Vous pensez être infecté, des pubs s'affichent quand vous naviguez sur internet ?
Perte de données, ralentissement système, virus USB ?
Désinfectez votre ordinateur gratuitement !
  • Avatar du membre
  • Avatar du membre
#14583
Avec USBfix, la désinfection (qui fonctionne) s'arrete donc bien a 95% lors de la vaccination

Le rapport de suppression :
Code: Tout sélectionner
############################## | UsbFix V 7.149 | [Suppression]

Utilisateur: Thomas (Administrateur) # PC-TDELIEGE
Mis à  jour le 03/11/2013 par El Desaparecido - Team SosVirus
Lancé à  12:22:07 | 05/11/2013

Site Web: https://www.usbfix.net/
Forum : https://www.sosvirus.net/
Upload Malware: https://www.sosvirus.net/upload_malware.php
Contact: https://www.usbfix.net/contact/

PC: Dell Inc. (0U692R)
CPU: Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz
RAM -> [Total : 4048 | Free : 2329]
Bios: Dell Inc.
Boot: Normal boot

OS: Microsoft Windows 8.1 Professionnel (6.2.9200 64-Bit)
WB: Windows Internet Explorer : 11.0.9600.16384
WB: Google Chrome : 30.0.1599.101

SC: Security Center Service [Enabled]
WU: Windows Update Service [(!) Disabled]
AV: Ad-Aware Antivirus [(!) Disabled | (!) Outdated]
AS: Windows Defender : 4.3.9600.16384 (winblue_rtm.130821-1623)
AS: Malwarebytes' Anti-Malware : 1.75.0001
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Disque fixe # 149 Go (87 Go libre(s) - 58%) [] # NTFS
D:\ -> CD-ROM
E:\ -> Disque amovible # 15 Go (15 Go libre(s) - 99%) [] # NTFS
F:\ -> Disque amovible # 4 Go (4 Go libre(s) - 100%) [Nouveau vol] # FAT32

################## | Processus Stoppés |

Stoppé! C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\AdAwareService.exe (ID: 728 |ParentID: 492)
Stoppé! C:\Windows\System32\WUDFHost.exe (ID: 380 |ParentID: 852)
Stoppé! C:\Windows\System32\spoolsv.exe (ID: 1112 |ParentID: 492)
Stoppé! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1292 |ParentID: 492)
Stoppé! C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 1348 |ParentID: 492)
Stoppé! C:\Program Files\Bonjour\mDNSResponder.exe (ID: 1432 |ParentID: 492)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE (ID: 1572 |ParentID: 492)
Stoppé! C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe (ID: 1652 |ParentID: 492)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSvcm.exe (ID: 1724 |ParentID: 1572)
Stoppé! C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe (ID: 1776 |ParentID: 492)
Stoppé! C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe (ID: 692 |ParentID: 492)
Stoppé! C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe (ID: 1924 |ParentID: 492)
Stoppé! C:\Windows\Explorer.EXE (ID: 2380 |ParentID: 2344)
Stoppé! C:\Windows\system32\taskhostex.exe (ID: 2592 |ParentID: 868)
Stoppé! C:\Windows\System32\SettingSyncHost.exe (ID: 3120 |ParentID: 608)
Stoppé! C:\Windows\system32\SearchIndexer.exe (ID: 3580 |ParentID: 492)
Stoppé! C:\Windows\System32\skydrive.exe (ID: 3628 |ParentID: 608)
Stoppé! C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\AdAwareTray.exe (ID: 3708 |ParentID: 2380)
Stoppé! C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (ID: 3800 |ParentID: 2380)
Stoppé! C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (ID: 3972 |ParentID: 2380)
Stoppé! C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID: 3764 |ParentID: 3852)
Stoppé! C:\Windows\System32\WUDFHost.exe (ID: 2400 |ParentID: 852)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (ID: 2132 |ParentID: 492)
Stoppé! C:\Windows\system32\taskeng.exe (ID: 4204 |ParentID: 868)
Stoppé! C:\Windows\system32\SearchProtocolHost.exe (ID: 3324 |ParentID: 3580)
Stoppé! C:\Windows\system32\SearchFilterHost.exe (ID: 4296 |ParentID: 3580)

################## | Regedit Run |

04 - HKLM\SOFTWARE | Run : [Communicator] - "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [Communicator] - "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
04 - HKU\S-1-5-21-3653578804-3571681521-2262723874-1001\SOFTWARE | Run : [OfficeSyncProcess] - "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"

################## | Recherche générique |


(!) Fichiers temporaires supprimés.


################## | Registre |


################## | Listing |

[03/10/2013 - 14:14:15 | SHD ] C:\$Recycle.Bin
[25/09/2013 - 09:30:44 | N | 1024] C:\.rnd
[04/11/2013 - 14:39:28 | D ] C:\AdwCleaner
[23/09/2013 - 12:16:25 | D ] C:\APX
[22/08/2013 - 06:31:45 | RASH | 427680] C:\bootmgr
[18/06/2013 - 13:18:29 | N | 1] C:\BOOTNXT
[04/11/2013 - 16:38:28 | SHD ] C:\Config.Msi
[22/08/2013 - 15:45:52 | SHD ] C:\Documents and Settings
[05/11/2013 - 10:08:07 | ASH | 3395633152] C:\hiberfil.sys
[23/09/2013 - 10:13:15 | RHD ] C:\MSOCache
[05/11/2013 - 10:08:09 | ASH | 738197504] C:\pagefile.sys
[22/08/2013 - 16:22:35 | D ] C:\PerfLogs
[04/11/2013 - 16:37:24 | D ] C:\Program Files
[04/11/2013 - 16:17:50 | D ] C:\Program Files (x86)
[04/11/2013 - 16:35:44 | HD ] C:\ProgramData
[05/11/2013 - 10:08:09 | ASH | 268435456] C:\swapfile.sys
[04/11/2013 - 13:17:26 | SHD ] C:\System Volume Information
[05/11/2013 - 12:22:34 | D ] C:\UsbFix
[05/11/2013 - 12:22:37 | A | 6035] C:\UsbFix [Clean 1] PC-TDELIEGE.txt
[05/11/2013 - 12:21:26 | N | 5898] C:\UsbFix [Scan 1] PC-TDELIEGE.txt
[23/09/2013 - 09:45:23 | RD ] C:\Users
[04/11/2013 - 16:23:15 | D ] C:\Windows
[04/10/2013 - 14:28:14 | D ] C:\Xerox
[04/11/2013 - 16:13:25 | SHD ] E:\System Volume Information
[16/10/2013 - 15:24:12 | N | 155639] F:\266534.jpg
[31/10/2013 - 16:58:28 | N | 517864] F:\Barakamon.full.1483732.jpg
[16/10/2013 - 15:22:58 | N | 161520] F:\CATS-PICTURES.ORG_-_apofiss-solo.jpg
[05/11/2013 - 09:28:56 | SHD ] F:\System Volume Information

################## | Vaccin |
Le rapport ZHPDiag:
Code: Tout sélectionner
~ Rapport de ZHPDiag v2013.11.4.4 - Nicolas Coolman (04/11/2013)
~ Lancé par Thomas (05/11/2013 13:48:37)
~ Adresse du Site Web https://nicolascoolman.webs.com
~ Forums gratuits d'Assistance à  la désinfection : https://nicolascoolman.webs.com/apps/links/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.16384
GCIE: Google Chrome v30.0.1599.101 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows 8 Business Edition, 64-bit Service Pack 1 (9600)
Windows Server License Manager Script : OK
~ ion : Windows(R) Operating System, RETAIL channel
Windows ID Activation : OK
~ Windows Partial Key : JTXGM
Windows License : OK
~ Windows Remaining Initializations Number : 1000
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 1.75.0.1300
Ad-Aware Antivirus v11.0.4555.0
Windows Defender W8

---\\ Logiciels d'optimisation du système

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Reader XI
Java 7 Update 45

---\\ Informations sur le système
~ Processor: Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 4047 MB (62% free)
System Restore: Activé (Enable)
System drive C: has 87 GB (58%) free of 149 GB

---\\ Mode de connexion au système
~ Computer Name: PC-TDELIEGE
~ User Name: Thomas
~ All Users Names: ___VMware_Conv_SA___, Thomas, Administrateur,
~ Unselected Option: None
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Thomas\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Thomas\AppData\Roaming\
~ %Desktop% : C:\Users\Thomas\Desktop\
~ %Favorites% : C:\Users\Thomas\Favorites\
~ %LocalAppData% : C:\Users\Thomas\AppData\Local\
~ %StartMenu% : C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 87 Go of 149 Go)
D: CD-ROM drive (Not Inserted)
E: Floppy drive, Flash card reader, USB Key (Free 15 Go of 15 Go)
F: Floppy drive, Flash card reader, USB Key (Free 4 Go of 4 Go)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : Out Of Date
~ Security Center: 41 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.8479DC46E9A09015C0777A16BC22A15D] - (.Microsoft Corporation - Explorateur Windows.) (.22/08/2013 - 13:39:51.) -- C:\Windows\Explorer.exe [2328880]
[MD5.48CFA7BE561A7BE144C29BB912055016] - (.Microsoft Corporation - Application de démarrage de Windows.) (.22/08/2013 - 10:58:29.) -- C:\Windows\System32\Wininit.exe [144384]
[MD5.F267E9AE8279DF0F4F0246135F2BAF5C] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.26/09/2013 - 08:21:02.) -- C:\Windows\System32\wininet.dll [2332160]
[MD5.7C94FDA3809015B8F2208D2E1C221F17] - (.Microsoft Corporation - Application d‚ouverture de session Windows.) (.22/08/2013 - 10:55:08.) -- C:\Windows\System32\Winlogon.exe [564736]
[MD5.2F18065618E39AA2E656EE737B71E791] - (.Microsoft Corporation - Bibliothèque de licences.) (.22/08/2013 - 11:39:40.) -- C:\Windows\System32\sppcomapi.dll [447488]
[MD5.239268BAB58EAE9A3FF4E08334C00451] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.22/08/2013 - 14:25:35.) -- C:\Windows\system32\Drivers\AFD.sys [567296]
[MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.22/08/2013 - 13:43:41.) -- C:\Windows\system32\Drivers\atapi.sys [26464]
[MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) (.22/08/2013 - 12:40:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [88576]
[MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.22/08/2013 - 09:46:35.) -- C:\Windows\system32\Drivers\Cdrom.sys [164352]
[MD5.5DB26D7E0216D0BF364A81D3829AD7B9] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.22/08/2013 - 12:38:00.) -- C:\Windows\system32\Drivers\DfsC.sys [134656]
[MD5.03909BDBFF0DCACCABF2B2D4ADEE44DC] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.22/08/2013 - 12:38:38.) -- C:\Windows\system32\Drivers\HDAudBus.sys [78336]
[MD5.84CFC5EFA97D0C965EDE1D56F116A541] - (.Microsoft Corporation - Pilote de port i8042.) (.22/08/2013 - 12:39:15.) -- C:\Windows\system32\Drivers\i8042prt.sys [107520]
[MD5.0063040EFD7C5B81D67CF985BA35388A] - (.Microsoft Corporation - IP Network Address Translator.) (.22/08/2013 - 12:35:33.) -- C:\Windows\system32\Drivers\IpNat.sys [141824]
[MD5.405A2E5754DF76663CF0522B87D7929F] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.22/08/2013 - 12:36:11.) -- C:\Windows\system32\Drivers\MRxSmb.sys [402432]
[MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) (.22/08/2013 - 12:37:02.) -- C:\Windows\system32\Drivers\netBT.sys [282624]
[MD5.4412D565C0278C401575E11072C7DCE3] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.22/08/2013 - 14:25:41.) -- C:\Windows\system32\Drivers\ntfs.sys [2011488]
[MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Pilote de port parallèle.) (.22/08/2013 - 12:40:02.) -- C:\Windows\system32\Drivers\Parport.sys [94208]
[MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.22/08/2013 - 12:35:51.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [120832]
[MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.22/08/2013 - 23:26:13.) -- C:\Windows\system32\Drivers\rdpdr.sys [195584]
[MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) (.22/08/2013 - 14:25:35.) -- C:\Windows\system32\Drivers\tdx.sys [107520]
[MD5.9F9CE33B50611A1C61A46B8911E0B30B] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.22/08/2013 - 13:39:15.) -- C:\Windows\system32\Drivers\volsnap.sys [312160]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/2
~ Mes musiques (My Musics) : 1/50
~ Mes Favoris (My Favorites) : 1/3
~ Mes Documents (My Documents) : 2/12
~ Mon Bureau (My Desktop) : 1/2822
~ Menu demarrer (Programs) : 1/21
~ Hidden Files: Scanned in 00mn 00s



---\\ Processus lancés
[MD5.3E399A1328181C2A352472369DE2A93A] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [844752] [PID.3980]
[MD5.89BECCA60E9A652934D65EDB72A438A4] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8174080] [PID.1740]
~ Processes Running: Scanned in 00mn 00s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Preferences
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.5.0 (Activé)
~ Google Browser: 15 Legitimates Filtered in 00mn 10s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.fr.auchan.com
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21



---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: Ad-Aware Antivirus.lnk . (...) -- C:\Program Files (x86)\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\AdAwareDesktop.exe (.not file.)
O4 - GS\Desktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\Desktop [Public]: SimulPret 2013.lnk . (.WebImmo - SimulPret 2013.) -- C:\Program Files (x86)\WebImmo\SIMULPRET.exe
O4 - GS\Desktop [Public]: VMware vCenter Converter Standalone Client.lnk . (.VMware, Inc. - Converter Standalone Application.) -- C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\converter.exe
O4 - GS\Desktop [Public]: VMware vSphere Client.lnk . (.VMware, Inc. - VpxClient.) -- C:\Program Files (x86)\VMware\Infrastructure\Virtual Infrastructure Client\Launcher\VpxClient.exe
O4 - GS\Program [Public]: Desktop.lnk - Clé orpheline
O4 - GS\QuickLaunch [Thomas]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\QuickLaunch [Thomas]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\TaskBar [Thomas]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\TaskBar [Thomas]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Program [Thomas]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Desktop [Thomas]: Secure Download Manager.lnk . (...) -- C:\Users\Thomas\AppData\Roaming\Microsoft\Installer\{6DEC47B2-CAF8-484A-B482-851BB8C1657B}\_C0FD2C793C8AF50B9B1C8A.exe
O4 - GS\Desktop [Thomas]: SosVirus Forum Gratuit.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe https://www.sosvirus.net
O4 - GS\Desktop [Thomas]: SosVirus sur Facebook.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe https://www.facebook.com
O4 - GS\Desktop [Thomas]: Tera Term.lnk . (.TeraTerm Project T. Teranishi - Tera Term.) -- C:\Program Files (x86)\teraterm\ttermpro.exe
O4 - GS\Desktop [Thomas]: Tftpd64.lnk . (...) -- C:\Program Files (x86)\Tftpd64\tftpd64.exe (.not file.)
~ Global Startup: 50 Legitimates Filtered in 00mn 00s



---\\ Applications lancées au démarrage du sytème (O4)
O4 - GS\Startup [Thomas]: OneNote 2010 - Capture d‚écran et lancement.lnk . (...) -- C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.exe (.not file.)
O4 - HKLM\..\Run: [AdAwareTray] . (...) -- C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\AdAwareTray.exe
O4 - HKCU\..\Run: [OfficeSyncProcess] . (.Microsoft Corporation - Microsoft Office Document Cache.) -- C:\Program Files\Microsoft Office\Office14\MSOSYNC.exe
O4 - HKLM\..\Wow6432Node\Run: [Communicator] . (.Microsoft Corporation - Microsoft Lync 2010.) -- C:\Program Files (x86)\Microsoft Lync\communicator.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle Corporation
O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKUS\S-1-5-21-3653578804-3571681521-2262723874-1001\..\Run: [OfficeSyncProcess] . (.Microsoft Corporation - Microsoft Office Document Cache.) -- C:\Program Files\Microsoft Office\Office14\MSOSYNC.exe
~ Application: Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: &Envoyer à  OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files (x86)\MICROS~1\Office14\ONBttnIE.dll =>.Microsoft Corporation
O9 - Extra button: Notes &liées OneNote [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files (x86)\MICROS~1\Office14\ONBTTN~1.dll =>.Microsoft Corporation
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{178490F9-525D-44DC-9329-D31FF54F3F6D}: DhcpNameServer = 10.59.0.22 10.54.201.12
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A7CF58F-05C4-4828-AB6B-578A8F8F2B63}: DhcpNameServer = 128.239.31.12 128.239.31.11
O17 - HKLM\System\CCS\Services\Tcpip\..\{81C82394-CBF7-4C3A-B53B-E0ED9941F3D1}: DhcpNameServer = 192.168.10.110
O17 - HKLM\System\CCS\Services\Tcpip\..\{CB9C42AC-3F95-45EB-922D-C885F0D62966}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\..\{178490F9-525D-44DC-9329-D31FF54F3F6D}: DhcpDomain = groupe.loc
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A7CF58F-05C4-4828-AB6B-578A8F8F2B63}: DhcpDomain = f9971.fr.auchan.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{178490F9-525D-44DC-9329-D31FF54F3F6D}: DhcpNameServer = 10.59.0.22 10.54.201.12
O17 - HKLM\System\CS1\Services\Tcpip\..\{2A7CF58F-05C4-4828-AB6B-578A8F8F2B63}: DhcpNameServer = 128.239.31.12 128.239.31.11
O17 - HKLM\System\CS1\Services\Tcpip\..\{81C82394-CBF7-4C3A-B53B-E0ED9941F3D1}: DhcpNameServer = 192.168.10.110
O17 - HKLM\System\CS1\Services\Tcpip\..\{CB9C42AC-3F95-45EB-922D-C885F0D62966}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CS1\Services\Tcpip\..\{178490F9-525D-44DC-9329-D31FF54F3F6D}: DhcpDomain = groupe.loc
O17 - HKLM\System\CS1\Services\Tcpip\..\{2A7CF58F-05C4-4828-AB6B-578A8F8F2B63}: DhcpDomain = f9971.fr.auchan.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.59.0.22 10.54.201.12
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Ad-Aware Service 11 (LavasoftAdAwareService11) . (...) - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\AdAwareService.exe
O23 - Service: VMware vCenter Converter Standalone Work (vmware-converter-worker) . (.VMware, Inc. - VMware Converter Service.) - C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe
~ Services: 11 Legitimates Filtered in 00mn 02s



---\\ Logiciels installés (O42)
O42 - Logiciel: SimulPret 2013 - (.WebImmo.) [HKLM][64Bits] -- {443417E0-B824-406D-9900-7E38BA9C8D5D}_is1
O42 - Logiciel: Tftpd64 Standalone Edition (remove only) - (...) [HKLM][64Bits] -- Tftpd64
~ Logic: 55 Legitimates Filtered in 00mn 00s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\Litecoin]
[HKCU\Software\WebImmo]
[HKLM\Software\Wow6432Node\Litecoin]
[HKLM\Software\Wow6432Node\WebImmo]
~ Key Software: 114 Legitimates Filtered in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 23/09/2013 - 12:15:08 - [9,930] ----D C:\Program Files (x86)\teraterm
O43 - CFD: 30/10/2013 - 16:28:47 - [22,637] ----D C:\Program Files (x86)\WebImmo
O43 - CFD: 30/10/2013 - 16:28:50 - [0] ----D C:\ProgramData\WebImmo
O43 - CFD: 29/10/2013 - 10:43:41 - [28,324] ----D C:\Users\Thomas\AppData\Roaming\Litecoin
O43 - CFD: 30/10/2013 - 16:28:51 - [0,009] ----D C:\Users\Thomas\AppData\Local\WebImmo
~ Program Folder: 108 Legitimates Filtered in 00mn 00s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.E42AA704FE95A55263792152E2A449F5] - 05/11/2013 - 12:21:26 ----- . (...) -- C:\UsbFix [Scan 1] PC-TDELIEGE.txt [5898]
O44 - LFC:[MD5.9E963867AEFAA72BB73D975DD43AAB21] - 05/11/2013 - 12:22:37 ---A- . (...) -- C:\UsbFix [Clean 1] PC-TDELIEGE.txt [6663]
O44 - LFC:[MD5.1363812D50F19B484B6C42F64D2ACA2E] - 23/10/2013 - 07:58:06 ---A- . (...) -- C:\Windows\vbaddin.ini [39]
~ Files: 19 Legitimates Filtered in 00mn 02s



---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.801F5107652A31CF64BD622C8D4C841B] - 04/11/2013 - 11:24:48 ---A- - C:\Windows\Prefetch\RCSETUP148.EXE-EC5128BF.pf
O45 - LFCP:[MD5.88AE0372401F6E27E3153FDF56FF7E83] - 04/11/2013 - 11:36:00 ---A- - C:\Windows\Prefetch\PDR6FREE.TMP-68BE4404.pf
O45 - LFCP:[MD5.44C93D0411D9B8F31020CFA3127F5A70] - 04/11/2013 - 11:36:01 ---A- - C:\Windows\Prefetch\PDR6FREE.TMP-4405F9DC.pf
O45 - LFCP:[MD5.AD610ADA3E0C9CAB605DB122687D7944] - 04/11/2013 - 11:36:37 ---A- - C:\Windows\Prefetch\POWERDATARECOVERY.EXE-83C70CC5.pf
O45 - LFCP:[MD5.282B6E474D5D34D057C1C419ECFD600F] - 04/11/2013 - 11:47:45 ---A- - C:\Windows\Prefetch\_IU14D2N.TMP-1EDFD8EE.pf
O45 - LFCP:[MD5.32BD376DD8C38A4166C850A9B4BB28AE] - 04/11/2013 - 12:00:23 ---A- - C:\Windows\Prefetch\INSTUP.EXE-37308BC5.pf
O45 - LFCP:[MD5.6B30A8716DD6BF181EAFBB50A0763658] - 04/11/2013 - 15:13:30 ---A- - C:\Windows\Prefetch\OPEN-CONFIG.EXE-E33F11B1.pf
O45 - LFCP:[MD5.23CFD470CCACA122B896087B49D7EE65] - 04/11/2013 - 15:58:37 ---A- - C:\Windows\Prefetch\INSTUP.EXE-7E543EAF.pf
O45 - LFCP:[MD5.2919ADDD0755FF7C6894930B1D49AE61] - 04/11/2013 - 15:58:37 ---A- - C:\Windows\Prefetch\MSOIDSVC.EXE-CD102AD6.pf
O45 - LFCP:[MD5.52377A0568E18027B567DF4DCD6ACEB1] - 04/11/2013 - 16:35:54 ---A- - C:\Windows\Prefetch\ADAWARE_INSTALLER.EXE-5C87D1EA.pf
O45 - LFCP:[MD5.D55A3E6079091832BC4072354B0F6CDF] - 04/11/2013 - 16:39:49 ---A- - C:\Windows\Prefetch\ADAWARESECURITYCENTER.EXE-4F0BFFB9.pf
O45 - LFCP:[MD5.EF4375DC46E734CB42835D8045A13C79] - 05/11/2013 - 09:29:10 ---A- - C:\Windows\Prefetch\UCMAPI64.EXE-0D52D91F.pf
O45 - LFCP:[MD5.97DA09414E32B67274012AA7DC1A2327] - 05/11/2013 - 09:43:11 ---A- - C:\Windows\Prefetch\ADAWARESERVICE.EXE-B2E18E61.pf
O45 - LFCP:[MD5.F2F264D194C1C519ADC5E096DECBA2DA] - 05/11/2013 - 09:43:21 ---A- - C:\Windows\Prefetch\ADAWAREDESKTOP.EXE-519564B6.pf
O45 - LFCP:[MD5.55F57C095C788EA29679F4E221EA2C20] - 05/11/2013 - 10:10:33 ---A- - C:\Windows\Prefetch\ADAWARETRAY.EXE-8158A9F4.pf
O45 - LFCP:[MD5.57D927519D93C47EC97F9D572F3D9483] - 05/11/2013 - 10:12:43 ---A- - C:\Windows\Prefetch\WSHOST.EXE-3BD2AA25.pf
O45 - LFCP:[MD5.8E6CCED31078BF184048AD862DF50867] - 05/11/2013 - 12:08:41 ---A- - C:\Windows\Prefetch\dynreservedpri.db
O45 - LFCP:[MD5.D55ADEF32498452D7B5379EBA3F6AA80] - 05/11/2013 - 12:20:17 ---A- - C:\Windows\Prefetch\GO.EXE-0A7DE786.pf
O45 - LFCP:[MD5.DB7DF352D4D0A48A24B67D0B6C4E915E] - 05/11/2013 - 12:21:03 ---A- - C:\Windows\Prefetch\FSUM.COM-68738D89.pf
O45 - LFCP:[MD5.68998E65ABFDE55C66FE07A74AB137EC] - 05/11/2013 - 12:22:35 ---A- - C:\Windows\Prefetch\MSOIDSVCM.EXE-459B27E7.pf
O45 - LFCP:[MD5.AF6A601385591A7D93010DCEA1BA709D] - 05/11/2013 - 13:09:32 ---A- - C:\Windows\Prefetch\PfPre_4fbb62e8.db
O45 - LFCP:[MD5.1794F3DE1901E89DAD0CA8DFDE23FDA7] - 17/10/2013 - 13:52:50 ---A- - C:\Windows\Prefetch\G2MSTART.EXE-56055175.pf
O45 - LFCP:[MD5.C74646001A7A6EBB3663EC96FB028F9F] - 17/10/2013 - 13:52:51 ---A- - C:\Windows\Prefetch\G2MMATCHMAKING.EXE-FD010203.pf
O45 - LFCP:[MD5.170E15E288D61F1C447E4619AA01CA93] - 17/10/2013 - 13:53:01 ---A- - C:\Windows\Prefetch\G2MUI.EXE-19AF2C85.pf
O45 - LFCP:[MD5.283E0388B854B2D75D0E4E5E44F24F12] - 23/10/2013 - 14:07:20 ---A- - C:\Windows\Prefetch\VISIO.EXE-EDBB8EEB.pf
O45 - LFCP:[MD5.60063A614DB5FC020D4A336DB03FAA69] - 25/10/2013 - 08:51:04 ---A- - C:\Windows\Prefetch\SECUREDOWNLOADMANAGER.EXE-16B6807F.pf
O45 - LFCP:[MD5.44BBD4D7560B5D464FC102DE011C3F06] - 25/10/2013 - 13:01:09 ---A- - C:\Windows\Prefetch\PCNSL.EXE-C694F48A.pf
O45 - LFCP:[MD5.1E8F1A348632DB08A3DFF1276AD54837] - 29/10/2013 - 10:23:48 ---A- - C:\Windows\Prefetch\LITECOIN-0.8.5.1-WIN32-SETUP.-2D1FE562.pf
O45 - LFCP:[MD5.3583C29F9D593E498213690951640E3C] - 29/10/2013 - 10:38:43 ---A- - C:\Windows\Prefetch\LITECOIN-QT.EXE-15429771.pf
O45 - LFCP:[MD5.90ABB495BA379A25CCDBC7B989444651] - 30/10/2013 - 16:28:48 ---A- - C:\Windows\Prefetch\SETUP-SIMULPRET-2013.TMP-3BE61801.pf
O45 - LFCP:[MD5.DCC0A9C82CB7C8344535B1036289025D] - 30/10/2013 - 16:28:48 ---A- - C:\Windows\Prefetch\SETUP-SIMULPRET-2013.TMP-7A15FC46.pf
O45 - LFCP:[MD5.3346A58BE9414841D4BA095049E961E1] - 30/10/2013 - 16:29:00 ---A- - C:\Windows\Prefetch\SIMULPRET.EXE-867A9092.pf
O45 - LFCP:[MD5.E4782D96EBC7D7055649D8333161C006] - 30/10/2013 - 16:33:00 ---A- - C:\Windows\Prefetch\REGSMP.EXE-6872167F.pf
O45 - LFCP:[MD5.A468DB39D7A01D3E4BC85172D3EC51A8] - 31/10/2013 - 11:28:36 ---A- - C:\Windows\Prefetch\X2JOBTMS.EXE-A85C9702.pf
~ Prefetcher: 219 Legitimates Filtered in 00mn 00s



---\\ Opérations et fonctions au démarrage de Windows Explorer (O46)
O46 - SEH:ShellExecuteHooks - Groove GFS Stub Execution Hook [64Bits] - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
~ ShellExecuteHooks: Scanned in 00mn 00s



---\\ Déni du service (Local Security Authority) (O48)
~ LSA: 4 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 17 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 3 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.C1ABB0F7E3BEA48A0417BDF6FF14AB21] - 13/08/2013 - 00:25:46 ---A- . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\Drivers\bcmfn2.sys [17624]
~ Drivers: 17 Legitimates Filtered in 00mn 00s



---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 04/11/2013 - 13:49:14 ---A- . (...) -- C:\Users\Thomas\AppData\Roaming\LavasoftStatistics\adaware.xml [770]
O61 - LFC: 04/11/2013 - 13:49:14 ---A- . (...) -- C:\Users\Thomas\AppData\Roaming\Lavasoft\Ad-Aware 11\Options\Language.db [0]
O61 - LFC: 04/11/2013 - 13:49:14 ---A- . (...) -- C:\Users\Thomas\AppData\Roaming\Lavasoft\Ad-Aware 11\Options\NotificationCenter.db [2048]
O61 - LFC: 04/11/2013 - 13:49:14 ---A- . (...) -- C:\Users\Thomas\Downloads\Adaware_Installer.exe [1723528]
O61 - LFC: 05/11/2013 - 13:49:12 ---A- . (...) -- C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Local State [47150]
O61 - LFC: 05/11/2013 - 13:49:14 ---A- . (...) -- C:\Users\Thomas\AppData\Roaming\Lavasoft\Ad-Aware 11\Options\FirstRun [0]
O61 - LFC: 05/11/2013 - 13:49:14 ---A- . (...) -- C:\Users\Thomas\AppData\Roaming\Microsoft\MMC\services [93504]
O61 - LFC: 05/11/2013 - 13:49:14 ---A- . (...) -- C:\Users\Thomas\AppData\Roaming\ZHP\Log.txt [17067] =>.Nicolas Coolman
O61 - LFC: 05/11/2013 - 13:49:14 ---A- . (...) -- C:\Users\Thomas\AppData\Roaming\ZHP\TestsZHPDiag.txt [2875] =>.Nicolas Coolman
O61 - LFC: 05/11/2013 - 13:49:14 ---A- . (...) -- C:\Users\Thomas\Tracing\Communicator-uccapi-0.uccapilog [0]
O61 - LFC: 05/11/2013 - 13:49:14 ---A- . (...) -- C:\Users\Thomas\Tracing\Communicator-uccapi-0.uccapilog.bak [0]
O61 - LFC: 05/11/2013 - 13:49:14 -SHA- . (...) -- C:\Users\Thomas\AppData\Roaming\Microsoft\Credentials\9A7273293F661FADBDDF9630262410BD [608]
~ 1 Fichiers temporaires (Temporary files)
~ Files: 191 Legitimates Filtered in 00mn 03s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: UsbFix By El Desaparecido - (.El Desaparecido - https://www.usbfix.net.) [HKLM] -- Usbfix
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 10 Legitimates Filtered in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - https://www.bing.com
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à  la racine du système (SPRF) (O84)
[MD5.A3CCFD0AA0B17FD23AA9FD0D84B86C05] [SPRF][17/12/2012] (.Simon Tatham - SSH, Telnet and Rlogin client.) -- C:\Users\Thomas\Desktop\putty.exe [483328]
~ Files: 2 Legitimates Filtered in 00mn 08s



---\\ Liste des exceptions du parefeu (FirewallRules) (O87)
O87 - FAEL: "TCP Query User{9B16F93F-99AB-4F29-8A2F-D0580DE17D2F}C:\program files\tftpd64\tftpd64.exe" | In - Public - P6 - TRUE | .(.Ph. Jounin - TFTP server.) -- C:\program files\tftpd64\tftpd64.exe
O87 - FAEL: "UDP Query User{1CF81E52-7091-4A62-9122-6B6173011395}C:\program files\tftpd64\tftpd64.exe" | In - Public - P17 - TRUE | .(.Ph. Jounin - TFTP server.) -- C:\program files\tftpd64\tftpd64.exe
O87 - FAEL: "TCP Query User{CD4E3E7F-277D-45C4-A7F0-27D4F8D802F8}C:\program files (x86)\litecoin\litecoin-qt.exe" |In - Public - P6 - TRUE | .(...) -- C:\program files (x86)\litecoin\litecoin-qt.exe (.not file.)
O87 - FAEL: "UDP Query User{A1E1340B-7AA8-4969-BEC8-2A731A7C41AB}C:\program files (x86)\litecoin\litecoin-qt.exe" |In - Public - P17 - TRUE | .(...) -- C:\program files (x86)\litecoin\litecoin-qt.exe (.not file.)
~ Firewall: 241 Legitimates Filtered in 00mn 00s



---\\ Enumère les codes produits des logiciels (PUC) (O90)
O90 - PUC: "24BED006A334FA04CB4180E20475B72F" . (.AntimalwareEngine.) -- C:\Windows\Installer\{600DEB42-433A-40AF-BC14-082E40577BF2}\ARPPRODUCTICON.exe
O90 - PUC: "7EC780A0346F8EF45A2DB0AB4F7A0B23" . (.AdAwareUpdater.) -- C:\Windows\Installer\{0A087CE7-F643-4FE8-A5D2-0BBAF4A7B032}\ARPPRODUCTICON.exe
O90 - PUC: "894D1EBE767AE9840ADD3F718A8B5397" . (.AdAwareInstaller.) -- C:\Windows\Installer\{EBE1D498-A767-489E-A0DD-F317A8B83579}\ARPPRODUCTICON.exe
~ Update Products: 44 Legitimates Filtered in 00mn 00s



---\\ Enumère les données de la clé NameSpace (MNS) (O92)
O92 - MNS: - {1CF1260C-4DD0-4ebb-811F-33C572699FDE}
O92 - MNS: - {374DE290-123F-4565-9164-39C4925E467B}
O92 - MNS: - {3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA}
O92 - MNS: - {A0953C92-50DC-43bf-BE83-3742FED03C9C}
O92 - MNS: - {A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}
O92 - MNS: - {B4BFCC3A-DB2C-424C-B029-7FE99A87C641}
~ MNS: 6 Legitimates Filtered in 00mn 00s



---\\ Etat général des services not Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Auto 05/09/2013 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 07/09/2013 55624 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SS - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SS - | Auto 23/09/2013 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 23/09/2013 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 23/10/2013 641352 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SS - | Auto 18/10/2013 517344 | (LavasoftAdAwareService11) . (...) - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\AdAwareService.exe
SS - | Auto 04/04/2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
SS - | Auto 04/04/2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
SR - | Auto 05/09/2012 856728 | (VMUSBArbService) . (.VMware, Inc..) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
SS - | Auto 09/04/2013 479824 | (vmware-converter-agent) . (.VMware, Inc..) - C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe
SR - | Auto 09/04/2013 479824 | (vmware-converter-server) . (.VMware, Inc..) - C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe
SS - | Auto 09/04/2013 479824 | (vmware-converter-worker) . (.VMware, Inc..) - C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe
SR - | Demand 10/07/1658 0 | (WdNisSvc) . (...) - C:\Program Files (x86)\Windows Defender\NisSrv.exe
SS - | Demand 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
SS - | Demand 22/08/2013 37768 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 22s



---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Run by Thomas at 05/11/2013 13:50:17
~ OS 64 not supported by MBR tool
~ MBR: 0 Legitimates Filtered in 00mn 00s



---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, https://ad13.geekstog
Run by Thomas at 05/11/2013 13:50:19

********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 02s



---\\ Scan Additionnel (O88)
Database Version : 12971 - (04/11/2013)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 0

[HKLM\Software\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}] =>Toolbar.Ask
~ Additionnel Scan: 264641 Items scanned in 00mn 19s



---\\ Récapitulatif des détections trouvées sur votre station
~ https://nicolascoolman.webs.com/apps/blog/show/28927746-toolbar-ask =>Toolbar.Ask
~ MSI: 1 link(s) detected in 00mn 19s



~ 1169 Legitimates filtered by white list
End of the scan (471 lines in 02mn 02s)(0)
#14585
Re ,

Ton PC ainsi que ta clé ne présente pas|plus d'infection , je reverrais la vaccination UsbFix pour Windows 8.1 ;)

En attendant , tu peux vacciner ta clé via Bitdefender immunizer :) : https://www.bitdefender.fr/toolbox/freeapps/desktop/ ( Téléchargement direct )

Tu vas pouvoir désinstaller ZhpDiag ainsi que UsbFix et passer ton sujet en résolu :)

Tu aimes SosVirus ? : Like notre page afin de nous faire connaitre :super:

[pagefan][/pagefan]
navigateur qui plante

Bonjour, Pour commencer, nous allons éta[…]

PC bloqué sur une image

salut à vous peut-être tester avec u[…]

[RESOLU] Virus sur pc

Merci à vous pour l'aide :)

Mimisuitou N' installez pas de cracks sur votre […]