cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Report of ZHPDiag v2014.12.27.179 - Nicolas Coolman (27-12-2014)
~ Launched by admin (29-12-2014 12:48:28)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Web forum address : http://forum.nicolascoolman.fr
~ Translated by
~ Version State : New version available
~ White List : Activate by program
~ Elevation of privilege : OK
~ User Account Control : Deactivate by user


---\\ Internet browsers
MSIE: Internet Explorer v11.0.9600.16663
MFIE: Mozilla Firefox 34.0.5 (Defaut)
GCIE: Google Chrome

---\\ Windows product information
~ Langage: Anglais
Windows 8.1 Pro with Media Center, 32-bit (Build 9600)
Windows Server License Manager Script : OK
~ Windows(R) Operating System, RETAIL channel
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ System protection software
Windows Defender W8 (Activate)

---\\ System optimization software
CCleaner v5.01

---\\ Sharing software PeerToPeer

---\\ Surveillance software
Adobe Flash Player 16 NPAPI

---\\ Information on the system
~ Processor: x86 Family 15 Model 4 Stepping 3, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 1015.4 MB (42% free)
System Restore: Activé (Enable)
System drive C: has 25 GB (64%) free of 39 GB

---\\ Connection to the system mode
~ Computer Name: REDWAN
~ User Name: admin
~ All Users Names: Guest, Administrator, admin,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Environment variables
~ System Unit : C:\
~ %AppZHP% : C:\Users\admin\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\admin\AppData\Roaming\
~ %Desktop% : C:\Users\admin\Desktop\
~ %Favorites% : C:\Users\admin\Favorites\
~ %LocalAppData% : C:\Users\admin\AppData\Local\
~ %StartMenu% : C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumeration of the disk units
A: Floppy drive, Flash card reader, USB Key (Not Inserted)
C: Hard drive, Flash drive, Thumb drive (Free 25 Go of 39 Go)
D: Hard drive, Flash drive, Thumb drive (Free 12 Go of 35 Go)
E: CD-ROM drive (Not Inserted)
H: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)



---\\ State of the Windows Security Center
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
~ Security Center: 46 Legitimates Filtered in 00mn 00s



---\\ Search Generic System Files
[MD5.2CA8E3C9335C3C8BAEB335345E48364D] - (.Microsoft Corporation - مستكشف Windows.) (.22-08-2013 - 5:25:34.) -- C:\Windows\Explorer.exe [2063408]
[MD5.02BC073156B3097E94D63C4D609020DD] - (.Microsoft Corporation - ‎‎تطبيق بدء تشغيل Windows.) (.22-08-2013 - 2:49:55.) -- C:\Windows\System32\Wininit.exe [112640]
[MD5.AAFEAB4FC9D70253F8C7E353E879E8A2] - (.Microsoft Corporation - ملحقات الإنترنت لـ Win32.) (.01-03-2014 - 2:32:16.) -- C:\Windows\System32\wininet.dll [1820160]
[MD5.94385F95EF948FB274A70DE3EDE5696D] - (.Microsoft Corporation - تطبيق تسجيل دخول Windows.) (.22-08-2013 - 2:48:19.) -- C:\Windows\System32\Winlogon.exe [458752]
[MD5.BFB9E1202225113991F981D29BFB9029] - (.Microsoft Corporation - مكتبة تراخيص البرامج.) (.21-12-2013 - 8:08:12.) -- C:\Windows\System32\sppcomapi.dll [438272]
[MD5.2AF7DA157FFF947A507FCB4AB8BB4C7C] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.22-08-2013 - 6:13:54.) -- C:\Windows\system32\Drivers\AFD.sys [455168]
[MD5.72FCAE2CE6DFEAB2AB072435017F3417] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.22-08-2013 - 5:33:25.) -- C:\Windows\system32\Drivers\atapi.sys [23392]
[MD5.CE232BB0965C0C0B786C3F976CCBFB7D] - (.Microsoft Corporation - CD-ROM File System Driver.) (.22-08-2013 - 4:11:55.) -- C:\Windows\system32\Drivers\Cdfs.sys [73728]
[MD5.E2FC132D48EA4E8B04432C33EFB77801] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.22-08-2013 - 1:59:12.) -- C:\Windows\system32\Drivers\Cdrom.sys [124928]
[MD5.D4ADBFC2409EF883164F3AA49B22F366] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.22-08-2013 - 4:09:45.) -- C:\Windows\system32\Drivers\DfsC.sys [101376]
[MD5.A31901DE6A22EA67AB83AAF7036F98CC] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.22-08-2013 - 4:10:12.) -- C:\Windows\system32\Drivers\HDAudBus.sys [69632]
[MD5.5043E69532392A43549E5D41E22638AA] - (.Microsoft Corporation - i8042 Port Driver.) (.22-08-2013 - 4:10:59.) -- C:\Windows\system32\Drivers\i8042prt.sys [82944]
[MD5.FA6C94C754A566EA8A61D658932F32DE] - (.Microsoft Corporation - IP Network Address Translator.) (.27-11-2013 - 11:03:35.) -- C:\Windows\system32\Drivers\IpNat.sys [126976]
[MD5.9E030D5C03E68E0C78EA120212759D66] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.23-11-2013 - 6:09:50.) -- C:\Windows\system32\Drivers\MRxSmb.sys [332800]
[MD5.BC242922B0D08F61CF7C87FD08FAFA8B] - (.Microsoft Corporation - MBT Transport driver.) (.22-08-2013 - 4:08:26.) -- C:\Windows\system32\Drivers\netBT.sys [218624]
[MD5.D13D35452A5F452DCC1626AE1A7D9790] - (.Microsoft Corporation - NT File System Driver.) (.10-03-2014 - 8:43:52.) -- C:\Windows\system32\Drivers\ntfs.sys [1673048]
[MD5.4F30970F15ADCC382544B31D5D7E368E] - (.Microsoft Corporation - Parallel Port Driver.) (.22-08-2013 - 4:11:49.) -- C:\Windows\system32\Drivers\Parport.sys [81408]
[MD5.C51AB62AB41A2E8560D12472B204CC00] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.22-08-2013 - 4:07:36.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [81920]
[MD5.67E91843B0344411820A012063E876B2] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.22-08-2013 - 14:39:05.) -- C:\Windows\system32\Drivers\rdpdr.sys [143872]
[MD5.DB0C184142CF9FA1746F598A16EE92B2] - (.Microsoft Corporation - TDI Translation Driver.) (.22-08-2013 - 6:13:54.) -- C:\Windows\system32\Drivers\tdx.sys [87040]
[MD5.CA3C52D981550DEA46576F9FFBA22C58] - (.Microsoft Corporation - Volume Shadow Copy Driver.) (.31-01-2014 - 14:04:24.) -- C:\Windows\system32\Drivers\volsnap.sys [265560]
~ Generic Processes: Scanned in 00mn 00s



---\\ Hidden files state (Hidden/Total)
~ Mes Favoris (My Favorites) : 1/4
~ Mon Bureau (My Desktop) : 1/114
~ Menu demarrer (Programs) : 1/31
~ Hidden Files: Scanned in 00mn 00s



---\\ Process running
[MD5.61A5597AB30F257BCC47A8E61711F039] - (.Microsoft Corporation - Host Process for Windows Tasks.) -- C:\WINDOWS\system32\taskhostex.exe [66632] [PID.796]
[MD5.349AB4F70E2AC44970894E7F03E1576E] - (.Huawei Technologies Co., Ltd. - DataCardMonitor MFC Application.) -- C:\ProgramData\DatacardService\DCSHelper.exe [236384] [PID.1724]
[MD5.C37C8414D1439EC22C1D1EA42185A94B] - (.Microsoft Corporation - SkyDrive Sync Engine Host.) -- C:\Windows\System32\skydrive.exe [460800] [PID.2448]
[MD5.D78C53AC8418D9E5811D837103E594CE] - (.IObit - No Comment.) -- C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe [182048] [PID.3140]
[MD5.07782C388EDDB13CB0A1040F7E1DDCDC] - (.No owner - Real-time Protector.) -- C:\Program Files\IObit\Advanced SystemCare 8\RealTimeProtector.exe [1106720] [PID.3180]
[MD5.42433CDEC449D40F508752F2D487D8E4] - (.Microsoft Corporation - Host Process for Setting Synchronization.) -- C:\Windows\System32\SettingSyncHost.exe [478208] [PID.3292]
[MD5.E47AC731D42B2452D4C0BF096DF3DD6E] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8145408] [PID.3660]
~ Processes Running: Scanned in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Line Analysis F0, F1, F2, F3 - IniFiles, Auto loading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s



---\\ Auto loading programs from Registry and folders (O4)
O4 - HKLM\..\Run: [UIExec] . (...) -- C:\Program Files\Internet Mobile+\UIexec.exe
O4 - HKCU\..\Run: [Advanced SystemCare 8] . (.IObit - Advanced SystemCare 8.) -- C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe
O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
O4 - HKUS\S-1-5-21-559679301-2718928345-356766008-1001\..\Run: [Advanced SystemCare 8] . (.IObit - Advanced SystemCare 8.) -- C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe
O4 - HKUS\S-1-5-21-559679301-2718928345-356766008-1001\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe
O4 - HKUS\S-1-5-21-559679301-2718928345-356766008-1001\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
~ Application: Scanned in 00mn 00s



---\\ Lop.com/Domain Hijackers (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{D46A0BFF-9352-490A-A426-30E96F15665C}: NameServer = 8.8.8.8 41.214.140.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{D46A0BFF-9352-490A-A426-30E96F15665C}: NameServer = 8.8.8.8 41.214.140.5
~ Domain: Scanned in 00mn 00s



---\\ Extra protocols (O18)
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - عارض Microsoft (R) HTML.) -- C:\Windows\System32\mshtml.dll
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Non Microsoft non disabled Windows XP/NT/2000 Services (O23)
O23 - Service: HWDeviceService.exe (HWDeviceService.exe) . (.No owner - DCSHOST.) - C:\ProgramData\DatacardService\HWDeviceService.exe
~ Services: 5 Legitimates Filtered in 00mn 04s



---\\ Task Planned Automatically (039)
[MD5.00000000000000000000000000000000] [APT] [{EC49A737-BF4C-49E3-B9D4-1951E2C302B9}] (...) -- F:\Setup.exe (.not file.) [0]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [830]
O39 - APT: - (..) -- C:\Windows\Tasks\ASC8_SkipUac_admin.job [244]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\ASC8_SkipUac_admin [244]
~ Scheduled Task: 7 Legitimates Filtered in 00mn 07s



---\\ Drivers launched at startup (O41)
O41 - Driver: (HWiNFO32) . (.REALiX(tm) - HWiNFO x86 Kernel Driver.) - C:\WINDOWS\system32\drivers\HWiNFO32.sys
~ Drivers: 36 Legitimates Filtered in 00mn 00s



---\\ Software installed (O42)
O42 - Logiciel: herdProtect Anti-Malware Scanner - (.Reason Company Software Inc..) [HKLM] -- herdProtectScan
~ Logic: 3 Legitimates Filtered in 00mn 00s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\AdsFix]
[HKCU\Software\InCodeSolutions]
[HKLM\Software\AdsFix]
[HKLM\Software\SMR]
~ Key Software: 100 Legitimates Filtered in 00mn 00s



---\\ Contents of the Common Files folders (O43)
O43 - CFD: 29-12-2014 - 2:23:40 - [] ----D C:\ProgramData\ProductData
O43 - CFD: 19-12-2014 - 8:20:19 - [] ----D C:\ProgramData\SMR430
O43 - CFD: 12-12-2014 - 19:31:32 - [0] ----D C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
O43 - CFD: 23-12-2014 - 6:19:15 - [] ----D C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690}
O43 - CFD: 23-12-2014 - 6:19:13 - [] ----D C:\ProgramData\{E1ED556E-3EA0-4F44-8BE7-CC5FB0F4B424}
O43 - CFD: 27-12-2014 - 13:38:41 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\herdProtect
O43 - CFD: 22-08-2013 - 14:39:14 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 24-12-2014 - 3:22:38 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WASEET303
O43 - CFD: 24-12-2014 - 3:25:51 - [] ----D C:\Users\admin\AppData\Roaming\InCode Solutions
O43 - CFD: 14-12-2014 - 19:48:53 - [] ----D C:\Users\admin\AppData\Roaming\ProductData
O43 - CFD: 16-12-2014 - 6:29:19 - [] ----D C:\Users\admin\AppData\Local\Smart_PC_Soft_&_Efam_Comp
O43 - CFD: 19-12-2014 - 2:57:54 - [0] ----D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WASEET303
~ Program Folder: 124 Legitimates Filtered in 00mn 00s



---\\ Last modified or created files under Windows and System32 (O44)
O44 - LFC:[MD5.814231B961760C39A5807A43D8ED71E1] - 18-12-2014 - 7:38:28 ---A- . (...) -- C:\Windows\System32\Drivers\RTAIODAT.DAT [1443340]
O44 - LFC:[MD5.11D34FC869F5BDA29949FE3858380894] - 19-12-2014 - 5:43:48 ---A- . (.The OpenVPN Project - TAP-Win32 Virtual Network Driver.) -- C:\Windows\System32\Drivers\tap0901.sys [26112]
O44 - LFC:[MD5.6FFB351C9C9BB88E91785F4CD7396D31] - 20-12-2014 - 5:20:22 ---A- . (.REALiX(tm) - HWiNFO x86 Kernel Driver.) -- C:\Windows\System32\Drivers\HWiNFO32.SYS [23840]
O44 - LFC:[MD5.24E455DD1CCE07253AAE04D9EAC5F725] - 24-12-2014 - 12:56:36 ---A- . (...) -- C:\Windows\System32\unrar.dll [217176]
O44 - LFC:[MD5.2F237E41B9F198FBA75681CCB488DEBE] - 28-12-2014 - 9:30:51 ---A- . (...) -- C:\Windows\ProfessionalWMC.xml [17851]
O44 - LFC:[MD5.4703C45615D8E349410B8F3FC165CE6A] - 29-12-2014 - 12:39:40 ---A- . (...) -- C:\AdsFix_29_12_2014_12_39_40.txt [20323]
O44 - LFC:[MD5.58F56396C0FA068730A09B937D40B7A1] - 29-12-2014 - 12:48:28 ---A- . (...) -- C:\Windows\ntbtlog.txt [17936]
~ Files: 145 Legitimates Filtered in 00mn 07s



---\\ Local Security Authority-LSA Deny (O48)
~ LSA: 3 Legitimates Filtered in 00mn 00s



---\\ Safe Boot Control (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\CleanHlp.sys . (...) -- C:\Windows\System32\Drivers\CleanHlp.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\CleanHlp.sys . (...) -- C:\Windows\System32\Drivers\CleanHlp.sys (.not file.)
~ CSB: 24 Legitimates Filtered in 00mn 00s



---\\ MountPoints2 Shell Key (MPSK) (O51)
O51 - MPSK:{26164089-8da5-11e4-9735-9f75d9fbf8ce}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.)
O51 - MPSK:{2f340925-822f-11e4-9712-806e6f6e6963}\AutoRun\command. (...) -- F:\Autorun.exe (.not file.)
O51 - MPSK:{58d11287-8dc5-11e4-9736-e9ac36526ec3}\AutoRun\command. (...) -- F:\Autorun.exe (.not file.)
O51 - MPSK:{58d11640-8dc5-11e4-9736-c16150d219d7}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.)
O51 - MPSK:{58d11688-8dc5-11e4-9736-c16150d219d7}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.)
O51 - MPSK:{b47738d8-8a2c-11e4-9720-a423e488e0b8}\AutoRun\command. (...) -- F:\Setup.exe (.not file.)
O51 - MPSK:{e4e08ed8-8bf6-11e4-9732-ea06263e3c09}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.)
O51 - MPSK:{e4e08f33-8bf6-11e4-9732-ea06263e3c09}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.)
~ Keys: Scanned in 00mn 00s



---\\ Microsoft Windows Policies System (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 17 Legitimates Filtered in 00mn 00s



---\\ System Drivers List (SDL) (O58)
O58 - SDL:12-08-2013 - 23:25:32 ---A- . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\Drivers\bcmfn2.sys [16088]
O58 - SDL:13-12-2012 - 15:41:10 ---A- . (.Windows (R) Win 7 DDK provider - Explore Systems Virtual Audio Device.) -- C:\Windows\System32\Drivers\dfx11_1.sys [24424]
O58 - SDL:28-12-2014 - 1:23:51 ---A- . (.Huawei Tech. Co., Ltd. - HUAWEI USB Smart Card Driver.) -- C:\Windows\System32\Drivers\ewdcsc.sys [25856]
O58 - SDL:20-12-2014 - 5:20:22 ---A- . (.REALiX(tm) - HWiNFO x86 Kernel Driver.) -- C:\Windows\System32\Drivers\HWiNFO32.SYS [23840]
O58 - SDL:29-11-2014 - 0:37:06 ---A- . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\Drivers\idmwfp.sys [115752]
O58 - SDL:02-03-2011 - 17:12:46 ---A- . (.MBB Incorporated - CDROM Filter.) -- C:\Windows\System32\Drivers\massfilter.sys [9216]
O58 - SDL:28-12-2014 - 1:23:53 ---A- . (.DiBcom SA - DiBcom AVSTREAM BDA driver.) -- C:\Windows\System32\Drivers\mod7700.sys [861696]
O58 - SDL:22-08-2013 - 5:32:57 ---A- . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x86.) -- C:\Windows\System32\Drivers\stexstor.sys [26976]
O58 - SDL:21-08-2010 - 4:08:46 ---A- . (.The OpenVPN Project - TAP-Win32 Virtual Network Driver.) -- C:\Windows\System32\Drivers\tap0901.sys [26112]
~ Drivers: 53 Legitimates Filtered in 00mn 03s



---\\ List all tools cleaner (LATC) (O63)
O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Start Menu Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Search Browser Infection (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s



---\\ Search Particular Root Folder (SPRF) (O84)
[MD5.E8C9A28B66B8B56F319216FEFF2A8824] [SPRF][29-12-2014] (.No owner - AdsFix.) -- C:\Users\admin\Desktop\AdsFix.exe [2437632]
[MD5.9A8336796A7C71E9F33DE848B8320ED3] [SPRF][29-12-2014] (...) -- C:\Users\admin\Desktop\wzgfklpt.exe [380416]
~ Files: 3 Legitimates Filtered in 00mn 00s



---\\ General States of Services not Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 18-12-2014 267440 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Auto 28-12-2014 655712 | (Internet Mobile. RunOuc) . (...) - C:\Program Files\Internet Mobile\UpdateDog\ouc.exe
SS - | Demand 13-12-2014 114800 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 18-12-2014 252632 | (RtkAudioService) . (.Realtek Semiconductor.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe
SS - | Demand 22-08-2013 31552 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 04-11-2014 815392 | (AdvancedSystemCareService8) . (.IObit.) - C:\Program Files\IObit\Advanced SystemCare 8\ASCService.exe
SR - | Auto 14-03-2011 271712 | (HWDeviceService.exe) . (...) - C:\ProgramData\DatacardService\HWDeviceService.exe
SR - | Auto 10-12-2014 2631456 | (LiveUpdateSvc) . (.IObit.) - C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
SR - | Auto 15-03-2011 261456 | (UI Assistant Service) . (...) - C:\Program Files\Internet Mobile+\AssistantServices.exe
SR - | Auto 30-10-2013 22224 | (WinDefend) . (.Microsoft Corporation.) - C:\Program Files\Windows Defender\MsMpEng.exe
~ Services: Scanned in 00mn 17s



---\\ Scan Additionnel (O88)
Database Version : 13026 - (27-12-2014)
Clés trouvées (Keys found) : 0
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 0

~ Additionnel Scan: 168384 Items scanned in 00mn 39s



---\\ Additional information about modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Auto loading programs from Registry and folders (O4)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.MountPoints2 Shell Key (MPSK) (O51)
~ AMI: 3 Legitimates Filtered in 00mn 00s



~ 590 Legitimates filtered by white list
End of the scan (347 lines in 01mn 44s)(0)

Publicité


Signaler le contenu de ce document

Publicité