cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2015.5.2.45 - Nicolas Coolman (02.05.2015)
~ Lancé par PC-PC (02.05.2015 21:19:39)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17728 (Defaut)
GCIE: Google Chrome v42.0.2311.135

---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows(R) Operating System, OEM_DM channel
Windows ID Activation : OK
~ Windows Partial Key : 7QTBG
Windows License : OK
~ Windows Remaining Initializations Number : 1000
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 8.1, 64-bit (Build 9600)

---\\ Logiciels de protection du système
Kaspersky Anti-Virus v14.0.0.4651
Windows Defender W8 (Deactivate)

---\\ Logiciels d'optimisation du système

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Reader XI

---\\ Informations sur le système
~ Processor: Intel64 Family 6 Model 60 Stepping 3, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 16316 MB (83% free)
System Restore: Activé (Enable)
System drive C: has 798 GB (87%) free of 910 GB

---\\ Mode de connexion au système
~ Computer Name: PC
~ User Name: PC-PC
~ All Users Names: UpdatusUser, PC-PC, HomeGroupUser$, Administrateur,
~ Unselected Option: None
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\PC-PC\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\PC-PC\AppData\Roaming\
~ %Desktop% : C:\Users\PC-PC\Desktop\
~ %Favorites% : C:\Users\PC-PC\Favorites\
~ %LocalAppData% : C:\Users\PC-PC\AppData\Local\
~ %StartMenu% : C:\Users\PC-PC\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 798 Go of 910 Go)
D: Hard drive, Flash drive, Thumb drive (Free 2 Go of 21 Go)
E: Hard drive, Flash drive, Thumb drive (Free 931 Go of 932 Go)
F: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
~ Security Center: 44 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.C10A66189DC8C090E7C84873EDCEBC88] - (.Microsoft Corporation - Explorateur Windows.) (.28.01.2015 - 00:47:12.) -- C:\Windows\Explorer.exe [2501368]
[MD5.A570A64292214C43E0BA50E6A72A6380] - (.Microsoft Corporation - Application de démarrage de Windows.) (.29.10.2014 - 02:25:54.) -- C:\Windows\System32\Wininit.exe [145920]
[MD5.77B35D0FC22A2D2EAC8D07C3F9784DBF] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.13.03.2015 - 03:45:57.) -- C:\Windows\System32\wininet.dll [2358784]
[MD5.EC498BAE1F0D3E0E401C963F8D76C437] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.29.10.2014 - 02:22:52.) -- C:\Windows\System32\Winlogon.exe [572416]
[MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - (.Microsoft Corporation - Bibliothèque de licences.) (.18.03.2014 - 11:09:55.) -- C:\Windows\System32\sppcomapi.dll [447488]
[MD5.374E27295F0A9DCAA8FC96370F9BEEA5] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.30.05.2014 - 04:03:03.) -- C:\Windows\system32\Drivers\AFD.sys [563200]
[MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.22.08.2013 - 13:43:41.) -- C:\Windows\system32\Drivers\atapi.sys [26464]
[MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) (.22.08.2013 - 12:40:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [88576]
[MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.22.08.2013 - 09:46:35.) -- C:\Windows\system32\Drivers\Cdrom.sys [164352]
[MD5.A03F362C5557E238CBFA914689C77248] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.30.04.2014 - 17:29:43.) -- C:\Windows\system32\Drivers\DfsC.sys [134144]
[MD5.D4B7ED39C7900384D9E5C1283F1E7926] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.24.07.2014 - 12:45:39.) -- C:\Windows\system32\Drivers\HDAudBus.sys [76800]
[MD5.D887446F3F6051C60C26F4FD1FC8D43F] - (.Microsoft Corporation - Pilote de port i8042.) (.07.10.2014 - 04:29:50.) -- C:\Windows\system32\Drivers\i8042prt.sys [107520]
[MD5.B7342B3C58E91107F6E946A93D9D4EFD] - (.Microsoft Corporation - IP Network Address Translator.) (.18.03.2014 - 11:09:57.) -- C:\Windows\system32\Drivers\IpNat.sys [142848]
[MD5.31233271EDE50D1BBB220F78AFA60486] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.08.10.2014 - 08:32:10.) -- C:\Windows\system32\Drivers\MRxSmb.sys [405504]
[MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) (.22.08.2013 - 12:37:02.) -- C:\Windows\system32\Drivers\netBT.sys [282624]
[MD5.7F68063A5A0461E02BC860CE0E6BFDDC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.15.10.2014 - 09:32:37.) -- C:\Windows\system32\Drivers\ntfs.sys [2025792]
[MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Pilote de port parallèle.) (.22.08.2013 - 12:40:02.) -- C:\Windows\system32\Drivers\Parport.sys [94208]
[MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.22.08.2013 - 12:35:51.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [120832]
[MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.18.03.2014 - 10:41:24.) -- C:\Windows\system32\Drivers\rdpdr.sys [195584]
[MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) (.22.08.2013 - 14:25:35.) -- C:\Windows\system32\Drivers\tdx.sys [107520]
[MD5.64CA2B4A49A8EAF495E435623ECCE7DB] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.19.06.2014 - 03:13:36.) -- C:\Windows\system32\Drivers\volsnap.sys [310080]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 2/4402
~ Mes musiques (My Musics) : 1/184
~ Mes Favoris (My Favorites) : 1/31
~ Mes Documents (My Documents) : 1/200
~ Mon Bureau (My Desktop) : 1/4
~ Menu demarrer (Programs) : 1/31
~ Hidden Files: Scanned in 00mn 00s



---\\ Processus lancés
[MD5.C9E2D38B73524AF3B281299BA04E5205] - (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe [1005352] [PID.7492]
[MD5.EFC5D323E170D859F26E4666C885484E] - (.AuthenTec Inc. - TouchControl.) -- C:\Program Files (x86)\HP SimplePass\TouchControl.exe [3695912] [PID.8120]
[MD5.FC9095973170EB63BAB2A8554E5D25A5] - (.Pas de propriétaire - IEWebSiteLogon.) -- C:\Program Files (x86)\HP SimplePass\IEWebSiteLogon.exe [4073768] [PID.7652]
[MD5.05EF48203CC819B57F8665217FB6DDF5] - (.Electronic Arts - Origin.) -- C:\Program Files (x86)\Origin\Origin.exe [3632472] [PID.5556]
[MD5.0E84A5A8C621F733621B270C717B4379] - (.Intel Corporation - ISCT SysTray.) -- C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe [249320] [PID.2496]
[MD5.BD9B0E544F4D70E20781A00A27FF98E5] - (.IVT Corporation - Bluetooth Application.) -- C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [379904] [PID.836]
[MD5.D1C8B0DC04347B6B9B5B3B9204DF6756] - (.Hewlett-Packard Development Company, L.P. - HP CoolSense.) -- C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1343904] [PID.5364]
[MD5.3A0710EED4371267DC2CA63AAE26954A] - (.Hewlett-Packard Development Company, L.P. - HP Message Service.) -- C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [475448] [PID.6612]
[MD5.D88B2D487439305A2EC308A6796C3044] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392] [PID.7248]
[MD5.4F1F1783FBD5EDCE63CD546813E4AAFE] - (.APN - Ask Toolbar Notifier.) -- C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [2004360] [PID.5588] =>Toolbar.AskBar
[MD5.4E95B1FDDC9E51678BFA2A723EAA94EF] - (.Pas de propriétaire - AgentMon Application.) -- C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280] [PID.2536]
[MD5.548EE4F7C7F39111048B7A708C2DC245] - (.BlueStack Systems, Inc. - BlueStacks Agent.) -- C:\Program Files (x86)\BlueStacks\HD-Agent.exe [843480] [PID.7132]
[MD5.5F1B1148C830C0F149A476A58CE0D09D] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\IEXPLORE.exe [815248] [PID.7060]
[MD5.C06C9EC74A0971A31A40723432201C86] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8206336] [PID.8088]
~ Processes Running: Scanned in 00mn 00s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\PC-PC\AppData\Local\Google\Chrome\User Data\Default\Preferences
G1 - GCS: Preference [User Data\Default] http://www.mystartsearch.com =>PUP.StartSearch
G0 - GCSP: Preference [User Data\Default] http://www.mystartsearch.com =>PUP.StartSearch
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Drive v.6.3 (Activé)
G2 - GCE: Preference [User Data\Default] [dchlnpcodkpfdpacogkljefecpegganj] URL Advisor v.14.0.0.4651 (Désactivé)
G2 - GCE: Preference [User Data\Default] [hghkgaeecgjhjkannahfamoehjmkjail] Module de blocage des sites Internet dangereux v.14.0.0.4651 (Désactivé)
G2 - GCE: Preference [User Data\Default] [jagncdcchgajhfhijbbhecadmaiegcmh] Virtual Keyboard v.14.0.0.4917 (Désactivé)
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.6.1 (Activé)

---\\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 32 Legitimates Filtered in 00mn 02s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com =>PUP.StartSearch
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com =>PUP.StartSearch
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com =>PUP.StartSearch
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com =>PUP.StartSearch
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com =>PUP.StartSearch
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com =>PUP.StartSearch
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = preserve
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com =>PUP.StartSearch
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com =>PUP.StartSearch
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com =>PUP.StartSearch
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com =>PUP.StartSearch
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com =>PUP.StartSearch
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com =>PUP.StartSearch
~ IE Browser: 22 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <-loopback> =>Hijacker.Proxy
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:62443;https=127.0.0.1:62443 =>Hijacker.Proxy
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: Adblock Plus for IE Browser Helper Object [64Bits] - {FFCB3198-32F3-4E8B-9539-4324694ED664} . (.Adblock Plus - Adblock Plus Module.) -- C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
O2 - BHO: Lync Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} Clé orpheline
O2 - BHO: Linkey [64Bits] - {4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} Clé orpheline =>PUP.LinkeySearch
O2 - BHO: Search App by Ask BHO [64Bits] - {4F524A2D-5350-4500-76A7-7A786E7484D7} . (...) -- "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll" (.not file.) =>Toolbar.AskBar
~ BHO: 22 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Search App by Ask - [HKLM]{4F524A2D-5350-4500-76A7-7A786E7484D7} . (.APN LLC. - Passport.) -- C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport_x64.dll =>Toolbar.AskBar
O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{4F524A2D-5350-4500-76A7-7A786E7484D7} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Applications lancées au démarrage du système (O4)
O4 - GS\Startup [PC-PC]: hqghumeaylnlf.lnk . (.PC Utilities Software Limited - OptimizerPro – Clean up your PC.) -- C:\ProgramData\{b6b3d924-6f9d-04db-b6b3-3d9246f96491}\hqghumeaylnlf.exe =>PUP.OptimizerPro
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.)
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray64.exe
O4 - HKCU\..\Run: [SkyDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\PC-PC\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
O4 - HKCU\..\Run: [Akamai NetSession Interface] . (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\PC-PC\AppData\Local\Akamai\netsession_win.exe
O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EADM] . (.Electronic Arts - Origin.) -- C:\Program Files (x86)\Origin\Origin.exe
O4 - HKCU\..\Run: [Power2GoExpress8] NA
O4 - HKCU\..\Run: [Optimizer Pro] . (...) -- C:\Program Files (x86)\Optimizer Pro 3.86\OptProLauncher.exe =>PUP.OptimizerPro
O4 - HKLM\..\Wow6432Node\Run: [BtTray] . (.IVT Corporation - Bluetooth Application.) -- C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe
O4 - HKLM\..\Wow6432Node\Run: [RemoteControl10] . (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
O4 - HKLM\..\Wow6432Node\Run: [BDRegion] . (.cyberlink - brs.) -- C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
O4 - HKLM\..\Wow6432Node\Run: [HP CoolSense] . (.Hewlett-Packard Development Company, L.P. - HP CoolSense.) -- C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
O4 - HKLM\..\Wow6432Node\Run: [AccelerometerSysTrayApplet] . (.Hewlett-Packard Company - Hp Accelerometer System Tray.) -- C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe
O4 - HKLM\..\Wow6432Node\Run: [HPMessageService] . (.Hewlett-Packard Development Company, L.P. - HP Message Service.) -- C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
O4 - HKLM\..\Wow6432Node\Run: [ApnTBMon] . (.APN - Ask Toolbar Notifier.) -- C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe =>Toolbar.AskBar
O4 - HKLM\..\Wow6432Node\Run: [AgentMonitor] . (.Pas de propriétaire - AgentMon Application.) -- C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
O4 - HKLM\..\Wow6432Node\Run: [YouCam Service] C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [BlueStacks Agent] . (.BlueStack Systems, Inc. - BlueStacks Agent.) -- C:\Program Files (x86)\BlueStacks\HD-Agent.exe
O4 - HKUS\S-1-5-21-1748765071-3366339864-2193208255-1001\..\RunOnce: [WAB Migrate] . (.Microsoft Corporation - Windows Contacts.) -- C:\Program Files (x86)\Windows Mail\wab.exe =>.Microsoft Corporation
~ Application: Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Clavier virtuel [64Bits] - {0C4CC089-D306-440D-9772-464E226F6539} . (...) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\kbrd.ico
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 [64Bits] - {25510184-5A38-4A99-B273-DCA8EEF6CD08} . (...) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\Resources\Icons\HP.ico
O9 - Extra button: Se&nd to OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll =>.Microsoft Corporation
O9 - Extra button: Lync Click to Call [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\lync.exe (.not file.)
O9 - Extra button: OneNote Lin&ked Notes [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll =>.Microsoft Corporation
O9 - Extra button: Analyse des liens [64Bits] - {CCF151D8-D089-449F-A5A4-D9909053F20F} . (...) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\logo.ico
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] http.aeriagames.com
~ IE Zone Confiance: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{52479A72-BC64-4BBA-82DD-6A961DF4C3C9}: DhcpNameServer = 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60
O17 - HKLM\System\CCS\Services\Tcpip\..\{BF8F4EBA-73CD-46AC-B1D5-CDA13489EE57}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{DFD731CD-25A1-46EE-B200-DD5B11D9B780}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{DFD731CD-25A1-46EE-B200-DD5B11D9B780}: DhcpDomain = fritz.box
O17 - HKLM\System\CS1\Services\Tcpip\..\{52479A72-BC64-4BBA-82DD-6A961DF4C3C9}: DhcpNameServer = 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60
O17 - HKLM\System\CS1\Services\Tcpip\..\{BF8F4EBA-73CD-46AC-B1D5-CDA13489EE57}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{DFD731CD-25A1-46EE-B200-DD5B11D9B780}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{DFD731CD-25A1-46EE-B200-DD5B11D9B780}: DhcpDomain = fritz.box
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: OptimizerPro Monitoring (4abaf598) . (...) - c:\Program Files (x86)\Optimizer Pro 3.86\OptProMon.dll =>PUP.OptimizerPro
O23 - Service: Service de mise à jour Ask (APNMCP) . (.APN LLC. - APN Updater.) - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe =>Toolbar.AskBar
O23 - Service: Intel(R) Smart Connect Technology Agent (ISCTAgent) . (.Pas de propriétaire - ISCT Agent Application.) - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
O23 - Service: Validity WBF Policy Service (valWBFPolicyService) . (...) - C:\Windows\system32\valWBFPolicyService.exe
O23 - Service: WaNetworkEnhance Service (WaNetworkEnhance Service) . (...) - C:\Program Files (x86)\WaNetworkEnhance\WaNetworkEnhance Internet Enhancer\InternetEnhancerService.exe
O23 - Service: Web Bar Service (wbsvc) (wbsvc) . (.Web Bar Media - Web Bar Service.) - C:\Program Files\WebBar\wbsvc.exe =>PUP.WebBar
~ Services: 28 Legitimates Filtered in 00mn 07s



---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [PCHelpers1st] (...) -- C:\Program Files (x86)\Optimizer Elite Max\Optimizer Elite Max.exe (.not file.) [0] =>PUP.OptimizerEliteMax
[MD5.00000000000000000000000000000000] [APT] [PCHelpers_period] (...) -- C:\Program Files (x86)\Optimizer Elite Max\Optimizer Elite Max.exe (.not file.) [0] =>PUP.OptimizerEliteMax
[MD5.998C279948759C00A4277C49141E3049] [APT] [WebBarLaunchTask] (.Web Bar Media.) -- C:\Program Files\WebBar\wbsvc.exe [37144] =>PUP.WebBar
[MD5.998C279948759C00A4277C49141E3049] [APT] [WebBarUpdateTask] (.Web Bar Media.) -- C:\Program Files\WebBar\wbsvc.exe [37144] =>PUP.WebBar
[MD5.00000000000000000000000000000000] [APT] [{71889AD3-60BA-46C6-9142-D8EFC63240E1}] (...) -- F:\HeartOfDarkness_Fr.exe (.not file.) [0]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1078]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1082]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\HPCeeScheduleForPC-PC [338]
O39 - APT: PCHelpers1st - (...) -- C:\Windows\Tasks\PCHelpers1st.job [306] =>PUP.OptimizerEliteMax
O39 - APT: PCHelpers1st - (...) -- C:\Windows\System32\Tasks\PCHelpers1st [306] =>PUP.OptimizerEliteMax
O39 - APT: PCHelpers_period - (...) -- C:\Windows\Tasks\PCHelpers_period.job [306] =>PUP.OptimizerEliteMax
O39 - APT: PCHelpers_period - (...) -- C:\Windows\System32\Tasks\PCHelpers_period [306] =>PUP.OptimizerEliteMax
~ Scheduled Task: 20 Legitimates Filtered in 00mn 04s



---\\ Logiciels installés (O42)
O42 - Logiciel: F1 2002 - (...) [HKLM][64Bits] -- {C64121E9-B741-4177-00BD-7B228D3F6723}
O42 - Logiciel: LPT System Updater Service - (.LPT.) [HKLM][64Bits] -- {BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24} =>Adware.IncrediBar
O42 - Logiciel: Search App by Ask - (.APN, LLC.) [HKLM][64Bits] -- {4F524A2D-5350-4500-76A7-A758B70C1C01} =>Toolbar.Ask
O42 - Logiciel: Shopping Helper Smartbar - (.ReSoft Ltd..) [HKLM][64Bits] -- {AC6E9B2A-A7E6-4B17-8A6C-29D519673E12} =>Hijacker.SmartBar
O42 - Logiciel: Shopping Helper Smartbar Engine - (.ReSoft Ltd..) [HKCU][64Bits] -- {12c1b278-9702-42fe-9f7c-46123468fd27} =>Hijacker.SmartBar
O42 - Logiciel: Wajam - (.WaNetworkEnhance.) [HKLM][64Bits] -- WaNetworkEnhance =>PUP.Wajam
O42 - Logiciel: Web Bar 2.0.5574.22315 - (.Web Bar Media.) [HKLM][64Bits] -- {0BCE8B0A-1E76-44E5-9909-3CF804D92E4D}_is1 =>PUP.WebBar
O42 - Logiciel: mystartsearch uninstall - (.mystartsearch.) [HKLM][64Bits] -- mystartsearch uninstall =>PUP.StartSearch
~ Logic: 41 Legitimates Filtered in 00mn 00s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\APN PIP]
[HKCU\Software\AskPartnerNetwork] =>Toolbar.AskBar
[HKCU\Software\HomeTab] =>PUP.CertifiedToolbar
[HKCU\Software\Kromtech]
[HKCU\Software\Smartbar] =>Hijacker.SmartBar
[HKCU\Software\WaNetworkEnhance]
[HKCU\Software\WajIEnhance] =>PUP.Wajam
[HKCU\Software\Yulm]
[HKCU\Software\melondrea] =>PUP.Melondrea
[HKLM\Software\AskPartnerNetwork] =>Toolbar.AskBar
[HKLM\Software\Linkey] =>PUP.LinkeySearch
[HKLM\Software\WebBar] =>PUP.WebBar
[HKLM\Software\Wow6432Node\AIM Toolbar]
[HKLM\Software\Wow6432Node\AskPartnerNetwork] =>Toolbar.AskBar
[HKLM\Software\Wow6432Node\Conduit] =>Toolbar.Conduit
[HKLM\Software\Wow6432Node\Iminent] =>Adware.IMBooster
[HKLM\Software\Wow6432Node\SpeedBit]
[HKLM\Software\Wow6432Node\SystemK] =>PUP.SystemK
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\melondrea] =>PUP.Melondrea
~ Key Software: 326 Legitimates Filtered in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 21.10.2014 - 14:34:26 - [] ----D C:\Program Files (x86)\AskPartnerNetwork =>Toolbar.AskBar
O43 - CFD: 05.03.2014 - 20:31:31 - [] ----D C:\Program Files (x86)\SCANIA Truck Driving Simulator
O43 - CFD: 31.03.2014 - 13:25:11 - [] ----D C:\Program Files (x86)\Uninstaller
O43 - CFD: 01.05.2015 - 13:39:40 - [] ----D C:\Program Files (x86)\Wajam =>PUP.Wajam
O43 - CFD: 01.05.2015 - 13:39:41 - [] ----D C:\Program Files (x86)\WaNetworkEnhance =>PUP.Wajam
O43 - CFD: 21.10.2014 - 14:34:22 - [] ----D C:\ProgramData\APN
O43 - CFD: 21.10.2014 - 14:34:26 - [] ----D C:\ProgramData\AskPartnerNetwork =>Toolbar.AskBar
O43 - CFD: 21.06.2014 - 13:26:47 - [] ----D C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
O43 - CFD: 01.05.2015 - 13:49:04 - [] ----D C:\ProgramData\{b6b3d924-6f9d-04db-b6b3-3d9246f96491}
O43 - CFD: 17.07.2014 - 20:12:40 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos
O43 - CFD: 09.04.2015 - 18:41:25 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
O43 - CFD: 30.04.2014 - 17:49:43 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
O43 - CFD: 30.04.2014 - 17:55:59 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services
O43 - CFD: 18.03.2014 - 11:41:33 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 01.05.2015 - 13:39:42 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WaNetworkEnhance
O43 - CFD: 01.05.2015 - 13:39:05 - [] ----D C:\Users\PC-PC\AppData\Roaming\mystartsearch =>PUP.StartSearch
O43 - CFD: 21.10.2014 - 14:34:29 - [] ----D C:\Users\PC-PC\AppData\Local\AskPartnerNetwork =>Toolbar.AskBar
O43 - CFD: 16.11.2014 - 10:03:44 - [] -SH-D C:\Users\PC-PC\AppData\Local\EmieBrowserModeList
O43 - CFD: 01.05.2015 - 13:55:27 - [] ----D C:\Users\PC-PC\AppData\Local\WebBar =>PUP.WebBar
~ Program Folder: 220 Legitimates Filtered in 00mn 00s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.7CA09731EB7FC99B910C7F239E57720F] - 01.05.2015 - 13:15:19 ---A- . (...) -- C:\Windows\System32\Drivers\WPRO_41_2001.sys [34752]
~ Files: 7 Legitimates Filtered in 00mn 24s



---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.22981F905E0FE207FFA4A0EB69970383] - 01.05.2015 - 12:38:49 ---A- - C:\Windows\Prefetch\WEBBAR_1404--7CB639C8.TMP-38961406.pf =>PUP.WebBar
~ Prefetcher: 1 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 19 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 4 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:13.08.2013 - 00:25:46 ---A- . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\Drivers\bcmfn2.sys [17624]
O58 - SDL:13.02.2013 - 09:28:26 ---A- . (.Pas de propriétaire - Intel Keyboard Class Upper Filter Driver.) -- C:\Windows\System32\Drivers\ikbevent.sys [21048]
O58 - SDL:13.02.2013 - 09:28:28 ---A- . (.Pas de propriétaire - Intel Mouse Class Upper Filter Driver.) -- C:\Windows\System32\Drivers\imsevent.sys [21048]
O58 - SDL:13.02.2013 - 09:28:28 ---A- . (.Pas de propriétaire - Intel(R) Smart Connect Technology Device Driver.) -- C:\Windows\System32\Drivers\ISCTD64.sys [46568]
O58 - SDL:22.08.2013 - 13:43:32 ---A- . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x64.) -- C:\Windows\System32\Drivers\stexstor.sys [31072]
O58 - SDL:17.07.2014 - 19:19:15 ---A- . (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\Drivers\stwrt64.sys [551936]
O58 - SDL:28.07.2014 - 13:52:00 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\Drivers\usbaapl64.sys [54784]
O58 - SDL:01.05.2015 - 13:15:19 ---A- . (...) -- C:\Windows\System32\Drivers\WPRO_41_2001.sys [34752]
~ Drivers: 70 Legitimates Filtered in 00mn 03s



---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 01.05.2015 - 21:20:35 ---A- . (...) -- C:\Users\PC-PC\AppData\Local\Microsoft\Windows\INetCache\IE\TWPTHV6G\Clash Of Clans pour PC.exe [542944]
O61 - LFC: 01.05.2015 - 21:20:35 ---A- . (...) -- C:\Users\PC-PC\AppData\Local\Microsoft\Windows\INetCache\Low\IE\M3S6LKJC\BlueStacks-SplitInstaller_native[1].exe [0]
O61 - LFC: 02.05.2015 - 21:20:35 ---A- . (...) -- C:\Users\PC-PC\AppData\Local\Microsoft\Windows\INetCache\IE\UEXGY9YJ\urlblockindex[2].bin [16]
O61 - LFC: 28.04.2015 - 21:20:31 ---A- . (.APN LLC.) -- C:\Users\PC-PC\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrvStub.dll [111496] =>Toolbar.AskBar
O61 - LFC: 28.04.2015 - 21:20:31 ---A- . (.APN LLC.) -- C:\Users\PC-PC\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrvStub_x64.dll [130440] =>Toolbar.AskBar
O61 - LFC: 28.04.2015 - 21:20:31 ---A- . (.APN LLC..) -- C:\Users\PC-PC\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr.exe [171912] =>Toolbar.AskBar
O61 - LFC: 28.04.2015 - 21:20:31 ---A- . (.APN LLC..) -- C:\Users\PC-PC\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr_x64.exe [182152] =>Toolbar.AskBar
O61 - LFC: 28.04.2015 - 21:20:31 ---A- . (.APN.) -- C:\Users\PC-PC\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrv.dll [460680] =>Toolbar.AskBar
O61 - LFC: 28.04.2015 - 21:20:31 ---A- . (.APN.) -- C:\Users\PC-PC\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcSrv_x64.dll [561032] =>Toolbar.AskBar
~ 2364 Fichiers temporaires (Temporary files)
~ 1 Fichiers cookies (Cookies files)
~ Files: 22 Legitimates Filtered in 00mn 14s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://www.mystartsearch.com =>PUP.StartSearch
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com =>PUP.StartSearch
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0F45768A-5F1D-41D5-89E8-19E777FA8333} - (Ask Search) - http://www.search.ask.com
O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} - (mystartsearch) - http://www.mystartsearch.com =>PUP.StartSearch
O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - http://www.google.com
O69 - SBI: SearchScopes [HKCU] {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} - (default-search.net) - http://www.default-search.net =>Hijacker.Browsers
O69 - SBI: SearchScopes [HKCU] {D944BB61-2E34-4DBF-A683-47E505C587DC} [DefaultScope] - (eBay) - http://rover.ebay.com
O69 - SBI: SearchScopes [HKUS\.DEFAULT] {006ee092-9658-4fd6-bd8e-a21a348e59f5} - (Web Search) - http://feed.snapdo.com =>Hijacker.SmartBar
O69 - SBI: SearchScopes [HKUS\S-1-5-18] {006ee092-9658-4fd6-bd8e-a21a348e59f5} - (Web Search) - http://feed.snapdo.com =>Hijacker.SmartBar
~ Keys: Scanned in 00mn 00s



---\\ Export de clés de registre aléatoires (O91)
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:060df2cd="alAl/YP/b/Af/X6/bxAu/Y//alAf/YP/HPAj/Xb/UxAp/X2/GxAk////"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:0c230bcb="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:0dc3ee96="/P////%%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:0e93c3f3="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:1520c6f1="V/////%%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:1c311243="b/Af/X6/alAl/YP/HPAi/Yq/GPAf/Yb/GPAz/B2/FlAk/Xh////%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:27ddcf6f="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:2d71d5ab="V/////%%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:2e22d94e="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:340d3099="/P////%%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:37b7a6d8="UlAr/XJ/c//k////"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:38583bc3="Ml/2/CF/M//g/CZ////%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:3c09c42b="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:414bc593="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:48bd1aff="V/////%%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:51d2f2ea="IlAl/YP/HPAi/Xt/dxAu/YZ/J/Af/X6/Z/AM/X6/axAp/YP/alAf/Xt/axAr/B//VP/j/Cx/V//j/C
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:587b5709="V/////%%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:6185d035="VP/h/CP/V//l////"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:65114b36="VP/+////"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:72758a5d="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:7367429f="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:7f69fa1f="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:8b9e4cbc="V/////%%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:a0743acc="N/////%%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:a1dcff5b="V/////%%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:a2e3b941="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:bbf88800="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:c24899a6="VP/g/CV/Vl/1/CF////%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:c5705860="Vx////%%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:c6c5dd44="V/////%%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:c99a5f5c="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:d1abcdb6="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:d94388d2="b/Af/X6/alAl/YP/HPAi/Yq/GPAf/Yb/GPAz/B2/FlAk/Xh////%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:e46c271e="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:e8f9dcc7="UlAr/XJ/c//k////"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:f0bf0bde="///%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:f1f24e29="Vl/l/C/////%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:f2c53c49="UlAr/XJ/c//k////"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:f6ad6fa6="V/////%%"
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722\22286396302236360\eae10f9d]:fe94ce1e="V/////%%"
~ Export Key Software: Scanned in 00mn 00s



---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.BC8FAF80A6FEE9CA7D51F744A6F0D45E] [WIS][31.03.2014] (.ReSoft Ltd. - Shopping Helper Smartbar.) -- C:\Windows\Installer\1fa64a3c.msi [9502720] =>Hijacker.SmartBar
[MD5.0A517BFDBF16092D7D813FAA69BB7F65] [WIS][09.02.2014] (.LPT - LPT System Updater Service.) -- C:\Windows\Installer\1fa64a42.msi [1712128] =>Adware.IncrediBar
[MD5.8855552919EDB0C2E28D1AC589FD5162] [WIS][28.04.2015] (.APN, LLC - Search App by Ask.) -- C:\Windows\Installer\3852b53f.msi [516096] =>Toolbar.Ask
~ WIS: 3 Legitimates Filtered in 00mn 03s



---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}] (Linkey) =>PUP.LinkeySearch
~ BCK: 5312 Legitimates Filtered in 00mn 06s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Auto 31.01.2013 1626872 | (BlueSoleilCS) . (.IVT Corporation.) - C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe
SS - | Auto 07.10.2014 409304 | (BstHdAndroidSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-Service.exe
SS - | Auto 28.01.2013 241264 | (CLKMSVC10_38F51D56) . (.CyberLink.) - C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe
SS - | Demand 25.01.2014 279000 | (cphs) . (.Intel Corporation.) - C:\Windows\SysWow64\IntelCpHeciSvc.exe
SS - | Auto 03.05.2014 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 03.05.2014 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 03.05.2014 194032 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
SS - | Demand 10.12.2012 803872 | (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
SS - | Demand 10.04.2015 1931632 | (Origin Client Service) . (.Electronic Arts.) - C:\Program Files (x86)\Origin\OriginClientService.exe
SS - | Auto 06.04.2015 37144 | (wbsvc) . (.Web Bar Media.) - C:\Program Files\WebBar\wbsvc.exe =>PUP.WebBar
SR - | Auto 01.05.2015 1792552 | (4abaf598) . (...) - c:\Program Files (x86)\Optimizer Pro 3.86\OptProMon.dll =>PUP.OptimizerPro
SR - | Auto 19.12.2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 28.04.2015 178568 | (APNMCP) . (.APN LLC..) - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe =>Toolbar.AskBar
SR - | Auto 28.08.2014 43336 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 12.03.2014 214512 | (AVP) . (.Kaspersky Lab ZAO.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe
SR - | Auto 30.08.2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Demand 10.01.2013 138752 | (BsHelpCS) . (.IVT Corporation.) - C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe
SR - | Auto 07.10.2014 388824 | (BstHdLogRotatorSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
SR - | Auto 07.10.2014 782040 | (BstHdUpdaterSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
SR - | Auto 07.02.2013 1641768 | (FPLService) . (.HP.) - C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe
SR - | Auto 04.11.2013 92160 | (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe =>.Hewlett-Packard Co
SR - | Demand 13.05.2013 1129760 | (hpqwmiex) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
SR - | Auto 01.03.2013 43320 | (hpsrv) . (.Hewlett-Packard Company.) - C:\Windows\System32\Hpservice.exe
SR - | Auto 26.03.2014 469304 | (HPWMISVC) . (.Hewlett-Packard Development Company, L.P..) - c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
SR - | Auto 30.08.2013 15720 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
SR - | Auto 10.12.2012 732160 | (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe
SR - | Auto 22.02.2013 129848 | (Intel(R) ME Service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
SR - | Demand 01.09.2014 640840 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 13.02.2013 180200 | (ISCTAgent) . (...) - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
SR - | Auto 22.02.2013 167736 | (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
SR - | Auto 22.02.2013 364856 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 07.03.2013 884512 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe
SR - | Auto 07.03.2013 1260320 | (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
SR - | Auto 17.07.2014 339456 | (STacSV) . (.IDT, Inc..) - C:\Program Files\IDT\WDM\STacSV64.exe
SR - | Demand 07.01.2013 401856 | (TrueService) . (.AuthenTec, Inc..) - C:\Program Files\Common Files\AuthenTec\TrueService.exe
SR - | Auto 19.03.2013 28160 | (valWBFPolicyService) . (...) - C:\Windows\system32\valWBFPolicyService.exe
SR - | Auto 14.04.2015 686592 | (WaNetworkEnhance Service) . (...) - C:\Program Files (x86)\WaNetworkEnhance\WaNetworkEnhance Internet Enhancer\InternetEnhancerService.exe
SR - | Demand 22.07.1658 0 | (WdNisSvc) . (...) - C:\Program Files (x86)\Windows Defender\NisSrv.exe
SR - | Demand 22.07.1658 0 | (WinDefend) . (...) - C:\Program Files (x86)\Windows Defender\MsMpEng.exe
SR - | Auto 22.07.1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
SR - | Demand 29.10.2014 38792 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 07s



---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Run by PC-PC at 02.05.2015 21:21:26
~ OS 64 not supported by MBR tool
~ MBR: 0 Legitimates Filtered in 00mn 00s



---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by PC-PC at 02.05.2015 21:21:28
********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 02s



---\\ Scan Additionnel (O88)
Database Version : 13008 - (02.05.2015)
Clés trouvées (Keys found) : 31
Valeurs trouvées (Values found) : 3
Dossiers trouvés (Folders found) : 7
Fichiers trouvés (Files found) : 19

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}] =>PUP.LinkeySearch^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4F524A2D-5350-4500-76A7-7A786E7484D7}] =>Toolbar.AskBar^
[HKLM\SYSTEM\CurrentControlSet\Services\4abaf598] =>PUP.OptimizerPro^
[HKLM\SYSTEM\CurrentControlSet\Services\APNMCP] =>Toolbar.AskBar^
[HKLM\SYSTEM\CurrentControlSet\Services\wbsvc) (wbsvc] =>PUP.WebBar^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}] =>Adware.IncrediBar^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4F524A2D-5350-4500-76A7-A758B70C1C01}] =>Toolbar.Ask^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AC6E9B2A-A7E6-4B17-8A6C-29D519673E12}] =>Hijacker.SmartBar^
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{12c1b278-9702-42fe-9f7c-46123468fd27}] =>Hijacker.SmartBar^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WaNetworkEnhance] =>PUP.Wajam^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0BCE8B0A-1E76-44E5-9909-3CF804D92E4D}_is1] =>PUP.WebBar^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall] =>PUP.StartSearch^
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software
[HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software
[HKLM\Software\Classes\protector_dll.protectorbho.1] =>PUP.BProtector
[HKLM\Software\Classes\protector_dll.protectorbho] =>PUP.BProtector
[HKCU\Software\APN PIP] =>Toolbar.Ask
[HKLM\Software\Wow6432Node\Iminent] =>Adware.IMBooster
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP] =>Adware.IMBooster
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP] =>Adware.IMBooster
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect] =>PUP.Conduit
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect] =>PUP.Conduit
[HKCU\Software\AskPartnerNetwork] =>Toolbar.Ask
[HKLM\Software\AskPartnerNetwork] =>Toolbar.Ask
[HKLM\Software\Wow6432Node\AskPartnerNetwork] =>Toolbar.Ask
[HKCU\Software\HomeTab] =>PUP.CertifiedToolbar
[HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro
[HKLM\Software\Wow6432Node\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar] =>Adware.IMBooster
[HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}] =>Adware.Bandoo^
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{4F524A2D-5350-4500-76A7-7A786E7484D7} =>Toolbar.AskBar^
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:Optimizer Pro =>PUP.OptimizerPro^
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:ApnTBMon =>Toolbar.AskBar^
C:\Program Files (x86)\AskPartnerNetwork =>Toolbar.AskBar^
C:\Program Files (x86)\Wajam =>PUP.Wajam^
C:\Program Files (x86)\WaNetworkEnhance =>PUP.Wajam^
C:\ProgramData\AskPartnerNetwork =>Toolbar.AskBar^
C:\Users\PC-PC\AppData\Roaming\mystartsearch =>PUP.StartSearch^
C:\Users\PC-PC\AppData\Local\AskPartnerNetwork =>Toolbar.AskBar^
C:\Users\PC-PC\AppData\Local\WebBar =>PUP.WebBar^
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe =>Toolbar.AskBar^
C:\Program Files\WebBar\wbsvc.exe =>PUP.WebBar^
C:\Windows\Tasks\PCHelpers1st.job =>PUP.OptimizerEliteMax^
C:\Windows\System32\Tasks\PCHelpers1st =>PUP.OptimizerEliteMax^
C:\Windows\Tasks\PCHelpers_period.job =>PUP.OptimizerEliteMax^
C:\Windows\System32\Tasks\PCHelpers_period =>PUP.OptimizerEliteMax^
[HKCU\Software\Smartbar] =>Hijacker.SmartBar^
[HKCU\Software\WajIEnhance] =>PUP.Wajam^
[HKCU\Software\melondrea] =>PUP.Melondrea^
[HKLM\Software\Linkey] =>PUP.LinkeySearch^
[HKLM\Software\WebBar] =>PUP.WebBar^
[HKLM\Software\Wow6432Node\Conduit] =>Toolbar.Conduit^
[HKLM\Software\Wow6432Node\SystemK] =>PUP.SystemK^
[HKLM\Software\Wow6432Node\a793fa8f-95f1-3872-edcf-d7fd574ea722] =>PUP.CrossRider^
[HKLM\Software\Wow6432Node\melondrea] =>PUP.Melondrea^
C:\Windows\Installer\1fa64a3c.msi =>Hijacker.SmartBar^
C:\Windows\Installer\1fa64a42.msi =>Adware.IncrediBar^
C:\Windows\Installer\3852b53f.msi =>Toolbar.Ask^
[HKCR\CLSID\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}] (Linkey) =>PUP.LinkeySearch^
~ Additionnel Scan: 389170 Items scanned in 00mn 33s



---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/g0-page-de-demarrage-google-chrome/ =>.Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
~ http://nicolascoolman.fr/g2-google-chrome-extensions/ =>.Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects de navigateur (O2)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ AMI: 6 Legitimates Filtered in 00mn 00s



---\\ Récapitulatif des détections trouvées sur votre station
http://www.nicolascoolman.fr/blog/ =>Toolbar.AskBar
http://nicolascoolman.fr/pup-startsearch =>PUP.StartSearch
http://nicolascoolman.fr/hijacker-proxy =>Hijacker.Proxy
http://nicolascoolman.fr/pup-linkeysearch =>PUP.LinkeySearch
http://nicolascoolman.fr/pup-optimizerpro =>PUP.OptimizerPro
http://www.nicolascoolman.fr/blog/ =>PUP.WebBar
http://nicolascoolman.fr/pup-optimizerelitemax =>PUP.OptimizerEliteMax
http://nicolascoolman.fr/adware-incredibar =>Adware.IncrediBar
http://nicolascoolman.fr/toolbar-ask =>Toolbar.Ask
http://nicolascoolman.fr/hijacker-smartbar =>Hijacker.SmartBar
http://nicolascoolman.fr/pup-wajam =>PUP.Wajam
http://nicolascoolman.fr/pup-certifiedtoolbar =>PUP.CertifiedToolbar
http://nicolascoolman.fr/pup-melondrea =>PUP.Melondrea
http://nicolascoolman.fr/toolbar-conduit =>Toolbar.Conduit
http://nicolascoolman.fr/adware-imbooster =>Adware.IMBooster
http://nicolascoolman.fr/pup-systemk =>PUP.SystemK
http://nicolascoolman.fr/pup-crossrider =>PUP.CrossRider
http://nicolascoolman.fr/hijacker-browsers =>Hijacker.Browsers
http://nicolascoolman.fr/pup-v9software =>PUP.V9Software
http://nicolascoolman.fr/pup-bprotector =>PUP.BProtector
http://www.nicolascoolman.fr/blog/ =>PUP.Conduit
http://nicolascoolman.fr/adware-bandoo =>Adware.Bandoo
~ MSI: 22 link(s) detected in 00mn 00s



---\\ Alert Messages
WARNING : Hijacker Proxy found, Clean with ZHPCleaner Tool

~ 782 Legitimates filtered by white list
End of the scan (689 lines in 02mn 24s)(0.10)

Publicité


Signaler le contenu de ce document

Publicité