cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2015.6.4.54 - Nicolas Coolman (31/05/2015)
~ Lancé par david (13/08/2015 20:55:29)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Nouvelle version disponible
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17914
MFIE: Mozilla Firefox 23.0.1
GCIE: Google Chrome v44.0.2403.155

---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows Operating System - Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 3Q6C9
Windows License : OK
~ Windows Remaining Initializations Number : 2
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)

---\\ Logiciels de protection du système
Microsoft Security Client v4.8.0204.0
Windows Defender W7 (Deactivate)

---\\ Logiciels d'optimisation du système
CCleaner v5.07

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Reader XI

---\\ Informations sur le système
~ Processor: AMD64 Family 16 Model 6 Stepping 2, AuthenticAMD
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 4092 MB (27% free)
System Restore: Activé (Enable)
System drive C: has 403 GB (89%) free of 452 GB

---\\ Mode de connexion au système
~ Computer Name: DAVID-PC
~ User Name: david
~ All Users Names: david, Administrateur,
~ Unselected Option: None
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\david\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\david\AppData\Roaming\
~ %Desktop% : C:\Users\david\Desktop\
~ %Favorites% : C:\Users\david\Favorites\
~ %LocalAppData% : C:\Users\david\AppData\Local\
~ %StartMenu% : C:\Users\david\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 403 Go of 452 Go)
D: Hard drive, Flash drive, Thumb drive (Free 2 Go of 14 Go)
E: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)
F: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
~ Security Center: 49 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.E066FDC3A2074D926903B8C31EF3B347] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.20/06/2015 - 19:26:01.) -- C:\Windows\System32\wininet.dll [2427392]
[MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.17/07/2014 - 03:07:24.) -- C:\Windows\System32\Winlogon.exe [455168]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.FA886682CFC5D36718D3E436AACF10B9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:45:52.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.1877EB1495CFBDAB27D6A32F6DDF3818] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.01/07/2015 - 20:27:34.) -- C:\Windows\system32\Drivers\MRxSmb.sys [159232]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:37:55.) -- C:\Windows\system32\Drivers\ntfs.sys [1684928]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.70988118145F5F10EF24720B97F35F65] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:46:26.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/104
~ Mes musiques (My Musics) : 3/11
~ Mes Videos (My Videos) : 1/170
~ Mes Favoris (My Favorites) : 1/68
~ Mes Documents (My Documents) : 6/284
~ Mon Bureau (My Desktop) : 1/1406
~ Menu demarrer (Programs) : 1/50
~ Hidden Files: Scanned in 00mn 00s



---\\ Processus lancés
[MD5.732ED03303FEE8003E2922D87ABF9903] - (...) -- C:\Program Files (x86)\LuckyBrowse\app\luckybrowse.exe [585728] [PID.1828]
[MD5.A5F78606A9BA8F0C4C8FF9DED6ED5107] - (.Hewlett-Packard - HP Advisor.) -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe [1685048] [PID.2312]
[MD5.019D774B725DCFD9A188F07764A32214] - (. Hewlett-Packard Development Company, L.P. - Quick Launch Buttons.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe [322104] [PID.2460]
[MD5.5516C26A6AF8EB4E2CAB48EC98A74398] - (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe [54576] [PID.2468]
[MD5.BDEFC081D02C162DCB90738BE432D66B] - (.Easybits - Software update notification.) -- C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1258504] [PID.2540]
[MD5.1CE55AE7E57826457FD56EB3C50E4E54] - (.CyberLink Corp. - HP MediaSmart TV Resident Program.) -- c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe [415016] [PID.3280]
[MD5.C6331D11F80B3AFFD91A9B3858E00F23] - (.CyberLink - CyberLink MediaLibray Service.) -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [210216] [PID.3436]
[MD5.0DE3C7622EC33126579B1742260F08C2] - (.Pas de propriétaire - HpqToaster Module.) -- C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe [632888] [PID.3632]
[MD5.F820401D0D2754C3A78C707927058A41] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896] [PID.1536]
[MD5.12E2FC1F74265881402DE856D01EFFFE] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8214016] [PID.3952]
[MD5.013697369EAFFA675D0671607F036020] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [82128] [PID.1604]
[MD5.EF4073DBDE481B51782B915DA5496CF0] - (.SFR - SFR.Dashboard.Service.) -- C:\Program Files (x86)\SFR\Gestionnaire de Connexion\SFR.DashBoard.Service.exe [32160] [PID.1844]
[MD5.EC9739A46F1F83C6E52A7A4697F44A65] - (.Hewlett-Packard Company - hpqwmiex Module.) -- C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [799800] [PID.2212]
[MD5.F9A79C5B27037821112C50A9C8FB367A] - (.Hewlett-Packard Development Company, L.P. - Com for QLB application.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [228408] [PID.3380]
~ Processes Running: Scanned in 00mn 00s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Preferences

---\\ Liste des dossiers d'extension Google Chrome
G2 - EXT: C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [__MSG_appName__]
~ Google Lines Browser: 6 Legitimates Filtered in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\f83wjcap.default\prefs.js
M3 - MFPP: Plugins - [david] -- C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\f83wjcap.default\searchplugins\Yahoo!.xml
M0 - MFSP: prefs.js [david - f83wjcap.default] http://www.bing.com
M2 - MFEP: Extension [david - f83wjcap.default] j004-efxyrmbzyotmaw@jetpack.xpi
M2 - MFEP: Extension [david - f83wjcap.default] staged
M2 - MFEP: Extension [david - f83wjcap.default] trash
M2 - MFEP: Extension [david - f83wjcap.default] {e2dd7c12-8e49-8b22-cbb2-c69b9d1d18fe}
~ Firefox Browser: 26 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\SystemTools [david]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe http://yourwebing.com =>Hijacker.Browsers
~ Global Startup: 1 Legitimates Filtered in 00mn 01s



---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.)
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray64.exe
O4 - HKLM\..\Run: [SmartMenu] . (.Pas de propriétaire - SmartMenu.) -- C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKCU\..\Run: [HPADVISOR] . (.Hewlett-Packard - HP Advisor.) -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (.not file.)
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd
O4 - HKLM\..\Wow6432Node\Run: [HPCam_Menu] . (.CyberLink Corp. - MUI StartMenu Application.) -- c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe
O4 - HKLM\..\Wow6432Node\Run: [QlbCtrl.exe] . (. Hewlett-Packard Development Company, L.P. - Quick Launch Buttons.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
O4 - HKLM\..\Wow6432Node\Run: [HP Software Update] . (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe =>.Hewlett-Packard Co
O4 - HKLM\..\Wow6432Node\Run: [WirelessAssistant] . (.Hewlett-Packard Company - HP Wireless Assistant Main Program.) -- C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Wow6432Node\Run: [Magic Desktop for HP notification] . (.Easybits - Software update notification.) -- C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-685536127-3515990415-680006497-1000\..\Run: [HPADVISOR] . (.Hewlett-Packard - HP Advisor.) -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
O4 - HKUS\S-1-5-21-685536127-3515990415-680006497-1000\..\Run: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (.not file.)
O4 - HKUS\S-1-5-21-685536127-3515990415-680006497-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd
~ Application: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{DAB07047-1A4F-4C2A-9F9E-42D483F07B0A}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{DAB07047-1A4F-4C2A-9F9E-42D483F07B0A}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{DAB07047-1A4F-4C2A-9F9E-42D483F07B0A}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: LuckyBrowse (LuckyBrowse) . (.Pas de propriétaire - ServiceStarter.) - C:\Program Files (x86)\LuckyBrowse\app\luckyBrowseStarter.exe
~ Services: 7 Legitimates Filtered in 00mn 04s



---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [JDDFNWGDJL1] (...) -- C:\ProgramData\TomorrowGames\TomorrowGames.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{0DFE59E7-D739-458C-B9F3-FA47264BC268}] (...) -- C:\Program Files (x86)\SFR\Gestionnaire de Connexion SFR\ABCd.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{1B651464-EA0B-4921-BB42-71E033FDDDCB}] (...) -- C:\Users\david\Downloads\install_www--1551-flashplayer.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{5DDF57A4-C1AE-49E5-A832-603FC63003F3}] (...) -- C:\Program Files (x86)\SearchProtect\bin\uninstall.exe (.not file.) [0] =>PUP.SearchProtect
[MD5.00000000000000000000000000000000] [APT] [{772ED3AB-4724-4C7D-91A2-8F9733057079}] (...) -- C:\Program Files (x86)\SFR\Gestionnaire de Connexion SFR\ABCd.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{89FD545F-EDDE-4DEB-A88B-A56C39CB3891}] (...) -- C:\Users\david\AppData\Roaming\webssearches\UninstallManager.exe (.not file.) [0] =>Hijacker.WebsSearches
[MD5.FDDB0E0F6E067F386186CFF764984BB9] [APT] [{C5BB827B-26A2-4F33-9ADD-E4FAA143BF5B}] (.LowRateVoip.) -- C:\Program Files (x86)\LowRateVoip.com\LowRateVoip\LowRateVoip.exe [19452736]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1062]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1066]
O39 - APT: JDDFNWGDJL1 - (...) -- C:\Windows\Tasks\JDDFNWGDJL1.job [354]
O39 - APT: JDDFNWGDJL1 - (...) -- C:\Windows\System32\Tasks\JDDFNWGDJL1 [354]
~ Scheduled Task: 50 Legitimates Filtered in 00mn 04s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\Activeris] =>PUP.Activeris
[HKCU\Software\OB]
[HKCU\Software\PluginAddon]
[HKCU\Software\Smartbar] =>Hijacker.SmartBar
[HKLM\Software\CouponDownloader ] =>PUP.CouponDownloader
[HKLM\Software\F2E59BED-97F5-4486-9726-66DE2DDE3B23] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Activeris] =>PUP.Activeris
[HKLM\Software\Wow6432Node\LuckyBrowse]
[HKLM\Software\Wow6432Node\MaxPower]
[HKLM\Software\Wow6432Node\RrFilter] =>PUP.SupraSavings
[HKLM\Software\Wow6432Node\anset]
~ Key Software: 229 Legitimates Filtered in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 30/11/2014 - 13:48:51 - [] ----D C:\Program Files (x86)\F2E59BED-97F5-4486-9726-66DE2DDE3B23
O43 - CFD: 09/08/2015 - 21:13:04 - [] ----D C:\Program Files (x86)\LuckyBrowse
O43 - CFD: 09/08/2015 - 21:12:09 - [] ----D C:\ProgramData\19a87fa1ec024bbcbb41931263354405
O43 - CFD: 09/08/2015 - 21:13:05 - [] ----D C:\ProgramData\LuckyBrowse
O43 - CFD: 09/08/2015 - 21:13:02 - [0] ----D C:\ProgramData\Service1104
O43 - CFD: 13/08/2015 - 00:17:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
O43 - CFD: 19/07/2015 - 14:32:58 - [] ----D C:\Users\david\AppData\Roaming\.lifecraft
O43 - CFD: 13/08/2015 - 01:07:54 - [] ----D C:\Users\david\AppData\Roaming\Elex-tech =>PUP.Elex
O43 - CFD: 07/09/2013 - 13:59:25 - [] ----D C:\Users\david\AppData\Roaming\TFP
O43 - CFD: 17/05/2014 - 03:42:33 - [] ----D C:\Users\david\AppData\Local\com
O43 - CFD: 14/03/2010 - 15:15:38 - [] ----D C:\Users\david\AppData\Local\{816D4EC3-C307-4638-B68C-7AEDA7A1E9D6}
~ 1012 Dossier CLSID vide (CLSID Empty Folder)
~ Program Folder: 1247 Legitimates Filtered in 00mn 23s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 10/08/2015 - 21:30:51 ---A- . (...) -- C:\autoexec.bat [0]
~ Files: 12 Legitimates Filtered in 00mn 02s



---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.FB6BD893EF7FB7564CD3483E5BBB270C] - 10/08/2015 - 21:30:31 ---A- - C:\Windows\Prefetch\SPYHUNTER4.EXE-7BD5E907.pf =>Crapware.SpyHunter
~ Prefetcher: 1 Legitimates Filtered in 00mn 00s



---\\ Clé de registre Shell MountPoints2 (MPSK) (O51)
O51 - MPSK:{09dc636e-b05d-11e0-9ee3-00269eb6c27b}\AutoRun\command. (...) -- G:\SFR.exe (.not file.)
O51 - MPSK:{156390f0-b1f7-11e0-91e1-00269eb6c27b}\AutoRun\command. (...) -- G:\SFR.exe (.not file.)
O51 - MPSK:{4096f97d-4bd5-11e3-ab9c-00269eb6c27b}\AutoRun\command. (...) -- G:\SFR.exe (.not file.)
O51 - MPSK:{4096f988-4bd5-11e3-ab9c-00269eb6c27b}\AutoRun\command. (...) -- H:\SFR.exe (.not file.)
O51 - MPSK:{4c170f6b-b547-11e0-8858-00269eb6c27b}\AutoRun\command. (...) -- G:\SFR.exe (.not file.)
O51 - MPSK:{4c170f86-b547-11e0-8858-00269eb6c27b}\AutoRun\command. (...) -- G:\SFR.exe (.not file.)
O51 - MPSK:{5bd6b8f5-dad3-11e3-81a4-00269eb6c27b}\AutoRun\command. (...) -- G:\SFR.exe (.not file.)
O51 - MPSK:{5bd6b8f8-dad3-11e3-81a4-00269eb6c27b}\AutoRun\command. (...) -- G:\SFR.exe (.not file.)
O51 - MPSK:{78ca8714-2952-11df-82fe-00269eb6c27b}\AutoRun\command. (...) -- G:\SFR.exe (.not file.)
O51 - MPSK:{78ca8756-2952-11df-82fe-00269eb6c27b}\AutoRun\command. (...) -- G:\Vodaphone_uninstaller.exe (.not file.)
O51 - MPSK:{86ad3ee0-b20b-11e0-9e58-00269eb6c27b}\AutoRun\command. (...) -- G:\SFR.exe (.not file.)
O51 - MPSK:{a16309fa-2f6c-11df-af37-00269eb6c27b}\AutoRun\command. (...) -- G:\SFR.exe (.not file.)
O51 - MPSK:{d89a188e-82d1-11e3-899b-00269eb6c27b}\AutoRun\command. (...) -- G:\SFR.exe (.not file.)
O51 - MPSK:{d89a1890-82d1-11e3-899b-00269eb6c27b}\AutoRun\command. (...) -- G:\SFR.exe (.not file.)
O51 - MPSK:{d89a1894-82d1-11e3-899b-00269eb6c27b}\AutoRun\command. (...) -- G:\SFR.exe (.not file.)
~ Keys: Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 20 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoLowDiskSpaceChecks"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 12 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
O58 - SDL:29/06/2009 - 19:17:00 ---A- . (.ENE TECHNOLOGY INC. - ENE CIR Driver for eHome(64).) -- C:\Windows\System32\Drivers\enecir.sys [70656]
O58 - SDL:25/09/2013 - 16:08:46 ---A- . (.Huawei Tech. Co., Ltd. - HUAWEI USB Smart Card Driver.) -- C:\Windows\System32\Drivers\ewdcsc.sys [32768]
O58 - SDL:10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
O58 - SDL:25/09/2013 - 16:08:46 ---A- . (.DiBcom SA - DiBcom AVSTREAM BDA driver.) -- C:\Windows\System32\Drivers\mod7700.sys [1001472]
O58 - SDL:14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
O58 - SDL:22/07/2009 - 02:33:32 ---A- . (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\Drivers\stwrt64.sys [487936]
~ Drivers: 74 Legitimates Filtered in 00mn 00s



---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 09/08/2015 - 20:56:24 ---A- . (...) -- C:\Users\david\AppData\Local\Microsoft\Internet Explorer\UrlBlockManager\urlblocklist.bin [0]
O61 - LFC: 13/08/2015 - 20:56:24 ---A- . (...) -- C:\Users\david\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [1113849]
O61 - LFC: 13/08/2015 - 20:56:25 ---A- . (...) -- C:\Users\david\Downloads\adwcleaner_4.208 (2).exe [2248704]
~ 110 Fichiers temporaires (Temporary files)
~ 4 Fichiers cookies (Cookies files)
~ Files: 9 Legitimates Filtered in 00mn 01s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\iirsp.sys (iirsp) .(.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) - LEGACY_IIRSP
~ Legacy: 121 Legitimates Filtered in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115..clientLogIsEnabled", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.AppTrackingLastCheckTime", "Thu Jun 14 2012 22:47:42 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.BrowserCompStateIsOpen_129659302320675289", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.BrowserCompStateIsOpen_129780208973942041", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.BrowserCompStateIsOpen_129784494686275364", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.BrowserCompStateIsOpen_129790546080283738", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.BrowserCompStateIsOpen_1366638976000", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.BrowserCompStateIsOpen_1367226505000", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.CTID", "CT2542115");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.CurrentServerDate", "10-11-2013");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.DialogsAlignMode", "LTR");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.DialogsGetterLastCheckTime", "Sun Nov 10 2013 17:05:09 GMT+0100");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.DownloadReferralCookieData", "");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.EMailNotifierPollDate", "Wed Apr 03 2013 21:23:25 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedLastCount3702671119025834822", 989);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579606993571455", "Fri Oct 28 2011 23:24:06 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579607031076616", "Fri Oct 28 2011 23:24:03 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579607120332248", "Fri Oct 28 2011 23:24:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579607120463320", "Fri Oct 28 2011 23:24:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579607120528856", "Fri Oct 28 2011 23:24:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579607120594392", "Fri Oct 28 2011 23:24:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579607120659928", "Fri Oct 28 2011 23:24:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579607254614839", "Fri Oct 28 2011 23:24:04 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579607731405437", "Fri Oct 28 2011 23:24:03 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579608231640385", "Fri Oct 28 2011 23:24:03 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579608467137450", "Fri Oct 28 2011 23:24:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579608468016907", "Fri Oct 28 2011 23:24:03 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579608628136389", "Fri Oct 28 2011 23:24:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579608675890832", "Fri Oct 28 2011 23:24:03 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579608833656362", "Fri Oct 28 2011 23:24:04 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579609299927420", "Fri Oct 28 2011 23:24:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579609521108563", "Fri Oct 28 2011 23:24:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579609576983218", "Fri Oct 28 2011 23:24:03 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579610226745907", "Fri Oct 28 2011 23:24:06 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579610508907107", "Fri Oct 28 2011 23:24:04 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate1154579610709294640", "Fri Oct 28 2011 23:24:03 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189313", "Thu Aug 12 2010 00:00:25 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189319", "Thu Aug 12 2010 00:00:25 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189325", "Thu Aug 12 2010 00:00:25 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189331", "Thu Aug 12 2010 00:00:25 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189337", "Thu Aug 12 2010 00:00:25 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189343", "Thu Aug 12 2010 00:00:25 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189349", "Thu Aug 12 2010 00:00:25 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189355", "Thu Aug 12 2010 00:00:25 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189361", "Thu Aug 12 2010 00:00:25 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189367", "Thu Aug 12 2010 00:00:25 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189373", "Thu Aug 12 2010 00:00:25 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189379", "Thu Aug 12 2010 00:00:26 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189385", "Thu Aug 12 2010 00:00:26 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189391", "Thu Aug 12 2010 00:00:26 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189397", "Thu Aug 12 2010 00:00:26 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189403", "Thu Aug 12 2010 00:00:26 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189409", "Thu Aug 12 2010 00:00:26 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189415", "Thu Aug 12 2010 00:00:26 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189421", "Thu Aug 12 2010 00:00:26 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189427", "Thu Aug 12 2010 00:00:26 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129212453356189433", "Thu Aug 12 2010 00:00:26 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915761", "Thu Mar 31 2011 12:09:05 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915767", "Thu Mar 31 2011 12:09:05 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915773", "Thu Mar 31 2011 12:09:05 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915779", "Thu Mar 31 2011 12:09:06 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915785", "Thu Mar 31 2011 12:09:06 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915791", "Thu Mar 31 2011 12:09:06 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915797", "Thu Mar 31 2011 12:09:06 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915803", "Thu Mar 31 2011 12:09:06 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915809", "Thu Mar 31 2011 12:09:06 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915815", "Thu Mar 31 2011 12:09:06 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915821", "Thu Mar 31 2011 12:09:06 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915827", "Thu Mar 31 2011 12:09:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915833", "Thu Mar 31 2011 12:09:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915839", "Thu Mar 31 2011 12:09:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915845", "Thu Mar 31 2011 12:09:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915851", "Thu Mar 31 2011 12:09:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915857", "Thu Mar 31 2011 12:09:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915863", "Thu Mar 31 2011 12:09:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915869", "Thu Mar 31 2011 12:09:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915875", "Thu Mar 31 2011 12:09:07 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate129255209834915881", "Thu Mar 31 2011 12:09:08 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671116010200387", "Sat Jun 19 2010 23:23:24 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671116247168829", "Sat Jun 19 2010 23:23:23 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671116333354629", "Sat Jun 19 2010 23:23:23 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671116345354421", "Sat Jun 19 2010 23:23:24 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671116431452240", "Sat Jun 19 2010 23:23:23 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671116465124373", "Sat Jun 19 2010 23:23:23 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671116530052943", "Sat Jun 19 2010 23:23:24 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671116544676229", "Sat Jun 19 2010 23:23:22 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671116824931754", "Sat Jun 19 2010 23:23:22 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671116887165206", "Sat Jun 19 2010 23:23:24 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671117050235810", "Sat Jun 19 2010 23:23:23 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671117473300114", "Sat Jun 19 2010 23:23:22 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671118292815052", "Sat Jun 19 2010 23:23:23 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671118503245856", "Sat Jun 19 2010 23:23:23 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671118542975718", "Sat Jun 19 2010 23:23:24 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671118557300311", "Sat Jun 19 2010 23:23:23 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671118775564128", "Sat Jun 19 2010 23:23:24 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671118779732141", "Sat Jun 19 2010 23:23:23 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671118881041330", "Sat Jun 19 2010 23:23:23 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671119410801097", "Sat Jun 19 2010 23:23:24 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedPollDate3702671119426574937", "Sat Jun 19 2010 23:23:22 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL1154579606993571455", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL1154579607731405437", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL1154579608468016907", 30);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL1154579608675890832", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL1154579608833656362", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL1154579609521108563", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL1154579609576983218", 15);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL1154579610508907107", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL1154579610709294640", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129212453356189313", 30);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129212453356189319", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129212453356189325", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129212453356189337", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129212453356189343", 30);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129212453356189361", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129212453356189367", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129212453356189373", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129212453356189391", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129255209834915761", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129255209834915767", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129255209834915773", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129255209834915785", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129255209834915791", 30);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129255209834915809", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129255209834915815", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129255209834915821", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL129255209834915839", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL3702671116333354629", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL3702671116465124373", 30);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL3702671116544676229", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL3702671116824931754", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL3702671117050235810", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL3702671118292815052", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL3702671118503245856", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL3702671118881041330", 5);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FeedTTL3702671119426574937", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FirstServerDate", "13-5-2010");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FirstTime", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FirstTimeFF3", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.FixPageNotFoundErrors", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.GroupingServerCheckInterval", 1440);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.HasUserGlobalKeys", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.HomePageProtectorEnabled", false);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.HomepageBeforeUnload", "http://rechercher-fr.com/");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.Initialize", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.InitializeCommonPrefs", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.InstallationAndCookieDataSentCount", 3);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.InstalledDate", "Thu May 13 2010 16:20:42 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.InvalidateCache", false);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.IsAlertDBUpdated", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.IsGrouping", false);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.IsMulticommunity", false);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.IsOpenThankYouPage", false);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.IsOpenUninstallPage", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LanguagePackLastCheckTime", "Sun Nov 10 2013 17:05:09 GMT+0100");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LanguagePackReloadIntervalMM", 1440);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LastLogin_2.5.8.6", "Sat Jul 09 2011 21:23:45 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LastLogin_3.10.0.1", "Sat Apr 21 2012 22:15:25 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LastLogin_3.12.0.7", "Mon Apr 30 2012 15:39:01 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LastLogin_3.12.2.3", "Sat Jun 02 2012 02:14:25 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LastLogin_3.13.0.6", "Sun Jul 22 2012 01:20:03 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LastLogin_3.14.1.0", "Tue Aug 21 2012 21:02:18 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LastLogin_3.15.1.0", "Mon Nov 26 2012 00:15:53 GMT+0100");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LastLogin_3.16.0.3", "Mon Mar 04 2013 01:41:12 GMT+0100");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LastLogin_3.18.0.7", "Tue Jul 16 2013 13:45:51 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LastLogin_3.19.0.3", "Sun Nov 10 2013 17:05:09 GMT+0100");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LastLogin_3.3.3.2", "Sun Dec 11 2011 10:06:41 GMT+0100");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LastLogin_3.8.1.0", "Sun Jan 15 2012 19:21:48 GMT+0100");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LastLogin_3.9.0.3", "Tue Mar 06 2012 21:26:40 GMT+0100");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LatestVersion", "3.20.0.4");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.Locale", "fr-fr");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.LoginCache", 4);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.MCDetectTooltipHeight", "83");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.MCDetectTooltipUrl", "http://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.MCDetectTooltipWidth", "295");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.MyStuffEnabledAtInstallation", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.RadioIsPodcast", false);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.RadioLastCheckTime", "Wed Apr 03 2013 21:02:50 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.RadioLastUpdateIPServer", "3");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.RadioLastUpdateServer", "3");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.RadioMediaID", "9962");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.RadioMediaType", "Media Player");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.RadioMenuSelectedID", "EBRadioMenu_CT2542115_RECENT9962");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.RadioShrinkedFromSetup", false);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.RadioStationName", "California%20Rock");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.RadioStationURL", "http://feedlive.net/california.asx");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.SHRINK_TOOLBAR", 1);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.SavedHomepage", "resource:/browserconfig.properties");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.SearchEngineBeforeUnload", "Customized Search");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.SearchFromAddressBarIsInit", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.SearchInNewTabEnabled", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.SearchInNewTabIntervalMM", 1440);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.SearchInNewTabLastCheckTime", "Sun Nov 10 2013 17:05:06 GMT+0100");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.SearchProtectorEnabled", false); =>PUP.SearchProtect
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.SearchProtectorToolbarDisabled", false); =>PUP.SearchProtect
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.ServiceMapLastCheckTime", "Sun Nov 10 2013 17:05:07 GMT+0100");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.SettingsCheckIntervalMin", 120);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.SettingsLastCheckTime", "Sun Nov 10 2013 17:05:05 GMT+0100");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.SettingsLastUpdate", "1384073878");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.ThirdPartyComponentsInterval", 504);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.ThirdPartyComponentsLastCheck", "Sat Mar 30 2013 03:00:20 GMT+0100");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.ThirdPartyComponentsLastUpdate", "1331805999");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.UserID", "UN04086006609792336");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.ValidationData_Search", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.ValidationData_Toolbar", 2);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.WeatherNetwork", "");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.WeatherPollDate", "Wed Apr 03 2013 21:02:50 GMT+0200");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.WeatherUnit", "C");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.alertChannelId", "935078");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.homepageProtectorEnableByLogin", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.initDone", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.myStuffEnabled", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.myStuffPublihserMinWidth", 400);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.myStuffServiceIntervalMM", 1440);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.revertSettingsEnabled", true);
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"false\"}"); =>PUP.SearchProtect
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.searchProtectorDialogDelayInSec", 10); =>PUP.SearchProtect
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.searchProtectorEnableByLogin", true); =>PUP.SearchProtect
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.testingCtid", "");
O69 - SBI: prefs.js [david - f83wjcap.default] user_pref("CT2542115.toolbarAppMetaDataLastCheckTime", "Sun Nov 10 2013 17:05:09 GMT+0100");
O69 - SBI: SearchScopes [HKCU] {0191A6B0-1154-4C22-9182-23A95BBE92D9} [DefaultScope] - (Google) - http://www.google.com
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {FDC320A9-B4B2-491E-B140-815C11613CB6} - (Yahoo!) - http://search.yahoo.com
O69 - SBI: SearchScopes [HKCR] {0191A6B0-1154-4C22-9182-23A95BBE92D9} [DefaultScope] - (Google) - http://www.google.com
O69 - SBI: SearchScopes [HKCR] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKCR] {FDC320A9-B4B2-491E-B140-815C11613CB6} - (Yahoo!) - http://search.yahoo.com
O69 - SBI: SearchScopes [HKUS\.DEFAULT] {0191A6B0-1154-4C22-9182-23A95BBE92D9} [DefaultScope] - (Google) - http://www.google.com
O69 - SBI: SearchScopes [HKUS\.DEFAULT] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKUS\.DEFAULT] {FDC320A9-B4B2-491E-B140-815C11613CB6} - (Yahoo!) - http://search.yahoo.com
O69 - SBI: SearchScopes [HKUS\S-1-5-18] {0191A6B0-1154-4C22-9182-23A95BBE92D9} [DefaultScope] - (Google) - http://www.google.com
O69 - SBI: SearchScopes [HKUS\S-1-5-18] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKUS\S-1-5-18] {FDC320A9-B4B2-491E-B140-815C11613CB6} - (Yahoo!) - http://search.yahoo.com
O69 - SBI: SearchScopes [HKUS\S-1-5-19] {0191A6B0-1154-4C22-9182-23A95BBE92D9} [DefaultScope] - (Google) - http://www.google.com
O69 - SBI: SearchScopes [HKUS\S-1-5-19] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKUS\S-1-5-19] {FDC320A9-B4B2-491E-B140-815C11613CB6} - (Yahoo!) - http://search.yahoo.com
O69 - SBI: SearchScopes [HKUS\S-1-5-20] {0191A6B0-1154-4C22-9182-23A95BBE92D9} [DefaultScope] - (Google) - http://www.google.com
O69 - SBI: SearchScopes [HKUS\S-1-5-20] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKUS\S-1-5-20] {FDC320A9-B4B2-491E-B140-815C11613CB6} - (Yahoo!) - http://search.yahoo.com
~ Keys: Scanned in 00mn 00s



---\\ Enumère les fichiers Crack & Keygen (CKF) (O82)
C:\Users\david\Downloads\peugeot_radio_decoder_calculator_keygen.zip =>.Crack,Keygen
C:\Users\david\Downloads\peugeot_radio_decoder_calculator_keygen.zip =>.Crack,Keygen
~ Files: Scanned in 00mn 23s



---\\ Recherche d'infection Rogue (SRI) (O86)
O43 - CFD: 09/08/2015 - 21:12:09 - [] ----D C:\ProgramData\19a87fa1ec024bbcbb41931263354405
~ Files: Scanned in 00mn 00s



---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.09D232ED38DC5023D3E61A6B890144EC] [WIS][17/05/2014] (.ReSoft Ltd. - Snap.Do.) -- C:\Windows\Installer\11521b.msi [10108928] =>Hijacker.SmartBar
[MD5.0018C0854FB76747B5FCECD34856186D] [WIS][08/04/2014] (.LPT - LPT System Updater Service.) -- C:\Windows\Installer\115222.msi [1892352] =>Adware.IncrediBar
[MD5.54D2F6EC72B0A9F8F85E07137F6D098A] [WIS][07/01/2012] (.SweetIM Technologies Ltd. - SweetIM for Messenger 3.6.) -- C:\Windows\Installer\448701.msi [3552768] =>PUP.SweetIM
[MD5.0FD2EF6954C43CE4D2C1E93825355AFB] [WIS][07/01/2012] (.SweetIM Technologies Ltd. - SweetIM Toolbar for Internet Explorer 4.0.) -- C:\Windows\Installer\448708.msi [3027968] =>PUP.SweetIM
~ WIS: 4 Legitimates Filtered in 00mn 01s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 02/03/2009 89600 | (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
SS - | Auto 10/08/2015 144200 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 10/08/2015 144200 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 09/09/2011 86072 | (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe =>.Hewlett-Packard Co
SS - | Auto 09/08/2015 281600 | (LuckyBrowse) . (...) - C:\Program Files (x86)\LuckyBrowse\app\luckyBrowseStarter.exe
SS - | Demand 17/08/2013 117656 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Auto 25/06/2015 327296 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SS - | Demand 22/07/2009 240128 | (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe
SS - | Demand 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SS - | Disabled 22/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
SR - | Auto 07/07/2015 82128 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 05/08/2009 203264 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
SR - | Demand 05/05/2009 228408 | (Com4QLBEx) . (.Hewlett-Packard Development Company, L.P..) - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\ezsvc7.dll (ezSharedSvc) . (.EasyBits Sofware AS.) - C:\Windows\System32\svchost.exe
SR - | Demand 28/03/2011 799800 | (hpqwmiex) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
SR - | Auto 08/07/2009 30520 | (hpsrv) . (.Hewlett-Packard.) - C:\Windows\System32\Hpservice.exe
SR - | Auto 30/04/2015 23816 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 11/10/2013 32160 | (SFR.DashBoard.Service) . (.SFR.) - C:\Program Files (x86)\SFR\Gestionnaire de Connexion\SFR.DashBoard.Service.exe
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 14s



---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Run by david at 13/08/2015 20:57:13
~ OS 64 not supported by MBR tool
~ MBR: 0 Legitimates Filtered in 00mn 00s



---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by david at 13/08/2015 20:57:15
********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 02s



---\\ Scan Additionnel (O88)
Database Version : 13008 - (31/05/2015)
Clés trouvées (Keys found) : 2
Valeurs trouvées (Values found) : 1
Dossiers trouvés (Folders found) : 3
Fichiers trouvés (Files found) : 10

[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536] =>PUP.SweetIM^
C:\Users\david\AppData\Roaming\Elex-tech =>PUP.Elex^
C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\f83wjcap.default\Conduit =>PUP.Conduit
C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\f83wjcap.default\Smartbar =>Hijacker.SmartBar
[HKCU\Software\Activeris] =>PUP.Activeris^
[HKCU\Software\Smartbar] =>Hijacker.SmartBar^
[HKLM\Software\CouponDownloader ] =>PUP.CouponDownloader^
[HKLM\Software\F2E59BED-97F5-4486-9726-66DE2DDE3B23] =>PUP.CrossRider^
[HKLM\Software\Wow6432Node\Activeris] =>PUP.Activeris^
[HKLM\Software\Wow6432Node\RrFilter] =>PUP.SupraSavings^
C:\Windows\Installer\11521b.msi =>Hijacker.SmartBar^
C:\Windows\Installer\115222.msi =>Adware.IncrediBar^
C:\Windows\Installer\448701.msi =>PUP.SweetIM^
C:\Windows\Installer\448708.msi =>PUP.SweetIM^
~ Additionnel Scan: 327775 Items scanned in 00mn 26s



---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/g2-google-chrome-extensions/ =>.Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
~ AMI: 5 Legitimates Filtered in 00mn 00s



---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/hijacker-browsers =>Hijacker.Browsers
http://nicolascoolman.fr/pup-searchprotect =>PUP.SearchProtect
http://nicolascoolman.fr/hijacker-webssearches =>Hijacker.WebsSearches
http://nicolascoolman.fr/pup-activeris =>PUP.Activeris
http://nicolascoolman.fr/hijacker-smartbar =>Hijacker.SmartBar
http://www.nicolascoolman.fr/blog/ =>PUP.CouponDownloader
http://nicolascoolman.fr/pup-crossrider =>PUP.CrossRider
http://nicolascoolman.fr/pup-suprasavings =>PUP.SupraSavings
http://nicolascoolman.fr/pup-elex =>PUP.Elex
http://nicolascoolman.fr/crapware-spyhunter =>Crapware.SpyHunter
http://nicolascoolman.fr/adware-incredibar =>Adware.IncrediBar
http://nicolascoolman.fr/pup-sweetim =>PUP.SweetIM
http://www.nicolascoolman.fr/blog/ =>PUP.Conduit
~ MSI: 13 link(s) detected in 00mn 00s



~ 1911 Legitimates filtered by white list
End of the scan (739 lines in 02mn 16s)(2.11)

Publicité


Signaler le contenu de ce document

Publicité