cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2014.8.21.121 - Nicolas Coolman (21/08/2014)
~ Lancé par jc (21/08/2014 21:14:38)
~ Adresse du Site Web http://nicolascoolman.fr
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17031
MFIE: Mozilla Firefox 31.0 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows 8.1 Pro, 32-bit (Build 9600)
Windows Server License Manager Script : OK
~ Windows(R) Operating System, RETAIL channel
Windows ID Activation : OK
~ Windows Partial Key : XWY9B
Windows License : OK
~ Windows Remaining Initializations Number : 1000
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Logiciels de protection du système
avast! Free Antivirus v9.0.2021
Windows Defender W8 (Deactivate)

---\\ Logiciels d'optimisation du système

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 14 Plugin
Adobe Reader XI

---\\ Informations sur le système
~ Processor: x86 Family 16 Model 6 Stepping 2, AuthenticAMD
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2815 MB (66% free)
System Restore: Activé (Enable)
System drive C: has 451 GB (96%) free of 466 GB

---\\ Mode de connexion au système
~ Computer Name: JC
~ User Name: jc
~ All Users Names: jc, HomeGroupUser$, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\jc\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\jc\AppData\Roaming\
~ %Desktop% : C:\Users\jc\Desktop\
~ %Favorites% : C:\Users\jc\Favorites\
~ %LocalAppData% : C:\Users\jc\AppData\Local\
~ %StartMenu% : C:\Users\jc\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 451 Go of 466 Go)
D: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
~ Security Center: 37 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.E0C84A30581BC508E289E4371A723F58] - (.Microsoft Corporation - Explorateur Windows.) (.18/03/2014 - 09:00:01.) -- C:\Windows\Explorer.exe [2088160]
[MD5.02BC073156B3097E94D63C4D609020DD] - (.Microsoft Corporation - Application de démarrage de Windows.) (.22/08/2013 - 03:49:55.) -- C:\Windows\System32\Wininit.exe [112640]
[MD5.F89C2BDB6E385ED6CA2AC0085BB6643A] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.18/03/2014 - 08:59:52.) -- C:\Windows\System32\wininet.dll [1789440]
[MD5.70C57DC69D4A7D92D2CAC90C3AD16E6F] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.18/03/2014 - 08:59:51.) -- C:\Windows\System32\Winlogon.exe [459264]
[MD5.BFB9E1202225113991F981D29BFB9029] - (.Microsoft Corporation - Bibliothèque de licences.) (.18/03/2014 - 08:59:51.) -- C:\Windows\System32\sppcomapi.dll [438272]
[MD5.2AF7DA157FFF947A507FCB4AB8BB4C7C] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.22/08/2013 - 07:13:54.) -- C:\Windows\system32\Drivers\AFD.sys [455168]
[MD5.72FCAE2CE6DFEAB2AB072435017F3417] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.22/08/2013 - 06:33:25.) -- C:\Windows\system32\Drivers\atapi.sys [23392]
[MD5.CE232BB0965C0C0B786C3F976CCBFB7D] - (.Microsoft Corporation - CD-ROM File System Driver.) (.22/08/2013 - 05:11:55.) -- C:\Windows\system32\Drivers\Cdfs.sys [73728]
[MD5.E2FC132D48EA4E8B04432C33EFB77801] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.22/08/2013 - 02:59:12.) -- C:\Windows\system32\Drivers\Cdrom.sys [124928]
[MD5.CD6A836DE4F4CC39D7BD8B19AEA93065] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.18/03/2014 - 08:59:38.) -- C:\Windows\system32\Drivers\DfsC.sys [101376]
[MD5.A31901DE6A22EA67AB83AAF7036F98CC] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.22/08/2013 - 05:10:12.) -- C:\Windows\system32\Drivers\HDAudBus.sys [69632]
[MD5.5043E69532392A43549E5D41E22638AA] - (.Microsoft Corporation - Pilote de port i8042.) (.22/08/2013 - 05:10:59.) -- C:\Windows\system32\Drivers\i8042prt.sys [82944]
[MD5.FA6C94C754A566EA8A61D658932F32DE] - (.Microsoft Corporation - IP Network Address Translator.) (.18/03/2014 - 08:59:54.) -- C:\Windows\system32\Drivers\IpNat.sys [126976]
[MD5.9579309510C35D00BC9E4D5C10C2CEE4] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.18/03/2014 - 08:59:38.) -- C:\Windows\system32\Drivers\MRxSmb.sys [333824]
[MD5.BC242922B0D08F61CF7C87FD08FAFA8B] - (.Microsoft Corporation - MBT Transport driver.) (.22/08/2013 - 05:08:26.) -- C:\Windows\system32\Drivers\netBT.sys [218624]
[MD5.9595B28CE24351C201A51A5019966862] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.18/03/2014 - 08:59:37.) -- C:\Windows\system32\Drivers\ntfs.sys [1679704]
[MD5.4F30970F15ADCC382544B31D5D7E368E] - (.Microsoft Corporation - Pilote de port parallèle.) (.22/08/2013 - 05:11:49.) -- C:\Windows\system32\Drivers\Parport.sys [81408]
[MD5.C51AB62AB41A2E8560D12472B204CC00] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.22/08/2013 - 05:07:36.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [81920]
[MD5.67E91843B0344411820A012063E876B2] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.18/03/2014 - 08:38:09.) -- C:\Windows\system32\Drivers\rdpdr.sys [143872]
[MD5.DB0C184142CF9FA1746F598A16EE92B2] - (.Microsoft Corporation - TDI Translation Driver.) (.22/08/2013 - 07:13:54.) -- C:\Windows\system32\Drivers\tdx.sys [87040]
[MD5.085918BF459BCB835CFC535BE7138539] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.18/03/2014 - 08:59:36.) -- C:\Windows\system32\Drivers\volsnap.sys [265048]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes Favoris (My Favorites) : 1/3
~ Mes Documents (My Documents) : 1/3
~ Mon Bureau (My Desktop) : 1/120
~ Menu demarrer (Programs) : 1/25
~ Hidden Files: Scanned in 00mn 00s



---\\ Processus lancés
[MD5.2197DED64442B4B342971598208A7D1A] - (.Microsoft Corporation - Processus hôte pour Tâches Windows.) -- C:\Windows\system32\taskhostex.exe [66624] [PID.1584]
[MD5.45B6ED23AD7155C196F809BEE1D7CB5D] - (.IvoSoft - Classic Start Menu.) -- C:\Program Files\Classic Shell\ClassicStartMenu.exe [150208] [PID.2172]
[MD5.5457E108FA0265380666C0A55E76589B] - (.Microsoft Corporation - Communications Service.) -- C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20573_x86__8wekyb3d8bbwe\LiveComm.exe [138240] [PID.3976]
[MD5.1A8908FB099B39FAC54E6CF010AFC550] - (.Microsoft Corporation - OneDrive Sync Engine Host.) -- C:\Windows\System32\skydrive.exe [672256] [PID.3808]
[MD5.DB0FE6E51909BEB42004242EB08FEF47] - (.Microsoft Corporation - Host Process for Setting Synchronization.) -- C:\Windows\System32\SettingSyncHost.exe [517120] [PID.2576]
[MD5.8998A4837A47F16F27000C0A61EFC90D] - (.Microsoft Corporation - Runtime Broker.) -- C:\Windows\System32\RuntimeBroker.exe [29920] [PID.3736]
[MD5.26B558B2D31C7425B455B00E562EAD93] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastui.exe [4085896] [PID.648]
[MD5.10F36FB8CD6218CD7F818268E0F3F9C6] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [275568] [PID.4868]
[MD5.9D506DEFE177A7A4B4C88977A2FA735B] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8094720] [PID.2200]
~ Processes Running: Scanned in 00mn 01s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\jc\AppData\Local\Google\Chrome\User Data\Default\Preferences
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Drive v.6.2 (Activé)
G2 - GCE: Preference [User Data\Default] [kmendfapggjehodndflmmgagdbamhnfd] CryptoTokenExtension v.0.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [neajdppkdcdipfabeoofebfddakdcjhd] Google Network Speech v.1.0 (Activé)
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.6.1 (Activé)

---\\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 16 Legitimates Filtered in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\jc\AppData\Roaming\Mozilla\Firefox\Profiles\ptuavaif.default\prefs.js
M3 - MFPP: Plugins - [jc] -- C:\Users\jc\AppData\Roaming\Mozilla\Firefox\Profiles\ptuavaif.default\searchplugins\default-search.xml =>Hijacker.Browsers
~ Firefox Browser: 7 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Classic Explorer Bar - [HKLM]{553891B7-A0D5-4526-BE18-D3CE461D6310} . (.IvoSoft - Adds classic Windows Explorer features.) -- C:\Program Files\Classic Shell\ClassicExplorer32.dll
~ Toolbar: Scanned in 00mn 00s



---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [Classic Start Menu] . (.IvoSoft - Classic Start Menu.) -- C:\Program Files\Classic Shell\ClassicStartMenu.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated
O4 - HKLM\..\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
~ Application: Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} -- Clé orpheline
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] http.ma-config.com
O15 - Trusted Zone: [HKCU\...\Domains] http.touslesdrivers.com
~ IE Zone Confiance: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{69A36705-C70D-4CE8-BD5F-038F44B8C788}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{69A36705-C70D-4CE8-BD5F-038F44B8C788}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
O39 - APT: - (..) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
~ Scheduled Task: 5 Legitimates Filtered in 00mn 05s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 10/08/2014 - 18:33:24 - [] ----D C:\ProgramData\ClassicShell
O43 - CFD: 21/08/2014 - 21:12:59 - [] ----D C:\Users\jc\AppData\Roaming\ClassicShell
O43 - CFD: 10/08/2014 - 17:25:14 - [0] ----D C:\Users\jc\AppData\Local\PackageStaging
~ Program Folder: 88 Legitimates Filtered in 00mn 00s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.24C25247B9383DE2BC299D68EE494043] - 10/08/2014 - 16:12:52 ---A- . (...) -- C:\Windows\DtcInstall.log [2664]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 10/08/2014 - 16:31:59 ---A- . (...) -- C:\Windows\System32\atiicdxx.dat [0]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 10/08/2014 - 16:31:59 ---A- . (...) -- C:\Windows\ativpsrm.bin [0]
O44 - LFC:[MD5.69EB905EEDE8BB7995BCD337B511C153] - 13/08/2014 - 14:37:52 ---A- . (...) -- C:\Windows\System32\xcdsfx32.bin [110602]
O44 - LFC:[MD5.3BFBB5DAE801CB893B8B46345FED6437] - 13/08/2014 - 16:13:28 ---A- . (...) -- C:\Windows\System32\Drivers\aswHwid.sys [24184]
O44 - LFC:[MD5.4068AA6D462ABC016C9AD53BE4DBC5ED] - 13/08/2014 - 18:18:14 ---A- . (...) -- C:\Windows\System32\bootPrep_BASE+CSWITCH_1.etl [71303168]
O44 - LFC:[MD5.243C233636A65B2B9DA5FD0DE284A52F] - 13/08/2014 - 18:18:23 ---A- . (...) -- C:\Windows\System32\bootPrep_BASE+CSWITCH_1.cab [2663350]
O44 - LFC:[MD5.B626A1317EA7392462B535BE182AA867] - 13/08/2014 - 18:21:59 ---A- . (...) -- C:\Windows\System32\bootPrep_BASE+CSWITCH_2.etl [74448896]
O44 - LFC:[MD5.F9900395D802D95A4F4B202C4EBD6B44] - 13/08/2014 - 18:22:16 ---A- . (...) -- C:\Windows\System32\bootPrep_BASE+CSWITCH_2.cab [4052595]
O44 - LFC:[MD5.FDCB91D796EF919161B58E4B105DB525] - 13/08/2014 - 18:58:42 ---A- . (...) -- C:\Windows\System32\bootPrep_BASE+CSWITCH_3.etl [69206016]
O44 - LFC:[MD5.0871E8BF6D06E6A20396FA869688FD7A] - 13/08/2014 - 18:59:21 ---A- . (...) -- C:\Windows\System32\bootPrep_BASE+CSWITCH_3.cab [5429301]
O44 - LFC:[MD5.758F741B69BA11CB6E571629A67177D9] - 13/08/2014 - 19:02:54 ---A- . (...) -- C:\Windows\System32\bootPrep_BASE+CSWITCH_4.etl [71303168]
O44 - LFC:[MD5.8202DDC61B62961ACF34E574A55D3651] - 13/08/2014 - 19:03:29 ---A- . (...) -- C:\Windows\System32\bootPrep_BASE+CSWITCH_4.cab [6698621]
O44 - LFC:[MD5.2B0D88758AAD2E27C5E96FB20EF96EA6] - 13/08/2014 - 19:06:58 ---A- . (...) -- C:\Windows\System32\bootPrep_BASE+CSWITCH_5.etl [74448896]
O44 - LFC:[MD5.4D511ACC44F56DB4C3A15CD81206B527] - 13/08/2014 - 19:07:33 ---A- . (...) -- C:\Windows\System32\bootPrep_BASE+CSWITCH_5.cab [7950838]
O44 - LFC:[MD5.BBF223904B8A2DDBED646200EACA5D07] - 13/08/2014 - 19:11:07 ---A- . (...) -- C:\Windows\System32\bootPrep_BASE+CSWITCH_6.etl [72351744]
O44 - LFC:[MD5.58C7B683629ADEB25501AAC7B79E3472] - 13/08/2014 - 19:11:40 ---A- . (...) -- C:\Windows\System32\bootPrep_BASE+CSWITCH_6.cab [8435446]
O44 - LFC:[MD5.776905DAA7C232ED233CD1046BD9F627] - 13/08/2014 - 19:15:12 ---A- . (...) -- C:\Windows\System32\boot_BASE+CSWITCH_1.etl [69206016]
O44 - LFC:[MD5.850CF28F5037BA469E776C323ABB8723] - 13/08/2014 - 19:15:46 ---A- . (...) -- C:\Windows\System32\boot_BASE+CSWITCH_1.cab [8911204]
~ Files: 50 Legitimates Filtered in 00mn 46s



---\\ Déni du service (Local Security Authority) (O48)
~ LSA: 3 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 17 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:13/08/2014 - 16:13:28 ---A- . (...) -- C:\Windows\System32\Drivers\aswHwid.sys [24184] =>.ALWIL Software
O58 - SDL:13/08/2014 - 16:13:28 ---A- . (...) -- C:\Windows\System32\Drivers\aswRvrt.sys [49944] =>.ALWIL Software
O58 - SDL:13/08/2014 - 16:13:29 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys [192352] =>.ALWIL Software
O58 - SDL:13/08/2013 - 00:25:32 ---A- . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\Drivers\bcmfn2.sys [16088]
O58 - SDL:22/08/2013 - 06:32:57 ---A- . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x86.) -- C:\Windows\System32\Drivers\stexstor.sys [26976]
~ Drivers: 41 Legitimates Filtered in 00mn 10s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 13/08/2014 262320 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 17/07/2014 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SR - | Auto 08/05/2014 65432 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 13/08/2014 50344 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
SR - | Auto 24/06/2014 2117448 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe
SR - | Auto 10/03/2010 189728 | (PSI_SVC_2) . (.Protexis Inc..) - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
SR - | Demand 22/08/2013 22240 | (WinDefend) . (.Microsoft Corporation.) - C:\Program Files\Windows Defender\MsMpEng.exe
SR - | Demand 22/08/2013 31552 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 16s



---\\ Scan Additionnel (O88)
Database Version : 13026 - (21/08/2014)
Clés trouvées (Keys found) : 0
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 0

~ Additionnel Scan: 169215 Items scanned in 00mn 48s



---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/g2-google-chrome-extensions/ =>.Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ AMI: 4 Legitimates Filtered in 00mn 00s



---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/hijacker-browsers =>Hijacker.Browsers
~ MSI: 1 link(s) detected in 00mn 00s



~ 429 Legitimates filtered by white list
End of the scan (329 lines in 02mn 40s)(0)

Publicité


Signaler le contenu de ce document

Publicité