR - | Auto 10/12/2012 732160 | (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe
SR - | Auto 16/02/2013 169432 | (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
SR - | Auto 16/02/2013 366552 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 03/04/2014 1809720 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
SR - | Auto 03/04/2014 857912 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
SR - | Auto 18/04/2013 160768 | (Micro Star SCM) . (.Micro-Star International Co., Ltd..) - C:\Program Files (x86)\SCM\MSIService.exe
SR - | Auto 08/02/2013 154112 | (MSI_SuperCharger) . (.MSI.) - C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
SR - | Auto 19/08/2012 143928 | (NAT) . (.Symantec Corporation.) - C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe
SR - | Auto 14/06/2012 143928 | (NIS) . (.Symantec Corporation.) - C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\ccSvcHst.exe
SR - | Auto 13/08/2012 123320 | (Norton PC Checkup Application Launcher) . (.Symantec Corporation.) - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\SymcPCCULaunchSvc.exe
SR - | Auto 10/03/2013 884512 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe
SR - | Auto 09/07/2013 1260320 | (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
SR - | Auto 13/08/2012 126392 | (PCCUJobMgr) . (.Symantec Corporation.) - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\ccSvcHst.exe
SR - | Demand 25/02/2014 568512 | (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
SR - | Auto 22/02/2013 2849120 | (TeamViewer7) . (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
SR - | Auto 13/04/2013 55056 | (WD Boost) . (.Western Digital.) - C:\Program Files\Western Digital\WD Boost\WDBoost.exe
SR - | Demand 10/07/1658 0 | (WinDefend) . (...) - C:\Program Files (x86)\Windows Defender\MsMpEng.exe
SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation

~ Services: Scanned in 00mn 07s



---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Run by Yannn at 20/04/2014 23:48:05
~ OS 64 not supported by MBR tool

~ MBR: 0 Legitimates Filtered in 00mn 00s



---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by Yannn at 20/04/2014 23:48:07

********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin

~ MBR: Scanned in 00mn 02s



---\\ Scan Additionnel (O88)
Database Version : 13044 - (19/04/2014)
Clés trouvées (Keys found) : 8
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 6
Fichiers trouvés (Files found) : 5

[HKLM\Software\Google\Chrome\Extensions\lndipknmjijnalnkamonmljeaojdbpna] =>PUP.CrossRider^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\FileParade bundle uninstaller] =>PUP.FileParadeBundle^
[HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater] =>Toolbar.Wajam
[HKLM\Software\Wow6432Node\SweetIM] =>PUP.SweetIM
[HKCU\Software\InstalledBrowserExtensions\] =>PUP.CrossRider
[HKCU\Software\InstalledBrowserExtensions] =>PUP.CrossRider
[HKLM\Software\InstalledBrowserExtensions] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\InstalledBrowserExtensions] =>PUP.CrossRider
C:\Users\Yannn\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna =>PUP.CrossRider^
C:\Program Files (x86)\SupTab =>PUP.SupTab^
C:\Program Files (x86)\sweetpacks bundle uninstaller =>PUP.SweetIM^
C:\ProgramData\WPM =>PUP.WpManager^
C:\Users\Yannn\AppData\Roaming\SupTab =>PUP.SupTab^
C:\Users\Yannn\AppData\Local\SearchProtect =>Toolbar.Conduit
[HKCU\Software\Conduit] =>Toolbar.Conduit^
[HKLM\Software\Wow6432Node\SWEETIM] =>PUP.SweetIM^
[HKLM\Software\Wow6432Node\WAJAM] =>PUP.Wajam^
[HKLM\Software\Wow6432Node\supTab] =>PUP.SupTab^
[HKLM\Software\Wow6432Node\supWPM] =>PUP.WpManager^
~ Additionnel Scan: 195410 Items scanned in 00mn 12s



---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.webs.com/apps/blog/show/27583526-pup-crossrider =>PUP.CrossRider
http://nicolascoolman.webs.com/apps/blog/show/41011964-pup-awesomehp =>PUP.Awesomehp
http://nicolascoolman.webs.com/apps/blog/show/29507721-toolbar-conduit =>Toolbar.Conduit
http://nicolascoolman.webs.com/apps/blog/show/27557062-adware-vidsaver =>Adware.VidSaver
http://nicolascoolman.webs.com/apps/blog/show/29216159-pup-sweetim =>PUP.SweetIM
http://nicolascoolman.webs.com/apps/blog/show/27379491-toolbar-wajam =>PUP.Wajam
http://nicolascoolman.webs.com/apps/blog/show/41133513-pup-suptab =>PUP.SupTab
http://nicolascoolman.webs.com/apps/blog/show/38737316-pup-wpmanager =>PUP.WpManager
http://nicolascoolman.webs.com/apps/blog/show/37242682-pup-tubedimmer =>PUP.TubeDimmer
~ MSI: 9 link(s) detected in 00mn 00s



~ 1680 Legitimates filtered by white list
End of the scan (567 lines in 02mn 32s)(0)

Publicité


Signaler le contenu de ce document

Publicité