1place.org

Bonjour,

depuis quelques jours, je m'aperçois que quand je fais une recherche sur internet, j'ai en première proposition un lien qui mène sur ce site "1place.org" et j'ai ça avec n'importe quelle recherche.

Serait-ce un virus?

Pas moyen de savoir de où cela peut provenir. :/

41 réponses

Résumé de la discussion

Une anomalie persiste lors des recherches sur Internet, avec le lien 1place.org affiché en tête sur Windows 7 et Mozilla 11.0, ce qui suggère une infection ou un hijack du navigateur. Des éléments évoquent un Trojan détecté et des indices de compromission dans le fichier HOSTS et les paramètres proxy, compatibles avec un détournement des requêtes. Des outils de diagnostic comme RogueKiller ont été utilisés pour analyser les processus et les entrées de registre, et générer des rapports sur les éléments malveillants. En parallèle, des conseils destinés à neutraliser l’infection mentionnent la désactivation du proxy, la réalisation d’un scan complet et la vérification des rapports zhpdiag pour confirmer l’absence d’autres traces.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Tu as dû installer des logiciels potentiellement indésirables

    Pour éviter ce genre de problème :

    - Ne télécharge aucun programme proposé dans des publicités ou sur des sites suspects. A noter que certains sites connus comme O1net, Softronic, Tuto4PC, etc modifient parfois les programmes proposés au téléchargement pour y ajouter des logiciels publicitaires ==> Préfère toujours le téléchargement directement sur le site de l'éditeur.

    - Au cours de l'installation d'un programme gratuit, lis bien attentivement et décoche tous les programmes additionnels qui sont proposés, en particulier les barres d'outils.

    Pour ton information lis ces dossier sur les Programmes Potentiellement Indésirables et Les Barres d'Outils ce n'est pas obligatoires

    * Télécharge cet outil simple d'utilisation

    https://toolslib.net (de Xplode) sur ton bureau.

    * Si problème avec le 1er lien prends le ici https://www.commentcamarche.net/telecharger/securite/2759-adwcleaner/

    * Lance le (Sous vista/seven/8 clic droit dessus,et sur exécuter en tant qu'administrateur)si tu es sous xp double cliques dessus

    * Cliques sur scanner
    * Poste le rapport de recherche C:\Adwcleaner[R]

    * Note le rapport de recherche est également sauvegardé sous C:\Adwcleaner[R1]
    0
    1. Bonjour,

      merci de cette réponse rapide.
      Alors voici le rapport:

      # AdwCleaner v3.019 - Rapport créé le 26/02/2014 à 19:26:17
      # Mis à jour le 17/02/2014 par Xplode
      # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
      # Nom d'utilisateur : mook - MOOK-PC
      # Exécuté depuis : C:\Users\mook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K732TNQF\adwcleaner.exe
      # Option : Scanner

      ***** [ Services ] *****

      ***** [ Fichiers / Dossiers ] *****

      Dossier Présent C:\Users\mook\AppData\Local\Temp\boost_interprocess

      ***** [ Raccourcis ] *****

      ***** [ Registre ] *****

      ***** [ Navigateurs ] *****

      -\\ Internet Explorer v11.0.9600.16518

      -\\ Mozilla Firefox v

      [ Fichier : C:\Users\mook\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js ]

      *************************

      AdwCleaner[R0].txt - [7728 octets] - [07/02/2014 19:14:14]
      AdwCleaner[R1].txt - [1231 octets] - [07/02/2014 19:35:58]
      AdwCleaner[R2].txt - [5344 octets] - [08/02/2014 09:53:10]
      AdwCleaner[R3].txt - [4891 octets] - [24/02/2014 22:58:42]
      AdwCleaner[R4].txt - [1028 octets] - [26/02/2014 19:26:17]
      AdwCleaner[S0].txt - [6999 octets] - [07/02/2014 19:22:23]
      AdwCleaner[S1].txt - [1257 octets] - [07/02/2014 19:48:32]
      AdwCleaner[S2].txt - [5242 octets] - [08/02/2014 09:53:44]
      AdwCleaner[S3].txt - [4583 octets] - [24/02/2014 23:00:17]

      ########## EOF - C:\AdwCleaner\AdwCleaner[R4].txt - [1328 octets] ##########
      0
      1. Contributeur sécurité
        * Télécharge ZHPDiag (de Nicolas Coolman)
        https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html ou https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/

        * Au cas où le premier lien ne marcherai pas, clique sur celui de dessous
        ftp://zebulon.fr/ZHPDiag2.exe

        * Laisse toi guider lors de l'installation, il se lancera automatiquement à la fin.

        * Surtout, n'oublie pas d'installer son icône sur le bureau l'icône est en forme de parchemin
        https://www.cjoint.com/13sp/CIvuQfap3YY_zhpdiag.png

        * A l'ouverture du logiciel il te sera proposé deux options "rechercher" et "configurer"

        * Cliques sur configurer

        * Tournevis puis tous

        * Clique sur l'icône représentant une loupe + (« Lancer le diagnostic »)

        * Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette

        * Pour héberger le rapport, rends toi sur cjoint.com
        * Clique sur choisissez un fichier va chercher le rapport dans ton PC.

        * Le rapport est hébergé:
        - Pour XP : C:\Documents and Settings\username\Local Settings\Application Data\ZHP
        - Depuis Vista : C:\Users\username\AppData\Roaming\ZHP

        * Une fois le rapport trouvé, sélectionne le, et clique sur Ouvrir

        * Choisis le type de diffusion(je te conseille privée 4 jours il sera détruit)

        * Puis cliques sur créer le lien cjoint

        * Une fois que tu auras obtenu le lien copies colle dans ta prochaine réponse

        * Pour t'aider https://www.commentcamarche.net/faq/29493-utiliser-cjoint-pour-heberger-des-fichiers
        0
        1. je ne trouve pas tournevis :s je doit être blonde
          0
          1. Contributeur sécurité
            Tu es bien sur zhpdiag?
            0
            1. excusez-moi je m'étais trompé d'icône :) donc c'est bon la ça charge
              0
              1. voilà, Est-ce ça?

                ~ Rapport de ZHPDiag v2014.2.23.20 - Nicolas Coolman (23/02/2014)
                ~ Lancé par mook (26/02/2014 19:51:27)
                ~ Adresse du Site Web https://nicolascoolman.webs.com/
                ~ Forums gratuits d'Assistance à la désinfection : https://nicolascoolman.webs.com/
                ~ Traduit par Nicolas Coolman
                ~ Etat de la version :
                ~ Liste blanche : Activée par le programme
                ~ Elévation des Privilèges : OK
                ~ User Account Control (UAC): Deactivate by program

                ---\\ Navigateurs Internet
                MSIE: Internet Explorer v11.0.9600.16518 (Defaut)

                ---\\ Informations sur les produits Windows
                ~ Langage: Français
                Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)
                Windows Server License Manager Script : OK
                ~ Windows(R) 7, OEM_SLP channel
                System Locked Preinstallation (OEM_SLP) : OK
                Windows ID Activation : OK
                ~ Windows Partial Key : 7QJB7
                Windows License : OK
                ~ Windows Remaining Initializations Number : 2
                Software Protection Service (Protection logicielle) : OK
                Windows Automatic Updates : OK
                Windows Activation Technologies : OK

                ---\\ Logiciels de protection du système
                AVG 2014 v14.0.3705
                Malwarebytes Anti-Malware version 1.75.0.1300
                Ad-Aware Antivirus v11.1.5354.0
                Windows Defender W7

                ---\\ Logiciels d'optimisation du système

                ---\\ Logiciels de partage PeerToPeer

                ---\\ Surveillance de Logiciels
                Adobe Flash Player 12 Plugin
                Adobe Reader 9.5.5 MUI

                ---\\ Informations sur le système
                ~ Processor: Intel64 Family 6 Model 37 Stepping 5, GenuineIntel
                ~ Operating System: 64 Bits
                Boot mode: Normal (Normal boot)
                Total RAM: 1972 MB (18% free)
                System Restore: Activé (Enable)
                System drive C: has 532 GB (91%) free of 583 GB

                ---\\ Mode de connexion au système
                ~ Computer Name: MOOK-PC
                ~ User Name: mook
                ~ All Users Names: mook, HomeGroupUser$, Administrateur,
                ~ Unselected Option: None
                Logged in as Administrator

                ---\\ Variables d'environnement
                ~ System Unit : C:\
                ~ %AppZHP% : C:\Users\mook\AppData\Roaming\ZHP\
                ~ %AppData% : C:\Users\mook\AppData\Roaming\
                ~ %Desktop% : C:\Users\mook\Desktop\
                ~ %Favorites% : C:\Users\mook\Favorites\
                ~ %LocalAppData% : C:\Users\mook\AppData\Local\
                ~ %StartMenu% : C:\Users\mook\AppData\Roaming\Microsoft\Windows\Start Menu\
                ~ %Windir% : C:\Windows\
                ~ %System% : C:\Windows\System32\

                ---\\ Enumération des unités disques
                C: Hard drive, Flash drive, Thumb drive (Free 532 Go of 583 Go)
                D: CD-ROM drive (Not Inserted)
                Q: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)

                ---\\ Etat du Centre de Sécurité Windows
                [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
                ~ Security Center: 49 Legitimates Filtered in 00mn 00s

                ---\\ Recherche particulière de fichiers génériques
                [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
                [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
                [MD5.263B6E451526A90FF8B1CEC759F22956] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.06/02/2014 - 10:24:52.) -- C:\Windows\System32\wininet.dll [2334208]
                [MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.20/11/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
                [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
                [MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/09/2013 - 02:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
                [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
                [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
                [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
                [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
                [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
                [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
                [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
                [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
                [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
                [MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680]
                [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
                [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
                [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
                [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
                [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
                ~ Generic Processes: Scanned in 00mn 00s

                ---\\ Etat des fichiers cachés (Caché/Total)
                ~ Mes images (My Pictures) : 1/33
                ~ Mes Favoris (My Favorites) : 1/47
                ~ Mes Documents (My Documents) : 2/14
                ~ Mon Bureau (My Desktop) : 1/246
                ~ Menu demarrer (Programs) : 1/22
                ~ Hidden Files: Scanned in 00mn 00s

                ---\\ Processus lancés
                [MD5.D1D5DAB39DCB4BE0359943738D87409B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [532040] [PID.3820]
                [MD5.2A3FB4C98F139038E23330D2439DB8A4] - (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\mook\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [PID.720]
                [MD5.2782D83D9B1071E28E2A4D9C6F5307C6] - (.NewTech Infosystems, Inc. - Acer Backup Manager.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [260608] [PID.1680]
                [MD5.B283F9A1DEABD43ACC7481F893CF21E9] - (.Dritek System Inc. - Launch Manager.) -- C:\Program Files (x86)\Launch Manager\LManager.exe [908368] [PID.2764]
                [MD5.16EE5FC85A65296FFFC4BA8BDDDD0933] - (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4962320] [PID.3120]
                [MD5.D1A7A7D193A0DDBF31F53610DBA05CAC] - (.Lavasoft - Ad-Aware Browsing Protection and Anti-Phish.) -- C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696] [PID.4156]
                [MD5.5AAA9F136A6DEC2992529F5258AE4F54] - (.Dritek System Inc. - Launch Manager Worker.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe [298064] [PID.4308]
                [MD5.6C695B04E2E29459CDC2E5C0970B883B] - (.Egis Technology Inc. - EgisUpdate Release Application.) -- C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201512] [PID.4544]
                [MD5.33E1F4D1BA2C558BAB72959EB3706C32] - (...) -- C:\Users\mook\AppData\Local\PirritSuggestor\PirritDesktop.exe [190808] [PID.4636] =>PUP.PirritSuggestor
                [MD5.4263F6C131E513CEA1AE82B5B81A4E1A] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\IEXPLORE.exe [808152] [PID.5136]
                [MD5.42FEDBCB3ED926F6F529E0FDDF750BE0] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8339968] [PID.872]
                [MD5.45982902C522F1883A2B403844CA9B07] - (.AVG Technologies CZ, s.r.o. - AVG Identity Protection Service.) -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3788816] [PID.1844]
                [MD5.B747B6BB015E552F49C634BB19540F3D] - (.AVG Technologies CZ, s.r.o. - AVG Watchdog Service.) -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008] [PID.1884]
                [MD5.E2B2853A0210D6EDAB2261870BD80C1A] - (.Dritek System Inc. - Dritek WMI Service.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe [312400] [PID.1912]
                [MD5.0191DEE9B9EB7902AF2CF4F67301095D] - (.Acer Incorporated - Global Registration Service.) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [23584] [PID.2032]
                [MD5.23DE5B62B0445A6F874BE633C95B483E] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [268824] [PID.1684]
                [MD5.65085456FD9A74D7F1A999520C299ECB] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376] [PID.1644]
                [MD5.E0D7732F2D2E24B2DB3F67B6750295B8] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512] [PID.1904]
                [MD5.5B3CE960C62DBE864BE9A0BD043A3E30] - (.NewTech Infosystems, Inc. - Backup Manager Module.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [250368] [PID.1388]
                [MD5.B5071E15D4C3F5EF5018AFF7E85A85E5] - (.NewTech Infosystems, Inc. - NTI Backup Now 5 SchedulerSvc NT Service.) -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [144640] [PID.2116]
                [MD5.8ECE08EF255693EC4B1A335FD80DC509] - (...) -- C:\Users\mook\AppData\Local\PirritSuggestor\PirritService.exe [52568] [PID.2152] =>PUP.PirritSuggestor
                [MD5.39B1D0A636A400304565D4521FAD6D77] - (.Microsoft Corporation - Microsoft Application Virtualization Virtua.) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [207528] [PID.2520]
                [MD5.F9EC9ACD504D823D9B9CA98A4F8D3CA2] - (.Acer Group - Updater Service.) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232] [PID.2652]
                [MD5.F065CD1247F838D9A88B3E86D5A9A57B] - (...) -- C:\Program Files (x86)\WinRST\WinRST.exe [59904] [PID.2732]
                [MD5.77C5A741A7452812F278EF2C18478862] - (.Microsoft Corporation - Microsoft Application Virtualization Client.) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [523944] [PID.2812]
                [MD5.FD557A50A65E44041CD2FCEF4BEB04DB] - (.Microsoft Corporation - Microsoft Office Client Virtualization Serv.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.exe [822504] [PID.3052]
                [MD5.CC3775100ABA633984F73DFAE1F55CAE] - (.Intel Corporation - User Notification Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2320920] [PID.4016]
                ~ Processes Running: Scanned in 00mn 00s

                ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
                C:\Users\mook\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js
                ~ Firefox Browser: 3 Legitimates Filtered in 00mn 00s

                ---\\ Internet Explorer, Proxy Management (R5)
                R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <local>
                R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://127.0.0.1:9880 =>Hijacker.Proxy
                R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 1
                R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
                R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
                R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
                ~ Proxy management: Scanned in 00mn 00s

                ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
                F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
                F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
                F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
                ~ Keys: Scanned in 00mn 00s

                ---\\ Hosts file redirection (O1)
                O1 - Hosts: 216.239.32.20 google.com www.google.com
                O1 - Hosts: 216.239.32.20 google.com www.google.ad
                O1 - Hosts: 216.239.32.20 google.com www.google.ae
                O1 - Hosts: 216.239.32.20 google.com www.google.com.af
                O1 - Hosts: 216.239.32.20 google.com www.google.com.ag
                O1 - Hosts: 216.239.32.20 google.com www.google.com.ai
                O1 - Hosts: 216.239.32.20 google.com www.google.al
                O1 - Hosts: 216.239.32.20 google.com www.google.am
                O1 - Hosts: 216.239.32.20 google.com www.google.co.ao
                O1 - Hosts: 216.239.32.20 google.com www.google.com.ar
                O1 - Hosts: 216.239.32.20 google.com www.google.as
                O1 - Hosts: 216.239.32.20 google.com www.google.at
                O1 - Hosts: 216.239.32.20 google.com www.google.com.au
                O1 - Hosts: 216.239.32.20 google.com www.google.az
                O1 - Hosts: 216.239.32.20 google.com www.google.ba
                O1 - Hosts: 216.239.32.20 google.com www.google.com.bd
                O1 - Hosts: 216.239.32.20 google.com www.google.be
                O1 - Hosts: 216.239.32.20 google.com www.google.bf
                O1 - Hosts: 216.239.32.20 google.com www.google.bg
                O1 - Hosts: 216.239.32.20 google.com www.google.com.bh
                O1 - Hosts: 216.239.32.20 google.com www.google.bi
                O1 - Hosts: 216.239.32.20 google.com www.google.bj
                O1 - Hosts: 216.239.32.20 google.com www.google.com.bn
                O1 - Hosts: 216.239.32.20 google.com www.google.com.bo
                O1 - Hosts: 216.239.32.20 google.com www.google.com.br
                O1 - Hosts: 216.239.32.20 google.com www.google.bs
                O1 - Hosts: 216.239.32.20 google.com www.google.bt
                O1 - Hosts: 216.239.32.20 google.com www.google.co.bw
                O1 - Hosts: 216.239.32.20 google.com www.google.by
                O1 - Hosts: 216.239.32.20 google.com www.google.com.bz
                O1 - Hosts: 216.239.32.20 google.com www.google.ca
                O1 - Hosts: 216.239.32.20 google.com www.google.cd
                O1 - Hosts: 216.239.32.20 google.com www.google.cf
                O1 - Hosts: 216.239.32.20 google.com www.google.cg
                O1 - Hosts: 216.239.32.20 google.com www.google.ch
                O1 - Hosts: 216.239.32.20 google.com www.google.ci
                O1 - Hosts: 216.239.32.20 google.com www.google.co.ck
                O1 - Hosts: 216.239.32.20 google.com www.google.cl
                O1 - Hosts: 216.239.32.20 google.com www.google.cm
                O1 - Hosts: 216.239.32.20 google.com www.google.cn
                O1 - Hosts: 216.239.32.20 google.com www.google.com.co
                O1 - Hosts: 216.239.32.20 google.com www.google.co.cr
                O1 - Hosts: 216.239.32.20 google.com www.google.com.cu
                O1 - Hosts: 216.239.32.20 google.com www.google.cv
                O1 - Hosts: 216.239.32.20 google.com www.google.com.cy
                O1 - Hosts: 216.239.32.20 google.com www.google.cz
                O1 - Hosts: 216.239.32.20 google.com www.google.de
                O1 - Hosts: 216.239.32.20 google.com www.google.dj
                O1 - Hosts: 216.239.32.20 google.com www.google.dk
                O1 - Hosts: 216.239.32.20 google.com www.google.dm
                O1 - Hosts: 216.239.32.20 google.com www.google.com.do
                O1 - Hosts: 216.239.32.20 google.com www.google.dz
                O1 - Hosts: 216.239.32.20 google.com www.google.com.ec
                O1 - Hosts: 216.239.32.20 google.com www.google.ee
                O1 - Hosts: 216.239.32.20 google.com www.google.com.eg
                O1 - Hosts: 216.239.32.20 google.com www.google.es
                O1 - Hosts: 216.239.32.20 google.com www.google.com.et
                O1 - Hosts: 216.239.32.20 google.com www.google.fi
                O1 - Hosts: 216.239.32.20 google.com www.google.com.fj
                O1 - Hosts: 216.239.32.20 google.com www.google.fm
                O1 - Hosts: 216.239.32.20 google.com www.google.fr
                O1 - Hosts: 216.239.32.20 google.com www.google.ga
                O1 - Hosts: 216.239.32.20 google.com www.google.ge
                O1 - Hosts: 216.239.32.20 google.com www.google.gg
                O1 - Hosts: 216.239.32.20 google.com www.google.com.gh
                O1 - Hosts: 216.239.32.20 google.com www.google.com.gi
                O1 - Hosts: 216.239.32.20 google.com www.google.gl
                O1 - Hosts: 216.239.32.20 google.com www.google.gm
                O1 - Hosts: 216.239.32.20 google.com www.google.gp
                O1 - Hosts: 216.239.32.20 google.com www.google.gr
                O1 - Hosts: 216.239.32.20 google.com www.google.com.gt
                O1 - Hosts: 216.239.32.20 google.com www.google.gy
                O1 - Hosts: 216.239.32.20 google.com www.google.com.hk
                O1 - Hosts: 216.239.32.20 google.com www.google.hn
                O1 - Hosts: 216.239.32.20 google.com www.google.hr
                O1 - Hosts: 216.239.32.20 google.com www.google.ht
                O1 - Hosts: 216.239.32.20 google.com www.google.hu
                O1 - Hosts: 216.239.32.20 google.com www.google.co.id
                O1 - Hosts: 216.239.32.20 google.com www.google.ie
                O1 - Hosts: 216.239.32.20 google.com www.google.co.il
                O1 - Hosts: 216.239.32.20 google.com www.google.im
                O1 - Hosts: 216.239.32.20 google.com www.google.co.in
                O1 - Hosts: 216.239.32.20 google.com www.google.iq
                O1 - Hosts: 216.239.32.20 google.com www.google.is
                O1 - Hosts: 216.239.32.20 google.com www.google.it
                O1 - Hosts: 216.239.32.20 google.com www.google.je
                O1 - Hosts: 216.239.32.20 google.com www.google.com.jm
                O1 - Hosts: 216.239.32.20 google.com www.google.jo
                O1 - Hosts: 216.239.32.20 google.com www.google.co.jp
                O1 - Hosts: 216.239.32.20 google.com www.google.co.ke
                O1 - Hosts: 216.239.32.20 google.com www.google.com.kh
                O1 - Hosts: 216.239.32.20 google.com www.google.ki
                O1 - Hosts: 216.239.32.20 google.com www.google.kg
                O1 - Hosts: 216.239.32.20 google.com www.google.co.kr
                O1 - Hosts: 216.239.32.20 google.com www.google.com.kw
                O1 - Hosts: 216.239.32.20 google.com www.google.kz
                O1 - Hosts: 216.239.32.20 google.com www.google.la
                O1 - Hosts: 216.239.32.20 google.com www.google.com.lb
                O1 - Hosts: 216.239.32.20 google.com www.google.li
                [...]
                ~ Hosts File: Scanned in 00mn 00s
                ~ Nombre de lignes (Lines number): 214

                ---\\ Browser Helper Objects de navigateur (O2)
                O2 - BHO: Adblock Plus for IE Browser Helper Object [64Bits] - {FFCB3198-32F3-4E8B-9539-4324694ED664} . (.Adblock Plus - Adblock Plus Module.) -- C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
                ~ BHO: 4 Legitimates Filtered in 00mn 00s

                ---\\ Internet Explorer Toolbars (O3)
                O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
                ~ Toolbar: Scanned in 00mn 00s

                ---\\ Autres liens utilisateurs (O4)
                O4 - GS\QuickLaunch [mook]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
                O4 - GS\TaskBar [mook]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
                O4 - GS\Program [mook]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
                O4 - GS\SystemTools [mook]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
                O4 - GS\Desktop [mook]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
                O4 - GS\Desktop [mook]: Numériser un document ou une photo - Raccourci.lnk - Clé orpheline
                ~ Global Startup: 51 Legitimates Filtered in 00mn 00s

                ---\\ Applications lancées au démarrage du sytème (O4)
                O4 - HKLM\..\Run: [AmIcoSinglun64] . (.Alcor Micro Corp. - Single LUN Icon Utility for VID 058F PID 63.) -- C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
                O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp
                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.)
                O4 - HKLM\..\Run: [Acer ePower Management] . (.Acer Incorporated - ePowerTray.) -- C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
                O4 - HKLM\..\Run: [AdAwareTray] . (...) -- C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareTray.exe
                O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\mook\AppData\Local\Facebook\Update\FacebookUpdate.exe
                O4 - HKLM\..\Wow6432Node\Run: [BackupManagerTray] . (.NewTech Infosystems, Inc. - Acer Backup Manager.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
                O4 - HKLM\..\Wow6432Node\Run: [NortonOnlineBackupReminder] . (.Symantec Corporation - Norton Online Backup Service.) -- C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe =>.Symantec Corporation
                O4 - HKLM\..\Wow6432Node\Run: [EgisUpdate] . (.Egis Technology Inc. - EgisUpdate Release Application.) -- C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
                O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe =>.Advanced Micro Devices, Inc
                O4 - HKLM\..\Wow6432Node\Run: [LManager] . (.Dritek System Inc. - Launch Manager.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
                O4 - HKLM\..\Wow6432Node\Run: [AVG_UI] . (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Program Files (x86)\AVG\AVG2014\avgui.exe
                O4 - HKLM\..\Wow6432Node\Run: [Ad-Aware Browsing Protection] . (.Lavasoft - Ad-Aware Browsing Protection and Anti-Phish.) -- C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
                O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation
                O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation
                O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
                O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
                O4 - HKUS\S-1-5-21-1276848107-3358066748-859583164-1001\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\mook\AppData\Local\Facebook\Update\FacebookUpdate.exe
                ~ Application: Scanned in 00mn 00s

                ---\\ Modification Domaine/Adresses DNS (O17)
                O17 - HKLM\System\CCS\Services\Tcpip\..\{EEE9DA09-6334-4CD3-8154-6D7DCD86692C}: DhcpNameServer = 89.2.0.1 89.2.0.2
                O17 - HKLM\System\CS1\Services\Tcpip\..\{EEE9DA09-6334-4CD3-8154-6D7DCD86692C}: DhcpNameServer = 89.2.0.1 89.2.0.2
                O17 - HKLM\System\CS2\Services\Tcpip\..\{EEE9DA09-6334-4CD3-8154-6D7DCD86692C}: DhcpNameServer = 89.2.0.1 89.2.0.2
                O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.2.0.1 89.2.0.2
                ~ Domain: Scanned in 00mn 00s

                ---\\ Protocole additionnel (O18)
                O18 - Handler: wlmailhtml [64Bits] - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (...) --
                O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
                ~ Protocole Additionnel: Scanned in 00mn 00s

                ---\\ Liste des services NT non Microsoft et non désactivés (O23)
                O23 - Service: Ad-Aware Service 11 (LavasoftAdAwareService11) . (...) - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe
                O23 - Service: PirritDesktop (PirritDesktop) . (...) - C:\Users\mook\AppData\Local\PirritSuggestor\PirritService.exe =>PUP.PirritSuggestor
                O23 - Service: WinRST (WinRST) . (...) - C:\Program Files (x86)\WinRST\WinRST.exe
                ~ Services: 17 Legitimates Filtered in 00mn 05s

                ---\\ Tâches planifiées en automatique (O39)
                O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Acer Registration - Data Sending task.job [384]
                ~ Scheduled Task: 13 Legitimates Filtered in 00mn 04s

                ---\\ Logiciels installés (O42)
                O42 - Logiciel: fst_fr_50 - (.FREESOFTTODAY.) [HKLM][64Bits] -- fst_fr_50_is1 =>PUA.FSTfr9
                ~ Logic: 20 Legitimates Filtered in 00mn 00s

                ---\\ HKCU & HKLM Software Keys
                [HKCU\Software\40594InstEnd]
                [HKCU\Software\BrowserOptout]
                [HKLM\Software\Wow6432Node\BrowserOptout]
                [HKLM\Software\Wow6432Node\RST]
                ~ Key Software: 224 Legitimates Filtered in 00mn 00s

                ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
                O43 - CFD: 06/01/2014 - 15:47:57 - [0] ----D C:\Program Files (x86)\SquirrelWeb
                O43 - CFD: 21/02/2014 - 19:13:10 - [4,679] ----D C:\Program Files (x86)\WinRST
                O43 - CFD: 04/02/2014 - 10:06:11 - [1,284] ----D C:\ProgramData\Ad-Aware Browsing Protection
                O43 - CFD: 03/12/2013 - 07:52:16 - [0] -SH-D C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
                O43 - CFD: 04/02/2014 - 10:06:01 - [0,014] ----D C:\Users\mook\AppData\Roaming\SecureSearch
                O43 - CFD: 21/02/2014 - 19:13:12 - [0] ----D C:\Users\mook\AppData\Local\WinRST
                ~ Program Folder: 151 Legitimates Filtered in 00mn 00s

                ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
                O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 24/02/2014 - 20:22:54 ---A- . (...) -- C:\autoexec.bat [0]
                ~ Files: 47 Legitimates Filtered in 00mn 02s

                ---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
                O45 - LFCP:[MD5.C31CFF884CE072B0482FF23C325A98B4] - 23/02/2014 - 07:55:03 ---A- - C:\Windows\Prefetch\PIRRITUPDATER.TMP-83F87782.pf
                O45 - LFCP:[MD5.DD481A9B1525102EC433B2B3C6338E69] - 23/02/2014 - 09:28:43 ---A- - C:\Windows\Prefetch\PIRRITUPDATER.TMP-831DC155.pf
                O45 - LFCP:[MD5.4FE4157E816FF69A3FD23F174B663E03] - 24/02/2014 - 11:01:51 ---A- - C:\Windows\Prefetch\PIRRITUPDATER.TMP-71D6DDD9.pf
                O45 - LFCP:[MD5.C2F5A685D80FAB4A8A53891771CDB731] - 24/02/2014 - 12:33:16 ---A- - C:\Windows\Prefetch\PIRRITUPDATER.TMP-E13CC987.pf
                O45 - LFCP:[MD5.44545C157B9898B51106BD140F2C3F74] - 24/02/2014 - 12:33:16 ---A- - C:\Windows\Prefetch\WINRST.EXE-7B5CE2BC.pf
                O45 - LFCP:[MD5.DFF7C96FDB550685C2D6BA2F7CEA81BA] - 24/02/2014 - 20:17:59 ---A- - C:\Windows\Prefetch\SPYHUNTER-INSTALLER.EXE-B98DF857.pf =>Crapware.SpyHunter
                O45 - LFCP:[MD5.5545ABB339D3D3A26A808484451E458A] - 24/02/2014 - 20:20:07 ---A- - C:\Windows\Prefetch\WISECUSTOMCALLA32.EXE-0AE83C6A.pf =>Crapware.SpyHunter
                O45 - LFCP:[MD5.FA590D43E426112CCBCD84010A698BC2] - 24/02/2014 - 20:20:32 ---A- - C:\Windows\Prefetch\WISECUSTOMCALLA33.EXE-1E3DF6EF.pf =>Crapware.SpyHunter
                O45 - LFCP:[MD5.36954AB7F7EBB99C19DF5BC0E19B10CE] - 24/02/2014 - 20:20:35 ---A- - C:\Windows\Prefetch\WISECUSTOMCALLA34.EXE-3193B174.pf =>Crapware.SpyHunter
                O45 - LFCP:[MD5.82AEC7D5A94E5BAE8F8A65E68318B15E] - 24/02/2014 - 20:22:10 ---A- - C:\Windows\Prefetch\ESGRKCHK.EXE-6F276CDA.pf
                O45 - LFCP:[MD5.A37C1E99BB257CECDDB3CD2885A93D35] - 24/02/2014 - 20:22:16 ---A- - C:\Windows\Prefetch\SPYHUNTER4.EXE-5B920D84.pf =>Crapware.SpyHunter
                O45 - LFCP:[MD5.97B452E1D5DDE414824FE1F6C81CA917] - 24/02/2014 - 20:41:57 ---A- - C:\Windows\Prefetch\WISECUSTOMCALLA31.EXE-F79281E5.pf =>Crapware.SpyHunter
                O45 - LFCP:[MD5.BDF535659B27930EE69FA0E0220790BA] - 24/02/2014 - 20:42:03 ---A- - C:\Windows\Prefetch\SH4SER~1.EXE-2C0BA2D0.pf
                O45 - LFCP:[MD5.4A8D506CA11D5D6492646241AFCC3D46] - 24/02/2014 - 20:42:56 ---A- - C:\Windows\Prefetch\WISECUSTOMCALLA37.EXE-6B94E103.pf =>Crapware.SpyHunter
                O45 - LFCP:[MD5.43A81DE3BC5C6524A779215E28A916F1] - 24/02/2014 - 21:07:19 ---A- - C:\Windows\Prefetch\ADAWARETRAY.EXE-9456305C.pf
                O45 - LFCP:[MD5.F10556B20AC4A865877C68DDE8FF812A] - 24/02/2014 - 21:07:28 ---A- - C:\Windows\Prefetch\ADAWAREDESKTOP.EXE-3E86EC5E.pf
                O45 - LFCP:[MD5.4AB4709BB10DA062D345F2344EF5F017] - 24/02/2014 - 21:24:12 ---A- - C:\Windows\Prefetch\_IU14D2N.TMP-8D143E9D.pf
                O45 - LFCP:[MD5.01DB8DDAB811F0324B84E7998EBB9FE3] - 26/02/2014 - 08:21:56 ---A- - C:\Windows\Prefetch\ADBLOCKPLUSENGINE.EXE-2DDB5F32.pf
                O45 - LFCP:[MD5.433269AA20E2F3DE5E2B21D41A19A51E] - 26/02/2014 - 11:00:19 ---A- - C:\Windows\Prefetch\GREG.EXE-570F7FE1.pf
                O45 - LFCP:[MD5.D2A69169961DAF68950854AA0D56D0EA] - 26/02/2014 - 11:24:37 ---A- - C:\Windows\Prefetch\PIRRITDESKTOP.EXE-97A9DAA3.pf
                ~ Prefetcher: 141 Legitimates Filtered in 00mn 00s

                ---\\ Clé de registre Shell MountPoints2 (MPKS) (O51)
                O51 - MPSK:{49a19922-3248-11e3-a585-206a8a172447}\AutoRun\command. (...) -- F:\LGAutoRun.exe (.not file.)
                ~ Keys: Scanned in 00mn 00s

                ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
                O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
                O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
                ~ MWPS: 16 Legitimates Filtered in 00mn 00s

                ---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
                O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
                ~ MWPE Keys: 3 Legitimates Filtered in 00mn 00s

                ---\\ Liste des pilotes du système (SDL) (O58)
                O58 - SDL:[MD5.2E83D2621E87C493AB45DC6655BA77D4] - 28/06/2013 - 07:35:36 ---A- . (...) -- C:\Windows\System32\Drivers\aswSnx.sys.sum [175]
                O58 - SDL:[MD5.A5F29AC2F0ADE8B995B49D7350CE3AC0] - 28/06/2013 - 07:35:36 ---A- . (...) -- C:\Windows\System32\Drivers\aswSP.sys.sum [175]
                O58 - SDL:[MD5.E86C64478D9A90D62255FE9EB0150C6E] - 28/06/2013 - 07:35:36 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys.sum [175]
                O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
                O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
                O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
                ~ Drivers: 16 Legitimates Filtered in 00mn 01s

                ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
                O61 - LFC: 24/02/2014 - 19:51:51 ---A- . (...) -- C:\Users\mook\AppData\Roaming\Lavasoft\Ad-Aware 11\Options\FirstRun [0]
                O61 - LFC: 26/02/2014 - 19:51:51 ---A- . (...) -- C:\Users\mook\AppData\Roaming\ZHP\Log.txt [67083] =>.Nicolas Coolman
                O61 - LFC: 26/02/2014 - 19:51:51 ---A- . (...) -- C:\Users\mook\AppData\Roaming\ZHP\TestsZHPDiag.txt [2826] =>.Nicolas Coolman
                O61 - LFC: 26/02/2014 - 19:51:51 ---A- . (...) -- C:\Users\mook\AppData\Roaming\ZHP\ZHPADSReport.txt [351] =>.Nicolas Coolman
                ~ 2 Fichiers temporaires (Temporary files)
                ~ Files: 31 Legitimates Filtered in 00mn 02s

                ---\\ Liste des outils de désinfection (LATC) (O63)
                O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
                ~ ADS: Scanned in 00mn 00s

                ---\\ Menu de démarrage Internet (SMI) (O68)
                O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (...) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
                ~ Keys: Scanned in 00mn 00s

                ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
                O69 - SBI: SearchScopes [HKCU] {67A2568C-7A0A-4EED-AECC-B5405DE63B64} [DefaultScope] - (Google) - https://www.google.com/?gws_rd=ssl
                O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - https://www.google.com/?gws_rd=ssl
                ~ Keys: Scanned in 00mn 00s

                ---\\ Recherche particulière à la racine du système (SPRF) (O84)
                [MD5.6ACBD475647D7A160657CB3E460F0F35] [SPRF][27/01/2010] (...) -- C:\ProgramData\FullRemove.exe [131472]
                ~ Files: 1 Legitimates Filtered in 00mn 00s

                ---\\ Liste des exceptions du parefeu (FirewallRules) (O87)
                O87 - FAEL: "{5BD7D331-4BCB-4DC2-9838-530A07BA6F51}" | In - Private - P6 - TRUE | .(.Visicom Media Inc. - DtUser.) -- C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe
                O87 - FAEL: "{5B972662-0EDE-4F35-AAD4-EA40E9A73238}" | In - Private - P17 - TRUE | .(.Visicom Media Inc. - DtUser.) -- C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe
                ~ Firewall: 201 Legitimates Filtered in 00mn 00s

                ---\\ Enumère les codes produits des logiciels (PUC) (O90)
                O90 - PUC: "24BED006A334FA04CB4180E20475B72F" . (.AntimalwareEngine.) -- C:\Windows\Installer\{600DEB42-433A-40AF-BC14-082E40577BF2}\ARPPRODUCTICON.exe
                O90 - PUC: "5ADA61A603B0398448BA69B131041DA4" . (.AdAwareUpdater.) -- C:\Windows\Installer\{6A16ADA5-0B30-4893-84AB-961B1340D14A}\ARPPRODUCTICON.exe
                O90 - PUC: "A216D7CA50898BB48AACC4FC3E164B7B" . (.AdAwareInstaller.) -- C:\Windows\Installer\{AC7D612A-9805-4BB8-A8CA-4CCFE361B4B7}\ARPPRODUCTICON.exe
                ~ Update Products: 86 Legitimates Filtered in 00mn 00s

                ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
                SS - | Demand 21/02/2014 257928 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
                SS - | Demand 15/06/2013 194032 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
                SS - | Demand 06/11/2009 50432 | (NTIBackupSvc) . (.NewTech InfoSystems, Inc..) - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
                SS - | Auto 23/10/2013 172192 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
                SS - | Demand 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

                SR - | Auto 22/01/2010 202752 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
                SR - | Auto 22/01/2014 3788816 | (AVGIDSAgent) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
                SR - | Auto 24/09/2013 348008 | (avgwd) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
                SR - | Auto 08/04/2010 312400 | (DsiWMIService) . (.Dritek System Inc..) - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
                SR - | Auto 23/04/2010 867360 | (ePowerSvc) . (.Acer Incorporated.) - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
                SR - | Auto 08/01/2010 23584 | (GREGService) . (.Acer Incorporated.) - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
                SR - | Auto 23/01/2014 702744 | (LavasoftAdAwareService11) . (...) - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe
                SR - | Auto 03/03/2010 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
                SR - | Auto 04/04/2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
                SR - | Auto 04/04/2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
                SR - | Auto 09/03/2010 250368 | (NTI IScheduleSvc) . (.NewTech Infosystems, Inc..) - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
                SR - | Auto 06/11/2009 144640 | (NTISchedulerSvc) . (.NewTech Infosystems, Inc..) - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
                SR - | Auto 14/02/2014 52568 | (PirritDesktop) . (...) - C:\Users\mook\AppData\Local\PirritSuggestor\PirritService.exe =>PUP.PirritSuggestor
                SR - | Auto 03/03/2010 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
                SR - | Auto 29/01/2010 243232 | (Updater Service) . (.Acer Group.) - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
                SR - | Auto 21/02/2014 59904 | (WinRST) . (...) - C:\Program Files (x86)\WinRST\WinRST.exe
                SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
                SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

                ~ Services: Scanned in 00mn 22s

                ---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
                Run by mook at 26/02/2014 19:52:21
                ~ OS 64 not supported by MBR tool

                ~ MBR: 0 Legitimates Filtered in 00mn 00s

                ---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
                Written by ad13, http://ad13.geekstog
                Run by mook at 26/02/2014 19:52:23

                ********* Dump file Name *********
                C:\PhysicalDisk0_MBR.bin

                ~ MBR: Scanned in 00mn 02s

                ---\\ Scan Additionnel (O88)
                Database Version : 13031 - (23/02/2014)
                Clés trouvées (Keys found) : 3
                Valeurs trouvées (Values found) : 0
                Dossiers trouvés (Folders found) : 0
                Fichiers trouvés (Files found) : 5

                [HKLM\SYSTEM\CurrentControlSet\Services\PirritDesktop] =>PUP.PirritSuggestor^
                [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\fst_fr_50_is1] =>PUA.FSTfr9^
                [HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6c97a91e-4524-4019-86af-2aa2d567bf5c}] =>Toolbar.AdAware
                C:\Users\mook\AppData\Local\PirritSuggestor\PirritDesktop.exe =>PUP.PirritSuggestor^
                C:\Users\mook\AppData\Local\PirritSuggestor\PirritService.exe =>PUP.PirritSuggestor^
                C:\Users\mook\AppData\Local\Temp\uninst1.exe =>PUP.Babylon
                C:\Users\mook\AppData\Local\Temp\GoogleToolbarInstaller1.log =>PUP.Babylon
                ~ Additionnel Scan: 201963 Items scanned in 00mn 28s

                ---\\ Récapitulatif des détections trouvées sur votre station
                ~ http://nicolascoolman.webs.com/apps/blog/show/41590424-pup-pirritsuggestor =>PUP.PirritSuggestor
                ~ http://nicolascoolman.webs.com/apps/blog/show/27232411-hijacker-proxy =>Hijacker.Proxy
                ~ http://nicolascoolman.webs.com/apps/blog/show/34014358-pua-fstfr9 =>PUA.FSTfr9
                ~ http://nicolascoolman.webs.com/apps/blog/show/26609241-crapware-spyhunter =>Crapware.SpyHunter
                ~ http://nicolascoolman.webs.com/apps/blog/show/26627369-toolbar-babylon =>PUP.Babylon
                ~ MSI: 5 link(s) detected in 00mn 28s

                ~ 1202 Legitimates filtered by white list
                End of the scan (573 lines in 01mn 25s)(0)
                0
                1. bon ben j'attends votre réponse.
                  0
                  1. Contributeur sécurité
                    Hello

                    Parfait mais ça aurait été mieux hébergé

                    En deux étapes

                    On va restaurer ton fichier host avec Rsthost

                    => http://general-changelog-team.fr/fr/downloads/view.download/10

                    * Télécharge sur le bureau RogueKiller

                    * Quitte tous tes programmes en cours.

                    * Sous Vista/Seven et windows 8 , clique droit -> lancer en tant qu'administrateur

                    * Sinon lance simplement RogueKiller.exe

                    * Patiente pendant le pre-scan, puis clique sur le bouton Scan

                    * Un rapport RKreport.txt a du se créer sur le bureau, poste-le.

                    Note : Si le programme a été bloqué, ne pas hésiter à essayer plusieurs fois.

                    0
                    1. voilà

                      RogueKiller V8.8.9 [Feb 24 2014] par Tigzy
                      mail : tigzyRK<at>gmail<dot>com
                      Remontees : https://forum.adlice.com/
                      Site Web : http://www.surlatoile.org/RogueKiller/
                      Blog : https://www.adlice.com/

                      Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
                      Demarrage : Mode normal
                      Utilisateur : mook [Droits d'admin]
                      Mode : Recherche -- Date : 02/26/2014 21:57:38
                      | ARK || FAK || MBR |

                      ¤¤¤ Processus malicieux : 2 ¤¤¤
                      [SUSP PATH] PirritService.exe -- C:\Users\mook\AppData\Local\PirritSuggestor\PirritService.exe [7] -> TUÉ [TermProc]
                      [SUSP PATH] PirritDesktop.exe -- C:\Users\mook\AppData\Local\PirritSuggestor\PirritDesktop.exe [7] -> TUÉ [TermProc]

                      ¤¤¤ Entrees de registre : 4 ¤¤¤
                      [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (hxxp=hxxp://127.0.0.1:9880 [Country: , City: ]) -> TROUVÉ
                      [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyEnable (1) -> TROUVÉ
                      [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> TROUVÉ
                      [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ

                      ¤¤¤ Tâches planifiées : 0 ¤¤¤

                      ¤¤¤ Entrées Startup : 0 ¤¤¤

                      ¤¤¤ Navigateurs web : 0 ¤¤¤

                      ¤¤¤ Addons navigateur : 0 ¤¤¤

                      ¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

                      ¤¤¤ Driver : [NON CHARGE 0x0] ¤¤¤

                      ¤¤¤ Ruches Externes: ¤¤¤

                      ¤¤¤ Infection : Mal.Hosts ¤¤¤

                      ¤¤¤ Fichier HOSTS: ¤¤¤
                      --> %SystemRoot%\System32\drivers\etc\hosts

                      216.239.32.20 google.com www.google.com --> Potentially malicious!

                      216.239.32.20 google.com www.google.com
                      216.239.32.20 google.com www.google.ad
                      216.239.32.20 google.com www.google.ae
                      216.239.32.20 google.com www.google.com.af
                      216.239.32.20 google.com www.google.com.ag
                      216.239.32.20 google.com www.google.com.ai
                      216.239.32.20 google.com www.google.al
                      216.239.32.20 google.com www.google.am
                      216.239.32.20 google.com www.google.co.ao
                      216.239.32.20 google.com www.google.com.ar
                      216.239.32.20 google.com www.google.as
                      216.239.32.20 google.com www.google.at
                      216.239.32.20 google.com www.google.com.au
                      216.239.32.20 google.com www.google.az
                      216.239.32.20 google.com www.google.ba
                      216.239.32.20 google.com www.google.com.bd
                      216.239.32.20 google.com www.google.be
                      216.239.32.20 google.com www.google.bf
                      216.239.32.20 google.com www.google.bg
                      216.239.32.20 google.com www.google.com.bh
                      [...]

                      ¤¤¤ MBR Verif: ¤¤¤

                      +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) SAMSUNG HN-M640MBB +++++
                      --- User ---
                      [MBR] 1fd4deb77772fd53b19fb6e343470649
                      [BSP] 14fc8064d49f6e67310296ae415edfc1 : Windows Vista MBR Code
                      Partition table:
                      0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 13500 Mo
                      1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 27650048 | Size: 100 Mo
                      2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 27854848 | Size: 596878 Mo
                      User = LL1 ... OK!
                      User = LL2 ... OK!

                      Termine : << RKreport[0]_S_02262014_215738.txt >>
                      0
                      1. Contributeur sécurité
                        * Quitte tous tes programmes en cours

                        * Sous Vista/Seven , clique droit -> lancer en tant qu'administrateur

                        * Sinon lance simplement RogueKiller.exe

                        * Patiente pendant le pre-scan, clique sur Scan

                        * Vérifie que tous les éléments sont cochés puis clique sur Suppression

                        * Poste le rapport RKreport.txt présent sur le bureau.

                        HOST RAZ aussi
                        0
                        1. Désolé du temps, je n'ai plus accès à internet à chaque scan :/ 'plus de proxis...
                          voici le rapport,

                          RogueKiller V8.8.9 [Feb 24 2014] par Tigzy
                          mail : tigzyRK<at>gmail<dot>com
                          Remontees : https://forum.adlice.com/
                          Site Web : http://www.surlatoile.org/RogueKiller/
                          Blog : https://www.adlice.com/

                          Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
                          Demarrage : Mode normal
                          Utilisateur : mook [Droits d'admin]
                          Mode : Recherche -- Date : 02/26/2014 22:20:55
                          | ARK || FAK || MBR |

                          ¤¤¤ Processus malicieux : 2 ¤¤¤
                          [SUSP PATH] PirritService.exe -- C:\Users\mook\AppData\Local\PirritSuggestor\PirritService.exe [7] -> TUÉ [TermProc]
                          [SUSP PATH] PirritDesktop.exe -- C:\Users\mook\AppData\Local\PirritSuggestor\PirritDesktop.exe [7] -> TUÉ [TermProc]

                          ¤¤¤ Entrees de registre : 4 ¤¤¤
                          [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (hxxp=hxxp://127.0.0.1:9880 [Country: , City: ]) -> TROUVÉ
                          [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyEnable (1) -> TROUVÉ
                          [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> TROUVÉ
                          [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ

                          ¤¤¤ Tâches planifiées : 0 ¤¤¤

                          ¤¤¤ Entrées Startup : 0 ¤¤¤

                          ¤¤¤ Navigateurs web : 0 ¤¤¤

                          ¤¤¤ Addons navigateur : 0 ¤¤¤

                          ¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

                          ¤¤¤ Driver : [NON CHARGE 0x0] ¤¤¤

                          ¤¤¤ Ruches Externes: ¤¤¤

                          ¤¤¤ Infection : Mal.Hosts ¤¤¤

                          ¤¤¤ Fichier HOSTS: ¤¤¤
                          --> %SystemRoot%\System32\drivers\etc\hosts

                          216.239.32.20 google.com www.google.com --> Potentially malicious!

                          216.239.32.20 google.com www.google.com
                          216.239.32.20 google.com www.google.ad
                          216.239.32.20 google.com www.google.ae
                          216.239.32.20 google.com www.google.com.af
                          216.239.32.20 google.com www.google.com.ag
                          216.239.32.20 google.com www.google.com.ai
                          216.239.32.20 google.com www.google.al
                          216.239.32.20 google.com www.google.am
                          216.239.32.20 google.com www.google.co.ao
                          216.239.32.20 google.com www.google.com.ar
                          216.239.32.20 google.com www.google.as
                          216.239.32.20 google.com www.google.at
                          216.239.32.20 google.com www.google.com.au
                          216.239.32.20 google.com www.google.az
                          216.239.32.20 google.com www.google.ba
                          216.239.32.20 google.com www.google.com.bd
                          216.239.32.20 google.com www.google.be
                          216.239.32.20 google.com www.google.bf
                          216.239.32.20 google.com www.google.bg
                          216.239.32.20 google.com www.google.com.bh
                          [...]

                          ¤¤¤ MBR Verif: ¤¤¤

                          +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) SAMSUNG HN-M640MBB +++++
                          --- User ---
                          [MBR] 1fd4deb77772fd53b19fb6e343470649
                          [BSP] 14fc8064d49f6e67310296ae415edfc1 : Windows Vista MBR Code
                          Partition table:
                          0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 13500 Mo
                          1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 27650048 | Size: 100 Mo
                          2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 27854848 | Size: 596878 Mo
                          User = LL1 ... OK!
                          User = LL2 ... OK!

                          Termine : << RKreport[0]_S_02262014_222055.txt >>
                          RKreport[0]_S_02262014_215738.txt
                          0
                          1. Contributeur sécurité
                            Hello

                            Il suffit de décocher me connecter avec un proxy :)

                            Fais HOST RAZ
                            0
                            1. bonjour,

                              ah oui effectivement la case "se connecter avec un proxy" était coché alors que je n'ai jamais touché à cela.
                              Et excusez-moi j'avais pas vu cette manipulation à faire, donc voilà le rapport:

                              RogueKiller V8.8.9 [Feb 24 2014] par Tigzy
                              mail : tigzyRK<at>gmail<dot>com
                              Remontees : https://forum.adlice.com/
                              Site Web : http://www.surlatoile.org/RogueKiller/
                              Blog : https://www.adlice.com/

                              Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
                              Demarrage : Mode normal
                              Utilisateur : mook [Droits d'admin]
                              Mode : HOSTS RAZ -- Date : 02/27/2014 07:37:18
                              | ARK || FAK || MBR |

                              ¤¤¤ Processus malicieux : 0 ¤¤¤

                              ¤¤¤ Entrees de registre : 0 ¤¤¤

                              ¤¤¤ Driver : [NON CHARGE 0x0] ¤¤¤

                              ¤¤¤ Ruches Externes: ¤¤¤

                              ¤¤¤ Infection : Mal.Hosts ¤¤¤

                              ¤¤¤ Fichier HOSTS: ¤¤¤
                              --> %SystemRoot%\System32\drivers\etc\hosts

                              216.239.32.20 google.com www.google.com --> Potentially malicious!

                              216.239.32.20 google.com www.google.com
                              216.239.32.20 google.com www.google.ad
                              216.239.32.20 google.com www.google.ae
                              216.239.32.20 google.com www.google.com.af
                              216.239.32.20 google.com www.google.com.ag
                              216.239.32.20 google.com www.google.com.ai
                              216.239.32.20 google.com www.google.al
                              216.239.32.20 google.com www.google.am
                              216.239.32.20 google.com www.google.co.ao
                              216.239.32.20 google.com www.google.com.ar
                              216.239.32.20 google.com www.google.as
                              216.239.32.20 google.com www.google.at
                              216.239.32.20 google.com www.google.com.au
                              216.239.32.20 google.com www.google.az
                              216.239.32.20 google.com www.google.ba
                              216.239.32.20 google.com www.google.com.bd
                              216.239.32.20 google.com www.google.be
                              216.239.32.20 google.com www.google.bf
                              216.239.32.20 google.com www.google.bg
                              216.239.32.20 google.com www.google.com.bh
                              [...]

                              ¤¤¤ Nouveau fichier HOSTS: ¤¤¤
                              127.0.0.1 localhost

                              Termine : << RKreport[0]_H_02272014_073718.txt >>
                              RKreport[0]_D_02262014_222123.txt;RKreport[0]_S_02262014_215738.txt;RKreport[0]_S_02262014_222055.txt
                              RKreport[0]_S_02272014_072913.txt;RKreport[0]_S_02272014_073657.txt
                              0
                              1. Contributeur sécurité
                                :)

                                Toujours sur Roguekiller fais Proxy raz

                                Ensuite Refais un zhpdiag :)

                                Si problème il y a il existe toujours une solution
                                ~~~~~~ Cs ~~~~~~
                                0
                                1. je vous donne toujours les rapports?
                                  0
                                  1. Voici celui avec Proxy Raz:

                                    RogueKiller V8.8.9 [Feb 24 2014] par Tigzy
                                    mail : tigzyRK<at>gmail<dot>com
                                    Remontees : https://forum.adlice.com/
                                    Site Web : http://www.surlatoile.org/RogueKiller/
                                    Blog : https://www.adlice.com/

                                    Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
                                    Demarrage : Mode normal
                                    Utilisateur : mook [Droits d'admin]
                                    Mode : Proxy RAZ -- Date : 02/27/2014 08:01:14
                                    | ARK || FAK || MBR |

                                    ¤¤¤ Processus malicieux : 0 ¤¤¤

                                    ¤¤¤ Entrees de registre : 1 ¤¤¤
                                    [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (hxxp=hxxp://127.0.0.1:9881 [Country: (Private Address) (XX), City: (Private Address)]) -> SUPPRIMÉ

                                    ¤¤¤ Navigateurs web : 0 ¤¤¤

                                    ¤¤¤ Driver : [NON CHARGE 0x0] ¤¤¤

                                    ¤¤¤ Ruches Externes: ¤¤¤

                                    ¤¤¤ Infection : Mal.Hosts ¤¤¤

                                    Termine : << RKreport[0]_PR_02272014_080114.txt >>
                                    RKreport[0]_D_02262014_222123.txt;RKreport[0]_H_02272014_073718.txt;RKreport[0]_S_02262014_215738.txt
                                    RKreport[0]_S_02262014_222055.txt;RKreport[0]_S_02272014_072913.txt;RKreport[0]_S_02272014_073657.txt

                                    ainsi de celui de ZHP

                                    ~ Rapport de ZHPDiag v2014.2.23.20 - Nicolas Coolman (23/02/2014)
                                    ~ Lancé par mook (27/02/2014 08:02:36)
                                    ~ Adresse du Site Web https://nicolascoolman.webs.com/
                                    ~ Forums gratuits d'Assistance à la désinfection : https://nicolascoolman.webs.com/
                                    ~ Traduit par Nicolas Coolman
                                    ~ Etat de la version :
                                    ~ Liste blanche : Activée par le programme
                                    ~ Elévation des Privilèges : OK
                                    ~ User Account Control (UAC): Activate by user

                                    ---\\ Navigateurs Internet
                                    MSIE: Internet Explorer v11.0.9600.16518 (Defaut)

                                    ---\\ Informations sur les produits Windows
                                    ~ Langage: Français
                                    Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)
                                    Windows Server License Manager Script : OK
                                    ~ Windows(R) 7, OEM_SLP channel
                                    System Locked Preinstallation (OEM_SLP) : OK
                                    Windows ID Activation : OK
                                    ~ Windows Partial Key : 7QJB7
                                    Windows License : OK
                                    ~ Windows Remaining Initializations Number : 2
                                    Software Protection Service (Protection logicielle) : OK
                                    Windows Automatic Updates : OK
                                    Windows Activation Technologies : OK

                                    ---\\ Logiciels de protection du système
                                    AVG 2014 v14.0.3705
                                    Malwarebytes Anti-Malware version 1.75.0.1300
                                    Ad-Aware Antivirus v11.1.5354.0
                                    Windows Defender W7

                                    ---\\ Logiciels d'optimisation du système

                                    ---\\ Logiciels de partage PeerToPeer

                                    ---\\ Surveillance de Logiciels
                                    Adobe Flash Player 12 Plugin
                                    Adobe Reader 9.5.5 MUI

                                    ---\\ Informations sur le système
                                    ~ Processor: Intel64 Family 6 Model 37 Stepping 5, GenuineIntel
                                    ~ Operating System: 64 Bits
                                    Boot mode: Normal (Normal boot)
                                    Total RAM: 1972 MB (29% free)
                                    System Restore: Activé (Enable)
                                    System drive C: has 534 GB (91%) free of 583 GB

                                    ---\\ Mode de connexion au système
                                    ~ Computer Name: MOOK-PC
                                    ~ User Name: mook
                                    ~ All Users Names: mook, HomeGroupUser$, Administrateur,
                                    ~ Unselected Option: None
                                    Logged in as Administrator

                                    ---\\ Variables d'environnement
                                    ~ System Unit : C:\
                                    ~ %AppZHP% : C:\Users\mook\AppData\Roaming\ZHP\
                                    ~ %AppData% : C:\Users\mook\AppData\Roaming\
                                    ~ %Desktop% : C:\Users\mook\Desktop\
                                    ~ %Favorites% : C:\Users\mook\Favorites\
                                    ~ %LocalAppData% : C:\Users\mook\AppData\Local\
                                    ~ %StartMenu% : C:\Users\mook\AppData\Roaming\Microsoft\Windows\Start Menu\
                                    ~ %Windir% : C:\Windows\
                                    ~ %System% : C:\Windows\System32\

                                    ---\\ Enumération des unités disques
                                    C: Hard drive, Flash drive, Thumb drive (Free 534 Go of 583 Go)
                                    D: CD-ROM drive (Not Inserted)
                                    Q: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)

                                    ---\\ Etat du Centre de Sécurité Windows
                                    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
                                    ~ Security Center: 49 Legitimates Filtered in 00mn 00s

                                    ---\\ Recherche particulière de fichiers génériques
                                    [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
                                    [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
                                    [MD5.263B6E451526A90FF8B1CEC759F22956] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.06/02/2014 - 10:24:52.) -- C:\Windows\System32\wininet.dll [2334208]
                                    [MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.20/11/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
                                    [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
                                    [MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/09/2013 - 02:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
                                    [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
                                    [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
                                    [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
                                    [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
                                    [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
                                    [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
                                    [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
                                    [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
                                    [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
                                    [MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680]
                                    [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
                                    [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
                                    [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
                                    [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
                                    [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
                                    ~ Generic Processes: Scanned in 00mn 08s

                                    ---\\ Etat des fichiers cachés (Caché/Total)
                                    ~ Mes images (My Pictures) : 1/33
                                    ~ Mes Favoris (My Favorites) : 1/48
                                    ~ Mes Documents (My Documents) : 2/14
                                    ~ Mon Bureau (My Desktop) : 1/258
                                    ~ Menu demarrer (Programs) : 1/22
                                    ~ Hidden Files: Scanned in 00mn 01s

                                    ---\\ Processus lancés
                                    [MD5.D1D5DAB39DCB4BE0359943738D87409B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [532040] [PID.2996]
                                    [MD5.2A3FB4C98F139038E23330D2439DB8A4] - (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\mook\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [PID.3912]
                                    [MD5.2782D83D9B1071E28E2A4D9C6F5307C6] - (.NewTech Infosystems, Inc. - Acer Backup Manager.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [260608] [PID.3948]
                                    [MD5.B283F9A1DEABD43ACC7481F893CF21E9] - (.Dritek System Inc. - Launch Manager.) -- C:\Program Files (x86)\Launch Manager\LManager.exe [908368] [PID.2364]
                                    [MD5.16EE5FC85A65296FFFC4BA8BDDDD0933] - (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4962320] [PID.1436]
                                    [MD5.D1A7A7D193A0DDBF31F53610DBA05CAC] - (.Lavasoft - Ad-Aware Browsing Protection and Anti-Phish.) -- C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696] [PID.3996]
                                    [MD5.5AAA9F136A6DEC2992529F5258AE4F54] - (.Dritek System Inc. - Launch Manager Worker.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe [298064] [PID.4144]
                                    [MD5.6C695B04E2E29459CDC2E5C0970B883B] - (.Egis Technology Inc. - EgisUpdate Release Application.) -- C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201512] [PID.4496]
                                    [MD5.4263F6C131E513CEA1AE82B5B81A4E1A] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\IEXPLORE.exe [808152] [PID.5164]
                                    [MD5.42FEDBCB3ED926F6F529E0FDDF750BE0] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8339968] [PID.11160]
                                    [MD5.45982902C522F1883A2B403844CA9B07] - (.AVG Technologies CZ, s.r.o. - AVG Identity Protection Service.) -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3788816] [PID.1824]
                                    [MD5.B747B6BB015E552F49C634BB19540F3D] - (.AVG Technologies CZ, s.r.o. - AVG Watchdog Service.) -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008] [PID.1852]
                                    [MD5.E2B2853A0210D6EDAB2261870BD80C1A] - (.Dritek System Inc. - Dritek WMI Service.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe [312400] [PID.1880]
                                    [MD5.0191DEE9B9EB7902AF2CF4F67301095D] - (.Acer Incorporated - Global Registration Service.) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [23584] [PID.2012]
                                    [MD5.23DE5B62B0445A6F874BE633C95B483E] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [268824] [PID.1376]
                                    [MD5.65085456FD9A74D7F1A999520C299ECB] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376] [PID.1664]
                                    [MD5.E0D7732F2D2E24B2DB3F67B6750295B8] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512] [PID.1608]
                                    [MD5.5B3CE960C62DBE864BE9A0BD043A3E30] - (.NewTech Infosystems, Inc. - Backup Manager Module.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [250368] [PID.1180]
                                    [MD5.B5071E15D4C3F5EF5018AFF7E85A85E5] - (.NewTech Infosystems, Inc. - NTI Backup Now 5 SchedulerSvc NT Service.) -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [144640] [PID.2064]
                                    [MD5.39B1D0A636A400304565D4521FAD6D77] - (.Microsoft Corporation - Microsoft Application Virtualization Virtua.) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [207528] [PID.2444]
                                    [MD5.F9EC9ACD504D823D9B9CA98A4F8D3CA2] - (.Acer Group - Updater Service.) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232] [PID.2592]
                                    [MD5.F065CD1247F838D9A88B3E86D5A9A57B] - (...) -- C:\Program Files (x86)\WinRST\WinRST.exe [59904] [PID.2640]
                                    [MD5.77C5A741A7452812F278EF2C18478862] - (.Microsoft Corporation - Microsoft Application Virtualization Client.) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [523944] [PID.2732]
                                    [MD5.FD557A50A65E44041CD2FCEF4BEB04DB] - (.Microsoft Corporation - Microsoft Office Client Virtualization Serv.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.exe [822504] [PID.3632]
                                    [MD5.CC3775100ABA633984F73DFAE1F55CAE] - (.Intel Corporation - User Notification Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2320920] [PID.4344]
                                    [MD5.3EBF71D22F8B2035026B66A5BDFD4A9B] - (...) -- C:\Users\mook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UJ5N5W3U\RogueKiller.exe [3818496] [PID.4088]
                                    [MD5.E87213F37A13E2B54391E40934F071D0] - (.Microsoft Corporation - .NET Runtime Optimization Service.) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [105144] [PID.11368]
                                    ~ Processes Running: Scanned in 00mn 01s

                                    ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
                                    C:\Users\mook\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js
                                    ~ Firefox Browser: 3 Legitimates Filtered in 00mn 00s

                                    ---\\ Internet Explorer, Proxy Management (R5)
                                    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <local>
                                    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
                                    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
                                    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
                                    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
                                    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
                                    ~ Proxy management: Scanned in 00mn 00s

                                    ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
                                    F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
                                    F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
                                    F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
                                    ~ Keys: Scanned in 00mn 00s

                                    ---\\ Hosts file redirection (O1)
                                    ~ Le fichier hosts est sain (The hosts file is clean).
                                    ~ Hosts File: Scanned in 00mn 00s
                                    ~ Nombre de lignes (Lines number): 19

                                    ---\\ Browser Helper Objects de navigateur (O2)
                                    O2 - BHO: Adblock Plus for IE Browser Helper Object [64Bits] - {FFCB3198-32F3-4E8B-9539-4324694ED664} . (.Adblock Plus - Adblock Plus Module.) -- C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
                                    ~ BHO: 4 Legitimates Filtered in 00mn 00s

                                    ---\\ Internet Explorer Toolbars (O3)
                                    O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
                                    ~ Toolbar: Scanned in 00mn 00s

                                    ---\\ Autres liens utilisateurs (O4)
                                    O4 - GS\QuickLaunch [mook]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                    O4 - GS\TaskBar [mook]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
                                    O4 - GS\Program [mook]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
                                    O4 - GS\SystemTools [mook]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
                                    O4 - GS\Desktop [mook]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
                                    O4 - GS\Desktop [mook]: Numériser un document ou une photo - Raccourci.lnk - Clé orpheline
                                    ~ Global Startup: 51 Legitimates Filtered in 00mn 04s

                                    ---\\ Applications lancées au démarrage du sytème (O4)
                                    O4 - HKLM\..\Run: [AmIcoSinglun64] . (.Alcor Micro Corp. - Single LUN Icon Utility for VID 058F PID 63.) -- C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
                                    O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp
                                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.)
                                    O4 - HKLM\..\Run: [Acer ePower Management] . (.Acer Incorporated - ePowerTray.) -- C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
                                    O4 - HKLM\..\Run: [AdAwareTray] . (...) -- C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareTray.exe
                                    O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\mook\AppData\Local\Facebook\Update\FacebookUpdate.exe
                                    O4 - HKLM\..\Wow6432Node\Run: [BackupManagerTray] . (.NewTech Infosystems, Inc. - Acer Backup Manager.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
                                    O4 - HKLM\..\Wow6432Node\Run: [NortonOnlineBackupReminder] . (.Symantec Corporation - Norton Online Backup Service.) -- C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe =>.Symantec Corporation
                                    O4 - HKLM\..\Wow6432Node\Run: [EgisUpdate] . (.Egis Technology Inc. - EgisUpdate Release Application.) -- C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
                                    O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe =>.Advanced Micro Devices, Inc
                                    O4 - HKLM\..\Wow6432Node\Run: [LManager] . (.Dritek System Inc. - Launch Manager.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
                                    O4 - HKLM\..\Wow6432Node\Run: [AVG_UI] . (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Program Files (x86)\AVG\AVG2014\avgui.exe
                                    O4 - HKLM\..\Wow6432Node\Run: [Ad-Aware Browsing Protection] . (.Lavasoft - Ad-Aware Browsing Protection and Anti-Phish.) -- C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
                                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
                                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
                                    O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation
                                    O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation
                                    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
                                    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
                                    O4 - HKUS\S-1-5-21-1276848107-3358066748-859583164-1001\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\mook\AppData\Local\Facebook\Update\FacebookUpdate.exe
                                    ~ Application: Scanned in 00mn 00s

                                    ---\\ Modification Domaine/Adresses DNS (O17)
                                    O17 - HKLM\System\CCS\Services\Tcpip\..\{EEE9DA09-6334-4CD3-8154-6D7DCD86692C}: DhcpNameServer = 89.2.0.1 89.2.0.2
                                    O17 - HKLM\System\CS1\Services\Tcpip\..\{EEE9DA09-6334-4CD3-8154-6D7DCD86692C}: DhcpNameServer = 89.2.0.1 89.2.0.2
                                    O17 - HKLM\System\CS2\Services\Tcpip\..\{EEE9DA09-6334-4CD3-8154-6D7DCD86692C}: DhcpNameServer = 89.2.0.1 89.2.0.2
                                    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.2.0.1 89.2.0.2
                                    ~ Domain: Scanned in 00mn 00s

                                    ---\\ Protocole additionnel (O18)
                                    O18 - Handler: wlmailhtml [64Bits] - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (...) --
                                    O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
                                    ~ Protocole Additionnel: Scanned in 00mn 00s

                                    ---\\ Liste des services NT non Microsoft et non désactivés (O23)
                                    O23 - Service: Ad-Aware Service 11 (LavasoftAdAwareService11) . (...) - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe
                                    O23 - Service: PirritDesktop (PirritDesktop) . (...) - C:\Users\mook\AppData\Local\PirritSuggestor\PirritService.exe =>PUP.PirritSuggestor
                                    O23 - Service: WinRST (WinRST) . (...) - C:\Program Files (x86)\WinRST\WinRST.exe
                                    ~ Services: 17 Legitimates Filtered in 00mn 07s

                                    ---\\ Tâches planifiées en automatique (O39)
                                    O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Acer Registration - Data Sending task.job [384]
                                    ~ Scheduled Task: 13 Legitimates Filtered in 00mn 07s

                                    ---\\ Logiciels installés (O42)
                                    O42 - Logiciel: fst_fr_50 - (.FREESOFTTODAY.) [HKLM][64Bits] -- fst_fr_50_is1 =>PUA.FSTfr9
                                    ~ Logic: 20 Legitimates Filtered in 00mn 00s

                                    ---\\ HKCU & HKLM Software Keys
                                    [HKCU\Software\40594InstEnd]
                                    [HKCU\Software\BrowserOptout]
                                    [HKLM\Software\Wow6432Node\BrowserOptout]
                                    [HKLM\Software\Wow6432Node\RST]
                                    ~ Key Software: 224 Legitimates Filtered in 00mn 00s

                                    ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
                                    O43 - CFD: 06/01/2014 - 15:47:57 - [0] ----D C:\Program Files (x86)\SquirrelWeb
                                    O43 - CFD: 21/02/2014 - 19:13:10 - [4,679] ----D C:\Program Files (x86)\WinRST
                                    O43 - CFD: 04/02/2014 - 10:06:11 - [1,284] ----D C:\ProgramData\Ad-Aware Browsing Protection
                                    O43 - CFD: 03/12/2013 - 07:52:16 - [0] -SH-D C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
                                    O43 - CFD: 04/02/2014 - 10:06:01 - [0,014] ----D C:\Users\mook\AppData\Roaming\SecureSearch
                                    O43 - CFD: 21/02/2014 - 19:13:12 - [0] ----D C:\Users\mook\AppData\Local\WinRST
                                    ~ Program Folder: 151 Legitimates Filtered in 01mn 32s

                                    ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
                                    O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 24/02/2014 - 20:22:54 ---A- . (...) -- C:\autoexec.bat [0]
                                    ~ Files: 48 Legitimates Filtered in 00mn 08s

                                    ---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
                                    O45 - LFCP:[MD5.C31CFF884CE072B0482FF23C325A98B4] - 23/02/2014 - 07:55:03 ---A- - C:\Windows\Prefetch\PIRRITUPDATER.TMP-83F87782.pf
                                    O45 - LFCP:[MD5.DD481A9B1525102EC433B2B3C6338E69] - 23/02/2014 - 09:28:43 ---A- - C:\Windows\Prefetch\PIRRITUPDATER.TMP-831DC155.pf
                                    O45 - LFCP:[MD5.4FE4157E816FF69A3FD23F174B663E03] - 24/02/2014 - 11:01:51 ---A- - C:\Windows\Prefetch\PIRRITUPDATER.TMP-71D6DDD9.pf
                                    O45 - LFCP:[MD5.C2F5A685D80FAB4A8A53891771CDB731] - 24/02/2014 - 12:33:16 ---A- - C:\Windows\Prefetch\PIRRITUPDATER.TMP-E13CC987.pf
                                    O45 - LFCP:[MD5.44545C157B9898B51106BD140F2C3F74] - 24/02/2014 - 12:33:16 ---A- - C:\Windows\Prefetch\WINRST.EXE-7B5CE2BC.pf
                                    O45 - LFCP:[MD5.DFF7C96FDB550685C2D6BA2F7CEA81BA] - 24/02/2014 - 20:17:59 ---A- - C:\Windows\Prefetch\SPYHUNTER-INSTALLER.EXE-B98DF857.pf =>Crapware.SpyHunter
                                    O45 - LFCP:[MD5.5545ABB339D3D3A26A808484451E458A] - 24/02/2014 - 20:20:07 ---A- - C:\Windows\Prefetch\WISECUSTOMCALLA32.EXE-0AE83C6A.pf =>Crapware.SpyHunter
                                    O45 - LFCP:[MD5.FA590D43E426112CCBCD84010A698BC2] - 24/02/2014 - 20:20:32 ---A- - C:\Windows\Prefetch\WISECUSTOMCALLA33.EXE-1E3DF6EF.pf =>Crapware.SpyHunter
                                    O45 - LFCP:[MD5.36954AB7F7EBB99C19DF5BC0E19B10CE] - 24/02/2014 - 20:20:35 ---A- - C:\Windows\Prefetch\WISECUSTOMCALLA34.EXE-3193B174.pf =>Crapware.SpyHunter
                                    O45 - LFCP:[MD5.82AEC7D5A94E5BAE8F8A65E68318B15E] - 24/02/2014 - 20:22:10 ---A- - C:\Windows\Prefetch\ESGRKCHK.EXE-6F276CDA.pf
                                    O45 - LFCP:[MD5.A37C1E99BB257CECDDB3CD2885A93D35] - 24/02/2014 - 20:22:16 ---A- - C:\Windows\Prefetch\SPYHUNTER4.EXE-5B920D84.pf =>Crapware.SpyHunter
                                    O45 - LFCP:[MD5.97B452E1D5DDE414824FE1F6C81CA917] - 24/02/2014 - 20:41:57 ---A- - C:\Windows\Prefetch\WISECUSTOMCALLA31.EXE-F79281E5.pf =>Crapware.SpyHunter
                                    O45 - LFCP:[MD5.BDF535659B27930EE69FA0E0220790BA] - 24/02/2014 - 20:42:03 ---A- - C:\Windows\Prefetch\SH4SER~1.EXE-2C0BA2D0.pf
                                    O45 - LFCP:[MD5.4A8D506CA11D5D6492646241AFCC3D46] - 24/02/2014 - 20:42:56 ---A- - C:\Windows\Prefetch\WISECUSTOMCALLA37.EXE-6B94E103.pf =>Crapware.SpyHunter
                                    O45 - LFCP:[MD5.F10556B20AC4A865877C68DDE8FF812A] - 24/02/2014 - 21:07:28 ---A- - C:\Windows\Prefetch\ADAWAREDESKTOP.EXE-3E86EC5E.pf
                                    O45 - LFCP:[MD5.4AB4709BB10DA062D345F2344EF5F017] - 24/02/2014 - 21:24:12 ---A- - C:\Windows\Prefetch\_IU14D2N.TMP-8D143E9D.pf
                                    O45 - LFCP:[MD5.01DB8DDAB811F0324B84E7998EBB9FE3] - 26/02/2014 - 08:21:56 ---A- - C:\Windows\Prefetch\ADBLOCKPLUSENGINE.EXE-2DDB5F32.pf
                                    O45 - LFCP:[MD5.433269AA20E2F3DE5E2B21D41A19A51E] - 26/02/2014 - 11:00:19 ---A- - C:\Windows\Prefetch\GREG.EXE-570F7FE1.pf
                                    O45 - LFCP:[MD5.030E82800F2CB8A5093220DF74F30D09] - 26/02/2014 - 22:26:14 ---A- - C:\Windows\Prefetch\ADAWARETRAY.EXE-9456305C.pf
                                    O45 - LFCP:[MD5.ACBCD609DEA97D87DC780F129A2E1E46] - 26/02/2014 - 22:27:29 ---A- - C:\Windows\Prefetch\PIRRITDESKTOP.EXE-97A9DAA3.pf
                                    ~ Prefetcher: 141 Legitimates Filtered in 00mn 01s

                                    ---\\ Clé de registre Shell MountPoints2 (MPKS) (O51)
                                    O51 - MPSK:{49a19922-3248-11e3-a585-206a8a172447}\AutoRun\command. (...) -- F:\LGAutoRun.exe (.not file.)
                                    ~ Keys: Scanned in 00mn 00s

                                    ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
                                    O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
                                    O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
                                    ~ MWPS: 16 Legitimates Filtered in 00mn 00s

                                    ---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
                                    O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
                                    ~ MWPE Keys: 3 Legitimates Filtered in 00mn 00s

                                    ---\\ Liste des pilotes du système (SDL) (O58)
                                    O58 - SDL:[MD5.2E83D2621E87C493AB45DC6655BA77D4] - 28/06/2013 - 07:35:36 ---A- . (...) -- C:\Windows\System32\Drivers\aswSnx.sys.sum [175]
                                    O58 - SDL:[MD5.A5F29AC2F0ADE8B995B49D7350CE3AC0] - 28/06/2013 - 07:35:36 ---A- . (...) -- C:\Windows\System32\Drivers\aswSP.sys.sum [175]
                                    O58 - SDL:[MD5.E86C64478D9A90D62255FE9EB0150C6E] - 28/06/2013 - 07:35:36 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys.sum [175]
                                    O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
                                    O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
                                    O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
                                    ~ Drivers: 16 Legitimates Filtered in 00mn 06s

                                    ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
                                    O61 - LFC: 24/02/2014 - 08:06:07 ---A- . (...) -- C:\Users\mook\AppData\Roaming\Lavasoft\Ad-Aware 11\Options\FirstRun [0]
                                    O61 - LFC: 26/02/2014 - 08:06:03 ---A- . (...) -- C:\Users\mook\AppData\Local\Avg2014\log\avgui.log.1 [131224]
                                    O61 - LFC: 26/02/2014 - 08:06:08 ---A- . (...) -- C:\Users\mook\AppData\Roaming\ZHP\ZHPADSReport.txt [351] =>.Nicolas Coolman
                                    O61 - LFC: 26/02/2014 - 08:06:08 ---A- . (...) -- C:\Users\mook\AppData\Roaming\ZHP\ZHPDiag.txt [38977] =>.Nicolas Coolman
                                    O61 - LFC: 27/02/2014 - 08:06:03 ---A- . (...) -- C:\Users\mook\AppData\Local\Avg2014\log\avgdecider.log.1 [65663]
                                    O61 - LFC: 27/02/2014 - 08:06:08 ---A- . (...) -- C:\Users\mook\AppData\Roaming\ZHP\HOSTS.txt [741] =>.Nicolas Coolman
                                    O61 - LFC: 27/02/2014 - 08:06:08 ---A- . (...) -- C:\Users\mook\AppData\Roaming\ZHP\Log.txt [87258] =>.Nicolas Coolman
                                    O61 - LFC: 27/02/2014 - 08:06:08 ---A- . (...) -- C:\Users\mook\AppData\Roaming\ZHP\TestsZHPDiag.txt [2826] =>.Nicolas Coolman
                                    ~ 3 Fichiers temporaires (Temporary files)
                                    ~ Files: 44 Legitimates Filtered in 00mn 05s

                                    ---\\ Liste des outils de désinfection (LATC) (O63)
                                    O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
                                    ~ ADS: Scanned in 00mn 00s

                                    ---\\ Menu de démarrage Internet (SMI) (O68)
                                    O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (...) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                    ~ Keys: Scanned in 00mn 00s

                                    ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
                                    O69 - SBI: SearchScopes [HKCU] {67A2568C-7A0A-4EED-AECC-B5405DE63B64} [DefaultScope] - (Google) - https://www.google.com/?gws_rd=ssl
                                    O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - https://www.google.com/?gws_rd=ssl
                                    ~ Keys: Scanned in 00mn 00s

                                    ---\\ Recherche particulière à la racine du système (SPRF) (O84)
                                    [MD5.6ACBD475647D7A160657CB3E460F0F35] [SPRF][27/01/2010] (...) -- C:\ProgramData\FullRemove.exe [131472]
                                    ~ Files: 1 Legitimates Filtered in 00mn 00s

                                    ---\\ Liste des exceptions du parefeu (FirewallRules) (O87)
                                    O87 - FAEL: "{5BD7D331-4BCB-4DC2-9838-530A07BA6F51}" | In - Private - P6 - TRUE | .(.Visicom Media Inc. - DtUser.) -- C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe
                                    O87 - FAEL: "{5B972662-0EDE-4F35-AAD4-EA40E9A73238}" | In - Private - P17 - TRUE | .(.Visicom Media Inc. - DtUser.) -- C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe
                                    ~ Firewall: 202 Legitimates Filtered in 00mn 01s

                                    ---\\ Enumère les codes produits des logiciels (PUC) (O90)
                                    O90 - PUC: "24BED006A334FA04CB4180E20475B72F" . (.AntimalwareEngine.) -- C:\Windows\Installer\{600DEB42-433A-40AF-BC14-082E40577BF2}\ARPPRODUCTICON.exe
                                    O90 - PUC: "5ADA61A603B0398448BA69B131041DA4" . (.AdAwareUpdater.) -- C:\Windows\Installer\{6A16ADA5-0B30-4893-84AB-961B1340D14A}\ARPPRODUCTICON.exe
                                    O90 - PUC: "A216D7CA50898BB48AACC4FC3E164B7B" . (.AdAwareInstaller.) -- C:\Windows\Installer\{AC7D612A-9805-4BB8-A8CA-4CCFE361B4B7}\ARPPRODUCTICON.exe
                                    ~ Update Products: 86 Legitimates Filtered in 00mn 00s

                                    ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
                                    SS - | Demand 21/02/2014 257928 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
                                    SS - | Demand 15/06/2013 194032 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    SS - | Demand 06/11/2009 50432 | (NTIBackupSvc) . (.NewTech InfoSystems, Inc..) - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
                                    SS - | Auto 14/02/2014 52568 | (PirritDesktop) . (...) - C:\Users\mook\AppData\Local\PirritSuggestor\PirritService.exe =>PUP.PirritSuggestor
                                    SS - | Auto 23/10/2013 172192 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
                                    SS - | Demand 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

                                    SR - | Auto 22/01/2010 202752 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
                                    SR - | Auto 22/01/2014 3788816 | (AVGIDSAgent) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
                                    SR - | Auto 24/09/2013 348008 | (avgwd) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
                                    SR - | Auto 08/04/2010 312400 | (DsiWMIService) . (.Dritek System Inc..) - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
                                    SR - | Auto 23/04/2010 867360 | (ePowerSvc) . (.Acer Incorporated.) - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
                                    SR - | Auto 08/01/2010 23584 | (GREGService) . (.Acer Incorporated.) - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
                                    SR - | Auto 23/01/2014 702744 | (LavasoftAdAwareService11) . (...) - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe
                                    SR - | Auto 03/03/2010 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
                                    SR - | Auto 04/04/2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
                                    SR - | Auto 04/04/2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
                                    SR - | Auto 09/03/2010 250368 | (NTI IScheduleSvc) . (.NewTech Infosystems, Inc..) - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
                                    SR - | Auto 06/11/2009 144640 | (NTISchedulerSvc) . (.NewTech Infosystems, Inc..) - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
                                    SR - | Auto 03/03/2010 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
                                    SR - | Auto 29/01/2010 243232 | (Updater Service) . (.Acer Group.) - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
                                    SR - | Auto 21/02/2014 59904 | (WinRST) . (...) - C:\Program Files (x86)\WinRST\WinRST.exe
                                    SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
                                    SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

                                    ~ Services: Scanned in 00mn 16s

                                    ---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
                                    Run by mook at 27/02/2014 08:06:44
                                    ~ OS 64 not supported by MBR tool

                                    ~ MBR: 0 Legitimates Filtered in 00mn 00s

                                    ---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
                                    Written by ad13, http://ad13.geekstog
                                    Run by mook at 27/02/2014 08:06:46

                                    ********* Dump file Name *********
                                    C:\PhysicalDisk0_MBR.bin

                                    ~ MBR: Scanned in 00mn 02s

                                    ---\\ Scan Additionnel (O88)
                                    Database Version : 13031 - (23/02/2014)
                                    Clés trouvées (Keys found) : 3
                                    Valeurs trouvées (Values found) : 0
                                    Dossiers trouvés (Folders found) : 0
                                    Fichiers trouvés (Files found) : 3

                                    [HKLM\SYSTEM\CurrentControlSet\Services\PirritDesktop] =>PUP.PirritSuggestor^
                                    [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\fst_fr_50_is1] =>PUA.FSTfr9^
                                    [HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6c97a91e-4524-4019-86af-2aa2d567bf5c}] =>Toolbar.AdAware
                                    C:\Users\mook\AppData\Local\Temp\uninst1.exe =>PUP.Babylon
                                    C:\Users\mook\AppData\Local\Temp\GoogleToolbarInstaller1.log =>PUP.Babylon
                                    ~ Additionnel Scan: 205956 Items scanned in 00mn 27s

                                    ---\\ Récapitulatif des détections trouvées sur votre station
                                    ~ http://nicolascoolman.webs.com/apps/blog/show/41590424-pup-pirritsuggestor =>PUP.PirritSuggestor
                                    ~ http://nicolascoolman.webs.com/apps/blog/show/34014358-pua-fstfr9 =>PUA.FSTfr9
                                    ~ http://nicolascoolman.webs.com/apps/blog/show/26609241-crapware-spyhunter =>Crapware.SpyHunter
                                    ~ http://nicolascoolman.webs.com/apps/blog/show/26627369-toolbar-babylon =>PUP.Babylon
                                    ~ MSI: 4 link(s) detected in 00mn 27s

                                    ~ 1217 Legitimates filtered by white list
                                    End of the scan (475 lines in 04mn 39s)(0)
                                    0
                                    1. Contributeur sécurité
                                      Désinstalles ad aware
                                      0
                                      • 1
                                      • 2
                                      • 3