Vous pensez être infecté, des pubs s'affichent quand vous naviguez sur internet ?
Perte de données, ralentissement système, virus USB ?
Désinfectez votre ordinateur gratuitement !
  • Avatar du membre
Avatar du membre
par Raelley
#24580
############################## | UsbFix V 7.156 | [Recherche]

Utilisateur: SALIM (Administrateur) # SALIM-PC
Mis à  jour le 27/12/2013 par El Desaparecido - Team SosVirus
Lancé à  23:10:39 | 27/12/2013

Site Web : http://www.usbfix.net" onclick="window.open(this.href);return false;
Forum : http://www.sosvirus.net/" onclick="window.open(this.href);return false;
Upload Malware : http://www.sosvirus.net/upload_malware.php" onclick="window.open(this.href);return false;
Contact : http://www.usbfix.net/contact/" onclick="window.open(this.href);return false;

PC: INFINITY ( )
CPU: Intel(R) Pentium(R) M processor 1.60GHz
RAM -> [Total : 2038 | Free : 1251]
Bios: INFINITY
Boot: Normal boot

OS: Microsoft Windows 7 Professionnel (6.1.7600 32-Bit)
WB: Windows Internet Explorer : 9.0.8112.16421

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Kaspersky PURE 3.0 [Enabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Disque fixe # 58 Go (9 Go libre(s) - 16%) [] # NTFS
D:\ -> Disque fixe # 35 Go (7 Go libre(s) - 21%) [] # NTFS
E:\ -> CD-ROM
F:\ -> Disque amovible # 15 Go (7 Go libre(s) - 47%) [DORIS] # FAT32
Z:\ -> Disque fixe # 100 Mo (70 Mo libre(s) - 70%) [Réservé au système] # NTFS

################## | Processus Actif |

C:\Windows\system32\csrss.exe (ID: 500 |ParentID: 484)
C:\Windows\system32\wininit.exe (ID: 548 |ParentID: 484)
C:\Windows\system32\csrss.exe (ID: 572 |ParentID: 540)
C:\Windows\system32\winlogon.exe (ID: 608 |ParentID: 540)
C:\Windows\system32\services.exe (ID: 656 |ParentID: 548)
C:\Windows\system32\lsass.exe (ID: 664 |ParentID: 548)
C:\Windows\system32\lsm.exe (ID: 672 |ParentID: 548)
C:\Windows\system32\svchost.exe (ID: 780 |ParentID: 656)
C:\Windows\system32\svchost.exe (ID: 844 |ParentID: 656)
C:\Windows\System32\svchost.exe (ID: 892 |ParentID: 656)
C:\Windows\System32\svchost.exe (ID: 1000 |ParentID: 656)
C:\Windows\system32\svchost.exe (ID: 1048 |ParentID: 656)
C:\Windows\system32\svchost.exe (ID: 1180 |ParentID: 656)
C:\Windows\system32\svchost.exe (ID: 1324 |ParentID: 656)
C:\Windows\System32\spoolsv.exe (ID: 1504 |ParentID: 656)
C:\Windows\system32\svchost.exe (ID: 1540 |ParentID: 656)
C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (ID: 1608 |ParentID: 656)
C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (ID: 1664 |ParentID: 656)
C:\Windows\system32\srvany.exe (ID: 1692 |ParentID: 656)
C:\Windows\KMService.exe (ID: 1732 |ParentID: 1692)
C:\Program Files\Common Files\LightScribe\LSSrvc.exe (ID: 1756 |ParentID: 656)
C:\Windows\system32\conhost.exe (ID: 1764 |ParentID: 500)
C:\Windows\system32\svchost.exe (ID: 1920 |ParentID: 656)
C:\Windows\system32\UAService.exe (ID: 1948 |ParentID: 656)
C:\Windows\system32\svchost.exe (ID: 336 |ParentID: 656)
C:\Windows\system32\taskhost.exe (ID: 2228 |ParentID: 656)
C:\Windows\system32\Dwm.exe (ID: 2280 |ParentID: 1000)
C:\Windows\Explorer.EXE (ID: 2308 |ParentID: 2272)
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (ID: 2612 |ParentID: 2308)
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (ID: 2620 |ParentID: 2308)
C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (ID: 2660 |ParentID: 2308)
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (ID: 2668 |ParentID: 2308)
C:\Users\SALIM\AppData\Roaming\DRPSu\DrvUpdater.exe (ID: 2696 |ParentID: 2308)
C:\Program Files\Windows Sidebar\sidebar.exe (ID: 2704 |ParentID: 2308)
C:\Users\SALIM\AppData\Roaming\Search Protection\SearchProtection.exe (ID: 2712 |ParentID: 2308)
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (ID: 2720 |ParentID: 2308)
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (ID: 2728 |ParentID: 2308)
C:\Program Files\Samsung\Kies\Kies.exe (ID: 2736 |ParentID: 2308)
C:\Program Files\Larousse\Petit Larousse 2010\bin\Hyperappel.exe (ID: 2752 |ParentID: 2308)
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (ID: 3188 |ParentID: 656)
C:\Windows\system32\svchost.exe (ID: 3316 |ParentID: 656)
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (ID: 3400 |ParentID: 780)
C:\Windows\system32\SearchIndexer.exe (ID: 3500 |ParentID: 656)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 3676 |ParentID: 656)
C:\Windows\System32\svchost.exe (ID: 3976 |ParentID: 656)
C:\Windows\System32\svchost.exe (ID: 1560 |ParentID: 656)
C:\Windows\system32\wuauclt.exe (ID: 2648 |ParentID: 1048)
C:\Users\SALIM\AppData\Roaming\uTorrent\uTorrent.exe (ID: 2340 |ParentID: 2308)
C:\Program Files\Internet Explorer\iexplore.exe (ID: 3832 |ParentID: 2308)
C:\Program Files\Internet Explorer\iexplore.exe (ID: 6000 |ParentID: 3832)
C:\Windows\system32\WUDFHost.exe (ID: 412 |ParentID: 1000)
C:\UsbFix\Go.exe (ID: 2200 |ParentID: 1100)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 5472 |ParentID: 780)

################## | Regedit Run |

04 - HKLM\SOFTWARE | Run : [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
04 - HKLM\SOFTWARE | Run : [SMSERIAL] - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
04 - HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
04 - HKLM\SOFTWARE | Run : [BCSSync] - "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
04 - HKLM\SOFTWARE | Run : [NeroFilterCheck] - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
04 - HKLM\SOFTWARE | Run : [AVP] - "C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe"
04 - HKLM\SOFTWARE | Run : [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
04 - HKLM\SOFTWARE | Run : [Adobe Reader Speed Launcher] - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [DrvUpdater] - C:\Users\SALIM\AppData\Roaming\DRPSu\DrvUpdater.exe
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [SearchProtection] - "C:\Users\SALIM\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe /preload
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
04 - HKU\S-1-5-18\SOFTWARE | Run : [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe

################## | Recherche générique |


################## | Registre |

Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyGames -> 0

################## | Vaccin |

D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
Z:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)

################## | E.O.F | http://www.usbfix.net" onclick="window.open(this.href);return false; - http://www.sosvirus.net" onclick="window.open(this.href);return false; |
Avatar du membre
par Evasion60
#24581
:hello: Bonsoir et bienvenue sur SoSVirus

/!\ C'est pas la politesse qui t'étouffe :(
Nous sommes des Humains et pas des Robots, donc un minimun, merci !

Relance USBFix
Clique sur Suppression
Poste son rapport

A de te lire
;)
Avatar du membre
par Invité
#24869
BONNE RECEPTION MON AMI; désolé mais c'est ce m.... qui m'a comblé de rage. Merci.

je vous transmets le rapport.

############################## | UsbFix V 7.156 | [Suppression]

Utilisateur: SALIM (Administrateur) # SALIM-PC
Mis à  jour le 27/12/2013 par El Desaparecido - Team SosVirus
Lancé à  17:28:47 | 28/12/2013

Site Web : http://www.usbfix.net" onclick="window.open(this.href);return false;
Forum : http://www.sosvirus.net/" onclick="window.open(this.href);return false;
Upload Malware : http://www.sosvirus.net/upload_malware.php" onclick="window.open(this.href);return false;
Contact : http://www.usbfix.net/contact/" onclick="window.open(this.href);return false;

PC: INFINITY ( )
CPU: Intel(R) Pentium(R) M processor 1.60GHz
RAM -> [Total : 2038 | Free : 997]
Bios: INFINITY
Boot: Normal boot

OS: Microsoft Windows 7 Professionnel (6.1.7600 32-Bit)
WB: Windows Internet Explorer : 9.0.8112.16421

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Kaspersky PURE 3.0 [Enabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Disque fixe # 58 Go (8 Go libre(s) - 14%) [] # NTFS
D:\ -> Disque fixe # 35 Go (7 Go libre(s) - 21%) [] # NTFS
E:\ -> CD-ROM
F:\ -> Disque amovible # 15 Go (7 Go libre(s) - 47%) [DORIS] # FAT32
Z:\ -> Disque fixe # 100 Mo (70 Mo libre(s) - 70%) [Réservé au système] # NTFS

################## | Processus Stoppés |

Stoppé! C:\Windows\System32\spoolsv.exe (ID: 1508 |ParentID: 608)
Stoppé! C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (ID: 1612 |ParentID: 608)
Stoppé! C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (ID: 1640 |ParentID: 608)
Stoppé! C:\Windows\system32\srvany.exe (ID: 1708 |ParentID: 608)
Stoppé! C:\Program Files\Common Files\LightScribe\LSSrvc.exe (ID: 1736 |ParentID: 608)
Stoppé! C:\Windows\KMService.exe (ID: 1744 |ParentID: 1708)
Stoppé! C:\Windows\system32\sppsvc.exe (ID: 1848 |ParentID: 608)
Stoppé! C:\Windows\system32\UAService.exe (ID: 1944 |ParentID: 608)
Stoppé! C:\Windows\system32\taskhost.exe (ID: 2268 |ParentID: 608)
Stoppé! C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (ID: 2588 |ParentID: 2368)
Stoppé! C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (ID: 2596 |ParentID: 2368)
Stoppé! C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (ID: 2696 |ParentID: 2368)
Stoppé! C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (ID: 2732 |ParentID: 2368)
Stoppé! C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe (ID: 2744 |ParentID: 2368)
Stoppé! C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (ID: 2752 |ParentID: 2368)
Stoppé! C:\Users\SALIM\AppData\Roaming\DRPSu\DrvUpdater.exe (ID: 2760 |ParentID: 2368)
Stoppé! C:\Program Files\Windows Sidebar\sidebar.exe (ID: 2780 |ParentID: 2368)
Stoppé! C:\Users\SALIM\AppData\Roaming\Search Protection\SearchProtection.exe (ID: 2800 |ParentID: 2368)
Stoppé! C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (ID: 2836 |ParentID: 2368)
Stoppé! C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (ID: 2864 |ParentID: 2368)
Stoppé! C:\Program Files\Samsung\Kies\Kies.exe (ID: 2872 |ParentID: 2368)
Stoppé! C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (ID: 2904 |ParentID: 2368)
Stoppé! C:\Program Files\Larousse\Petit Larousse 2010\bin\Hyperappel.exe (ID: 3044 |ParentID: 2368)
Stoppé! C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (ID: 3080 |ParentID: 608)
Stoppé! C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (ID: 3116 |ParentID: 776)
Stoppé! C:\Windows\system32\SearchIndexer.exe (ID: 3364 |ParentID: 608)
Stoppé! C:\Windows\system32\WUDFHost.exe (ID: 3900 |ParentID: 1016)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 4084 |ParentID: 608)
Stoppé! C:\Windows\servicing\TrustedInstaller.exe (ID: 3720 |ParentID: 608)
Stoppé! C:\Windows\system32\wuauclt.exe (ID: 3716 |ParentID: 1064)
Stoppé! C:\Windows\system32\SearchProtocolHost.exe (ID: 2660 |ParentID: 3364)
Stoppé! C:\Windows\system32\SearchFilterHost.exe (ID: 992 |ParentID: 3364)
Stoppé! C:\Windows\system32\SearchProtocolHost.exe (ID: 4024 |ParentID: 3364)

################## | Regedit Run |

04 - HKLM\SOFTWARE | Run : [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
04 - HKLM\SOFTWARE | Run : [SMSERIAL] - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
04 - HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
04 - HKLM\SOFTWARE | Run : [BCSSync] - "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
04 - HKLM\SOFTWARE | Run : [NeroFilterCheck] - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
04 - HKLM\SOFTWARE | Run : [AVP] - "C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe"
04 - HKLM\SOFTWARE | Run : [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
04 - HKLM\SOFTWARE | Run : [Adobe Reader Speed Launcher] - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [DrvUpdater] - C:\Users\SALIM\AppData\Roaming\DRPSu\DrvUpdater.exe
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [SearchProtection] - "C:\Users\SALIM\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe /preload
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup
04 - HKU\S-1-5-21-3018142079-1987253306-990982502-1000\SOFTWARE | Run : [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
04 - HKU\S-1-5-18\SOFTWARE | Run : [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe

################## | Recherche générique |


(!) Fichiers temporaires supprimés. (202021 Ko)

################## | Registre |

Réparé ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyGames -> 1

################## | Listing |

[27/12/2013 - 23:13:25 | N | 8 Ko] - C:\UsbFix [Scan 1] SALIM-PC.txt
[28/12/2013 - 17:31:50 | A | 7 Ko] - C:\UsbFix [Clean 2] SALIM-PC.txt
[16/02/2012 - 20:54:57 | D] - C:\~QTWTMP.TMP
[10/06/2009 - 22:42:20 | N | 0 Ko] - C:\config.sys
[08/12/2011 - 14:27:52 | N | 0 Ko] - C:\IO.SYS
[08/12/2011 - 14:27:52 | N | 0 Ko] - C:\MSDOS.SYS
[28/12/2013 - 17:24:04 | ASH | 1565560 Ko] - C:\hiberfil.sys
[28/12/2013 - 17:24:08 | ASH | 2087416 Ko] - C:\pagefile.sys
[08/06/2013 - 10:29:41 | D] - C:\Windows.old
[11/11/2013 - 22:17:27 | D] - C:\Config.Msi
[15/07/2013 - 12:14:16 | N | 3 Ko] - C:\M7BL_Rapport.log
[08/06/2013 - 11:27:16 | SHD] - C:\$Recycle.Bin
[10/06/2009 - 22:42:20 | A | 0 Ko] - C:\autoexec.bat
[14/07/2009 - 03:37:05 | D] - C:\PerfLogs
[14/07/2009 - 05:53:55 | SHD] - C:\Documents and Settings
[29/09/2011 - 15:47:09 | RHD] - C:\MSOCache
[08/12/2011 - 15:16:07 | D] - C:\MyWorks
[16/02/2012 - 20:54:08 | D] - C:\PMPEF
[16/02/2012 - 20:54:32 | D] - C:\HGASRAPI
[15/11/2012 - 16:58:49 | D] - C:\Temp
[08/06/2013 - 11:26:39 | SHD] - C:\Recovery
[08/06/2013 - 11:27:00 | D] - C:\Users
[08/06/2013 - 23:41:03 | D] - C:\Intel
[06/10/2013 - 19:44:17 | HD] - C:\ProgramData
[06/10/2013 - 19:44:56 | D] - C:\Windows
[11/11/2013 - 19:35:39 | D] - C:\Program Files
[28/12/2013 - 11:46:15 | SHD] - C:\System Volume Information
[28/12/2013 - 17:28:50 | D] - C:\UsbFix
[26/12/2012 - 21:43:38 | D] - D:\Game.Of.Thrones.S02
[27/12/2013 - 23:13:24 | RASHD] - D:\Autorun.inf
[08/06/2013 - 11:27:16 | SHD] - D:\$RECYCLE.BIN
[29/09/2011 - 16:05:29 | D] - D:\Windows Loader
[16/12/2011 - 16:27:51 | D] - D:\Carte mémoire
[28/12/2011 - 13:51:38 | D] - D:\Info Smrt Client
[09/05/2012 - 08:08:37 | D] - D:\AOUABDIA 1
[09/05/2012 - 08:09:14 | D] - D:\AOUABDIA 2
[09/05/2012 - 08:10:09 | D] - D:\AOUABDIA 3
[23/10/2012 - 13:28:52 | D] - D:\Maya Sérine
[01/07/2013 - 13:30:35 | D] - D:\video
[15/07/2013 - 12:10:23 | SHD] - D:\System Volume Information
[27/12/2013 - 23:13:26 | RASHD] - F:\Autorun.inf
[25/12/2013 - 18:54:34 | D] - F:\ 
[27/12/2013 - 22:35:14 | D] - F:\Nouveau dossier
[27/12/2013 - 23:13:25 | RASHD] - Z:\Autorun.inf
[26/06/2013 - 07:29:25 | SHD] - Z:\$RECYCLE.BIN
[08/06/2013 - 10:57:24 | N | 8 Ko] - Z:\BOOTSECT.BAK
[20/11/2010 - 13:40:07 | RASH | 375 Ko] - Z:\bootmgr
[29/09/2011 - 16:06:35 | | 323 Ko] - Z:\ADKTF
[03/07/2013 - 14:41:41 | SHD] - Z:\Boot
[15/07/2013 - 08:18:20 | SHD] - Z:\System Volume Information
[15/07/2013 - 08:18:21 | | 346 Ko] - Z:\TQCKN

################## | Vaccin |

D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
Z:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)

################## | E.O.F | http://www.usbfix.net" onclick="window.open(this.href);return false; - http://www.sosvirus.net" onclick="window.open(this.href);return false; |
Avatar du membre
par Evasion60
#24871
:hello: Bonsoir

Nous continuons =>

Téléchargez et enregistrez ZHPDiag => https://www.sosvirus.net/telecharger/zhpdiag/" onclick="window.open(this.href);return false; sur votre ordinateur.
Cliquez ensuite sur le fichier téléchargé pour exécuter l'installation du logiciel.
Laissez vous guider lors de l'installation en laissant les réglages par défaut, n'oubliez pas de cocher la case "raccourci bureau".
Suite à  ces actions, deux raccourcis bureau sont présents. (ZHPFix, ZHPDiag)

Image

Pour exécuter une analyse compléte, cliquez sur l'icône bureau "ZHPDiag" représentant un "parchemin".
Dans l'interface du logiciel, cliquez sur le bouton "Configurer" pour accéder aux réglages.
Cliquez ensuite sur bouton "Loupe +" en bas à  gauche, pour lancer un Diagnostic Full options

Image

L'analyse s'effectue, patientez quelques minutes pendant le travail de l'outil indiqué par "Traitement en cours...".

Image

Il arrive parfois que le programme affiche un message "Ne répond pas", attendez qu'il le fasse.
Le blocage étant le plus souvent "temporaire"...patientez

Image

A l'issue de l'analyse le rapport va s'ouvrir dans le bloc note
Vous pouvez poster ce rapport par copier/coller et fermer le programme.
Le rapport ZHPDiag.txt sera aussi sur votre bureau.
En cas de nécessité, il est sauvegardé dans C:\User\nomxxx\AppData\Roaming\ZHP\ZHPDiag.txt

Rappel pour poster par copier/coller

Vérifier dans le bloc notes (Notepad) > Format , que "Retour automatique à  la ligne" soit décoché.
Mettre le curseur de la souris sur le rapport ouvert
Appuyer simultanément sur les touches CTRL et A pour tout sélectionner (surligné en bleu en général) et relà¢cher les touches.
Appuyer simultanément sur les touches CTRL et C pour copier le contenu du rapport dans le presse-papier de Windows et relà¢cher les touches.
Ouvrir une réponse dans votre sujet sur le forum qui vous aide ou en créer un, y pointer le curseur de la souris.
Appuyer simultanément sur les touches CTRL et V pour coller le contenu du presse-papier.

Si le rapport est trop lourd alors hébergez le afin d'y accéder => http://upload.sosvirus.net/" onclick="window.open(this.href);return false;

:)
*
Avatar du membre
par Raelley
#24876
bonsoir.

~ Rapport de ZHPDiag v2013.12.26.23 - Nicolas Coolman (26/12/2013)
~ Lancé par SALIM (28/12/2013 19:55:55)
~ Adresse du Site Web http://nicolascoolman.webs.com" onclick="window.open(this.href);return false;
~ Forums gratuits d'Assistance à  la désinfection : http://nicolascoolman.webs.com/apps/links/" onclick="window.open(this.href);return false;
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v9.0.8112.16421 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows 7 Professional, 32-bit (Build 7600)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 6P6GT
Windows License : OK
~ Windows Remaining Initializations Number : 3
Software Protection Service (Protection logicielle) : OK
Key Management Service client information : KO
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Logiciels de protection du système
Kaspersky PURE 3.0 v13.0.2.558
Windows Defender W7

---\\ Logiciels d'optimisation du système

---\\ Logiciels de partage PeerToPeer
µTorrent v3.3.0.29677 =>P2P.µTorrent

---\\ Surveillance de Logiciels
Adobe Flash Player 11 ActiveX & Plugin
Adobe Reader 9.5.5 - Français
Java 7 Update 17

---\\ Informations sur le système
~ Processor: x86 Family 6 Model 13 Stepping 8, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2038 MB (59% free)
System Restore: Activé (Enable)
System drive C: has 8 GB (13%) free of 58 GB

---\\ Mode de connexion au système
~ Computer Name: SALIM-PC
~ User Name: SALIM
~ All Users Names: SALIM, HomeGroupUser$, Administrateur,
~ Unselected Option: None
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\SALIM\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\SALIM\AppData\Roaming\
~ %Desktop% : C:\Users\SALIM\Desktop\
~ %Favorites% : C:\Users\SALIM\Favorites\
~ %LocalAppData% : C:\Users\SALIM\AppData\Local\
~ %StartMenu% : C:\Users\SALIM\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 8 Go of 58 Go)
D: Hard drive, Flash drive, Thumb drive (Free 7 Go of 35 Go)
E: CD-ROM drive (Not Inserted)
F: Floppy drive, Flash card reader, USB Key (Free 7 Go of 15 Go)
Z: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : Out Of Date
~ Security Center: 42 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.2626FC9755BE22F805D3CFA0CE3EE727] - (.Microsoft Corporation - Explorateur Windows.) (.31/10/2009 - 06:45:39.) -- C:\Windows\Explorer.exe [2614272]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.EA952A5C277CABCBA69EA806146BB984] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.14/07/2013 - 22:18:57.) -- C:\Windows\System32\wininet.dll [1129472]
[MD5.37CDB7E72EB66BA85A87CBE37E7F03FD] - (.Microsoft Corporation - Application d‚ouverture de session Windows.) (.28/10/2009 - 07:17:59.) -- C:\Windows\System32\Winlogon.exe [285696]
[MD5.58C94EAE54BF0C5E2B80B2E5E7744D4C] - (.Microsoft Corporation - Bibliothèque de licences.) (.14/07/2009 - 02:16:15.) -- C:\Windows\System32\sppcomapi.dll [193024]
[MD5.0DB7A48388D54D154EBEC120461A0FCD] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.25/04/2011 - 03:35:40.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BA6E70AA0E6091BC39DE29477D866A77] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.14/07/2009 - 00:11:26.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.83D1ECEA8FAAE75604C0FA49AC7AD996] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.27/04/2011 - 03:33:46.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.717A2207FD6F13AD3E664C7D5A43C7BF] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.14/07/2009 - 00:50:56.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.CA7570E42522E24324A12161DB14EC02] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.04/05/2011 - 03:43:41.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123392]
[MD5.DD52A733BF4CA5AF84562A5E2F963B91] - (.Microsoft Corporation - MBT Transport driver.) (.14/07/2009 - 00:12:21.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.A8F59428E9F361C7AC42A94AC1560BC9] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 14:58:11.) -- C:\Windows\system32\Drivers\ntfs.sys [1210728]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.C5FF95883FFEF704D50C40D21CFB3AB5] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.14/07/2009 - 01:02:58.) -- C:\Windows\system32\Drivers\rdpdr.sys [133120]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.CB39E896A2A83702D1737BFD402B3542] - (.Microsoft Corporation - TDI Translation Driver.) (.14/07/2009 - 00:12:11.) -- C:\Windows\system32\Drivers\tdx.sys [74240]
[MD5.59F06B4968E58BC83DFC56CA4517960E] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.06/09/2012 - 17:48:29.) -- C:\Windows\system32\Drivers\volsnap.sys [245616]
~ Generic Processes: Scanned in 00mn 01s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/11
~ Mes Favoris (My Favorites) : 1/30
~ Mes Documents (My Documents) : 1/5
~ Mon Bureau (My Desktop) : 1/65
~ Menu demarrer (Programs) : 1/29
~ Hidden Files: Scanned in 00mn 00s



---\\ Processus lancés
[MD5.AFFCDEFF7DC9C6A2B3D99D801D71A141] - (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [11738184] [PID.2628]
[MD5.E4B4751917DE8620B58A5C91062BBC5F] - (.Motorola Inc. - SM56 Modem Helper.) -- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [1466368] [PID.2636]
[MD5.7E91655B4947EC1B18B3BC1645839145] - (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe [356128] [PID.1604]
[MD5.BF739971EC9B05DAFEC793767B632BA9] - (.Samsung Electronics Co., Ltd. - Kies TrayAgent Application.) -- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152] [PID.2688]
[MD5.48BE298F7FD1BEF4D8FBACB04D8D95C4] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576] [PID.2704]
[MD5.1DB3300FE6EF0D52ECABBB903FCA6A41] - (.Pas de propriétaire - DRP Su Updater.) -- C:\Users\SALIM\AppData\Roaming\DRPSu\DrvUpdater.exe [195256] [PID.2712]
[MD5.A9C71D2C838DDCE573888D82B3E17A8B] - (.Spigot, Inc. - Search Protection.) -- C:\Users\SALIM\AppData\Roaming\Search Protection\SearchProtection.exe [832360] [PID.2728] =>PUP.Dealio
[MD5.86F0D0B3A07C142C81DAB47E8495A822] - (.Nero AG - Nero Home.) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [152872] [PID.2736]
[MD5.4A9295C9BE22739D030AB072E9A0B169] - (.Hewlett-Packard Company - Pas de description.) -- C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392] [PID.2744]
[MD5.8CFAFCD10B661D5770A32111EB4CD266] - (.Samsung - Kies.) -- C:\Program Files\Samsung\Kies\Kies.exe [1564528] [PID.2752]
[MD5.E4B89C1434AC5EE740E87CCF7769F50D] - (.Samsung - KiesPDLR.) -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656] [PID.2760]
[MD5.D3AE1A1CF8DE0E56FD0656825BA5AAD8] - (.Pas de propriétaire - Application MFC hyperappel.) -- C:\Program Files\Larousse\Petit Larousse 2010\bin\Hyperappel.exe [237568] [PID.2768]
[MD5.FFBD5650348D4F9E0AA8E72938DC6478] - (.Nero AG - Nero Home.) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe [1213736] [PID.3416]
[MD5.EE12BA876C4190532A4085994BA9B616] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [757400] [PID.4040]
[MD5.2E0B0A051FFAA86E358465BB0880D453] - (.Microsoft Corporation - Windows Update.) -- C:\Windows\system32\wuauclt.exe [53784] [PID.5280]
[MD5.346736EF043C6920A9D64CBE63CF9B64] - (.BitTorrent Inc. - µTorrent.) -- C:\Users\SALIM\AppData\Roaming\uTorrent\uTorrent.exe [1045072] [PID.1264] =>P2P.BitTorrent
[MD5.870DF389D7676EDBB635141336A867C6] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8302080] [PID.4240]
~ Processes Running: Scanned in 00mn 03s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\Userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} . (...) -- C:\Program Files\IDM\QUICKfind\PlugIns\IEHelp.dll
~ BHO: 22 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Kaspersky Passsword Manager Toolbar - [HKLM]{215BA832-75A3-426E-A4FC-7C5B58CE6A10} . (.Kaspersky Lab - Autofill Engine for IE-based web browsers.) -- C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll
~ Toolbar: Scanned in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: Kaspersky PURE 3.0.lnk . (.Kaspersky Lab ZAO - Kaspersky Anti-Virus Launcher.) -- C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\starter_avp.exe
O4 - GS\Desktop [Public]: Oxford Advanced Learner's Dictionary - 7th edition.lnk . (.Mozilla, Netscape - Mozilla.) -- C:\Program Files\Oxford\OALD7\oald7.exe
O4 - GS\Desktop [Public]: Petit Larousse 2010.lnk . (.Larousse - Le Petit Larousse 2010.) -- C:\Program Files\Larousse\Petit Larousse 2010\bin\PLViewer.exe
O4 - GS\Desktop [Public]: QVGDM Seconde Edition.lnk . (...) -- C:\Program Files\Eidos Interactive\HotHouse Creations\QVGDM Seconde Edition\Game.exe
O4 - GS\Desktop [Public]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Users\SALIM\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent
O4 - GS\QuickLaunch [SALIM]: FreeArc.lnk . (...) -- C:\Program Files\FreeArc\bin\FreeArc.exe
O4 - GS\QuickLaunch [SALIM]: Google Chrome.lnk . (...) -- C:\Program Files\Google\Chrome\Application\chrome.exe (.not file.)
O4 - GS\QuickLaunch [SALIM]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\TaskBar [SALIM]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\Program [SALIM]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\SystemTools [SALIM]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\Desktop [SALIM]: Brain Training -Boost Memory,Maximize Mental Agility, & Awaken Your Inner Genius -Mantesh - Raccourci.lnk . (...) -- D:\video\E BOOK\Brain Training -Boost Memory,Maximize Mental Agility, & Awaken Your Inner Genius -Mantesh
O4 - GS\Desktop [SALIM]: FreeArc.lnk . (...) -- C:\Program Files\FreeArc\bin\FreeArc.exe
O4 - GS\Desktop [SALIM]: Keep Your Brain Alive 83 Neurobic Exercises to Help Prevent Memory Loss and Increase Mental Fitness - Raccourci.lnk . (...) -- D:\video\E BOOK\Keep Your Brain Alive 83 Neurobic Exercises to Help Prevent Memory Loss and Increase Mental Fitness
O4 - GS\Desktop [SALIM]: PDF2Word v1.4.lnk . (...) -- C:\Program Files\PDF2Word v1.4\pdf2rtf.exe
O4 - GS\Desktop [SALIM]: Protection des transactions bancaires.lnk . (.Kaspersky Lab ZAO - Kaspersky Anti-Virus Launcher.) -- C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\starter_avp.exe
O4 - GS\Desktop [SALIM]: The Speed Reading Book + The Speed Reading Monster Course - Accelerate Your Reading and Learning Abilities to the Extreme - Mantesh - Raccourci.lnk . (...) -- D:\video\E BOOK\The Speed Reading Book + The Speed Reading Monster Course - Accelerate Your Reading and Learning Abilities to the Extreme - Mantesh
O4 - GS\Desktop [SALIM]: Triple Your Reading Speed-Mantesh - Raccourci.lnk . (...) -- D:\video\E BOOK\Triple Your Reading Speed-Mantesh
~ Global Startup: 73 Legitimates Filtered in 00mn 03s



---\\ Applications lancées au démarrage du sytème (O4)
O4 - GS\Startup [Public]: Hyperappel du Petit Larousse 2010.lnk . (...) -- C:\Program Files\Larousse\Petit Larousse 2010\bin\Hyperappel.exe
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe =>.Realtek Semiconductor Corp
O4 - HKLM\..\Run: [SMSERIAL] . (.Motorola Inc. - SM56 Modem Helper.) -- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime Alternative\QTTask.exe
O4 - HKLM\..\Run: [BCSSync] . (.Microsoft Corporation - Microsoft Office 2010 component.) -- C:\Program Files\Microsoft Office\Office14\BCSSync.exe =>.Microsoft Corporation
O4 - HKLM\..\Run: [NeroFilterCheck] . (.Nero AG - NeroCheck.) -- C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVP] . (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
O4 - HKLM\..\Run: [KiesTrayAgent] . (.Samsung Electronics Co., Ltd. - Kies TrayAgent Application.) -- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe =>.Samsung Electronics Co
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated
O4 - HKCU\..\Run: [DrvUpdater] . (.Pas de propriétaire - DRP Su Updater.) -- C:\Users\SALIM\AppData\Roaming\DRPSu\DrvUpdater.exe
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKCU\..\Run: [SearchProtection] . (.Spigot, Inc. - Search Protection.) -- C:\Users\SALIM\AppData\Roaming\Search Protection\SearchProtection.exe =>PUP.Dealio
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] . (.Nero AG - Nero Home.) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] . (.Hewlett-Packard Company - Pas de description.) -- C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
O4 - HKCU\..\Run: [KiesPreload] . (.Samsung - Kies.) -- C:\Program Files\Samsung\Kies\Kies.exe
O4 - HKCU\..\Run: [KiesAirMessage] C:\Program Files\Samsung\Kies\KiesAirMessage.exe (.not file.)
O4 - HKUS\S-1-5-18\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-3018142079-1987253306-990982502-1000\..\Run: [DrvUpdater] . (.Pas de propriétaire - DRP Su Updater.) -- C:\Users\SALIM\AppData\Roaming\DRPSu\DrvUpdater.exe
O4 - HKUS\S-1-5-21-3018142079-1987253306-990982502-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-3018142079-1987253306-990982502-1000\..\Run: [SearchProtection] . (.Spigot, Inc. - Search Protection.) -- C:\Users\SALIM\AppData\Roaming\Search Protection\SearchProtection.exe =>PUP.Dealio
O4 - HKUS\S-1-5-21-3018142079-1987253306-990982502-1000\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] . (.Nero AG - Nero Home.) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
O4 - HKUS\S-1-5-21-3018142079-1987253306-990982502-1000\..\Run: [LightScribe Control Panel] . (.Hewlett-Packard Company - Pas de description.) -- C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
O4 - HKUS\S-1-5-21-3018142079-1987253306-990982502-1000\..\Run: [KiesPreload] . (.Samsung - Kies.) -- C:\Program Files\Samsung\Kies\Kies.exe
O4 - HKUS\S-1-5-21-3018142079-1987253306-990982502-1000\..\Run: [KiesAirMessage] C:\Program Files\Samsung\Kies\KiesAirMessage.exe (.not file.)
~ Application: Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Clavier virtuel - {0C4CC089-D306-440D-9772-464E226F6539} . (...) -- C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\kbrd.ico
O9 - Extra button: &Envoyer à  OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\MICROS~1\Office14\ONBttnIE.dll =>.Microsoft Corporation
O9 - Extra button: Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\MICROS~1\Office14\ONBTTN~1.dll =>.Microsoft Corporation
O9 - Extra button: Analyse des liens - {CCF151D8-D089-449F-A5A4-D9909053F20F} . (...) -- C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\logo.ico
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{9C6E6EAE-9E2E-41A7-A111-F17B19C85BD5}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{9C6E6EAE-9E2E-41A7-A111-F17B19C85BD5}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{9C6E6EAE-9E2E-41A7-A111-F17B19C85BD5}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: KMService (KMService) . (...) - C:\Windows\system32\srvany.exe =>Hijacker.Office
O23 - Service: SecuROM User Access Service (UserAccess) . (...) - C:\Windows\system32\UAService.exe
~ Services: 6 Legitimates Filtered in 00mn 15s



---\\ Tà¢ches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [{57E10CDE-FD95-41D2-8EFD-AD48EF688903}] (...) -- E:\Office 2007\SETUP.exe (.not file.) [0]
~ Scheduled Task: 1 Legitimates Filtered in 00mn 05s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 09/06/2013 - 22:52:20 - [3,170] ----D C:\Program Files\TEXTware
O43 - CFD: 09/06/2013 - 11:11:43 - [0,828] ----D C:\Program Files\utvideo
~ Program Folder: 133 Legitimates Filtered in 00mn 21s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.F556DE62A0DF629FC6F9EE23100D586E] - 27/12/2013 - 23:13:25 ----- . (...) -- C:\UsbFix [Scan 1] SALIM-PC.txt [8076]
O44 - LFC:[MD5.5C78E898698F288EED1E9987F61D4BC7] - 28/12/2013 - 17:31:53 ---A- . (...) -- C:\UsbFix [Clean 2] SALIM-PC.txt [9914]
~ Files: 10 Legitimates Filtered in 00mn 07s



---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.29DA87BFD93EBA0C756EE209A85E8651] - 28/12/2013 - 18:13:44 ---A- - C:\Windows\Prefetch\PROTECTEDOBJECTSSRV.EXE-C456726A.pf
~ Prefetcher: 53 Legitimates Filtered in 00mn 00s



---\\ Opérations et fonctions au démarrage de Windows Explorer (O46)
O46 - SEH:ShellExecuteHooks - Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\MICROS~1\Office14\GROOVEEX.DLL
~ ShellExecuteHooks: Scanned in 00mn 00s



---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"VIDC.CSCD"="CamCodec.dll" . (.CamStudio Group - CamStudio Lossless Video Codec.) -- C:\Windows\System32\CamCodec.dll
O52 - TDSD: \Drivers32\"VIDC.MLCY"="mlc.dll" . (...) -- C:\Windows\System32\mlc.dll
O52 - TDSD: \Drivers32\"VIDC.ULRA"="C:\Windows\system32\utv_vcm.dll" . (...) -- C:\Windows\system32\utv_vcm.dll
O52 - TDSD: \Drivers32\"VIDC.ULRG"="C:\Windows\system32\utv_vcm.dll" . (...) -- C:\Windows\system32\utv_vcm.dll
O52 - TDSD: \Drivers32\"VIDC.ULY0"="C:\Windows\system32\utv_vcm.dll" . (...) -- C:\Windows\system32\utv_vcm.dll
O52 - TDSD: \Drivers32\"VIDC.ULY2"="C:\Windows\system32\utv_vcm.dll" . (...) -- C:\Windows\system32\utv_vcm.dll
O52 - TDSD: \Drivers32\"VIDC.VP80"="vp8vfw.dll" . (.Optima SC Inc. - Google VP8 VFW Video Codec.) -- C:\Windows\System32\vp8vfw.dll
O52 - TDSD: \Drivers32\"VIDC.GEOX"="GeoCodec.dll" . (.GeoVision - GeoVision(R) Codec.) -- C:\Windows\System32\GeoCodec.dll
O52 - TDSD: \Drivers32\"VIDC.GEOV"="GeoCodec.dll" . (.GeoVision - GeoVision(R) Codec.) -- C:\Windows\System32\GeoCodec.dll
O52 - TDSD: \Drivers32\"VIDC.GEOS"="GeoCodecD.dll" . (.GeoVision - GeoVision(R) Codec.) -- C:\Windows\System32\GeoCodecD.dll
O52 - TDSD: \drivers.desc\"CamCodec.dll"="CamStudio Lossless Codec" . (.CamStudio Group - CamStudio Lossless Video Codec.) -- C:\Windows\System32\CamCodec.dll
O52 - TDSD: \drivers.desc\"mlc.dll"="MLC Lossless Codec" . (...) -- C:\Windows\System32\mlc.dll
O52 - TDSD: \drivers.desc\"vp8vfw.dll"="VP8 Video Codec" . (.Optima SC Inc. - Google VP8 VFW Video Codec.) -- C:\Windows\System32\vp8vfw.dll
O52 - TDSD: \drivers.desc\"GeoCodec.dll"="GeoVision MPEG4" . (.GeoVision - GeoVision(R) Codec.) -- C:\Windows\System32\GeoCodec.dll
O52 - TDSD: \drivers.desc\"GeoCodecD.dll"="GeoVision MPEG4 Decoder" . (.GeoVision - GeoVision(R) Codec.) -- C:\Windows\System32\GeoCodecD.dll
~ TDSD: 40 Legitimates Filtered in 00mn 01s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.64D579F38C5FADFB05182B34808469E1] - 02/06/2011 - 14:39:44 ---A- . (.Infowatch - Cryptographic Algorithm Lib Driver..) -- C:\Windows\System32\Drivers\CSCrySec.sys [88632]
O58 - SDL:[MD5.4CEDBC3811E655567D99D3123804647B] - 02/06/2011 - 14:39:44 ---A- . (.Infowatch - Virtual Volume Container Driver (wxp).) -- C:\Windows\System32\Drivers\CSVirtualDiskDrv.sys [39736]
O58 - SDL:[MD5.0ED67910C8C326796FAA00B2BF6D9D3C] - 14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712]
O58 - SDL:[MD5.C44E3C2BAB6837DB337DDEE7544736DB] - 13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624]
O58 - SDL:[MD5.ECBCEE3C0B795CCAF3F3051C1EF22B29] - 02/09/2009 - 12:52:50 ---A- . (.SMSC - SMSC Fast Infrared Driver.) -- C:\Windows\System32\Drivers\smscirda.sys [31232]
O58 - SDL:[MD5.54D0B8343CE8C22412A5F29D32EFD211] - 21/06/2013 - 01:07:52 ---A- . (.DEVGURU Co., LTD.(http://www.devguru.co.kr" onclick="window.open(this.href);return false;) - SAMSUNG USB Composite Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudbus.sys [84248]
O58 - SDL:[MD5.D2C02234E3E87EA5FE420F045068099B] - 21/06/2013 - 01:07:52 ---A- . (.DEVGURU Co., LTD.(http://www.devguru.co.kr" onclick="window.open(this.href);return false;) - SAMSUNG Android Modem Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudmdm.sys [181912]
O58 - SDL:[MD5.DB32D325C192B801DF274BFD12A7E72B] - 14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072]
O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:[MD5.E6BC0F98FECEF245A0010D350C1A0B9B] - 13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:[MD5.492090267B9608C62B956CD29BE3AFB7] - 13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:[MD5.FFFF296A08DBF2AC0126C62E3778AC0D] - 13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:[MD5.2E4112FB7D1B76E11ADFD7487B5D0E95] - 13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:[MD5.A98EBD4C2DF983665BF2D1AF49949974] - 13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:[MD5.3F7E6406EDEF197C5CAAB2240EEF6F48] - 13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:[MD5.3E64D681B776CC57BDC38A46D881F85B] - 13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:[MD5.D86B6435729231C171432B4E77801BDB] - 13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672]
~ Drivers: 16 Legitimates Filtered in 00mn 30s



---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 27/12/2013 - 19:58:58 ---A- . (...) -- C:\Users\SALIM\Downloads\Red.FRENCH.DVDRip.XviD-AYMO\aymo_xvid_red.nfo [471]
O61 - LFC: 28/12/2013 - 19:58:56 ---A- . (...) -- C:\Users\SALIM\AppData\Roaming\ZHP\Log.txt [21561] =>.Nicolas Coolman
O61 - LFC: 28/12/2013 - 19:58:56 ---A- . (...) -- C:\Users\SALIM\AppData\Roaming\ZHP\TestsZHPDiag.txt [2797] =>.Nicolas Coolman
O61 - LFC: 28/12/2013 - 19:58:58 R--A- . (...) -- C:\Users\SALIM\Downloads\[www.OMGTORRENT.com] Runner Runner 2013 FRENCH BRRip XviD-CARPEDIEM\Films DVDRIP sur http://www.OMGTORRENT.com.html" onclick="window.open(this.href);return false; [443]
O61 - LFC: 28/12/2013 - 19:58:58 R--A- . (...) -- C:\Users\SALIM\Downloads\[www.OMGTORRENT.com] Runner Runner 2013 FRENCH BRRip XviD-CARPEDIEM\Films et series sur http://www.OMGTORRENT.com.txt" onclick="window.open(this.href);return false; [60]
O61 - LFC: 28/12/2013 - 19:58:58 R--A- . (...) -- C:\Users\SALIM\Downloads\[www.OMGTORRENT.com] Runner Runner 2013 FRENCH BRRip XviD-CARPEDIEM\Les derniers films et series sur http://www.OMGTORRENT.com" onclick="window.open(this.href);return false; - cliquez ici !.html [443]
O61 - LFC: 28/12/2013 - 19:58:58 R--A- . (...) -- C:\Users\SALIM\Downloads\[www.OMGTORRENT.com] Runner Runner 2013 FRENCH BRRip XviD-CARPEDIEM\Runner Runner 2013 FRENCH BRRip XviD-CARPEDIEM.nfo [4973]
~ 9 Fichiers temporaires (Temporary files)
~ 1 Fichiers cookies (Cookies files)
~ Files: 111 Legitimates Filtered in 01mn 13s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: UsbFix - (.El Desaparecido - http://www.usbfix.net" onclick="window.open(this.href);return false; - http://www.sosvirus.net" onclick="window.open(this.href);return false;.) [HKLM] -- Usbfix
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com" onclick="window.open(this.href);return false;
O69 - SBI: SearchScopes [HKCU] {708C47B3-5BFB-4648-88D1-5CAAD6BC0A23} [DefaultScope] - (Yahoo! Search) - http://search.yahoo.com" onclick="window.open(this.href);return false;
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à  la racine du système (SPRF) (O84)
[MD5.FB9DA1DD951232244203558A96E8FF66] [SPRF][07/02/2013] (.Pas de propriétaire - AntiDust Tool.) -- C:\Program Files\AntiDust.exe [50330]
~ Files: 4 Legitimates Filtered in 00mn 00s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 29/06/2007 800040 | (NBService) . (.Nero AG.) - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
SS - | Auto 07/02/2013 161384 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe

SR - | Auto 20/10/2013 356128 | (AVP) . (.Kaspersky Lab ZAO.) - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
SR - | Auto 21/12/2012 819040 | (CSObjectsSrv) . (.Infowatch.) - C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
SR - | Auto 18/04/2003 8192 | (KMService) . (...) - C:\Windows\system32\srvany.exe =>Hijacker.Office
SR - | Auto 09/06/2008 73728 | (LightScribeService) . (.Hewlett-Packard Company.) - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
SR - | Demand 27/06/2007 279848 | (NMIndexingService) . (.Nero AG.) - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
SR - | Auto 09/06/2013 126976 | (UserAccess) . (...) - C:\Windows\system32\UAService.exe
SR - | Auto 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

~ Services: Scanned in 00mn 19s



---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net" onclick="window.open(this.href);return false;
Run by SALIM at 28/12/2013 20:05:58

device: opened successfully
user: error reading MBR

Disk trace:
error: Read Descripteur non valide
kernel: error reading MBR

~ MBR: 9 Legitimates Filtered in 00mn 17s



---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog" onclick="window.open(this.href);return false;
Run by SALIM at 28/12/2013 20:06:08

********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin

~ MBR: Scanned in 00mn 27s



---\\ Scan Additionnel (O88)
Database Version : 13013 - (26/12/2013)
Clés trouvées (Keys found) : 11
Valeurs trouvées (Values found) : 2
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 3

[HKLM\SYSTEM\CurrentControlSet\Services\KMService] =>Hijacker.Office^
[HKLM\Software\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}] =>Toolbar.Agent
[HKLM\Software\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}] =>PUP.Whitesmoke
[HKLM\Software\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}] =>PUP.Whitesmoke
[HKLM\Software\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}] =>Toolbar.Ask
[HKLM\Software\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}] =>PUP.Babylon
[HKLM\Software\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}] =>PUP.Babylon
[HKLM\Software\Classes\AppID\secman.DLL] =>PUP.Babylon
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47] =>Adware.IMBooster
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856] =>Adware.IMBooster
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494] =>Adware.IMBooster
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:SearchProtection =>PUP.Dealio^
C:\Users\SALIM\AppData\Roaming\Search Protection\SearchProtection.exe =>PUP.Dealio^
C:\Users\SALIM\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent^
C:\Windows\KMService.exe =>Hijacker.Windows
~ Additionnel Scan: 242738 Items scanned in 00mn 59s



---\\ Récapitulatif des détections trouvées sur votre station
~ http://nicolascoolman.webs.com/apps/blo ... pup-dealio" onclick="window.open(this.href);return false; =>PUP.Dealio
~ http://nicolascoolman.webs.com/apps/blo ... ker-office" onclick="window.open(this.href);return false; =>Hijacker.Office
~ http://nicolascoolman.webs.com/apps/blo ... whitesmoke" onclick="window.open(this.href);return false; =>PUP.WhiteSmoke
~ http://nicolascoolman.webs.com/apps/blo ... oolbar-ask" onclick="window.open(this.href);return false; =>Toolbar.Ask
~ http://nicolascoolman.webs.com/apps/blo ... ar-babylon" onclick="window.open(this.href);return false; =>PUP.Babylon
~ http://nicolascoolman.webs.com/apps/blo ... -imbooster" onclick="window.open(this.href);return false; =>Adware.IMBooster
~ http://nicolascoolman.webs.com/apps/blo ... er-windows" onclick="window.open(this.href);return false; =>Hijacker.Windows
~ MSI: 7 link(s) detected in 00mn 59s



~ 1113 Legitimates filtered by white list
End of the scan (479 lines in 11mn 13s)(0)

:merci2:
Avatar du membre
par Evasion60
#24878
:hello: Re

/!\ Désolé, je ne prends pas en charge des PC avec des Cracks & Keygens
Dans ton cas, c'est la Suite Office de Microsoft qui est déplombée et un Seven douteux :(

---\\ Informations sur les produits Windows
~ Langage: Français
Windows 7 Professional, 32-bit (Build 7600) // Seven est en SP1
Key Management Service client information : KO => Microsoft Office version crackée

C:\Windows\KMService.exe =>Hijacker.Windows
O23 - Service: KMService (KMService) . (...) - C:\Windows\system32\srvany.exe =>Hijacker.Office

Bonne continuation ;)

*

bonsoir oki pour la fermeture je m'en charge car[…]

how to clean junk files

Hello don't use this program , it's a bullshit :)

Bonjour https://www.aht.li/3213847/AdsFix.exe b[…]

De rien Bon WE :)