Répondre à : Infection USB 2016-09-08T13:37:42+00:00
Laurianne
Participant
Nombre d'articles : 5
Spoiler for czxqmfq1

~ Rapport de ZHPDiag v2014.4.28.48 – Nicolas Coolman (28/04/2014)
~ Lancé par Laurianne.REMY (29/04/2014 21:35:21)
~ Adresse du Site Web http://nicolascoolman.webs.com” onclick=”window.open(this.href);return false;
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/” onclick=”window.open(this.href);return false;
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user

—\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17031
GCIE: Google Chrome v34.0.1847.116 (Defaut)

—\ Informations sur les produits Windows
~ Langage: Français
Windows 8.1, 64-bit (Build 9600)
Windows Server License Manager Script : OK
~ Windows(R) Operating System, OEM_DM channel
Windows ID Activation : OK
~ Windows Partial Key : FX6HD
Windows License : OK
~ Windows Remaining Initializations Number : 999
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

—\ Logiciels de protection du système
Malwarebytes Anti-Malware version 2.0.1.1004
Windows Defender W8

—\ Logiciels d'optimisation du système

—\ Logiciels de partage PeerToPeer

—\ Surveillance de Logiciels
Adobe Reader XI

—\ Informations sur le système
~ Processor: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3981 MB (52% free)
System Restore: Activé (Enable)
System drive C: has 141 GB (75%) free of 186 GB

—\ Mode de connexion au système
~ Computer Name: MINILAURIANNE
~ User Name: Laurianne.REMY
~ All Users Names: Laurianne.REMY, HomeGroupUser$, Administrateur,
~ Unselected Option: None
Logged in as Administrator

—\ Variables d'environnement
~ System Unit : C:
~ %AppZHP% : C:UsersLaurianne.REMYAppDataRoamingZHP
~ %AppData% : C:UsersLaurianne.REMYAppDataRoaming
~ %Desktop% : C:UsersLaurianne.REMYDesktop
~ %Favorites% : C:UsersLaurianne.REMYFavorites
~ %LocalAppData% : C:UsersLaurianne.REMYAppDataLocal
~ %StartMenu% : C:UsersLaurianne.REMYAppDataRoamingMicrosoftWindowsStart Menu
~ %Windir% : C:Windows
~ %System% : C:WindowsSystem32

—\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 141 Go of 186 Go)
D: Hard drive, Flash drive, Thumb drive (Free 258 Go of 258 Go)
E: Floppy drive, Flash card reader, USB Key (Free 2 Go of 2 Go)
F: Floppy drive, Flash card reader, USB Key (Free 0 Go of 0 Go)
G: Floppy drive, Flash card reader, USB Key (Free 4 Go of 7 Go)
H: Floppy drive, Flash card reader, USB Key (Free 1 Go of 1 Go)

—\ Etat du Centre de Sécurité Windows
[HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorer] NoActiveDesktopChanges: Modified
~ Security Center: 41 Legitimates Filtered in 00mn 00s

—\ Recherche particulière de fichiers génériques
[MD5.81394C91B7B5A7C799E249AE82491F13] – (.Microsoft Corporation – Explorateur Windows.) (.04/03/2014 – 13:25:49.) — C:WindowsExplorer.exe [2373784]
[MD5.48CFA7BE561A7BE144C29BB912055016] – (.Microsoft Corporation – Application de démarrage de Windows.) (.22/08/2013 – 10:58:29.) — C:WindowsSystem32Wininit.exe [144384]
[MD5.65C36A29A131A3A5D64B29FAC4EF6DD6] – (.Microsoft Corporation – Extensions Internet pour Win32.) (.22/02/2014 – 10:11:56.) — C:WindowsSystem32wininet.dll [2262016]
[MD5.306EB21E5B480AE9065EA55AC8C35936] – (.Microsoft Corporation – Application d’ouverture de session Windows.) (.22/02/2014 – 10:45:48.) — C:WindowsSystem32Winlogon.exe [562176]
[MD5.AFCAB4DC692CCE37E283B00E2D7B438F] – (.Microsoft Corporation – Bibliothèque de licences.) (.21/12/2013 – 09:54:07.) — C:WindowsSystem32sppcomapi.dll [447488]
[MD5.239268BAB58EAE9A3FF4E08334C00451] – (.Microsoft Corporation – Pilote de fonction connexe pour WinSock.) (.22/08/2013 – 14:25:35.) — C:Windowssystem32DriversAFD.sys [567296]
[MD5.74B14192CF79A72F7536B27CB8814FBD] – (.Microsoft Corporation – ATAPI IDE Miniport Driver.) (.22/08/2013 – 13:43:41.) — C:Windowssystem32Driversatapi.sys [26464]
[MD5.2FA6510E33F7DEFEC03658B74101A9B9] – (.Microsoft Corporation – CD-ROM File System Driver.) (.22/08/2013 – 12:40:15.) — C:Windowssystem32DriversCdfs.sys [88576]
[MD5.C6796EA22B513E3457514D92DCDB1A3D] – (.Microsoft Corporation – SCSI CD-ROM Driver.) (.22/08/2013 – 09:46:35.) — C:Windowssystem32DriversCdrom.sys [164352]
[MD5.A03F362C5557E238CBFA914689C77248] – (.Microsoft Corporation – DFS Namespace Client Driver.) (.06/03/2014 – 10:22:50.) — C:Windowssystem32DriversDfsC.sys [134144]
[MD5.03909BDBFF0DCACCABF2B2D4ADEE44DC] – (.Microsoft Corporation – High Definition Audio Bus Driver.) (.22/08/2013 – 12:38:38.) — C:Windowssystem32DriversHDAudBus.sys [78336]
[MD5.84CFC5EFA97D0C965EDE1D56F116A541] – (.Microsoft Corporation – Pilote de port i8042.) (.22/08/2013 – 12:39:15.) — C:Windowssystem32Driversi8042prt.sys [107520]
[MD5.B7342B3C58E91107F6E946A93D9D4EFD] – (.Microsoft Corporation – IP Network Address Translator.) (.27/11/2013 – 13:02:29.) — C:Windowssystem32DriversIpNat.sys [142848]
[MD5.C997E6A37BA8915224B3FB5024A34F69] – (.Microsoft Corporation – Minirdr SMB Windows NT.) (.06/03/2014 – 10:20:23.) — C:Windowssystem32DriversMRxSmb.sys [402944]
[MD5.0217532E19A748F0E5D569307363D5FD] – (.Microsoft Corporation – MBT Transport driver.) (.22/08/2013 – 12:37:02.) — C:Windowssystem32DriversnetBT.sys [282624]
[MD5.1C80517BE6836A812F6A9B99B8321351] – (.Microsoft Corporation – Pilote du système de fichiers NT.) (.20/03/2014 – 04:41:24.) — C:Windowssystem32Driversntfs.sys [2013016]
[MD5.764B1121867B2D9B31C491668AC72B2B] – (.Microsoft Corporation – Pilote de port parallèle.) (.22/08/2013 – 12:40:02.) — C:Windowssystem32DriversParport.sys [94208]
[MD5.BBB6272B7F46C4640A8CDB8A70C3450F] – (.Microsoft Corporation – RAS L2TP mini-port/call-manager driver.) (.22/08/2013 – 12:35:51.) — C:Windowssystem32DriversRasl2tp.sys [120832]
[MD5.680C1DAE268B6FB67FA21B389A8B79EF] – (.Microsoft Corporation – Redirecteur de périphérique de Microsoft RDP.) (.14/11/2013 – 08:16:40.) — C:Windowssystem32Driversrdpdr.sys [195584]
[MD5.FFF28F9F6823EB1756C60F1649560BBF] – (.Microsoft Corporation – TDI Translation Driver.) (.22/08/2013 – 14:25:35.) — C:Windowssystem32Driverstdx.sys [107520]
[MD5.3595FBDF25F8BA6256072D103937D7D6] – (.Microsoft Corporation – Pilote de cliché instantané du volume.) (.22/02/2014 – 16:44:13.) — C:Windowssystem32Driversvolsnap.sys [311640]
~ Generic Processes: Scanned in 00mn 00s

—\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 2/4
Mes Videos (My Videos) : 2/2 (Modified)
~ Mes Favoris (My Favorites) : 1/7
~ Mes Documents (My Documents) : 2/4
~ Mon Bureau (My Desktop) : 2/6
~ Menu demarrer (Programs) : 1/27
~ Hidden Files: Scanned in 00mn 00s

—\ Processus lancés
[MD5.2F03C763EE0DFB4DE56176737DEFB2E2] – (.Microsoft Corporation – Touch Keyboard and Handwriting Panel Helper.) — C:Program Files (x86)Common FilesMicrosoft SharedInkTabTip32.exe [21184] [PID.3320]
[MD5.F1CB88B90F5CE1A6D2BCDE90E2100ECC] – (.Apache Software Foundation – OpenOffice Writer.) — C:Program Files (x86)OpenOffice 4programswriter.exe [103936] [PID.4048]
[MD5.55F18BE55D04A5CC961B0A013B2B8FD7] – (.Apache Software Foundation – OpenOffice 4.0.1.) — C:Program Files (x86)OpenOffice 4programsoffice.exe [9837056] [PID.4060]
[MD5.70BC8374217BFC5C24D4504C2459FEB6] – (.CyberLink – CyberLink MediaLibray Service.) — C:Program Files (x86)CyberLinkPower2GoCLMLSvc.exe [111120] [PID.4080]
[MD5.0AC5756636A90E33559439295B25FA94] – (.Apache Software Foundation – OpenOffice 4.0.1.) — C:Program Files (x86)OpenOffice 4programsoffice.bin [9828864] [PID.4092]
[MD5.48BE298F7FD1BEF4D8FBACB04D8D95C4] – (.Adobe Systems Incorporated – Adobe Reader and Acrobat Manager.) — C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe [958576] [PID.2688]
[MD5.6F85F3875C387BEEA08A3A7D60B06036] – (.Microsoft Corp. – Bing Desktop Application.) — C:Program Files (x86)MicrosoftBingDesktopBingDesktop.exe [2353880] [PID.3188]
[MD5.053648EC64B4C4AADE8886CA9ACC644D] – (.Microsoft Corp. – BDExtHost.exe.) — C:Program Files (x86)MicrosoftBingDesktopBDExtHost.exe [207576] [PID.4960]
[MD5.377E3B00DA2FDC33ADB7DA976ECE3B95] – (.Microsoft Corp. – BDAppHost.exe.) — C:Program Files (x86)MicrosoftBingDesktopBDAppHost.exe [153304] [PID.5000]
[MD5.CF3A4298B6D8B1C7441812058C748E7A] – (.Microsoft Corp. – BDRuntimeHost.exe.) — C:Program Files (x86)MicrosoftBingDesktopBDRuntimeHost.exe [369880] [PID.5032]
[MD5.0B50F07E63EE15383CDFDC26D7A3D3E3] – (.ASUSTek Computer Inc. – ATK Media.) — C:Program Files (x86)ASUSATK PackageATK MediaDMedia.exe [205184] [PID.4396]
[MD5.23075147F62C896784C66D706F38360E] – (.ASUSTek Computer Inc. – ATKOSD2.) — C:Program Files (x86)ASUSATK PackageATKOSD2ATKOSD2.exe [328504] [PID.4448]
[MD5.AA03C052F3000CED0A300C0AC949B50F] – (.ASUSTeK Computer Inc. – ASUS Quick Gesture Exe.) — C:Program Files (x86)ASUSASUS Smart GestureQuickGesturex86QuickGesture.exe [20280] [PID.4784]
[MD5.C570FD825751F7805CE226F68C4605DE] – (.ASUS – ACMON.) — C:Program Files (x86)ASUSSplendidACMON.exe [54488] [PID.3108]
[MD5.B07086D59443DAC6A668D691B27B968C] – (.ASUSTeK Computer Inc. – ASUS Color Engine.) — C:Program Files (x86)ASUSSplendidColorUService.exe [176240] [PID.2932]
[MD5.97432AB9F1B3B3E63E778C1E69E71E91] – (.ASUSTek Computer Inc. – ASUS USB Charger Plus.) — C:Program Files (x86)ASUSUSBChargerPlusUSBChargerPlus.exe [1124032] [PID.2804]
[MD5.D127D2EF6893B7A333FADFACF49AAD74] – (.Conexant Systems, Inc – SmartAudio.) — C:Program FilesConexantSAIISmartAudio.exe [1020632] [PID.692]
[MD5.2EBBBFC120593C683796092F2DDA0EFC] – (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe [841032] [PID.336]
[MD5.41AD6110110A2E89957F831DCBFAF892] – (.Malwarebytes Corporation – Malwarebytes Anti-Malware.) — C:Program Files (x86)Malwarebytes Anti-Malwarembam.exe [6963512] [PID.1468]
[MD5.1780A53FCE5975B94604775CD9460F22] – (.Nicolas Coolman – ZHPDiag.) — C:Program Files (x86)ZHPDiagZHPDiag.exe [7865344] [PID.5232]
~ Processes Running: Scanned in 00mn 00s

—\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:UsersLaurianne.REMYAppDataLocalGoogleChromeUser DataDefaultPreferences
G1 – GCS: Preference [User DataDefault] http://www.bing.com” onclick=”window.open(this.href);return false;
G0 – GCSP: Preference [User DataDefault][HomePage] http://www.msn.com” onclick=”window.open(this.href);return false;
G2 – GCE: Preference [User DataDefault] [neajdppkdcdipfabeoofebfddakdcjhd] Google Network Speech v.1.0 (Activé)
G2 – GCE: Preference [User DataDefault] [nkeimhogjdpnpccoofpliimaahmaaome] Hangout Services v.1.0 (Activé)
G2 – GCE: Preference [User DataDefault] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.6.1 (Activé)

—\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 12 Legitimates Filtered in 00mn 13s

—\ Internet Explorer, Proxy Management (R5)
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = no key
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyEnable = 0
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,MigrateProxy = 1
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,EnableHttp1_1 = 1
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s

—\ Analyse des lignes F0, F1, F2, F3 – IniFiles, Autoloading programs
F2 – REG:system.ini: USERINIT=C:Windowssystem32userinit.exe,
F2 – REG:system.ini: Shell=C:Windowsexplorer.exe
F2 – REG:system.ini: VMApplet=C:WindowsSystem32SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s

—\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21

—\ Internet Explorer Toolbars (O3)
O3 – Toolbar: Google Toolbar – [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. – Google Toolbar.) — C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_64.dll =>Toolbar.Google
O3 – ToolbarWebBrowser: (no name) – [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
~ Toolbar: Scanned in 00mn 00s

—\ Applications lancées au démarrage du système (O4)
O4 – HKLM..Run: [Persistence] . (.Intel Corporation – persistence Module.) — C:WINDOWSsystem32igfxpers.exe
O4 – HKCU..Run: [Power2GoExpress] Clé orpheline
O4 – HKLM..Wow6432NodeRun: [CLMLServer] . (.CyberLink – CyberLink MediaLibray Service.) — C:Program Files (x86)CyberLinkPower2GoCLMLSvc.exe
O4 – HKLM..Wow6432NodeRun: [Adobe ARM] . (.Adobe Systems Incorporated – Adobe Reader and Acrobat Manager.) — C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe =>.Adobe Systems Incorporated
O4 – HKLM..Wow6432NodeRun: [BingDesktop] . (.Microsoft Corp. – Bing Desktop Application.) — C:Program Files (x86)MicrosoftBingDesktopBingDesktop.exe
O4 – HKUSS-1-5-21-2438500433-15155753-1834781870-1001..Run: [Power2GoExpress] Clé orpheline
~ Application: Scanned in 00mn 00s

—\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 – Extra button: Se&nd to OneNote [64Bits] – {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation – Microsoft OneNote Internet Explorer Add-in.) — C:Program FilesMicrosoft Office 15rootVFSProgramFilesX64Microsoft OfficeOffice15ONBttnIE.dll =>.Microsoft Corporation
O9 – Extra button: Lync Click to Call [64Bits] – {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} — C:Program FilesMicrosoft Office 15rootVFSProgramFilesX64Microsoft OfficeOffice15lync.exe (.not file.)
O9 – Extra button: OneNote Lin&ked Notes [64Bits] – {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation – Microsoft OneNote Internet Explorer Add-in.) — C:Program FilesMicrosoft Office 15rootVFSProgramFilesX64Microsoft OfficeOffice15ONBttnIELinkedNotes.dll =>.Microsoft Corporation
~ IE Extra Buttons: Scanned in 00mn 00s

—\ Modification Domaine/Adresses DNS (O17)
O17 – HKLMSystemCCSServicesTcpip..{3566455D-3A6E-49EC-9CB0-8D1036AF60CE}: DhcpNameServer = 192.168.0.254
O17 – HKLMSystemCCSServicesTcpip..{3897232E-62EF-4685-AD45-1F04681F7B33}: DhcpNameServer = 192.168.0.254
O17 – HKLMSystemCS1ServicesTcpip..{3566455D-3A6E-49EC-9CB0-8D1036AF60CE}: DhcpNameServer = 192.168.0.254
O17 – HKLMSystemCS1ServicesTcpip..{3897232E-62EF-4685-AD45-1F04681F7B33}: DhcpNameServer = 192.168.0.254
O17 – HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 192.168.0.254
~ Domain: Scanned in 00mn 00s

—\ Protocole additionnel (O18)
O18 – Handler: wlpg [64Bits] – {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (…) —
O18 – Filter: application/x-msdownload [64Bits] – {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation – Microsoft .NET Runtime Execution Engine.) — C:WindowsSystem32mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s

—\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 – Winlogon Notify: igfxcui . (.Intel Corporation – igfxdev Module.) — C:WindowsSystem32igfxdev.dll
~ Winlogon: Scanned in 00mn 00s

—\ Tâches planifiées en automatique (O39)
O39 – APT: – (..) — C:WindowsSystem32TasksGoogleUpdateTaskMachineCore [1108]
O39 – APT: – (..) — C:WindowsSystem32TasksGoogleUpdateTaskMachineUA [1112]
~ Scheduled Task: 16 Legitimates Filtered in 00mn 03s

—\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 – CFD: 07/11/2013 – 14:09:43 – [] —-D C:ProgramDataInstallMate =>PUP.Tarma
~ Program Folder: 117 Legitimates Filtered in 00mn 00s

—\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 – LFC:[MD5.12B0701B1CEC1A7BB0E4C71D97661E23] – 20/04/2014 – 14:03:26 —A- . (…) — C:WindowsSystem32ApnDatabase.xml [387210]
O44 – LFC:[MD5.385AF1C48CE3E86B37B9E66749FFEC1B] – 20/04/2014 – 14:22:11 —A- . (…) — C:WindowsSystem32srms.dat [50053]
O44 – LFC:[MD5.E7B53AF004BEE5112F787A6E5B04D737] – 20/04/2014 – 14:22:15 —A- . (…) — C:WindowsSystem32connectedsearch-results.searchconnector-ms [11109]
O44 – LFC:[MD5.F1DB86EA935C13CDFF27AB957297136A] – 20/04/2014 – 14:22:35 —A- . (…) — C:WindowsSystem32connectedsearch-suggestions.searchconnector-ms [7762]
O44 – LFC:[MD5.1FDF29F970E2E843B4DC5D0626D0EDD5] – 20/04/2014 – 14:22:35 —A- . (…) — C:WindowsSystem32connectedsearch-zeroinput.searchconnector-ms [7130]
O44 – LFC:[MD5.DE461B86C05946D10E519F512D09E389] – 20/04/2014 – 14:22:36 —A- . (…) — C:WindowsSystem32RacRules.xml [100197]
O44 – LFC:[MD5.119E0F7A71775A5CFB208B036ECE35E1] – 20/04/2014 – 14:23:50 —A- . (…) — C:WindowsSystem32WimBootCompress.ini [2255]
O44 – LFC:[MD5.DCF2510E0745720E543E84F5E921FCC0] – 20/04/2014 – 14:26:32 —A- . (…) — C:WindowsSystem32dfpinc.dat [262335]
O44 – LFC:[MD5.FFFCC3C3ED6886A95D3C0E1B49C652BA] – 20/04/2014 – 14:28:59 —A- . (…) — C:WindowsSystem32systemsf.ebd [139600]
O44 – LFC:[MD5.08750A50CF027F93070C8BB78E27C3B7] – 20/04/2014 – 14:45:01 -SH– . (…) — C:WindowsSystem32desktop.ini [75]
O44 – LFC:[MD5.443D7516B17BC4B41DC8B1363C4B6902] – 29/04/2014 – 10:53:13


. (…) — C:UsbFix [Scan 1] MINILAURIANNE.txt [9413]
O44 – LFC:[MD5.026BE04579F68BED3F020A853306971B] – 29/04/2014 – 10:54:51


. (…) — C:.~lock.UsbFix [Scan 1] MINILAURIANNE.txt# [136]
O44 – LFC:[MD5.8A78944199D210A4A3970BE6E0A553B7] – 29/04/2014 – 14:47:30 —A- . (…) — C:UsbFix [Clean 2] MINILAURIANNE.txt [6170]
O44 – LFC:[MD5.002EFB31D057FB934CAEEDAB0066B314] – 29/04/2014 – 18:24:55 —A- . (…) — C:UsbFix [Scan 2] MINILAURIANNE.txt [8873]
~ Files: 564 Legitimates Filtered in 00mn 12s

—\ Enumération des clés de registre StartupReg (SMSR) (O53)
O53 – SMSR:HKLM…startupregDisableS3S4 [Key] . (…) — c:windowstempDisableS3S464sethigh.cmd (.not file.)
~ SMSR Keys: 10 Legitimates Filtered in 00mn 00s

—\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 – MWPS:[HKLM…PoliciesSystem] – “PromptOnSecureDesktop”=0
O55 – MWPS:[HKLM…PoliciesSystem] – “EnableUIADesktopToggle”=0
O55 – MWPS:[HKLM…PoliciesSystem] – “FilterAdministratorToken”=0
~ MWPS: 19 Legitimates Filtered in 00mn 00s

—\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 – MWPE:[HKLM…policiesExplorer] – “NoActiveDesktopChanges”=1
~ MWPE Keys: 5 Legitimates Filtered in 00mn 00s

—\ Liste des pilotes du système (SDL) (O58)
O58 – SDL:13/08/2013 – 00:25:46 —A- . (.Windows (R) Win 7 DDK provider – BCM Function 2 Device Driver.) — C:WindowsSystem32Driversbcmfn2.sys [17624]
O58 – SDL:02/08/2012 – 04:22:48 —A- . (.Pas de propriétaire – Keyboard Filter Driver.) — C:WindowsSystem32Driverskbfiltr.sys [14992]
O58 – SDL:22/01/2014 – 07:52:10 —A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) – SAMSUNG USB Composite Device Driver (MSS Ver.3).) — C:WindowsSystem32Driversssudbus.sys [108800]
O58 – SDL:22/01/2014 – 07:52:10 —A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) – SAMSUNG Android Modem Device Driver (MSS Ver.3).) — C:WindowsSystem32Driversssudmdm.sys [206080]
O58 – SDL:22/08/2013 – 13:43:32 —A- . (.Promise Technology, Inc. – Promise SuperTrak EX Series Driver for Windows x64.) — C:WindowsSystem32Driversstexstor.sys [31072]
~ Drivers: 52 Legitimates Filtered in 00mn 01s

—\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 – LFC: 28/04/2014 – 21:37:13 —A- . (.Premium Installer.) — C:UsersLaurianne.REMYDownloadsSetup.exe [237856]
O61 – LFC: 29/04/2014 – 21:36:25 —A- . (.SQLite Development Team.) — C:UsersLaurianne.REMYAppDataLocalMicrosoftWindowsINetCacheIEFIE63SCXSQLite3_300700200[1].dll [536576]
O61 – LFC: 29/04/2014 – 21:36:42 —A- . (…) — C:UsersLaurianne.REMYAppDataRoamingsp_data.sys [74]
O61 – LFC: 29/04/2014 – 21:37:06 —A- . (…) — C:UsersLaurianne.REMYDownloadsadwcleaner.exe [1310621]
O61 – LFC: 29/04/2014 – 21:37:09 —A- . (…) — C:UsersLaurianne.REMYDownloadsantivirus2.exe [684744]
~ 263 Fichiers temporaires (Temporary files)
~ Files: 26 Legitimates Filtered in 00mn 55s

—\ Liste des outils de désinfection (LATC) (O63)
O63 – Logiciel: UsbFix – (.El Desaparecido – http://www.usbfix.nethttp://www.sosvirus.net.) [HKLM] — Usbfix
O63 – Logiciel: ZHPDiag 2014 – (.Nicolas Coolman.) [HKLM] — ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s

—\ Associations Shell Spawning (O67)
O67 – Shell Spawning: [HKCU..openCommand] (.Not Key.)
~ FASS Keys: 11 Legitimates Filtered in 00mn 00s

—\ Menu de démarrage Internet (SMI) (O68)
O68 – StartMenuInternet: [HKLM..ShellopenCommand] (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe
O68 – StartMenuInternet: [HKLM..ShellopenCommand] (.Microsoft Corporation – Internet Explorer.) — C:Program FilesInternet Exploreriexplore.exe
~ Keys: Scanned in 00mn 00s

—\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 – SBI: SearchScopes [HKCU] A92BC789786F4515BF5580F77E655B54 – (Mysearchdial) – http://start.mysearchdial.com” onclick=”window.open(this.href);return false; =>Adware.MyWebSearch
O69 – SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} – (Bing) – http://www.bing.com” onclick=”window.open(this.href);return false;
O69 – SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} – (Google) – http://www.google.com” onclick=”window.open(this.href);return false;
O69 – SBI: SearchScopes [HKCU] {9CB96984-43C3-4D44-90EF-01466EFCF7BB} – (Yahoo! (Avast)) – http://fr.yhs4.search.yahoo.com” onclick=”window.open(this.href);return false;
~ Keys: Scanned in 00mn 00s

—\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.4A93070098539B54FDA391D4D551C880] [SPRF][22/07/2009] (…) — C:ProgramDataSetStretch.exe [24576]
[MD5.CA4A865B04D84129AC08664560AA7CCD] [SPRF][11/04/2014] (…) — C:UsersLaurianne.REMYAppDataRoamingmy_intel.sys [21]
[MD5.52C8A1FF6B580F6B056B3D017182FF8E] [SPRF][29/04/2014] (…) — C:UsersLaurianne.REMYAppDataRoamingsp_data.sys [74]
~ Files: 3 Legitimates Filtered in 00mn 00s

—\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.FC0C921189E6B2BF41C363678B37BD9F] [WIS][12/10/2013] (.Google Inc. – Google Toolbar for Internet Explorer.) — C:WindowsInstaller9418df.msi [28672] =>Toolbar.Google
~ WIS: 1 Legitimates Filtered in 00mn 02s

—\ Recherche de clés de registre Tracing (O100)
HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarNotifier_RASAPI32 =>Toolbar.Google
~ BTK: 52 Legitimates Filtered in 00mn 00s

—\ Recherche de clés de registre CLSID (O101)
[HKCRCLSID{2318C2B1-4965-11d4-9B18-009027A5CD4F}] (Google Toolbar) =>Toolbar.Google
[HKCRCLSID{AA58ED58-01DD-4d91-8333-CF10577473F7}] (Google Toolbar Helper) =>Toolbar.Google
~ BCK: 5082 Legitimates Filtered in 00mn 10s

—\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS – | Demand 01/10/2013 279000 | (cphs) . (.Intel Corporation.) – C:WindowsSysWow64IntelCpHeciSvc.exe
SS – | Demand 12/10/2010 206072 | (GamesAppService) . (.WildTangent, Inc..) – C:Program Files (x86)WildTangent GamesAppGamesAppService.exe
SS – | Auto 26/08/2013 116648 | (gupdate) . (.Google Inc..) – C:Program Files (x86)GoogleUpdateGoogleUpdate.exe
SS – | Demand 26/08/2013 116648 | (gupdatem) . (.Google Inc..) – C:Program Files (x86)GoogleUpdateGoogleUpdate.exe
SS – | Demand 12/10/2013 194032 | (gusvc) . (.Google.) – C:Program Files (x86)GoogleCommonGoogle UpdaterGoogleUpdaterService.exe
SR – | Auto 11/05/2013 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) – C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe
SR – | Auto 14/06/2013 1281640 | (AFBAgent) . (.ASUSTeK Computer Inc..) – C:Windowssystem32FBAgent.exe
SR – | Demand 15/01/2013 107320 | (ASLDRService) . (.ASUSTek Computer Inc..) – C:Program Files (x86)ASUSATK PackageATK HotkeyASLDRSrv.exe
SR – | Demand 29/04/2013 277120 | (ASUS InstantOn) . (.ASUS.) – C:Program FilesASUSP4GInsOnSrv.exe
SR – | Demand 19/12/2012 72192 | (Asus WebStorage Windows Service) . (…) – C:Program Files (x86)ASUSWebStorage Sync Agent1.1.18.159AsusWSWinService.exe
SR – | Demand 21/11/2011 96896 | (ATKGFNEXSrv) . (.ASUS.) – C:Program Files (x86)ASUSATK PackageATKGFNEXGFNEXSrv.exe
SR – | Auto 12/03/2014 227904 | (GamesAppIntegrationService) . (.WildTangent.) – C:Program Files (x86)WildTangent GamesAppGamesAppIntegrationService.exe
SR – | Demand 24/04/2012 169752 | (ICCS) . (.Intel Corporation.) – C:Program Files (x86)IntelIntel(R) Integrated Clock Controller ServiceICCProxy.exe
SR – | Demand 20/04/2012 635104 | (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) – C:Program FilesInteliCLS ClientHeciServer.exe
SR – | Demand 27/06/2012 129856 | (Intel(R) ME Service) . (.Intel Corporation.) – C:Program Files (x86)IntelIntel(R) Management Engine ComponentsFWServiceIntelMeFWService.exe
SR – | Demand 25/06/2012 166720 | (jhi_service) . (.Intel Corporation.) – C:Program Files (x86)IntelIntel(R) Management Engine ComponentsDALjhi_service.exe
SR – | Demand 17/07/2012 277824 | (LMS) . (.Intel Corporation.) – C:Program Files (x86)IntelIntel(R) Management Engine ComponentsLMSLMS.exe
SR – | Auto 03/04/2014 1809720 | (MBAMScheduler) . (.Malwarebytes Corporation.) – C:Program Files (x86)Malwarebytes Anti-Malwarembamscheduler.exe
SR – | Auto 03/04/2014 857912 | (MBAMService) . (.Malwarebytes Corporation.) – C:Program Files (x86)Malwarebytes Anti-Malwarembamservice.exe
SR – | Demand 17/07/2012 365376 | (UNS) . (.Intel Corporation.) – C:Program Files (x86)IntelIntel(R) Management Engine ComponentsUNSUNS.exe
SR – | Demand 10/07/1658 0 | (WdNisSvc) . (…) – C:Program Files (x86)Windows DefenderNisSrv.exe
SR – | Auto 10/07/1658 0 | (WinDefend) . (…) – C:Program Files (x86)Windows DefenderMsMpEng.exe
SR – | Auto 10/07/1658 0 | (WMPNetworkSvc) . (…) – C:Program Files (x86)Windows Media Playerwmpnetwk.exe =>.Microsoft Corporation
SR – | Demand 22/08/2013 37768 | C:WindowsSystem32wuaueng.dll (wuauserv) . (.Microsoft Corporation.) – C:WindowsSystem32svchost.exe
~ Services: Scanned in 00mn 11s

—\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Run by Laurianne.REMY at 29/04/2014 21:38:25
~ OS 64 not supported by MBR tool
~ MBR: 0 Legitimates Filtered in 00mn 00s

—\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog” onclick=”window.open(this.href);return false;
Run by Laurianne.REMY at 29/04/2014 21:38:28
********* Dump file Name *********
C:PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 02s

—\ Scan Additionnel (O88)
Database Version : 13045 – (28/04/2014)
Clés trouvées (Keys found) : 0
Valeurs trouvées (Values found) : 1
Dossiers trouvés (Folders found) : 1
Fichiers trouvés (Files found) : 3

[HKLMSoftwareMicrosoftInternet ExplorerToolbar]:{2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google^
C:ProgramDataInstallMate =>PUP.Tarma^
C:WindowsInstaller9418df.msi =>Toolbar.Google^
[HKCRCLSID{2318C2B1-4965-11d4-9B18-009027A5CD4F}] (Google Toolbar) =>Toolbar.Google^
[HKCRCLSID{AA58ED58-01DD-4d91-8333-CF10577473F7}] (Google Toolbar Helper) =>Toolbar.Google^
~ Additionnel Scan: 192828 Items scanned in 00mn 24s

—\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.webs.com/apps/blog/show/29637859-toolbar-tarma” onclick=”window.open(this.href);return false; =>PUP.Tarma
http://nicolascoolman.webs.com/apps/blog/show/27146838-adware-mywebsearch” onclick=”window.open(this.href);return false; =>Adware.MyWebSearch
~ MSI: 2 link(s) detected in 00mn 00s

~ 1096 Legitimates filtered by white list
End of the scan (428 lines in 03mn 31s)(0)[/spoiler:czxqmfq1]