~ Rapport de ZHPDiag v2013.11.17.37 - Nicolas Coolman (17/11/2013)
~ Lancé par ELVIRA (17/11/2013 11:46:31)
~ Adresse du Site Web
https://nicolascoolman.webs.com
~ Forums gratuits d'Assistance à la désinfection :
https://nicolascoolman.webs.com/apps/links/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by program
---\\ Navigateurs Internet
MSIE: Internet Explorer v10.0.9200.16736
MFIE: Mozilla Firefox 25.0.1 (Defaut)
GCIE: Google Chrome v6.0.422.0
---\\ Informations sur les produits Windows
~ Langage: Français
Windows 7 Ultimate Edition, 32-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : HYRR2
Windows License : OK
~ Windows Remaining Initializations Number : 4
Software Protection Service (Protection logicielle) : OK
Key Management Service client information : KO
Windows Automatic Updates : OK
Windows Activation Technologies : OK
---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft Security Client v4.4.0304.0
Windows Defender W7
---\\ Logiciels d'optimisation du système
CCleaner v3.10 =>Piriform Ltd
---\\ Logiciels de partage PeerToPeer
µTorrent v3.0.0 =>P2P.µTorrent
---\\ Surveillance de Logiciels
Adobe Flash Player 9 ActiveX
Adobe Reader XI
---\\ Informations sur le système
~ Processor: x86 Family 6 Model 42 Stepping 7, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3498 MB (48% free)
System Restore: Activé (Enable)
System drive C: has 28 GB (34%) free of 80 GB
---\\ Mode de connexion au système
~ Computer Name: LABARAKA
~ User Name: ELVIRA
~ All Users Names: ELVIRA, Administrateur,
~ Unselected Option: None
Logged in as Administrator
---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\ELVIRA\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\ELVIRA\AppData\Roaming\
~ %Desktop% : C:\Users\ELVIRA\Desktop\
~ %Favorites% : C:\Users\ELVIRA\Favorites\
~ %LocalAppData% : C:\Users\ELVIRA\AppData\Local\
~ %StartMenu% : C:\Users\ELVIRA\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 28 Go of 80 Go)
D: Hard drive, Flash drive, Thumb drive (Free 62 Go of 204 Go)
E: CD-ROM drive (Not Inserted)
G: Floppy drive, Flash card reader, USB Key (Not Inserted)
H: CD-ROM drive (Not Inserted)
---\\ Etat du Centre de Sécurité Windows
~ Security Center: 43 Legitimates Filtered in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 05:30:54.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 01:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.5FD4335DCD343D0FEA9FA6B18ED408D9] - (.Microsoft Corporation - Internet Extensions for Win32.) (.12/10/2013 - 07:03:50.) -- C:\Windows\System32\wininet.dll [1767936]
[MD5.6D13E1406F50C66E2A95D97F22C47560] - (.Microsoft Corporation - Application d‚ouverture de session Windows.) (.20/11/2010 - 12:17:54.) -- C:\Windows\System32\Winlogon.exe [286720]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 12:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.F81BB7E487EDCEAB630A7EE66CF23913] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.14/09/2013 - 00:48:58.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 01:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.13/07/2009 - 23:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 08:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 08:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 09:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.13/07/2009 - 23:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.13/07/2009 - 23:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 02:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 08:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.5E43D2B0EE64123D4880DFA6626DEFDE] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 13:45:29.) -- C:\Windows\system32\Drivers\ntfs.sys [1211752]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.13/07/2009 - 23:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.13/07/2009 - 23:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.B973FCFC50DC1434E1970A146F7E3885] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.20/11/2010 - 10:24:46.) -- C:\Windows\system32\Drivers\rdpdr.sys [133632]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.13/07/2009 - 23:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.B459575348C20E8121D6039DA063C704] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 08:39:17.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 12:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Generic Processes: Scanned in 00mn 04s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 0/2
~ Mes musiques (My Musics) : 0/0
~ Mes Videos (My Videos) : 0/2
~ Mes Favoris (My Favorites) : 0/26
~ Mes Documents (My Documents) : 0/115
~ Mon Bureau (My Desktop) : 0/227
~ Menu demarrer (Programs) : 0/51
~ Hidden Files: Scanned in 00mn 01s
---\\ Processus lancés
[MD5.D1D5DAB39DCB4BE0359943738D87409B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [532040] [PID.1088]
[MD5.9BF89FDDE6B35216394FC7495404E8C0] - (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxtray.exe [144704] [PID.1972]
[MD5.67C9CE015B1183BA94103587F69CE7C9] - (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe [180544] [PID.2556]
[MD5.9F572DB1A9E57A0ACE41680144D8E6C2] - (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe [188224] [PID.4076]
[MD5.D658AB1B55127D18DCFBCAC8CAAEA522] - (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files\HP\HP Software Update\hpwuschd2.exe [49208] [PID.3020]
[MD5.5BD2DA256A68E99622D6968330DCC461] - (.Microsoft Corporation - Zune Auto-Launcher.) -- C:\Program Files\Zune\ZuneLauncher.exe [159456] [PID.2188]
[MD5.3CB07566302BCEEB898DE270A0BEC175] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352] [PID.2756]
[MD5.C948AC73822CA662CF44185B909EA18B] - (.Microsoft Corporation - Microsoft Office Document Cache.) -- C:\Program Files\Microsoft Office\Office14\MSOSYNC.exe [720064] [PID.4072]
[MD5.BB7245420097B251D1271F5B6F0C9F02] - (.BitTorrent Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe [802136] [PID.1820] =>P2P.BitTorrent
[MD5.2A3FB4C98F139038E23330D2439DB8A4] - (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\ELVIRA\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [PID.3696]
[MD5.B2D8D369CA7C2EDB57B45891894C38D7] - (.ManyCam LLC - ManyCam Virtual Webcam.) -- C:\Program Files\ManyCam\Bin\ManyCam.exe [1760328] [PID.4008]
[MD5.2A1BE3D0B2F439ABB52EF1570D8EB4F7] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe [20549280] [PID.476]
[MD5.E3C9871EF0954E96AB76DAF9287D89D0] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet download manager\IDMan.exe [3118512] [PID.3928]
[MD5.16095BD0F5CA64BA76DBE7A72E16EA45] - (...) -- C:\Program Files\InternetEverywhere\InternetEverywhere_Launcher.exe [523208] [PID.2020]
[MD5.C64E9B1C9EA057DCECDCB98F34377811] - (.Microsoft Corporation - Microsoft OneNote Quick Launcher.) -- C:\Program Files\Microsoft Office\Office14\ONENOTEM.exe [228552] [PID.3060]
[MD5.52B3F695EDC908F3575A6834311E2968] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files\Internet download manager\IEMonitor.exe [251312] [PID.5228]
[MD5.50650A6B920C576FC1C8266E17DD28BD] - (.Intel Corporation - IAStorIcon.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284480] [PID.3964]
[MD5.824512C3EAE3462388B8861986907E28] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8227328] [PID.5212]
~ Processes Running: Scanned in 00mn 14s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\ELVIRA\AppData\Local\Google\Chrome\User Data\Default\Preferences
G1 - GCS: Preference [User Data\Default]
https://www.bing.com
~ Google Browser: 1 Legitimates Filtered in 00mn 24s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\ELVIRA\AppData\Roaming\Mozilla\Firefox\Profiles\tmz4fszt.default\prefs.js
M2 - MFEP: prefs.js [ELVIRA - tmz4fszt.default\
89a067de1f3b83b4cf75a861d6bc674b16123522@builder.extensionfactory.com] [] jeuneafrique.com v1.2.2 (..)
~ Firefox Browser: 13 Legitimates Filtered in 00mn 01s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\Userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Tonec Inc. - IDM BHO Module.) -- C:\Program Files\Internet download manager\IDMIECC.dll
O2 - BHO: qualitink - {73ad5d47-66e5-4127-80ca-c0eedabafbcc} . (.qualitink - qualitink.) -- C:\Program Files\qualitink\qualitinkBHO.dll =>Adware.Qualitink
~ BHO: 12 Legitimates Filtered in 00mn 01s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Bing Bar - [HKLM]{eec0f710-38b5-4aba-99bf-ec87564a4e13} . (.Microsoft Corporation. - Extensions du client Bing.) -- C:\Program Files\Microsoft\BingBar\7.2.241.0\BingExt.dll =>Toolbar.Bing
~ Toolbar: Scanned in 00mn 00s
---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: Anti Raccourci 1.0.9.lnk . (.Format Lux Corporation - BELAID OUAREZKI.) -- C:\Program Files\Anti Raccourci 1.0.9\autorun.exe
O4 - GS\Desktop [Public]: Internet Everywhere.lnk . (...) -- C:\Program Files\InternetEverywhere\InternetEverywhere.exe
O4 - GS\Desktop [Public]: LG PC Suite II.lnk . (...) -- C:\Program Files\LG PC Suite II\LG_MobileSync_Launcher.exe
O4 - GS\Desktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O4 - GS\Desktop [Public]: S7-200 Documents.lnk . (...) -- C:\Program Files\Siemens\SIMATIC S7-200 Documentation\start.htm
O4 - GS\Desktop [Public]: V1.0 TD Keypad Designer.lnk . (.Siemens - TD Keypad Designer.) -- C:\Program Files\Siemens\TD Keypad Designer\Bin\KeypadDesigner.exe
O4 - GS\Desktop [Public]: V2.0 S7-200 Explorer.lnk . (.Siemens - S7-200 Explorer.) -- C:\Program Files\Siemens\S7-200 Explorer\bin\S7200Explor.exe
O4 - GS\Desktop [Public]: V4.0 STEP 7 MicroWIN SP9.lnk . (.Siemens - Micro/WIN Executable.) -- C:\Program Files\Siemens\STEP 7-MicroWIN V4.0\bin\microwin.exe
O4 - GS\Desktop [Public]: WiMAX Connection Manager.lnk . (.HUAWEI - WiMAX Connection Manager.) -- C:\Program Files\WiMAX Connection Manager\WiMAX Connection Manager.exe
O4 - GS\Desktop [Public]: Xilisoft HD Vidéo Convertisseur 6.lnk . (...) -- C:\Program Files\Xilisoft\HD Video Converter 6\vcloader.exe =>.Xilisoft
O4 - GS\Desktop [Public]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe =>P2P.BitTorrent
O4 - GS\Program [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O4 - GS\QuickLaunch [ELVIRA]: Babylon.lnk . (...) -- C:\Program Files\Babylon\Babylon-Pro\Babylon.exe (.not file.) =>PUP.Babylon
O4 - GS\QuickLaunch [ELVIRA]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch [ELVIRA]: Xilisoft HD Vidéo Convertisseur 6.lnk . (...) -- C:\Program Files\Xilisoft\HD Video Converter 6\vcloader.exe =>.Xilisoft
O4 - GS\QuickLaunch [ELVIRA]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe =>P2P.BitTorrent
O4 - GS\TaskBar [ELVIRA]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\TaskBar [ELVIRA]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O4 - GS\Program [ELVIRA]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\SystemTools [ELVIRA]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\Desktop [ELVIRA]: catalogue buhler - Raccourci.lnk . (...) -- D:\catalogue buhler
O4 - GS\Desktop [ELVIRA]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Users\ELVIRA\AppData\Local\Google\Chrome\Application\chrome.exe
O4 - GS\Desktop [ELVIRA]: Le Grand Robert.lnk . (.Bureau Van Dijk – Dictionnaires Le Robert - Le Grand Robert de la langue française.) -- C:\Program Files\Le Grand Robert\grwin.exe
O4 - GS\Desktop [ELVIRA]: Media Player Classic.lnk . (.MPC-HC Team - Media Player Classic - Home Cinema.) -- C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe
O4 - GS\Desktop [ELVIRA]: NBA 2K14.lnk . (.2K Sports - 2K Sports NBA 2K14.) -- C:\Program Files\2K Sports\NBA 2K14\nba2k14.exe
O4 - GS\Desktop [ELVIRA]: q&aqaq&&.lnk . (...) -- C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\xlicons.exe
O4 - GS\Desktop [ELVIRA]: SIMATIC S7-200 Documentation.lnk . (...) -- C:\Program Files\Siemens\SIMATIC S7-200 Documentation
O4 - GS\Desktop [ELVIRA]: UltraISO.lnk . (.EZB Systems, Inc. - UltraISO Premium.) -- C:\Program Files\UltraISO\UltraISO.exe
O4 - GS\Desktop [ELVIRA]: VirtualDJ Home FREE.lnk . (.Atomix Productions - VirtualDJ.) -- C:\Program Files\VirtualDJ\virtualdj_home.exe
O4 - GS\Desktop [ELVIRA]: XRelais.lnk . (.Macrovision Corporation - InstallShield.) -- C:\Windows\Installer\{406EAD6B-EAAA-4B2B-8C95-B518D806EBD0}\XRelais.exe_F0E12CA97EFA472095C8B34F1020E5AF.exe
~ Global Startup: 93 Legitimates Filtered in 00mn 07s
---\\ Applications lancées au démarrage du sytème (O4)
O4 - GS\Startup [Public]: Launcher.lnk . (...) -- C:\Program Files\InternetEverywhere\InternetEverywhere_Launcher.exe
O4 - GS\Startup [ELVIRA]: OneNote 2010 - Capture d‚écran et lancement.lnk . (.Microsoft Corporation - Microsoft OneNote Quick Launcher.) -- C:\Program Files\Microsoft Office\Office14\ONENOTEM.exe =>.Microsoft Corporation
O4 - HKLM\..\Run: [BCSSync] . (.Microsoft Corporation - Microsoft Office 2010 component.) -- C:\Program Files\Microsoft Office\Office14\BCSSync.exe =>.Microsoft Corporation
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAStorIcon] . (.Intel Corporation - Delayed launcher.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
O4 - HKLM\..\Run: [HP Software Update] . (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe =>.Hewlett-Packard Co
O4 - HKLM\..\Run: [NeroFilterCheck] . (.Ahead Software Gmbh - NeroCheck.) -- C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Zune Launcher] . (.Microsoft Corporation - Zune Auto-Launcher.) -- C:\Program Files\Zune\ZuneLauncher.exe
O4 - HKLM\..\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated
O4 - HKLM\..\Run: [Autodesk Sync] . (.Autodesk, Inc. - Autodesk Sync.) -- C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- C:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKCU\..\Run: [OfficeSyncProcess] . (.Microsoft Corporation - Microsoft Office Document Cache.) -- C:\Program Files\Microsoft Office\Office14\MSOSYNC.exe
O4 - HKCU\..\Run: [uTorrent] . (.BitTorrent Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe =>P2P.BitTorrent
O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\ELVIRA\AppData\Local\Facebook\Update\FacebookUpdate.exe
O4 - HKCU\..\Run: [ManyCam] . (.ManyCam LLC - ManyCam Virtual Webcam.) -- C:\Program Files\ManyCam\Bin\ManyCam.exe
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet download manager\IDMan.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-2407514497-2368568406-4096991692-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-2407514497-2368568406-4096991692-1000\..\Run: [OfficeSyncProcess] . (.Microsoft Corporation - Microsoft Office Document Cache.) -- C:\Program Files\Microsoft Office\Office14\MSOSYNC.exe
O4 - HKUS\S-1-5-21-2407514497-2368568406-4096991692-1000\..\Run: [uTorrent] . (.BitTorrent Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe =>P2P.BitTorrent
O4 - HKUS\S-1-5-21-2407514497-2368568406-4096991692-1000\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\ELVIRA\AppData\Local\Facebook\Update\FacebookUpdate.exe
O4 - HKUS\S-1-5-21-2407514497-2368568406-4096991692-1000\..\Run: [ManyCam] . (.ManyCam LLC - ManyCam Virtual Webcam.) -- C:\Program Files\ManyCam\Bin\ManyCam.exe
O4 - HKUS\S-1-5-21-2407514497-2368568406-4096991692-1000\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKUS\S-1-5-21-2407514497-2368568406-4096991692-1000\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet download manager\IDMan.exe
~ Application: Scanned in 00mn 00s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\MICROS~2\Office14\ONBttnIE.dll =>.Microsoft Corporation
O9 - Extra button: Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\MICROS~2\Office14\ONBTTN~1.dll =>.Microsoft Corporation
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{462AC0BD-81BA-4E8B-BA37-E8A2F9EBA96E}: NameServer = 127.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{8B4430EB-DF19-4112-92D8-33C8B35E1F70}: NameServer = 192.168.16.250
O17 - HKLM\System\CCS\Services\Tcpip\..\{396CBDE8-04B5-4759-8D19-830966318304}: DhcpNameServer = 41.206.65.1 196.47.182.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{396CBDE8-04B5-4759-8D19-830966318304}: DhcpDomain = mtn.ci
O17 - HKLM\System\CS1\Services\Tcpip\..\{462AC0BD-81BA-4E8B-BA37-E8A2F9EBA96E}: NameServer = 127.0.0.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{8B4430EB-DF19-4112-92D8-33C8B35E1F70}: NameServer = 192.168.16.250
O17 - HKLM\System\CS1\Services\Tcpip\..\{396CBDE8-04B5-4759-8D19-830966318304}: DhcpNameServer = 41.206.65.1 196.47.182.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{396CBDE8-04B5-4759-8D19-830966318304}: DhcpDomain = mtn.ci
O17 - HKLM\System\CS2\Services\Tcpip\..\{462AC0BD-81BA-4E8B-BA37-E8A2F9EBA96E}: NameServer = 127.0.0.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{8B4430EB-DF19-4112-92D8-33C8B35E1F70}: NameServer = 192.168.16.250
O17 - HKLM\System\CS2\Services\Tcpip\..\{396CBDE8-04B5-4759-8D19-830966318304}: DhcpNameServer = 41.206.65.1 196.47.182.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{396CBDE8-04B5-4759-8D19-830966318304}: DhcpDomain = mtn.ci
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll
O18 - Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: KMService (KMService) . (...) - C:\Windows\system32\srvany.exe =>Hijacker.Office
O23 - Service: Update qualitink (Update qualitink) . (...) - C:\Program Files\qualitink\updatequalitink.exe =>Adware.Qualitink
O23 - Service: Util qualitink (Util qualitink) . (...) - C:\Program Files\qualitink\bin\utilqualitink.exe =>Adware.Qualitink
~ Services: 19 Legitimates Filtered in 00mn 17s
---\\ Tàches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [{0474B08F-1884-480D-86BB-65D101CD6B9B}] (...) -- E:\xrelais 3.1\instmsiw.exe (.not file.) [0]
~ Scheduled Task: 11 Legitimates Filtered in 00mn 15s
---\\ Logiciels installés (O42)
O42 - Logiciel: Anti Raccourci 1.0.9 version 1.0.9 - (.format lux Company, Inc..) [HKLM] -- {35B534B0-EF7F-414A-9203-B3BD407CB7DA}_is1
O42 - Logiciel: qualitink 2013.11.07.204414 - (.qualitink.) [HKLM] -- qualitink =>Adware.Qualitink
~ Logic: 111 Legitimates Filtered in 00mn 01s
---\\ HKCU & HKLM Software Keys
[HKCU\Software\crocodile-clips]
[HKCU\Software\qualitink] =>Adware.Qualitink
~ Key Software: 172 Legitimates Filtered in 00mn 01s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 16/11/2013 - 16:56:50 - [13,984] ----D C:\Program Files\Anti Raccourci 1.0.9
O43 - CFD: 24/06/2012 - 13:14:37 - [3,806] ----D C:\Program Files\LGInternetKit
O43 - CFD: 17/11/2013 - 09:04:28 - [2,256] ----D C:\Program Files\qualitink =>Adware.Qualitink
O43 - CFD: 18/01/2013 - 21:11:36 - [0,041] ----D C:\Program Files\SEE Electrical LT
O43 - CFD: 02/08/2012 - 23:36:30 - [1,196] ----D C:\ProgramData\InstallMate =>PUP.Tarma
~ Program Folder: 205 Legitimates Filtered in 01mn 38s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 10/11/2013 - 21:07:00 ----- . (...) -- C:\IO.SYS [0]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 10/11/2013 - 21:07:00 ----- . (...) -- C:\MSDOS.SYS [0]
O44 - LFC:[MD5.14556335F7E968509283065424F4F31E] - 16/11/2013 - 16:25:31 ----- . (...) -- C:\UsbFix [Scan 1] LABARAKA.txt [11905]
O44 - LFC:[MD5.9FC4B35D8E61764F3D730F95F87FB006] - 16/11/2013 - 16:47:34 ----- . (...) -- C:\UsbFix [Clean 1] LABARAKA.txt [10734]
O44 - LFC:[MD5.174C83EAD70ECECAB46083B1D0D701AC] - 16/11/2013 - 17:27:20 ---A- . (...) -- C:\UsbFix [Clean 2] LABARAKA.txt [12108]
O44 - LFC:[MD5.778B7391F9BF0423D890086904334396] - 16/11/2013 - 17:36:38 ---A- . (...) -- C:\Windows\grwin.ini [30]
~ Files: 128 Legitimates Filtered in 00mn 44s
---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.FBFFBFC3E7ADD8195BF2F5814B38C460] - 16/11/2013 - 17:36:39 ---A- - C:\Windows\Prefetch\GRWIN.EXE-CA8E011B.pf
O45 - LFCP:[MD5.5B23F58E921DB883EE26A9F4C855BFEB] - 16/11/2013 - 17:36:40 ---A- - C:\Windows\Prefetch\GRWINHYPER.EXE-8122F46B.pf
O45 - LFCP:[MD5.097F8EEC22F7B466B42C5A3C07570438] - 16/11/2013 - 17:43:21 ---A- - C:\Windows\Prefetch\VIRUS SHORTCUT REMOVER V2.1(B-ECBDC42A.pf
O45 - LFCP:[MD5.28122375DA9641BFD023774EBD2F6D39] - 17/11/2013 - 07:24:22 ---A- - C:\Windows\Prefetch\UTILQUALITINK.EXE-A71C4ABC.pf =>Adware.Qualitink
O45 - LFCP:[MD5.6F33340552C0123394363ECB0FC95BA5] - 17/11/2013 - 09:05:02 ---A- - C:\Windows\Prefetch\BABYLON.EXE-86F523FC.pf =>PUP.Babylon
O45 - LFCP:[MD5.152AB92EDE54528F7414985CCA0508D4] - 17/11/2013 - 09:05:24 ---A- - C:\Windows\Prefetch\BABYLONTC.EXE-4CD11326.pf =>PUP.Babylon
O45 - LFCP:[MD5.AA03BAB6AA126F0CF9CCE9E456779719] - 17/11/2013 - 11:45:18 ---A- - C:\Windows\Prefetch\PNIOPCAC.EXE-91BE8425.pf
~ Prefetcher: 135 Legitimates Filtered in 00mn 05s
---\\ Opérations et fonctions au démarrage de Windows Explorer (O46)
O46 - SEH:ShellExecuteHooks - Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
~ ShellExecuteHooks: Scanned in 00mn 00s
---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Legitimates Filtered in 00mn 00s
---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.0ED67910C8C326796FAA00B2BF6D9D3C] - 14/07/2009 - 01:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712]
O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 13/07/2009 - 21:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
~ Drivers: 16 Legitimates Filtered in 00mn 01s
---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 16/11/2013 - 11:51:28 ---A- . (...) -- C:\Users\ELVIRA\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt [4]
O61 - LFC: 16/11/2013 - 11:51:30 ---A- . (...) -- C:\Users\ELVIRA\AppData\Local\Google\Chrome\User Data\Local State [48907]
O61 - LFC: 16/11/2013 - 11:51:35 ---A- . (...) -- C:\Users\ELVIRA\AppData\Local\Mozilla\updates\308046B0AF4A39CB\active-update.xml [57]
O61 - LFC: 16/11/2013 - 11:51:35 ---A- . (...) -- C:\Users\ELVIRA\AppData\Local\Mozilla\updates\308046B0AF4A39CB\updates.xml [14765]
O61 - LFC: 16/11/2013 - 11:52:04 ---A- . (...) -- C:\Users\ELVIRA\AppData\Roaming\Microsoft\Templates\Normal.dotm [22104]
O61 - LFC: 16/11/2013 - 11:52:28 ---A- . (...) -- C:\Users\ELVIRA\Documents\Downloads\Programs\Virus_Shortcut_Remover_v2_1_Beta_2_zip.exe [300128]
O61 - LFC: 16/11/2013 - 11:52:28 ---A- . (...) -- C:\Users\ELVIRA\Documents\Downloads\Programs\Virus_Shortcut_Remover_v2_1_Beta_zip.exe [300128]
O61 - LFC: 17/11/2013 - 11:52:28 ---A- . (...) -- C:\Users\ELVIRA\AppData\Roaming\ZHP\Log.txt [41606] =>.Nicolas Coolman
O61 - LFC: 17/11/2013 - 11:52:28 ---A- . (...) -- C:\Users\ELVIRA\AppData\Roaming\ZHP\TestsZHPDiag.txt [2841] =>.Nicolas Coolman
O61 - LFC: 17/11/2013 - 11:52:28 ---A- . (...) -- C:\Users\ELVIRA\AppData\Roaming\ZHP\ZHPADSReport.txt [351] =>.Nicolas Coolman
O61 - LFC: 17/11/2013 - 11:52:28 ---A- . (...) -- C:\Users\ELVIRA\AppData\Roaming\ZHP\ZHPDiag.txt [42335] =>.Nicolas Coolman
~ 55 Fichiers temporaires (Temporary files)
~ Files: 158 Legitimates Filtered in 02mn 11s
---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: UsbFix By El Desaparecido - (.El Desaparecido -
https://www.usbfix.net.) [HKLM] -- Usbfix
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s
---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\ELVIRA\AppData\Local\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s
---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) -
https://www.bing.com
O69 - SBI: SearchScopes [HKCU] {755582FF-A168-4D35-8AC4-9465E22DEC29} - (Ask Search) -
https://websearch.ask.com =>Toolbar.Ask
~ Keys: Scanned in 00mn 00s
---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.6AC365B716BF5C77A64708F9A5AA004A] [SPRF][17/11/2013] (...) -- C:\Users\ELVIRA\AppData\Local\Temp\mbr.sys [25088]
[MD5.378189889438568FEF3D98588283B3A5] [SPRF][11/11/2013] (...) -- C:\Users\ELVIRA\AppData\Local\Temp\Quarantine.exe [350377]
[MD5.9812917FE2FCDEA2FD800573D7842E5D] [SPRF][17/11/2013] (...) -- C:\Users\ELVIRA\Desktop\adwcleaner.exe [1085542]
~ Files: 7 Legitimates Filtered in 00mn 06s
---\\ Liste des exceptions du parefeu (FirewallRules) (O87)
O87 - FAEL: "{E2EE13C9-6290-4C68-B540-70577CB74A21}" |In - Public - P6 - TRUE | .(...) -- C:\Program Files\YourFileDownloader\Downloader.exe (.not file.) =>PUP.YourFileDownloader
O87 - FAEL: "{E833F56A-5224-43F6-83DD-18DBD67CD3C8}" |In - Public - P17 - TRUE | .(...) -- C:\Program Files\YourFileDownloader\Downloader.exe (.not file.) =>PUP.YourFileDownloader
O87 - FAEL: "{FD8717D3-7F7B-4B34-95CE-28085B9D5028}" |In - Public - P6 - TRUE | .(...) -- C:\Program Files\YourFileDownloader\YourFile.exe (.not file.) =>PUP.YourFileDownloader
O87 - FAEL: "{DC605DBA-A376-43DE-8C7C-DEB0FBE4F684}" |In - Public - P17 - TRUE | .(...) -- C:\Program Files\YourFileDownloader\YourFile.exe (.not file.) =>PUP.YourFileDownloader
~ Firewall: 260 Legitimates Filtered in 00mn 05s
---\\ Enumère les codes produits des logiciels (PUC) (O90)
O90 - PUC: "3E9A223DB85706D47A4C568CF83D870D" . (.Bing Bar.) -- C:\Windows\Installer\{D322A9E3-758B-4D60-A7C4-65C88FD378D0}\icon_installer_ico =>Toolbar.Bing
O90 - PUC: "B6DAE604AAAEB2B4C8595B818D60BE0D" . (.XRELAIS 3.2a - Version complète.) -- C:\Windows\Installer\{406EAD6B-EAAA-4B2B-8C95-B518D806EBD0}\ARPPRODUCTICON.exe
~ Update Products: 85 Legitimates Filtered in 00mn 00s
---\\ Etat général des services not Microsoft (EGS) (SR=Running, SS=Stopped)
SR - | Auto 18/12/2012 65192 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SS - | Demand 08/10/2013 257416 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SR - | Auto 11/08/2012 55184 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 31/01/2012 19232 | (Autodesk Content Service) . (.Autodesk, Inc..) - C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
SS - | Auto 23/07/2013 193696 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files\Microsoft\BingBar\7.2.241.0\BBSvc.exe
SR - | Demand 23/07/2013 240288 | (BBUpdate) . (.Microsoft Corporation..) - C:\Program Files\Microsoft\BingBar\7.2.241.0\SeaPort.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SS - | Demand 21/05/2012 276288 | (cphs) . (.Intel Corporation.) - C:\Windows\System32\IntelCpHeciSvc.exe
SS - | Demand 18/08/2005 7168 | (EverestDriver) . (...) - C:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt
SS - | Demand 04/06/2013 1044816 | (FLEXnet Licensing Service) . (.Flexera Software, Inc..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SR - | Auto 30/05/2012 13632 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
SR - | Auto 02/02/2012 458464 | (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - c:\Program Files\Intel\iCLS Client\HeciServer.exe
SR - | Auto 02/02/2012 342984 | (InternetEverywhere_Service) . (...) - C:\Program Files\InternetEverywhere\InternetEverywhere_Service.exe
SS - | Demand 09/09/2012 821648 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 29/02/2012 161560 | (jhi_service) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
SS - | Auto 18/04/2003 8192 | (KMService) . (...) - C:\Windows\system32\srvany.exe =>Hijacker.Office
SR - | Auto 29/02/2012 277784 | (LMS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SS - | Demand 25/11/2011 311928 | (maconfservice) . (.CybelSoft.) - C:\Program Files\ma-config.com\maconfservice.exe
SR - | Auto 04/04/2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
SR - | Auto 04/04/2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
SS - | Demand 16/11/2013 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 25/06/2010 117264 | (rpcapd) . (.CACE Technologies, Inc..) - C:\Program Files\WinPcap\rpcapd.exe
SR - | Auto 29/06/2011 412808 | (s7oiehsx) . (.SIEMENS AG.) - C:\program files\common files\Siemens\S7IEPG\s7oiehsx.exe
SR - | Auto 29/06/2011 556168 | (S7TraceServiceX) . (.SIEMENS AG.) - C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceServiceX.exe
SR - | Auto 05/07/2012 3048136 | (Skype C2C Service) . (.Skype Technologies S.A..) - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
SS - | Auto 05/09/2013 171680 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SR - | Auto 29/02/2012 363800 | (UNS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 07/11/2013 66336 | (Update qualitink) . (...) - C:\Program Files\qualitink\updatequalitink.exe =>Adware.Qualitink
SR - | Auto 17/11/2013 66336 | (Util qualitink) . (...) - C:\Program Files\qualitink\bin\utilqualitink.exe =>Adware.Qualitink
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 23s
---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13,
https://ad13.geekstog
Run by ELVIRA at 17/11/2013 11:55:32
********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s
---\\ Scan Additionnel (O88)
Database Version : 12996 - (17/11/2013)
Clés trouvées (Keys found) : 13
Valeurs trouvées (Values found) : 2
Dossiers trouvés (Folders found) : 2
Fichiers trouvés (Files found) : 2
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73AD5D47-66E5-4127-80CA-C0EEDABAFBCC}] =>Adware.Qualitink^
[HKLM\SYSTEM\CurrentControlSet\Services\KMService] =>Hijacker.Office^
[HKLM\SYSTEM\CurrentControlSet\Services\Update qualitink] =>Adware.Qualitink^
[HKLM\SYSTEM\CurrentControlSet\Services\Util qualitink] =>Adware.Qualitink^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\qualitink] =>Adware.Qualitink^
[HKLM\Software\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] =>Toolbar.Skype
[HKLM\Software\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] =>Toolbar.Skype
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}] =>Toolbar.Ask
[HKLM\Software\Microsoft\Tracing\YourFile_RASAPI32] =>PUP.YourFileDownloader
[HKLM\Software\Classes\Interface\{7131C082-F3C6-404D-B8CC-8AF9CFB6209D}] =>Toolbar.Agent
[HKLM\Software\Classes\AppID\{5C731C2A-6ADF-487E-99A2-7291BF794A14}] =>Toolbar.Agent
[HKLM\Software\Classes\AppID\osmax.ocx] =>Toolbar.Agent
[HKLM\Software\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}] =>Adware.BrowseFox
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{eec0f710-38b5-4aba-99bf-ec87564a4e13} =>Toolbar.Bing^
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:uTorrent =>P2P.BitTorrent^
C:\Program Files\qualitink =>Adware.Qualitink^
C:\ProgramData\InstallMate =>PUP.Tarma^
C:\Program Files\uTorrent\uTorrent.exe =>P2P.BitTorrent^
[HKCU\Software\qualitink] =>Adware.Qualitink^
~ Additionnel Scan: 313714 Items scanned in 00mn 18s
---\\ Récapitulatif des détections trouvées sur votre station
~
https://nicolascoolman.webs.com/apps/blo ... -qualitink =>Adware.Qualitink
~
https://nicolascoolman.webs.com/apps/blo ... ar-babylon =>PUP.Babylon
~
https://nicolascoolman.webs.com/apps/blo ... ker-office =>Hijacker.Office
~
https://nicolascoolman.webs.com/apps/blo ... lbar-tarma =>PUP.Tarma
~
https://nicolascoolman.webs.com/apps/blo ... oolbar-ask =>Toolbar.Ask
~
https://nicolascoolman.webs.com/apps/blo ... downloader =>PUP.YourFileDownloader
~
https://nicolascoolman.webs.com/apps/blo ... -browsefox =>Adware.BrowseFox
~ MSI: 7 link(s) detected in 00mn 18s
~ 1536 Legitimates filtered by white list
End of the scan (546 lines in 09mn 21s)(0)