~ Rapport de ZHPDiag v2014.2.14.14 - Nicolas Coolman (14/02/2014) ~ Lancé par MHR (15/02/2014 13:51:14) ~ Adresse du Site Web http://nicolascoolman.webs.com ~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/ ~ Traduit par Nicolas Coolman ~ Etat de la version : ~ Liste blanche : Activée par le programme ~ Elévation des Privilèges : OK ~ User Account Control (UAC): Activate by user ---\\ Navigateurs Internet MSIE: Internet Explorer v11.0.9600.16518 (Defaut) MFIE: Mozilla Firefox 26.0 GCIE: Google Chrome v32.0.1700.107 ---\\ Informations sur les produits Windows ~ Langage: Français Windows 7 Ultimate, 64-bit Service Pack 1 (Build 7601) Windows Server License Manager Script : OK ~ Windows(R) 7, OEM_COA_NSLP channel Windows ID Activation : OK ~ Windows Partial Key : T2CX9 Windows License : OK ~ Windows Remaining Initializations Number : 4 Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ Logiciels de protection du système avast! Free Antivirus v9.0.2013 Malwarebytes Anti-Malware version 1.75.0.1300 Windows Defender W7 ---\\ Logiciels d'optimisation du système ---\\ Logiciels de partage PeerToPeer ---\\ Surveillance de Logiciels Adobe Flash Player 11 Plugin Adobe Reader X Java 7 Update 51 ---\\ Informations sur le système ~ Processor: Intel64 Family 6 Model 23 Stepping 10, GenuineIntel ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 3318 MB (52% free) System Restore: Activé (Enable) System drive C: has 23 GB (29%) free of 78 GB ---\\ Mode de connexion au système ~ Computer Name: PC-MHR ~ User Name: MHR ~ All Users Names: MHR, Administrateur, ~ Unselected Option: None Logged in as Administrator ---\\ Variables d'environnement ~ System Unit : C:\ ~ %AppZHP% : C:\Users\MHR\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\MHR\AppData\Roaming\ ~ %Desktop% : C:\Users\MHR\Desktop\ ~ %Favorites% : C:\Users\MHR\Favorites\ ~ %LocalAppData% : C:\Users\MHR\AppData\Local\ ~ %StartMenu% : C:\Users\MHR\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumération des unités disques C: Hard drive, Flash drive, Thumb drive (Free 23 Go of 78 Go) D: Hard drive, Flash drive, Thumb drive (Free 195 Go of 220 Go) E: CD-ROM drive (Not Inserted) K: Floppy drive, Flash card reader, USB Key (Not Inserted) ---\\ Etat du Centre de Sécurité Windows [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified ~ Security Center: 46 Legitimates Filtered in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808] [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024] [MD5.263B6E451526A90FF8B1CEC759F22956] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.06/02/2014 - 10:24:52.) -- C:\Windows\System32\wininet.dll [2334208] [MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.20/11/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656] [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448] [MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/09/2013 - 02:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152] [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128] [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160] [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456] [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400] [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368] [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472] [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224] [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208] [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632] [MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680] [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280] [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536] [MD5.1B6163C503398B23FF8B939C67747683] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.20/11/2010 - 12:06:41.) -- C:\Windows\system32\Drivers\rdpdr.sys [165888] [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184] [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296] [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808] ~ Generic Processes: Scanned in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 1/5128 ~ Mes musiques (My Musics) : 7/306 ~ Mes Videos (My Videos) : 1/314 ~ Mes Favoris (My Favorites) : 1/120 ~ Mes Documents (My Documents) : 1/1474 ~ Mon Bureau (My Desktop) : 1/4577 ~ Menu demarrer (Programs) : 1/23 ~ Hidden Files: Scanned in 00mn 07s ---\\ Processus lancés [MD5.16C427D4D0D841414E3B45C5C1474E22] - (.BrowserSafeguard - BrowserSafeguard.) -- C:\Users\MHR\AppData\Local\BrowserSafeguard\BrowserSafeguard.exe [417792] [PID.1764] =>PUP.BrowserSafeguard [MD5.C5B5552E5C1A0079C1F7313E7CC7707E] - (.Google - Google Calendar Sync.) -- C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe [542264] [PID.1672] [MD5.4D5D968FE6AE6BF94A807F73F7FF6B3D] - (.Brother Industries, Ltd. - Brother Status Monitor Application.) -- C:\Program Files (x86)\BROTHER\Brmfcmon\BrMfcWnd.exe [1159168] [PID.2468] [MD5.12FD7C1EADDDA10A67B1D6F905B3CC1E] - (.Sony Corporation - Content Transfer Walkman Detector.) -- C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe [583016] [PID.2484] [MD5.36E5CA5DCE72A831A3F7C7ED8AEA83AE] - (.Brother Industries, Ltd. - Control Center 3 Main Program.) -- C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe [872448] [PID.2968] [MD5.A7810B302294793DE88542AAE177D1B1] - (.ArcSoft Inc. - ArcSoft Connect Daemon.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424] [PID.2396] [MD5.F400694D7D2785F60133C20F7F2F4F7A] - (.ArcSoft Inc. - ArcSoft Connect Notifier.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac [309824] [PID.2620] [MD5.A78AAB0D2D70EF7DD56B7328AC502059] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096] [PID.3168] [MD5.5B6E8E09BE6401A7E022F52FDFCB2FF8] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336] [PID.3184] [MD5.490F9A7948EF661DF32A9F0DC8534284] - (.Brother Industries, Ltd. - Brother Status Monitor (Local).) -- C:\Program Files (x86)\BROTHER\Brmfcmon\BrMfcmon.exe [221184] [PID.2324] [MD5.4263F6C131E513CEA1AE82B5B81A4E1A] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\IEXPLORE.exe [808152] [PID.3088] [MD5.4F3B668714E0CA3592867E2E7317F459] - (.Microsoft Corporation - Microsoft Office Word.) -- C:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.exe [12319896] [PID.2960] [MD5.5CCF60E8557F42D6494ACE11144E16C3] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8337920] [PID.1496] [MD5.CC42F104172B4A62793083D380867317] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344] [PID.1136] [MD5.ADC420616C501B45D26C0FD3EF1E54E4] - (.ArcSoft Inc. - ArcSoft Connect Service.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152] [PID.1600] [MD5.B362181ED3771DC03B4141927C80F801] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65432] [PID.1676] [MD5.11F714F85530A2BD134074DC30E99FCA] - (.Microsoft Corporation - Machine Debug Manager.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.exe [322120] [PID.1788] [MD5.7AEA4DF1CA68FD45DD4BBE1F0243CE7F] - (...) -- C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe [71096] [PID.2276] ~ Processes Running: Scanned in 00mn 00s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Users\MHR\AppData\Roaming\Mozilla\Firefox\Profiles\qtchhwvo.default\prefs.js C:\Users\MHR\AppData\Roaming\Mozilla\Firefox\Profiles\rkwfv1im.default-1392145655875\prefs.js ~ Firefox Browser: 15 Legitimates Filtered in 00mn 00s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com =>PUP.Awesomehp R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com =>PUP.Awesomehp R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com =>PUP.Awesomehp R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com =>PUP.Awesomehp R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com =>PUP.Awesomehp ~ IE Browser: 23 Legitimates Filtered in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <-loopback> =>Hijacker.Proxy R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:49160;https=127.0.0.1:49160 =>Hijacker.Proxy R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Hosts file redirection (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Hosts File: Scanned in 00mn 03s ~ Nombre de lignes (Lines number): 12658 ---\\ Internet Explorer Toolbars (O3) O3 - Toolbar: avast! Online Security - [HKLM]{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll =>Toolbar.Google ~ Toolbar: Scanned in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\Desktop [Public]: Google Calendar.lnk - Clé orpheline O4 - GS\Desktop [Public]: Malwarebytes Anti-Malware.lnk . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe O4 - GS\Desktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O4 - GS\Desktop [Public]: Skype.lnk . (...) -- C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe O4 - GS\Program [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.awesomehp.com =>PUP.Awesomehp O4 - GS\QuickLaunch [MHR]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.awesomehp.com =>PUP.Awesomehp O4 - GS\TaskBar [MHR]: ControlCenter3.lnk . (.Brother Industries, Ltd. - ControlCenter Program.) -- C:\Program Files (x86)\BROTHER\ControlCenter3\BrCtrCen.exe O4 - GS\TaskBar [MHR]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O4 - GS\Program [MHR]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe http://www.awesomehp.com =>PUP.Awesomehp O4 - GS\SystemTools [MHR]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe http://www.awesomehp.com =>PUP.Awesomehp O4 - GS\Desktop [MHR]: BASE 2014 - Raccourci.lnk . (...) -- D:\_System\Users\mhr\Documents\OVNI\Traitement base de données\BASE 2014 O4 - GS\Desktop [MHR]: Google Drive.lnk . (...) -- C:\Users\MHR\Google Drive O4 - GS\Desktop [MHR]: L'Assistant DartyBox.lnk . (.Celliance - Assistant DartyBox.) -- C:\Program Files (x86)\DartyBox_v3\Bewan\AssistantDB\AssistantDB_Bewan.exe O4 - GS\Desktop [MHR]: PC Chrono.lnk . (.highspheres.com - PC Chrono.) -- C:\Program Files (x86)\PC Chrono\PCChrono.exe ~ Global Startup: 70 Legitimates Filtered in 00mn 01s ---\\ Applications lancées au démarrage du sytème (O4) O4 - GS\Startup [Public]: Google Calendar Sync.lnk . (.Google - Google Calendar Sync.) -- C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\MHR\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc O4 - HKCU\..\Run: [BrowserSafeguard] . (.BrowserSafeguard - BrowserSafeguard.) -- C:\Users\MHR\AppData\Local\BrowserSafeguard\BrowserSafeguard.exe =>PUP.BrowserSafeguard O4 - HKCU\..\Run: [BrowserSafeguard Update Task] . (...) -- C:\Users\MHR\AppData\Local\BrowserSafeguard\uninstall.BrowserSafeguard.exe =>PUP.BrowserSafeguard O4 - HKLM\..\Wow6432Node\Run: [BrMfcWnd] . (.Brother Industries, Ltd. - Brother Status Monitor Application.) -- C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe O4 - HKLM\..\Wow6432Node\Run: [ControlCenter3] . (.Brother Industries, Ltd. - ControlCenter Program.) -- C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe O4 - HKLM\..\Wow6432Node\Run: [NPSStartup] Clé orpheline O4 - HKLM\..\Wow6432Node\Run: [ContentTransferWMDetector.exe] . (.Sony Corporation - Content Transfer Walkman Detector.) -- C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe O4 - HKLM\..\Wow6432Node\Run: [ArcSoft Connection Service] . (.ArcSoft Inc. - ArcSoft Connect Daemon.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated O4 - HKLM\..\Wow6432Node\Run: [Wondershare Helper Compact.exe] . (.Wondershare - Wondershare Studio.) -- C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle Corporation O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-2060399966-628706912-3090598337-1000\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\MHR\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc O4 - HKUS\S-1-5-21-2060399966-628706912-3090598337-1000\..\Run: [BrowserSafeguard] . (.BrowserSafeguard - BrowserSafeguard.) -- C:\Users\MHR\AppData\Local\BrowserSafeguard\BrowserSafeguard.exe =>PUP.BrowserSafeguard O4 - HKUS\S-1-5-21-2060399966-628706912-3090598337-1000\..\Run: [BrowserSafeguard Update Task] . (...) -- C:\Users\MHR\AppData\Local\BrowserSafeguard\uninstall.BrowserSafeguard.exe =>PUP.BrowserSafeguard ~ Application: Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{C47FD8F6-DA4E-4387-B410-BD7DCA0C9B72}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CCS\Services\Tcpip\..\{C47FD8F6-DA4E-4387-B410-BD7DCA0C9B72}: DhcpDomain = darty O17 - HKLM\System\CS1\Services\Tcpip\..\{C47FD8F6-DA4E-4387-B410-BD7DCA0C9B72}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CS1\Services\Tcpip\..\{C47FD8F6-DA4E-4387-B410-BD7DCA0C9B72}: DhcpDomain = darty O17 - HKLM\System\CS2\Services\Tcpip\..\{C47FD8F6-DA4E-4387-B410-BD7DCA0C9B72}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CS2\Services\Tcpip\..\{C47FD8F6-DA4E-4387-B410-BD7DCA0C9B72}: DhcpDomain = darty O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: wlmailhtml [64Bits] - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (...) -- O18 - Filter: text/xml [64Bits] - {807553E5-5146-11D5-A672-00B0D022E945} . (...) -- ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: GoToAssist . (...) -- C:\Program Files (x86)\Citrix\GoToAssist\508\G2AWinLogon_x64.dll (.not file.) O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll ~ Winlogon: Scanned in 00mn 00s ---\\ Tâches planifiées en automatique (O39) [MD5.00000000000000000000000000000000] [APT] [4412] (...) -- C:\Users\MHR\AppData\Local\Temp\launchie.vbs \\B (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{071D2806-769D-4C39-BECA-2E0535CB97DF}] (...) -- D:\_System\Users\mhr\Downloads\Firefox Setup 3.5.2.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{B7F076C4-1FB2-434C-8190-5F1F58397170}] (...) -- C:\Program Files (x86)\Desk 365\eUninstall.exe (.not file.) [0] =>Hijacker.22Find [MD5.00000000000000000000000000000000] [APT] [{CF201C5F-0439-4D2C-8CFA-8377461CA6C0}] (...) -- D:\_System\Users\mhr\Downloads\avira-antivir-personal-free-antivirus_avira_antivir_personal_free_10.0.0.652_anglais_10821.exe (.not file.) [0] ~ Scheduled Task: 26 Legitimates Filtered in 00mn 02s ---\\ Logiciels installés (O42) O42 - Logiciel: BrowserSafeguard - (.Browsersafeguard.) [HKCU][64Bits] -- Browsersafeguard =>PUP.BrowserSafeguard O42 - Logiciel: Meteo Fusion 1.5.9.11 - (.Eggiz.) [HKLM][64Bits] -- Meteo Fusion _is1 O42 - Logiciel: Playviz 1.7.7 - (.Previznet.) [HKCU][64Bits] -- Playviz 1.7.7 ~ Logic: 25 Legitimates Filtered in 00mn 00s ---\\ HKCU & HKLM Software Keys [HKCU\Software\BrowsersafeguardInstalled] =>PUP.BrowserSafeguard [HKCU\Software\WSVCUPlugin] [HKCU\Software\로컬 응용 프로그램 마법사에서 생성된 응용 프로그램] [HKLM\Software\Wow6432Node\Wpm] =>PUP.WpManager [HKLM\Software\Wow6432Node\supTab] =>PUP.SupTab [HKLM\Software\Wow6432Node\supWPM] =>PUP.WpManager ~ Key Software: 257 Legitimates Filtered in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 12/02/2014 - 22:02:18 - [0] ----D C:\Program Files (x86)\SupTab =>PUP.SupTab O43 - CFD: 12/02/2014 - 20:07:12 - [0] ----D C:\ProgramData\WPM =>PUP.WpManager O43 - CFD: 12/02/2014 - 18:21:41 - [0,001] ----D C:\Users\MHR\AppData\Roaming\Focus Mp3 Recorder O43 - CFD: 08/01/2014 - 21:31:32 - [0] ----D C:\Users\MHR\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A} O43 - CFD: 12/02/2014 - 18:21:15 - [4,823] ----D C:\Users\MHR\AppData\Local\BrowserSafeguard =>PUP.BrowserSafeguard ~ 437 Dossiers CLSID vides (CLSID Empty Folders) ~ Program Folder: 631 Legitimates Filtered in 00mn 11s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.04B13C3A597CD763F1BDB26BC846E7D8] - 11/02/2014 - 19:37:11 ---A- . (...) -- C:\rapport.txt [2035] O44 - LFC:[MD5.0DAC5883BBA4AB8EF9D777D7D1905AD2] - 14/02/2014 - 19:49:57 ---A- . (...) -- C:\Windows\ntbtlog.txt [143616] ~ Files: 58 Legitimates Filtered in 00mn 02s ---\\ Derniers fichiers créés dans Windows Prefetcher (O45) O45 - LFCP:[MD5.FA377137E9145720F8B463A4B386D7B2] - 14/02/2014 - 17:47:51 ---A- - C:\Windows\Prefetch\NDP45-KB2901126-X64.EXE-FDCC32D5.pf O45 - LFCP:[MD5.055791F85E73E80401EB974B119EE7D6] - 14/02/2014 - 17:49:51 ---A- - C:\Windows\Prefetch\NDP45-KB2898869-X64.EXE-BFC1D916.pf O45 - LFCP:[MD5.EB199D92C8D2BB1CAED85774C6603EA3] - 14/02/2014 - 17:57:13 ---A- - C:\Windows\Prefetch\BROWSERSAFEGUARD.EXE-74E75212.pf =>PUP.BrowserSafeguard O45 - LFCP:[MD5.F70D494DD19F265DAB6B8FA2D1B16E2A] - 14/02/2014 - 17:57:15 ---A- - C:\Windows\Prefetch\GOOGLECALENDARSYNC.EXE-EF88EEA6.pf O45 - LFCP:[MD5.183C2FE65D58B6562AF60E6D4BBAF9B7] - 14/02/2014 - 17:57:15 ---A- - C:\Windows\Prefetch\UNINSTALL.BROWSERSAFEGUARD.EX-DEE1F5AA.pf =>PUP.BrowserSafeguard O45 - LFCP:[MD5.74F33477597FB92CA9A61F0BAF25C282] - 14/02/2014 - 19:52:37 ---A- - C:\Windows\Prefetch\CERTUTIL.EXE-828074B3.pf O45 - LFCP:[MD5.2145C7D6D7B925587A691F74180D8C9C] - 14/02/2014 - 19:52:41 ---A- - C:\Windows\Prefetch\BRMFCWND.EXE-48F6D0C6.pf O45 - LFCP:[MD5.D5AFBECCAA2775EA82AA424DB65CDB7C] - 14/02/2014 - 19:52:44 ---A- - C:\Windows\Prefetch\BRCCMCTL.EXE-817EEE0E.pf O45 - LFCP:[MD5.D164F79120C30BC34953AEA8771087F6] - 14/02/2014 - 19:52:44 ---A- - C:\Windows\Prefetch\BRCTRCEN.EXE-35ABB3DB.pf O45 - LFCP:[MD5.54C351E44A2F67595B1AB1AAC072E86B] - 14/02/2014 - 19:52:45 ---A- - C:\Windows\Prefetch\CONTENTTRANSFERWMDETECTOR.EXE-1C0FA108.pf O45 - LFCP:[MD5.90493D44A125CBD069FF421EC2D46DBA] - 15/02/2014 - 12:09:37 ---A- - C:\Windows\Prefetch\BRMFCMON.EXE-65C6F323.pf ~ Prefetcher: 139 Legitimates Filtered in 00mn 00s ---\\ Contrôle du Safe Boot (CSB) (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\hitmanpro36.sys . (...) -- C:\Windows\System32\Drivers\hitmanpro36.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\hitmanpro36.sys . (...) -- C:\Windows\System32\Drivers\hitmanpro36.sys (.not file.) ~ CSB: 15 Legitimates Filtered in 00mn 00s ---\\ Enumération des clés de registre StartupReg (SMSR) (O53) O53 - SMSR:HKLM\...\startupreg\Desk 365 [Key] . (...) -- C:\Program Files (x86)\Desk 365\desk365.exe (.not file.) =>Hijacker.22Find O53 - SMSR:HKLM\...\startupreg\PCFixSpeed [Key] . (...) -- C:\Program Files (x86)\PCFixSpeed\PCFixTray.exe (.not file.) =>PUP.PCFixSpeed ~ SMSR Keys: 2 Legitimates Filtered in 00mn 00s ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 16 Legitimates Filtered in 00mn 00s ---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56) O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 ~ MWPE Keys: 4 Legitimates Filtered in 00mn 00s ---\\ Liste des pilotes du système (SDL) (O58) O58 - SDL:[MD5.C04F7B373881009D7994D9BF55D24AB4] - 12/02/2014 - 18:34:35 ---A- . (...) -- C:\Windows\System32\Drivers\aswRvrt.sys [65776] O58 - SDL:[MD5.90399625F341AB76BA4B85A5E860EB1F] - 12/02/2014 - 18:34:35 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys [207904] O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496] O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232] O58 - SDL:[MD5.E57B778208C783D8DEBAB320C16A1B82] - 12/11/2009 - 13:48:56 ---A- . (...) -- C:\Windows\System32\Drivers\StarOpen.sys [5504] O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656] O58 - SDL:[MD5.48D9D00C2E0E72C3D4F52772C80355F6] - 14/06/2010 - 01:32:54 ---A- . (.Teruten Inc - File System Mini Filter Drvier.) -- C:\Windows\System32\Drivers\TFsExDisk.sys [16448] O58 - SDL:[MD5.F92254B0BCFCD10CAAC7BCCC7CB7F467] - 12/11/2009 - 13:48:56 ---A- . (...) -- C:\Windows\SysWOW64\drivers\StarOpen.sys [7168] O58 - SDL:[MD5.48D9D00C2E0E72C3D4F52772C80355F6] - 14/06/2010 - 01:32:54 ---A- . (.Teruten Inc - File System Mini Filter Drvier.) -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys [16448] ~ Drivers: 16 Legitimates Filtered in 00mn 03s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC: 13/02/2014 - 13:52:46 ---A- . (...) -- C:\Users\MHR\AppData\Roaming\Microsoft\OIS\Toolbars.dat [780] O61 - LFC: 14/02/2014 - 13:52:13 ---A- . (...) -- C:\Users\MHR\AppData\Local\Google\Google Calendar Sync\data_files\4969C1E099932509FA70A395FF3C0AB4.FEED [694] O61 - LFC: 14/02/2014 - 13:52:13 ---A- . (...) -- C:\Users\MHR\AppData\Local\Google\Google Calendar Sync\data_files\65442EB2E97E955C3CFB33EF4CCEF786 [24537] O61 - LFC: 15/02/2014 - 13:52:48 ---A- . (...) -- C:\Users\MHR\AppData\Roaming\ZHP\Log.txt [18253] =>.Nicolas Coolman O61 - LFC: 15/02/2014 - 13:52:48 ---A- . (...) -- C:\Users\MHR\AppData\Roaming\ZHP\TestsZHPDiag.txt [2828] =>.Nicolas Coolman ~ 17 Fichiers temporaires (Temporary files) ~ Files: 82 Legitimates Filtered in 00mn 37s ---\\ Fichiers Alternate Data Stream (ADS) (O62) O62 - ADS:Alternate Data Stream File - C:\Windows\System32\msvcr71.dll:Zone.Identifier ~ ADS: Scanned in 00mn 00s ---\\ Liste des outils de désinfection (LATC) (O63) O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn 00s ---\\ Associations Shell Spawning (O67) O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Not Key.) ~ FASS Keys: 11 Legitimates Filtered in 00mn 00s ---\\ Menu de démarrage Internet (SMI) (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- firefox.exe (.not file.) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {3B88EEF8-3507-4CC6-94E5-271AF46037AB} [DefaultScope] - (Google) - http://www.google.com ~ Keys: Scanned in 00mn 00s ---\\ Recherche particulière à la racine du système (SPRF) (O84) [MD5.16E53BFC96CE14021C0E07EB1C198478] [SPRF][25/05/2010] (...) -- C:\Users\MHR\AppData\Roaming\inst.exe [99384] [MD5.76A26BD58BFD0B4B696B90DC92C8BF3B] [SPRF][18/11/2010] (.Total Immersion - D'Fusion @Home Web Plug-In Installer.) -- C:\Windows\Downloaded Program Files\DFusionHomeWebPlugIn.InstallerFull.exe [3642368] ~ Files: 3 Legitimates Filtered in 00mn 00s ---\\ Liste des exceptions du parefeu (FirewallRules) (O87) O87 - FAEL: "TCP Query User{A3A072D4-2321-4D23-98D6-56E8B28239E3}C:\program files (x86)\msn backup\msnbackup.exe" | In - Private - P6 - TRUE | .(.Leonardo Bai - MSN BackUp.) -- C:\program files (x86)\msn backup\msnbackup.exe O87 - FAEL: "UDP Query User{9F8DCEC1-0030-4F74-9DA6-653EFAB8E682}C:\program files (x86)\msn backup\msnbackup.exe" | In - Private - P17 - TRUE | .(.Leonardo Bai - MSN BackUp.) -- C:\program files (x86)\msn backup\msnbackup.exe O87 - FAEL: "TCP Query User{902F194E-0A95-4527-A38C-34FBD8D5693A}C:\program files (x86)\msn backup\msnbackup.exe" | In - Public - P6 - TRUE | .(.Leonardo Bai - MSN BackUp.) -- C:\program files (x86)\msn backup\msnbackup.exe O87 - FAEL: "UDP Query User{3043AA43-900B-4BBB-B995-4898C90CBE53}C:\program files (x86)\msn backup\msnbackup.exe" | In - Public - P17 - TRUE | .(.Leonardo Bai - MSN BackUp.) -- C:\program files (x86)\msn backup\msnbackup.exe O87 - FAEL: "{9770B01A-FFFB-4005-B1A3-39A4DFF83AC1}" |In - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Freeplayer\fbx-playlist.exe (.not file.) O87 - FAEL: "{41695AA2-5BBC-454F-BE67-B8203F77F7D3}" |In - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Freeplayer\fbx-playlist.exe (.not file.) O87 - FAEL: "{8E2127CC-B425-450F-8188-3712D51E7A24}" |In - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Freeplayer\fbx-playlist.exe (.not file.) O87 - FAEL: "{65694145-2769-4032-BDC1-3640A87220AD}" |In - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Freeplayer\fbx-playlist.exe (.not file.) O87 - FAEL: "{662F93C8-B8B5-4A8A-9601-D067D02DFBCF}" |In - Public - P6 - TRUE | .(...) -- C:\Users\MHR\AppData\Local\Temp\Update_1bee.exe (.not file.) O87 - FAEL: "{6A0602B7-9BC4-42F4-81D7-87612B322205}" |In - Public - P17 - TRUE | .(...) -- C:\Users\MHR\AppData\Local\Temp\Update_1bee.exe (.not file.) O87 - FAEL: "{77BE0DAE-ADC5-4583-8759-7FD38672D36B}" |In - Public - P6 - TRUE | .(...) -- C:\ProgramData\eSafe\eGdpSvc.exe (.not file.) =>PUP.eSafeSecurity ~ Firewall: 239 Legitimates Filtered in 00mn 00s ---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS) [MD5.47FE6777BC5F33EC9FB4A6741E96E665] [WIS][07/12/2013] (.Google, Inc. - Google Drive.) -- C:\Windows\Installer\17c5a4c.msi [31694848] ~ WIS: 66 Legitimates Filtered in 00mn 04s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 14/07/2009 27136 | C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (getPlusHelper) . (.NOS Microsystems Ltd..) - C:\Windows\System32\svchost.exe SS - | Demand 12/06/2012 16680 | (GoToAssist) . (.Citrix Online, a division of Citrix Systems.) - C:\Program Files (x86)\Citrix\GoToAssist\508\g2aservice.exe SS - | Auto 21/01/2010 135664 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 21/01/2010 135664 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 13/02/2014 194032 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe SS - | Demand 21/12/2013 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe SS - | Auto 21/06/2013 162408 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe SR - | Auto 18/03/2010 113152 | (ACDaemon) . (.ArcSoft Inc..) - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe SR - | Auto 18/12/2013 65432 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe SR - | Auto 12/02/2014 50344 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe SR - | Auto 04/03/2010 71096 | (NMSAccess) . (...) - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Demand 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Services: Scanned in 00mn 06s ---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80) Run by MHR at 15/02/2014 13:53:06 ~ OS 64 not supported by MBR tool ~ MBR: 0 Legitimates Filtered in 00mn 00s ---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by MHR at 15/02/2014 13:53:08 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 02s ---\\ Scan Additionnel (O88) Database Version : 13031 - (14/02/2014) Clés trouvées (Keys found) : 9 Valeurs trouvées (Values found) : 2 Dossiers trouvés (Folders found) : 3 Fichiers trouvés (Files found) : 9 [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Browsersafeguard] =>PUP.BrowserSafeguard^ [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\Desk 365] =>Hijacker.22Find^ [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\PCFixSpeed] =>PUP.PCFixSpeed^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9] =>PUP.Dealio [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24] =>PUP.Dealio [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607] =>PUP.Dealio [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F] =>PUP.Dealio [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21] =>PUP.Dealio [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF] =>PUP.Dealio [HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google^ [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:BrowserSafeguard =>PUP.BrowserSafeguard^ C:\Program Files (x86)\SupTab =>PUP.SupTab^ C:\ProgramData\WPM =>PUP.WpManager^ C:\Users\MHR\AppData\Local\BrowserSafeguard =>PUP.BrowserSafeguard^ C:\Users\MHR\AppData\Local\BrowserSafeguard\BrowserSafeguard.exe =>PUP.BrowserSafeguard^ [HKCU\Software\BrowsersafeguardInstalled] =>PUP.BrowserSafeguard^ [HKLM\Software\Wow6432Node\Wpm] =>PUP.WpManager^ [HKLM\Software\Wow6432Node\supTab] =>PUP.SupTab^ [HKLM\Software\Wow6432Node\supWPM] =>PUP.WpManager^ C:\Users\MHR\AppData\Local\Temp\uninst1.exe =>PUP.Babylon C:\Users\MHR\AppData\Local\Temp\GoogleToolbarInstaller1.log =>PUP.Babylon C:\Users\MHR\AppData\Local\Temp\GoogleToolbarInstaller2.log =>PUP.Babylon ~ Additionnel Scan: 311954 Items scanned in 00mn 25s ---\\ Récapitulatif des détections trouvées sur votre station ~ http://nicolascoolman.webs.com/apps/blog/show/32799788-pup-browsersafeguard =>PUP.BrowserSafeguard ~ http://nicolascoolman.webs.com/apps/blog/show/41011964-pup-awesomehp =>PUP.Awesomehp ~ http://nicolascoolman.webs.com/apps/blog/show/27232411-hijacker-proxy =>Hijacker.Proxy ~ http://nicolascoolman.webs.com/apps/blog/show/26630379-hijacker-22find =>Hijacker.22Find ~ http://nicolascoolman.webs.com/apps/blog/show/38737316-pup-wpmanager =>PUP.WpManager ~ http://nicolascoolman.webs.com/apps/blog/show/41133513-pup-suptab =>PUP.SupTab ~ http://nicolascoolman.webs.com/apps/blog/show/33519836-pup-pcfixspeed =>PUP.PCFixSpeed ~ http://nicolascoolman.webs.com/apps/blog/show/27588628-pup-esafesecurity =>PUP.eSafeSecurity ~ http://nicolascoolman.webs.com/apps/blog/show/27443462-pup-dealio =>PUP.Dealio ~ http://nicolascoolman.webs.com/apps/blog/show/26627369-toolbar-babylon =>PUP.Babylon ~ MSI: 10 link(s) detected in 00mn 25s ~ 1807 Legitimates filtered by white list End of the scan (534 lines in 02mn 19s)(0)