~ Rapport de ZHPDiag v2014.4.19.34 - Nicolas Coolman (19/04/2014) ~ Lancé par ♪ Blackstar ♪ (19/04/2014 13:29:16) ~ Adresse du Site Web http://nicolascoolman.webs.com ~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/ ~ Traduit par Nicolas Coolman ~ Etat de la version : ~ Liste blanche : Activée par le programme ~ Elévation des Privilèges : OK ~ User Account Control (UAC): Activate by user ---\\ Navigateurs Internet MSIE: Internet Explorer v11.0.9600.16659 GCIE: Google Chrome v34.0.1847.116 (Defaut) ---\\ Informations sur les produits Windows ~ Langage: Français Windows 8.1, 64-bit (Build 9600) Windows Server License Manager Script : OK ~ Windows(R) Operating System, OEM_DM channel Windows ID Activation : OK ~ Windows Partial Key : GJCVD Windows License : OK ~ Windows Remaining Initializations Number : 999 Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ Logiciels de protection du système avast! Free Antivirus v9.0.2016 Windows Defender W8 ---\\ Logiciels d'optimisation du système CCleaner v4.12 =>.Piriform Ltd ---\\ Logiciels de partage PeerToPeer ---\\ Surveillance de Logiciels Adobe Reader XI ---\\ Informations sur le système ~ Processor: AMD64 Family 22 Model 0 Stepping 1, AuthenticAMD ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 3525 MB (50% free) System Restore: Activé (Enable) System drive C: has 393 GB (87%) free of 450 GB ---\\ Mode de connexion au système ~ Computer Name: SYLVIO ~ User Name: ♪ Blackstar ♪ ~ All Users Names: ♪ Blackstar ♪, Administrateur, ~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89 Logged in as Administrator ---\\ Variables d'environnement ~ System Unit : C:\ ~ %AppZHP% : C:\Users\Sylvio\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\Sylvio\AppData\Roaming\ ~ %Desktop% : C:\Users\Sylvio\Desktop\ ~ %Favorites% : C:\Users\Sylvio\Favorites\ ~ %LocalAppData% : C:\Users\Sylvio\AppData\Local\ ~ %StartMenu% : C:\Users\Sylvio\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumération des unités disques C: Hard drive, Flash drive, Thumb drive (Free 393 Go of 450 Go) Q: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go) ---\\ Etat du Centre de Sécurité Windows [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified ~ Security Center: 41 Legitimates Filtered in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.63DC38C3E4564B2405D562855643ABA2] - (.Microsoft Corporation - Explorateur Windows.) (.14/11/2013 - 08:37:16.) -- C:\Windows\Explorer.exe [2328872] [MD5.48CFA7BE561A7BE144C29BB912055016] - (.Microsoft Corporation - Application de démarrage de Windows.) (.22/08/2013 - 10:58:29.) -- C:\Windows\System32\Wininit.exe [144384] [MD5.DF79CE9B950C62677D232154E93A81C7] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.01/03/2014 - 04:10:28.) -- C:\Windows\System32\wininet.dll [2334208] [MD5.7C94FDA3809015B8F2208D2E1C221F17] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.22/08/2013 - 10:55:08.) -- C:\Windows\System32\Winlogon.exe [564736] [MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - (.Microsoft Corporation - Bibliothèque de licences.) (.21/12/2013 - 09:54:07.) -- C:\Windows\System32\sppcomapi.dll [447488] [MD5.239268BAB58EAE9A3FF4E08334C00451] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.22/08/2013 - 14:25:35.) -- C:\Windows\system32\Drivers\AFD.sys [567296] [MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.22/08/2013 - 13:43:41.) -- C:\Windows\system32\Drivers\atapi.sys [26464] [MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) (.22/08/2013 - 12:40:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [88576] [MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.22/08/2013 - 09:46:35.) -- C:\Windows\system32\Drivers\Cdrom.sys [164352] [MD5.5DB26D7E0216D0BF364A81D3829AD7B9] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.22/08/2013 - 12:38:00.) -- C:\Windows\system32\Drivers\DfsC.sys [134656] [MD5.03909BDBFF0DCACCABF2B2D4ADEE44DC] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.22/08/2013 - 12:38:38.) -- C:\Windows\system32\Drivers\HDAudBus.sys [78336] [MD5.84CFC5EFA97D0C965EDE1D56F116A541] - (.Microsoft Corporation - Pilote de port i8042.) (.22/08/2013 - 12:39:15.) -- C:\Windows\system32\Drivers\i8042prt.sys [107520] [MD5.B7342B3C58E91107F6E946A93D9D4EFD] - (.Microsoft Corporation - IP Network Address Translator.) (.27/11/2013 - 13:02:29.) -- C:\Windows\system32\Drivers\IpNat.sys [142848] [MD5.79B6F3DF7CDFD12159871FF71464F0CE] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.23/11/2013 - 08:08:19.) -- C:\Windows\system32\Drivers\MRxSmb.sys [403456] [MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) (.22/08/2013 - 12:37:02.) -- C:\Windows\system32\Drivers\netBT.sys [282624] [MD5.725EF69B2DBEB7B33280019A556201BC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.10/03/2014 - 11:35:58.) -- C:\Windows\system32\Drivers\ntfs.sys [2008408] [MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Pilote de port parallèle.) (.22/08/2013 - 12:40:02.) -- C:\Windows\system32\Drivers\Parport.sys [94208] [MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.22/08/2013 - 12:35:51.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [120832] [MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.14/11/2013 - 08:16:40.) -- C:\Windows\system32\Drivers\rdpdr.sys [195584] [MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) (.22/08/2013 - 14:25:35.) -- C:\Windows\system32\Drivers\tdx.sys [107520] [MD5.C85C075DE5B6D0FE116043054DE8EE02] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.31/01/2014 - 17:15:23.) -- C:\Windows\system32\Drivers\volsnap.sys [311640] ~ Generic Processes: Scanned in 00mn 01s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 1/1658 ~ Mes musiques (My Musics) : 383/2339 ~ Mes Videos (My Videos) : 1/198 ~ Mes Favoris (My Favorites) : 1/6 ~ Mes Documents (My Documents) : 1/77 ~ Mon Bureau (My Desktop) : 1/3 ~ Menu demarrer (Programs) : 1/23 ~ Hidden Files: Scanned in 00mn 10s ---\\ Processus lancés [MD5.2F03C763EE0DFB4DE56176737DEFB2E2] - (.Microsoft Corporation - Touch Keyboard and Handwriting Panel Helper.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe [21184] [PID.3032] [MD5.7DFCCC67990B6DE7F30F553A4E4612A4] - (...) -- C:\Program Files (x86)\RocketDock\RocketDock.exe [495616] [PID.5624] [MD5.0049D80BAB72557E9DD09C223FD71E58] - (...) -- C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1193176] [PID.3624] [MD5.79C28DDF889C26FDD6162F796FD49BC4] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392] [PID.3748] [MD5.4BFA1849DC7AA3CB99C160D9EB96C67B] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640] [PID.5188] [MD5.7B65026188834DDB4A3DF2B4B86B756D] - (.Pas de propriétaire - IM+.) -- C:\Program Files\WindowsApps\SHAPEGmbH.IM_1.8.0.0_neutral__mp7z04cf0c36r\IMPlusW8.exe [1013760] [PID.5348] [MD5.849D66021A0EF43A20137BA9D85ECADF] - (.Microsoft Corporation - Internet Low-Mic Utility Tool.) -- C:\Program Files (x86)\Internet Explorer\IELowutil.exe [222720] [PID.2864] [MD5.2EBBBFC120593C683796092F2DDA0EFC] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [841032] [PID.3216] [MD5.98265438577CBA3C0AE707AD92316CCE] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8219136] [PID.4724] ~ Processes Running: Scanned in 00mn 01s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Hosts file redirection (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Hosts File: Scanned in 00mn 00s ~ Nombre de lignes (Lines number): 21 ---\\ Autres liens utilisateurs (O4) O4 - GS\Program [Public]: Acer Games.lnk . (...) -- C:\Users\Sylvio\AppData\Local\Pokki\Engine\pokki.exe (.not file.) O4 - GS\Program [Public]: Desktop.lnk - Clé orpheline ~ Global Startup: 25 Legitimates Filtered in 00mn 01s ---\\ Applications lancées au démarrage du système (O4) O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp O4 - HKLM\..\Run: [ETDCtrl] C:\Program Files (x86)\Elantech\ETDCtrl.exe (.not file.) O4 - HKCU\..\Run: [RocketDock] . (...) -- C:\Program Files (x86)\RocketDock\RocketDock.exe O4 - HKCU\..\Run: [Spotify Web Helper] . (...) -- C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe =>.Advanced Micro Devices, Inc O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe O4 - HKLM\..\policies\Explorer\Run: [BtvStack] . (.Qualcomm Atheros Commnucations - Extension Core.) -- C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe O4 - HKUS\S-1-5-21-1661936240-4243406952-3761941970-1001\..\Run: [RocketDock] . (...) -- C:\Program Files (x86)\RocketDock\RocketDock.exe O4 - HKUS\S-1-5-21-1661936240-4243406952-3761941970-1001\..\Run: [Spotify Web Helper] . (...) -- C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe ~ Application: Scanned in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: Send by Bluetooth to [64Bits] - {7815BE26-237D-41A8-A98F-F7BD75F71086} -- Clé orpheline ~ IE Extra Buttons: Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{25C17B1E-F3DA-4EE0-AF20-FE97B2ECA8A4}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CCS\Services\Tcpip\..\{25C17B1E-F3DA-4EE0-AF20-FE97B2ECA8A4}: DhcpDomain = lan O17 - HKLM\System\CS1\Services\Tcpip\..\{25C17B1E-F3DA-4EE0-AF20-FE97B2ECA8A4}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CS1\Services\Tcpip\..\{25C17B1E-F3DA-4EE0-AF20-FE97B2ECA8A4}: DhcpDomain = lan O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: nuttkoqiez64 (nuttkoqiez64) . (...) - C:\Program Files\003\nuttkoqiez64.exe =>PUP.AdPeak O23 - Service: PriceMeterLiveUpdate Service (pricemeterliveUpdate) (pricemeterliveUpdate) . (.PriceMeter - PriceMeterLiveUpdate Update.) - C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe =>PUP.PriceMeter O23 - Service: SecureAssist (SecureAssist) . (.SecureAssist - Pas de description.) - c:\Program Files\SupraSavings\SecureAssist.exe =>PUP.SupraSavings O23 - Service: Update BrowseMark (Update BrowseMark) . (...) - C:\Program Files (x86)\BrowseMark\updateBrowseMark.exe (.not file.) =>PUP.BrowseMark ~ Services: 15 Legitimates Filtered in 00mn 23s ---\\ Tâches planifiées en automatique (O39) [MD5.00000000000000000000000000000000] [APT] [pricemeterdownloader] (...) -- C:\Users\♪ Blackstar ♪\AppData\Local\PriceMeter\pricemeterd.exe (.not file.) [0] =>PUP.PriceMeter [MD5.3D8B851E7EFCDC130E4B301BDDE10099] [APT] [PriceMeterLiveUpdate.exe /c] (.PriceMeter.) -- C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe [150504] =>PUP.PriceMeter [MD5.3D8B851E7EFCDC130E4B301BDDE10099] [APT] [PriceMeterLiveUpdate.exe /ua /installsource scheduler] (.PriceMeter.) -- C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe [150504] =>PUP.PriceMeter [MD5.00000000000000000000000000000000] [APT] [SaveSenseLive.exe /ua /installsource scheduler] (...) -- C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe (.not file.) [0] =>PUP.SaveSense [MD5.00000000000000000000000000000000] [APT] [{90347F6E-63D2-45D8-AF76-AB27AD8C7F3F}] (...) -- C:\Users\♪ Blackstar ♪\AppData\Local\PriceMeter\uninst.exe (.not file.) [0] =>PUP.PriceMeter O39 - APT: Apple Software Update - (.Apple Inc..) -- C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore.job [990] =>PUP.PriceMeter O39 - APT: Apple Software Update - (.Apple Inc..) -- C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA.job [994] =>PUP.PriceMeter O39 - APT: Apple Software Update - (.Apple Inc..) -- C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job [960] =>PUP.SaveSense ~ Scheduled Task: 23 Legitimates Filtered in 00mn 14s ---\\ Logiciels installés (O42) O42 - Logiciel: OEM Application Profile - (.Nom de votre société.) [HKLM][64Bits] -- {276FD4A2-030F-8A24-7DFE-9B1384131BCD} ~ Logic: 29 Legitimates Filtered in 00mn 02s ---\\ HKCU & HKLM Software Keys [HKCU\Software\SaveSense] =>PUP.SaveSense [HKCU\Software\SupraSavings] =>PUP.SupraSavings [HKLM\Software\LevelQualityWatcher] =>PUP.LevelQualityWatcher [HKLM\Software\Rr Savings] =>PUP.SupraSavings [HKLM\Software\Wow6432Node\SupraSavings] =>PUP.SupraSavings [HKLM\Software\Wow6432Node\anset] [HKLM\Software\suprasavings] =>PUP.SupraSavings ~ Key Software: 234 Legitimates Filtered in 00mn 02s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 05/02/2014 - 15:57:54 - [] ----D C:\Program Files (x86)\Ares O43 - CFD: 17/04/2014 - 02:17:19 - [0] ----D C:\Program Files (x86)\BrowseMark =>PUP.BrowseMark O43 - CFD: 31/03/2014 - 22:40:49 - [] ----D C:\Program Files (x86)\Shock Utility O43 - CFD: 10/01/2014 - 18:08:03 - [] ----D C:\ProgramData\APN O43 - CFD: 09/01/2014 - 00:33:20 - [] ----D C:\ProgramData\OEM_YAHOO O43 - CFD: 09/01/2014 - 13:16:11 - [] ----D C:\Users\Sylvio\AppData\Roaming\RealWorld O43 - CFD: 21/01/2014 - 21:11:35 - [] ----D C:\Users\Sylvio\AppData\Local\Ares O43 - CFD: 12/04/2014 - 12:18:42 - [] ----D C:\Users\Sylvio\AppData\Local\com ~ Program Folder: 142 Legitimates Filtered in 00mn 02s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.0DE593914F0268FB2B4DE7B9C7B33057] - 11/04/2014 - 20:46:15 ---A- . (.SecureAssist - WFP driver.) -- C:\Windows\System32\Drivers\SAWFP64.sys [41768] =>PUP.SupraSavings O44 - LFC:[MD5.812D9238EBEBDBB8FD2372C9464014FD] - 17/04/2014 - 22:26:19 ---A- . (...) -- C:\Windows\System32\SecureAssist.ini [5584] =>PUP.SupraSavings O44 - LFC:[MD5.769B5F06E053A1FC87476750642C1D67] - 17/04/2014 - 22:26:19 ---A- . (...) -- C:\Windows\System32\SecureAssistOff.ini [2536] =>PUP.SupraSavings ~ Files: 28 Legitimates Filtered in 00mn 20s ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLinkedConnections"=1 ~ MWPS: 20 Legitimates Filtered in 00mn 00s ---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56) O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 ~ MWPE Keys: 5 Legitimates Filtered in 00mn 00s ---\\ Liste des pilotes du système (SDL) (O58) O58 - SDL:[MD5.8D4B8BF93C65BDBC133B20706A3B5208] - 17/04/2014 - 20:38:46 ---A- . (...) -- C:\Windows\System32\Drivers\aswRvrt.sys [65776] O58 - SDL:[MD5.0606875650850B0697D662934529F6FC] - 17/04/2014 - 20:38:47 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys [208928] O58 - SDL:[MD5.C1ABB0F7E3BEA48A0417BDF6FF14AB21] - 13/08/2013 - 00:25:46 ---A- . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\Drivers\bcmfn2.sys [17624] O58 - SDL:[MD5.AC20C1DAC4E6E871F2930D57EF0906B3] - 18/07/2013 - 10:25:36 ---A- . (.ELAN Microelectronics Corp. - ETD Kernel Center.) -- C:\Windows\System32\Drivers\ETD.sys [381768] O58 - SDL:[MD5.0DE593914F0268FB2B4DE7B9C7B33057] - 18/03/2014 - 14:12:04 ---A- . (.SecureAssist - WFP driver.) -- C:\Windows\System32\Drivers\SAWFP64.sys [41768] =>PUP.SupraSavings O58 - SDL:[MD5.366DEA74BBA65B362BCCFC6FC2ADFD8B] - 22/08/2013 - 13:43:32 ---A- . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x64.) -- C:\Windows\System32\Drivers\stexstor.sys [31072] ~ Drivers: 20 Legitimates Filtered in 00mn 12s ---\\ Liste des outils de désinfection (LATC) (O63) O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn 00s ---\\ Associations Shell Spawning (O67) O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Not Key.) ~ FASS Keys: 11 Legitimates Filtered in 00mn 00s ---\\ Menu de démarrage Internet (SMI) (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {AA9A4890-4262-4441-8977-E2FFCBFB706C} - (Yahoo!) - http://fr.yhs4.search.yahoo.com ~ Keys: Scanned in 00mn 00s ---\\ Liste des exceptions du parefeu (FirewallRules) (O87) O87 - FAEL: "TCP Query User{028B5C26-14FD-4061-B75D-847A7596A141}C:\program files (x86)\ares\ares.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files (x86)\ares\ares.exe (.not file.) O87 - FAEL: "UDP Query User{4950BC47-EAB3-4DD1-8EC6-4BE105A0F443}C:\program files (x86)\ares\ares.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files (x86)\ares\ares.exe (.not file.) O87 - FAEL: "{705A63C5-71AE-4810-92D1-E4A3B381A374}" |In - Public - P17 - TRUE | .(...) -- C:\program files (x86)\ares\ares.exe (.not file.) O87 - FAEL: "{08898493-03BD-41F0-B364-CE752B941A00}" |In - Public - P6 - TRUE | .(...) -- C:\program files (x86)\ares\ares.exe (.not file.) ~ Firewall: 254 Legitimates Filtered in 00mn 04s ---\\ Enumère les codes produits des logiciels (PUC) (O90) O90 - PUC: "1BF4A48A307DBD84980E866B94D98210" . (..) -- C:\Windows\Installer\{A84A4FB1-D703-48DB-89E0-68B6499D2801}\ARPPRODUCTICON.exe O90 - PUC: "BD04C21DD7DC68D42958E5F22E63394E" . (.SupraSavings.) -- c:\WINDOWS\Installer\{D12C40DB-CD7D-4D86-9285-5E2FE23693E4}\icon64.ico =>PUP.SupraSavings ~ Update Products: 77 Legitimates Filtered in 00mn 00s ---\\ Enumère les données de la clé NameSpace (MNS) (O92) O92 - MNS: - {1CF1260C-4DD0-4ebb-811F-33C572699FDE} O92 - MNS: - {374DE290-123F-4565-9164-39C4925E467B} O92 - MNS: - {3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA} O92 - MNS: - {A0953C92-50DC-43bf-BE83-3742FED03C9C} O92 - MNS: - {A8CDFF1C-4878-43be-B5FD-F8091C1C60D0} O92 - MNS: - {B4BFCC3A-DB2C-424C-B029-7FE99A87C641} ~ MNS: 6 Legitimates Filtered in 00mn 00s ---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS) [MD5.9D0767859EE938C0C4FAC30693109843] [WIS][11/04/2014] (.SupraSavings - SupraSavings.) -- C:\Windows\Installer\730ddf6.msi [3162112] =>PUP.SupraSavings [MD5.9A5263D3C011F34BFA10C5458CF27197] [WIS][11/04/2014] (.SupraSavings - SupraSavings.) -- C:\Windows\Installer\73214b9.msi [4997120] =>PUP.SupraSavings ~ WIS: 78 Legitimates Filtered in 00mn 15s ---\\ Recherche de clés de registre Tracing (O100) HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BrowseMark_RASAPI32 =>PUP.BrowseMark HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BrowseMark_RASMANCS =>PUP.BrowseMark HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateBrowseMark_RASAPI32 =>PUP.BrowseMark HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateBrowseMark_RASMANCS =>PUP.BrowseMark HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilBrowseMark_RASAPI32 =>PUP.BrowseMark HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilBrowseMark_RASMANCS =>PUP.BrowseMark ~ BTK: 56 Legitimates Filtered in 00mn 00s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 12/10/2010 206072 | (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe SS - | Auto 17/04/2014 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 17/04/2014 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Auto 11/04/2014 150504 | (pricemeterliveUpdate) . (.PriceMeter.) - C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe =>PUP.PriceMeter SS - | Demand 11/04/2014 150504 | (pricemeterliveUpdatem) . (.PriceMeter.) - C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe =>PUP.PriceMeter SS - | Auto 10/07/1658 0 | (Update BrowseMark) . (...) - C:\Program Files (x86)\BrowseMark\updateBrowseMark.exe =>PUP.BrowseMark SS - | Demand 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation SR - | Auto 21/12/2013 65432 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe SR - | Auto 13/12/2013 239616 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe SR - | Auto 12/02/2014 43336 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe SR - | Auto 12/04/2013 228480 | (AtherosSvc) . (.Qualcomm Atheros Commnucations.) - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe SR - | Auto 17/04/2014 50344 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe SR - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe SR - | Auto 27/02/2013 2615368 | (CCDMonitorService) . (.Acer Incorporated.) - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe SR - | Demand 15/03/2013 662088 | (ePowerSvc) . (.Acer Incorporated.) - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe SR - | Auto 12/12/2013 9216 | (FreemakeVideoCapture) . (.Ellora Assets Corp..) - C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe SR - | Auto 14/01/2014 227904 | (GamesAppIntegrationService) . (.WildTangent.) - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe SR - | Demand 21/02/2014 641352 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe SR - | Auto 25/04/2013 431656 | (LMSvc) . (.Acer Incorporate.) - C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe SR - | Auto 14/07/2012 769432 | (NAUpdate) . (.Nero AG.) - c:\Program Files (x86)\Nero\Update\NASvc.exe SR - | Auto 11/04/2014 706560 | (nuttkoqiez64) . (...) - C:\Program Files\003\nuttkoqiez64.exe =>PUP.AdPeak SR - | Auto 12/03/2014 1558032 | (SecureAssist) . (.SecureAssist.) - c:\Program Files\SupraSavings\SecureAssist.exe =>PUP.SupraSavings SR - | Demand 10/07/1658 0 | (WdNisSvc) . (...) - C:\Program Files (x86)\Windows Defender\NisSrv.exe SR - | Demand 10/07/1658 0 | (WinDefend) . (...) - C:\Program Files (x86)\Windows Defender\MsMpEng.exe SR - | Demand 22/08/2013 37768 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Services: Scanned in 00mn 32s ---\\ Scan Additionnel (O88) Database Version : 13044 - (19/04/2014) Clés trouvées (Keys found) : 4 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 1 Fichiers trouvés (Files found) : 12 [HKLM\SYSTEM\CurrentControlSet\Services\nuttkoqiez64] =>PUP.AdPeak^ [HKLM\SYSTEM\CurrentControlSet\Services\pricemeterliveUpdate) (pricemeterliveUpdate] =>PUP.PriceMeter^ [HKLM\SYSTEM\CurrentControlSet\Services\SecureAssist] =>PUP.SupraSavings^ [HKLM\SYSTEM\CurrentControlSet\Services\Update BrowseMark] =>PUP.BrowseMark^ C:\Program Files (x86)\BrowseMark =>PUP.BrowseMark^ C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe =>PUP.PriceMeter^ C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore.job =>PUP.PriceMeter^ C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA.job =>PUP.PriceMeter^ C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job =>PUP.SaveSense^ [HKCU\Software\SaveSense] =>PUP.SaveSense^ [HKCU\Software\SupraSavings] =>PUP.SupraSavings^ [HKLM\Software\LevelQualityWatcher] =>PUP.LevelQualityWatcher^ [HKLM\Software\Rr Savings] =>PUP.SupraSavings^ [HKLM\Software\Wow6432Node\SupraSavings] =>PUP.SupraSavings^ [HKLM\Software\suprasavings] =>PUP.SupraSavings^ C:\Windows\Installer\730ddf6.msi =>PUP.SupraSavings^ C:\Windows\Installer\73214b9.msi =>PUP.SupraSavings^ ~ Additionnel Scan: 229523 Items scanned in 01mn 45s ---\\ Récapitulatif des détections trouvées sur votre station http://nicolascoolman.webs.com/apps/blog/show/42126939-pup-adpeak =>PUP.AdPeak http://nicolascoolman.webs.com/apps/blog/show/41981105-pup-pricemeter =>PUP.PriceMeter http://nicolascoolman.webs.com/apps/blog/show/42067481-pup-suprasavings =>PUP.SupraSavings http://nicolascoolman.webs.com/apps/blog/show/42099886-pup-browsemark =>PUP.BrowseMark http://nicolascoolman.webs.com/apps/blog/show/36853930-pup-savesense =>PUP.SaveSense ~ MSI: 5 link(s) detected in 00mn 00s ~ 934 Legitimates filtered by white list End of the scan (430 lines in 05mn 02s)(0)