cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2014.12.27.179 - Nicolas Coolman (27/12/2014)
~ Lancé par win (11/05/2015 15:42:15)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Nouvelle version disponible
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Not Found


---\\ Navigateurs Internet
MSIE: Internet Explorer v6.0.2900.5512
GCIE: Google Chrome v35.0.1916.114 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Microsoft Windows XP, 32-bit Service Pack 3 (Build 2600)
Windows Automatic Updates : OK
Windows Genuine Advantage : OK
Windows Guenuine Advantage (antiwpa) : OK =>PUP.Wpakill

---\\ Logiciels de protection du système

---\\ Logiciels d'optimisation du système
CCleaner

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 13 ActiveX
Adobe Reader X - Français
Java 7 Update 60

---\\ Informations sur le système
~ Processor: x86 Family 6 Model 58 Stepping 9, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 1921 MB (77% free)
System Restore: Activé (Enable)
System drive C: has 32 GB (32%) free of 98 GB

---\\ Mode de connexion au système
~ Computer Name: USER
~ User Name: win
~ All Users Names: win, SUPPORT_388945a0, HelpAssistant, ASPNET, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Documents and Settings\win\Application Data\ZHP\
~ %AppData% : C:\Documents and Settings\win\Application Data\
~ %Desktop% : C:\Documents and Settings\win\Bureau\
~ %Favorites% : C:\Documents and Settings\win\Favoris\
~ %LocalAppData% : C:\Documents and Settings\win\Local Settings\Application Data\
~ %StartMenu% : C:\Documents and Settings\win\Menu Démarrer\
~ %Windir% : C:\WINDOWS\
~ %System% : C:\WINDOWS\system32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 32 Go of 98 Go)
D: Hard drive, Flash drive, Thumb drive (Free 193 Go of 195 Go)
E: Hard drive, Flash drive, Thumb drive (Free 172 Go of 173 Go)
F: Floppy drive, Flash card reader, USB Key (Not Inserted)
G: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
~ Security Center: 47 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.BCFE894467AC9C3BD94059BC6E3A0E08] - (.Microsoft Corporation - Explorateur Windows.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\Explorer.exe [1065472]
[MD5.4A6E04EA20F48D750D9BFED8600D516B] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\wininet.dll [670208]
[MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows NT.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Winlogon.exe [512000]
[MD5.322D0E36693D6E24A2398BEE62A268CD] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\AFD.sys [138112]
[MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\atapi.sys [96512]
[MD5.C885B02847F5D2FD45A24E219ED93B32] - (.Microsoft Corporation - CD-ROM File System Driver.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\Cdfs.sys [63744]
[MD5.1F4260CC5B42272D71F79E570A27A4FE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\Cdrom.sys [62976]
[MD5.31F923EB2170FC172C81ABDA0045D18C] - (.Microsoft Corporation - Pilote de cryptographie FIPS.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\Fips.sys [44672]
[MD5.573C7D0A32852B48F3058CFD8026F511] - (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\HDAudBus.sys [144384]
[MD5.083A052659F5310DD8B6A6CB05EDCF8E] - (.Microsoft Corporation - IMAPI Kernel Driver.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\Imapi.sys [42112]
[MD5.CC748EA12C6EFFDE940EE98098BF96BB] - (.Microsoft Corporation - IP Network Address Translator.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\IpNat.sys [152832]
[MD5.23C74D75E36E7158768DD63D92789A91] - (.Microsoft Corporation - IPSec Driver.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\IPSec.sys [75264]
[MD5.68755F0FF16070178B54674FE5B847B0] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\MRxSmb.sys [456576]
[MD5.74B2B2F5BEA5E9A3DC021D685551BD3D] - (.Microsoft Corporation - MBT Transport driver.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\netBT.sys [162816]
[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\ntfs.sys [574976]
[MD5.8FD0BDBEA875D06CCF6C945CA9ABAF75] - (.Microsoft Corporation - Pilote de port parallèle.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\Parport.sys [80384]
[MD5.11B4A627BC9614B885C4969BFA5FF8A6] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\Rasl2tp.sys [51328]
[MD5.15CABD0F7C00C47C70124907916AF3F1] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.13/04/2008 - 09:32:52.) -- C:\WINDOWS\system32\Drivers\rdpdr.sys [196224]
[MD5.D8EB2A7904DB6C916EB5361878DDCBAE] - (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) (.13/04/2008 - 18:57:36.) -- C:\WINDOWS\system32\Drivers\redbook.sys [58752]
[MD5.46DE1126684369BACE4849E4FC8C43CA] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.27/04/2007 - 03:37:00.) -- C:\WINDOWS\system32\Drivers\volsnap.sys [53376]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/2
~ Mes musiques (My Musics) : 1/2
~ Mes Favoris (My Favorites) : 1/6
~ Mes Documents (My Documents) : 2/281
~ Mon Bureau (My Desktop) : 1/21
~ Menu demarrer (Programs) : 1/29
~ Hidden Files: Scanned in 00mn 00s



---\\ Processus lancés
[MD5.BAD6BEA0DE1F69C82BDB74378CE0C20A] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe [932288] [PID.2024]
[MD5.6ECDDB12DF3765B36C59D7B3C9E3E65D] - (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\System32\WScript.exe [184320] [PID.124]
[MD5.71D8F6D5DC35517275BC38EBCC815F9F] - (.AutoIt Team - AutoIt v3 Script.) -- C:\Google\AutoIt3.exe [750320] [PID.256]
[MD5.1F153EC5635BFEE5326145B872C527E1] - (.Intel Corporation - igfxTray Module.) -- C:\WINDOWS\system32\igfxtray.exe [144880] [PID.264]
[MD5.567BE23D24BB494DAEF7B05EDE628C98] - (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\system32\hkcmd.exe [182768] [PID.276]
[MD5.4213D515EAABD76710D2D055598A0E98] - (.Intel Corporation - persistence Module.) -- C:\WINDOWS\system32\igfxpers.exe [170992] [PID.304]
[MD5.A846816E1C18A53BEBD02CB08F351552] - (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.exe [20118088] [PID.420]
[MD5.8F27080C762E074B8F39A904FD630B7D] - (.ESET - ESET GUI.) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [3117344] [PID.428]
[MD5.A01E058BE6C37F438F14470BFF944EC6] - (...) -- C:\mustaphaCDRom1\MustaphaCDRom.exe [627200] [PID.612]
[MD5.E87885A59FDC241B6575943A75E495D9] - (.Oracle Corporation - Java Quick Starter Service.) -- C:\Program Files\Java\jre7\bin\jqs.exe [182696] [PID.1680]
[MD5.4C2FECBFE3E630ECB1FE64938AD86850] - (.Microsoft Corporation - Telnet.) -- C:\WINDOWS\system32\tlntsvr.exe [102912] [PID.1964]
[MD5.1C72EAEDB7B68A43795D14CFC2C4FF70] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe [120832] [PID.3936]
[MD5.FF1516C8C5864F574373F6C7B64EA057] - (...) -- C:\Documents and Settings\win\Local Settings\Temp\mact.exe [31914] [PID.3664]
[MD5.8D5E30909246371204FA47539FBF20A2] - (.Microsoft Corporation - Windows® installer.) -- C:\WINDOWS\system32\msiexec.exe [106496] [PID.2608]
[MD5.3F12C9A93757DCEB7FB1F5539628789A] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8173056] [PID.1712]
[MD5.AD4FAADE819E0DA9933BEA7C01D2C763] - (.ESET - ESET Service.) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [913144] [PID.1740]
~ Processes Running: Scanned in 00mn 00s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Documents and Settings\win\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Drive v.6.3 (Activé)
G2 - GCE: Preference [User Data\Default] [mfffpogegjflfpflabcdkioaeobkgjik] GaiaAuthExtension v.0.0.1, (Activé)
G2 - GCE: Preference [User Data\Default] [neajdppkdcdipfabeoofebfddakdcjhd] Google Network Speech v.1.0 (Activé)
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.6.1 (Activé)
G2 - GCE: Preference [User Data\Default] [pafkbggdmjlpgkdkcbjmhmfcdpncadgh] Google Now v.1.2.0.1 (Activé)

---\\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 18 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 1
~ IE Browser: 11 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\WINDOWS\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (0)
~ Hosts File: Scanned in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{01E04581-4EEE-11D0-BFE9-00AA005B4383} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{0E5CBF21-D15F-11D0-8301-00AA005B4383} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated
O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe =>.Oracle Corporation
O4 - HKLM\..\Run: [AssistedTelephonyMaj] . (.Alctal Telecom - ALCATMAJ.) -- C:\WINDOWS\Inf\ALCATMAJ.exe
O4 - HKLM\..\Run: [Serviecs.vbs] . (...) -- C:\Documents and Settings\win\Local Settings\Temp\Serviecs.vbs
O4 - HKLM\..\Run: [Windows Update] . (...) -- C:\Google\Windowsupdate.lnk
O4 - HKLM\..\Run: [JavaUpdate] . (...) -- C:\Google\GoogleUpdate.lnk
O4 - HKLM\..\Run: [NewJavaInstall] . (.AutoIt Team - AutoIt v3 Script.) -- C:\Google\AutoIt3.exe
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] . (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.exe =>.Realtek Semiconductor Corp
O4 - HKLM\..\Run: [egui] . (.ESET - ESET GUI.) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Serviecs.vbs] . (...) -- C:\Documents and Settings\win\Local Settings\Temp\Serviecs.vbs
O4 - HKCU\..\Run: [Windows Update] . (...) -- C:\Google\Windowsupdate.lnk
O4 - HKCU\..\Run: [AdopeUpdate] . (...) -- C:\Google\GoogleUpdate.lnk
O4 - HKCU\..\Run: [AdopeFlash] . (.AutoIt Team - AutoIt v3 Script.) -- C:\Google\AutoIt3.exe
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (.not file.)
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (.not file.)
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
O4 - HKUS\S-1-5-21-117609710-1336601894-682003330-1003\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-117609710-1336601894-682003330-1003\..\Run: [Serviecs.vbs] . (...) -- C:\Documents and Settings\win\Local Settings\Temp\Serviecs.vbs
O4 - HKUS\S-1-5-21-117609710-1336601894-682003330-1003\..\Run: [Windows Update] . (...) -- C:\Google\Windowsupdate.lnk
O4 - HKUS\S-1-5-21-117609710-1336601894-682003330-1003\..\Run: [AdopeUpdate] . (...) -- C:\Google\GoogleUpdate.lnk
O4 - HKUS\S-1-5-21-117609710-1336601894-682003330-1003\..\Run: [AdopeFlash] . (.AutoIt Team - AutoIt v3 Script.) -- C:\Google\AutoIt3.exe
~ Application: Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -- Clé orpheline
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {05CA9FB0-3E3E-4b36-BF41-0E3A5CAA8CD8} ((no name)) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} ((no name)) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} ((no name)) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123705518796
O16 - DPF: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3} ((no name)) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1139406804265
~ Objets ActiveX: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{09B8183A-46C4-47F3-9627-6A33EE6F5417}: NameServer = 10.0.0.249
O17 - HKLM\System\CS1\Services\Tcpip\..\{09B8183A-46C4-47F3-9627-6A33EE6F5417}: NameServer = 10.0.0.249
O17 - HKLM\System\CS2\Services\Tcpip\..\{09B8183A-46C4-47F3-9627-6A33EE6F5417}: NameServer = 10.0.0.249
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} . (.Microsoft Corporation - WIA Scripting Layer.) -- C:\WINDOWS\system32\wiascr.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: Antiwpa . (.Pas de propriétaire - AntiWPA3 for X86.) -- C:\WINDOWS\system32\antiwpa.dll =>PUP.Wpakill
O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\WINDOWS\system32\crypt32.dll
O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\WINDOWS\system32\cryptnet.dll
O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agent réseau hors connexion.) -- C:\WINDOWS\system32\cscdll.dll
O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\system32\dimsntfy.dll
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\WINDOWS\system32\igfxdev.dll
O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL secondaire de notification de service d.) -- C:\WINDOWS\system32\sclgntfy.dll
O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\WlNotify.dll
O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Desktop General: BackupWallPaper - .(...) - C:\Documents and Settings\win\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop General: WallPaper - .(...) - C:\Documents and Settings\win\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
~ Desktop Component: 4 Legitimates Filtered in 00mn 00s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\Afu]
[HKCU\Software\Elwofdd]
~ Key Software: 126 Legitimates Filtered in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 09/06/2014 - 15:49:10 - [] R---D C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Jeux
~ Program Folder: 94 Legitimates Filtered in 00mn 00s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.886164E10D40D90C5162AA02C109941C] - 10/05/2015 - 12:10:06 RSH-- . (...) -- C:\vsvie.exe [103140]
O44 - LFC:[MD5.180C61197633ED74C196D14E42BEE1ED] - 11/05/2015 - 10:30:58 RSH-- . (...) -- C:\autorun.inf [238]
O44 - LFC:[MD5.6396DC1DDDA3270933279931453B2918] - 11/05/2015 - 10:30:58 RSH-- . (...) -- C:\wabkyj.exe [130787]
O44 - LFC:[MD5.0ADAD4EB46285A98C48084DA759E6EFB] - 11/05/2015 - 12:13:44 ---A- . (...) -- C:\WINDOWS\setupapi.old [644600]
O44 - LFC:[MD5.A799EA2E17F8C6747801E37F25FE078F] - 11/05/2015 - 12:21:29 R--A- . (...) -- C:\WINDOWS\SET6A.tmp [1246130]
O44 - LFC:[MD5.7DEBF83AF61B07063EF0CEEADD4B4E59] - 11/05/2015 - 12:21:30 R--A- . (...) -- C:\WINDOWS\SET6D.tmp [1088840]
O44 - LFC:[MD5.619D9DD12A0BFDB080A86CE19F09CA10] - 11/05/2015 - 12:21:31 R--A- . (...) -- C:\WINDOWS\SET79.tmp [16825]
O44 - LFC:[MD5.E582B44F1BFB54DCF745CFD8AE0A8F61] - 11/05/2015 - 12:21:44 ---A- . (...) -- C:\WINDOWS\regopt.log [2722]
O44 - LFC:[MD5.E06F91604E104480520388C83540012C] - 11/05/2015 - 12:21:44 ---A- . (...) -- C:\WINDOWS\system.ini [264]
O44 - LFC:[MD5.73D97E793986D9F5188AFD76A05C9F8A] - 11/05/2015 - 12:25:47 ---A- . (...) -- C:\WINDOWS\wiadebug.log [393]
O44 - LFC:[MD5.6F97A266B33CC394083058F4DB250505] - 11/05/2015 - 12:25:47 ---A- . (...) -- C:\WINDOWS\wiaservc.log [50]
O44 - LFC:[MD5.A168F4764EDB3AF34C920BFBE294C48E] - 11/05/2015 - 12:26:05 ---A- . (...) -- C:\WINDOWS\system32\pid.PNF [4444]
O44 - LFC:[MD5.5E3B5FE561BE7CDC61B18029BC6D2958] - 11/05/2015 - 12:31:23 ---A- . (...) -- C:\WINDOWS\cmsetacl.log [373]
O44 - LFC:[MD5.39F43DBCE366B2561DF073B4C0839299] - 11/05/2015 - 12:31:58 ---A- . (...) -- C:\WINDOWS\Bulles de savon.bmp [65978]
O44 - LFC:[MD5.1AC5E83598D4F2143B59A2D893C3279A] - 11/05/2015 - 12:31:58 ---A- . (...) -- C:\WINDOWS\Granit vert.bmp [26582]
O44 - LFC:[MD5.203EF178BF8B0A8EC34E27E4DEDB6349] - 11/05/2015 - 12:31:58 ---A- . (...) -- C:\WINDOWS\Jour de pêche.bmp [17336]
O44 - LFC:[MD5.EB3BFC14E41FBAA41B4FD4489AA82D39] - 11/05/2015 - 12:31:58 ---A- . (...) -- C:\WINDOWS\Mur de Santa Fe.bmp [65832]
O44 - LFC:[MD5.3A8B85AB7B415BF3F8AFE285DFE0CE29] - 11/05/2015 - 12:31:58 ---A- . (...) -- C:\WINDOWS\Plume.bmp [16730]
O44 - LFC:[MD5.927A66BD587E31CB12D3AB25381658DC] - 11/05/2015 - 12:31:58 ---A- . (...) -- C:\WINDOWS\Rhododendron.bmp [17362]
O44 - LFC:[MD5.5B4AC407E566076BB726BA91E067D313] - 11/05/2015 - 12:31:58 ---A- . (...) -- C:\WINDOWS\Rivière Sumida.bmp [26680]
O44 - LFC:[MD5.DAC71A10A6A71CB6E3F427AE3283734B] - 11/05/2015 - 12:31:58 ---A- . (...) -- C:\WINDOWS\Rosace bleue 16.bmp [1272]
O44 - LFC:[MD5.73D70ED3EC3BBFD8FD35DF431C38F374] - 11/05/2015 - 12:31:58 ---A- . (...) -- C:\WINDOWS\Tasse à café.bmp [17062]
O44 - LFC:[MD5.280920B6773C74C3649A934257112BE1] - 11/05/2015 - 12:31:58 ---A- . (...) -- C:\WINDOWS\Vent de prairie.bmp [65954]
O44 - LFC:[MD5.5290EA6951F4724259F423B12C8E1393] - 11/05/2015 - 12:31:58 ---A- . (...) -- C:\WINDOWS\Zapotec.bmp [9522]
O44 - LFC:[MD5.772F25ACD2DF75FEEB7D307BA9C06D6B] - 11/05/2015 - 12:32:01 ---A- . (...) -- C:\WINDOWS\msmqinst.log [22550]
O44 - LFC:[MD5.4CCE5918BB9B5C97806487730D7B634D] - 11/05/2015 - 12:32:06 ---A- . (...) -- C:\WINDOWS\DtcInstall.log [247]
O44 - LFC:[MD5.A6A0FE21F0E4412FDB681662D93509AE] - 11/05/2015 - 12:32:19 ---A- . (...) -- C:\WINDOWS\system32\emptyregdb.dat [23660]
O44 - LFC:[MD5.58D8E9B83D2FECD09F99C0EF146A08BC] - 11/05/2015 - 12:32:42 ---A- . (...) -- C:\WINDOWS\netfxocm.log [6663]
O44 - LFC:[MD5.3C0EB89A954640E7742681256A2E0E12] - 11/05/2015 - 12:32:44 ---A- . (...) -- C:\WINDOWS\FaxSetup.log [29318]
O44 - LFC:[MD5.8B9AB939A1FD22DCBA2B32DFBA369A3E] - 11/05/2015 - 12:32:44 ---A- . (...) -- C:\WINDOWS\MedCtrOC.log [3547]
O44 - LFC:[MD5.7E63F19A97C37E4CACCB6F070A7E97AC] - 11/05/2015 - 12:32:44 ---A- . (...) -- C:\WINDOWS\msgsocm.log [871]
O44 - LFC:[MD5.D07D4258CC0964E51772A5CD2D8942D2] - 11/05/2015 - 12:32:44 ---A- . (...) -- C:\WINDOWS\ocgen.log [32929]
O44 - LFC:[MD5.521758C38A09F59475153B40142166CB] - 11/05/2015 - 12:32:44 ---A- . (...) -- C:\WINDOWS\sessmgr.setup.log [2063]
O44 - LFC:[MD5.8FBEC4D51D39DB985490F7C049AF488E] - 11/05/2015 - 12:32:57 -SH-- . (...) -- C:\WINDOWS\winnt.bmp [49102]
O44 - LFC:[MD5.8FBEC4D51D39DB985490F7C049AF488E] - 11/05/2015 - 12:32:57 -SH-- . (...) -- C:\WINDOWS\winnt256.bmp [49102]
O44 - LFC:[MD5.E9D723EAD26DAC6C3D2248C4131D8688] - 11/05/2015 - 12:33:09 ---A- . (...) -- C:\WINDOWS\win.ini [582]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 11/05/2015 - 12:33:17 R-HA- . (...) -- C:\WINDOWS\WindowsShell.Manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 11/05/2015 - 12:33:17 R-HA- . (...) -- C:\WINDOWS\system32\cdplayer.exe.manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 11/05/2015 - 12:33:17 R-HA- . (...) -- C:\WINDOWS\system32\ncpa.cpl.manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 11/05/2015 - 12:33:17 R-HA- . (...) -- C:\WINDOWS\system32\nwc.cpl.manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 11/05/2015 - 12:33:17 R-HA- . (...) -- C:\WINDOWS\system32\sapi.cpl.manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 11/05/2015 - 12:33:17 R-HA- . (...) -- C:\WINDOWS\system32\wuaucpl.cpl.manifest [749]
O44 - LFC:[MD5.5D76C3FB736514E1D7C88791E7322784] - 11/05/2015 - 12:33:19 R-HA- . (...) -- C:\WINDOWS\system32\WindowsLogon.manifest [488]
O44 - LFC:[MD5.5D76C3FB736514E1D7C88791E7322784] - 11/05/2015 - 12:33:19 R-HA- . (...) -- C:\WINDOWS\system32\logonui.exe.manifest [488]
O44 - LFC:[MD5.2B9C717D21A1331BA3731886E3EE87BB] - 11/05/2015 - 12:33:52 ---A- . (...) -- C:\WINDOWS\ODBCINST.INI [4205]
O44 - LFC:[MD5.8501E064CC0CA642A17FC6E81FCB20F9] - 11/05/2015 - 12:33:54 ---A- . (...) -- C:\WINDOWS\OEWABLog.txt [1280]
O44 - LFC:[MD5.DC17DD0189B0C36D863B4DD0A036C10F] - 11/05/2015 - 12:33:58 ---A- . (...) -- C:\WINDOWS\WMSysPr9.prx [316640]
O44 - LFC:[MD5.6D6F4B1886E91EB37ABCCAD19C561EE0] - 11/05/2015 - 12:33:58 ---A- . (...) -- C:\WINDOWS\system32\amcompat.tlb [16832]
O44 - LFC:[MD5.A32B14BE5EDAE794FCE1A9E970827509] - 11/05/2015 - 12:33:58 ---A- . (...) -- C:\WINDOWS\system32\nscompat.tlb [23392]
O44 - LFC:[MD5.4DE429EE80E759FED37C6243EEB84AC9] - 11/05/2015 - 12:34:00 ---A- . (...) -- C:\WINDOWS\wmsetup.log [4057]
O44 - LFC:[MD5.033632E79AE66AA85986DAC00ACA878F] - 11/05/2015 - 12:35:19 ---A- . (...) -- C:\WINDOWS\system32\$winnt$.inf [316]
O44 - LFC:[MD5.C511CFA72797D4937CEC72912ABBBC92] - 11/05/2015 - 12:35:29 ---A- . (...) -- C:\WINDOWS\iis6.log [116055]
O44 - LFC:[MD5.77BF9E952F8B003DD915DD5DC0A857BA] - 11/05/2015 - 12:35:29 ---A- . (...) -- C:\WINDOWS\imsins.log [4382]
O44 - LFC:[MD5.782CDF563C59CF6F8CA445E01E1EADC7] - 11/05/2015 - 12:35:29 ---A- . (...) -- C:\WINDOWS\ntdtcsetup.log [20634]
O44 - LFC:[MD5.7083BFA46C053C0E04095989B16F1CBF] - 11/05/2015 - 12:35:29 ---A- . (...) -- C:\WINDOWS\ocmsn.log [885]
O44 - LFC:[MD5.CD80D01678554E358211F4BB3748FFB6] - 11/05/2015 - 12:35:29 ---A- . (...) -- C:\WINDOWS\tabletoc.log [2815]
O44 - LFC:[MD5.2C5783EF913B430C6238103F8E59CDBD] - 11/05/2015 - 12:35:29 ---A- . (...) -- C:\WINDOWS\tsoc.log [25489]
O44 - LFC:[MD5.68653AD976E868D2541E767F32F6FF09] - 11/05/2015 - 12:35:30 ---A- . (...) -- C:\WINDOWS\setuplog.txt [689367]
O44 - LFC:[MD5.E12A2179C146E397F0A03DCFA714BCBB] - 11/05/2015 - 12:39:51 ---A- . (...) -- C:\WINDOWS\comsetup.log [39751]
O44 - LFC:[MD5.CD3429B33D0917799EAEBBB9423BFCFA] - 11/05/2015 - 12:50:06 ---A- . (...) -- C:\WINDOWS\COM+.log [3086]
O44 - LFC:[MD5.6BE93BF8ACA460552C2FCB4A54E045DB] - 11/05/2015 - 14:34:57 ---A- . (...) -- C:\WINDOWS\WINDOWS.lnk [637]
~ Files: 78 Legitimates Filtered in 00mn 16s



---\\ Opérations et fonctions au démarrage de Windows Explorer (O46)
O46 - SEH:ShellExecuteHooks - URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll
~ ShellExecuteHooks: Scanned in 00mn 00s



---\\ Export de clé d'application autorisée (O47)
O47 - AAKE:Key Export SP - "H:\htwhu.exe" [Enabled] .(...) -- H:\htwhu.exe (.not file.)
O47 - AAKE:Key Export SP - "C:\Program Files\Common Files\Microsoft Shared\explorer.exe" [Enabled] .(.Pas de propriétaire.) -- C:\Program Files\Common Files\Microsoft Shared\explorer.exe
O47 - AAKE:Key Export SP - "C:\DOCUME~1\win\LOCALS~1\Temp\winpxfq.exe" [Enabled] .(...) -- C:\DOCUME~1\win\LOCALS~1\Temp\winpxfq.exe (.not file.)
O47 - AAKE:Key Export SP - "C:\DOCUME~1\win\LOCALS~1\Temp\IXP001.TMP\dxwsetup.exe" [Enabled] .(...) -- C:\DOCUME~1\win\LOCALS~1\Temp\IXP001.TMP\dxwsetup.exe (.not file.)
O47 - AAKE:Key Export SP - "C:\WINDOWS\system32\rundll32.exe" [Enabled] Clé orpheline
O47 - AAKE:Key Export SP - "C:\DOCUME~1\win\LOCALS~1\Temp\winyjia.exe" [Enabled] .(...) -- C:\DOCUME~1\win\LOCALS~1\Temp\winyjia.exe (.not file.)
O47 - AAKE:Key Export SP - "C:\DOCUME~1\win\LOCALS~1\Temp\cbia.exe" [Enabled] .(...) -- C:\DOCUME~1\win\LOCALS~1\Temp\cbia.exe (.not file.)
O47 - AAKE:Key Export SP - "C:\DOCUME~1\win\LOCALS~1\Temp\lrbnq.exe" [Enabled] .(...) -- C:\DOCUME~1\win\LOCALS~1\Temp\lrbnq.exe (.not file.)
O47 - AAKE:Key Export SP - "C:\DOCUME~1\win\LOCALS~1\Temp\publfm.exe" [Enabled] .(...) -- C:\DOCUME~1\win\LOCALS~1\Temp\publfm.exe (.not file.)
O47 - AAKE:Key Export SP - "C:\DOCUME~1\win\LOCALS~1\Temp\winxkmwc.exe" [Enabled] .(...) -- C:\DOCUME~1\win\LOCALS~1\Temp\winxkmwc.exe (.not file.)
O47 - AAKE:Key Export SP - "C:\DOCUME~1\win\LOCALS~1\Temp\winoqbk.exe" [Enabled] .(...) -- C:\DOCUME~1\win\LOCALS~1\Temp\winoqbk.exe (.not file.)
O47 - AAKE:Key Export SP - "C:\DOCUME~1\win\LOCALS~1\Temp\pblmr.exe" [Enabled] .(...) -- C:\DOCUME~1\win\LOCALS~1\Temp\pblmr.exe (.not file.)
O47 - AAKE:Key Export SP - "C:\mustaphaCDRom1\MustaphaCDRom.exe" [Enabled] .(.Pas de propriétaire.) -- C:\mustaphaCDRom1\MustaphaCDRom.exe
O47 - AAKE:Key Export SP - "C:\DOCUME~1\win\LOCALS~1\Temp\winohmgyp.exe" [Enabled] .(...) -- C:\DOCUME~1\win\LOCALS~1\Temp\winohmgyp.exe (.not file.)
O47 - AAKE:Key Export SP - "C:\DOCUME~1\win\LOCALS~1\Temp\mact.exe" [Enabled] .(.Pas de propriétaire.) -- C:\DOCUME~1\win\LOCALS~1\Temp\mact.exe
~ Keys Export: 33 Legitimates Filtered in 00mn 00s



---\\ Image File Execution Options (IFEO) (O50)
O50 - IFEO:Image File Execution Options - 360rp.exe - ntsd -d
O50 - IFEO:Image File Execution Options - 360rpt.exe - ntsd -d
O50 - IFEO:Image File Execution Options - 360Safe.exe - ntsd -d
O50 - IFEO:Image File Execution Options - 360safebox.exe - ntsd -d
O50 - IFEO:Image File Execution Options - 360sd.exe - ntsd -d
O50 - IFEO:Image File Execution Options - 360tray.exe - ntsd -d
O50 - IFEO:Image File Execution Options - 799d.exe - ntsd -d
O50 - IFEO:Image File Execution Options - adam.exe - ntsd -d
O50 - IFEO:Image File Execution Options - AgentSvr.exe - ntsd -d
O50 - IFEO:Image File Execution Options - AntiU.exe - ntsd -d
O50 - IFEO:Image File Execution Options - AoYun.exe - ntsd -d
O50 - IFEO:Image File Execution Options - appdllman.exe - ntsd -d
O50 - IFEO:Image File Execution Options - AppSvc32.exe - ntsd -d
O50 - IFEO:Image File Execution Options - ArSwp.exe - ntsd -d
O50 - IFEO:Image File Execution Options - ArSwp2.exe - ntsd -d
O50 - IFEO:Image File Execution Options - ArSwp3.exe - ntsd -d
O50 - IFEO:Image File Execution Options - AST.exe - ntsd -d
O50 - IFEO:Image File Execution Options - auto.exe - ntsd -d
O50 - IFEO:Image File Execution Options - AutoRun.exe - ntsd -d
O50 - IFEO:Image File Execution Options - autoruns.exe - ntsd -d
O50 - IFEO:Image File Execution Options - av.exe - ntsd -d
O50 - IFEO:Image File Execution Options - AvastU3.exe - ntsd -d
O50 - IFEO:Image File Execution Options - avconsol.exe - ntsd -d
O50 - IFEO:Image File Execution Options - avgrssvc.exe - ntsd -d
O50 - IFEO:Image File Execution Options - AvMonitor.exe - ntsd -d
O50 - IFEO:Image File Execution Options - avp.com - ntsd -d
O50 - IFEO:Image File Execution Options - avp.exe - ntsd -d
O50 - IFEO:Image File Execution Options - AvU3Launcher.exe - ntsd -d
O50 - IFEO:Image File Execution Options - CCenter.exe - ntsd -d
O50 - IFEO:Image File Execution Options - ccSvcHst.exe - ntsd -d
O50 - IFEO:Image File Execution Options - cross.exe - ntsd -d
O50 - IFEO:Image File Execution Options - Discovery.exe - ntsd -d
O50 - IFEO:Image File Execution Options - DSMain.exe - ntsd -d
O50 - IFEO:Image File Execution Options - EGHOST.exe - ntsd -d
O50 - IFEO:Image File Execution Options - FileDsty.exe - ntsd -d
O50 - IFEO:Image File Execution Options - filmst.exe - ntsd -d
O50 - IFEO:Image File Execution Options - FTCleanerShell.exe - ntsd -d
O50 - IFEO:Image File Execution Options - FYFireWall.exe - ntsd -d
O50 - IFEO:Image File Execution Options - ghost.exe - ntsd -d
O50 - IFEO:Image File Execution Options - guangd.exe - ntsd -d
O50 - IFEO:Image File Execution Options - HijackThis.exe - ntsd -d
O50 - IFEO:Image File Execution Options - IceSword.exe - ntsd -d
O50 - IFEO:Image File Execution Options - iparmo.exe - ntsd -d
O50 - IFEO:Image File Execution Options - Iparmor.exe - ntsd -d
O50 - IFEO:Image File Execution Options - irsetup.exe - ntsd -d
O50 - IFEO:Image File Execution Options - isPwdSvc.exe - ntsd -d
O50 - IFEO:Image File Execution Options - jisu.exe - ntsd -d
O50 - IFEO:Image File Execution Options - kabaload.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KaScrScn.SCR - ntsd -d
O50 - IFEO:Image File Execution Options - KASMain.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KASTask.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KAV32.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KAVDX.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KAVPF.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KAVPFW.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KAVSetup.exe - ntsd -d
O50 - IFEO:Image File Execution Options - kavstart.exe - ntsd -d
O50 - IFEO:Image File Execution Options - kernelwind32.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KISLnchr.exe - ntsd -d
O50 - IFEO:Image File Execution Options - kissvc.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KMailMon.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KMFilter.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KPFW32.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KPFW32X.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KPfwSvc.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KRegEx.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KRepair.com - ntsd -d
O50 - IFEO:Image File Execution Options - KsLoader.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KVCenter.kxp - ntsd -d
O50 - IFEO:Image File Execution Options - KvDetect.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KvfwMcl.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KVMonXP.kxp - ntsd -d
O50 - IFEO:Image File Execution Options - KVMonXP_1.kxp - ntsd -d
O50 - IFEO:Image File Execution Options - kvol.exe - ntsd -d
O50 - IFEO:Image File Execution Options - kvolself.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KvReport.kxp - ntsd -d
O50 - IFEO:Image File Execution Options - KVScan.kxp - ntsd -d
O50 - IFEO:Image File Execution Options - KVSrvXP.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KVStub.kxp - ntsd -d
O50 - IFEO:Image File Execution Options - kvupload.exe - ntsd -d
O50 - IFEO:Image File Execution Options - kvwsc.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KvXP.kxp - ntsd -d
O50 - IFEO:Image File Execution Options - KvXP_1.kxp - ntsd -d
O50 - IFEO:Image File Execution Options - KWatch.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KWatch9x.exe - ntsd -d
O50 - IFEO:Image File Execution Options - KWatchX.exe - ntsd -d
O50 - IFEO:Image File Execution Options - loaddll.exe - ntsd -d
O50 - IFEO:Image File Execution Options - logogo.exe - ntsd -d
O50 - IFEO:Image File Execution Options - MagicSet.exe - ntsd -d
O50 - IFEO:Image File Execution Options - mcconsol.exe - ntsd -d
O50 - IFEO:Image File Execution Options - mmqczj.exe - ntsd -d
O50 - IFEO:Image File Execution Options - mmsk.exe - ntsd -d
O50 - IFEO:Image File Execution Options - Navapsvc.exe - ntsd -d
O50 - IFEO:Image File Execution Options - Navapw32.exe - ntsd -d
O50 - IFEO:Image File Execution Options - NAVSetup.exe - ntsd -d
O50 - IFEO:Image File Execution Options - niu.exe - ntsd -d
O50 - IFEO:Image File Execution Options - nod32.exe - ntsd -d
O50 - IFEO:Image File Execution Options - nod32krn.exe - ntsd -d
O50 - IFEO:Image File Execution Options - nod32kui.exe - ntsd -d
O50 - IFEO:Image File Execution Options - NPFMntor.exe - ntsd -d
O50 - IFEO:Image File Execution Options - pagefile.exe - ntsd -d
O50 - IFEO:Image File Execution Options - pagefile.pif - ntsd -d
O50 - IFEO:Image File Execution Options - pfserver.exe - ntsd -d
O50 - IFEO:Image File Execution Options - PFW.exe - ntsd -d
O50 - IFEO:Image File Execution Options - PFWLiveUpdate.exe - ntsd -d
O50 - IFEO:Image File Execution Options - qheart.exe - ntsd -d
O50 - IFEO:Image File Execution Options - QHSET.exe - ntsd -d
O50 - IFEO:Image File Execution Options - QQDoctor.exe - ntsd -d
O50 - IFEO:Image File Execution Options - QQDoctorMain.exe - ntsd -d
O50 - IFEO:Image File Execution Options - QQDoctorRtp.exe - ntsd -d
O50 - IFEO:Image File Execution Options - QQKav.exe - ntsd -d
O50 - IFEO:Image File Execution Options - QQSC.exe - ntsd -d
O50 - IFEO:Image File Execution Options - qsetup.exe - ntsd -d
O50 - IFEO:Image File Execution Options - Ras.exe - ntsd -d
O50 - IFEO:Image File Execution Options - Rav.exe - ntsd -d
O50 - IFEO:Image File Execution Options - ravcopy.exe - ntsd -d
O50 - IFEO:Image File Execution Options - RavMon.exe - ntsd -d
O50 - IFEO:Image File Execution Options - RavMonD.exe - ntsd -d
O50 - IFEO:Image File Execution Options - RavStub.exe - ntsd -d
O50 - IFEO:Image File Execution Options - RavTask.exe - ntsd -d
O50 - IFEO:Image File Execution Options - RegClean.exe - ntsd -d
O50 - IFEO:Image File Execution Options - rfwcfg.exe - ntsd -d
O50 - IFEO:Image File Execution Options - rfwmain.exe - ntsd -d
O50 - IFEO:Image File Execution Options - rfwProxy.exe - ntsd -d
O50 - IFEO:Image File Execution Options - rfwsrv.exe - ntsd -d
O50 - IFEO:Image File Execution Options - RsAgent.exe - ntsd -d
O50 - IFEO:Image File Execution Options - Rsaupd.exe - ntsd -d
O50 - IFEO:Image File Execution Options - rsnetsvr.exe - ntsd -d
O50 - IFEO:Image File Execution Options - RsTray.exe - ntsd -d
O50 - IFEO:Image File Execution Options - rstrui.exe - ntsd -d
O50 - IFEO:Image File Execution Options - runiep.exe - ntsd -d
O50 - IFEO:Image File Execution Options - safeboxTray.exe - ntsd -d
O50 - IFEO:Image File Execution Options - safelive.exe - ntsd -d
O50 - IFEO:Image File Execution Options - scan32.exe - ntsd -d
O50 - IFEO:Image File Execution Options - ScanFrm.exe - ntsd -d
O50 - IFEO:Image File Execution Options - ScanU3.exe - ntsd -d
O50 - IFEO:Image File Execution Options - SDGames.exe - ntsd -d
O50 - IFEO:Image File Execution Options - SelfUpdate.exe - ntsd -d
O50 - IFEO:Image File Execution Options - servet.exe - ntsd -d
O50 - IFEO:Image File Execution Options - shcfg32.exe - ntsd -d
O50 - IFEO:Image File Execution Options - SmartUp.exe - ntsd -d
O50 - IFEO:Image File Execution Options - sos.exe - ntsd -d
O50 - IFEO:Image File Execution Options - SREng.EXE - ntsd -d
O50 - IFEO:Image File Execution Options - SREngPS.EXE - ntsd -d
O50 - IFEO:Image File Execution Options - stormii.exe - ntsd -d
O50 - IFEO:Image File Execution Options - sxgame.exe - ntsd -d
O50 - IFEO:Image File Execution Options - symlcsvc.exe - ntsd -d
O50 - IFEO:Image File Execution Options - SysSafe.exe - ntsd -d
O50 - IFEO:Image File Execution Options - tmp.exe - ntsd -d
O50 - IFEO:Image File Execution Options - TNT.Exe - ntsd -d
O50 - IFEO:Image File Execution Options - TrojanDetector.exe - ntsd -d
O50 - IFEO:Image File Execution Options - Trojanwall.exe - ntsd -d
O50 - IFEO:Image File Execution Options - TrojDie.kxp - ntsd -d
O50 - IFEO:Image File Execution Options - TxoMoU.Exe - ntsd -d
O50 - IFEO:Image File Execution Options - UFO.exe - ntsd -d
O50 - IFEO:Image File Execution Options - UIHost.exe - ntsd -d
O50 - IFEO:Image File Execution Options - UmxAgent.exe - ntsd -d
O50 - IFEO:Image File Execution Options - UmxAttachment.exe - ntsd -d
O50 - IFEO:Image File Execution Options - UmxCfg.exe - ntsd -d
O50 - IFEO:Image File Execution Options - UmxFwHlp.exe - ntsd -d
O50 - IFEO:Image File Execution Options - UmxPol.exe - ntsd -d
O50 - IFEO:Image File Execution Options - upiea.exe - ntsd -d
O50 - IFEO:Image File Execution Options - UpLive.exe - ntsd -d
O50 - IFEO:Image File Execution Options - USBCleaner.exe - ntsd -d
O50 - IFEO:Image File Execution Options - vsstat.exe - ntsd -d
O50 - IFEO:Image File Execution Options - wbapp.exe - ntsd -d
O50 - IFEO:Image File Execution Options - webscanx.exe - ntsd -d
O50 - IFEO:Image File Execution Options - WoptiClean.exe - ntsd -d
O50 - IFEO:Image File Execution Options - Wsyscheck.exe - ntsd -d
O50 - IFEO:Image File Execution Options - XDelBox.exe - ntsd -d
O50 - IFEO:Image File Execution Options - XP.exe - ntsd -d
O50 - IFEO:Image File Execution Options - zhudongfangyu.exe - ntsd -d
O50 - IFEO:Image File Execution Options - zjb.exe - ntsd -d
O50 - IFEO:Image File Execution Options - zxsweep.exe - ntsd -d
O50 - IFEO:Image File Execution Options - ~.exe - ntsd -d
~ IFEO: Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKCU\...\Policies\System] - "DisableTaskMgr"=1
O55 - MWPS:[HKCU\...\Policies\System] - "DisableRegistryTools"=1
~ MWPS: 9 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "ForceClassicControlPanel"=1
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoResolveTrack"=1
O56 - MWPE:[HKCU\...\policies\Explorer] - "LinkResolveIgnoreLinkInfo"=1
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoResolveSearch"=1
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoSMHelp"=1
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoStartMenuPinnedList"=1
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoSMConfigurePrograms"=1
~ MWPE Keys: 8 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (.RAVISENT Technologies Inc. - Pilote principal CineMaster C 1.2 WDM.) -- C:\WINDOWS\system32\Drivers\cinemst2.sys [262528]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) -- C:\WINDOWS\system32\Drivers\hdaudbus.sys [144384]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (.Parallel Technologies, Inc. - Parallel Technologies DirectParallel IO Library.) -- C:\WINDOWS\system32\Drivers\ptilink.sys [17792]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (.RAVISENT Technologies Inc. - CineMaster C WDM DVD Minidriver.) -- C:\WINDOWS\system32\Drivers\vdmindvd.sys [58112]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\ansi.sys [9037]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\country.sys [27097]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\himem.sys [4912]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\key01.sys [42809]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\keyboard.sys [42537]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos.sys [27916]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos404.sys [29146]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos411.sys [29370]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos412.sys [29274]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos804.sys [29146]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\ntio.sys [34000]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\ntio404.sys [34560]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\ntio411.sys [35648]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\ntio412.sys [35424]
O58 - SDL:27/04/2007 - 03:37:00 ---A- . (...) -- C:\WINDOWS\system32\ntio804.sys [34560]
~ Drivers: 40 Legitimates Filtered in 00mn 01s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - 11/04/1745 - C:\WINDOWS\system32\drivers\nlmgkq.sys (amsint32) .(...) - LEGACY_AMSINT32
~ Legacy: 116 Legitimates Filtered in 00mn 01s



---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 10 Legitimates Filtered in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://search.live.com
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.514982E9C77F9047A896947ECD64A121] [SPRF][11/05/2015] (...) -- C:\Documents and Settings\win\Bureau\htc.reg [606]
~ Files: 3 Legitimates Filtered in 00mn 00s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 27/04/2007 252928 | (dmadmin) . (.Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\dmadmin.exe
SS - | Auto 09/06/2014 116648 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 09/06/2014 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SR - | Auto 07/03/2012 913144 | (ekrn) . (.ESET.) - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
SR - | Auto 09/06/2014 182696 | (JavaQuickStarterService) . (.Oracle Corporation.) - C:\Program Files\Java\jre7\bin\jqs.exe
~ Services: Scanned in 00mn 06s



---\\ Scan Additionnel (O88)
Database Version : 13026 - (27/12/2014)
Clés trouvées (Keys found) : 0
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 0

~ Additionnel Scan: 152695 Items scanned in 00mn 11s



---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/g2-google-chrome-extensions/ =>.Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ http://nicolascoolman.fr/o50-image-file-execution-options-zhpdiag/ =>.Image File Execution Options (IFEO) (O50)
~ AMI: 5 Legitimates Filtered in 00mn 00s



---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/33243679-pup-wpakill =>PUP.Wpakill
~ MSI: 1 link(s) detected in 00mn 00s



~ 702 Legitimates filtered by white list
End of the scan (684 lines in 00mn 49s)(0)

Publicité


Signaler le contenu de ce document

Publicité