FORUM D’ENTRAIDE INFORMATIQUE (FEI)
Site d’assistance et de sécurité informatique

Aide à la désinfection (pages publicitaires, moteur de recherche remplacé, redirections, virus...).
Règles du forum : Entraide concernant la désinfection et la sécurité informatique : en cas de publicités intempestives, pop-up, redirections, logiciels indésirables, ralentissements suspects, virus, etc.
Une désinfection complète vous sera assurée : désinfection, sécurisation, puis prévention.
Seuls les helpers (personnes qualifiées et formées à la désinfection) ainsi que le staff sont autorisés à apporter leur aide dans cette section.
Merci également de prendre connaissance de la charte générale du forum.
  • Avatar du membre
  • Avatar du membre
Avatar du membre
par clochette83
#100836
Bonjour,
comme pas mal de personnes sur ce forum je me retrouve infectée par le "virus" awsomeph.
J'ai tenté de le supprimer, mais je ne suis pas une pro donc j'ai échoué.
je ne sais plus quoi faire, ça me pourrri mon ordi.

Est ce que quelqu'un pourrai me donner quelques conseils?    

Merci d'avance

Clo
Avatar du membre
par clochette83
#100857
J'ai fait l'analyse avec ZHP Diag, voilà le rapport.
J'ai vu dans d'autres post que c'est ce qui été demandé...
Je me suis dis que ça pourrait aider.


~ Rapport de ZHPDiag v2014.1.25.26 - Nicolas Coolman (25/01/2014)
~ Lancé par Chloé (05/02/2014 15:11:59)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC):


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.16476
MFIE: Mozilla Firefox 26.0 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 7QJB7
Windows License : OK
~ Windows Remaining Initializations Number : 3
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Logiciels de protection du système
Avira Free Antivirus v14.0.2.286
Malwarebytes Anti-Malware version 1.75.0.1300
Windows Defender W7

---\\ Logiciels d'optimisation du système
CCleaner v3.28 =Piriform Ltd

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 11 Plugin
Adobe Reader XI
Java 7 Update 51

---\\ Informations sur le système
~ Processor: AMD64 Family 20 Model 1 Stepping 0, AuthenticAMD
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3818 MB (53% free)
System Restore: Activé (Enable)
System drive C: has 242 GB (53%) free of 451 GB

---\\ Mode de connexion au système
~ Computer Name: CHLOÉ-PC
~ User Name: Chloé
~ All Users Names: HomeGroupUser$, Chloé, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Chloé\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Chloé\AppData\Roaming\
~ %Desktop% : C:\Users\Chloé\Desktop\
~ %Favorites% : C:\Users\Chloé\Favorites\
~ %LocalAppData% : C:\Users\Chloé\AppData\Local\
~ %StartMenu% : C:\Users\Chloé\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 242 Go of 451 Go)
D: CD-ROM drive (Free 0 Go of 0 Go)
Q: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
~ Security Center: 49 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.9B6678DB9C6A232C5A84D2FDFFF8B0E1] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.26/11/2013 - 08:07:57.) -- C:\Windows\System32\wininet.dll [2334208]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.20/11/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/09/2013 - 02:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 2/5495
~ Mes musiques (My Musics) : 1/5538
~ Mes Videos (My Videos) : 1/45
~ Mes Favoris (My Favorites) : 1/30
~ Mes Documents (My Documents) : 1/1394
~ Mon Bureau (My Desktop) : 1/18
~ Menu demarrer (Programs) : 1/30
~ Hidden Files: Scanned in 00mn 03s



---\\ Processus lancés
[MD5.896A1DB9A972AD2339C2E8569EC926D1] - (.Safer Networking Limited - System settings protector.) -- C:\Program Files (x86)\Spybot - Search Destroy\TeaTimer.exe [2144088] [PID.1800]
[MD5.B4446957BEC6BF9E6FC2B3FAAAE21BE5] - (.NTI Corporation - Acer Backup Manager.) -- C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [296768] [PID.1284]
[MD5.DED59B9CAFB20D0ABC4F15574209E09C] - (.Dritek System Inc. - Launch Manager.) -- C:\Program Files (x86)\Launch Manager\LManager.exe [1025616] [PID.1536]
[MD5.CDB517386A26AE420CB24BDB3CD88779] - (.Research In Motion Limited - Launch Agent Service.) -- C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [90448] [PID.1356]
[MD5.DD231039B13EC2ABDE315D76E658EF0E] - (.Avira Operations GmbH Co. KG - Antivirus System Tray Tool (Desktop).) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600] [PID.2120]
[MD5.5B6E8E09BE6401A7E022F52FDFCB2FF8] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336] [PID.2144]
[MD5.BAF535F843A3E790E04A7613811B55BC] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392] [PID.2152]
[MD5.0D2DB8305904E25300CBFD844A239315] - (.Dritek System Inc. - Launch Manager Worker.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe [287824] [PID.2192]
[MD5.1EEA6C1B35191DC177EA83672B9C3FC0] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [275568] [PID.4680]
[MD5.534A3CB0847BA114F0D8A5F2BB2EF6D0] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe [887432] [PID.2540]
[MD5.0DD74786D22EDFF0CE5B8E1B1E398618] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe [18544] [PID.3236]
[MD5.D8425B8D6DC2AA8D871363B0775BCF18] - (.Adobe Systems, Inc. - Adobe Flash Player 11.8 r800.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe [1861512] [PID.3752]
[MD5.CA25CAEEBDBE25D85565877219F684F8] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8339968] [PID.2544]
[MD5.FE79366FECD444A16CCA9979134DBEA8] - (.Avira Operations GmbH Co. KG - Antivirus Host Framework Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376] [PID.1452]
[MD5.B362181ED3771DC03B4141927C80F801] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65432] [PID.1976]
[MD5.FDE9C7030FB1E9E2715E113EE6A10F90] - (.Avira Operations GmbH Co. KG - Antivirus Host Framework Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376] [PID.1128]
[MD5.30E3850F303EAE5C364782EA78579CC9] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55624] [PID.1464]
[MD5.470F7F19188AB45463F8B612D6DDE7C8] - (.Dritek System Inc. - Dritek WMI Service.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe [311376] [PID.1584]
[MD5.CDCA791AFA0483F44BBA576DBFAFD04D] - (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.exe [102400] [PID.2084]
[MD5.0191DEE9B9EB7902AF2CF4F67301095D] - (.Acer Incorporated - Global Registration Service.) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [23584] [PID.2320]
[MD5.8F59A2506AF43F96F5397B3C79938AE9] - (.NTI Corporation - Backup Manager Module.) -- C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344] [PID.2404]
[MD5.39B1D0A636A400304565D4521FAD6D77] - (.Microsoft Corporation - Microsoft Application Virtualization Virtua.) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [207528] [PID.2636]
[MD5.506B0B498216371D64ABB69145B70E4C] - (...) -- C:\Program Files (x86)\Tor\tor.exe [3233806] [PID.2856]
[MD5.F9EC9ACD504D823D9B9CA98A4F8D3CA2] - (.Acer Group - Updater Service.) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232] [PID.2928]
[MD5.77C5A741A7452812F278EF2C18478862] - (.Microsoft Corporation - Microsoft Application Virtualization Client.) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [523944] [PID.888]
[MD5.FD557A50A65E44041CD2FCEF4BEB04DB] - (.Microsoft Corporation - Microsoft Office Client Virtualization Serv.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.exe [822504] [PID.3700]
~ Processes Running: Scanned in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Chloé\AppData\Roaming\Mozilla\Firefox\Profiles\ytrjg94w.default\prefs.js
C:\Users\Chloé\AppData\Roaming\Mozilla\Firefox\Profiles\ytrjg94w.default\user.js
M3 - MFPP: Plugins - [Chloé] -- C:\Users\Chloé\AppData\Roaming\Mozilla\Firefox\Profiles\ytrjg94w.default\searchplugins\babylon.xml =PUP.Babylon
M3 - MFPP: Plugins - [Chloé] -- C:\Users\Chloé\AppData\Roaming\Mozilla\Firefox\Profiles\ytrjg94w.default\searchplugins\conduit-search.xml =Toolbar.Conduit
M3 - MFPP: Plugins - [Chloé] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\awesomehp.xml =PUP.Awesomehp
M3 - MFPP: Plugins - [Chloé] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\babylon.xml =PUP.Babylon
~ Firefox Browser: 24 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com =PUP.Awesomehp
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com =PUP.Awesomehp
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com =PUP.Awesomehp
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com =PUP.Awesomehp
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com =PUP.Awesomehp
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com =PUP.Awesomehp
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com =PUP.Awesomehp
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com =PUP.Awesomehp
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com =PUP.Awesomehp
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com =PUP.Awesomehp
~ IE Browser: 20 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21



---\\ Autres liens utilisateurs (O4)
O4 - GS\Program [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\QuickLaunch [Chloé]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch [Chloé]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\TaskBar [Chloé]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Program [Chloé]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\SystemTools [Chloé]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe http://www.awesomehp.com =PUP.Awesomehp
O4 - GS\Desktop [Chloé]: CALVIN THOMAS.lnk . (...) -- C:\Users\Chloé\Documents\DOCU USUELS\CALVIN THOMAS
O4 - GS\Desktop [Chloé]: DOCUMENTS USUELS.lnk . (...) -- C:\Users\Chloé\Documents\DOCU USUELS
O4 - GS\Desktop [Chloé]: GROSESSE.lnk . (...) -- C:\Users\Chloé\Documents\DOCU USUELS\GROSESSE 20082014
O4 - GS\Desktop [Chloé]: JEUX.lnk . (...) -- C:\Users\Chloé\Documents\JEUX
O4 - GS\Desktop [Chloé]: SCAN.lnk - Clé orpheline
O4 - GS\Desktop [Chloé]: SERIES - Raccourci.lnk . (...) -- C:\Users\Chloé\Videos\SERIES
O4 - GS\Desktop [Chloé]: SUVI SERIES.impots.lnk . (...) -- C:\Users\Chloé\Documents\DOCU USUELS\LOISIRS\SUVI SERIES.xls
O4 - GS\Desktop [Chloé]: VIDEOS.lnk . (...) -- C:\Users\Chloé\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms
~ Global Startup: 70 Legitimates Filtered in 00mn 00s



---\\ Applications lancées au démarrage du sytème (O4)
O4 - HKLM\..\Run: [Acer ePower Management] . (.Acer Incorporated - ePowerTray.) -- C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.)
O4 - HKCU\..\Run: [SpybotSD TeaTimer] . (.Safer Networking Limited - System settings protector.) -- C:\Program Files (x86)\Spybot - Search Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [LiveSupport] C:\Program Files (x86)\LiveSupport\LiveSupport.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [BackupManagerTray] . (.NTI Corporation - Acer Backup Manager.) -- C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
O4 - HKLM\..\Wow6432Node\Run: [LManager] . (.Dritek System Inc. - Launch Manager.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe =.Advanced Micro Devices, Inc
O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Wow6432Node\Run: [RIMBBLaunchAgent.exe] . (.Research In Motion Limited - Launch Agent Service.) -- C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =.Adobe Systems Incorporated
O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH Co. KG - Antivirus System Tray Tool (Desktop).) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =.Oracle Corporation
O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =.Microsoft Corporation
O4 - HKUS\.DEFAULT\..\RunOnce: [IsMyWinLockerReboot] . (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\System32\msiexec.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [IsMyWinLockerReboot] . (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\System32\msiexec.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [IsMyWinLockerReboot] . (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\System32\msiexec.exe
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [IsMyWinLockerReboot] . (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\System32\msiexec.exe
O4 - HKUS\S-1-5-21-2814036381-2848721664-3518809906-1002\..\Run: [SpybotSD TeaTimer] . (.Safer Networking Limited - System settings protector.) -- C:\Program Files (x86)\Spybot - Search Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-2814036381-2848721664-3518809906-1002\..\Run: [LiveSupport] C:\Program Files (x86)\LiveSupport\LiveSupport.exe (.not file.)
~ Application: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A118C30-2CA8-4B2E-B4B4-C286496D948D}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{320B4790-73D2-4BB9-ADBB-2ADE05A08E8F}: DhcpNameServer = 192.168.10.110
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2CEDED8-4172-4D05-B473-9BFBDF81EE5E}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1A118C30-2CA8-4B2E-B4B4-C286496D948D}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{320B4790-73D2-4BB9-ADBB-2ADE05A08E8F}: DhcpNameServer = 192.168.10.110
O17 - HKLM\System\CS1\Services\Tcpip\..\{C2CEDED8-4172-4D05-B473-9BFBDF81EE5E}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{1A118C30-2CA8-4B2E-B4B4-C286496D948D}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{320B4790-73D2-4BB9-ADBB-2ADE05A08E8F}: DhcpNameServer = 192.168.10.110
O17 - HKLM\System\CS2\Services\Tcpip\..\{C2CEDED8-4172-4D05-B473-9BFBDF81EE5E}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - AppInit_DLLs: . (...) - c:\progra~3\bitguard\271832~1.68\{16cdf~1\loader.dll (.not file.) =PUP.BitGuard
~ AppInit DLL: Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Tor Win32 Service (tor) . (...) - C:\Program Files (x86)\Tor\tor.exe
O23 - Service: Updater Service (Updater Service) . (.Acer Group - Updater Service.) - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
~ Services: 16 Legitimates Filtered in 00mn 11s



---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [{7ED1A1AB-F778-4509-90AF-6224D251DF36}] (...) -- C:\Users\Chloé\Downloads\Install_HOSTS_Anti-Adware.exe (.not file.) [0]
~ Scheduled Task: 15 Legitimates Filtered in 00mn 04s



---\\ HKCU HKLM Software Keys
[HKCU\Software\BabSolution] =Hijacker.BabSolution
[HKCU\Software\BrowserMngr] =PUP.Babylon
[HKCU\Software\Code Industry]
[HKCU\Software\Code-Industry]
[HKCU\Software\DataMngr] =PUP.Datamngr
[HKCU\Software\DataMngr_Toolbar] =PUP.Datamngr
[HKCU\Software\FileScout] =PUP.FileScout
[HKCU\Software\InstallCore] =Adware.InstallCore
[HKLM\Software\Wow6432Node\Babylon] =PUP.Babylon
[HKLM\Software\Wow6432Node\DataMngr] =PUP.Datamngr
[HKLM\Software\Wow6432Node\SPCP]
[HKLM\Software\Wow6432Node\Wpm] =PUP.WpManager
[HKLM\Software\Wow6432Node\supTab]
[HKLM\Software\Wow6432Node\supWPM] =PUP.WpManager
~ Key Software: 271 Legitimates Filtered in 00mn 01s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 05/02/2014 - 14:41:32 - [0] ----D C:\Program Files (x86)\Plus-HD-7.6 =Adware.PlusHD
O43 - CFD: 05/02/2014 - 14:41:04 - [0,489] ----D C:\Program Files (x86)\SupTab
O43 - CFD: 05/02/2014 - 14:44:03 - [0] ----D C:\ProgramData\boost_interprocess
O43 - CFD: 05/02/2014 - 14:40:24 - [0] ----D C:\ProgramData\IePluginService =Trojan.SProtector
O43 - CFD: 05/02/2014 - 14:41:41 - [0] ----D C:\ProgramData\WPM =PUP.WpManager
O43 - CFD: 16/06/2013 - 12:40:51 - [0,308] ----D C:\Users\Chloé\AppData\Roaming\File Scout =PUP.FileScout
O43 - CFD: 05/02/2014 - 13:23:25 - [0,222] ----D C:\Users\Chloé\AppData\Roaming\iSafe =Trojan.Staser
O43 - CFD: 16/09/2013 - 16:59:31 - [0,009] ----D C:\Users\Chloé\AppData\Roaming\{90140011-0066-040C-0000-0000000FF1CE}
O43 - CFD: 06/09/2011 - 18:24:03 - [0] ----D C:\Users\Chloé\AppData\Local\PDF Maker
O43 - CFD: 13/07/2012 - 20:51:18 - [0,002] -SH-D C:\Users\Chloé\AppData\Local\{6490b7d9-dbb8-d5b6-d82b-a03c76dc5dc0}
~ 37 Dossiers CLSID vides (CLSID Empty Folders)
~ Program Folder: 262 Legitimates Filtered in 00mn 04s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 03/02/2014 - 21:42:29 ---A- . (...) -- C:\END [0]
O44 - LFC:[MD5.71C2517ABA69D1B7964163FFEB6A40BF] - 05/02/2014 - 12:39:04 ---A- . (...) -- C:\Windows\wininit.ini [835]
O44 - LFC:[MD5.F862CD08F1AD4EE39BD506853F3C6103] - 24/01/2014 - 18:51:38 ---A- . (...) -- C:\Windows\System32\ieuinit.inf [16284]
~ Files: 72 Legitimates Filtered in 00mn 04s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 17 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 4 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
O58 - SDL:[MD5.BBC89DA4065BDCE34257BE95B2F636EE] - 01/08/2012 - 19:13:42 ---A- . (.AnchorFree Inc. - Hotspot Shield Routing Driver.) -- C:\Windows\System32\Drivers\hssdrv6.sys [41704]
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
O58 - SDL:[MD5.B70DF208E97536CA9F29289E609F5B16] - 01/08/2012 - 19:13:40 ---A- . (.AnchorFree Inc - TAP-Win32 Virtual Network Driver.) -- C:\Windows\System32\Drivers\taphss.sys [38632]
O58 - SDL:[MD5.C9E9D59C0099A9FF51697E9306A44240] - 13/12/2012 - 13:50:36 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\Drivers\usbaapl64.sys [54784]
~ Drivers: 17 Legitimates Filtered in 00mn 01s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- c:\program files (x86)\mozilla firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- c:\program files\internet explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("avg.install.userHPSettings", "http://search.babylon.com/?affID=113357 ... =3433576d0[...] =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("avg.install.userSPSettings", "Search the web (Babylon)"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("browser.search.order.1", "Search the web (Babylon)"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar.admin", false); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar.aflt", "babsst"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar.dfltLng", "en"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar.excTlbr", false); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar.id", "3433576d00000000000018f46ad23b5b"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar.instlDay", "15620"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar.instlRef", "sst"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar.tlbrId", "tb9"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "http://search.babylon.com/?babsrc=TB_de ... 18f46ad23b[...] =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar.vrsn", "1.8.0.7"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar.vrsni", "1.8.0.7"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar_i.newTab", true); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar_i.newTabUrl", "abouthome"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.0.722:09:55"); =PUP.Babylon
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.crossrider.bic", "143f97c366e3c8e4841285c66145b38a"); =PUP.CrossRider
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("extensions.enabledItems", "{B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1,engine@conduit.com:3.2.5.2,{05eeb91a-aef7-4f8a-[...]
O69 - SBI: prefs.js [Chloé - ytrjg94w.default] user_pref("keyword.URL", "http://search.babylon.com/?affID=113357 ... 00000018f4[...] =PUP.Babylon
O69 - SBI: SearchScopes [HKCU] {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} - (Conduit Search) - http://search.conduit.com
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Search the web (Babylon)) - http://search.babylon.com =PUP.Babylon
O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} [DefaultScope] - (awesomehp) - http://www.awesomehp.com =PUP.Awesomehp
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.0D3B680986310AE5540578C0E481C6A0] [SPRF][03/03/2010] (...) -- C:\ProgramData\FullRemove.exe [131984]
[MD5.C67BCF6441E378371F0D6EEFB7EF0861] [SPRF][03/02/2014] (.Conduit - SP Usage Sender.) -- C:\Users\Chloé\AppData\Local\Temp\nsqE08.exe [167812] =Toolbar.Conduit
[MD5.0D9D952F7928398E35CDF107606C8426] [SPRF][05/02/2014] (.Pas de propriétaire - Installer.) -- C:\Users\Chloé\AppData\Local\Temp\setup__3815.exe [333312]
[MD5.0D9D952F7928398E35CDF107606C8426] [SPRF][05/02/2014] (.Pas de propriétaire - Installer.) -- C:\Users\Chloé\AppData\Local\Temp\setup__5872.exe [333312]
[MD5.CBF9C44A4C35599989CA8BDA97DDC586] [SPRF][05/02/2014] (...) -- C:\Users\Chloé\AppData\Local\Temp\uttDF19.tmp.bat [77]
~ Files: 5 Legitimates Filtered in 00mn 00s



---\\ Export de clés de registre aléatoires (O91)
[HKCU\Software\582dddab13bea15\2.6.1339.144\upd]:="upd=1" =PUP.Babylon
[HKCU\Software\582dddab13bea15\2.6.1519.190\upd]:="upd=1" =PUP.Babylon
[HKCU\Software\582dddab13bea15\2.6.1673.238\upd]:="upd=1" =PUP.Babylon
[HKCU\Software\582dddab13bea15\2.6.1694.246\upd]:="upd=" =PUP.Babylon
[HKCU\Software\582dddab13bea15\2.7.1769.27\upd]:="upd=" =PUP.Babylon
[HKCU\Software\582dddab13bea15\2.7.1832.68\upd]:="upd=" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.3.765.24]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.3.765.24]:version="2.3.765.24" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1123.78]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1123.78]:version="2.6.1123.78" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1125.80]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1125.80]:version="2.6.1125.80" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1249.132]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1249.132]:version="2.6.1249.132" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1339.144]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1339.144]:version="2.6.1339.144" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1519.190]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1519.190]:version="2.6.1519.190" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1673.238]:dllName="BitGuard.dll" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1673.238]:exeName="BitGuard.exe" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1673.238]:folderName="BitGuard" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1673.238]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1673.238]:serviceName="BitGuard" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1673.238]:version="2.6.1673.238" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1694.246]:dllName="BitGuard.dll" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1694.246]:exeName="BitGuard.exe" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1694.246]:folderName="BitGuard" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1694.246]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1694.246]:serviceName="BitGuard" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1694.246]:version="2.6.1694.246" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.7.1769.27]:SERVICE_NAME="BitGuard" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.7.1769.27]:dllName="BitGuard.dll" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.7.1769.27]:exeName="BitGuard.exe" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.7.1769.27]:folderName="BitGuard" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.7.1769.27]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.7.1769.27]:version="2.7.1769.27" =PUP.Babylon
[HKLM\Software\Wow6432Node\582dddab13bea15] = Clé orpheline
~ Export Key Software: Scanned in 00mn 00s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 20/12/2010 655624 | (FLEXnet Licensing Service) . (.Acresso Software Inc..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Demand 08/02/2011 136120 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
SS - | Demand 11/12/2013 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Auto 05/09/2013 171680 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SS - | Demand 11/12/2013 569768 | (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

SR - | Auto 21/12/2013 65432 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 09/11/2010 203776 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
SR - | Auto 18/11/2010 354304 | (AMD FUEL Service) . (.Advanced Micro Devices, Inc..) - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
SR - | Auto 17/06/2010 194496 | (AMD Reservation Manager) . (.Advanced Micro Devices.) - C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
SR - | Auto 19/12/2013 440376 | (AntiVirSchedulerService) . (.Avira Operations GmbH Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
SR - | Auto 27/11/2013 440376 | (AntiVirService) . (.Avira Operations GmbH Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
SR - | Auto 07/09/2013 55624 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 09/12/2010 311376 | (DsiWMIService) . (.Dritek System Inc..) - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
SR - | Auto 29/10/2010 868224 | (ePowerSvc) . (.Acer Incorporated.) - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
SR - | Auto 18/04/2006 102400 | (EPSON_PM_RPCV4_01) . (.SEIKO EPSON CORPORATION.) - C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.exe
SR - | Auto 08/01/2010 23584 | (GREGService) . (.Acer Incorporated.) - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
SR - | Demand 02/11/2013 641352 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 12/11/2010 257344 | (NTI IScheduleSvc) . (.NTI Corporation.) - C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
SR - | Auto 11/09/2013 3233806 | (tor) . (...) - C:\Program Files (x86)\Tor\tor.exe
SR - | Auto 29/01/2010 243232 | (Updater Service) . (.Acer Group.) - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =.Microsoft Corporation
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

~ Services: Scanned in 00mn 12s



---\\ Scan Additionnel (O88)
Database Version : 13030 - (25/01/2014)
Clés trouvées (Keys found) : 24
Valeurs trouvées (Values found) : 1
Dossiers trouvés (Folders found) : 10
Fichiers trouvés (Files found) : 17

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}] =PUP.Babylon
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =PUP.V9Software
[HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =PUP.V9Software
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =PUP.V9Software
[HKLM\Software\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}] =Adware.CDNHelper
[HKLM\Software\Wow6432Node\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}] =Adware.CDNHelper
[HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\HssSrv] =Toolbar.Agent
[HKCU\Software\BrowserMngr] =PUP.Babylon
[HKCU\Software\DataMngr] =Adware.Bandoo
[HKLM\Software\Wow6432Node\DataMngr] =Adware.Bandoo
[HKCU\Software\SpeedyPC Software] =PUP.SpeedyPC
[HKLM\Software\Wow6432Node\SpeedyPC Software] =PUP.SpeedyPC
[HKLM\Software\Wow6432Node\Microsoft\Tracing\MyBabylontb_RASAPI32] =PUP.Babylon
[HKLM\Software\Wow6432Node\Microsoft\Tracing\MyBabylontb_RASMANCS] =PUP.Babylon
[HKLM\Software\Wow6432Node\Microsoft\Tracing\Searchqu Toolbar uninstall_RASAPI32] =Adware.Bandoo
[HKLM\Software\Wow6432Node\Microsoft\Tracing\Searchqu Toolbar uninstall_RASMANCS] =Adware.Bandoo
[HKLM\Software\Classes\Prod.cap] =PUP.Babylon
[HKCU\Software\InstallCore] =Adware.InstallCore
[HKCU\Software\AppDataLow\Software\Crossrider] =PUP.CrossRider
[HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}] =PUP.OptimizerPro
[HKLM\Software\Wow6432Node\{1146AC44-2F03-4431-B4FD-889BC837521F}] =PUP.OptimizerPro
[HKLM\Software\Wow6432Node\Microsoft\Tracing\apnstub_RASAPI32] =Toolbar.Ask
[HKLM\Software\Wow6432Node\Microsoft\Tracing\apnstub_RASMANCS] =Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =Adware.Boxore^
C:\Program Files (x86)\Plus-HD-7.6 =Adware.PlusHD^
C:\ProgramData\IePluginService =Trojan.SProtector^
C:\ProgramData\WPM =PUP.WpManager^
C:\Users\Chloé\AppData\Roaming\File Scout =PUP.FileScout^
C:\Users\Chloé\AppData\Roaming\iSafe =Trojan.Staser^
C:\Program Files (x86)\Software =Adware.Boxore
C:\ProgramData\Software =Adware.Boxore
C:\ProgramData\SpeedyPC Software =PUP.SpeedyPC
C:\Users\Chloé\AppData\Roaming\SpeedyPC Software =PUP.SpeedyPC
C:\Users\Chloé\AppData\Local\Software =Adware.Boxore
[HKCU\Software\BabSolution] =Hijacker.BabSolution^
[HKCU\Software\DataMngr_Toolbar] =PUP.Datamngr^
[HKCU\Software\FileScout] =PUP.FileScout^
[HKLM\Software\Wow6432Node\Babylon] =PUP.Babylon^
[HKLM\Software\Wow6432Node\Wpm] =PUP.WpManager^
[HKLM\Software\Wow6432Node\supWPM] =PUP.WpManager^
C:\Users\Chloé\AppData\Local\Temp\nsqE08.exe =Toolbar.Conduit^
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.3.765.24]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon^
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1123.78]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon^
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1125.80]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon^
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1249.132]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon^
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1339.144]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon^
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1519.190]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =PUP.Babylon^
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1673.238]:dllName="BitGuard.dll" =PUP.Babylon^
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1694.246]:dllName="BitGuard.dll" =PUP.Babylon^
[HKCU\Software\582dddab13bea15\history\{16cdff19-861d-48e3-a751-d99a27784753}2.7.1769.27]:SERVICE_NAME="BitGuard" =PUP.Babylon^
~ Additionnel Scan: 274058 Items scanned in 00mn 45s



---\\ Récapitulatif des détections trouvées sur votre station
~ http://nicolascoolman.webs.com/apps/blo ... ar-babylon =PUP.Babylon
~ http://nicolascoolman.webs.com/apps/blo ... ar-conduit =Toolbar.Conduit
~ http://nicolascoolman.webs.com/apps/blo ... -awesomehp =PUP.Awesomehp
~ http://nicolascoolman.webs.com/apps/blo ... p-bitguard =PUP.BitGuard
~ http://nicolascoolman.webs.com/apps/blo ... absolution =Hijacker.BabSolution
~ http://nicolascoolman.webs.com/apps/blo ... p-datamngr =PUP.Datamngr
~ http://nicolascoolman.webs.com/apps/blo ... -filescout =PUP.FileScout
~ http://nicolascoolman.webs.com/apps/blo ... nstallcore =Adware.InstallCore
~ http://nicolascoolman.webs.com/apps/blo ... -wpmanager =PUP.WpManager
~ http://nicolascoolman.webs.com/apps/blo ... are-plushd =Adware.PlusHD
~ http://nicolascoolman.webs.com/apps/blo ... sprotector =Trojan.SProtector
~ http://nicolascoolman.webs.com/apps/blo ... jan-staser =Trojan.Staser
~ http://nicolascoolman.webs.com/apps/blo ... crossrider =PUP.CrossRider
~ http://nicolascoolman.webs.com/apps/blo ... v9software =PUP.V9Software
~ http://nicolascoolman.webs.com/apps/blo ... are-bandoo =Adware.Bandoo
~ http://nicolascoolman.webs.com/apps/blo ... p-speedypc =PUP.SpeedyPC
~ http://nicolascoolman.webs.com/apps/blo ... timizerpro =PUP.OptimizerPro
~ http://nicolascoolman.webs.com/apps/blo ... oolbar-ask =Toolbar.Ask
~ http://nicolascoolman.webs.com/apps/blo ... are-boxore =Adware.Boxore
~ MSI: 19 link(s) detected in 00mn 46s



~ 1266 Legitimates filtered by white list
End of the scan (574 lines in 01mn 56s)(0)
Avatar du membre
par clochette83
#100951
Re

Voici le rapport de ADW Cleaner

# AdwCleaner v3.018 - Rapport créé le 05/02/2014 à 18:47:14
# Mis à jour le 28/01/2014 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : Chloé - CHLOÉ-PC
# Exécuté depuis : C:\Users\Chloé\Downloads\adwcleaner.exe
# Option : Nettoyer

***** [ Services ] *****

Service Supprimé : CltMngSvc

***** [ Fichiers / Dossiers ] *****

Dossier Supprimé : C:\ProgramData\boost_interprocess
Dossier Supprimé : C:\ProgramData\SpeedyPC Software
Dossier Supprimé : C:\Program Files (x86)\Nosibay
Dossier Supprimé : C:\Program Files (x86)\Searchprotect
Dossier Supprimé : C:\Users\Chloé\Qtrax
Dossier Supprimé : C:\Users\Chloé\AppData\Local\PackageAware
Dossier Supprimé : C:\Users\Chloé\AppData\Local\Searchprotect
Dossier Supprimé : C:\Users\Chloé\AppData\Roaming\DriverCure
Dossier Supprimé : C:\Users\Chloé\AppData\Roaming\file scout
Dossier Supprimé : C:\Users\Chloé\AppData\Roaming\Nosibay
Dossier Supprimé : C:\Users\Chloé\AppData\Roaming\SpeedyPC Software
Dossier Supprimé : C:\Users\Chloé\Documents\optimizer pro
Dossier Supprimé : C:\Program Files (x86)\Software
Fichier Supprimé : C:\END
Fichier Supprimé : C:\Users\Chloé\AppData\Roaming\Mozilla\Firefox\Profiles\ytrjg94w.default\bProtector_extensions.rdf
Fichier Supprimé : C:\Users\Chloé\AppData\Roaming\Mozilla\Firefox\Profiles\ytrjg94w.default\searchplugins\Babylon.xml
Fichier Supprimé : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Babylon.xml
Fichier Supprimé : C:\Users\Chloé\AppData\Roaming\Mozilla\Firefox\Profiles\ytrjg94w.default\searchplugins\conduit-search.xml
Fichier Supprimé : C:\Users\Chloé\AppData\Roaming\Mozilla\Firefox\Profiles\ytrjg94w.default\user.js
Fichier Supprimé : C:\Windows\System32\Tasks\Browser Manager

***** [ Raccourcis ] *****


***** [ Registre ] *****

Valeur Supprimée : HKCU\Software\Microsoft\Internet Explorer\Main [BrowserMngr Start Page]
Valeur Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [BrowserMngrDefaultScope]
Clé Supprimée : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Clé Supprimée : HKLM\SOFTWARE\Classes\Prod.cap
Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASAPI32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASMANCS
Clé Supprimée : HKCU\Software\582dddab13bea15
Clé Supprimée : HKLM\SOFTWARE\582dddab13bea15
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Clé Supprimée : HKCU\Software\BabSolution
Clé Supprimée : HKCU\Software\BrowserMngr
Clé Supprimée : HKCU\Software\DataMngr
[#] Clé Supprimée : HKCU\Software\DataMngr_Toolbar
Clé Supprimée : HKCU\Software\filescout
Clé Supprimée : HKCU\Software\InstallCore
Clé Supprimée : HKCU\Software\Nosibay
Clé Supprimée : HKCU\Software\SpeedyPC Software
Clé Supprimée : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Clé Supprimée : HKCU\Software\AppDataLow\Software\Crossrider
Clé Supprimée : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Clé Supprimée : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Clé Supprimée : HKLM\Software\Babylon
Clé Supprimée : HKLM\Software\DataMngr
Clé Supprimée : HKLM\Software\SearchProtect
Clé Supprimée : HKLM\Software\SpeedyPC Software
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Donnée Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll
Donnée Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\bitguard\271832~1.68\{16cdf~1\loader.dll
Donnée Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\bitguard\271769~1.27\{16cdf~1\loader.dll

***** [ Navigateurs ] *****

-\\ Internet Explorer v11.0.9600.16428

Paramètre Restauré : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v26.0 (fr)

[ Fichier : C:\Users\Chloé\AppData\Roaming\Mozilla\Firefox\Profiles\ytrjg94w.default\prefs.js ]

Ligne Supprimée : user_pref("avg.install.userHPSettings", "hxxp://search.babylon.com/?affID=113357tt=071012_24_4012_4babsrc=HP_ssmntrId=3433576d00000000000018f46ad23b5b");
Ligne Supprimée : user_pref("avg.install.userSPSettings", "Search the web (Babylon)");
Ligne Supprimée : user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3314958octid=EB_ORIGINAL_CTIDSearchSource=69CUI=SSPV=Lay=1UM=4UP=SPDE0437C5-3BE1-4EA1-A60A-CFBFAF4035D8");
Ligne Supprimée : user_pref("browser.search.order.1", "Search the web (Babylon)");
Ligne Supprimée : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3314958octid=EB_ORIGINAL_CTIDSearchSource=55CUI=UM=4UP=SPDE0437C5-3BE1-4EA1-A60A-CFBFAF4035D8SSPV=");
Ligne Supprimée : user_pref("extensions.BabylonToolbar.admin", false);
Ligne Supprimée : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Ligne Supprimée : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");
Ligne Supprimée : user_pref("extensions.BabylonToolbar.dfltLng", "en");
Ligne Supprimée : user_pref("extensions.BabylonToolbar.excTlbr", false);
Ligne Supprimée : user_pref("extensions.BabylonToolbar.id", "3433576d00000000000018f46ad23b5b");
Ligne Supprimée : user_pref("extensions.BabylonToolbar.instlDay", "15620");
Ligne Supprimée : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Ligne Supprimée : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Ligne Supprimée : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Ligne Supprimée : user_pref("extensions.BabylonToolbar.tlbrId", "tb9");
Ligne Supprimée : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_defmntrId=3433576d00000000000018f46ad23b5bq=");
Ligne Supprimée : user_pref("extensions.BabylonToolbar.vrsn", "1.8.0.7");
Ligne Supprimée : user_pref("extensions.BabylonToolbar.vrsni", "1.8.0.7");
Ligne Supprimée : user_pref("extensions.BabylonToolbar_i.newTab", true);
Ligne Supprimée : user_pref("extensions.BabylonToolbar_i.newTabUrl", "abouthome");
Ligne Supprimée : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Ligne Supprimée : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.0.722:09:55");
Ligne Supprimée : user_pref("extensions.crossrider.bic", "143f97c366e3c8e4841285c66145b38a");
Ligne Supprimée : user_pref("extensions.enabledItems", "{B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1,engine@conduit.com:3.2.5.2,{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}:3.2.5.2,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.[...]
Ligne Supprimée : user_pref("keyword.URL", "hxxp://search.babylon.com/?affID=113357tt=071012_24_4012_4babsrc=KW_ssmntrId=3433576d00000000000018f46ad23b5bq=");
Ligne Supprimée : user_pref("browser.search.selectedEngine", "Conduit Search");

*************************

AdwCleaner[R0].txt - [9515 octets] - [05/02/2014 18:43:50]
AdwCleaner[S0].txt - [8699 octets] - [05/02/2014 18:47:14]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8759 octets] ##########
Avatar du membre
par 2011N2
#100974
Re,

T'es allé voir sous C:\Shortcut_Module_XX_XX_XX.txt ?
Y'a forcément un rapport.

Et la désinfection n'est pas terminée même si tu ne vois plus l'infection, car ton PC est toujours infecté.

Gabriel.
Avatar du membre
par clochette83
#100977
oui oui , quand je dis que ça a fonctionné je parle du logiciel.
Je suis bien allée dans le dossier, il n'y a rien qui ressemble a ce rapport.

y'a 3 images, et 2 .exe


Je l'ai trouvé ailleurs..... lol

Le voici

¤¤¤¤¤¤¤¤¤¤ | Shortcut_Module | g3n-h@ckm@n | 02.02.2014.2

¤¤¤¤¤ XP | Vista | 7 | 8 - 32/64 bits ¤¤¤¤¤ - Start 18:52:06 - 05/02/2014

Mis à jour le : 02/02/2014 | 18.25 par g3n-h@ckm@n

Contact : http://www.sosvirus.net

Boot : Normal

Système : Windows 7 Home Premium (64 bits) HomePremium Service Pack 1

Mémoire RAM = Total (MB) : 3911 | Libre (MB) : 2428
Pagefile = Total (MB) : 7819 | Libre (MB) : 6116
Virtuelle = Total (MB) : 4194 | Libre (MB) : 4055

¤¤¤¤¤¤¤¤¤¤ | Mises à jour Windows

Aucune mise à jour détectée !!!


(804) -- atiesrxx.exe
(1092) -- atieclxx.exe
(1236) -- spoolsv.exe
(1256) -- taskeng.exe
(1416) -- taskhost.exe
(1604) -- explorer.exe
(1808) -- armsvc.exe
(1856) -- AMD Reservation Manager.exe
(1980) -- AppleMobileDeviceService.exe
(2000) -- ePowerTray.exe
(2012) -- SynTPEnh.exe
(2028) -- TeaTimer.exe
(1456) -- mDNSResponder.exe
(1484) -- BackupManagerTray.exe
(2104) -- LManager.exe
(2116) -- dsiwmis.exe
(2176) -- ePowerSvc.exe
(2204) -- MMDx64Fx.exe
(2252) -- E_S30RP1.EXE
(2280) -- LMworker.exe
(2288) -- RIMBBLaunchAgent.exe
(2416) -- jusched.exe
(2428) -- iTunesHelper.exe
(2452) -- GREGsvc.exe
(2492) -- IScheduleSvc.exe
(2792) -- sftvsa.exe
(3008) -- tor.exe
(3048) -- UpdaterService.exe
(2168) -- WLIDSVC.EXE
(2448) -- Fuel.Service.exe
(2548) -- sftlist.exe
(2156) -- WLIDSVCM.EXE
(3644) -- ePowerEvent.exe
(3684) -- CVHSVC.EXE
(3736) -- firefox.exe
(3292) -- SearchIndexer.exe
(3936) -- MOM.exe
(1036) -- iPodService.exe
(3068) -- SearchProtocolHost.exe
(3464) -- SearchFilterHost.exe
(4580) -- wmpnetwk.exe
(5012) -- SynTPHelper.exe
(4916) -- CCC.exe

¤¤¤¤¤¤¤¤¤¤ | Détournements de raccourcis

Désinfecté : C:\Users\Chloé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://www.awesomehp.com/?type=scts=1391602808 ... 6B70UDZ2LX)

¤¤¤¤¤¤¤¤¤¤ | Détournement internet Explorer

Réparé : [HKU\S-1-5-21-2814036381-2848721664-3518809906-1002\Software\Microsoft\Internet Explorer\Main]|[Start Page] : http://www.google.com - http://www.google.com/
Réparé : [HKU\S-1-5-21-2814036381-2848721664-3518809906-1002\Software\Microsoft\Internet Explorer\Main]|[Local Page] : C:\Windows\system32\blank.htm - C:\Windows\SysWOW64\blank.htm
Réparé : [HKU\S-1-5-21-2814036381-2848721664-3518809906-1002\Software\Microsoft\Internet Explorer\Main]|[Search Page] : http://go.microsoft.com/fwlink/?LinkId=54896 - http://www.microsoft.com/isapi/redir.dl ... r=iesearch
Réparé : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Start Page] : http://www.awesomehp.com/?type=hpts=139 ... 6B70UDZ2LX - http://go.microsoft.com/fwlink/?LinkId=69157
Réparé : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Search_URL] : http://www.awesomehp.com/web/?type=dsts ... earchTerms} - http://go.microsoft.com/fwlink/?LinkId=54896
Réparé : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Page_URL] : http://www.awesomehp.com/?type=hpts=139 ... 6B70UDZ2LX - http://go.microsoft.com/fwlink/?LinkId=69157
Réparé : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Search Page] : http://www.awesomehp.com/web/?type=dsts ... earchTerms} - http://go.microsoft.com/fwlink/?LinkId=54896
Réparé : [HKLM64\Software\Microsoft\Internet Explorer\Main]|[Start Page] : http://www.awesomehp.com/?type=hpts=139 ... 6B70UDZ2LX - http://go.microsoft.com/fwlink/?LinkId=69157
Réparé : [HKLM64\Software\Microsoft\Internet Explorer\Main]|[Local Page] : C:\Windows\System32\blank.htm - C:\Windows\SysWOW64\blank.htm
Réparé : [HKLM64\Software\Microsoft\Internet Explorer\Main]|[Default_Search_URL] : http://www.awesomehp.com/web/?type=dsts ... earchTerms} - http://go.microsoft.com/fwlink/?LinkId=54896
Réparé : [HKLM64\Software\Microsoft\Internet Explorer\Main]|[Default_Page_URL] : http://www.awesomehp.com/?type=hpts=139 ... 6B70UDZ2LX - http://go.microsoft.com/fwlink/?LinkId=69157
Réparé : [HKLM64\Software\Microsoft\Internet Explorer\Main]|[Search Page] : http://www.awesomehp.com/web/?type=dsts ... earchTerms} - http://go.microsoft.com/fwlink/?LinkId=54896
Réparé : [HKU\S-1-5-21-2814036381-2848721664-3518809906-1002\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[WarnonZoneCrossing] : 0 - 1

¤¤¤¤¤¤¤¤¤¤ | Détournement Google Chrome


¤¤¤¤¤¤¤¤¤¤ | Détournement Firefox


¤¤¤¤¤¤¤¤¤¤ | Détournement des clés StartMenuInternet

Réparé : [HKLM\Software\Clients\StartMenuInternet\IExplore.exe\shell\open\command] : "c:\program files\internet explorer\iexplore.exe" - "C:\Program Files (x86)\Internet Explorer\iexplore.exe"

¤¤¤¤¤¤¤¤¤¤ | Détournement Javascript


¤¤¤¤¤¤¤¤¤¤ | Fichiers temporaires

[Default User] Fichiers temporaires Supprimés : 0 Ko
[All Users] Fichiers temporaires Supprimés : 0 Ko
[Default] Fichiers temporaires Supprimés : 0 Ko
[Administrator] Fichiers temporaires Supprimés : 0 Ko
[Public] Fichiers temporaires Supprimés : 0 Ko
[Invité] Fichiers temporaires Supprimés : 53 Ko
[LUIS] Fichiers temporaires Supprimés : 0 Ko
[Chloé] Fichiers temporaires Supprimés : 63577 Ko


¤¤¤¤¤¤¤¤¤¤ |EOF| ¤¤¤¤¤¤¤¤¤¤
Avatar du membre
par clochette83
#100991
rapport

~ Rapport de ZHPDiag v2014.1.25.26 - Nicolas Coolman (25/01/2014)
~ Lancé par Chloé (05/02/2014 19:38:21)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.16476
MFIE: Mozilla Firefox 26.0 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows Vista (TM) Ultimate, 64-bit Service Pack 1 (Build 6000)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 7QJB7
Windows License : OK
~ Windows Remaining Initializations Number : 3
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK

---\\ Logiciels de protection du système
Avira Free Antivirus v14.0.2.286

---\\ Logiciels d'optimisation du système
CCleaner v3.28 =Piriform Ltd

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 11 Plugin
Adobe Reader XI
Java 7 Update 51

---\\ Informations sur le système
~ Processor: AMD64 Family 20 Model 1 Stepping 0, AuthenticAMD
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3818 MB (59% free)
System Restore: Activé (Enable)
System drive C: has 241 GB (53%) free of 451 GB

---\\ Mode de connexion au système
~ Computer Name: CHLOÉ-PC
~ User Name: Chloé
~ All Users Names: HomeGroupUser$, Chloé, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Chloé\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Chloé\AppData\Roaming\
~ %Desktop% : C:\Users\Chloé\Desktop\
~ %Favorites% : C:\Users\Chloé\Favorites\
~ %LocalAppData% : C:\Users\Chloé\AppData\Local\
~ %StartMenu% : C:\Users\Chloé\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 241 Go of 451 Go)
D: CD-ROM drive (Free 0 Go of 0 Go)
Q: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
~ Security Center: 49 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.9B6678DB9C6A232C5A84D2FDFFF8B0E1] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.26/11/2013 - 08:07:57.) -- C:\Windows\System32\wininet.dll [2334208]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.20/11/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/09/2013 - 02:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 01s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 2/5495
~ Mes musiques (My Musics) : 1/5538
~ Mes Videos (My Videos) : 1/45
~ Mes Favoris (My Favorites) : 1/30
~ Mes Documents (My Documents) : 1/1393
~ Mon Bureau (My Desktop) : 1/19
~ Menu demarrer (Programs) : 1/31
~ Hidden Files: Scanned in 00mn 09s



---\\ Processus lancés
[MD5.896A1DB9A972AD2339C2E8569EC926D1] - (.Safer Networking Limited - System settings protector.) -- C:\Program Files (x86)\Spybot - Search Destroy\TeaTimer.exe [2144088] [PID.564]
[MD5.B4446957BEC6BF9E6FC2B3FAAAE21BE5] - (.NTI Corporation - Acer Backup Manager.) -- C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [296768] [PID.2080]
[MD5.DED59B9CAFB20D0ABC4F15574209E09C] - (.Dritek System Inc. - Launch Manager.) -- C:\Program Files (x86)\Launch Manager\LManager.exe [1025616] [PID.2112]
[MD5.0D2DB8305904E25300CBFD844A239315] - (.Dritek System Inc. - Launch Manager Worker.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe [287824] [PID.2176]
[MD5.CDB517386A26AE420CB24BDB3CD88779] - (.Research In Motion Limited - Launch Agent Service.) -- C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [90448] [PID.2208]
[MD5.DD231039B13EC2ABDE315D76E658EF0E] - (.Avira Operations GmbH Co. KG - Antivirus System Tray Tool (Desktop).) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600] [PID.2256]
[MD5.5B6E8E09BE6401A7E022F52FDFCB2FF8] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336] [PID.2280]
[MD5.BAF535F843A3E790E04A7613811B55BC] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392] [PID.2296]
[MD5.1EEA6C1B35191DC177EA83672B9C3FC0] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [275568] [PID.4936]
[MD5.0DD74786D22EDFF0CE5B8E1B1E398618] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe [18544] [PID.2908]
[MD5.D8425B8D6DC2AA8D871363B0775BCF18] - (.Adobe Systems, Inc. - Adobe Flash Player 11.8 r800.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe [1861512] [PID.2992]
[MD5.7BCC6D6A58C120E6CDCB4FB654A9EA1B] - (.BitTorrent Inc. - µTorrent.) -- C:\Users\Chloé\AppData\Roaming\uTorrent\uTorrent.exe [1307736] [PID.2736] =P2P.BitTorrent
[MD5.1FDBBD2F2CF2D11E6247734797DEC3C9] - (.Microsoft Corporation - Microsoft Office Client Virtualization Hand.) -- C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.exe [3207912] [PID.2872]
[MD5.F2C82BA7E80C6054D5D20F3FBD4CFD34] - (...) -- C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe [77664] [PID.2452]
[MD5.CA25CAEEBDBE25D85565877219F684F8] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8339968] [PID.3236]
[MD5.FE79366FECD444A16CCA9979134DBEA8] - (.Avira Operations GmbH Co. KG - Antivirus Host Framework Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376] [PID.1400]
[MD5.B362181ED3771DC03B4141927C80F801] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65432] [PID.1800]
[MD5.FDE9C7030FB1E9E2715E113EE6A10F90] - (.Avira Operations GmbH Co. KG - Antivirus Host Framework Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376] [PID.1900]
[MD5.30E3850F303EAE5C364782EA78579CC9] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55624] [PID.1924]
[MD5.470F7F19188AB45463F8B612D6DDE7C8] - (.Dritek System Inc. - Dritek WMI Service.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe [311376] [PID.972]
[MD5.CDCA791AFA0483F44BBA576DBFAFD04D] - (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.exe [102400] [PID.2052]
[MD5.0191DEE9B9EB7902AF2CF4F67301095D] - (.Acer Incorporated - Global Registration Service.) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [23584] [PID.2164]
[MD5.8F59A2506AF43F96F5397B3C79938AE9] - (.NTI Corporation - Backup Manager Module.) -- C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344] [PID.2248]
[MD5.39B1D0A636A400304565D4521FAD6D77] - (.Microsoft Corporation - Microsoft Application Virtualization Virtua.) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [207528] [PID.2668]
[MD5.506B0B498216371D64ABB69145B70E4C] - (...) -- C:\Program Files (x86)\Tor\tor.exe [3233806] [PID.3016]
[MD5.F9EC9ACD504D823D9B9CA98A4F8D3CA2] - (.Acer Group - Updater Service.) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232] [PID.2024]
[MD5.77C5A741A7452812F278EF2C18478862] - (.Microsoft Corporation - Microsoft Application Virtualization Client.) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [523944] [PID.2860]
[MD5.FD557A50A65E44041CD2FCEF4BEB04DB] - (.Microsoft Corporation - Microsoft Office Client Virtualization Serv.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.exe [822504] [PID.3704]
~ Processes Running: Scanned in 00mn 01s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Chloé\AppData\Roaming\Mozilla\Firefox\Profiles\ytrjg94w.default\prefs.js
M3 - MFPP: Plugins - [Chloé] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\awesomehp.xml =PUP.Awesomehp
~ Firefox Browser: 20 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com =PUP.Awesomehp
~ IE Browser: 19 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21



---\\ Autres liens utilisateurs (O4)
O4 - GS\Program [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\QuickLaunch [Chloé]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch [Chloé]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\QuickLaunch [Chloé]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Chloé\AppData\Roaming\uTorrent\uTorrent.exe =P2P.BitTorrent
O4 - GS\TaskBar [Chloé]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Program [Chloé]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\SystemTools [Chloé]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\Desktop [Chloé]: CALVIN THOMAS.lnk . (...) -- C:\Users\Chloé\Documents\DOCU USUELS\CALVIN THOMAS
O4 - GS\Desktop [Chloé]: DOCUMENTS USUELS.lnk . (...) -- C:\Users\Chloé\Documents\DOCU USUELS
O4 - GS\Desktop [Chloé]: GROSESSE.lnk . (...) -- C:\Users\Chloé\Documents\DOCU USUELS\GROSESSE 20082014
O4 - GS\Desktop [Chloé]: JEUX.lnk . (...) -- C:\Users\Chloé\Documents\JEUX
O4 - GS\Desktop [Chloé]: SCAN.lnk - Clé orpheline
O4 - GS\Desktop [Chloé]: SERIES - Raccourci.lnk . (...) -- C:\Users\Chloé\Videos\SERIES
O4 - GS\Desktop [Chloé]: SUVI SERIES.impots.lnk . (...) -- C:\Users\Chloé\Documents\DOCU USUELS\LOISIRS\SUVI SERIES.xls
O4 - GS\Desktop [Chloé]: VIDEOS.lnk . (...) -- C:\Users\Chloé\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms
O4 - GS\Desktop [Chloé]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Chloé\AppData\Roaming\uTorrent\uTorrent.exe =P2P.BitTorrent
~ Global Startup: 71 Legitimates Filtered in 00mn 03s



---\\ Applications lancées au démarrage du sytème (O4)
O4 - HKLM\..\Run: [Acer ePower Management] . (.Acer Incorporated - ePowerTray.) -- C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.)
O4 - HKCU\..\Run: [SpybotSD TeaTimer] . (.Safer Networking Limited - System settings protector.) -- C:\Program Files (x86)\Spybot - Search Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [LiveSupport] C:\Program Files (x86)\LiveSupport\LiveSupport.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [BackupManagerTray] . (.NTI Corporation - Acer Backup Manager.) -- C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
O4 - HKLM\..\Wow6432Node\Run: [LManager] . (.Dritek System Inc. - Launch Manager.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe =.Advanced Micro Devices, Inc
O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Wow6432Node\Run: [RIMBBLaunchAgent.exe] . (.Research In Motion Limited - Launch Agent Service.) -- C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =.Adobe Systems Incorporated
O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH Co. KG - Antivirus System Tray Tool (Desktop).) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =.Oracle Corporation
O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =.Microsoft Corporation
O4 - HKUS\.DEFAULT\..\RunOnce: [IsMyWinLockerReboot] . (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\System32\msiexec.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [IsMyWinLockerReboot] . (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\System32\msiexec.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [IsMyWinLockerReboot] . (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\System32\msiexec.exe
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [IsMyWinLockerReboot] . (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\System32\msiexec.exe
O4 - HKUS\S-1-5-21-2814036381-2848721664-3518809906-1002\..\Run: [SpybotSD TeaTimer] . (.Safer Networking Limited - System settings protector.) -- C:\Program Files (x86)\Spybot - Search Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-2814036381-2848721664-3518809906-1002\..\Run: [LiveSupport] C:\Program Files (x86)\LiveSupport\LiveSupport.exe (.not file.)
~ Application: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A118C30-2CA8-4B2E-B4B4-C286496D948D}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{320B4790-73D2-4BB9-ADBB-2ADE05A08E8F}: DhcpNameServer = 192.168.10.110
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2CEDED8-4172-4D05-B473-9BFBDF81EE5E}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1A118C30-2CA8-4B2E-B4B4-C286496D948D}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{320B4790-73D2-4BB9-ADBB-2ADE05A08E8F}: DhcpNameServer = 192.168.10.110
O17 - HKLM\System\CS1\Services\Tcpip\..\{C2CEDED8-4172-4D05-B473-9BFBDF81EE5E}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{1A118C30-2CA8-4B2E-B4B4-C286496D948D}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{320B4790-73D2-4BB9-ADBB-2ADE05A08E8F}: DhcpNameServer = 192.168.10.110
O17 - HKLM\System\CS2\Services\Tcpip\..\{C2CEDED8-4172-4D05-B473-9BFBDF81EE5E}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Tor Win32 Service (tor) . (...) - C:\Program Files (x86)\Tor\tor.exe
O23 - Service: Updater Service (Updater Service) . (.Acer Group - Updater Service.) - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
~ Services: 16 Legitimates Filtered in 00mn 23s



---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [{7ED1A1AB-F778-4509-90AF-6224D251DF36}] (...) -- C:\Users\Chloé\Downloads\Install_HOSTS_Anti-Adware.exe (.not file.) [0]
~ Scheduled Task: 15 Legitimates Filtered in 00mn 22s



---\\ HKCU HKLM Software Keys
[HKCU\Software\Code Industry]
[HKCU\Software\Code-Industry]
[HKLM\Software\Wow6432Node\SPCP]
[HKLM\Software\Wow6432Node\Shortcut_Module]
[HKLM\Software\Wow6432Node\Wpm] =PUP.WpManager
[HKLM\Software\Wow6432Node\supTab]
[HKLM\Software\Wow6432Node\supWPM] =PUP.WpManager
~ Key Software: 260 Legitimates Filtered in 00mn 01s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 05/02/2014 - 14:41:32 - [0] ----D C:\Program Files (x86)\Plus-HD-7.6 =Adware.PlusHD
O43 - CFD: 05/02/2014 - 14:41:04 - [0,489] ----D C:\Program Files (x86)\SupTab
O43 - CFD: 05/02/2014 - 19:09:14 - [0] ----D C:\ProgramData\boost_interprocess
O43 - CFD: 05/02/2014 - 14:40:24 - [0] ----D C:\ProgramData\IePluginService =Trojan.SProtector
O43 - CFD: 05/02/2014 - 14:41:41 - [0] ----D C:\ProgramData\WPM =PUP.WpManager
O43 - CFD: 05/02/2014 - 13:23:25 - [0,222] ----D C:\Users\Chloé\AppData\Roaming\iSafe =Trojan.Staser
O43 - CFD: 16/09/2013 - 16:59:31 - [0,009] ----D C:\Users\Chloé\AppData\Roaming\{90140011-0066-040C-0000-0000000FF1CE}
O43 - CFD: 06/09/2011 - 18:24:03 - [0] ----D C:\Users\Chloé\AppData\Local\PDF Maker
O43 - CFD: 13/07/2012 - 20:51:18 - [0,002] -SH-D C:\Users\Chloé\AppData\Local\{6490b7d9-dbb8-d5b6-d82b-a03c76dc5dc0}
~ 37 Dossiers CLSID vides (CLSID Empty Folders)
~ Program Folder: 253 Legitimates Filtered in 00mn 58s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.71C2517ABA69D1B7964163FFEB6A40BF] - 05/02/2014 - 12:39:04 ---A- . (...) -- C:\Windows\wininit.ini [835]
O44 - LFC:[MD5.F862CD08F1AD4EE39BD506853F3C6103] - 24/01/2014 - 18:51:38 ---A- . (...) -- C:\Windows\System32\ieuinit.inf [16284]
~ Files: 70 Legitimates Filtered in 01mn 10s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnablELUA"=0
~ MWPS: 18 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 4 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
O58 - SDL:[MD5.BBC89DA4065BDCE34257BE95B2F636EE] - 01/08/2012 - 19:13:42 ---A- . (.AnchorFree Inc. - Hotspot Shield Routing Driver.) -- C:\Windows\System32\Drivers\hssdrv6.sys [41704]
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
O58 - SDL:[MD5.B70DF208E97536CA9F29289E609F5B16] - 01/08/2012 - 19:13:40 ---A- . (.AnchorFree Inc - TAP-Win32 Virtual Network Driver.) -- C:\Windows\System32\Drivers\taphss.sys [38632]
O58 - SDL:[MD5.C9E9D59C0099A9FF51697E9306A44240] - 13/12/2012 - 13:50:36 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\Drivers\usbaapl64.sys [54784]
~ Drivers: 18 Legitimates Filtered in 00mn 47s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- c:\program files (x86)\mozilla firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.0D3B680986310AE5540578C0E481C6A0] [SPRF][03/03/2010] (...) -- C:\ProgramData\FullRemove.exe [131984]
~ Files: 1 Legitimates Filtered in 00mn 00s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 20/12/2010 655624 | (FLEXnet Licensing Service) . (.Acresso Software Inc..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Demand 08/02/2011 136120 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
SS - | Demand 11/12/2013 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Auto 05/09/2013 171680 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SS - | Demand 11/12/2013 569768 | (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

SR - | Auto 21/12/2013 65432 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 09/11/2010 203776 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
SR - | Auto 18/11/2010 354304 | (AMD FUEL Service) . (.Advanced Micro Devices, Inc..) - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
SR - | Auto 17/06/2010 194496 | (AMD Reservation Manager) . (.Advanced Micro Devices.) - C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
SR - | Auto 19/12/2013 440376 | (AntiVirSchedulerService) . (.Avira Operations GmbH Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
SR - | Auto 27/11/2013 440376 | (AntiVirService) . (.Avira Operations GmbH Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
SR - | Auto 07/09/2013 55624 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 09/12/2010 311376 | (DsiWMIService) . (.Dritek System Inc..) - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
SR - | Auto 29/10/2010 868224 | (ePowerSvc) . (.Acer Incorporated.) - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
SR - | Auto 18/04/2006 102400 | (EPSON_PM_RPCV4_01) . (.SEIKO EPSON CORPORATION.) - C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.exe
SR - | Auto 08/01/2010 23584 | (GREGService) . (.Acer Incorporated.) - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
SR - | Demand 02/11/2013 641352 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 12/11/2010 257344 | (NTI IScheduleSvc) . (.NTI Corporation.) - C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
SR - | Auto 11/09/2013 3233806 | (tor) . (...) - C:\Program Files (x86)\Tor\tor.exe
SR - | Auto 29/01/2010 243232 | (Updater Service) . (.Acer Group.) - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =.Microsoft Corporation
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

~ Services: Scanned in 00mn 17s



---\\ Scan Additionnel (O88)
Database Version : 13030 - (25/01/2014)
Clés trouvées (Keys found) : 3
Valeurs trouvées (Values found) : 2
Dossiers trouvés (Folders found) : 6
Fichiers trouvés (Files found) : 3

[HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\HssSrv] =Toolbar.Agent
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Browser Manager] =PUP.Babylon
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =Adware.Boxore^
C:\Program Files (x86)\Plus-HD-7.6 =Adware.PlusHD^
C:\ProgramData\IePluginService =Trojan.SProtector^
C:\ProgramData\WPM =PUP.WpManager^
C:\Users\Chloé\AppData\Roaming\iSafe =Trojan.Staser^
C:\ProgramData\Software =Adware.Boxore
C:\Users\Chloé\AppData\Local\Software =Adware.Boxore
C:\Users\Chloé\AppData\Roaming\uTorrent\uTorrent.exe =P2P.BitTorrent^
[HKLM\Software\Wow6432Node\Wpm] =PUP.WpManager^
[HKLM\Software\Wow6432Node\supWPM] =PUP.WpManager^
~ Additionnel Scan: 273414 Items scanned in 01mn 32s



---\\ Récapitulatif des détections trouvées sur votre station
~ http://nicolascoolman.webs.com/apps/blo ... -awesomehp =PUP.Awesomehp
~ http://nicolascoolman.webs.com/apps/blo ... -wpmanager =PUP.WpManager
~ http://nicolascoolman.webs.com/apps/blo ... are-plushd =Adware.PlusHD
~ http://nicolascoolman.webs.com/apps/blo ... sprotector =Trojan.SProtector
~ http://nicolascoolman.webs.com/apps/blo ... jan-staser =Trojan.Staser
~ http://nicolascoolman.webs.com/apps/blo ... ar-babylon =PUP.Babylon
~ http://nicolascoolman.webs.com/apps/blo ... are-boxore =Adware.Boxore
~ MSI: 7 link(s) detected in 01mn 32s



~ 1242 Legitimates filtered by white list
End of the scan (427 lines in 06mn 29s)(0)
Avatar du membre
par clochette83
#101007
voilou!

Rapport de ZHPFix 2014.1.17.2 par Nicolas Coolman, Update du 17/01/2014
Fichier d'export Registre :
Run by Chloé at 05/02/2014 20:04:20
High Elevated Privileges : OK
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)

Corbeille vidée (00mn 06s)
Dossier Prefetcher vidé

========== Clés du Registre ==========
SUPPRIMÉ: HKLM\Software\Wow6432Node\Wpm
SUPPRIMÉ: HKLM\Software\Wow6432Node\supTab
SUPPRIMÉ: HKLM\Software\Wow6432Node\supWPM
SUPPRIMÉ:* HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Browser Manager
SUPPRIMÉ:* HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC
SUPPRIMÉ: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\HssSrv

========== Valeurs du Registre ==========
SUPPRIMÉ RunValue: SpybotSD TeaTimer
SUPPRIMÉ RunValue: LiveSupport

========== Eléments de donnée du Registre ==========
SUPPRIMÉ: R1 Search Page =

========== Dossiers ==========
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{02CBD26D-9427-47C2-9B8A-75B950856682}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{0E2249FC-1912-46E4-8732-6DB97A5D3AB3}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{1ADA2B92-1C2A-4767-9F45-2D408383B083}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{1EA15910-8A67-4991-B52C-6CC5BEC0EF29}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{1FFBEBAF-88D0-4A6D-B04A-32FF969FA714}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{2AB8BDA4-2C92-4844-ACC0-13FB9A5EA127}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{35627227-F270-40D1-B05F-725E6A6C3D02}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{3909F289-98DA-4544-BCB7-76E524F7C3AD}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{3E7F2058-2F24-4ECC-8C64-8B7C76A1C5C7}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{420BF484-CC06-4E9C-A099-B819E63743FD}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{45841834-6F05-4A3F-B71A-A66A13CDB7E5}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{53F946A7-09C3-463F-BAED-9BAF5592EBF9}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{669C08A9-E2F5-48C1-BAD5-8E8A5BFE7F63}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{7C8877FD-6302-47CB-A8E8-F9FBCCC26863}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{7DA8EE08-0C1F-4AFB-8B0F-39A1C9E4224C}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{8E277548-AB5F-4925-90CE-FE92357CA79E}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{985D503C-7654-47D4-AC48-B6E1E1B36330}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{A50C928E-04CA-4AB2-B748-C62C8645C680}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{B2F43306-C6E0-4D90-B944-B94B4D04B34A}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{B37D6C18-DF8B-43A4-8426-1454DFF51F20}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{B6D80CFD-A6FE-4F59-9CE2-245C6543E5D5}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{C7B90FF2-780F-426D-81C9-F4C5495A19D3}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{C8E7EA01-0B15-433A-9C55-CA8E20561AB6}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{CCB09170-CB70-4C38-9468-D74976B79145}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{CE87DF46-6DF8-4DA6-8101-2E4394513334}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{D075DB64-5278-4650-A5E9-BCC80409B2E7}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{D67108B7-968A-4B6C-9433-0FD46B8108DD}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{DAA191A7-B617-4558-8FDF-E3154BE03D82}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{DEF1F379-A277-4636-B348-801982705DCC}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{E397AB93-1F39-4331-8BC2-5DC3E707AC62}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{E490299B-D3F1-42D8-B23B-13C18EDC5AEF}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{E4E3B813-3550-4BD3-A247-74B01D9B7E52}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{ECE864C1-1E41-4F0B-A377-D0FF753102D4}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{ED55EAFF-7F68-40EC-8C3E-C13C130C9248}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{F118C348-CFFB-46D1-89F2-5D9A87769103}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{F9AF77DA-009D-4DFF-8EDB-4FFAE387F22F}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{FDBFA995-CC68-42D0-8D75-A1BBEEBA189D}
SUPPRIMÉ: C:\Users\Chloé\AppData\Local\{FF73A0CE-4440-4C74-9356-C10E6E604C83}

========== Fichiers ==========
SUPPRIMÉ: c:\program files (x86)\mozilla firefox\searchplugins\awesomehp.xml
SUPPRIMÉS Temporaires Windows (13) (786 916 octets)
SUPPRIMÉS Flash Cookies (0) (0 octets)

========== Tache planifiée ==========
SUPPRIMÉ: {7ED1A1AB-F778-4509-90AF-6224D251DF36}

========== Restauration Système ==========
Point de restauration du système créé avec succès


========== Récapitulatif ==========
6 : Clés du Registre
2 : Valeurs du Registre
1 : Eléments de donnée du Registre
38 : Dossiers
3 : Fichiers
1 : Tache planifiée
1 : Restauration Système


End of clean in 01mn 05s

========== Chemin de fichier rapport ==========
C:\Users\Chloé\AppData\Roaming\ZHP\ZHPFix[R1].txt - 05/02/2014 20:04:26 [4686]
Avatar du membre
par clochette83
#101255
Bonjour!

Voici le rapport

Malwarebytes Anti-Malware (Essai) 1.75.0.1300
http://www.malwarebytes.org

Version de la base de données: v2014.02.05.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Chloé :: CHLOÉ-PC [administrateur]

Protection: Activé

05/02/2014 20:13:51
mbam-log-2014-02-05 (20-13-51).txt

Type d'examen: Examen complet (C:\|Q:\|)
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 579126
Temps écoulé: 3 heure(s), 36 minute(s), 9 seconde(s)

Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Clé(s) du Registre détectée(s): 1
HKLM\Software\awesomehpSoftware (PUP.Optional.Awesomehp.A) - Mis en quarantaine et supprimé avec succès.

Valeur(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)

Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)

Dossier(s) détecté(s): 0
(Aucun élément nuisible détecté)

Fichier(s) détecté(s): 13
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\Main\bin\CltMngSvc.exe.vir (PUP.Optional.Conduit.A) - Mis en quarantaine et supprimé avec succès.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\Main\bin\SPTool.dll.vir (PUP.Optional.Conduit.A) - Mis en quarantaine et supprimé avec succès.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\Main\bin\uninstall.exe.vir (PUP.Optional.Conduit.A) - Mis en quarantaine et supprimé avec succès.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\cltmng.exe.vir (PUP.Optional.Conduit.A) - Mis en quarantaine et supprimé avec succès.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPTool64.exe.vir (PUP.Optional.Conduit.A) - Mis en quarantaine et supprimé avec succès.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPVC32.dll.vir (PUP.Optional.Conduit.A) - Mis en quarantaine et supprimé avec succès.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPVC32Loader.dll.vir (PUP.Optional.Conduit.A) - Mis en quarantaine et supprimé avec succès.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPVC64.dll.vir (PUP.Optional.Conduit.A) - Mis en quarantaine et supprimé avec succès.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPVC64Loader.dll.vir (PUP.Optional.Conduit.A) - Mis en quarantaine et supprimé avec succès.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\UI\bin\cltmngui.exe.vir (PUP.Optional.Conduit.A) - Mis en quarantaine et supprimé avec succès.
C:\AdwCleaner\Quarantine\C\Users\Chloé\AppData\Roaming\file scout\filescout.exe.vir (PUP.Optional.FileScout.A) - Mis en quarantaine et supprimé avec succès.
C:\Users\Chloé\AppData\Roaming\ZHP\Quarantine\SupTab.DIR\SupTab.dll (PUP.Optional.SupTab.A) - Mis en quarantaine et supprimé avec succès.
C:\Users\Chloé\AppData\Roaming\Bubble Dock.boostrap.log (PUP.Optional.Bubbledock.A) - Mis en quarantaine et supprimé avec succès.

(fin)
Avatar du membre
par clochette83
#101545
voila:

~ Rapport de ZHPDiag v2014.1.25.26 - Nicolas Coolman (25/01/2014)
~ Lancé par Chloé (06/02/2014 20:34:54)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.16476
MFIE: Mozilla Firefox 26.0 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows Vista (TM) Ultimate, 64-bit Service Pack 1 (Build 6000)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 7QJB7
Windows License : OK
~ Windows Remaining Initializations Number : 3
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK

---\\ Logiciels de protection du système
Avira Free Antivirus v14.0.2.286
Malwarebytes Anti-Malware version 1.75.0.1300

---\\ Logiciels d'optimisation du système
CCleaner v3.28 =Piriform Ltd

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 11 Plugin
Adobe Reader XI
Java 7 Update 51

---\\ Informations sur le système
~ Processor: AMD64 Family 20 Model 1 Stepping 0, AuthenticAMD
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3818 MB (56% free)
System Restore: Activé (Enable)
System drive C: has 242 GB (53%) free of 451 GB

---\\ Mode de connexion au système
~ Computer Name: CHLOÉ-PC
~ User Name: Chloé
~ All Users Names: HomeGroupUser$, Chloé, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Chloé\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Chloé\AppData\Roaming\
~ %Desktop% : C:\Users\Chloé\Desktop\
~ %Favorites% : C:\Users\Chloé\Favorites\
~ %LocalAppData% : C:\Users\Chloé\AppData\Local\
~ %StartMenu% : C:\Users\Chloé\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 242 Go of 451 Go)
D: CD-ROM drive (Free 0 Go of 0 Go)
Q: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
~ Security Center: 49 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.9B6678DB9C6A232C5A84D2FDFFF8B0E1] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.26/11/2013 - 08:07:57.) -- C:\Windows\System32\wininet.dll [2334208]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.20/11/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/09/2013 - 02:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 2/5495
~ Mes musiques (My Musics) : 1/5537
~ Mes Videos (My Videos) : 1/44
~ Mes Favoris (My Favorites) : 1/30
~ Mes Documents (My Documents) : 1/1394
~ Mon Bureau (My Desktop) : 1/21
~ Menu demarrer (Programs) : 1/31
~ Hidden Files: Scanned in 00mn 14s



---\\ Processus lancés
[MD5.D1D5DAB39DCB4BE0359943738D87409B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [532040] [PID.2116]
[MD5.B4446957BEC6BF9E6FC2B3FAAAE21BE5] - (.NTI Corporation - Acer Backup Manager.) -- C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [296768] [PID.3636]
[MD5.DED59B9CAFB20D0ABC4F15574209E09C] - (.Dritek System Inc. - Launch Manager.) -- C:\Program Files (x86)\Launch Manager\LManager.exe [1025616] [PID.3696]
[MD5.CDB517386A26AE420CB24BDB3CD88779] - (.Research In Motion Limited - Launch Agent Service.) -- C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [90448] [PID.3972]
[MD5.DD231039B13EC2ABDE315D76E658EF0E] - (.Avira Operations GmbH Co. KG - Antivirus System Tray Tool (Desktop).) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600] [PID.3320]
[MD5.5B6E8E09BE6401A7E022F52FDFCB2FF8] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336] [PID.3420]
[MD5.BAF535F843A3E790E04A7613811B55BC] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392] [PID.3612]
[MD5.0D2DB8305904E25300CBFD844A239315] - (.Dritek System Inc. - Launch Manager Worker.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe [287824] [PID.512]
[MD5.1EEA6C1B35191DC177EA83672B9C3FC0] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [275568] [PID.2560]
[MD5.5DBDC85A9AB1C338E82DB4F118C04D6E] - (.Apple Inc. - distnoted.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe [13712] [PID.3960]
[MD5.F9DF3367F803C180D38EE2359264408C] - (.Apple Inc. - SyncServer.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe [55624] [PID.428]
[MD5.1FDBBD2F2CF2D11E6247734797DEC3C9] - (.Microsoft Corporation - Microsoft Office Client Virtualization Hand.) -- C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe [3207912] [PID.3872]
[MD5.F2C82BA7E80C6054D5D20F3FBD4CFD34] - (...) -- C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe [77664] [PID.5136]
[MD5.CA25CAEEBDBE25D85565877219F684F8] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8339968] [PID.5656]
[MD5.FE79366FECD444A16CCA9979134DBEA8] - (.Avira Operations GmbH Co. KG - Antivirus Host Framework Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376] [PID.1300]
[MD5.B362181ED3771DC03B4141927C80F801] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65432] [PID.1844]
[MD5.FDE9C7030FB1E9E2715E113EE6A10F90] - (.Avira Operations GmbH Co. KG - Antivirus Host Framework Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376] [PID.1936]
[MD5.30E3850F303EAE5C364782EA78579CC9] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55624] [PID.1964]
[MD5.470F7F19188AB45463F8B612D6DDE7C8] - (.Dritek System Inc. - Dritek WMI Service.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe [311376] [PID.1072]
[MD5.CDCA791AFA0483F44BBA576DBFAFD04D] - (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.exe [102400] [PID.1252]
[MD5.0191DEE9B9EB7902AF2CF4F67301095D] - (.Acer Incorporated - Global Registration Service.) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [23584] [PID.1400]
[MD5.65085456FD9A74D7F1A999520C299ECB] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376] [PID.1720]
[MD5.E0D7732F2D2E24B2DB3F67B6750295B8] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512] [PID.1808]
[MD5.8F59A2506AF43F96F5397B3C79938AE9] - (.NTI Corporation - Backup Manager Module.) -- C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344] [PID.2040]
[MD5.39B1D0A636A400304565D4521FAD6D77] - (.Microsoft Corporation - Microsoft Application Virtualization Virtua.) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [207528] [PID.2408]
[MD5.506B0B498216371D64ABB69145B70E4C] - (...) -- C:\Program Files (x86)\Tor\tor.exe [3233806] [PID.2488]
[MD5.F9EC9ACD504D823D9B9CA98A4F8D3CA2] - (.Acer Group - Updater Service.) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232] [PID.2548]
[MD5.77C5A741A7452812F278EF2C18478862] - (.Microsoft Corporation - Microsoft Application Virtualization Client.) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [523944] [PID.2868]
[MD5.FD557A50A65E44041CD2FCEF4BEB04DB] - (.Microsoft Corporation - Microsoft Office Client Virtualization Serv.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.exe [822504] [PID.2816]
~ Processes Running: Scanned in 00mn 03s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Chloé\AppData\Roaming\Mozilla\Firefox\Profiles\ytrjg94w.default\prefs.js
~ Firefox Browser: 20 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21



---\\ Autres liens utilisateurs (O4)
O4 - GS\Program [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\QuickLaunch [Chloé]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch [Chloé]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\QuickLaunch [Chloé]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Chloé\AppData\Roaming\uTorrent\uTorrent.exe =P2P.BitTorrent
O4 - GS\TaskBar [Chloé]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Program [Chloé]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\SystemTools [Chloé]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\Desktop [Chloé]: CALVIN THOMAS.lnk . (...) -- C:\Users\Chloé\Documents\DOCU USUELS\CALVIN THOMAS
O4 - GS\Desktop [Chloé]: DOCUMENTS USUELS.lnk . (...) -- C:\Users\Chloé\Documents\DOCU USUELS
O4 - GS\Desktop [Chloé]: GROSESSE.lnk . (...) -- C:\Users\Chloé\Documents\DOCU USUELS\GROSESSE 20082014
O4 - GS\Desktop [Chloé]: JEUX.lnk . (...) -- C:\Users\Chloé\Documents\JEUX
O4 - GS\Desktop [Chloé]: SCAN.lnk - Clé orpheline
O4 - GS\Desktop [Chloé]: SERIES - Raccourci.lnk . (...) -- C:\Users\Chloé\Videos\SERIES
O4 - GS\Desktop [Chloé]: SUVI SERIES.impots.lnk . (...) -- C:\Users\Chloé\Documents\DOCU USUELS\LOISIRS\SUVI SERIES.xls
O4 - GS\Desktop [Chloé]: VIDEOS.lnk . (...) -- C:\Users\Chloé\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms
O4 - GS\Desktop [Chloé]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Chloé\AppData\Roaming\uTorrent\uTorrent.exe =P2P.BitTorrent
~ Global Startup: 72 Legitimates Filtered in 00mn 07s



---\\ Applications lancées au démarrage du sytème (O4)
O4 - HKLM\..\Run: [Acer ePower Management] . (.Acer Incorporated - ePowerTray.) -- C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [BackupManagerTray] . (.NTI Corporation - Acer Backup Manager.) -- C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
O4 - HKLM\..\Wow6432Node\Run: [LManager] . (.Dritek System Inc. - Launch Manager.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe =.Advanced Micro Devices, Inc
O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Wow6432Node\Run: [RIMBBLaunchAgent.exe] . (.Research In Motion Limited - Launch Agent Service.) -- C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =.Adobe Systems Incorporated
O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH Co. KG - Antivirus System Tray Tool (Desktop).) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =.Oracle Corporation
O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =.Microsoft Corporation
O4 - HKUS\.DEFAULT\..\RunOnce: [IsMyWinLockerReboot] . (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\System32\msiexec.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [IsMyWinLockerReboot] . (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\System32\msiexec.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [IsMyWinLockerReboot] . (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\System32\msiexec.exe
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [IsMyWinLockerReboot] . (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\System32\msiexec.exe
~ Application: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A118C30-2CA8-4B2E-B4B4-C286496D948D}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{320B4790-73D2-4BB9-ADBB-2ADE05A08E8F}: DhcpNameServer = 192.168.10.110
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2CEDED8-4172-4D05-B473-9BFBDF81EE5E}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1A118C30-2CA8-4B2E-B4B4-C286496D948D}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{320B4790-73D2-4BB9-ADBB-2ADE05A08E8F}: DhcpNameServer = 192.168.10.110
O17 - HKLM\System\CS1\Services\Tcpip\..\{C2CEDED8-4172-4D05-B473-9BFBDF81EE5E}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{1A118C30-2CA8-4B2E-B4B4-C286496D948D}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{320B4790-73D2-4BB9-ADBB-2ADE05A08E8F}: DhcpNameServer = 192.168.10.110
O17 - HKLM\System\CS2\Services\Tcpip\..\{C2CEDED8-4172-4D05-B473-9BFBDF81EE5E}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Tor Win32 Service (tor) . (...) - C:\Program Files (x86)\Tor\tor.exe
O23 - Service: Updater Service (Updater Service) . (.Acer Group - Updater Service.) - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
~ Services: 18 Legitimates Filtered in 00mn 42s



---\\ HKCU HKLM Software Keys
[HKCU\Software\Code Industry]
[HKCU\Software\Code-Industry]
[HKLM\Software\Wow6432Node\SPCP]
[HKLM\Software\Wow6432Node\Shortcut_Module]
~ Key Software: 259 Legitimates Filtered in 00mn 01s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 06/02/2014 - 09:40:57 - [0] ----D C:\ProgramData\boost_interprocess
O43 - CFD: 16/09/2013 - 16:59:31 - [0,009] ----D C:\Users\Chloé\AppData\Roaming\{90140011-0066-040C-0000-0000000FF1CE}
O43 - CFD: 13/07/2012 - 20:51:18 - [0,002] -SH-D C:\Users\Chloé\AppData\Local\{6490b7d9-dbb8-d5b6-d82b-a03c76dc5dc0}
~ Program Folder: 208 Legitimates Filtered in 01mn 10s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.71C2517ABA69D1B7964163FFEB6A40BF] - 05/02/2014 - 12:39:04 ---A- . (...) -- C:\Windows\wininit.ini [835]
O44 - LFC:[MD5.F862CD08F1AD4EE39BD506853F3C6103] - 24/01/2014 - 18:51:38 ---A- . (...) -- C:\Windows\System32\ieuinit.inf [16284]
~ Files: 71 Legitimates Filtered in 01mn 34s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnablELUA"=0
~ MWPS: 18 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 4 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
O58 - SDL:[MD5.BBC89DA4065BDCE34257BE95B2F636EE] - 01/08/2012 - 19:13:42 ---A- . (.AnchorFree Inc. - Hotspot Shield Routing Driver.) -- C:\Windows\System32\Drivers\hssdrv6.sys [41704]
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
O58 - SDL:[MD5.B70DF208E97536CA9F29289E609F5B16] - 01/08/2012 - 19:13:40 ---A- . (.AnchorFree Inc - TAP-Win32 Virtual Network Driver.) -- C:\Windows\System32\Drivers\taphss.sys [38632]
O58 - SDL:[MD5.C9E9D59C0099A9FF51697E9306A44240] - 13/12/2012 - 13:50:36 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\Drivers\usbaapl64.sys [54784]
~ Drivers: 18 Legitimates Filtered in 00mn 02s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- c:\program files (x86)\mozilla firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.0D3B680986310AE5540578C0E481C6A0] [SPRF][03/03/2010] (...) -- C:\ProgramData\FullRemove.exe [131984]
~ Files: 1 Legitimates Filtered in 00mn 00s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 20/12/2010 655624 | (FLEXnet Licensing Service) . (.Acresso Software Inc..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Demand 08/02/2011 136120 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
SS - | Demand 11/12/2013 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Auto 05/09/2013 171680 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SS - | Demand 11/12/2013 569768 | (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

SR - | Auto 21/12/2013 65432 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 09/11/2010 203776 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
SR - | Auto 18/11/2010 354304 | (AMD FUEL Service) . (.Advanced Micro Devices, Inc..) - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
SR - | Auto 17/06/2010 194496 | (AMD Reservation Manager) . (.Advanced Micro Devices.) - C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
SR - | Auto 19/12/2013 440376 | (AntiVirSchedulerService) . (.Avira Operations GmbH Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
SR - | Auto 27/11/2013 440376 | (AntiVirService) . (.Avira Operations GmbH Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
SR - | Auto 07/09/2013 55624 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 09/12/2010 311376 | (DsiWMIService) . (.Dritek System Inc..) - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
SR - | Auto 29/10/2010 868224 | (ePowerSvc) . (.Acer Incorporated.) - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
SR - | Auto 18/04/2006 102400 | (EPSON_PM_RPCV4_01) . (.SEIKO EPSON CORPORATION.) - C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.exe
SR - | Auto 08/01/2010 23584 | (GREGService) . (.Acer Incorporated.) - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
SR - | Demand 02/11/2013 641352 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 04/04/2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
SR - | Auto 04/04/2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
SR - | Auto 12/11/2010 257344 | (NTI IScheduleSvc) . (.NTI Corporation.) - C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
SR - | Auto 11/09/2013 3233806 | (tor) . (...) - C:\Program Files (x86)\Tor\tor.exe
SR - | Auto 29/01/2010 243232 | (Updater Service) . (.Acer Group.) - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =.Microsoft Corporation
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

~ Services: Scanned in 00mn 24s



---\\ Scan Additionnel (O88)
Database Version : 13030 - (25/01/2014)
Clés trouvées (Keys found) : 0
Valeurs trouvées (Values found) : 2
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 0

~ Additionnel Scan: 272859 Items scanned in 01mn 34s



---\\ Récapitulatif des détections trouvées sur votre station
~ MSI: 0 link(s) detected in 01mn 34s



~ 1197 Legitimates filtered by white list
End of the scan (385 lines in 07mn 06s)(0)
Avatar du membre
par clochette83
#101585
delfix

# DelFix v10.6 - Rapport créé le 06/02/2014 à 21:12:52
# Mis à jour le 11/11/2013 par Xplode
# Nom d'utilisateur : Chloé - CHLOÉ-PC
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Activation de l'UAC ... OK

~ Suppression des outils de désinfection ...

Supprimé : C:\Shortcut_Module
Supprimé : C:\AdwCleaner
Supprimé : C:\Users\Chloé\AppData\Roaming\ZHP
Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
Supprimé : C:\Program Files (x86)\ZHPDiag
Supprimé : C:\Users\Chloé\Desktop\ZHPDiag.lnk
Supprimé : C:\Users\Chloé\Desktop\ZHPDiag.txt
Supprimé : C:\Users\Chloé\Desktop\ZHPFix.lnk
Supprimé : C:\Users\Chloé\Desktop\ZHPFixReport.txt
Supprimé : C:\Users\Chloé\Downloads\adwcleaner.exe
Supprimé : C:\Users\Chloé\Downloads\SecurityCheck.exe
Supprimé : C:\Users\Chloé\Downloads\ZHPDiag2.exe
Supprimée : HKLM\SOFTWARE\AdwCleaner
Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1

~ Sauvegarde de la base de registre ... OK

~ Purge de la restauration système ...

Supprimé : RP #404 [Windows Update | 02/01/2014 09:06:47]
Supprimé : RP #405 [Installed Java 7 Update 51 | 02/01/2014 10:23:44]
Supprimé : RP #406 [Windows Update | 02/04/2014 16:24:37]
Supprimé : RP #407 [ZHPFix Restore System Point | 02/05/2014 19:03:46]

Nouveau point de restauration créé !

~ Réinitialisation des paramètres système ... OK

########## - EOF - ##########
Avatar du membre
par clochette83
#101597
security check

Results of screen317's Security Check version 0.99.79
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
Avira Desktop
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
Java(TM) 6 Update 31
Java 7 Update 51
Adobe Flash Player 11.8.800.94
Adobe Reader XI
Mozilla Firefox (26.0)
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: =
````````````````````End of Log``````````````````````

Hello Il y avait 2 Adwares, ce n' est pas tr&ea[…]

Salut à tous Nous recherchons urgemment un […]

Bonjour :bonjour: , Je me permets de faire appel[…]

Bonjour, Je viens de monter un pc bureautique et &[…]