~ Rapport de ZHPDiag v2013.9.11.20 - Nicolas Coolman (2013-09-11) ~ Lancé par propriétaire (2013-09-12 19:01:41) ~ Adresse du Site Web http://nicolascoolman.webs.com ~ Traduit par Nicolas Coolman ~ Etat de la version : ~ Liste blanche : Activée par le programme ~ Elévation des Privilèges : OK ~ User Account Control (UAC): Activate by user ---\\ Navigateurs Internet MSIE: Internet Explorer v10.0.9200.16686 ---\\ Informations sur les produits Windows ~ Langage: Français Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601) Windows Server License Manager Script : OK ~ Windows(R) 7, OEM_SLP channel System Locked Preinstallation (OEM_SLP) : OK Windows ID Activation : OK ~ Windows Partial Key : W8DQG Windows License : OK ~ Windows Remaining Initializations Number : 4 Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ Logiciels de protection du système Avira Free Antivirus v13.0.0.4042 Malwarebytes Anti-Malware version 1.75.0.1300 Windows Defender W7 ---\\ Logiciels d'optimisation du système CCleaner v3.24 =>Piriform Ltd ---\\ Logiciels de partage PeerToPeer ---\\ Surveillance de Logiciels Adobe Flash Player 11 Plugin Adobe Reader X Java 7 Update 25 ---\\ Informations sur le système ~ Processor: Intel64 Family 6 Model 37 Stepping 5, GenuineIntel ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 3894 MB (62% free) System Restore: Activé (Enable) System drive C: has 336 GB (59%) free of 563 GB ---\\ Mode de connexion au système ~ Computer Name: PROPRIÉTAIRE-PC ~ User Name: propriétaire ~ All Users Names: propriétaire, HomeGroupUser$, Administrateur, ~ Unselected Option: None Logged in as Administrator ---\\ Variables d'environnement ~ System Unit : C:\ ~ %AppData% : C:\Users\propriétaire\AppData\Roaming\ ~ %Desktop% : C:\Users\propriétaire\Desktop\ ~ %Favorites% : C:\Users\propriétaire\Favorites\ ~ %LocalAppData% : C:\Users\propriétaire\AppData\Local\ ~ %StartMenu% : C:\Users\propriétaire\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumération des unités disques C:\ Hard drive, Flash drive, Thumb drive (Free 336 Go of 563 Go) D:\ CD-ROM drive (Not Inserted) ---\\ Etat du Centre de Sécurité Windows [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified ~ Security Center: 37 Legitimates Filtered in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.2011-02-25 - 01:19:30.) -- C:\Windows\Explorer.exe [2871808] [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.2009-07-13 - 20:39:52.) -- C:\Windows\System32\Wininit.exe [129024] [MD5.AAFA952E774DDDB0956D3BDFAE5B5B99] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.2013-08-10 - 00:22:18.) -- C:\Windows\System32\wininet.dll [2241024] [MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.2010-11-20 - 08:25:30.) -- C:\Windows\System32\Winlogon.exe [390656] [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.2010-11-20 - 08:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448] [MD5.1C7857B62DE5994A75B054A9FD4C3825] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.2011-12-27 - 22:59:24.) -- C:\Windows\system32\Drivers\AFD.sys [498688] [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.2009-07-13 - 20:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128] [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.2009-07-13 - 18:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160] [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.2010-11-20 - 04:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456] [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.2010-11-20 - 04:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400] [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.2010-11-20 - 05:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368] [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.2009-07-13 - 18:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472] [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.2009-07-13 - 19:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224] [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.2011-04-26 - 21:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208] [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.2010-11-20 - 04:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632] [MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.2013-04-12 - 09:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680] [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.2009-07-13 - 19:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280] [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.2010-11-20 - 05:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536] [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.2009-07-13 - 19:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184] [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.2010-11-20 - 04:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296] [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.2010-11-20 - 08:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808] ~ Generic Processes: Scanned in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 10/7615 ~ Mes musiques (My Musics) : 9/2942 ~ Mes Videos (My Videos) : 3/346 ~ Mes Favoris (My Favorites) : 1/98 ~ Mes Documents (My Documents) : 3/6125 ~ Mon Bureau (My Desktop) : 1/8 ~ Menu demarrer (Programs) : 1/24 ~ Hidden Files: Scanned in 00mn 27s ---\\ Processus lancés [MD5.DF1BBA1168C0AD1D080A1F1B99576A76] - (.Google Inc. - Google Chrome.) -- C:\Users\propriétaire\AppData\Local\Google\Chrome\Application\chrome.exe [829392] [PID.2040] [MD5.DB3F7F19F942D3CE4E1A0E8D9FF541FB] - (.Avira Operations GmbH & Co. KG - Avira System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192] [PID.348] [MD5.A7E406711790197712D376B44A9FBB0B] - (.TOSHIBA CORPORATION - ConfigFree Task Tray Menu.) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe [304496] [PID.2360] [MD5.8A07221789D46B2EA7DFCA2BC807572A] - (.TOSHIBA CORPORATION - ConfigFree Switch Manager Process.) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe [62848] [PID.3544] [MD5.D2FB1CFB2E4E6C7F14FE302B982A4E18] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [7938560] [PID.3160] [MD5.8769E2D1072B62AB071F166F03B3E3DC] - (.Avira Operations GmbH & Co. KG - Avira Scheduler.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024] [PID.1216] [MD5.ADDA5E1951B90D3D23C56D3CF0622ADC] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65640] [PID.1368] [MD5.4FE5C6D40664AE07BE5105874357D2ED] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [57008] [PID.1488] [MD5.8726802EA4FBFFA3FD54FD2449BF51D4] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe [217992] [PID.1912] [MD5.23DE5B62B0445A6F874BE633C95B483E] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [268824] [PID.2456] [MD5.A6A7AD767BF5141665F5C675F671B3E1] - (.Protexis Inc. - PsiService PsiService.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [185632] [PID.2508] [MD5.0765EE4A7A0D6609BF91CA2E4700E885] - (.TomTom - Windows Service for TomTom HOME.) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [93072] [PID.2720] [MD5.C5A75EB48E2344ABDC162BDA79E16841] - (.Microsoft Corporation - .NET Runtime Optimization Service.) -- C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [130384] [PID.2836] [MD5.CAB0EEAF5295FC96DDD3E19DCE27E131] - (.TOSHIBA CORPORATION - ConfigFree Service Process.) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [46448] [PID.1344] [MD5.CC3775100ABA633984F73DFAE1F55CAE] - (.Intel Corporation - User Notification Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2320920] [PID.1508] [MD5.AD1D13E6326E0B8DA2A7BE13B39A8FE0] - (.Avira Operations GmbH & Co. KG - Avira On-Access Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088] [PID.1200] ~ Processes Running: Scanned in 00mn 00s ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2) C:\Users\propriétaire\AppData\Local\Google\Chrome\User Data\Default\Preferences G2 - GCE: Preference [User Data\Default] [bfhgfkeegdkhaghijaklnooemnbbhiek] the smurfs movie v.1 (Activé) G2 - GCE: Preference [User Data\Default] [clgliemokfgimmfodoeboneoibjklncc] Crazy4Jigsaws v.1.1.1 (Activé) G2 - GCE: Preference [User Data\Default] [fapbbpdnlcmiolkdfjnnjhabmcndadad] Météo v.0.9.0.6 (Activé) G2 - GCE: Preference [User Data\Default] [odklcfojpedohplkimfdpcamkjnhanaj] Picky Wallpapers v.1.0.0 (Activé) ~ Google Browser: 17 Legitimates Filtered in 00mn 31s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Hosts file redirection (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Hosts File: Scanned in 00mn 04s ~ Nombre de lignes (Lines number): 54450 ---\\ Internet Explorer Toolbars (O3) O3 - Toolbar: (no name) [64Bits] - [HKLM]{0BF43445-2F28-4351-9252-17FE6E806AA0} Clé orpheline O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Clé orpheline ~ Toolbar: Scanned in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\Program [Public]: Aide de Recovery Media Creator.lnk . (...) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Recovery Media Creator\TrdcHelp.html (.not file.) O4 - GS\Program [Public]: Cisco Connect.lnk . (.Cisco Consumer Products LLC - Linksys Software.) -- C:\Program Files (x86)\Cisco Systems\Cisco Connect\Cisco Connect.exe O4 - GS\Program [Public]: GIMP 2.lnk . (.Spencer Kimball, Peter Mattis and the GIMP - GNU Image Manipulation Program.) -- C:\Program Files\GIMP 2\bin\gimp-2.8.exe O4 - GS\Program [Public]: Recovery Media Creator.lnk . (...) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Recovery Media Creator\TRMCLcher.exe (.not file.) O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Afficher le commutateur.) -- C:\windows\system32\displayswitch.exe O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Accessoire du panneau de saisie mathématiqu.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Centre de mobilité Windows.) -- C:\windows\system32\mblctr.exe O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) -- C:\windows\system32\mspaint.exe O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) -- C:\windows\system32\mstsc.exe O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Magnétophone Windows.) -- C:\windows\system32\SoundRecorder.exe O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) -- C:\windows\System32\mobsync.exe O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Table des caractères.) -- C:\windows\system32\charmap.exe O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Défragmenteur de disque Microsoft®.) -- C:\windows\system32\dfrgui.exe O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Gestionnaire de nettoyage de disque pour Wi.) -- C:\windows\system32\cleanmgr.exe O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Moniteur de ressources et de performances.) -- C:\windows\system32\perfmon.exe O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - Informations système.) -- C:\windows\system32\msinfo32.exe O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Restauration du système de Microsoft® Windo.) -- C:\windows\system32\rstrui.exe O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) -- C:\windows\system32\taskschd.msc \s (.not file.) O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Application post-migration de transfert de.) -- C:\windows\system32\migwiz\postmig.exe O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Application Transfert de fichiers et paramè.) -- C:\windows\system32\migwiz\migwiz.exe O4 - GS\SendTo [propriétaire]: TOSHIBA Disc Creator (CD audio).lnk . (.TOSHIBA Corporation - Pas de description.) -- C:\Program Files (x86)\Toshiba\TOSHIBA Disc Creator\ToDisc.exe O4 - GS\SendTo [propriétaire]: TOSHIBA Disc Creator (Disque de données).lnk . (.TOSHIBA Corporation - Pas de description.) -- C:\Program Files (x86)\Toshiba\TOSHIBA Disc Creator\ToDisc.exe O4 - GS\SendTo [propriétaire]: TOSHIBA Disc Creator (Images vers disque).lnk . (.TOSHIBA Corporation - Pas de description.) -- C:\Program Files (x86)\Toshiba\TOSHIBA Disc Creator\ToDisc.exe ~ Global Startup: 54 Legitimates Filtered in 00mn 05s ---\\ Applications lancées au démarrage du sytème (O4) O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_48A618CE24F76BA47910EB5250B8D86C] . (.Google Inc. - Google Chrome.) -- C:\Users\propriétaire\AppData\Local\Google\Chrome\Application\chrome.exe O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Avira System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe O4 - HKUS\S-1-5-21-54028736-3391823240-78155860-1000\..\Run: [GoogleChromeAutoLaunch_48A618CE24F76BA47910EB5250B8D86C] . (.Google Inc. - Google Chrome.) -- C:\Users\propriétaire\AppData\Local\Google\Chrome\Application\chrome.exe ~ Application: Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{B79A9B14-7846-4AC3-A75A-6A4FF2268B6C}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{5EF20569-28A2-4A10-AC93-98BA6488BFD5}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{B79A9B14-7846-4AC3-A75A-6A4FF2268B6C}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{5EF20569-28A2-4A10-AC93-98BA6488BFD5}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{B79A9B14-7846-4AC3-A75A-6A4FF2268B6C}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{5EF20569-28A2-4A10-AC93-98BA6488BFD5}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll ~ Winlogon: Scanned in 00mn 00s ---\\ Tâches planifiées en automatique (O39) [MD5.00000000000000000000000000000000] [APT] [{5434BF7E-30B2-48D1-8056-2500B49A3C1D}] (...) -- D:\setup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{98DFB89D-4EE4-45B9-A601-743C98EF047C}] (...) -- F:\Setup.exe (.not file.) [0] ~ Scheduled Task: 19 Legitimates Filtered in 00mn 06s ---\\ Logiciels installés (O42) O42 - Logiciel: QuickFinder - (.NetNucleous.) [HKLM][64Bits] -- {5D377627-137F-4531-A6FF-2D7327467741} ~ Logic: 137 Legitimates Filtered in 00mn 01s ---\\ HKCU & HKLM Software Keys [HKCU\Software\Ares] [HKCU\Software\IncrediMail] [HKCU\Software\Reimage] =>Rogue.ReimageRepair [HKLM\Software\Reimage] =>Rogue.ReimageRepair ~ Key Software: 274 Legitimates Filtered in 00mn 01s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 2011-10-19 - 22:27:57 - [1,349] ----D C:\Program Files (x86)\Ares O43 - CFD: 2012-03-24 - 23:18:58 - [0,001] ----D C:\Program Files (x86)\Complex O43 - CFD: 2012-06-01 - 13:24:57 - [19,449] ----D C:\Program Files (x86)\MPAccess O43 - CFD: 2011-10-19 - 22:27:25 - [1,031] ----D C:\Program Files (x86)\Shareaza O43 - CFD: 2013-08-07 - 16:01:22 - [0,000] ----D C:\ProgramData\IM O43 - CFD: 2013-08-07 - 16:00:19 - [0,012] ----D C:\ProgramData\IncrediMail O43 - CFD: 2012-08-01 - 13:35:17 - [54,052] ----D C:\Users\propriétaire\AppData\Roaming\MultiMi O43 - CFD: 2012-10-14 - 18:58:57 - [0,000] ----D C:\Users\propriétaire\AppData\Roaming\OwnRooms O43 - CFD: 2011-10-19 - 22:27:24 - [0,218] ----D C:\Users\propriétaire\AppData\Roaming\Shareaza O43 - CFD: 2012-08-07 - 20:13:23 - [0,080] ----D C:\Users\propriétaire\AppData\Local\Ares O43 - CFD: 2013-06-03 - 17:52:38 - [0,804] ----D C:\Users\propriétaire\AppData\Local\D734AB01-5C8C-47E5-A905-DCBE34B7C8C0.aplzod O43 - CFD: 2013-08-09 - 21:36:57 - [227,997] ----D C:\Users\propriétaire\AppData\Local\IM O43 - CFD: 2011-08-12 - 21:01:59 - [0,474] ----D C:\Users\propriétaire\AppData\Local\Shareaza O43 - CFD: 2012-08-08 - 12:30:20 - [0] ----D C:\Users\propriétaire\AppData\Local\WmaMp3-Converter.com ~ Program Folder: 275 Legitimates Filtered in 00mn 58s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.20F474F6FC226D7BF28BEED7775B9680] - 2013-09-07 - 11:48:45 ---A- . (...) -- C:\Windows\Brownie.ini [558] O44 - LFC:[MD5.543FC597F199AE617FB77F458BDA92CE] - 2013-09-09 - 19:24:01 ---A- . (...) -- C:\Windows\Reimage.ini [154] =>Rogue.ReimageRepair ~ Files: 147 Legitimates Filtered in 00mn 58s ---\\ Derniers fichiers créés dans Windows Prefetcher (O45) O45 - LFCP:[MD5.DE26DDC2FE9D28DAE97D6B89B561638B] - 2013-09-04 - 18:57:37 ---A- - C:\Windows\Prefetch\EREPOR~1.EXE-DA8FBAF7.pf O45 - LFCP:[MD5.ABBFE960E1CE25041295945007DE9103] - 2013-09-06 - 10:44:34 ---A- - C:\Windows\Prefetch\29.0.1547.66_29.0.1547.62_CHR-1D0DE5C7.pf O45 - LFCP:[MD5.1745FEC18CCF29A0292E214F5BBDB58E] - 2013-09-06 - 10:56:39 ---A- - C:\Windows\Prefetch\AELDR.EXE-41E94B09.pf O45 - LFCP:[MD5.F81242D7E62C309563DD82C8DB97B7D4] - 2013-09-07 - 10:11:22 ---A- - C:\Windows\Prefetch\PDFPROFILTSRVPP.EXE-E8B72F39.pf O45 - LFCP:[MD5.4CBEF35F028688D7F3714E08F6EFD954] - 2013-09-07 - 10:12:12 ---A- - C:\Windows\Prefetch\PDFPRO5HOOK.EXE-DA7136FC.pf O45 - LFCP:[MD5.C19EF3F7AD5718B3D0EB286622A73825] - 2013-09-07 - 10:12:14 ---A- - C:\Windows\Prefetch\REGISTRYCONTROLLER.EXE-FC8FA110.pf O45 - LFCP:[MD5.375A56E724BBAE92B099F4FC4B291DFD] - 2013-09-10 - 18:58:06 ---A- - C:\Windows\Prefetch\IMLPP.EXE-C9266A11.pf O45 - LFCP:[MD5.B023D2881ED6D0B61CF3092D0783380C] - 2013-09-10 - 18:58:46 ---A- - C:\Windows\Prefetch\IMBPP.EXE-BF2AD1FF.pf O45 - LFCP:[MD5.4AC052E6BA4B659348BA4D8219A1E2F2] - 2013-09-10 - 19:30:33 ---A- - C:\Windows\Prefetch\INCMAIL.EXE-F91AEC10.pf O45 - LFCP:[MD5.936F277582B440DE4D1053E277D7D65D] - 2013-09-10 - 19:30:35 ---A- - C:\Windows\Prefetch\IMAPP.EXE-3E2B42CA.pf O45 - LFCP:[MD5.AEBA990E5E515A45D1609E0C5C14B433] - 2013-09-10 - 20:04:14 ---A- - C:\Windows\Prefetch\PSISERVICE_2.EXE-019720BD.pf O45 - LFCP:[MD5.CF67C3991A4364AC1FEECF16048EA918] - 2013-09-11 - 16:46:40 ---A- - C:\Windows\Prefetch\TECOSERVICE.EXE-C4744937.pf O45 - LFCP:[MD5.0D3B09B875D2321F3710A504FC54194E] - 2013-09-11 - 18:57:38 ---A- - C:\Windows\Prefetch\EREPORTER.EXE-044CC358.pf ~ Prefetcher: 139 Legitimates Filtered in 00mn 00s ---\\ Enumération des clés de registre StartupReg (SMSR) (O53) O53 - SMSR:HKLM\...\startupreg\BrStsWnd [Key] . (.brother - brstswnd.) -- C:\Program Files (x86)\Brownie\BrstsW64.exe O53 - SMSR:HKLM\...\startupreg\IncrediMail [Key] . (...) -- C:\Program Files (x86)\IncrediMail\bin\IncMail.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\IndexSearch [Key] . (...) -- C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\ISUSPM [Key] . (...) -- C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\PaperPort PTD [Key] . (...) -- C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\PDF5 Registry Controller [Key] . (...) -- C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\PDFHook [Key] . (...) -- C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\SmartAudio [Key] . (.Pas de propriétaire - SAIICpl MFC Application.) -- C:\Program Files\CONEXANT\SAII\SAIICpl.exe ~ SMSR Keys: 37 Legitimates Filtered in 00mn 00s ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 18 Legitimates Filtered in 00mn 00s ---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56) O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 ~ MWPE Keys: 5 Legitimates Filtered in 00mn 00s ---\\ Liste des pilotes du système (SDL) (O58) O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 2009-07-13 - 20:47:48 . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496] O58 - SDL:[MD5.B280C4608AC389DA9515A35AC4CAB0FD] - 2012-05-24 - 08:59:50 ---A- . (.http://libusb-win32.sourceforge.net - LibUSB-Win32 - Kernel Driver.) -- C:\Windows\SysWOW64\drivers\libusb0.sys [21504] ~ Drivers: 18 Legitimates Filtered in 00mn 00s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC: 2013-09-09 - 17:24:04 -SHA- . (...) -- C:\Users\propriétaire\Documents\Divers\Thumbs.db [245760] O61 - LFC: 2013-09-09 - 17:31:15 ---A- . (...) -- C:\Users\propriétaire\Documents\Courriel.docx [98635] O61 - LFC: 2013-09-10 - 18:58:07 ---A- . (...) -- C:\Users\propriétaire\AppData\Local\IM\content.xml [15627] O61 - LFC: 2013-09-11 - 02:09:29 ---A- . (...) -- C:\Users\propriétaire\AppData\Local\Google\Chrome\User Data\Certificate Revocation Lists [261280] O61 - LFC: 2013-09-11 - 02:41:12 ---A- . (...) -- C:\Users\propriétaire\Links\Desktop.lnk [513] O61 - LFC: 2013-09-11 - 02:41:12 ---A- . (...) -- C:\Users\propriétaire\Links\Downloads.lnk [1161] O61 - LFC: 2013-09-11 - 02:41:12 ---A- . (...) -- C:\Users\propriétaire\Links\RecentPlaces.lnk [383] O61 - LFC: 2013-09-12 - 17:28:28 ---A- . (...) -- C:\Users\propriétaire\AppData\Roaming\Microsoft\Access\AccessDCActionFile.xml [283] O61 - LFC: 2013-09-12 - 18:03:48 ---A- . (...) -- C:\Users\propriétaire\AppData\Local\Google\Chrome\User Data\Local State [42943] ~ 37 Fichiers temporaires (Temporary files) ~ Files: 496 Legitimates Filtered in 04mn 14s ---\\ Fichiers Alternate Data Stream (ADS) (O62) O62 - ADS:Alternate Data Stream File - C:\Windows\System32\SpoonUninstall.exe:Zone.Identifier ~ ADS: Scanned in 01mn 03s ---\\ Liste des outils de désinfection (LATC) (O63) O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 ~ ADS: Scanned in 00mn 00s ---\\ Liste les services legacy du registre (LALS) (O64) O64 - Services: CurCS - 1601-01-01 - Pas de propriétaire (esgiguard) .(...) - LEGACY_ESGIGUARD =>Crapware.SpyHunter ~ Legacy: 81 Legitimates Filtered in 00mn 00s ---\\ Associations Shell Spawning (O67) O67 - Shell Spawning: <.exe> [HKCU\..\open\Command] (.Not Key.) ~ FASS Keys: 20 Legitimates Filtered in 00mn 00s ---\\ Menu de démarrage Internet (SMI) (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\propriétaire\AppData\Local\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - http://www.google.com ~ Keys: Scanned in 00mn 00s ---\\ Recherche particulière à la racine du système (SPRF) (O84) [MD5.0641A46F1E58529A42EAD4573A3A0861] [SPRF][2011-10-13] (...) -- C:\ProgramData\CE2EDDB718.sys [8] [MD5.A0A95D6EA8B2C2311F4B38F7395CEF62] [SPRF][2011-05-27] (...) -- C:\ProgramData\ezsidmv.dat [56] [MD5.DCD5CBE5AFD7E6E3C028428BA8C61455] [SPRF][2013-08-31] (...) -- C:\ProgramData\KGyGaAvL.sys [3766] [MD5.3BF79E6868B44D3ADB2796BA99521891] [SPRF][2013-09-07] (...) -- C:\Users\propriétaire\AppData\Local\Temp\Quarantine.exe [344583] [MD5.48EEC4A0E0571C9047442F7B876A745D] [SPRF][2013-09-09] (.Reimage® - Reimage Repair.) -- C:\Users\propriétaire\AppData\Local\Temp\ReimagePackage.exe [10199976] =>Rogue.ReimageRepair [MD5.91CDCEA4BE94624E198D3012F5442584] [SPRF][2013-07-11] (...) -- C:\Users\propriétaire\AppData\Local\Temp\sqlite3.exe [488960] [MD5.16E53BFC96CE14021C0E07EB1C198478] [SPRF][2012-09-08] (...) -- C:\Users\propriétaire\AppData\Roaming\inst.exe [99384] [MD5.AF7CE12C4F3DC8CB2B07685C916BBCFE] [SPRF][2012-09-08] (.VSO Software - low level access layer for CD/DVD/BD devices.) -- C:\Users\propriétaire\AppData\Roaming\pcouffin.sys [82816] [MD5.720CBF9C4E60540122BED3EA8CC0EAAC] [SPRF][2013-09-09] (...) -- C:\Users\propriétaire\Desktop\adwcleaner.exe [1037278] [MD5.17A515F253ACF6C461FE4FC3F8F0FC00] [SPRF][2013-09-09] (.Reimage® - Reimage Downloader.) -- C:\Users\propriétaire\Desktop\ReimageRepair.exe [761160] =>Rogue.ReimageRepair ~ Files: 13 Legitimates Filtered in 00mn 02s ---\\ Liste des exceptions du parefeu (FirewallRules) (O87) O87 - FAEL: "TCP Query User{B49D334C-9EA5-4E82-9B46-53EFE685290F}C:\program files (x86)\ares\ares.exe" | In - Private - P6 - TRUE | .(.Ares Development Group - Ares p2p for windows.) -- C:\program files (x86)\ares\ares.exe O87 - FAEL: "UDP Query User{7866C14A-5902-4E09-B32A-DF80A2C824D0}C:\program files (x86)\ares\ares.exe" | In - Private - P17 - TRUE | .(.Ares Development Group - Ares p2p for windows.) -- C:\program files (x86)\ares\ares.exe O87 - FAEL: "TCP Query User{91732554-619C-47CA-AD11-A57854FA2514}C:\program files (x86)\ares\chatserver.exe" | In - Private - P6 - TRUE | .(.Ares Development Group - Ares Chat Server.) -- C:\program files (x86)\ares\chatserver.exe O87 - FAEL: "UDP Query User{14FB4E2B-5B01-4981-B3E7-D5FD7D24E8CB}C:\program files (x86)\ares\chatserver.exe" | In - Private - P17 - TRUE | .(.Ares Development Group - Ares Chat Server.) -- C:\program files (x86)\ares\chatserver.exe O87 - FAEL: "TCP Query User{5F8B983A-9C60-49FA-8D4C-96E4D114B4DA}C:\program files (x86)\ares\ares.exe" | In - Public - P6 - TRUE | .(.Ares Development Group - Ares p2p for windows.) -- C:\program files (x86)\ares\ares.exe O87 - FAEL: "UDP Query User{7038A412-5486-4135-9581-C82BD0988B24}C:\program files (x86)\ares\ares.exe" | In - Public - P17 - TRUE | .(.Ares Development Group - Ares p2p for windows.) -- C:\program files (x86)\ares\ares.exe O87 - FAEL: "{D30653FF-C8B9-4075-840F-8825CA517817}" |In - Private - P6 - FALSE | .(...) -- C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe (.not file.) O87 - FAEL: "{281777B4-3286-4745-810B-A1EFF703D160}" |In - Private - P17 - FALSE | .(...) -- C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe (.not file.) O87 - FAEL: "{CC064000-A7AE-4E00-82EA-F19D68CE3898}" |In - Private - P6 - FALSE | .(...) -- C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe (.not file.) O87 - FAEL: "{0882BB85-D1A6-45F8-96A9-44925F6C5BE3}" |In - Private - P17 - FALSE | .(...) -- C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe (.not file.) O87 - FAEL: "{F2212250-2C77-448E-8593-AED2B4F7BEEA}" |In - Private - P6 - FALSE | .(...) -- C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe (.not file.) O87 - FAEL: "{74D3AFAA-FDDA-4A8C-B2F6-C37B292C0713}" |In - Private - P17 - FALSE | .(...) -- C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe (.not file.) ~ Firewall: 228 Legitimates Filtered in 00mn 03s ---\\ Enumère les codes produits des logiciels (PUC) (O90) O90 - PUC: "404BC4E74E1F18E41ABCC2BB1340181D" . (.MLE.) -- C:\windows\Installer\{7E4CB404-F1E4-4E81-A1CB-2CBB310481D1}\ARPPRODUCTICON.exe O90 - PUC: "D4B8248F423EC5F4C97C8EB835DC67E5" . (.ContentHD.) -- C:\windows\Installer\{F8428B4D-E324-4F5C-9CC7-E88B53CD765E}\ARPPRODUCTICON.exe ~ Update Products: 101 Legitimates Filtered in 00mn 00s ---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS) [MD5.78B41A323699DAF1C25265890733BE26] [WIS][2012-04-05] (.Adobe - Blank Project Template.) -- C:\Windows\Installer\19183b5.msi [1997312] ~ WIS: 104 Legitimates Filtered in 00mn 41s ---\\ Etat général des services not Microsoft (EGS) (SR=Running, SS=Stopped) SR - | Auto 2013-05-10 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe SS - | Demand 2012-10-09 250808 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe SR - | Auto 2013-09-10 84024 | (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe SR - | Auto 2013-09-10 108088 | (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe SR - | Auto 2012-12-21 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe SS - | Demand 2012-06-05 266240 | (BrYNSvc) . (.Brother Industries, Ltd..) - C:\Program Files (x86)\Browny02\BrYNSvc.exe SR - | Auto 2010-01-28 249200 | (cfWiMAXService) . (.TOSHIBA CORPORATION.) - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe SR - | Auto 2009-03-10 46448 | (ConfigFree Service) . (.TOSHIBA CORPORATION.) - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe SS - | Auto 2011-05-23 135664 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 2011-05-23 135664 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Auto 2013-08-07 285795 | (HOSTS Anti-PUPs) . (...) - C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe SS - | Demand 2013-05-31 641352 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe SR - | Auto 2010-03-03 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe SR - | Auto 2007-07-24 185632 | (PSI_SVC_2) . (.Protexis Inc..) - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe SS - | Demand 2009-10-06 51512 | (TMachInfo) . (.TOSHIBA Corporation.) - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe SR - | Auto 2009-07-28 140632 | (TODDSrv) . (.TOSHIBA Corporation.) - C:\windows\system32\TODDSrv.exe SR - | Auto 2013-03-22 93072 | (TomTomHOMEService) . (.TomTom.) - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe SR - | Auto 2009-11-05 489312 | (TosCoSrv) . (.TOSHIBA Corporation.) - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe SR - | Auto 2010-03-17 258928 | (TOSHIBA eco Utility Service) . (.TOSHIBA Corporation.) - C:\Program Files\TOSHIBA\TECO\TecoService.exe SS - | Demand 2010-02-05 137560 | (TOSHIBA HDD SSD Alert Service) . (.TOSHIBA Corporation.) - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe SS - | Demand 2010-02-23 835952 | (TPCHSrv) . (.TOSHIBA Corporation.) - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe SR - | Auto 2010-03-03 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe SR - | Auto 2009-07-13 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 1658-07-10 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe SR - | Auto 2009-07-13 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Services: Scanned in 00mn 43s ---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80) Run by propriétaire at 2013-09-12 19:11:59 ~ OS 64 not supported by MBR tool ~ MBR: 0 Legitimates Filtered in 00mn 00s ---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by propriétaire at 2013-09-12 19:12:01 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 02s ---\\ Scan Additionnel (O88) Database Version : 12904 - (2013-09-11) Clés trouvées (Keys found) : 2 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 0 Fichiers trouvés (Files found) : 3 [HKCU\Software\Reimage] =>Rogue.ReimageRepair [HKLM\Software\Reimage] =>Rogue.ReimageRepair C:\Windows\Reimage.ini =>Rogue.ReimageRepair^ C:\Users\propriétaire\AppData\Local\Temp\ReimagePackage.exe =>Rogue.ReimageRepair^ C:\Users\propriétaire\Desktop\ReimageRepair.exe =>Rogue.ReimageRepair^ ~ Additionnel Scan: 359625 Items scanned in 00mn 17s ---\\ Récapitulatif des détections trouvées sur votre station ~ http://nicolascoolman.webs.com/apps/blog/show/26633218-rogue-reimagerepair =>Rogue.ReimageRepair ~ http://nicolascoolman.webs.com/apps/blog/show/26609241-crapware-spyhunter =>Crapware.SpyHunter ~ MSI: 2 link(s) detected in 00mn 17s ~ 2060 Legitimates filtered by white list End of the scan (515 lines in 10mn 37s)(0)