cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2015.3.5.26 - Nicolas Coolman (01/03/2015)
~ Lancé par HAFSAOUI (07/03/2015 16:43:23)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Nouvelle version disponible
~ Liste blanche : Désactivée par l'utilisateur
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by program


---\\ Navigateurs Internet
MSIE: Internet Explorer v9.0.8080.16413
MFIE: Mozilla Firefox 33.0.2 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows Operating System - Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : P4K27
Windows License : OK
~ Windows Remaining Initializations Number : 3
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 7 Ultimate, 32-bit (Build 7600)

---\\ Logiciels de protection du système
Kaspersky Internet Security v15.0.0.463
Windows Defender W7 (Activate)

---\\ Logiciels d'optimisation du système
CCleaner v3.15

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 11 Plugin

---\\ Informations sur le système
~ Processor: x86 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 1910 MB (37% free)
System Restore: Activé (Enable)
System drive C: has 75 GB (69%) free of 109 GB

---\\ Mode de connexion au système
~ Computer Name: HAFSAOUI-PC
~ User Name: HAFSAOUI
~ All Users Names: HAFSAOUI, Administrateur,
~ Unselected Option: None
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\HAFSAOUI\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\HAFSAOUI\AppData\Roaming\
~ %Desktop% : C:\Users\HAFSAOUI\Desktop\
~ %Favorites% : C:\Users\HAFSAOUI\Favorites\
~ %LocalAppData% : C:\Users\HAFSAOUI\AppData\Local\
~ %StartMenu% : C:\Users\HAFSAOUI\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 75 Go of 109 Go)
D: Hard drive, Flash drive, Thumb drive (Free 108 Go of 109 Go)
E: Hard drive, Flash drive, Thumb drive (Free 215 Go of 249 Go)
F: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : Out Of Date
~ Security Center: 50 Scanned in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.2626FC9755BE22F805D3CFA0CE3EE727] - (.Microsoft Corporation - Explorateur Windows.) (.31/10/2009 - 06:45:39.) -- C:\Windows\Explorer.exe [2614272]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.111CB0C322A2387E16ED1B013533598D] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.20/08/2014 - 14:58:17.) -- C:\Windows\System32\wininet.dll [1125376]
[MD5.37CDB7E72EB66BA85A87CBE37E7F03FD] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.28/10/2009 - 07:17:59.) -- C:\Windows\System32\Winlogon.exe [285696]
[MD5.58C94EAE54BF0C5E2B80B2E5E7744D4C] - (.Microsoft Corporation - Bibliothèque de licences.) (.14/07/2009 - 02:16:15.) -- C:\Windows\System32\sppcomapi.dll [193024]
[MD5.0DB7A48388D54D154EBEC120461A0FCD] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.25/04/2011 - 03:35:40.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BA6E70AA0E6091BC39DE29477D866A77] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.14/07/2009 - 00:11:26.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.83D1ECEA8FAAE75604C0FA49AC7AD996] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.27/04/2011 - 03:33:46.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.717A2207FD6F13AD3E664C7D5A43C7BF] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.14/07/2009 - 00:50:56.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.CA7570E42522E24324A12161DB14EC02] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.04/05/2011 - 03:43:41.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123392]
[MD5.DD52A733BF4CA5AF84562A5E2F963B91] - (.Microsoft Corporation - MBT Transport driver.) (.14/07/2009 - 00:12:21.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.A8F59428E9F361C7AC42A94AC1560BC9] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 14:58:11.) -- C:\Windows\system32\Drivers\ntfs.sys [1210728]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.C5FF95883FFEF704D50C40D21CFB3AB5] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.14/07/2009 - 01:02:58.) -- C:\Windows\system32\Drivers\rdpdr.sys [133120]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.CB39E896A2A83702D1737BFD402B3542] - (.Microsoft Corporation - TDI Translation Driver.) (.14/07/2009 - 00:12:11.) -- C:\Windows\system32\Drivers\tdx.sys [74240]
[MD5.59F06B4968E58BC83DFC56CA4517960E] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.06/09/2012 - 17:48:29.) -- C:\Windows\system32\Drivers\volsnap.sys [245616]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes Favoris (My Favorites) : 1/61
~ Mes Documents (My Documents) : 1/62
~ Mon Bureau (My Desktop) : 1/23
~ Menu demarrer (Programs) : 1/40
~ Hidden Files: Scanned in 00mn 00s



---\\ Processus lancés
[MD5.61B03DE685C85A9D1185CCA8257FB3A3] - (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5941760] [PID.3048]
[MD5.00A9DFC5EF873004F0851D3C234E4801] - (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\quickset.exe [3405168] [PID.3320]
[MD5.D740133A8E2D525C9487EBA160539956] - (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxtray.exe [143384] [PID.3408]
[MD5.25E911BB3C2307201890B85A6E935E49] - (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe [176664] [PID.3416]
[MD5.B9A5D8BC8D2CC0350D9C5DA85D769CD2] - (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe [178200] [PID.3424]
[MD5.E586CE8AD2E20F114F71F37A010DEB4A] - (.IDT, Inc. - IDT PC Audio TPE.) -- C:\Program Files\IDT\WDM\sttray.exe [1138783] [PID.3516]
[MD5.3AF8CBAE0709D89E07E5E21B2825A499] - (...) -- C:\Program Files\Mobiconnect\CancelAutoPlay_byt.exe [431432] [PID.3524]
[MD5.5965EDE791559A33EA806AA8A2DCC312] - (...) -- C:\Program Files\Mobiconnect\UIexec.exe [157000] [PID.3532]
[MD5.7D6E1809C844B1D2AA02B6DCF1950084] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe [31087200] [PID.3716]
[MD5.E78FA80D4D7FD757A53781E17A3B7402] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe [3487128] [PID.3744]
[MD5.14767A3B686BB46F600C2325D2689C8E] - (.Broadcom Corporation. - Bluetooth Tray Application.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [840992] [PID.3956]
[MD5.BD95E822E7A958BBCA842D078426A151] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe [269848] [PID.3772]
[MD5.BA4F0F6D114A44F51893C5206DD5A4CA] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [745784] [PID.4092]
[MD5.566F5A07C950D52ECB5CEBDAE39DDEC0] - (.Internet Download Manager, Tonec Inc. - Broker for reading of IDM settings.) -- C:\Program Files\Internet Download Manager\idmBroker.exe [69144] [PID.1120]
[MD5.A854BC2D2AD9856F6B84C7870FF246D9] - (.Adobe Systems Incorporated - Adobe® Flash® Player Installer/Uninstaller.) -- C:\Windows\system32\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe [706776] [PID.6060]
[MD5.35F8A4C2ED66BDDC29C961419DEF147D] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8184320] [PID.4412]
~ Processes Running: Scanned in 00mn 01s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\HAFSAOUI\AppData\Local\Google\Chrome\User Data\Default\Preferences

---\\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 0 Scanned in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
M0 - MFSP: prefs.js [HAFSAOUI - ke7z0gnh.default] http://www.google.com
M2 - MFEP: Extension [HAFSAOUI - 8cmqvxch.default] {6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi
M2 - MFEP: Extension [HAFSAOUI - 8cmqvxch.default] {b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi
M2 - MFEP: Extension [HAFSAOUI - 8cmqvxch.default] {DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
M2 - MFEP: prefs.js [HAFSAOUI - ke7z0gnh.default\mozilla_cc@internetdownloadmanager.com] [] IDM CC v7.3.97 (..)
M2 - MFEP: prefs.js [HAFSAOUI - ke7z0gnh.default\youtubeunblocker@unblocker.yt] [] YouTube Unblocker v0.6.5 (..)
M2 - MFEP: Extension [HAFSAOUI - ke7z0gnh.default] {6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi
M2 - MFEP: Extension [HAFSAOUI - ke7z0gnh.default] {b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi
M2 - MFEP: Extension [HAFSAOUI - ke7z0gnh.default] {DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll
P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll =>.Google Inc
P2 - FPN: [HKCU] [@Skype Limited.com/Facebook Video Calling Plugin] - (.Skype Limited - Facebook Video Calling Plugin.) -- C:\Users\HAFSAOUI\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
~ Firefox Browser: 13 Scanned in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.yahoo.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Skype Limited - Facebook Video Calling Plugin.) (No version) -- (.not file.)
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 0
~ IE Browser: 11 Scanned in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} Clé orpheline
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} . (.Kaspersky Lab ZAO - Content Blocker Plugin.) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} . (.Kaspersky Lab ZAO - Virtual Keyboard Plugin.) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} Clé orpheline
O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} . (.Kaspersky Lab ZAO - Safe Money Plugin.) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\OnlineBanking\online_banking_bho.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} . (.Kaspersky Lab ZAO - URL Advisor Plugin.) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll
~ BHO: 18 Scanned in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\QuickLaunch [HAFSAOUI]: BoBrowser.lnk . (.The BoBrowser Authors - BoBrowser.) -- C:\Users\HAFSAOUI\AppData\Local\BoBrowser\Application\bobrowser.exe =>PUP.BoBrowser
O4 - GS\Desktop [HAFSAOUI]: SpeedAnalysis.lnk - Clé orpheline =>PUP.SpeedAnalysis
~ Global Startup: 2 Scanned in 00mn 04s



---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] . (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [Apoint] . (.Alps Electric Co., Ltd. - Alps Pointing-device Driver.) -- C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [QuickSet] . (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio TPE.) -- C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [20131121] C:\Program Files\AVAST Software\Avast\setup\emupdate\8e290a69-d824-49e9-8ba0-8993c68122f9.exe (.not file.)
O4 - HKLM\..\Run: [CancelAutoPlay_byt] . (...) -- C:\Program Files\Mobiconnect\CancelAutoPlay_byt.exe
O4 - HKLM\..\Run: [UIExec] . (...) -- C:\Program Files\Mobiconnect\UIexec.exe
O4 - HKCU\..\Run: [Servieca.vbs] C:\Users\HAFSAOUI\AppData\Local\Temp\Servieca.vbs (.not file.)
O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\HAFSAOUI\AppData\Local\Facebook\Update\FacebookUpdate.exe
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe
O4 - HKCU\..\Run: [BoBrowser] . (.The BoBrowser Authors - BoBrowser.) -- C:\Users\HAFSAOUI\AppData\Local\BoBrowser\Application\bobrowser.exe =>PUP.BoBrowser
O4 - HKUS\.DEFAULT\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKUS\S-1-5-18\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-2507926342-3944409784-4027650927-1000\..\Run: [Servieca.vbs] C:\Users\HAFSAOUI\AppData\Local\Temp\Servieca.vbs (.not file.)
O4 - HKUS\S-1-5-21-2507926342-3944409784-4027650927-1000\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\HAFSAOUI\AppData\Local\Facebook\Update\FacebookUpdate.exe
O4 - HKUS\S-1-5-21-2507926342-3944409784-4027650927-1000\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKUS\S-1-5-21-2507926342-3944409784-4027650927-1000\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe
O4 - HKUS\S-1-5-21-2507926342-3944409784-4027650927-1000\..\Run: [BoBrowser] . (.The BoBrowser Authors - BoBrowser.) -- C:\Users\HAFSAOUI\AppData\Local\BoBrowser\Application\bobrowser.exe =>PUP.BoBrowser
~ Application: Scanned in 00mn 00s



---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ IE Control Panel: 1 Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Clavier virtuel - {0C4CC089-D306-440D-9772-464E226F6539} . (...) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\kbrd.ico
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- C:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
O9 - Extra button: Analyse des liens - {CCF151D8-D089-449F-A5A4-D9909053F20F} . (...) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\logo.ico
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
~ Winsock: 7 Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{2AB62FCF-684C-49F8-A41B-9C87F83CBEBA}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B8D950F-EA79-4193-848F-8E3C13D2C78D}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{2AB62FCF-684C-49F8-A41B-9C87F83CBEBA}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{4B8D950F-EA79-4193-848F-8E3C13D2C78D}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{2AB62FCF-684C-49F8-A41B-9C87F83CBEBA}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{4B8D950F-EA79-4193-848F-8E3C13D2C78D}: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ SSODL: 1 Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Andrea ST Filters Service (AESTFilters) . (.Andrea Electronics Corporation - Andrea filters APO access service (32-bit).) - C:\Program Files\IDT\WDM\aestsrv.exe
O23 - Service: Kaspersky Anti-Virus Service 15.0.0 (AVP15.0.0) . (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe
O23 - Service: Bluetooth Service (btwdins) . (.Broadcom Corporation. - Bluetooth Support Server.) - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: ClaraUpdater (ClaraUpdater) . (.ClaraLabs - ClaraUpdater.) - C:\Program Files\Common Files\ClaraUpdater\ClaraUpdater.exe =>Adware.SupTab
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: C:\Windows\System32\stlang.dll (STacSV) . (.IDT, Inc. - IDT PC Audio TPE.) - C:\Program Files\IDT\WDM\STacSV.exe
O23 - Service: UI Assistant Service (UI Assistant Service) . (...) - C:\Program Files\Mobiconnect\AssistantServices.exe
O23 - Service: Intel(R) Management & Security Application User Notificatio (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: DW WLAN Tray Service (wltrysvc) . (.Dell Inc. - DW WLAN Card Wireless Network Service.) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
~ Services: 10 Scanned in 00mn 08s



---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Desktop Component: 4 Scanned in 00mn 00s



---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
[MD5.BA7E0BAD9AFF2E62F10F74DFB4783986] [APT] [avastBCLRestartS-1-5-21-2507926342-3944409784-4027650927-1000] (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\firefox.exe [275568]
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-2507926342-3944409784-4027650927-1000Core] (.Facebook Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096]
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-2507926342-3944409784-4027650927-1000UA] (.Facebook Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096]
[MD5.00000000000000000000000000000000] [APT] [GoforFilesUpdate] (...) -- C:\Program Files\GoforFiles\GFFUpdater.exe (.not file.) [0] =>P2P.GoforFiles
[MD5.00000000000000000000000000000000] [APT] [PostPoneInstall] (...) -- C:\Users\HAFSAOUI\AppData\Local\Temp\ce98ac2e-20c0-4a93-86f6-bdb3e61caf55.exe (.not file.) [0]
[MD5.1B7263F59C7AEB95664B338846BC5F3E] [APT] [Run_Bobby_Browser] (.The BoBrowser Authors.) -- C:\Users\HAFSAOUI\AppData\Local\BoBrowser\Application\bobrowser.exe [7353992] =>PUP.BoBrowser
[MD5.00000000000000000000000000000000] [APT] [Torntv V6.0-updater] (...) -- C:\Program Files\Torntv V6.0\Torntv V6.0-updater.exe (.not file.) [0] =>Hijacker.TornTV
[MD5.00000000000000000000000000000000] [APT] [{90103B30-6120-4D11-88FB-1025BB7313F7}] (...) -- G:\autorun.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C79C6774-B763-44A2-A26E-A18B90EE1DB8}] (...) -- G:\autorun.exe (.not file.) [0]
O39 - APT: - (..) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT: FacebookUpdateTaskUserS-1-5-21-2507926342-3944409784-4027650927-1000Core - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2507926342-3944409784-4027650927-1000Core.job [918]
O39 - APT: FacebookUpdateTaskUserS-1-5-21-2507926342-3944409784-4027650927-1000Core - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2507926342-3944409784-4027650927-1000Core [918]
O39 - APT: FacebookUpdateTaskUserS-1-5-21-2507926342-3944409784-4027650927-1000UA - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2507926342-3944409784-4027650927-1000UA.job [940]
O39 - APT: FacebookUpdateTaskUserS-1-5-21-2507926342-3944409784-4027650927-1000UA - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2507926342-3944409784-4027650927-1000UA [940]
O39 - APT: - (..) -- C:\Windows\Tasks\Torntv V6.0-codedownloader.job [1182] =>PUP.CrossRider
O39 - APT: - (..) -- C:\Windows\Tasks\Torntv V6.0-enabler.job [1092] =>PUP.CrossRider
O39 - APT: Torntv V6.0-updater - (...) -- C:\Windows\Tasks\Torntv V6.0-updater.job [1290] =>PUP.CrossRider
O39 - APT: Torntv V6.0-updater - (...) -- C:\Windows\System32\Tasks\Torntv V6.0-updater [1290] =>PUP.CrossRider
~ Scheduled Task: 16 Scanned in 00mn 06s



---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Internet Explorer - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
~ Active Setup: 10 Scanned in 00mn 00s



---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys
O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
O41 - Driver: C:\Windows\System32\cscsvc.dll (CSC) . (.Microsoft Corporation - Windows Client Side Caching Driver.) - C:\Windows\System32\drivers\csc.sys
O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
O41 - Driver: (klhk) . (.Kaspersky Lab ZAO - KLHK [fre_wlh_x86].) - C:\Windows\System32\DRIVERS\klhk.sys
O41 - Driver: (KLIF) . (.Kaspersky Lab ZAO - Klif Mini-Filter [fre_wlh_x86].) - C:\Windows\System32\DRIVERS\klif.sys
O41 - Driver: (KLIM6) . (.Kaspersky Lab ZAO - Kaspersky Lab Intermediate Network Driver.) - C:\Windows\System32\DRIVERS\klim6.sys
O41 - Driver: (klpd) . (.Kaspersky Lab ZAO - KLPD [fre_wnet_x86].) - C:\Windows\System32\DRIVERS\klpd.sys
O41 - Driver: (kltdi) . (.Kaspersky Lab ZAO - Network filtering component [fre_wxp_x86].) - C:\Windows\System32\DRIVERS\kltdi.sys
O41 - Driver: (kneps) . (.Kaspersky Lab ZAO - KNEPS Power [fre_wxp_x86].) - C:\Windows\System32\DRIVERS\kneps.sys
O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\System32\DRIVERS\mssmbios.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys
O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
~ Drivers: 81 Scanned in 00mn 00s



---\\ Logiciels installés (O42)
O42 - Logiciel: Adobe Flash Player 11 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
O42 - Logiciel: Broadcom 802.11 Network Adapter - (.Broadcom Corporation.) [HKLM] -- Broadcom 802.11 Network Adapter
O42 - Logiciel: BurnAware Free 4.9 - (.Burnaware Technologies.) [HKLM] -- BurnAware Free_is1
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM] -- {64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {51C7AD07-C3F6-4635-8E8A-231306D810FE}
O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
O42 - Logiciel: Convert FLV to MP3 - (.convertflvtomp3.com.) [HKLM] -- {0B026E2A-3026-4608-A1B9-03AD1C8CDF77}_is1
O42 - Logiciel: DW WLAN Card Utility - (.Dell Inc..) [HKLM] -- DW WLAN Card Utility
O42 - Logiciel: Dell Touchpad - (.ALPS ELECTRIC CO., LTD..) [HKLM] -- {9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}
O42 - Logiciel: Facebook Video Calling 3.1.0.521 - (.Skype Limited.) [HKLM] -- {2091F234-EB58-4B80-8C96-8EB78C808CF7}
O42 - Logiciel: Feedback Tool - (.Microsoft Corporation.) [HKLM] -- {13A5E785-5197-4EAD-8EE3-D660271E49BC}
O42 - Logiciel: FormatFactory 2.60 - (.Free Time.) [HKLM] -- FormatFactory
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}
O42 - Logiciel: Haali Media Splitter - (...) [HKLM] -- HaaliMkx
O42 - Logiciel: IDT Audio - (.IDT.) [HKLM] -- {E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM] -- Internet Download Manager
O42 - Logiciel: Kaspersky Internet Security - (.Kaspersky Lab.) [HKLM] -- InstallWIX_{653C1B5A-3287-47B1-8613-0745D4E771C4}
O42 - Logiciel: Kaspersky Internet Security - (.Kaspersky Lab.) [HKLM] -- {653C1B5A-3287-47B1-8613-0745D4E771C4}
O42 - Logiciel: Logiciel d'archivage WinRAR - (...) [HKLM] -- WinRAR archiver
O42 - Logiciel: Mobiconnect - (.ZTE Corporation.) [HKLM] -- {A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}
O42 - Logiciel: Modem Diagnostic Tool - (.Dell.) [HKLM] -- {294EAADF-E50F-4DD8-AD8D-19587EA10512}
O42 - Logiciel: Mozilla Firefox 33.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 33.0.2 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: MultiSkypeLauncher (remove only) - (.MultiSkypeLauncher.) [HKLM] -- MultiSkypeLauncher
O42 - Logiciel: QuickSet32 - (.Dell Inc..) [HKLM] -- {C4972073-2BFE-475D-8441-564EA97DA161}
O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476}
O42 - Logiciel: Realtek USB 2.0 Card Reader - (.Realtek Semiconductor Corp..) [HKLM] -- {96AE7E41-E34E-47D0-AC07-1091A8127911}
O42 - Logiciel: Royale Remixed Theme - (.Copyright © oddbasket, 2007.) [HKLM] -- {993A94A9-DCE3-4774-B35D-D8C74FC1E0BE}
O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701}
O42 - Logiciel: Skype™ 7.1 - (.Skype Technologies S.A..) [HKLM] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
O42 - Logiciel: Total Video Converter 3.11 - (.EffectMatrix Inc..) [HKLM] -- Total Video Converter 3.11_is1
O42 - Logiciel: VLC media player 1.1.11 - (.VideoLAN.) [HKLM] -- VLC media player =>.VideoLAN
O42 - Logiciel: Visual Studio 2012 x86 Redistributables - (.AVG Technologies CZ, s.r.o..) [HKLM] -- {98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}
O42 - Logiciel: WIDCOMM Bluetooth Software - (.Broadcom Corporation.) [HKLM] -- {436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}
O42 - Logiciel: Windows 7 USB/DVD Download Tool - (.Microsoft Corporation.) [HKLM] -- {CCF298AF-9CE1-4B26-B251-486E98A34789}
O42 - Logiciel: Your Uninstaller! 2008 Version 6.0 - (.URSoft, Inc..) [HKLM] -- Your Uninstaller! 2008_is1
O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU] -- uTorrent =>P2P.BitTorrent
~ Logic: 33 Scanned in 00mn 00s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\1ClickDownload] =>PUP.1ClickDownloader
[HKCU\Software\5853dcd9bc69e440] =>Hijacker.Eazel
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider
[HKCU\Software\AppDataLow\Software\Torntv V6.0] =>Hijacker.TornTV
[HKCU\Software\AppDataLow\Software\Yahoo]
[HKCU\Software\AppDataLow]
[HKCU\Software\BI]
[HKCU\Software\BabylonToolbar] =>PUP.Babylon
[HKCU\Software\BcmSetup]
[HKCU\Software\BitTorrent] =>P2P.BitTorrent
[HKCU\Software\BoBrowser] =>PUP.BoBrowser
[HKCU\Software\Broadcom]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\DataMngr] =>PUP.Datamngr
[HKCU\Software\DataMngr_Toolbar] =>PUP.Datamngr
[HKCU\Software\DownloadManager]
[HKCU\Software\Facebook]
[HKCU\Software\FileScout] =>PUP.FileScout
[HKCU\Software\FreeTime]
[HKCU\Software\GNU]
[HKCU\Software\Gabest]
[HKCU\Software\GoforFiles] =>P2P.GoforFiles
[HKCU\Software\Google]
[HKCU\Software\Haali]
[HKCU\Software\HookNetwork]
[HKCU\Software\IM Providers]
[HKCU\Software\InstalledBrowserExtensions] =>PUP.BrowserExtensions
[HKCU\Software\Intel]
[HKCU\Software\KasperskyLab]
[HKCU\Software\Licenses]
[HKCU\Software\Macromedia]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Netscape]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\SWiSHzone.com]
[HKCU\Software\SkypeRS]
[HKCU\Software\Skype]
[HKCU\Software\Softonic] =>Toolbar.Conduit
[HKCU\Software\Trolltech]
[HKCU\Software\URSoft]
[HKCU\Software\Widcomm]
[HKCU\Software\WinRAR]
[HKCU\Software\Yahoo]
[HKCU\Software\ZebHelpProcess Helper]
[HKCU\Software\jZip]
[HKCU\Software\tvp]
[HKLM\Software\5853dcd9bc69e440] =>Hijacker.Eazel
[HKLM\Software\ATI Technologies]
[HKLM\Software\Adobe]
[HKLM\Software\Alps]
[HKLM\Software\AviSynth]
[HKLM\Software\Babylon] =>PUP.Babylon
[HKLM\Software\BcmSetup]
[HKLM\Software\Broadcom]
[HKLM\Software\Clara]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\DataMngr] =>PUP.Datamngr
[HKLM\Software\Dell Computer Corporation]
[HKLM\Software\Dell]
[HKLM\Software\ESET]
[HKLM\Software\GNU]
[HKLM\Software\GoforFiles] =>P2P.GoforFiles
[HKLM\Software\Google]
[HKLM\Software\IDT]
[HKLM\Software\IM Providers]
[HKLM\Software\InstalledOptions]
[HKLM\Software\Intel]
[HKLM\Software\KasperskyLab]
[HKLM\Software\Licenses]
[HKLM\Software\Macromedia]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\ODBC]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\RTLSetup]
[HKLM\Software\Realtek Semiconductor Corp.]
[HKLM\Software\Realtek]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\SRS Labs]
[HKLM\Software\Skype]
[HKLM\Software\Sonic]
[HKLM\Software\SuppHelpDir]
[HKLM\Software\TOSHIBA]
[HKLM\Software\Torntv V6.0] =>Hijacker.TornTV
[HKLM\Software\VideoLAN]
[HKLM\Software\Waves Audio]
[HKLM\Software\WhlProvider]
[HKLM\Software\Widcomm]
[HKLM\Software\WinRAR]
[HKLM\Software\Wow6432Node]
[HKLM\Software\Yahoo]
[HKLM\Software\ZTE Corporation]
[HKLM\Software\ZTEUSBDriverFlag]
[HKLM\Software\iTinySoft]
[HKLM\Software\mozilla.org]
~ Key Software: 179 Scanned in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 19/03/2013 - 07:21:49 - [] ----D C:\Program Files\Adobe
O43 - CFD: 06/05/2014 - 11:50:28 - [0] ----D C:\Program Files\AVG Secure Search =>Toolbar.AVGSearch
O43 - CFD: 18/03/2013 - 13:20:23 - [] ----D C:\Program Files\Broadcom
O43 - CFD: 18/04/2013 - 10:43:03 - [] ----D C:\Program Files\BurnAware Free
O43 - CFD: 19/03/2013 - 07:25:03 - [] ----D C:\Program Files\CCleaner
O43 - CFD: 20/03/2013 - 07:59:36 - [] ----D C:\Program Files\Cisco
O43 - CFD: 23/02/2015 - 18:56:59 - [] ----D C:\Program Files\Common Files
O43 - CFD: 09/10/2013 - 16:19:58 - [] ----D C:\Program Files\Convert FLV to MP3
O43 - CFD: 20/03/2013 - 07:24:19 - [] ----D C:\Program Files\Dell
O43 - CFD: 20/03/2013 - 07:21:22 - [] ----D C:\Program Files\DellTPad
O43 - CFD: 14/07/2009 - 10:01:30 - [] ----D C:\Program Files\DVD Maker
O43 - CFD: 26/02/2015 - 20:10:48 - [] ----D C:\Program Files\Enigma Software Group =>PUP.EnigmaSoftware
O43 - CFD: 20/08/2014 - 14:22:39 - [] ----D C:\Program Files\Feedback Tool
O43 - CFD: 18/03/2013 - 13:05:57 - [] -SH-D C:\Program Files\Fichiers communs
O43 - CFD: 09/10/2013 - 13:06:58 - [] ----D C:\Program Files\FreeTime
O43 - CFD: 07/03/2015 - 16:06:52 - [] ----D C:\Program Files\Google
O43 - CFD: 07/03/2015 - 08:03:27 - [0] ----D C:\Program Files\GUM1C08.tmp
O43 - CFD: 22/08/2014 - 12:28:30 - [0] ----D C:\Program Files\GUMECFE.tmp
O43 - CFD: 02/03/2014 - 20:48:52 - [] ----D C:\Program Files\HSPA USB Modem
O43 - CFD: 20/03/2013 - 08:06:10 - [] ----D C:\Program Files\IDT
O43 - CFD: 15/06/2014 - 19:09:18 - [] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 20/03/2013 - 07:34:13 - [] ----D C:\Program Files\Intel
O43 - CFD: 05/02/2015 - 13:38:39 - [] ----D C:\Program Files\Internet Download Manager
O43 - CFD: 20/08/2014 - 14:59:57 - [] ----D C:\Program Files\Internet Explorer
O43 - CFD: 27/02/2015 - 19:04:05 - [] ----D C:\Program Files\Kaspersky Lab
O43 - CFD: 14/07/2009 - 10:01:21 - [] ----D C:\Program Files\Microsoft Games
O43 - CFD: 03/02/2015 - 20:17:13 - [] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 07/01/2015 - 20:31:57 - [] ----D C:\Program Files\Mobiconnect
O43 - CFD: 20/03/2013 - 08:08:52 - [] ----D C:\Program Files\Modem Diagnostic Tool
O43 - CFD: 22/09/2013 - 19:53:08 - [] ----D C:\Program Files\Movies Toolbar =>PUP.MoviesToolbar
O43 - CFD: 07/03/2015 - 08:08:13 - [] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 07/03/2015 - 08:08:13 - [] ----D C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 14/07/2009 - 05:52:30 - [] ----D C:\Program Files\MSBuild
O43 - CFD: 28/08/2014 - 13:39:35 - [] ----D C:\Program Files\MultiSkypeLauncher
O43 - CFD: 20/03/2013 - 08:04:08 - [] ----D C:\Program Files\Realtek
O43 - CFD: 14/07/2009 - 05:52:30 - [] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 10/08/2013 - 12:34:10 - [] ----D C:\Program Files\ReviverSoft
O43 - CFD: 18/02/2015 - 20:06:37 - [] R---D C:\Program Files\Skype
O43 - CFD: 07/01/2015 - 15:44:38 - [] ----D C:\Program Files\SupportAppCB
O43 - CFD: 25/02/2015 - 18:03:26 - [] ----D C:\Program Files\Torntv V6.0 =>Hijacker.TornTV
O43 - CFD: 25/11/2013 - 11:39:55 - [] ----D C:\Program Files\TornTV.com =>Hijacker.TornTV
O43 - CFD: 19/03/2013 - 07:35:03 - [] ----D C:\Program Files\Total Video Converter
O43 - CFD: 14/07/2009 - 05:53:23 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 05/11/2014 - 20:51:58 - [0] ----D C:\Program Files\uTorrent =>P2P.µTorrent
O43 - CFD: 19/03/2013 - 07:39:30 - [] ----D C:\Program Files\VideoLAN
O43 - CFD: 18/03/2013 - 13:46:33 - [] ----D C:\Program Files\WIDCOMM
O43 - CFD: 14/07/2009 - 09:39:39 - [] ----D C:\Program Files\Windows Defender
O43 - CFD: 05/08/2013 - 12:06:23 - [] ----D C:\Program Files\Windows Journal
O43 - CFD: 05/08/2013 - 12:06:25 - [] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 05/08/2013 - 12:06:21 - [] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 18/03/2013 - 13:05:57 - [] ----D C:\Program Files\Windows NT
O43 - CFD: 14/07/2009 - 09:39:39 - [] ----D C:\Program Files\Windows Photo Viewer
O43 - CFD: 14/07/2009 - 05:52:32 - [] ----D C:\Program Files\Windows Portable Devices
O43 - CFD: 14/07/2009 - 09:39:39 - [] ----D C:\Program Files\Windows Sidebar
O43 - CFD: 19/03/2013 - 07:16:41 - [] ----D C:\Program Files\WinRAR
O43 - CFD: 20/08/2014 - 21:13:46 - [0] ----D C:\Program Files\WWW.HOSTJSC.NET
O43 - CFD: 26/07/2014 - 02:40:49 - [0] ----D C:\Program Files\Yahoo!
O43 - CFD: 26/02/2015 - 16:41:13 - [] ----D C:\Program Files\Your Uninstaller 2008
O43 - CFD: 07/03/2015 - 16:20:15 - [] ----D C:\Program Files\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 19/03/2013 - 07:22:00 - [] ----D C:\Program Files\Common Files\Adobe
O43 - CFD: 23/02/2015 - 18:56:59 - [] ----D C:\Program Files\Common Files\ClaraUpdater =>Adware.SupTab
O43 - CFD: 20/03/2013 - 07:34:14 - [] ----D C:\Program Files\Common Files\Intel
O43 - CFD: 18/03/2013 - 14:15:59 - [] ----D C:\Program Files\Common Files\microsoft shared
O43 - CFD: 18/03/2013 - 14:14:15 - [] ----D C:\Program Files\Common Files\postureAgent
O43 - CFD: 14/07/2009 - 03:37:05 - [] ----D C:\Program Files\Common Files\Services
O43 - CFD: 22/12/2014 - 06:46:21 - [] ----D C:\Program Files\Common Files\Skype
O43 - CFD: 14/07/2009 - 03:37:05 - [] ----D C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 05/08/2013 - 12:06:26 - [] ----D C:\Program Files\Common Files\System
O43 - CFD: 19/04/2013 - 11:47:12 - [] ----D C:\ProgramData\Adobe
O43 - CFD: 14/07/2009 - 05:53:55 - [] -SH-D C:\ProgramData\Application Data
O43 - CFD: 27/02/2015 - 18:52:07 - [] ----D C:\ProgramData\AVAST Software
O43 - CFD: 18/03/2013 - 13:05:57 - [] -SH-D C:\ProgramData\Bureau
O43 - CFD: 27/11/2013 - 12:52:09 - [] --H-D C:\ProgramData\Common Files
O43 - CFD: 20/03/2013 - 07:24:21 - [] ----D C:\ProgramData\Dell
O43 - CFD: 14/07/2009 - 05:53:55 - [] -SH-D C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 05:53:55 - [] -SH-D C:\ProgramData\Documents
O43 - CFD: 09/10/2013 - 05:28:52 - [0] ----D C:\ProgramData\DSearchLink =>Toolbar.DeltaSearch
O43 - CFD: 18/03/2013 - 13:05:57 - [] -SH-D C:\ProgramData\Favoris
O43 - CFD: 14/07/2009 - 05:53:55 - [] -SH-D C:\ProgramData\Favorites
O43 - CFD: 16/04/2013 - 17:55:46 - [0] ----D C:\ProgramData\IBUpdaterService =>Adware.InstallBrain
O43 - CFD: 01/04/2013 - 16:54:21 - [0] ----D C:\ProgramData\IDM
O43 - CFD: 07/03/2015 - 16:07:27 - [] ----D C:\ProgramData\Kaspersky Lab
O43 - CFD: 18/03/2013 - 13:05:57 - [] -SH-D C:\ProgramData\Menu Démarrer
O43 - CFD: 30/12/2013 - 21:49:51 - [] ----D C:\ProgramData\MFAData
O43 - CFD: 31/03/2013 - 18:42:47 - [] -S--D C:\ProgramData\Microsoft
O43 - CFD: 18/03/2013 - 13:05:57 - [] -SH-D C:\ProgramData\Modèles
O43 - CFD: 16/04/2013 - 13:31:12 - [] ----D C:\ProgramData\Mozilla
O43 - CFD: 18/03/2013 - 19:02:00 - [] ----D C:\ProgramData\Office Genuine Advantage
O43 - CFD: 09/02/2014 - 14:12:32 - [0] ----D C:\ProgramData\PreventPlay
O43 - CFD: 10/08/2013 - 12:34:27 - [] ----D C:\ProgramData\ReviverSoft
O43 - CFD: 18/02/2015 - 20:06:52 - [] ----D C:\ProgramData\Skype
O43 - CFD: 14/07/2009 - 05:53:55 - [] -SH-D C:\ProgramData\Start Menu
O43 - CFD: 06/03/2015 - 08:07:57 - [0] ---AD C:\ProgramData\TEMP
O43 - CFD: 14/07/2009 - 05:53:55 - [] -SH-D C:\ProgramData\Templates
O43 - CFD: 26/07/2014 - 02:40:44 - [] ----D C:\ProgramData\Yahoo!
O43 - CFD: 20/03/2013 - 07:30:47 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 18/03/2013 - 13:02:42 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 18/04/2013 - 10:43:03 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BurnAware Free
O43 - CFD: 19/03/2013 - 07:25:03 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
O43 - CFD: 09/10/2013 - 16:19:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Convert FLV to MP3
O43 - CFD: 20/03/2013 - 07:59:18 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DW WLAN
O43 - CFD: 18/03/2013 - 13:02:39 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 22/08/2014 - 11:25:19 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth =>.Google Inc
O43 - CFD: 16/04/2013 - 17:55:45 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
O43 - CFD: 22/12/2014 - 06:46:28 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 27/02/2015 - 19:05:27 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
O43 - CFD: 14/07/2009 - 05:42:30 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 19/11/2014 - 21:26:18 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mobiconnect
O43 - CFD: 20/03/2013 - 08:08:55 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outil de diagnostic de modem
O43 - CFD: 17/04/2013 - 17:01:46 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Royale Remixed Theme
O43 - CFD: 18/09/2014 - 17:10:11 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 20/03/2013 - 07:25:52 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 14/07/2009 - 10:00:32 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 19/03/2013 - 07:34:59 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Total Video Converter
O43 - CFD: 05/02/2015 - 13:34:53 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
O43 - CFD: 19/03/2013 - 07:16:41 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 06/11/2014 - 13:26:53 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Your Uninstaller! 2008
O43 - CFD: 07/03/2015 - 16:20:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP =>.Nicolas Coolman
O43 - CFD: 02/04/2013 - 16:10:06 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\Adobe
O43 - CFD: 16/04/2013 - 13:30:46 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\Babylon =>PUP.Babylon
O43 - CFD: 07/03/2015 - 09:27:31 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\DMCache
O43 - CFD: 02/04/2014 - 17:24:09 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\dvdcss
O43 - CFD: 27/02/2015 - 14:07:27 - [0] ----D C:\Users\HAFSAOUI\AppData\Roaming\File Scout =>PUP.FileScout
O43 - CFD: 16/04/2013 - 13:30:49 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\GoforFiles =>P2P.GoforFiles
O43 - CFD: 18/03/2013 - 13:06:20 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\Identities
O43 - CFD: 06/02/2015 - 04:55:58 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\IDM
O43 - CFD: 03/04/2013 - 17:56:26 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\IDT
O43 - CFD: 18/03/2013 - 14:13:16 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\InstallShield
O43 - CFD: 02/04/2013 - 16:10:56 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\Macromedia
O43 - CFD: 14/07/2009 - 10:00:32 - [0] ----D C:\Users\HAFSAOUI\AppData\Roaming\Media Center Programs
O43 - CFD: 14/06/2013 - 19:45:02 - [] -S--D C:\Users\HAFSAOUI\AppData\Roaming\Microsoft
O43 - CFD: 05/11/2014 - 19:43:23 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\Mozilla
O43 - CFD: 28/08/2014 - 13:41:08 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\MultiSkypeLauncher
O43 - CFD: 16/04/2013 - 17:56:13 - [0] ----D C:\Users\HAFSAOUI\AppData\Roaming\PerformerSoft =>PUP.PerformerSoft
O43 - CFD: 07/03/2015 - 16:20:00 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\Skype
O43 - CFD: 16/04/2013 - 17:53:35 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\SpeedanAlysis =>PUP.SpeedAnalysis
O43 - CFD: 27/11/2013 - 12:56:47 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\TuneUp Software
O43 - CFD: 19/03/2013 - 07:18:16 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\URSoft
O43 - CFD: 26/02/2015 - 15:30:27 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\uTorrent =>P2P.µTorrent
O43 - CFD: 02/03/2015 - 13:57:31 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\vlc
O43 - CFD: 18/03/2013 - 13:20:12 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\WinBatch
O43 - CFD: 19/03/2013 - 07:17:09 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\WinRAR
O43 - CFD: 11/07/2014 - 22:36:37 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\Yahoo!
O43 - CFD: 11/08/2013 - 10:19:52 - [0] ----D C:\Users\HAFSAOUI\AppData\Roaming\Youtube Downloader HD
O43 - CFD: 07/03/2015 - 16:43:53 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 07/03/2014 - 14:02:19 - [] ----D C:\Users\HAFSAOUI\AppData\Local\4473
O43 - CFD: 23/08/2014 - 12:45:38 - [] ----D C:\Users\HAFSAOUI\AppData\Local\Adobe
O43 - CFD: 18/03/2013 - 13:06:06 - [] -SH-D C:\Users\HAFSAOUI\AppData\Local\Application Data
O43 - CFD: 18/03/2013 - 18:59:38 - [] ----D C:\Users\HAFSAOUI\AppData\Local\Apps
O43 - CFD: 08/10/2013 - 19:28:16 - [] ----D C:\Users\HAFSAOUI\AppData\Local\Babylon =>PUP.Babylon
O43 - CFD: 23/02/2015 - 18:57:09 - [] ----D C:\Users\HAFSAOUI\AppData\Local\BoBrowser =>PUP.BoBrowser
O43 - CFD: 18/03/2013 - 13:49:30 - [] ----D C:\Users\HAFSAOUI\AppData\Local\Broadcom
O43 - CFD: 18/04/2013 - 10:18:18 - [] ----D C:\Users\HAFSAOUI\AppData\Local\Bundled software uninstaller =>Adware.MegaSearch
O43 - CFD: 21/02/2014 - 21:49:43 - [] ----D C:\Users\HAFSAOUI\AppData\Local\Diagnostics
O43 - CFD: 18/12/2013 - 22:24:23 - [] ----D C:\Users\HAFSAOUI\AppData\Local\ElevatedDiagnostics
O43 - CFD: 01/05/2014 - 00:02:40 - [] ----D C:\Users\HAFSAOUI\AppData\Local\Facebook
O43 - CFD: 07/03/2015 - 08:32:42 - [] ----D C:\Users\HAFSAOUI\AppData\Local\Google
O43 - CFD: 18/03/2013 - 13:06:06 - [] -SH-D C:\Users\HAFSAOUI\AppData\Local\Historique
O43 - CFD: 25/11/2013 - 05:27:00 - [0] ----D C:\Users\HAFSAOUI\AppData\Local\jZip
O43 - CFD: 19/04/2013 - 16:55:15 - [] ----D C:\Users\HAFSAOUI\AppData\Local\Macromedia
O43 - CFD: 27/11/2013 - 12:52:08 - [] ----D C:\Users\HAFSAOUI\AppData\Local\MFAData
O43 - CFD: 22/12/2014 - 06:45:52 - [] ----D C:\Users\HAFSAOUI\AppData\Local\Microsoft
O43 - CFD: 15/06/2014 - 19:09:37 - [] ----D C:\Users\HAFSAOUI\AppData\Local\Mozilla
O43 - CFD: 26/08/2014 - 18:40:42 - [] ----D C:\Users\HAFSAOUI\AppData\Local\Skype
O43 - CFD: 07/03/2015 - 16:38:23 - [] ----D C:\Users\HAFSAOUI\AppData\Local\Temp
O43 - CFD: 18/03/2013 - 13:06:06 - [] -SH-D C:\Users\HAFSAOUI\AppData\Local\Temporary Internet Files
O43 - CFD: 04/08/2013 - 13:02:09 - [] ----D C:\Users\HAFSAOUI\AppData\Local\VirtualStore
O43 - CFD: 14/07/2009 - 05:42:04 - [] R---D C:\Users\HAFSAOUI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 05/08/2013 - 12:10:36 - [] R---D C:\Users\HAFSAOUI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 09/02/2015 - 18:44:26 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
O43 - CFD: 22/12/2014 - 06:46:32 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 28/08/2014 - 13:39:35 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MultiSkypeLauncher
O43 - CFD: 01/12/2014 - 06:59:42 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Périphériques Bluetooth
O43 - CFD: 28/08/2014 - 13:39:35 - [] R---D C:\Users\HAFSAOUI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 18/03/2013 - 18:59:38 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
O43 - CFD: 19/03/2013 - 07:16:41 - [] ----D C:\Users\HAFSAOUI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
~ Program Folder: 176 Scanned in 00mn 00s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 02/03/2015 - 15:36:57 ---A- . (...) -- C:\Windows\setuperr.log [0]
O44 - LFC:[MD5.AF36123BCD62AAFCAAE5BFED2FD1DF6A] - 03/03/2015 - 12:21:25 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1549700]
O44 - LFC:[MD5.2EA94CB373AE05FBE40EB8027DA883E0] - 03/03/2015 - 12:21:25 ---A- . (...) -- C:\Windows\System32\perfc009.dat [106388]
O44 - LFC:[MD5.1B2F8271ED208300C83171EB692303BC] - 03/03/2015 - 12:21:25 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [130754]
O44 - LFC:[MD5.B54C311A0A26A367A50C15ED75C910C6] - 03/03/2015 - 12:21:25 ---A- . (...) -- C:\Windows\System32\perfh009.dat [616008]
O44 - LFC:[MD5.8DE42622F85B608666BC53A89A0145FF] - 03/03/2015 - 12:21:25 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [704480]
O44 - LFC:[MD5.6BEEA80A2503F4AC743FAF0F959631A9] - 07/03/2015 - 16:06:53 ---A- . (...) -- C:\Windows\PFRO.log [1166]
O44 - LFC:[MD5.4FAEA311E07696859831A5205CDD4F32] - 07/03/2015 - 16:06:59 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.A48D8C80F99A5473D174152BE48B05B5] - 07/03/2015 - 16:07:07 ---A- . (...) -- C:\Windows\setupact.log [952]
O44 - LFC:[MD5.C46A6D9E09DB96B44CA984F8FF901168] - 07/03/2015 - 16:43:00 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1716660]
O44 - LFC:[MD5.C3FBD1C844EEFCF21B4E791F55F458B8] - 27/02/2015 - 06:02:08 ---A- . (...) -- C:\Windows\System32\2015-02-27-05-02-05.084-AvastVBoxSVC.exe-2540.log [197]
O44 - LFC:[MD5.6669BD8C76033B9E0516E6A5E03C9CDC] - 27/02/2015 - 06:09:29 ---A- . (...) -- C:\Windows\System32\2015-02-27-05-02-12.089-aswFe.exe-4988.log [247]
O44 - LFC:[MD5.D937D97AC80C6E7D1C6307F40267E752] - 27/02/2015 - 06:09:40 ---A- . (...) -- C:\Windows\System32\2015-02-27-05-09-39.033-aswFe.exe-4820.log [247]
O44 - LFC:[MD5.FCE39E8BE6BDDD29957628C66CE077DE] - 27/02/2015 - 13:16:36 ---A- . (...) -- C:\Windows\System32\2015-02-27-12-16-35.081-AvastVBoxSVC.exe-2500.log [197]
O44 - LFC:[MD5.9C8ED8E7C51106650A3A9FD809D39385] - 27/02/2015 - 18:20:20 ---A- . (...) -- C:\Windows\System32\2015-02-27-17-20-20.062-AvastVBoxSVC.exe-2504.log [197]
O44 - LFC:[MD5.81017E96D63529A42EE67108E35DADE3] - 27/02/2015 - 18:33:36 ---A- . (...) -- C:\Windows\System32\2015-02-27-17-33-35.062-AvastVBoxSVC.exe-3132.log [197]
O44 - LFC:[MD5.C02EC9EEE4E3CFEF82478B9C345F94FE] - 27/02/2015 - 19:03:45 ---A- . (.Kaspersky Lab ZAO - KLHK [fre_wlh_x86].) -- C:\Windows\System32\Drivers\klhk.sys [34400]
O44 - LFC:[MD5.3EAA179537FF9A3C9071E868C07275FA] - 27/02/2015 - 23:45:46 ---A- . (.Kaspersky Lab ZAO - Filter Core [fre_wlh_x86].) -- C:\Windows\System32\Drivers\klflt.sys [112136]
O44 - LFC:[MD5.894A09BF826E79C1971ADE0121F2B607] - 27/02/2015 - 23:45:46 ---A- . (.Kaspersky Lab ZAO - Klif Mini-Filter [fre_wlh_x86].) -- C:\Windows\System32\Drivers\klif.sys [644808]
~ Files: 19 Scanned in 00mn 04s



---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.5433F3BC91F63DC8F40AD3469DD74CA6] - 07/03/2015 - 16:07:55 ---A- - C:\Windows\Prefetch\BOBROWSER.EXE-217F44CD.pf =>PUP.BoBrowser
~ Prefetcher: 1 Scanned in 00mn 00s



---\\ Déni du service (Local Security Authority) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll
~ LSA: 8 Scanned in 00mn 00s



---\\ Contrôle du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\Wdf01000.sys . (.Microsoft Corporation - Runtime de l’infrastructure de pilotes en mode noyau.) -- C:\Windows\System32\Drivers\Wdf01000.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\Wdf01000.sys . (.Microsoft Corporation - Runtime de l’infrastructure de pilotes en mode noyau.) -- C:\Windows\System32\Drivers\Wdf01000.sys
~ CSB: 15 Scanned in 00mn 00s



---\\ Clé de registre Shell MountPoints2 (MPSK) (O51)
O51 - MPSK:{0794aeef-1cac-11e3-bc99-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{082b7a6f-9190-11e3-a50b-18037396134f}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{12c725a0-1c74-11e3-a7b2-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{1452dbef-1c87-11e3-9618-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{2184ff7f-42ef-11e3-b44b-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{28dbc461-9aee-11e3-b6a5-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{291c5140-1c6f-11e3-b7f5-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{3662d922-63bc-11e3-a348-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{3c00a3e0-6875-11e3-9fd5-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{3c506c73-918b-11e3-a583-18037396134f}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{3f881aae-a187-11e3-ab53-806e6f6e6963}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{422dacd7-700e-11e4-9632-18037396134f}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{444405ac-928c-11e3-afd5-18037396134f}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{44516ba0-6e5a-11e4-90bd-18037396134f}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{46bc6874-9e11-11e3-b4be-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{4774e560-b2a4-11e2-bd22-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{4ca4b7d5-b2dd-11e2-a3e6-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{4ca4b80a-b2dd-11e2-a3e6-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{4e2a4430-f495-11e3-ad69-18037396134f}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{4fd62b9d-09de-11e3-bc1e-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{526cbfa0-426a-11e3-846f-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{52b87645-9d94-11e3-a831-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{5d7e7c8a-be6c-11e2-bfc9-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{65e10b7c-6826-11e3-8938-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{6670a162-edab-11e2-bd43-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{6ddea6ec-a13d-11e3-aed9-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{73f9c542-bffd-11e2-adf0-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{742501ca-bfbb-11e2-803c-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{74f71a0e-9401-11e3-a297-18037396134f}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{7822d8fc-bbbf-11e3-b22e-18037396134f}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{82791800-b2a8-11e2-a388-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{83ec8480-9381-11e2-89b0-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{841c2bca-c1dd-11e2-ae1f-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{844a6555-619b-11e3-b975-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{85b94718-912d-11e2-8c25-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{8a956722-beb1-11e2-92d8-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{913da1c4-96e6-11e2-ae2f-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{9215e7e1-1c85-11e3-82e2-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{9555d2c2-e0cc-11e2-b98f-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{95b1f6a2-c140-11e2-ba43-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{98724104-9b34-11e3-919e-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{991af14a-ba5e-11e2-ba6e-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{9a342b1f-42ec-11e3-8f50-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{9a95deab-c04d-11e2-ae79-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{9bb55661-b42e-11e2-a07f-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{9d110944-bb96-11e2-aeae-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{a076d720-42ed-11e3-8ea4-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{a2349681-6870-11e3-aee8-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{a36daa26-9062-11e2-8844-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{a36daa3c-9062-11e2-8844-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{aca3c222-bda9-11e2-ba66-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{af2fc1c2-bf33-11e2-b0e4-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{b117ad22-bda0-11e2-844b-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{b35293e5-a0ab-11e3-bc6f-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{be288788-c2e3-11e2-962b-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{c2e248fc-6971-11e4-8d6c-18037396134f}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{c32acf49-b348-11e2-a23b-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{c32acf6a-b348-11e2-a23b-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{c482d142-bd24-11e2-a780-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{c6d9f410-7029-11e4-bade-18037396134f}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{ca7e8b6f-f4ba-11e3-9fc3-18037396134f}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{cb0399f0-9a65-11e3-b709-18037396134f}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{cfeca181-9edc-11e3-9484-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{deb6e592-92bb-11e2-abbd-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{e0da2581-b434-11e2-abdb-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{e2e26722-b4b6-11e2-8b0f-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{e394985e-f4d0-11e3-951e-18037396134f}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{e3bfce7f-96d9-11e2-acae-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{e3d61510-8fdb-11e2-ac05-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{e3d61515-8fdb-11e2-ac05-ccaf78a6d408}\AutoRun\command. (...) -- H:\autorun.exe (.not file.)
O51 - MPSK:{e5de94cb-c1e1-11e2-aed2-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{e8ff97e7-b2a6-11e2-a2e7-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{eddf023d-90d1-11e2-8d36-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{ee0865d5-9d8d-11e3-8351-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{eef192c5-9ee4-11e3-acdd-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{f2ede201-9ddd-11e3-af87-18037396134f}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{f4eccb03-ee58-11e2-93a4-ccaf78a6d408}\AutoRun\command. (...) -- G:\autorun.exe (.not file.)
O51 - MPSK:{fcba24d3-2099-11e4-add2-ccaf78a6d408}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
~ TDSD: 3 Scanned in 00mn 00s



---\\ Enumération des clés de registre SecurityProviders (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
~ MSCP: 2 Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "SoftwareSASGeneration"=1
~ MWPS: 17 Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDriveTypeAutoRun"=60
~ MWPE Keys: 1 Scanned in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976]
O58 - SDL:14/07/2009 - 02:26:17 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [297552]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\Drivers\adpu320.sys [146512]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [14400]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [79952]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows fa.) -- C:\Windows\System32\Drivers\amdsbs.sys [159312]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [23616]
O58 - SDL:31/03/2011 - 19:34:32 ---A- . (.Alps Electric Co., Ltd. - Alps Touch Pad Driver.) -- C:\Windows\System32\Drivers\Apfiltr.sys [294520]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [76368]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [86608]
O58 - SDL:24/10/2011 - 05:39:40 ---A- . (.AVEO - aveodcnt.) -- C:\Windows\System32\Drivers\AVEOdcnt.sys [278528]
O58 - SDL:13/07/2009 - 23:02:49 ---A- . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gigabit Ethernet..) -- C:\Windows\System32\Drivers\b57nd60x.sys [229888]
O58 - SDL:20/03/2013 - 07:58:09 ---A- . (.Broadcom Corporation - Broadcom iLine10(tm) PCI Network Adapter Proxy Protocol Driver.) -- C:\Windows\System32\Drivers\bcm42rly.sys [18496]
O58 - SDL:18/03/2013 - 14:14:49 ---A- . (.Broadcom Corporation - Broadcom 802.11 Network Adapter wireless driver.) -- C:\Windows\System32\Drivers\BCMWL6.SYS [4247616]
O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [13568]
O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [5248]
O58 - SDL:14/07/2009 - 01:57:25 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [272128]
O58 - SDL:13/07/2009 - 23:53:32 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [62336]
O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [12160]
O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [11904]
O58 - SDL:08/02/2011 - 13:13:04 ---A- . (.Broadcom Corporation. - Broadcom Bluetooth USB AMP Filter for Windows Vista.) -- C:\Windows\System32\Drivers\btwampfl.sys [302120]
O58 - SDL:08/02/2011 - 13:13:02 ---A- . (.Broadcom Corporation. - Bluetooth Audio Device.) -- C:\Windows\System32\Drivers\btwaudio.sys [93224]
O58 - SDL:08/02/2011 - 13:13:02 ---A- . (.Broadcom Corporation. - Broadcom Bluetooth AVDT Service.) -- C:\Windows\System32\Drivers\btwavdt.sys [114728]
O58 - SDL:08/02/2011 - 13:13:02 ---A- . (.Broadcom Corporation. - Broadcom Bluetooth L2CAP Service.) -- C:\Windows\System32\Drivers\btwl2cap.sys [33832]
O58 - SDL:08/02/2011 - 13:13:02 ---A- . (.Broadcom Corporation. - Bluetooth Remote Control HID Minidriver.) -- C:\Windows\System32\Drivers\btwrchid.sys [18728]
O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbdx.sys [430080]
O58 - SDL:14/07/2009 - 02:26:21 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [15952]
O58 - SDL:29/08/2008 - 17:54:40 ---A- . (.Mobile Connector - USB/Serial Device Driver.) -- C:\Windows\System32\Drivers\cmusbser.sys [103552]
O58 - SDL:14/12/2009 - 12:44:24 ---A- . (.Infowatch - Cryptographic Algorithm Lib Driver..) -- C:\Windows\System32\Drivers\CSCrySec.sys [88632]
O58 - SDL:14/12/2009 - 12:44:24 ---A- . (.Infowatch - Virtual Volume Container Driver (wxp).) -- C:\Windows\System32\Drivers\CSVirtualDiskDrv.sys [39352]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\Drivers\djsvs.sys [70720]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712]
O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbdx.sys [3100160]
O58 - SDL:13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624]
O58 - SDL:18/09/2009 - 04:54:14 ---A- . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\Drivers\HECI.sys [41088]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [67152]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332352]
O58 - SDL:29/11/2014 - 01:37:06 ---A- . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\Drivers\idmwfp.sys [115752]
O58 - SDL:25/03/2011 - 18:12:06 ---A- . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\Drivers\igdkmd32.sys [10542080]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [41040]
O58 - SDL:26/02/2010 - 17:31:22 ---A- . (.Intel Corporation - Intel(R) Turbo Boost Technology Driver.) -- C:\Windows\System32\Drivers\Impcd.sys [132480]
O58 - SDL:15/10/2010 - 01:27:18 ---A- . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\Drivers\IntcDAud.sys [269824]
O58 - SDL:20/02/2014 - 12:59:02 ---A- . (.Kaspersky Lab ZAO - Kaspersky Unified Driver.) -- C:\Windows\System32\Drivers\kl1.sys [135264]
O58 - SDL:27/02/2015 - 23:45:46 ---A- . (.Kaspersky Lab ZAO - Filter Core [fre_wlh_x86].) -- C:\Windows\System32\Drivers\klflt.sys [112136]
O58 - SDL:10/04/2014 - 17:25:32 ---A- . (.Kaspersky Lab ZAO - KLHK [fre_wlh_x86].) -- C:\Windows\System32\Drivers\klhk.sys [34400]
O58 - SDL:27/02/2015 - 23:45:46 ---A- . (.Kaspersky Lab ZAO - Klif Mini-Filter [fre_wlh_x86].) -- C:\Windows\System32\Drivers\klif.sys [644808]
O58 - SDL:25/02/2014 - 13:09:02 ---A- . (.Kaspersky Lab ZAO - Kaspersky Lab Intermediate Network Driver.) -- C:\Windows\System32\Drivers\klim6.sys [25696]
O58 - SDL:28/03/2014 - 17:51:02 ---A- . (.Kaspersky Lab ZAO - KLKBDFLT Keyboard Device Filter [fre_wlh_x86].) -- C:\Windows\System32\Drivers\klkbdflt.sys [24672]
O58 - SDL:08/08/2013 - 17:10:58 ---A- . (.Kaspersky Lab ZAO - KLMOUFLT Mouse Device Filter [fre_wlh_x86].) -- C:\Windows\System32\Drivers\klmouflt.sys [25696]
O58 - SDL:12/04/2013 - 15:34:48 ---A- . (.Kaspersky Lab ZAO - KLPD [fre_wnet_x86].) -- C:\Windows\System32\Drivers\klpd.sys [14432]
O58 - SDL:25/03/2014 - 16:26:04 ---A- . (.Kaspersky Lab ZAO - Network filtering component [fre_wxp_x86].) -- C:\Windows\System32\Drivers\kltdi.sys [45024]
O58 - SDL:26/03/2014 - 17:05:26 ---A- . (.Kaspersky Lab ZAO - KNEPS Power [fre_wxp_x86].) -- C:\Windows\System32\Drivers\kneps.sys [145888]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [95824]
O58 - SDL:14/07/2009 - 02:20:37 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [89168]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [54864]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [96848]
O58 - SDL:29/08/2011 - 11:42:56 ---A- . (.MBB Incorporated - CDROM Filter.) -- C:\Windows\System32\Drivers\massfilter.sys [9216]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7 for x86.) -- C:\Windows\System32\Drivers\megasas.sys [30800]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [235584]
O58 - SDL:14/07/2009 - 02:20:44 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [44624]
O58 - SDL:20/03/2013 - 07:58:13 ---A- . (.CACE Technologies, Inc. - npf.sys (NT5/6 x86) Kernel Driver.) -- C:\Windows\System32\Drivers\npf.sys [50704]
O58 - SDL:14/07/2009 - 02:20:44 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117312]
O58 - SDL:14/07/2009 - 02:20:44 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [142416]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1383488]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [106064]
O58 - SDL:16/05/2011 - 23:55:28 ---A- . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.20 32-bit Driver.) -- C:\Windows\System32\Drivers\Rt86win7.sys [391272]
O58 - SDL:29/10/2010 - 17:11:08 ---A- . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/Vista/Win7.) -- C:\Windows\System32\Drivers\RtsUStor.sys [197224]
O58 - SDL:13/07/2009 - 21:50:20 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [20480]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [40016]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [77888]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072]
O58 - SDL:27/05/2011 - 12:06:16 ---A- . (.IDT, Inc. - IDT PC Audio TPE.) -- C:\Windows\System32\Drivers\stwrt.sys [441856]
O58 - SDL:14/07/2009 - 02:19:10 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [16976]
O58 - SDL:14/07/2009 - 02:19:11 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [141904]
O58 - SDL:29/08/2011 - 11:42:56 ---A- . (.ZTE Incorporated - ZTE Incorporated.) -- C:\Windows\System32\Drivers\ZTEusbmdm6k.sys [107520]
O58 - SDL:29/08/2011 - 11:42:56 ---A- . (.ZTE Incorporated - ZTE Incorporated.) -- C:\Windows\System32\Drivers\ZTEusbnmea.sys [107520]
O58 - SDL:29/08/2011 - 11:42:56 ---A- . (.ZTE Incorporated - ZTE Incorporated.) -- C:\Windows\System32\Drivers\ZTEusbser6k.sys [107520]
O58 - SDL:13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672]
~ Drivers: 92 Scanned in 00mn 03s



---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\GoogleCrashHandler.exe [223112]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\GoogleCrashHandler64.exe [273800]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\GoogleUpdateBroker.exe [51080]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\GoogleUpdateOnDemand.exe [51080]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdate.dll [847752]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_am.dll [858504]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_ar.dll [859528]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_bg.dll [863112]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_bn.dll [862088]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_ca.dll [862600]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_cs.dll [862088]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_da.dll [862088]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_de.dll [864136]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_el.dll [864136]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_en-GB.dll [861064]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_en.dll [861064]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_es-419.dll [862088]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_es.dll [864136]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_et.dll [861064]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_fa.dll [860552]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_fi.dll [862088]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_fil.dll [863112]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_fr.dll [863624]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_gu.dll [862088]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_hi.dll [862088]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_hr.dll [862600]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_hu.dll [863112]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_id.dll [861576]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_is.dll [861576]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_it.dll [863624]
O61 - LFC: 07/03/2015 - 16:44:24 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_iw.dll [859016]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc.) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_ko.dll [856456]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_ja.dll [857480]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_kn.dll [862600]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_lv.dll [863112]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_ml.dll [865160]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_mr.dll [862088]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_ms.dll [861576]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_nl.dll [863624]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_no.dll [862600]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_pl.dll [863112]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_pt-BR.dll [862088]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_pt-PT.dll [862600]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_ro.dll [863112]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_ru.dll [861576]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_sk.dll [862600]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_sl.dll [862600]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_sr.dll [862088]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_sv.dll [862088]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_sw.dll [862600]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_ta.dll [863112]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_te.dll [862600]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_th.dll [860552]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_tr.dll [862088]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_uk.dll [861576]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_ur.dll [861576]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_vi.dll [861064]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_zh-CN.dll [854408]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_zh-TW.dll [854920]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\npGoogleUpdate3.dll [578440]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\psmachine.dll [166792]
O61 - LFC: 07/03/2015 - 16:44:25 ---A- . (.„Google Inc.“.) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\goopdateres_lt.dll [861576]
O61 - LFC: 07/03/2015 - 16:44:26 ---A- . (...) -- C:\Users\HAFSAOUI\AppData\Local\Temp\{203C1A2F-0C05-43F4-ADA9-CDF946AD9951}-41.0.2272.76_chrome_installer.exe [0]
O61 - LFC: 07/03/2015 - 16:44:26 ---A- . (.Google Inc..) -- C:\Users\HAFSAOUI\AppData\Local\Temp\GUM738A.tmp\psuser.dll [166792]
O61 - LFC: 07/03/2015 - 16:44:26 ---A- . (.Tonec Inc..) -- C:\Users\HAFSAOUI\AppData\Roaming\IDM\idmmzcc5\components11\idmmzcc.dll [26136]
O61 - LFC: 07/03/2015 - 16:44:26 ---A- . (.Tonec Inc..) -- C:\Users\HAFSAOUI\AppData\Roaming\IDM\idmmzcc5\components11\idmmzcc64.dll [31256]
O61 - LFC: 07/03/2015 - 16:44:26 ---A- . (.Tonec Inc..) -- C:\Users\HAFSAOUI\AppData\Roaming\IDM\idmmzcc5\components\idmmzcc.dll [34216]
O61 - LFC: 07/03/2015 - 16:44:27 ---A- . (.Tonec Inc..) -- C:\Users\HAFSAOUI\AppData\Roaming\IDM\idmmzcc5\components2\idmcchandler2.dll [330264]
O61 - LFC: 07/03/2015 - 16:44:27 ---A- . (.Tonec Inc..) -- C:\Users\HAFSAOUI\AppData\Roaming\IDM\idmmzcc5\components2\idmcchandler2_64.dll [459800]
O61 - LFC: 07/03/2015 - 16:44:27 ---A- . (.Tonec Inc..) -- C:\Users\HAFSAOUI\AppData\Roaming\IDM\idmmzcc5\components2\idmmzcc.dll [34216]
O61 - LFC: 07/03/2015 - 16:44:27 ---A- . (.Tonec Inc..) -- C:\Users\HAFSAOUI\AppData\Roaming\IDM\idmmzcc5\components2\idmmzcc64.dll [28512]
O61 - LFC: 07/03/2015 - 16:44:39 ---A- . (.Nicolas Coolman.) -- C:\Users\HAFSAOUI\Desktop\ZHPDiag2.exe [6876286] =>.Nicolas Coolman
~ 77 Fichiers temporaires (Temporary files)
~ 54 Fichiers cookies (Cookies files)
~ Files: 72 Scanned in 00mn 28s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - 20/03/2013 - C:\Windows\System32\drivers\BCM42RLY.sys (BCM42RLY) .(.Broadcom Corporation - Broadcom iLine10(tm) PCI Network Adapter Pr.) - LEGACY_BCM42RLY
O64 - Services: CurCS - 29/11/2014 - C:\Windows\System32\DRIVERS\idmwfp.sys (IDMWFP) .(.Tonec Inc. - Internet Download Manager WFP Driver.) - LEGACY_IDMWFP
O64 - Services: CurCS - 20/02/2014 - C:\Windows\System32\DRIVERS\kl1.sys (KL1) .(.Kaspersky Lab ZAO - Kaspersky Unified Driver.) - LEGACY_KL1
O64 - Services: CurCS - 10/04/2014 - C:\Windows\System32\DRIVERS\klhk.sys (klhk) .(.Kaspersky Lab ZAO - KLHK [fre_wlh_x86].) - LEGACY_KLHK
O64 - Services: CurCS - 25/02/2014 - C:\Windows\System32\DRIVERS\klim6.sys (KLIM6) .(.Kaspersky Lab ZAO - Kaspersky Lab Intermediate Network Driver.) - LEGACY_KLIM6
O64 - Services: CurCS - 12/04/2013 - C:\Windows\System32\DRIVERS\klpd.sys (klpd) .(.Kaspersky Lab ZAO - KLPD [fre_wnet_x86].) - LEGACY_KLPD
O64 - Services: CurCS - 25/03/2014 - C:\Windows\System32\DRIVERS\kltdi.sys (kltdi) .(.Kaspersky Lab ZAO - Network filtering component [fre_wxp_x86].) - LEGACY_KLTDI
O64 - Services: CurCS - 26/03/2014 - C:\Windows\System32\DRIVERS\kneps.sys (kneps) .(.Kaspersky Lab ZAO - KNEPS Power [fre_wxp_x86].) - LEGACY_KNEPS
O64 - Services: CurCS - 13/07/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV
~ Legacy: 95 Scanned in 00mn 00s



---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
~ FASS Keys: 11 Scanned in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.admin", false);
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.aflt", "babsst");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.autoRvrt", "false");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.dfltLng", "en");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.excTlbr", false);
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.ffxUnstlRst", true);
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.id", "3e208e8100000000000018037396134f");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.instlDay", "15813");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.instlRef", "sst");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.newTab", false);
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.prdct", "delta");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.prtnrId", "delta");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.rvrt", "false");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.smplGrp", "none");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.tlbrId", "base");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.tlbrSrchUrl", "");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.vrsn", "1.8.16.16");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.vrsnTs", "1.8.16.1610:16:54");
O69 - SBI: prefs.js [HAFSAOUI - ke7z0gnh.default] user_pref("extensions.delta.vrsni", "1.8.16.16");
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Delta Search) - http://www1.delta-search.com =>Toolbar.DeltaSearch
O69 - SBI: SearchScopes [HKCU] {9D5BD211-422C-4164-9298-BB4186A30F31} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {A58F5A7B-8F34-4C37-958E-10424D855103} - (Comment Ça Marche) - http://www.com
O69 - SBI: SearchScopes [HKCU] {DECA3892-BA8F-44b8-A993-A466AD694AE4} - (Yahoo!) - http://fr.search.yahoo.com
~ Keys: Scanned in 00mn 00s



---\\ Enumère les service demarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168448]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [591360]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [667136]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [473088]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [285184]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [241664]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [543232]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [1933848]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [589312]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [497152]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [46592]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [49664]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [162816]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [749056]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [71168]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [99328]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [102912]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800]
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [149504]
~ Services: 33 Scanned in 00mn 01s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.2AE8B75BFC2179CC9BDC657E19FEFEDA] [SPRF][27/02/2015] (...) -- C:\ProgramData\ntuser.dat [262144]
[MD5.8D7633D20F53D1F83E4C536403271D4C] [SPRF][04/04/2010] (.BitTorrent, Inc. - µTorrent.) -- C:\Users\HAFSAOUI\Desktop\uTorrent.exe [319792] =>P2P.BitTorrent
[MD5.A9B0F397020CED7915C759A8586A4EFF] [SPRF][07/03/2015] (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Users\HAFSAOUI\Desktop\ZHPDiag2.exe [6876286]
~ Files: 3 Scanned in 00mn 00s



---\\ Liste des exceptions du parefeu (FirewallRules) (O87)
O87 - FAEL: "TCP Query User{371FB72D-6B3C-4DD0-A875-C0DBED40B1A3}E:\contenu de partition e\mes logiciels\utorrent\utorrent.exe" | In - Public - P6 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- E:\contenu de partition e\mes logiciels\utorrent\utorrent.exe =>P2P.BitTorrent
O87 - FAEL: "UDP Query User{3D141509-F525-41F3-BC5E-83C6140C81EA}E:\contenu de partition e\mes logiciels\utorrent\utorrent.exe" | In - Public - P17 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- E:\contenu de partition e\mes logiciels\utorrent\utorrent.exe =>P2P.BitTorrent
O87 - FAEL: "{4433E6FA-A34E-48CD-9E0E-FEDE74DC6225}" | In - None - P17 - TRUE | .(.The BoBrowser Authors - BoBrowser.) -- C:\Users\HAFSAOUI\AppData\Local\BoBrowser\Application\bobrowser.exe =>PUP.BoBrowser
~ Firewall: 3 Scanned in 00mn 02s



---\\ Export de clés de registre aléatoires (O91)
[HKCU\Software\5853dcd9bc69e440\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1125.80]:guid="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" =>Hijacker.Eazel
[HKCU\Software\5853dcd9bc69e440\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1125.80]:version="2.6.1125.80" =>Hijacker.Eazel
[HKCU\Software\5853dcd9bc69e440] =>PUP.Babylon^
[HKLM\Software\5853dcd9bc69e440] => Clé orpheline => Clé orpheline => Clé orpheline => Clé orpheline
~ Export Key Software: Scanned in 00mn 00s



---\\ Recherche de clés de registre Tracing (O100)
HKLM\SOFTWARE\Microsoft\Tracing\ApnStub_RASAPI32 =>Toolbar.Ask
HKLM\SOFTWARE\Microsoft\Tracing\ApnStub_RASMANCS =>Toolbar.Ask
HKLM\SOFTWARE\Microsoft\Tracing\avg-secure-search-installer_RASAPI32 =>Toolbar.AVGSearch
HKLM\SOFTWARE\Microsoft\Tracing\avg-secure-search-installer_RASMANCS =>Toolbar.AVGSearch
HKLM\SOFTWARE\Microsoft\Tracing\biclient_RASAPI32 =>Adware.MegaSearch
HKLM\SOFTWARE\Microsoft\Tracing\biclient_RASMANCS =>Adware.MegaSearch
HKLM\SOFTWARE\Microsoft\Tracing\bobrowser_RASAPI32 =>PUP.BoBrowser
HKLM\SOFTWARE\Microsoft\Tracing\bobrowser_RASMANCS =>PUP.BoBrowser
HKLM\SOFTWARE\Microsoft\Tracing\ClaraUpdater_RASAPI32 =>Adware.SupTab
HKLM\SOFTWARE\Microsoft\Tracing\ClaraUpdater_RASMANCS =>Adware.SupTab
HKLM\SOFTWARE\Microsoft\Tracing\GoforFiles_RASAPI32 =>P2P.GoforFiles
HKLM\SOFTWARE\Microsoft\Tracing\GoforFiles_RASMANCS =>P2P.GoforFiles
HKLM\SOFTWARE\Microsoft\Tracing\MyBabylonTB_RASAPI32 =>PUP.Babylon
HKLM\SOFTWARE\Microsoft\Tracing\MyBabylonTB_RASMANCS =>PUP.Babylon
HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_pour_avg-anti-virus-free-2014_2_RASAPI32 =>Toolbar.Conduit
HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_pour_avg-anti-virus-free-2014_2_RASMANCS =>Toolbar.Conduit
HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_pour_avg-anti-virus-free-2014_RASAPI32 =>Toolbar.Conduit
HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_pour_avg-anti-virus-free-2014_RASMANCS =>Toolbar.Conduit
HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_pour_check-flash_RASAPI32 =>Toolbar.Conduit
HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_pour_check-flash_RASMANCS =>Toolbar.Conduit
HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_pour_internet-explorer_RASAPI32 =>Toolbar.Conduit
HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_pour_internet-explorer_RASMANCS =>Toolbar.Conduit
HKLM\SOFTWARE\Microsoft\Tracing\Torntv Downloader_RASAPI32 =>Hijacker.TornTV
HKLM\SOFTWARE\Microsoft\Tracing\Torntv Downloader_RASMANCS =>Hijacker.TornTV
HKLM\SOFTWARE\Microsoft\Tracing\Torntv V6_RASAPI32 =>Hijacker.TornTV
HKLM\SOFTWARE\Microsoft\Tracing\Torntv V6_RASMANCS =>Hijacker.TornTV
HKLM\SOFTWARE\Microsoft\Tracing\TornTV_RASAPI32 =>Hijacker.TornTV
HKLM\SOFTWARE\Microsoft\Tracing\TornTV_RASMANCS =>Hijacker.TornTV
HKLM\SOFTWARE\Microsoft\Tracing\uTorrent_RASAPI32 =>P2P.µTorrent
HKLM\SOFTWARE\Microsoft\Tracing\uTorrent_RASMANCS =>P2P.µTorrent
~ BTK: 274 Scanned in 00mn 00s



---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{22222222-2222-2222-2222-220422592260}] (CrossriderApp0045960.Sandbox) =>PUP.CrossRider
~ BCK: 4758 Scanned in 00mn 09s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Auto 20/04/2014 233552 | (AVP15.0.0) . (.Kaspersky Lab ZAO.) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe
SS - | Demand 27/02/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Auto 02/01/2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SR - | Auto 03/03/2009 81920 | (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Program Files\IDT\WDM\aestsrv.exe
SR - | Auto 08/02/2011 660768 | (btwdins) . (.Broadcom Corporation..) - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
SR - | Auto 23/02/2015 328304 | (ClaraUpdater) . (.ClaraLabs.) - C:\Program Files\Common Files\ClaraUpdater\ClaraUpdater.exe =>Adware.SupTab
SR - | Auto 02/07/2010 325656 | (LMS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 27/05/2011 282709 | (STacSV) . (.IDT, Inc..) - C:\Program Files\IDT\WDM\STacSV.exe
SR - | Auto 03/12/2012 275784 | (UI Assistant Service) . (...) - C:\Program Files\Mobiconnect\AssistantServices.exe
SR - | Auto 02/07/2010 2533400 | (UNS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 20/03/2013 40960 | (wltrysvc) . (.Dell Inc..) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 11s



---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Run by HAFSAOUI at 07/03/2015 16:45:15
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
1 ntkrnlpa!IofCallDriver[0x83651718] >> \Device\Harddisk0\DR0[0x86A11318]
3 CLASSPNP[0x8A10859E] >> ntkrnlpa!IofCallDriver[0x83651718] >> [0x868B7918]
5 ACPI[0x89B4B3B2] >> ntkrnlpa!IofCallDriver[0x83651718] >> \Device\Ide\IdeDeviceP0T0L0-0[0x868B1908]
kernel: MBR read successfully
user & kernel MBR OK
~ MBR: 13 Scanned in 00mn 02s



---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by HAFSAOUI at 07/03/2015 16:45:18
********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s



---\\ Scan Additionnel (O88)
Database Version : 13008 - (01/03/2015)
Clés trouvées (Keys found) : 40
Valeurs trouvées (Values found) : 3
Dossiers trouvés (Folders found) : 20
Fichiers trouvés (Files found) : 17

[HKLM\SYSTEM\CurrentControlSet\Services\ClaraUpdater] =>Adware.SupTab^
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoforFilesUpdate] =>P2P.GoforFiles^
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Run_Bobby_Browser] =>PUP.BoBrowser^
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Torntv V6.0-updater] =>Hijacker.TornTV^
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent] =>P2P.BitTorrent^
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}] =>PUP.Babylon
[HKLM\Software\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}] =>Toolbar.AVGSearch
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}] =>Adware.Bandoo
[HKLM\Software\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] =>Toolbar.AVGSearch
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}] =>Toolbar.AVGSearch
[HKLM\Software\Classes\Prod.cap] =>PUP.ClaroSearch
[HKLM\Software\Classes\AppID\ScriptHelper.EXE] =>Toolbar.AVGSearch
[HKCU\Software\1ClickDownload] =>PUP.1ClickDownloader
[HKCU\Software\BabylonToolbar] =>PUP.Babylon
[HKCU\Software\DataMngr] =>Adware.Bandoo
[HKLM\Software\DataMngr] =>Adware.Bandoo
[HKCU\Software\DataMngr_Toolbar] =>Toolbar.Agent
[HKCU\Software\Softonic] =>Toolbar.Conduit
[HKLM\Software\Microsoft\Tracing\MyBabylontb_RASAPI32] =>PUP.Babylon
[HKLM\Software\Microsoft\Tracing\MyBabylontb_RASMANCS] =>PUP.Babylon
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}] =>Toolbar.Yahoo
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}] =>Toolbar.Yahoo
[HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}] =>Toolbar.Yahoo
[HKLM\Software\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}] =>Toolbar.DeltaSearch
[HKLM\Software\Microsoft\Tracing\apnstub_RASMANCS] =>Toolbar.Ask
[HKLM\Software\Microsoft\Tracing\apnstub_RASAPI32] =>Toolbar.Ask
[HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider
[HKCU\Software\InstalledBrowserExtensions\] =>PUP.CrossRider
[HKCU\Software\BI] =>Adware.MegaSearch
[HKCU\Software\InstalledBrowserExtensions] =>PUP.CrossRider
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}] =>Toolbar.Yahoo
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}] =>Toolbar.Yahoo
[HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}] =>Toolbar.Yahoo
[HKLM\Software\Classes\CrossriderApp0045960.BHO] =>PUP.CrossRider
[HKLM\Software\Classes\CrossriderApp0045960.BHO.1] =>PUP.CrossRider
[HKLM\Software\Classes\CrossriderApp0045960.Sandbox] =>PUP.CrossRider
[HKLM\Software\Classes\CrossriderApp0045960.Sandbox.1] =>PUP.CrossRider
[HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411591160}] =>PUP.CrossRider
[HKLM\Software\Classes\CLSID\{22222222-2222-2222-2222-220422592260}] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411591160}] =>PUP.CrossRider
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:BoBrowser =>PUP.BoBrowser^
C:\Program Files\AVG Secure Search =>Toolbar.AVGSearch^
C:\Program Files\Enigma Software Group =>PUP.EnigmaSoftware^
C:\Program Files\Movies Toolbar =>PUP.MoviesToolbar^
C:\Program Files\Torntv V6.0 =>Hijacker.TornTV^
C:\Program Files\TornTV.com =>Hijacker.TornTV^
C:\Program Files\uTorrent =>P2P.µTorrent^
C:\Program Files\Common Files\ClaraUpdater =>Adware.SupTab^
C:\ProgramData\DSearchLink =>Toolbar.DeltaSearch^
C:\ProgramData\IBUpdaterService =>Adware.InstallBrain^
C:\Users\HAFSAOUI\AppData\Roaming\Babylon =>PUP.Babylon^
C:\Users\HAFSAOUI\AppData\Roaming\File Scout =>PUP.FileScout^
C:\Users\HAFSAOUI\AppData\Roaming\GoforFiles =>P2P.GoforFiles^
C:\Users\HAFSAOUI\AppData\Roaming\PerformerSoft =>PUP.PerformerSoft^
C:\Users\HAFSAOUI\AppData\Roaming\SpeedanAlysis =>PUP.SpeedAnalysis^
C:\Users\HAFSAOUI\AppData\Roaming\uTorrent =>P2P.µTorrent^
C:\Users\HAFSAOUI\AppData\Local\Babylon =>PUP.Babylon^
C:\Users\HAFSAOUI\AppData\Local\BoBrowser =>PUP.BoBrowser^
C:\Users\HAFSAOUI\AppData\Local\Bundled software uninstaller =>Adware.MegaSearch^
C:\Users\HAFSAOUI\AppData\LocalLow\searchresultstb =>Toolbar.Agent
C:\Users\HAFSAOUI\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfcbmgbfdbijmjgjihagbomfbjfjmgon =>PUP.SpeedAnalysis
C:\Users\HAFSAOUI\AppData\Local\BoBrowser\Application\bobrowser.exe =>PUP.BoBrowser^
C:\Windows\Tasks\Torntv V6.0-codedownloader.job =>PUP.CrossRider^
C:\Windows\Tasks\Torntv V6.0-enabler.job =>PUP.CrossRider^
C:\Windows\Tasks\Torntv V6.0-updater.job =>PUP.CrossRider^
C:\Windows\System32\Tasks\Torntv V6.0-updater =>PUP.CrossRider^
[HKCU\Software\AppDataLow\Software\Torntv V6.0] =>Hijacker.TornTV^
[HKCU\Software\BitTorrent] =>P2P.BitTorrent^
[HKCU\Software\BoBrowser] =>PUP.BoBrowser^
[HKCU\Software\FileScout] =>PUP.FileScout^
[HKCU\Software\GoforFiles] =>P2P.GoforFiles^
[HKLM\Software\Babylon] =>PUP.Babylon^
[HKLM\Software\GoforFiles] =>P2P.GoforFiles^
[HKLM\Software\Torntv V6.0] =>Hijacker.TornTV^
C:\Users\HAFSAOUI\Desktop\uTorrent.exe =>P2P.BitTorrent^
[HKCU\Software\5853dcd9bc69e440\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1125.80]:guid="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" =>Hijacker.Eazel^
[HKCU\Software\5853dcd9bc69e440] =>PUP.Babylon^^
[HKCR\CLSID\{22222222-2222-2222-2222-220422592260}] (CrossriderApp0045960.Sandbox) =>PUP.CrossRider^
~ Additionnel Scan: 158059 Items scanned in 00mn 22s



---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects de navigateur (O2)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
~ AMI: 5 Scanned in 00mn 00s



---\\ Récapitulatif des détections trouvées sur votre station
http://www.nicolascoolman.fr/blog/ =>PUP.BoBrowser
http://nicolascoolman.fr/pup-speedanalysis =>PUP.SpeedAnalysis
http://www.nicolascoolman.fr/blog/ =>Adware.SupTab
http://nicolascoolman.fr/hijacker-torntv =>Hijacker.TornTV
http://nicolascoolman.fr/pup-crossrider =>PUP.CrossRider
http://nicolascoolman.fr/pup-1clickdownloader =>PUP.1ClickDownloader
http://nicolascoolman.fr/hijacker-eazel =>Hijacker.Eazel
http://nicolascoolman.fr/pup-babylon =>PUP.Babylon
http://nicolascoolman.fr/pup-datamngr =>PUP.Datamngr
http://nicolascoolman.fr/pup-filescout =>PUP.FileScout
http://www.nicolascoolman.fr/blog/ =>PUP.BrowserExtensions
http://nicolascoolman.fr/toolbar-conduit =>Toolbar.Conduit
http://www.nicolascoolman.fr/blog/ =>PUP.EnigmaSoftware
http://nicolascoolman.fr/pup-moviestoolbar =>PUP.MoviesToolbar
http://nicolascoolman.fr/toolbar-deltasearch =>Toolbar.DeltaSearch
http://nicolascoolman.fr/adware-installbrain =>Adware.InstallBrain
http://www.nicolascoolman.fr/blog/ =>PUP.PerformerSoft
http://nicolascoolman.fr/adware-megasearch =>Adware.MegaSearch
Clé orpheline => Clé orpheline => Clé orpheline => Clé orpheline
http://nicolascoolman.fr/toolbar-ask =>Toolbar.Ask
http://nicolascoolman.fr/adware-bandoo =>Adware.Bandoo
http://nicolascoolman.fr/pup-clarosearch =>PUP.ClaroSearch
http://www.nicolascoolman.fr/blog/ =>Toolbar.Agent
http://www.nicolascoolman.fr/blog/ =>Toolbar.Yahoo
~ MSI: 24 link(s) detected in 00mn 00s



End of the scan (1473 lines in 02mn 27s)(0.11)

Publicité


Signaler le contenu de ce document

Publicité