Problème avec OOPle

Fermé
COCO499 - 17 déc. 2013 à 18:08
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 - 19 déc. 2013 à 10:20
Bonjour,

Voici mon rapport ZHPdiag, que dois-je en faire?



Merci
~ Rapport de ZHPDiag v2013.12.14.22 - Nicolas Coolman (2013-12-14)
~ Lancé par admin (2013-12-17 11:50:14)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.16476
MFIE: Mozilla Firefox 25.0.1 (Defaut)
GCIE: Google Chrome v31.0.1650.63

---\\ Informations sur les produits Windows
~ Langage: Français
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 3Q6C9
Windows License : OK
~ Windows Remaining Initializations Number : 2
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft Security Client v4.4.0304.0
McAfee Security Scan Plus v3.8.130.10
Spybot - Search & Destroy v1.6.2
Windows Defender W7

---\\ Logiciels d'optimisation du système
CCleaner v3.04 =>Piriform Ltd

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 11 Plugin
Adobe Reader X
Java 7 Update 45

---\\ Informations sur le système
~ Processor: Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3999 MB (49% free)
System Restore: Activé (Enable)
System drive C: has 345 GB (76%) free of 453 GB

---\\ Mode de connexion au système
~ Computer Name: ADMIN-PC
~ User Name: admin
~ All Users Names: HomeGroupUser$, Charlot et Mimi, Administrateur, admin,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\admin\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\admin\AppData\Roaming\
~ %Desktop% : C:\Users\admin\Desktop\
~ %Favorites% : C:\Users\admin\Favorites\
~ %LocalAppData% : C:\Users\admin\AppData\Local\
~ %StartMenu% : C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 345 Go of 453 Go)
D: Hard drive, Flash drive, Thumb drive (Free 2 Go of 13 Go)
E: CD-ROM drive (Not Inserted)
F: Floppy drive, Flash card reader, USB Key (Free 7 Go of 8 Go)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
~ Security Center: 50 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.2011-02-25 - 01:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.2009-07-13 - 20:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.9B6678DB9C6A232C5A84D2FDFFF8B0E1] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.2013-11-26 - 02:07:57.) -- C:\Windows\System32\wininet.dll [2334208]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.2010-11-20 - 08:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.2010-11-20 - 08:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.2013-09-27 - 20:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.2009-07-13 - 20:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.2009-07-13 - 18:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.2010-11-20 - 04:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.2010-11-20 - 04:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.2010-11-20 - 05:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.2009-07-13 - 18:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.2009-07-13 - 19:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.2011-04-26 - 21:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.2010-11-20 - 04:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.2013-04-12 - 09:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.2009-07-13 - 19:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.2010-11-20 - 05:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.2009-07-13 - 19:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.2010-11-20 - 04:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.2010-11-20 - 08:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 2/3003
~ Mes musiques (My Musics) : 50/727
~ Mes Videos (My Videos) : 2/9
~ Mes Favoris (My Favorites) : 1/473
~ Mes Documents (My Documents) : 14/18684
~ Mon Bureau (My Desktop) : 1/4
~ Menu demarrer (Programs) : 1/29
~ Hidden Files: Scanned in 00mn 14s



---\\ Processus lancés
[MD5.D1D5DAB39DCB4BE0359943738D87409B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [532040] [PID.2688]
[MD5.AC5034C83702370B0630039E7FC1E1BA] - (.Druide informatique inc. - AgentAntidote.) -- C:\Program Files (x86)\Druide\Antidote 8\Programmes32\AgentAntidote.exe [1144544] [PID.3324]
[MD5.E02E715FA2BC8D88FF9362374E309D76] - (.Hewlett-Packard Company - Pas de description.) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392] [PID.3768]
[MD5.817F3DB00337569001B7DC9814F121B5] - (.Pas de propriétaire - Business-in-a-Box Launcher Application.) -- C:\Program Files (x86)\Business-in-a-Box\BIBLauncher.exe [901600] [PID.3876]
[MD5.497F27E279C0F921E2130BB89C1CB5CA] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe [18705664] [PID.4092]
[MD5.32C26797AB646074A2BB562F9D10ADB5] - (.Microsoft Corporation - Microsoft Office OneNote Quick Launcher.) -- C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.exe [97680] [PID.3712]
[MD5.8F89E6CB82E6DB45BC993D423CD0FDBD] - (. Hewlett-Packard Development Company, L.P. - Quick Launch Buttons.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe [323640] [PID.3660]
[MD5.41431C8D04A49D06FDCCBCDBC68F7AE5] - (.Sage - Sage 50 Connection Manager [0036-rel\2014.0.) -- C:\Program Files (x86)\winsim\ConnectionManager\Simply.SystemTrayIcon.exe [152880] [PID.4032]
[MD5.C637FC4638A96165256B28D38DE7B953] - (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208] [PID.3752]
[MD5.8E53B67FA3816E854B07C5DC66E10730] - (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files (x86)\real\realplayer\Update\realsched.exe [296056] [PID.3040]
[MD5.8E2A7F1F62467A7DCB8AB2C0642F47CA] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392] [PID.3008]
[MD5.5B6E8E09BE6401A7E022F52FDFCB2FF8] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336] [PID.3020]
[MD5.C1DB9BDF885C2F1ADC15264FBEA2788F] - (.Pas de propriétaire - HOSTS Anti-PUPs/Adwares.) -- C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe [302961] [PID.3852]
[MD5.534A3CB0847BA114F0D8A5F2BB2EF6D0] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe [887432] [PID.4896]
[MD5.0DE3C7622EC33126579B1742260F08C2] - (.Pas de propriétaire - HpqToaster Module.) -- C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe [632888] [PID.4436]
[MD5.077D59BA0FD4007E841B6C670862B065] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [275568] [PID.2580]
[MD5.CC02FE4520CA886508069245D9A6962F] - (.Microsoft Corporation - Internet Low-Mic Utility Tool.) -- C:\Program Files (x86)\Internet Explorer\IELowutil.exe [222720] [PID.2680]
[MD5.E0B173F23D873286169995D66B9E3CDF] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe [18544] [PID.4372]
[MD5.5D60EE718D0C708D69DFF4B3336B68BF] - (.Adobe Systems, Inc. - Adobe Flash Player 11.9 r900.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe [1862536] [PID.4892]
[MD5.2330B5A4A3824F042DC96D524893A6B5] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8295936] [PID.5404]
[MD5.ADDA5E1951B90D3D23C56D3CF0622ADC] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65640] [PID.1476]
[MD5.4FE5C6D40664AE07BE5105874357D2ED] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [57008] [PID.1512]
[MD5.CFD54D70F76E84E1E737AE1140FBC5C0] - (.Garmin Ltd or its subsidiaries - Garmin Core Update Service.) -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [220504] [PID.1656]
[MD5.9D287ED0BF88FEC8CE11F9829B81A3D7] - (.Sage - Sage 50 Connection Manager [0036-rel\2014.0.) -- C:\Program Files (x86)\Winsim\ConnectionManager\SimplyConnectionManager.exe [24368] [PID.1760]
[MD5.B7382BEC806B7B00FC84B3E2061FF48E] - (.Hewlett-Packard Company - HP Quick Synchronization Service.) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [197536] [PID.2300]
[MD5.2238B91AC1A12CC6CC4C4FED41258B2A] - (.Hewlett-Packard Company - LightScribe Service.) -- C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728] [PID.2352]
[MD5.65085456FD9A74D7F1A999520C299ECB] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376] [PID.2384]
[MD5.E0D7732F2D2E24B2DB3F67B6750295B8] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512] [PID.2404]
[MD5.A1688A4FB2EC49D040C027EF6DC7A87B] - (.pdfforge GbR - PDF Architect Helper Service.) -- C:\Program Files (x86)\PDF Architect\HelperService.exe [1324104] [PID.2432]
[MD5.E23FF9B2F8EEAB2BDDA681C21C48E843] - (.pdfforge GbR - PDF Architect Conversion Service.) -- C:\Program Files (x86)\PDF Architect\ConversionService.exe [795208] [PID.2468]
[MD5.498EB62A160674E793FA40FD65390625] - (.Pas de propriétaire - RichVideo Module.) -- C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152] [PID.2492]
[MD5.388AE59FE75F1B959DFA0900923C61BB] - (.Skype Technologies S.A. - Skype C2C Service.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000] [PID.2524]
[MD5.794D4B48DFB6E999537C7C3947863463] - (.Safer Networking Ltd. - Spybot-S&D Security Center integration.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368] [PID.2752]
[MD5.9B7EDD3FE7C211C36E921D34D18A3A0A] - (.Hewlett-Packard Company - HP Software Framework WMI Service.) -- C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [1001376] [PID.4692]
[MD5.C7A0E61D5714AC20DE52D4F66EC773B8] - (.Hewlett-Packard Development Company, L.P. - Com for QLB application.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [227896] [PID.2120]
~ Processes Running: Scanned in 00mn 01s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
G1 - GCS: Preference [User Data\Default] http://www.google.com
G2 - GCE: Preference [User Data\Default] [dpajjaohbgbnjlccpoocjgbncmlnijmb] Oople v.10.22.5.10, (Désactivé)
G2 - GCE: Preference [User Data\Default] [mjcnhgdodmhnpmndnljbmafpgomahfal] Antidote v.8.20.29 (Activé)
~ Google Browser: 17 Legitimates Filtered in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\gdu3277x.default\prefs.js
M3 - MFPP: Plugins - [admin] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\avg_igeared.xml
M2 - MFEP: prefs.js [admin - gdu3277x.default\***@***] [] Module d'Antidote v8.16.29 (..)
~ Firefox Browser: 31 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 06s
~ Nombre de lignes (Lines number): 16848



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: QUICKfind BHO Object [64Bits] - {C08DF07A-3E49-4E25-9AB0-D3882835F153} . (.IDM - QUICKfind BHO Object.) -- C:\Program Files (x86)\IDM\QUICKfind\PlugIns\IEHelp.dll
~ BHO: 16 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{472734EA-242A-422B-ADF8-83D1E48CC825} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{1FCA4DF8-9ACD-4DFB-89CC-DDD0082FC588} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{55D7C7BC-12A7-4F9B-81C0-600D9A182395} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: LogiTermPro.lnk . (.Terminotix - LogiTermWeb Client.) -- C:\Program Files (x86)\Terminotix\LogiTerm\ltwebclient.exe
O4 - GS\Desktop [Public]: Longman Dictionary of Contemporary English 5th Edition.lnk . (.mozilla.org - ldoce5.) -- C:\Program Files (x86)\Longman\LDOCE5\ldoce5.exe
O4 - GS\Desktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Desktop [Public]: OmegaT.lnk . (...) -- C:\Program Files (x86)\OmegaT\OmegaT.exe
O4 - GS\Desktop [Public]: Sage 50 Comptabilité Pro .lnk . (.Sage - Sage 50 Accounting [0008-rel\2014.1].) -- C:\Program Files (x86)\Sage 50 Comptabilité Pro\Sage50Accounting.exe
O4 - GS\Desktop [Public]: Talk to Me 7.0.lnk . (.Auralog - Talk to Me application.) -- C:\Program Files (x86)\Auralog\Talk to Me 7.0\bin\ttm.exe
O4 - GS\Desktop [Public]: TaxTron T2 2013.1 Netfile.lnk . (.TaxTron - TaxTron.) -- C:\Program Files (x86)\TaxTron\TaxTron T2 2013.1 Netfile\bin\TaxTron.exe
O4 - GS\Program [Public]: DT Max.lnk . (.Flexera Software LLC - InstallShield.) -- C:\Windows\Installer\{51A64F91-BB6F-4D27-9BD0-DA8F08277E7F}\NewShortcut2_51A64F91BB6F4D279BD0DA8F08277E7F.exe
O4 - GS\Program [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\QuickLaunch [Charlot et Mimi]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\QuickLaunch [Charlot et Mimi]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\TaskBar [Charlot et Mimi]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\TaskBar [Charlot et Mimi]: HPAdvisor.lnk . (.Hewlett-Packard - HP Advisor.) -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
O4 - GS\TaskBar [Charlot et Mimi]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\TaskBar [Charlot et Mimi]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Program [Charlot et Mimi]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\SystemTools [Charlot et Mimi]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Desktop [Charlot et Mimi]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\QuickLaunch [admin]: Business-in-a-Box.lnk . (...) -- C:\Program Files (x86)\Business-in-a-Box\BIB.exe
O4 - GS\QuickLaunch [admin]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\QuickLaunch [admin]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch [admin]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\QuickLaunch [admin]: Play HP Games.lnk . (...) -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsole-wt.exe (.not file.)
O4 - GS\QuickLaunch [admin]: Spybot - Search & Destroy.lnk . (.Safer Networking Limited - Spybot - Search & Destroy.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
O4 - GS\TaskBar [admin]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Program [admin]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\SystemTools [admin]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Desktop [admin]: tabagie - Raccourci.lnk . (...) -- C:\Users\admin\Documents\tabagie
~ Global Startup: 89 Legitimates Filtered in 00mn 02s



---\\ Applications lancées au démarrage du sytème (O4)
O4 - GS\Startup [Public]: McAfee Security Scan Plus.lnk . (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
O4 - GS\Startup [admin]: OneNote 2007 - Capture d'écran et lancement.lnk . (.Microsoft Corporation - Microsoft Office OneNote Quick Launcher.) -- C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.)
O4 - HKLM\..\Run: [cAudioFilterAgent] . (.Conexant Systems, Inc. - Conexant High Definition Audio Filter Agent.) -- C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jusched.exe =>.Oracle Corporation
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKLM\..\Run: [AgentAntidote32] . (.Druide informatique inc. - AgentAntidote.) -- C:\Program Files (x86)\Druide\Antidote 8\Programmes32\AgentAntidote.exe
O4 - HKLM\..\Run: [AgentAntidote64] . (.Druide informatique inc. - AgentAntidote.) -- C:\Program Files (x86)\Druide\Antidote 8\Programmes64\AgentAntidote.exe
O4 - HKLM\..\RunOnce: [NCPluginUpdater] . (.Hewlett-Packard - NCPluginUpdater.) -- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] . (.Hewlett-Packard Company - Pas de description.) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
O4 - HKCU\..\Run: [BIBLauncher] . (.Pas de propriétaire - Business-in-a-Box Launcher Application.) -- C:\Program Files (x86)\Business-in-a-Box\BIBLauncher.exe
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKCU\..\Run: [GarminExpressTrayApp] . (.Garmin Ltd or its subsidiaries - Express Tray.) -- C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKLM\..\Wow6432Node\Run: [QlbCtrl.exe] . (. Hewlett-Packard Development Company, L.P. - Quick Launch Buttons.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
O4 - HKLM\..\Wow6432Node\Run: [ConnectionManager] . (.Sage - Sage 50 Connection Manager [0036-rel\2014.0.) -- C:\Program Files (x86)\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe
O4 - HKLM\..\Wow6432Node\Run: [WirelessAssistant] . (.Hewlett-Packard Company - HP Wireless Assistant Main Program.) -- C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated
O4 - HKLM\..\Wow6432Node\Run: [HP Software Update] . (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe =>.Hewlett-Packard Co
O4 - HKLM\..\Wow6432Node\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- c:\program files (x86)\real\realplayer\Update\realsched.exe =>.RealNetworks, Inc
O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Wow6432Node\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files (x86)\QuickTime\QTTask.exe
O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle Corporation
O4 - HKLM\..\Wow6432Node\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [HOSTS Anti-Adware_PUPs] . (.Pas de propriétaire - HOSTS Anti-PUPs/Adwares.) -- C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-1645801248-2251260275-3349309149-1000\..\Run: [LightScribe Control Panel] . (.Hewlett-Packard Company - Pas de description.) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
O4 - HKUS\S-1-5-21-1645801248-2251260275-3349309149-1000\..\Run: [BIBLauncher] . (.Pas de propriétaire - Business-in-a-Box Launcher Application.) -- C:\Program Files (x86)\Business-in-a-Box\BIBLauncher.exe
O4 - HKUS\S-1-5-21-1645801248-2251260275-3349309149-1000\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKUS\S-1-5-21-1645801248-2251260275-3349309149-1000\..\Run: [GarminExpressTrayApp] . (.Garmin Ltd or its subsidiaries - Express Tray.) -- C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
O4 - HKUS\S-1-5-21-1645801248-2251260275-3349309149-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
~ Application: Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 [64Bits] - {25510184-5A38-4A99-B273-DCA8EEF6CD08} . (...) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\Resources\Icons\HP.ico
O9 - Extra button: Skype Click to Call [64Bits] - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- c:\program files (x86)\skype\toolbars\internet explorer x64\icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{A97172C0-8973-4519-84C5-6D888EBACB41}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\..\{D7010167-2688-4C8C-804C-B14ACA2757D7}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{A97172C0-8973-4519-84C5-6D888EBACB41}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CS1\Services\Tcpip\..\{D7010167-2688-4C8C-804C-B14ACA2757D7}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{A97172C0-8973-4519-84C5-6D888EBACB41}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CS2\Services\Tcpip\..\{D7010167-2688-4C8C-804C-B14ACA2757D7}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [{08977A61-4CDD-4D89-AC9C-45B201E0D662}] (...) -- C:\Program Files (x86)\Fusion 2006\Fusion.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{43AC2235-1540-47B7-BCAE-9AB31E69F556}] (...) -- C:\Program Files (x86)\Simple Comptable Pro 2010\SimplyAccounting.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{5098C0B6-01C1-40CB-AC4E-6B4BF12D728B}] (...) -- C:\Users\admin\Downloads\Babylon10_setup(1).exe (.not file.) [0] =>PUP.Babylon
[MD5.00000000000000000000000000000000] [APT] [{74CF03E9-D6BC-4716-AB3F-6C7DD371182E}] (...) -- C:\Users\admin\AppData\Local\Temp\Temp1_okcustommap_1_0_7.zip\setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{E6B3E15B-6FB1-430B-9D38-B9140144108D}] (...) -- C:\Program Files (x86)\TELUQ\TRA 4010\TRA4010.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{EFEB3A9A-0412-4631-A1D2-4B8B8595E41A}] (...) -- C:\Program Files (x86)\TELUQ\TRA 4010\TRA4010.exe (.not file.) [0]
~ Scheduled Task: 27 Legitimates Filtered in 00mn 04s



---\\ Logiciels installés (O42)
O42 - Logiciel: LogiTerm Pro - (.Terminotix Inc..) [HKLM][64Bits] -- LogiTerm_is1
O42 - Logiciel: OkCustomMap - (.GianPaoloSaliola.) [HKLM][64Bits] -- {D22B8479-B41F-461A-93AF-2515C79E3898}
O42 - Logiciel: Talk to Me - (...) [HKLM][64Bits] -- TTM70
O42 - Logiciel: TaxTron T2 2013.1 Netfile - (.TaxTron.) [HKLM][64Bits] -- TaxTron T2 2013.1 Netfile
O42 - Logiciel: TaxTron T2 2013.1 Netfile - (.TaxTron.) [HKLM][64Bits] -- {E475B5D0-AF6A-44F0-93C5-BFBFF1153BAF}
~ Logic: 38 Legitimates Filtered in 00mn 01s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\INaLF]
[HKCU\Software\IncrediMail]
[HKCU\Software\LICEF]
[HKCU\Software\MultiCorpora]
[HKCU\Software\PerfectIt]
[HKCU\Software\Terminotix]
[HKCU\Software\eMusic]
[HKLM\Software\Wow6432Node\Fusion]
[HKLM\Software\Wow6432Node\Kilgray]
[HKLM\Software\Wow6432Node\Licef]
[HKLM\Software\Wow6432Node\MultiCorpora]
[HKLM\Software\Wow6432Node\PCTools]
[HKLM\Software\Wow6432Node\TaxTron]
~ Key Software: 432 Legitimates Filtered in 00mn 01s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 2013-01-15 - 11:59:45 - [606,520] ----D C:\Program Files (x86)\DT Max
O43 - CFD: 2011-03-31 - 21:29:21 - [0,419] ----D C:\Program Files (x86)\Fusion 2006
O43 - CFD: 2012-01-25 - 19:08:51 - [0,097] ----D C:\Program Files (x86)\Fusion Translate
O43 - CFD: 2011-03-09 - 20:34:35 - [0,117] ----D C:\Program Files (x86)\Kilgray
O43 - CFD: 2010-11-03 - 12:05:24 - [1496,581] ----D C:\Program Files (x86)\Longman
O43 - CFD: 2011-03-04 - 15:58:00 - [0,239] ----D C:\Program Files (x86)\MultiCorpora
O43 - CFD: 2011-05-13 - 09:56:42 - [8,531] ----D C:\Program Files (x86)\OkCustomMap
O43 - CFD: 2013-12-10 - 13:19:24 - [71,700] ----D C:\Program Files (x86)\TaxTron
O43 - CFD: 2011-03-06 - 19:42:32 - [0] ----D C:\Program Files (x86)\TELUQ
O43 - CFD: 2012-05-25 - 12:18:24 - [177,525] ----D C:\Program Files (x86)\Terminotix
O43 - CFD: 2012-04-20 - 07:50:36 - [0,004] ----D C:\Program Files (x86)\UFile 2009
O43 - CFD: 2011-03-13 - 19:26:39 - [0,003] ----D C:\ProgramData\clp
O43 - CFD: 2010-08-03 - 11:27:45 - [0] ----D C:\ProgramData\IM
O43 - CFD: 2010-08-03 - 11:26:53 - [0,009] ----D C:\ProgramData\IncrediMail
O43 - CFD: 2012-01-25 - 19:09:46 - [19,903] ----D C:\ProgramData\MemoQ
O43 - CFD: 2011-03-07 - 11:55:38 - [0] ----D C:\ProgramData\Passolo 2009
O43 - CFD: 2011-03-14 - 12:11:21 - [67,565] ----D C:\ProgramData\STOPzilla!
O43 - CFD: 2013-12-10 - 13:19:37 - [0,011] ----D C:\ProgramData\TaxTron
O43 - CFD: 2013-12-10 - 13:19:28 - [90,352] --H-D C:\ProgramData\{646DA196-DEF8-4597-98F7-FA9D8A51811F}
O43 - CFD: 2013-12-15 - 16:08:24 - [0,023] ----D C:\Users\admin\AppData\Roaming\.oit
O43 - CFD: 2011-03-26 - 18:43:23 - [0] ----D C:\Users\admin\AppData\Roaming\eMusic
O43 - CFD: 2010-11-03 - 12:11:01 - [0,033] ----D C:\Users\admin\AppData\Roaming\ldoce5
O43 - CFD: 2011-08-10 - 08:54:12 - [0,792] ----D C:\Users\admin\AppData\Roaming\MemoQ
O43 - CFD: 2011-03-09 - 19:34:42 - [0,369] ----D C:\Users\admin\AppData\Roaming\Passolo 2009
O43 - CFD: 2012-05-25 - 12:19:05 - [234,756] ----D C:\Users\admin\AppData\Roaming\Terminotix
O43 - CFD: 2010-06-11 - 20:12:40 - [1,024] ----D C:\Users\admin\AppData\Local\DT Max
O43 - CFD: 2011-03-25 - 12:23:04 - [2,189] ----D C:\Users\admin\AppData\Local\eMusic
O43 - CFD: 2010-08-03 - 11:28:02 - [10,791] ----D C:\Users\admin\AppData\Local\IM
O43 - CFD: 2010-11-03 - 12:11:00 - [0,054] ----D C:\Users\admin\AppData\Local\ldoce5
O43 - CFD: 2012-09-12 - 11:22:22 - [0,104] ----D C:\Users\admin\AppData\Local\PerfectIt2
O43 - CFD: 2013-02-23 - 21:00:04 - [0,002] ----D C:\Users\admin\AppData\Local\Terminotix
O43 - CFD: 2010-11-03 - 12:10:26 - [0] ----D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Longman
O43 - CFD: 2013-08-27 - 10:52:29 - [0,006] ----D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PerfectIt 2
~ 1467 Dossiers CLSID vides (CLSID Empty Folders)
~ Program Folder: 1810 Legitimates Filtered in 01mn 07s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.D3FA32D155D266290E9FD91E27994C98] - 2013-12-16 - 13:17:09 ---A- . (...) -- C:\Windows\wininit.ini [1123]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 2013-12-16 - 16:13:54 ---A- . (...) -- C:\autoexec.bat [0]
~ Files: 46 Legitimates Filtered in 00mn 03s



---\\ Clé de registre Shell MountPoints2 (MPKS) (O51)
O51 - MPSK:{47e99516-8e0e-11e1-a272-00a0c6000000}\AutoRun\command. (...) -- F:\AutoLaunch.exe (.not file.)
O51 - MPSK:{a265b7e3-728b-11df-9d24-00262db1ac9c}\AutoRun\command. (...) -- F:\AutoLaunch.exe (.not file.)
~ Keys: Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 4 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 2009-07-13 - 20:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
O58 - SDL:[MD5.F572B7467B5CB4FA8FB6319575902E41] - 2011-05-24 - 13:29:38 ---A- . (.Huawei Tech. Co., Ltd. - HUAWEI USB Smart Card Driver.) -- C:\Windows\System32\Drivers\ewdcsc.sys [32768]
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 2009-06-10 - 15:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
O58 - SDL:[MD5.15E399875C850B54FC253A2323AD8021] - 2011-05-24 - 13:29:38 ---A- . (.DiBcom SA - DiBcom AVSTREAM BDA driver.) -- C:\Windows\System32\Drivers\mod7700.sys [1001472]
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 2009-07-13 - 20:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
O58 - SDL:[MD5.C9E9D59C0099A9FF51697E9306A44240] - 2012-12-13 - 12:50:36 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\Drivers\usbaapl64.sys [54784]
~ Drivers: 16 Legitimates Filtered in 00mn 03s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
O63 - Logiciel: ZHPFix 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPFix_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.exe> <exefile>[HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 12 Legitimates Filtered in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {4A50834F-5959-4983-9633-901AC6B83F76} - (Oople Customized Web Search) - http://search.conduit.com
O69 - SBI: SearchScopes [HKCU] {ECB2C06F-2797-4692-B09A-EA011B18DC13} - (AVG Secure Search) - http://search.avg.com =>Toolbar.AVGSearch
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.0F6E0C96326CC0906BBCDC79F5E95F37] [SPRF][2013-12-11] (...) -- C:\Users\admin\AppData\Local\Temp\109.51631724950455_Update.exe [108544]
[MD5.DA1F52F275BB5881FBBF7792DB713A34] [SPRF][2011-10-18] (.Ask.com - AskStub Application.) -- C:\Users\admin\AppData\Local\Temp\ApnStub.exe [357032]
[MD5.3B32CAA07D672F8A2E0DF5CB3A873F45] [SPRF][2012-06-22] (...) -- C:\Users\admin\AppData\Local\Temp\ESGScanner.sys [22704]
[MD5.3C74C26999F2060BC6302448F173A342] [SPRF][2013-08-28] (.Babylon Ltd. - Uninstaller Application.) -- C:\Users\admin\AppData\Local\Temp\GUninstaller.exe [340464] =>PUP.Babylon
[MD5.24F6D923EF6956ABD0449C879F36D7C7] [SPRF][2013-05-17] (...) -- C:\Users\admin\AppData\Local\Temp\i4jdel0.exe [27411]
[MD5.9649444D04BB6E48CC693CBF98C9264C] [SPRF][2013-11-29] (...) -- C:\Users\admin\AppData\Local\Temp\ICReinstall_PDFWriterSetup.exe [1311304]
[MD5.FBC207AD85D053D4FD9DD93C595D1A1D] [SPRF][2013-12-17] (.Pas de propriétaire - HOSTS Anti-PUPs/Adwares.) -- C:\Users\admin\AppData\Local\Temp\Install_HOSTS_Anti-Adware.exe [285455]
[MD5.0DEBBD09E6C3CA6AF253BEBE3B73AC3E] [SPRF][2012-07-22] (.Pas de propriétaire - MachineIdCreator Application.) -- C:\Users\admin\AppData\Local\Temp\MachineIdCreator.exe [162144]
[MD5.A7EA8C18B021E5AA041EB35D0BAD3145] [SPRF][2013-12-16] (...) -- C:\Users\admin\AppData\Local\Temp\SHSetup.exe [46777424] =>Crapware.SpyHunter
[MD5.73406FA9287B36CA4163797C73A2CD04] [SPRF][2012-07-16] (.Conduit Ltd. - Conduit Toolbar.) -- C:\Users\admin\AppData\Local\Temp\tbedrs.dll [4451144] =>Toolbar.Conduit
[MD5.73406FA9287B36CA4163797C73A2CD04] [SPRF][2012-07-16] (.Conduit Ltd. - Conduit Toolbar.) -- C:\Users\admin\AppData\Local\Temp\tbFree.dll [4451144] =>Toolbar.Conduit
[MD5.73406FA9287B36CA4163797C73A2CD04] [SPRF][2012-07-16] (.Conduit Ltd. - Conduit Toolbar.) -- C:\Users\admin\AppData\Local\Temp\tbProd.dll [4451144] =>Toolbar.Conduit
[MD5.93546758BF74E0B8F0A705A2F5B7DE8C] [SPRF][2013-01-03] (...) -- C:\Users\admin\AppData\Local\Temp\temp.bat [444]
[MD5.3C74C26999F2060BC6302448F173A342] [SPRF][2013-08-28] (.Babylon Ltd. - Uninstaller Application.) -- C:\Users\admin\AppData\Local\Temp\uninst1.exe [340464] =>PUP.Babylon
[MD5.859D633B66FC22E0FBF4A8C875784657] [SPRF][2011-09-21] (...) -- C:\Users\admin\AppData\Local\Temp\wbxtrc1.dat [230546]
[MD5.8636666B0EFD78714E1AF98AB28C9F02] [SPRF][2011-09-28] (...) -- C:\Users\admin\AppData\Local\Temp\wbxtrc2.dat [230546]
[MD5.2B64D6F6C4C476D8D5A4B8139880A4BD] [SPRF][2011-09-28] (...) -- C:\Users\admin\AppData\Local\Temp\wbxtrc3.dat [230546]
[MD5.D41D8CD98F00B204E9800998ECF8427E] [SPRF][2011-11-18] (...) -- C:\Users\admin\AppData\Local\Temp\{B04BE791-42E2-470E-B22E-714C11F883DC}-chrome_updater.exe [0]
[MD5.D41D8CD98F00B204E9800998ECF8427E] [SPRF][2011-05-10] (...) -- C:\Users\admin\AppData\LocalLow\prvlcl.dat [0]
[MD5.D41D8CD98F00B204E9800998ECF8427E] [SPRF][2011-05-09] (...) -- C:\Users\admin\AppData\Roaming\wklnhst.dat [0]
[MD5.1C1CFE7C5D61AFF134CC7D1A4A9117DB] [SPRF][2000-06-14] (.Pas de propriétaire - IESP Module.) -- C:\Windows\Downloaded Program Files\SpeechPlugin.dll [77824]
~ Files: 53 Legitimates Filtered in 00mn 12s



---\\ Liste des exceptions du parefeu (FirewallRules) (O87)
O87 - FAEL: "{C2386ADA-15D2-4AA5-AC4C-CF00D3B96D94}" |In - Private - P6 - FALSE | .(...) -- C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe (.not file.)
O87 - FAEL: "{0187EF16-8B6B-4020-8BF5-6FAF8375ADF6}" |In - Private - P17 - FALSE | .(...) -- C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe (.not file.)
O87 - FAEL: "{894AFAEA-920A-47A5-B25E-BE52499BFD16}" |In - Private - P6 - FALSE | .(...) -- C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe (.not file.)
O87 - FAEL: "{4B9B07F2-1DDC-48D8-8ABB-8DAFDD84D31C}" |In - Private - P17 - FALSE | .(...) -- C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe (.not file.)
O87 - FAEL: "{6CEF0090-C3A4-4C5D-B042-EB9E188263D5}" |In - Private - P6 - FALSE | .(...) -- C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe (.not file.)
O87 - FAEL: "{4D56A540-E1D0-4586-A4A4-A25F88BAA471}" |In - Private - P17 - FALSE | .(...) -- C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe (.not file.)
O87 - FAEL: "TCP Query User{8E14E43C-CA9D-4F9B-833E-DCB53B9A8753}C:\program files (x86)\terminotix\logiterm\server\engine\logiterm.exe" | In - Public - P6 - TRUE | .(.Terminotix - LogiTerm Data Engine.) -- C:\program files (x86)\terminotix\logiterm\server\engine\logiterm.exe
O87 - FAEL: "UDP Query User{0C49103A-B208-4476-953A-8D33996EEEF1}C:\program files (x86)\terminotix\logiterm\server\engine\logiterm.exe" | In - Public - P17 - TRUE | .(.Terminotix - LogiTerm Data Engine.) -- C:\program files (x86)\terminotix\logiterm\server\engine\logiterm.exe
O87 - FAEL: "{5BC986CF-3CAC-44DA-90AD-65E9F4962CB6}" | In - Private - P6 - FALSE | .(.Terminotix - LogiTerm Data Engine.) -- C:\Program Files (x86)\Terminotix\LogiTerm\server\engine\LogiTerm.exe
O87 - FAEL: "{4A86C81E-CD51-4B09-9411-B0A4E3CA503E}" | In - Private - P17 - FALSE | .(.Terminotix - LogiTerm Data Engine.) -- C:\Program Files (x86)\Terminotix\LogiTerm\server\engine\LogiTerm.exe
~ Firewall: 269 Legitimates Filtered in 00mn 01s



---\\ Enumère les codes produits des logiciels (PUC) (O90)
O90 - PUC: "19F46A15F6BB72D4B90DADF88072E7F7" . (.DT Max - System.) -- C:\Windows\Installer\{51A64F91-BB6F-4D27-9BD0-DA8F08277E7F}\ARPPRODUCTICON.exe
~ Update Products: 167 Legitimates Filtered in 00mn 00s



---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.84DCBA56AA175405FD1B57A4200AB504] [WIS][2013-12-10] (.TaxTron - TaxTron T2 2013.1 Netfile Installation.) -- C:\Windows\Installer\1575b.msi [397312]
[MD5.C1CF2F238023ABC668B2A5AC48E44DA6] [WIS][2013-03-19] (.pdfforge - PDF Architect Installer.) -- C:\Windows\Installer\1b2db3f.msi [49815552]
[MD5.49E5129ED6EDDE4CD2B0B8FBB3BCAA17] [WIS][2010-01-08] (.Novate Wireless - Microsoft Windows VC8.0 Support Files.) -- C:\Windows\Installer\2d283.msi [3094016]
[MD5.C8AAFE7F1CBDC313BC029D37C5CB9BDD] [WIS][2011-05-13] (.GianPaoloSaliola - Garmin Custom Maps.) -- C:\Windows\Installer\7d8cf8.msi [4123136]
~ WIS: 180 Legitimates Filtered in 00mn 57s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 2013-06-06 36144 | ( Sage 50 Gestionnaire de transactions 2013 - CDN) . (.Sage.) - C:\Program Files (x86)\Winsim\TransactionManager2013 - CDN\Sage_SA.TransactionManager.exe
SS - | Demand 2013-12-14 257416 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 2011-03-04 651720 | (FLEXnet Licensing Service) . (.Macrovision Europe Ltd..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Auto 2010-08-04 136176 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 2010-08-04 136176 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Auto 2013-12-17 285795 | (HOSTS Anti-PUPs) . (...) - C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe
SS - | Demand 2013-09-06 288776 | (McComponentHostService) . (.McAfee, Inc..) - C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe
SS - | Demand 2013-11-18 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 2013-06-06 36144 | (Sage 50 Gestionnaire de transactions 2013 - CDN) . (.Sage.) - C:\Program Files (x86)\Winsim\TransactionManager2013 - CDN\Sage_SA.TransactionManager.exe
SS - | Demand 2013-09-09 36144 | (Sage 50 Gestionnaire de transactions 2014 - CDN) . (.Sage.) - C:\Program Files (x86)\Winsim\TransactionManager2014 - CDN\Sage_SA.TransactionManager.exe
SS - | Auto 2013-01-08 161536 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SS - | Demand 2011-03-01 2301816 | (TeamViewer6) . (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
SS - | Demand 2009-07-13 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

SR - | Auto 2013-05-10 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 2012-12-21 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 2011-08-30 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Demand 2010-01-12 227896 | (Com4QLBEx) . (.Hewlett-Packard Development Company, L.P..) - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
SR - | Auto 2013-08-22 220504 | (Garmin Core Update Service) . (.Garmin Ltd or its subsidiaries.) - C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
SR - | Auto 2013-08-14 24368 | (Gestionnaire de connexion de Simple Comptable) . (.Sage.) - C:\Program Files (x86)\Winsim\ConnectionManager\SimplyConnectionManager.exe
SR - | Auto 2012-09-27 86528 | (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe =>.Hewlett-Packard Co
SR - | Auto 2012-08-10 197536 | (HPDrvMntSvc.exe) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
SR - | Demand 2012-08-10 1001376 | (hpqwmiex) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
SR - | Auto 2009-07-13 27136 | C:\Windows\SysWOW64\XAudio64.dll (HsfXAudioService) . (.Conexant Systems, Inc..) - C:\Windows\System32\svchost.exe
SR - | Demand 2013-02-20 641352 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 2009-08-20 73728 | (LightScribeService) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
SR - | Auto 2013-04-04 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
SR - | Auto 2013-04-04 701512 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
SR - | Auto 2013-10-23 23808 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 2013-01-09 1324104 | (PDF Architect Helper Service) . (.pdfforge GbR.) - C:\Program Files (x86)\PDF Architect\HelperService.exe
SR - | Auto 2013-01-09 795208 | (PDF Architect Service) . (.pdfforge GbR.) - C:\Program Files (x86)\PDF Architect\ConversionService.exe
SR - | Auto 2009-07-06 247152 | (RichVideo) . (...) - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
SR - | Auto 2012-10-02 3064000 | (Skype C2C Service) . (.Skype Technologies S.A..) - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
SR - | Auto 1658-07-10 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
SR - | Auto 2009-07-13 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

~ Services: Scanned in 00mn 58s



---\\ Scan Additionnel (O88)
Database Version : 13013 - (2013-12-14)
Clés trouvées (Keys found) : 6
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 11

[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9] =>PUP.Dealio
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24] =>PUP.Dealio
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607] =>PUP.Dealio
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F] =>PUP.Dealio
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21] =>PUP.Dealio
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF] =>PUP.Dealio
C:\Users\admin\AppData\Local\Temp\GUninstaller.exe =>PUP.Babylon^
C:\Users\admin\AppData\Local\Temp\SHSetup.exe =>Crapware.SpyHunter^
C:\Users\admin\AppData\Local\Temp\tbedrs.dll =>Toolbar.Conduit^
C:\Users\admin\AppData\Local\Temp\tbFree.dll =>Toolbar.Conduit^
C:\Users\admin\AppData\Local\Temp\tbProd.dll =>Toolbar.Conduit^
C:\Users\admin\AppData\Local\Temp\uninst1.exe =>PUP.Babylon^
C:\Users\admin\AppData\Local\Temp\GoogleToolbarInstaller1.log =>PUP.Babylon
~ Additionnel Scan: 538313 Items scanned in 01mn 38s



---\\ Récapitulatif des détections trouvées sur votre station
~ http://nicolascoolman.webs.com/apps/blog/show/26627369-toolbar-babylon =>PUP.Babylon
~ http://nicolascoolman.webs.com/apps/blog/show/26609241-crapware-spyhunter =>Crapware.SpyHunter
~ http://nicolascoolman.webs.com/apps/blog/show/29507721-toolbar-conduit =>Toolbar.Conduit
~ http://nicolascoolman.webs.com/apps/blog/show/27443462-pup-dealio =>PUP.Dealio
~ MSI: 4 link(s) detected in 01mn 38s



~ 3067 Legitimates filtered by white list
End of the scan (609 lines in 05mn 10s)(0)



2 réponses

Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 656
17 déc. 2013 à 23:43
1
J'avais déjà fait cette étape.
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 656
19 déc. 2013 à 10:20
alors c'est good.
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 656
Modifié par Malekal_morte- le 17/12/2013 à 18:11
Salut,

Faut supprimer l'extension OOPle sur Google Chrome.


Sur Google Chrome : Menu en haut à droite puis Outils / Extensions

Like the angel you are, you laugh creating a lightness in my chest,
Your eyes they penetrate me,
(Your answer's always 'maybe')
That's when I got up and left
0
Comment je vais?
0
Comment faire?
0
Merci ;-)

Y-a-t-il d'autres failles que je devrais corriger selon mon rapport ZHP?
0