Supprimer Iminent

Fermé
drea07 - 8 mai 2015 à 10:40
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 - 12 mai 2015 à 20:24
Bonjour,

j'ai fait un scan avec Mbam et supprimé HKLM imminent A. J'ai vu qu'une personne avais eu le même problème et donc suivi vos prescriptions avec un scan avec adwcleaner. Voici le rapport. Quels éléments dois-je supprimer ? tout ?

Dernièrement j'ai des élévations de la température du CPU anormale. pendant le scan Mbam les CPU ont monté vers les 90° d'après Coretemp. Est ce que ça peut venir de ce virus ?

Merci d'avance

# AdwCleaner v4.203 - Rapport créé le 08/05/2015 à 10:29:07
# Mis à jour le 30/04/2015 par Xplode
# Base de données : 2015-05-05.1 [Serveur]
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (x86)
# Nom d'utilisateur : Amaury - AMAURY-PC
# Exécuté depuis : C:\Users\Amaury\Downloads\adwcleaner_4.203.exe
# Option : Scanner
          • [ Services ] *****
          • [ Fichiers / Dossiers ] *****


Dossier Trouvé : C:\Program Files\sweetpacks bundle uninstaller
Dossier Trouvé : C:\Users\Amaury\AppData\Roaming\YourFileDownloader
Fichier Trouvé : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
          • [ Tâches planifiées ] *****
          • [ Raccourcis ] *****
          • [ Registre ] *****


Clé Trouvée : HKCU\Software\Conduit
Clé Trouvée : HKCU\Software\Softonic
Clé Trouvée : HKCU\Software\YourFileDownloader
Clé Trouvée : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Clé Trouvée : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Clé Trouvée : HKLM\SOFTWARE\Classes\FTDownloader
Clé Trouvée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Clé Trouvée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Clé Trouvée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
Clé Trouvée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
Clé Trouvée : HKLM\SOFTWARE\YourFileDownloader
Donnée Trouvée : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
          • [ Navigateurs ] *****


-\\ Internet Explorer v11.0.9600.17728


-\\ Mozilla Firefox v37.0.2 (x86 fr)


-\\ Google Chrome v


AdwCleaner[R0].txt - [1857 octets] - [08/05/2015 10:29:07]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1917 octets] ##########
A voir également:

36 réponses

lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 804
8 mai 2015 à 11:09
Oui tu peux supprimer
0
Le rapport après redémarrage. Le pc montre toujours des signes de chauffe, en particulier quand je suis sous Mozilla j'ai l'impression.

La suite de la procédure c'est un ZHPdiag ? Pouvez-vous me renvoyer le lien ?

# AdwCleaner v4.203 - Rapport créé le 08/05/2015 à 10:45:05
# Mis à jour le 30/04/2015 par Xplode
# Base de données : 2015-05-05.1 [Serveur]
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (x86)
# Nom d'utilisateur : Amaury - AMAURY-PC
# Exécuté depuis : C:\Users\Amaury\Downloads\adwcleaner_4.203.exe
# Option : Nettoyer
          • [ Services ] *****
          • [ Fichiers / Dossiers ] *****


Dossier Supprimé : C:\Program Files\sweetpacks bundle uninstaller
Dossier Supprimé : C:\Users\Amaury\AppData\Roaming\YourFileDownloader
Fichier Supprimé : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
          • [ Tâches planifiées ] *****
          • [ Raccourcis ] *****
          • [ Registre ] *****


Clé Supprimée : HKLM\SOFTWARE\Classes\FTDownloader
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Clé Supprimée : HKCU\Software\Conduit
Clé Supprimée : HKCU\Software\Softonic
Clé Supprimée : HKCU\Software\YourFileDownloader
Clé Supprimée : HKLM\SOFTWARE\YourFileDownloader
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Donnée Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
          • [ Navigateurs ] *****


-\\ Internet Explorer v11.0.9600.17728


-\\ Mozilla Firefox v37.0.2 (x86 fr)


-\\ Google Chrome v
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 804
8 mai 2015 à 14:26
oui
0
Voici le rapport de ZHP diag

~ Rapport de ZHPDiag v2015.5.8.47 - Nicolas Coolman (05/05/2015)
~ Lancé par Amaury (08/05/2015 16:09:56)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17728
MFIE: Mozilla Firefox 37.0.2 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows Operating System - Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : RMV82
Windows License : OK
~ Windows Remaining Initializations Number : 4
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 7 Home Premium, 32-bit Service Pack 1 (Build 7601)

---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 2.1.6.1022
Microsoft Security Client v4.7.0205.0
Windows Defender W7 (Deactivate)

---\\ Logiciels d'optimisation du système
CCleaner v5.05

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 17 NPAPI
Adobe Reader X

---\\ Informations sur le système
~ Processor: x86 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2998 MB (59% free)
System Restore: Activé (Enable)
System drive C: has 33 GB (11%) free of 287 GB

---\\ Mode de connexion au système
~ Computer Name: AMAURY-PC
~ User Name: Amaury
~ All Users Names: HomeGroupUser$, Amaury, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Amaury\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Amaury\AppData\Roaming\
~ %Desktop% : C:\Users\Amaury\Desktop\
~ %Favorites% : C:\Users\Amaury\Favorites\
~ %LocalAppData% : C:\Users\Amaury\AppData\Local\
~ %StartMenu% : C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 33 Go of 287 Go)
D: CD-ROM drive (Not Inserted)
F: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
~ Security Center: 43 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.C46904F2E9E121A91DDDABB48D7648C3] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.13/03/2015 - 03:20:28.) -- C:\Windows\System32\wininet.dll [1888256]
[MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.17/07/2014 - 02:39:27.) -- C:\Windows\System32\Winlogon.exe [304128]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 13:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:36:07.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 09:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 09:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 10:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 09:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:18:22.) -- C:\Windows\system32\Drivers\ntfs.sys [1212352]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:32:14.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 13:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Generic Processes: Scanned in 00mn 01s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/3
~ Mes musiques (My Musics) : 1/185
~ Mes Favoris (My Favorites) : 1/30
~ Mes Documents (My Documents) : 2/1045
~ Mon Bureau (My Desktop) : 15/103881
~ Menu demarrer (Programs) : 1/30
~ Hidden Files: Scanned in 01mn 51s



---\\ Processus lancés
[MD5.567B0B979E206C3E1E7B4422A2D0A5AD] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1602856] [PID.3756]
[MD5.A9D62C7793510D81342AC1AC50FB70F5] - (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe [495708] [PID.3764]
[MD5.C7AF01132A0DD241A1A0DBE9B62A9A1C] - (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\quickset.exe [3873648] [PID.3772]
[MD5.D50F04F005C94FA3802A6E05CFCF4A9A] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.3824]
[MD5.B7680F36C41AE21C0ECA96523443831F] - (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe [727664] [PID.4060]
[MD5.22001D1308E34153D2BCD51368E14F7B] - (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5249024] [PID.2244]
[MD5.2059A96CB2254829488A6A676AA4BA15] - (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\DpAgent.exe [842816] [PID.2284]
[MD5.0FE0EDF01CEA3BEB2E65A904BB87525E] - (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe [640376] [PID.2336]
[MD5.4476C54D84C792E6B9ECFE4C68BE50D0] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [152392] [PID.2668]
[MD5.9A8568C7642B79F43DCEB0BDF9F49050] - (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe [542136] [PID.3148]
[MD5.9F047EAEC4E5259CFA27A36EE604E9CA] - (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920] [PID.3424]
[MD5.CCA0C5482B8A6A275D9D49433F435DFA] - (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe [542096] [PID.4356]
[MD5.46B9C74861D98EDA9E6E56D19BEAF91A] - (.Broadcom Corporation. - Bluetooth Tray Application.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [795936] [PID.4384]
[MD5.207E54FC226446E2A218EDB400541D80] - (.Pas de propriétaire - CPU temperature and system information util.) -- C:\Users\Amaury\AppData\Local\Temp\Rar$EX00.707\Core Temp.exe [794272] [PID.4608]
[MD5.CFF96E0CE6F81F5968A6D61786642855] - (.Microsoft Corporation - Windows Update.) -- C:\Windows\system32\wuauclt.exe [131584] [PID.3652]
[MD5.7E212E742BF06BF678AE35E9C1B74B8F] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe [6212920] [PID.4764]
[MD5.254EC04C72D02E4C8EEC08D4CF3658B1] - (.PC-Doctor, Inc. - PC-Doctor Module.) -- C:\Program Files\Dell\SupportAssist\uaclauncher.exe [1189200] [PID.6208]
[MD5.2727208EA26F6B6DA898AB6890417214] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8208384] [PID.7680]
~ Processes Running: Scanned in 00mn 05s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Amaury\AppData\Local\Google\Chrome\User Data\Default\Preferences

---\\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 0 Legitimates Filtered in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
~ Firefox Browser: 31 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Adobe PDF - [HKLM]{47833539-D0C5-4125-9FA8-0819E2EAAC93} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{47833539-D0C5-4125-9FA8-0819E2EAAC93} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [QuickSet] . (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [FreeFallProtection] . (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] . (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [DpAgent] . (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] . (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKLM\..\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKCU\..\Run: [AdobeBridge] . (.Adobe Systems, Inc. - Adobe Bridge.) -- C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe =>.Adobe Systems Incorporated
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe =>.DT Soft Ltd
O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKCU\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [AdobeBridge] . (.Adobe Systems, Inc. - Adobe Bridge.) -- C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe =>.Adobe Systems Incorporated
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [DAEMON Tools Lite] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe =>.DT Soft Ltd
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
~ Application: Scanned in 00mn 10s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} . (.Microsoft Corporation - Windows Live Messenger Companion core resources.) -- C:\Program Files\Windows Live\Companion\companionres.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- c:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] *.dell.com
~ IE Zone Confiance: Scanned in 00mn 00s



---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} ((no name)) - http://support.euro.dell.com/systemprofiler/DellSystemLite.CAB
~ Objets ActiveX: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [YourFile Update] (...) -- C:\Program Files\YourFileDownloader\YourFileUpdater.exe (.not file.) [0] =>PUP.YourFileDownloader
O39 - APT: - (..) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1054]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1058]
~ Scheduled Task: 17 Legitimates Filtered in 00mn 05s



---\\ Logiciels installés (O42)
O42 - Logiciel: 7Zip Bundle by Fileparade.com - (.SweetPacks LTD.) [HKLM] -- 7Zip Bundle by Fileparade.com =>PUP.SweetIM
~ Logic: 16 Legitimates Filtered in 00mn 00s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\HKEY_LOCAL_MACHINE]
[HKCU\Software\STUDIO SARMADI]
~ Key Software: 338 Legitimates Filtered in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 18/09/2012 - 08:30:24 - [] ----D C:\Program Files\GUMBB52.tmp
O43 - CFD: 05/05/2015 - 13:48:55 - [] ----D C:\ProgramData\SupportAssistAgent
O43 - CFD: 07/01/2011 - 14:47:42 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DW WLAN
O43 - CFD: 14/07/2009 - 11:00:22 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 05/04/2015 - 11:25:56 - [0] ----D C:\Users\Amaury\AppData\Local\._LiveCode_
O43 - CFD: 19/11/2014 - 21:12:56 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieBrowserModeList
O43 - CFD: 10/12/2011 - 16:51:20 - [0] ----D C:\Users\Amaury\AppData\Local\pcnrqyro
~ Program Folder: 263 Legitimates Filtered in 00mn 01s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.C16DFA9241F3CE8867E7EA8806B8F5DD] - 08/05/2015 - 08:31:05 ---A- . (...) -- C:\Windows\Antidote.ini [143]
~ Files: 12 Legitimates Filtered in 00mn 17s



---\\ Clé de registre Shell MountPoints2 (MPSK) (O51)
O51 - MPSK:{30236676-b194-11e1-8151-f04da2c023f1}\AutoRun\command. (...) -- E:\unlock.exe (.not file.)
O51 - MPSK:{74702b01-b586-11e3-ba34-f04da2c023f1}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)
O51 - MPSK:{d22ae3b2-20ad-11e0-a6a7-f04da2c023f1}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)
~ Keys: Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:03/12/2009 - 07:24:38 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\System32\Drivers\Acceler.sys [41648]
O58 - SDL:29/09/2010 - 17:38:00 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\System32\Drivers\Accelern.sys [43888]
O58 - SDL:23/09/2013 - 13:34:45 ---A- . (.DT Soft Ltd - DAEMON Tools Virtual Bus Driver.) -- C:\Windows\System32\Drivers\dtsoftbus01.sys [242240]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712]
O58 - SDL:13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624]
O58 - SDL:20/08/2010 - 18:04:38 ---A- . (.ST Microelectronics - Disk Class Filter Driver for Accelerometer.) -- C:\Windows\System32\Drivers\stdcfltn.sys [17648]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072]
O58 - SDL:07/04/2010 - 13:35:04 ---A- . (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\Drivers\stwrt.sys [423936]
O58 - SDL:13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672]
~ Drivers: 91 Legitimates Filtered in 00mn 04s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Liste les services legacy du registre (LALS) (O64)
~ Legacy: 116 Legitimates Filtered in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.825768E0D92DAD41A59BF0D16FB76F40] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.1520.bin [4248]
[MD5.946CF417E94D2C9A873D14E6FE0415A1] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2120.bin [70375]
[MD5.6236D6B734152B266EBAB93CF24E5830] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2532.bin [1698]
[MD5.5BC0BA4A5185D7B285B5F8EBE4FCB0FA] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2748.bin [456927]
[MD5.18BC0B6609141E87DE09F4C7DEA97547] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.3716.bin [4259]
[MD5.D9A90DDEBEC281317E31AAEC06FEBD48] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4140.bin [1670]
[MD5.453B258E97C86572BE40C8E28C8CB637] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4464.bin [1260]
[MD5.3F5C7469DC6A45255FA5723B270DFB56] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4664.bin [21151]
[MD5.C6E5D0B9966A3707497421164BAA017C] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4676.bin [70625]
[MD5.5999CF6DDDD5FF5F62A7DA285C5FFF3A] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4696.bin [9108]
[MD5.FAE27419C38CC9DE62F607B0FD4458D6] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.bdinstall.bin [73728]
[MD5.B76FA9566970A7E5255B0717C35B5EC9] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539329.bdinstall.bin [80408]
[MD5.33FE59A381CCF8297F7F8C38FF954D41] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539409.bdinstall.bin [90911]
[MD5.6502D4AE77F9B0EFAED624903C20B22F] [SPRF][03/12/2011] (...) -- C:\Users\Amaury\Desktop\4wz4p2vg.exe [83111856]
~ Files: 14 Legitimates Filtered in 00mn 02s



---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab
~ BCK: 18520 Legitimates Filtered in 00mn 37s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 15/04/2015 268464 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 23/09/2013 1044816 | (FLEXnet Licensing Service) . (.Flexera Software, Inc..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Auto 22/10/2014 107912 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 22/10/2014 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 24/04/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 04/09/2010 1116656 | (RoxMediaDB12OEM) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
SS - | Auto 04/09/2010 219632 | (RoxWatch12) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
SS - | Auto 18/02/2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SS - | Demand 26/08/2010 74392 | (stllssvr) . (.MicroVision Development, Inc..) - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 03/03/2009 81920 | (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 20/10/2009 595232 | (btwdins) . (.Broadcom Corporation..) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
SR - | Auto 26/02/2015 1947344 | (DellDataVault) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
SR - | Auto 26/02/2015 184016 | (DellDataVaultWiz) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
SR - | Auto 13/05/2009 322624 | (DpHost) . (.DigitalPersona, Inc..) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
SR - | Demand 15/05/2013 553288 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 04/11/2009 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 14/04/2015 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
SR - | Auto 14/04/2015 1080120 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
SR - | Auto 30/01/2015 22184 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 13/07/2012 769432 | (NAUpdate) . (.Nero AG.) - C:\Program Files\Nero\Update\NASvc.exe
SR - | Auto 07/04/2010 229458 | (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
SR - | Auto 10/04/2015 19288 | (SupportAssistAgent) . (.Dell Inc..) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
SR - | Auto 04/11/2009 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 03/06/2010 1664304 | (vcsFPService) . (.Validity Sensors, Inc..) - C:\Windows\system32\vcsFPService.exe
SR - | Auto 07/01/2011 40960 | (wltrysvc) . (.Dell Inc..) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 40s



---\\ Scan Additionnel (O88)
Database Version : 13008 - (05/05/2015)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 41

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\7Zip Bundle by Fileparade.com] =>PUP.SweetIM^
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro^
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab^
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar^
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab^
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab^
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo^
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay^
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy^
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo^
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo^
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab^
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab^
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream^
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo^
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo^
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream^
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine^
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab^
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager^
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab^
~ Additionnel Scan: 674478 Items scanned in 01mn 14s



---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
~ AMI: 4 Legitimates Filtered in 00mn 00s



---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/pup-yourfiledownloader =>PUP.YourFileDownloader
http://nicolascoolman.fr/pup-sweetim =>PUP.SweetIM
http://nicolascoolman.fr/pup-optimizerpro =>PUP.OptimizerPro
http://www.nicolascoolman.fr/blog/ =>PUP.Nosibay
http://nicolascoolman.fr/adware-onetab =>Adware.OneTab
http://nicolascoolman.fr/hijacker-findrtoolbar =>Hijacker.FindrToolbar
http://nicolascoolman.fr/hijacker-smartbar =>Hijacker.SmartBar
http://nicolascoolman.fr/pup-eorezo =>PUP.EoRezo
http://nicolascoolman.fr/pup-minibar =>PUP.Minibar
http://nicolascoolman.fr/hijacker-proxy =>Hijacker.Proxy
http://nicolascoolman.fr/adware-metastream =>Adware.MetaStream
http://nicolascoolman.fr/pup-softwareengine =>PUP.SoftwareEngine
http://nicolascoolman.fr/pup-manager =>PUP.Manager
~ MSI: 13 link(s) detected in 00mn 00s



~ 916 Legitimates filtered by white list
End of the scan (559 lines in 05mn 27s)(0.11)
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 804
8 mai 2015 à 16:38
rapport incomplet

fais de la place il te reste 11%
0
Pourquoi incomplet. Je vois le début et le End of the scan à la fin. Apparemment tout a été copié. Je le copie une nouvelle fois en faisant Ctrl A mais normalement ya tout le rapport.

~ Rapport de ZHPDiag v2015.5.8.47 - Nicolas Coolman (05/05/2015)
~ Lancé par Amaury (08/05/2015 16:09:56)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17728
MFIE: Mozilla Firefox 37.0.2 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows Operating System - Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : RMV82
Windows License : OK
~ Windows Remaining Initializations Number : 4
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 7 Home Premium, 32-bit Service Pack 1 (Build 7601)

---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 2.1.6.1022
Microsoft Security Client v4.7.0205.0
Windows Defender W7 (Deactivate)

---\\ Logiciels d'optimisation du système
CCleaner v5.05

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 17 NPAPI
Adobe Reader X

---\\ Informations sur le système
~ Processor: x86 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2998 MB (59% free)
System Restore: Activé (Enable)
System drive C: has 33 GB (11%) free of 287 GB

---\\ Mode de connexion au système
~ Computer Name: AMAURY-PC
~ User Name: Amaury
~ All Users Names: HomeGroupUser$, Amaury, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Amaury\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Amaury\AppData\Roaming\
~ %Desktop% : C:\Users\Amaury\Desktop\
~ %Favorites% : C:\Users\Amaury\Favorites\
~ %LocalAppData% : C:\Users\Amaury\AppData\Local\
~ %StartMenu% : C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 33 Go of 287 Go)
D: CD-ROM drive (Not Inserted)
F: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
~ Security Center: 43 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.C46904F2E9E121A91DDDABB48D7648C3] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.13/03/2015 - 03:20:28.) -- C:\Windows\System32\wininet.dll [1888256]
[MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.17/07/2014 - 02:39:27.) -- C:\Windows\System32\Winlogon.exe [304128]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 13:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:36:07.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 09:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 09:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 10:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 09:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:18:22.) -- C:\Windows\system32\Drivers\ntfs.sys [1212352]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:32:14.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 13:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Generic Processes: Scanned in 00mn 01s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/3
~ Mes musiques (My Musics) : 1/185
~ Mes Favoris (My Favorites) : 1/30
~ Mes Documents (My Documents) : 2/1045
~ Mon Bureau (My Desktop) : 15/103881
~ Menu demarrer (Programs) : 1/30
~ Hidden Files: Scanned in 01mn 51s



---\\ Processus lancés
[MD5.567B0B979E206C3E1E7B4422A2D0A5AD] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1602856] [PID.3756]
[MD5.A9D62C7793510D81342AC1AC50FB70F5] - (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe [495708] [PID.3764]
[MD5.C7AF01132A0DD241A1A0DBE9B62A9A1C] - (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\quickset.exe [3873648] [PID.3772]
[MD5.D50F04F005C94FA3802A6E05CFCF4A9A] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.3824]
[MD5.B7680F36C41AE21C0ECA96523443831F] - (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe [727664] [PID.4060]
[MD5.22001D1308E34153D2BCD51368E14F7B] - (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5249024] [PID.2244]
[MD5.2059A96CB2254829488A6A676AA4BA15] - (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\DpAgent.exe [842816] [PID.2284]
[MD5.0FE0EDF01CEA3BEB2E65A904BB87525E] - (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe [640376] [PID.2336]
[MD5.4476C54D84C792E6B9ECFE4C68BE50D0] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [152392] [PID.2668]
[MD5.9A8568C7642B79F43DCEB0BDF9F49050] - (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe [542136] [PID.3148]
[MD5.9F047EAEC4E5259CFA27A36EE604E9CA] - (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920] [PID.3424]
[MD5.CCA0C5482B8A6A275D9D49433F435DFA] - (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe [542096] [PID.4356]
[MD5.46B9C74861D98EDA9E6E56D19BEAF91A] - (.Broadcom Corporation. - Bluetooth Tray Application.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [795936] [PID.4384]
[MD5.207E54FC226446E2A218EDB400541D80] - (.Pas de propriétaire - CPU temperature and system information util.) -- C:\Users\Amaury\AppData\Local\Temp\Rar$EX00.707\Core Temp.exe [794272] [PID.4608]
[MD5.CFF96E0CE6F81F5968A6D61786642855] - (.Microsoft Corporation - Windows Update.) -- C:\Windows\system32\wuauclt.exe [131584] [PID.3652]
[MD5.7E212E742BF06BF678AE35E9C1B74B8F] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe [6212920] [PID.4764]
[MD5.254EC04C72D02E4C8EEC08D4CF3658B1] - (.PC-Doctor, Inc. - PC-Doctor Module.) -- C:\Program Files\Dell\SupportAssist\uaclauncher.exe [1189200] [PID.6208]
[MD5.2727208EA26F6B6DA898AB6890417214] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8208384] [PID.7680]
~ Processes Running: Scanned in 00mn 05s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Amaury\AppData\Local\Google\Chrome\User Data\Default\Preferences

---\\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 0 Legitimates Filtered in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
~ Firefox Browser: 31 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Adobe PDF - [HKLM]{47833539-D0C5-4125-9FA8-0819E2EAAC93} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{47833539-D0C5-4125-9FA8-0819E2EAAC93} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [QuickSet] . (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [FreeFallProtection] . (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] . (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [DpAgent] . (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] . (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKLM\..\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKCU\..\Run: [AdobeBridge] . (.Adobe Systems, Inc. - Adobe Bridge.) -- C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe =>.Adobe Systems Incorporated
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe =>.DT Soft Ltd
O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKCU\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [AdobeBridge] . (.Adobe Systems, Inc. - Adobe Bridge.) -- C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe =>.Adobe Systems Incorporated
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [DAEMON Tools Lite] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe =>.DT Soft Ltd
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
~ Application: Scanned in 00mn 10s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} . (.Microsoft Corporation - Windows Live Messenger Companion core resources.) -- C:\Program Files\Windows Live\Companion\companionres.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- c:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] *.dell.com
~ IE Zone Confiance: Scanned in 00mn 00s



---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} ((no name)) - http://support.euro.dell.com/systemprofiler/DellSystemLite.CAB
~ Objets ActiveX: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [YourFile Update] (...) -- C:\Program Files\YourFileDownloader\YourFileUpdater.exe (.not file.) [0] =>PUP.YourFileDownloader
O39 - APT: - (..) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1054]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1058]
~ Scheduled Task: 17 Legitimates Filtered in 00mn 05s



---\\ Logiciels installés (O42)
O42 - Logiciel: 7Zip Bundle by Fileparade.com - (.SweetPacks LTD.) [HKLM] -- 7Zip Bundle by Fileparade.com =>PUP.SweetIM
~ Logic: 16 Legitimates Filtered in 00mn 00s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\HKEY_LOCAL_MACHINE]
[HKCU\Software\STUDIO SARMADI]
~ Key Software: 338 Legitimates Filtered in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 18/09/2012 - 08:30:24 - [] ----D C:\Program Files\GUMBB52.tmp
O43 - CFD: 05/05/2015 - 13:48:55 - [] ----D C:\ProgramData\SupportAssistAgent
O43 - CFD: 07/01/2011 - 14:47:42 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DW WLAN
O43 - CFD: 14/07/2009 - 11:00:22 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 05/04/2015 - 11:25:56 - [0] ----D C:\Users\Amaury\AppData\Local\._LiveCode_
O43 - CFD: 19/11/2014 - 21:12:56 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieBrowserModeList
O43 - CFD: 10/12/2011 - 16:51:20 - [0] ----D C:\Users\Amaury\AppData\Local\pcnrqyro
~ Program Folder: 263 Legitimates Filtered in 00mn 01s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.C16DFA9241F3CE8867E7EA8806B8F5DD] - 08/05/2015 - 08:31:05 ---A- . (...) -- C:\Windows\Antidote.ini [143]
~ Files: 12 Legitimates Filtered in 00mn 17s



---\\ Clé de registre Shell MountPoints2 (MPSK) (O51)
O51 - MPSK:{30236676-b194-11e1-8151-f04da2c023f1}\AutoRun\command. (...) -- E:\unlock.exe (.not file.)
O51 - MPSK:{74702b01-b586-11e3-ba34-f04da2c023f1}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)
O51 - MPSK:{d22ae3b2-20ad-11e0-a6a7-f04da2c023f1}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)
~ Keys: Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:03/12/2009 - 07:24:38 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\System32\Drivers\Acceler.sys [41648]
O58 - SDL:29/09/2010 - 17:38:00 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\System32\Drivers\Accelern.sys [43888]
O58 - SDL:23/09/2013 - 13:34:45 ---A- . (.DT Soft Ltd - DAEMON Tools Virtual Bus Driver.) -- C:\Windows\System32\Drivers\dtsoftbus01.sys [242240]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712]
O58 - SDL:13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624]
O58 - SDL:20/08/2010 - 18:04:38 ---A- . (.ST Microelectronics - Disk Class Filter Driver for Accelerometer.) -- C:\Windows\System32\Drivers\stdcfltn.sys [17648]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072]
O58 - SDL:07/04/2010 - 13:35:04 ---A- . (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\Drivers\stwrt.sys [423936]
O58 - SDL:13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672]
~ Drivers: 91 Legitimates Filtered in 00mn 04s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Liste les services legacy du registre (LALS) (O64)
~ Legacy: 116 Legitimates Filtered in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.825768E0D92DAD41A59BF0D16FB76F40] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.1520.bin [4248]
[MD5.946CF417E94D2C9A873D14E6FE0415A1] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2120.bin [70375]
[MD5.6236D6B734152B266EBAB93CF24E5830] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2532.bin [1698]
[MD5.5BC0BA4A5185D7B285B5F8EBE4FCB0FA] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2748.bin [456927]
[MD5.18BC0B6609141E87DE09F4C7DEA97547] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.3716.bin [4259]
[MD5.D9A90DDEBEC281317E31AAEC06FEBD48] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4140.bin [1670]
[MD5.453B258E97C86572BE40C8E28C8CB637] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4464.bin [1260]
[MD5.3F5C7469DC6A45255FA5723B270DFB56] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4664.bin [21151]
[MD5.C6E5D0B9966A3707497421164BAA017C] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4676.bin [70625]
[MD5.5999CF6DDDD5FF5F62A7DA285C5FFF3A] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4696.bin [9108]
[MD5.FAE27419C38CC9DE62F607B0FD4458D6] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.bdinstall.bin [73728]
[MD5.B76FA9566970A7E5255B0717C35B5EC9] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539329.bdinstall.bin [80408]
[MD5.33FE59A381CCF8297F7F8C38FF954D41] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539409.bdinstall.bin [90911]
[MD5.6502D4AE77F9B0EFAED624903C20B22F] [SPRF][03/12/2011] (...) -- C:\Users\Amaury\Desktop\4wz4p2vg.exe [83111856]
~ Files: 14 Legitimates Filtered in 00mn 02s



---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab
~ BCK: 18520 Legitimates Filtered in 00mn 37s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 15/04/2015 268464 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 23/09/2013 1044816 | (FLEXnet Licensing Service) . (.Flexera Software, Inc..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Auto 22/10/2014 107912 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 22/10/2014 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 24/04/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 04/09/2010 1116656 | (RoxMediaDB12OEM) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
SS - | Auto 04/09/2010 219632 | (RoxWatch12) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
SS - | Auto 18/02/2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SS - | Demand 26/08/2010 74392 | (stllssvr) . (.MicroVision Development, Inc..) - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 03/03/2009 81920 | (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 20/10/2009 595232 | (btwdins) . (.Broadcom Corporation..) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
SR - | Auto 26/02/2015 1947344 | (DellDataVault) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
SR - | Auto 26/02/2015 184016 | (DellDataVaultWiz) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
SR - | Auto 13/05/2009 322624 | (DpHost) . (.DigitalPersona, Inc..) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
SR - | Demand 15/05/2013 553288 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 04/11/2009 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 14/04/2015 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
SR - | Auto 14/04/2015 1080120 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
SR - | Auto 30/01/2015 22184 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 13/07/2012 769432 | (NAUpdate) . (.Nero AG.) - C:\Program Files\Nero\Update\NASvc.exe
SR - | Auto 07/04/2010 229458 | (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
SR - | Auto 10/04/2015 19288 | (SupportAssistAgent) . (.Dell Inc..) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
SR - | Auto 04/11/2009 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 03/06/2010 1664304 | (vcsFPService) . (.Validity Sensors, Inc..) - C:\Windows\system32\vcsFPService.exe
SR - | Auto 07/01/2011 40960 | (wltrysvc) . (.Dell Inc..) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 40s



---\\ Scan Additionnel (O88)
Database Version : 13008 - (05/05/2015)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 41

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\7Zip Bundle by Fileparade.com] =>PUP.SweetIM^
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro^
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab^
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar^
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab^
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab^
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo^
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay^
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy^
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo^
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo^
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab^
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab^
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream^
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo^
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo^
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream^
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine^
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab^
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager^
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab^
~ Additionnel Scan: 674478 Items scanned in 01mn 14s



---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
~ AMI: 4 Legitimates Filtered in 00mn 00s



---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/pup-yourfiledownloader =>PUP.YourFileDownloader
http://nicolascoolman.fr/pup-sweetim =>PUP.SweetIM
http://nicolascoolman.fr/pup-optimizerpro =>PUP.OptimizerPro
http://www.nicolascoolman.fr/blog/ =>PUP.Nosibay
http://nicolascoolman.fr/adware-onetab =>Adware.OneTab
http://nicolascoolman.fr/hijacker-findrtoolbar =>Hijacker.FindrToolbar
http://nicolascoolman.fr/hijacker-smartbar =>Hijacker.SmartBar
http://nicolascoolman.fr/pup-eorezo =>PUP.EoRezo
http://nicolascoolman.fr/pup-minibar =>PUP.Minibar
http://nicolascoolman.fr/hijacker-proxy =>Hijacker.Proxy
http://nicolascoolman.fr/adware-metastream =>Adware.MetaStream
http://nicolascoolman.fr/pup-softwareengine =>PUP.SoftwareEngine
http://nicolascoolman.fr/pup-manager =>PUP.Manager
~ MSI: 13 link(s) detected in 00mn 00s



~ 916 Legitimates filtered by white list
End of the scan (559 lines in 05mn 27s)(0.11)
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 804
8 mai 2015 à 17:45
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89

0
Voici le scan tout beau tout chaud.

~ Rapport de ZHPDiag v2015.5.8.47 - Nicolas Coolman (05/05/2015)
~ Lancé par Amaury (08/05/2015 17:55:16)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17728
MFIE: Mozilla Firefox 37.0.2 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows Operating System - Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : RMV82
Windows License : OK
~ Windows Remaining Initializations Number : 4
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 7 Home Premium, 32-bit Service Pack 1 (Build 7601)

---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 2.1.6.1022
Microsoft Security Client v4.7.0205.0
Windows Defender W7 (Deactivate)

---\\ Logiciels d'optimisation du système
CCleaner v5.05

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 17 NPAPI
Adobe Reader X

---\\ Informations sur le système
~ Processor: x86 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2998 MB (47% free)
System Restore: Activé (Enable)
System drive C: has 91 GB (31%) free of 287 GB

---\\ Mode de connexion au système
~ Computer Name: AMAURY-PC
~ User Name: Amaury
~ All Users Names: HomeGroupUser$, Amaury, Administrateur,
~ Unselected Option: None
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Amaury\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Amaury\AppData\Roaming\
~ %Desktop% : C:\Users\Amaury\Desktop\
~ %Favorites% : C:\Users\Amaury\Favorites\
~ %LocalAppData% : C:\Users\Amaury\AppData\Local\
~ %StartMenu% : C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 91 Go of 287 Go)
D: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
~ Security Center: 43 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.C46904F2E9E121A91DDDABB48D7648C3] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.13/03/2015 - 03:20:28.) -- C:\Windows\System32\wininet.dll [1888256]
[MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.17/07/2014 - 02:39:27.) -- C:\Windows\System32\Winlogon.exe [304128]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 13:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:36:07.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 09:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 09:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 10:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 09:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:18:22.) -- C:\Windows\system32\Drivers\ntfs.sys [1212352]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:32:14.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 13:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/3
~ Mes musiques (My Musics) : 1/185
~ Mes Favoris (My Favorites) : 1/30
~ Mes Documents (My Documents) : 2/1045
~ Mon Bureau (My Desktop) : 15/103881
~ Menu demarrer (Programs) : 1/30
~ Hidden Files: Scanned in 01mn 30s



---\\ Processus lancés
[MD5.567B0B979E206C3E1E7B4422A2D0A5AD] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1602856] [PID.3756]
[MD5.A9D62C7793510D81342AC1AC50FB70F5] - (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe [495708] [PID.3764]
[MD5.C7AF01132A0DD241A1A0DBE9B62A9A1C] - (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\quickset.exe [3873648] [PID.3772]
[MD5.D50F04F005C94FA3802A6E05CFCF4A9A] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.3824]
[MD5.B7680F36C41AE21C0ECA96523443831F] - (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe [727664] [PID.4060]
[MD5.22001D1308E34153D2BCD51368E14F7B] - (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5249024] [PID.2244]
[MD5.2059A96CB2254829488A6A676AA4BA15] - (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\DpAgent.exe [842816] [PID.2284]
[MD5.0FE0EDF01CEA3BEB2E65A904BB87525E] - (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe [640376] [PID.2336]
[MD5.4476C54D84C792E6B9ECFE4C68BE50D0] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [152392] [PID.2668]
[MD5.9A8568C7642B79F43DCEB0BDF9F49050] - (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe [542136] [PID.3148]
[MD5.9F047EAEC4E5259CFA27A36EE604E9CA] - (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920] [PID.3424]
[MD5.CCA0C5482B8A6A275D9D49433F435DFA] - (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe [542096] [PID.4356]
[MD5.46B9C74861D98EDA9E6E56D19BEAF91A] - (.Broadcom Corporation. - Bluetooth Tray Application.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [795936] [PID.4384]
[MD5.207E54FC226446E2A218EDB400541D80] - (.Pas de propriétaire - CPU temperature and system information util.) -- C:\Users\Amaury\AppData\Local\Temp\Rar$EX00.707\Core Temp.exe [794272] [PID.4608]
[MD5.CFF96E0CE6F81F5968A6D61786642855] - (.Microsoft Corporation - Windows Update.) -- C:\Windows\system32\wuauclt.exe [131584] [PID.3652]
[MD5.7E212E742BF06BF678AE35E9C1B74B8F] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe [6212920] [PID.4764]
[MD5.2727208EA26F6B6DA898AB6890417214] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8208384] [PID.2924]
~ Processes Running: Scanned in 00mn 01s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Amaury\AppData\Local\Google\Chrome\User Data\Default\Preferences

---\\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 0 Legitimates Filtered in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
~ Firefox Browser: 31 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Adobe PDF - [HKLM]{47833539-D0C5-4125-9FA8-0819E2EAAC93} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{47833539-D0C5-4125-9FA8-0819E2EAAC93} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [QuickSet] . (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [FreeFallProtection] . (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] . (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [DpAgent] . (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] . (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKLM\..\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKCU\..\Run: [AdobeBridge] . (.Adobe Systems, Inc. - Adobe Bridge.) -- C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe =>.Adobe Systems Incorporated
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe
O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKCU\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [AdobeBridge] . (.Adobe Systems, Inc. - Adobe Bridge.) -- C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe =>.Adobe Systems Incorporated
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
~ Application: Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} . (.Microsoft Corporation - Windows Live Messenger Companion core resources.) -- C:\Program Files\Windows Live\Companion\companionres.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- c:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] *.dell.com
~ IE Zone Confiance: Scanned in 00mn 00s



---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} ((no name)) - http://support.euro.dell.com/systemprofiler/DellSystemLite.CAB
~ Objets ActiveX: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [YourFile Update] (...) -- C:\Program Files\YourFileDownloader\YourFileUpdater.exe (.not file.) [0] =>PUP.YourFileDownloader
O39 - APT: - (..) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1054]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1058]
~ Scheduled Task: 17 Legitimates Filtered in 00mn 06s



---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: (dtsoftbus01) . (. - .) - C:\Windows\System32\DRIVERS\dtsoftbus01.sys (.not file.)
~ Drivers: 64 Legitimates Filtered in 00mn 00s



---\\ Logiciels installés (O42)
O42 - Logiciel: 7Zip Bundle by Fileparade.com - (.SweetPacks LTD.) [HKLM] -- 7Zip Bundle by Fileparade.com =>PUP.SweetIM
~ Logic: 16 Legitimates Filtered in 00mn 00s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\HKEY_LOCAL_MACHINE]
[HKCU\Software\STUDIO SARMADI]
~ Key Software: 335 Legitimates Filtered in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 18/09/2012 - 08:30:24 - [] ----D C:\Program Files\GUMBB52.tmp
O43 - CFD: 05/05/2015 - 13:48:55 - [] ----D C:\ProgramData\SupportAssistAgent
O43 - CFD: 07/01/2011 - 14:47:42 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DW WLAN
O43 - CFD: 14/07/2009 - 11:00:22 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 05/04/2015 - 11:25:56 - [0] ----D C:\Users\Amaury\AppData\Local\._LiveCode_
O43 - CFD: 19/11/2014 - 21:12:56 - [] -SH-D C:\Users\Amaury\AppData\Local\EmieBrowserModeList
O43 - CFD: 10/12/2011 - 16:51:20 - [0] ----D C:\Users\Amaury\AppData\Local\pcnrqyro
~ Program Folder: 259 Legitimates Filtered in 00mn 01s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.C16DFA9241F3CE8867E7EA8806B8F5DD] - 08/05/2015 - 08:31:05 ---A- . (...) -- C:\Windows\Antidote.ini [143]
~ Files: 14 Legitimates Filtered in 00mn 02s



---\\ Clé de registre Shell MountPoints2 (MPSK) (O51)
O51 - MPSK:{30236676-b194-11e1-8151-f04da2c023f1}\AutoRun\command. (...) -- E:\unlock.exe (.not file.)
O51 - MPSK:{74702b01-b586-11e3-ba34-f04da2c023f1}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)
O51 - MPSK:{d22ae3b2-20ad-11e0-a6a7-f04da2c023f1}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)
~ Keys: Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:03/12/2009 - 07:24:38 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\System32\Drivers\Acceler.sys [41648]
O58 - SDL:29/09/2010 - 17:38:00 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\System32\Drivers\Accelern.sys [43888]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712]
O58 - SDL:13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624]
O58 - SDL:20/08/2010 - 18:04:38 ---A- . (.ST Microelectronics - Disk Class Filter Driver for Accelerometer.) -- C:\Windows\System32\Drivers\stdcfltn.sys [17648]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072]
O58 - SDL:07/04/2010 - 13:35:04 ---A- . (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\Drivers\stwrt.sys [423936]
O58 - SDL:13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672]
~ Drivers: 90 Legitimates Filtered in 00mn 04s



---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 08/05/2015 - 17:57:52 ---A- . (...) -- C:\Users\Amaury\Downloads\adwcleaner_4.203.exe [2204160]
~ 37 Fichiers temporaires (Temporary files)
~ 5 Fichiers cookies (Cookies files)
~ Files: 16 Legitimates Filtered in 00mn 31s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Liste les services legacy du registre (LALS) (O64)
~ Legacy: 116 Legitimates Filtered in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s



---\\ Enumère les fichiers Crack & Keygen (CKF) (O82)
C:\Users\Amaury\Desktop\Adobe CS4\Master Collection\Adobe CS4\Adobe_Master_Collection_CS4_Keygen_by_Milkman.zip =>.Crack,Keygen
C:\Users\Amaury\Desktop\EndNote X6 Bld 6348\Cracked\EndNote.exe =>.Crack,Keygen
~ Files: Scanned in 00mn 46s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.825768E0D92DAD41A59BF0D16FB76F40] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.1520.bin [4248]
[MD5.946CF417E94D2C9A873D14E6FE0415A1] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2120.bin [70375]
[MD5.6236D6B734152B266EBAB93CF24E5830] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2532.bin [1698]
[MD5.5BC0BA4A5185D7B285B5F8EBE4FCB0FA] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.2748.bin [456927]
[MD5.18BC0B6609141E87DE09F4C7DEA97547] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.3716.bin [4259]
[MD5.D9A90DDEBEC281317E31AAEC06FEBD48] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4140.bin [1670]
[MD5.453B258E97C86572BE40C8E28C8CB637] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4464.bin [1260]
[MD5.3F5C7469DC6A45255FA5723B270DFB56] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4664.bin [21151]
[MD5.C6E5D0B9966A3707497421164BAA017C] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4676.bin [70625]
[MD5.5999CF6DDDD5FF5F62A7DA285C5FFF3A] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.4696.bin [9108]
[MD5.FAE27419C38CC9DE62F607B0FD4458D6] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323535517.bdinstall.bin [73728]
[MD5.B76FA9566970A7E5255B0717C35B5EC9] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539329.bdinstall.bin [80408]
[MD5.33FE59A381CCF8297F7F8C38FF954D41] [SPRF][10/12/2011] (...) -- C:\ProgramData\1323539409.bdinstall.bin [90911]
[MD5.6502D4AE77F9B0EFAED624903C20B22F] [SPRF][03/12/2011] (...) -- C:\Users\Amaury\Desktop\4wz4p2vg.exe [83111856]
~ Files: 14 Legitimates Filtered in 00mn 01s



---\\ Export de clés de registre aléatoires (O91)
[HKLM\Software\14919ea49a8f3b4aa3cf1058d9a64cec]:s="0"
~ Export Key Software: Scanned in 00mn 00s



---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab
~ BCK: 18520 Legitimates Filtered in 00mn 35s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 15/04/2015 268464 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 23/09/2013 1044816 | (FLEXnet Licensing Service) . (.Flexera Software, Inc..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Auto 22/10/2014 107912 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 22/10/2014 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 24/04/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 04/09/2010 1116656 | (RoxMediaDB12OEM) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
SS - | Auto 04/09/2010 219632 | (RoxWatch12) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
SS - | Auto 18/02/2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SS - | Demand 26/08/2010 74392 | (stllssvr) . (.MicroVision Development, Inc..) - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 03/03/2009 81920 | (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 20/10/2009 595232 | (btwdins) . (.Broadcom Corporation..) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
SR - | Auto 26/02/2015 1947344 | (DellDataVault) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
SR - | Auto 26/02/2015 184016 | (DellDataVaultWiz) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
SR - | Auto 13/05/2009 322624 | (DpHost) . (.DigitalPersona, Inc..) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
SR - | Demand 15/05/2013 553288 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 04/11/2009 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 14/04/2015 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
SR - | Auto 14/04/2015 1080120 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
SR - | Auto 30/01/2015 22184 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 13/07/2012 769432 | (NAUpdate) . (.Nero AG.) - C:\Program Files\Nero\Update\NASvc.exe
SR - | Auto 07/04/2010 229458 | (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
SR - | Auto 10/04/2015 19288 | (SupportAssistAgent) . (.Dell Inc..) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
SR - | Auto 04/11/2009 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 03/06/2010 1664304 | (vcsFPService) . (.Validity Sensors, Inc..) - C:\Windows\system32\vcsFPService.exe
SR - | Auto 07/01/2011 40960 | (wltrysvc) . (.Dell Inc..) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 37s



---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
~ MBR: 1 Legitimates Filtered in 00mn 02s



---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by Amaury at 08/05/2015 17:59:42
                  • Dump file Name *********

C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s



---\\ Scan Additionnel (O88)
Database Version : 13008 - (05/05/2015)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 41

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\7Zip Bundle by Fileparade.com] =>PUP.SweetIM^
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro^
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab^
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar^
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab^
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab^
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo^
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay^
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy^
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo^
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo^
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab^
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab^
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream^
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo^
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo^
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream^
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine^
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab^
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager^
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab^
~ Additionnel Scan: 674438 Items scanned in 00mn 29s



---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
~ AMI: 4 Legitimates Filtered in 00mn 00s



---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/pup-yourfiledownloader =>PUP.YourFileDownloader
http://nicolascoolman.fr/pup-sweetim =>PUP.SweetIM
http://nicolascoolman.fr/pup-optimizerpro =>PUP.OptimizerPro
http://www.nicolascoolman.fr/blog/ =>PUP.Nosibay
http://nicolascoolman.fr/adware-onetab =>Adware.OneTab
http://nicolascoolman.fr/hijacker-findrtoolbar =>Hijacker.FindrToolbar
http://nicolascoolman.fr/hijacker-smartbar =>Hijacker.SmartBar
http://nicolascoolman.fr/pup-eorezo =>PUP.EoRezo
http://nicolascoolman.fr/pup-minibar =>PUP.Minibar
http://nicolascoolman.fr/hijacker-proxy =>Hijacker.Proxy
http://nicolascoolman.fr/adware-metastream =>Adware.MetaStream
http://nicolascoolman.fr/pup-softwareengine =>PUP.SoftwareEngine
http://nicolascoolman.fr/pup-manager =>PUP.Manager
~ MSI: 13 link(s) detected in 00mn 00s



~ 928 Legitimates filtered by white list
End of the scan (596 lines in 04mn 56s)(2.11)
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 804
8 mai 2015 à 18:07
Cliques sur "complet" lors du lancement de zhpdiag
0
Voilà

~ Rapport de ZHPDiag v2015.5.8.47 - Nicolas Coolman (05/05/2015)
~ Lancé par Amaury (08/05/2015 19:03:33)
~ Facebook : https://www.facebook.com/nicolascoolman1
~ Adresse du Forum http://forum.nicolascoolman.fr
~ Traduit par Nicolas Coolman
~ Etat de la version : Version à jour.
~ Liste blanche : Désactivée par l'utilisateur
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17728
MFIE: Mozilla Firefox 37.0.2 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows Server License Manager Script : OK
~ Windows Operating System - Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : RMV82
Windows License : OK
~ Windows Remaining Initializations Number : 4
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
Windows 7 Home Premium, 32-bit Service Pack 1 (Build 7601)

---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 2.1.6.1022
Microsoft Security Client v4.7.0205.0
Windows Defender W7 (Deactivate)

---\\ Logiciels d'optimisation du système
CCleaner v5.05

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 17 NPAPI
Adobe Reader X

---\\ Informations sur le système
~ Processor: x86 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2998 MB (36% free)
System Restore: Activé (Enable)
System drive C: has 91 GB (31%) free of 287 GB

---\\ Mode de connexion au système
~ Computer Name: AMAURY-PC
~ User Name: Amaury
~ All Users Names: HomeGroupUser$, Amaury, Administrateur,
~ Unselected Option: None
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Amaury\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Amaury\AppData\Roaming\
~ %Desktop% : C:\Users\Amaury\Desktop\
~ %Favorites% : C:\Users\Amaury\Favorites\
~ %LocalAppData% : C:\Users\Amaury\AppData\Local\
~ %StartMenu% : C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 91 Go of 287 Go)
D: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: 43 Scanned in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.C46904F2E9E121A91DDDABB48D7648C3] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.13/03/2015 - 03:20:28.) -- C:\Windows\System32\wininet.dll [1888256]
[MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.17/07/2014 - 02:39:27.) -- C:\Windows\System32\Winlogon.exe [304128]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 13:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.30/05/2014 - 07:36:07.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 09:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 09:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 10:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 09:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:18:22.) -- C:\Windows\system32\Drivers\ntfs.sys [1212352]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - (.Microsoft Corporation - TDI Translation Driver.) (.11/11/2014 - 02:32:14.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 13:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/3
~ Mes musiques (My Musics) : 1/185
~ Mes Favoris (My Favorites) : 1/30
~ Mes Documents (My Documents) : 2/1045
~ Mon Bureau (My Desktop) : 15/103882
~ Menu demarrer (Programs) : 1/30
~ Hidden Files: Scanned in 03mn 33s



---\\ Processus lancés
[MD5.567B0B979E206C3E1E7B4422A2D0A5AD] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1602856] [PID.3756]
[MD5.A9D62C7793510D81342AC1AC50FB70F5] - (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe [495708] [PID.3764]
[MD5.C7AF01132A0DD241A1A0DBE9B62A9A1C] - (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\quickset.exe [3873648] [PID.3772]
[MD5.D50F04F005C94FA3802A6E05CFCF4A9A] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.3824]
[MD5.B7680F36C41AE21C0ECA96523443831F] - (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe [727664] [PID.4060]
[MD5.22001D1308E34153D2BCD51368E14F7B] - (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5249024] [PID.2244]
[MD5.2059A96CB2254829488A6A676AA4BA15] - (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\DpAgent.exe [842816] [PID.2284]
[MD5.0FE0EDF01CEA3BEB2E65A904BB87525E] - (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe [640376] [PID.2336]
[MD5.4476C54D84C792E6B9ECFE4C68BE50D0] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [152392] [PID.2668]
[MD5.9A8568C7642B79F43DCEB0BDF9F49050] - (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe [542136] [PID.3148]
[MD5.9F047EAEC4E5259CFA27A36EE604E9CA] - (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920] [PID.3424]
[MD5.CCA0C5482B8A6A275D9D49433F435DFA] - (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe [542096] [PID.4356]
[MD5.46B9C74861D98EDA9E6E56D19BEAF91A] - (.Broadcom Corporation. - Bluetooth Tray Application.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [795936] [PID.4384]
[MD5.207E54FC226446E2A218EDB400541D80] - (.Pas de propriétaire - CPU temperature and system information util.) -- C:\Users\Amaury\AppData\Local\Temp\Rar$EX00.707\Core Temp.exe [794272] [PID.4608]
[MD5.CFF96E0CE6F81F5968A6D61786642855] - (.Microsoft Corporation - Windows Update.) -- C:\Windows\system32\wuauclt.exe [131584] [PID.3652]
[MD5.7E212E742BF06BF678AE35E9C1B74B8F] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe [6212920] [PID.4764]
[MD5.C58FDF24BBB5A418D32FF6231566F91C] - (.Microsoft Corporation - Microsoft Office Excel.) -- C:\Program Files\Microsoft Office\Office12\EXCEL.exe [18365096] [PID.4668]
[MD5.5D1BFF0FCE80F9E2E539F436710D4A79] - (.Microsoft Corporation - Preview Handler Surrogate Host.) -- C:\Windows\system32\prevhost.exe [31232] [PID.4288]
[MD5.81AFD3AF381A4B7DB1800CB2CE8F8F6C] - (.Adobe Systems Incorporated - Adobe Acrobat 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AcrobatInfo.exe [14704] [PID.6684]
[MD5.2727208EA26F6B6DA898AB6890417214] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8208384] [PID.5516]
[MD5.1D281C5353D1B12AFB9C4A4AE61E5675] - (.Adobe Systems Incorporated - Adobe Acrobat 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat.exe [353640] [PID.2384]
~ Processes Running: Scanned in 00mn 02s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Amaury\AppData\Local\Google\Chrome\User Data\Default\Preferences

---\\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 0 Scanned in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFF12.DLL
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.4.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay-france.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo-france.xml
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll =>.Google Inc
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=11.31.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Windows\system32\npdeployJava1.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Oracle Corporation - Next Generation Java Plug-in 11.31.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=11.31.2] - (.Oracle Corporation - Next Generation Java Plug-in 11.31.2 for Mozilla browsers.) -- C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.4.) -- C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
~ Firefox Browser: 31 Scanned in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.4.) (No version) -- (.not file.)
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
~ IE Browser: 11 Scanned in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hôte est sain (The hosts file is clean) (21)
~ Hosts File: Scanned in 00mn 00s



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DigitalPersona Fingerprint Software Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} . (.DigitalPersona, Inc. - DigitalPersona OTS Feedback.) -- C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} . (.Microsoft Corporation - Windows Live Messenger Companion Core.) -- C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
~ BHO: 16 Scanned in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Adobe PDF - [HKLM]{47833539-D0C5-4125-9FA8-0819E2EAAC93} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{47833539-D0C5-4125-9FA8-0819E2EAAC93} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Applications lancées au démarrage du système (O4)
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [QuickSet] . (.Dell Inc. - QuickSet.) -- C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [FreeFallProtection] . (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] . (.Dell Inc. - DW WLAN Card Wireless Network Tray Applet.) -- C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [DpAgent] . (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] . (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKLM\..\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKCU\..\Run: [AdobeBridge] . (.Adobe Systems, Inc. - Adobe Bridge.) -- C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe =>.Adobe Systems Incorporated
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe
O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKCU\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [AdobeBridge] . (.Adobe Systems, Inc. - Adobe Bridge.) -- C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe =>.Adobe Systems Incorporated
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Gestionnaire Antidote.exe] . (.Druide informatique inc. - Gestionnaire Antidote.) -- C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Amaury\AppData\Roaming\Spotify\SpotifyWebHelper.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [DellSystemDetect] C:\Users\Amaury\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms (.not file.)
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Adobe Acrobat Synchronizer] . (.Adobe Systems Incorporated - Adobe Collaboration Synchronizer 9.0.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeCollabSync.exe
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKUS\S-1-5-21-1205577285-3594029024-4112892350-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd
~ Application: Scanned in 00mn 00s



---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ IE Control Panel: 1 Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} . (.Microsoft Corporation - Windows Live Messenger Companion core resources.) -- C:\Program Files\Windows Live\Companion\companionres.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- c:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000009\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000010\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll
~ Winsock: 10 Scanned in 00mn 00s



---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains] *.dell.com
~ IE Zone Confiance: Scanned in 00mn 00s



---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} ((no name)) - http://support.euro.dell.com/systemprofiler/DellSystemLite.CAB
~ Objets ActiveX: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{4ADC8BAC-8EFD-47CC-988C-A2B805C48E47}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{6F012F82-3736-41C6-B01B-F4ADAE564A92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ SSODL: 1 Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) . (.Andrea Electronics Corporation - Andrea filters APO access service (32-bit).) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) . (.Broadcom Corporation. - Bluetooth Support Server.) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dell Data Vault (DellDataVault) . (.Dell Inc. - Dell Data Vault Service.) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
O23 - Service: Dell Data Vault Wizard (DellDataVaultWiz) . (.Dell Inc. - Dell Data Vault Wizard.) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
O23 - Service: C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DpHost) . (.DigitalPersona, Inc. - DigitalPersona Local Host.) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: C:\Program Files\Nero\Update\NASvc.exe (NAUpdate) . (.Nero AG - NeroUpdate.) - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) . (.Sonic Solutions - RoxWatch12 Module.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Audio Service (STacSV) . (.IDT, Inc. - IDT PC Audio.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
O23 - Service: Dell SupportAssist Agent (SupportAssistAgent) . (.Dell Inc. - Service.) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
O23 - Service: Intel(R) Management & Security Application User Notificatio (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) . (.Validity Sensors, Inc. - VFS101 VCS API Library.) - C:\Windows\system32\vcsFPService.exe
O23 - Service: DW WLAN Tray Service (wltrysvc) . (.Dell Inc. - DW WLAN Card Wireless Network Service.) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
~ Services: 20 Scanned in 00mn 07s



---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Desktop Component: 4 Scanned in 00mn 00s



---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
[MD5.3E04F1E482357B1FC8B088197C3D9FF8] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152]
[MD5.B04A4810C6CC205F9DC72DC22E4AB236] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [268464]
[MD5.1F014EA12ECB13C909DA9395E9CD3D18] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6278424]
[MD5.2BCB174FF294F83C3520D46B57DBD917] [APT] [Dell SupportAssistAgent AutoUpdate] (.Dell Inc..) -- C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [27472]
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107912]
[MD5.51508F0C2476177E50C31B0BBFBF1BDB] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [107912]
[MD5.79B5DD0E04130BF31AA598F2AEBB1B78] [APT] [PCDEventLauncherTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell\SupportAssist\sessionchecker.exe [433488]
[MD5.254EC04C72D02E4C8EEC08D4CF3658B1] [APT] [PCDoctorBackgroundMonitorTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell\SupportAssist\uaclauncher.exe [1189200]
[MD5.00000000000000000000000000000000] [APT] [YourFile Update] (...) -- C:\Program Files\YourFileDownloader\YourFileUpdater.exe (.not file.) [0] =>PUP.YourFileDownloader
[MD5.A75AE3B84B6423CE6A088E80A2BC23C2] [APT] [{4773655F-F316-4A0B-AAD8-B898B8AF2A0A}] (.Skype Technologies S.A..) -- C:\Program Files\Skype\Phone\Skype.exe [31280256]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{7A7B4145-1139-4669-8765-5936ED3BBC3A}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.345B45BE09381D2011EB7F9AC11D8AC4] [APT] [{A28E5010-28AC-4FF0-9EDF-0210636C319A}] (.Mozilla Corporation.) -- c:\program files\mozilla firefox\firefox.exe [376944]
[MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [561984]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1054]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1054]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1058]
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1058]
~ Scheduled Task: 17 Scanned in 00mn 05s



---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft VM - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Microsoft Corporation - Microsoft® VM.) -- C:\Windows\system32\msjava.dll
O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Disable SSL3 - {7D715857-A67C-4C2F-A929-038448584D63} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
~ Active Setup: 11 Scanned in 00mn 00s



---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys
O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
O41 - Driver: (MpKsl825f7c87) . (.Microsoft Corporation - KSLDriver.) - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{65AB3B06-1A63-4FEA-8E43-904D32629B85}\MpKsl825f7c87.sys
O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys
O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
O41 - Driver: (dtsoftbus01) . (. - .) - C:\Windows\System32\DRIVERS\dtsoftbus01.sys (.not file.)
O41 - Driver: (MpKslb4576870) . (. - .) - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{65AB3B06-1A63-4FEA-8E43-904D32629B85}\MpKslb4576870.sys (.not file.)
~ Drivers: 64 Scanned in 00mn 00s



---\\ Logiciels installés (O42)
O42 - Logiciel: 7-Zip 9.20 - (...) [HKLM] -- 7-Zip
O42 - Logiciel: 7Zip Bundle by Fileparade.com - (.SweetPacks LTD.) [HKLM] -- 7Zip Bundle by Fileparade.com =>PUP.SweetIM
O42 - Logiciel: AccelerometerP11 - (.STMicroelectronics.) [HKLM] -- {87434D51-51DB-4109-B68F-A829ECDCF380}
O42 - Logiciel: Adobe After Effects CS4 Third Party Content - (.Adobe Systems Incorporated.) [HKLM] -- {67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}
O42 - Logiciel: Adobe Anchor Service CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {1618734A-3957-4ADD-8199-F973763109A8}
O42 - Logiciel: Adobe Bridge CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {83877DB1-8B77-45BC-AB43-2BAC22E093E0} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe CMaps CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {94D398EB-D2FD-4FD1-B8C4-592635E8A191}
O42 - Logiciel: Adobe CSI CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0F723FC1-7606-4867-866C-CE80AD292DAF}
O42 - Logiciel: Adobe Color EU Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}
O42 - Logiciel: Adobe Color JA Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0D6013AB-A0C7-41DC-973C-E93129C9A29F}
O42 - Logiciel: Adobe Color NA Recommended Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {00ADFB20-AE75-46F4-AD2C-F48B15AC3100}
O42 - Logiciel: Adobe Color Video Profiles CS CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {63C24A08-70F3-4C8E-B9FB-9F21A903801D}
O42 - Logiciel: Adobe Creative Suite 4 Master Collection - (.Adobe Systems Incorporated.) [HKLM] -- Adobe_b2b1c7c62c4ae0a954789ed71d36a7a
O42 - Logiciel: Adobe Creative Suite 4 Master Collection - (.Adobe Systems Incorporated.) [HKLM] -- {D0EE7809-8F5E-46EF-95DC-B30DCE22653F}
O42 - Logiciel: Adobe Default Language CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {C52E3EC1-048C-45E1-8D53-10B0C6509683}
O42 - Logiciel: Adobe Encore CS4 Codecs - (.Adobe Systems Incorporated.) [HKLM] -- {FB2A5FCC-B81B-48C2-A009-7804694D83E9}
O42 - Logiciel: Adobe ExtendScript Toolkit CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F8EF2B3F-C345-4F20-8FE4-791A20333CD5} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Extension Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {054EFA56-2AC1-48F4-A883-0AB89874B972}
O42 - Logiciel: Adobe Flash Player 17 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 17 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI
O42 - Logiciel: Adobe Fonts All - (.Adobe Systems Incorporated.) [HKLM] -- {FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
O42 - Logiciel: Adobe Illustrator CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05C677A1-A161-447E-92ED-2D5B38AA0740} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {A2160D84-F2D0-47A3-AA59-CCB3CA21D558} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Application Feature Set Files (Roman) - (.Adobe Systems Incorporated.) [HKLM] -- {C950299F-BCAB-4695-B077-FC3B2748C25D} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Common Base Files - (.Adobe Systems Incorporated.) [HKLM] -- {26F72DC3-DDBE-424F-B9F0-94E5D0E5A12B} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe InDesign CS4 Icon Handler - (.Adobe Systems Incorporated.) [HKLM] -- {2BA4F7B0-F38E-4AE8-80A2-E9C5956C6D6D} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Linguistics CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {931AB7EA-3656-4BB7-864D-022B09E3DD67}
O42 - Logiciel: Adobe Media Encoder CS4 Exporter - (.Adobe Systems Incorporated.) [HKLM] -- {561968FD-56A1-49FD-9ED0-F55482C7C5BC}
O42 - Logiciel: Adobe Media Encoder CS4 Importer - (.Adobe Systems Incorporated.) [HKLM] -- {8186FF34-D389-4B7E-9A2F-C197585BCFBD}
O42 - Logiciel: Adobe Output Module - (.Adobe Systems Incorporated.) [HKLM] -- {BB4E33EC-8181-4685-96F7-8554293DEC6A}
O42 - Logiciel: Adobe PDF Library Files CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F93C84A6-0DC6-42AF-89FA-776F7C377353}
O42 - Logiciel: Adobe Photoshop CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {E2E01E91-2314-42BC-B5E3-1715DAE84F98} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Photoshop CS4 Support - (.Adobe Systems Incorporated.) [HKLM] -- {73E17122-EC84-45B4-943B-735257B5CBDC} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Premiere Pro CS4 Third Party Content - (.Adobe Systems Incorporated.) [HKLM] -- {E1951CF4-91CE-46F0-A1BD-3A4A67069097}
O42 - Logiciel: Adobe Reader X (10.1.4) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AA1000000001}
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-0804-1033-1959-001802114130}
O42 - Logiciel: Adobe SGM CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}
O42 - Logiciel: Adobe SING CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {8CB16C77-9D75-4966-91E8-D785B87EC078}
O42 - Logiciel: Adobe Search for Help - (.Adobe Systems Incorporated.) [HKLM] -- {F0E64E2E-3A60-40D8-A55D-92F6831875DA}
O42 - Logiciel: Adobe Service Manager Extension - (.Adobe Systems Incorporated.) [HKLM] -- {4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
O42 - Logiciel: Adobe Setup - (.Adobe Systems Incorporated.) [HKLM] -- {6577657B-A10C-47A1-A50D-512C7748CB2C}
O42 - Logiciel: Adobe Soundbooth CS4 Codecs - (.Adobe Systems Incorporated.) [HKLM] -- {52232EF4-CC12-4C21-ABCF-ADB79618302D}
O42 - Logiciel: Adobe Type Support CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
O42 - Logiciel: Adobe Update Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05308C4E-7285-4066-BAE3-6B50DA6ED755}
O42 - Logiciel: Adobe WinSoft Linguistics Plugin - (.Adobe Systems Incorporated.) [HKLM] -- {3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
O42 - Logiciel: Adobe XMP Panels CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
O42 - Logiciel: AdobeColorCommonSetCMYK - (.Adobe Systems Incorporated.) [HKLM] -- {E5FCED12-3E77-4C0E-A305-5AEB38A52A70}
O42 - Logiciel: AdobeColorCommonSetRGB - (.Adobe Systems Incorporated.) [HKLM] -- {16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
O42 - Logiciel: Advanced Audio FX Engine - (.Creative Technology Ltd.) [HKLM] -- Advanced Audio FX Engine
O42 - Logiciel: Antidote RX v7 - (.Druide informatique inc..) [HKLM] -- {A474EA56-5DBD-4181-8230-806A4762EA7F}
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {5D09C772-ECB3-442B-9CC6-B4341C78FDC2}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {E14ADE0E-75F3-4A46-87E5-26692DD626EC}
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} =>.Apple Inc
O42 - Logiciel: ArcGIS 10.1 for Desktop - (.Environmental Systems Research Institute, Inc..) [HKLM] -- ArcGIS 10.1 for Desktop
O42 - Logiciel: ArcGIS 10.1 for Desktop - Module linguistique français - (.Environmental Systems Research Institute, Inc..) [HKLM] -- ArcGIS 10.1 for Desktop - Module linguistique français
O42 - Logiciel: ArcGIS 10.1 for Desktop - Module linguistique français - (.Environmental Systems Research Institute, Inc..) [HKLM] -- {311DA2E4-3B6A-464F-8987-C4AAE6B9386D}
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {79155F2B-9895-49D7-8612-D92580E0DE5B}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: CDBurnerXP - (.CDBurnerXP.) [HKLM] -- {7E265513-8CDA-4631-B696-F40D983F3B07}_is1
O42 - Logiciel: Canon MG5200 series MP Drivers - (...) [HKLM] -- {1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series
O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM] -- {64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {51C7AD07-C3F6-4635-8E8A-231306D810FE}
O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
O42 - Logiciel: Complément Messenger - (.Microsoft Corporation.) [HKLM] -- {6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}
O42 - Logiciel: Connect - (.Adobe Systems Incorporated.) [HKLM] -- {B29AD377-CC12-490A-A480-1452337C618D}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM] -- InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: CyberLink PowerDVD 9.5 - (.CyberLink Corp..) [HKLM] -- {A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
O42 - Logiciel: DW WLAN Card Utility - (.Dell Inc..) [HKLM] -- DW WLAN Card Utility
O42 - Logiciel: Dell Backup and Recovery Manager - (.Dell Inc..) [HKLM] -- {4688EB75-28E2-4731-9BCB-55E624F7CD45}
O42 - Logiciel: Dell Data Vault - (.Dell Inc..) [HKLM] -- {2E55EEFD-2162-4A7D-9158-EDB0305603A6}
O42 - Logiciel: Dell Edoc Viewer - (.Dell Inc.) [HKLM] -- {3138EAD3-700B-4A10-B617-B3F8096EE30D}
O42 - Logiciel: Dell SupportAssist - (.Dell.) [HKLM] -- PC-Doctor for Windows
O42 - Logiciel: Dell SupportAssistAgent - (.Dell.) [HKLM] -- {287348C8-8B47-4C36-AF28-441A3B7D8722}
O42 - Logiciel: Dell Touchpad - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey
O42 - Logiciel: Dell Webcam Central - (.Creative Technology Ltd.) [HKLM] -- Dell Webcam Central
O42 - Logiciel: DigitalPersona Personal 4.01 - (.DigitalPersona, Inc..) [HKLM] -- {3D8AE086-030F-4EF4-B705-63F8130B043E}
O42 - Logiciel: DirectX 9 Runtime - (.Sonic Solutions.) [HKLM] -- {AF9E97C1-7431-426D-A8D5-ABE40995C0B1}
O42 - Logiciel: EndNote X3 - (.Thomson Reuters.) [HKLM] -- {86B3F2D6-AC2B-4E88-8AE1-F2F77F781B0C}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}
O42 - Logiciel: IRIScan(TM) Direct - (.IRIScanDirect.) [HKLM] -- IRIScanDirect_is1
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
O42 - Logiciel: Java 8 Update 31 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83218031F0}
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
O42 - Logiciel: Logiciel d'archivage WinRAR - (...) [HKLM] -- WinRAR archiver
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: Malwarebytes Anti-Malware version 2.1.6.1022 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1
O42 - Logiciel: Mesh Runtime - (.Microsoft Corporation.) [HKLM] -- {8C6D6116-B724-4810-8F2D-D047E6B7D68E}
O42 - Logiciel: Microsoft Image Composite Editor - (.Microsoft Corporation.) [HKLM] -- {3D599ADA-65D9-4B51-898F-CE718DEC5DBB}
O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {D6F9CBDC-58B6-430A-8DD4-8F61CBC1ADF4}
O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Mozilla Firefox 37.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 37.0.2 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: Nero Burning ROM - (.Nero AG.) [HKLM] -- {CF508721-0E1E-4F99-A359-59E4EA8DAEC1}
O42 - Logiciel: Nero Burning ROM Help (CHM) - (.Nero AG.) [HKLM] -- {2890E324-6F3B-4975-8B95-E7D6D80E0226}
O42 - Logiciel: Nero BurningROM 12 - (.Nero AG.) [HKLM] -- {DCF34348-8673-4E60-97E5-1CBC0D7293AC}
O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM] -- {ABC88553-8770-4B97-B43E-5A90647A5B63}
O42 - Logiciel: Nero ControlCenter Help (CHM) - (.Nero AG.) [HKLM] -- {C994C746-C6D0-4EBA-B09E-DF7B18381B69}
O42 - Logiciel: Nero Core Components - (.Nero AG.) [HKLM] -- {BEBEE34D-84A2-4EDD-8BEA-96CC54371263}
O42 - Logiciel: Nero SharedVideoCodecs - (.Nero AG.) [HKLM] -- {2432E589-6256-4513-B0BF-EFA8E325D5F0}
O42 - Logiciel: Nero Update - (.Nero AG.) [HKLM] -- {65BB0407-4CC8-4DC7-952E-3EEFDF05602A}
O42 - Logiciel: PDF Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
O42 - Logiciel: PhotoShowExpress - (.Sonic Solutions.) [HKLM] -- {3250260C-7A95-4632-893B-89657EB5545B}
O42 - Logiciel: Photoshop Camera Raw - (.Adobe Systems Incorporated.) [HKLM] -- {CC75AB5C-2110-4A7F-AF52-708680D22FE8}
O42 - Logiciel: QuickSet32 - (.Dell Inc..) [HKLM] -- {C4972073-2BFE-475D-8441-564EA97DA161}
O42 - Logiciel: ResearchSoft Direct Export Helper - (...) [HKLM] -- ResearchSoft Direct Export Helper
O42 - Logiciel: Roxio Activation Module - (.Roxio.) [HKLM] -- {A121EEDE-C68F-461D-91AA-D48BA226AF1C}
O42 - Logiciel: Roxio BackOnTrack - (.Roxio.) [HKLM] -- {5A06423A-210C-49FB-950E-CB0EB8C5CEC7}
O42 - Logiciel: Roxio Burn - (.Roxio.) [HKLM] -- {9569E6BC-326A-432F-97AB-35263A327BF1}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {EF56258E-0326-48C5-A86C-3BAC26FC15DF}
O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}
O42 - Logiciel: Roxio Express Labeler 3 - (.Roxio.) [HKLM] -- {6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
O42 - Logiciel: Roxio File Backup - (.Roxio.) [HKLM] -- {60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}
O42 - Logiciel: Samsung Printer Live Update - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung Printer Live Update
O42 - Logiciel: Satsuki Decoder Pack - (.Satsuki Yatoshi'S Softs.) [HKLM] -- Satsuki Decoder Pack
O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701}
O42 - Logiciel: Skype(TM) 7.4 - (.Skype Technologies S.A..) [HKLM] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
O42 - Logiciel: Sonic CinePlayer Decoder Pack - (.Sonic Solutions.) [HKLM] -- {9A00EC4E-27E1-42C4-98DD-662F32AC8870}
O42 - Logiciel: Spotify - (...) [HKLM] -- Spotify
O42 - Logiciel: Spotify - (.Spotify AB.) [HKCU] -- Spotify
O42 - Logiciel: Suite Shared Configuration CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {842B4B72-9E8F-4962-B3C1-1C422A5C4434}
O42 - Logiciel: TuxGuitar 1.2 - (...) [HKLM] -- TuxGuitar_0
O42 - Logiciel: Validity Sensors DDK - (.Validity Sensors, Inc..) [HKLM] -- {9FCB6355-689E-4141-9714-3EEC2AE10292}
O42 - Logiciel: WIDCOMM Bluetooth Software - (.Broadcom Corporation.) [HKLM] -- {9E9D49A4-1DF4-4138-B7DB-5D87A893088E}
O42 - Logiciel: XnView 2.22 - (.Gougelet Pierre-e.) [HKLM] -- XnView_is1
O42 - Logiciel: Xvid 1.2.1 final uninstall - (.Xvid team (Koepi).) [HKLM] -- Xvid_is1
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {11E568E0-3244-4BCB-875E-F334269DFDCB}
O42 - Logiciel: kuler - (.Adobe Systems Incorporated.) [HKLM] -- {098727E1-775A-4450-B573-3F441F1CA243}
~ Logic: 44 Scanned in 00mn 00s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\7-Zip]
[HKCU\Software\AC3Filter]
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow\Software\DigitalPersona]
[HKCU\Software\AppDataLow\Software\JavaSoft]
[HKCU\Software\AppDataLow\Software\Smartbar] =>Hijacker.SmartBar
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Arobas Music]
[HKCU\Software\Broadcom]
[HKCU\Software\CG Information]
[HKCU\Software\Canneverbe Limited]
[HKCU\Software\Canon]
[HKCU\Software\Citrix]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\Creative Tech]
[HKCU\Software\CyberLink]
[HKCU\Software\DT Soft]
[HKCU\Software\Developer Express]
[HKCU\Software\DigitalPersona]
[HKCU\Software\Druide informatique inc.]
[HKCU\Software\ERDAS]
[HKCU\Software\ESRI]
[HKCU\Software\EasyBits]
[HKCU\Software\Eset]
[HKCU\Software\GNU]
[HKCU\Software\Gabest]
[HKCU\Software\Google]
[HKCU\Software\HKEY_LOCAL_MACHINE]
[HKCU\Software\Haali]
[HKCU\Software\Herac]
[HKCU\Software\IDAVLab]
[HKCU\Software\IDT]
[HKCU\Software\IM Providers]
[HKCU\Software\ISI ResearchSoft]
[HKCU\Software\Intel]
[HKCU\Software\JavaSoft]
[HKCU\Software\Lake]
[HKCU\Software\LogiShrd]
[HKCU\Software\MCAFEE]
[HKCU\Software\Macromedia]
[HKCU\Software\Macrovision]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Nero]
[HKCU\Software\Netscape]
[HKCU\Software\Northcode Inc]
[HKCU\Software\ODBC]
[HKCU\Software\PC-Doctor]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\RICOH]
[HKCU\Software\RealNetworks]
[HKCU\Software\RegisteredApplications]
[HKCU\Software\Roxio]
[HKCU\Software\SSPrint]
[HKCU\Software\STUDIO SARMADI]
[HKCU\Software\Samsung]
[HKCU\Software\Satsuki Decoder Pack]
[HKCU\Software\SecuROM]
[HKCU\Software\Skype]
[HKCU\Software\Synaptics]
[HKCU\Software\Trolltech]
[HKCU\Software\Widcomm]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKLM\Software\14919ea49a8f3b4aa3cf1058d9a64cec] =>PUP.CrossRider
[HKLM\Software\ATI Technologies]
[HKLM\Software\Adobe]
[HKLM\Software\AdwCleaner]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\BcmSetup]
[HKLM\Software\Broadcom]
[HKLM\Software\Canneverbe Limited]
[HKLM\Software\Canon]
[HKLM\Software\Citrix]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Creative Tech]
[HKLM\Software\CyberLink]
[HKLM\Software\DT Soft]
[HKLM\Software\Debug]
[HKLM\Software\Dell Computer Corporation]
[HKLM\Software\Dell Inc.]
[HKLM\Software\Dell]
[HKLM\Software\DigitalPersona]
[HKLM\Software\Druide informatique inc.]
[HKLM\Software\ERDAS]
[HKLM\Software\ESRI]
[HKLM\Software\FreeFallProtection]
[HKLM\Software\GEAR Software]
[HKLM\Software\GNU]
[HKLM\Software\Gabest]
[HKLM\Software\Google]
[HKLM\Software\HaaliMkx]
[HKLM\Software\IDAVLab]
[HKLM\Software\IDT]
[HKLM\Software\IM Providers]
[HKLM\Software\ISI ResearchSoft]
[HKLM\Software\Imagineer Systems Ltd]
[HKLM\Software\InstalledOptions]
[HKLM\Software\Intel]
[HKLM\Software\InterVideo]
[HKLM\Software\JavaSoft]
[HKLM\Software\JreMetrics]
[HKLM\Software\Lake]
[HKLM\Software\Logishrd]
[HKLM\Software\MAXSOFT-OCRON]
[HKLM\Software\Macromedia]
[HKLM\Software\Macrovision]
[HKLM\Software\Malwarebytes' Anti-Malware (Trial)]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\ManageableUpdatePackage]
[HKLM\Software\McAfee.com]
[HKLM\Software\McAfeeInstaller]
[HKLM\Software\McAfee]
[HKLM\Software\MicroVision]
[HKLM\Software\MimarSinan]
[HKLM\Software\Mircrosoft]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Nero]
[HKLM\Software\Novell]
[HKLM\Software\ODBC]
[HKLM\Software\PC-Doctor]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\Python]
[HKLM\Software\RealNetworks]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Roxio]
[HKLM\Software\SSPrint]
[HKLM\Software\STMicroelectronics]
[HKLM\Software\Samsung]
[HKLM\Software\Skype]
[HKLM\Software\Sonic]
[HKLM\Software\Synaptics]
[HKLM\Software\Synthetic Aperture]
[HKLM\Software\Validity]
[HKLM\Software\Vantage Software Technologies]
[HKLM\Software\Volatile]
[HKLM\Software\Widcomm]
[HKLM\Software\WinRAR]
[HKLM\Software\Windows]
[HKLM\Software\Wise Solutions]
[HKLM\Software\XnView]
[HKLM\Software\illiminable]
[HKLM\Software\mozilla.org]
~ Key Software: 335 Scanned in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 23/09/2013 - 18:48:51 - [] ----D C:\Program Files\7-Zip
O43 - CFD: 14/10/2012 - 17:01:19 - [] ----D C:\Program Files\Adobe
O43 - CFD: 27/10/2012 - 13:10:03 - [] ----D C:\Program Files\Apple Software Update =>.Apple Inc
O43 - CFD: 23/09/2013 - 14:43:50 - [] ----D C:\Program Files\ArcGIS
O43 - CFD: 27/10/2012 - 13:09:43 - [] ----D C:\Program Files\Bonjour
O43 - CFD: 08/05/2015 - 11:47:02 - [] ----D C:\Program Files\CCleaner
O43 - CFD: 04/12/2011 - 23:56:37 - [] ----D C:\Program Files\CDBurnerXP
O43 - CFD: 07/01/2011 - 14:48:11 - [] ----D C:\Program Files\Cisco
O43 - CFD: 09/04/2013 - 08:24:59 - [] ----D C:\Program Files\Citrix
O43 - CFD: 01/02/2015 - 19:25:56 - [] ----D C:\Program Files\Common Files
O43 - CFD: 07/01/2011 - 14:52:12 - [] ----D C:\Program Files\Creative
O43 - CFD: 07/01/2011 - 14:51:48 - [] ----D C:\Program Files\Creative Live! Cam
O43 - CFD: 07/01/2011 - 14:51:24 - [] ----D C:\Program Files\CyberLink
O43 - CFD: 13/02/2015 - 17:07:18 - [] ----D C:\Program Files\Dell
O43 - CFD: 07/01/2011 - 14:41:47 - [] ----D C:\Program Files\Dell Inc
O43 - CFD: 01/04/2015 - 15:56:44 - [] ----D C:\Program Files\Dell Support Center
O43 - CFD: 07/01/2011 - 14:51:52 - [] ----D C:\Program Files\Dell Webcam
O43 - CFD: 07/01/2011 - 14:49:33 - [] ----D C:\Program Files\DigitalPersona
O43 - CFD: 05/10/2011 - 21:15:44 - [] ----D C:\Program Files\Druide
O43 - CFD: 04/01/2012 - 19:58:59 - [] ----D C:\Program Files\DVD Maker
O43 - CFD: 30/05/2013 - 16:35:59 - [] ----D C:\Program Files\EndNote X3
O43 - CFD: 23/08/2012 - 09:49:39 - [] ----D C:\Program Files\ESET
O43 - CFD: 12/01/2011 - 13:59:10 - [] -SH-D C:\Program Files\Fichiers communs
O43 - CFD: 09/08/2013 - 08:30:00 - [] ----D C:\Program Files\Google
O43 - CFD: 18/09/2012 - 08:30:24 - [] ----D C:\Program Files\GUMBB52.tmp
O43 - CFD: 07/01/2011 - 07:38:05 - [] ----D C:\Program Files\IDT
O43 - CFD: 07/01/2011 - 14:51:50 - [] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 07/01/2011 - 14:43:38 - [] ----D C:\Program Files\Intel
O43 - CFD: 16/04/2015 - 07:41:45 - [] ----D C:\Program Files\Internet Explorer
O43 - CFD: 02/06/2013 - 16:57:17 - [] ----D C:\Program Files\iPod
O43 - CFD: 30/05/2014 - 17:24:54 - [] ----D C:\Program Files\IRIScan Direct
O43 - CFD: 02/06/2013 - 16:57:47 - [] ----D C:\Program Files\iTunes
O43 - CFD: 01/02/2015 - 19:24:51 - [] ----D C:\Program Files\Java
O43 - CFD: 08/05/2015 - 12:02:05 - [] ----D C:\Program Files\Malwarebytes Anti-Malware
O43 - CFD: 19/08/2014 - 07:39:24 - [] ----D C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 05/02/2011 - 11:49:23 - [] ----D C:\Program Files\McAfee
O43 - CFD: 15/01/2011 - 17:51:35 - [0] ----D C:\Program Files\Microsoft
O43 - CFD: 14/07/2009 - 11:00:58 - [] ----D C:\Program Files\Microsoft Games
O43 - CFD: 27/08/2012 - 21:15:59 - [] ----D C:\Program Files\Microsoft Office
O43 - CFD: 10/02/2012 - 09:38:04 - [] ----D C:\Program Files\Microsoft Research
O43 - CFD: 11/02/2015 - 20:53:43 - [] ----D C:\Program Files\Microsoft Security Client
O43 - CFD: 24/07/2014 - 17:05:44 - [] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 07/01/2011 - 15:02:44 - [] ----D C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 13/03/2011 - 22:40:16 - [] ----D C:\Program Files\Microsoft Visual Studio
O43 - CFD: 13/03/2011 - 22:37:09 - [] ----D C:\Program Files\Microsoft Visual Studio 8
O43 - CFD: 23/08/2012 - 08:17:10 - [] ----D C:\Program Files\Microsoft Works
O43 - CFD: 13/03/2011 - 22:40:04 - [] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 24/04/2015 - 12:09:10 - [] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 26/04/2015 - 08:23:34 - [] ----D C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 13/03/2011 - 22:40:20 - [] ----D C:\Program Files\MSBuild
O43 - CFD: 15/01/2011 - 23:49:59 - [0] ----D C:\Program Files\MSXML 4.0
O43 - CFD: 27/06/2013 - 21:45:49 - [] ----D C:\Program Files\Nero
O43 - CFD: 14/07/2009 - 06:52:30 - [] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 07/01/2011 - 14:58:04 - [] ----D C:\Program Files\Roxio
O43 - CFD: 03/03/2014 - 12:14:18 - [] ----D C:\Program Files\SamsungPrinterLiveUpdate
O43 - CFD: 03/03/2014 - 12:04:04 - [] ----D C:\Program Files\SamsungPrinterLiveUpdateInstaller
O43 - CFD: 05/02/2011 - 11:29:22 - [] ----D C:\Program Files\Satsuki Decoder Pack
O43 - CFD: 14/04/2015 - 08:03:39 - [] R---D C:\Program Files\Skype
O43 - CFD: 24/03/2015 - 20:36:20 - [] ----D C:\Program Files\Spotify
O43 - CFD: 07/01/2011 - 14:44:04 - [] ----D C:\Program Files\STMicroelectronics
O43 - CFD: 07/01/2011 - 16:33:50 - [] ----D C:\Program Files\Synaptics
O43 - CFD: 10/12/2011 - 19:15:54 - [] ----D C:\Program Files\Trend Micro
O43
0
Et enfin le dernier bout qui n'a pas apparu dans le dernier post

---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 15/04/2015 268464 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Auto 22/10/2014 107912 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 22/10/2014 107912 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 24/04/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 04/09/2010 1116656 | (RoxMediaDB12OEM) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
SS - | Auto 04/09/2010 219632 | (RoxWatch12) . (.Sonic Solutions.) - C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
SS - | Auto 18/02/2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SS - | Demand 26/08/2010 74392 | (stllssvr) . (.MicroVision Development, Inc..) - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 03/03/2009 81920 | (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 20/10/2009 595232 | (btwdins) . (.Broadcom Corporation..) - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
SR - | Auto 26/02/2015 1947344 | (DellDataVault) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVault.exe
SR - | Auto 26/02/2015 184016 | (DellDataVaultWiz) . (.Dell Inc..) - C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
SR - | Auto 13/05/2009 322624 | (DpHost) . (.DigitalPersona, Inc..) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
SR - | Demand 23/09/2013 1044816 | (FLEXnet Licensing Service) . (.Flexera Software, Inc..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SR - | Demand 15/05/2013 553288 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 04/11/2009 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 14/04/2015 1871160 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
SR - | Auto 14/04/2015 1080120 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
SR - | Auto 30/01/2015 22184 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 13/07/2012 769432 | (NAUpdate) . (.Nero AG.) - C:\Program Files\Nero\Update\NASvc.exe
SR - | Auto 07/04/2010 229458 | (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
SR - | Auto 10/04/2015 19288 | (SupportAssistAgent) . (.Dell Inc..) - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
SR - | Auto 04/11/2009 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 03/06/2010 1664304 | (vcsFPService) . (.Validity Sensors, Inc..) - C:\Windows\system32\vcsFPService.exe
SR - | Auto 07/01/2011 40960 | (wltrysvc) . (.Dell Inc..) - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 37s



---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Run by Amaury at 08/05/2015 19:09:31
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys stdcfltn.sys ACPI.sys halmacpi.dll iaStor.sys
C:\Windows\system32\DRIVERS\stdcfltn.sys ST Microelectronics Disk Class Filter Driver for Accelerometer
C:\Windows\system32\DRIVERS\iaStor.sys Intel Corporation Intel Rapid Storage Technology driver
1 ntkrnlpa!IofCallDriver[0x8364FBBA] >> \Device\Harddisk0\DR0[0x88601990]
3 CLASSPNP[0x8BF9E59E] >> ntkrnlpa!IofCallDriver[0x8364FBBA] >> [0x88601020]
5 stdcfltn[0x8C1DD896] >> ntkrnlpa!IofCallDriver[0x8364FBBA] >> [0x86A608B8]
7 ACPI[0x8B8AD3D4] >> ntkrnlpa!IofCallDriver[0x8364FBBA] >> \Device\Ide\IAAStorageDevice-1[0x86A45028]
kernel: MBR read successfully
user & kernel MBR OK
~ MBR: 16 Scanned in 00mn 02s



---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by Amaury at 08/05/2015 19:09:33
                  • Dump file Name *********

C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s



---\\ Scan Additionnel (O88)
Database Version : 13008 - (05/05/2015)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 43

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\7Zip Bundle by Fileparade.com] =>PUP.SweetIM^
[HKCU\Software\AppDataLow\Software\Smartbar] =>Hijacker.SmartBar^
[HKLM\Software\14919ea49a8f3b4aa3cf1058d9a64cec] =>PUP.CrossRider^
[HKCR\CLSID\{046174D9-22D5-4D5A-AC5F-FAE82285D8E0}] (esriGeneralization.OptimizerProximity) =>PUP.OptimizerPro^
[HKCR\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}] (esriGlobeCoreUI.GxGlobeViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{0CEDD0BD-4060-4D6C-AD04-61453E906C79}] (esriCarto.StandaloneTableInfos) =>Adware.OneTab^
[HKCR\CLSID\{16DA8D40-1D0A-45B8-8A9F-C9ABD3CC11E7}] (esriGlobeCore.GlobeServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}] (esriEditor.SnapDockWindow) =>Hijacker.SmartBar^
[HKCR\CLSID\{217F3E22-AEFC-4DEF-82D1-2B83B87D7936}] (esriSchematicUI.SchematicFindRelatedDiagramsCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{383FA402-05D9-4670-AA7A-C8667769157B}] (esriCarto.StandaloneTableDescription) =>Adware.OneTab^
[HKCR\CLSID\{393F91DC-8DAF-4147-9C8B-60EE7A2E1CE2}] (esriCarto.StandaloneTableInfo) =>Adware.OneTab^
[HKCR\CLSID\{3E1FBA8F-891C-4BBF-A441-0A634490D058}] (esriControls.ControlsFindRouteAddStopsTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{427FD9F5-3E06-4C4B-836D-B82140536ECC}] (esriCartoX.AnalyzeUnregisteredDataSourceStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{4D6CAB29-5A91-4AD0-A636-CCA3D56BDED3}] (esriArcMapUI.MapServerSublayersPropertyPage) =>PUP.EoRezo^
[HKCR\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}] (esriGeoprocessingUI.NewToolsetMenuItem) =>PUP.Nosibay^
[HKCR\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}] (esriArcMapUI.MxDrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}] (esriArcCatalogUI.GxGeographicViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}] (esriEditor.ConstructionMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}] (esriGeoprocessing.GPConvertCoordinateNotation) =>Hijacker.Proxy^
[HKCR\CLSID\{7D3F2C22-2765-4365-AD68-41B7B1E60E2C}] (esriGlobeCore.GlobeServerSubLayer) =>PUP.EoRezo^
[HKCR\CLSID\{8A073E77-E06E-4584-81E1-3719C7D44293}] (esriGlobeCore.GlobeServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{92C2ED17-BBD2-448C-B9F2-5362BF1F0A61}] (esriArcMapUI.MapServerSublayerLabelsCommand) =>PUP.EoRezo^
[HKCR\CLSID\{954F6F4D-A17E-4469-8C41-A6BB5F98218F}] (esriCartoX.CIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}] (esriCadastralUI.ParcelTransformationMiniBar) =>PUP.Minibar^
[HKCR\CLSID\{9F6986C2-DB2C-4225-B7B6-64FD2366C337}] (esriControls.ControlsFindRouteAddBarriersTool) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{A0C752A1-827C-4A58-9121-E9441784E0AB}] (esriCartoX.AnalyzeStandaloneTableWithClassExt) =>Adware.OneTab^
[HKCR\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}] (esri3DAnalystUI.GxWorldViewTools) =>PUP.Nosibay^
[HKCR\CLSID\{A800E039-7351-466C-8A9A-ABBF5A4A1CB0}] (esriCartoX.ArrayOfCIMStandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{A9B7F81C-E135-456F-8415-687425E05BB9}] (esriEditorExt.StandaloneTableGeneralPropPage) =>Adware.OneTab^
[HKCR\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}] (esriArcScan.DrawToolsPalette) =>PUP.Nosibay^
[HKCR\CLSID\{B168C705-03AA-4987-BDB0-AE72B534CE47}] (esriControls.ControlsFindRoute) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}] (esriArcMapUI.ViewpointDockWin) =>Adware.MetaStream^
[HKCR\CLSID\{BB83AE43-DCA7-4096-8034-90E54EA6B37F}] (esriArcMapUI.MapServerSublayerContextAnalyzer) =>PUP.EoRezo^
[HKCR\CLSID\{BDC68B11-B152-4933-A870-3E4271BC42CA}] (esriControls.ControlsFindRouteCommand) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{C8EC264A-CB6D-4C0F-9E40-F5068CA2B98D}] (esriArcMapUI.MapServerSublayerContextMenu) =>PUP.EoRezo^
[HKCR\CLSID\{C9831F1F-957B-4A93-AD46-6AECE0D858CE}] (esriControls.FindRouteAppHelper) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}] (esriArcMapUI.ViewpointCommand) =>Adware.MetaStream^
[HKCR\CLSID\{D43F1B58-B1A6-42ed-9B3A-D084AB6061C5}] (AGOLLargeDownloader Class) =>PUP.SoftwareEngine^
[HKCR\CLSID\{DF9ADEE0-54B2-43D7-90BF-B2CB9BCC3735}] (esriCarto.MapServerFindResult) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{EC9121BF-25EE-4C00-8629-7273FCBAFF03}] (esriEditorExt.StandaloneTableSourcePropPage) =>Adware.OneTab^
[HKCR\CLSID\{EE7C5047-E3DB-11D3-A096-00C04F6BC626}] (esriCarto.StandaloneTable) =>Adware.OneTab^
[HKCR\CLSID\{F6AC7A93-95A9-455A-8FF3-EEE4A46E073A}] (esriCarto.MapServerFindResults) =>Hijacker.FindrToolbar^
[HKCR\CLSID\{FD6F0C6B-5103-43BA-AB0F-D9036B40E2B7}] (esriDataSourcesRasterUI.VariableManagerRFxPropPage) =>PUP.Manager^
[HKCR\CLSID\{FE6A5B40-F898-4197-A807-2E554A18E1F7}] (esriCarto.StandaloneTableDescriptions) =>Adware.OneTab^
~ Additionnel Scan: 674465 Items scanned in 00mn 30s



---\\ Informations complémentaires sur les modules
~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5)
~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects de navigateur (O2)
~ http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Applications lancées au démarrage du système (O4)
~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
~ AMI: 5 Scanned in 00mn 00s



---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/pup-yourfiledownloader =>PUP.YourFileDownloader
http://nicolascoolman.fr/pup-sweetim =>PUP.SweetIM
http://nicolascoolman.fr/hijacker-smartbar =>Hijacker.SmartBar
http://nicolascoolman.fr/pup-crossrider =>PUP.CrossRider
http://nicolascoolman.fr/pup-optimizerpro =>PUP.OptimizerPro
http://www.nicolascoolman.fr/blog/ =>PUP.Nosibay
http://nicolascoolman.fr/adware-onetab =>Adware.OneTab
http://nicolascoolman.fr/hijacker-findrtoolbar =>Hijacker.FindrToolbar
http://nicolascoolman.fr/pup-eorezo =>PUP.EoRezo
http://nicolascoolman.fr/pup-minibar =>PUP.Minibar
http://nicolascoolman.fr/hijacker-proxy =>Hijacker.Proxy
http://nicolascoolman.fr/adware-metastream =>Adware.MetaStream
http://nicolascoolman.fr/pup-softwareengine =>PUP.SoftwareEngine
http://nicolascoolman.fr/pup-manager =>PUP.Manager
~ MSI: 14 link(s) detected in 00mn 00s



End of the scan (1555 lines in 06mn 34s)(2.11)
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 804
8 mai 2015 à 19:36
ZHPCleaner




Désactiver l'Anti-virus

Ton moteur de recherche va se fermer il faudra le réouvrir pour poster les rapports

téléchargement : https://nicolascoolman.eu




- Cet outil ne nécessite aucune installation, il est très rapide car basé sur l'éxécution de scripts.
- Clique droit sur le dossier téléchargé


- Clique sur Scanner :

- Savoir que tous les navigateurs ou onglets ouvert seront fermés et qu'il faudra les remettre

- En cas de présence d'un proxy, un message apparaît avec la question suivante
- Avez-vous installé ce proxy ? suivi de l'adresse IP du proxy
- Si vous n'avez pas installé de Proxy, cliquer sur "NON" pour accepter la réparation du proxy.

- En cas de présence d'un serveur inconnu, un message peut apparaître avec la question suivante
- Avez-vous installé ce serveur ? suivi du nom du serveur
- Si vous n'avez pas installé de serveur,, cliquer sur "NON" pour accepter la réparation



- Fournir le rapport

0
Voici le rapport du scan

~ ZHPCleaner v2015.5.8.218 by Nicolas Coolman (08/05/2015)
~ Run by Amaury (Administrator) (08/05/2015 20:18:43)
~ Forum : http://forum.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Scanner
~ Report : C:\Users\Amaury\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Amaury\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Deactivate
~ Boot Mode : Normal (Normal boot)
~ Windows 7, 32-bit Service Pack 1 (Build 7601)


---\\ Service. (0)
~ Aucun élément malicieux trouvé.


---\\ Navigateur internet. (0)
~ Aucun élément malicieux trouvé.


---\\ Fichier hôte. (1)
~ Le fichier hôte est légitime. (21)


---\\ Tâche planifiée. (1)
TROUVÉ tâche: [YourFile Update] [C:\Program Files\YourFileDownloader\YourFileUpdater.exe (Not File) ] (PUP.YourFileDownloader)


---\\ Explorateur ( Dossiers, Fichiers ). (0)
~ Aucun élément malicieux trouvé.


---\\ Base de Registres ( Clés, Valeurs, Données ). (54)
TROUVÉ clé: HKCU\Software\AppDataLow\Software\Smartbar [] (PUP.QuickShare)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esri3DAnalystUI.GxWorldViewTools [] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esri3DAnalystUI.GxWorldViewTools.1 [] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriArcCatalogUI.GxGeographicViewTools [] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriArcCatalogUI.GxGeographicViewTools.1 [] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriArcMapUI.MxDrawToolsPalette [] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriArcMapUI.MxDrawToolsPalette.1 [] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriArcMapUI.ViewpointCommand [] (Adware.MetaStream)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriArcMapUI.ViewpointCommand.1 [] (Adware.MetaStream)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriArcMapUI.ViewpointDockWin [] (Adware.MetaStream)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriArcMapUI.ViewpointDockWin.1 [] (Adware.MetaStream)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriArcScan.DrawToolsPalette [] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriArcScan.DrawToolsPalette.1 [] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriCadastralUI.ParcelTransformationMiniBar [] (PUP.Minibar)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriCadastralUI.ParcelTransformationMiniBar.1 [] (PUP.Minibar)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriEditor.ConstructionMiniBar [] (PUP.Minibar)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriEditor.ConstructionMiniBar.1 [] (PUP.Minibar)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriEditor.SnapDockWindow [] (Hijacker.SmartBar)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriEditor.SnapDockWindow.1 [] (Hijacker.SmartBar)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriEditorExt.FeatureFromAreaContainsPointErrorCommand [] (Adware.SPointer)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriEditorExt.FeatureFromAreaContainsPointErrorCommand.1 [] (Adware.SPointer)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriGeoprocessing.GPConvertCoordinateNotation [] (Hijacker.Proxy)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriGeoprocessing.GPConvertCoordinateNotation.1 [] (Hijacker.Proxy)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriGeoprocessingUI.NewToolsetMenuItem [] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriGeoprocessingUI.NewToolsetMenuItem.1 [] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriGlobeCoreUI.GxGlobeViewTools [] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\esriGlobeCoreUI.GxGlobeViewTools.1 [] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C} [esriGlobeCoreUI.GxGlobeViewTools] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261} [esriEditor.SnapDockWindow] (Hijacker.SmartBar)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{261CCD33-54FD-44B5-9F31-1CB24C550455} [esriEditorExt.FeatureFromAreaContainsPointErrorCommand] (Adware.SPointer)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60} [esriGeoprocessingUI.NewToolsetMenuItem] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A} [esriArcMapUI.MxDrawToolsPalette] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B} [esriArcCatalogUI.GxGeographicViewTools] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745} [esriEditor.ConstructionMiniBar] (PUP.Minibar)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475} [esriGeoprocessing.GPConvertCoordinateNotation] (Hijacker.Proxy)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A} [esriCadastralUI.ParcelTransformationMiniBar] (PUP.Minibar)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D} [esri3DAnalystUI.GxWorldViewTools] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE} [esriArcScan.DrawToolsPalette] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14} [esriArcMapUI.ViewpointDockWin] (Adware.MetaStream)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634} [esriArcMapUI.ViewpointCommand] (Adware.MetaStream)
TROUVÉ clé: HKLM\SOFTWARE\14919ea49a8f3b4aa3cf1058d9a64cec [] (Hijacker.Browser)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{0C40B6A6-179C-4BBE-BE04-91E55D6A1F2C}\InprocServer32 [C:\Program Files\Common Files\ArcGIS\bin\ArcGISVersion.dll] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{17FAB8C4-7790-4CD1-A666-8FEF04740261}\InprocServer32 [C:\Program Files\Common Files\ArcGIS\bin\ArcGISVersion.dll] (Hijacker.SmartBar)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{261CCD33-54FD-44B5-9F31-1CB24C550455}\InprocServer32 [C:\Program Files\Common Files\ArcGIS\bin\ArcGISVersion.dll] (Adware.SPointer)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{56C41C26-C5A9-4BBC-AFD3-CEC348425A60}\InprocServer32 [C:\Program Files\Common Files\ArcGIS\bin\ArcGISVersion.dll] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{5AAD204F-D030-11D2-9F35-00C04F6BC61A}\InprocServer32 [C:\Program Files\Common Files\ArcGIS\bin\ArcGISVersion.dll] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{64BF3C7E-E501-11D1-AEE5-080009EC734B}\InprocServer32 [C:\Program Files\Common Files\ArcGIS\bin\ArcGISVersion.dll] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{6CE1AEA7-2C0B-4451-B7C2-6E8EDE7E2745}\InprocServer32 [C:\Program Files\Common Files\ArcGIS\bin\ArcGISVersion.dll] (PUP.Minibar)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{7BEBBA6F-78F6-4F0B-BE58-4EC8DA7E5475}\InprocServer32 [C:\Program Files\Common Files\ArcGIS\bin\ArcGISVersion.dll] (Hijacker.Proxy)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{968721FC-A548-4C73-BE21-2B106BA6323A}\InprocServer32 [C:\Program Files\Common Files\ArcGIS\bin\ArcGISVersion.dll] (PUP.Minibar)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{A42EB656-AC5E-11D2-9FAE-00C04F8ECE3D}\InprocServer32 [C:\Program Files\Common Files\ArcGIS\bin\ArcGISVersion.dll] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{B087AB73-531D-4CA2-A3FF-1C06770D2EDE}\InprocServer32 [C:\Program Files\Common Files\ArcGIS\bin\ArcGISVersion.dll] (PUP.Nosibay)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{B89E24AB-D38A-4D91-A89B-101ED1C7EC14}\InprocServer32 [C:\Program Files\Common Files\ArcGIS\bin\ArcGISVersion.dll] (Adware.MetaStream)
TROUVÉ clé: HKLM\SOFTWARE\Classes\CLSID\{CA762F62-686A-4EDC-8ABB-B9AE4425A634}\InprocServer32 [C:\Program Files\Common Files\ArcGIS\bin\ArcGISVersion.dll] (Adware.MetaStream)


---\\ Bilan de la réparation
~ Aucune réparation effectuée.
~ Ce navigateur est absent (Opera Software)


---\\ Statistiques
~ Items scannés : 129314
~ Items trouvés : 68
~ Items annulés : 0
~ Items réparés : 0


End of clean at 20:44:35
===================
ZHPCleaner-[S]-08052015-20_44_35.txt
0
Ya pas mal de choses qui font référence à ESRI/Arcgis ou arcMap. Si je fais clean, les logiciels fonctionneront encore?
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 804
8 mai 2015 à 21:12
Non ne fais pas nettoyer sans doute un faux positif je fais remonter l'info :=)
0
Cette tâche me dit rien par contre.
TROUVÉ tâche: [YourFile Update] [C:\Program Files\YourFileDownloader\YourFileUpdater.exe (Not File) ] (PUP.YourFileDownloader)

J'attend ta confirmation pour savoir si c'est bon où s'il reste des merdes dans le lot. Merci pour ton suivi.
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 804
8 mai 2015 à 21:46
oui cette ligne là est néfaste


0
Ok j'attends ton retour pour la procédure à suivre pour éliminer le mauvais et garder le bon
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 804
8 mai 2015 à 22:53
C'est bon retelecharge zhpcleaner
0
le nouveau rapport du scan:

~ ZHPCleaner v2015.5.8.220 by Nicolas Coolman (09/05/2015)
~ Run by Amaury (Administrator) (09/05/2015 09:55:16)
~ Forum : http://forum.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Scanner
~ Report : C:\Users\Amaury\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Amaury\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Deactivate
~ Boot Mode : Normal (Normal boot)
~ Windows 7, 32-bit Service Pack 1 (Build 7601)


---\\ Service. (0)
~ Aucun élément malicieux trouvé.


---\\ Navigateur internet. (0)
~ Aucun élément malicieux trouvé.


---\\ Fichier hôte. (1)
~ Le fichier hôte est légitime. (21)


---\\ Tâche planifiée. (1)
TROUVÉ tâche: [YourFile Update] [C:\Program Files\YourFileDownloader\YourFileUpdater.exe (Not File) ] (PUP.YourFileDownloader)


---\\ Explorateur ( Dossiers, Fichiers ). (0)
~ Aucun élément malicieux trouvé.


---\\ Base de Registres ( Clés, Valeurs, Données ). (1)
TROUVÉ clé: HKCU\Software\AppDataLow\Software\Smartbar [] (PUP.QuickShare)


---\\ Bilan de la réparation
~ Aucune réparation effectuée.
~ Ce navigateur est absent (Opera Software)


---\\ Statistiques
~ Items scannés : 129316
~ Items trouvés : 2
~ Items annulés : 0
~ Items réparés : 0


End of clean at 10:19:21
===================
ZHPCleaner-[S]-08052015-20_44_35.txt
ZHPCleaner-[S]-09052015-10_19_21.txt
0