cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2015.2.19.22 - Nicolas Coolman (19/02/2015)
~ Lancé par Bernard (22/02/2015 06:01:20)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17633 (Defaut)
MFIE: Mozilla Firefox 31.0

---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
Windows ID Activation : OK
~ Windows Partial Key : KF2YT
Windows License : OK
~ Windows Remaining Initializations Number : 3
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)

---\\ Logiciels de protection du système
Antivirus Pro v14.0.7.468
Malwarebytes Anti-Malware version 2.0.4.1028
Microsoft Security Client FR-FR Language Pack v2.1.1116.0
Kaspersky Security Scan v12.0.1.881
Windows Defender W7 (Activate)

---\\ Logiciels d'optimisation du système
CCleaner v5.02

---\\ Logiciels de partage PeerToPeer
eMule

---\\ Surveillance de Logiciels
Adobe Flash Player 16 NPAPI
Adobe Reader XI

---\\ Informations sur le système
~ Processor: Intel64 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 12151 MB (74% free)
System Restore: Désactivé (Disabled)
System drive C: has 60 GB (37%) free of 159 GB

---\\ Mode de connexion au système
~ Computer Name: PC-BERNARD
~ User Name: Bernard
~ All Users Names: HomeGroupUser$, Emilie, Bernard, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Bernard\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Bernard\AppData\Roaming\
~ %Desktop% : C:\Users\Bernard\Desktop\
~ %Favorites% : C:\Users\Bernard\Favorites\
~ %LocalAppData% : C:\Users\Bernard\AppData\Local\
~ %StartMenu% : C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 60 Go of 159 Go)
D: Hard drive, Flash drive, Thumb drive (Free 319 Go of 772 Go)
E: CD-ROM drive (Not Inserted)
F: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
~ Security Center: 50 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.9DFE41A69DF70AAB75CB5BA8C1109EA2] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.12/01/2015 - 02:27:32.) -- C:\Windows\System32\wininet.dll [2358272]
[MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.17/07/2014 - 03:07:24.) -- C:\Windows\System32\Winlogon.exe [455168]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.21/11/2010 - 04:24:16.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.FA886682CFC5D36718D3E436AACF10B9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:45:52.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.21/11/2010 - 04:24:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.21/11/2010 - 04:23:51.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:37:55.) -- C:\Windows\system32\Drivers\ntfs.sys [1684928]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.21/11/2010 - 04:24:33.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.70988118145F5F10EF24720B97F35F65] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:46:26.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/158
~ Mes musiques (My Musics) : 1/2
~ Mes Videos (My Videos) : 1/3
~ Mes Favoris (My Favorites) : 1/1916
~ Mes Documents (My Documents) : 2/2089
~ Mon Bureau (My Desktop) : 1/41
~ Menu demarrer (Programs) : 1/231
~ Hidden Files: Scanned in 00mn 00s



---\\ Processus lancés
[MD5.4F011F572DAC7057DF9D6E9064AA77E8] - (.NVIDIA Corporation - NVIDIA GeForce Experience Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2460488] [PID.2516]
[MD5.A2DBDE21B550F57EC83AEAC2034D12A5] - (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe [110160] [PID.2640]
[MD5.E98EA7471918E1987075815DC4C61001] - (.Yahoo! Inc. - Yahoo! Widgets.) -- C:\Program Files (x86)\Yahoo!\Widgets\YahooWidgets.exe [4742184] [PID.2880]
[MD5.A162B967A88BF374A81E01EF6E7A2655] - (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768] [PID.2436]
[MD5.F6158734F1E24C6C510155CF0D363911] - (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [295512] [PID.2500]
[MD5.8943465BEFA91044227D42E84ECB8280] - (.Renesas Electronics Corporation - USB 3.0 Monitor.) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048] [PID.1860]
[MD5.8FFDB89A0FB7C8ABC3A8825E38047341] - (.Logitech Inc. - Logitech Webcam Software.) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136] [PID.3076]
[MD5.E4C53CE8409DCFF708C790A0AC76398D] - (...) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe [264040] [PID.3308]
[MD5.0C04D13438560D24EA3A97BD7B26B5B7] - (.RaMMicHaeL - Unchecky Background Process.) -- C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe [402536] [PID.4100]
[MD5.B17B3A8C3A11D20F9D9C8F4D83DAF050] - (.Intel Corporation - IAStorIcon.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [323312] [PID.4860]
[MD5.9F5F2F0FB0A7F5AA9F16B9A7B6DAD89F] - (.Google - Google Desktop.) -- C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [30192] [PID.3768]
[MD5.363BC25BACB34E9D40441968B1B3D5BE] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\IEXPLORE.exe [815288] [PID.5060]
[MD5.24FF7E8C2F71E3E5C11936EE948BB68D] - (.McAfee, Inc. - SiteAdvisor.) -- C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe [1205944] [PID.2092]
[MD5.E8B7FD67DA14A7BE57A5CB80E3139E60] - (.Google Inc. - Google Toolbar Broker.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe [309704] [PID.1932]
[MD5.F3F709C2D49DD6636F4EDE5C2CAE5448] - (.http://www.emule-project.net - eMule.) -- C:\Program Files (x86)\eMule\emule.exe [5758976] [PID.800] =>P2P.eMule
[MD5.3A482BF9D10776B2EB0A52C9C87158E0] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8176128] [PID.1488]
[MD5.2F442BAA7A739EDFB8CBF6BFBE8F5388] - (.IObit - Advanced SystemCare Service.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [815392] [PID.904]
[MD5.C2700D35AA42311A32DF7EA09630B401] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920] [PID.1636]
[MD5.FC5B75CA6A1DA31EDD4F8D53F5540B98] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [81088] [PID.2020]
[MD5.C2700D35AA42311A32DF7EA09630B401] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920] [PID.1276]
[MD5.C34411A244029F1C08687F7C752C4563] - (.Hewlett-Packard Company - LightScribe Service.) -- C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728] [PID.2068]
[MD5.E38775922D4A4C05B5D96733AB4CE169] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [268824] [PID.2236]
[MD5.0BB29DE40C9D9529793DCDB59A43CF5B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160] [PID.2324]
[MD5.F172AD4E906D97ED8F071896FC6789DC] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107912] [PID.2400]
[MD5.83BB030C71C9727DCFB2737005772C4E] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe [232264] [PID.2504]
[MD5.7CF1B716372B89568AE4C0FE769F5869] - (.Microsoft Corporation - Machine Debug Manager.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872] [PID.2952]
[MD5.63694C307273062A2167AE4CE80730EF] - (.Sony Corporation - Device Information Provider.) -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [398176] [PID.1960]
[MD5.51138BEEA3E2C21EC44D0932C71762A8] - (...) -- ysWOW64\rundll32.exe [0] [PID.3416]
[MD5.E1E13735B6D2FE4FFEAEB91989B9C46F] - (.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5436176] [PID.3460]
[MD5.FD2804048115F06FD8402C3255E0BC78] - (.RaMMicHaeL - Unchecky Service.) -- C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [126568] [PID.3760]
[MD5.02C298382359653BEC4C737C2AB7F9C5] - (.Intel Corporation - User Notification Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2320920] [PID.3780]
[MD5.7D6FFF60082AD63C5D8C67D7BDE7F034] - (.Intel Corporation - IAStorDataSvc.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [19184] [PID.4064]
[MD5.D0F2BD42CD3AC015BD93A81638210BC7] - (.Avira Operations GmbH & Co. KG - Antivirus MailScanner WFP Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [807672] [PID.4936]
[MD5.027820FE847A7B4245234A4E6E825BE1] - (.Avira Operations GmbH & Co. KG - AntiVir WebGuard WFP Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [993584] [PID.4960]
~ Processes Running: Scanned in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Bernard\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js
C:\Users\Bernard\AppData\Roaming\Mozilla\Firefox\Profiles\y34b53cq.default\prefs.js
M2 - MFEP: RegExtension {22119944-ED35-4ab1-910B-E619EA06A115} . (...) --
M2 - MFEP: prefs.js [Bernard - extensions\iobitascsurfingprotection@iobit.com] [] Advanced SystemCare Surfing Protection v2.0 (..)
M2 - MFEP: prefs.js [Bernard - y34b53cq.default\iobitascsurfingprotection@iobit.com] [] Advanced SystemCare Surfing Protection v2.0 (..)
~ Firefox Browser: 38 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = preserve
~ IE Browser: 21 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\System32\Userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (54)
~ Hosts File: Scanned in 00mn 00s



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: Ads Removal [64Bits] - {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} . (.Adblock - Helps you remove browser ads!.) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll
O2 - BHO: Adblock Plus for IE Browser Helper Object [64Bits] - {FFCB3198-32F3-4E8B-9539-4324694ED664} . (.Adblock Plus - Adblock Plus Module.) -- C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
~ BHO: 23 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - [HKLM]{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} . (.McAfee, Inc. - SiteAdvisor.) -- C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
O3 - Toolbar: &RoboForm Toolbar - [HKLM]{724d43a0-0d85-11d4-9908-00400523e39a} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{71576546-354D-41C9-AAE8-31F2EC22BF0D} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{724D43A0-0D85-11D4-9908-00400523E39A} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{D3028143-6145-4318-99D3-3EDCE54A95A9} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: eMule.lnk . (.http://www.emule-project.net - eMule.) -- C:\Program Files (x86)\eMule\emule.exe =>P2P.eMule
O4 - GS\Desktop [Bernard]: Ebay - Bernard.LNK . (...) -- C:\Users\Bernard\Documents\My RoboForm Data\Default Profile\Ebay - Bernard.rfp -l (.not file.) =>Toolbar.eBay
~ Global Startup: 2 Legitimates Filtered in 00mn 09s



---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [NvBackend] . (.NVIDIA Corporation - NVIDIA GeForce Experience Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
O4 - HKLM\..\Run: [EvtMgr6] . (.Logitech, Inc. - Logitech SetPoint Event Manager (UNICODE).) -- C:\Program Files\Logitech\SetPointP\SetPoint.exe
O4 - HKLM\..\Run: [IAStorIcon] . (.Intel Corporation - Delayed launcher.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp
O4 - HKCU\..\Run: [RoboForm] . (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] . (.Disc Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe =>.DT Soft Ltd
O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
O4 - HKLM\..\Wow6432Node\Run: [GrooveMonitor] . (.Microsoft Corporation - GrooveMonitor Utility.) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe
O4 - HKLM\..\Wow6432Node\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe =>.RealNetworks, Inc
O4 - HKLM\..\Wow6432Node\Run: [NUSB3MON] . (.Renesas Electronics Corporation - USB 3.0 Monitor.) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
O4 - HKLM\..\Wow6432Node\Run: [LWS] . (.Logitech Inc. - Logitech Webcam Software.) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe =>.Logitech Inc
O4 - HKLM\..\Wow6432Node\Run: [Google Desktop Search] . (.Google - Google Desktop.) -- C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
O4 - HKUS\S-1-5-21-2503739192-254968964-1925577246-1001\..\Run: [RoboForm] . (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
O4 - HKUS\S-1-5-21-2503739192-254968964-1925577246-1001\..\Run: [DAEMON Tools Lite] . (.Disc Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe =>.DT Soft Ltd
O4 - HKUS\S-1-5-21-2503739192-254968964-1925577246-1001\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
~ Application: Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Remplir les formulaires [64Bits] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: Enregistrer les formulaires [64Bits] - {320AF880-6646-11D3-ABEE-C5DBF3571F49} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: Personnaliser le menu [64Bits] - {320AF880-6646-11D3-ABEE-C5DBF3571F4E} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: Barre RoboForm [64Bits] - {724d43aa-0d85-11d4-9908-00400523e39a} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: Skype Click to Call [64Bits] - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- c:\program files (x86)\skype\toolbars\internet explorer x64\icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{0D5C9240-E3CF-402D-98BC-E4642A24EA9B}: DhcpNameServer = 192.168.1.10 192.168.1.10
O17 - HKLM\System\CS1\Services\Tcpip\..\{0D5C9240-E3CF-402D-98BC-E4642A24EA9B}: DhcpNameServer = 192.168.1.10 192.168.1.10
O17 - HKLM\System\CS2\Services\Tcpip\..\{0D5C9240-E3CF-402D-98BC-E4642A24EA9B}: DhcpNameServer = 192.168.1.10 192.168.1.10
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.10 192.168.1.10
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wot [64Bits] - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} . (...) --
O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: LBTWlgn . (.Logitech, Inc. - Logitech Bluetooth Service.) -- c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: (no name) [64Bits] - {73526E5A-FD53-4BE7-B5E2-D3C89D7413DC} - (.not file.)
~ STS/SSO: Scanned in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [{164C8768-29C1-4F1A-B70D-CDAA94C6D145}] (...) -- E:\Documents Ma Mule\Bernard\Watcher_Setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{1CD023A9-8ED7-4102-B909-ED3FC8032054}] (...) -- F:\Setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{1ED7B2B4-8882-461E-A5CC-E9B3F35850F2}] (...) -- E:\mura.bernard\RegCleaner V4.3.0.780.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{2C24FB4C-E1BA-4ECE-92FA-02588E01896C}] (...) -- E:\mura.bernard\WinZip 9.0 Fr + Keygen\Setup Winzip 9.0\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{2F935AB3-F37A-4E97-82E1-C1A5935AF7B8}] (...) -- E:\mura.bernard\Worldwind_1.4_IGE_PluginFrancais_1.0.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{3086A7A1-508B-4D72-9A1F-2FF0CF876247}] (...) -- D:\mura.bernard\WinAce 2.55 Fr + Key\w25b5_fr.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{332B5B5C-44C1-4E14-901A-1D969FE55662}] (...) -- E:\mura.bernard\Everio mediaBrowser HD Edition V 2.02.23.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{4242B7C6-BBB3-4B52-9D6D-1E1B7E137408}] (...) -- D:\mura.bernard\[3DMark.2006.Professional.Edition].3DMark06_v102_installer\3DMark06_v102_installer.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{48D1180A-694A-490C-A846-A2BE12A1D191}] (...) -- D:\mura.bernard\HOSTS_Install_V2.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{54E6FC19-4CBC-4D7F-9927-98AA2283C568}] (...) -- C:\Users\Bernard\Desktop\OverDisk011b.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{5E34C36D-DEA2-453E-99CD-4011E7CC9CC2}] (...) -- C:\Users\Bernard\Downloads\PC Drivers HeadQuarters\Driver Detective\Vista_Win7_R261.exe (.not file.) [0] =>DriverDetective
[MD5.00000000000000000000000000000000] [APT] [{61ECB5BE-D2E1-4175-82B4-D942287AFDF8}] (...) -- D:\mura.bernard\Q-Dir 5.68\Q-Dir_Installer.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{717ECDFE-5ED4-4136-B164-9C0C26A0BC69}] (...) -- D:\mura.bernard\RegCleaner V4.3.0.780.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{7C8C3F18-3F26-4014-B7AB-17F34B3F710E}] (...) -- E:\mura.bernard\Windirstat V 1.1.2.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{85FF3D00-AF4D-412E-8B2D-94AF61CC8B4E}] (...) -- D:\mura.bernard\Q-Dir 5.61\Q-Dir_Installer.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{899B7A70-2979-4501-A1A5-C278DDD5C980}] (...) -- E:\mura.bernard\jre-6u29-windows-i586-iftw.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{B1385BB0-CFA4-418B-B2D5-A6ADD6574377}] (...) -- E:\mura.bernard\Cities 3D.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C6CF36D1-CA8C-4062-925D-5507DC051351}] (...) -- E:\Documents Ma Mule\Bernard\Digi Watcher 2.30 + Remote View 1.40 - Webcam Spy\Digi.Watcher.v2.30.WinAll.Incl.Keygenerator-TMG\Watcher_Setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{CEF3BE90-C84F-4F4D-B9B4-4D7CE38EF454}] (...) -- C:\Users\Bernard\AppData\Local\Temp\tasks\PSSetup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{CF102249-EC4A-4DB7-BE13-A47AB839FB95}] (...) -- E:\Documents Ma Mule\Bernard\AutoCAD Architecture 2009\setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{D64C8214-B066-478C-A58D-E62F57B59B9E}] (...) -- E:\Documents Ma Mule\Bernard\Setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{E0C5BAC2-544C-4319-B76E-514260B807F2}] (...) -- F:\ScreenSaver\ScreenSaver.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{F0B39416-0058-4009-9D54-E15191210AE1}] (...) -- C:\Users\Bernard\Desktop\FSXDemo.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{F41DC170-5789-4843-A957-D840682AB270}] (...) -- E:\Documents Ma Mule\Bernard (.not file.) [0]
[MD5.3ABF1C149873E25D4E266225FBF37CBF] [APT] [{F8DBCDA0-F393-408A-89C5-27E0BC364B72}] (...) -- D:\mura.bernard\Windirstat V 1.1.2.exe [645729]
[MD5.00000000000000000000000000000000] [APT] [{F979C2E0-F74C-4670-A411-2D1621A4C1F1}] (...) -- E:\mura.bernard\Epson Stylus SX 105.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{FCB90EDB-C2C8-43AC-82B8-49F86631A228}] (...) -- C:\Users\Bernard\Desktop\internettv_setup[1].exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{FE5F614C-2B70-4C0E-8779-8DFC2FE7C1F1}] (...) -- D:\mura.bernard\favorg (mise … jour des icones)\FavOrg (gère les icones des favoris).exe (.not file.) [0]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1066]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1070]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2503739192-254968964-1925577246-1001Core [1034]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2503739192-254968964-1925577246-1001UA [1086]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\Spybot - Search & Destroy - Scheduled Task [304]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\Spybot - Search & Destroy Updater - Scheduled Task [330]
~ Scheduled Task: 58 Legitimates Filtered in 00mn 02s



---\\ Logiciels installés (O42)
O42 - Logiciel: AC3File 0.6b - (.Alexander Vigovsky.) [HKLM][64Bits] -- AC3File_is1
O42 - Logiciel: Billiardino 1.0 - (.Falco Software, Inc..) [HKLM][64Bits] -- Billiardino_is1
O42 - Logiciel: Billiards Club - (.FreeGamePick.com.) [HKLM][64Bits] -- Billiards Club_is1
O42 - Logiciel: Bowling Evolution 1.05 - (...) [HKLM][64Bits] -- Bowling Evolution 1.05
O42 - Logiciel: Cities of Earth 3D Screensaver v. 2.1 - (.Screenomania.com.) [HKLM][64Bits] -- Cities of Earth 3D Screensaver_is1
O42 - Logiciel: CleanTemp 1.5.5 - (.Update Computer Services.) [HKLM][64Bits] -- {536CB2B8-199F-4C8B-9C3A-D91666558772}
O42 - Logiciel: FavOrg - (.PC Magazine.) [HKLM][64Bits] -- FavOrg
O42 - Logiciel: Fmrid 4.01 - (.Fabio Chelly.) [HKLM][64Bits] -- Fmrid
O42 - Logiciel: MenuUninstaller - (.Leizer Soft.) [HKLM][64Bits] -- {52BAA6C6-FAB0-46F3-9C14-ADDD1A85F6FE}
O42 - Logiciel: Mozaik - (...) [HKLM][64Bits] -- Mozaik
O42 - Logiciel: OSSearch version 0.7.1 - (.Parcouss.) [HKLM][64Bits] -- {BFCA578C-F5EB-49BF-B1C7-4ABE70471E22}_is1
O42 - Logiciel: OverDisk (remove only) - (...) [HKLM][64Bits] -- OverDisk
O42 - Logiciel: UpStarter - (...) [HKCU][64Bits] -- UpStarter
O42 - Logiciel: Windows Tweaker - (.SuRe Softwares.) [HKLM][64Bits] -- {092D4427-C1D9-43C0-B1BB-C8BCFE67D5C0}
~ Logic: 48 Legitimates Filtered in 00mn 01s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\BeauSoft]
[HKCU\Software\Digi-Watcher C:]
[HKCU\Software\Filefacts]
[HKCU\Software\Fmrid]
[HKCU\Software\FreshWebMaster]
[HKCU\Software\FriedCookie]
[HKCU\Software\Inventivio]
[HKCU\Software\MovieCollection]
[HKCU\Software\OB]
[HKCU\Software\Parcouss Apps]
[HKCU\Software\Reg]
[HKCU\Software\Screenomania]
[HKCU\Software\TVixC]
[HKCU\Software\UCS]
[HKCU\Software\babidyxp]
[HKCU\Software\bunkus.org]
[HKCU\Software\zyceffcal]
[HKLM\Software\Wow6432Node\ADSRemoval]
[HKLM\Software\Wow6432Node\FreshWebMaster]
[HKLM\Software\Wow6432Node\Inventivio]
[HKLM\Software\Wow6432Node\Reg]
[HKLM\Software\Wow6432Node\Screenomania]
[HKLM\Software\Wow6432Node\Secured-IE]
[HKLM\Software\Wow6432Node\Virustotal]
~ Key Software: 966 Legitimates Filtered in 00mn 01s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 08/12/2014 - 14:12:50 - [] ----D C:\Program Files (x86)\3RVX
O43 - CFD: 08/12/2014 - 14:12:51 - [] ----D C:\Program Files (x86)\AC3File
O43 - CFD: 08/01/2015 - 18:17:36 - [] ----D C:\Program Files (x86)\AHD
O43 - CFD: 08/12/2014 - 14:13:25 - [] ----D C:\Program Files (x86)\Beausoft
O43 - CFD: 08/12/2014 - 14:13:25 - [] ----D C:\Program Files (x86)\Billiardino
O43 - CFD: 08/12/2014 - 14:13:26 - [] ----D C:\Program Files (x86)\Bowling Evolution 1.05
O43 - CFD: 08/12/2014 - 14:13:26 - [] ----D C:\Program Files (x86)\Cities of Earth
O43 - CFD: 08/12/2014 - 14:13:26 - [] ----D C:\Program Files (x86)\CleanTemp 1.5
O43 - CFD: 08/12/2014 - 14:14:02 - [] ----D C:\Program Files (x86)\Crime Catcher
O43 - CFD: 08/12/2014 - 14:14:17 - [] ----D C:\Program Files (x86)\EuroThink
O43 - CFD: 08/12/2014 - 14:14:18 - [] ----D C:\Program Files (x86)\Fmrid
O43 - CFD: 08/12/2014 - 14:14:18 - [] ----D C:\Program Files (x86)\Font Explorer
O43 - CFD: 08/12/2014 - 14:14:20 - [] ----D C:\Program Files (x86)\FreshWebmaster
O43 - CFD: 08/12/2014 - 14:14:21 - [] ----D C:\Program Files (x86)\Gigaset QuickSync
O43 - CFD: 08/12/2014 - 14:18:41 - [] ----D C:\Program Files (x86)\LeeGT-Games
O43 - CFD: 08/12/2014 - 14:18:42 - [] ----D C:\Program Files (x86)\Leizer Soft
O43 - CFD: 08/12/2014 - 14:19:27 - [] ----D C:\Program Files (x86)\MalchroSoft
O43 - CFD: 08/12/2014 - 14:20:53 - [] ----D C:\Program Files (x86)\Onwijs
O43 - CFD: 25/12/2014 - 18:52:15 - [] ----D C:\Program Files (x86)\OSSearch
O43 - CFD: 08/12/2014 - 14:20:55 - [] ----D C:\Program Files (x86)\OverDisk
O43 - CFD: 08/12/2014 - 14:21:18 - [] ----D C:\Program Files (x86)\PMSSAARI
O43 - CFD: 08/12/2014 - 14:21:18 - [] ----D C:\Program Files (x86)\QTranslate
O43 - CFD: 21/07/2012 - 09:52:43 - [0] ----D C:\Program Files (x86)\Secured-IE
O43 - CFD: 08/12/2014 - 14:21:48 - [] ----D C:\Program Files (x86)\User's Guide
O43 - CFD: 23/12/2014 - 14:27:49 - [] ----D C:\Program Files (x86)\VJS Productions
O43 - CFD: 08/12/2014 - 14:21:48 - [] ----D C:\Program Files (x86)\WAN Miniport IKEv2
O43 - CFD: 08/12/2014 - 14:21:57 - [] ----D C:\Program Files (x86)\Windows Tweaker
O43 - CFD: 04/08/2011 - 17:29:56 - [0] ----D C:\Program Files (x86)\Yahoo! Jeux
O43 - CFD: 08/12/2014 - 14:14:02 - [] ----D C:\Program Files (x86)\Common Files\WAN Miniport IKEv2
O43 - CFD: 08/12/2014 - 14:22:33 - [] ----D C:\ProgramData\Advanced Uninstaller PRO
O43 - CFD: 08/12/2014 - 14:22:34 - [] ----D C:\ProgramData\bmkfieeegpeeafckaajcnajmpklckeah
O43 - CFD: 08/12/2014 - 14:22:34 - [] ----D C:\ProgramData\ClamAV
O43 - CFD: 11/05/2014 - 14:18:16 - [0] ----D C:\ProgramData\Duplicate Photo Cleaner
O43 - CFD: 08/12/2014 - 14:22:35 - [] ----D C:\ProgramData\Gigaset QuickSync
O43 - CFD: 22/02/2015 - 04:35:02 - [] ----D C:\ProgramData\ProductData
O43 - CFD: 08/12/2014 - 14:23:41 - [] ----D C:\ProgramData\SecureAge Technology
O43 - CFD: 08/12/2014 - 14:23:41 - [] ----D C:\ProgramData\SnowApp
O43 - CFD: 08/01/2015 - 00:30:08 - [0] ----D C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
O43 - CFD: 08/12/2014 - 14:24:30 - [] -SH-D C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
O43 - CFD: 08/12/2014 - 14:22:56 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AC3File
O43 - CFD: 08/01/2015 - 18:17:36 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AHD
O43 - CFD: 08/12/2014 - 14:23:00 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Billiardino
O43 - CFD: 08/12/2014 - 14:23:00 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bowling Evolution 1.05
O43 - CFD: 08/12/2014 - 14:23:01 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eReaders
O43 - CFD: 08/12/2014 - 14:23:03 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fmrid
O43 - CFD: 08/12/2014 - 14:23:04 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gigaset QuickSync
O43 - CFD: 28/01/2015 - 07:49:51 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Grand Master Chess
O43 - CFD: 08/12/2014 - 14:23:06 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I2P
O43 - CFD: 08/12/2014 - 14:23:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Manuel de l’utilisateur
O43 - CFD: 08/12/2014 - 14:23:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozaik
O43 - CFD: 25/12/2014 - 18:52:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OSSearch
O43 - CFD: 08/12/2014 - 14:23:12 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OverDisk
O43 - CFD: 03/02/2015 - 16:57:05 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reanimator
O43 - CFD: 08/12/2014 - 14:23:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Screenomania
O43 - CFD: 08/12/2014 - 14:23:15 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SentryVision
O43 - CFD: 12/04/2011 - 10:27:52 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 08/12/2014 - 14:23:18 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Tweaker
O43 - CFD: 14/01/2014 - 11:38:22 - [0] ----D C:\Users\Bernard\AppData\Roaming\7 Sticky Notes
O43 - CFD: 08/12/2014 - 14:44:06 - [] ----D C:\Users\Bernard\AppData\Roaming\Bitser
O43 - CFD: 08/12/2014 - 14:44:06 - [] ----D C:\Users\Bernard\AppData\Roaming\ClassicShell
O43 - CFD: 08/12/2014 - 14:44:09 - [] ----D C:\Users\Bernard\AppData\Roaming\Efficient Calendar Free
O43 - CFD: 08/12/2014 - 14:44:09 - [] ----D C:\Users\Bernard\AppData\Roaming\Ember_Media_Manager
O43 - CFD: 08/12/2014 - 14:44:09 - [] ----D C:\Users\Bernard\AppData\Roaming\Epic_Pen
O43 - CFD: 08/12/2014 - 14:44:09 - [] ----D C:\Users\Bernard\AppData\Roaming\Filey, Inc
O43 - CFD: 08/12/2014 - 14:44:12 - [] ----D C:\Users\Bernard\AppData\Roaming\I2P
O43 - CFD: 08/12/2014 - 14:44:12 - [] ----D C:\Users\Bernard\AppData\Roaming\Inventivio
O43 - CFD: 09/11/2014 - 09:50:25 - [0] ----D C:\Users\Bernard\AppData\Roaming\Litecoin
O43 - CFD: 08/01/2015 - 00:06:36 - [] ----D C:\Users\Bernard\AppData\Roaming\Mediatronic
O43 - CFD: 08/12/2014 - 14:44:39 - [] ----D C:\Users\Bernard\AppData\Roaming\MultiMiner
O43 - CFD: 20/02/2015 - 17:08:44 - [] ----D C:\Users\Bernard\AppData\Roaming\ProductData
O43 - CFD: 08/12/2014 - 14:44:50 - [] ----D C:\Users\Bernard\AppData\Roaming\QTranslate
O43 - CFD: 08/12/2014 - 14:59:32 - [] ----D C:\Users\Bernard\AppData\Roaming\Votre Budget 2008
O43 - CFD: 08/12/2014 - 14:59:33 - [] ----D C:\Users\Bernard\AppData\Roaming\WIPE2013
O43 - CFD: 08/01/2015 - 18:21:59 - [] ----D C:\Users\Bernard\AppData\Local\AHD
O43 - CFD: 08/12/2014 - 14:42:59 - [] ----D C:\Users\Bernard\AppData\Local\Bitser
O43 - CFD: 09/12/2014 - 08:22:25 - [] -SH-D C:\Users\Bernard\AppData\Local\EmieBrowserModeList
O43 - CFD: 08/12/2014 - 14:43:00 - [] ----D C:\Users\Bernard\AppData\Local\Films
O43 - CFD: 08/12/2014 - 14:43:06 - [] ----D C:\Users\Bernard\AppData\Local\hq
O43 - CFD: 08/12/2014 - 14:43:06 - [] ----D C:\Users\Bernard\AppData\Local\IFM38
O43 - CFD: 08/12/2014 - 14:43:17 - [] ----D C:\Users\Bernard\AppData\Local\MovieCollection
O43 - CFD: 08/12/2014 - 14:43:30 - [] ----D C:\Users\Bernard\AppData\Local\StudioGPU
O43 - CFD: 08/12/2014 - 14:44:35 - [] ----D C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Font Explorer
O43 - CFD: 08/12/2014 - 14:44:35 - [] ----D C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup
O43 - CFD: 08/12/2014 - 14:44:36 - [] ----D C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QTranslate
O43 - CFD: 08/12/2014 - 14:44:36 - [] ----D C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UpStarter
~ Program Folder: 835 Legitimates Filtered in 00mn 01s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.814231B961760C39A5807A43D8ED71E1] - 12/02/2015 - 13:01:14 ---A- . (...) -- C:\Windows\System32\Drivers\RTAIODAT.DAT [1443340]
O44 - LFC:[MD5.531121E7ED50084B493A69F8F8A7A927] - 19/02/2015 - 17:48:06 ---A- . (...) -- C:\Windows\System32\Drivers\TrueSight.sys [37624]
O44 - LFC:[MD5.C7BC96C3711C0D269DA26D1F0ECEC547] - 20/02/2015 - 10:50:20 ---A- . (...) -- C:\Windows\NeroDigital.ini [69]
O44 - LFC:[MD5.1E9484BD0A31A3734587E5C57109B18A] - 20/02/2015 - 18:11:19 ---A- . (...) -- C:\Windows\Antidote.ini [151]
O44 - LFC:[MD5.64623C1D083F03D9BCC7FCA4944D685D] - 21/02/2015 - 07:21:57 ---A- . (...) -- C:\Windows\Q-Dir.ini [53241]
O44 - LFC:[MD5.9A187570176002D975A7BEFF5C7D85EC] - 21/02/2015 - 07:24:01 ---A- . (...) -- C:\Windows\System32\TeamViewer10_Hooks.log [1001]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 22/02/2015 - 04:32:22 --HA- . (...) -- C:\asc_rdflag [0]
~ Files: 120 Legitimates Filtered in 00mn 01s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
~ MWPS: 19 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:25/02/2013 - 21:05:09 ---A- . (.Doctor Web, Ltd. - Dr.Web boot operations for Windows.) -- C:\Windows\System32\Drivers\28F881EE1.sys [23080]
O58 - SDL:01/03/2010 - 23:59:50 ---A- . (...) -- C:\Windows\System32\Drivers\cpqdfw.sys [24376]
O58 - SDL:01/03/2010 - 23:59:50 ---A- . (...) -- C:\Windows\System32\Drivers\cqcpu.sys [24376]
O58 - SDL:14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
O58 - SDL:23/05/2013 - 07:39:24 ---A- . (.ThreatTrack Security - gfiark64.sys.) -- C:\Windows\System32\Drivers\gfiark.sys [41032]
O58 - SDL:04/09/2013 - 13:57:44 ---A- . (.ThreatTrack Security - GFI Utility driver.) -- C:\Windows\System32\Drivers\gfiutil.sys [31264]
O58 - SDL:10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
O58 - SDL:25/05/2012 - 12:14:24 ---A- . (.GFI Software - GFI Anti-Rootkit Driver.) -- C:\Windows\System32\Drivers\SBREDrv.sys [57976]
O58 - SDL:14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
O58 - SDL:14/06/2010 - 08:32:54 ---A- . (.Teruten Inc - File System Mini Filter Drvier.) -- C:\Windows\System32\Drivers\TFsExDisk.sys [16448]
O58 - SDL:19/02/2015 - 17:48:06 ---A- . (...) -- C:\Windows\System32\Drivers\TrueSight.sys [37624]
O58 - SDL:18/12/2013 - 11:33:16 ---A- . (...) -- C:\Windows\System32\ampa.sys [17008]
O58 - SDL:20/01/2005 - 02:17:12 ---A- . (...) -- C:\Windows\SysWOW64\drivers\ASUSHWIO.SYS [5824]
O58 - SDL:25/10/2004 - 19:02:58 ---A- . (.EnTech Taiwan - Pas de description.) -- C:\Windows\SysWOW64\drivers\Entech.sys [21664]
O58 - SDL:22/06/2004 - 14:44:50 ---A- . (.EnTech Taiwan - EnTech driver for Windows XP 64.) -- C:\Windows\SysWOW64\drivers\Entech64.sys [5632]
O58 - SDL:04/11/2014 - 06:13:55 ---A- . (...) -- C:\Windows\SysWOW64\drivers\fsbts.sys [33920]
O58 - SDL:19/11/2001 - 18:05:18 ---A- . (...) -- C:\Windows\SysWOW64\drivers\PciBus.sys [3972]
O58 - SDL:27/06/2011 - 22:33:14 ---A- . (...) -- C:\Windows\SysWOW64\drivers\StarOpen.sys [5632]
O58 - SDL:27/06/2011 - 22:33:28 ---A- . (.Teruten Inc - File System Mini Filter Drvier.) -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys [16392]
O58 - SDL:06/10/2014 - 19:16:52 ---A- . (...) -- C:\Windows\SysWOW64\drivers\TrueSight.sys [33512]
O58 - SDL:18/12/2013 - 11:33:16 ---A- . (...) -- C:\Windows\SysWOW64\ampa.sys [17008]
O58 - SDL:22/05/2013 - 12:34:26 ---A- . (...) -- C:\Windows\SysWOW64\FsUsbExDisk.Sys [37344]
~ Drivers: 122 Legitimates Filtered in 00mn 00s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - 06/10/2009 - C:\Windows\System32\DRIVERS\ahcix64s.sys (ahcix64s) .(.Advanced Micro Devices, Inc - AMD AHCI Compatible Controller Driver for W.) - LEGACY_AHCIX64S
~ Legacy: 130 Legitimates Filtered in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Not Key.)
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {22760072-BB10-4A5F-AE9D-FF14E9B5299E} - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {6760948A-B0DC-4609-AFCA-2AEE65C3AD83} [DefaultScope] - (Recherche sécurisée) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - http://www.google.com
O69 - SBI: SearchScopes [HKCU] {A093DEBB-885B-4FB9-9A35-C1329E4C1AC2} - ((www.google.com) Google) - http://www.google.com
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.90A7C2C7404D877865ED6670339C51EC] [SPRF][25/12/2014] (...) -- C:\Users\Bernard\AppData\Roaming\1D959CA221C7573.sys [24]
[MD5.90A7C2C7404D877865ED6670339C51EC] [SPRF][25/12/2014] (...) -- C:\Users\Bernard\AppData\Roaming\System5908ConfigCollection.dat [24]
[MD5.E168731F246AA436A38641340C85AB2B] [SPRF][30/09/2011] (...) -- C:\Program Files (x86)\Uninstall_IGE_PluginFrancais.exe [128004]
~ Files: 3 Legitimates Filtered in 00mn 00s



---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.CAFF4EC5F93485EAD6320A3A4F2AD718] [WIS][22/05/2014] (.APN, LLC - Ask Toolbar.) -- C:\Windows\Installer\1c269f.msi [469504] =>Toolbar.Avira
[MD5.3A8281C3CAA9601E522CF24035328877] [WIS][25/06/2014] (.APN, LLC - Ask Toolbar.) -- C:\Windows\Installer\1c26ac.msi [507904] =>Toolbar.Avira
[MD5.35C918348CBB0877BCD5A3CF24C13761] [WIS][25/11/2012] (.DeltaInstaller - Delta Chrome Toolbar.) -- C:\Windows\Installer\930f79c.msi [573440] =>Toolbar.DeltaSearch
~ WIS: 3 Legitimates Filtered in 00mn 00s



---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{320AF880-6646-11D3-ABEE-C5DBF3571F49}] (SavePass) =>PUP.CrossRider
~ BCK: 5868 Legitimates Filtered in 00mn 08s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 01/09/2011 169624 | (AdobeActiveFileMonitor10.0) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
SS - | Demand 12/02/2015 267440 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 08/03/2010 192000 | (BsHelpCS) . (.IVT Corporation.) - C:\Program Files (x86)\IVT Corporation\BlueSoleil\BsHelpCS.exe
SS - | Disabled 29/07/2009 163840 | (EPSON_EB_RPCV4_01) . (.SEIKO EPSON CORPORATION.) - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.exe
SS - | Disabled 29/07/2009 126464 | (EPSON_PM_RPCV4_01) . (.SEIKO EPSON CORPORATION.) - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.exe
SS - | Demand 19/01/2012 1030600 | (FLEXnet Licensing Service 64) . (.Macrovision Europe Ltd..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
SS - | Demand 19/06/2010 246520 | (GameConsoleService) . (.WildTangent, Inc..) - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
SS - | Demand 12/06/2011 30192 | (GoogleDesktopManager-051210-111108) . (.Google.) - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
SS - | Auto 31/01/2015 107912 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 31/01/2015 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 11/08/2012 194032 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
SS - | Demand 09/09/2011 86072 | (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe =>.Hewlett-Packard Co
SS - | Demand 06/08/2010 291896 | (HPClientSvc) . (.Hewlett-Packard Company.) - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
SS - | Demand 01/04/2014 49464 | (HPSupportSolutionsFrameworkService) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
SS - | Demand 22/10/2004 73728 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
SS - | Demand 24/03/2014 357144 | (LBTServ) . (.Logitech, Inc..) - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
SS - | Auto 16/01/2015 2724128 | (LiveUpdateSvc) . (.IObit.) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
SS - | Demand 15/10/2014 2820424 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe
SS - | Auto 21/11/2014 969016 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
SS - | Demand 24/01/2015 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 24/09/2008 935208 | (Nero BackItUp Scheduler 4.0) . (.Nero AG.) - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
SS - | Demand 14/07/2009 27136 | C:\Windows\system32\HPZinw12.dll (Net Driver HPZ12) . (.Hewlett-Packard.) - C:\Windows\System32\svchost.exe
SS - | Disabled 17/09/2014 1795912 | (NvNetworkService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
SS - | Disabled 17/09/2014 19439944 | (NvStreamSvc) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
SS - | Disabled 02/07/2014 935368 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe
SS - | Demand 14/07/2009 27136 | C:\Windows\system32\HPZipm12.dll (Pml Driver HPZ12) . (.Hewlett-Packard.) - C:\Windows\System32\svchost.exe
SS - | Demand 14/08/2013 39056 | (RealNetworks Downloader Resolver Service) . (...) - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
SS - | Disabled 06/12/2007 88560 | (Roxio UPnP Renderer 9) . (.Sonic Solutions.) - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
SS - | Disabled 06/12/2007 362992 | (Roxio Upnp Server 9) . (.Sonic Solutions.) - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUpnpService9.exe
SS - | Auto 11/04/2009 313840 | (RoxLiveShare9) . (.Sonic Solutions.) - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
SS - | Demand 11/04/2009 1108464 | (RoxMediaDB9) . (.Sonic Solutions.) - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
SS - | Disabled 11/04/2009 170480 | (RoxWatch9) . (.Sonic Solutions.) - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
SS - | Demand 05/11/2014 73200 | (SandraAgentSrv) . (.SiSoftware.) - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3\RpcAgentSrv.exe
SS - | Demand 30/06/2011 1191936 | (SgtSch2Svc) . (.Seagate.) - C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe
SS - | Demand 04/02/2013 155824 | (Sony PC Companion) . (.Avanquest Software.) - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
SS - | Disabled 02/07/2014 411936 | (Stereo Service) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
SS - | Demand 05/06/2014 93040 | (TomTomHOMEService) . (.TomTom.) - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 04/11/2014 815392 | (AdvancedSystemCareService8) . (.IObit.) - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe
SR - | Auto 17/12/2014 807672 | (AntiVirMailService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
SR - | Auto 17/12/2014 431920 | (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
SR - | Auto 17/12/2014 431920 | (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
SR - | Auto 17/12/2014 993584 | (AntiVirWebService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
SR - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Demand 14/07/2009 27136 | C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll (hpqcxs08) . (.Hewlett-Packard Co..) - C:\Windows\System32\svchost.exe
SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll (hpqddsvc) . (.Hewlett-Packard Co..) - C:\Windows\System32\svchost.exe
SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.dll (HPSLPSVC) . (.Hewlett-Packard Co..) - C:\Windows\System32\svchost.exe
SR - | Auto 04/12/2014 19184 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
SR - | Auto 04/03/2011 73728 | (LightScribeService) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
SR - | Auto 01/10/2009 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 21/11/2014 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
SR - | Auto 12/02/2015 155368 | (McAfee SiteAdvisor Service) . (.McAfee, Inc..) - C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
SR - | Auto 26/11/2010 398176 | (PMBDeviceInfoProvider) . (.Sony Corporation.) - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
SR - | Auto 04/09/2014 292568 | (RtkAudioService) . (.Realtek Semiconductor.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
SR - | Auto 17/02/2015 5436176 | (TeamViewer) . (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
SR - | Auto 01/02/2015 126568 | (Unchecky) . (.RaMMicHaeL.) - C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
SR - | Auto 01/10/2009 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Demand 22/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 08s



---\\ Scan Additionnel (O88)
Database Version : 13008 - (19/02/2015)
Clés trouvées (Keys found) : 0
Valeurs trouvées (Values found) : 2
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 5

C:\Program Files (x86)\eMule\emule.exe =>P2P.eMule^
C:\Windows\Installer\1c269f.msi =>Toolbar.Avira^
C:\Windows\Installer\1c26ac.msi =>Toolbar.Avira^
C:\Windows\Installer\930f79c.msi =>Toolbar.DeltaSearch^
[HKCR\CLSID\{320AF880-6646-11D3-ABEE-C5DBF3571F49}] (SavePass) =>PUP.CrossRider^
~ Additionnel Scan: 607979 Items scanned in 00mn 19s



---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects de navigateur (O2)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ AMI: 4 Legitimates Filtered in 00mn 00s



---\\ Récapitulatif des détections trouvées sur votre station
http://www.nicolascoolman.fr/blog/ =>DriverDetective
http://nicolascoolman.fr/toolbar-deltasearch =>Toolbar.DeltaSearch
http://nicolascoolman.fr/pup-crossrider =>PUP.CrossRider
~ MSI: 3 link(s) detected in 00mn 00s



~ 2136 Legitimates filtered by white list
End of the scan (667 lines in 01mn 03s)(0.11)

Publicité


Signaler le contenu de ce document

Publicité