zigo7
Participant
Nombre d'articles : 7

Avec USBfix, la désinfection (qui fonctionne) s’arrete donc bien a 95% lors de la vaccination

Le rapport de suppression :
[spoiler:2ti7ye1d]############################## | UsbFix V 7.149 | [Suppression]

Utilisateur: Thomas (Administrateur) # PC-TDELIEGE
Mis à jour le 03/11/2013 par El Desaparecido – Team SosVirus
Lancé à 12:22:07 | 05/11/2013

Site Web: http://www.usbfix.net/” onclick=”window.open(this.href);return false;
Forum : https://www.sosvirus.net/” onclick=”window.open(this.href);return false;
Upload Malware: upload_malware.php
Contact: http://www.usbfix.net/contact/” onclick=”window.open(this.href);return false;

PC: Dell Inc. (0U692R)
CPU: Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz
RAM -> [Total : 4048 | Free : 2329]
Bios: Dell Inc.
Boot: Normal boot

OS: Microsoft Windows 8.1 Professionnel (6.2.9200 64-Bit)
WB: Windows Internet Explorer : 11.0.9600.16384
WB: Google Chrome : 30.0.1599.101

SC: Security Center Service [Enabled]
WU: Windows Update Service [(!) Disabled]
AV: Ad-Aware Antivirus [(!) Disabled | (!) Outdated]
AS: Windows Defender : 4.3.9600.16384 (winblue_rtm.130821-1623)
AS: Malwarebytes' Anti-Malware : 1.75.0001
FW: Windows FireWall Service [Enabled]

C: (%systemdrive%) -> Disque fixe # 149 Go (87 Go libre(s) – 58%) [] # NTFS
D: -> CD-ROM
E: -> Disque amovible # 15 Go (15 Go libre(s) – 99%) [] # NTFS
F: -> Disque amovible # 4 Go (4 Go libre(s) – 100%) [Nouveau vol] # FAT32

################## | Processus Stoppés |

Stoppé! C:Program FilesLavasoftAd-Aware AntivirusAd-Aware Antivirus11.0.4555.0AdAwareService.exe (ID: 728 |ParentID: 492)
Stoppé! C:WindowsSystem32WUDFHost.exe (ID: 380 |ParentID: 852)
Stoppé! C:WindowsSystem32spoolsv.exe (ID: 1112 |ParentID: 492)
Stoppé! C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe (ID: 1292 |ParentID: 492)
Stoppé! C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe (ID: 1348 |ParentID: 492)
Stoppé! C:Program FilesBonjourmDNSResponder.exe (ID: 1432 |ParentID: 492)
Stoppé! C:Program FilesCommon FilesMicrosoft SharedMicrosoft Online ServicesMSOIDSVC.EXE (ID: 1572 |ParentID: 492)
Stoppé! C:Program Files (x86)Common FilesVMwareUSBvmware-usbarbitrator64.exe (ID: 1652 |ParentID: 492)
Stoppé! C:Program FilesCommon FilesMicrosoft SharedMicrosoft Online ServicesMSOIDSvcm.exe (ID: 1724 |ParentID: 1572)
Stoppé! C:Program Files (x86)VMwareVMware vCenter Converter Standalonevmware-converter-a.exe (ID: 1776 |ParentID: 492)
Stoppé! C:Program Files (x86)VMwareVMware vCenter Converter Standalonevmware-converter.exe (ID: 692 |ParentID: 492)
Stoppé! C:Program Files (x86)VMwareVMware vCenter Converter Standalonevmware-converter.exe (ID: 1924 |ParentID: 492)
Stoppé! C:WindowsExplorer.EXE (ID: 2380 |ParentID: 2344)
Stoppé! C:Windowssystem32taskhostex.exe (ID: 2592 |ParentID: 868)
Stoppé! C:WindowsSystem32SettingSyncHost.exe (ID: 3120 |ParentID: 608)
Stoppé! C:Windowssystem32SearchIndexer.exe (ID: 3580 |ParentID: 492)
Stoppé! C:WindowsSystem32skydrive.exe (ID: 3628 |ParentID: 608)
Stoppé! C:Program FilesLavasoftAd-Aware AntivirusAd-Aware Antivirus11.0.4555.0AdAwareTray.exe (ID: 3708 |ParentID: 2380)
Stoppé! C:Program FilesMicrosoft OfficeOffice14MSOSYNC.EXE (ID: 3800 |ParentID: 2380)
Stoppé! C:Program FilesMicrosoft OfficeOffice14ONENOTEM.EXE (ID: 3972 |ParentID: 2380)
Stoppé! C:Program Files (x86)Common FilesJavaJava Updatejusched.exe (ID: 3764 |ParentID: 3852)
Stoppé! C:WindowsSystem32WUDFHost.exe (ID: 2400 |ParentID: 852)
Stoppé! C:Program FilesCommon FilesMicrosoft SharedOfficeSoftwareProtectionPlatformOSPPSVC.EXE (ID: 2132 |ParentID: 492)
Stoppé! C:Windowssystem32taskeng.exe (ID: 4204 |ParentID: 868)
Stoppé! C:Windowssystem32SearchProtocolHost.exe (ID: 3324 |ParentID: 3580)
Stoppé! C:Windowssystem32SearchFilterHost.exe (ID: 4296 |ParentID: 3580)

################## | Regedit Run |

04 – HKLMSOFTWARE | Run : [Communicator] – “C:Program Files (x86)Microsoft Lynccommunicator.exe” /fromrunkey
04 – HKLMSOFTWARE | Run : [Adobe ARM] – “C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe”
04 – HKLMSOFTWARE | Run : [SunJavaUpdateSched] – “C:Program Files (x86)Common FilesJavaJava Updatejusched.exe”
04 – HKLMSOFTWARE | Run : [APSDaemon] – “C:Program Files (x86)Common FilesAppleApple Application SupportAPSDaemon.exe”
04 – HKLMSOFTWAREwow6432Node | Run : [Communicator] – “C:Program Files (x86)Microsoft Lynccommunicator.exe” /fromrunkey
04 – HKLMSOFTWAREwow6432Node | Run : [Adobe ARM] – “C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe”
04 – HKLMSOFTWAREwow6432Node | Run : [SunJavaUpdateSched] – “C:Program Files (x86)Common FilesJavaJava Updatejusched.exe”
04 – HKLMSOFTWAREwow6432Node | Run : [APSDaemon] – “C:Program Files (x86)Common FilesAppleApple Application SupportAPSDaemon.exe”
04 – HKLMSOFTWARE | RunOnce : [] –
04 – HKLMSOFTWAREwow6432Node | RunOnce : [] –
04 – HKUS-1-5-21-3653578804-3571681521-2262723874-1001SOFTWARE | Run : [OfficeSyncProcess] – “C:Program FilesMicrosoft OfficeOffice14MSOSYNC.EXE”

################## | Recherche générique |

(!) Fichiers temporaires supprimés.

################## | Registre |

################## | Listing |

[03/10/2013 – 14:14:15 | SHD ] C:$Recycle.Bin
[25/09/2013 – 09:30:44 | N | 1024] C:.rnd
[04/11/2013 – 14:39:28 | D ] C:AdwCleaner
[23/09/2013 – 12:16:25 | D ] C:APX
[22/08/2013 – 06:31:45 | RASH | 427680] C:bootmgr
[18/06/2013 – 13:18:29 | N | 1] C:BOOTNXT
[04/11/2013 – 16:38:28 | SHD ] C:Config.Msi
[22/08/2013 – 15:45:52 | SHD ] C:Documents and Settings
[05/11/2013 – 10:08:07 | ASH | 3395633152] C:hiberfil.sys
[23/09/2013 – 10:13:15 | RHD ] C:MSOCache
[05/11/2013 – 10:08:09 | ASH | 738197504] C:pagefile.sys
[22/08/2013 – 16:22:35 | D ] C:PerfLogs
[04/11/2013 – 16:37:24 | D ] C:Program Files
[04/11/2013 – 16:17:50 | D ] C:Program Files (x86)
[04/11/2013 – 16:35:44 | HD ] C:ProgramData
[05/11/2013 – 10:08:09 | ASH | 268435456] C:swapfile.sys
[04/11/2013 – 13:17:26 | SHD ] C:System Volume Information
[05/11/2013 – 12:22:34 | D ] C:UsbFix
[05/11/2013 – 12:22:37 | A | 6035] C:UsbFix [Clean 1] PC-TDELIEGE.txt
[05/11/2013 – 12:21:26 | N | 5898] C:UsbFix [Scan 1] PC-TDELIEGE.txt
[23/09/2013 – 09:45:23 | RD ] C:Users
[04/11/2013 – 16:23:15 | D ] C:Windows
[04/10/2013 – 14:28:14 | D ] C:Xerox
[04/11/2013 – 16:13:25 | SHD ] E:System Volume Information
[16/10/2013 – 15:24:12 | N | 155639] F:266534.jpg
[31/10/2013 – 16:58:28 | N | 517864] F:Barakamon.full.1483732.jpg
[16/10/2013 – 15:22:58 | N | 161520] F:CATS-PICTURES.ORG_-_apofiss-solo.jpg
[05/11/2013 – 09:28:56 | SHD ] F:System Volume Information

################## | Vaccin |[/spoiler:2ti7ye1d]

Le rapport ZHPDiag:
[spoiler:2ti7ye1d]~ Rapport de ZHPDiag v2013.11.4.4 – Nicolas Coolman (04/11/2013)
~ Lancé par Thomas (05/11/2013 13:48:37)
~ Adresse du Site Web http://nicolascoolman.webs.com” onclick=”window.open(this.href);return false;
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/” onclick=”window.open(this.href);return false;
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user

—\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.16384
GCIE: Google Chrome v30.0.1599.101 (Defaut)

—\ Informations sur les produits Windows
~ Langage: Français
Windows 8 Business Edition, 64-bit Service Pack 1 (9600)
Windows Server License Manager Script : OK
~ ion : Windows(R) Operating System, RETAIL channel
Windows ID Activation : OK
~ Windows Partial Key : JTXGM
Windows License : OK
~ Windows Remaining Initializations Number : 1000
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

—\ Logiciels de protection du système
Malwarebytes Anti-Malware version 1.75.0.1300
Ad-Aware Antivirus v11.0.4555.0
Windows Defender W8

—\ Logiciels d'optimisation du système

—\ Logiciels de partage PeerToPeer

—\ Surveillance de Logiciels
Adobe Reader XI
Java 7 Update 45

—\ Informations sur le système
~ Processor: Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 4047 MB (62% free)
System Restore: Activé (Enable)
System drive C: has 87 GB (58%) free of 149 GB

—\ Mode de connexion au système
~ Computer Name: PC-TDELIEGE
~ User Name: Thomas
~ All Users Names: ___VMware_Conv_SA___, Thomas, Administrateur,
~ Unselected Option: None
Logged in as Administrator

—\ Variables d'environnement
~ System Unit : C:
~ %AppZHP% : C:UsersThomasAppDataRoamingZHP
~ %AppData% : C:UsersThomasAppDataRoaming
~ %Desktop% : C:UsersThomasDesktop
~ %Favorites% : C:UsersThomasFavorites
~ %LocalAppData% : C:UsersThomasAppDataLocal
~ %StartMenu% : C:UsersThomasAppDataRoamingMicrosoftWindowsStart Menu
~ %Windir% : C:Windows
~ %System% : C:WindowsSystem32

—\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 87 Go of 149 Go)
D: CD-ROM drive (Not Inserted)
E: Floppy drive, Flash card reader, USB Key (Free 15 Go of 15 Go)
F: Floppy drive, Flash card reader, USB Key (Free 4 Go of 4 Go)

—\ Etat du Centre de Sécurité Windows
[HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorer] NoActiveDesktopChanges: Modified
[HKLMSOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall] LastSuccessTime : Out Of Date
~ Security Center: 41 Legitimates Filtered in 00mn 00s

—\ Recherche particulière de fichiers génériques
[MD5.8479DC46E9A09015C0777A16BC22A15D] – (.Microsoft Corporation – Explorateur Windows.) (.22/08/2013 – 13:39:51.) — C:WindowsExplorer.exe [2328880]
[MD5.48CFA7BE561A7BE144C29BB912055016] – (.Microsoft Corporation – Application de démarrage de Windows.) (.22/08/2013 – 10:58:29.) — C:WindowsSystem32Wininit.exe [144384]
[MD5.F267E9AE8279DF0F4F0246135F2BAF5C] – (.Microsoft Corporation – Extensions Internet pour Win32.) (.26/09/2013 – 08:21:02.) — C:WindowsSystem32wininet.dll [2332160]
[MD5.7C94FDA3809015B8F2208D2E1C221F17] – (.Microsoft Corporation – Application d’ouverture de session Windows.) (.22/08/2013 – 10:55:08.) — C:WindowsSystem32Winlogon.exe [564736]
[MD5.2F18065618E39AA2E656EE737B71E791] – (.Microsoft Corporation – Bibliothèque de licences.) (.22/08/2013 – 11:39:40.) — C:WindowsSystem32sppcomapi.dll [447488]
[MD5.239268BAB58EAE9A3FF4E08334C00451] – (.Microsoft Corporation – Pilote de fonction connexe pour WinSock.) (.22/08/2013 – 14:25:35.) — C:Windowssystem32DriversAFD.sys [567296]
[MD5.74B14192CF79A72F7536B27CB8814FBD] – (.Microsoft Corporation – ATAPI IDE Miniport Driver.) (.22/08/2013 – 13:43:41.) — C:Windowssystem32Driversatapi.sys [26464]
[MD5.2FA6510E33F7DEFEC03658B74101A9B9] – (.Microsoft Corporation – CD-ROM File System Driver.) (.22/08/2013 – 12:40:15.) — C:Windowssystem32DriversCdfs.sys [88576]
[MD5.C6796EA22B513E3457514D92DCDB1A3D] – (.Microsoft Corporation – SCSI CD-ROM Driver.) (.22/08/2013 – 09:46:35.) — C:Windowssystem32DriversCdrom.sys [164352]
[MD5.5DB26D7E0216D0BF364A81D3829AD7B9] – (.Microsoft Corporation – DFS Namespace Client Driver.) (.22/08/2013 – 12:38:00.) — C:Windowssystem32DriversDfsC.sys [134656]
[MD5.03909BDBFF0DCACCABF2B2D4ADEE44DC] – (.Microsoft Corporation – High Definition Audio Bus Driver.) (.22/08/2013 – 12:38:38.) — C:Windowssystem32DriversHDAudBus.sys [78336]
[MD5.84CFC5EFA97D0C965EDE1D56F116A541] – (.Microsoft Corporation – Pilote de port i8042.) (.22/08/2013 – 12:39:15.) — C:Windowssystem32Driversi8042prt.sys [107520]
[MD5.0063040EFD7C5B81D67CF985BA35388A] – (.Microsoft Corporation – IP Network Address Translator.) (.22/08/2013 – 12:35:33.) — C:Windowssystem32DriversIpNat.sys [141824]
[MD5.405A2E5754DF76663CF0522B87D7929F] – (.Microsoft Corporation – Minirdr SMB Windows NT.) (.22/08/2013 – 12:36:11.) — C:Windowssystem32DriversMRxSmb.sys [402432]
[MD5.0217532E19A748F0E5D569307363D5FD] – (.Microsoft Corporation – MBT Transport driver.) (.22/08/2013 – 12:37:02.) — C:Windowssystem32DriversnetBT.sys [282624]
[MD5.4412D565C0278C401575E11072C7DCE3] – (.Microsoft Corporation – Pilote du système de fichiers NT.) (.22/08/2013 – 14:25:41.) — C:Windowssystem32Driversntfs.sys [2011488]
[MD5.764B1121867B2D9B31C491668AC72B2B] – (.Microsoft Corporation – Pilote de port parallèle.) (.22/08/2013 – 12:40:02.) — C:Windowssystem32DriversParport.sys [94208]
[MD5.BBB6272B7F46C4640A8CDB8A70C3450F] – (.Microsoft Corporation – RAS L2TP mini-port/call-manager driver.) (.22/08/2013 – 12:35:51.) — C:Windowssystem32DriversRasl2tp.sys [120832]
[MD5.680C1DAE268B6FB67FA21B389A8B79EF] – (.Microsoft Corporation – Redirecteur de périphérique de Microsoft RDP.) (.22/08/2013 – 23:26:13.) — C:Windowssystem32Driversrdpdr.sys [195584]
[MD5.FFF28F9F6823EB1756C60F1649560BBF] – (.Microsoft Corporation – TDI Translation Driver.) (.22/08/2013 – 14:25:35.) — C:Windowssystem32Driverstdx.sys [107520]
[MD5.9F9CE33B50611A1C61A46B8911E0B30B] – (.Microsoft Corporation – Pilote de cliché instantané du volume.) (.22/08/2013 – 13:39:15.) — C:Windowssystem32Driversvolsnap.sys [312160]
~ Generic Processes: Scanned in 00mn 00s

—\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/2
~ Mes musiques (My Musics) : 1/50
~ Mes Favoris (My Favorites) : 1/3
~ Mes Documents (My Documents) : 2/12
~ Mon Bureau (My Desktop) : 1/2822
~ Menu demarrer (Programs) : 1/21
~ Hidden Files: Scanned in 00mn 00s

—\ Processus lancés
[MD5.3E399A1328181C2A352472369DE2A93A] – (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe [844752] [PID.3980]
[MD5.89BECCA60E9A652934D65EDB72A438A4] – (.Nicolas Coolman – ZHPDiag.) — C:Program Files (x86)ZHPDiagZHPDiag.exe [8174080] [PID.1740]
~ Processes Running: Scanned in 00mn 00s

—\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:UsersThomasAppDataLocalGoogleChromeUser DataDefaultPreferences
G2 – GCE: Preference [User DataDefault] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.5.0 (Activé)
~ Google Browser: 15 Legitimates Filtered in 00mn 10s

—\ Internet Explorer, Proxy Management (R5)
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = proxy.fr.auchan.com
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyEnable = 0
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,MigrateProxy = 1
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,EnableHttp1_1 = 1
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s

—\ Analyse des lignes F0, F1, F2, F3 – IniFiles, Autoloading programs
F2 – REG:system.ini: USERINIT=C:Windowssystem32userinit.exe,
F2 – REG:system.ini: Shell=C:Windowsexplorer.exe
F2 – REG:system.ini: VMApplet=C:WindowsSystem32SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s

—\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21

—\ Autres liens utilisateurs (O4)
O4 – GSDesktop [Public]: Ad-Aware Antivirus.lnk . (…) — C:Program Files (x86)LavasoftAd-Aware AntivirusAd-Aware Antivirus11.0.4555.0AdAwareDesktop.exe (.not file.)
O4 – GSDesktop [Public]: Google Chrome.lnk . (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe
O4 – GSDesktop [Public]: SimulPret 2013.lnk . (.WebImmo – SimulPret 2013.) — C:Program Files (x86)WebImmoSIMULPRET.exe
O4 – GSDesktop [Public]: VMware vCenter Converter Standalone Client.lnk . (.VMware, Inc. – Converter Standalone Application.) — C:Program Files (x86)VMwareVMware vCenter Converter Standaloneconverter.exe
O4 – GSDesktop [Public]: VMware vSphere Client.lnk . (.VMware, Inc. – VpxClient.) — C:Program Files (x86)VMwareInfrastructureVirtual Infrastructure ClientLauncherVpxClient.exe
O4 – GSProgram [Public]: Desktop.lnk – Clé orpheline
O4 – GSQuickLaunch [Thomas]: Google Chrome.lnk . (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe
O4 – GSQuickLaunch [Thomas]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation – Internet Explorer.) — C:Program Files (x86)Internet Exploreriexplore.exe
O4 – GSTaskBar [Thomas]: Google Chrome.lnk . (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe
O4 – GSTaskBar [Thomas]: Internet Explorer.lnk . (.Microsoft Corporation – Internet Explorer.) — C:Program Files (x86)Internet Exploreriexplore.exe
O4 – GSProgram [Thomas]: Internet Explorer.lnk . (.Microsoft Corporation – Internet Explorer.) — C:Program Files (x86)Internet Exploreriexplore.exe
O4 – GSDesktop [Thomas]: Secure Download Manager.lnk . (…) — C:UsersThomasAppDataRoamingMicrosoftInstaller{6DEC47B2-CAF8-484A-B482-851BB8C1657B}_C0FD2C793C8AF50B9B1C8A.exe
O4 – GSDesktop [Thomas]: SosVirus Forum Gratuit.lnk . (.Microsoft Corporation – Internet Explorer.) — C:Program Files (x86)Internet Exploreriexplore.exe https://www.sosvirus.net” onclick=”window.open(this.href);return false;
O4 – GSDesktop [Thomas]: SosVirus sur Facebook.lnk . (.Microsoft Corporation – Internet Explorer.) — C:Program Files (x86)Internet Exploreriexplore.exe http://www.facebook.com” onclick=”window.open(this.href);return false;
O4 – GSDesktop [Thomas]: Tera Term.lnk . (.TeraTerm Project T. Teranishi – Tera Term.) — C:Program Files (x86)teratermttermpro.exe
O4 – GSDesktop [Thomas]: Tftpd64.lnk . (…) — C:Program Files (x86)Tftpd64tftpd64.exe (.not file.)
~ Global Startup: 50 Legitimates Filtered in 00mn 00s

—\ Applications lancées au démarrage du sytème (O4)
O4 – GSStartup [Thomas]: OneNote 2010 – Capture d’écran et lancement.lnk . (…) — C:Program Files (x86)Microsoft OfficeOffice14ONENOTEM.exe (.not file.)
O4 – HKLM..Run: [AdAwareTray] . (…) — C:Program FilesLavasoftAd-Aware AntivirusAd-Aware Antivirus11.0.4555.0AdAwareTray.exe
O4 – HKCU..Run: [OfficeSyncProcess] . (.Microsoft Corporation – Microsoft Office Document Cache.) — C:Program FilesMicrosoft OfficeOffice14MSOSYNC.exe
O4 – HKLM..Wow6432NodeRun: [Communicator] . (.Microsoft Corporation – Microsoft Lync 2010.) — C:Program Files (x86)Microsoft Lynccommunicator.exe
O4 – HKLM..Wow6432NodeRun: [Adobe ARM] . (.Adobe Systems Incorporated – Adobe Reader and Acrobat Manager.) — C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe =>.Adobe Systems Incorporated
O4 – HKLM..Wow6432NodeRun: [SunJavaUpdateSched] . (.Oracle Corporation – Java(TM) Update Scheduler.) — C:Program Files (x86)Common FilesJavaJava Updatejusched.exe =>.Oracle Corporation
O4 – HKLM..Wow6432NodeRun: [APSDaemon] . (.Apple Inc. – Apple Push.) — C:Program Files (x86)Common FilesAppleApple Application SupportAPSDaemon.exe
O4 – HKUSS-1-5-21-3653578804-3571681521-2262723874-1001..Run: [OfficeSyncProcess] . (.Microsoft Corporation – Microsoft Office Document Cache.) — C:Program FilesMicrosoft OfficeOffice14MSOSYNC.exe
~ Application: Scanned in 00mn 00s

—\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 – Extra button: &Envoyer à OneNote [64Bits] – {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation – Microsoft OneNote Internet Explorer Add-in.) — C:Program Files (x86)MICROS~1Office14ONBttnIE.dll =>.Microsoft Corporation
O9 – Extra button: Notes &liées OneNote [64Bits] – {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation – Microsoft OneNote Internet Explorer Add-in.) — C:Program Files (x86)MICROS~1Office14ONBTTN~1.dll =>.Microsoft Corporation
~ IE Extra Buttons: Scanned in 00mn 00s

—\ Modification Domaine/Adresses DNS (O17)
O17 – HKLMSystemCCSServicesTcpip..{178490F9-525D-44DC-9329-D31FF54F3F6D}: DhcpNameServer = 10.59.0.22 10.54.201.12
O17 – HKLMSystemCCSServicesTcpip..{2A7CF58F-05C4-4828-AB6B-578A8F8F2B63}: DhcpNameServer = 128.239.31.12 128.239.31.11
O17 – HKLMSystemCCSServicesTcpip..{81C82394-CBF7-4C3A-B53B-E0ED9941F3D1}: DhcpNameServer = 192.168.10.110
O17 – HKLMSystemCCSServicesTcpip..{CB9C42AC-3F95-45EB-922D-C885F0D62966}: DhcpNameServer = 192.168.42.129
O17 – HKLMSystemCCSServicesTcpip..{178490F9-525D-44DC-9329-D31FF54F3F6D}: DhcpDomain = groupe.loc
O17 – HKLMSystemCCSServicesTcpip..{2A7CF58F-05C4-4828-AB6B-578A8F8F2B63}: DhcpDomain = f9971.fr.auchan.com
O17 – HKLMSystemCS1ServicesTcpip..{178490F9-525D-44DC-9329-D31FF54F3F6D}: DhcpNameServer = 10.59.0.22 10.54.201.12
O17 – HKLMSystemCS1ServicesTcpip..{2A7CF58F-05C4-4828-AB6B-578A8F8F2B63}: DhcpNameServer = 128.239.31.12 128.239.31.11
O17 – HKLMSystemCS1ServicesTcpip..{81C82394-CBF7-4C3A-B53B-E0ED9941F3D1}: DhcpNameServer = 192.168.10.110
O17 – HKLMSystemCS1ServicesTcpip..{CB9C42AC-3F95-45EB-922D-C885F0D62966}: DhcpNameServer = 192.168.42.129
O17 – HKLMSystemCS1ServicesTcpip..{178490F9-525D-44DC-9329-D31FF54F3F6D}: DhcpDomain = groupe.loc
O17 – HKLMSystemCS1ServicesTcpip..{2A7CF58F-05C4-4828-AB6B-578A8F8F2B63}: DhcpDomain = f9971.fr.auchan.com
O17 – HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 10.59.0.22 10.54.201.12
~ Domain: Scanned in 00mn 00s

—\ Protocole additionnel (O18)
O18 – Handler: vbscript [64Bits] – {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation – Visionneuse HTML Microsoft (R).) — C:WindowsSystem32mshtml.dll =>.Microsoft Corporation
O18 – Filter: text/xml [64Bits] – {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation – Microsoft Office XML MIME Filter.) — C:Program FilesCommon FilesMicrosoft SharedOFFICE14MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s

—\ Liste des services NT non Microsoft et non désactivés (O23)
O23 – Service: Ad-Aware Service 11 (LavasoftAdAwareService11) . (…) – C:Program FilesLavasoftAd-Aware AntivirusAd-Aware Antivirus11.0.4555.0AdAwareService.exe
O23 – Service: VMware vCenter Converter Standalone Work (vmware-converter-worker) . (.VMware, Inc. – VMware Converter Service.) – C:Program Files (x86)VMwareVMware vCenter Converter Standalonevmware-converter.exe
~ Services: 11 Legitimates Filtered in 00mn 02s

—\ Logiciels installés (O42)
O42 – Logiciel: SimulPret 2013 – (.WebImmo.) [HKLM][64Bits] — {443417E0-B824-406D-9900-7E38BA9C8D5D}_is1
O42 – Logiciel: Tftpd64 Standalone Edition (remove only) – (…) [HKLM][64Bits] — Tftpd64
~ Logic: 55 Legitimates Filtered in 00mn 00s

—\ HKCU & HKLM Software Keys
[HKCUSoftwareLitecoin]
[HKCUSoftwareWebImmo]
[HKLMSoftwareWow6432NodeLitecoin]
[HKLMSoftwareWow6432NodeWebImmo]
~ Key Software: 114 Legitimates Filtered in 00mn 00s

—\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 – CFD: 23/09/2013 – 12:15:08 – [9,930] —-D C:Program Files (x86)teraterm
O43 – CFD: 30/10/2013 – 16:28:47 – [22,637] —-D C:Program Files (x86)WebImmo
O43 – CFD: 30/10/2013 – 16:28:50 – [0] —-D C:ProgramDataWebImmo
O43 – CFD: 29/10/2013 – 10:43:41 – [28,324] —-D C:UsersThomasAppDataRoamingLitecoin
O43 – CFD: 30/10/2013 – 16:28:51 – [0,009] —-D C:UsersThomasAppDataLocalWebImmo
~ Program Folder: 108 Legitimates Filtered in 00mn 00s

—\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 – LFC:[MD5.E42AA704FE95A55263792152E2A449F5] – 05/11/2013 – 12:21:26


. (…) — C:UsbFix [Scan 1] PC-TDELIEGE.txt [5898]
O44 – LFC:[MD5.9E963867AEFAA72BB73D975DD43AAB21] – 05/11/2013 – 12:22:37 —A- . (…) — C:UsbFix [Clean 1] PC-TDELIEGE.txt [6663]
O44 – LFC:[MD5.1363812D50F19B484B6C42F64D2ACA2E] – 23/10/2013 – 07:58:06 —A- . (…) — C:Windowsvbaddin.ini [39]
~ Files: 19 Legitimates Filtered in 00mn 02s

—\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 – LFCP:[MD5.801F5107652A31CF64BD622C8D4C841B] – 04/11/2013 – 11:24:48 —A- – C:WindowsPrefetchRCSETUP148.EXE-EC5128BF.pf
O45 – LFCP:[MD5.88AE0372401F6E27E3153FDF56FF7E83] – 04/11/2013 – 11:36:00 —A- – C:WindowsPrefetchPDR6FREE.TMP-68BE4404.pf
O45 – LFCP:[MD5.44C93D0411D9B8F31020CFA3127F5A70] – 04/11/2013 – 11:36:01 —A- – C:WindowsPrefetchPDR6FREE.TMP-4405F9DC.pf
O45 – LFCP:[MD5.AD610ADA3E0C9CAB605DB122687D7944] – 04/11/2013 – 11:36:37 —A- – C:WindowsPrefetchPOWERDATARECOVERY.EXE-83C70CC5.pf
O45 – LFCP:[MD5.282B6E474D5D34D057C1C419ECFD600F] – 04/11/2013 – 11:47:45 —A- – C:WindowsPrefetch_IU14D2N.TMP-1EDFD8EE.pf
O45 – LFCP:[MD5.32BD376DD8C38A4166C850A9B4BB28AE] – 04/11/2013 – 12:00:23 —A- – C:WindowsPrefetchINSTUP.EXE-37308BC5.pf
O45 – LFCP:[MD5.6B30A8716DD6BF181EAFBB50A0763658] – 04/11/2013 – 15:13:30 —A- – C:WindowsPrefetchOPEN-CONFIG.EXE-E33F11B1.pf
O45 – LFCP:[MD5.23CFD470CCACA122B896087B49D7EE65] – 04/11/2013 – 15:58:37 —A- – C:WindowsPrefetchINSTUP.EXE-7E543EAF.pf
O45 – LFCP:[MD5.2919ADDD0755FF7C6894930B1D49AE61] – 04/11/2013 – 15:58:37 —A- – C:WindowsPrefetchMSOIDSVC.EXE-CD102AD6.pf
O45 – LFCP:[MD5.52377A0568E18027B567DF4DCD6ACEB1] – 04/11/2013 – 16:35:54 —A- – C:WindowsPrefetchADAWARE_INSTALLER.EXE-5C87D1EA.pf
O45 – LFCP:[MD5.D55A3E6079091832BC4072354B0F6CDF] – 04/11/2013 – 16:39:49 —A- – C:WindowsPrefetchADAWARESECURITYCENTER.EXE-4F0BFFB9.pf
O45 – LFCP:[MD5.EF4375DC46E734CB42835D8045A13C79] – 05/11/2013 – 09:29:10 —A- – C:WindowsPrefetchUCMAPI64.EXE-0D52D91F.pf
O45 – LFCP:[MD5.97DA09414E32B67274012AA7DC1A2327] – 05/11/2013 – 09:43:11 —A- – C:WindowsPrefetchADAWARESERVICE.EXE-B2E18E61.pf
O45 – LFCP:[MD5.F2F264D194C1C519ADC5E096DECBA2DA] – 05/11/2013 – 09:43:21 —A- – C:WindowsPrefetchADAWAREDESKTOP.EXE-519564B6.pf
O45 – LFCP:[MD5.55F57C095C788EA29679F4E221EA2C20] – 05/11/2013 – 10:10:33 —A- – C:WindowsPrefetchADAWARETRAY.EXE-8158A9F4.pf
O45 – LFCP:[MD5.57D927519D93C47EC97F9D572F3D9483] – 05/11/2013 – 10:12:43 —A- – C:WindowsPrefetchWSHOST.EXE-3BD2AA25.pf
O45 – LFCP:[MD5.8E6CCED31078BF184048AD862DF50867] – 05/11/2013 – 12:08:41 —A- – C:WindowsPrefetchdynreservedpri.db
O45 – LFCP:[MD5.D55ADEF32498452D7B5379EBA3F6AA80] – 05/11/2013 – 12:20:17 —A- – C:WindowsPrefetchGO.EXE-0A7DE786.pf
O45 – LFCP:[MD5.DB7DF352D4D0A48A24B67D0B6C4E915E] – 05/11/2013 – 12:21:03 —A- – C:WindowsPrefetchFSUM.COM-68738D89.pf
O45 – LFCP:[MD5.68998E65ABFDE55C66FE07A74AB137EC] – 05/11/2013 – 12:22:35 —A- – C:WindowsPrefetchMSOIDSVCM.EXE-459B27E7.pf
O45 – LFCP:[MD5.AF6A601385591A7D93010DCEA1BA709D] – 05/11/2013 – 13:09:32 —A- – C:WindowsPrefetchPfPre_4fbb62e8.db
O45 – LFCP:[MD5.1794F3DE1901E89DAD0CA8DFDE23FDA7] – 17/10/2013 – 13:52:50 —A- – C:WindowsPrefetchG2MSTART.EXE-56055175.pf
O45 – LFCP:[MD5.C74646001A7A6EBB3663EC96FB028F9F] – 17/10/2013 – 13:52:51 —A- – C:WindowsPrefetchG2MMATCHMAKING.EXE-FD010203.pf
O45 – LFCP:[MD5.170E15E288D61F1C447E4619AA01CA93] – 17/10/2013 – 13:53:01 —A- – C:WindowsPrefetchG2MUI.EXE-19AF2C85.pf
O45 – LFCP:[MD5.283E0388B854B2D75D0E4E5E44F24F12] – 23/10/2013 – 14:07:20 —A- – C:WindowsPrefetchVISIO.EXE-EDBB8EEB.pf
O45 – LFCP:[MD5.60063A614DB5FC020D4A336DB03FAA69] – 25/10/2013 – 08:51:04 —A- – C:WindowsPrefetchSECUREDOWNLOADMANAGER.EXE-16B6807F.pf
O45 – LFCP:[MD5.44BBD4D7560B5D464FC102DE011C3F06] – 25/10/2013 – 13:01:09 —A- – C:WindowsPrefetchPCNSL.EXE-C694F48A.pf
O45 – LFCP:[MD5.1E8F1A348632DB08A3DFF1276AD54837] – 29/10/2013 – 10:23:48 —A- – C:WindowsPrefetchLITECOIN-0.8.5.1-WIN32-SETUP.-2D1FE562.pf
O45 – LFCP:[MD5.3583C29F9D593E498213690951640E3C] – 29/10/2013 – 10:38:43 —A- – C:WindowsPrefetchLITECOIN-QT.EXE-15429771.pf
O45 – LFCP:[MD5.90ABB495BA379A25CCDBC7B989444651] – 30/10/2013 – 16:28:48 —A- – C:WindowsPrefetchSETUP-SIMULPRET-2013.TMP-3BE61801.pf
O45 – LFCP:[MD5.DCC0A9C82CB7C8344535B1036289025D] – 30/10/2013 – 16:28:48 —A- – C:WindowsPrefetchSETUP-SIMULPRET-2013.TMP-7A15FC46.pf
O45 – LFCP:[MD5.3346A58BE9414841D4BA095049E961E1] – 30/10/2013 – 16:29:00 —A- – C:WindowsPrefetchSIMULPRET.EXE-867A9092.pf
O45 – LFCP:[MD5.E4782D96EBC7D7055649D8333161C006] – 30/10/2013 – 16:33:00 —A- – C:WindowsPrefetchREGSMP.EXE-6872167F.pf
O45 – LFCP:[MD5.A468DB39D7A01D3E4BC85172D3EC51A8] – 31/10/2013 – 11:28:36 —A- – C:WindowsPrefetchX2JOBTMS.EXE-A85C9702.pf
~ Prefetcher: 219 Legitimates Filtered in 00mn 00s

—\ Opérations et fonctions au démarrage de Windows Explorer (O46)
O46 – SEH:ShellExecuteHooks – Groove GFS Stub Execution Hook [64Bits] – {B5A7F190-DDA6-4420-B3BA-52453494E6CD} – C:PROGRA~2MICROS~1Office14GROOVEEX.DLL
~ ShellExecuteHooks: Scanned in 00mn 00s

—\ Déni du service (Local Security Authority) (O48)
~ LSA: 4 Legitimates Filtered in 00mn 00s

—\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 – MWPS:[HKLM…PoliciesSystem] – “PromptOnSecureDesktop”=0
O55 – MWPS:[HKLM…PoliciesSystem] – “EnableUIADesktopToggle”=0
O55 – MWPS:[HKLM…PoliciesSystem] – “FilterAdministratorToken”=0
~ MWPS: 17 Legitimates Filtered in 00mn 00s

—\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 – MWPE:[HKLM…policiesExplorer] – “NoActiveDesktopChanges”=1
~ MWPE Keys: 3 Legitimates Filtered in 00mn 00s

—\ Liste des pilotes du système (SDL) (O58)
O58 – SDL:[MD5.C1ABB0F7E3BEA48A0417BDF6FF14AB21] – 13/08/2013 – 00:25:46 —A- . (.Windows (R) Win 7 DDK provider – BCM Function 2 Device Driver.) — C:WindowsSystem32Driversbcmfn2.sys [17624]
~ Drivers: 17 Legitimates Filtered in 00mn 00s

—\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 – LFC: 04/11/2013 – 13:49:14 —A- . (…) — C:UsersThomasAppDataRoamingLavasoftStatisticsadaware.xml [770]
O61 – LFC: 04/11/2013 – 13:49:14 —A- . (…) — C:UsersThomasAppDataRoamingLavasoftAd-Aware 11OptionsLanguage.db [0]
O61 – LFC: 04/11/2013 – 13:49:14 —A- . (…) — C:UsersThomasAppDataRoamingLavasoftAd-Aware 11OptionsNotificationCenter.db [2048]
O61 – LFC: 04/11/2013 – 13:49:14 —A- . (…) — C:UsersThomasDownloadsAdaware_Installer.exe [1723528]
O61 – LFC: 05/11/2013 – 13:49:12 —A- . (…) — C:UsersThomasAppDataLocalGoogleChromeUser DataLocal State [47150]
O61 – LFC: 05/11/2013 – 13:49:14 —A- . (…) — C:UsersThomasAppDataRoamingLavasoftAd-Aware 11OptionsFirstRun [0]
O61 – LFC: 05/11/2013 – 13:49:14 —A- . (…) — C:UsersThomasAppDataRoamingMicrosoftMMCservices [93504]
O61 – LFC: 05/11/2013 – 13:49:14 —A- . (…) — C:UsersThomasAppDataRoamingZHPLog.txt [17067] =>.Nicolas Coolman
O61 – LFC: 05/11/2013 – 13:49:14 —A- . (…) — C:UsersThomasAppDataRoamingZHPTestsZHPDiag.txt [2875] =>.Nicolas Coolman
O61 – LFC: 05/11/2013 – 13:49:14 —A- . (…) — C:UsersThomasTracingCommunicator-uccapi-0.uccapilog [0]
O61 – LFC: 05/11/2013 – 13:49:14 —A- . (…) — C:UsersThomasTracingCommunicator-uccapi-0.uccapilog.bak [0]
O61 – LFC: 05/11/2013 – 13:49:14 -SHA- . (…) — C:UsersThomasAppDataRoamingMicrosoftCredentials9A7273293F661FADBDDF9630262410BD [608]
~ 1 Fichiers temporaires (Temporary files)
~ Files: 191 Legitimates Filtered in 00mn 03s

—\ Liste des outils de désinfection (LATC) (O63)
O63 – Logiciel: UsbFix By El Desaparecido – (.El Desaparecido – http://www.usbfix.net.)” onclick=”window.open(this.href);return false; [HKLM] — Usbfix
O63 – Logiciel: ZHPDiag 2013 – (.Nicolas Coolman.) [HKLM] — ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s

—\ Associations Shell Spawning (O67)
O67 – Shell Spawning: [HKCU..openCommand] (.Not Key.)
~ FASS Keys: 10 Legitimates Filtered in 00mn 00s

—\ Menu de démarrage Internet (SMI) (O68)
O68 – StartMenuInternet: [HKLM..ShellopenCommand] (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe
O68 – StartMenuInternet: [HKLM..ShellopenCommand] (.Microsoft Corporation – Internet Explorer.) — C:Program FilesInternet Exploreriexplore.exe
~ Keys: Scanned in 00mn 00s

—\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 – SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] – (Bing) – http://www.bing.com” onclick=”window.open(this.href);return false;
~ Keys: Scanned in 00mn 00s

—\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.A3CCFD0AA0B17FD23AA9FD0D84B86C05] [SPRF][17/12/2012] (.Simon Tatham – SSH, Telnet and Rlogin client.) — C:UsersThomasDesktopputty.exe [483328]
~ Files: 2 Legitimates Filtered in 00mn 08s

—\ Liste des exceptions du parefeu (FirewallRules) (O87)
O87 – FAEL: “TCP Query User{9B16F93F-99AB-4F29-8A2F-D0580DE17D2F}C:program filestftpd64tftpd64.exe” | In – Public – P6 – TRUE | .(.Ph. Jounin – TFTP server.) — C:program filestftpd64tftpd64.exe
O87 – FAEL: “UDP Query User{1CF81E52-7091-4A62-9122-6B6173011395}C:program filestftpd64tftpd64.exe” | In – Public – P17 – TRUE | .(.Ph. Jounin – TFTP server.) — C:program filestftpd64tftpd64.exe
O87 – FAEL: “TCP Query User{CD4E3E7F-277D-45C4-A7F0-27D4F8D802F8}C:program files (x86)litecoinlitecoin-qt.exe” |In – Public – P6 – TRUE | .(…) — C:program files (x86)litecoinlitecoin-qt.exe (.not file.)
O87 – FAEL: “UDP Query User{A1E1340B-7AA8-4969-BEC8-2A731A7C41AB}C:program files (x86)litecoinlitecoin-qt.exe” |In – Public – P17 – TRUE | .(…) — C:program files (x86)litecoinlitecoin-qt.exe (.not file.)
~ Firewall: 241 Legitimates Filtered in 00mn 00s

—\ Enumère les codes produits des logiciels (PUC) (O90)
O90 – PUC: “24BED006A334FA04CB4180E20475B72F” . (.AntimalwareEngine.) — C:WindowsInstaller{600DEB42-433A-40AF-BC14-082E40577BF2}ARPPRODUCTICON.exe
O90 – PUC: “7EC780A0346F8EF45A2DB0AB4F7A0B23” . (.AdAwareUpdater.) — C:WindowsInstaller{0A087CE7-F643-4FE8-A5D2-0BBAF4A7B032}ARPPRODUCTICON.exe
O90 – PUC: “894D1EBE767AE9840ADD3F718A8B5397” . (.AdAwareInstaller.) — C:WindowsInstaller{EBE1D498-A767-489E-A0DD-F317A8B83579}ARPPRODUCTICON.exe
~ Update Products: 44 Legitimates Filtered in 00mn 00s

—\ Enumère les données de la clé NameSpace (MNS) (O92)
O92 – MNS: – {1CF1260C-4DD0-4ebb-811F-33C572699FDE}
O92 – MNS: – {374DE290-123F-4565-9164-39C4925E467B}
O92 – MNS: – {3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA}
O92 – MNS: – {A0953C92-50DC-43bf-BE83-3742FED03C9C}
O92 – MNS: – {A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}
O92 – MNS: – {B4BFCC3A-DB2C-424C-B029-7FE99A87C641}
~ MNS: 6 Legitimates Filtered in 00mn 00s

—\ Etat général des services not Microsoft (EGS) (SR=Running, SS=Stopped)
SS – | Auto 05/09/2013 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) – C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe
SR – | Auto 07/09/2013 55624 | (Apple Mobile Device) . (.Apple Inc..) – C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe
SS – | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) – C:Program FilesBonjourmDNSResponder.exe
SS – | Auto 23/09/2013 116648 | (gupdate) . (.Google Inc..) – C:Program Files (x86)GoogleUpdateGoogleUpdate.exe
SS – | Demand 23/09/2013 116648 | (gupdatem) . (.Google Inc..) – C:Program Files (x86)GoogleUpdateGoogleUpdate.exe
SS – | Demand 23/10/2013 641352 | (iPod Service) . (.Apple Inc..) – C:Program FilesiPodbiniPodService.exe
SS – | Auto 18/10/2013 517344 | (LavasoftAdAwareService11) . (…) – C:Program FilesLavasoftAd-Aware AntivirusAd-Aware Antivirus11.0.4555.0AdAwareService.exe
SS – | Auto 04/04/2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) – C:Program Files (x86)Malwarebytes' Anti-Malwarembamscheduler.exe
SS – | Auto 04/04/2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) – C:Program Files (x86)Malwarebytes' Anti-Malwarembamservice.exe
SR – | Auto 05/09/2012 856728 | (VMUSBArbService) . (.VMware, Inc..) – C:Program Files (x86)Common FilesVMwareUSBvmware-usbarbitrator64.exe
SS – | Auto 09/04/2013 479824 | (vmware-converter-agent) . (.VMware, Inc..) – C:Program Files (x86)VMwareVMware vCenter Converter Standalonevmware-converter-a.exe
SR – | Auto 09/04/2013 479824 | (vmware-converter-server) . (.VMware, Inc..) – C:Program Files (x86)VMwareVMware vCenter Converter Standalonevmware-converter.exe
SS – | Auto 09/04/2013 479824 | (vmware-converter-worker) . (.VMware, Inc..) – C:Program Files (x86)VMwareVMware vCenter Converter Standalonevmware-converter.exe
SR – | Demand 10/07/1658 0 | (WdNisSvc) . (…) – C:Program Files (x86)Windows DefenderNisSrv.exe
SS – | Demand 10/07/1658 0 | (WMPNetworkSvc) . (…) – C:Program Files (x86)Windows Media Playerwmpnetwk.exe =>.Microsoft Corporation
SS – | Demand 22/08/2013 37768 | C:WindowsSystem32wuaueng.dll (wuauserv) . (.Microsoft Corporation.) – C:WindowsSystem32svchost.exe
~ Services: Scanned in 00mn 22s

—\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Run by Thomas at 05/11/2013 13:50:17
~ OS 64 not supported by MBR tool
~ MBR: 0 Legitimates Filtered in 00mn 00s

—\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog” onclick=”window.open(this.href);return false;
Run by Thomas at 05/11/2013 13:50:19

********* Dump file Name *********
C:PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 02s

—\ Scan Additionnel (O88)
Database Version : 12971 – (04/11/2013)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 0

[HKLMSoftwareClassesInterface{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}] =>Toolbar.Ask
~ Additionnel Scan: 264641 Items scanned in 00mn 19s

—\ Récapitulatif des détections trouvées sur votre station
~ http://nicolascoolman.webs.com/apps/blog/show/28927746-toolbar-ask” onclick=”window.open(this.href);return false; =>Toolbar.Ask
~ MSI: 1 link(s) detected in 00mn 19s

~ 1169 Legitimates filtered by white list
End of the scan (471 lines in 02mn 02s)(0)[/spoiler:2ti7ye1d]