Aller au contenu

moonglow

Membres
  • Compteur de contenus

    23
  • Inscription

  • Dernière visite

Tout ce qui a été posté par moonglow

  1. Bonsoir, J'ai déjà réinitialisé les navigateurs. Par contre le lien pour télécharger Delfix ne fonctionne pas. Merci de votre aide en tout cas.
  2. Bonsoir, Voici le rapprt SFTGC: http://www.cjoint.com/c/FJptjoBfjfw
  3. Bonsoir, Voici le rapport ADW Cleaner: # AdwCleaner v6.021 - Rapport créé le 15/10/2016 à 18:21:58 # Mis à jour le 06/10/2016 par ToolsLib # Base de données : 2016-10-15.2 [serveur] # Système d'exploitation : Windows 10 Pro (X86) # Nom d'utilisateur : Matthieu - PC-DE-MATTHIEU # Exécuté depuis : C:\Users\Matthieu\Downloads\adwcleaner_6.021.exe # Mode: Nettoyage # Support : https://toolslib.net/forum ***** [ Services ] ***** [-] Service supprimé: wStLibG ***** [ Dossiers ] ***** [-] Dossier supprimé: C:\Users\Matthieu\AppData\Local\Mail.Ru [-] Dossier supprimé: C:\Users\Matthieu\AppData\Roaming\mipony [-] Dossier supprimé: C:\Users\Matthieu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\mipony [-] Dossier supprimé: C:\Users\Matthieu\Documents\mipony [-] Dossier supprimé: C:\ProgramData\Mail.Ru [#] Dossier supprimé au redémarrage: C:\ProgramData\Application Data\Mail.Ru [-] Dossier supprimé: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mipony [-] Dossier supprimé: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC [-] Dossier supprimé: C:\Program Files\mipony [-] Dossier supprimé: C:\Program Files\Common Files\freemake shared [-] Dossier supprimé: C:\Users\Matthieu\AppData\Roaming\Mozilla\Firefox\Profiles\jwcz3mo4.default\extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7} [-] Dossier supprimé: C:\Users\Matthieu\AppData\Roaming\Mozilla\Firefox\Profiles\jwcz3mo4.default\extensions\search@mail.ru [-] Dossier supprimé: C:\Users\Matthieu\AppData\Roaming\Mozilla\Firefox\Profiles\jwcz3mo4.default\extensions\homepage@mail.ru [-] Dossier supprimé: C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm [-] Dossier supprimé: C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma [-] Dossier supprimé: C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Extensions\aigpfkhfcodepjoiomimcjgjiefkdgdj [-] Dossier supprimé: C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldjkgaaoikpmhmkelcgkgacicjfbofhh ***** [ Fichiers ] ***** [-] Fichier supprimé: C:\Users\Matthieu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\MiPony.lnk [-] Fichier supprimé: C:\Users\Matthieu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk [-] Fichier supprimé: C:\Users\Matthieu\Favorites\Mail.Ru.url [-] Fichier supprimé: C:\Users\Matthieu\Favorites\Mail.Ru Агент - используй для общения!.url [-] Fichier supprimé: C:\Users\Matthieu\Desktop\Вoйти в Интeрнет.lnk [-] Fichier supprimé: C:\Users\Matthieu\Desktop\MiPony.lnk [-] Fichier supprimé: C:\Program Files\Mozilla Firefox\browser\searchplugins\istartsurf.xml [-] Fichier supprimé: C:\Users\Matthieu\AppData\Roaming\Mozilla\Firefox\Profiles\jwcz3mo4.default\searchplugins\mailru.xml [#] Fichier supprimé: C:\Program Files\Mozilla Firefox\browser\searchplugins\istartsurf.xml [#] Fichier supprimé: C:\Program Files\Mozilla Firefox\browser\searchplugins\istartsurf.xml [-] Fichier supprimé: C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_deghekbbihbapplmbffglehkdhkeibbm_0.localstorage [-] Fichier supprimé: C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage [-] Fichier supprimé: C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage-journal ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Raccourcis ] ***** [!] Raccourci non supprimé: C:\Users\Matthieu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk ***** [ Tâches planifiées ] ***** ***** [ Registre ] ***** [-] Valeur supprimée: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [Plus-HD-3.5-chromeinstaller.job.fp] [-] Valeur supprimée: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [Plus-HD-3.5-codedownloader.job.fp] [-] Valeur supprimée: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures [Plus-HD-3.5-updater.job.fp] [-] Valeur supprimée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ProductUpdater] [-] Clé supprimée: HKLM\SOFTWARE\Classes\mipony [-] Clé supprimée: HKLM\SOFTWARE\Classes\mipony-ext [-] Clé supprimée: HKLM\SOFTWARE\Classes\mpybrowser [-] Clé supprimée: HKLM\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099} [-] Clé supprimée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E8F97CD-60B5-456F-A201-73065652D099} [-] Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E8F97CD-60B5-456F-A201-73065652D099} [-] Valeur supprimée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{58124A0B-DC32-4180-9BFF-E0E21AE34026}] [-] Valeur supprimée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}] [-] Valeur supprimée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] [-] Clé supprimée: HKU\S-1-5-21-1133659715-3320907596-4153438008-1000\Software\Mail.Ru [-] Clé supprimée: HKU\S-1-5-21-1133659715-3320907596-4153438008-1000\Software\MICROSOFT\IDSC [-] Clé supprimée: HKU\S-1-5-21-1133659715-3320907596-4153438008-1000\Software\AppDataLow\Software\Mail.Ru [-] Clé supprimée: HKU\S-1-5-21-1133659715-3320907596-4153438008-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Crossrider [-] Clé supprimée: HKU\S-1-5-21-1133659715-3320907596-4153438008-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\media enhance [#] Clé supprimée au redémarrage: HKCU\Software\Mail.Ru [#] Clé supprimée au redémarrage: HKCU\Software\MICROSOFT\IDSC [#] Clé supprimée au redémarrage: HKCU\Software\AppDataLow\Software\Mail.Ru [-] Clé supprimée: HKLM\SOFTWARE\Taronja [-] Clé supprimée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MiPony [-] Clé supprimée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18C9E3869A16248439FE3FF9EB02207A [-] Valeur supprimée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [sound+] [-] Clé supprimée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MiPony.exe [-] Clé supprimée: HKCU\Software\Google\Chrome\Extensions\oelpkepjlgmehajehfeicfbjdiobdkfj [-] Clé supprimée: HKCU\Software\Google\Chrome\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd [-] Clé supprimée: HKCU\Software\Google\Chrome\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof ***** [ Navigateurs ] ***** [-] Préférences Firefox nettoyées: "browser.search.defaultenginename" - "GoSearch" [-] Préférences Firefox nettoyées: "browser.search.selectedEngine" - "GoSearch" [-] Préférences Firefox nettoyées: [-] Préférences Firefox nettoyées: [-] [C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Web data] [search Provider] Supprimé: nationzoom.com [-] [C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Web data] [search Provider] Supprimé: aartemis [-] [C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Web data] [search Provider] Supprimé: nationzoom [-] [C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Web data] [search Provider] Supprimé: delta-search.com ************************* :: Clés "Tracing" supprimées :: Paramètres Winsock réinitialisés ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [8051 octets] - [15/10/2016 18:21:58] C:\AdwCleaner\AdwCleaner[s0].txt - [8477 octets] - [15/10/2016 17:52:59] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [8199 octets] ##########
  4. Bonjour, Voici le rapport ZHPFix: Rapport de ZHPFix 2015.10.19.9 par Nicolas Coolman, Update du 19/10/2015 Fichier d'export Registre : Run by Matthieu at 15/10/2016 16:28:35 High Elevated Privileges : OK Windows 8 Business Edition, 32-bit Service Pack 1 (14393) Corbeille vidée (04mn 43s) Dossier Prefetcher vidé Réparation des raccourcis navigateur ========== Clés du Registre ========== SUPPRIMÉ: Service: RelevantKnowledge SUPPRIMÉ: SearchScopes :{A06ED961-D98F-4CF9-A89B-80AB11DB149C} SUPPRIMÉ: SearchScopes :{FFEBBF0A-C22C-4172-89FF-45215A135AC7} SUPPRIMÉ: SearchScopes :{210073B5-670D-4ABE-A7CB-83EDBC77BF35} Branche de Base de Registres IFEO non infectée ! ========== Valeurs du Registre ========== SUPPRIMÉ RunValue: Sound+ Aucune Valeur Standard Profile: FirewallRaz : Aucune Valeur Domain Profile: FirewallRaz : SUPPRIMÉ: FirewallRaz (None) : {A9080F4C-BE69-49F6-87CD-FAE444526D27} SUPPRIMÉ: FirewallRaz (Domain) : {AF4CD98F-A6B6-4B1C-8D65-661A94CE0BDE} SUPPRIMÉ: FirewallRaz (Domain) : {E87C4EB6-6F4C-4E7F-8385-633B5F0CA2DD} SUPPRIMÉ: FirewallRaz (None) : {77C2D87D-0E8C-482E-A214-64BC5D93F597} ProxyFix : Configuration proxy supprimée avec succès SUPPRIMÉ ProxyServer Value SUPPRIMÉ ProxyEnable Value SUPPRIMÉ EnableHttp1_1 Value SUPPRIMÉ ProxyHttp1.1 Value SUPPRIMÉ ProxyOverride Value ========== Eléments de donnée du Registre ========== SUPPRIMÉ: R0 - Main,Start Page = KCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page ========== Préférences navigateur ========== PRESENT Chrome File: C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ABSENT Chrome Site: 0 - GCSP: Secure Preferences [user Data\Default][HomePage] SUPPRIMÉ Folder Chrome: C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldikpdnngdmeceeameoaannjilbjppnm SUPPRIMÉ Folder Chrome: C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma SUPPRIMÉ Mozilla Pref: user_pref("extensions.a0c822a17a68f40669257d229458d21ca9c178d17dc614aafb2da1425ac7300accom44150.44150.name", "MediaPlayerEnhance")[...] ABSENT Mozilla Pref: user_pref("extensions.a0c822a17a68f40669257d229458d21ca9c178d17dc614aafb2da1425ac7300accom44150.44150.publisher", "Feven"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.description", "HQ Videos is [...] ABSENT Mozilla Pref: user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.name", "HQ-Video-Pro-1.9"); ABSENT Mozilla Pref: https://mail.ru/cnt/...1.0.3&gp=811009 ========== Dossiers ========== SUPPRIMÉ: C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldikpdnngdmeceeameoaannjilbjppnm SUPPRIMÉ: C:\Users\Matthieu\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma SUPPRIMÉ: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\m4ng_v5 SUPPRIMÉ: C:\Users\Matthieu\AppData\Local\ComDev SUPPRIMÉ: C:\Users\Matthieu\AppData\Local\fupdate SUPPRIMÉS Flash Cookies (0) ========== Fichiers ========== SUPPRIMÉS Flash Cookies (0) (0 octets) ========== Restauration Système ========== Point de restauration du système créé avec succès ========== Autre ========== NON TRAITÉ [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoundPlus ] NON TRAITÉ [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} ] ========== Récapitulatif ========== 5 : Clés du Registre 13 : Valeurs du Registre 1 : Eléments de donnée du Registre 6 : Dossiers 1 : Fichiers 9 : Préférences navigateur 1 : Restauration Système 2 : Autre End of clean in 13mn 00s ========== Chemin de fichier rapport ========== C:\Users\Matthieu\AppData\Roaming\ZHP\ZHPFix[R1].txt - 15/10/2016 16:33:19 [3815]
  5. Bonjour, Merci de m'aider tout d'abord. Voici le lien ZHP.diag: http://www.cjoint.com/c/FJpniOdvZnw
  6. Bonsoir, J'ai pas mal de pages qui s'ouvrent de manière intempestive ou quand je clique sur une recherche à partir de Chrome ou Firefox, les pages ouvertes ne sont pas celles demandées. Il semblearait que mail.ru ait infecté le système. J'ai donc besoin de votre aide. Merci à celui qui pourra s'occuper de mon cas. Matth.
  7. Tout a fonctionné parfaitement. Merci pour votre aide et les conseils de protection.
  8. Bonjour, Je suis de retour avec le rapport ZhpCleaner: ~ ZHPCleaner v2016.1.18.11 by Nicolas Coolman (2016/01/18) ~ Run by Amandine (Administrator) (20/01/2016 10:08:08) ~ Site : http://www.nicolascoolman.fr ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Type : Nettoyer ~ Report : C:\Users\Amandine\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\Amandine\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt ~ UAC : Deactivate ~ Boot Mode : Normal (Normal boot) Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601) ---\\ Service. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Navigateur internet. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Fichier hôte. (1) ~ Le fichier hôte est légitime. (21) ---\\ Tâche planifiée. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Explorateur ( Dossiers, Fichiers ). (1) DEPLACÉ fichier: C:\Users\Amandine\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\FLV Player.lnk [bad : C:\Program Files (x86)\FLVPlayer\FLVPlayer.exe] =>PUP.Optional.FLVPlayer ---\\ Base de Registres ( Clés, Valeurs, Données ). (1) SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} [iTool] =>Toolbar.Ask ---\\ Récapitulatif des éléments trouvés sur votre station. (2) ---\\ Nettoyage Additionnel. (29) ~ Suppression des Clés de registre Tracing. (29) ~ Suppression des anciens rapports ZHPCleaner. (0) ---\\ Bilan de la réparation ~ Réparation réalisée avec succès. ~ Ce navigateur est absent (Google Chrome) ~ Ce navigateur est absent (Opera Software) ---\\ Statistiques ~ Items scannés : 548 ~ Items trouvés : 0 ~ Items annulés : 0 ~ Items réparés : 2 ~ End of clean in 00h00mn07s =================== ZHPCleaner-[R]-20012016-10_08_15.txt ZHPCleaner--20012016-08_24_57.txt
  9. Bonjour, Je vous poste le rapport Short Cleaner: Shortcut Cleaner 1.3.9 by Lawrence Abrams (Grinler) http://www.bleepingcomputer.com/ Copyright 2008-2016 BleepingComputer.com More Information about Shortcut Cleaner can be found at this link: http://www.bleepingcomputer.com/download/shortcut-cleaner/ Windows Version: Windows 7 Home Premium Service Pack 1 Program started at: 01/20/2016 08:14:29 AM. Scanning for registry hijacks: * No issues found in the Registry. Searching for Hijacked Shortcuts: Searching C:\Users\Amandine\AppData\Roaming\Microsoft\Windows\Start Menu\ Searching C:\ProgramData\Microsoft\Windows\Start Menu\ Searching C:\Users\Amandine\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ Searching C:\Users\Public\Desktop\ Searching C:\Users\Amandine\Desktop\ Searching C:\Users\Public\Desktop\ 0 bad shortcuts found. Program finished at: 01/20/2016 08:14:32 AM Execution time: 0 hours(s), 0 minute(s), and 3 seconds(s)
  10. Bonjour, Voici le contenu du rapport MBAM/ Malwarebytes Anti-Malware www.malwarebytes.org Date de l'analyse: 19/01/2016 Heure de l'analyse: 22:30 Fichier journal: Administrateur: Oui Version: 2.2.0.1024 Base de données de programmes malveillants: v2016.01.19.05 Base de données de rootkits: v2016.01.09.01 Licence: Essai Protection contre les programmes malveillants: Activé Protection contre les sites Web malveillants: Activé Autoprotection: Désactivé Système d'exploitation: Windows 7 Service Pack 1 Processeur: x64 Système de fichiers: NTFS Utilisateur: Amandine Type d'analyse: Analyse personnalisée Résultat: Terminé Objets analysés: 656514 Temps écoulé: 2 h, 32 min, 15 s Mémoire: Activé Démarrage: Activé Système de fichiers: Activé Archives: Activé Rootkits: Désactivé Heuristique: Activé PUP: Activé PUM: Activé Processus: 0 (Aucun élément malveillant détecté) Modules: 0 (Aucun élément malveillant détecté) Clés du Registre: 4 PUP.Optional.Goobzo, HKLM\SOFTWARE\CLASSES\ShopperPro.ShopperProBHO, En quarantaine, [d0b16bd07722b77f0c2adcf8c04207f9], PUP.Optional.Goobzo, HKLM\SOFTWARE\CLASSES\ShopperPro.ShopperProBHO.1, En quarantaine, [e0a10b30cbce0432c472bc189d65b14f], PUP.Optional.Goobzo, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperPro.ShopperProBHO, En quarantaine, [10718caf3267bf7762d4439123df619f], PUP.Optional.Goobzo, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperPro.ShopperProBHO.1, En quarantaine, [641d04371f7aa492ea4cf8dc8d7526da], Valeurs du Registre: 0 (Aucun élément malveillant détecté) Données du Registre: 0 (Aucun élément malveillant détecté) Dossiers: 0 (Aucun élément malveillant détecté) Fichiers: 19 PUP.Optional.Amonetize, C:\Users\Amandine\AppData\Local\Temp\xwU1xZRI\Top+Body+Menus+Pdf__10924_i1825998170_il352033.exe, En quarantaine, [037ee457d1c8e056142003be05fc0bf5], PUP.Optional.Goobzo, C:\Users\Amandine\AppData\Local\Temp\Install_15108\ins_shopperpro3.exe, En quarantaine, [3a4741fa0594c373ea4708c83ac7ac54], PUP.Optional.ClickRunSoftware, C:\Users\Amandine\Downloads\FLVPlayerSetup.exe, En quarantaine, [bcc549f23069989e55410ad2ea1a11ef], PUP.Optional.Goobzo, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\ShopperPro3\spbia.exe.vir, En quarantaine, [1869ee4dfc9df14514604f805aa74bb5], PUP.Optional.Goobzo, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\ShopperPro3\spbici64.dll.vir, En quarantaine, [b8c9013a851473c3fcd2218c5ba9619f], PUP.Optional.Goobzo, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\ShopperPro3\spbii64.exe.vir, En quarantaine, [89f8d16abbdebd7971429b34857c23dd], PUP.Optional.Goobzo, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\ShopperPro3\spbiu.exe.vir, En quarantaine, [6a170d2ed4c56dc90c68735c8b7613ed], PUP.Optional.InstallCore, C:\AdwCleaner\Quarantine\C\Program Files (x86)\FlvPlayer\FLVPlayer.exe.vir, En quarantaine, [c4bdcf6c0d8c7bbbb92034da15eb32ce], PUP.Optional.ClickRunSoftware, C:\AdwCleaner\Quarantine\C\Program Files (x86)\FlvPlayer\Uninstall\Uninstall.exe.vir, En quarantaine, [1b66a19a9504a98df1a5f4e818ec1ae6], PUP.Optional.Goobzo, C:\AdwCleaner\Quarantine\C\Program Files (x86)\ShopperPro3\ShopperPro364.dll.vir, En quarantaine, [4041f9421980d660790695bf55abda26], PUP.Optional.Goobzo, C:\AdwCleaner\Quarantine\C\Program Files (x86)\ShopperPro3\JSDriver\jsdrv.exe.vir, En quarantaine, [bfc2d06b841564d24de4d2fe16eb5fa1], PUP.Optional.ShopperPro, C:\AdwCleaner\Quarantine\C\Program Files (x86)\ShopperPro3\JSDriver\jsdrv.sys.vir, En quarantaine, [315004374851c1758ceb1cb3728fdd23], PUP.Optional.Goobzo, C:\AdwCleaner\Quarantine\C\Program Files (x86)\ShopperPro3\JSDriver\1.42.1.10633\jsdrv.exe.vir, En quarantaine, [98e9df5ca7f2a78f9c959c34d42d35cb], PUP.Optional.ShopperPro, C:\AdwCleaner\Quarantine\C\Program Files (x86)\ShopperPro3\JSDriver\1.42.1.10633\jsdrv.sys.vir, En quarantaine, [e998cb7053460531720525aa7d84a759], PUP.Optional.WindoWeather, C:\AdwCleaner\Quarantine\C\Program Files (x86)\WindoWeather\uninst.exe.vir, En quarantaine, [a2dfbb8093068ea85444b2194fb204fc], PUP.Optional.WindoWeather, C:\AdwCleaner\Quarantine\C\Program Files (x86)\WindoWeather\WindoWeather.exe.vir, En quarantaine, [9fe2b388c9d0f93d56591a394eb2847c], PUP.Optional.TrailerTime, C:\AdwCleaner\Quarantine\C\Users\Amandine\AppData\Roaming\TrailerTime\Uninstall.exe.vir, En quarantaine, [027fca716a2f33034d25478579886d93], PUP.Optional.PCKeeper, C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.pckeeper.com_0.localstorage, En quarantaine, [4839b9824b4e4fe7e2fc27088c78857b], PUP.Optional.PCKeeper, C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.pckeeper.com_0.localstorage-journal, En quarantaine, [651c7ac1bcdd89ad2cb255da3cc8e818], Secteurs physiques: 0 (Aucun élément malveillant détecté) (end)
  11. Voici le rapport JRT.txt: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.0.2 (01.06.2016) Operating System: Windows 7 Home Premium x64 Ran by Amandine (Administrator) on 19/01/2016 at 22:13:10,37 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 84 Failed to delete: C:\Users\Amandine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KT1OXZUK (Folder) Successfully deleted: C:\Users\Amandine\AppData\Local\a8242262dbd80f24912d8e48d59dbb02 (File) Successfully deleted: C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio (Folder) Successfully deleted: C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gkojfkhlekighikafcpjkiklfbnlmeio_0.localstorage-journal (File) Successfully deleted: C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gkojfkhlekighikafcpjkiklfbnlmeio_0.localstorage (File) Successfully deleted: C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal (File) Successfully deleted: C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage (File) Successfully deleted: C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.metrolyrics.com_0.localstorage-journal (File) Successfully deleted: C:\Users\Amandine\AppData\Local\installer (Folder) Successfully deleted: C:\Users\Amandine\AppData\Roaming\Mozilla\Firefox\Profiles\8kjxmes0.default\extensions\smarterwiki@wikiatic.com.xpi (File) Successfully deleted: C:\Users\Amandine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JOGS1FLV (Folder) Successfully deleted: C:\Users\Amandine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QW5NXIBI (Folder) Successfully deleted: C:\Users\Amandine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RH9NB3XK (Folder) Successfully deleted: C:\Windows\prefetch\DRIVERQUERY.EXE-DF9DD6EE.pf (File) Successfully deleted: C:\Windows\SysWOW64\sho1018.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho1079.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho16FA.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho2144.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho2274.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho2316.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho279D.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho29FD.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho2F2B.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho33AE.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho33C.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho3426.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho3929.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho3BF7.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho4470.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho46FF.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho4D93.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho52F5.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho5E13.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho5F0C.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho6.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho6194.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho67F9.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho695D.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho73A0.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho73FD.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho7667.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho7A0D.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho7E01.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho8B3C.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho8BA.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho934B.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho95A6.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho97F8.tmp (File) Successfully deleted: C:\Windows\SysWOW64\sho9EB3.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoAC07.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoAEE0.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoB636.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoB6E7.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoB7C8.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoBB19.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoBC31.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoBE8B.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoBFF.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoC467.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoC688.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoC88B.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoC93F.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoCB28.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoD0F8.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoD2FF.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoD41E.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoDA.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoDD34.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoDFB9.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoE268.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoE30D.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoE510.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoE653.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoE942.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoEB29.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoEDB.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoF936.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoFB8B.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoFBDA.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoFC17.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoFC76.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoFDEF.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoFE8.tmp (File) Successfully deleted: C:\Windows\SysWOW64\shoFF49.tmp (File) Registry: 2 Successfully deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Free Download Manager (Registry Value) Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 19/01/2016 at 22:17:58,70 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  12. Bonsoir, Voici le rapport ADW-Cleaner: # AdwCleaner v5.030 - Rapport créé le 19/01/2016 à 22:00:34 # Mis à jour le 17/01/2016 par Xplode # Base de données : 2016-01-19.2 [serveur] # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (x64) # Nom d'utilisateur : Amandine - AMANDINE-HP2231 # Exécuté depuis : C:\Users\Amandine\Downloads\adwcleaner_5.030.exe # Option : Nettoyer # Support : http://toolslib.net/forum ***** [ Services ] ***** [-] Service Supprimé : BrsHelper [-] Service Supprimé : sbmntr [-] Service Supprimé : SPBIUpd [-] Service Supprimé : SPBIUpdd [-] Service Supprimé : SPDRIVER_1.42.1.10633 ***** [ Dossiers ] ***** [-] Dossier Supprimé : C:\Program Files (x86)\FlvPlayer [-] Dossier Supprimé : C:\Program Files (x86)\ShopperPro3 [-] Dossier Supprimé : C:\Program Files (x86)\WindoWeather [-] Dossier Supprimé : C:\Program Files (x86)\YTDownloader [-] Dossier Supprimé : C:\Program Files\Common Files\ShopperPro3 [-] Dossier Supprimé : C:\ProgramData\ShopperPro3 [-] Dossier Supprimé : C:\ProgramData\WindoWeatherConfig [-] Dossier Supprimé : C:\Users\Amandine\AppData\Local\BrowserHelper [-] Dossier Supprimé : C:\Users\Amandine\AppData\Local\TrailerTime [-] Dossier Supprimé : C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldikpdnngdmeceeameoaannjilbjppnm [-] Dossier Supprimé : C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnaiinchjaonopoejhknmgjingcnaloc [-] Dossier Supprimé : C:\Users\Amandine\AppData\Local\Installer\Install_21952 [-] Dossier Supprimé : C:\Users\Amandine\AppData\Local\Installer\Install_7553 [-] Dossier Supprimé : C:\Users\Amandine\AppData\Roaming\TrailerTime [-] Dossier Supprimé : C:\Users\Amandine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player [-] Dossier Supprimé : C:\Users\Amandine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TrailerTime [-] Dossier Supprimé : C:\Users\Amandine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WindoWeather [-] Dossier Supprimé : C:\Users\Amandine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YTDownloader [-] Dossier Supprimé : C:\Users\Amandine\AppData\Roaming\Mozilla\Firefox\Profiles\8kjxmes0.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [-] Dossier Supprimé : C:\Users\Public\Documents\ShopperPro3 [#] Dossier Supprimé : C:\Windows\SysNative\Tasks\ShopperPro3 [#] Dossier Supprimé : C:\Windows\SysNative\Tasks\YTDownloader ***** [ Fichiers ] ***** [-] Fichier Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk [-] Fichier Supprimé : C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.v9.com_0.localstorage [-] Fichier Supprimé : C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.v9.com_0.localstorage-journal ***** [ DLLs ] ***** ***** [ Raccourcis ] ***** ***** [ Tâches planifiées ] ***** [-] Tâche Supprimée : Scheduled Update for Ask Toolbar [-] Tâche Supprimée : ShopperProJSUpd [-] Tâche Supprimée : SPDriver [-] Tâche Supprimée : YTDownloader [-] Tâche Supprimée : YTDownloaderUpd [-] Tâche Supprimée : ShopperPro3 [-] Tâche Supprimée : SPBIW_UpdateTask_Time_3631323235333833382d3437415a556c2a3223346c41 ***** [ Registre ] ***** [-] Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\ShopperPro.DLL [-] Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [ExploreTech.exe] [-] Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [WindoWeather.exe] [-] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ShopperPro3.exe [-] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\YTDownloader.exe [-] Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{0DC81A74-1FBD-4EF6-82B2-DE3FA05E8233} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{1B26E4A2-7F09-4365-9AB8-13E6891E42CB} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{21402197-BB5B-476C-AA1D-3FFED8ED813A} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{42E8D680-A18B-4CAA-ACE0-18EA05E4A056} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{454A4044-16EC-4D64-9069-C5B8832B7B55} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{4FEB1BAD-35AD-4A08-B6EC-E6D832F1ED4D} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{8F2B3016-17D4-447A-B207-FFA8957A834A} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{E66B63B0-49F8-47E3-A9BA-799287B59E87} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{F8FA5B48-B7A2-4BC6-8389-9587643A4660} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413} [-] Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF} [-] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} [-] Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} [-] Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1} [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{0DC81A74-1FBD-4EF6-82B2-DE3FA05E8233} [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{1B26E4A2-7F09-4365-9AB8-13E6891E42CB} [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{21402197-BB5B-476C-AA1D-3FFED8ED813A} [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{42E8D680-A18B-4CAA-ACE0-18EA05E4A056} [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{454A4044-16EC-4D64-9069-C5B8832B7B55} [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{4FEB1BAD-35AD-4A08-B6EC-E6D832F1ED4D} [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{8F2B3016-17D4-447A-B207-FFA8957A834A} [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{E66B63B0-49F8-47E3-A9BA-799287B59E87} [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{F8FA5B48-B7A2-4BC6-8389-9587643A4660} [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} [-] Clé Supprimée : HKCU\Software\YTDownloader [-] Clé Supprimée : HKCU\Software\AppDataLow\Software\TrailerTime [-] Clé Supprimée : HKLM\SOFTWARE\Microsoft\WindoWeather [-] Clé Supprimée : HKLM\SOFTWARE\ShopperPro3 [-] Clé Supprimée : HKLM\SOFTWARE\WindoWeather [-] Clé Supprimée : HKLM\SOFTWARE\YTDownloader [-] Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\FLV Player [-] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro3 [-] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TrailerTime [-] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindoWeather [-] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YTDownloader [-] Clé Supprimée : [x64] HKLM\SOFTWARE\ShopperPro3 [-] Clé Supprimée : HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9 [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2 [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6 [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7 [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852 [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0 [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96 [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8 [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01 [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59 [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472 [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296 [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888 [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\120DFADEB50841F408F04D2A278F9509 [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9 [-] Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} [-] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} [-] Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} [-] Valeur Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [sPDriver] [-] Valeur Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [YTDownloader] [-] Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [sPDriver] [-] Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [TrailerTime] [-] Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [WindoWeather] [-] Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [YTDownloader] [-] Clé Supprimée : HKLM\SOFTWARE\Classes\AniGIFCtrl.AniGIF [-] Clé Supprimée : HKLM\SOFTWARE\Classes\AniGIFPpg.AniGIFPpg [-] Clé Supprimée : HKLM\SOFTWARE\Classes\AniGIFPpg.AniGIFPpg.1 [-] Clé Supprimée : HKLM\SOFTWARE\Classes\AniGIFPpg2.AniGIFPpg2 [-] Clé Supprimée : HKLM\SOFTWARE\Classes\AniGIFPpg2.AniGIFPpg2.1 ***** [ Navigateurs ] ***** [-] [C:\Users\Amandine\AppData\Roaming\Mozilla\Firefox\Profiles\8kjxmes0.default\prefs.js] [Preference] Supprimée : user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url(\"I[...] [-] [C:\Users\Amandine\AppData\Roaming\Mozilla\Firefox\Profiles\8kjxmes0.default\prefs.js] [Preference] Supprimée : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*"); [-] [C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Web Data] [search Provider] Supprimé : eu.ask.com [-] [C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Web Data] [search Provider] Supprimé : nationzoom.com [-] [C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Web Data] [search Provider] Supprimé : aartemis [-] [C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Web Data] [search Provider] Supprimé : nationzoom [-] [C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Web Data] [search Provider] Supprimé : delta-search.com [-] [C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Supprimé : ldikpdnngdmeceeameoaannjilbjppnm [-] [C:\Users\Amandine\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Supprimé : pnaiinchjaonopoejhknmgjingcnaloc ************************* :: Clés "Tracing" supprimées :: Paramètres Winsock réinitialisés ************************* C:\AdwCleaner[R1].txt - [9124 octets] - [13/11/2011 18:34:57] C:\AdwCleaner[R2].txt - [1396 octets] - [13/11/2011 18:40:25] C:\AdwCleaner[s1].txt - [7769 octets] - [13/11/2011 18:35:09] C:\AdwCleaner[s2].txt - [1426 octets] - [13/11/2011 18:40:33] C:\AdwCleaner[s3].txt - [1486 octets] - [13/11/2011 18:53:21] ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [14381 octets] ##########
  13. Bonsoir, Voici le rapport: CTR Désolé, j'ai oublié de coller le contenu: Rapport de Contrôle restrictions Pierre13 (CTR version 2.1.0.0 ) du 19\01\2016 à 21:40:38 PC de Amandine Windows 7 Home Premium Service Pack 1 (64 bits) Réparation erreur 2203 effectuée. Contrôle présence restrictions [TROJ_POWELIKS.B] clé feature_browser_emulation supprimée. [bKDR_BLACKEN.A] clé Check_Associations supprimée. [bKDR_BLACKEN.A] clé WarnOnClose corrigée. Autorisation installation sponsor Java(x86) supprimée. Autorisation installation sponsor Java(x64) supprimée. Restriction Affichage Documents récents supprimée. Restriction Affichage Documents supprimée. Restriction synchronisation en arrière-plan des flux d’informations et des Web Slices supprimée. Restriction découverte des flux RSS et des Web Slices supprimée. Pavé numérique activé. Restriction utilisateur pour Windows Installer supprimée. Configuration Windows Update déjà en auto. Recherche Windows Update rétablie. Service Pare feu Windows activé. Paramètres Pare feu Windows rétablis par défaut et activé. 232 restrictions contrôlées. 13 restriction(s) réparée(s). Re démarrer le PC pour prendre en compte la ou les réparations. Le rapport est sur le bureau (C:\Users\Amandine\Desktop\CTR.txt) Faut-il redémarrer le PC comme demandé dans le rapport?
  14. Bonsoir, le lien pour télécharger CTR.exe ne fonctionne pas.
  15. Bonjour, Merci de l'aide. Voici le lien Cjoint: http://www.cjoint.com/c/FAtsl00Zz6Y à plus.
  16. Bonjour, Je crois que mon PC a été infecté. En cliquant sur Chrome, j'ai plusieurs pages qui s'ouvrent de manière totalement anarchique en lieu et place de ma page d'accueil habituelle. C'est assez aléatoire, mais on retrouve les adresses suivantes: - omtzz.pcloadletter.niiz.info - lightning-support.com - traki.engine - une page me demande aussi d'installer Flash Player video (obligatoire) - une fenêtre s'ouvre aussi sans arrêt et m'indique qu'Internet Explorer a cessé de fonctionner ( alors que je n'utilise pas ce navigateur). Si je clique pour la fermer, elle s'ouvre à nouveau. Voilà, j'espère que la description est claire et que vous pourrez m'aidez. Merci d'avance pour vos conseils et aides. Mat.
  17. Bonsoir, Voici le rapport ZHPFix: Rapport de ZHPFix 2014.10.24.12 par Nicolas Coolman, Update du 24/10/2014 Fichier d'export Registre : Run by Charline at 04/11/2014 20:29:09 High Elevated Privileges : OK Windows 7 Home Premium Edition, 32-bit Service Pack 1 (Build 7601) Corbeille vidée (00mn 03s) Dossier Prefetcher vidé Réparation des raccourcis navigateur ========== Clés du Registre ========== SUPPRIMÉ: HKLM\Software\ASK Branche de Base de Registres IFEO non infectée ! ========== Valeurs du Registre ========== ProxyFix : Configuration proxy supprimée avec succès SUPPRIMÉ ProxyServer Value SUPPRIMÉ ProxyEnable Value SUPPRIMÉ EnableHttp1_1 Value SUPPRIMÉ ProxyHttp1.1 Value SUPPRIMÉ ProxyOverride Value Aucune Valeur Standard Profile: FirewallRaz : Aucune Valeur Domain Profile: FirewallRaz : ========== Dossiers ========== Aucun dossiers CLSID Local utilisateur vide SUPPRIMÉS Temporaires Windows (17) SUPPRIMÉS Flash Cookies (0) ========== Fichiers ========== SUPPRIMÉ: c:\users\charline\downloads\spybot-2.4.exe SUPPRIMÉS Temporaires Windows (19) (399 446 octets) SUPPRIMÉS Flash Cookies (0) (0 octets) ========== Tache planifiée ========== SUPPRIMÉ: {8BAAACF0-4896-41C3-8FCF-7CC475E2BFA4} ========== Récapitulatif ========== 2 : Clés du Registre 8 : Valeurs du Registre 3 : Dossiers 3 : Fichiers 1 : Tache planifiée End of clean in 00mn 15s ========== Chemin de fichier rapport ========== C:\Users\Charline\AppData\Roaming\ZHP\ZHPFix[R1].txt - 02/11/2014 18:22:47 [2249] C:\Users\Charline\AppData\Roaming\ZHP\ZHPFix[R2].txt - 04/11/2014 20:29:13 [1513] Le PC fonctionne beaucoup mieux après tout ça. Merci beaucoup pour l'aide.
  18. Bonsoir, J'ai fait les différentes mises à jour ainsi que celles des navigateurs. Voici le rapport ZHPDiag: http://cjoint.com/?0KcutAWxYaJ @ Plus
  19. Bonsoir, 1) Voici le rapport ADW Cleaner: # AdwCleaner v3.311 - Rapport créé le 02/11/2014 à 18:12:25 # Mis à jour le 30/09/2014 par Xplode # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (32 bits) # Nom d'utilisateur : Charline - CHARLINE-PC # Exécuté depuis : C:\Users\Charline\Downloads\adwcleaner_3.311.exe # Option : Nettoyer ***** [ Services ] ***** ***** [ Fichiers / Dossiers ] ***** ***** [ Tâches planifiées ] ***** ***** [ Raccourcis ] ***** ***** [ Registre ] ***** ***** [ Navigateurs ] ***** -\\ Internet Explorer v11.0.9600.17280 -\\ Mozilla Firefox v33.0.2 (x86 fr) [ Fichier : C:\Users\Charline\AppData\Roaming\Mozilla\Firefox\Profiles\yc800de0.default-1414882704020\prefs.js ] -\\ Google Chrome v30.0.1599.69 [ Fichier : C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R6].txt - [1893 octets] - [30/10/2014 13:13:09] AdwCleaner[R7].txt - [1136 octets] - [02/11/2014 17:42:29] AdwCleaner[R8].txt - [1256 octets] - [02/11/2014 18:10:17] AdwCleaner[s3].txt - [1981 octets] - [30/10/2014 13:19:38] AdwCleaner[s4].txt - [1198 octets] - [02/11/2014 17:44:34] AdwCleaner[s5].txt - [1178 octets] - [02/11/2014 18:12:25] ########## EOF - C:\AdwCleaner\AdwCleaner[s5].txt - [1238 octets] ########## 2) Voici le rapport ZHPFix: Rapport de ZHPFix 2014.10.24.12 par Nicolas Coolman, Update du 24/10/2014 Fichier d'export Registre : Run by Charline at 02/11/2014 18:22:43 High Elevated Privileges : OK Windows 7 Home Premium Edition, 32-bit Service Pack 1 (Build 7601) Corbeille vidée (00mn 04s) Dossier Prefetcher vidé Réparation des raccourcis navigateur ========== Clés du Registre ========== SUPPRIMÉ: [HKLM\Software\Classes\Installer\Products\\A07B748F92CF28B478E2852FECD9EE90] SUPPRIMÉ: [HKLM\Software\Classes\Installer\Features\A07B748F92CF28B478E2852FECD9EE90] SUPPRIMÉ: HKLM\SOFTWARE\SOFTWARE\UPDATE\CLIENTS\{5B54E9B6-D6C4-11E0-8E9D-92FB4824019B} Branche de Base de Registres IFEO non infectée ! ========== Valeurs du Registre ========== ProxyFix : Configuration proxy supprimée avec succès SUPPRIMÉ ProxyServer Value SUPPRIMÉ ProxyEnable Value SUPPRIMÉ EnableHttp1_1 Value SUPPRIMÉ ProxyHttp1.1 Value SUPPRIMÉ ProxyOverride Value Aucune Valeur Standard Profile: FirewallRaz : Aucune Valeur Domain Profile: FirewallRaz : SUPPRIMÉ: FirewallRaz (Private) : {DC9BABD1-7BAE-43B4-8169-1D73776ED0B5} SUPPRIMÉ: FirewallRaz (Private) : {C15ED23D-1330-4236-AF9B-89E19350C3EF} ========== Préférences navigateur ========== SUPPRIMÉ Folder Chrome: C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibokihboaojdolnlgbejebillmaodnfc ========== Dossiers ========== Aucun dossiers CLSID Local utilisateur vide SUPPRIMÉS Temporaires Windows (25) SUPPRIMÉS Flash Cookies (0) ========== Fichiers ========== SUPPRIMÉ: c:\users\charline\appdata\local\google\chrome\user data\default\preferences SUPPRIMÉ: C:\Windows\Installer\29a623.msi SUPPRIMÉ: C:\Windows\Installer\6549a.msi SUPPRIMÉ: C:\Windows\Installer\6f22e2.msi SUPPRIMÉS Temporaires Windows (24) (642 052 octets) SUPPRIMÉS Flash Cookies (0) (0 octets) ========== Tache planifiée ========== SUPPRIMÉ: Yahoo! Search Updater ========== Récapitulatif ========== 4 : Clés du Registre 10 : Valeurs du Registre 3 : Dossiers 6 : Fichiers 1 : Préférences navigateur 1 : Tache planifiée End of clean in 00mn 12s ========== Chemin de fichier rapport ========== C:\Users\Charline\AppData\Roaming\ZHP\ZHPFix[R1].txt - 02/11/2014 18:22:47 [2166]
  20. Bonjour, Rapport ZHP Diag : http://cjoint.com/?0KcrUgATJ9a 2) Rapport ADWCleaner : quels fichiers faut-il scanner pour obtenir C:\AdwCleaner.txt [s0]? J'ai scanné, puis nettoyé la partie "services" et obtenu le rapport C:\AdwCleaner.txt [s4]. A plus.
  21. Bonsoir, Désolé d'avoir pris tout ce temps. Je n'étais pas chez moi ces 2 jours. Voici les différents rapports demandés: Bonjour, Voici les rapports: 1) Rapport JRT: http://cjoint.com/?0JEnmzHGb4Z 2) Rapport ADWCleaner: # AdwCleaner v3.311 - Rapport créé le 30/10/2014 à 13:13:09 # Mis à jour le 30/09/2014 par Xplode # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (32 bits) # Nom d'utilisateur : Charline - CHARLINE-PC # Exécuté depuis : C:\Users\Charline\Downloads\adwcleaner_3.311.exe # Option : Scanner ***** [ Services ] ***** ***** [ Fichiers / Dossiers ] ***** Dossier Présent : C:\Program Files\Software Dossier Présent : C:\Users\Charline\AppData\Local\Software ***** [ Tâches planifiées ] ***** ***** [ Raccourcis ] ***** ***** [ Registre ] ***** Clé Présente : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{006E6A46-8D55-4F10-BBA8-2C9653B4278B} ***** [ Navigateurs ] ***** -\\ Internet Explorer v11.0.9600.17280 -\\ Mozilla Firefox v33.0.2 (x86 fr) [ Fichier : C:\Users\Charline\AppData\Roaming\Mozilla\Firefox\Profiles\8ha0sz14.default\prefs.js ] -\\ Google Chrome v30.0.1599.69 [ Fichier : C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\preferences ] Trouvée [Extension] : booedmolknjekdopkepjjeckmjkdpfgl Trouvée [Extension] : dhdepfaagokllfmhfbcfmocaeigmoebo Trouvée [Extension] : engaigpbgdjjmanonjcjkcmomgibneba Trouvée [Extension] : fbmimoidopbghbcmdmpkjaffffmcbmbg Trouvée [Extension] : flpcjncodpafbgdpnkljologafpionhb Trouvée [Extension] : hphibigbodkkohoglgfkddblldpfohjl Trouvée [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej Trouvée [Extension] : kincjchfokkeneeofpeefomkikfkiedl Trouvée [Extension] : kkkeikdkpjenmoiicggnnodbkebafgpc Trouvée [Extension] : pbaohildkhbcljgoabiecdoinkaedlca Trouvée [Extension] : pgmfkblbflahhponhjmkcnpjinenhlnc ************************* AdwCleaner[R6].txt - [1753 octets] - [30/10/2014 13:13:09] ########## EOF - C:\AdwCleaner\AdwCleaner[R6].txt - [1813 octets] ########## 3) Rapport SFTGC: http://cjoint.com/?0JEnTLX17Bu 4) Rapport MBAM2: Malwarebytes Anti-Malware www.malwarebytes.org Date de l'examen: 01/11/2014 Heure de l'examen: 18:19:35 Fichier journal: rapport MBAM.txt Administrateur: Oui Version: 2.00.3.1025 Base de données Malveillants: v2014.11.01.06 Base de données Rootkits: v2014.10.22.01 Licence: Gratuit Protection contre les malveillants: Désactivé(e) Protection contre les sites Web malveillants: Désactivé(e) Auto-protection: Désactivé(e) Système d'exploitation: Windows 7 Service Pack 1 Processeur: x86 Système de fichiers: NTFS Utilisateur: Charline Type d'examen: Examen "Personnalisé" Résultat: Terminé Objets analysés: 422251 Temps écoulé: 5 h, 3 min, 43 sec Mémoire: Activé(e) Démarrage: Activé(e) Système de fichiers: Activé(e) Archives: Activé(e) Rootkits: Désactivé(e) Heuristique: Activé(e) PUP: Activé(e) PUM: Activé(e) Processus: 0 (Aucun élément malicieux detecté) Modules: 0 (Aucun élément malicieux detecté) Clés du Registre: 0 (Aucun élément malicieux detecté) Valeurs du Registre: 0 (Aucun élément malicieux detecté) Données du Registre: 0 (Aucun élément malicieux detecté) Dossiers: 1 PUP.Optional.FindRight.A, C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibokihboaojdolnlgbejebillmaodnfc, , [e5b58fa7eb91ce68bb8da8532dd542be], Fichiers: 57 Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\SoftwareUpdate.exe.vir, , [3e5c01356913191de4c0f5e3c13f2ad6], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_cs.dll.vir, , [d6c4063094e8c96d4164654fb947817f], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_da.dll.vir, , [bae0360008747eb84362e1d3e818ef11], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_de.dll.vir, , [2f6b9d99d9a34aecb0f5b202ef1154ac], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_el.dll.vir, , [cecc44f2b1cb46f0dcc9645000002fd1], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_en-GB.dll.vir, , [c5d5f1451963f541d6cf4d67da262cd4], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_en.dll.vir, , [237757df92eaa78f15901e96bf41857b], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_es-419.dll.vir, , [7b1fdd59443854e2dbcaf8bc00003cc4], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_es.dll.vir, , [2d6d3006215ba1957f26e1d347b9cb35], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_et.dll.vir, , [8911cb6b7a027fb773326c4841bf51af], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_fa.dll.vir, , [396136007408ee48c1e44e668b75a65a], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_fi.dll.vir, , [1585ba7c0e6e3ff7a8fdfdb7f709e31d], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_fil.dll.vir, , [c1d94bebdd9fae88b2f36d47ce324db3], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_fr.dll.vir, , [673340f62b5187af990c64503ec26c94], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_gu.dll.vir, , [4d4d3cfa54284aecadf89f15cc3443bd], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_hi.dll.vir, , [d4c6b68086f6d85efea7f1c34fb1867a], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_hu.dll.vir, , [d5c5a78f5e1ea88ecdd8f0c4aa56f40c], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_id.dll.vir, , [1b7fc86e79031026b2f3c5ef9769c43c], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_is.dll.vir, , [8d0dcb6be39996a08520a90b2cd4db25], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_it.dll.vir, , [85150d290379af87a9fc3f75d12f29d7], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_iw.dll.vir, , [a1f9ee48b5c71026a2031a9a1de3cc34], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_ja.dll.vir, , [c9d17abcc3b9fd399510d5dfc53bcd33], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_kn.dll.vir, , [bddd2214cab20630149162523cc455ab], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_ko.dll.vir, , [2377ae887b0169cd1491b9fb50b09967], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_lv.dll.vir, , [5f3bad89e29a70c6e8bd8b299d632cd4], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_ml.dll.vir, , [267415210b713ff7cadbc2f201ff44bc], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_mr.dll.vir, , [23772115502c82b4a5002e86cb35dc24], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_ms.dll.vir, , [a4f600362b510f2775306351be42b34d], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_nl.dll.vir, , [e2b8270ffd7fa98dbde85d578f71b64a], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_no.dll.vir, , [1b7f0d29d3a991a52e77bef67888f60a], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_ar.dll.vir, , [524878be7309ba7cb9ec9c1802fe8c74], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_bg.dll.vir, , [d5c5a98dbcc08da9a401ab097789fa06], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_bn.dll.vir, , [564472c4b2caad89f0b5b30146ba29d7], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_pl.dll.vir, , [257562d4d9a3e6501f86dada5fa11fe1], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_pt-BR.dll.vir, , [6c2e270ff78595a13a6b654fe21e4ab6], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_pt-PT.dll.vir, , [3e5ce056116b290d861fd9dbbe420000], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_ro.dll.vir, , [584242f4e795d462d1d4b6feb14fd927], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_ru.dll.vir, , [801a88ae2a52181e396c9d172cd4649c], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_sk.dll.vir, , [9505c3733943ce684e577242ab554eb2], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_sl.dll.vir, , [a9f1ed4933496dc96045555ff60a867a], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_sr.dll.vir, , [e9b177bf96e67eb87b2a2f85fa0603fd], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_sv.dll.vir, , [e9b13ef8cbb16ec82f767143817f10f0], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_ta.dll.vir, , [a3f7a29415672a0cb5f0793b06fabf41], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_te.dll.vir, , [089266d06517b97d7c29179d2ad69b65], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_th.dll.vir, , [debc81b534489e985c49278dfa060000], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_tr.dll.vir, , [336733030f6d42f4c7de0ca8f20ed52b], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_uk.dll.vir, , [07934fe74e2e7fb75352d8dcc23ed030], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_ur.dll.vir, , [2773290ddf9dbf77267f6252a95711ef], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_vi.dll.vir, , [a2f80f27cdafbc7a60457a3ae9179f61], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_zh-CN.dll.vir, , [5f3b54e2413bc175e5c062523bc519e7], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_zh-TW.dll.vir, , [ff9bb4829ce09e987d2807ada65ae11f], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\SoftwareCrashHandler.exe.vir, , [d0ca81b5215b979f396bf5e3e51b26da], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\SoftwareUpdate.exe.vir, , [4555b97d077540f6f0b47b5d9967d22e], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_ca.dll.vir, , [2278e45295e7de5882232c88c04042be], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_hr.dll.vir, , [e0ba9b9b3349f73f198cf7bd9e62de22], Adware.Boxore, C:\AdwCleaner\Quarantine\C\Program Files\Software\Update\1.2.201.0\goopdateres_or.dll.vir, , [8e0cd26486f64cea8a1bd3e11be56799], Adware.Boxore, C:\Windows\Installer\6549a.msi, , [4c4e181e8eee1f17733451636b9551af], Secteurs physiques: 0 (Aucun élément malicieux detecté) (end) 5) Rapport Short Cut Cleaner : Shortcut Cleaner 1.3.3 by Lawrence Abrams (Grinler) http://www.bleepingcomputer.com/ Copyright 2008-2014 BleepingComputer.com More Information about Shortcut Cleaner can be found at this link: http://www.bleepingcomputer.com/download/shortcut-cleaner/ Windows Version: Windows 7 Home Premium Service Pack 1 Program started at: 11/01/2014 11:37:49 PM. Scanning for registry hijacks: * No issues found in the Registry. Searching for Hijacked Shortcuts: Searching C:\Users\Charline\AppData\Roaming\Microsoft\Windows\Start Menu\ Searching C:\ProgramData\Microsoft\Windows\Start Menu\ Searching C:\Users\Charline\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ Searching C:\Users\Public\Desktop\ Searching C:\Users\Charline\Desktop 0 bad shortcuts found. Program finished at: 11/01/2014 11:37:53 PM Execution time: 0 hours(s), 0 minute(s), and 3 seconds(s) 6) Rapport ZHP Diag: ~ Rapport de ZHPDiag v2014.10.28.152 - Nicolas Coolman (28/10/2014) ~ Lancé par Charline (01/11/2014 23:50:03) ~ Adresse du Site Web http://nicolascoolman.fr ~ Adresse du Forum http://forum.nicolascoolman.fr ~ Traduit par Nicolas Coolman ~ Etat de la version : Nouvelle version disponible ~ Liste blanche : Désactivée par l'utilisateur ~ Elévation des Privilèges : OK ~ User Account Control (UAC): Activate by user ---\\ Navigateurs Internet MSIE: Internet Explorer v11.0.9600.17280 MFIE: Mozilla Firefox 33.0.2 GCIE: Google Chrome v30.0.1599.69 (Defaut) ---\\ Informations sur les produits Windows ~ Langage: Français Windows 7 Home Premium, 32-bit Service Pack 1 (Build 7601) Windows Server License Manager Script : OK ~ Windows Operating System - Windows® 7, OEM_SLP channel System Locked Preinstallation (OEM_SLP) : OK Windows ID Activation : OK ~ Windows Partial Key : 2BT4J Windows License : OK ~ Windows Remaining Initializations Number : 3 Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ Logiciels de protection du système avast! Free Antivirus v9.0.2021 Malwarebytes Anti-Malware version 2.0.3.1025 Windows Defender W7 (Activate) ---\\ Logiciels d'optimisation du système CCleaner v4.11 ---\\ Logiciels de partage PeerToPeer ---\\ Surveillance de Logiciels Adobe Flash Player 15 Plugin Adobe Reader XI ---\\ Informations sur le système ~ Processor: x86 Family 6 Model 23 Stepping 10, GenuineIntel ~ Operating System: 32 Bits Boot mode: Normal (Normal boot) Total RAM: 3004 MB (45% free) System Restore: Activé (Enable) System drive C: has 48 GB (33%) free of 144 GB ---\\ Mode de connexion au système ~ Computer Name: CHARLINE-PC ~ User Name: Charline ~ All Users Names: HomeGroupUser$, Charline, Administrateur, ~ Unselected Option: None Logged in as Administrator ---\\ Variables d'environnement ~ System Unit : C:\ ~ %AppZHP% : C:\Users\Charline\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\Charline\AppData\Roaming\ ~ %Desktop% : C:\Users\Charline\Desktop\ ~ %Favorites% : C:\Users\Charline\Favorites\ ~ %LocalAppData% : C:\Users\Charline\AppData\Local\ ~ %StartMenu% : C:\Users\Charline\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumération des unités disques C: Hard drive, Flash drive, Thumb drive (Free 48 Go of 144 Go) D: Hard drive, Flash drive, Thumb drive (Free 126 Go of 144 Go) E: CD-ROM drive (Not Inserted) ---\\ Etat du Centre de Sécurité Windows [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableRegistryTools: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ~ Security Center: 41 Scanned in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320] [MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256] [MD5.D58988722C72D265B51A54103DFC2C6F] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.18/08/2014 - 21:46:48.) -- C:\Windows\System32\wininet.dll [1812992] [MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.17/07/2014 - 02:39:27.) -- C:\Windows\System32\Winlogon.exe [304128] [MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 13:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536] [MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:36:07.) -- C:\Windows\system32\Drivers\AFD.sys [338944] [MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584] [MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656] [MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 09:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544] [MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 09:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336] [MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 10:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544] [MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896] [MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888] [MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904] [MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 09:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904] [MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:18:22.) -- C:\Windows\system32\Drivers\ntfs.sys [1212352] [MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360] [MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848] [MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168] [MD5.B459575348C20E8121D6039DA063C704] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 09:39:17.) -- C:\Windows\system32\Drivers\tdx.sys [74752] [MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 13:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632] ~ Generic Processes: Scanned in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 2/9360 ~ Mes musiques (My Musics) : 1/2115 ~ Mes Videos (My Videos) : 2/13 ~ Mes Favoris (My Favorites) : 1/36 ~ Mes Documents (My Documents) : 1/1090 ~ Mon Bureau (My Desktop) : 5/1176 ~ Menu demarrer (Programs) : 1/59 ~ Hidden Files: Scanned in 00mn 07s ---\\ Processus lancés [MD5.E4A94D17436B4E9F53CD64D08E53D964] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448] [PID.984] [MD5.54FA8528EDA1B6B34615F4EA3FCB35E6] - (.CyberLink - CyberLink MediaLibray Service.) -- C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [103720] [PID.1948] [MD5.28FD28A29C637C9AFEFE0A26E27C6DFE] - (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe [91432] [PID.1184] [MD5.8A0B0E4102C2CCA25DA3134FE12FCC3E] - (.SAMSUNG Electronics - SSCKbdHk.) -- C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe [91136] [PID.2100] [MD5.97101B7CCCFA2BDFEFC2E0B84205D144] - (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8120864] [PID.2108] [MD5.1029B84ECBE4B95ACB8491A3FE63D70F] - (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxtray.exe [136216] [PID.2116] [MD5.3CD5BBDA19A1AB4EBA359E0A14FDF0F0] - (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe [171032] [PID.2132] [MD5.3142195521FEE436088EE8A5748DE1B1] - (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe [170520] [PID.2168] [MD5.26B558B2D31C7425B455B00E562EAD93] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\avastui.exe [4085896] [PID.2244] [MD5.CFBBF2CF26F7E55EC11D4B1DB17A9F38] - (.TomTom - System Tray application for TomTom HOME.) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [248208] [PID.2252] [MD5.697D1E5E6452171F0B9FE3849889BC90] - (.BitTorrent Inc. - µTorrent.) -- C:\Users\Charline\AppData\Roaming\uTorrent\uTorrent.exe [1385808] [PID.2284] =>P2P.BitTorrent [MD5.EB8E27A3C1EA82711BC4037D53EE5122] - (.Dropbox, Inc. - Dropbox.) -- C:\Users\Charline\AppData\Roaming\Dropbox\bin\Dropbox.exe [36414624] [PID.2424] [MD5.F2E6E0276876A52A527F30DBD2CBE365] - (.Sony Corporation - Media Check Tool.) -- C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [327680] [PID.2588] [MD5.E3735DC796E5183D63F35921B058934C] - (.Samsung Electronics Co., Ltd. - EasySpeedUpManager.) -- C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [716800] [PID.2600] [MD5.167F9E5AF87B57763DAAA27D3144C2A0] - (.SEC - Samsung Recovery Solution 4.) -- C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2201192] [PID.2628] [MD5.A46796CCF032D35720347262998D1F90] - (.Samsung Electronics Co., Ltd. - Easy Display Manager.) -- C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [835072] [PID.2784] [MD5.F2F3617C63B87AA2DE139DC9E37420B5] - (.Intel Corporation - igfxext Module.) -- C:\Windows\system32\igfxext.exe [179224] [PID.3684] [MD5.B9AA850CDA55097EB13E03698C8F5828] - (.Intel Corporation - igfxsrvc Module.) -- C:\Windows\system32\igfxsrvc.exe [266776] [PID.3820] [MD5.2A4F72E6C43FAEE62A341F2FC24A442C] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.4276] [MD5.F89773DFA9B8C95A3AC2AF1E7D99E483] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe [7229752] [PID.3500] [MD5.BA7E0BAD9AFF2E62F10F74DFB4783986] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [275568] [PID.1240] [MD5.4ADB31B7C88BBBBB6203968E6C2CBDA1] - (.Microsoft Corporation - Microsoft Office Word.) -- C:\Program Files\Microsoft Office\OFFICE11\WINWORD.exe [12317848] [PID.1564] [MD5.C5FD920FFCCC051D0EAF35D380999AD5] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files\Mozilla Firefox\plugin-container.exe [145520] [PID.3176] [MD5.1944758C8663046A62CF8375533D9E31] - (.Adobe Systems, Inc. - Adobe Flash Player 15.0 r0.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exe [1880752] [PID.6112] [MD5.1080E3DBAF229F0DF7A1D8C09564BDCE] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8116224] [PID.4916] ~ Processes Running: Scanned in 00mn 02s ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2) C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\Preferences G1 - GCS: Preference [user Data\Default] None G0 - GCSP: Preference [user Data\Default] http://www.facebook.com G2 - GCE: Preference [user Data\Default] [ahfgeienlihckogmohjhadlkjgocpleb] Google00A0Store v.0.2 (Activé) G2 - GCE: Preference [user Data\Default] [aohghmighlieiainnegkcijnfilokake] Documents Google v.0.5 (Activé) G2 - GCE: Preference [user Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google00A0Drive v.6.3 (Activé) G2 - GCE: Preference [user Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] YouTube v.4.2.6 (Activé) G2 - GCE: Preference [user Data\Default] [cfhdojbkjhnklbpkdaibdccddilifddb] Adblock Plus v.1.8.1, (Activé) G2 - GCE: Preference [user Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Recherche Google v.0.0.0.20 (Activé) G2 - GCE: Preference [user Data\Default] [eemcgdkfndhakfknompkggombfjjjeno] Bookmark Manager v.0.1 (Activé) G2 - GCE: Preference [user Data\Default] [ennkphjdgehloodpbhlhldgbnhmacadg] Settings v.0.2 (Activé) G2 - GCE: Preference [user Data\Default] [ibokihboaojdolnlgbejebillmaodnfc] FindRight v.1.0.1 (Activé) =>Hijacker.FindrToolbar G2 - GCE: Preference [user Data\Default] [mfehgcgbbipciphmccgaenjidiccnmng] Cloud Print v.0.1 (Activé) G2 - GCE: Preference [user Data\Default] [mgndgikekgjfcpckkfioiadnlibdjbkf] Chrome v.0.1 (Activé) G2 - GCE: Preference [user Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google00A0Wallet v.0.0.6.1 (Activé) G2 - GCE: Preference [user Data\Default] [pbaxxildkhbcljgoabiecdoinkaedlca] Smart Display v.1.8, (Activé) =>Spyware.SmartDisplay G2 - GCE: Preference [user Data\Default] [pbpohilckhbcljgoabiecdoinkaedlca] Smart Display v.1.6 (Activé) =>Spyware.SmartDisplay G2 - GCE: Preference [user Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Gmail v.7 (Activé) ---\\ Liste des dossiers d'extension Google Chrome G2 - EXT: C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [Documents Google] G2 - EXT: C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [Google00A0Drive] G2 - EXT: C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [YouTube] G2 - EXT: C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [Adblock Plus] G2 - EXT: C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [Recherche Google] G2 - EXT: C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibokihboaojdolnlgbejebillmaodnfc [FindRight] =>Hijacker.FindrToolbar G2 - EXT: C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [Google00A0Wallet] G2 - EXT: C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [Gmail] ~ Google Lines Browser: 25 Scanned in 00mn 16s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Users\Charline\AppData\Roaming\Mozilla\Firefox\Profiles\8ha0sz14.default\prefs.js P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_189.dll P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3508.1109] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3538.0513] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.9.) -- C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll ~ Firefox Browser: 8 Scanned in 00mn 00s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = http://www.google.com R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.9.) (No version) -- (.not file.) R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1 ~ IE Browser: 11 Scanned in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Hosts file redirection (O1) ~ Le fichier hôte est sain (The hosts file is clean) (21) ~ Hosts File: Scanned in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\QuickLaunch [Charline]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Charline\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent O4 - GS\TaskBar [Charline]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Charline\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent ~ Global Startup: 2 Scanned in 00mn 01s ---\\ Applications lancées au démarrage du système (O4) O4 - HKLM\..\Run: [synTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [updateLBPShortCut] . (.CyberLink Corp. - MUI StartMenu Application.) -- C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe O4 - HKLM\..\Run: [CLMLServer] . (.CyberLink - CyberLink MediaLibray Service.) -- C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe O4 - HKLM\..\Run: [updateP2GoShortCut] . (.CyberLink Corp. - MUI StartMenu Application.) -- C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe O4 - HKLM\..\Run: [updatePDRShortCut] . (.CyberLink Corp. - StartMen Application.) -- C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe O4 - HKLM\..\Run: [RemoteControl8] . (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe O4 - HKLM\..\Run: [PDVD8LanguageShortcut] . (.CyberLink Corp. - PowerDVD Language Application.) -- C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe O4 - HKLM\..\Run: [updatePPShortCut] . (.CyberLink Corp. - MUI StartMenu Application.) -- C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe O4 - HKLM\..\Run: [updatePSTShortCut] . (.CyberLink Corp. - MUI StartMenu Application.) -- C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe O4 - HKLM\..\Run: [APLangApp] . (.DoctorSoft - AnyPC Language Application.) -- C:\Program Files\AnyPC Client\APLangApp.exe O4 - HKLM\..\Run: [uCam_Menu] . (.CyberLink Corp. - MUI StartMenu Application.) -- C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe =>.Realtek Semiconductor Corp O4 - HKLM\..\Run: [igfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated O4 - HKLM\..\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe O4 - HKCU\..\Run: [TomTomHOME.exe] . (.TomTom - System Tray application for TomTom HOME.) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe O4 - HKCU\..\Run: [uTorrent] . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Charline\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent O4 - HKCU\..\Run: [infigo] C:\Program Files\Infigo\Infigo.exe (.not file.) O4 - HKUS\S-1-5-19\..\Run: [sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\Run: [sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-3222255861-1738671955-1542238764-1000\..\Run: [TomTomHOME.exe] . (.TomTom - System Tray application for TomTom HOME.) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe O4 - HKUS\S-1-5-21-3222255861-1738671955-1542238764-1000\..\Run: [uTorrent] . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Charline\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent O4 - HKUS\S-1-5-21-3222255861-1738671955-1542238764-1000\..\Run: [infigo] C:\Program Files\Infigo\Infigo.exe (.not file.) ~ Application: Scanned in 00mn 00s ---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5) O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no ~ IE Control Panel: 1 Scanned in 00mn 00s ---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation ~ Winsock: 8 Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{65689721-626E-4932-B577-09E124680B7D}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{C32437DE-40E9-4AD5-9C04-F62152CE4203}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CS1\Services\Tcpip\..\{65689721-626E-4932-B577-09E124680B7D}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{C32437DE-40E9-4AD5-9C04-F62152CE4203}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CS2\Services\Tcpip\..\{65689721-626E-4932-B577-09E124680B7D}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{C32437DE-40E9-4AD5-9C04-F62152CE4203}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll ~ Winlogon: Scanned in 00mn 00s ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. ~ SSODL: 1 Scanned in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: avast! Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc O23 - Service: MaintainerSvc3.75.5000057 (MaintainerSvc3.75.5000057) . (...) - C:\ProgramData\75acca2f-18f9-4ee2-81a2-0d40cd9a3cbd\maintainer.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) . (.Pas de propriétaire - RichVideo Module.) - C:\Program Files\CyberLink\Shared files\RichVideo.exe O23 - Service: TomTomHOMEService (TomTomHOMEService) . (.TomTom - Windows Service for TomTom HOME.) - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe ~ Services: 6 Scanned in 00mn 05s ---\\ Enumération Active Desktop & MHTML Editor (O24) O24 - Default MHTML Editor: Last - .(...) - (.not file.) ~ Desktop Component: 4 Scanned in 00mn 00s ---\\ Enumère les données de BootExecute (BEX) (O34) O34 - HKLM BootExecute: (autocheck autochk *) - File not found ~ BEX: 1 Scanned in 00mn 00s ---\\ Tâches planifiées en automatique (O39) [MD5.2637233632CCD1837A1A57A43CAF00A4] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [267440] [MD5.167F9E5AF87B57763DAAA27D3144C2A0] [APT] [advSRS4] (.SEC.) -- C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2201192] [MD5.081DBA7C93F21B61DF1C5CE9E8AD0522] [APT] [APSchedulerC] (.DoctorSoft.) -- C:\Program Files\AnyPC Client\APLanMgrC.exe [79360] [MD5.1AD8512A5C40AD1A0558498D8E0AC2AA] [APT] [avast! Emergency Update] (.AVAST Software.) -- C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe [808448] [MD5.21E26DC6538C0C255467312559BEB107] [APT] [batteryLifeExtender] (.Samsung Electronics. Co. Ltd..) -- C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [567976] [MD5.04505C46F9CB7D8F8769B566EDC42282] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [4505368] [MD5.A46796CCF032D35720347262998D1F90] [APT] [EasyDisplayMgr] (.Samsung Electronics Co., Ltd..) -- C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [835072] [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [116648] [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [116648] [MD5.00000000000000000000000000000000] [APT] [Yahoo! Search Updater] (...) -- C:\Users\Charline\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrsetup.exe (.not file.) [0] =>PUP.PaybyAds [MD5.00000000000000000000000000000000] [APT] [{14767F98-96CE-4E23-BF77-63D8A3EA9847}] (...) -- C:\Program Files\Skype\Phone\Skype.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{148E6CB2-1D31-41E2-9E76-42CDC86DBC0A}] (...) -- C:\Program Files\Skype\Phone\Skype.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{8BAAACF0-4896-41C3-8FCF-7CC475E2BFA4}] (...) -- E:\Sims3Setup.exe (.not file.) [0] [MD5.0D3745CA2F064F2D6B6388C6AA5D3BC7] [APT] [{BF0D74FF-157E-4F8B-8466-F187EC54DF6C}] (.Google Inc..) -- c:\program files\google\chrome\application\chrome.exe [844752] [MD5.0D3745CA2F064F2D6B6388C6AA5D3BC7] [APT] [{DA2811D2-E785-414D-AF7F-219BE69DC4E9}] (.Google Inc..) -- c:\program files\google\chrome\application\chrome.exe [844752] O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002] O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1056] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1056] O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1060] O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1060] ~ Scheduled Task: 21 Scanned in 00mn 05s ---\\ Composants installés (ActiveSetup Installed Components) (O40) O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll O40 - ASIC: Internet Explorer - {2D46B6DC-2207-486B-B523-A557E6D54B47} . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\system32\cmd.exe =>.Microsoft Corporation O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll O40 - ASIC: Google Chrome - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\30.0.1599.69\Installer\chrmstp.exe O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11CF-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 15.0 r0.) -- C:\Windows\system32\Macromed\Flash\Flash32_15_0_0_167.ocx ~ Active Setup: 12 Scanned in 00mn 00s ---\\ Pilotes lancés au démarrage du système (O41) O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys O41 - Driver: (aswRdr) . (.AVAST Software - avast! WFP Redirect Driver.) - C:\Windows\system32\drivers\aswRdr2.sys O41 - Driver: (aswSnx) . (.AVAST Software - avast! Virtualization Driver.) - C:\Windows\system32\drivers\aswSnx.sys O41 - Driver: (aswSP) . (.AVAST Software - avast! self protection module.) - C:\Windows\system32\drivers\aswSP.sys O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys O41 - Driver: (SABI) . (.SAMSUNG ELECTRONICS - SAMSUNG Kernel Driver.) - C:\Windows\system32\Drivers\SABI.sys O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys ~ Drivers: 72 Scanned in 00mn 00s ---\\ Logiciels installés (O42) O42 - Logiciel: Adobe Flash Player 15 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Flash Player 15 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin O42 - Logiciel: Adobe Reader XI (11.0.09) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AB0000000001} O42 - Logiciel: AnyPC Client - (.Doctorsoft.) [HKLM] -- {1AFA1FEF-8CF9-4A51-AC46-64FAA7F3D9E2} O42 - Logiciel: Archiveur WinRAR - (...) [HKLM] -- WinRAR archiver O42 - Logiciel: Atheros Client Installation Program - (.Atheros.) [HKLM] -- {D1434266-0486-4469-B338-A60082CC04E1} O42 - Logiciel: Auslogics DiskDefrag - (.Auslogics Labs Pty Ltd.) [HKLM] -- {DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1 O42 - Logiciel: BatteryLifeExtender - (.Samsung.) [HKLM] -- {853F8A41-A3C9-43FA-87FA-1AE74FC6F3F7} O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner O42 - Logiciel: CPUID CPU-Z 1.71 - (...) [HKLM] -- CPUID CPU-Z_is1 O42 - Logiciel: Complément Messenger - (.Microsoft Corporation.) [HKLM] -- {6E5324C1-84FC-4F76-9A3A-C65E07F80EE6} O42 - Logiciel: CyberLink DVD Suite - (.CyberLink Corp..) [HKLM] -- InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79} O42 - Logiciel: CyberLink DVD Suite - (.CyberLink Corp..) [HKLM] -- {1FBF6C24-C1FD-4101-A42B-0C564F9E8E79} O42 - Logiciel: CyberLink LabelPrint - (.CyberLink Corp..) [HKLM] -- InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243} O42 - Logiciel: CyberLink LabelPrint - (.CyberLink Corp..) [HKLM] -- {C59C179C-668D-49A9-B6EA-0121CCFC1243} O42 - Logiciel: CyberLink Power2Go - (.CyberLink Corp..) [HKLM] -- InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658} O42 - Logiciel: CyberLink Power2Go - (.CyberLink Corp..) [HKLM] -- {40BF1E83-20EB-11D8-97C5-0009C5020658} O42 - Logiciel: CyberLink PowerDVD 8 - (.CyberLink Corp..) [HKLM] -- InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47} O42 - Logiciel: CyberLink PowerDVD 8 - (.CyberLink Corp..) [HKLM] -- {2BF2E31F-B8BB-40A7-B650-98D28E0F7D47} O42 - Logiciel: CyberLink PowerDirector - (.CyberLink Corp..) [HKLM] -- InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1} O42 - Logiciel: CyberLink PowerDirector - (.CyberLink Corp..) [HKLM] -- {CB099890-1D5F-11D5-9EA9-0050BAE317E1} O42 - Logiciel: CyberLink PowerProducer - (.CyberLink Corp..) [HKLM] -- InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861} O42 - Logiciel: CyberLink PowerProducer - (.CyberLink Corp..) [HKLM] -- {B7A0CE06-068E-11D6-97FD-0050BACBF861} O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM] -- InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D} O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM] -- {01FB4998-33C4-4431-85ED-079E3EEFE75D} O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} O42 - Logiciel: Dropbox - (.Dropbox, Inc..) [HKCU] -- Dropbox O42 - Logiciel: Easy Display Manager - (.Samsung Electronics Co., Ltd..) [HKLM] -- {17283B95-21A8-4996-97DA-547A48DB266F} O42 - Logiciel: Easy Network Manager - (.Samsung.) [HKLM] -- {A5675A9E-F073-414A-9A04-F9BCD50459D7} O42 - Logiciel: Easy SpeedUp Manager - (.Samsung Electronics Co.,Ltd..) [HKLM] -- {EF367AA4-070B-493C-9575-85BE59D789C9} O42 - Logiciel: EasyBatteryManager - (.Samsung.) [HKLM] -- {178EE5F4-0F86-4BF0-A0D1-9790AFF409D1} O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} O42 - Logiciel: Intel® Matrix Storage Manager - (.Intel Corporation.) [HKLM] -- {9068B2BE-D93A-4C0A-861C-5E35E2C0E09E} O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4} O42 - Logiciel: K-Lite Codec Pack 7.0.0 (Standard) - (...) [HKLM] -- KLiteCodecPack_is1 O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71} O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC} O42 - Logiciel: Malwarebytes Anti-Malware version 2.0.3.1025 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1 O42 - Logiciel: Marvell Miniport Driver - (.Marvell.) [HKLM] -- Marvell Miniport Driver O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} O42 - Logiciel: Mozilla Firefox 33.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 33.0.2 (x86 fr) O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService O42 - Logiciel: Music Transfer - (.Sony Corporation.) [HKLM] -- {CE2121C6-C94D-4A73-8EA4-6943F33EE335} O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} O42 - Logiciel: Recuva - (.Piriform.) [HKLM] -- Recuva O42 - Logiciel: Reimage Protector - (.Reimage.) [HKLM] -- Reimage Protector =>Rogue.ReimageRepair O42 - Logiciel: Samsung Recovery Solution 4 - (.Samsung.) [HKLM] -- {145DE957-0679-4A2A-BB5C-1D3E9808FAB2} O42 - Logiciel: Samsung Support Center - (.Samsung.) [HKLM] -- {CCC2B140-B47A-45FA-AAE3-BD60DA41AE00} O42 - Logiciel: Samsung Update Plus - (.Samsung Electronics Co., Ltd..) [HKLM] -- {D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5} O42 - Logiciel: Sony Picture Utility - (.Sony Corporation.) [HKLM] -- {D5068583-D569-468B-9755-5FBF5848F46F} O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey O42 - Logiciel: TomTom HOME - (.Nom de votre société.) [HKLM] -- {99072AB4-D795-44D5-9D65-E3C9F8322C97} O42 - Logiciel: TomTom HOME Visual Studio Merge Modules - (.TomTom International B.V..) [HKLM] -- {8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533} O42 - Logiciel: Ultra Defragmenter - (.UltraDefrag Development Team.) [HKLM] -- UltraDefrag O42 - Logiciel: User Guide - (...) [HKLM] -- {BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA} O42 - Logiciel: avast! Free Antivirus v9.0.2021 - (.AVAST Software.) [HKLM] -- avast O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU] -- uTorrent =>P2P.BitTorrent ~ Logic: 34 Scanned in 00mn 00s ---\\ HKCU & HKLM Software Keys [HKCU\Software\ALWIL Software] [HKCU\Software\AVAST Software] [HKCU\Software\Adobe] [HKCU\Software\AlexSoft] [HKCU\Software\AppDataLow\FDA] [HKCU\Software\AppDataLow] [HKCU\Software\Aurigma] [HKCU\Software\BitTorrent] =>P2P.BitTorrent [HKCU\Software\CeWe Color] [HKCU\Software\Classes] [HKCU\Software\Clients] [HKCU\Software\CyberLink] [HKCU\Software\EasyBits] [HKCU\Software\FreeOpener] [HKCU\Software\GNU] [HKCU\Software\Gabest] [HKCU\Software\Google] [HKCU\Software\Haali] [HKCU\Software\IM Providers] [HKCU\Software\Infigo] [HKCU\Software\Intel] [HKCU\Software\Lake] [HKCU\Software\Local AppWizard-Generated Applications] [HKCU\Software\MCAFEE] [HKCU\Software\MONOGRAM] [HKCU\Software\Macromedia] [HKCU\Software\MediaInfo] [HKCU\Software\MozillaPlugins] [HKCU\Software\Mozilla] [HKCU\Software\Netscape] [HKCU\Software\ODBC] [HKCU\Software\Piriform] [HKCU\Software\Policies] [HKCU\Software\Realtek] [HKCU\Software\Samsung] [HKCU\Software\Skype] [HKCU\Software\Sony Corporation] [HKCU\Software\Synaptics] [HKCU\Software\TeleCharger] [HKCU\Software\TomTom] [HKCU\Software\Trolltech] [HKCU\Software\VB and VBA Program Settings] [HKCU\Software\WinRAR SFX] [HKCU\Software\WinRAR] [HKCU\Software\ZebHelpProcess Helper] [HKCU\Software\madFlac] [HKLM\Software\ALWIL Software] [HKLM\Software\ASK] [HKLM\Software\ATI Technologies] [HKLM\Software\AVAST Software] [HKLM\Software\Adobe] [HKLM\Software\AdwCleaner] [HKLM\Software\America Online] [HKLM\Software\Atheros] [HKLM\Software\Auslogics] [HKLM\Software\BrowserChoice] [HKLM\Software\Bunndle] [HKLM\Software\CHECKINSTALLER] [HKLM\Software\CPUID] [HKLM\Software\Canon] [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\Codec Tweak Tool] [HKLM\Software\CyberLink] [HKLM\Software\Dr.Soft] [HKLM\Software\Electronic Arts] [HKLM\Software\GNU] [HKLM\Software\Google] [HKLM\Software\HPS] [HKLM\Software\HaaliMkx] [HKLM\Software\Infigo] [HKLM\Software\InstalledOptions] [HKLM\Software\Intel] [HKLM\Software\KLCodecPack] [HKLM\Software\Lake] [HKLM\Software\Macromedia] [HKLM\Software\Marvell] [HKLM\Software\McAfee.com] [HKLM\Software\McAfeeInstaller] [HKLM\Software\Mircrosoft] [HKLM\Software\MozillaPlugins] [HKLM\Software\Mozilla] [HKLM\Software\ODBC] [HKLM\Software\Piriform] [HKLM\Software\Policies] [HKLM\Software\Realtek Semiconductor Corp.] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\SRS Labs] [HKLM\Software\Samsung] [HKLM\Software\Sims] [HKLM\Software\Skype] [HKLM\Software\Software] [HKLM\Software\Sonic] [HKLM\Software\Sony Corporation] [HKLM\Software\Synaptics] [HKLM\Software\Techcity] [HKLM\Software\TomTom] [HKLM\Software\Volatile] [HKLM\Software\Waves Audio] [HKLM\Software\mcafeeupdater] [HKLM\Software\mozilla.org] ~ Key Software: 198 Scanned in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 25/02/2013 - 13:47:02 - [] ----D C:\Program Files\Adobe O43 - CFD: 11/12/2010 - 23:44:11 - [] ----D C:\Program Files\Alwil Software O43 - CFD: 08/09/2013 - 17:25:47 - [] ----D C:\Program Files\AnyPC Client O43 - CFD: 07/04/2010 - 08:50:33 - [] ----D C:\Program Files\Atheros Client Installation Program O43 - CFD: 30/10/2014 - 21:35:27 - [] ----D C:\Program Files\Auslogics O43 - CFD: 04/03/2014 - 18:33:10 - [] ----D C:\Program Files\CCleaner O43 - CFD: 15/08/2014 - 15:49:54 - [] ----D C:\Program Files\Common Files O43 - CFD: 29/10/2014 - 20:18:33 - [] ----D C:\Program Files\CPUID O43 - CFD: 07/04/2010 - 09:14:33 - [] ----D C:\Program Files\CyberLink O43 - CFD: 22/06/2011 - 09:10:10 - [] ----D C:\Program Files\DVD Maker O43 - CFD: 02/01/2011 - 17:55:13 - [] ----D C:\Program Files\Electronic Arts O43 - CFD: 03/12/2010 - 17:20:48 - [] -SH-D C:\Program Files\Fichiers communs O43 - CFD: 07/10/2013 - 14:58:03 - [] ----D C:\Program Files\Google O43 - CFD: 07/04/2011 - 08:04:20 - [] --H-D C:\Program Files\InstallShield Installation Information O43 - CFD: 05/02/2011 - 01:41:32 - [] ----D C:\Program Files\Intel O43 - CFD: 14/09/2014 - 14:18:57 - [] ----D C:\Program Files\Internet Explorer O43 - CFD: 28/11/2012 - 22:03:13 - [] ----D C:\Program Files\K-Lite Codec Pack O43 - CFD: 29/10/2014 - 17:25:48 - [] ----D C:\Program Files\Malwarebytes Anti-Malware O43 - CFD: 07/04/2010 - 08:49:51 - [] ----D C:\Program Files\Marvell O43 - CFD: 05/12/2010 - 14:23:38 - [0] ----D C:\Program Files\Microsoft O43 - CFD: 14/07/2009 - 08:49:30 - [] ----D C:\Program Files\Microsoft Games O43 - CFD: 01/07/2011 - 17:34:56 - [] ----D C:\Program Files\Microsoft Office O43 - CFD: 30/07/2014 - 18:49:32 - [] ----D C:\Program Files\Microsoft Silverlight O43 - CFD: 05/12/2010 - 14:32:01 - [] ----D C:\Program Files\Microsoft SQL Server Compact Edition O43 - CFD: 28/12/2010 - 18:49:55 - [] ----D C:\Program Files\Microsoft.NET O43 - CFD: 29/10/2014 - 18:06:54 - [] ----D C:\Program Files\Mozilla Firefox O43 - CFD: 29/10/2014 - 17:19:59 - [] ----D C:\Program Files\Mozilla Maintenance Service O43 - CFD: 14/07/2009 - 05:52:30 - [] ----D C:\Program Files\MSBuild O43 - CFD: 13/01/2011 - 19:01:36 - [0] ----D C:\Program Files\MSXML 4.0 O43 - CFD: 05/02/2013 - 18:38:13 - [0] ----D C:\Program Files\photomoinscher 4.6 O43 - CFD: 28/11/2012 - 21:14:45 - [] ----D C:\Program Files\PixelApp Studio O43 - CFD: 07/04/2010 - 08:49:10 - [] ----D C:\Program Files\Realtek O43 - CFD: 24/10/2013 - 11:26:08 - [] ----D C:\Program Files\Recuva O43 - CFD: 14/07/2009 - 05:52:30 - [] ----D C:\Program Files\Reference Assemblies O43 - CFD: 18/12/2010 - 10:20:24 - [] ----D C:\Program Files\Samsung O43 - CFD: 08/01/2011 - 13:37:42 - [] ----D C:\Program Files\Sony O43 - CFD: 07/04/2010 - 08:50:45 - [] ----D C:\Program Files\Synaptics O43 - CFD: 03/05/2011 - 17:18:51 - [] ----D C:\Program Files\Techcity O43 - CFD: 07/04/2011 - 08:04:47 - [0] --H-D C:\Program Files\Temp O43 - CFD: 07/10/2013 - 14:46:11 - [] ----D C:\Program Files\TomTom HOME 2 O43 - CFD: 30/04/2012 - 08:12:33 - [] ----D C:\Program Files\TomTom International B.V O43 - CFD: 01/11/2014 - 18:32:52 - [] ----D C:\Program Files\UltraDefrag O43 - CFD: 14/07/2009 - 05:53:23 - [0] --H-D C:\Program Files\Uninstall Information O43 - CFD: 03/08/2014 - 18:21:37 - [0] ----D C:\Program Files\VideoLAN O43 - CFD: 14/07/2013 - 15:08:47 - [] ----D C:\Program Files\Windows Defender O43 - CFD: 14/07/2014 - 20:18:46 - [] ----D C:\Program Files\Windows Journal O43 - CFD: 05/02/2013 - 18:41:39 - [] ----D C:\Program Files\Windows Live O43 - CFD: 22/06/2011 - 09:10:10 - [] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation O43 - CFD: 16/10/2014 - 16:02:06 - [] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation O43 - CFD: 03/12/2010 - 17:20:48 - [] ----D C:\Program Files\Windows NT O43 - CFD: 22/06/2011 - 09:10:10 - [] ----D C:\Program Files\Windows Photo Viewer O43 - CFD: 22/06/2011 - 09:10:10 - [] ----D C:\Program Files\Windows Portable Devices O43 - CFD: 22/06/2011 - 09:10:10 - [] ----D C:\Program Files\Windows Sidebar O43 - CFD: 12/12/2010 - 11:45:48 - [] ----D C:\Program Files\WinRAR O43 - CFD: 29/10/2014 - 21:29:53 - [] ----D C:\Program Files\ZHPDiag =>.Nicolas Coolman O43 - CFD: 25/02/2013 - 13:47:17 - [] ----D C:\Program Files\Common Files\Adobe O43 - CFD: 07/04/2010 - 08:55:29 - [] ----D C:\Program Files\Common Files\CyberLink O43 - CFD: 28/12/2010 - 18:52:51 - [] ----D C:\Program Files\Common Files\DESIGNER O43 - CFD: 07/04/2010 - 08:49:07 - [] ----D C:\Program Files\Common Files\InstallShield O43 - CFD: 29/07/2011 - 12:05:31 - [] ----D C:\Program Files\Common Files\microsoft shared O43 - CFD: 08/01/2011 - 13:37:27 - [] ----D C:\Program Files\Common Files\PX Storage Engine O43 - CFD: 14/07/2009 - 03:37:05 - [] ----D C:\Program Files\Common Files\Services O43 - CFD: 14/07/2009 - 03:37:05 - [] ----D C:\Program Files\Common Files\SpeechEngines O43 - CFD: 13/11/2011 - 10:18:42 - [] ----D C:\Program Files\Common Files\System O43 - CFD: 05/12/2010 - 13:37:00 - [] ----D C:\Program Files\Common Files\Windows Live O43 - CFD: 01/11/2014 - 18:17:22 - [] ----D C:\ProgramData\75acca2f-18f9-4ee2-81a2-0d40cd9a3cbd O43 - CFD: 27/02/2013 - 10:30:59 - [] ----D C:\ProgramData\Adobe O43 - CFD: 11/12/2010 - 23:44:11 - [] ----D C:\ProgramData\Alwil Software O43 - CFD: 14/07/2009 - 05:53:55 - [] -SH-D C:\ProgramData\Application Data O43 - CFD: 30/10/2014 - 21:35:54 - [] ----D C:\ProgramData\Auslogics O43 - CFD: 03/10/2014 - 18:51:39 - [] ----D C:\ProgramData\AVAST Software O43 - CFD: 03/12/2010 - 17:20:48 - [] -SH-D C:\ProgramData\Bureau O43 - CFD: 12/12/2010 - 10:02:22 - [] --H-D C:\ProgramData\CanonBJ O43 - CFD: 19/02/2011 - 13:08:08 - [] ----D C:\ProgramData\CyberLink O43 - CFD: 14/07/2009 - 05:53:55 - [] -SH-D C:\ProgramData\Desktop O43 - CFD: 14/07/2009 - 05:53:55 - [] -SH-D C:\ProgramData\Documents O43 - CFD: 15/02/2012 - 13:53:47 - [0] ----D C:\ProgramData\eMule O43 - CFD: 03/12/2010 - 17:20:48 - [] -SH-D C:\ProgramData\Favoris O43 - CFD: 14/07/2009 - 05:53:55 - [] -SH-D C:\ProgramData\Favorites O43 - CFD: 11/12/2010 - 14:35:05 - [] ----D C:\ProgramData\hps O43 - CFD: 29/10/2014 - 17:25:44 - [] ----D C:\ProgramData\Malwarebytes O43 - CFD: 27/08/2012 - 09:16:44 - [] ----D C:\ProgramData\McAfee O43 - CFD: 03/12/2010 - 17:20:48 - [] -SH-D C:\ProgramData\Menu Démarrer O43 - CFD: 04/03/2014 - 19:12:56 - [] -S--D C:\ProgramData\Microsoft O43 - CFD: 03/12/2010 - 17:20:48 - [] -SH-D C:\ProgramData\Modèles O43 - CFD: 29/10/2014 - 17:19:58 - [] ----D C:\ProgramData\Mozilla O43 - CFD: 07/04/2010 - 09:03:27 - [] ----D C:\ProgramData\SAMSUNG O43 - CFD: 07/04/2010 - 09:02:46 - [] ----D C:\ProgramData\SiteAdvisor O43 - CFD: 15/08/2014 - 15:49:34 - [] ----D C:\ProgramData\Skype O43 - CFD: 14/07/2009 - 05:53:55 - [] -SH-D C:\ProgramData\Start Menu O43 - CFD: 07/04/2010 - 09:14:20 - [] ----D C:\ProgramData\Temp O43 - CFD: 14/07/2009 - 05:53:55 - [] -SH-D C:\ProgramData\Templates O43 - CFD: 11/12/2010 - 14:53:44 - [] ----D C:\ProgramData\tmp O43 - CFD: 30/04/2012 - 08:12:56 - [] ----D C:\ProgramData\TomTom O43 - CFD: 18/12/2010 - 10:20:54 - [] ----D C:\ProgramData\WinClon O43 - CFD: 25/02/2013 - 13:49:19 - [] ----D C:\Users\Charline\AppData\Roaming\Adobe O43 - CFD: 14/10/2014 - 18:01:20 - [] ----D C:\Users\Charline\AppData\Roaming\AVAST Software O43 - CFD: 19/02/2011 - 12:20:56 - [] ----D C:\Users\Charline\AppData\Roaming\CyberLink O43 - CFD: 01/11/2014 - 18:16:59 - [] ----D C:\Users\Charline\AppData\Roaming\Dropbox O43 - CFD: 29/06/2012 - 14:21:40 - [] ----D C:\Users\Charline\AppData\Roaming\dvdcss O43 - CFD: 28/11/2012 - 21:15:53 - [0] ----D C:\Users\Charline\AppData\Roaming\Free Photo Converter O43 - CFD: 03/12/2010 - 17:21:39 - [] ----D C:\Users\Charline\AppData\Roaming\Identities O43 - CFD: 08/01/2011 - 13:36:34 - [] ----D C:\Users\Charline\AppData\Roaming\InstallShield O43 - CFD: 05/12/2010 - 11:16:40 - [] ----D C:\Users\Charline\AppData\Roaming\Macromedia O43 - CFD: 14/07/2009 - 08:48:18 - [0] ----D C:\Users\Charline\AppData\Roaming\Media Center Programs O43 - CFD: 22/10/2013 - 17:37:42 - [] -S--D C:\Users\Charline\AppData\Roaming\Microsoft O43 - CFD: 29/10/2014 - 17:20:06 - [] ----D C:\Users\Charline\AppData\Roaming\Mozilla O43 - CFD: 04/03/2014 - 18:35:27 - [] ----D C:\Users\Charline\AppData\Roaming\Skype O43 - CFD: 05/07/2011 - 15:17:22 - [] ----D C:\Users\Charline\AppData\Roaming\skypePM O43 - CFD: 08/01/2011 - 13:48:49 - [] ----D C:\Users\Charline\AppData\Roaming\Sony Corporation O43 - CFD: 30/04/2012 - 08:12:42 - [] ----D C:\Users\Charline\AppData\Roaming\TomTom O43 - CFD: 01/11/2014 - 23:50:32 - [] ----D C:\Users\Charline\AppData\Roaming\uTorrent =>P2P.µTorrent O43 - CFD: 23/12/2010 - 17:07:03 - [] ----D C:\Users\Charline\AppData\Roaming\vlc O43 - CFD: 25/04/2012 - 13:43:10 - [] ----D C:\Users\Charline\AppData\Roaming\Windows Live Writer O43 - CFD: 28/11/2012 - 21:44:52 - [] ----D C:\Users\Charline\AppData\Roaming\XnView O43 - CFD: 01/11/2014 - 23:50:51 - [] ----D C:\Users\Charline\AppData\Roaming\ZHP =>.Nicolas Coolman O43 - CFD: 29/10/2014 - 20:40:09 - [] ----D C:\Users\Charline\AppData\Local\Adobe O43 - CFD: 03/12/2010 - 17:20:57 - [] -SH-D C:\Users\Charline\AppData\Local\Application Data O43 - CFD: 05/12/2010 - 12:22:32 - [] ----D C:\Users\Charline\AppData\Local\Apps O43 - CFD: 07/10/2013 - 14:57:42 - [0] ----D C:\Users\Charline\AppData\Local\Deployment O43 - CFD: 21/04/2014 - 12:35:54 - [0] ----D C:\Users\Charline\AppData\Local\Diagnostics O43 - CFD: 07/10/2013 - 14:43:36 - [] ----D C:\Users\Charline\AppData\Local\Downloaded Installations O43 - CFD: 15/08/2014 - 15:45:23 - [] -SH-D C:\Users\Charline\AppData\Local\EmieSiteList O43 - CFD: 15/08/2014 - 15:45:23 - [] -SH-D C:\Users\Charline\AppData\Local\EmieUserList O43 - CFD: 05/12/2010 - 14:28:01 - [] ----D C:\Users\Charline\AppData\Local\Google O43 - CFD: 03/12/2010 - 17:20:57 - [] -SH-D C:\Users\Charline\AppData\Local\Historique O43 - CFD: 29/10/2014 - 21:08:58 - [] ----D C:\Users\Charline\AppData\Local\Macromedia O43 - CFD: 01/12/2013 - 14:55:05 - [] ----D C:\Users\Charline\AppData\Local\Microsoft O43 - CFD: 20/03/2011 - 17:46:36 - [] ----D C:\Users\Charline\AppData\Local\Microsoft Games O43 - CFD: 29/10/2014 - 17:20:49 - [] ----D C:\Users\Charline\AppData\Local\Mozilla O43 - CFD: 03/12/2010 - 17:22:47 - [] ----D C:\Users\Charline\AppData\Local\Power2Go O43 - CFD: 29/10/2014 - 17:25:19 - [] ----D C:\Users\Charline\AppData\Local\Programs O43 - CFD: 01/11/2014 - 23:48:51 - [] ----D C:\Users\Charline\AppData\Local\Temp O43 - CFD: 03/12/2010 - 17:20:57 - [] -SH-D C:\Users\Charline\AppData\Local\Temporary Internet Files O43 - CFD: 30/04/2012 - 08:12:42 - [] ----D C:\Users\Charline\AppData\Local\TomTom O43 - CFD: 28/11/2012 - 22:05:05 - [] ----D C:\Users\Charline\AppData\Local\UniversalFileOpener O43 - CFD: 22/10/2013 - 17:37:42 - [] ----D C:\Users\Charline\AppData\Local\VirtualStore O43 - CFD: 28/11/2012 - 21:23:43 - [] ----D C:\Users\Charline\AppData\Local\Windows Live O43 - CFD: 25/05/2011 - 16:12:41 - [] ----D C:\Users\Charline\AppData\Local\Windows Live Writer O43 - CFD: 14/07/2009 - 05:42:04 - [] R---D C:\Users\Charline\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 15/08/2014 - 14:56:59 - [] R---D C:\Users\Charline\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 01/11/2014 - 18:16:12 - [] ----D C:\Users\Charline\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite O43 - CFD: 07/04/2010 - 09:14:47 - [] ----D C:\Users\Charline\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam O43 - CFD: 20/09/2014 - 18:58:45 - [] ----D C:\Users\Charline\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox O43 - CFD: 14/07/2009 - 05:37:42 - [] R---D C:\Users\Charline\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 20/09/2014 - 18:59:07 - [] R---D C:\Users\Charline\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 12/12/2010 - 11:45:49 - [0] ----D C:\Users\Charline\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ~ Program Folder: 147 Scanned in 00mn 00s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.EC08099338112273BE4F97026A95B6B6] - 01/11/2014 - 18:16:00 ---A- . (...) -- C:\Windows\setupact.log [5902] O44 - LFC:[MD5.8E2E9CCD873ABF180F48BCAEEEBE347D] - 01/11/2014 - 18:19:35 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [114904] O44 - LFC:[MD5.EE596E83E0AB161B83E85063C2B29EDB] - 01/11/2014 - 22:41:15 -S-A- . (...) -- C:\Windows\bootstat.dat [67584] O44 - LFC:[MD5.4D27AEA86C0CEEE497764E7779761FFD] - 01/11/2014 - 22:41:24 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1485278] O44 - LFC:[MD5.28D7B6BF4EF26BF9FD04B7FCD8591BB9] - 01/11/2014 - 23:37:53 ---A- . (...) -- C:\sc-cleaner.txt [1814] O44 - LFC:[MD5.42E72543868464142A8520C13C48CE66] - 25/10/2014 - 03:06:22 ---A- . (.UltraDefrag Development Team - ZenWINX library.) -- C:\Windows\System32\zenwinx.dll [343552] O44 - LFC:[MD5.6D778FB06C095AA773E8B647F922EECD] - 25/10/2014 - 03:06:32 ---A- . (.UltraDefrag Development Team - UltraDefrag common procedures.) -- C:\Windows\System32\udefrag.dll [69120] O44 - LFC:[MD5.97A68F1EF4DAA6FC3D1BE5B52982D7AD] - 25/10/2014 - 03:07:04 ---A- . (.UltraDefrag Development Team - UltraDefrag native interface.) -- C:\Windows\System32\defrag_native.exe [416256] O44 - LFC:[MD5.2064E33AA5D0417FBD6B8A194FDD75A6] - 25/10/2014 - 03:07:24 ---A- . (...) -- C:\Windows\System32\lua5.1a.dll [125440] O44 - LFC:[MD5.B48E0512459FF8D7B2B46D9F8741275C] - 25/10/2014 - 03:07:38 ---A- . (.UltraDefrag Development Team - Windows GUI Extended (WGX) Library.) -- C:\Windows\System32\wgx.dll [33792] O44 - LFC:[MD5.DC1DC5E4DA48C4E029CB6965615873A0] - 25/10/2014 - 03:07:40 ---A- . (.UltraDefrag Development Team - BootExecute Control program.) -- C:\Windows\System32\bootexctrl.exe [13824] O44 - LFC:[MD5.19152DCF0BAB44DC5749B9D75A1C6D37] - 25/10/2014 - 03:07:40 ---A- . (.UltraDefrag Development Team - Hibernate for Windows.) -- C:\Windows\System32\hibernate4win.exe [14336] O44 - LFC:[MD5.6B8AE454C6ACE8F609FC6B5179892CAB] - 25/10/2014 - 03:07:46 ---A- . (.UltraDefrag Development Team - UltraDefrag console interface.) -- C:\Windows\System32\udefrag.exe [94208] O44 - LFC:[MD5.D618D6D6E8C006E8D426500ED20BF4A4] - 28/10/2014 - 06:35:00 ----- . (.Microsoft Corporation - Microsoft Malware Protection Signature Upda.) -- C:\Windows\System32\MpSigStub.exe [229000] O44 - LFC:[MD5.205213E58C19B72E02E6D3DDEAB38998] - 29/10/2014 - 17:04:54 ---A- . (...) -- C:\Windows\win.ini [633] O44 - LFC:[MD5.D2DED3C333A5D9CB3F4C244B0F0DD877] - 29/10/2014 - 17:25:44 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23256] O44 - LFC:[MD5.E89B115E1DD297DCB694B22CFA90BF61] - 29/10/2014 - 17:25:44 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [75480] O44 - LFC:[MD5.7A6526C8BD114DB7CA8930AB22D52A0B] - 29/10/2014 - 17:25:44 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [51928] O44 - LFC:[MD5.BD66DA54FFF371C491CE1C342BB23763] - 29/10/2014 - 20:38:51 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\Windows\System32\FlashPlayerApp.exe [701104] O44 - LFC:[MD5.A4A64E86CE5D3090C82D0A7D4C90AA32] - 29/10/2014 - 20:38:51 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [71344] O44 - LFC:[MD5.016E3F030D09DB15030E454DA2F8F1C0] - 29/10/2014 - 21:07:38 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1669656] O44 - LFC:[MD5.05BB12B1B636F1DD1B4FDC103E467B60] - 29/10/2014 - 21:07:38 ---A- . (...) -- C:\Windows\System32\perfc009.dat [122352] O44 - LFC:[MD5.55FB0472C45C13FEFCD57F236206D235] - 29/10/2014 - 21:07:38 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [150402] O44 - LFC:[MD5.F8747944FA0D972295616CFF255302E4] - 29/10/2014 - 21:07:38 ---A- . (...) -- C:\Windows\System32\perfh009.dat [654480] O44 - LFC:[MD5.B467DBC2FC2CF945D49A91C22BD9B126] - 29/10/2014 - 21:07:38 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [747910] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 29/10/2014 - 21:29:55 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [0] O44 - LFC:[MD5.0DC5AF80D059DEC792B665ED598C6567] - 30/10/2014 - 13:14:42 ---A- . (.SQLite Development Team - SQLite Dynamic Link Library (No TCL).) -- C:\Windows\System32\sqlite3.dll [536576] O44 - LFC:[MD5.C6933E1D41C2BAF1ACEFFE319F5CF646] - 30/10/2014 - 13:20:36 ---A- . (...) -- C:\Windows\PFRO.log [169162] ~ Files: 28 Scanned in 00mn 24s ---\\ Déni du service (Local Security Authority) (O48) O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corp. - LiveSSP.) -- C:\Windows\System32\livessp.dll ~ LSA: 9 Scanned in 00mn 00s ---\\ Contrôle du Safe Boot (CSB) (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys ~ CSB: 13 Scanned in 00mn 00s ---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52) O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll O52 - TDSD: \Drivers32\"VIDC.XVID"="xvidvfw.dll" . (...) -- C:\Windows\System32\xvidvfw.dll O52 - TDSD: \Drivers32\"VIDC.YV12"="yv12vfw.dll" . (.www.helixcommunity.org - Helix YV12 YUV Codec.) -- C:\Windows\System32\yv12vfw.dll O52 - TDSD: \Drivers32\"msacm.ac3acm"="ac3acm.acm" . (.fccHandler - AC-3 ACM Codec.) -- C:\Windows\System32\ac3acm.acm O52 - TDSD: \Drivers32\"msacm.lameacm"="lameACM.acm" . (.http://www.mp3dev.org/ - Lame MP3 codec engine.) -- C:\Windows\System32\lameACM.acm O52 - TDSD: \Drivers32\"VIDC.FFDS"="ff_vfw.dll" . (...) -- C:\Windows\System32\ff_vfw.dll O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \drivers.desc\"ac3acm.acm"="AC-3 ACM Codec" . (.fccHandler - AC-3 ACM Codec.) -- C:\Windows\System32\ac3acm.acm O52 - TDSD: \drivers.desc\"ff_vfw.dll"="ffdshow video encoder" . (...) -- C:\Windows\System32\ff_vfw.dll ~ TDSD: 10 Scanned in 00mn 00s ---\\ Enumération des clés de registre SecurityProviders (MCSP) (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll ~ MSCP: 2 Scanned in 00mn 00s ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0 O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 O55 - MWPS:[HKCU\...\Policies\System] - "DisableRegistryTools"=0 O55 - MWPS:[HKCU\...\Policies\System] - "DisableTaskMgr"=0 ~ MWPS: 18 Scanned in 00mn 00s ---\\ Liste des pilotes du système (SDL) (O58) O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976] O58 - SDL:14/07/2009 - 02:26:17 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [297552] O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\Drivers\adpu320.sys [146512] O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [14400] O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [80256] O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows fa.) -- C:\Windows\System32\Drivers\amdsbs.sys [159312] O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [22400] O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [76368] O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [86608] O58 - SDL:03/10/2014 - 18:54:17 ---A- . (...) -- C:\Windows\System32\Drivers\aswHwid.sys [24184] =>.ALWIL Software O58 - SDL:03/10/2014 - 18:54:17 ---A- . (.AVAST Software - avast! File System Minifilter for Windows 2003/Vista.) -- C:\Windows\System32\Drivers\aswMonFlt.sys [67824] O58 - SDL:07/09/2010 - 16:47:46 ---A- . (.AVAST Software - avast! TDI RDR Driver.) -- C:\Windows\System32\Drivers\aswRdr.sys [23376] O58 - SDL:03/10/2014 - 18:54:17 ---A- . (.AVAST Software - avast! WFP Redirect Driver.) -- C:\Windows\System32\Drivers\aswRdr2.sys [81768] O58 - SDL:03/10/2014 - 18:54:17 ---A- . (...) -- C:\Windows\System32\Drivers\aswRvrt.sys [49944] =>.ALWIL Software O58 - SDL:03/10/2014 - 18:54:18 ---A- . (.AVAST Software - avast! Virtualization Driver.) -- C:\Windows\System32\Drivers\aswSnx.sys [779536] O58 - SDL:14/10/2014 - 18:55:15 ---A- . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\Drivers\aswsp.sys [414520] O58 - SDL:03/10/2014 - 18:54:18 ---A- . (.AVAST Software - Stream Filter.) -- C:\Windows\System32\Drivers\aswStm.sys [71944] O58 - SDL:03/10/2014 - 18:54:18 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys [192352] =>.ALWIL Software O58 - SDL:23/11/2010 - 16:10:44 ---A- . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driver.) -- C:\Windows\System32\Drivers\athr.sys [1249792] O58 - SDL:13/07/2009 - 23:02:49 ---A- . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gigabit Ethernet..) -- C:\Windows\System32\Drivers\b57nd60x.sys [229888] O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [13568] O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [5248] O58 - SDL:14/07/2009 - 01:57:25 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [272128] O58 - SDL:13/07/2009 - 23:53:32 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [62336] O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [12160] O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [11904] O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbdx.sys [430080] O58 - SDL:04/07/2008 - 11:22:36 ---A- . (.Sonic Solutions - CDR4 CD and DVD Place Holder Driver (see PxHelp).) -- C:\Windows\System32\Drivers\cdr4_xp.sys [9072] O58 - SDL:04/07/2008 - 11:22:36 ---A- . (.Sonic Solutions - CDRAL Place Holder Driver (see PxHelp).) -- C:\Windows\System32\Drivers\cdralw2k.sys [9200] O58 - SDL:14/07/2009 - 02:26:21 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [15952] O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\Drivers\djsvs.sys [70720] O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712] O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbdx.sys [3100160] O58 - SDL:13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624] O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [67152] O58 - SDL:13/10/2009 - 10:09:36 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStor.sys [331288] O58 - SDL:11/03/2011 - 06:38:51 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332160] O58 - SDL:25/08/2010 - 19:31:30 ---A- . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\Drivers\igdkmd32.sys [9024512] O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [41040] O58 - SDL:26/02/2010 - 19:37:15 ---A- . (.Intel® Corporation - Intel® High Definition Audio HDMI.) -- C:\Windows\System32\Drivers\IntcHdmi.sys [122880] O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [95824] O58 - SDL:14/07/2009 - 02:20:37 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [89168] O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [54864] O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [96848] O58 - SDL:01/10/2014 - 11:11:10 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23256] O58 - SDL:01/10/2014 - 11:11:14 ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [75480] O58 - SDL:01/11/2014 - 18:19:35 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [114904] O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7 for x86.) -- C:\Windows\System32\Drivers\megasas.sys [30800] O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [235584] O58 - SDL:01/10/2014 - 11:11:24 ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [51928] O58 - SDL:14/07/2009 - 02:20:44 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [44624] O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117120] O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [143744] O58 - SDL:04/07/2008 - 11:22:36 ---A- . (.Sonic Solutions - Px Engine Device Driver for Windows 2000/XP.) -- C:\Windows\System32\Drivers\pxhelp20.sys [44944] O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1383488] O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [106064] O58 - SDL:14/12/2009 - 16:44:30 ---A- . (.Realtek Semiconductor Corp. - Realtek® High Definition Audio Function Driver.) -- C:\Windows\System32\Drivers\RTKVHDA.sys [2977248] O58 - SDL:28/05/2009 - 14:38:12 ---A- . (.SAMSUNG ELECTRONICS - SAMSUNG Kernel Driver.) -- C:\Windows\System32\Drivers\SABI.sys [10752] O58 - SDL:13/07/2009 - 21:50:20 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [20480] O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [40016] O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [77888] O58 - SDL:22/01/2014 - 07:52:12 ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudbus.sys [88576] O58 - SDL:22/01/2014 - 07:52:12 ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudmdm.sys [184192] O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072] O58 - SDL:26/02/2010 - 10:33:00 ---A- . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\Windows\System32\Drivers\SynTP.sys [242992] O58 - SDL:14/07/2009 - 02:19:10 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [16976] O58 - SDL:14/07/2009 - 02:19:11 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [141904] O58 - SDL:28/09/2009 - 10:22:00 ---A- . (...) -- C:\Windows\System32\Drivers\yk62x86.sys [315392] O58 - SDL:13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029] O58 - SDL:13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097] O58 - SDL:13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768] O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809] O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537] O58 - SDL:13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866] O58 - SDL:13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146] O58 - SDL:13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370] O58 - SDL:13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274] O58 - SDL:13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146] O58 - SDL:13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952] O58 - SDL:13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672] O58 - SDL:13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776] O58 - SDL:13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536] O58 - SDL:13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672] ~ Drivers: 83 Scanned in 00mn 04s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC: 01/11/2014 - 23:51:27 ---A- . (...) -- C:\Users\Charline\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpbaigwa.dll [43008] O61 - LFC: 29/10/2014 - 23:51:29 ---A- . (...) -- C:\Users\Charline\Downloads\Firefox Setup Stub 33.0.2.exe [244352] O61 - LFC: 29/10/2014 - 23:51:29 ---A- . (...) -- C:\Users\Charline\Downloads\adwcleaner_4.002.exe [1998336] O61 - LFC: 29/10/2014 - 23:51:29 ---A- . (...) -- C:\Users\Charline\Downloads\cpu-z_1-71-0_en_11090.exe [1540816] O61 - LFC: 29/10/2014 - 23:51:29 ---A- . (.BitTorrent Inc..) -- C:\Users\Charline\AppData\Roaming\uTorrent\uTorrent.exe [1385808] =>P2P.BitTorrent O61 - LFC: 29/10/2014 - 23:51:29 ---A- . (.BitTorrent Inc..) -- C:\Users\Charline\AppData\Roaming\uTorrent\updates\3.4.2_34944.exe [1385808] =>P2P.BitTorrent O61 - LFC: 29/10/2014 - 23:51:29 ---A- . (.Malwarebytes Corporation.) -- C:\Users\Charline\Downloads\mbam-setup-2.0.3.1025.exe [19828376] O61 - LFC: 29/10/2014 - 23:51:29 ---A- . (.Nicolas Coolman.) -- C:\Users\Charline\Desktop\ZHPDiag2.exe [6862591] =>.Nicolas Coolman O61 - LFC: 29/10/2014 - 23:51:29 ---A- . (.Nicolas Coolman.) -- C:\Users\Charline\Downloads\ZHPDiag2.exe [6862591] =>.Nicolas Coolman O61 - LFC: 29/10/2014 - 23:51:29 ---A- . (.Piriform Ltd.) -- C:\Users\Charline\Downloads\ccsetup419.exe [4974864] O61 - LFC: 29/10/2014 - 23:51:29 ---A- . (.Safer-Networking Ltd..) -- C:\Users\Charline\Downloads\spybot-2.4.exe [46522704] O61 - LFC: 29/10/2014 - 23:51:29 ---A- . (.Thisisu.) -- C:\Users\Charline\Downloads\JRT.exe [1706144] O61 - LFC: 30/10/2014 - 23:51:26 ---A- . (...) -- C:\Users\Charline\AppData\Local\Microsoft\Internet Explorer\UrlBlockManager\urlblocklist.bin [0] O61 - LFC: 30/10/2014 - 23:51:29 ---A- . (...) -- C:\Users\Charline\Downloads\SFTGC.exe [1348096] O61 - LFC: 30/10/2014 - 23:51:29 ---A- . (...) -- C:\Users\Charline\Downloads\adwcleaner_3.311.exe [1375089] O61 - LFC: 30/10/2014 - 23:51:29 ---A- . (.Auslogics Labs Pty Ltd.) -- C:\Users\Charline\Downloads\auslogics-disk-defrag_5-0-0-0_en_26672.exe [6600096] O61 - LFC: 30/10/2014 - 23:51:29 ---A- . (.Bleeping Computer, LLC.) -- C:\Users\Charline\Downloads\sc-cleaner.exe [441592] O61 - LFC: 30/10/2014 - 23:51:29 ---A- . (.Thisisu.) -- C:\Users\Charline\Downloads\JRT(1).exe [1706144] O61 - LFC: 30/10/2014 - 23:51:29 ---A- . (.UltraDefrag Development Team.) -- C:\Users\Charline\Downloads\ultradefrag_6-0-4_fr_68760_32.exe [684238] ~ 29 Fichiers temporaires (Temporary files) ~ 43 Fichiers cookies (Cookies files) ~ Files: 19 Scanned in 00mn 03s ---\\ Liste des outils de désinfection (LATC) (O63) O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn 00s ---\\ Liste les services legacy du registre (LALS) (O64) O64 - Services: CurCS - 03/10/2014 - C:\Windows\system32\drivers\aswHwid.sys (aswHwid) .(...) - LEGACY_ASWHWID O64 - Services: CurCS - 03/10/2014 - C:\Windows\system32\drivers\aswMonFlt.sys (aswMonFlt) .(.AVAST Software - avast! File System Minifilter for Windows 2.) - LEGACY_ASWMONFLT O64 - Services: CurCS - 03/10/2014 - C:\Windows\system32\drivers\aswRdr2.sys (aswRdr) .(.AVAST Software - avast! WFP Redirect Driver.) - LEGACY_ASWRDR O64 - Services: CurCS - 03/10/2014 - C:\Windows\System32\Drivers\aswRvrt.sys (aswRvrt) .(...) - LEGACY_ASWRVRT O64 - Services: CurCS - 03/10/2014 - C:\Windows\system32\drivers\aswSnx.sys (aswSnx) .(.AVAST Software - avast! Virtualization Driver.) - LEGACY_ASWSNX O64 - Services: CurCS - 14/10/2014 - C:\Windows\system32\drivers\aswSP.sys (aswSP) .(.AVAST Software - avast! self protection module.) - LEGACY_ASWSP O64 - Services: CurCS - 03/10/2014 - C:\Windows\system32\drivers\aswStm.sys (aswStm) .(.AVAST Software - Stream Filter.) - LEGACY_ASWSTM O64 - Services: CurCS - 03/10/2014 - C:\Windows\System32\Drivers\aswVmm.sys (aswVmm) .(...) - LEGACY_ASWVMM O64 - Services: CurCS - 01/11/2014 - C:\Windows\system32\drivers\MBAMSwissArmy.sys (MBAMSwissArmy) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMSWISSARMY O64 - Services: CurCS - 28/05/2009 - C:\Windows\system32\Drivers\SABI.sys (SABI) .(.SAMSUNG ELECTRONICS - SAMSUNG Kernel Driver.) - LEGACY_SABI O64 - Services: CurCS - 13/07/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV ~ Legacy: 88 Scanned in 00mn 00s ---\\ Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Not Key.) ~ FASS Keys: 11 Scanned in 00mn 00s ---\\ Menu de démarrage Internet (SMI) (O68) O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com ~ Keys: Scanned in 00mn 00s ---\\ Enumère les service demarrés par Svchost (SSS) (O83) O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [62464] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [473600] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [90624] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [286208] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [49664] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows.) -- C:\Windows\System32\tapisrv.dll [242176] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [523264] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [1973728] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [47104] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [49664] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164352] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [71168] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [113664] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [102912] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800] ~ Services: 32 Scanned in 00mn 00s ---\\ Recherche particulière à la racine du système (SPRF) (O84) [MD5.EDF5D90FBC4CEB47321401C64E9D352E] [sPRF][05/12/2010] (...) -- C:\ProgramData\ezsidmv.dat [56] [MD5.BB2E802B1351700ACE164CB3DE270C1F] [sPRF][29/10/2014] (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Users\Charline\Desktop\ZHPDiag2.exe [6862591] ~ Files: 2 Scanned in 00mn 00s ---\\ Liste des exceptions du parefeu (FirewallRules) (O87) O87 - FAEL: "{76C81D6A-E430-4F3B-A869-B1A21FB37B47}" | In - None - P6 - TRUE | .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Charline\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent O87 - FAEL: "{091169DB-7469-4B9A-960A-6F3170606413}" | In - None - P17 - TRUE | .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Charline\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent O87 - FAEL: "{B4A8BD78-1ADF-4501-A63C-2D50393D1CF6}" | In - None - P6 - TRUE | .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Charline\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent O87 - FAEL: "{65F51880-B89D-41C1-8520-C11A51B63770}" | In - None - P17 - TRUE | .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Charline\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent ~ Firewall: 4 Scanned in 00mn 01s ---\\ Enumère les codes produits des logiciels (PUC) (O90) O90 - PUC: "A07B748F92CF28B478E2852FECD9EE90" . (.Boxore Client.) -- C:\Windows\Installer\{F847B70A-FC29-4B82-872E-58F2CE9DEE09}\boxore.ico =>Adware.Boxore ~ Update Products: 1 Scanned in 00mn 00s ---\\ Enumère les données de la clé NameSpace (MNS) (O92) O92 - MNS: Dossiers Web - {BDEADF00-C265-11D0-BCED-00A0C90AB50F} ~ MNS: 1 Scanned in 00mn 00s ---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS) [MD5.B67811645C5A3B8E4E4B1A1DB1EE271C] [WIS][28/11/2012] (.Boxore OU. - Software Update Helper.) -- C:\Windows\Installer\29a623.msi [45056] =>Adware.Boxore [MD5.1D4BC451F0DCAA5CBCD2471610C33B5E] [WIS][20/06/2014] (.Boxore OU - Boxore Client Installer.) -- C:\Windows\Installer\6549a.msi [2473984] =>Adware.Boxore [MD5.22C9E7805145D0A0C4C62DDB591D2DAE] [WIS][27/06/2012] (.Babylon Ltd - BabylonObjectInstaller.) -- C:\Windows\Installer\6f22e2.msi [353280] =>PUP.Babylon ~ WIS: 3 Scanned in 00mn 02s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 29/10/2014 267440 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe SS - | Auto 07/10/2013 116648 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Demand 07/10/2013 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Demand 28/10/2014 114288 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe SR - | Auto 12/09/2014 64704 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe SR - | Auto 03/10/2014 50344 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe SR - | Auto 01/11/2014 123632 | (MaintainerSvc3.75.5000057) . (...) - C:\ProgramData\75acca2f-18f9-4ee2-81a2-0d40cd9a3cbd\maintainer.exe SR - | Auto 26/02/2010 247152 | (RichVideo) . (...) - C:\Program Files\CyberLink\Shared files\RichVideo.exe SR - | Auto 02/07/2013 93072 | (TomTomHOMEService) . (.TomTom.) - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe SR - | Auto 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Services: Scanned in 00mn 13s ---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80) Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net Run by Charline at 01/11/2014 23:52:17 device: opened successfully user: MBR read successfully Disk trace: called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys halmacpi.dll C:\Windows\system32\DRIVERS\iaStor.sys Intel Corporation Intel Matrix Storage Manager driver 1 nt!IofCallDriver[0x83037FC6] >> \Device\Harddisk0\DR0[0x86D717D0] 3 CLASSPNP[0x8C25459E] >> nt!IofCallDriver[0x83037FC6] >> \Device\Ide\IAAStorageDevice-1[0x85F29028] kernel: MBR read successfully user & kernel MBR OK ~ MBR: 13 Scanned in 00mn 02s ---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by Charline at 01/11/2014 23:52:20 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 04s ---\\ Scan Additionnel (O88) Database Version : 13026 - (28/10/2014) Clés trouvées (Keys found) : 6 Valeurs trouvées (Values found) : 3 Dossiers trouvés (Folders found) : 4 Fichiers trouvés (Files found) : 5 [HKLM\Software\Google\Chrome\Extensions\ibokihboaojdolnlgbejebillmaodnfc] =>Hijacker.FindrToolbar^ [HKLM\Software\Google\Chrome\Extensions\pbaxxildkhbcljgoabiecdoinkaedlca] =>Spyware.SmartDisplay^ [HKLM\Software\Google\Chrome\Extensions\pbpohilckhbcljgoabiecdoinkaedlca] =>Spyware.SmartDisplay^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Protector] =>Rogue.ReimageRepair^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent] =>P2P.BitTorrent^ [HKLM\SOFTWARE\SOFTWARE\UPDATE\CLIENTS\{5B54E9B6-D6C4-11E0-8E9D-92FB4824019B}] =>Adware.Boxore [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:uTorrent =>P2P.BitTorrent^ C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibokihboaojdolnlgbejebillmaodnfc =>Hijacker.FindrToolbar^ C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbaxxildkhbcljgoabiecdoinkaedlca =>Spyware.SmartDisplay^ C:\Users\Charline\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbpohilckhbcljgoabiecdoinkaedlca =>Spyware.SmartDisplay^ C:\Users\Charline\AppData\Roaming\uTorrent =>P2P.µTorrent^ C:\Users\Charline\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent^ [HKCU\Software\BitTorrent] =>P2P.BitTorrent^ C:\Windows\Installer\29a623.msi =>Adware.Boxore^ C:\Windows\Installer\6549a.msi =>Adware.Boxore^ C:\Windows\Installer\6f22e2.msi =>PUP.Babylon^ ~ Additionnel Scan: 240476 Items scanned in 00mn 25s ---\\ Informations complémentaires sur les modules ~ ~ ~ ~ ~ AMI: 4 Scanned in 00mn 00s ---\\ Récapitulatif des détections trouvées sur votre station ~ MSI: 6 link(s) detected in 00mn 00s End of the scan (1194 lines in 02mn 45s)(0)
  22. Bonjour, Désolé pour la multiplication des messages. Mon amie n'y connait rien, ne savait pas vers quel site se tourner, c'est aussi simple. Je vais suivre la procédure indiquée dans le lien et je te tiens au courant. @ plus
  23. Bonjour, Une amie m'a demandé de l'aide pour son PC infecté. Comme je ne voudrais pas faire de fausse manip, je me tourne vers vous. Voilà ce qui apparait lorsqu'elle ouvre Chrome. Je vous copie le rapport généré par ZHP Diag http://cjoint.com/?0JDxlEdQLoo Merci de votre aide. @ Bientôt. -édit- Dans cette section, il ne faut pas multiplier les messages dans ton sujet avant d'avoir été pris en charge : au vu de la présence d'une « réponse », les helpers ne s'y intéresseront pas, croyant le problème pris en mains par l'un des leurs. Utilise plutôt la touche « Modifier » située en bas à droite de ton premier message…
×
×
  • Créer...