cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.12.25.196 Par Nicolas Coolman (2015/12/25)
~ Démarré par shady (Administrator) (2015/12/25 15:32:26)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Documents and Settings\shady\Bureau\ZHPDiag.txt
~ Rapport: C:\Documents and Settings\shady\Application Data\ZHP\ZHPDiag.txt
~ UAC: Deactivate
~ Démarrage du système: Normal (Normal boot)
Windows XP, 32-bit Service Pack 3 (Build 2600)

---\\ Navigateurs Internet (3) - 0s
GCIE: Google Chrome v47.0.2526.106
MFIE: Mozilla Firefox 42.0 (x86 fr) v42.0
MSIE: Internet Explorer v6.0.2900.5512

---\\ Informations sur les produits Windows (3) - 0s
Windows Automatic Updates : OK
Windows Activation Technologies : KO
Windows Genuine Advantage : KO

---\\ Logiciels de protection (1) - 1s
Malwarebytes Anti-Malware version 2.2.0.1024

---\\ Logiciels d'optimisation (1) - 2s
CCleaner v4.14

---\\ Surveillance de Logiciels (1) - 2s
Adobe Flash Player 20 NPAPI

---\\ Informations sur le système (6) - 0s
~ Operating System: x86 Family 6 Model 15 Stepping 11, GenuineIntel
~ Operating System: 32-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 1034.472 MB (70% free)
System Restore: Activé (Enable)
System drive C: has 27 GB () free of 76 GB

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: SHAADY-0863B4AB
~ User Name: shady
~ Logged in as Administrator

---\\ Enumération des unités disques (1) - 0s
~ Drive C: has 27 GB free of 76 GB (System)

---\\ Etat du Centre de Sécurité Windows (9) - 0s
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Intl: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] XMLLookup: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Recherche particulière de fichiers génériques (23) - 0s
[MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - 13/04/2008 - (.Microsoft Corporation - Explorateur Windows.) -- C:\WINDOWS\Explorer.exe [1037824] ©
[MD5.93AD0B78C7357A05F50E594EC7C22300] - 13/04/2008 - (.Microsoft Corporation - Exécuter une DLL en tant qu'application.) -- C:\WINDOWS\System32\rundll32.exe [33792] ©
[MD5.ACDDE3874BF2BEDB91B334307C68CA53] - 12/10/2013 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\WINDOWS\System32\wininet.dll [672768] ©
[MD5.DD73D6B9F6B4CB630CF35B438B540174] - 13/04/2008 - (.Microsoft Corporation - Application d'ouverture de session Windows.) -- C:\WINDOWS\System32\Winlogon.exe [512000] ©
[MD5.D76A076ADB74F8132924E498D63123A2] - 03/03/2011 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\WINDOWS\System32\dnsapi.dll [149504] ©
[MD5.1E44BC1E83D8FD2305F8D452DB109CF9] - 17/08/2011 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [138496] ©
[MD5.9F3A2F5AA6875C72BF062C712CFA2674] - 13/04/2008 - (.Microsoft Corporation - IDE/ATAPI Port Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [96512] ©
[MD5.C885B02847F5D2FD45A24E219ED93B32] - 13/04/2008 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [63744] ©
[MD5.1F4260CC5B42272D71F79E570A27A4FE] - 13/04/2008 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [62976] ©
[MD5.31F923EB2170FC172C81ABDA0045D18C] - 13/04/2008 - (.Microsoft Corporation - Pilote de cryptographie FIPS.) -- C:\WINDOWS\System32\drivers\Fips.sys [44672] ©
[MD5.573C7D0A32852B48F3058CFD8026F511] - 13/04/2008 - (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [144384]
[MD5.A09BDC4ED10E3B2E0EC27BB94AF32516] - 13/04/2008 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [54144] ©
[MD5.083A052659F5310DD8B6A6CB05EDCF8E] - 13/04/2008 - (.Microsoft Corporation - IMAPI Kernel Driver.) -- C:\WINDOWS\System32\drivers\Imapi.sys [42112] ©
[MD5.CC748EA12C6EFFDE940EE98098BF96BB] - 13/04/2008 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [152832] ©
[MD5.23C74D75E36E7158768DD63D92789A91] - 13/04/2008 - (.Microsoft Corporation - IPSec Driver.) -- C:\WINDOWS\System32\drivers\IPSec.sys [75264] ©
[MD5.7D304A5EB4344EBEEAB53A2FE3FFB9F0] - 15/07/2011 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [456320] ©
[MD5.74B2B2F5BEA5E9A3DC021D685551BD3D] - 13/04/2008 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [162816] ©
[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - 13/04/2008 - (.Microsoft Corporation - NT File System Driver.) -- C:\WINDOWS\System32\drivers\ntfs.sys [574976] ©
[MD5.8FD0BDBEA875D06CCF6C945CA9ABAF75] - 13/04/2008 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\WINDOWS\System32\drivers\Parport.sys [80384] ©
[MD5.11B4A627BC9614B885C4969BFA5FF8A6] - 13/04/2008 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [51328] ©
[MD5.15CABD0F7C00C47C70124907916AF3F1] - 13/04/2008 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [196224] ©
[MD5.D8EB2A7904DB6C916EB5361878DDCBAE] - 13/04/2008 - (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) -- C:\WINDOWS\System32\drivers\redbook.sys [58752] ©
[MD5.46DE1126684369BACE4849E4FC8C43CA] - 13/04/2008 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\WINDOWS\System32\drivers\volsnap.sys [53376] ©

---\\ Liste des services NT non Microsoft et non désactivés (1) - 0s
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc®

---\\ Processus lancés (3) - 1s
[MD5.5AAD17D8D4DBB1457D4BE6AF30BC3E20] - (.Analog Devices, Inc. - SMax4PNP.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe [1015808] [PID.1784] ©
[MD5.889CFF36EDDD89281E1C9BF1CE91B223] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe [3907152] [PID.1068] ©
[MD5.EF7229D381AE39A88A88D2AFB40ACCD7] - (.Copyright (C) 2015 Nicolas Coolman - ZHPDiag.) -- C:\Documents and Settings\shady\ZHPDiag3.exe [2041856] [PID.2816] ©

---\\ Google Chrome, Démarrage,Recherche,Extensions (14) - 0s
G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [cfhdojbkjhnklbpkdaibdccddilifddb] __MSG_name__ =>.AdblocPlus Plugin
G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [eeajicmampllnpkmfimkhefbndkfeloo] Facebook Group Invite All
G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [gfgpmemehnpapnkoanpoekdbcenaeaic] Facebook Friends Requests Accept/Reject
G2 - GCE: Preference [User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [inmmhkeajgflmokoaaoadgkhhmibjbpj] Facebook Invite All
G2 - GCE: Preference [User Data\Default] [ngpampappnmepgilojfohadhhmbhlaek] IDM Integration Module
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc.

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (5) - 1s
P2 - EXT FILE: (...) -- C:\Documents and Settings\shady\Application Data\Mozilla\Firefox\Profiles\ssv4m7dt.default\extensions\info@youtube-mp3.org.xpi
P2 - EXT FILE: (...) -- C:\Documents and Settings\shady\Application Data\Mozilla\Firefox\Profiles\ssv4m7dt.default\extensions\{7b9de502-149c-8165-ec2c-db01128febfe}.xpi
P2 - EXT FILE: (...) -- C:\Documents and Settings\shady\Application Data\Mozilla\Firefox\Profiles\ssv4m7dt.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ©
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_20_0_0_235.dll ©

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (8) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/

---\\ Internet Explorer,Proxy Management (5) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe (.Microsoft Corporation.) ©
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) ©
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"

---\\ Etude du fichier hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (23)

---\\ Browser Helper Object de navigateur (BHO) (1) - 0s
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files\Internet Download Manager\IDMIECC.dll =>.Tonec Inc.®

---\\ Applications lancées au démarrage du système (16) - 0s
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\WINDOWS\system32\igfxtray.exe =>.Intel Corporation®
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\system32\hkcmd.exe =>.Intel Corporation®
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\WINDOWS\system32\igfxpers.exe =>.Intel Corporation®
O4 - HKLM\..\Run: [SoundMAXPnP] . (.Analog Devices, Inc. - SMax4PNP.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe ©
O4 - HKLM\..\Run: [IMJPMIG8.1] . (.Microsoft Corporation - Microsoft IME.) -- C:\WINDOWS\ime\imjp8_1\imjpmig.exe ©
O4 - HKLM\..\Run: [MSPY2002] . (...) -- C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE
O4 - HKLM\..\Run: [PHIME2002ASync] . (.Microsoft Corporation - 微軟新注音輸入法 2002a.) -- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE ©
O4 - HKLM\..\Run: [PHIME2002A] . (.Microsoft Corporation - 微軟新注音輸入法 2002a.) -- C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE ©
O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe ©
O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe ©
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe ©
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe ©
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe ©
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe ©
O4 - HKUS\S-1-5-21-842925246-1060284298-1801674531-1003\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe ©
O4 - HKUS\S-1-5-21-842925246-1060284298-1801674531-1003\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe ©

---\\ Modification Domaine/Adresses DNS (2) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{24D287BF-A2F0-4B59-9838-A19E7F9DFF97}: DhcpNameServer = 192.168.1.1

---\\ Protocole additionnel (27) - 0s
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\WINDOWS\system32\mshtml.dll ©
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\WINDOWS\system32\msvidctl.dll ©
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll ©
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\WINDOWS\system32\mshtml.dll ©
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\WINDOWS\system32\mshtml.dll ©
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API.) -- C:\WINDOWS\system32\inetcomm.dll ©
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation®
O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll ©
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\WINDOWS\system32\mshtml.dll ©
O18 - Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\WINDOWS\system32\mshtml.dll ©
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\WINDOWS\system32\msvidctl.dll ©
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\WINDOWS\system32\mshtml.dll ©
O18 - Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} . (.Microsoft Corporation - WIA Scripting Layer.) -- C:\WINDOWS\system32\wiascr.dll ©
O18 - Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\WINDOWS\system32\urlmon.dll ©
O18 - Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll ©
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSOXMLMF.DLL =>.Microsoft Corporation®

---\\ Logiciels installés (37) - 13s
O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU] -- uTorrent =>.BitTorrent Inc®
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- {31B9D218-FED2-4C6C-B19F-7294FFC130B0} ©
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- Adobe AIR =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Flash Player 20 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Shockwave Player 12.1 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Shockwave Player ©
O42 - Logiciel: Bandicam - (.Bandisoft.com.) [HKLM] -- Bandicam ©
O42 - Logiciel: Bandisoft MPEG-1 Decoder - (.Bandisoft.com.) [HKLM] -- BandiMPEG1 ©
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner =>.Piriform Ltd®
O42 - Logiciel: Cheat Engine 6.4 - (.Cheat Engine.) [HKLM] -- Cheat Engine 6.4_is1 =>.Cheat Engine®
O42 - Logiciel: CLEO 4.3 - (.Seemann, Deji, Alien.) [HKLM] -- {A8F37EB0-C741-41D7-8CAB-5B40ECEEF094}_is1
O42 - Logiciel: Counter-Strike - (.Valve.) [HKLM] -- Steam App 10 =>.Valve®
O42 - Logiciel: Counter-Strike: Condition Zero - (.Valve.) [HKLM] -- Steam App 80 =>.Valve®
O42 - Logiciel: FlashFXP 5 - (.OpenSight Software LLC.) [HKLM] -- FlashFXP 5
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome =>.Google Inc®
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} ©
O42 - Logiciel: Half-Life - (.Valve.) [HKLM] -- Steam App 70 =>.Valve®
O42 - Logiciel: Half-Life: Opposing Force - (.Gearbox Software.) [HKLM] -- Steam App 50 =>.Valve®
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (...) [HKLM] -- HDMI =>.Intel Corporation®
O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM] -- Internet Download Manager =>.Tonec Inc.®
O42 - Logiciel: KMSAuto Net 1.3.8 - (.MSFree Inc..) [HKLM] -- KMSAuto Net 1.3.8
O42 - Logiciel: Malwarebytes Anti-Malware version 2.2.0.1024 - (.Malwarebytes.) [HKLM] -- Malwarebytes Anti-Malware_is1 ©
O42 - Logiciel: Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 - (.Microsoft Corporation.) [HKLM] -- Wdf01007 =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Software Update for Web Folders (French) 12 - (.Microsoft Corporation.) [HKLM] -- {90120000-0010-040C-0000-0000000FF1CE} ©
O42 - Logiciel: Mozilla Firefox 42.0 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 42.0 (x86 fr) =>.Mozilla Corporation®
O42 - Logiciel: MSN - (...) [HKLM] -- MSNINST
O42 - Logiciel: PhotoFiltre Studio X - (...) [HKCU] -- PhotoFiltre Studio X
O42 - Logiciel: Pro Evolution Soccer 2010 - (.KONAMI.) [HKLM] -- {283FFB23-8751-4B08-ACB8-5E0F8BCF7727} ©
O42 - Logiciel: Steam - (.Valve Corporation.) [HKLM] -- Steam =>.Valve®
O42 - Logiciel: SWAT 4 - (.Sierra Entertainment, Inc..) [HKLM] -- {8E1CCF20-9E12-4824-BD59-7AD9E0486DD8}
O42 - Logiciel: SWAT 4 - (.Sierra Entertainment, Inc..) [HKLM] -- InstallShield_{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8}
O42 - Logiciel: swMSM - (.Adobe Systems, Inc.) [HKLM] -- {612C34C7-5E90-47D8-9B5C-0F717DD82726} ©
O42 - Logiciel: TeamSpeak 3 Client - (.TeamSpeak Systems GmbH.) [HKLM] -- TeamSpeak 3 Client ©
O42 - Logiciel: Video Watermark Pro - (.WonderFox Soft, Inc. All Rights Reserved..) [HKCU] -- VideoWatermarkPro
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM] -- VLC media player ©
O42 - Logiciel: WebFldrs XP - (.Microsoft Corporation.) [HKLM] -- {350C940c-3D7C-4EE8-BAA9-00BCB3D54227} ©
O42 - Logiciel: WinRAR 5.21 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver =>.win.rar GmbH®
O42 - Logiciel: ZHPFix 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPFix_is1 ©

---\\ HKCU & HKLM Software Keys (78) - 13s
HKLM\SOFTWARE\Adobe
HKLM\SOFTWARE\AdwCleaner
HKLM\SOFTWARE\Analog Devices
HKLM\SOFTWARE\Andrea Electronics
HKLM\SOFTWARE\Ankama Games
HKLM\SOFTWARE\AppDataLow
HKLM\SOFTWARE\Apple Inc.
HKLM\SOFTWARE\BandiMPEG1
HKLM\SOFTWARE\BANDISOFT
HKLM\SOFTWARE\C07ft5Y
HKLM\SOFTWARE\CLSID
HKLM\SOFTWARE\Dofus2Beta
HKLM\SOFTWARE\FlashFXP
HKLM\SOFTWARE\GameModding.net
HKLM\SOFTWARE\Gemplus
HKLM\SOFTWARE\Google
HKLM\SOFTWARE\InstalledOptions
HKLM\SOFTWARE\InstallShield
HKLM\SOFTWARE\Intel
HKLM\SOFTWARE\Internet Download Manager
HKLM\SOFTWARE\JavaSoft
HKLM\SOFTWARE\KONAMI
HKLM\SOFTWARE\Macromedia
HKLM\SOFTWARE\Malwarebytes' Anti-Malware
HKLM\SOFTWARE\MimarSinan
HKLM\SOFTWARE\Mozilla
HKLM\SOFTWARE\mozilla.org
HKLM\SOFTWARE\MozillaPlugins
HKLM\SOFTWARE\ODBC
HKLM\SOFTWARE\Opera Software
HKLM\SOFTWARE\Overwolf
HKLM\SOFTWARE\Piriform
HKLM\SOFTWARE\Program Groups
HKLM\SOFTWARE\RegisteredApplications
HKLM\SOFTWARE\Schlumberger
HKLM\SOFTWARE\Secure
HKLM\SOFTWARE\Sierra
HKLM\SOFTWARE\Skype
HKLM\SOFTWARE\TeamSpeak 3 Client
HKLM\SOFTWARE\TeamViewer
HKLM\SOFTWARE\THQ
HKLM\SOFTWARE\Valve
HKLM\SOFTWARE\VideoLAN
HKLM\SOFTWARE\Windows 3.1 Migration Status
HKLM\SOFTWARE\WinRAR
HKLM\SOFTWARE\WitStudio
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\Analog Devices
HKCU\SOFTWARE\Ankama
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\BandiMPEG1
HKCU\SOFTWARE\BANDISOFT
HKCU\SOFTWARE\BitTorrent
HKCU\SOFTWARE\Cheat Engine
HKCU\SOFTWARE\DownloadManager
HKCU\SOFTWARE\FlashFXP
HKCU\SOFTWARE\GameModding.net
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\GTAGarage
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\Intel
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\ODBC
HKCU\SOFTWARE\Opera Software
HKCU\SOFTWARE\PhotoFiltre Studio X
HKCU\SOFTWARE\Piriform
HKCU\SOFTWARE\QtProject
HKCU\SOFTWARE\Skype
HKCU\SOFTWARE\TeamViewer
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\Valve
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\Software

---\\ Contenu des dossiers Programmes (140) - 47s
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\Adobe =>.Adobe Systems Incorporated®
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\Analog Devices
O43 - CFD: 26/07/2015 - [] D -- C:\Program Files\AoaoPhoto Digital Studio
O43 - CFD: 18/07/2015 - [] D -- C:\Program Files\Bandicam {1A08E425DDDBB34E1E26D6E7856E9FB8}
O43 - CFD: 18/07/2015 - [] D -- C:\Program Files\BandiMPEG1
O43 - CFD: 24/07/2015 - [] D -- C:\Program Files\CCleaner =>.Piriform Ltd®
O43 - CFD: 06/09/2015 - [] D -- C:\Program Files\Cheat Engine 6.4 =>.Cheat Engine®
O43 - CFD: 29/06/2015 - [0] D -- C:\Program Files\ComPlus Applications
O43 - CFD: 18/10/2015 - [0] D -- C:\Program Files\Dofus2Beta
O43 - CFD: 19/12/2015 - [] D -- C:\Program Files\Fichiers communs
O43 - CFD: 26/07/2015 - [] D -- C:\Program Files\FlashFXP 5 {7C71FD6A64A6E0C3B995B927F555F6AB}
O43 - CFD: 30/07/2015 - [] D -- C:\Program Files\Google =>.Google Inc®
O43 - CFD: 19/09/2015 - [] D -- C:\Program Files\InstallShield Installation Information
O43 - CFD: 28/08/2015 - [] D -- C:\Program Files\Internet Download Manager
O43 - CFD: 30/06/2015 - [] D -- C:\Program Files\Internet Explorer
O43 - CFD: 01/09/2015 - [] D -- C:\Program Files\KONAMI
O43 - CFD: 24/12/2015 - [] D -- C:\Program Files\Malwarebytes Anti-Malware =>.Malwarebytes Corporation®
O43 - CFD: 30/06/2015 - [] D -- C:\Program Files\Messenger
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\microsoft frontpage
O43 - CFD: 19/12/2015 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation®
O43 - CFD: 19/12/2015 - [] D -- C:\Program Files\Microsoft Visual Studio
O43 - CFD: 19/12/2015 - [] D -- C:\Program Files\Microsoft Works
O43 - CFD: 30/06/2015 - [] D -- C:\Program Files\Movie Maker
O43 - CFD: 25/12/2015 - [] D -- C:\Program Files\Mozilla Firefox =>.Mozilla Corporation®
O43 - CFD: 19/12/2015 - [] D -- C:\Program Files\MSBuild
O43 - CFD: 23/12/2015 - [] D -- C:\Program Files\MSFree Inc
O43 - CFD: 17/07/2015 - [] D -- C:\Program Files\MSN
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\MSN Gaming Zone
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\NetMeeting
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\Online Services
O43 - CFD: 02/07/2015 - [] D -- C:\Program Files\Opera =>.Opera Software ASA®
O43 - CFD: 30/06/2015 - [] D -- C:\Program Files\Outlook Express
O43 - CFD: 30/06/2015 - [] D -- C:\Program Files\PhotoFiltre Studio X
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\Services en ligne
O43 - CFD: 19/09/2015 - [] D -- C:\Program Files\Sierra
O43 - CFD: 13/12/2015 - [] RD -- C:\Program Files\Skype
O43 - CFD: 23/12/2015 - [] D -- C:\Program Files\Steam =>.Valve®
O43 - CFD: 08/09/2015 - [] D -- C:\Program Files\TeamSpeak 3 Client
O43 - CFD: 07/10/2015 - [] D -- C:\Program Files\TeamViewer
O43 - CFD: 29/06/2015 - [0] HD -- C:\Program Files\Uninstall Information
O43 - CFD: 26/07/2015 - [] D -- C:\Program Files\VideoLAN
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\Windows Media Player
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\Windows NT
O43 - CFD: 29/06/2015 - [0] HD -- C:\Program Files\WindowsUpdate
O43 - CFD: 30/06/2015 - [] D -- C:\Program Files\WinRAR =>.win.rar GmbH®
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\xerox
O43 - CFD: 25/12/2015 - [] D -- C:\Program Files\ZHPFix
O43 - CFD: 29/06/2015 - [] RD -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Accessoires
O43 - CFD: 18/07/2015 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Bandicam
O43 - CFD: 24/07/2015 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\CCleaner
O43 - CFD: 06/09/2015 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Cheat Engine 6.4
O43 - CFD: 13/12/2015 - [] RD -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
O43 - CFD: 24/12/2015 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Google Chrome
O43 - CFD: 27/08/2015 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Internet Download Manager
O43 - CFD: 29/06/2015 - [] RD -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Jeux
O43 - CFD: 01/09/2015 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\KONAMI
O43 - CFD: 24/12/2015 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Malwarebytes Anti-Malware
O43 - CFD: 19/12/2015 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Microsoft Office
O43 - CFD: 29/06/2015 - [] RD -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Outils d'administration
O43 - CFD: 29/06/2015 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Steam
O43 - CFD: 18/07/2015 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\TeamSpeak 3 Client
O43 - CFD: 26/07/2015 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\VideoLAN
O43 - CFD: 30/06/2015 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinRAR
O43 - CFD: 24/12/2015 - [] D -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ZHP
O43 - CFD: 29/06/2015 - [] D -- C:\Documents and Settings\All Users\Application Data\Adobe
O43 - CFD: 16/07/2015 - [] D -- C:\Documents and Settings\All Users\Application Data\FlashFXP
O43 - CFD: 01/07/2015 - [0] D -- C:\Documents and Settings\All Users\Application Data\IDM
O43 - CFD: 01/09/2015 - [] D -- C:\Documents and Settings\All Users\Application Data\KONAMI
O43 - CFD: 24/12/2015 - [] D -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
O43 - CFD: 19/11/2015 - [] SD -- C:\Documents and Settings\All Users\Application Data\Microsoft
O43 - CFD: 19/12/2015 - [] D -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
O43 - CFD: 13/10/2015 - [0] D -- C:\Documents and Settings\All Users\Application Data\modloader
O43 - CFD: 16/07/2015 - [] D -- C:\Documents and Settings\All Users\Application Data\regid.2000-02.com.flashfxp
O43 - CFD: 24/12/2015 - [] D -- C:\Documents and Settings\All Users\Application Data\RogueKiller
O43 - CFD: 13/12/2015 - [] D -- C:\Documents and Settings\All Users\Application Data\Skype
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\Fichiers communs\Adobe AIR
O43 - CFD: 19/12/2015 - [] D -- C:\Program Files\Fichiers communs\DESIGNER
O43 - CFD: 15/07/2015 - [] D -- C:\Program Files\Fichiers communs\DirectX
O43 - CFD: 19/09/2015 - [] D -- C:\Program Files\Fichiers communs\InstallShield
O43 - CFD: 19/12/2015 - [] D -- C:\Program Files\Fichiers communs\Microsoft Shared
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\Fichiers communs\MSSoap
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\Fichiers communs\ODBC
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\Fichiers communs\Services
O43 - CFD: 29/06/2015 - [] D -- C:\Program Files\Fichiers communs\SpeechEngines
O43 - CFD: 19/12/2015 - [] D -- C:\Program Files\Fichiers communs\System
O43 - CFD: 27/11/2015 - [] D -- C:\Documents and Settings\shady\Application Data\2048-e8ec873ccb4fa5d957f40330a92ae1fa
O43 - CFD: 29/06/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Adobe
O43 - CFD: 29/06/2015 - [] D -- C:\Documents and Settings\shady\Application Data\AnkamaCertificates
O43 - CFD: 29/06/2015 - [] D -- C:\Documents and Settings\shady\Application Data\app
O43 - CFD: 18/07/2015 - [] D -- C:\Documents and Settings\shady\Application Data\BANDISOFT
O43 - CFD: 23/12/2015 - [] D -- C:\Documents and Settings\shady\Application Data\DMCache
O43 - CFD: 16/07/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Dofus
O43 - CFD: 29/06/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Dofus-2
O43 - CFD: 30/06/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Dofus-3
O43 - CFD: 30/06/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Dofus-4
O43 - CFD: 16/07/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Dofus2Beta
O43 - CFD: 03/07/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Dofusbeta
O43 - CFD: 03/07/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Dofusbeta-2
O43 - CFD: 23/09/2015 - [] D -- C:\Documents and Settings\shady\Application Data\FreeFixer
O43 - CFD: 30/06/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Identities
O43 - CFD: 18/12/2015 - [] D -- C:\Documents and Settings\shady\Application Data\IDM
O43 - CFD: 29/06/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Macromedia
O43 - CFD: 19/12/2015 - [] SD -- C:\Documents and Settings\shady\Application Data\Microsoft
O43 - CFD: 29/06/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Mozilla
O43 - CFD: 02/07/2015 - [0] D -- C:\Documents and Settings\shady\Application Data\Opera Software
O43 - CFD: 30/06/2015 - [] D -- C:\Documents and Settings\shady\Application Data\PhotoFiltre Studio X
O43 - CFD: 08/07/2015 - [] D -- C:\Documents and Settings\shady\Application Data\QSocial
O43 - CFD: 29/06/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Reg
O43 - CFD: 03/07/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Regbeta
O43 - CFD: 01/07/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Shortcut
O43 - CFD: 31/08/2015 - [] D -- C:\Documents and Settings\shady\Application Data\Skype
O43 - CFD: 13/12/2015 - [] D -- C:\Documents and Settings\shady\Application Data\TS3Client
O43 - CFD: 13/12/2015 - [] D -- C:\Documents and Settings\shady\Application Data\uTorrent
O43 - CFD: 17/12/2015 - [] D -- C:\Documents and Settings\shady\Application Data\vlc
O43 - CFD: 30/06/2015 - [] D -- C:\Documents and Settings\shady\Application Data\WinRAR
O43 - CFD: 25/12/2015 - [] D -- C:\Documents and Settings\shady\Application Data\ZHP
O43 - CFD: 23/09/2015 - [] D -- C:\Documents and Settings\shady\Local Settings\Application Data\Adobe
O43 - CFD: 18/10/2015 - [0] D -- C:\Documents and Settings\shady\Local Settings\Application Data\Ankama
O43 - CFD: 22/07/2015 - [] D -- C:\Documents and Settings\shady\Local Settings\Application Data\CEF
O43 - CFD: 23/09/2015 - [] D -- C:\Documents and Settings\shady\Local Settings\Application Data\FreeFixer
O43 - CFD: 27/09/2015 - [] D -- C:\Documents and Settings\shady\Local Settings\Application Data\Google
O43 - CFD: 19/07/2015 - [] D -- C:\Documents and Settings\shady\Local Settings\Application Data\Identities
O43 - CFD: 02/09/2015 - [] D -- C:\Documents and Settings\shady\Local Settings\Application Data\Mega Limited
O43 - CFD: 11/12/2015 - [] D -- C:\Documents and Settings\shady\Local Settings\Application Data\Microsoft
O43 - CFD: 19/11/2015 - [0] D -- C:\Documents and Settings\shady\Local Settings\Application Data\Microsoft Help
O43 - CFD: 13/10/2015 - [] D -- C:\Documents and Settings\shady\Local Settings\Application Data\modloader
O43 - CFD: 29/06/2015 - [] D -- C:\Documents and Settings\shady\Local Settings\Application Data\Mozilla
O43 - CFD: 02/07/2015 - [0] D -- C:\Documents and Settings\shady\Local Settings\Application Data\Opera Software
O43 - CFD: 21/07/2015 - [] D -- C:\Documents and Settings\shady\Local Settings\Application Data\Skype
O43 - CFD: 03/12/2015 - [] D -- C:\Documents and Settings\shady\Local Settings\Application Data\Steam
O43 - CFD: 08/11/2015 - [0] D -- C:\Documents and Settings\shady\Local Settings\Application Data\WMTools Downloaded Files
O43 - CFD: 29/06/2015 - [] RD -- C:\Documents and Settings\shady\Menu Démarrer\Programmes\Accessoires
O43 - CFD: 03/07/2015 - [] D -- C:\Documents and Settings\shady\Menu Démarrer\Programmes\Dofus2Beta
O43 - CFD: 24/12/2015 - [] RD -- C:\Documents and Settings\shady\Menu Démarrer\Programmes\Démarrage
O43 - CFD: 27/08/2015 - [] D -- C:\Documents and Settings\shady\Menu Démarrer\Programmes\Internet Download Manager
O43 - CFD: 30/06/2015 - [] D -- C:\Documents and Settings\shady\Menu Démarrer\Programmes\PhotoFiltre Studio X
O43 - CFD: 19/09/2015 - [] D -- C:\Documents and Settings\shady\Menu Démarrer\Programmes\Sierra
O43 - CFD: 21/11/2015 - [] D -- C:\Documents and Settings\shady\Menu Démarrer\Programmes\Steam
O43 - CFD: 26/07/2015 - [] D -- C:\Documents and Settings\shady\Menu Démarrer\Programmes\Video Watermark Pro
O43 - CFD: 30/06/2015 - [] D -- C:\Documents and Settings\shady\Menu Démarrer\Programmes\WinRAR

---\\ ShellIconOverlayIdentifiers (SIOI) (2) - 0s
O106 - SIOI: Offline Files Menu [Fichiers hors connexion] - {750fdf0e-2a26-11d1-a3ea-080036587f03}. (.Microsoft Corporation - IU de cache côté client.) -- C:\WINDOWS\system32\cscui.dll ©
O106 - SIOI: IDM Shell Extension [IDM Shell Extension] - {CDC95B92-E27C-4745-A8C5-64A52A78855D}. (.Tonec Inc. - Internet Download Manager module.) -- C:\Program Files\Internet Download Manager\IDMShellExt.dll =>.Tonec Inc.®

---\\ Enumération des clés StartupReg (2) - 0s
O53 - SMSR:HKLM\...\startupreg\CCleaner Monitoring [Key] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe ©
O53 - SMSR:HKLM\...\startupreg\MSMSGS [Key] . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe ©

---\\ Liste des pilotes du système (39) - 4s
O58 - SDL:2007/05/24 13:50:26 A . (.Analog Devices, Inc. - High Definition Audio Function Driver.) -- C:\WINDOWS\System32\drivers\ADIHdAud.sys [306688] ©
O58 - SDL:2007/05/18 08:20:24 A . (.Andrea Electronics Corporation - Audio Noise Filtering Driver (32-bit).) -- C:\WINDOWS\System32\drivers\aeaudio.sys [94848] ©
O58 - SDL:2001/08/28 13:00:00 A . (.RAVISENT Technologies Inc. - Pilote principal CineMaster C 1.2 WDM.) -- C:\WINDOWS\System32\drivers\cinemst2.sys [262528] ©
O58 - SDL:2001/08/28 13:00:00 A . (.Compaq Computer Corporation - Compaq PA-1 Player Driver.) -- C:\WINDOWS\System32\drivers\cpqdap01.sys [11776] ©
O58 - SDL:2008/04/13 18:05:08 A . (.Microsoft Corp., Veritas Software - Pilote de démarrage du gestionnaire de disq.) -- C:\WINDOWS\System32\drivers\dmboot.sys [800256] ©
O58 - SDL:2008/04/13 18:05:14 A . (.Microsoft Corp., Veritas Software - Pilote E/S du Gestionnaire de disques NT.) -- C:\WINDOWS\System32\drivers\dmio.sys [154496] ©
O58 - SDL:2001/08/28 13:00:00 A . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\System32\drivers\dmload.sys [5888] ©
O58 - SDL:2008/02/06 23:39:32 A . (.Intel Corporation - Intel(R) PRO/1000 Adapter NDIS 5.2 deserial.) -- C:\WINDOWS\System32\drivers\e1e5132.sys [242320] =>.Intel Corporation®
O58 - SDL:2008/04/13 08:36:06 A . (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) -- C:\WINDOWS\System32\drivers\hdaudbus.sys [144384]
O58 - SDL:2007/05/11 18:00:14 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\HECI.sys [45056] ©
O58 - SDL:2015/06/12 03:00:58 A . (.Tonec Inc. - Internet Download Manager TDI Driver.) -- C:\WINDOWS\System32\drivers\idmtdi.sys [128528] =>.Tonec Inc.®
O58 - SDL:2007/01/23 14:13:26 A . (.Infineon Technologies AG - Infineon Trusted Platform Module.) -- C:\WINDOWS\System32\drivers\ifxtpm.sys [36608]
O58 - SDL:2008/11/03 10:46:34 A . (.Intel Corporation - Intel Graphics Miniport Driver.) -- C:\WINDOWS\System32\drivers\igxpmp32.sys [6273504] ©
O58 - SDL:2015/10/05 09:50:04 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\mbam.sys [23256] =>.Malwarebytes Corporation®
O58 - SDL:2015/10/05 09:50:10 A . (.Malwarebytes - Malwarebytes Chameleon Protection Driver.) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys [121560] =>.Malwarebytes Corporation®
O58 - SDL:2015/12/24 18:18:34 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [170200] =>.Malwarebytes Corporation®
O58 - SDL:2001/08/28 13:00:00 A . (.S3/Diamond Multimedia Systems - NikeDrv Usb Driver.) -- C:\WINDOWS\System32\drivers\nikedrv.sys [12032] ©
O58 - SDL:2001/08/28 13:00:00 A . (.Parallel Technologies, Inc. - Parallel Technologies DirectParallel IO Lib.) -- C:\WINDOWS\System32\drivers\ptilink.sys [17792] ©
O58 - SDL:2001/08/28 13:00:00 A . (.S3/Diamond Multimedia Systems - Rio8Drv.sys Usb Driver.) -- C:\WINDOWS\System32\drivers\rio8drv.sys [12032] ©
O58 - SDL:2001/08/28 13:00:00 A . (.S3/Diamond Multimedia Systems - RioDrv Usb Driver.) -- C:\WINDOWS\System32\drivers\riodrv.sys [12032] ©
O58 - SDL:2008/04/13 08:39:16 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\WINDOWS\System32\drivers\secdrv.sys [20480] ©
O58 - SDL:2015/12/24 17:21:16 A . (...) -- C:\WINDOWS\System32\drivers\TrueSight.sys [30848] =>.Adlice®
O58 - SDL:2001/08/28 13:00:00 A . (.Toshiba Corporation - WDM Toshiba Tecra Video Capture Driver.) -- C:\WINDOWS\System32\drivers\tsbvcap.sys [21376] ©
O58 - SDL:2001/08/28 13:00:00 A . (.RAVISENT Technologies Inc. - CineMaster C WDM DVD Minidriver.) -- C:\WINDOWS\System32\drivers\vdmindvd.sys [58112] ©
O58 - SDL:2001/08/28 13:00:00 A . (...) -- C:\WINDOWS\System32\ansi.sys [9037]
O58 - SDL:2001/08/28 13:00:00 A . (...) -- C:\WINDOWS\System32\country.sys [27097]
O58 - SDL:2001/08/28 13:00:00 A . (...) -- C:\WINDOWS\System32\himem.sys [4912]
O58 - SDL:2001/08/28 13:00:00 A . (...) -- C:\WINDOWS\System32\key01.sys [42809]
O58 - SDL:2008/04/13 08:50:56 A . (...) -- C:\WINDOWS\System32\keyboard.sys [42537]
O58 - SDL:2001/08/28 13:00:00 A . (...) -- C:\WINDOWS\System32\ntdos.sys [27916]
O58 - SDL:2001/08/28 13:00:00 A . (...) -- C:\WINDOWS\System32\ntdos404.sys [29146]
O58 - SDL:2001/08/28 13:00:00 A . (...) -- C:\WINDOWS\System32\ntdos411.sys [29370]
O58 - SDL:2001/08/28 13:00:00 A . (...) -- C:\WINDOWS\System32\ntdos412.sys [29274]
O58 - SDL:2001/08/28 13:00:00 A . (...) -- C:\WINDOWS\System32\ntdos804.sys [29146]
O58 - SDL:2008/04/13 08:49:52 A . (...) -- C:\WINDOWS\System32\ntio.sys [34000]
O58 - SDL:2008/04/13 08:49:44 A . (...) -- C:\WINDOWS\System32\ntio404.sys [34560]
O58 - SDL:2008/04/13 08:49:40 A . (...) -- C:\WINDOWS\System32\ntio411.sys [35648]
O58 - SDL:2008/04/13 08:49:44 A . (...) -- C:\WINDOWS\System32\ntio412.sys [35424]
O58 - SDL:2008/04/13 08:49:42 A . (...) -- C:\WINDOWS\System32\ntio804.sys [34560]

---\\ Associations Shell Spawning (9) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll ©
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\system32\wscript.exe ©
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe ©
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®

---\\ Menu de démarrage Internet (13) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ©
O68 - StartMenuInternet: <>[HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Opera\launcher.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - 'Firefox' Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Windows NT User Data Migration Tool.) -- C:\WINDOWS\system32\shmgrate.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - 'Firefox' Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Windows NT User Data Migration Tool.) -- C:\WINDOWS\system32\shmgrate.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - 'Firefox' Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Windows NT User Data Migration Tool.) -- C:\WINDOWS\system32\shmgrate.exe ©

---\\ Recherche d'infection sur les navigateurs (1) - 4s
O69 - SBI: prefs.js [shady - ssv4m7dt.default] user_pref("browser.search.searchengine.url", "http://www.yoursites123.com/web/?type=ds&ts=1450181567&z=21e223b3f0c97db3c281da1g7zc[...] =>PUP.Optional.YourSites123

---\\ Enumère les services démarrés par Svchost (40) - 1s
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\WINDOWS\system32\appmgmts.dll [176640] ©
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\WINDOWS\system32\audiosrv.dll [42496] ©
O83 - Search Svchost Services: Browser (Browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINDOWS\system32\browser.dll [78336] ©
O83 - Search Svchost Services: CryptSvc (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) -- C:\WINDOWS\system32\cryptsvc.dll [62464] ©
O83 - Search Svchost Services: DMServer (DMServer) . (.Microsoft Corp. - DLL Service gestionnaire de disque logique.) -- C:\WINDOWS\system32\dmserver.dll [24576] ©
O83 - Search Svchost Services: DHCP (DHCP) . (.Microsoft Corporation - Service client DHCP.) -- C:\WINDOWS\system32\dhcpcsvc.dll [127488] ©
O83 - Search Svchost Services: ERSvc (ERSvc) . (.Microsoft Corporation - Windows Error Reporting Service.) -- C:\WINDOWS\system32\ersvc.dll [23040] ©
O83 - Search Svchost Services: EventSystem (EventSystem) . (.Microsoft Corporation - .) -- C:\WINDOWS\system32\es.dll [253952] ©
O83 - Search Svchost Services: FastUserSwitchingCompatibility (FastUserSwitchingCompatibility) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680] ©
O83 - Search Svchost Services: HidServ (HidServ) . (.Microsoft Corporation - HID Audio Service.) -- C:\WINDOWS\system32\hidserv.dll [21504] ©
O83 - Search Svchost Services: LanmanServer (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\system32\srvsvc.dll [96768] ©
O83 - Search Svchost Services: LanmanWorkstation (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) -- C:\WINDOWS\system32\wkssvc.dll [132096] ©
O83 - Search Svchost Services: Messenger (Messenger) . (.Microsoft Corporation - NT Messenger Service.) -- C:\WINDOWS\system32\msgsvc.dll [33792] ©
O83 - Search Svchost Services: Netman (Netman) . (.Microsoft Corporation - Gestionnaire de connexions réseau.) -- C:\WINDOWS\system32\netman.dll [198144] ©
O83 - Search Svchost Services: Nla (Nla) . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Micro.) -- C:\WINDOWS\system32\mswsock.dll [247808] ©
O83 - Search Svchost Services: Ntmssvc (Ntmssvc) . (.Microsoft Corporation - Gestionnaire de stockage amovible.) -- C:\WINDOWS\system32\ntmssvc.dll [438272] ©
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\system32\rasauto.dll [88576] ©
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\system32\rasmans.dll [186368] ©
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\WINDOWS\system32\mprdim.dll [53248] ©
O83 - Search Svchost Services: Schedule (Schedule) . (.Microsoft Corporation - Moteur du Planificateur de tâches.) -- C:\WINDOWS\system32\schedsvc.dll [194560] ©
O83 - Search Svchost Services: Seclogon (Seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secon.) -- C:\WINDOWS\system32\seclogon.dll [18944] ©
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\system32\sens.dll [39424] ©
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à.) -- C:\WINDOWS\system32\ipnathlp.dll [332800] ©
O83 - Search Svchost Services: SRService (SRService) . (.Microsoft Corporation - Service de restauration du système.) -- C:\WINDOWS\system32\srsvc.dll [171520] ©
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\WINDOWS\system32\tapisrv.dll [249856] ©
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680] ©
O83 - Search Svchost Services: TrkWks (TrkWks) . (.Microsoft Corporation - Distributed Link Tracking Client.) -- C:\WINDOWS\system32\trkwks.dll [90112] ©
O83 - Search Svchost Services: W32Time (W32Time) . (.Microsoft Corporation - Service de temps Windows.) -- C:\WINDOWS\system32\w32time.dll [178176] ©
O83 - Search Svchost Services: WZCSVC (WZCSVC) . (.Microsoft Corporation - Service configuration automatique sans fil.) -- C:\WINDOWS\system32\wzcsvc.dll [483840] ©
O83 - Search Svchost Services: Wmi (Wmi) . (.Microsoft Corporation - API avancées Windows 32.) -- C:\WINDOWS\system32\advapi32.dll [685568] ©
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\wmisvc.dll [145408] ©
O83 - Search Svchost Services: wscsvc (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) -- C:\WINDOWS\system32\wscsvc.dll [80896] ©
O83 - Search Svchost Services: xmlprov (xmlprov) . (.Microsoft Corporation - Network Provisioning Service.) -- C:\WINDOWS\system32\xmlprov.dll [129024] ©
O83 - Search Svchost Services: napagent (napagent) . (.Microsoft Corporation - Exécution du service Agent de quarantaine.) -- C:\WINDOWS\system32\qagentrt.dll [293376] ©
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\WINDOWS\system32\kmsvc.dll [61440] ©
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\WINDOWS\system32\qmgr.dll [409088] ©
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update AutoUpdate Service.) -- C:\WINDOWS\system32\wuauserv.dll [6656] ©
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680] ©
O83 - Search Svchost Services: helpsvc (helpsvc) . (.Microsoft Corporation - Microsoft PCHealth Service Holder.) -- C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll [38400] ©
O83 - Search Svchost Services: WmdmPmSN (WmdmPmSN) . (.Microsoft Corporation - Fournisseur de services de périphérique mul.) -- C:\WINDOWS\system32\mspmsnsv.dll [52736] ©

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (4) - 7s

SS - Demand [09/12/2015] [ 269504] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
SS - Auto [30/07/2015] [ 144200] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [30/07/2015] [ 144200] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc®

---\\ Scan Additionnel (1) - 0s
~ Aucun élément malicieux ou superflu trouvé.

---\\ Récapitulatif des éléments trouvés sur votre station (1) - 0s
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.YourSites123

~ End of the scan, 30692 items in 00h02mn11s (539)(0)

Publicité


Signaler le contenu de ce document

Publicité