5 réponses
yoann090
Messages postés
9180
Date d'inscription
mercredi 12 août 2009
Statut
Contributeur sécurité
Dernière intervention
13 avril 2016
1 689
Modifié par yoann090 le 4/09/2013 à 19:59
Modifié par yoann090 le 4/09/2013 à 19:59
Bonjour,
Suis ce tutoriel stp : https://www.security-helpzone.com/2013/04/14/adwcleaner-rechercher-les-adwares/
et donne le rapport qui s'affiche
++
Suis ce tutoriel stp : https://www.security-helpzone.com/2013/04/14/adwcleaner-rechercher-les-adwares/
et donne le rapport qui s'affiche
++
# AdwCleaner v3.002 - Rapport créé le 04/09/2013 à 20:11:06
# Mis à jour le 01/09/2013 par Xplode
# Système d'exploitation : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Nom d'utilisateur : Françoise - PCMAISON
# Exécuté depuis : C:\Users\Françoise\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VDOIT9WZ\adwcleaner.exe
# Option : Scanner
***** [ Services ] *****
***** [ Fichiers / Dossiers ] *****
***** [ Raccourcis ] *****
***** [ Registre ] *****
***** [ Navigateurs ] *****
-\\ Internet Explorer v9.0.8112.16502
-\\ Google Chrome v29.0.1547.66
[ Fichier : C:\Users\Françoise\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[0].txt - [1800 octets] - [14/08/2013 16:52:30]
AdwCleaner[R0].txt - [2268 octets] - [04/09/2013 17:07:13]
AdwCleaner[R1].txt - [1196 octets] - [04/09/2013 18:01:46]
AdwCleaner[R2].txt - [1188 octets] - [04/09/2013 19:18:27]
AdwCleaner[R3].txt - [989 octets] - [04/09/2013 20:11:06]
AdwCleaner[S0].txt - [2342 octets] - [04/09/2013 17:09:46]
AdwCleaner[S1].txt - [1259 octets] - [04/09/2013 18:03:35]
AdwCleaner[S2].txt - [1250 octets] - [04/09/2013 19:20:35]
########## EOF - C:\AdwCleaner\AdwCleaner[R3].txt - [1228 octets] ##########
# Mis à jour le 01/09/2013 par Xplode
# Système d'exploitation : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Nom d'utilisateur : Françoise - PCMAISON
# Exécuté depuis : C:\Users\Françoise\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VDOIT9WZ\adwcleaner.exe
# Option : Scanner
***** [ Services ] *****
***** [ Fichiers / Dossiers ] *****
***** [ Raccourcis ] *****
***** [ Registre ] *****
***** [ Navigateurs ] *****
-\\ Internet Explorer v9.0.8112.16502
-\\ Google Chrome v29.0.1547.66
[ Fichier : C:\Users\Françoise\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[0].txt - [1800 octets] - [14/08/2013 16:52:30]
AdwCleaner[R0].txt - [2268 octets] - [04/09/2013 17:07:13]
AdwCleaner[R1].txt - [1196 octets] - [04/09/2013 18:01:46]
AdwCleaner[R2].txt - [1188 octets] - [04/09/2013 19:18:27]
AdwCleaner[R3].txt - [989 octets] - [04/09/2013 20:11:06]
AdwCleaner[S0].txt - [2342 octets] - [04/09/2013 17:09:46]
AdwCleaner[S1].txt - [1259 octets] - [04/09/2013 18:03:35]
AdwCleaner[S2].txt - [1250 octets] - [04/09/2013 19:20:35]
########## EOF - C:\AdwCleaner\AdwCleaner[R3].txt - [1228 octets] ##########
yoann090
Messages postés
9180
Date d'inscription
mercredi 12 août 2009
Statut
Contributeur sécurité
Dernière intervention
13 avril 2016
1 689
4 sept. 2013 à 20:20
4 sept. 2013 à 20:20
Ok vous l'avez déja exécuter aujourd'hui, et deltaply est toujours là ?
On va faire un diagnostique, suivez ce tutoriel : http://www.security-helpzone.com/Thread-ZHPDiag-Generer-un-rapport
++
On va faire un diagnostique, suivez ce tutoriel : http://www.security-helpzone.com/Thread-ZHPDiag-Generer-un-rapport
++
Quand je veux le télécharger on me dit que ce n'est pas sûr...
yoann090
Messages postés
9180
Date d'inscription
mercredi 12 août 2009
Statut
Contributeur sécurité
Dernière intervention
13 avril 2016
1 689
4 sept. 2013 à 21:01
4 sept. 2013 à 21:01
Passer outre, c est un faux positif
yoann090
Messages postés
9180
Date d'inscription
mercredi 12 août 2009
Statut
Contributeur sécurité
Dernière intervention
13 avril 2016
1 689
Modifié par yoann090 le 4/09/2013 à 21:32
Modifié par yoann090 le 4/09/2013 à 21:32
Tu as un autre navigateur qu internet explorer ?
yoann090
Messages postés
9180
Date d'inscription
mercredi 12 août 2009
Statut
Contributeur sécurité
Dernière intervention
13 avril 2016
1 689
4 sept. 2013 à 21:44
4 sept. 2013 à 21:44
Ok alors il faudra peut etre desactiver le filtre smartscreen.
Ca fait quoi quand tu cliques sur action
Ca fait quoi quand tu cliques sur action
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
yoann090
Messages postés
9180
Date d'inscription
mercredi 12 août 2009
Statut
Contributeur sécurité
Dernière intervention
13 avril 2016
1 689
4 sept. 2013 à 22:11
4 sept. 2013 à 22:11
Ok
Desactivez le alors : http://www.security-helpzone.com/blog/internet_explorer_ie_activer_desactiver_le_filtre_smartscren-news-54.html
Desactivez le alors : http://www.security-helpzone.com/blog/internet_explorer_ie_activer_desactiver_le_filtre_smartscren-news-54.html
yoann090
Messages postés
9180
Date d'inscription
mercredi 12 août 2009
Statut
Contributeur sécurité
Dernière intervention
13 avril 2016
1 689
5 sept. 2013 à 20:23
5 sept. 2013 à 20:23
Pas de soucis
~ Rapport de ZHPDiag v2013.9.4.601 - Nicolas Coolman (04/09/2013)
~ Lancé par Françoise (05/09/2013 12:11:53)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user
---\\ Navigateurs Internet
MSIE: Internet Explorer v9.0.8112.16421
GCIE: Google Chrome v29.0.1547.66 (Defaut)
OBIE: Safari v5.34.57.2
---\\ Informations sur les produits Windows
~ Langage: Français
Windows Vista Home Premium Edition, 32-bit Service Pack 2 (Build 6002)
Windows Server License Manager Script : OK
~ Vista, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : G6MF9
Windows License : OK
Windows Automatic Updates : OK
---\\ Logiciels de protection du système
avast! Free Antivirus v8.0.1489.0
Spybot - Search & Destroy v1.6.2
---\\ Logiciels d'optimisation du système
CCleaner v4.05 =>Piriform Ltd
---\\ Logiciels de partage PeerToPeer
---\\ Surveillance de Logiciels
Adobe Flash Player 11 Plugin
Adobe Reader X
Java 7 Update 25
---\\ Informations sur le système
~ Processor: x86 Family 6 Model 15 Stepping 11, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2045 MB (16% free)
System Restore: Activé (Enable)
System drive C: has 119 GB (44%) free of 269 GB
---\\ Mode de connexion au système
~ Computer Name: PCMAISON
~ User Name: Françoise
~ All Users Names: Françoise, ASPNET, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator
---\\ Variables d'environnement
~ System Unit : C:\
~ %AppData% : C:\Users\Françoise\AppData\Roaming\
~ %Desktop% : C:\Users\Françoise\Desktop\
~ %Favorites% : C:\Users\Françoise\Pictures\Favorites\Favorites\
~ %LocalAppData% : C:\Users\Françoise\AppData\Local\
~ %StartMenu% : C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ Enumération des unités disques
C:\ Hard drive, Flash drive, Thumb drive (Free 119 Go of 269 Go)
D:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
E:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
F:\ CD-ROM drive (Not Inserted)
---\\ Etat du Centre de Sécurité Windows
~ Security Center: 38 Legitimates Filtered in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.D07D4C3038F3578FFCE1C0237F2A1253] - (.Microsoft Corporation - Explorateur Windows.) (.11/04/2009 - 07:27:36.) -- C:\Windows\Explorer.exe [2926592]
[MD5.101BA3EA053480BB5D957EF37C06B5ED] - (.Microsoft Corporation - Application de démarrage de Windows.) (.19/01/2008 - 08:33:37.) -- C:\Windows\System32\Wininit.exe [96768]
[MD5.6839F14A2507D9273BD13565DD880377] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.25/07/2013 - 03:26:10.) -- C:\Windows\System32\wininet.dll [1129472]
[MD5.898E7C06A350D4A1A64A9EA264D55452] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.11/04/2009 - 07:28:13.) -- C:\Windows\System32\Winlogon.exe [314368]
[MD5.3911B972B55FEA0478476B2E777B29FA] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.21/04/2011 - 14:58:27.) -- C:\Windows\system32\Drivers\AFD.sys [273408]
[MD5.1F05B78AB91C9075565A9D8A4B880BC4] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.11/04/2009 - 07:32:26.) -- C:\Windows\system32\Drivers\atapi.sys [19944]
[MD5.7ADD03E75BEB9E6DD102C3081D29840A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.19/01/2008 - 06:28:02.) -- C:\Windows\system32\Drivers\Cdfs.sys [70144]
[MD5.6B4BFFB9BECD728097024276430DB314] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.11/04/2009 - 05:39:17.) -- C:\Windows\system32\Drivers\Cdrom.sys [67072]
[MD5.622C41A07CA7E6DD91770F50D532CB6C] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.14/04/2011 - 15:59:03.) -- C:\Windows\system32\Drivers\DfsC.sys [75264]
[MD5.062452B7FFD68C8C042A6261FE8DFF4A] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.11/04/2009 - 05:42:42.) -- C:\Windows\system32\Drivers\HDAudBus.sys [561152]
[MD5.22D56C8184586B7A1F6FA60BE5F5A2BD] - (.Microsoft Corporation - Pilote de port i8042.) (.19/01/2008 - 06:49:18.) -- C:\Windows\system32\Drivers\i8042prt.sys [54784]
[MD5.8793643A67B42CEC66490B2A0CF92D68] - (.Microsoft Corporation - IP Network Address Translator.) (.19/01/2008 - 06:56:28.) -- C:\Windows\system32\Drivers\IpNat.sys [100864]
[MD5.1E94971C4B446AB2290DEB71D01CF0C2] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.29/04/2011 - 14:24:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [106496]
[MD5.ECD64230A59CBD93C85F1CD1CAB9F3F6] - (.Microsoft Corporation - MBT Transport driver.) (.11/04/2009 - 05:45:37.) -- C:\Windows\system32\Drivers\netBT.sys [185856]
[MD5.2C1121F2B87E9A6B12485DF53CD848C7] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.03/03/2013 - 20:07:52.) -- C:\Windows\system32\Drivers\ntfs.sys [1082232]
[MD5.0FA9B5055484649D63C303FE404E5F4D] - (.Microsoft Corporation - Pilote de port parallèle.) (.02/11/2006 - 09:51:30.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.A214ADBAF4CB47DD2728859EF31F26B0] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.19/01/2008 - 06:56:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [76288]
[MD5.E8BD98D46F2ED77132BA927FCCB47D8B] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.02/11/2006 - 10:03:00.) -- C:\Windows\system32\Drivers\rdpdr.sys [242688]
[MD5.7B75299A4D201D6A6533603D6914AB04] - (.Microsoft Corporation - SMB Transport driver.) (.11/04/2009 - 05:45:22.) -- C:\Windows\system32\Drivers\smb.sys [66560]
[MD5.76B06EB8A01FC8624D699E7045303E54] - (.Microsoft Corporation - TDI Translation Driver.) (.11/04/2009 - 05:45:56.) -- C:\Windows\system32\Drivers\tdx.sys [72192]
[MD5.786DB5771F05EF300390399F626BF30A] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.21/08/2012 - 12:47:42.) -- C:\Windows\system32\Drivers\volsnap.sys [224640]
~ Generic Processes: Scanned in 00mn 01s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/14322
~ Mes musiques (My Musics) : 1/817
~ Mes Videos (My Videos) : 1/19
~ Mes Favoris (My Favorites) : 0/0
~ Mes Documents (My Documents) : 2/852
~ Mon Bureau (My Desktop) : 1/20
~ Menu demarrer (Programs) : 1/34
~ Hidden Files: Scanned in 00mn 46s
---\\ Processus lancés au démarrage du système
[MD5.AF334CA84536E743D6AEF32548223403] - (.Sony Corporation - Wireless Switch Setting Utility.) -- C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe [469112] [PID.2400]
[MD5.F9EA44A4691F738159D64848509D7B5C] - (.Sony Corporation - VAIO Update.) -- C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe [870240] [PID.3304]
[MD5.B6624D1D446A9683BAF8E482B1774C05] - (.Glarysoft Ltd - Glary Utilities 3.) -- C:\Program Files\Glary Utilities 3\Integrator.exe [470816] [PID.4524]
[MD5.3F11B20D12D89365D7721BDC860CE5F0] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe [4858968] [PID.4532]
[MD5.D63797E8E7781EE1500A810CB6194FA6] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816] [PID.4624]
[MD5.C1DB9BDF885C2F1ADC15264FBEA2788F] - (.Pas de propriétaire - HOSTS Anti-PUPs/Adwares.) -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe [302961] [PID.4672]
[MD5.CE42DFE915F78246364D464902E47360] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [152392] [PID.4688]
[MD5.5D61BE7DB55B026A5D61A3EED09D0EAD] - (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408] [PID.4696]
[MD5.BF08674925F151BD4537B89A493E3E0C] - (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehtray.exe [125952] [PID.4704]
[MD5.3F3A26E471CCCB3CFFCA68F0C052F35F] - (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\w32x86\3\E_FATIIKE.exe [249440] [PID.4752]
[MD5.211206B7623FD9F54B5484E39CF1471A] - (.Sony NSCE - Marketing Tools.) -- C:\Program Files\Sony\Marketing Tools\MarketingTools.exe [36864] [PID.5564]
[MD5.0F4195B9B348DE5CF9B822F81704B20E] - (.Microsoft Corporation - Media Center Media Status Aggregator Servic.) -- C:\Windows\ehome\ehmsas.exe [37376] [PID.5908]
[MD5.6080A176D09435FC8E6E800996656E18] - (.Microsoft Corporation - Console IME.) -- C:\Windows\system32\conime.exe [69120] [PID.6132]
[MD5.7E6EA9CB72B5DE84A5D700BED877E5F9] - (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe [397312] [PID.5784]
[MD5.57EC630DBD5F0713E77CB3540AB80A8E] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [757400] [PID.2444]
[MD5.10B01048B1DA075CD1EE27E30B4CF342] - (.Google Inc. - Google Toolbar Broker.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe [308816] [PID.5756] =>Toolbar.Google
[MD5.5B7E4A7A93BBCC820B6DA12B28841B57] - (.Adobe Systems Incorporated - Adobe® Flash® Player Installer/Uninstaller.) -- C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe [814984] [PID.4288]
[MD5.2D821AFA5A1A9CA7F9F997A1AAD09E72] - (.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe [168960] [PID.5892]
[MD5.1DE123E71FF306C076147813047AF987] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [7874560] [PID.7576]
[MD5.862BB4CBC05D80C5B45BE430E5EF872F] - (.Microsoft Corporation - Service de gestion des licences Microsoft.) -- C:\Windows\system32\SLsvc.exe [3408896] [PID.1360]
[MD5.28D6701C710AD7BA3CB95E75F8F1A9AA] - (.AVAST Software - avast! Service.) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [46808] [PID.1748]
[MD5.ADC420616C501B45D26C0FD3EF1E54E4] - (.ArcSoft Inc. - ArcSoft Connect Service.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152] [PID.400]
[MD5.E8FE4FCE23D2809BD88BCC1D0F8408CE] - (...) -- C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [124832] [PID.496]
[MD5.ADDA5E1951B90D3D23C56D3CF0622ADC] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [65640] [PID.608]
[MD5.7D4E8DE794E4B3A06CB274E48F36C578] - (.Home - Pas de description.) -- C:\Program Files\APLI-AGIPA\Agipa Master\AgipaAutoUpdater.exe [167936] [PID.12]
[MD5.4FE5C6D40664AE07BE5105874357D2ED] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [57008] [PID.840]
[MD5.DB5BEA73EDAF19AC68B2C0FAD0F92B1A] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [390504] [PID.1032]
[MD5.E9EFCB47B90FD5498695BB7FEFD36CAE] - (.Seiko Epson Corporation - Epson Scanner Service (32bit).) -- C:\Windows\system32\EscSvc.exe [122000] [PID.2000]
[MD5.582F2D900A3AC34C98FBDC2C0ABEF6B9] - (.Intel Corporation - RAID Monitor.) -- C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [355096] [PID.2484]
[MD5.388AE59FE75F1B959DFA0900923C61BB] - (.Skype Technologies S.A. - Skype C2C Service.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000] [PID.2736]
[MD5.7E6DD4B34ACD36AF6C711D2BDE91B040] - (.IDT, Inc. - STacSV Module.) -- C:\Windows\system32\stacsv.exe [102400] [PID.2800]
[MD5.3D7B66D3B25DFBDE7B96114E2D8EF2B3] - (.ArcSoft, Inc. - MgiSvr.) -- C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe [104960] [PID.2888]
[MD5.8A9F18ADAD471402236CA931553BF79B] - (.Sony Corporation - VAIO Event Service (Service Module).) -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [182392] [PID.2912]
[MD5.4D6644132F26EF055A1F754B1C38C084] - (.Sony Corporation - VAIO Entertainment UPnP Client Adapter.) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [274432] [PID.3000]
[MD5.15A317674A08DF26BE65164D959E9203] - (.Conexant Systems, Inc. - Modem Audio Service.) -- C:\Windows\system32\DRIVERS\xaudio.exe [386560] [PID.3380]
[MD5.794D4B48DFB6E999537C7C3947863463] - (.Safer Networking Ltd. - Spybot-S&D Security Center integration.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368] [PID.3472]
[MD5.2E785F4F92C4C67CEBB61DD55ED1F6A1] - (.Sony Corporation - VAIO Entertainment Database Service.) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512] [PID.3580]
[MD5.B0C84CEA4FE07231BA87A054AF95984D] - (.Sony Corporation - VAIO Event Service(Service Sub Module).) -- C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe [100472] [PID.3696]
[MD5.2D876CAD8C7FFB08179DFF361FF851E6] - (.Sony Corporation - VAIO Entertainment File Import Service.) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe [131072] [PID.3836]
[MD5.ECEF404F62863755951E09C802C94AD5] - (.Microsoft Corporation - Détection de services interactifs.) -- C:\Windows\system32\UI0Detect.exe [35840] [PID.4000]
[MD5.605AC5F17669767C7A750314753CF8EB] - (.Sony Corporation - SPM Module.) -- C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [921600] [PID.3012]
[MD5.C559672F31ABE6BA7277DD73C4502238] - (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\system32\msiexec.exe [73216] [PID.1432]
[MD5.D8B8B5A8FE57CF4F307A540D9A153C23] - (.Apple Inc. - iPodService Module (32-bit).) -- C:\Program Files\iPod\bin\iPodService.exe [553288] [PID.2536]
~ Processes Running: Scanned in 00mn 04s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Françoise\AppData\Local\Google\Chrome\User Data\Default\Preferences
~ Google Browser: 1 Legitimates Filtered in 00mn 10s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN: [HKLM] [@fluxdvd.com/NPAPIX] - (.Pas de propriétaire - APIX Mozilla Plugin.) -- C:\Program Files\Common Files\fluxDVD\APIX\NPAPIX.dll
P2 - FPN: [HKLM] [@fluxdvd.com/NPFluxBrowserHelper] - (.Pas de propriétaire - fluxDVD Browser Helper Plugin.) -- C:\Program Files\Common Files\fluxDVD\BrowserIntegration\NPFluxBrowserHelper.dll
P2 - FPN: [HKLM] [@protectdisc.com/NPMPDRM] - (.Pas de propriétaire - MPDRM License Acquisition Plugin.) -- C:\Program Files\Common Files\mpDRM\NPMPDRM.dll
P2 - FPN: [HKLM] [***@***/YahooActiveXPluginBridge;version=1.0.0.1] - (...) -- C:\Program Files\Yahoo!\Common\npyaxmpb.dll (.not file.) =>Toolbar.Yahoo
~ Firefox Browser: 31 Legitimates Filtered in 00mn 01s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.free.fr
~ IE Browser: 9 Legitimates Filtered in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 03s
~ Nombre de lignes (Lines number): 22823
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: MHTBPos00 - {0C37B053-FD68-456a-82E1-D788EE342E6F} . (.Pas de propriétaire - IE Toolbar Engine.) -- C:\Program Files\Family Toolbar\tbcore3.dll
O2 - BHO: MyHeritage New Tab - {D62EC836-BF1E-4CAC-81BE-FB9179835D8E} . (.Pas de propriétaire - mhxpcomi New Tab Library.) -- C:\Program Files\Family Toolbar\mhxpcomi.dll
~ BHO: 24 Legitimates Filtered in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: EPSON Web-To-Page - [HKLM]{EE5D279F-081B-4404-994D-C6B60AAEBA6D} . (.SEIKO EPSON CORPORATION - EPSON Web-To-Page.) -- C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Easy Photo Print - [HKLM]{9421DD08-935F-4701-A9CA-22DF90AC4EA6} . (.SEIKO EPSON CORPORATION / CyCom Technology - Epson Easy Photo Print (TBL).) -- C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: avast! WebRep - [HKLM]{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{F2CF5485-4E02-4F68-819C-B92DE9277049} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{EE5D279F-081B-4404-994D-C6B60AAEBA6D} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{21FA44EF-376D-4D53-9B0F-8A89D3229068} Clé orpheline
~ Toolbar: Scanned in 00mn 00s
---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKLM\..\Run: [avast] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\avastUI.exe
O4 - HKLM\..\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Run: [Google Desktop Search] . (.Google - Google Desktop.) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe
O4 - HKLM\..\Run: [HOSTS Anti-Adware_PUPs] . (.Pas de propriétaire - HOSTS Anti-PUPs/Adwares.) -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe
O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\windows sidebar\sidebar.exe
O4 - HKCU\..\Run: [EPLTarget\P0000000000000002] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIIKE.exe
O4 - HKCU\..\Run: [WMPNSCFG] . (.Microsoft Corporation - Application de configuration du service Par.) -- C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] oobefldr.dll
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] oobefldr.dll
O4 - HKUS\S-1-5-21-149699470-4155078432-4155011755-1000\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-149699470-4155078432-4155011755-1000\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-21-149699470-4155078432-4155011755-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\windows sidebar\sidebar.exe
O4 - HKUS\S-1-5-21-149699470-4155078432-4155011755-1000\..\Run: [EPLTarget\P0000000000000002] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIIKE.exe
O4 - HKUS\S-1-5-21-149699470-4155078432-4155011755-1000\..\Run: [WMPNSCFG] . (.Microsoft Corporation - Application de configuration du service Par.) -- C:\Program Files\Windows Media Player\WMPNSCFG.exe
~ Application: Scanned in 00mn 00s
---\\ Autres liens utilisateurs (O4)
O4 - GS\Programs: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\Programs: RescuePRO Deluxe DEMO.lnk . (...) -- C:\Users\Françoise\AppData\Roaming\Microsoft\Installer\{FEE63C37-2AA8-4D3F-97B8-D7E010C684E9}\IconFEE63C37.exe
O4 - GS\Programs: Uninstall RescuePRO Deluxe DEMO.lnk . (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\System32\msiexec.exe
O4 - GS\Programs: Windows Mail.lnk . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe
O4 - GS\Programs: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe
O4 - GS\QuickLaunch: Glary Utilities 3.lnk . (.Glarysoft Ltd - Glary Utilities 3.) -- C:\Program Files\Glary Utilities 3\Integrator.exe
O4 - GS\QuickLaunch: Gmail Notifier.lnk . (.Google Inc. - Gmail Notifier.) -- C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - GS\QuickLaunch: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
O4 - GS\QuickLaunch: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture.) -- C:\Windows\System32\SnippingTool.exe
O4 - GS\QuickLaunch: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe
O4 - GS\Accessories: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\SendTo: Assistant Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - Pas de description.) -- C:\Windows\System32\fsquirt.exe
O4 - GS\SendTo: Documents sur GPS.LNK - Clé orpheline
O4 - GS\SendTo: Format Factory.lnk . (.Free Time - FormatFactory.) -- C:\Program Files\FreeTime\FormatFactory\FormatFactory.exe
O4 - GS\SendTo: Skype.lnk . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe
O4 - GS\Desktop: Format Factory.lnk . (.Free Time - FormatFactory.) -- C:\Program Files\FreeTime\FormatFactory\FormatFactory.exe
O4 - GS\Desktop: Free Video Flip and Rotate.lnk . (.DVDVideoSoft Ltd. - FreeVideoFlipAndRotate.) -- C:\Program Files\DVDVideoSoft\Free Video Flip and Rotate\FreeVideoFlipAndRotate.exe
O4 - GS\Desktop: JkDefrag.lnk . (.www.jkdefrag.fr - JkDefrag - défragmenteur de disque léger, c.) -- C:\Program Files\JkDefrag\JkDefrag.exe
O4 - GS\Desktop: Microsoft Office - Raccourci.lnk . (...) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O4 - GS\Desktop: Spider Solitaire - Raccourci.lnk - Clé orpheline
O4 - GS\Desktop: Spybot - Search & Destroy.lnk . (.Safer Networking Limited - Spybot - Search & Destroy.) -- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
O4 - GS\Desktop: Windows Mail.lnk . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe
~ Global Startup: Scanned in 00mn 01s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft Office OneNote Internet Explorer Add-in.) -- C:\Program Files\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} . (.Microsoft Corporation - Synchronisation des favoris ActiveSync.) -- C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -- Clé orpheline
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\OFFICE11\REFBARH.ICO
O9 - Extra button: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- C:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
O9 - Extra button: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -- Clé orpheline
~ IE Extra Buttons: Scanned in 00mn 00s
---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] *.canalplay.com
O15 - Trusted Zone: [HKCU\...\Domains] *.canalplusactive.com
O15 - Trusted Zone: [HKLM\...\Domains] *.canalplay.com
O15 - Trusted Zone: [HKLM\...\Domains] *.canalplusactive.com
~ IE Zone Confiance: Scanned in 00mn 03s
---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} ((no name)) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_5_1_4_0.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ((no name)) - http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} ((no name)) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} ((no name)) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
~ Objets ActiveX: Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{60ED18D1-C5FF-4B7E-8BCF-5B123D3ACB05}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\..\{FBC46F45-57E2-47D0-99B3-AFE967BD7D4C}: DhcpNameServer = 192.168.10.110 192.168.10.110 192.168.10.110 192.168.10.110
O17 - HKLM\System\CS1\Services\Tcpip\..\{60ED18D1-C5FF-4B7E-8BCF-5B123D3ACB05}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CS1\Services\Tcpip\..\{FBC46F45-57E2-47D0-99B3-AFE967BD7D4C}: DhcpNameServer = 192.168.10.110 192.168.10.110 192.168.10.110 192.168.10.110
O17 - HKLM\System\CS2\Services\Tcpip\..\{2F3A536B-0C0E-49CD-82FE-B832AEBBBD1B}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CS2\Services\Tcpip\..\{60ED18D1-C5FF-4B7E-8BCF-5B123D3ACB05}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CS3\Services\Tcpip\..\{2F3A536B-0C0E-49CD-82FE-B832AEBBBD1B}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CS3\Services\Tcpip\..\{60ED18D1-C5FF-4B7E-8BCF-5B123D3ACB05}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
~ Domain: Scanned in 00mn 00s
---\\ Titr_HJT34=Protocole additionnel (O18)
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: VESWinlogon . (.Sony Corporation - VAIO Event Service (Winlogon Notification M.) -- C:\Windows\System32\VESWinlogon.dll
~ Winlogon: Scanned in 00mn 00s
---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\Windows\System32\browseui.dll
~ STS/SSO: Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Agipa Master AutoUpdater (Agipa Master AutoUpdater) . (.Home - Pas de description.) - C:\Program Files\APLI-AGIPA\Agipa Master\AgipaAutoUpdater.exe
O23 - Service: XAudioService (XAudioService) . (.Conexant Systems, Inc. - Modem Audio Service.) - C:\Windows\System32\DRIVERS\xaudio.exe
~ Services: 20 Legitimates Filtered in 00mn 08s
---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk * ) - File not found
O34 - HKLM BootExecute: (BootDefrag.exe) - File not found
~ BEX: 2 Legitimates Filtered in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [4803] (...) -- C:\Users\Françoise\AppData\Local\Temp\launchie.vbs \\B (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{01C7D2C0-C225-404C-89CA-A5FBBF2A8638}] (...) -- C:\Users\Françoise\Documents\lide20lide30n670un676un1240uvst7031a_xpen.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{26080B8B-3149-4EE2-AE37-A2D23956E703}] (...) -- C:\Users\Françoise\Desktop\lide20lide30n670un676un1240uvst7031a_xpfr\SetupSG\SETUPSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{2C86FE19-7D4C-4B94-8C1A-6594EE3CA136}] (...) -- G:\EmDesk.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{3585497F-D6B1-4C9F-BC47-B55F56DF0BFD}] (...) -- C:\Users\Françoise\Desktop\lide20lide30n670un676un1240uvst7031a_xpfr\SetupSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{3660D07E-67EC-4DF0-9767-856B94BB5205}] (...) -- C:\Users\Françoise\Documents\Mes sites web\lide20lide30n670un676un1240uvst7031a_xpfr\SetupSG\SETUPSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{3826FBE6-FD88-4A8D-A241-DB72ECE164D1}] (...) -- C:\Users\Françoise\Documents\Mes sites web\SetupSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{38BA088E-EFCD-46D2-BC25-8F2C0FAE577D}] (...) -- C:\Users\Françoise\Documents\Mes sites web\lide20lide30n670un676un1240uvst7031a_xpfr\SetupSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{54A0FA59-ED9C-4853-B61E-8EECAA0698E3}] (...) -- C:\Users\Françoise\Documents\LiDE60_11100WNEN\SetupSG\SETUPSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{59B34607-DD2B-4B60-83AC-4F0D95EADBF1}] (...) -- C:\Users\Françoise\Documents\LiDE60_11100WNEN\SetupSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{6056F133-4C6C-463B-BFC4-5F8FB242BCE6}] (...) -- C:\Users\Françoise\Documents\LiDE60_11100WNEN\LiDE60_11100WNEN.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{6CC0830E-29F2-4ACA-A41C-07B4A1C5A10D}] (...) -- C:\Users\Françoise\Documents\Mes sites web\netsight_setup_5.1.2.15_MP_Production_mid50997575378_p.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{6EAB97D1-4F78-4666-A01A-F2667EC566B7}] (...) -- C:\Users\Françoise\Downloads\epson323813eu.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{74242A98-47B5-4597-A042-E32C472F9FB3}] (...) -- C:\Big Fish Games\sudoku\Uninstall.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{7A5CC06F-BC63-4153-86D9-B105C9FCD2F7}] (...) -- C:\Users\Françoise\Documents\TOTO\lide20lide30n670un676un1240uvst7031a_xpfr\lide20lide30n670un676un1240uvst7031a_xpfr\SetupSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{842FD594-FEDD-4120-9147-8047F6966A18}] (...) -- c:\Users\Françoise\Downloads\installer_intervideo_windvd_2010.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{91B956AB-EFDA-4DA6-950E-5140571E7013}] (...) -- C:\Users\Françoise\Documents\Mes sites web\install_7z460.exe.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{D041C939-81F7-4849-8471-4355E7272ED5}] (...) -- C:\Users\Françoise\Documents\Mes sites web\lide20lide30n670un676un1240uvst7031a_xpfr\lide20lide30n670un676un1240uvst7031a_xpfr\SetupSG.exe (.not file.) [0]
~ Scheduled Task: 42 Legitimates Filtered in 00mn 09s
---\\ Logiciels installés (O42)
O42 - Logiciel: Agipa Master - (...) [HKLM] -- {2F607417-9C1C-4B10-B634-839920C0C6E0}
O42 - Logiciel: Agipa Master - (.APLI-AGIPA S.A.S..) [HKLM] -- InstallShield_{233D0B18-0D06-48B9-87E0-E28B5A1D512C}
O42 - Logiciel: Magic-i Visual Effects - (...) [HKLM] -- {8866BCB3-3818-4C66-83BC-92006B5EFE50}
O42 - Logiciel: Module d'enregistrement 1.5.1.2 - (.YDP SA.) [HKLM] -- FlashComponents
O42 - Logiciel: Votre Economiseur Personnel 1.0 - (...) [HKLM] -- Votre Economiseur Personnel_is1
~ Logic: 179 Legitimates Filtered in 00mn 00s
---\\ HKCU & HKLM Software Keys
[HKCU\Software\Agipa]
[HKCU\Software\AsioStHd]
[HKCU\Software\LC Technology]
[HKCU\Software\RKD]
[HKCU\Software\WWA]
[HKCU\Software\Yahoo] =>Toolbar.Yahoo
[HKCU\Software\sms164]
[HKLM\Software\NSCPID]
[HKLM\Software\RKD]
[HKLM\Software\Winsudate]
[HKLM\Software\Yahoo] =>Toolbar.Yahoo
~ Key Software: 254 Legitimates Filtered in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 29/08/2008 - 18:03:30 - [7,147] ----D C:\Program Files\AGIPA
O43 - CFD: 21/11/2007 - 15:50:58 - [0,316] ----D C:\Program Files\BFG
O43 - CFD: 19/04/2011 - 12:39:36 - [0,095] ----D C:\Program Files\Bonjour(4)
O43 - CFD: 01/02/2011 - 14:08:13 - [5,726] ----D C:\Program Files\Family Toolbar
O43 - CFD: 28/08/2013 - 13:38:59 - [19,324] ----D C:\Program Files\Postcard Maker
O43 - CFD: 30/05/2013 - 21:23:41 - [0,000] ----D C:\Users\Françoise\AppData\Roaming\AgipaMaster
O43 - CFD: 20/08/2009 - 14:30:45 - [0,000] ----D C:\Users\Françoise\AppData\Roaming\play2p
O43 - CFD: 28/08/2013 - 13:55:37 - [69,867] ----D C:\Users\Françoise\AppData\Roaming\TNS
~ Program Folder: 244 Legitimates Filtered in 02mn 50s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.1F0331632F3137FE02170E95798A8BDE] - 03/09/2013 - 09:56:24 ---A- . (...) -- C:\DiskDefrag.log [75]
~ Files: 13 Legitimates Filtered in 00mn 21s
---\\ Clé de registre Shell MountPoints2 (MPKS) (O51)
O51 - MPSK:{4032caa9-f549-11df-a260-001a80b70d3f}\AutoRun\command. (...) -- I:\iStudio.exe (.not file.)
O51 - MPSK:{d85f96f4-49a7-11dd-a051-001a80b70d3f}\AutoRun\command. (...) -- C:\Windows\system32\copy.exe (.not file.)
O51 - MPSK:{d85f971a-49a7-11dd-a051-001a80b70d3f}\AutoRun\command. (...) -- C:\Windows\system32\copy.exe (.not file.)
O51 - MPSK:{d85f9720-49a7-11dd-a051-001a80b70d3f}\AutoRun\command. (...) -- C:\Windows\system32\copy.exe (.not file.)
~ Keys: Scanned in 00mn 00s
---\\ Enumération des clés de registre StartupReg (SMSR) (O53)
O53 - SMSR:HKLM\...\startupreg\MobileDocuments [Key] . (...) -- C:\Program Files\Common Files\Apple\Internet Services\ubd.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\WWA_Manager [Key] . (.TNS - wwamgr.exe.) -- C:\Users\Françoise\AppData\Roaming\TNS\wwamgr.exe
~ SMSR Keys: 22 Legitimates Filtered in 00mn 00s
---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
~ MWPS: 16 Legitimates Filtered in 00mn 00s
---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.B680134BA1813B78B47FDD1DFF223CA5] - 09/05/2013 - 09:59:10 ---A- . (...) -- C:\Windows\System32\Drivers\aswRvrt.sys [49376]
O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 02/11/2006 - 08:09:42 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
~ Drivers: 16 Legitimates Filtered in 00mn 00s
---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
O63 - Logiciel: RSIT - (.random/random.)
~ ADS: Scanned in 00mn 00s
---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - ??\??\???? - Pas de propriétaire (BootDefragDriver) .(...) - LEGACY_BOOTDEFRAGDRIVER
~ Legacy: 83 Legitimates Filtered in 00mn 00s
---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 19 Legitimates Filtered in 00mn 00s
---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <chrome.exe> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: <Safari.exe> <Safari>[HKLM\..\Shell\open\Command] (.Apple Inc. - Safari.) -- C:\Program Files\Safari\Safari.exe
~ Keys: Scanned in 00mn 00s
---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (@ieframe.dll,-12512) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {5EA074F4-5E5C-423B-9805-F051F7CA528D} - (Ask Search) - http://websearch.ask.com =>Toolbar.Ask
O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (@ieframe.dll,-12512) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {90F0023A-B14D-4A21-9B5D-DD48934AE8DC} [DefaultScope] - (Google) - http://www.google.fr
O69 - SBI: SearchScopes [HKCU] {AB63604F-3039-423E-A3C0-7C3A9254363D} - (Fast Browser Search) - http://www.fastbrowsersearch.com =>PUP.FbSearch
O69 - SBI: SearchScopes [HKCU] {BE28C22E-F666-424d-B5FD-125C4AFEE34E} - (Chercher) - http://search.myheritage.com
O69 - SBI: SearchScopes [HKCU] {c1d89ae7-449d-4929-b24b-fded04adbe06} - (Glary Search) - http://isearch.glarysoft.com
O69 - SBI: SearchScopes [HKCU] {e3bc0642-1dee-4740-9a16-c91c793e452f} - (Wibeez) - http://www.wibeez.com
O69 - SBI: SearchScopes [HKCU] {F0EA1748-2B93-4853-BE98-6080B9045A68} - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s
---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.A840741DAC99B0524F8D480E22F07EAA] [SPRF][28/04/2012] (...) -- C:\ProgramData\KGyGaAvL.sys [952]
[MD5.0BC6B3FBD3348E3DDE864747FC7A797F] [SPRF][29/07/2013] (...) -- C:\Users\Françoise\AppData\Local\d3d9caps.dat [8944]
[MD5.2666172098FF4F5BEFC0EB97ADBBE1AE] [SPRF][28/09/2009] (...) -- C:\Users\Françoise\AppData\Local\fusioncache.dat [97]
[MD5.7D7B4BB2FC34A15763157A23ED89F8B4] [SPRF][05/09/2013] (...) -- C:\Users\Françoise\AppData\Local\Temp\~gu3-ver.dat [160]
[MD5.08512BFFB233FFA2D77379B74C4EBB54] [SPRF][05/09/2013] (...) -- C:\Users\Françoise\AppData\Local\Temp\~upgrade.dat [936]
[MD5.490EF3EC464E7B3FE857AA1243F910E6] [SPRF][16/01/2010] (...) -- C:\Users\Françoise\AppData\Roaming\mdbu.bin [2049]
[MD5.97911873425E743D8F8857516FFA5627] [SPRF][11/05/2012] (...) -- C:\Users\Françoise\AppData\Roaming\nvModes.dat [262391]
[MD5.D41D8CD98F00B204E9800998ECF8427E] [SPRF][10/11/2011] (...) -- C:\Users\Françoise\AppData\Roaming\wklnhst.dat [0]
[MD5.33B3C89A9F5600F3D7D9C96AE4579F2C] [SPRF][15/12/2012] (.Google - Google Desktop.) -- C:\Users\Françoise\Desktop\GoogleDesktopSetup.exe [2021360]
~ Files: 12 Legitimates Filtered in 00mn 00s
---\\ Liste des exceptions du parefeu (FirewallRules) (O87)
O87 - FAEL: "TCP Query User{AB1C2C4F-C022-4EBD-BEB2-6788208FB978}C:\users\françoise\appdata\roaming\tns\wwamgr.exe" | In - Public - P6 - TRUE | .(.TNS - wwamgr.exe.) -- C:\users\françoise\appdata\roaming\tns\wwamgr.exe
O87 - FAEL: "UDP Query User{6F7732AC-20BD-4134-9B46-5079DD8C7160}C:\users\françoise\appdata\roaming\tns\wwamgr.exe" | In - Public - P17 - TRUE | .(.TNS - wwamgr.exe.) -- C:\users\françoise\appdata\roaming\tns\wwamgr.exe
~ Firewall: 237 Legitimates Filtered in 00mn 02s
---\\ Enumère les codes produits des logiciels (PUC) (O90)
O90 - PUC: "A81E737A17150D040843D72D34240018" . (.Software Updater.) -- C:\Windows\Installer\{A737E18A-5171-40D0-8034-7DD243420081}\icon.ico =>PUP.Eorezo
~ Update Products: 128 Legitimates Filtered in 00mn 00s
---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.72A2E3C1CDB80947BCDDB7138F39293C] [WIS][10/12/2009] (.Google - Google Earth.) -- C:\Windows\Installer\1ba5cc8.msi [1291776]
[MD5.250E76D26AA471D208065B8E3A0FE0BA] [WIS][30/05/2013] (.APLI-AGIPA S.A.S. - Agipa Master.) -- C:\Windows\Installer\2aa6d60.msi [8752640]
[MD5.CB4D9AF1F97286903EF0ACEEE1E5E1D0] [WIS][23/06/2009] (.LC Technology International, Inc - Version 4.1.) -- C:\Windows\Installer\73c315.msi [472576]
~ WIS: 139 Legitimates Filtered in 00mn 19s
---\\ Etat général des services not Microsoft (EGS) (SR=Running, SS=Stopped)
SR - | Auto 18/03/2010 113152 | (ACDaemon) . (.ArcSoft Inc..) - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
SR - | Auto 10/09/2007 124832 | (AdobeActiveFileMonitor6.0) . (...) - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
SR - | Auto 10/05/2013 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SS - | Demand 21/08/2013 257416 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SR - | Auto 17/10/2011 167936 | (Agipa Master AutoUpdater) . (.Home.) - C:\Program Files\APLI-AGIPA\Agipa Master\AgipaAutoUpdater.exe
SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 09/05/2013 46808 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 12/12/2011 122000 | (EpsonScanSvc) . (.Seiko Epson Corporation.) - C:\Windows\system32\EscSvc.exe
SS - | Demand 08/10/2012 654848 | (FLEXnet Licensing Service) . (.Macrovision Europe Ltd..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Demand 17/12/2012 30192 | (GoogleDesktopManager-051210-111108) . (.Google.) - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
SS - | Auto 13/06/2009 133104 | (gupdate1c9ec57d8767753) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 13/06/2009 133104 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 11/08/2012 194032 | (gusvc) . (.Google.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
SS - | Auto 17/08/2013 285795 | (HOSTS Anti-PUPs) . (...) - C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe
SR - | Auto 12/02/2007 355096 | (IAANTMON) . (.Intel Corporation.) - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
SS - | Demand 03/04/2005 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
SR - | Demand 16/08/2013 553288 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SS - | Demand 14/12/2006 45056 | (MSCSPTISRV) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
SS - | Demand 14/12/2006 57344 | (PACSPTISVR) . (...) - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
SR - | Auto 26/01/2009 1153368 | (SBSDWSCService) . (.Safer Networking Ltd..) - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
SR - | Auto 22/09/2010 249136 | (SeaPort) . (.Microsoft Corporation.) - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
SS - | Demand 20/06/2008 436096 | (Service CANALPLAY) . (.Canal+ Distribution.) - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
SR - | Auto 02/10/2012 3064000 | (Skype C2C Service) . (.Skype Technologies S.A..) - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
SS - | Auto 13/07/2012 160944 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SS - | Demand 14/12/2006 69632 | (SPTISRV) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
SR - | Auto 27/10/2007 102400 | (STacSV) . (.IDT, Inc..) - C:\Windows\system32\stacsv.exe
SR - | Auto 09/11/2007 104960 | (uCamMonitor) . (.ArcSoft, Inc..) - C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe
SS - | Demand 28/06/2007 73728 | (VAIO Entertainment TV Device Arbitration Service) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
SR - | Auto 14/08/2007 182392 | (VAIO Event Service) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
SS - | Demand 20/06/2007 2523136 | (VAIOMediaPlatform-IntegratedServer-AppServer) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
SS - | Demand 20/06/2007 397312 | (VAIOMediaPlatform-IntegratedServer-HTTP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
SS - | Demand 20/06/2007 1089536 | (VAIOMediaPlatform-IntegratedServer-UPnP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
SS - | Demand 20/06/2007 499712 | (VAIOMediaPlatform-Mobile-Gateway) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
SS - | Demand 10/01/2007 745472 | (VAIOMediaPlatform-UCLS-AppServer) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
SS - | Demand 20/06/2007 397312 | (VAIOMediaPlatform-UCLS-HTTP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
SS - | Demand 20/06/2007 1089536 | (VAIOMediaPlatform-UCLS-UPnP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
SS - | Demand 28/09/2007 292128 | (VcmIAlzMgr) . (.Sony Corporation.) - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
SS - | Demand 17/03/2008 87328 | (VcmXmlIfHelper) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
SR - | Demand 28/06/2007 274432 | (Vcsw) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
SR - | Auto 28/08/2007 192512 | (VzCdbSvc) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
SR - | Auto 28/08/2007 131072 | (VzFw) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
SR - | Auto 19/01/2008 21504 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 19/01/2008 21504 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 27/09/2007 386560 | (XAudioService) . (.Conexant Systems, Inc..) - C:\Windows\System32\DRIVERS\xaudio.exe
~ Services: Scanned in 00mn 23s
---\\ Scan Additionnel (O88)
Database Version : v2.12882 - (04/09/2013)
Clés trouvées (Keys found) : 3
Valeurs trouvées (Values found) : 1
Dossiers trouvés (Folders found) : 1
Fichiers trouvés (Files found) : 5
[HKLM\Software\Winsudate] =>Adware.Gibmedia
[HKLM\Software\Classes\Toolbar3.MHTBPos00] =>Toolbar.Agent
[HKLM\Software\Classes\Toolbar3.MHTBPos00.1] =>Toolbar.Agent
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google^
C:\Program Files\Family Toolbar =>Toolbar.Agent
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe =>Toolbar.Google^
C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google^
[HKCU\Software\Yahoo] =>Toolbar.Yahoo^
[HKLM\Software\Yahoo] =>Toolbar.Yahoo^
C:\Windows\Installer\{A737E18A-5171-40D0-8034-7DD243420081}\icon.ico =>PUP.Eorezo^
~ Additionnel Scan: 391248 Items scanned in 00mn 50s
---\\ Récapitulatif des détections trouvées sur votre station
~ http://nicolascoolman.webs.com/apps/blog/show/32384220-toolbar-google =>Toolbar.Google
~ http://nicolascoolman.webs.com/apps/blog/show/30268689-toolbar-yahoo =>Toolbar.Yahoo
~ http://nicolascoolman.webs.com/apps/blog/show/28927746-toolbar-ask =>Toolbar.Ask
~ http://nicolascoolman.webs.com/apps/blog/show/27629963-pup-fbsearch =>PUP.Fbsearch
~ http://nicolascoolman.webs.com/apps/blog/show/27469224-pup-eorezo =>PUP.EoRezo
~ MSI: 5 link(s) detected in 00mn 50s
~ 1350 Legitimates filtered by white list
End of the scan (620 lines in 06mn 29s)(0)
~ Lancé par Françoise (05/09/2013 12:11:53)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user
---\\ Navigateurs Internet
MSIE: Internet Explorer v9.0.8112.16421
GCIE: Google Chrome v29.0.1547.66 (Defaut)
OBIE: Safari v5.34.57.2
---\\ Informations sur les produits Windows
~ Langage: Français
Windows Vista Home Premium Edition, 32-bit Service Pack 2 (Build 6002)
Windows Server License Manager Script : OK
~ Vista, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : G6MF9
Windows License : OK
Windows Automatic Updates : OK
---\\ Logiciels de protection du système
avast! Free Antivirus v8.0.1489.0
Spybot - Search & Destroy v1.6.2
---\\ Logiciels d'optimisation du système
CCleaner v4.05 =>Piriform Ltd
---\\ Logiciels de partage PeerToPeer
---\\ Surveillance de Logiciels
Adobe Flash Player 11 Plugin
Adobe Reader X
Java 7 Update 25
---\\ Informations sur le système
~ Processor: x86 Family 6 Model 15 Stepping 11, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2045 MB (16% free)
System Restore: Activé (Enable)
System drive C: has 119 GB (44%) free of 269 GB
---\\ Mode de connexion au système
~ Computer Name: PCMAISON
~ User Name: Françoise
~ All Users Names: Françoise, ASPNET, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator
---\\ Variables d'environnement
~ System Unit : C:\
~ %AppData% : C:\Users\Françoise\AppData\Roaming\
~ %Desktop% : C:\Users\Françoise\Desktop\
~ %Favorites% : C:\Users\Françoise\Pictures\Favorites\Favorites\
~ %LocalAppData% : C:\Users\Françoise\AppData\Local\
~ %StartMenu% : C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ Enumération des unités disques
C:\ Hard drive, Flash drive, Thumb drive (Free 119 Go of 269 Go)
D:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
E:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
F:\ CD-ROM drive (Not Inserted)
---\\ Etat du Centre de Sécurité Windows
~ Security Center: 38 Legitimates Filtered in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.D07D4C3038F3578FFCE1C0237F2A1253] - (.Microsoft Corporation - Explorateur Windows.) (.11/04/2009 - 07:27:36.) -- C:\Windows\Explorer.exe [2926592]
[MD5.101BA3EA053480BB5D957EF37C06B5ED] - (.Microsoft Corporation - Application de démarrage de Windows.) (.19/01/2008 - 08:33:37.) -- C:\Windows\System32\Wininit.exe [96768]
[MD5.6839F14A2507D9273BD13565DD880377] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.25/07/2013 - 03:26:10.) -- C:\Windows\System32\wininet.dll [1129472]
[MD5.898E7C06A350D4A1A64A9EA264D55452] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.11/04/2009 - 07:28:13.) -- C:\Windows\System32\Winlogon.exe [314368]
[MD5.3911B972B55FEA0478476B2E777B29FA] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.21/04/2011 - 14:58:27.) -- C:\Windows\system32\Drivers\AFD.sys [273408]
[MD5.1F05B78AB91C9075565A9D8A4B880BC4] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.11/04/2009 - 07:32:26.) -- C:\Windows\system32\Drivers\atapi.sys [19944]
[MD5.7ADD03E75BEB9E6DD102C3081D29840A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.19/01/2008 - 06:28:02.) -- C:\Windows\system32\Drivers\Cdfs.sys [70144]
[MD5.6B4BFFB9BECD728097024276430DB314] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.11/04/2009 - 05:39:17.) -- C:\Windows\system32\Drivers\Cdrom.sys [67072]
[MD5.622C41A07CA7E6DD91770F50D532CB6C] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.14/04/2011 - 15:59:03.) -- C:\Windows\system32\Drivers\DfsC.sys [75264]
[MD5.062452B7FFD68C8C042A6261FE8DFF4A] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.11/04/2009 - 05:42:42.) -- C:\Windows\system32\Drivers\HDAudBus.sys [561152]
[MD5.22D56C8184586B7A1F6FA60BE5F5A2BD] - (.Microsoft Corporation - Pilote de port i8042.) (.19/01/2008 - 06:49:18.) -- C:\Windows\system32\Drivers\i8042prt.sys [54784]
[MD5.8793643A67B42CEC66490B2A0CF92D68] - (.Microsoft Corporation - IP Network Address Translator.) (.19/01/2008 - 06:56:28.) -- C:\Windows\system32\Drivers\IpNat.sys [100864]
[MD5.1E94971C4B446AB2290DEB71D01CF0C2] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.29/04/2011 - 14:24:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [106496]
[MD5.ECD64230A59CBD93C85F1CD1CAB9F3F6] - (.Microsoft Corporation - MBT Transport driver.) (.11/04/2009 - 05:45:37.) -- C:\Windows\system32\Drivers\netBT.sys [185856]
[MD5.2C1121F2B87E9A6B12485DF53CD848C7] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.03/03/2013 - 20:07:52.) -- C:\Windows\system32\Drivers\ntfs.sys [1082232]
[MD5.0FA9B5055484649D63C303FE404E5F4D] - (.Microsoft Corporation - Pilote de port parallèle.) (.02/11/2006 - 09:51:30.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.A214ADBAF4CB47DD2728859EF31F26B0] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.19/01/2008 - 06:56:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [76288]
[MD5.E8BD98D46F2ED77132BA927FCCB47D8B] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.02/11/2006 - 10:03:00.) -- C:\Windows\system32\Drivers\rdpdr.sys [242688]
[MD5.7B75299A4D201D6A6533603D6914AB04] - (.Microsoft Corporation - SMB Transport driver.) (.11/04/2009 - 05:45:22.) -- C:\Windows\system32\Drivers\smb.sys [66560]
[MD5.76B06EB8A01FC8624D699E7045303E54] - (.Microsoft Corporation - TDI Translation Driver.) (.11/04/2009 - 05:45:56.) -- C:\Windows\system32\Drivers\tdx.sys [72192]
[MD5.786DB5771F05EF300390399F626BF30A] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.21/08/2012 - 12:47:42.) -- C:\Windows\system32\Drivers\volsnap.sys [224640]
~ Generic Processes: Scanned in 00mn 01s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/14322
~ Mes musiques (My Musics) : 1/817
~ Mes Videos (My Videos) : 1/19
~ Mes Favoris (My Favorites) : 0/0
~ Mes Documents (My Documents) : 2/852
~ Mon Bureau (My Desktop) : 1/20
~ Menu demarrer (Programs) : 1/34
~ Hidden Files: Scanned in 00mn 46s
---\\ Processus lancés au démarrage du système
[MD5.AF334CA84536E743D6AEF32548223403] - (.Sony Corporation - Wireless Switch Setting Utility.) -- C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe [469112] [PID.2400]
[MD5.F9EA44A4691F738159D64848509D7B5C] - (.Sony Corporation - VAIO Update.) -- C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe [870240] [PID.3304]
[MD5.B6624D1D446A9683BAF8E482B1774C05] - (.Glarysoft Ltd - Glary Utilities 3.) -- C:\Program Files\Glary Utilities 3\Integrator.exe [470816] [PID.4524]
[MD5.3F11B20D12D89365D7721BDC860CE5F0] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe [4858968] [PID.4532]
[MD5.D63797E8E7781EE1500A810CB6194FA6] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816] [PID.4624]
[MD5.C1DB9BDF885C2F1ADC15264FBEA2788F] - (.Pas de propriétaire - HOSTS Anti-PUPs/Adwares.) -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe [302961] [PID.4672]
[MD5.CE42DFE915F78246364D464902E47360] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [152392] [PID.4688]
[MD5.5D61BE7DB55B026A5D61A3EED09D0EAD] - (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408] [PID.4696]
[MD5.BF08674925F151BD4537B89A493E3E0C] - (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehtray.exe [125952] [PID.4704]
[MD5.3F3A26E471CCCB3CFFCA68F0C052F35F] - (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\w32x86\3\E_FATIIKE.exe [249440] [PID.4752]
[MD5.211206B7623FD9F54B5484E39CF1471A] - (.Sony NSCE - Marketing Tools.) -- C:\Program Files\Sony\Marketing Tools\MarketingTools.exe [36864] [PID.5564]
[MD5.0F4195B9B348DE5CF9B822F81704B20E] - (.Microsoft Corporation - Media Center Media Status Aggregator Servic.) -- C:\Windows\ehome\ehmsas.exe [37376] [PID.5908]
[MD5.6080A176D09435FC8E6E800996656E18] - (.Microsoft Corporation - Console IME.) -- C:\Windows\system32\conime.exe [69120] [PID.6132]
[MD5.7E6EA9CB72B5DE84A5D700BED877E5F9] - (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe [397312] [PID.5784]
[MD5.57EC630DBD5F0713E77CB3540AB80A8E] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [757400] [PID.2444]
[MD5.10B01048B1DA075CD1EE27E30B4CF342] - (.Google Inc. - Google Toolbar Broker.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe [308816] [PID.5756] =>Toolbar.Google
[MD5.5B7E4A7A93BBCC820B6DA12B28841B57] - (.Adobe Systems Incorporated - Adobe® Flash® Player Installer/Uninstaller.) -- C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe [814984] [PID.4288]
[MD5.2D821AFA5A1A9CA7F9F997A1AAD09E72] - (.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe [168960] [PID.5892]
[MD5.1DE123E71FF306C076147813047AF987] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [7874560] [PID.7576]
[MD5.862BB4CBC05D80C5B45BE430E5EF872F] - (.Microsoft Corporation - Service de gestion des licences Microsoft.) -- C:\Windows\system32\SLsvc.exe [3408896] [PID.1360]
[MD5.28D6701C710AD7BA3CB95E75F8F1A9AA] - (.AVAST Software - avast! Service.) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [46808] [PID.1748]
[MD5.ADC420616C501B45D26C0FD3EF1E54E4] - (.ArcSoft Inc. - ArcSoft Connect Service.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152] [PID.400]
[MD5.E8FE4FCE23D2809BD88BCC1D0F8408CE] - (...) -- C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [124832] [PID.496]
[MD5.ADDA5E1951B90D3D23C56D3CF0622ADC] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [65640] [PID.608]
[MD5.7D4E8DE794E4B3A06CB274E48F36C578] - (.Home - Pas de description.) -- C:\Program Files\APLI-AGIPA\Agipa Master\AgipaAutoUpdater.exe [167936] [PID.12]
[MD5.4FE5C6D40664AE07BE5105874357D2ED] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [57008] [PID.840]
[MD5.DB5BEA73EDAF19AC68B2C0FAD0F92B1A] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [390504] [PID.1032]
[MD5.E9EFCB47B90FD5498695BB7FEFD36CAE] - (.Seiko Epson Corporation - Epson Scanner Service (32bit).) -- C:\Windows\system32\EscSvc.exe [122000] [PID.2000]
[MD5.582F2D900A3AC34C98FBDC2C0ABEF6B9] - (.Intel Corporation - RAID Monitor.) -- C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [355096] [PID.2484]
[MD5.388AE59FE75F1B959DFA0900923C61BB] - (.Skype Technologies S.A. - Skype C2C Service.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000] [PID.2736]
[MD5.7E6DD4B34ACD36AF6C711D2BDE91B040] - (.IDT, Inc. - STacSV Module.) -- C:\Windows\system32\stacsv.exe [102400] [PID.2800]
[MD5.3D7B66D3B25DFBDE7B96114E2D8EF2B3] - (.ArcSoft, Inc. - MgiSvr.) -- C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe [104960] [PID.2888]
[MD5.8A9F18ADAD471402236CA931553BF79B] - (.Sony Corporation - VAIO Event Service (Service Module).) -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [182392] [PID.2912]
[MD5.4D6644132F26EF055A1F754B1C38C084] - (.Sony Corporation - VAIO Entertainment UPnP Client Adapter.) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [274432] [PID.3000]
[MD5.15A317674A08DF26BE65164D959E9203] - (.Conexant Systems, Inc. - Modem Audio Service.) -- C:\Windows\system32\DRIVERS\xaudio.exe [386560] [PID.3380]
[MD5.794D4B48DFB6E999537C7C3947863463] - (.Safer Networking Ltd. - Spybot-S&D Security Center integration.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368] [PID.3472]
[MD5.2E785F4F92C4C67CEBB61DD55ED1F6A1] - (.Sony Corporation - VAIO Entertainment Database Service.) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512] [PID.3580]
[MD5.B0C84CEA4FE07231BA87A054AF95984D] - (.Sony Corporation - VAIO Event Service(Service Sub Module).) -- C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe [100472] [PID.3696]
[MD5.2D876CAD8C7FFB08179DFF361FF851E6] - (.Sony Corporation - VAIO Entertainment File Import Service.) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe [131072] [PID.3836]
[MD5.ECEF404F62863755951E09C802C94AD5] - (.Microsoft Corporation - Détection de services interactifs.) -- C:\Windows\system32\UI0Detect.exe [35840] [PID.4000]
[MD5.605AC5F17669767C7A750314753CF8EB] - (.Sony Corporation - SPM Module.) -- C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [921600] [PID.3012]
[MD5.C559672F31ABE6BA7277DD73C4502238] - (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\system32\msiexec.exe [73216] [PID.1432]
[MD5.D8B8B5A8FE57CF4F307A540D9A153C23] - (.Apple Inc. - iPodService Module (32-bit).) -- C:\Program Files\iPod\bin\iPodService.exe [553288] [PID.2536]
~ Processes Running: Scanned in 00mn 04s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Françoise\AppData\Local\Google\Chrome\User Data\Default\Preferences
~ Google Browser: 1 Legitimates Filtered in 00mn 10s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN: [HKLM] [@fluxdvd.com/NPAPIX] - (.Pas de propriétaire - APIX Mozilla Plugin.) -- C:\Program Files\Common Files\fluxDVD\APIX\NPAPIX.dll
P2 - FPN: [HKLM] [@fluxdvd.com/NPFluxBrowserHelper] - (.Pas de propriétaire - fluxDVD Browser Helper Plugin.) -- C:\Program Files\Common Files\fluxDVD\BrowserIntegration\NPFluxBrowserHelper.dll
P2 - FPN: [HKLM] [@protectdisc.com/NPMPDRM] - (.Pas de propriétaire - MPDRM License Acquisition Plugin.) -- C:\Program Files\Common Files\mpDRM\NPMPDRM.dll
P2 - FPN: [HKLM] [***@***/YahooActiveXPluginBridge;version=1.0.0.1] - (...) -- C:\Program Files\Yahoo!\Common\npyaxmpb.dll (.not file.) =>Toolbar.Yahoo
~ Firefox Browser: 31 Legitimates Filtered in 00mn 01s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.free.fr
~ IE Browser: 9 Legitimates Filtered in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 03s
~ Nombre de lignes (Lines number): 22823
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: MHTBPos00 - {0C37B053-FD68-456a-82E1-D788EE342E6F} . (.Pas de propriétaire - IE Toolbar Engine.) -- C:\Program Files\Family Toolbar\tbcore3.dll
O2 - BHO: MyHeritage New Tab - {D62EC836-BF1E-4CAC-81BE-FB9179835D8E} . (.Pas de propriétaire - mhxpcomi New Tab Library.) -- C:\Program Files\Family Toolbar\mhxpcomi.dll
~ BHO: 24 Legitimates Filtered in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: EPSON Web-To-Page - [HKLM]{EE5D279F-081B-4404-994D-C6B60AAEBA6D} . (.SEIKO EPSON CORPORATION - EPSON Web-To-Page.) -- C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Easy Photo Print - [HKLM]{9421DD08-935F-4701-A9CA-22DF90AC4EA6} . (.SEIKO EPSON CORPORATION / CyCom Technology - Epson Easy Photo Print (TBL).) -- C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: avast! WebRep - [HKLM]{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{F2CF5485-4E02-4F68-819C-B92DE9277049} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{EE5D279F-081B-4404-994D-C6B60AAEBA6D} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{21FA44EF-376D-4D53-9B0F-8A89D3229068} Clé orpheline
~ Toolbar: Scanned in 00mn 00s
---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKLM\..\Run: [avast] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\avastUI.exe
O4 - HKLM\..\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Run: [Google Desktop Search] . (.Google - Google Desktop.) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe
O4 - HKLM\..\Run: [HOSTS Anti-Adware_PUPs] . (.Pas de propriétaire - HOSTS Anti-PUPs/Adwares.) -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe
O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\windows sidebar\sidebar.exe
O4 - HKCU\..\Run: [EPLTarget\P0000000000000002] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIIKE.exe
O4 - HKCU\..\Run: [WMPNSCFG] . (.Microsoft Corporation - Application de configuration du service Par.) -- C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] oobefldr.dll
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] oobefldr.dll
O4 - HKUS\S-1-5-21-149699470-4155078432-4155011755-1000\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-149699470-4155078432-4155011755-1000\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-21-149699470-4155078432-4155011755-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\windows sidebar\sidebar.exe
O4 - HKUS\S-1-5-21-149699470-4155078432-4155011755-1000\..\Run: [EPLTarget\P0000000000000002] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIIKE.exe
O4 - HKUS\S-1-5-21-149699470-4155078432-4155011755-1000\..\Run: [WMPNSCFG] . (.Microsoft Corporation - Application de configuration du service Par.) -- C:\Program Files\Windows Media Player\WMPNSCFG.exe
~ Application: Scanned in 00mn 00s
---\\ Autres liens utilisateurs (O4)
O4 - GS\Programs: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\Programs: RescuePRO Deluxe DEMO.lnk . (...) -- C:\Users\Françoise\AppData\Roaming\Microsoft\Installer\{FEE63C37-2AA8-4D3F-97B8-D7E010C684E9}\IconFEE63C37.exe
O4 - GS\Programs: Uninstall RescuePRO Deluxe DEMO.lnk . (.Microsoft Corporation - Installateur Windows®.) -- C:\Windows\System32\msiexec.exe
O4 - GS\Programs: Windows Mail.lnk . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe
O4 - GS\Programs: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe
O4 - GS\QuickLaunch: Glary Utilities 3.lnk . (.Glarysoft Ltd - Glary Utilities 3.) -- C:\Program Files\Glary Utilities 3\Integrator.exe
O4 - GS\QuickLaunch: Gmail Notifier.lnk . (.Google Inc. - Gmail Notifier.) -- C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - GS\QuickLaunch: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
O4 - GS\QuickLaunch: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture.) -- C:\Windows\System32\SnippingTool.exe
O4 - GS\QuickLaunch: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe
O4 - GS\Accessories: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\SendTo: Assistant Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - Pas de description.) -- C:\Windows\System32\fsquirt.exe
O4 - GS\SendTo: Documents sur GPS.LNK - Clé orpheline
O4 - GS\SendTo: Format Factory.lnk . (.Free Time - FormatFactory.) -- C:\Program Files\FreeTime\FormatFactory\FormatFactory.exe
O4 - GS\SendTo: Skype.lnk . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe
O4 - GS\Desktop: Format Factory.lnk . (.Free Time - FormatFactory.) -- C:\Program Files\FreeTime\FormatFactory\FormatFactory.exe
O4 - GS\Desktop: Free Video Flip and Rotate.lnk . (.DVDVideoSoft Ltd. - FreeVideoFlipAndRotate.) -- C:\Program Files\DVDVideoSoft\Free Video Flip and Rotate\FreeVideoFlipAndRotate.exe
O4 - GS\Desktop: JkDefrag.lnk . (.www.jkdefrag.fr - JkDefrag - défragmenteur de disque léger, c.) -- C:\Program Files\JkDefrag\JkDefrag.exe
O4 - GS\Desktop: Microsoft Office - Raccourci.lnk . (...) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O4 - GS\Desktop: Spider Solitaire - Raccourci.lnk - Clé orpheline
O4 - GS\Desktop: Spybot - Search & Destroy.lnk . (.Safer Networking Limited - Spybot - Search & Destroy.) -- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
O4 - GS\Desktop: Windows Mail.lnk . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe
~ Global Startup: Scanned in 00mn 01s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft Office OneNote Internet Explorer Add-in.) -- C:\Program Files\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} . (.Microsoft Corporation - Synchronisation des favoris ActiveSync.) -- C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -- Clé orpheline
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\OFFICE11\REFBARH.ICO
O9 - Extra button: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- C:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
O9 - Extra button: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -- Clé orpheline
~ IE Extra Buttons: Scanned in 00mn 00s
---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] *.canalplay.com
O15 - Trusted Zone: [HKCU\...\Domains] *.canalplusactive.com
O15 - Trusted Zone: [HKLM\...\Domains] *.canalplay.com
O15 - Trusted Zone: [HKLM\...\Domains] *.canalplusactive.com
~ IE Zone Confiance: Scanned in 00mn 03s
---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} ((no name)) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_5_1_4_0.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ((no name)) - http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} ((no name)) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} ((no name)) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
~ Objets ActiveX: Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{60ED18D1-C5FF-4B7E-8BCF-5B123D3ACB05}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\..\{FBC46F45-57E2-47D0-99B3-AFE967BD7D4C}: DhcpNameServer = 192.168.10.110 192.168.10.110 192.168.10.110 192.168.10.110
O17 - HKLM\System\CS1\Services\Tcpip\..\{60ED18D1-C5FF-4B7E-8BCF-5B123D3ACB05}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CS1\Services\Tcpip\..\{FBC46F45-57E2-47D0-99B3-AFE967BD7D4C}: DhcpNameServer = 192.168.10.110 192.168.10.110 192.168.10.110 192.168.10.110
O17 - HKLM\System\CS2\Services\Tcpip\..\{2F3A536B-0C0E-49CD-82FE-B832AEBBBD1B}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CS2\Services\Tcpip\..\{60ED18D1-C5FF-4B7E-8BCF-5B123D3ACB05}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CS3\Services\Tcpip\..\{2F3A536B-0C0E-49CD-82FE-B832AEBBBD1B}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CS3\Services\Tcpip\..\{60ED18D1-C5FF-4B7E-8BCF-5B123D3ACB05}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
~ Domain: Scanned in 00mn 00s
---\\ Titr_HJT34=Protocole additionnel (O18)
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: VESWinlogon . (.Sony Corporation - VAIO Event Service (Winlogon Notification M.) -- C:\Windows\System32\VESWinlogon.dll
~ Winlogon: Scanned in 00mn 00s
---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\Windows\System32\browseui.dll
~ STS/SSO: Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Agipa Master AutoUpdater (Agipa Master AutoUpdater) . (.Home - Pas de description.) - C:\Program Files\APLI-AGIPA\Agipa Master\AgipaAutoUpdater.exe
O23 - Service: XAudioService (XAudioService) . (.Conexant Systems, Inc. - Modem Audio Service.) - C:\Windows\System32\DRIVERS\xaudio.exe
~ Services: 20 Legitimates Filtered in 00mn 08s
---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk * ) - File not found
O34 - HKLM BootExecute: (BootDefrag.exe) - File not found
~ BEX: 2 Legitimates Filtered in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [4803] (...) -- C:\Users\Françoise\AppData\Local\Temp\launchie.vbs \\B (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{01C7D2C0-C225-404C-89CA-A5FBBF2A8638}] (...) -- C:\Users\Françoise\Documents\lide20lide30n670un676un1240uvst7031a_xpen.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{26080B8B-3149-4EE2-AE37-A2D23956E703}] (...) -- C:\Users\Françoise\Desktop\lide20lide30n670un676un1240uvst7031a_xpfr\SetupSG\SETUPSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{2C86FE19-7D4C-4B94-8C1A-6594EE3CA136}] (...) -- G:\EmDesk.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{3585497F-D6B1-4C9F-BC47-B55F56DF0BFD}] (...) -- C:\Users\Françoise\Desktop\lide20lide30n670un676un1240uvst7031a_xpfr\SetupSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{3660D07E-67EC-4DF0-9767-856B94BB5205}] (...) -- C:\Users\Françoise\Documents\Mes sites web\lide20lide30n670un676un1240uvst7031a_xpfr\SetupSG\SETUPSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{3826FBE6-FD88-4A8D-A241-DB72ECE164D1}] (...) -- C:\Users\Françoise\Documents\Mes sites web\SetupSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{38BA088E-EFCD-46D2-BC25-8F2C0FAE577D}] (...) -- C:\Users\Françoise\Documents\Mes sites web\lide20lide30n670un676un1240uvst7031a_xpfr\SetupSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{54A0FA59-ED9C-4853-B61E-8EECAA0698E3}] (...) -- C:\Users\Françoise\Documents\LiDE60_11100WNEN\SetupSG\SETUPSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{59B34607-DD2B-4B60-83AC-4F0D95EADBF1}] (...) -- C:\Users\Françoise\Documents\LiDE60_11100WNEN\SetupSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{6056F133-4C6C-463B-BFC4-5F8FB242BCE6}] (...) -- C:\Users\Françoise\Documents\LiDE60_11100WNEN\LiDE60_11100WNEN.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{6CC0830E-29F2-4ACA-A41C-07B4A1C5A10D}] (...) -- C:\Users\Françoise\Documents\Mes sites web\netsight_setup_5.1.2.15_MP_Production_mid50997575378_p.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{6EAB97D1-4F78-4666-A01A-F2667EC566B7}] (...) -- C:\Users\Françoise\Downloads\epson323813eu.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{74242A98-47B5-4597-A042-E32C472F9FB3}] (...) -- C:\Big Fish Games\sudoku\Uninstall.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{7A5CC06F-BC63-4153-86D9-B105C9FCD2F7}] (...) -- C:\Users\Françoise\Documents\TOTO\lide20lide30n670un676un1240uvst7031a_xpfr\lide20lide30n670un676un1240uvst7031a_xpfr\SetupSG.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{842FD594-FEDD-4120-9147-8047F6966A18}] (...) -- c:\Users\Françoise\Downloads\installer_intervideo_windvd_2010.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{91B956AB-EFDA-4DA6-950E-5140571E7013}] (...) -- C:\Users\Françoise\Documents\Mes sites web\install_7z460.exe.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{D041C939-81F7-4849-8471-4355E7272ED5}] (...) -- C:\Users\Françoise\Documents\Mes sites web\lide20lide30n670un676un1240uvst7031a_xpfr\lide20lide30n670un676un1240uvst7031a_xpfr\SetupSG.exe (.not file.) [0]
~ Scheduled Task: 42 Legitimates Filtered in 00mn 09s
---\\ Logiciels installés (O42)
O42 - Logiciel: Agipa Master - (...) [HKLM] -- {2F607417-9C1C-4B10-B634-839920C0C6E0}
O42 - Logiciel: Agipa Master - (.APLI-AGIPA S.A.S..) [HKLM] -- InstallShield_{233D0B18-0D06-48B9-87E0-E28B5A1D512C}
O42 - Logiciel: Magic-i Visual Effects - (...) [HKLM] -- {8866BCB3-3818-4C66-83BC-92006B5EFE50}
O42 - Logiciel: Module d'enregistrement 1.5.1.2 - (.YDP SA.) [HKLM] -- FlashComponents
O42 - Logiciel: Votre Economiseur Personnel 1.0 - (...) [HKLM] -- Votre Economiseur Personnel_is1
~ Logic: 179 Legitimates Filtered in 00mn 00s
---\\ HKCU & HKLM Software Keys
[HKCU\Software\Agipa]
[HKCU\Software\AsioStHd]
[HKCU\Software\LC Technology]
[HKCU\Software\RKD]
[HKCU\Software\WWA]
[HKCU\Software\Yahoo] =>Toolbar.Yahoo
[HKCU\Software\sms164]
[HKLM\Software\NSCPID]
[HKLM\Software\RKD]
[HKLM\Software\Winsudate]
[HKLM\Software\Yahoo] =>Toolbar.Yahoo
~ Key Software: 254 Legitimates Filtered in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 29/08/2008 - 18:03:30 - [7,147] ----D C:\Program Files\AGIPA
O43 - CFD: 21/11/2007 - 15:50:58 - [0,316] ----D C:\Program Files\BFG
O43 - CFD: 19/04/2011 - 12:39:36 - [0,095] ----D C:\Program Files\Bonjour(4)
O43 - CFD: 01/02/2011 - 14:08:13 - [5,726] ----D C:\Program Files\Family Toolbar
O43 - CFD: 28/08/2013 - 13:38:59 - [19,324] ----D C:\Program Files\Postcard Maker
O43 - CFD: 30/05/2013 - 21:23:41 - [0,000] ----D C:\Users\Françoise\AppData\Roaming\AgipaMaster
O43 - CFD: 20/08/2009 - 14:30:45 - [0,000] ----D C:\Users\Françoise\AppData\Roaming\play2p
O43 - CFD: 28/08/2013 - 13:55:37 - [69,867] ----D C:\Users\Françoise\AppData\Roaming\TNS
~ Program Folder: 244 Legitimates Filtered in 02mn 50s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.1F0331632F3137FE02170E95798A8BDE] - 03/09/2013 - 09:56:24 ---A- . (...) -- C:\DiskDefrag.log [75]
~ Files: 13 Legitimates Filtered in 00mn 21s
---\\ Clé de registre Shell MountPoints2 (MPKS) (O51)
O51 - MPSK:{4032caa9-f549-11df-a260-001a80b70d3f}\AutoRun\command. (...) -- I:\iStudio.exe (.not file.)
O51 - MPSK:{d85f96f4-49a7-11dd-a051-001a80b70d3f}\AutoRun\command. (...) -- C:\Windows\system32\copy.exe (.not file.)
O51 - MPSK:{d85f971a-49a7-11dd-a051-001a80b70d3f}\AutoRun\command. (...) -- C:\Windows\system32\copy.exe (.not file.)
O51 - MPSK:{d85f9720-49a7-11dd-a051-001a80b70d3f}\AutoRun\command. (...) -- C:\Windows\system32\copy.exe (.not file.)
~ Keys: Scanned in 00mn 00s
---\\ Enumération des clés de registre StartupReg (SMSR) (O53)
O53 - SMSR:HKLM\...\startupreg\MobileDocuments [Key] . (...) -- C:\Program Files\Common Files\Apple\Internet Services\ubd.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\WWA_Manager [Key] . (.TNS - wwamgr.exe.) -- C:\Users\Françoise\AppData\Roaming\TNS\wwamgr.exe
~ SMSR Keys: 22 Legitimates Filtered in 00mn 00s
---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
~ MWPS: 16 Legitimates Filtered in 00mn 00s
---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.B680134BA1813B78B47FDD1DFF223CA5] - 09/05/2013 - 09:59:10 ---A- . (...) -- C:\Windows\System32\Drivers\aswRvrt.sys [49376]
O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 02/11/2006 - 08:09:42 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
~ Drivers: 16 Legitimates Filtered in 00mn 00s
---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
O63 - Logiciel: RSIT - (.random/random.)
~ ADS: Scanned in 00mn 00s
---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - ??\??\???? - Pas de propriétaire (BootDefragDriver) .(...) - LEGACY_BOOTDEFRAGDRIVER
~ Legacy: 83 Legitimates Filtered in 00mn 00s
---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 19 Legitimates Filtered in 00mn 00s
---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <chrome.exe> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: <Safari.exe> <Safari>[HKLM\..\Shell\open\Command] (.Apple Inc. - Safari.) -- C:\Program Files\Safari\Safari.exe
~ Keys: Scanned in 00mn 00s
---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (@ieframe.dll,-12512) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {5EA074F4-5E5C-423B-9805-F051F7CA528D} - (Ask Search) - http://websearch.ask.com =>Toolbar.Ask
O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (@ieframe.dll,-12512) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {90F0023A-B14D-4A21-9B5D-DD48934AE8DC} [DefaultScope] - (Google) - http://www.google.fr
O69 - SBI: SearchScopes [HKCU] {AB63604F-3039-423E-A3C0-7C3A9254363D} - (Fast Browser Search) - http://www.fastbrowsersearch.com =>PUP.FbSearch
O69 - SBI: SearchScopes [HKCU] {BE28C22E-F666-424d-B5FD-125C4AFEE34E} - (Chercher) - http://search.myheritage.com
O69 - SBI: SearchScopes [HKCU] {c1d89ae7-449d-4929-b24b-fded04adbe06} - (Glary Search) - http://isearch.glarysoft.com
O69 - SBI: SearchScopes [HKCU] {e3bc0642-1dee-4740-9a16-c91c793e452f} - (Wibeez) - http://www.wibeez.com
O69 - SBI: SearchScopes [HKCU] {F0EA1748-2B93-4853-BE98-6080B9045A68} - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s
---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.A840741DAC99B0524F8D480E22F07EAA] [SPRF][28/04/2012] (...) -- C:\ProgramData\KGyGaAvL.sys [952]
[MD5.0BC6B3FBD3348E3DDE864747FC7A797F] [SPRF][29/07/2013] (...) -- C:\Users\Françoise\AppData\Local\d3d9caps.dat [8944]
[MD5.2666172098FF4F5BEFC0EB97ADBBE1AE] [SPRF][28/09/2009] (...) -- C:\Users\Françoise\AppData\Local\fusioncache.dat [97]
[MD5.7D7B4BB2FC34A15763157A23ED89F8B4] [SPRF][05/09/2013] (...) -- C:\Users\Françoise\AppData\Local\Temp\~gu3-ver.dat [160]
[MD5.08512BFFB233FFA2D77379B74C4EBB54] [SPRF][05/09/2013] (...) -- C:\Users\Françoise\AppData\Local\Temp\~upgrade.dat [936]
[MD5.490EF3EC464E7B3FE857AA1243F910E6] [SPRF][16/01/2010] (...) -- C:\Users\Françoise\AppData\Roaming\mdbu.bin [2049]
[MD5.97911873425E743D8F8857516FFA5627] [SPRF][11/05/2012] (...) -- C:\Users\Françoise\AppData\Roaming\nvModes.dat [262391]
[MD5.D41D8CD98F00B204E9800998ECF8427E] [SPRF][10/11/2011] (...) -- C:\Users\Françoise\AppData\Roaming\wklnhst.dat [0]
[MD5.33B3C89A9F5600F3D7D9C96AE4579F2C] [SPRF][15/12/2012] (.Google - Google Desktop.) -- C:\Users\Françoise\Desktop\GoogleDesktopSetup.exe [2021360]
~ Files: 12 Legitimates Filtered in 00mn 00s
---\\ Liste des exceptions du parefeu (FirewallRules) (O87)
O87 - FAEL: "TCP Query User{AB1C2C4F-C022-4EBD-BEB2-6788208FB978}C:\users\françoise\appdata\roaming\tns\wwamgr.exe" | In - Public - P6 - TRUE | .(.TNS - wwamgr.exe.) -- C:\users\françoise\appdata\roaming\tns\wwamgr.exe
O87 - FAEL: "UDP Query User{6F7732AC-20BD-4134-9B46-5079DD8C7160}C:\users\françoise\appdata\roaming\tns\wwamgr.exe" | In - Public - P17 - TRUE | .(.TNS - wwamgr.exe.) -- C:\users\françoise\appdata\roaming\tns\wwamgr.exe
~ Firewall: 237 Legitimates Filtered in 00mn 02s
---\\ Enumère les codes produits des logiciels (PUC) (O90)
O90 - PUC: "A81E737A17150D040843D72D34240018" . (.Software Updater.) -- C:\Windows\Installer\{A737E18A-5171-40D0-8034-7DD243420081}\icon.ico =>PUP.Eorezo
~ Update Products: 128 Legitimates Filtered in 00mn 00s
---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.72A2E3C1CDB80947BCDDB7138F39293C] [WIS][10/12/2009] (.Google - Google Earth.) -- C:\Windows\Installer\1ba5cc8.msi [1291776]
[MD5.250E76D26AA471D208065B8E3A0FE0BA] [WIS][30/05/2013] (.APLI-AGIPA S.A.S. - Agipa Master.) -- C:\Windows\Installer\2aa6d60.msi [8752640]
[MD5.CB4D9AF1F97286903EF0ACEEE1E5E1D0] [WIS][23/06/2009] (.LC Technology International, Inc - Version 4.1.) -- C:\Windows\Installer\73c315.msi [472576]
~ WIS: 139 Legitimates Filtered in 00mn 19s
---\\ Etat général des services not Microsoft (EGS) (SR=Running, SS=Stopped)
SR - | Auto 18/03/2010 113152 | (ACDaemon) . (.ArcSoft Inc..) - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
SR - | Auto 10/09/2007 124832 | (AdobeActiveFileMonitor6.0) . (...) - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
SR - | Auto 10/05/2013 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SS - | Demand 21/08/2013 257416 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SR - | Auto 17/10/2011 167936 | (Agipa Master AutoUpdater) . (.Home.) - C:\Program Files\APLI-AGIPA\Agipa Master\AgipaAutoUpdater.exe
SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 09/05/2013 46808 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 12/12/2011 122000 | (EpsonScanSvc) . (.Seiko Epson Corporation.) - C:\Windows\system32\EscSvc.exe
SS - | Demand 08/10/2012 654848 | (FLEXnet Licensing Service) . (.Macrovision Europe Ltd..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Demand 17/12/2012 30192 | (GoogleDesktopManager-051210-111108) . (.Google.) - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
SS - | Auto 13/06/2009 133104 | (gupdate1c9ec57d8767753) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 13/06/2009 133104 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 11/08/2012 194032 | (gusvc) . (.Google.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
SS - | Auto 17/08/2013 285795 | (HOSTS Anti-PUPs) . (...) - C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe
SR - | Auto 12/02/2007 355096 | (IAANTMON) . (.Intel Corporation.) - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
SS - | Demand 03/04/2005 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
SR - | Demand 16/08/2013 553288 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SS - | Demand 14/12/2006 45056 | (MSCSPTISRV) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
SS - | Demand 14/12/2006 57344 | (PACSPTISVR) . (...) - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
SR - | Auto 26/01/2009 1153368 | (SBSDWSCService) . (.Safer Networking Ltd..) - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
SR - | Auto 22/09/2010 249136 | (SeaPort) . (.Microsoft Corporation.) - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
SS - | Demand 20/06/2008 436096 | (Service CANALPLAY) . (.Canal+ Distribution.) - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
SR - | Auto 02/10/2012 3064000 | (Skype C2C Service) . (.Skype Technologies S.A..) - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
SS - | Auto 13/07/2012 160944 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SS - | Demand 14/12/2006 69632 | (SPTISRV) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
SR - | Auto 27/10/2007 102400 | (STacSV) . (.IDT, Inc..) - C:\Windows\system32\stacsv.exe
SR - | Auto 09/11/2007 104960 | (uCamMonitor) . (.ArcSoft, Inc..) - C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe
SS - | Demand 28/06/2007 73728 | (VAIO Entertainment TV Device Arbitration Service) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
SR - | Auto 14/08/2007 182392 | (VAIO Event Service) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
SS - | Demand 20/06/2007 2523136 | (VAIOMediaPlatform-IntegratedServer-AppServer) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
SS - | Demand 20/06/2007 397312 | (VAIOMediaPlatform-IntegratedServer-HTTP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
SS - | Demand 20/06/2007 1089536 | (VAIOMediaPlatform-IntegratedServer-UPnP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
SS - | Demand 20/06/2007 499712 | (VAIOMediaPlatform-Mobile-Gateway) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
SS - | Demand 10/01/2007 745472 | (VAIOMediaPlatform-UCLS-AppServer) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
SS - | Demand 20/06/2007 397312 | (VAIOMediaPlatform-UCLS-HTTP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
SS - | Demand 20/06/2007 1089536 | (VAIOMediaPlatform-UCLS-UPnP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
SS - | Demand 28/09/2007 292128 | (VcmIAlzMgr) . (.Sony Corporation.) - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
SS - | Demand 17/03/2008 87328 | (VcmXmlIfHelper) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
SR - | Demand 28/06/2007 274432 | (Vcsw) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
SR - | Auto 28/08/2007 192512 | (VzCdbSvc) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
SR - | Auto 28/08/2007 131072 | (VzFw) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
SR - | Auto 19/01/2008 21504 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 19/01/2008 21504 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 27/09/2007 386560 | (XAudioService) . (.Conexant Systems, Inc..) - C:\Windows\System32\DRIVERS\xaudio.exe
~ Services: Scanned in 00mn 23s
---\\ Scan Additionnel (O88)
Database Version : v2.12882 - (04/09/2013)
Clés trouvées (Keys found) : 3
Valeurs trouvées (Values found) : 1
Dossiers trouvés (Folders found) : 1
Fichiers trouvés (Files found) : 5
[HKLM\Software\Winsudate] =>Adware.Gibmedia
[HKLM\Software\Classes\Toolbar3.MHTBPos00] =>Toolbar.Agent
[HKLM\Software\Classes\Toolbar3.MHTBPos00.1] =>Toolbar.Agent
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google^
C:\Program Files\Family Toolbar =>Toolbar.Agent
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe =>Toolbar.Google^
C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google^
[HKCU\Software\Yahoo] =>Toolbar.Yahoo^
[HKLM\Software\Yahoo] =>Toolbar.Yahoo^
C:\Windows\Installer\{A737E18A-5171-40D0-8034-7DD243420081}\icon.ico =>PUP.Eorezo^
~ Additionnel Scan: 391248 Items scanned in 00mn 50s
---\\ Récapitulatif des détections trouvées sur votre station
~ http://nicolascoolman.webs.com/apps/blog/show/32384220-toolbar-google =>Toolbar.Google
~ http://nicolascoolman.webs.com/apps/blog/show/30268689-toolbar-yahoo =>Toolbar.Yahoo
~ http://nicolascoolman.webs.com/apps/blog/show/28927746-toolbar-ask =>Toolbar.Ask
~ http://nicolascoolman.webs.com/apps/blog/show/27629963-pup-fbsearch =>PUP.Fbsearch
~ http://nicolascoolman.webs.com/apps/blog/show/27469224-pup-eorezo =>PUP.EoRezo
~ MSI: 5 link(s) detected in 00mn 50s
~ 1350 Legitimates filtered by white list
End of the scan (620 lines in 06mn 29s)(0)
yoann090
Messages postés
9180
Date d'inscription
mercredi 12 août 2009
Statut
Contributeur sécurité
Dernière intervention
13 avril 2016
1 689
5 sept. 2013 à 21:02
5 sept. 2013 à 21:02
Ok La j ai quitté l ordi, je te passerai un script demain. ++