---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Clé\AppData\Roaming\Mozilla\Firefox\Profiles\6lyfic1c.default\prefs.js
M3 - MFPP: Plugins - [Clé] -- C:\Users\Clé\AppData\Roaming\Mozilla\Firefox\Profiles\6lyfic1c.default\searchplugins\ecosia.xml
M0 - MFSP: prefs.js [Clé - 6lyfic1c.default]
http://www.ecosia.org
M2 - MFEP: Extension [Clé - 6lyfic1c.default] {b0e1b4a6-2c6f-4e99-94f2-8e625d7ae255}
M2 - MFEP: Extension [Clé - 6lyfic1c.default] {d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}
~ Firefox Browser: 9 Legitimates Filtered in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: (no name) - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Clé orpheline
O3 - Toolbar: (no name) - [HKLM]{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} Clé orpheline
~ Toolbar: Scanned in 00mn 00s
---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [RtHDVBg] . (.Realtek Semiconductor - HD Audio Background Process.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe =.Advanced Micro Devices, Inc
O4 - HKLM\..\Wow6432Node\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [ISBMgr.exe] . (.Sony Corporation - ISB Utility.) -- C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Wow6432Node\Run: [PMBVolumeWatcher] . (.Sony Corporation - Media Check Tool.) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =.Adobe Systems Incorporated
O4 - HKLM\..\Wow6432Node\Run: [Intel AppUp(R) center] . (.Intel Corporation - Intel Services Manager.) -- C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
O4 - HKLM\..\Wow6432Node\Run: [ZoneAlarm] . (.Check Point Software Technologies LTD - ZoneAlarm.) -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
O4 - HKLM\..\Wow6432Node\Run: [FrameFox Extensions] . (.Duuqu Group - FrameFox Extensions.) -- C:\Program Files (x86)\FrameFox\Extensions\InternetExplorer\framefox.exe =PUP.Duuqu
O4 - HKLM\..\Wow6432Node\Run: [Wondershare Helper Compact.exe] . (.Wondershare - Wondershare Studio.) -- C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =.Oracle Corporation
~ Application: Scanned in 00mn 00s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Send by Bluetooth to [64Bits] - {7815BE26-237D-41A8-A98F-F7BD75F71086} -- Clé orpheline
~ IE Extra Buttons: Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{34128399-5B30-445F-8A42-4A3CF8A81B99}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{77E9EB10-030E-4542-B1B1-6AA8AEBF5926}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{34128399-5B30-445F-8A42-4A3CF8A81B99}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{77E9EB10-030E-4542-B1B1-6AA8AEBF5926}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - AppInit_DLLs: . (...) - C:\Program Files (x86)\SEARCH~1\SEARCH~1\bin\SPVC64~1.dll (.not file.)
~ AppInit DLL: Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Duuqu Update Service (dqupdate) (dqupdate) . (.Duuqu Group - Duuqu Installer.) - C:\Program Files (x86)\Duuqu\Update\DuuquUpdate.exe =PUP.Duuqu
O23 - Service: McAfee AP Service (McAPExe) . (...) - C:\Program Files\McAfee\MSC\McAPexe.exe (.not file.)
~ Services: 18 Legitimates Filtered in 00mn 42s
---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk * ) - File not found
~ BEX: 1 Legitimates Filtered in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [BoxSoftwareUpdate] (...) -- C:\ProgramData\BoxUpdChk\updchk.exe (.not file.) [0] =Adware.Boxore
[MD5.136E913B1D3771B3535C3622C36B5E38] [APT] [DuuquUpdateTaskMachineCore] (.Duuqu Group.) -- C:\Program Files (x86)\Duuqu\Update\DuuquUpdate.exe [98360] =PUP.Duuqu
[MD5.136E913B1D3771B3535C3622C36B5E38] [APT] [DuuquUpdateTaskMachineUA] (.Duuqu Group.) -- C:\Program Files (x86)\Duuqu\Update\DuuquUpdate.exe [98360] =PUP.Duuqu
[MD5.00000000000000000000000000000000] [APT] [SoftwareUpdateTaskMachineUA] (...) -- C:\Program Files (x86)\Software\Update\SoftwareUpdate.exe (.not file.) [0] =Adware.Boxore
[MD5.00000000000000000000000000000000] [APT] [UnHackMe Task Scheduler] (...) -- F:\Nouveau dossier\UnHackMe\hackmon.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [VAIO Care Rescue Tool] (...) -- C:\Windows\Temp\VAIO Care Rescue Tool.vbs (.not file.) [0]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: DuuquUpdateTaskMachineCore - (.Duuqu Group.) -- C:\Windows\Tasks\DuuquUpdateTaskMachineCore.job [890] =PUP.Duuqu
O39 - APT: DuuquUpdateTaskMachineCore - (.Duuqu Group.) -- C:\Windows\System32\Tasks\DuuquUpdateTaskMachineCore [890] =PUP.Duuqu
O39 - APT: DuuquUpdateTaskMachineUA - (.Duuqu Group.) -- C:\Windows\Tasks\DuuquUpdateTaskMachineUA.job [894] =PUP.Duuqu
O39 - APT: DuuquUpdateTaskMachineUA - (.Duuqu Group.) -- C:\Windows\System32\Tasks\DuuquUpdateTaskMachineUA [894] =PUP.Duuqu
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GlaryInitialize 4 [340]
O39 - APT: SoftwareUpdateTaskMachineUA - (...) -- C:\Windows\Tasks\SoftwareUpdateTaskMachineUA.job [924]
O39 - APT: SoftwareUpdateTaskMachineUA - (...) -- C:\Windows\System32\Tasks\SoftwareUpdateTaskMachineUA [924]
~ Scheduled Task: 56 Legitimates Filtered in 00mn 07s
---\\ Logiciels installés (O42)
O42 - Logiciel: Audio Amplifier Free - (.DanDans Digital Media.) [HKLM][64Bits] -- Audio Amplifier Free_is1
O42 - Logiciel: Boxore Client - (.Boxore OU.) [HKLM][64Bits] -- {CA2B24FD-EE10-42B9-B049-AA80268E7E21} =Adware.Boxore
O42 - Logiciel: Complitly - (.Complitly.) [HKLM][64Bits] -- {4FFBB818-B13C-11E0-931D-B2664824019B}_is1 =Adware.PredictAd
O42 - Logiciel: FileLab Plugin 1.1.33 - (.FileLab.) [HKLM][64Bits] -- {6AC5F630-9453-433D-90FF-BB3A8E4F8960}
O42 - Logiciel: Freecorder 2.22 - (...) [HKLM][64Bits] -- Freecorder_1.0
O42 - Logiciel: Movica - (.SourceForge.) [HKLM][64Bits] -- {29D3713C-80BB-4D5A-B284-81A971EF1322}
~ Logic: 27 Legitimates Filtered in 00mn 01s
---\\ HKCU HKLM Software Keys
[HKCU\Software\Boxore] =Adware.Boxore
[HKCU\Software\Complitly] =Adware.PredictAd
[HKCU\Software\Conduit] =Toolbar.Conduit
[HKCU\Software\Duuqu] =PUP.Duuqu
[HKCU\Software\ShiningMorning]
[HKLM\Software\Conduit] =Toolbar.Conduit
[HKLM\Software\Internet Content Filter]
[HKLM\Software\ShiningMorning]
[HKLM\Software\Wow6432Node\Conduit] =Toolbar.Conduit
[HKLM\Software\Wow6432Node\Duuqu] =PUP.Duuqu
[HKLM\Software\Wow6432Node\SimplyGen] =Adware.PredictAd
[HKLM\Software\Wow6432Node\VBMZ] =PUP.Duuqu
~ Key Software: 328 Legitimates Filtered in 00mn 01s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 15/12/2013 - 11:48:41 - [0] ----D C:\Program Files (x86)\Boxore =Adware.Boxore
O43 - CFD: 14/12/2013 - 20:22:19 - [0] ----D C:\Program Files (x86)\BrowseSmart =PUP.BrowseSmart
O43 - CFD: 14/12/2013 - 17:49:20 - [] ----D C:\Program Files (x86)\Complitly =Adware.PredictAd
O43 - CFD: 14/12/2013 - 17:50:40 - [] ----D C:\Program Files (x86)\Conduit
O43 - CFD: 14/12/2013 - 19:10:25 - [] ----D C:\Program Files (x86)\Duuqu =PUP.Duuqu
O43 - CFD: 14/12/2013 - 19:11:05 - [] ----D C:\Program Files (x86)\FrameFox
O43 - CFD: 15/12/2013 - 11:25:45 - [] ----D C:\Program Files (x86)\MyPC Backup =PUP.MyPCBackup
O43 - CFD: 06/02/2014 - 14:09:58 - [] ----D C:\ProgramData\BoxUpdChk =Adware.Boxore
O43 - CFD: 15/12/2013 - 11:37:10 - [] ----D C:\ProgramData\Conduit
O43 - CFD: 29/03/2014 - 19:30:34 - [] ----D C:\ProgramData\FileLab
O43 - CFD: 28/03/2013 - 09:42:04 - [] ----D C:\ProgramData\Internet Content Filter
O43 - CFD: 29/03/2014 - 14:02:03 - [] ----D C:\Users\Clé\AppData\Roaming\Freecorder 8 Audio
O43 - CFD: 14/12/2013 - 19:24:22 - [] ----D C:\Users\Clé\AppData\Roaming\Freecorder 8 Converter
O43 - CFD: 14/12/2013 - 19:23:01 - [] ----D C:\Users\Clé\AppData\Roaming\Freecorder 8 Screen
O43 - CFD: 14/12/2013 - 20:20:30 - [] ----D C:\Users\Clé\AppData\Roaming\Freecorder 8 Video
O43 - CFD: 23/03/2014 - 19:33:34 - [] ----D C:\Users\Clé\AppData\Roaming\VideoEditor
O43 - CFD: 21/07/2014 - 19:59:28 - [] ----D C:\Users\Clé\AppData\Local\arw
O43 - CFD: 14/12/2013 - 17:59:44 - [0] ----D C:\Users\Clé\AppData\Local\Conduit
O43 - CFD: 14/12/2013 - 19:10:25 - [] ----D C:\Users\Clé\AppData\Local\Duuqu =PUP.Duuqu
~ Program Folder: 164 Legitimates Filtered in 00mn 00s
---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.EA20FD45372DE3F28B468D3F99AED35C] - 08/09/2014 - 19:32:03 ---A- - C:\Windows\Prefetch\DUUQUCRASHHANDLER.EXE-A9586592.pf =PUP.Duuqu
O45 - LFCP:[MD5.36E2338860683E4B05A481D8417D1D79] - 08/09/2014 - 19:32:03 ---A- - C:\Windows\Prefetch\DUUQUUPDATE.EXE-DF33C20A.pf =PUP.Duuqu
~ Prefetcher: 2 Legitimates Filtered in 00mn 00s
---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "DisableCAD"=1
~ MWPS: 18 Legitimates Filtered in 00mn 00s
---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 6 Legitimates Filtered in 00mn 00s
---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:07/08/2014 - 11:12:05 ---A- . (...) -- C:\Windows\System32\Drivers\aswHwid.sys [29208] =.ALWIL Software
O58 - SDL:07/08/2014 - 11:12:06 ---A- . (...) -- C:\Windows\System32\Drivers\aswRvrt.sys [65776] =.ALWIL Software
O58 - SDL:07/08/2014 - 11:12:06 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys [224896] =.ALWIL Software
O58 - SDL:21/05/2013 - 15:50:28 ---A- . (.Shenzhen Moyea Software - Virtual Audio Device.) -- C:\Windows\System32\Drivers\leawo_vad.sys [36120]
O58 - SDL:12/05/2014 - 20:30:41 ---A- . (...) -- C:\Windows\System32\Drivers\semav6thermal64ro.sys [13792]
O58 - SDL:26/07/2012 - 06:00:55 ---A- . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x64.) -- C:\Windows\System32\Drivers\stexstor.sys [30960]
O58 - SDL:19/03/2012 - 14:12:38 ---A- . (.ShiningMorning Inc. - Pas de description.) -- C:\Windows\System32\Drivers\vasdDev.sys [1454896]
O58 - SDL:13/06/2014 - 02:09:18 ---A- . (.Pas de propriétaire - 虚拟声卡驱动.) -- C:\Windows\System32\Drivers\wav_mixer.sys [23248]
~ Drivers: 81 Legitimates Filtered in 00mn 02s
---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 04/09/2014 - 21:10:03 ---A- . (...) -- C:\Users\Clé\Downloads\setup_11.0.3.7.x01_2014_08_27_05_43.exe [158605304]
~ 92 Fichiers temporaires (Temporary files)
~ 32 Fichiers cookies (Cookies files)
~ Files: 4 Legitimates Filtered in 00mn 02s
---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =.Nicolas Coolman
~ ADS: Scanned in 00mn 00s
---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s
---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("Smartbar.ConduitHomepagesList", ""); =Hijacker.SmartBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("Smartbar.ConduitSearchEngineList", ""); =Hijacker.SmartBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("Smartbar.ConduitSearchUrlList", ""); =Hijacker.SmartBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.BackPageActive", true); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.DockingPositionDown", false); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.SmartbarDisabled", false); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.SmartbarStateMinimaized", false); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.Visibility", true); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.backPageCapacity", 3); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.backPageCounter", 0); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.backPageDay", 23); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.backPageLastEvent", "1395418212416"); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.backPageMinInterval", 15); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.barcodeid", "131737"); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.countryiso", "fr"); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.downloadprovider", "yahooocch"); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.fromautoupdate", "false"); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.installationid", "e1770da3-dd2d-5621-4967-a2606473ec01"); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.installdate", "23/03/2014"); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.keepAliveLastevent", "1395591011"); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.lastExternalJsUpdate", "1395591070035"); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("extensions.helperbar.publisher", "yahoooc"); =PUP.HelperBar
O69 - SBI: prefs.js [Clé - 6lyfic1c.default] user_pref("plugin.state.npconduitfirefoxplugin", 2);
O69 - SBI: SearchScopes [HKCU] {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} [DefaultScope] - (Microsoft (Bing)) -
http://www.bing.com
~ Keys: Scanned in 00mn 00s
---\\ Enumère les codes produits des logiciels (PUC) (O90)
O90 - PUC: "098CCE33084C42149BB5AB630E521B02" . (.FrameFox Extensions 1.0.7.0.) -- C:\Windows\Installer\{33ECC890-C480-4124-B95B-BA36E025B120}\FrameFox.ico =PUP.FrameFox
O90 - PUC: "DF42B2AC01EE9B240B94AA0862E8E712" . (.Boxore Client.) -- C:\Windows\Installer\{CA2B24FD-EE10-42B9-B049-AA80268E7E21}\boxore.ico =Adware.Boxore
~ Update Products: 2 Legitimates Filtered in 00mn 00s
---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.09C0A82DBFE03EA3371A73609D678285] [WIS][14/12/2013] (.The Software Group - Software Update Helper.) -- C:\Windows\Installer\63837ec.msi [45056] =Adware.Boxore
[MD5.5FF2B0F7835519063800D9F2DB535131] [WIS][14/12/2013] (.QwertyBox Team - FrameFox Extensions 1.0.7.0 Setup.) -- C:\Windows\Installer\63fc934.msi [417792] =PUP.FrameFox
~ WIS: 2 Legitimates Filtered in 00mn 01s
---\\ Recherche de clés de registre Tracing (O100)
HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32 =PUP.MyPCBackup
HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS =PUP.MyPCBackup
HKLM\SOFTWARE\Microsoft\Tracing\InstTracker_RASAPI32 =Adware.PredictAd
HKLM\SOFTWARE\Microsoft\Tracing\InstTracker_RASMANCS =Adware.PredictAd
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Smartbar_RASAPI32 =Hijacker.SmartBar
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Smartbar_RASMANCS =Hijacker.SmartBar
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\vbmz10_RASAPI32 =PUP.Duuqu
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\vbmz10_RASMANCS =PUP.Duuqu
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\VisualBeeSilent_RASAPI32 =Adware.VisualBeeToolbar
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\VisualBeeSilent_RASMANCS =Adware.VisualBeeToolbar
~ BTK: 55 Legitimates Filtered in 00mn 00s
---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 26/08/2014 262320 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Auto 14/12/2013 98360 | (dqupdate) . (.Duuqu Group.) - C:\Program Files (x86)\Duuqu\Update\DuuquUpdate.exe =PUP.Duuqu
SS - | Demand 14/12/2013 98360 | (dqupdatem) . (.Duuqu Group.) - C:\Program Files (x86)\Duuqu\Update\DuuquUpdate.exe =PUP.Duuqu
SS - | Demand 12/10/2010 206072 | (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
SS - | Auto 10/07/1658 0 | (McAPExe) . (...) - C:\Program Files\McAfee\MSC\McAPexe.exe
SS - | Demand 16/10/2013 235216 | (McComponentHostServiceSony) . (.McAfee, Inc..) - C:\Program Files (x86)\Sony\MSS\3.8.130\McCHSvc.exe
SS - | Demand 30/07/2014 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 17/10/2012 623784 | (NetworkSupport) . (.Sony Corporation.) - C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkSupport.exe
SS - | Demand 15/10/2012 123616 | (SOHCImp) . (.Sony Corporation.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
SS - | Demand 15/10/2012 461024 | (SOHDms) . (.Sony Corporation.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
SS - | Demand 15/10/2012 78560 | (SOHDs) . (.Sony Corporation.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
SS - | Demand 10/07/1658 0 | (SophosVirusRemovalTool) . (...) - E:\SVRTservice.exe
SS - | Demand 01/12/2011 289952 | (SpfService) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
SS - | Demand 19/11/2013 377768 | (USER_ESRV_SVC) . (.Intel Corporation.) - C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
SS - | Demand 19/07/2012 476328 | (VAIO Power Management) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
SS - | Demand 28/09/2012 964608 | (VCFw) . (.Sony Corporation.) - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
SR - | Auto 21/12/2013 65432 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - c:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 22/10/2012 239616 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
SR - | Auto 05/11/2012 231040 | (AtherosSvc) . (.Qualcomm Atheros Commnucations.) - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
SR - | Auto 07/08/2014 50344 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
SR - | Auto 19/11/2013 377768 | (ESRV_SVC) . (.Intel Corporation.) - C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
SR - | Auto 09/10/2012 2445968 | (IconMan_R) . (.Realsil Microelectronics Inc..) - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
SR - | Auto 20/04/2012 635104 | (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe
SR - | Auto 27/06/2012 129856 | (Intel(R) ME Service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
SR - | Auto 25/06/2012 166720 | (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
SR - | Auto 17/07/2012 277824 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 27/07/2012 474208 | (PMBDeviceInfoProvider) . (.Sony Corporation.) - C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
SR - | Auto 19/11/2013 266168 | (SampleCollector) . (.Intel Corporation.) - C:\Program Files\Sony\VAIO Care\VCPerfService.exe
SR - | Auto 17/07/2012 365376 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 15/09/2012 67536 | (VAIO Event Service) . (.Sony Corporation.) - C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
SR - | Demand 20/02/2014 60504 | (VCService) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Care\VCService.exe
SR - | Auto 25/10/2013 2445816 | (vsmon) . (.Check Point Software Technologies LTD.) - C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
SR - | Demand 27/02/2014 1642544 | (VUAgent) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Update\vuagent.exe
SR - | Demand 10/07/1658 0 | (WinDefend) . (...) - C:\Program Files (x86)\Windows Defender\MsMpEng.exe
SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =.Microsoft Corporation
SR - | Demand 20/10/2012 29696 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 15/10/2013 50704 | (ZAPrivacyService) . (.Check Point Software Technologies, Ltd..) - C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
SR - | Auto 05/11/2012 323584 | (ZAtheros Bt and Wlan Coex Agent) . (.Atheros.) - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
~ Services: Scanned in 00mn 16s
---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Run by Clé at 08/09/2014 21:11:23
~ OS 64 not supported by MBR tool
~ MBR: 0 Legitimates Filtered in 00mn 00s
---\\ Scan Additionnel (O88)
Database Version : 13026 - (07/09/2014)
Clés trouvées (Keys found) : 25
Valeurs trouvées (Values found) : 1
Dossiers trouvés (Folders found) : 16
Fichiers trouvés (Files found) : 13
[HKLM\SYSTEM\CurrentControlSet\Services\dqupdate) (dqupdate] =PUP.Duuqu^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CA2B24FD-EE10-42B9-B049-AA80268E7E21}] =Adware.Boxore^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4FFBB818-B13C-11E0-931D-B2664824019B}_is1] =Adware.PredictAd^
[HKLM\Software\Classes\TypeLib\{01bcb858-2f62-4f06-a8f4-48f927c15333}] =Adware.PredictAd
[HKLM\Software\Classes\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}] =Adware.Agent
[HKLM\Software\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}] =Parasite.Pugi
[HKLM\Software\Wow6432Node\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}] =Parasite.Pugi
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\1C875DDE39636004CA8CDAEC335B4160] =Adware.PredictAd
[HKCU\Software\Boxore] =Adware.Boxore
[HKCU\Software\AppDataLow\Software\ConduitSearchScopes] =Toolbar.Conduit
[HKCU\Software\Complitly] =Adware.PredictAd
[HKLM\Software\Wow6432Node\SimplyGen] =Adware.PredictAd
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4FFBB818-B13C-11E0-931D-B2664824019B}_is1] =Adware.PredictAd
[HKLM\Software\Wow6432Node\VBMZ] =Toolbar.Conduit
[HKLM\Software\Classes\AppID\RegistryHelper.DLL] =Toolbar.Freecorder
[HKLM\Software\Classes\AppID\{544C2426-48FD-4C40-AE3B-31257FF334D0}] =Toolbar.Freecorder
[HKLM\Software\Wow6432Node\Classes\AppID\{544C2426-48FD-4C40-AE3B-31257FF334D0}] =Toolbar.Freecorder
[HKLM\Software\Classes\CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}] =Toolbar.Freecorder
[HKLM\Software\Classes\CLSID\{A4341726-E922-47bb-86A6-23F4F4F67342}] =Toolbar.Freecorder
[HKLM\Software\Classes\Interface\{B887CA3B-D82B-4A01-AD29-E97444D01CE6}] =Toolbar.Freecorder
[HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}] =PUP.OptimizerPro
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\38D5CDD0A851B3940A43CC50ABBA251C] =Adware.Boxore^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AAC05EAA51DC78A41A1DCE3B31038584] =Adware.Boxore^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BA71D41F6CC0B6247B05D473850A8AEA] =Adware.Boxore^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =Adware.Boxore^
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:FrameFox Extensions =PUP.Duuqu^
C:\Program Files (x86)\Boxore =Adware.Boxore^
C:\Program Files (x86)\BrowseSmart =PUP.BrowseSmart^
C:\Program Files (x86)\Complitly =Adware.PredictAd^
C:\Program Files (x86)\Duuqu =PUP.Duuqu^
C:\Program Files (x86)\MyPC Backup =PUP.MyPCBackup^
C:\ProgramData\BoxUpdChk =Adware.Boxore^
C:\Users\Clé\AppData\Local\Duuqu =PUP.Duuqu^
C:\Program Files (x86)\Conduit =Toolbar.Conduit
C:\Program Files (x86)\FrameFox =Toolbar.DeltaSearch
C:\Program Files (x86)\SearchProtect =Toolbar.Conduit
C:\Program Files (x86)\Software =Adware.Boxore
C:\ProgramData\Conduit =Toolbar.Conduit
C:\Users\Clé\AppData\Roaming\SearchProtect =Toolbar.Conduit
C:\Users\Clé\AppData\Local\Conduit =Toolbar.Conduit
C:\Users\Clé\AppData\Local\Software =Adware.Boxore
C:\Users\Clé\AppData\LocalLow\Conduit =Toolbar.Conduit
C:\Program Files (x86)\FrameFox\Extensions\InternetExplorer\framefox.exe =PUP.Duuqu^
C:\Program Files (x86)\Duuqu\Update\DuuquUpdate.exe =PUP.Duuqu^
C:\Windows\Tasks\DuuquUpdateTaskMachineCore.job =PUP.Duuqu^
C:\Windows\System32\Tasks\DuuquUpdateTaskMachineCore =PUP.Duuqu^
C:\Windows\Tasks\DuuquUpdateTaskMachineUA.job =PUP.Duuqu^
C:\Windows\System32\Tasks\DuuquUpdateTaskMachineUA =PUP.Duuqu^
[HKCU\Software\Conduit] =Toolbar.Conduit^
[HKCU\Software\Duuqu] =PUP.Duuqu^
[HKLM\Software\Conduit] =Toolbar.Conduit^
[HKLM\Software\Wow6432Node\Conduit] =Toolbar.Conduit^
[HKLM\Software\Wow6432Node\Duuqu] =PUP.Duuqu^
C:\Windows\Installer\63837ec.msi =Adware.Boxore^
C:\Windows\Installer\63fc934.msi =PUP.FrameFox^
~ Additionnel Scan: 223031 Items scanned in 00mn 47s
---\\ Informations complémentaires sur les modules
~
http://nicolascoolman.fr/r5-internet-ex ... ment-iepm/ =.Internet Explorer, Proxy Management (R5)
~
http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =.Internet Explorer Toolbars (O3)
~
http://nicolascoolman.fr/o4-application ... -registre/ =.Applications lancées au démarrage du système (O4)
~ AMI: 3 Legitimates Filtered in 00mn 00s
---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/pup-duuqu =PUP.Duuqu
http://nicolascoolman.fr/adware-boxore =Adware.Boxore
http://nicolascoolman.fr/adware-predictad =Adware.PredictAd
http://nicolascoolman.fr/toolbar-conduit =Toolbar.Conduit
http://nicolascoolman.fr/pup-browsesmart =PUP.BrowseSmart
http://nicolascoolman.fr/pup-mypcbackup =PUP.MyPCBackup
http://nicolascoolman.fr/hijacker-smartbar =Hijacker.SmartBar
http://nicolascoolman.fr/pup-helperbar =PUP.HelperBar
http://nicolascoolman.fr/pup-framefox =PUP.FrameFox
http://nicolascoolman.fr/adware-visualbeetoolbar =Adware.VisualBeeToolbar
http://nicolascoolman.fr/parasite-pugi =Parasite.Pugi
http://nicolascoolman.fr/pup-optimizerpro =PUP.OptimizerPro
http://nicolascoolman.fr/toolbar-deltasearch =Toolbar.DeltaSearch
~ MSI: 13 link(s) detected in 00mn 00s